1. Cross-site scripting (reflected)
2.1. https://fixit.support.microsoft.com/SoftLanding.aspx
2.2. https://fixit.support.microsoft.com/reporting/
3.1. https://fixit.support.microsoft.com/reporting/
3.2. https://fixit.support.microsoft.com/reporting/gadget/fixit4me.gadget
Severity: | High |
Confidence: | Certain |
Host: | https://fixit.support |
Path: | /SoftLanding.aspx |
GET /SoftLanding.aspx?type Host: fixit.support.microsoft Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.218 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: MC1=GUID=f4593467ede |
HTTP/1.1 200 OK Cache-Control: no-cache Pragma: no-cache Content-Type: text/html; charset=utf-8 Expires: -1 Vary: Accept-Encoding Server: Microsoft-IIS/7.5 X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET ServerName: T07 Date: Sat, 03 Sep 2011 02:04:29 GMT Content-Length: 7340 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head><title> Fix it < ...[SNIP]... <a href="mailto:fix4me ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://fixit.support |
Path: | /SoftLanding.aspx |
GET /SoftLanding.aspx?type Host: fixit.support.microsoft Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.218 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: MC1=GUID=f4593467ede |
HTTP/1.1 200 OK Cache-Control: no-cache Pragma: no-cache Content-Type: text/html; charset=utf-8 Expires: -1 Vary: Accept-Encoding Server: Microsoft-IIS/7.5 X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET ServerName: T07 Date: Sat, 03 Sep 2011 02:02:20 GMT Content-Length: 7236 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head><title> Fix it < ...[SNIP]... <a href="mailto:fix4me@microsoft.com&subject=LR Solution ID -1"> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://fixit.support |
Path: | /reporting/ |
GET /reporting/ HTTP/1.1 Host: fixit.support.microsoft Connection: keep-alive Referer: http://www.google.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.218 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: MC1=GUID=f4593467ede |
HTTP/1.1 200 OK Cache-Control: private Content-Type: text/html; charset=utf-8 Vary: Accept-Encoding Server: Microsoft-IIS/7.5 X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET ServerName: T07 Date: Sat, 03 Sep 2011 02:05:49 GMT Content-Length: 11838 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head><title> Microsoft Fix ...[SNIP]... <a href="mailto:fixit4me@microsoft.com" title='Send e-mail to "Fix it"' style="text-decoration: none; color: White;"> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://fixit.support |
Path: | /reporting/ |
GET /reporting/ HTTP/1.1 Host: fixit.support.microsoft Connection: keep-alive Referer: http://www.google.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.218 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: MC1=GUID=f4593467ede |
HTTP/1.1 200 OK Cache-Control: private Content-Type: text/html; charset=utf-8 Vary: Accept-Encoding Server: Microsoft-IIS/7.5 X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET ServerName: T07 Date: Sat, 03 Sep 2011 02:05:49 GMT Content-Length: 11838 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head><title> Microsoft Fix ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://fixit.support |
Path: | /reporting/gadget |
GET /reporting/gadget Host: fixit.support.microsoft Connection: keep-alive Referer: http://support.microsoft User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.218 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: MC1=GUID=f4593467ede |
HTTP/1.1 200 OK Content-Type: application/x-windows Last-Modified: Wed, 15 Apr 2009 03:49:18 GMT Accept-Ranges: bytes ETag: "f3b75277dbdc91:0" Server: Microsoft-IIS/7.5 X-Powered-By: ASP.NET ServerName: T07 Date: Sat, 03 Sep 2011 02:02:08 GMT Content-Length: 154887 MSCF.....E......D........ ...[SNIP]... |