3. Silverlight cross-domain policy
4. Cookie without HttpOnly flag set
Severity: | High |
Confidence: | Certain |
Host: | http://uk.sitestat.com |
Path: | /cliffordchance |
GET /cliffordchance Host: uk.sitestat.com Proxy-Connection: keep-alive Referer: http://www.cliffordchance User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 302 Found Date: Tue, 22 Mar 2011 17:22:00 GMT Server: Apache Expires: Sat, 01 Jan 2000 00:00:00 GMT Pragma: no-cache Cache-Control: no-cache P3P: policyref="http://www Set-Cookie: s1=4D88DAB82B690246; expires=Sun, 20-Mar-2016 17:22:00 GMT; path=/cliffordchance Location: http://uk.sitestat.com a748fffe1de?content.cliffordchance Content-Length: 407 Connection: close Content-Type: text/html; charset=iso-8859-1 <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>302 Found</title> </head><body> <h1>Found</h1> <p>The document has moved <a href="http://uk.sitestat ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://uk.sitestat.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: uk.sitestat.com |
HTTP/1.1 200 OK Date: Tue, 22 Mar 2011 17:21:51 GMT Server: Apache Last-Modified: Mon, 24 Jan 2011 17:04:30 GMT ETag: "530010-a7-49a9a97d80380" Accept-Ranges: bytes Content-Length: 167 Connection: close Content-Type: text/xml <cross-domain-policy> <allow-access-from domain="*" secure="false" /> <allow-http-request </cross-domain-policy> |
Severity: | High |
Confidence: | Certain |
Host: | http://uk.sitestat.com |
Path: | /clientaccesspolicy.xml |
GET /clientaccesspolicy.xml HTTP/1.0 Host: uk.sitestat.com |
HTTP/1.1 200 OK Date: Tue, 22 Mar 2011 17:21:51 GMT Server: Apache Last-Modified: Mon, 24 Jan 2011 17:04:30 GMT ETag: "4df000f-137-49a9a97 Accept-Ranges: bytes Content-Length: 311 Connection: close Content-Type: text/xml <?xml version="1.0" encoding="utf-8"?> <access-policy> <cross-domain-access> <policy> <allow-from http-request-headers="*"> <domain uri="*"/> </allow-from> <grant-to> <reso ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://uk.sitestat.com |
Path: | /cliffordchance |
GET /cliffordchance Host: uk.sitestat.com Proxy-Connection: keep-alive Referer: http://www.cliffordchance User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 302 Found Date: Tue, 22 Mar 2011 17:21:50 GMT Server: Apache Expires: Sat, 01 Jan 2000 00:00:00 GMT Pragma: no-cache Cache-Control: no-cache P3P: policyref="http://www Set-Cookie: s1=4D88DAAE2D30007E; expires=Sun, 20-Mar-2016 17:21:50 GMT; path=/cliffordchance Location: http://uk.sitestat.com Content-Length: 390 Connection: close Content-Type: text/html; charset=iso-8859-1 <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>302 Found</title> </head><body> <h1>Found</h1> <p>The document has moved <a href="http://uk.sitestat ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://uk.sitestat.com |
Path: | / |
TRACE / HTTP/1.0 Host: uk.sitestat.com Cookie: bf6cb69b3af78b0d |
HTTP/1.1 200 OK Date: Tue, 22 Mar 2011 17:21:51 GMT Server: Apache Connection: close Content-Type: message/http TRACE / HTTP/1.0 Host: uk.sitestat.com Cookie: bf6cb69b3af78b0d |
Severity: | Information |
Confidence: | Certain |
Host: | http://uk.sitestat.com |
Path: | /cliffordchance |
GET /robots.txt HTTP/1.0 Host: uk.sitestat.com |
HTTP/1.1 200 OK Date: Tue, 22 Mar 2011 17:21:51 GMT Server: Apache Last-Modified: Mon, 24 Jan 2011 17:04:30 GMT ETag: "9b0014-1c-49a9a97d80380" Accept-Ranges: bytes Content-Length: 28 Connection: close Content-Type: text/plain; charset=UTF-8 User-agent: * Disallow: / |