2. Cookie without HttpOnly flag set
Severity: | High |
Confidence: | Tentative |
Host: | http://24.56.133.254 |
Path: | /triple-play |
GET /triple-play20203336'%20or%201%3d1-- Host: 24.56.133.254 Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 403 Forbidden Date: Thu, 09 Dec 2010 20:59:24 GMT Server: Apache/2.2.3 (CentOS) Content-Length: 310 Connection: close Content-Type: text/html; charset=iso-8859-1 <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>403 Forbidden</title> </head><body> <h1>Forbidden</h1> <p>You don't have permission to access /triple-play20203336' or 1=1-- on this server.</p> <hr> <address>Apache/2.2.3 (CentOS) Server at 24.56.133.254 Port 80</address> </body></html> |
GET /triple-play20203336'%20or%201%3d2-- Host: 24.56.133.254 Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 404 Not Found Date: Thu, 09 Dec 2010 20:59:24 GMT Server: Apache/2.2.3 (CentOS) X-Powered-By: PHP/5.1.6 Set-Cookie: SESS20f82c4c44c491cc Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Thu, 09 Dec 2010 20:59:24 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Content-Length: 7546 Connection: close Content-Type: text/html; charset=utf-8 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-Type" content="text/html; charset=utf-8" /> <title>Page not found | US Cable</title> <meta http-equiv="Content-Style <meta http-equiv="Content-Type" content="text/html; charset=utf-8" /> <link rel="shortcut icon" href="/sites/default <link type="text/css" rel="stylesheet" media="all" href="/modules/node/node <link type="text/css" rel="stylesheet" media="all" href="/modules/system <link type="text/css" rel="stylesheet" media="all" href="/modules/system <link type="text/css" rel="stylesheet" media="all" href="/modules/system <link type="text/css" rel="stylesheet" media="all" href="/modules/user/user <link type="text/css" rel="stylesheet" media="all" href="/sites/all/modules <link type="text/css" rel="stylesheet" media="all" href="/sites/all/modules <link type="text/css" rel="stylesheet" media="all" href="/sites/all/modules <link type="text/css" rel="stylesheet" media="all" href="/themes/uscable <script type="text/javascript" src="/sites/default/files ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://24.56.133.254 |
Path: | /triple-play |
GET /triple-play HTTP/1.1 Host: 24.56.133.254 Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Thu, 09 Dec 2010 20:58:55 GMT Server: Apache/2.2.3 (CentOS) X-Powered-By: PHP/5.1.6 Set-Cookie: SESS20f82c4c44c491cc Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Thu, 09 Dec 2010 20:58:55 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 13685 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://24.56.133.254 |
Path: | / |
TRACE / HTTP/1.0 Host: 24.56.133.254 Cookie: 8807587581ca085 |
HTTP/1.1 200 OK Date: Thu, 09 Dec 2010 20:58:55 GMT Server: Apache/2.2.3 (CentOS) Connection: close Content-Type: message/http TRACE / HTTP/1.0 Host: 24.56.133.254 Cookie: 8807587581ca085 |
Severity: | Information |
Confidence: | Certain |
Host: | http://24.56.133.254 |
Path: | /triple-play |
GET /robots.txt HTTP/1.0 Host: 24.56.133.254 |
HTTP/1.1 200 OK Date: Thu, 09 Dec 2010 20:58:56 GMT Server: Apache/2.2.3 (CentOS) Last-Modified: Wed, 10 Dec 2008 20:12:20 GMT ETag: "2003c7-636-e092f100" Accept-Ranges: bytes Content-Length: 1590 Cache-Control: max-age=1209600 Expires: Thu, 23 Dec 2010 20:58:56 GMT Connection: close Content-Type: text/plain; charset=UTF-8 # $Id: robots.txt,v 1.9.2.1 2008/12/10 20:12:19 goba Exp $ # # robots.txt # # This file is to prevent the crawling and indexing of certain parts # of your site by web crawlers and spiders run by sites ...[SNIP]... |