1.1. http://ad.yieldmanager.com/imp [_salt parameter]
1.2. http://ad.yieldmanager.com/imp [bh cookie]
Severity: | High |
Confidence: | Tentative |
Host: | http://ad.yieldmanager |
Path: | /imp |
GET /imp?_PVID=.GjhbELEa Host: ad.yieldmanager.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: uid=uid=689ad102-f426 |
HTTP/1.1 200 OK Date: Fri, 19 Nov 2010 23:39:15 GMT Server: YTS/1.18.4 P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa ADMa DEVa PSAa PSDa OUR BUS COM INT OTC PUR STA" X-RightMedia-Hostname: ad0690.rm.sp2 Set-Cookie: ih="b!!!!,!,5Ea!!!!'<apF) Set-Cookie: vuday1=!!!!#Ajz6)BgvR/F< Set-Cookie: BX=fqi84nl6de3q3&b=4&s=9s Set-Cookie: liday1=14ii1fYXY!.x Cache-Control: no-store Last-Modified: Fri, 19 Nov 2010 23:39:15 GMT Pragma: no-cache Content-Length: 1019 Content-Type: application/x-javascript Age: 0 Connection: close document.write('<a target=\"_blank\" href=\"http://ads var rm_data = new Object(); rm_data.creative_id = 7028172; rm_data.offer_type = 19; rm_data.entity_id = 286236; if (window.rm_crex_data) {rm_crex_data.push |
GET /imp?_PVID=.GjhbELEa Host: ad.yieldmanager.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: uid=uid=689ad102-f426 |
HTTP/1.1 200 OK Date: Fri, 19 Nov 2010 23:39:16 GMT Server: YTS/1.18.4 P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa ADMa DEVa PSAa PSDa OUR BUS COM INT OTC PUR STA" X-RightMedia-Hostname: ad2620.rm.sp2 Set-Cookie: ih="b!!!!,!,5Ea!!!!'<apF) Set-Cookie: vuday1=!!!!#Ajz6)BgvR/F< Set-Cookie: BX=fqi84nl6de3q3&b=4&s=9s Cache-Control: no-store Last-Modified: Fri, 19 Nov 2010 23:39:16 GMT Pragma: no-cache Content-Length: 1019 Content-Type: application/x-javascript Age: 0 Connection: close document.write('<a target=\"_blank\" href=\"http://ads var rm_data = new Object(); rm_data.creative_id = 6072354; rm_data.offer_type = 18; rm_data.entity_id = 331756; if (window.rm_crex_data) {rm_crex_data.push |
Severity: | High |
Confidence: | Tentative |
Host: | http://ad.yieldmanager |
Path: | /imp |
GET /imp?_PVID=Sel8aULEa Accept: */* Referer: http://ad.yieldmanager Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: ad.yieldmanager.com Proxy-Connection: Keep-Alive Cookie: BX=fqi84nl6de3q3&b=4&s=9s |
HTTP/1.1 200 OK Date: Fri, 19 Nov 2010 23:42:33 GMT Server: YTS/1.18.4 P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa ADMa DEVa PSAa PSDa OUR BUS COM INT OTC PUR STA" X-RightMedia-Hostname: ad1822.rm.sp2 Set-Cookie: ih="b!!!!)!,5Ea!!!!'<apF) Set-Cookie: vuday1=Ajz6)BgvR)F< Set-Cookie: BX=fqi84nl6de3q3&b=4&s=9s Set-Cookie: liday1=fYXXz.x<09N1Pl> Cache-Control: no-store Last-Modified: Fri, 19 Nov 2010 23:42:33 GMT Pragma: no-cache Content-Length: 1054 Content-Type: application/x-javascript Age: 0 Proxy-Connection: close document.write('<a target=\"_blank\" href=\"http://ads var rm_data = new Object(); rm_data.creative_id = 7136356; rm_data.offer_type = 19; rm_data.entity_id = 286236; if (window.rm_crex_data) {rm_crex_data.push |
GET /imp?_PVID=Sel8aULEa Accept: */* Referer: http://ad.yieldmanager Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: ad.yieldmanager.com Proxy-Connection: Keep-Alive Cookie: BX=fqi84nl6de3q3&b=4&s=9s |
HTTP/1.1 200 OK Date: Fri, 19 Nov 2010 23:42:34 GMT Server: YTS/1.18.4 P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa ADMa DEVa PSAa PSDa OUR BUS COM INT OTC PUR STA" X-RightMedia-Hostname: ad0465.rm.sp2 Set-Cookie: ih="b!!!!)!,5Ea!!!!'<apF) Set-Cookie: vuday1=Ajz6)BgvR)F< Set-Cookie: BX=fqi84nl6de3q3&b=4&s=9s Cache-Control: no-store Last-Modified: Fri, 19 Nov 2010 23:42:34 GMT Pragma: no-cache Content-Length: 1054 Content-Type: application/x-javascript Age: 0 Proxy-Connection: close document.write('<a target=\"_blank\" href=\"http://ads var rm_data = new Object(); rm_data.creative_id = 6072350; rm_data.offer_type = 18; rm_data.entity_id = 331756; if (window.rm_crex_data) {rm_crex_data.push |