2. Cross-site scripting (reflected)
2.1. http://cdn11.surphace.com/widgets/sphereit/js [baseurl parameter]
2.2. http://cdn11.surphace.com/widgets/sphereit/js [siteid parameter]
2.3. http://cdn11.surphace.com/widgets/sphereit/js [siteid parameter]
2.4. http://cdn11.surphace.com/widgets/sphereit/js [siteid parameter]
Severity: | High |
Confidence: | Tentative |
Host: | http://cdn11.surphace.com |
Path: | /widgets/sphereit/js |
GET /widgets/sphereit/js81524518'%20or%201%3d1-- Accept: */* Referer: http://www.engadget.com Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: cdn11.surphace.com Proxy-Connection: Keep-Alive |
HTTP/1.1 404 Not Found Server: Apache/2.2.9 (Debian) mod_python/3.3.1 Python/2.5.2 mod_ssl/2.2.9 OpenSSL/0.9.8g mod_perl/2.0.4 Perl/v5.10.0 Content-Type: text/html; charset=iso-8859-1 Content-Length: 404 X-Varnish: 1019787268 Date: Sun, 07 Nov 2010 21:50:25 GMT Connection: close Vary: Accept-Encoding <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>404 Not Found</title> </head><body> <h1>Not Found</h1> <p>The requested URL /widgets/sphereit ...[SNIP]... <address>Apache/2.2.9 (Debian) mod_python/3.3.1 Python/2.5.2 mod_ssl/2.2.9 OpenSSL/0.9.8g mod_perl/2.0.4 Perl/v5.10.0 Server at www.surphace.com Port 80</address> </body></html> |
GET /widgets/sphereit/js81524518'%20or%201%3d2-- Accept: */* Referer: http://www.engadget.com Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: cdn11.surphace.com Proxy-Connection: Keep-Alive |
HTTP/1.1 404 Not Found Server: Apache/2.2.9 (Debian) mod_ssl/2.2.9 OpenSSL/0.9.8g Content-Type: text/html; charset=iso-8859-1 Content-Length: 346 X-Varnish: 1019787324 Date: Sun, 07 Nov 2010 21:50:25 GMT Connection: close Vary: Accept-Encoding <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>404 Not Found</title> </head><body> <h1>Not Found</h1> <p>The requested URL /widgets/sphereit ...[SNIP]... <address>Apache/2.2.9 (Debian) mod_ssl/2.2.9 OpenSSL/0.9.8g Server at www.surphace.com Port 80</address> </body></html> |
Severity: | High |
Confidence: | Certain |
Host: | http://cdn11.surphace.com |
Path: | /widgets/sphereit/js |
GET /widgets/sphereit/js Accept: */* Referer: http://www.engadget.com Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: cdn11.surphace.com Proxy-Connection: Keep-Alive |
HTTP/1.1 200 OK Server: Apache/2.2.9 (Debian) mod_ssl/2.2.9 OpenSSL/0.9.8g Content-Location: js.php TCN: choice X-Machine: web24 Content-Type: text/javascript X-Forwarded-For: 204.0.5.36 X-Varnish: 1019770991 Vary: Accept-Encoding Cache-Control: max-age=8331 Date: Sun, 07 Nov 2010 21:49:08 GMT Connection: close Content-Length: 20200 /* -- BEGIN SPHERE JS -- */ // site id for bookmarket var SPHERE_SITE_ID = ""; SPHERE_SITE_ID = "blogsmith_widget //MediaPixel Removed // Omniture /* The core url used by all m ...[SNIP]... gGo, true); document.removeEvent } } function appendStylesheet() { Sphere.addStylesheet( } function appendGlamThemeStylesheet } } Animator = new function() { var interval ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://cdn11.surphace.com |
Path: | /widgets/sphereit/js |
GET /widgets/sphereit/js Accept: */* Referer: http://www.engadget.com Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: cdn11.surphace.com Proxy-Connection: Keep-Alive |
HTTP/1.1 200 OK Server: Apache/2.2.9 (Debian) mod_ssl/2.2.9 OpenSSL/0.9.8g Content-Location: js.php TCN: choice X-Machine: web9 Content-Type: text/javascript X-Forwarded-For: 204.0.5.36 X-Varnish: 1019772837 Vary: Accept-Encoding Cache-Control: max-age=12314 Date: Sun, 07 Nov 2010 21:49:17 GMT Connection: close Content-Length: 20367 /* -- BEGIN SPHERE JS -- */ // site id for bookmarket var SPHERE_SITE_ID = ""; SPHERE_SITE_ID = "blogsmith_widget //MediaPixel Removed // Omniture /* The core url used by all methods to make calls to the remote omniture code. the 'action' arg will be the name of a method to be called by eval in the sp ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://cdn11.surphace.com |
Path: | /widgets/sphereit/js |
GET /widgets/sphereit/js Accept: */* Referer: http://www.engadget.com Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: cdn11.surphace.com Proxy-Connection: Keep-Alive |
HTTP/1.1 200 OK Server: Apache/2.2.9 (Debian) mod_ssl/2.2.9 OpenSSL/0.9.8g Content-Location: js.php TCN: choice X-Machine: web8 Content-Type: text/javascript X-Forwarded-For: 204.0.5.36 X-Varnish: 1019773197 Vary: Accept-Encoding Cache-Control: max-age=12894 Date: Sun, 07 Nov 2010 21:49:19 GMT Connection: close Content-Length: 20367 /* -- BEGIN SPHERE JS -- */ // site id for bookmarket var SPHERE_SITE_ID = ""; SPHERE_SITE_ID = "blogsmith_widget //MediaPixel Removed // Omniture /* ...[SNIP]... l; widget=null; } } if( !widget ) draw(); show(); /* var reqimgurl = 'http://stats.surphace var reqimg = new Image(); reqimg.src = reqimgurl; if (reqimg.style) { // In Safari 2.0.x, reqimg has no style until it's appended, so skip this (fixed in ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://cdn11.surphace.com |
Path: | /widgets/sphereit/js |
GET /widgets/sphereit/js Accept: */* Referer: http://www.engadget.com Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: cdn11.surphace.com Proxy-Connection: Keep-Alive |
HTTP/1.1 200 OK Server: Apache/2.2.9 (Debian) mod_ssl/2.2.9 OpenSSL/0.9.8g Content-Location: js.php TCN: choice X-Machine: web24 Content-Type: text/javascript X-Forwarded-For: 204.0.5.36 X-Varnish: 1019773004 Vary: Accept-Encoding Cache-Control: max-age=8611 Date: Sun, 07 Nov 2010 21:49:18 GMT Connection: close Content-Length: 20367 /* -- BEGIN SPHERE JS -- */ // site id for bookmarket var SPHERE_SITE_ID = ""; SPHERE_SITE_ID = "blogsmith_widget //MediaPixel Removed // Omniture /* ...[SNIP]... </div>'; var CONTENT_URL = 'http://widgets.surphace if(document.characterSet) CONTENT_URL += ('&cset='+escape(document CONTENT_URL += '&CXNID=1000009 var widget; var widgetContent; var widge ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://cdn11.surphace.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: cdn11.surphace.com |
HTTP/1.0 200 OK Server: Apache/2.2.9 (Debian) mod_ssl/2.2.9 OpenSSL/0.9.8g Last-Modified: Fri, 17 Jul 2009 00:29:04 GMT X-Machine: web18 Content-Type: application/xml X-Forwarded-For: 204.0.5.36 X-Varnish: 1018935978 Date: Sun, 07 Nov 2010 20:40:08 GMT Content-Length: 217 Connection: close <?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="*"/> </cros ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://cdn11.surphace.com |
Path: | /javascript/omniture_h15 |
GET /javascript/omniture_h15 Accept: */* Referer: http://www.surphace.com Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: cdn11.surphace.com Proxy-Connection: Keep-Alive |
HTTP/1.1 200 OK Server: Apache/2.2.9 (Debian) mod_ssl/2.2.9 OpenSSL/0.9.8g Last-Modified: Fri, 17 Jul 2009 00:29:04 GMT X-Machine: web7 Content-Type: application/javascript Content-Length: 38862 X-Varnish: 2090671298 2074644860 Date: Sun, 07 Nov 2010 20:25:39 GMT Connection: close /* SiteCatalyst code version: H.15. Copyright 1997-2008 Omniture, Inc. More info available at http://www.omniture.com - updated 9/10/2008*/ /************************ ADDITIONAL FEATURES ************* ...[SNIP]... )`i+s.hav()+q+(qs?qs:s.rq +"_r)s.p_r()}^7(qs);^y`o( +"`R`N^K=t;s.`N`g=n;s.t( ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://cdn11.surphace.com |
Path: | /widgets/sphereit/css |
GET /robots.txt HTTP/1.0 Host: cdn11.surphace.com |
HTTP/1.0 200 OK Server: Apache/2.2.9 (Debian) mod_ssl/2.2.9 OpenSSL/0.9.8g Last-Modified: Fri, 17 Jul 2009 00:29:04 GMT X-Machine: web6 Content-Type: text/plain X-Forwarded-For: 64.134.144.120 X-Varnish: 1018936231 1018934292 Date: Sun, 07 Nov 2010 20:40:09 GMT Content-Length: 74 Connection: close User-agent: * Disallow: /featured-blogs Disallow: /profile Disallow: /rss |