2. Cookie without HttpOnly flag set
Severity: | High |
Confidence: | Tentative |
Host: | http://ads2.adbrite.com |
Path: | /v0/ad |
GET /v0/ad?sid=1198099&zs Host: ads2.adbrite.com Proxy-Connection: keep-alive Referer: http://d3.zedo.com/jsc/d3 Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.237 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: Apache=168362173x0.688 |
HTTP/1.1 500 Internal Server Error Server: Apache-Coyote/1.1 Cache-Control: no-cache, no-store, must-revalidate Expires: Mon, 26 Jul 1997 05:00:00 GMT P3P: policyref="http://files Content-Type: text/html;charset=utf-8 Content-Length: 1000 Date: Sat, 29 Jan 2011 01:56:24 GMT Connection: close <html><head><title>Apache Tomcat/6.0.18 - Error report</title><style><!- ...[SNIP]... |
GET /v0/ad?sid=1198099&zs Host: ads2.adbrite.com Proxy-Connection: keep-alive Referer: http://d3.zedo.com/jsc/d3 Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.237 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: Apache=168362173x0.688 |
HTTP/1.1 200 OK Server: Apache-Coyote/1.1 Cache-Control: no-cache, no-store, must-revalidate Expires: Mon, 26 Jul 1997 05:00:00 GMT P3P: policyref="http://files Set-Cookie: b=%3A%3Apogj; Domain=.adbrite.com; Expires=Sun, 29-Jan-2012 01:56:25 GMT; Path=/ Set-Cookie: geo=1%3ADchLDoMwDEXR Set-Cookie: vsd="0@1@4d4373c9@d3.zedo Content-Type: application/x-javascript Date: Sat, 29 Jan 2011 01:56:25 GMT Connection: close Content-Length: 376 document.writeln("<script language=\"JavaScript\">" document.writeln("var zflag_nid=\"951\"; var zflag_cid=\"2\"; var zflag_sid=\"2\"; var zflag_width=\"728\"; var zflag_height=\"90\"; var zflag_sz= ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://ads2.adbrite.com |
Path: | /favicon.ico |
GET /favicon.ico HTTP/1.1 Host: ads2.adbrite.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.237 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: Apache=168362173x0.688 |
HTTP/1.1 302 Moved Temporarily Server: Apache-Coyote/1.1 Set-Cookie: JSESSIONID=61FCC3DEA Location: http://bounce.adbrite.com Content-Type: text/html Date: Sat, 29 Jan 2011 14:20:55 GMT Connection: close |