1.1. http://wzus.ask.com/r [name of an arbitrarily supplied request parameter]
1.2. http://wzus.ask.com/r [u parameter]
1.3. http://wzus1.search-results.com/i/i.gif [REST URL parameter 1]
1.4. http://wzus1.search-results.com/i/i.gif [REST URL parameter 2]
Severity: | High |
Confidence: | Certain |
Host: | http://wzus.ask.com |
Path: | /r |
GET /r?t=a&d=us&s=a&c=sttc&ti Host: wzus.ask.com Proxy-Connection: keep-alive Referer: http://about.ask.com/en User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 302 Found Date: Tue, 22 Mar 2011 16:03:15 GMT Location: http://about.ask.com/en 9f0ad2dfc95=1 Content-Length: 260 Connection: close Content-Type: text/html; charset=iso-8859-1 <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>302 Found</title> </head><body> <h1>Found</h1> <p>The document has moved <a href="http://about.ask ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://wzus.ask.com |
Path: | /r |
GET /r?t=a&d=us&s=a&c=sttc&ti Host: wzus.ask.com Proxy-Connection: keep-alive Referer: http://about.ask.com/en User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 302 Found Date: Tue, 22 Mar 2011 16:03:14 GMT Location: http://about.ask.com/en 84e406bda80 Content-Length: 253 Connection: close Content-Type: text/html; charset=iso-8859-1 <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>302 Found</title> </head><body> <h1>Found</h1> <p>The document has moved <a href="http://about.ask ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://wzus1.search |
Path: | /i/i.gif |
GET /e127d%0d%0a2f61a717043/i.gif?t=v&d=apn&s=zdo&c Host: wzus1.search-results.com Proxy-Connection: keep-alive Referer: http://www.search-results User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: locale=en_US; accepting=1; qh=1-; qc=0; user=l=dir |
HTTP/1.1 302 Found Date: Tue, 22 Mar 2011 16:26:02 GMT Set-Cookie: wz_uid=0540D58D81CBD Set-Cookie: wz_sid=0F4AD58689CBD Set-Cookie: wz_scnt=1; path=/; expires=Thu, 21-Mar-2013 16:26:02 GMT; domain=.search-results Location: http://wzus1.search 2f61a717043/i.gif?t=S&d=apn&s=zdo&c Content-Length: 455 Connection: close Content-Type: text/html; charset=iso-8859-1 <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>302 Found</title> </head><body> <h1>Found</h1> <p>The document has moved <a href="http://wzus1.search 2f61a717 ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://wzus1.search |
Path: | /i/i.gif |
GET /i/2acb8%0d%0a5daa061daeb?t=v&d=apn&s=zdo&c=h&l Host: wzus1.search-results.com Proxy-Connection: keep-alive Referer: http://www.search-results User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: locale=en_US; accepting=1; qh=1-; qc=0; user=l=dir |
HTTP/1.1 302 Found Date: Tue, 22 Mar 2011 16:26:02 GMT Set-Cookie: wz_uid=0C45D38680CCD Set-Cookie: wz_sid=024ED88C84CCD Set-Cookie: wz_scnt=1; path=/; expires=Thu, 21-Mar-2013 16:26:02 GMT; domain=.search-results Location: http://wzus1.search 5daa061daeb?t=S&d=apn&s=zdo&c=h&l Content-Length: 451 Connection: close Content-Type: text/html; charset=iso-8859-1 <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>302 Found</title> </head><body> <h1>Found</h1> <p>The document has moved <a href="http://wzus1.search 5daa06 ...[SNIP]... |