3. Cross-site scripting (reflected)
4. Cookie scoped to parent domain
5. Cookie without HttpOnly flag set
7. HTML does not specify charset
8. Content type incorrectly stated
Severity: | High |
Confidence: | Certain |
Host: | http://bs.serving-sys.com |
Path: | /BurstingPipe/adServer.bs |
GET /BurstingPipe/adServer.bs Host: bs.serving-sys.com Proxy-Connection: keep-alive Referer: http://www.informati Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: eyeblaster=BWVal=&BWDate= |
HTTP/1.1 200 OK Cache-Control: no-cache, no-store Pragma: no-cache Content-Type: text/html Expires: Sun, 05-Jun-2005 22:00:00 GMT Vary: Accept-Encoding Set-Cookie: eyeblaster=BWVal=&BWDate= 2d03b3d1c8e; expires=Mon, 16-May-2011 16: 43:43 GMT; domain=bs.serving-sys.com Set-Cookie: A3=gIlWai190aCf00001 Set-Cookie: B3=8r8g0000000001tf7 Set-Cookie: u2=3a6c8499-0c84-46b7 P3P: CP="NOI DEVa OUR BUS UNI" Date: Tue, 15 Feb 2011 21:43:42 GMT Connection: close Content-Length: 2045 var ebPtcl="http://";var ebBigS="ds.serving-sys ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://bs.serving-sys.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: bs.serving-sys.com |
HTTP/1.1 200 OK Content-Type: text/xml Last-Modified: Thu, 21 Aug 2008 15:23:00 GMT Accept-Ranges: bytes ETag: "0e2c3cba13c91:0" P3P: CP="NOI DEVa OUR BUS UNI" Date: Tue, 15 Feb 2011 21:43:00 GMT Connection: close Content-Length: 100 <cross-domain-policy> <allow-access-from domain="*" secure="false" /> </cross-domain-policy> |
Severity: | Information |
Confidence: | Certain |
Host: | http://bs.serving-sys.com |
Path: | /BurstingPipe/adServer.bs |
GET /BurstingPipe/adServer.bs Host: bs.serving-sys.com Proxy-Connection: keep-alive Referer: http://www.informati Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: eyeblaster=BWVal=&BWDate= |
HTTP/1.1 200 OK Cache-Control: no-cache, no-store Pragma: no-cache Content-Type: text/html Expires: Sun, 05-Jun-2005 22:00:00 GMT Vary: Accept-Encoding Set-Cookie: eyeblaster=BWVal=&BWDate= Set-Cookie: A3=gIlWai190aCf00001 Set-Cookie: B3=8r8g0000000001tf7 Set-Cookie: u2=3a6c8499-0c84-46b7 P3P: CP="NOI DEVa OUR BUS UNI" Date: Tue, 15 Feb 2011 21:43:42 GMT Connection: close Content-Length: 2054 var ebPtcl="http://";var ebBigS="ds.serving-sys ...[SNIP]... \]/ig,ebRand).replace(/\[ ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://bs.serving-sys.com |
Path: | /BurstingPipe/adServer.bs |
GET /BurstingPipe/adServer.bs Host: bs.serving-sys.com Proxy-Connection: keep-alive Referer: http://www.v3.co.uk/v3 Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Cache-Control: no-cache, no-store Pragma: no-cache Content-Type: text/html Expires: Sun, 05-Jun-2005 22:00:00 GMT Vary: Accept-Encoding Set-Cookie: eyeblaster=BWVal=&BWDate= Set-Cookie: A3=gIlWai1a0aCf00001; expires=Mon, 16-May-2011 16:42:59 GMT; domain=.serving-sys.com; path=/ Set-Cookie: B3=8r8g0000000001tf; expires=Mon, 16-May-2011 16:42:59 GMT; domain=.serving-sys.com; path=/ Set-Cookie: C4=; expires=Mon, 16-May-2011 16:42:59 GMT; domain=.serving-sys.com; path=/ Set-Cookie: u2=58afad79-c764-4485 P3P: CP="NOI DEVa OUR BUS UNI" Date: Tue, 15 Feb 2011 21:42:59 GMT Connection: close Content-Length: 1951 var ebPtcl="http://";var ebBigS="ds.serving-sys ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://bs.serving-sys.com |
Path: | /BurstingPipe/adServer.bs |
GET /BurstingPipe/adServer.bs Host: bs.serving-sys.com Proxy-Connection: keep-alive Referer: http://www.v3.co.uk/v3 Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Cache-Control: no-cache, no-store Pragma: no-cache Content-Type: text/html Expires: Sun, 05-Jun-2005 22:00:00 GMT Vary: Accept-Encoding Set-Cookie: eyeblaster=BWVal=&BWDate= Set-Cookie: A3=gIlWai1a0aCf00001; expires=Mon, 16-May-2011 16:42:59 GMT; domain=.serving-sys.com; path=/ Set-Cookie: B3=8r8g0000000001tf; expires=Mon, 16-May-2011 16:42:59 GMT; domain=.serving-sys.com; path=/ Set-Cookie: C4=; expires=Mon, 16-May-2011 16:42:59 GMT; domain=.serving-sys.com; path=/ Set-Cookie: u2=58afad79-c764-4485 P3P: CP="NOI DEVa OUR BUS UNI" Date: Tue, 15 Feb 2011 21:42:59 GMT Connection: close Content-Length: 1951 var ebPtcl="http://";var ebBigS="ds.serving-sys ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://bs.serving-sys.com |
Path: | /BurstingPipe/adServer.bs |
GET /robots.txt HTTP/1.0 Host: bs.serving-sys.com |
HTTP/1.1 200 OK Content-Type: text/plain Last-Modified: Mon, 16 Jan 2006 20:19:44 GMT Accept-Ranges: bytes ETag: "0b02b30da1ac61:0" P3P: CP="NOI DEVa OUR BUS UNI" Date: Tue, 15 Feb 2011 21:43:00 GMT Connection: close Content-Length: 28 User-agent: * Disallow: / |
Severity: | Information |
Confidence: | Certain |
Host: | http://bs.serving-sys.com |
Path: | /BurstingPipe/adServer.bs |
GET /BurstingPipe/adServer.bs Host: bs.serving-sys.com Proxy-Connection: keep-alive Referer: http://www.v3.co.uk/v3 Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Cache-Control: no-cache, no-store Pragma: no-cache Content-Type: text/html Expires: Sun, 05-Jun-2005 22:00:00 GMT Vary: Accept-Encoding Set-Cookie: eyeblaster=BWVal=&BWDate= Set-Cookie: A3=gIlWai1a0aCf00001; expires=Mon, 16-May-2011 16:42:59 GMT; domain=.serving-sys.com; path=/ Set-Cookie: B3=8r8g0000000001tf; expires=Mon, 16-May-2011 16:42:59 GMT; domain=.serving-sys.com; path=/ Set-Cookie: C4=; expires=Mon, 16-May-2011 16:42:59 GMT; domain=.serving-sys.com; path=/ Set-Cookie: u2=58afad79-c764-4485 P3P: CP="NOI DEVa OUR BUS UNI" Date: Tue, 15 Feb 2011 21:42:59 GMT Connection: close Content-Length: 1951 var ebPtcl="http://";var ebBigS="ds.serving-sys ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://bs.serving-sys.com |
Path: | /BurstingPipe/adServer.bs |
GET /BurstingPipe/adServer.bs Host: bs.serving-sys.com Proxy-Connection: keep-alive Referer: http://www.v3.co.uk/v3 Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Cache-Control: no-cache, no-store Pragma: no-cache Content-Type: text/html Expires: Sun, 05-Jun-2005 22:00:00 GMT Vary: Accept-Encoding Set-Cookie: eyeblaster=BWVal=&BWDate= Set-Cookie: A3=gIlWai1a0aCf00001; expires=Mon, 16-May-2011 16:42:59 GMT; domain=.serving-sys.com; path=/ Set-Cookie: B3=8r8g0000000001tf; expires=Mon, 16-May-2011 16:42:59 GMT; domain=.serving-sys.com; path=/ Set-Cookie: C4=; expires=Mon, 16-May-2011 16:42:59 GMT; domain=.serving-sys.com; path=/ Set-Cookie: u2=58afad79-c764-4485 P3P: CP="NOI DEVa OUR BUS UNI" Date: Tue, 15 Feb 2011 21:42:59 GMT Connection: close Content-Length: 1951 var ebPtcl="http://";var ebBigS="ds.serving-sys ...[SNIP]... |