2. Cookie scoped to parent domain
2.1. http://140cc.v.fwmrm.net/ad/l/1
2.2. http://140cc.v.fwmrm.net/ad/p/1
2.3. http://140cc.v.fwmrm.net/ad/p/1
3. Cookie without HttpOnly flag set
3.1. http://140cc.v.fwmrm.net/ad/l/1
3.2. http://140cc.v.fwmrm.net/ad/p/1
3.3. http://140cc.v.fwmrm.net/ad/p/1
Severity: | High |
Confidence: | Certain |
Host: | http://140cc.v.fwmrm.net |
Path: | /ad/l/1 |
GET /ad/l/1?last=0&ct=0&metr Host: 140cc.v.fwmrm.net Proxy-Connection: keep-alive Referer: http://media.mtvnservices Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.133 Safari/534.16 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: NSC_okcbewjq1.gxnsn.ofu |
HTTP/1.1 302 Found Set-Cookie: _uid="c007_557700397 Set-Cookie: _auv="g158249~1 Set-Cookie: _vr="1299937980..333670 Set-Cookie: _cph="1299937795.439.1.1, Set-Cookie: _sc="sg158249.1299937795 Set-Cookie: _wr="g158249";expires=Mon Location: 3e69b 2cb842c799f Content-Length: 0 Date: Sat, 12 Mar 2011 13:53:05 GMT Server: FWS P3P: policyref="http://www |
Severity: | Information |
Confidence: | Certain |
Host: | http://140cc.v.fwmrm.net |
Path: | /ad/l/1 |
GET /ad/l/1?metr=127&ct=3&et Host: 140cc.v.fwmrm.net Proxy-Connection: keep-alive Referer: http://media.mtvnservices Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.133 Safari/534.16 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: NSC_okcbewjq1.gxnsn.ofu |
HTTP/1.1 200 OK Set-Cookie: _uid="c007_557700397 Set-Cookie: _auv="g158249~1 Set-Cookie: _vr="1299937823..333670 Set-Cookie: _cph="1299937795.439.1.1, Set-Cookie: _sc="sg158249.1299937795 Set-Cookie: _wr="g158249";expires=Mon Content-Type: text/html Content-Length: 0 Pragma: no-cache Date: Sat, 12 Mar 2011 13:50:32 GMT Server: FWS P3P: policyref="http://www |
Severity: | Information |
Confidence: | Certain |
Host: | http://140cc.v.fwmrm.net |
Path: | /ad/p/1 |
POST /ad/p/1? HTTP/1.1 Host: 140cc.v.fwmrm.net Proxy-Connection: keep-alive Referer: http://media.mtvnservices content-type: text/xml Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.133 Safari/534.16 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: _auv=""; _cph="1298497425.324.1.1, Content-Length: 1134 <adRequest profile="82125:MTVN_live" version="1" networkId="82125"> ...[SNIP]... |
HTTP/1.1 200 OK Set-Cookie: _sid="c114_558319069 Set-Cookie: _uid="c007_557700397 Set-Cookie: _auv="";expires=Mon, 11 Apr 2011 13:51:24 GMT;domain=.fwmrm.net Set-Cookie: _vr="1299937884..333670 Set-Cookie: _cph="1299937884.439.1.1, Set-Cookie: _sc="sg158249.1299937884 Set-Cookie: _wr="g158249";expires=Mon X-FW-Power-By: Smart Content-Type: text/xml Pragma: no-cache Vary: Accept-Encoding Date: Sat, 12 Mar 2011 13:51:24 GMT Server: FWS P3P: policyref="http://www Content-Length: 8279 <adResponse version='1'><rendere <adRenderers version='1'> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://140cc.v.fwmrm.net |
Path: | /ad/p/1 |
POST /ad/p/1? HTTP/1.1 Host: 140cc.v.fwmrm.net Proxy-Connection: keep-alive Referer: http://media.mtvnservices content-type: text/xml Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.133 Safari/534.16 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: NSC_okcbewjq1.gxnsn.ofu Content-Length: 1134 <adRequest profile="82125:MTVN_live" version="1" networkId="82125"> ...[SNIP]... |
HTTP/1.1 200 OK Set-Cookie: _uid="c007_557700397 Set-Cookie: _auv="g158249~1 Set-Cookie: _vr="1299937896..333670 Set-Cookie: _cph="1299937795.439.1.1, Set-Cookie: _sc="sg158249.1299937795 Set-Cookie: _wr="g158249";expires=Mon X-FW-Power-By: Smart Content-Type: text/xml Pragma: no-cache Vary: Accept-Encoding Date: Sat, 12 Mar 2011 13:51:35 GMT Server: FWS P3P: policyref="http://www Content-Length: 6957 <adResponse version='1'><rendere <adRenderers version='1'> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://140cc.v.fwmrm.net |
Path: | /ad/l/1 |
GET /ad/l/1?metr=127&ct=3&et Host: 140cc.v.fwmrm.net Proxy-Connection: keep-alive Referer: http://media.mtvnservices Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.133 Safari/534.16 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: NSC_okcbewjq1.gxnsn.ofu |
HTTP/1.1 200 OK Set-Cookie: _uid="c007_557700397 Set-Cookie: _auv="g158249~1 Set-Cookie: _vr="1299937823..333670 Set-Cookie: _cph="1299937795.439.1.1, Set-Cookie: _sc="sg158249.1299937795 Set-Cookie: _wr="g158249";expires=Mon Content-Type: text/html Content-Length: 0 Pragma: no-cache Date: Sat, 12 Mar 2011 13:50:32 GMT Server: FWS P3P: policyref="http://www |
Severity: | Information |
Confidence: | Certain |
Host: | http://140cc.v.fwmrm.net |
Path: | /ad/p/1 |
POST /ad/p/1? HTTP/1.1 Host: 140cc.v.fwmrm.net Proxy-Connection: keep-alive Referer: http://media.mtvnservices content-type: text/xml Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.133 Safari/534.16 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: NSC_okcbewjq1.gxnsn.ofu Content-Length: 1134 <adRequest profile="82125:MTVN_live" version="1" networkId="82125"> ...[SNIP]... |
HTTP/1.1 200 OK Set-Cookie: _uid="c007_557700397 Set-Cookie: _auv="g158249~1 Set-Cookie: _vr="1299937896..333670 Set-Cookie: _cph="1299937795.439.1.1, Set-Cookie: _sc="sg158249.1299937795 Set-Cookie: _wr="g158249";expires=Mon X-FW-Power-By: Smart Content-Type: text/xml Pragma: no-cache Vary: Accept-Encoding Date: Sat, 12 Mar 2011 13:51:35 GMT Server: FWS P3P: policyref="http://www Content-Length: 6957 <adResponse version='1'><rendere <adRenderers version='1'> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://140cc.v.fwmrm.net |
Path: | /ad/p/1 |
POST /ad/p/1? HTTP/1.1 Host: 140cc.v.fwmrm.net Proxy-Connection: keep-alive Referer: http://media.mtvnservices content-type: text/xml Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.133 Safari/534.16 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: _auv=""; _cph="1298497425.324.1.1, Content-Length: 1134 <adRequest profile="82125:MTVN_live" version="1" networkId="82125"> ...[SNIP]... |
HTTP/1.1 200 OK Set-Cookie: _sid="c114_558319069 Set-Cookie: _uid="c007_557700397 Set-Cookie: _auv="";expires=Mon, 11 Apr 2011 13:51:24 GMT;domain=.fwmrm.net Set-Cookie: _vr="1299937884..333670 Set-Cookie: _cph="1299937884.439.1.1, Set-Cookie: _sc="sg158249.1299937884 Set-Cookie: _wr="g158249";expires=Mon X-FW-Power-By: Smart Content-Type: text/xml Pragma: no-cache Vary: Accept-Encoding Date: Sat, 12 Mar 2011 13:51:24 GMT Server: FWS P3P: policyref="http://www Content-Length: 8279 <adResponse version='1'><rendere <adRenderers version='1'> ...[SNIP]... |