1.1. http://mp.apmebf.com/ad/js/10105-118547-2060-6 [REST URL parameter 1]
1.2. http://mp.apmebf.com/ad/js/10105-118547-2060-6 [REST URL parameter 2]
1.3. http://mp.apmebf.com/ad/js/10105-118547-2060-6 [REST URL parameter 3]
1.4. http://mp.apmebf.com/ad/js/10105-118547-2060-6 [S cookie]
4. Cookie scoped to parent domain
5. Cross-domain Referer leakage
5.1. http://mp.apmebf.com/ad/js/10105-118547-2060-6
5.2. http://mp.apmebf.com/ad/js/10105-118547-2060-6
5.3. http://mp.apmebf.com/ad/js/10105-118547-2060-6
6. Cookie without HttpOnly flag set
Severity: | High |
Confidence: | Certain |
Host: | http://mp.apmebf.com |
Path: | /ad/js/10105-118547-2060 |
GET /dcc52%0d%0a267c4eb9467/js/10105-118547-2060-6 Accept: */* Referer: http://www.msn.com/ Accept-Language: en-US User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0) Accept-Encoding: gzip, deflate Cookie: S=fks3qs-6545-129641 Proxy-Connection: Keep-Alive Host: mp.apmebf.com |
HTTP/1.1 302 Found Date: Sat, 12 Feb 2011 01:22:34 GMT Server: Apache P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR PSAo PSDo OUR IND UNI COM NAV" Set-Cookie: S=fks3qs-6545-129641 Location: http://altfarm.mediaplex 267c4eb9467/js/10105-118547-2060-6 Content-Length: 320 Content-Type: text/html; charset=iso-8859-1 <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>302 Found</title> </head><body> <h1>Found</h1> <p>The document has moved <a href="http://altfarm 267c4eb9467 ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://mp.apmebf.com |
Path: | /ad/js/10105-118547-2060 |
GET /ad/f64b5%0d%0a9ca9b2ee10f/10105-118547-2060-6?mpt= Accept: */* Referer: http://www.msn.com/ Accept-Language: en-US User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0) Accept-Encoding: gzip, deflate Cookie: S=fks3qs-6545-129641 Proxy-Connection: Keep-Alive Host: mp.apmebf.com |
HTTP/1.1 302 Found Date: Sat, 12 Feb 2011 01:22:34 GMT Server: Apache P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR PSAo PSDo OUR IND UNI COM NAV" Set-Cookie: S=fks3qs-6545-129641 Location: http://altfarm.mediaplex 9ca9b2ee10f/10105-118547-2060-6?mpt= Content-Length: 320 Content-Type: text/html; charset=iso-8859-1 <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>302 Found</title> </head><body> <h1>Found</h1> <p>The document has moved <a href="http://altfarm 9ca9b2ee ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://mp.apmebf.com |
Path: | /ad/js/10105-118547-2060 |
GET /ad/js/f9b34%0d%0a140281f6438?mpt=[2048082194ER]&mpvc= Accept: */* Referer: http://www.msn.com/ Accept-Language: en-US User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0) Accept-Encoding: gzip, deflate Cookie: S=fks3qs-6545-129641 Proxy-Connection: Keep-Alive Host: mp.apmebf.com |
HTTP/1.1 302 Found Date: Sat, 12 Feb 2011 01:22:35 GMT Server: Apache P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR PSAo PSDo OUR IND UNI COM NAV" Set-Cookie: S=fks3qs-6545-129641 Location: http://altfarm.mediaplex 140281f6438?mpt=[2048082194ER]&mpvc= Content-Length: 303 Content-Type: text/html; charset=iso-8859-1 <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>302 Found</title> </head><body> <h1>Found</h1> <p>The document has moved <a href="http://altfarm 14028 ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://mp.apmebf.com |
Path: | /ad/js/10105-118547-2060 |
GET /ad/js/10105-118547-2060 Accept: */* Referer: http://www.msn.com/ Accept-Language: en-US User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0) Accept-Encoding: gzip, deflate Cookie: S=f1edf%0d%0a6af820b5262 Proxy-Connection: Keep-Alive Host: mp.apmebf.com |
HTTP/1.1 302 Found Date: Sat, 12 Feb 2011 01:22:33 GMT Server: Apache P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR PSAo PSDo OUR IND UNI COM NAV" Set-Cookie: S=f1edf 6af820b5262; domain=.apmebf.com; path=/; expires=Mon, 11-Feb-2013 01:22:33 GMT Location: http://altfarm.mediaplex Content-Length: 304 Content-Type: text/html; charset=iso-8859-1 <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>302 Found</title> </head><body> <h1>Found</h1> <p>The document has moved <a href="http://altfarm ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://mp.apmebf.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: mp.apmebf.com |
HTTP/1.1 200 OK Date: Sat, 12 Feb 2011 01:22:32 GMT Server: Apache P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR PSAo PSDo OUR IND UNI COM NAV" Last-Modified: Fri, 19 Dec 2008 21:38:40 GMT ETag: "1b1f-c7-45e6d21e5d800" Accept-Ranges: bytes Content-Length: 199 Keep-Alive: timeout=5 Connection: Keep-Alive Content-Type: text/x-cross-domain <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml <cross-domain-policy> <allow-access-from domain="*" /> </cross-domain-policy> |
Severity: | Low |
Confidence: | Certain |
Host: | http://mp.apmebf.com |
Path: | /ad/js/10105-118547-2060 |
GET /ad/js/10105-118547-2060 Accept: */* Referer: http://www.msn.com/ Accept-Language: en-US User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0) Accept-Encoding: gzip, deflate Cookie: S=fks3qs-6545-129641 Proxy-Connection: Keep-Alive Host: mp.apmebf.com |
HTTP/1.1 302 Found Date: Sat, 12 Feb 2011 01:22:33 GMT Server: Apache P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR PSAo PSDo OUR IND UNI COM NAV" Set-Cookie: S=fks3qs-6545-129641 Location: http://.aad50df185639591e Content-Length: 302 Content-Type: text/html; charset=iso-8859-1 <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>302 Found</title> </head><body> <h1>Found</h1> <p>The document has moved <a href="http://.aad50d ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://mp.apmebf.com |
Path: | /ad/js/10105-118547-2060 |
GET /ad/js/10105-118547-2060 Accept: */* Referer: http://www.msn.com/ Accept-Language: en-US User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0) Accept-Encoding: gzip, deflate Cookie: S=fks3qs-6545-129641 Proxy-Connection: Keep-Alive Host: mp.apmebf.com |
HTTP/1.1 302 Found Date: Sat, 12 Feb 2011 01:22:32 GMT Server: Apache P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR PSAo PSDo OUR IND UNI COM NAV" Set-Cookie: S=fks3qs-6545-129641 Location: http://altfarm.mediaplex Content-Length: 304 Content-Type: text/html; charset=iso-8859-1 <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>302 Found</title> </head><body> <h1>Found</h1> <p>The document has moved <a href="http://altfarm ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://mp.apmebf.com |
Path: | /ad/js/10105-118547-2060 |
GET /ad/js/10105-118547-2060 Accept: */* Referer: http://www.msn.com/ Accept-Language: en-US User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0) Accept-Encoding: gzip, deflate Cookie: S=fks3qs-6545-129641 Proxy-Connection: Keep-Alive Host: mp.apmebf.com |
HTTP/1.1 302 Found Date: Sat, 12 Feb 2011 01:22:32 GMT Server: Apache P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR PSAo PSDo OUR IND UNI COM NAV" Set-Cookie: S=fks3qs-6545-129641 Location: http://altfarm.mediaplex Content-Length: 304 Content-Type: text/html; charset=iso-8859-1 <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>302 Found</title> </head><body> <h1>Found</h1> <p>The document has moved <a href="http://altfarm ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://mp.apmebf.com |
Path: | /ad/js/10105-118547-2060 |
GET /ad/js/10105-118547-2060 Host: mp.apmebf.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20101203 Firefox/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.msn.com/ |
HTTP/1.1 302 Found Date: Sat, 12 Feb 2011 01:58:05 GMT Server: Apache P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR PSAo PSDo OUR IND UNI COM NAV" Set-Cookie: S=g14vo-2196-1297475 Location: http://altfarm.mediaplex Content-Length: 304 Content-Type: text/html; charset=iso-8859-1 <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>302 Found</title> </head><body> <h1>Found</h1> <p>The document has moved <a href="http://altfarm ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://mp.apmebf.com |
Path: | /ad/js/10105-118547-2060 |
GET /ad/js/10105-118547-2060 Host: mp.apmebf.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20101203 Firefox/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.msn.com/ |
HTTP/1.1 302 Found Date: Sat, 12 Feb 2011 01:54:10 GMT Server: Apache P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR PSAo PSDo OUR IND UNI COM NAV" Set-Cookie: S=g14vo-4605-1297475 Location: http://altfarm.mediaplex Content-Length: 304 Content-Type: text/html; charset=iso-8859-1 <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>302 Found</title> </head><body> <h1>Found</h1> <p>The document has moved <a href="http://altfarm ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://mp.apmebf.com |
Path: | /ad/js/10105-118547-2060 |
GET /ad/js/10105-118547-2060 Accept: */* Referer: http://www.msn.com/ Accept-Language: en-US User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0) Accept-Encoding: gzip, deflate Cookie: S=fks3qs-6545-129641 Proxy-Connection: Keep-Alive Host: mp.apmebf.com |
HTTP/1.1 302 Found Date: Sat, 12 Feb 2011 01:22:32 GMT Server: Apache P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR PSAo PSDo OUR IND UNI COM NAV" Set-Cookie: S=fks3qs-6545-129641 Location: http://altfarm.mediaplex Content-Length: 304 Content-Type: text/html; charset=iso-8859-1 <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>302 Found</title> </head><body> <h1>Found</h1> <p>The document has moved <a href="http://altfarm ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://mp.apmebf.com |
Path: | / |
TRACE / HTTP/1.0 Host: mp.apmebf.com Cookie: b09559a5431f93e0 |
HTTP/1.1 200 OK Date: Sat, 12 Feb 2011 01:22:32 GMT Server: Apache Connection: close Content-Type: message/http TRACE / HTTP/1.0 Host: mp.apmebf.com Cookie: b09559a5431f93e0 Connection: Keep-Alive |
Severity: | Information |
Confidence: | Certain |
Host: | http://mp.apmebf.com |
Path: | /ad/js/10105-118547-2060 |
GET /robots.txt HTTP/1.0 Host: mp.apmebf.com |
HTTP/1.1 200 OK Date: Sat, 12 Feb 2011 01:22:32 GMT Server: Apache P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR PSAo PSDo OUR IND UNI COM NAV" Last-Modified: Sat, 10 Mar 2007 17:40:16 GMT ETag: "1b1a-1a-42b5608766000" Accept-Ranges: bytes Content-Length: 26 Keep-Alive: timeout=5 Connection: Keep-Alive Content-Type: text/plain; charset=ISO-8859-1 User-agent: * Disallow: / |