1.1. http://oascentral.wjla.com/RealMedia/ads/adstream.cap [c parameter]
1.2. http://oascentral.wjla.com/RealMedia/ads/adstream.cap [dv parameter]
2. Cookie without HttpOnly flag set
Severity: | High |
Confidence: | Certain |
Host: | http://oascentral.wjla |
Path: | /RealMedia/ads/adstream |
GET /RealMedia/ads/adstream Host: oascentral.wjla.com Proxy-Connection: keep-alive Referer: http://login.dotomi.com Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 302 Found Date: Wed, 16 Feb 2011 12:41:09 GMT Server: Apache/2.0.52 (Red Hat) P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p Set-Cookie: b4d66 e0b57d0f7da=1; expires=Tue, 30-Jun-15 00:00:00 GMT; path=/; domain=.wjla.com Location: /RealMedia/ads/Creatives Connection: close Content-Length: 0 Content-Type: text/plain Set-Cookie: NSC_d17efm_f_qppm_iuuq |
Severity: | High |
Confidence: | Certain |
Host: | http://oascentral.wjla |
Path: | /RealMedia/ads/adstream |
GET /RealMedia/ads/adstream Host: oascentral.wjla.com Proxy-Connection: keep-alive Referer: http://login.dotomi.com Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 500 Internal Server Error Date: Wed, 16 Feb 2011 12:41:09 GMT Server: Apache/2.0.52 (Red Hat) P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p OAS_DE_ERROR: error converting '6944d 2fff9b196cd' value to numeric value [i]. request to 'oascentral.wjla.com' for '/RealMedia/ads/adstream Cteonnt-Length: 620 Connection: close Content-Type: text/html; charset=iso-8859-1 Set-Cookie: NSC_d17efm_f_qppm_iuuq Cache-Control: private Content-Length: 620 <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>500 Internal Server Error</title> </head><body> <h1>Internal Server Error</h1> <p>The server encountered an internal error or mis ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://oascentral.wjla |
Path: | /RealMedia/ads/adstream |
GET /RealMedia/ads/adstream Host: oascentral.wjla.com Proxy-Connection: keep-alive Referer: http://login.dotomi.com Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 302 Found Date: Wed, 16 Feb 2011 12:40:53 GMT Server: Apache/2.0.52 (Red Hat) P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p Set-Cookie: dotomicookie=1; expires=Tue, 30-Jun-15 00:00:00 GMT; path=/; domain=.wjla.com Location: /RealMedia/ads/Creatives Connection: close Content-Length: 0 Content-Type: text/plain Set-Cookie: NSC_d17efm_f_qppm_iuuq |