1. Cross-site scripting (reflected)
3. Cookie scoped to parent domain
3.1. http://www.nbcuniversalstore.com/detail.php
3.2. http://www.nbcuniversalstore.com/cart.php
4. Cookie without HttpOnly flag set
4.1. http://www.nbcuniversalstore.com/detail.php
4.2. http://www.nbcuniversalstore.com/cart.php
5. Cross-domain Referer leakage
6. Cross-domain script include
7.1. http://www.nbcuniversalstore.com/js/omniture/s_code_dageneral.js
7.2. http://www.nbcuniversalstore.com/nbcuniversalstore/behavior/typeface-0.14.js
8. Credit card numbers disclosed
10. HTML does not specify charset
11. Content type incorrectly stated
Severity: | High |
Confidence: | Certain |
Host: | http://www.nbcuniver |
Path: | /detail.php |
GET /detail.php?p=60458f08db%3balert(1)/ Host: www.nbcuniversalstore.com Proxy-Connection: keep-alive Referer: http://my.nbc.com/ Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Server: Apache Vary: Accept-Encoding Content-Type: text/html Expires: Fri, 11 Feb 2011 15:45:03 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Fri, 11 Feb 2011 15:45:03 GMT Connection: close Set-Cookie: SESSID=44260ee841472 Set-Cookie: DAPART=PRF-TV2-101833; expires=Sun, 13-Mar-2011 15:45:03 GMT; path=/; domain=nbcuniversalstore Set-Cookie: DASHORTNAME=nbcunive Set-Cookie: DAABTEST=A; expires=Sat, 11-Jun-2011 15:45:03 GMT; path=/; domain=nbcuniversalstore Set-Cookie: DAPART=PRF-TV2-101833; expires=Sun, 13-Mar-2011 15:45:03 GMT; path=/; domain=nbcuniversalstore Set-Cookie: DACART=deleted; expires=Thu, 11-Feb-2010 15:45:02 GMT; path=/; domain=nbcuniversalstore Content-Length: 86363 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http ...[SNIP]... <script type="text/javascript"> var p = 60458f08db;alert(1)/ function openPopup(sku) { var url = 'detail.php?p=' + p + '&tpl=when_available url += '&email_me_sku=' + sku; ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www.nbcuniver |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: www.nbcuniversalstore.com |
HTTP/1.0 200 OK Server: Apache Last-Modified: Fri, 27 Aug 2010 19:49:19 GMT ETag: "2a810a-eef-48ed36913edc0 Content-Type: text/xml Expires: Fri, 11 Feb 2011 15:44:36 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Fri, 11 Feb 2011 15:44:36 GMT Content-Length: 3823 Connection: close <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="*.abc.com" /> <allow-access-from domain="*.aestaging.com" /> <allow-access-from domain="*.aetn.com" /> <allow-access-from domain="*.aetv.com" /> <allow-access-from domain="*.agentc.com" /> <allow-access-from domain="*.aggregateknowledge.com" /> <allow-access-from domain="*.amazon.com" /> <allow-access-from domain="*.bcsfootball.org" /> <allow-access-from domain="*.bebo.com" /> <allow-access-from domain="*.bdbshop.com" /> <allow-access-from domain="*.bio.com" /> <allow-access-from domain="*.biography.com" /> <allow-access-from domain="*.blogspot.com" /> <allow-access-from domain="*.cbs.com" /> <allow-access-from domain="*.cbsstore.com" /> <allow-access-from domain="*.clearspring.com" /> <allow-access-from domain="*.cmt.com" /> <allow-access-from domain="*.comedycentral.com" /> <allow-access-from domain="*.cooliris.com" /> <allow-access-from domain="*.deliveryagent.com" /> <allow-access-from domain="*.discovery.com" /> <allow-access-from domain="*.dotomi.com" /> <allow-access-from domain="*.facebook.com" /> <allow-access-from domain="*.feedburner.com" /> <allow-access-from domain="*.fox.com" /> <allow-access-from domain="*.foxsports.com" /> <allow-access-from domain="*.friendster.com" /> <allow-access-from domain="*.getfused.com" /> <allow-access-from domain="*.gifts.com" /> <allow-access-from domain="*.go.com" /> <allow-access-from domain="*.google.com" /> <allow-access-from domain="*.history.com" /> <allow-access-from domain="*.historychannel.com" /> <allow-access-from domain="*.hulu.com" /> <allow-access-from domain="*.hurley.com" /> <allow-access-from domain="*.jackassworld.com" /> <allow-access-from domain="*.marchex.com" /> <allow-access-from domain="*.marthastewart.com" /> <allow-access-from domain="*.marthastewartcrafts.com" /> <allow-access-from domain="*.marthastewartstore.com" /> <allow-access-from domain="*.mslo.com" /> <allow-access-from domain="*.msn.com" /> <allow-access-from domain="*.mtv.com" /> <allow-access-from domain="*.myspace.com" /> <allow-access-from domain="*.nbc.com" /> <allow-access-from domain="*.nbcuniversalstore.com" /> <allow-access-from domain="*.performics.com" /> <allow-access-from domain="*.resultsdemo.com" /> <allow-access-from domain="*.resultspage.com" /> <allow-access-from domain="*.rockbandstore.com" /> <allow-access-from domain="*.seenon.com" /> <allow-access-from domain="*.seenonmtv.com" /> <allow-access-from domain="*.seenonstyle.com" /> <allow-access-from domain="*.shopthefilm.com" /> <allow-access-from domain="*.shopthescene.com" /> <allow-access-from domain="*.sparkart.com" /> <allow-access-from domain="*.tbs.com" /> <allow-access-from domain="*.thesimpsonsshop.com" /> <allow-access-from domain="*.tnt.tv" /> <allow-access-from domain="*.trafficleader.tv" /> <allow-access-from domain="*.tvloop.com" /> <allow-access-from domain="*.ufc.com" /> <allow-access-from domain="*.vh1.com" /> <allow-access-from domain="*.warnerbrosrecords.com" /> <allow-access-from domain="*.watercooler-inc.com" /> <allow-access-from domain="*.yahoo.com" /> <allow-access-from domain="*.zedo.com" /> ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://www.nbcuniver |
Path: | /detail.php |
GET /detail.php?p=60458&v=nbc Host: www.nbcuniversalstore.com Proxy-Connection: keep-alive Referer: http://my.nbc.com/ Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Server: Apache Vary: Accept-Encoding Content-Type: text/html Expires: Fri, 11 Feb 2011 15:44:36 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Fri, 11 Feb 2011 15:44:36 GMT Connection: close Set-Cookie: SESSID=7f12cb30b34c5 Set-Cookie: DAPART=PRF-TV2-101833; expires=Sun, 13-Mar-2011 15:44:36 GMT; path=/; domain=nbcuniversalstore Set-Cookie: DASHORTNAME=nbcunive Set-Cookie: DAABTEST=A; expires=Sat, 11-Jun-2011 15:44:36 GMT; path=/; domain=nbcuniversalstore Set-Cookie: DAPART=PRF-TV2-101833; expires=Sun, 13-Mar-2011 15:44:36 GMT; path=/; domain=nbcuniversalstore Set-Cookie: DACART=deleted; expires=Thu, 11-Feb-2010 15:44:35 GMT; path=/; domain=nbcuniversalstore Content-Length: 86327 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.nbcuniver |
Path: | /cart.php |
POST /cart.php?p=60458 HTTP/1.1 Host: www.nbcuniversalstore.com Proxy-Connection: keep-alive Referer: http://www.nbcuniver Origin: http://www.nbcuniver X-Requested-With: XMLHttpRequest Content-type: application/x-www-form Accept: text/javascript, text/html, application/xml, text/xml, */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: SESSID=fc28e281c7fbf Content-Length: 24 is_ajax=1&id=60458&qty=1 |
HTTP/1.1 200 OK Server: Apache Vary: Accept-Encoding Content-Type: text/html Expires: Fri, 11 Feb 2011 15:45:08 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Fri, 11 Feb 2011 15:45:08 GMT Connection: close Set-Cookie: DACART=qKmgk5qRnaWskJc Content-Length: 2011 <div id="ajaxCartTitle" <script type="text/javascript"> document.cookie = "last_p_added=60458 <div id="ajaxCartCoun ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://www.nbcuniver |
Path: | /detail.php |
GET /detail.php?p=60458&v=nbc Host: www.nbcuniversalstore.com Proxy-Connection: keep-alive Referer: http://my.nbc.com/ Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Server: Apache Vary: Accept-Encoding Content-Type: text/html Expires: Fri, 11 Feb 2011 15:44:36 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Fri, 11 Feb 2011 15:44:36 GMT Connection: close Set-Cookie: SESSID=7f12cb30b34c5 Set-Cookie: DAPART=PRF-TV2-101833; expires=Sun, 13-Mar-2011 15:44:36 GMT; path=/; domain=nbcuniversalstore Set-Cookie: DASHORTNAME=nbcunive Set-Cookie: DAABTEST=A; expires=Sat, 11-Jun-2011 15:44:36 GMT; path=/; domain=nbcuniversalstore Set-Cookie: DAPART=PRF-TV2-101833; expires=Sun, 13-Mar-2011 15:44:36 GMT; path=/; domain=nbcuniversalstore Set-Cookie: DACART=deleted; expires=Thu, 11-Feb-2010 15:44:35 GMT; path=/; domain=nbcuniversalstore Content-Length: 86327 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.nbcuniver |
Path: | /cart.php |
POST /cart.php?p=60458 HTTP/1.1 Host: www.nbcuniversalstore.com Proxy-Connection: keep-alive Referer: http://www.nbcuniver Origin: http://www.nbcuniver X-Requested-With: XMLHttpRequest Content-type: application/x-www-form Accept: text/javascript, text/html, application/xml, text/xml, */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: SESSID=fc28e281c7fbf Content-Length: 24 is_ajax=1&id=60458&qty=1 |
HTTP/1.1 200 OK Server: Apache Vary: Accept-Encoding Content-Type: text/html Expires: Fri, 11 Feb 2011 15:45:08 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Fri, 11 Feb 2011 15:45:08 GMT Connection: close Set-Cookie: DACART=qKmgk5qRnaWskJc Content-Length: 2011 <div id="ajaxCartTitle" <script type="text/javascript"> document.cookie = "last_p_added=60458 <div id="ajaxCartCoun ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.nbcuniver |
Path: | /detail.php |
GET /detail.php?p=60458&v=nbc Host: www.nbcuniversalstore.com Proxy-Connection: keep-alive Referer: http://my.nbc.com/ Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Server: Apache Vary: Accept-Encoding Content-Type: text/html Expires: Fri, 11 Feb 2011 15:44:36 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Fri, 11 Feb 2011 15:44:36 GMT Connection: close Set-Cookie: SESSID=7f12cb30b34c5 Set-Cookie: DAPART=PRF-TV2-101833; expires=Sun, 13-Mar-2011 15:44:36 GMT; path=/; domain=nbcuniversalstore Set-Cookie: DASHORTNAME=nbcunive Set-Cookie: DAABTEST=A; expires=Sat, 11-Jun-2011 15:44:36 GMT; path=/; domain=nbcuniversalstore Set-Cookie: DAPART=PRF-TV2-101833; expires=Sun, 13-Mar-2011 15:44:36 GMT; path=/; domain=nbcuniversalstore Set-Cookie: DACART=deleted; expires=Thu, 11-Feb-2010 15:44:35 GMT; path=/; domain=nbcuniversalstore Content-Length: 86327 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http ...[SNIP]... <link href="/nbcuniversalstore <link rel="stylesheet" href="http://assets <link href="/nbcuniversalstore ...[SNIP]... </a> <a href="http://NBC.com/" target="_blank" class="partnerlink peacockPartner"> Visit <img src="/nbcuniversalstore ...[SNIP]... <div class="textPromo"> <iframe src="http://ad.doubl <script type="text/javascript" src="http://ad.doubl ...[SNIP]... <noscript><a href="http://ad ...[SNIP]... <div class="textPromo"> <iframe src="http://ad.doubl <script type="text/javascript" src="http://ad.doubl ...[SNIP]... <noscript><a href="http://ad ...[SNIP]... <div id="contentHolder"> <script type="text/javascript" src="http://api.recaptcha ...[SNIP]... <p> <iframe src="http://www.facebook ...[SNIP]... <div class="addthis_toolbox addthis_default_style"> <a href="http://www.addthis width="16" height="16" border="0" alt="" /> ...[SNIP]... </script> <script type="text/javascript" src="http://s7.addthis ...[SNIP]... <param name="quality" value="high" /><embed src="http://widget.nbc ...[SNIP]... <li> <a href="http://html <a href="http://html <a href="http://html ...[SNIP]... <li> <a href="http://html <a href="http://html <a href="http://html ...[SNIP]... <li class="last"> <a href="http://html <a href="http://html <a href="http://html ...[SNIP]... <div class="textPromo"> <iframe src="http://ad.doubl <script type="text/javascript" src="http://ad.doubl ...[SNIP]... <noscript><a href="http://ad ...[SNIP]... <div class="textPromo"> <iframe src="http://ad.doubl <script type="text/javascript" src="http://ad.doubl ...[SNIP]... <noscript><a href="http://ad ...[SNIP]... <!-- START SCANALERT CODE --> <a target="_blank" href="https://www ...[SNIP]... <p id="companyCopy" style="font-size:11px;"> ...[SNIP]... <p id="daPower" style="margin-top:5px;" ...[SNIP]... </script> <script language="JavaScript" src="http://edge.aperture </script> <noscript> <img height="1" width="1" border="0" src="http://edge.aperture </noscript> ...[SNIP]... </script> <iframe width="1" height="1" frameborder="0" src="http://html <script language="javascript" src="http://nbcunive ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.nbcuniver |
Path: | /detail.php |
GET /detail.php?p=60458&v=nbc Host: www.nbcuniversalstore.com Proxy-Connection: keep-alive Referer: http://my.nbc.com/ Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Server: Apache Vary: Accept-Encoding Content-Type: text/html Expires: Fri, 11 Feb 2011 15:44:36 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Fri, 11 Feb 2011 15:44:36 GMT Connection: close Set-Cookie: SESSID=7f12cb30b34c5 Set-Cookie: DAPART=PRF-TV2-101833; expires=Sun, 13-Mar-2011 15:44:36 GMT; path=/; domain=nbcuniversalstore Set-Cookie: DASHORTNAME=nbcunive Set-Cookie: DAABTEST=A; expires=Sat, 11-Jun-2011 15:44:36 GMT; path=/; domain=nbcuniversalstore Set-Cookie: DAPART=PRF-TV2-101833; expires=Sun, 13-Mar-2011 15:44:36 GMT; path=/; domain=nbcuniversalstore Set-Cookie: DACART=deleted; expires=Thu, 11-Feb-2010 15:44:35 GMT; path=/; domain=nbcuniversalstore Content-Length: 86327 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http ...[SNIP]... <iframe src="http://ad.doubl <script type="text/javascript" src="http://ad.doubl ...[SNIP]... <iframe src="http://ad.doubl <script type="text/javascript" src="http://ad.doubl ...[SNIP]... <div id="contentHolder"> <script type="text/javascript" src="http://api.recaptcha ...[SNIP]... </script> <script type="text/javascript" src="http://s7.addthis ...[SNIP]... <iframe src="http://ad.doubl <script type="text/javascript" src="http://ad.doubl ...[SNIP]... <iframe src="http://ad.doubl <script type="text/javascript" src="http://ad.doubl ...[SNIP]... </script> <script language="JavaScript" src="http://edge.aperture </script> ...[SNIP]... </iframe> <script language="javascript" src="http://nbcunive ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.nbcuniver |
Path: | /js/omniture/s_code |
GET /js/omniture/s_code Host: www.nbcuniversalstore.com Proxy-Connection: keep-alive Referer: http://www.nbcuniver Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: SESSID=fc28e281c7fbf |
HTTP/1.1 200 OK Server: Apache Last-Modified: Wed, 09 Feb 2011 08:08:44 GMT ETag: "178d49-5f5a-49bd4f9 Accept-Ranges: bytes Vary: Accept-Encoding Content-Type: application/x-javascript Date: Fri, 11 Feb 2011 15:44:36 GMT Connection: close Content-Length: 24410 /* SiteCatalyst code version: H.17. Copyright 1997-2008 Omniture, Inc. More info available at http://www.omniture.com */ /************************ ADDITIONAL FEATURES ************************ Plu ...[SNIP]... .hav()+q+(qs?qs:s." +"rq(^C)),0,id,ta);qs`e; +"lush`a()}`2$m`Atl`0o,t ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.nbcuniver |
Path: | /nbcuniversalstore |
GET /nbcuniversalstore Host: www.nbcuniversalstore.com Proxy-Connection: keep-alive Referer: http://www.nbcuniver Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: SESSID=fc28e281c7fbf |
HTTP/1.1 200 OK Server: Apache Last-Modified: Mon, 18 Oct 2010 21:42:33 GMT ETag: "1560101-5f12-492eb0 Accept-Ranges: bytes Vary: Accept-Encoding Content-Type: application/x-javascript Date: Fri, 11 Feb 2011 15:44:36 GMT Connection: close Content-Length: 24338 /************************ typeface.js, version 0.14 | typefacejs.neocracy.org Copyright (c) 2008 - 2009, David Chester davidchester@gmx.net Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, includ ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.nbcuniver |
Path: | /nbcuniversalstore |
GET /nbcuniversalstore Host: www.nbcuniversalstore.com Proxy-Connection: keep-alive Referer: http://www.nbcuniver Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: SESSID=fc28e281c7fbf |
HTTP/1.1 200 OK Server: Apache Last-Modified: Fri, 05 Nov 2010 23:52:12 GMT ETag: "20f0183-711c0-49456 Accept-Ranges: bytes Vary: Accept-Encoding Content-Type: application/x-javascript Date: Fri, 11 Feb 2011 15:44:36 GMT Connection: close Content-Length: 463296 if (_typeface_js && _typeface_js.loadFace) _typeface_js.loadFace({ ...[SNIP]... 1179 314 1179 q 504 1129 455 1179 q 554 1009 554 1080 m 473 1009 q 447 1073 473 1046 q 385 1100 421 1100 q 322 1074 348 1100 q 297 1009 297 1048 q 322 946 297 972 q 385 921 348 921 q 447 946 421 921 q 473 1009 473 972 "},"...":{"x_min":17 ...[SNIP]... 447 1147 q 474 1132 462 1147 l 674 906 q 681 885 684 895 q 665 876 679 876 l 549 876 q 512 896 527 876 l 415 1006 l 316 896 q 278 876 300 876 l 163 876 q 146 885 149 876 q 153 906 144 895 l 353 1132 q 382 1147 366 1147 "},"...":{"x_min":92,"x ...[SNIP]... 430 1061 q 458 1046 445 1061 l 658 819 q 665 798 667 808 q 648 789 662 789 l 533 789 q 495 809 511 789 l 398 919 l 299 809 q 262 789 284 789 l 146 789 q 130 798 133 789 q 137 819 127 808 l 337 1046 q 366 1061 349 1061 "},"...":{"x_min":1,"x ...[SNIP]... 80 1217 397 1217 q 576 1297 564 1217 q 600 1319 579 1319 l 665 1319 q 690 1296 690 1319 q 634 1147 690 1208 q 480 1086 579 1086 q 326 1147 381 1086 q 271 1296 271 1208 q 296 1319 271 1319 l 361 1319 q 385 1297 380 1319 "},"...":{"x_min":90,"x ...[SNIP]... 447 1147 q 474 1132 462 1147 l 674 905 q 681 884 684 894 q 665 875 679 875 l 549 875 q 512 895 527 875 l 415 1005 l 316 895 q 278 875 300 875 l 163 875 q 146 884 149 875 q 153 905 144 894 l 353 1132 q 382 1147 366 1147 "},"..":{"x_min":93,"x ...[SNIP]... q 466 6 473 12 q 452 0 460 0 l 310 0 q 290 20 290 0 m 387 1149 l 512 1149 q 529 1138 524 1149 q 527 1117 534 1128 l 391 899 q 359 877 377 877 l 264 877 q 246 891 248 877 q 253 917 245 906 l 357 1128 q 387 1149 369 1149 "},"..":{"x_min":53,"x ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.nbcuniver |
Path: | /nbcuniversalstore/layout |
GET /robots.txt HTTP/1.0 Host: www.nbcuniversalstore.com |
HTTP/1.0 200 OK Server: Apache Last-Modified: Fri, 07 Apr 2006 21:55:02 GMT ETag: "3f0126-19-410de4f0ed980" Content-Type: text/plain Expires: Fri, 11 Feb 2011 15:44:36 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Fri, 11 Feb 2011 15:44:36 GMT Content-Length: 25 Connection: close User-agent: * Disallow: |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.nbcuniver |
Path: | /cart.php |
POST /cart.php?p=60458 HTTP/1.1 Host: www.nbcuniversalstore.com Proxy-Connection: keep-alive Referer: http://www.nbcuniver Origin: http://www.nbcuniver X-Requested-With: XMLHttpRequest Content-type: application/x-www-form Accept: text/javascript, text/html, application/xml, text/xml, */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: SESSID=fc28e281c7fbf Content-Length: 24 is_ajax=1&id=60458&qty=1 |
HTTP/1.1 200 OK Server: Apache Vary: Accept-Encoding Content-Type: text/html Expires: Fri, 11 Feb 2011 15:45:08 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Fri, 11 Feb 2011 15:45:08 GMT Connection: close Set-Cookie: DACART=qKmgk5qRnaWskJc Content-Length: 2011 <div id="ajaxCartTitle" <script type="text/javascript"> document.cookie = "last_p_added=60458 <div id="ajaxCartCoun ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://www.nbcuniver |
Path: | /nbcuniversalstore/layout |
GET /nbcuniversalstore/layout Host: www.nbcuniversalstore.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: SESSID=fc28e281c7fbf |
HTTP/1.1 200 OK Server: Apache Last-Modified: Mon, 08 Nov 2010 20:13:44 GMT ETag: "4380d6-37e-4949042d06e00 Accept-Ranges: bytes Content-Length: 894 Content-Type: text/plain Date: Fri, 11 Feb 2011 15:44:49 GMT Connection: close ..............h.......(.. ...[SNIP]... |