1. Cross-site scripting (reflected)
2. Cookie without HttpOnly flag set
3. Cross-domain Referer leakage
4.1. http://concerts.stubhub.com/assets/js/jquery.colorbox.js
4.2. http://concerts.stubhub.com/assets/js/jquery.cookie.js
4.3. http://concerts.stubhub.com/assets/js/jquery.dimensions.js
5. Content type incorrectly stated
Severity: | High |
Confidence: | Certain |
Host: | http://concerts.stubhub |
Path: | /dave-matthews-band-blog/ |
GET /dave-matthews-band-blog/ Host: concerts.stubhub.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.2 (KHTML, like Gecko) Chrome/15.0.874.120 Safari/535.2 Accept: */* Referer: http://concerts.stubhub Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=440AE94A0D3D1 |
HTTP/1.1 200 OK Date: Sat, 12 Nov 2011 16:12:26 GMT Server: Apache/2.2.3 (CentOS) X-Powered-By: PHP/5.1.6 Set-Cookie: exp_last_activity Expires: Mon, 26 Jul 1997 05:00:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Last-Modified: Sat, 12 Nov 2011 16:12:26 GMT Vary: Accept-Encoding,User imagetoolbar: no Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 41556 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content ...[SNIP]... <!-- s.pageName="fansite s.hier1="ConcertHub" s.eVar26="www" var s_code=s.t();if(s_code ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://concerts.stubhub |
Path: | /dave-matthews-band-blog/ |
GET /dave-matthews-band-blog/ Host: concerts.stubhub.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Sat, 12 Nov 2011 16:04:41 GMT Server: Apache/2.2.3 (CentOS) X-Powered-By: PHP/5.1.6 Set-Cookie: exp_last_visit=1005753881 Set-Cookie: exp_last_activity Set-Cookie: PHPSESSID=cg7a4ar2kh Expires: Mon, 26 Jul 1997 05:00:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Last-Modified: Sat, 12 Nov 2011 16:04:41 GMT Vary: Accept-Encoding,User imagetoolbar: no Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 41108 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content ...[SNIP]... <!-- s.pageName="fansite s.hier1="ConcertHub" s.eVar26="www" var s_code=s.t();if(s_code ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://concerts.stubhub |
Path: | /dave-matthews-band-blog/ |
GET /dave-matthews-band-blog/ HTTP/1.1 Host: concerts.stubhub.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Sat, 12 Nov 2011 16:04:37 GMT Server: Apache/2.2.3 (CentOS) X-Powered-By: PHP/5.1.6 Set-Cookie: exp_last_visit=1005753877 Set-Cookie: exp_last_activity Set-Cookie: exp_tracker=a%3A1%3A%7Bi Set-Cookie: PHPSESSID=cbpieusbnh Expires: Mon, 26 Jul 1997 05:00:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Last-Modified: Sat, 12 Nov 2011 16:04:37 GMT Vary: Accept-Encoding,User imagetoolbar: no Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 40770 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://concerts.stubhub |
Path: | /dave-matthews-band-blog/ |
GET /dave-matthews-band-blog/ Host: concerts.stubhub.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.2 (KHTML, like Gecko) Chrome/15.0.874.120 Safari/535.2 Accept: */* Referer: http://concerts.stubhub Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=440AE94A0D3D1 |
HTTP/1.1 200 OK Date: Sat, 12 Nov 2011 16:12:08 GMT Server: Apache/2.2.3 (CentOS) X-Powered-By: PHP/5.1.6 Set-Cookie: exp_last_activity Expires: Mon, 26 Jul 1997 05:00:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Last-Modified: Sat, 12 Nov 2011 16:12:08 GMT Vary: Accept-Encoding,User imagetoolbar: no Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 41256 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content ...[SNIP]... <span style="position:relative; right:0; margin-left:77px;"> <a href="http://www.facebook <a href="http://twitter.com ...[SNIP]... p for a long time after they said that they would be going on an extended hiatus this year and just enjoying their time off. But it looks like you can’t really keep the guys away from the stage. <a href="http://www ...[SNIP]... </a>, and it will be a while yet. <a href="http://www.examiner ...[SNIP]... <p><a href="http://www.examiner ...[SNIP]... <p>Even though the Dave Matthews Band is now officially on hiatus, it doesn’t mean that fans need to go an entire lonely year without DMB music or cool merchandise. <a href="http://www ...[SNIP]... <p>Although they are now officially on hiatus, the Dave Matthews Band interrupted their vacation, just after it started for a <a href="http://www.jambands ...[SNIP]... <p><a href="http://www ...[SNIP]... <p><a href="http://www ...[SNIP]... <p>Whenever Dave Matthews and Tim Reynolds collaborate, it’s always a sure bet that they will make some pretty stellar music together. <a href="http://www.examiner ...[SNIP]... <p><a href="http://www.jambands ...[SNIP]... <p><a href="http://www.spinner ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://concerts.stubhub |
Path: | /assets/js/jquery |
GET /assets/js/jquery Host: concerts.stubhub.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.2 (KHTML, like Gecko) Chrome/15.0.874.120 Safari/535.2 Accept: */* Referer: http://concerts.stubhub Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=440AE94A0D3D1 |
HTTP/1.1 200 OK Date: Sat, 12 Nov 2011 16:12:08 GMT Server: Apache/2.2.3 (CentOS) Last-Modified: Mon, 14 Feb 2011 21:10:44 GMT ETag: "2ec4cc-5916-49c447b Accept-Ranges: bytes Vary: Accept-Encoding,User Content-Length: 22806 Connection: close Content-Type: application/x-javascript // ColorBox v1.3.6 - a full featured, light-weight, customizable lightbox based on jQuery 1.3 // c) 2009 Jack Moore - www.colorpowered.com - jack@colorpowered.com // Licensed under the MIT license: http://www.opensource.org (function ($) { // Shortcuts (to increase compression) var colorbox = 'colorbox', hover = 'hover', TRUE = tru ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://concerts.stubhub |
Path: | /assets/js/jquery.cookie |
GET /assets/js/jquery.cookie Host: concerts.stubhub.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.2 (KHTML, like Gecko) Chrome/15.0.874.120 Safari/535.2 Accept: */* Referer: http://concerts.stubhub Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=440AE94A0D3D1 |
HTTP/1.1 200 OK Date: Sat, 12 Nov 2011 16:12:07 GMT Server: Apache/2.2.3 (CentOS) Last-Modified: Mon, 14 Feb 2011 21:10:44 GMT ETag: "2ec4d0-1096-49c447b Accept-Ranges: bytes Vary: Accept-Encoding,User Content-Length: 4246 Connection: close Content-Type: application/x-javascript /** * Cookie plugin * * Copyright (c) 2006 Klaus Hartl (stilbuero.de) * Dual licensed under the MIT and GPL licenses: * http://www.opensource.org * http://www.gnu.org/li ...[SNIP]... kie will be set and the cookie transmission will * require a secure protocol (like HTTPS). * @type undefined * * @name $.cookie * @cat Plugins/Cookie * @author Klaus Hartl/klaus.hartl@stilbuero.de */ /** * Get the value of a cookie with the given name. * * @example $.cookie('the_cookie'); * @desc Get the value of a cookie. * * @param String name The name of the cookie. * @return The value of the cookie. * @type String * * @name $.cookie * @cat Plugins/Cookie * @author Klaus Hartl/klaus.hartl@stilbuero.de */ jQuery.cookie = function(name, value, options) { if (typeof value != 'undefined') { // name and value given, set cookie options = options || {}; if (value === null) { ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://concerts.stubhub |
Path: | /assets/js/jquery |
GET /assets/js/jquery Host: concerts.stubhub.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.2 (KHTML, like Gecko) Chrome/15.0.874.120 Safari/535.2 Accept: */* Referer: http://concerts.stubhub Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=440AE94A0D3D1 |
HTTP/1.1 200 OK Date: Sat, 12 Nov 2011 16:12:07 GMT Server: Apache/2.2.3 (CentOS) Last-Modified: Mon, 14 Feb 2011 21:10:44 GMT ETag: "2ec4d5-d72-49c447b1c3d00 Accept-Ranges: bytes Vary: Accept-Encoding,User Content-Length: 3442 Connection: close Content-Type: application/x-javascript /* Copyright (c) 2007 Paul Bakaus (paul.bakaus@googlemail * Dual licensed under the MIT (http://www.opensource * and GPL (http://www.opensource * * $LastCha ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://concerts.stubhub |
Path: | /favicon.ico |
GET /favicon.ico HTTP/1.1 Host: concerts.stubhub.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.2 (KHTML, like Gecko) Chrome/15.0.874.120 Safari/535.2 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTSID=440AE94A0D3D1 |
HTTP/1.1 200 OK Date: Sat, 12 Nov 2011 16:12:13 GMT Server: Apache/2.2.3 (CentOS) Last-Modified: Mon, 14 Feb 2011 21:06:50 GMT ETag: "2ec4e4-57e-49c446d29ae80 Accept-Ranges: bytes Vary: Accept-Encoding,User Content-Length: 1406 Connection: close Content-Type: text/plain; charset=UTF-8 ..............h.......(.. ...[SNIP]... |