1.1. http://mail.google.com/a/%domain.name%/channel/bind [RID parameter]
1.2. http://mail.google.com/a/%domain.name%/channel/bind [SID parameter]
2. Cross-site scripting (reflected)
3. Cookie without HttpOnly flag set
3.1. http://mail.google.com/a/%domain.name%/
3.2. http://mail.google.com/a/%domain.name%/
3.3. http://mail.google.com/a/%domain.name%/
3.4. http://mail.google.com/a/%domain.name%/
3.5. http://mail.google.com/a/%domain.name%/channel/bind
3.6. http://mail.google.com/a/%domain.name%/channel/test
4.1. http://mail.google.com/a/%domain.name%/
4.2. http://mail.google.com/a/%domain.name%/
4.3. http://mail.google.com/a/%domain.name%/
4.4. http://mail.google.com/a/%domain.name%/
4.5. http://mail.google.com/a/%domain.name%/
4.6. http://mail.google.com/a/%domain.name%/
4.7. http://mail.google.com/a/%domain.name%/
4.8. http://mail.google.com/a/%domain.name%/
4.9. http://mail.google.com/a/%domain.name%/
4.10. http://mail.google.com/a/%domain.name%/
4.11. http://mail.google.com/a/%domain.name%/
5. Content type incorrectly stated
5.1. http://mail.google.com/a/%domain.name%/
5.2. http://mail.google.com/a/%domain.name%/channel/bind
5.3. http://mail.google.com/a/%domain.name%/channel/test
Severity: | High |
Confidence: | Tentative |
Host: | http://mail.google.com |
Path: | /a/%domain.name%/channel |
GET /a/%domain.name%/channel Host: mail.google.com Proxy-Connection: keep-alive Referer: http://mail.google.com/a Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.224 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: S=gmail=ede-5Fzm |
HTTP/1.1 500 Internal Server Error Content-Type: text/html; charset=utf-8 Set-Cookie: GXAS=%domain.name% Set-Cookie: S=gmail=GRYY4PfxlCPm Cache-Control: no-cache, no-store, max-age=0, must-revalidate Pragma: no-cache Expires: Fri, 01 Jan 1990 00:00:00 GMT Date: Thu, 13 Jan 2011 01:15:25 GMT X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block Server: GSE Content-Length: 4830 <script><!-- var gmail_error=0; var gmail_show_error=false; --></script> <html> <head> <meta http-equiv=Content-Type content="text/html; charset=UTF-8"> <title>Server Error</title> <style><!-- body ...[SNIP]... |
GET /a/%domain.name%/channel Host: mail.google.com Proxy-Connection: keep-alive Referer: http://mail.google.com/a Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.224 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: S=gmail=ede-5Fzm |
HTTP/1.1 400 Unknown SID Content-Type: text/html; charset=UTF-8 Set-Cookie: GXAS=%domain.name% Set-Cookie: S=gmail=nZDfqOtytnFW Cache-Control: no-cache, no-store, max-age=0, must-revalidate Pragma: no-cache Expires: Fri, 01 Jan 1990 00:00:00 GMT Date: Thu, 13 Jan 2011 01:15:26 GMT Content-Length: 145 X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block Server: GSE <HTML> <HEAD> <TITLE>Unknown SID</TITLE> </HEAD> <BODY BGCOLOR="#FFFFFF" TEXT="#000000"> <H1>Unknown SID</H1> <H2>Error 400</H2> </BODY> </HTML> |
Severity: | High |
Confidence: | Tentative |
Host: | http://mail.google.com |
Path: | /a/%domain.name%/channel |
GET /a/%domain.name%/channel Host: mail.google.com Proxy-Connection: keep-alive Referer: http://mail.google.com/a Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.224 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: S=gmail=ede-5Fzm |
HTTP/1.1 500 Internal Server Error Content-Type: text/html; charset=utf-8 Set-Cookie: GXAS=%domain.name% Set-Cookie: S=gmail=O6zxcYihiZpg Cache-Control: no-cache, no-store, max-age=0, must-revalidate Pragma: no-cache Expires: Fri, 01 Jan 1990 00:00:00 GMT Date: Thu, 13 Jan 2011 01:15:31 GMT X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block Server: GSE Content-Length: 4830 <script><!-- var gmail_error=0; var gmail_show_error=false; --></script> <html> <head> <meta http-equiv=Content-Type content="text/html; charset=UTF-8"> <title>Server Error</title> <style><!-- body ...[SNIP]... |
GET /a/%domain.name%/channel Host: mail.google.com Proxy-Connection: keep-alive Referer: http://mail.google.com/a Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.224 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: S=gmail=ede-5Fzm |
HTTP/1.1 400 Unknown SID Content-Type: text/html; charset=UTF-8 Set-Cookie: GXAS=%domain.name% Set-Cookie: S=gmail=Fkp03LdbGNunWX Cache-Control: no-cache, no-store, max-age=0, must-revalidate Pragma: no-cache Expires: Fri, 01 Jan 1990 00:00:00 GMT Date: Thu, 13 Jan 2011 01:15:32 GMT Content-Length: 145 X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block Server: GSE <HTML> <HEAD> <TITLE>Unknown SID</TITLE> </HEAD> <BODY BGCOLOR="#FFFFFF" TEXT="#000000"> <H1>Unknown SID</H1> <H2>Error 400</H2> </BODY> </HTML> |
Severity: | High |
Confidence: | Certain |
Host: | http://mail.google.com |
Path: | /a/%domain.name%/ |
GET /a/%domain.name%%00ce180"><img%20src%3da Host: mail.google.com Proxy-Connection: keep-alive Referer: http://mail.google.com/a Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.224 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: S=gmail=ede-5Fzm |
HTTP/1.1 500 Internal Server Error Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache, no-store, max-age=0, must-revalidate Pragma: no-cache Expires: Fri, 01 Jan 1990 00:00:00 GMT Date: Thu, 13 Jan 2011 01:13:33 GMT X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block Server: GSE Content-Length: 5083 <script><!-- var gmail_error=0; var gmail_show_error=false; --></script> <html> <head> <meta http-equiv=Content-Type content="text/html; charset=UTF-8"> <title>Server Error</title> <style><!-- body ...[SNIP]... <a target=_top href="http://mail.google ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://mail.google.com |
Path: | /a/%domain.name%/ |
POST /a/%domain.name%/?ui=2&ik Host: mail.google.com Proxy-Connection: keep-alive Referer: http://mail.google.com/a X-Same-Domain: 1 Origin: http://mail.google.com Content-Type: application/x-www-form Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.224 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: S=gmail=ede-5Fzm Content-Length: 0 |
HTTP/1.1 200 OK Content-Type: text/javascript; charset=UTF-8 Set-Cookie: GXAS=%domain.name% Set-Cookie: GMAIL_IMP=EXPIRED; Expires=Wed, 12-Jan-2011 01:11:31 GMT; Path=/a/%domain.name% Set-Cookie: S=gmail=5QUaE27xe0 Cache-Control: no-cache, no-store, max-age=0, must-revalidate Pragma: no-cache Expires: Fri, 01 Jan 1990 00:00:00 GMT Date: Thu, 13 Jan 2011 01:11:31 GMT X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block Server: GSE Content-Length: 119014 while(1); [[["v","wwW1AwxxcRc.en.", ,["di",519] ,["ub",[["^i",129488 ,["^f",1294881087987] ,["Misc",1294881087987] ,["^k",1294881087987] ,["Follow up",1294881087987] ,[ ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://mail.google.com |
Path: | /a/%domain.name%/ |
POST /a/%domain.name%/?ui=2&ik Host: mail.google.com Proxy-Connection: keep-alive Referer: http://mail.google.com/a X-Same-Domain: 1 Origin: http://mail.google.com Content-Type: application/x-www-form Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.224 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: S=gmail=ede-5Fzm Content-Length: 0 |
HTTP/1.1 200 OK Content-Type: text/javascript; charset=UTF-8 Cache-Control: no-cache, no-store, max-age=0, must-revalidate Pragma: no-cache Expires: Fri, 01 Jan 1990 00:00:00 GMT Date: Sat, 08 Jan 2011 00:30:31 GMT Set-Cookie: GMAIL_STAT_24=EXPIRED; Expires=Fri, 07-Jan-2011 00:30:31 GMT; Path=/a/%domain.name% X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block Server: GSE Content-Length: 2951 while(1); [[["v","wwW1AwxxcRc.en.", ,["ub",[["^cob-processed ,["^i",1294446612937] ,["^f",1294446625314] ,["Misc",1294446625314] ,["^k",1294446625314] ,["Fo ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://mail.google.com |
Path: | /a/%domain.name%/ |
GET /a/%domain.name%/ HTTP/1.1 Host: mail.google.com Proxy-Connection: keep-alive Cache-Control: max-age=0 Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.224 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: GXAS=%domain.name% |
HTTP/1.1 200 OK Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache, no-store, max-age=0, must-revalidate Pragma: no-cache Expires: Fri, 01 Jan 1990 00:00:00 GMT Date: Sat, 08 Jan 2011 00:30:24 GMT X-DNS-Prefetch-Control: off Set-Cookie: S=gmail=ede-5Fzm Set-Cookie: GMAIL_AT=AF6bupNTjLM X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block Server: GSE Content-Length: 63745 <!DOCTYPE html> <html> <head> <meta http-equiv="Content-Type" content="text/html; charset=UTF-8"> <title>%domain.name% Mail</title> <meta name="application-name" content="%domain.name% Mail"> <meta name ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://mail.google.com |
Path: | /a/%domain.name%/ |
POST /a/%domain.name%/?ui=2&ik Host: mail.google.com Proxy-Connection: keep-alive Referer: http://mail.google.com/a X-Same-Domain: 1 Origin: http://mail.google.com Content-Type: application/x-www-form Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.224 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: S=gmail=ede-5Fzm Content-Length: 0 |
HTTP/1.1 200 OK Content-Type: text/javascript; charset=UTF-8 Cache-Control: no-cache, no-store, max-age=0, must-revalidate Pragma: no-cache Expires: Fri, 01 Jan 1990 00:00:00 GMT Date: Sat, 08 Jan 2011 00:30:34 GMT Set-Cookie: GMAIL_IMP=EXPIRED; Expires=Fri, 07-Jan-2011 00:30:34 GMT; Path=/a/%domain.name% Set-Cookie: GMAIL_STAT_24=EXPIRED; Expires=Fri, 07-Jan-2011 00:30:34 GMT; Path=/a/%domain.name% X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block Server: GSE Content-Length: 1858 while(1); [[["v","wwW1AwxxcRc.en.", ,["di",28] ,["ub",[["^cob-processed ,["^i",1294446612937] ,["^f",1294446625314] ,["Misc",1294446625314] ,["^k",129444662 ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://mail.google.com |
Path: | /a/%domain.name%/channel |
GET /a/%domain.name%/channel Host: mail.google.com Proxy-Connection: keep-alive Referer: http://mail.google.com/a Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.224 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: S=gmail=ede-5Fzm |
HTTP/1.1 400 Unknown SID Content-Type: text/html; charset=UTF-8 Set-Cookie: GXAS=%domain.name% Set-Cookie: S=gmail=2n-kC86oDsLF Cache-Control: no-cache, no-store, max-age=0, must-revalidate Pragma: no-cache Expires: Fri, 01 Jan 1990 00:00:00 GMT Date: Thu, 13 Jan 2011 01:13:38 GMT Content-Length: 145 X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block Server: GSE <HTML> <HEAD> <TITLE>Unknown SID</TITLE> </HEAD> <BODY BGCOLOR="#FFFFFF" TEXT="#000000"> <H1>Unknown SID</H1> <H2>Error 400</H2> </BODY> </HTML> |
Severity: | Information |
Confidence: | Certain |
Host: | http://mail.google.com |
Path: | /a/%domain.name%/channel |
GET /a/%domain.name%/channel Host: mail.google.com Proxy-Connection: keep-alive Referer: http://mail.google.com/a Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.224 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: S=gmail=ede-5Fzm |
HTTP/1.1 200 OK Content-Type: text/plain; charset=utf-8 Set-Cookie: GXAS=%domain.name% Set-Cookie: S=gmail=zToXYC8jpL5r Cache-Control: no-cache, no-store, max-age=0, must-revalidate Pragma: no-cache Expires: Fri, 01 Jan 1990 00:00:00 GMT Date: Thu, 13 Jan 2011 01:13:02 GMT X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block Content-Length: 6 Server: GSE ["b"] |
Severity: | Information |
Confidence: | Certain |
Host: | http://mail.google.com |
Path: | /a/%domain.name%/ |
GET /a/%domain.name%/ HTTP/1.1 Host: mail.google.com Proxy-Connection: keep-alive Cache-Control: max-age=0 Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.224 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: GXAS=%domain.name% |
HTTP/1.1 200 OK Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache, no-store, max-age=0, must-revalidate Pragma: no-cache Expires: Fri, 01 Jan 1990 00:00:00 GMT Date: Sat, 08 Jan 2011 03:28:58 GMT X-DNS-Prefetch-Control: off Set-Cookie: S=gmail=wt1AtOgdOfOL Set-Cookie: GMAIL_AT=AF6bupNTjLM X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block Server: GSE Content-Length: 63153 <!DOCTYPE html> <html> <head> <meta http-equiv="Content-Type" content="text/html; charset=UTF-8"> <title>%domain.name% Mail</title> <meta name="application-name" content="%domain.name% Mail"> <meta name ...[SNIP]... inbox",[] ,"62",-1,0,84,0,[] ,[] ] ,["tb",0,[["12d63771 ,[] ,"\u003cspan class\u003d\"yP\" email\u003d\"noreply@connect.symantec ...[SNIP]... 6a47f5032","12d63766 ,["^all","^cob-processed ,"\u003cspan class\u003d\"zF\" email\u003d\"donotreply@symantec.com\"\u003eSymAccount\u003c ...[SNIP]... 8:31 PM",1294453862883064,,[] ,,0,[] ,,[] ] ,["12d6307c28715b59", ,[] ,"\u003cspan class\u003d\"yP\" email\u003d\"no-reply@foxsports.com\"\u003eFox Sports\u003c/span\u003e", ...[SNIP]... 93776","12d6136ecca93776" ,["^all","^cob-processed ,"\u003cspan class\u003d\"zF\" email\u003d\"Aberdeen.Research ...[SNIP]... cd5db","12d602a4df0cd5db" ,["^all","^cob-processed ,"\u003cspan class\u003d\"zF\" email\u003d\"Aberdeen.Research ...[SNIP]... 2d5cd1402cb670c", ,["^all","^cob-processed ,"\u003cspan class\u003d\"zF\" email\u003d\"Aberdeen.Research ...[SNIP]... ac35d","12d56462377ac35d" ,["^all","^cob-processed ,"\u003cspan class\u003d\"zF\" email\u003d\"Aberdeen.Research ...[SNIP]... 9425d","12d5284739a9425d" ,["^all","^cob-processed ,"\u003cspan class\u003d\"zF\" email\u003d\"Aberdeen.Research ...[SNIP]... 1293975038445586,,[] ,,0,["Groupon"] ,,[] ] ,["12d43a867b1bdb0d", ,[] ,"\u003cspan class\u003d\"yP\" email\u003d\"clubnintendo.noreply@noa ...[SNIP]... ","12d432ea130aaa55", ,["^all","^cob-processed ,"\u003cspan class\u003d\"zF\" email\u003d\"info@netflix.com\"\u003eNetflix\u003c ...[SNIP]... f84b1","12d3c1bdd50f84b1" ,["^all","^cob-processed ,"\u003cspan class\u003d\"zF\" email\u003d\"Aberdeen.Research ...[SNIP]... "12d39fe441848c77",0,0,[" ,["^all","^cob-processed ,"\u003cspan class\u003d\"zF\" email\u003d\"test@test.cloudscan.us\"\u003etest\u003c/span ...[SNIP]... 2d38c4899853798", ,["^all","^cob-processed ,"\u003cspan class\u003d\"zF\" email\u003d\"Aberdeen.Research ...[SNIP]... 83ccb","12d327010dd83ccb" ,["^all","^cob-processed ,"\u003cspan class\u003d\"zF\" email\u003d\"Aberdeen.Research ...[SNIP]... ",1293628748802939,,[] ,,0,["Groupon"] ,,[] ] ,["12d2fe63f83c6dcc", ,[] ,"\u003cspan class\u003d\"yP\" email\u003d\"tagged@taggedmail.com\"\u003eTagged\u003c/span ...[SNIP]... 10e2a","12d2e77d54f10e2a" ,["^all","^cob-processed ,"\u003cspan class\u003d\"zF\" email\u003d\"Aberdeen.Research ...[SNIP]... 2d2db9e2374ba64", ,["^all","^cob-processed ,"\u003cspan class\u003d\"zF\" email\u003d\"Aberdeen.Research ...[SNIP]... 6b9bb1da5","12d1f3a6 ,["^all","^cob-processed ,"\u003cspan class\u003d\"zF\" email\u003d\"info@netflix.com\"\u003eNetflix\u003c ...[SNIP]... ] ] ,["12d14e51cea36bdb", ,["^all","^cob-processed ,"\u003cspan class\u003d\"zF\" email\u003d\"info@netflix.com\"\u003eNetflix\u003c ...[SNIP]... bd1fe","12d13f99561bd1fe" ,["^all","^cob-processed ,"\u003cspan class\u003d\"zF\" email\u003d\"Aberdeen.Research ...[SNIP]... "12d10e03335251ce", ,["^all","^cob-processed ,"\u003cspan class\u003d\"zF\" email\u003d\"marc@surfline.com\"\u003eMarc Beaty\u003c/span\u003e"," ...[SNIP]... e8f3c5fb1512","12d0e ,["^all","^cob-processed ,"\u003cspan class\u003d\"zF\" email\u003d\"cnbcmembershipservices ...[SNIP]... d0e63d3c9996ca", ,["^all","^cob-processed ,"\u003cspan class\u003d\"zF\" email\u003d\"Aberdeen.Research ...[SNIP]... e22e9","12d0a6beebee22e9" ,["^all","^cob-processed ,"\u003cspan class\u003d\"zF\" email\u003d\"Aberdeen.Research ...[SNIP]... d09451fa4fef64", ,["^all","^cob-processed ,"\u003cspan class\u003d\"zF\" email\u003d\"Aberdeen.Research |