1.1. http://www.facebook.com/extern/login_status.php [Referer HTTP header]
Severity: | High |
Confidence: | Tentative |
Host: | http://www.facebook.com |
Path: | /extern/login_status.php |
GET /extern/login_status.php Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E) Accept-Encoding: gzip, deflate Proxy-Connection: Keep-Alive Host: www.facebook.com Referer: http://www.google.com |
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 X-Cnection: close Date: Wed, 24 Nov 2010 02:20:19 GMT Content-Length: 22 Invalid Application ID |
GET /extern/login_status.php Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E) Accept-Encoding: gzip, deflate Proxy-Connection: Keep-Alive Host: www.facebook.com Referer: http://www.google.com |
HTTP/1.1 200 OK P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p" Set-Cookie: datr=ZHbsTHQdVvJDbYx Content-Type: text/html; charset=utf-8 X-Cnection: close Date: Wed, 24 Nov 2010 02:20:20 GMT Content-Length: 989 <script>document.domain = "facebook.com";</script> var config = {"base_domain": ...[SNIP]... |
Severity: | High |
Confidence: | Tentative |
Host: | http://www.facebook.com |
Path: | /extern/login_status.php |
GET /extern/login_status.php Host: www.facebook.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 Connection: close Date: Wed, 24 Nov 2010 02:18:00 GMT Content-Length: 22 Invalid Application ID |
GET /extern/login_status.php Host: www.facebook.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p" Set-Cookie: datr=2HXsTKR4fW5fcDb Content-Type: text/html; charset=utf-8 Connection: close Date: Wed, 24 Nov 2010 02:18:00 GMT Content-Length: 992 <script>document.domain = "facebook.com";</script> var config = {"base_domain": ...[SNIP]... |