1. Cross-site scripting (reflected)
2. Cleartext submission of password
2.1. http://www1.hilton.com/en_US/hi/customersupport/index.do
2.2. http://www1.hilton.com/en_US/hi/customersupport/site-usage.do
2.5. http://www1.hilton.com/en_US/hi/index.do
2.6. http://www1.hilton.com/en_US/hi/index.do
2.7. http://www1.hilton.com/en_US/hi/sitemap/index.do
2.8. http://www1.hilton.com/es/hi/index.do
2.9. http://www1.hilton.com/es/hi/index.do
2.10. http://www1.hilton.com/fr/hi/index.do
2.11. http://www1.hilton.com/fr/hi/index.do
3.1. http://www1.hilton.com/doxch.do
3.2. http://www1.hilton.com/en/ch/home.do
3.3. http://www1.hilton.com/en_US/dt/index.do
3.4. http://www1.hilton.com/en_US/es/index.do
3.5. http://www1.hilton.com/en_US/gi/index.do
3.6. http://www1.hilton.com/en_US/hh/home_index.do
3.7. http://www1.hilton.com/en_US/hi/customersupport/index.do
3.8. http://www1.hilton.com/en_US/hi/customersupport/site-usage.do
3.11. http://www1.hilton.com/en_US/hi/index.do
3.12. http://www1.hilton.com/en_US/hp/index.do
3.13. http://www1.hilton.com/en_US/ht/index.do
3.14. http://www1.hilton.com/en_US/hw/index.do
3.15. http://www1.hilton.com/en_US/ww/customersupport/privacy-policy.do
3.16. http://www1.hilton.com/es/hi/index.do
3.17. http://www1.hilton.com/fr/hi/index.do
4. Cookie without HttpOnly flag set
4.1. http://www1.hilton.com/en_US/hi/index.do
4.3. http://www1.hilton.com/ExittoAmericanEnglishSite.html
4.4. http://www1.hilton.com/ExittoFrenchSite.html
4.5. http://www1.hilton.com/ExittoGermanSite.html
4.6. http://www1.hilton.com/ExittoJapanSite.html
4.7. http://www1.hilton.com/ExittoSpanishSite.html
4.8. http://www1.hilton.com/ExittoUKSite.html
4.9. http://www1.hilton.com/doxch.do
4.10. http://www1.hilton.com/en/ch/home.do
4.11. http://www1.hilton.com/en_US/dt/index.do
4.12. http://www1.hilton.com/en_US/es/index.do
4.13. http://www1.hilton.com/en_US/gi/index.do
4.14. http://www1.hilton.com/en_US/hh/home_index.do
4.15. http://www1.hilton.com/en_US/hi/customersupport/index.do
4.16. http://www1.hilton.com/en_US/hi/customersupport/site-usage.do
4.17. http://www1.hilton.com/en_US/hi/homeNew.do
4.23. http://www1.hilton.com/en_US/hi/media/images/headers/hdr_signin.gif
4.24. http://www1.hilton.com/en_US/hi/sitemap/index.do
4.25. http://www1.hilton.com/en_US/hp/index.do
4.26. http://www1.hilton.com/en_US/ht/index.do
4.27. http://www1.hilton.com/en_US/hw/index.do
4.28. http://www1.hilton.com/en_US/ww/customersupport/privacy-policy.do
4.29. http://www1.hilton.com/es/hi/index.do
4.30. http://www1.hilton.com/fr/hi/index.do
4.31. http://www1.hilton.com/homepage/index.do
4.32. http://www1.hilton.com/ts/en_US/hi/jsp/inc_home_flash.xml
5. Password field with autocomplete enabled
5.1. http://www1.hilton.com/en_US/hi/customersupport/index.do
5.2. http://www1.hilton.com/en_US/hi/customersupport/site-usage.do
5.5. http://www1.hilton.com/en_US/hi/index.do
5.6. http://www1.hilton.com/en_US/hi/index.do
5.7. http://www1.hilton.com/en_US/hi/index.do
5.8. http://www1.hilton.com/en_US/hi/index.do
5.9. http://www1.hilton.com/en_US/hi/index.do
5.10. http://www1.hilton.com/en_US/hi/index.do
5.11. http://www1.hilton.com/en_US/hi/index.do
5.12. http://www1.hilton.com/en_US/hi/sitemap/index.do
5.13. http://www1.hilton.com/es/hi/index.do
5.14. http://www1.hilton.com/es/hi/index.do
5.15. http://www1.hilton.com/es/hi/index.do
5.16. http://www1.hilton.com/fr/hi/index.do
5.17. http://www1.hilton.com/fr/hi/index.do
5.18. http://www1.hilton.com/fr/hi/index.do
6. Cookie scoped to parent domain
6.1. http://www1.hilton.com/en_US/hi/media/images/headers/hdr_signin.gif
6.2. http://www1.hilton.com/es/hi/index.do
6.3. http://www1.hilton.com/fr/hi/index.do
7. Cross-domain Referer leakage
7.1. http://www1.hilton.com/en_US/hi/customersupport/index.do
7.2. http://www1.hilton.com/en_US/hi/customersupport/site-usage.do
7.5. http://www1.hilton.com/en_US/hi/index.do
7.6. http://www1.hilton.com/es/hi/index.do
7.7. http://www1.hilton.com/fr/hi/index.do
8.1. http://www1.hilton.com/en_US/hi/customersupport/index.do
8.2. http://www1.hilton.com/en_US/hi/customersupport/site-usage.do
10. Content type incorrectly stated
Severity: | High |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /en_US/hi/hotel/BOSFDHF |
GET /en_US/hi/hotel/BOSFDHF Host: www1.hilton.com Proxy-Connection: keep-alive Referer: http://www.hilton.com/en Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 200 OK Server: Apache Content-Language: en-US Content-Type: text/html;charset=UTF-8 Cache-Control: private Date: Fri, 11 Feb 2011 02:00:05 GMT Connection: close Vary: Accept-Encoding Set-Cookie: NSC_qse-qgt=44153db63660 Content-Length: 81271 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <meta http ...[SNIP]... <a href="/es/hi/hotel ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /en_US/hi/hotel/BOSFDHF |
GET /en_US/hi/hotel/BOSFDHF Host: www1.hilton.com Proxy-Connection: keep-alive Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 200 OK Server: Apache Content-Language: en-US Content-Type: text/html;charset=UTF-8 Cache-Control: private Vary: Accept-Encoding Date: Fri, 11 Feb 2011 02:03:02 GMT Connection: close Set-Cookie: NSC_qse-qgt=44153db63660 Content-Length: 81433 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <meta http ...[SNIP]... <img src=a onerror=alert(document ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /en_US/hi/customersupport |
GET /en_US/hi/customersupport Host: www1.hilton.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 200 OK Server: Apache Content-Language: en-US Content-Type: text/html;charset=UTF-8 Cache-Control: private Date: Fri, 11 Feb 2011 01:56:10 GMT Connection: close Connection: Transfer-Encoding Set-Cookie: NSC_qse-qgt=44153db63660 Content-Length: 34015 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <meta http-equi ...[SNIP]... <!--Affiliates changes start here - by kapil taneja--> <form name="frmSignin" action="/doxch.do?dst <!--Affiliates changes end here - by kapil taneja--> ...[SNIP]... <br/> <input id="PasswordPIN" name="password" type="password" tabindex="5" class="frmTextSignin"/><br/> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /en_US/hi/customersupport |
GET /en_US/hi/customersupport Host: www1.hilton.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 200 OK Server: Apache Content-Language: en-US Content-Type: text/html;charset=UTF-8 Cache-Control: private Date: Fri, 11 Feb 2011 01:56:15 GMT Connection: close Connection: Transfer-Encoding Set-Cookie: NSC_qse-qgt=44153db63660 Content-Length: 68574 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <meta http-equi ...[SNIP]... <!--Affiliates changes start here - by kapil taneja--> <form name="frmSignin" action="/doxch.do?dst <!--Affiliates changes end here - by kapil taneja--> ...[SNIP]... <br/> <input id="PasswordPIN" name="password" type="password" tabindex="5" class="frmTextSignin"/><br/> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /en_US/hi/hotel/BOSFDHF |
GET /en_US/hi/hotel/BOSFDHF Host: www1.hilton.com Proxy-Connection: keep-alive Referer: http://www.hilton.com/en Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 200 OK Server: Apache Content-Language: en-US Content-Type: text/html;charset=UTF-8 Cache-Control: private Vary: Accept-Encoding Date: Fri, 11 Feb 2011 01:59:39 GMT Connection: close Set-Cookie: NSC_qse-qgt=44153db63660 Content-Length: 81197 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <meta http ...[SNIP]... <!--Affiliates changes start here - by kapil taneja--> <form name="frmSignin" action="/doxch.do?dst <!--Affiliates changes end here - by kapil taneja--> ...[SNIP]... <br/> <input id="PasswordPIN" name="password" type="password" tabindex="5" class="frmTextSignin"/><br/> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /en_US/hi/hotel/BOSFDHF |
GET /en_US/hi/hotel/BOSFDHF Host: www1.hilton.com Proxy-Connection: keep-alive Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 200 OK Server: Apache Content-Language: en-US Content-Type: text/html;charset=UTF-8 Cache-Control: private Vary: Accept-Encoding Date: Fri, 11 Feb 2011 02:02:36 GMT Connection: close Set-Cookie: NSC_qse-qgt=44153db63660 Content-Length: 81274 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <meta http ...[SNIP]... <!--Affiliates changes start here - by kapil taneja--> <form name="frmSignin" action="/doxch.do?dst <!--Affiliates changes end here - by kapil taneja--> ...[SNIP]... <br/> <input id="PasswordPIN" name="password" type="password" tabindex="5" class="frmTextSignin"/><br/> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /en_US/hi/index.do |
GET /en_US/hi/index.do HTTP/1.1 Host: www1.hilton.com Proxy-Connection: keep-alive Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Server: Apache Content-Language: en-US Content-Type: text/html;charset=UTF-8 Cache-Control: private Vary: Accept-Encoding Date: Fri, 11 Feb 2011 01:51:15 GMT Connection: close Set-Cookie: JSESSIONID=DE3A2A627 Set-Cookie: cross-sell=hi; Domain=hilton.com; Path=/ Set-Cookie: NSC_qse-qgt=44153d5f3660 Content-Length: 95047 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <meta http-equiv="Content-Type" ...[SNIP]... <div id="myreservations" style="display:none;"> <form name="myForm" id="myForm" method="post"> <div class="containReserv ...[SNIP]... </label><input id="Password_myRes" tabindex="9" name="password" class="frmTextMed" type="password"> </fieldset> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /en_US/hi/index.do |
GET /en_US/hi/index.do HTTP/1.1 Host: www1.hilton.com Proxy-Connection: keep-alive Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Server: Apache Content-Language: en-US Content-Type: text/html;charset=UTF-8 Cache-Control: private Vary: Accept-Encoding Date: Fri, 11 Feb 2011 01:51:15 GMT Connection: close Set-Cookie: JSESSIONID=DE3A2A627 Set-Cookie: cross-sell=hi; Domain=hilton.com; Path=/ Set-Cookie: NSC_qse-qgt=44153d5f3660 Content-Length: 95047 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <meta http-equiv="Content-Type" ...[SNIP]... <!--Affiliates changes start here - by kapil taneja--> <form name="frmSignin" action="/doxch.do <!--Affiliates changes end here - by kapil taneja--> ...[SNIP]... <br/> <input id="PasswordPIN" name="password" type="password" tabindex="5" class="frmTextSignin"/><br/> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /en_US/hi/sitemap/index |
GET /en_US/hi/sitemap/index Host: www1.hilton.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 200 OK Server: Apache Content-Language: en-US Content-Type: text/html;charset=UTF-8 Cache-Control: private Date: Fri, 11 Feb 2011 01:56:10 GMT Connection: close Connection: Transfer-Encoding Set-Cookie: NSC_qse-qgt=44153db63660 Content-Length: 36519 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <meta http-equiv= ...[SNIP]... <!--Affiliates changes start here - by kapil taneja--> <form name="frmSignin" action="/doxch.do?dst <!--Affiliates changes end here - by kapil taneja--> ...[SNIP]... <br/> <input id="PasswordPIN" name="password" type="password" tabindex="5" class="frmTextSignin"/><br/> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /es/hi/index.do |
GET /es/hi/index.do Host: www1.hilton.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 200 OK Server: Apache Content-Language: es Content-Type: text/html;charset=UTF-8 Cache-Control: private Date: Fri, 11 Feb 2011 01:56:23 GMT Connection: close Connection: Transfer-Encoding Set-Cookie: tslang=hi|es; Domain=.hilton.com; Path=/ Set-Cookie: cross-sell=hi; Domain=hilton.com; Path=/ Set-Cookie: NSC_qse-qgt=44153db63660 Content-Length: 94224 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <meta http-equiv="Content-Type" ...[SNIP]... <!--Affiliates changes start here - by kapil taneja--> <form name="frmSignin" action="/doxch.do?dst <!--Affiliates changes end here - by kapil taneja--> ...[SNIP]... <br/> <input id="PasswordPIN" name="password" type="password" tabindex="5" class="frmTextSignin"/><br/> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /es/hi/index.do |
GET /es/hi/index.do Host: www1.hilton.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 200 OK Server: Apache Content-Language: es Content-Type: text/html;charset=UTF-8 Cache-Control: private Date: Fri, 11 Feb 2011 01:56:23 GMT Connection: close Connection: Transfer-Encoding Set-Cookie: tslang=hi|es; Domain=.hilton.com; Path=/ Set-Cookie: cross-sell=hi; Domain=hilton.com; Path=/ Set-Cookie: NSC_qse-qgt=44153db63660 Content-Length: 94224 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <meta http-equiv="Content-Type" ...[SNIP]... <div id="myreservations" style="display:none;"> <form name="myForm" id="myForm" method="post"> <div class="containReserv ...[SNIP]... </label><input id="Password_myRes" tabindex="9" name="password" class="frmTextMed" type="password"> </fieldset> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /fr/hi/index.do |
GET /fr/hi/index.do HTTP/1.1 Host: www1.hilton.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 200 OK Server: Apache Content-Language: fr Content-Type: text/html;charset=UTF-8 Cache-Control: private Date: Fri, 11 Feb 2011 01:56:25 GMT Connection: close Connection: Transfer-Encoding Set-Cookie: tslang=hi|fr; Domain=.hilton.com; Path=/ Set-Cookie: cross-sell=hi; Domain=hilton.com; Path=/ Set-Cookie: NSC_qse-qgt=44153db63660 Content-Length: 94917 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <meta http-equiv="Content-Type" ...[SNIP]... <div id="myreservations" style="display:none;"> <form name="myForm" id="myForm" method="post"> <div class="containReserv ...[SNIP]... </label><input id="Password_myRes" tabindex="9" name="password" class="frmTextMed" type="password"> </fieldset> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /fr/hi/index.do |
GET /fr/hi/index.do HTTP/1.1 Host: www1.hilton.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 200 OK Server: Apache Content-Language: fr Content-Type: text/html;charset=UTF-8 Cache-Control: private Date: Fri, 11 Feb 2011 01:56:25 GMT Connection: close Connection: Transfer-Encoding Set-Cookie: tslang=hi|fr; Domain=.hilton.com; Path=/ Set-Cookie: cross-sell=hi; Domain=hilton.com; Path=/ Set-Cookie: NSC_qse-qgt=44153db63660 Content-Length: 94917 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <meta http-equiv="Content-Type" ...[SNIP]... <!--Affiliates changes start here - by kapil taneja--> <form name="frmSignin" action="/doxch.do?dst <!--Affiliates changes end here - by kapil taneja--> ...[SNIP]... <br/> <input id="PasswordPIN" name="password" type="password" tabindex="5" class="frmTextSignin"/><br/> ...[SNIP]... |
Severity: | Medium |
Confidence: | Firm |
Host: | http://www1.hilton.com |
Path: | /doxch.do |
GET /doxch.do;jsessionid=0ABC42E492304CBBBCE5 Host: www1.hilton.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 302 Moved Temporarily Server: Apache Location: https://secure.hilton.com Content-Length: 0 Content-Type: text/plain; charset=UTF-8 Date: Fri, 11 Feb 2011 01:56:25 GMT Connection: close Set-Cookie: NSC_qse-qgt=44153db63660 |
Severity: | Medium |
Confidence: | Firm |
Host: | http://www1.hilton.com |
Path: | /en/ch/home.do |
GET /en/ch/home.do;jsessionid Host: www1.hilton.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 301 Moved Permanently Server: Apache Location: http://conradhotels1 Content-Length: 0 Content-Type: text/plain; charset=UTF-8 Date: Fri, 11 Feb 2011 01:56:19 GMT Connection: close Set-Cookie: NSC_qse-qgt=44153db63660 |
Severity: | Medium |
Confidence: | Firm |
Host: | http://www1.hilton.com |
Path: | /en_US/dt/index.do |
GET /en_US/dt/index.do Host: www1.hilton.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 301 Moved Permanently Server: Apache Location: http://doubletree1.hilton Content-Length: 0 Content-Type: text/plain; charset=UTF-8 Date: Fri, 11 Feb 2011 01:56:15 GMT Connection: close Set-Cookie: NSC_qse-qgt=44153db63660 |
Severity: | Medium |
Confidence: | Firm |
Host: | http://www1.hilton.com |
Path: | /en_US/es/index.do |
GET /en_US/es/index.do Host: www1.hilton.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 301 Moved Permanently Server: Apache Location: http://embassysuites1 Content-Length: 0 Content-Type: text/plain; charset=UTF-8 Date: Fri, 11 Feb 2011 01:56:16 GMT Connection: close Set-Cookie: NSC_qse-qgt=44153db63660 |
Severity: | Medium |
Confidence: | Firm |
Host: | http://www1.hilton.com |
Path: | /en_US/gi/index.do |
GET /en_US/gi/index.do Host: www1.hilton.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 301 Moved Permanently Server: Apache Location: http://hiltongardeninn1 Content-Length: 0 Content-Type: text/plain; charset=UTF-8 Date: Fri, 11 Feb 2011 01:56:16 GMT Connection: close Set-Cookie: NSC_qse-qgt=44153db63660 |
Severity: | Medium |
Confidence: | Firm |
Host: | http://www1.hilton.com |
Path: | /en_US/hh/home_index.do |
GET /en_US/hh/home_index.do Host: www1.hilton.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 301 Moved Permanently Server: Apache Location: http://hhonors1.hilton Content-Length: 0 Content-Type: text/plain; charset=UTF-8 Date: Fri, 11 Feb 2011 01:56:17 GMT Connection: close Set-Cookie: NSC_qse-qgt=44153db63660 |
Severity: | Medium |
Confidence: | Firm |
Host: | http://www1.hilton.com |
Path: | /en_US/hi/customersupport |
GET /en_US/hi/customersupport Host: www1.hilton.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 200 OK Server: Apache Content-Language: en-US Content-Type: text/html;charset=UTF-8 Cache-Control: private Date: Fri, 11 Feb 2011 01:56:11 GMT Connection: close Connection: Transfer-Encoding Set-Cookie: NSC_qse-qgt=44153db63660 Content-Length: 34015 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <meta http-equi ...[SNIP]... |
Severity: | Medium |
Confidence: | Firm |
Host: | http://www1.hilton.com |
Path: | /en_US/hi/customersupport |
GET /en_US/hi/customersupport Host: www1.hilton.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 200 OK Server: Apache Content-Language: en-US Content-Type: text/html;charset=UTF-8 Cache-Control: private Date: Fri, 11 Feb 2011 01:56:16 GMT Connection: close Connection: Transfer-Encoding Set-Cookie: NSC_qse-qgt=44153db63660 Content-Length: 68574 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <meta http-equi ...[SNIP]... |
Severity: | Medium |
Confidence: | Firm |
Host: | http://www1.hilton.com |
Path: | /en_US/hi/hotel/BOSFDHF |
GET /en_US/hi/hotel/BOSFDHF Host: www1.hilton.com Proxy-Connection: keep-alive Referer: http://www.hilton.com/en Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 200 OK Server: Apache Content-Language: en-US Content-Type: text/html;charset=UTF-8 Cache-Control: private Vary: Accept-Encoding Date: Fri, 11 Feb 2011 01:59:39 GMT Connection: close Set-Cookie: NSC_qse-qgt=44153db63660 Content-Length: 81197 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <meta http ...[SNIP]... |
Severity: | Medium |
Confidence: | Firm |
Host: | http://www1.hilton.com |
Path: | /en_US/hi/hotel/BOSFDHF |
GET /en_US/hi/hotel/BOSFDHF Host: www1.hilton.com Proxy-Connection: keep-alive Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 200 OK Server: Apache Content-Language: en-US Content-Type: text/html;charset=UTF-8 Cache-Control: private Vary: Accept-Encoding Date: Fri, 11 Feb 2011 02:02:36 GMT Connection: close Set-Cookie: NSC_qse-qgt=44153db63660 Content-Length: 81274 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <meta http ...[SNIP]... |
Severity: | Medium |
Confidence: | Firm |
Host: | http://www1.hilton.com |
Path: | /en_US/hi/index.do |
GET /en_US/hi/index.do HTTP/1.1 Host: www1.hilton.com Proxy-Connection: keep-alive Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Server: Apache Content-Language: en-US Content-Type: text/html;charset=UTF-8 Cache-Control: private Vary: Accept-Encoding Date: Fri, 11 Feb 2011 01:51:15 GMT Connection: close Set-Cookie: JSESSIONID=DE3A2A627 Set-Cookie: cross-sell=hi; Domain=hilton.com; Path=/ Set-Cookie: NSC_qse-qgt=44153d5f3660 Content-Length: 95047 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <meta http-equiv="Content-Type" ...[SNIP]... <td> <a href="/en_US/hi/index.do <img src="/en_US/hi/media ...[SNIP]... <li class="brandBarLi brandBarLi_CH" id="brandBarLi_CH"><a class="brandBarLiA" onmouseover="turnOnPopup( ...[SNIP]... <li class="brandBarLi brandBarLi_HI" id="brandBarLi_HI"><a class="brandBarLiA" onmouseover="turnOnPopup( ...[SNIP]... <li class="brandBarLi brandBarLi_DT" id="brandBarLi_DT"><a class="brandBarLiA" onmouseover="turnOnPopup( ...[SNIP]... <li class="brandBarLi brandBarLi_ES" id="brandBarLi_ES"><a class="brandBarLiA" onmouseover="turnOnPopup( ...[SNIP]... <li class="brandBarLi brandBarLi_GI" id="brandBarLi_GI"><a class="brandBarLiA" onmouseover="turnOnPopup( ...[SNIP]... <li class="brandBarLi brandBarLi_HP" id="brandBarLi_HP"><a class="brandBarLiA" onmouseover="turnOnPopup( ...[SNIP]... <li class="brandBarLi brandBarLi_HW" id="brandBarLi_HW"><a class="brandBarLiA" onmouseover="turnOnPopup( ...[SNIP]... <li class="brandBarLi brandBarLi_HT" id="brandBarLi_HT"><a class="brandBarLiA" onmouseover="turnOnPopup( ...[SNIP]... <li class="brandBarLi brandBarLi_WW" id="brandBarLi_WW"><a class="brandBarLiA" href="/en_US/hh/home ...[SNIP]... <li> <a href="/en_US/hi Customer Support </a> ...[SNIP]... <li> <a href="/en_US/ww Privacy Policy (updated July 2007) </a> ...[SNIP]... <li> <a href="/en_US/hi Site Usage Agreement </a> ...[SNIP]... <li><a href="/es/hi/index.do ...[SNIP]... <li><a href="/fr/hi/index.do ...[SNIP]... |
Severity: | Medium |
Confidence: | Firm |
Host: | http://www1.hilton.com |
Path: | /en_US/hp/index.do |
GET /en_US/hp/index.do Host: www1.hilton.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 301 Moved Permanently Server: Apache Location: http://hamptoninn1.hilton Content-Length: 0 Content-Type: text/plain; charset=UTF-8 Date: Fri, 11 Feb 2011 01:56:16 GMT Connection: close Set-Cookie: NSC_qse-qgt=44153db63660 |
Severity: | Medium |
Confidence: | Firm |
Host: | http://www1.hilton.com |
Path: | /en_US/ht/index.do |
GET /en_US/ht/index.do Host: www1.hilton.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 301 Moved Permanently Server: Apache Location: http://home2suites1 Content-Length: 0 Content-Type: text/plain; charset=UTF-8 Date: Fri, 11 Feb 2011 01:56:17 GMT Connection: close Set-Cookie: NSC_qse-qgt=44153db63660 |
Severity: | Medium |
Confidence: | Firm |
Host: | http://www1.hilton.com |
Path: | /en_US/hw/index.do |
GET /en_US/hw/index.do Host: www1.hilton.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 301 Moved Permanently Server: Apache Location: http://homewoodsuites1 Content-Length: 0 Content-Type: text/plain; charset=UTF-8 Date: Fri, 11 Feb 2011 01:56:16 GMT Connection: close Set-Cookie: NSC_qse-qgt=44153db63660 |
Severity: | Medium |
Confidence: | Firm |
Host: | http://www1.hilton.com |
Path: | /en_US/ww/customersupport |
GET /en_US/ww/customersupport Host: www1.hilton.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 301 Moved Permanently Server: Apache Location: http://hiltonworldwide1 Content-Length: 0 Content-Type: text/plain; charset=UTF-8 Date: Fri, 11 Feb 2011 01:56:18 GMT Connection: close Set-Cookie: NSC_qse-qgt=44153db63660 |
Severity: | Medium |
Confidence: | Firm |
Host: | http://www1.hilton.com |
Path: | /es/hi/index.do |
GET /es/hi/index.do Host: www1.hilton.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 200 OK Server: Apache Content-Language: es Content-Type: text/html;charset=UTF-8 Cache-Control: private Date: Fri, 11 Feb 2011 01:56:23 GMT Connection: close Connection: Transfer-Encoding Set-Cookie: tslang=hi|es; Domain=.hilton.com; Path=/ Set-Cookie: cross-sell=hi; Domain=hilton.com; Path=/ Set-Cookie: NSC_qse-qgt=44153db63660 Content-Length: 94224 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <meta http-equiv="Content-Type" ...[SNIP]... |
Severity: | Medium |
Confidence: | Firm |
Host: | http://www1.hilton.com |
Path: | /fr/hi/index.do |
GET /fr/hi/index.do Host: www1.hilton.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 200 OK Server: Apache Content-Language: fr Content-Type: text/html;charset=UTF-8 Cache-Control: private Date: Fri, 11 Feb 2011 01:56:25 GMT Connection: close Connection: Transfer-Encoding Set-Cookie: tslang=hi|fr; Domain=.hilton.com; Path=/ Set-Cookie: cross-sell=hi; Domain=hilton.com; Path=/ Set-Cookie: NSC_qse-qgt=44153db63660 Content-Length: 95124 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <meta http-equiv="Content-Type" ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://www1.hilton.com |
Path: | /en_US/hi/index.do |
GET /en_US/hi/index.do HTTP/1.1 Host: www1.hilton.com Proxy-Connection: keep-alive Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Server: Apache Content-Language: en-US Content-Type: text/html;charset=UTF-8 Cache-Control: private Vary: Accept-Encoding Date: Fri, 11 Feb 2011 01:51:15 GMT Connection: close Set-Cookie: JSESSIONID=DE3A2A627 Set-Cookie: cross-sell=hi; Domain=hilton.com; Path=/ Set-Cookie: NSC_qse-qgt=44153d5f3660 Content-Length: 95047 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <meta http-equiv="Content-Type" ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | / |
GET / HTTP/1.1 Host: www1.hilton.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 301 Moved Permanently Server: Apache Location: http://www1.hilton.com/en Content-Length: 0 Content-Type: text/plain; charset=UTF-8 Date: Fri, 11 Feb 2011 01:56:26 GMT Connection: close Set-Cookie: NSC_qse-qgt=44153db63660 |
Severity: | Information |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /ExittoAmericanEngli |
GET /ExittoAmericanEngli Host: www1.hilton.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 404 Not Found Server: Apache Last-Modified: Tue, 01 Feb 2011 21:00:52 GMT ETag: "15843c-90a-d3e32900" Content-Type: text/html; charset=UTF-8 Cache-Control: private Date: Fri, 11 Feb 2011 01:56:26 GMT Content-Length: 2314 Connection: close Set-Cookie: NSC_qse-qgt=44153db63660 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html lang="en"> <head> <meta http-equiv="X-UA <meta http-equiv ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /ExittoFrenchSite.html |
GET /ExittoFrenchSite.html HTTP/1.1 Host: www1.hilton.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 404 Not Found Server: Apache Last-Modified: Tue, 01 Feb 2011 21:00:52 GMT ETag: "15843c-90a-d3e32900" Content-Type: text/html; charset=UTF-8 Cache-Control: private Date: Fri, 11 Feb 2011 01:56:26 GMT Content-Length: 2314 Connection: close Set-Cookie: NSC_qse-qgt=44153db63660 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html lang="en"> <head> <meta http-equiv="X-UA <meta http-equiv ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /ExittoGermanSite.html |
GET /ExittoGermanSite.html HTTP/1.1 Host: www1.hilton.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 404 Not Found Server: Apache Last-Modified: Tue, 01 Feb 2011 21:00:52 GMT ETag: "15843c-90a-d3e32900" Content-Type: text/html; charset=UTF-8 Cache-Control: private Date: Fri, 11 Feb 2011 01:56:26 GMT Content-Length: 2314 Connection: close Set-Cookie: NSC_qse-qgt=44153db63660 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html lang="en"> <head> <meta http-equiv="X-UA <meta http-equiv ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /ExittoJapanSite.html |
GET /ExittoJapanSite.html HTTP/1.1 Host: www1.hilton.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 404 Not Found Server: Apache Last-Modified: Tue, 01 Feb 2011 21:00:52 GMT ETag: "15843c-90a-d3e32900" Content-Type: text/html; charset=UTF-8 Cache-Control: private Date: Fri, 11 Feb 2011 01:56:26 GMT Content-Length: 2314 Connection: close Set-Cookie: NSC_qse-qgt=44153db63660 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html lang="en"> <head> <meta http-equiv="X-UA <meta http-equiv ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /ExittoSpanishSite.html |
GET /ExittoSpanishSite.html HTTP/1.1 Host: www1.hilton.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 404 Not Found Server: Apache Last-Modified: Tue, 01 Feb 2011 21:00:52 GMT ETag: "15843c-90a-d3e32900" Content-Type: text/html; charset=UTF-8 Cache-Control: private Date: Fri, 11 Feb 2011 01:56:26 GMT Content-Length: 2314 Connection: close Set-Cookie: NSC_qse-qgt=44153db63660 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html lang="en"> <head> <meta http-equiv="X-UA <meta http-equiv ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /ExittoUKSite.html |
GET /ExittoUKSite.html HTTP/1.1 Host: www1.hilton.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 404 Not Found Server: Apache Last-Modified: Tue, 01 Feb 2011 21:00:52 GMT ETag: "15843c-90a-d3e32900" Content-Type: text/html; charset=UTF-8 Cache-Control: private Date: Fri, 11 Feb 2011 01:56:26 GMT Content-Length: 2314 Connection: close Set-Cookie: NSC_qse-qgt=44153db63660 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html lang="en"> <head> <meta http-equiv="X-UA <meta http-equiv ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /doxch.do |
POST /doxch.do?dst=http://HI Host: www1.hilton.com Proxy-Connection: keep-alive Referer: http://www1.hilton.com/en Cache-Control: max-age=0 Origin: http://www1.hilton.com Content-Type: application/x-www-form Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JSESSIONID=0ABC42E49 Content-Length: 881 brandsToSearch=ALL ...[SNIP]... |
HTTP/1.1 302 Moved Temporarily Server: Apache Location: http://www.hilton.com/en Content-Length: 0 Content-Type: text/plain; charset=UTF-8 Date: Fri, 11 Feb 2011 01:55:41 GMT Connection: close Set-Cookie: NSC_qse-qgt=44153db63660 |
Severity: | Information |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /en/ch/home.do |
GET /en/ch/home.do HTTP/1.1 Host: www1.hilton.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 301 Moved Permanently Server: Apache Location: http://conradhotels1 Content-Length: 0 Content-Type: text/plain; charset=UTF-8 Date: Fri, 11 Feb 2011 01:56:18 GMT Connection: close Set-Cookie: NSC_qse-qgt=44153db63660 |
Severity: | Information |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /en_US/dt/index.do |
GET /en_US/dt/index.do HTTP/1.1 Host: www1.hilton.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 301 Moved Permanently Server: Apache Location: http://doubletree1.hilton Content-Length: 0 Content-Type: text/plain; charset=UTF-8 Date: Fri, 11 Feb 2011 01:56:15 GMT Connection: close Set-Cookie: NSC_qse-qgt=44153db63660 |
Severity: | Information |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /en_US/es/index.do |
GET /en_US/es/index.do HTTP/1.1 Host: www1.hilton.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 301 Moved Permanently Server: Apache Location: http://embassysuites1 Content-Length: 0 Content-Type: text/plain; charset=UTF-8 Date: Fri, 11 Feb 2011 01:56:16 GMT Connection: close Set-Cookie: NSC_qse-qgt=44153db63660 |
Severity: | Information |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /en_US/gi/index.do |
GET /en_US/gi/index.do HTTP/1.1 Host: www1.hilton.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 301 Moved Permanently Server: Apache Location: http://hiltongardeninn1 Content-Length: 0 Content-Type: text/plain; charset=UTF-8 Date: Fri, 11 Feb 2011 01:56:16 GMT Connection: close Set-Cookie: NSC_qse-qgt=44153db63660 |
Severity: | Information |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /en_US/hh/home_index.do |
GET /en_US/hh/home_index.do HTTP/1.1 Host: www1.hilton.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 301 Moved Permanently Server: Apache Location: http://hhonors1.hilton Content-Length: 0 Content-Type: text/plain; charset=UTF-8 Date: Fri, 11 Feb 2011 01:56:17 GMT Connection: close Set-Cookie: NSC_qse-qgt=44153db63660 |
Severity: | Information |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /en_US/hi/customersupport |
GET /en_US/hi/customersupport Host: www1.hilton.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 200 OK Server: Apache Content-Language: en-US Content-Type: text/html;charset=UTF-8 Cache-Control: private Date: Fri, 11 Feb 2011 01:56:10 GMT Connection: close Connection: Transfer-Encoding Set-Cookie: NSC_qse-qgt=44153db63660 Content-Length: 34015 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <meta http-equi ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /en_US/hi/customersupport |
GET /en_US/hi/customersupport Host: www1.hilton.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 200 OK Server: Apache Content-Language: en-US Content-Type: text/html;charset=UTF-8 Cache-Control: private Date: Fri, 11 Feb 2011 01:56:15 GMT Connection: close Connection: Transfer-Encoding Set-Cookie: NSC_qse-qgt=44153db63660 Content-Length: 68574 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <meta http-equi ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /en_US/hi/homeNew.do |
GET /en_US/hi/homeNew.do HTTP/1.1 Host: www1.hilton.com Proxy-Connection: keep-alive Referer: http://www1.hilton.com/en Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 200 OK Server: Apache Content-Language: en-US Content-Type: text/html;charset=UTF-8 Cache-Control: private Vary: Accept-Encoding Date: Fri, 11 Feb 2011 01:51:21 GMT Connection: close Set-Cookie: NSC_qse-qgt=44153db63660 Content-Length: 5573 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html> <head> <title></title> <script language="javascript" type="text/javascript"> function gotopage(destUrl) { parent.l ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /en_US/hi/hotel/BOSFDHF |
GET /en_US/hi/hotel/BOSFDHF Host: www1.hilton.com Proxy-Connection: keep-alive Referer: http://www.hilton.com/en Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 200 OK Server: Apache Content-Language: en-US Content-Type: text/html;charset=UTF-8 Cache-Control: private Vary: Accept-Encoding Date: Fri, 11 Feb 2011 01:59:39 GMT Connection: close Set-Cookie: NSC_qse-qgt=44153db63660 Content-Length: 81197 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <meta http ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /en_US/hi/hotel/BOSFDHF |
GET /en_US/hi/hotel/BOSFDHF Host: www1.hilton.com Proxy-Connection: keep-alive Referer: http://www1.hilton.com/en Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 302 Moved Temporarily Server: Apache Location: http://www.hilton.com/en Content-Length: 0 Content-Type: text/plain; charset=UTF-8 Date: Fri, 11 Feb 2011 01:59:49 GMT Connection: close Set-Cookie: NSC_qse-qgt=44153db63660 |
Severity: | Information |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /en_US/hi/hotel/BOSFDHF |
GET /en_US/hi/hotel/BOSFDHF Host: www1.hilton.com Proxy-Connection: keep-alive Referer: http://www1.hilton.com/en Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 404 Not Found Server: Apache Last-Modified: Tue, 01 Feb 2011 21:00:52 GMT ETag: "15843c-90a-d3e32900" Accept-Ranges: bytes Content-Type: text/html; charset=UTF-8 Cache-Control: private Date: Fri, 11 Feb 2011 02:00:31 GMT Connection: close Vary: Accept-Encoding Set-Cookie: NSC_qse-qgt=44153db63660 Content-Length: 2314 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html lang="en"> <head> <meta http-equiv="X-UA <meta http-equiv ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /en_US/hi/hotel/BOSFDHF |
GET /en_US/hi/hotel/BOSFDHF Host: www1.hilton.com Proxy-Connection: keep-alive Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 200 OK Server: Apache Content-Language: en-US Content-Type: text/html;charset=UTF-8 Cache-Control: private Vary: Accept-Encoding Date: Fri, 11 Feb 2011 02:02:36 GMT Connection: close Set-Cookie: NSC_qse-qgt=44153db63660 Content-Length: 81274 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <meta http ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /en_US/hi/hotel/BOSFDHF |
GET /en_US/hi/hotel/BOSFDHF Host: www1.hilton.com Proxy-Connection: keep-alive Referer: http://www1.hilton.com/en Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 302 Moved Temporarily Server: Apache Location: http://www.hilton.com/en Content-Length: 0 Content-Type: text/plain; charset=UTF-8 Date: Fri, 11 Feb 2011 02:01:59 GMT Connection: close Set-Cookie: NSC_qse-qgt=44153db63660 |
Severity: | Information |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /en_US/hi/media/images |
GET /en_US/hi/media/images Host: www1.hilton.com Proxy-Connection: keep-alive Referer: http://www1.hilton.com/en Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 200 OK Server: Apache Last-Modified: Tue, 01 Feb 2011 21:00:50 GMT ETag: "15c367-166-d3c4a480" Accept-Ranges: bytes Content-Length: 358 Content-Type: image/gif Cache-Control: max-age=37017 Expires: Fri, 11 Feb 2011 12:08:16 GMT Date: Fri, 11 Feb 2011 01:51:19 GMT Connection: close Set-Cookie: K3R7=3LJJ3QmEbCVHlmR P3P: CP="NON DSP ADM DEV PSD OUR IND STP PHY PRE NAV UNI" GIF89a:...............Sbo ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /en_US/hi/sitemap/index |
GET /en_US/hi/sitemap/index Host: www1.hilton.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 200 OK Server: Apache Content-Language: en-US Content-Type: text/html;charset=UTF-8 Cache-Control: private Date: Fri, 11 Feb 2011 01:56:10 GMT Connection: close Connection: Transfer-Encoding Set-Cookie: NSC_qse-qgt=44153db63660 Content-Length: 36519 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <meta http-equiv= ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /en_US/hp/index.do |
GET /en_US/hp/index.do HTTP/1.1 Host: www1.hilton.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 301 Moved Permanently Server: Apache Location: http://hamptoninn1.hilton Content-Length: 0 Content-Type: text/plain; charset=UTF-8 Date: Fri, 11 Feb 2011 01:56:16 GMT Connection: close Set-Cookie: NSC_qse-qgt=44153db63660 |
Severity: | Information |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /en_US/ht/index.do |
GET /en_US/ht/index.do HTTP/1.1 Host: www1.hilton.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 301 Moved Permanently Server: Apache Location: http://home2suites1 Content-Length: 0 Content-Type: text/plain; charset=UTF-8 Date: Fri, 11 Feb 2011 01:56:16 GMT Connection: close Set-Cookie: NSC_qse-qgt=44153db63660 |
Severity: | Information |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /en_US/hw/index.do |
GET /en_US/hw/index.do HTTP/1.1 Host: www1.hilton.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 301 Moved Permanently Server: Apache Location: http://homewoodsuites1 Content-Length: 0 Content-Type: text/plain; charset=UTF-8 Date: Fri, 11 Feb 2011 01:56:16 GMT Connection: close Set-Cookie: NSC_qse-qgt=44153db63660 |
Severity: | Information |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /en_US/ww/customersupport |
GET /en_US/ww/customersupport Host: www1.hilton.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 301 Moved Permanently Server: Apache Location: http://hiltonworldwide1 Content-Length: 0 Content-Type: text/plain; charset=UTF-8 Date: Fri, 11 Feb 2011 01:56:18 GMT Connection: close Set-Cookie: NSC_qse-qgt=44153db63660 |
Severity: | Information |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /es/hi/index.do |
GET /es/hi/index.do Host: www1.hilton.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 200 OK Server: Apache Content-Language: es Content-Type: text/html;charset=UTF-8 Cache-Control: private Date: Fri, 11 Feb 2011 01:56:23 GMT Connection: close Connection: Transfer-Encoding Set-Cookie: tslang=hi|es; Domain=.hilton.com; Path=/ Set-Cookie: cross-sell=hi; Domain=hilton.com; Path=/ Set-Cookie: NSC_qse-qgt=44153db63660 Content-Length: 94224 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <meta http-equiv="Content-Type" ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /fr/hi/index.do |
GET /fr/hi/index.do HTTP/1.1 Host: www1.hilton.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 200 OK Server: Apache Content-Language: fr Content-Type: text/html;charset=UTF-8 Cache-Control: private Date: Fri, 11 Feb 2011 01:56:25 GMT Connection: close Connection: Transfer-Encoding Set-Cookie: tslang=hi|fr; Domain=.hilton.com; Path=/ Set-Cookie: cross-sell=hi; Domain=hilton.com; Path=/ Set-Cookie: NSC_qse-qgt=44153db63660 Content-Length: 94917 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <meta http-equiv="Content-Type" ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /homepage/index.do |
GET /homepage/index.do HTTP/1.1 Host: www1.hilton.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 404 Not Found Server: Apache ETag: W/"2314-1296594052000" Last-Modified: Tue, 01 Feb 2011 21:00:52 GMT Content-Type: text/html; charset=UTF-8 Cache-Control: private Date: Fri, 11 Feb 2011 01:56:26 GMT Content-Length: 2314 Connection: close Set-Cookie: NSC_qse-qgt=44153db63660 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html lang="en"> <head> <meta http-equiv="X-UA <meta http-equiv ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /ts/en_US/hi/jsp/inc_home |
GET /ts/en_US/hi/jsp/inc_home Host: www1.hilton.com Proxy-Connection: keep-alive Referer: http://www1.hilton.com/en Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 200 OK Server: Apache Last-Modified: Tue, 01 Feb 2011 04:49:58 GMT ETag: "9a411b-c44-43ada980" Accept-Ranges: bytes Content-Type: text/xml Cache-Control: private Date: Fri, 11 Feb 2011 01:51:28 GMT Connection: close Vary: Accept-Encoding Set-Cookie: NSC_qse-qgt=44153db63660 Content-Length: 3140 <Document> <Left> <Item id="1"> <Title><font color="#160a67"><a href="http://twitter.com <Content><font color="#817c7c"><a href="ht ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /en_US/hi/customersupport |
GET /en_US/hi/customersupport Host: www1.hilton.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 200 OK Server: Apache Content-Language: en-US Content-Type: text/html;charset=UTF-8 Cache-Control: private Date: Fri, 11 Feb 2011 01:56:10 GMT Connection: close Connection: Transfer-Encoding Set-Cookie: NSC_qse-qgt=44153db63660 Content-Length: 34015 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <meta http-equi ...[SNIP]... <!--Affiliates changes start here - by kapil taneja--> <form name="frmSignin" action="/doxch.do?dst <!--Affiliates changes end here - by kapil taneja--> ...[SNIP]... <br/> <input id="PasswordPIN" name="password" type="password" tabindex="5" class="frmTextSignin"/><br/> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /en_US/hi/customersupport |
GET /en_US/hi/customersupport Host: www1.hilton.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 200 OK Server: Apache Content-Language: en-US Content-Type: text/html;charset=UTF-8 Cache-Control: private Date: Fri, 11 Feb 2011 01:56:15 GMT Connection: close Connection: Transfer-Encoding Set-Cookie: NSC_qse-qgt=44153db63660 Content-Length: 68574 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <meta http-equi ...[SNIP]... <!--Affiliates changes start here - by kapil taneja--> <form name="frmSignin" action="/doxch.do?dst <!--Affiliates changes end here - by kapil taneja--> ...[SNIP]... <br/> <input id="PasswordPIN" name="password" type="password" tabindex="5" class="frmTextSignin"/><br/> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /en_US/hi/hotel/BOSFDHF |
GET /en_US/hi/hotel/BOSFDHF Host: www1.hilton.com Proxy-Connection: keep-alive Referer: http://www.hilton.com/en Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 200 OK Server: Apache Content-Language: en-US Content-Type: text/html;charset=UTF-8 Cache-Control: private Vary: Accept-Encoding Date: Fri, 11 Feb 2011 01:59:39 GMT Connection: close Set-Cookie: NSC_qse-qgt=44153db63660 Content-Length: 81197 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <meta http ...[SNIP]... <!--Affiliates changes start here - by kapil taneja--> <form name="frmSignin" action="/doxch.do?dst <!--Affiliates changes end here - by kapil taneja--> ...[SNIP]... <br/> <input id="PasswordPIN" name="password" type="password" tabindex="5" class="frmTextSignin"/><br/> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /en_US/hi/hotel/BOSFDHF |
GET /en_US/hi/hotel/BOSFDHF Host: www1.hilton.com Proxy-Connection: keep-alive Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 200 OK Server: Apache Content-Language: en-US Content-Type: text/html;charset=UTF-8 Cache-Control: private Vary: Accept-Encoding Date: Fri, 11 Feb 2011 02:02:36 GMT Connection: close Set-Cookie: NSC_qse-qgt=44153db63660 Content-Length: 81274 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <meta http ...[SNIP]... <!--Affiliates changes start here - by kapil taneja--> <form name="frmSignin" action="/doxch.do?dst <!--Affiliates changes end here - by kapil taneja--> ...[SNIP]... <br/> <input id="PasswordPIN" name="password" type="password" tabindex="5" class="frmTextSignin"/><br/> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /en_US/hi/index.do |
GET /en_US/hi/index.do Host: www1.hilton.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 200 OK Server: Apache Content-Language: en-US Content-Type: text/html;charset=UTF-8 Cache-Control: private Date: Fri, 11 Feb 2011 01:56:09 GMT Connection: close Connection: Transfer-Encoding Set-Cookie: cross-sell=hi; Domain=hilton.com; Path=/ Set-Cookie: NSC_qse-qgt=44153db63660 Content-Length: 93487 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <meta http-equiv="Content-Type" ...[SNIP]... <div id="myreservations" style="display:none;"> <form name="myForm" id="myForm" method="post"> <div class="containReserv ...[SNIP]... </label><input id="Password_myRes" tabindex="9" name="password" class="frmTextMed" type="password"> </fieldset> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /en_US/hi/index.do |
GET /en_US/hi/index.do HTTP/1.1 Host: www1.hilton.com Proxy-Connection: keep-alive Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 200 OK Server: Apache Content-Language: en-US Content-Type: text/html;charset=UTF-8 Cache-Control: private Date: Fri, 11 Feb 2011 01:55:25 GMT Connection: close Vary: Accept-Encoding Set-Cookie: cross-sell=hi; Domain=hilton.com; Path=/ Set-Cookie: NSC_qse-qgt=44153db63660 Content-Length: 93697 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <meta http-equiv="Content-Type" ...[SNIP]... <!--Affiliates changes start here - by kapil taneja--> <form name="frmSignin" action="/doxch.do?dst <!--Affiliates changes end here - by kapil taneja--> ...[SNIP]... <br/> <input id="PasswordPIN" name="password" type="password" tabindex="5" class="frmTextSignin"/><br/> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /en_US/hi/index.do |
GET /en_US/hi/index.do HTTP/1.1 Host: www1.hilton.com Proxy-Connection: keep-alive Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Server: Apache Content-Language: en-US Content-Type: text/html;charset=UTF-8 Cache-Control: private Vary: Accept-Encoding Date: Fri, 11 Feb 2011 01:51:14 GMT Connection: close Set-Cookie: JSESSIONID=0ABC42E49 Set-Cookie: cross-sell=hi; Domain=hilton.com; Path=/ Set-Cookie: NSC_qse-qgt=44153db63660 Content-Length: 95047 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <meta http-equiv="Content-Type" ...[SNIP]... <!--Affiliates changes start here - by kapil taneja--> <form name="frmSignin" action="/doxch.do <!--Affiliates changes end here - by kapil taneja--> ...[SNIP]... <br/> <input id="PasswordPIN" name="password" type="password" tabindex="5" class="frmTextSignin"/><br/> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /en_US/hi/index.do |
GET /en_US/hi/index.do HTTP/1.1 Host: www1.hilton.com Proxy-Connection: keep-alive Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Server: Apache Content-Language: en-US Content-Type: text/html;charset=UTF-8 Cache-Control: private Vary: Accept-Encoding Date: Fri, 11 Feb 2011 01:51:15 GMT Connection: close Set-Cookie: JSESSIONID=DE3A2A627 Set-Cookie: cross-sell=hi; Domain=hilton.com; Path=/ Set-Cookie: NSC_qse-qgt=44153d5f3660 Content-Length: 95047 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <meta http-equiv="Content-Type" ...[SNIP]... <div id="myreservations" style="display:none;"> <form name="myForm" id="myForm" method="post"> <div class="containReserv ...[SNIP]... </label><input id="Password_myRes" tabindex="9" name="password" class="frmTextMed" type="password"> </fieldset> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /en_US/hi/index.do |
GET /en_US/hi/index.do HTTP/1.1 Host: www1.hilton.com Proxy-Connection: keep-alive Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Server: Apache Content-Language: en-US Content-Type: text/html;charset=UTF-8 Cache-Control: private Vary: Accept-Encoding Date: Fri, 11 Feb 2011 01:53:44 GMT Connection: close Set-Cookie: JSESSIONID=65965F417 Set-Cookie: cross-sell=hi; Domain=hilton.com; Path=/ Set-Cookie: NSC_qse-qgt=44153d5f3660 Content-Length: 95047 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <meta http-equiv="Content-Type" ...[SNIP]... <!--Affiliates changes start here - by kapil taneja--> <form name="frmSignin" action="/doxch.do <!--Affiliates changes end here - by kapil taneja--> ...[SNIP]... <br/> <input id="PasswordPIN" name="password" type="password" tabindex="5" class="frmTextSignin"/><br/> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /en_US/hi/index.do |
GET /en_US/hi/index.do HTTP/1.1 Host: www1.hilton.com Proxy-Connection: keep-alive Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Server: Apache Content-Language: en-US Content-Type: text/html;charset=UTF-8 Cache-Control: private Vary: Accept-Encoding Date: Fri, 11 Feb 2011 01:53:19 GMT Connection: close Set-Cookie: JSESSIONID=3E443454C Set-Cookie: cross-sell=hi; Domain=hilton.com; Path=/ Set-Cookie: NSC_qse-qgt=44153db63660 Content-Length: 95047 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <meta http-equiv="Content-Type" ...[SNIP]... <!--Affiliates changes start here - by kapil taneja--> <form name="frmSignin" action="/doxch.do <!--Affiliates changes end here - by kapil taneja--> ...[SNIP]... <br/> <input id="PasswordPIN" name="password" type="password" tabindex="5" class="frmTextSignin"/><br/> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /en_US/hi/index.do |
GET /en_US/hi/index.do HTTP/1.1 Host: www1.hilton.com Proxy-Connection: keep-alive Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Server: Apache Content-Language: en-US Content-Type: text/html;charset=UTF-8 Cache-Control: private Vary: Accept-Encoding Date: Fri, 11 Feb 2011 01:51:15 GMT Connection: close Set-Cookie: JSESSIONID=DE3A2A627 Set-Cookie: cross-sell=hi; Domain=hilton.com; Path=/ Set-Cookie: NSC_qse-qgt=44153d5f3660 Content-Length: 95047 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <meta http-equiv="Content-Type" ...[SNIP]... <!--Affiliates changes start here - by kapil taneja--> <form name="frmSignin" action="/doxch.do <!--Affiliates changes end here - by kapil taneja--> ...[SNIP]... <br/> <input id="PasswordPIN" name="password" type="password" tabindex="5" class="frmTextSignin"/><br/> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /en_US/hi/sitemap/index |
GET /en_US/hi/sitemap/index Host: www1.hilton.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 200 OK Server: Apache Content-Language: en-US Content-Type: text/html;charset=UTF-8 Cache-Control: private Date: Fri, 11 Feb 2011 01:56:10 GMT Connection: close Connection: Transfer-Encoding Set-Cookie: NSC_qse-qgt=44153db63660 Content-Length: 36519 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <meta http-equiv= ...[SNIP]... <!--Affiliates changes start here - by kapil taneja--> <form name="frmSignin" action="/doxch.do?dst <!--Affiliates changes end here - by kapil taneja--> ...[SNIP]... <br/> <input id="PasswordPIN" name="password" type="password" tabindex="5" class="frmTextSignin"/><br/> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /es/hi/index.do |
GET /es/hi/index.do Host: www1.hilton.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 200 OK Server: Apache Content-Language: es Content-Type: text/html;charset=UTF-8 Cache-Control: private Date: Fri, 11 Feb 2011 01:56:23 GMT Connection: close Connection: Transfer-Encoding Set-Cookie: tslang=hi|es; Domain=.hilton.com; Path=/ Set-Cookie: cross-sell=hi; Domain=hilton.com; Path=/ Set-Cookie: NSC_qse-qgt=44153db63660 Content-Length: 94224 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <meta http-equiv="Content-Type" ...[SNIP]... <div id="myreservations" style="display:none;"> <form name="myForm" id="myForm" method="post"> <div class="containReserv ...[SNIP]... </label><input id="Password_myRes" tabindex="9" name="password" class="frmTextMed" type="password"> </fieldset> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /es/hi/index.do |
GET /es/hi/index.do HTTP/1.1 Host: www1.hilton.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 200 OK Server: Apache Content-Language: es Content-Type: text/html;charset=UTF-8 Cache-Control: private Date: Fri, 11 Feb 2011 01:56:24 GMT Connection: close Connection: Transfer-Encoding Set-Cookie: tslang=hi|es; Domain=.hilton.com; Path=/ Set-Cookie: cross-sell=hi; Domain=hilton.com; Path=/ Set-Cookie: NSC_qse-qgt=44153db63660 Content-Length: 94345 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <meta http-equiv="Content-Type" ...[SNIP]... <div id="myreservations" style="display:none;"> <form name="myForm" id="myForm" method="post"> <div class="containReserv ...[SNIP]... </label><input id="Password_myRes" tabindex="9" name="password" class="frmTextMed" type="password"> </fieldset> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /es/hi/index.do |
GET /es/hi/index.do Host: www1.hilton.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 200 OK Server: Apache Content-Language: es Content-Type: text/html;charset=UTF-8 Cache-Control: private Date: Fri, 11 Feb 2011 01:56:23 GMT Connection: close Connection: Transfer-Encoding Set-Cookie: tslang=hi|es; Domain=.hilton.com; Path=/ Set-Cookie: cross-sell=hi; Domain=hilton.com; Path=/ Set-Cookie: NSC_qse-qgt=44153db63660 Content-Length: 94224 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <meta http-equiv="Content-Type" ...[SNIP]... <!--Affiliates changes start here - by kapil taneja--> <form name="frmSignin" action="/doxch.do?dst <!--Affiliates changes end here - by kapil taneja--> ...[SNIP]... <br/> <input id="PasswordPIN" name="password" type="password" tabindex="5" class="frmTextSignin"/><br/> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /fr/hi/index.do |
GET /fr/hi/index.do Host: www1.hilton.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 200 OK Server: Apache Content-Language: fr Content-Type: text/html;charset=UTF-8 Cache-Control: private Date: Fri, 11 Feb 2011 01:56:25 GMT Connection: close Connection: Transfer-Encoding Set-Cookie: tslang=hi|fr; Domain=.hilton.com; Path=/ Set-Cookie: cross-sell=hi; Domain=hilton.com; Path=/ Set-Cookie: NSC_qse-qgt=44153db63660 Content-Length: 95124 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <meta http-equiv="Content-Type" ...[SNIP]... <div id="myreservations" style="display:none;"> <form name="myForm" id="myForm" method="post"> <div class="containReserv ...[SNIP]... </label><input id="Password_myRes" tabindex="9" name="password" class="frmTextMed" type="password"> </fieldset> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /fr/hi/index.do |
GET /fr/hi/index.do HTTP/1.1 Host: www1.hilton.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 200 OK Server: Apache Content-Language: fr Content-Type: text/html;charset=UTF-8 Cache-Control: private Date: Fri, 11 Feb 2011 01:56:25 GMT Connection: close Connection: Transfer-Encoding Set-Cookie: tslang=hi|fr; Domain=.hilton.com; Path=/ Set-Cookie: cross-sell=hi; Domain=hilton.com; Path=/ Set-Cookie: NSC_qse-qgt=44153db63660 Content-Length: 94917 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <meta http-equiv="Content-Type" ...[SNIP]... <!--Affiliates changes start here - by kapil taneja--> <form name="frmSignin" action="/doxch.do?dst <!--Affiliates changes end here - by kapil taneja--> ...[SNIP]... <br/> <input id="PasswordPIN" name="password" type="password" tabindex="5" class="frmTextSignin"/><br/> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /fr/hi/index.do |
GET /fr/hi/index.do HTTP/1.1 Host: www1.hilton.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 200 OK Server: Apache Content-Language: fr Content-Type: text/html;charset=UTF-8 Cache-Control: private Date: Fri, 11 Feb 2011 01:56:25 GMT Connection: close Connection: Transfer-Encoding Set-Cookie: tslang=hi|fr; Domain=.hilton.com; Path=/ Set-Cookie: cross-sell=hi; Domain=hilton.com; Path=/ Set-Cookie: NSC_qse-qgt=44153db63660 Content-Length: 94917 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <meta http-equiv="Content-Type" ...[SNIP]... <div id="myreservations" style="display:none;"> <form name="myForm" id="myForm" method="post"> <div class="containReserv ...[SNIP]... </label><input id="Password_myRes" tabindex="9" name="password" class="frmTextMed" type="password"> </fieldset> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /en_US/hi/media/images |
GET /en_US/hi/media/images Host: www1.hilton.com Proxy-Connection: keep-alive Referer: http://www1.hilton.com/en Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 200 OK Server: Apache Last-Modified: Tue, 01 Feb 2011 21:00:50 GMT ETag: "15c367-166-d3c4a480" Accept-Ranges: bytes Content-Length: 358 Content-Type: image/gif Cache-Control: max-age=37017 Expires: Fri, 11 Feb 2011 12:08:16 GMT Date: Fri, 11 Feb 2011 01:51:19 GMT Connection: close Set-Cookie: K3R7=3LJJ3QmEbCVHlmR P3P: CP="NON DSP ADM DEV PSD OUR IND STP PHY PRE NAV UNI" GIF89a:...............Sbo ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /es/hi/index.do |
GET /es/hi/index.do Host: www1.hilton.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 200 OK Server: Apache Content-Language: es Content-Type: text/html;charset=UTF-8 Cache-Control: private Date: Fri, 11 Feb 2011 01:56:23 GMT Connection: close Connection: Transfer-Encoding Set-Cookie: tslang=hi|es; Domain=.hilton.com; Path=/ Set-Cookie: cross-sell=hi; Domain=hilton.com; Path=/ Set-Cookie: NSC_qse-qgt=44153db63660 Content-Length: 94224 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <meta http-equiv="Content-Type" ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /fr/hi/index.do |
GET /fr/hi/index.do HTTP/1.1 Host: www1.hilton.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 200 OK Server: Apache Content-Language: fr Content-Type: text/html;charset=UTF-8 Cache-Control: private Date: Fri, 11 Feb 2011 01:56:25 GMT Connection: close Connection: Transfer-Encoding Set-Cookie: tslang=hi|fr; Domain=.hilton.com; Path=/ Set-Cookie: cross-sell=hi; Domain=hilton.com; Path=/ Set-Cookie: NSC_qse-qgt=44153db63660 Content-Length: 94917 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <meta http-equiv="Content-Type" ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /en_US/hi/customersupport |
GET /en_US/hi/customersupport Host: www1.hilton.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 200 OK Server: Apache Content-Language: en-US Content-Type: text/html;charset=UTF-8 Cache-Control: private Date: Fri, 11 Feb 2011 01:56:11 GMT Connection: close Connection: Transfer-Encoding Set-Cookie: NSC_qse-qgt=44153db63660 Content-Length: 34015 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <meta http-equi ...[SNIP]... <li class="brandBarLi brandBarLi_WA" id="brandBarLi_WA"><a class="brandBarLiA" onmouseover="turnOnPopup( ...[SNIP]... <li class="brandBarLi brandBarLi_HV" id="brandBarLi_HV"><a class="brandBarLiA" onmouseover="turnOnPopup( ...[SNIP]... <li> <a href="http://assistive View Text Only </a> ...[SNIP]... <li> <a href="http://www Hilton Worldwide </a> ...[SNIP]... <li> <a href="http://www Careers </a> ...[SNIP]... <li> <a href="http://www Franchise Development </a> ...[SNIP]... <li> <a href="http://www Press & Media </a> ...[SNIP]... <li><a href="http://www.hilton ...[SNIP]... <NOSCRIPT> <IMG ALT="" BORDER="0" NAME="DCSIMG" WIDTH="1" HEIGHT="1" SRC="http://statse </NOSCRIPT> ...[SNIP]... <NOSCRIPT> <IMG ALT="" BORDER="0" NAME="DCSIMG" WIDTH="1" HEIGHT="1" SRC="http://statse </NOSCRIPT> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /en_US/hi/customersupport |
GET /en_US/hi/customersupport Host: www1.hilton.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 200 OK Server: Apache Content-Language: en-US Content-Type: text/html;charset=UTF-8 Cache-Control: private Date: Fri, 11 Feb 2011 01:56:16 GMT Connection: close Connection: Transfer-Encoding Set-Cookie: NSC_qse-qgt=44153db63660 Content-Length: 68574 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <meta http-equi ...[SNIP]... entities that can form legally binding contracts under applicable law. Without limiting the foregoing, the Site and the services offered by the Site are not available to minors. If you do not qualify, <a href="http://www.google ...[SNIP]... <li class="brandBarLi brandBarLi_WA" id="brandBarLi_WA"><a class="brandBarLiA" onmouseover="turnOnPopup( ...[SNIP]... <li class="brandBarLi brandBarLi_HV" id="brandBarLi_HV"><a class="brandBarLiA" onmouseover="turnOnPopup( ...[SNIP]... <li> <a href="http://assistive View Text Only </a> ...[SNIP]... <li> <a href="http://www Hilton Worldwide </a> ...[SNIP]... <li> <a href="http://www Careers </a> ...[SNIP]... <li> <a href="http://www Franchise Development </a> ...[SNIP]... <li> <a href="http://www Press & Media </a> ...[SNIP]... <li><a href="http://www.hilton ...[SNIP]... <NOSCRIPT> <IMG ALT="" BORDER="0" NAME="DCSIMG" WIDTH="1" HEIGHT="1" SRC="http://statse </NOSCRIPT> ...[SNIP]... <NOSCRIPT> <IMG ALT="" BORDER="0" NAME="DCSIMG" WIDTH="1" HEIGHT="1" SRC="http://statse </NOSCRIPT> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /en_US/hi/hotel/BOSFDHF |
GET /en_US/hi/hotel/BOSFDHF Host: www1.hilton.com Proxy-Connection: keep-alive Referer: http://www.hilton.com/en Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 200 OK Server: Apache Content-Language: en-US Content-Type: text/html;charset=UTF-8 Cache-Control: private Vary: Accept-Encoding Date: Fri, 11 Feb 2011 02:03:39 GMT Connection: close Set-Cookie: NSC_qse-qgt=44153db63660 Content-Length: 81167 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <meta http ...[SNIP]... <div class="hotelBox"> <a href="http://hilton <img src="/common/media/images ...[SNIP]... <div class="rightNavLink"> <a href="http://hilton Hotel Factsheet </a> ...[SNIP]... <div class="hotelBox"> <a href="http://hilton <img src="/common/media/images ...[SNIP]... <div class="rightNavLink"> <a href="http://hilton Folleto del hotel </a> ...[SNIP]... <div class="hotelBox"> <a href="http://hilton <img src="/common/media/images ...[SNIP]... <div class="rightNavLink"> <a href="http://hilton Bulletin d'informations </a> ...[SNIP]... <div class="hotelBox"> <a href="http://data <img src="/common/media/images ...[SNIP]... <div class="rightNavLink"> <a href="http://data Click Here to Download MeetingMatrix Certified Room diagrams. </a> ...[SNIP]... <li> <a href="https://www ...[SNIP]... <li> <a href="https://hilton ...[SNIP]... <div id="rightNavMarketing <a href="http://www.teamusa ...[SNIP]... <li class="brandBarLi brandBarLi_WA" id="brandBarLi_WA"><a class="brandBarLiA" onmouseover="turnOnPopup( ...[SNIP]... <li class="brandBarLi brandBarLi_HV" id="brandBarLi_HV"><a class="brandBarLiA" onmouseover="turnOnPopup( ...[SNIP]... <li> <a href="http://assistive View Text Only </a> ...[SNIP]... <li> <a href="http://www Hilton Worldwide </a> ...[SNIP]... <li> <a href="http://www Careers </a> ...[SNIP]... <li> <a href="http://www Franchise Development </a> ...[SNIP]... <li> <a href="http://www Press & Media </a> ...[SNIP]... <li><a href="http://www.hilton ...[SNIP]... <NOSCRIPT> <IMG ALT="" BORDER="0" NAME="DCSIMG" WIDTH="1" HEIGHT="1" SRC="http://statse </NOSCRIPT> ...[SNIP]... <NOSCRIPT> <IMG ALT="" BORDER="0" NAME="DCSIMG" WIDTH="1" HEIGHT="1" SRC="http://statse </NOSCRIPT> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /en_US/hi/hotel/BOSFDHF |
GET /en_US/hi/hotel/BOSFDHF Host: www1.hilton.com Proxy-Connection: keep-alive Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 200 OK Server: Apache Content-Language: en-US Content-Type: text/html;charset=UTF-8 Cache-Control: private Vary: Accept-Encoding Date: Fri, 11 Feb 2011 02:02:36 GMT Connection: close Set-Cookie: NSC_qse-qgt=44153db63660 Content-Length: 81274 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <meta http ...[SNIP]... <div class="hotelBox"> <a href="http://hilton <img src="/common/media/images ...[SNIP]... <div class="rightNavLink"> <a href="http://hilton Hotel Factsheet </a> ...[SNIP]... <div class="hotelBox"> <a href="http://hilton <img src="/common/media/images ...[SNIP]... <div class="rightNavLink"> <a href="http://hilton Folleto del hotel </a> ...[SNIP]... <div class="hotelBox"> <a href="http://hilton <img src="/common/media/images ...[SNIP]... <div class="rightNavLink"> <a href="http://hilton Bulletin d'informations </a> ...[SNIP]... <div class="hotelBox"> <a href="http://data <img src="/common/media/images ...[SNIP]... <div class="rightNavLink"> <a href="http://data Click Here to Download MeetingMatrix Certified Room diagrams. </a> ...[SNIP]... <li> <a href="https://hilton ...[SNIP]... <div id="rightNavMarketing <a href="http://www.teamusa ...[SNIP]... <li class="brandBarLi brandBarLi_WA" id="brandBarLi_WA"><a class="brandBarLiA" onmouseover="turnOnPopup( ...[SNIP]... <li class="brandBarLi brandBarLi_HV" id="brandBarLi_HV"><a class="brandBarLiA" onmouseover="turnOnPopup( ...[SNIP]... <li> <a href="http://assistive View Text Only </a> ...[SNIP]... <li> <a href="http://www Hilton Worldwide </a> ...[SNIP]... <li> <a href="http://www Careers </a> ...[SNIP]... <li> <a href="http://www Franchise Development </a> ...[SNIP]... <li> <a href="http://www Press & Media </a> ...[SNIP]... <li><a href="http://www.hilton ...[SNIP]... <NOSCRIPT> <IMG ALT="" BORDER="0" NAME="DCSIMG" WIDTH="1" HEIGHT="1" SRC="http://statse </NOSCRIPT> ...[SNIP]... <NOSCRIPT> <IMG ALT="" BORDER="0" NAME="DCSIMG" WIDTH="1" HEIGHT="1" SRC="http://statse </NOSCRIPT> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /en_US/hi/index.do |
GET /en_US/hi/index.do Host: www1.hilton.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 200 OK Server: Apache Content-Language: en-US Content-Type: text/html;charset=UTF-8 Cache-Control: private Date: Fri, 11 Feb 2011 01:56:09 GMT Connection: close Connection: Transfer-Encoding Set-Cookie: cross-sell=hi; Domain=hilton.com; Path=/ Set-Cookie: NSC_qse-qgt=44153db63660 Content-Length: 93487 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <meta http-equiv="Content-Type" ...[SNIP]... <li><a href="http://assistive ...[SNIP]... <noscript> <object classid="clsid:d27cdb6e <div id="flashAlt"> ...[SNIP]... <li><a href="http://www ...[SNIP]... <span><a href="http://hiltonplus <a href="http://hilton ...[SNIP]... <div id="newsalert1">You are viewing a static version of this content. In order to see an animated version, <a href="http://www.adobe ...[SNIP]... <li><a href="https://www201 ...[SNIP]... <li><a href="http://www ...[SNIP]... <noscript> <object classid="clsid:d27cdb6e codebase="http:/ width="385" height="70" id="rotator_v1" align="middle"> <div id="flashAlt"> ...[SNIP]... <li class="brandBarLi brandBarLi_WA" id="brandBarLi_WA"><a class="brandBarLiA" onmouseover="turnOnPopup( ...[SNIP]... <li class="brandBarLi brandBarLi_HV" id="brandBarLi_HV"><a class="brandBarLiA" onmouseover="turnOnPopup( ...[SNIP]... <li> <a href="http://assistive View Text Only </a> ...[SNIP]... <li> <a href="http://www Hilton Worldwide </a> ...[SNIP]... <li> <a href="http://www Careers </a> ...[SNIP]... <li> <a href="http://www Franchise Development </a> ...[SNIP]... <li> <a href="http://www Press & Media </a> ...[SNIP]... <li><a href="http://www.hilton ...[SNIP]... <NOSCRIPT> <IMG ALT="" BORDER="0" NAME="DCSIMG" WIDTH="1" HEIGHT="1" SRC="http://statse </NOSCRIPT> ...[SNIP]... <NOSCRIPT> <IMG ALT="" BORDER="0" NAME="DCSIMG" WIDTH="1" HEIGHT="1" SRC="http://statse </NOSCRIPT> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /es/hi/index.do |
GET /es/hi/index.do Host: www1.hilton.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 200 OK Server: Apache Content-Language: es Content-Type: text/html;charset=UTF-8 Cache-Control: private Date: Fri, 11 Feb 2011 01:56:23 GMT Connection: close Connection: Transfer-Encoding Set-Cookie: tslang=hi|es; Domain=.hilton.com; Path=/ Set-Cookie: cross-sell=hi; Domain=hilton.com; Path=/ Set-Cookie: NSC_qse-qgt=44153db63660 Content-Length: 94224 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <meta http-equiv="Content-Type" ...[SNIP]... <li><a href="http://assistive ...[SNIP]... <noscript> <object classid="clsid:d27cdb6e <div id="flashAlt"> ...[SNIP]... <span><a href="http://hiltonplus <a href="http://hilton ...[SNIP]... <div id="newsalert1">You are viewing a static version of this content. In order to see an animated version, <a href="http://www.adobe ...[SNIP]... <li><a href="http://www ...[SNIP]... <noscript> <object classid="clsid:d27cdb6e codebase="http:/ width="385" height="70" id="rotator_v1" align="middle"> <div id="flashAlt"> ...[SNIP]... <li class="brandBarLi brandBarLi_WA" id="brandBarLi_WA"><a class="brandBarLiA" onmouseover="turnOnPopup( ...[SNIP]... <li class="brandBarLi brandBarLi_HV" id="brandBarLi_HV"><a class="brandBarLiA" onmouseover="turnOnPopup( ...[SNIP]... <li> <a href="http://assistive View Text Only </a> ...[SNIP]... <li> <a href="http://www Hilton Worldwide </a> ...[SNIP]... <li> <a href="http://www Careers </a> ...[SNIP]... <li> <a href="http://www Franchise Development </a> ...[SNIP]... <li> <a href="http://www Press & Media </a> ...[SNIP]... <li><a href="http://www.hilton ...[SNIP]... <NOSCRIPT> <IMG ALT="" BORDER="0" NAME="DCSIMG" WIDTH="1" HEIGHT="1" SRC="http://statse </NOSCRIPT> ...[SNIP]... <NOSCRIPT> <IMG ALT="" BORDER="0" NAME="DCSIMG" WIDTH="1" HEIGHT="1" SRC="http://statse </NOSCRIPT> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /fr/hi/index.do |
GET /fr/hi/index.do Host: www1.hilton.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 200 OK Server: Apache Content-Language: fr Content-Type: text/html;charset=UTF-8 Cache-Control: private Date: Fri, 11 Feb 2011 01:56:25 GMT Connection: close Connection: Transfer-Encoding Set-Cookie: tslang=hi|fr; Domain=.hilton.com; Path=/ Set-Cookie: cross-sell=hi; Domain=hilton.com; Path=/ Set-Cookie: NSC_qse-qgt=44153db63660 Content-Length: 95124 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <meta http-equiv="Content-Type" ...[SNIP]... <li><a href="http://assistive ...[SNIP]... <noscript> <object classid="clsid:d27cdb6e <div id="flashAlt"> ...[SNIP]... <span><a href="http://hiltonplus <a href="http://hilton ...[SNIP]... <div id="newsalert1">You are viewing a static version of this content. In order to see an animated version, <a href="http://www.adobe ...[SNIP]... <li><a href="http://www ...[SNIP]... <noscript> <object classid="clsid:d27cdb6e codebase="http:/ width="385" height="70" id="rotator_v1" align="middle"> <div id="flashAlt"> ...[SNIP]... <li class="brandBarLi brandBarLi_WA" id="brandBarLi_WA"><a class="brandBarLiA" onmouseover="turnOnPopup( ...[SNIP]... <li class="brandBarLi brandBarLi_HV" id="brandBarLi_HV"><a class="brandBarLiA" onmouseover="turnOnPopup( ...[SNIP]... <li> <a href="http://assistive View Text Only </a> ...[SNIP]... <li> <a href="http://www Hilton Worldwide </a> ...[SNIP]... <li> <a href="http://www Careers </a> ...[SNIP]... <li> <a href="http://www Franchise Development </a> ...[SNIP]... <li> <a href="http://www Press & Media </a> ...[SNIP]... <li><a href="http://www.hilton ...[SNIP]... <NOSCRIPT> <IMG ALT="" BORDER="0" NAME="DCSIMG" WIDTH="1" HEIGHT="1" SRC="http://statse </NOSCRIPT> ...[SNIP]... <NOSCRIPT> <IMG ALT="" BORDER="0" NAME="DCSIMG" WIDTH="1" HEIGHT="1" SRC="http://statse </NOSCRIPT> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /en_US/hi/customersupport |
GET /en_US/hi/customersupport Host: www1.hilton.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 200 OK Server: Apache Content-Language: en-US Content-Type: text/html;charset=UTF-8 Cache-Control: private Date: Fri, 11 Feb 2011 01:56:10 GMT Connection: close Connection: Transfer-Encoding Set-Cookie: NSC_qse-qgt=44153db63660 Content-Length: 34015 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <meta http-equi ...[SNIP]... <a href="mailto:Guest_Assistance@hilton ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /en_US/hi/customersupport |
GET /en_US/hi/customersupport Host: www1.hilton.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 200 OK Server: Apache Content-Language: en-US Content-Type: text/html;charset=UTF-8 Cache-Control: private Date: Fri, 11 Feb 2011 01:56:15 GMT Connection: close Connection: Transfer-Encoding Set-Cookie: NSC_qse-qgt=44153db63660 Content-Length: 68574 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <meta http-equi ...[SNIP]... <a href="mailto:CopyrightClaim@hilton.com">CopyrightClaim@hilton.com</a> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www1.hilton.com |
Path: | /common/js/util.js |
GET /robots.txt HTTP/1.0 Host: www1.hilton.com |
HTTP/1.0 200 OK Server: Apache Last-Modified: Tue, 01 Feb 2011 21:00:56 GMT ETag: "158451-120-d4203200" Content-Type: text/plain; charset=UTF-8 Cache-Control: private Date: Fri, 11 Feb 2011 01:51:15 GMT Content-Length: 288 Connection: close Set-Cookie: NSC_qse-qgt=44153db63660 User-agent: Googlebot Disallow:/en_US/hs/ User-agent: Yahoo! Slurp Disallow:/en_US/hs/ User-agent: MSNbot Disallow:/en_US/hs/ User-agent: Scooter Disallow:/en_US/hs/ User-agent: Ask.com/Teoma Disa ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://www1.hilton.com |
Path: | /favicon.ico |
GET /favicon.ico HTTP/1.1 Host: www1.hilton.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JSESSIONID=0ABC42E49 |
HTTP/1.1 200 OK Server: Apache Last-Modified: Tue, 01 Feb 2011 21:00:51 GMT ETag: "15843e-57e-d3d3e6c0" Accept-Ranges: bytes Content-Type: text/plain; charset=UTF-8 Vary: Accept-Encoding Cache-Control: private, max-age=21848 Expires: Fri, 11 Feb 2011 07:55:31 GMT Date: Fri, 11 Feb 2011 01:51:23 GMT Connection: close Content-Length: 1406 ..............h.......(.. ...[SNIP]... |