1. Cross-site scripting (reflected)
2. SSL cookie without secure flag set
4. Cookie without HttpOnly flag set
Severity: | High |
Confidence: | Certain |
Host: | https://www.ipredator.se |
Path: | / |
GET /?886bd"><script>alert(1)< Host: www.ipredator.se Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Thu, 24 Mar 2011 02:16:30 GMT Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny8 with Suhosin-Patch mod_ssl/2.2.9 OpenSSL/0.9.8g X-Powered-By: PHP/5.2.6-1+lenny8 Set-Cookie: PHPSESSID=3347d82ed3 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Type: text/html; charset=UTF-8 Content-Length: 6610 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content- ...[SNIP]... <input type="hidden" name="886bd"><script>alert(1)< ...[SNIP]... |
Severity: | Medium |
Confidence: | Firm |
Host: | https://www.ipredator.se |
Path: | / |
GET / HTTP/1.1 Host: www.ipredator.se Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Thu, 24 Mar 2011 02:16:14 GMT Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny8 with Suhosin-Patch mod_ssl/2.2.9 OpenSSL/0.9.8g X-Powered-By: PHP/5.2.6-1+lenny8 Set-Cookie: PHPSESSID=cf2368df74 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Type: text/html; charset=UTF-8 Content-Length: 6526 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content- ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www.ipredator.se |
Path: | / |
GET /?.acafca5166de95dd7/=1 HTTP/1.1 Host: www.ipredator.se Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 301 Moved Permanently Date: Thu, 24 Mar 2011 02:17:06 GMT Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny8 with Suhosin-Patch mod_ssl/2.2.9 OpenSSL/0.9.8g Location: https://www.ipredator.se? Vary: Accept-Encoding Content-Type: text/html; charset=iso-8859-1 Content-Length: 402 <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>301 Moved Permanently</title> </head><body> <h1>Moved Permanently</h1> <p>The document has moved <a href="https://www ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | https://www.ipredator.se |
Path: | / |
GET / HTTP/1.1 Host: www.ipredator.se Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Thu, 24 Mar 2011 02:16:14 GMT Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny8 with Suhosin-Patch mod_ssl/2.2.9 OpenSSL/0.9.8g X-Powered-By: PHP/5.2.6-1+lenny8 Set-Cookie: PHPSESSID=cf2368df74 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Type: text/html; charset=UTF-8 Content-Length: 6526 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content- ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.ipredator.se |
Path: | / |
TRACE / HTTP/1.0 Host: www.ipredator.se Cookie: 629005c59513bced |
HTTP/1.1 200 OK Date: Thu, 24 Mar 2011 02:16:16 GMT Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny8 with Suhosin-Patch mod_ssl/2.2.9 OpenSSL/0.9.8g Connection: close Content-Type: message/http TRACE / HTTP/1.0 Host: www.ipredator.se Cookie: 629005c59513bced |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.ipredator.se |
Path: | / |
GET / HTTP/1.1 Host: www.ipredator.se Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Thu, 24 Mar 2011 02:16:14 GMT Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny8 with Suhosin-Patch mod_ssl/2.2.9 OpenSSL/0.9.8g X-Powered-By: PHP/5.2.6-1+lenny8 Set-Cookie: PHPSESSID=cf2368df74 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Type: text/html; charset=UTF-8 Content-Length: 6526 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content- ...[SNIP]... <div id="copyleft">support@ipredator.se | Idleworks 2009 Kopimi</div> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.ipredator.se |
Path: | / |
Issued to: | www.ipredator.se |
Issued by: | Equifax Secure Certificate Authority |
Valid from: | Mon Jun 22 12:12:54 CDT 2009 |
Valid to: | Sat Jun 25 01:45:29 CDT 2011 |
Issued to: | Equifax Secure Certificate Authority |
Issued by: | Equifax Secure Certificate Authority |
Valid from: | Sat Aug 22 11:41:51 CDT 1998 |
Valid to: | Wed Aug 22 11:41:51 CDT 2018 |