1. Cross-site scripting (reflected)
2. Cookie scoped to parent domain
3. Cross-domain Referer leakage
3.1. http://ad.doubleclick.net/adi/N553.158901.DATAXU/B4970757.12
3.2. http://ad.doubleclick.net/adi/N553.158901.DATAXU/B4970757.12
4. Cross-domain script include
5. Cookie without HttpOnly flag set
6. HTML does not specify charset
Severity: | High |
Confidence: | Certain |
Host: | http://ad.doubleclick.net |
Path: | /adj/N5295.137916 |
GET /adj/N5295.137916 Host: ad.doubleclick.net Proxy-Connection: keep-alive Referer: http://www.snow-forecast Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.84 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: id=c653243310000d9 |
HTTP/1.1 200 OK Server: DCLK-AdSvr Content-Type: application/x-javascript Content-Length: 258 Cache-Control: no-cache Pragma: no-cache Date: Wed, 09 Feb 2011 21:55:50 GMT Expires: Wed, 09 Feb 2011 21:55:50 GMT document.write('<a target="_blank" href="http://ad ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://ad.doubleclick.net |
Path: | /click |
GET /click;h=v8/3aa9/17/231/* Host: ad.doubleclick.net Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: id=c653243310000d9 |
HTTP/1.1 302 Moved Temporarily Content-Length: 0 Location: http://delivery.ads Set-Cookie: id=c653243310000d9 P3P: CP="CURa ADMa DEVa PSAo PSDo OUR BUS UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR" Date: Wed, 09 Feb 2011 22:11:28 GMT Server: GFE/2.0 Content-Type: text/html Connection: close |
Severity: | Information |
Confidence: | Certain |
Host: | http://ad.doubleclick.net |
Path: | /adi/N553.158901.DATAXU |
GET /adi/N553.158901.DATAXU Host: ad.doubleclick.net Proxy-Connection: keep-alive Referer: http://cdn.w55c.net/i Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.84 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: id=c653243310000d9 |
HTTP/1.1 200 OK Server: DCLK-AdSvr Content-Type: text/html Content-Length: 4706 Cache-Control: no-cache Pragma: no-cache Date: Wed, 09 Feb 2011 22:04:35 GMT Expires: Wed, 09 Feb 2011 22:04:35 GMT <html><head><title ...[SNIP]... <!-- Copyright 2006 DoubleClick Inc., All rights reserved. --><script src="http://s0.2mdn.net ...[SNIP]... a9/3/0/%2a/n%3B233997768 ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://ad.doubleclick.net |
Path: | /adi/N553.158901.DATAXU |
GET /adi/N553.158901.DATAXU Host: ad.doubleclick.net Proxy-Connection: keep-alive Referer: http://cdn.w55c.net/i Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.84 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: id=c653243310000d9 |
HTTP/1.1 200 OK Server: DCLK-AdSvr Content-Type: text/html Content-Length: 4702 Cache-Control: no-cache Pragma: no-cache Date: Wed, 09 Feb 2011 22:02:25 GMT Expires: Wed, 09 Feb 2011 22:02:25 GMT <html><head><title ...[SNIP]... <!-- Copyright 2006 DoubleClick Inc., All rights reserved. --><script src="http://s0.2mdn.net ...[SNIP]... a9/3/0/%2a/g%3B233997768 ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://ad.doubleclick.net |
Path: | /adi/N553.158901.DATAXU |
GET /adi/N553.158901.DATAXU Host: ad.doubleclick.net Proxy-Connection: keep-alive Referer: http://cdn.w55c.net/i Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.84 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: id=c653243310000d9 |
HTTP/1.1 200 OK Server: DCLK-AdSvr Content-Type: text/html Content-Length: 4706 Cache-Control: no-cache Pragma: no-cache Date: Wed, 09 Feb 2011 22:04:35 GMT Expires: Wed, 09 Feb 2011 22:04:35 GMT <html><head><title ...[SNIP]... <!-- Copyright 2006 DoubleClick Inc., All rights reserved. --><script src="http://s0.2mdn.net ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://ad.doubleclick.net |
Path: | /click |
GET /click;h=v8/3aa9/17/231/* Host: ad.doubleclick.net Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: id=c653243310000d9 |
HTTP/1.1 302 Moved Temporarily Content-Length: 0 Location: http://delivery.ads Set-Cookie: id=c653243310000d9 P3P: CP="CURa ADMa DEVa PSAo PSDo OUR BUS UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR" Date: Wed, 09 Feb 2011 22:11:28 GMT Server: GFE/2.0 Content-Type: text/html Connection: close |
Severity: | Information |
Confidence: | Certain |
Host: | http://ad.doubleclick.net |
Path: | /adi/N553.158901.DATAXU |
GET /adi/N553.158901.DATAXU Host: ad.doubleclick.net Proxy-Connection: keep-alive Referer: http://cdn.w55c.net/i Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.84 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: id=c653243310000d9 |
HTTP/1.1 200 OK Server: DCLK-AdSvr Content-Type: text/html Content-Length: 4706 Cache-Control: no-cache Pragma: no-cache Date: Wed, 09 Feb 2011 22:04:35 GMT Expires: Wed, 09 Feb 2011 22:04:35 GMT <html><head><title ...[SNIP]... |