1.1. http://tacoda.at.atwola.com/rtx/r.js [N cookie]
1.2. http://tacoda.at.atwola.com/rtx/r.js [si parameter]
2. Cookie scoped to parent domain
3. Cookie without HttpOnly flag set
Severity: | High |
Confidence: | Certain |
Host: | http://tacoda.at.atwola |
Path: | /rtx/r.js |
GET /rtx/r.js?cmd=DWT:DUY&si Host: tacoda.at.atwola.com Proxy-Connection: keep-alive Referer: http://an.tacoda.net/an Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ATTACID=a3Z0aWQ9MTZs |
HTTP/1.1 200 OK Date: Sat, 26 Feb 2011 00:22:21 GMT Server: Apache/1.3.37 (Unix) mod_perl/1.29 P3P: policyref="http://www P3P: policyref="http://www Cache-Control: max-age=900 Expires: Sat, 26 Feb 2011 00:37:21 GMT Set-Cookie: ATTACID=a3Z0aWQ9MTZs Set-Cookie: ANRTT=53615^1^1299284541 Set-Cookie: Tsid=0^1298679741 Set-Cookie: TData=99999|^|53575|53656 Set-Cookie: Anxd=x; expires=Sat, 26-Feb-11 06:22:21 GMT; path=/; domain=tacoda.at.atwola Set-Cookie: N=2:2d4ec7443dfa469e dd134ef5f12,d2e443c9307d12f368e Set-Cookie: ATTAC=a3ZzZWc9OTk5OT Set-Cookie: eadx=1; path=/; expires=Sun, 26-Feb-12 00:22:21 GMT; domain=tacoda.at.atwola ntCoent-Length: 170 Content-Type: application/x-javascript Content-Length: 170 var ANUT=1; var ANOO=0; var ANSR=1; var ANTID='16lsqii1n1a3cr'; var ANSL='99999|^|53575|53656 ANRTXR(); |
Severity: | High |
Confidence: | Certain |
Host: | http://tacoda.at.atwola |
Path: | /rtx/r.js |
GET /rtx/r.js?cmd=DWT:DUY&si=b91d7%0d%0a7626810d274&pi=L&xs=3&pu=http%253A/ Host: tacoda.at.atwola.com Proxy-Connection: keep-alive Referer: http://an.tacoda.net/an Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ATTACID=a3Z0aWQ9MTZs |
HTTP/1.1 200 OK Date: Sat, 26 Feb 2011 00:20:08 GMT Server: Apache/1.3.37 (Unix) mod_perl/1.29 P3P: policyref="http://www P3P: policyref="http://www Cache-Control: max-age=900 Expires: Sat, 26 Feb 2011 00:35:08 GMT Set-Cookie: ATTACID=a3Z0aWQ9MTZs Set-Cookie: ANRTT=53615^1^1299284408 Set-Cookie: Tsid=0^1298679608 7626810d274^1298679608^1298681408; path=/; expires=Sat, 26-Feb-11 00:50:08 GMT; domain=tacoda.at.atwola Set-Cookie: TData=99999|^|53575|53656 Set-Cookie: Anxd=x; expires=Sat, 26-Feb-11 06:20:08 GMT; path=/; domain=tacoda.at.atwola Set-Cookie: N=2:2d4ec7443dfa469e Set-Cookie: ATTAC=a3ZzZWc9OTk5OT Set-Cookie: eadx=1; path=/; expires=Sun, 26-Feb-12 00:20:08 GMT; domain=tacoda.at.atwola Cteonnt-Length: 170 Content-Type: application/x-javascript Content-Length: 170 var ANUT=1; var ANOO=0; var ANSR=1; var ANTID='16lsqii1n1a3cr'; var ANSL='99999|^|53575|53656 ANRTXR(); |
Severity: | Information |
Confidence: | Certain |
Host: | http://tacoda.at.atwola |
Path: | /rtx/r.js |
GET /rtx/r.js?cmd=DWT:DUY&si Host: tacoda.at.atwola.com Proxy-Connection: keep-alive Referer: http://an.tacoda.net/an Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ATTACID=a3Z0aWQ9MTZs |
HTTP/1.1 200 OK Date: Sat, 26 Feb 2011 00:19:24 GMT Server: Apache/1.3.37 (Unix) mod_perl/1.29 P3P: policyref="http://www P3P: policyref="http://www Cache-Control: max-age=900 Expires: Sat, 26 Feb 2011 00:34:24 GMT Set-Cookie: ATTACID=a3Z0aWQ9MTZs Set-Cookie: ANRTT=53615^1^1299284364 Set-Cookie: Tsid=0^1298679564 Set-Cookie: TData=99999|^|53575|53656 Set-Cookie: Anxd=x; expires=Sat, 26-Feb-11 06:19:24 GMT; path=/; domain=tacoda.at.atwola Set-Cookie: N=2:2d4ec7443dfa469e Set-Cookie: ATTAC=a3ZzZWc9OTk5OT Set-Cookie: eadx=1; path=/; expires=Sun, 26-Feb-12 00:19:24 GMT; domain=tacoda.at.atwola ntCoent-Length: 170 Content-Type: application/x-javascript Content-Length: 170 var ANUT=1; var ANOO=0; var ANSR=1; var ANTID='16lsqii1n1a3cr'; var ANSL='99999|^|53575|53656 ANRTXR(); |
Severity: | Information |
Confidence: | Certain |
Host: | http://tacoda.at.atwola |
Path: | /rtx/r.js |
GET /rtx/r.js?cmd=DWT:DUY&si Host: tacoda.at.atwola.com Proxy-Connection: keep-alive Referer: http://an.tacoda.net/an Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ATTACID=a3Z0aWQ9MTZs |
HTTP/1.1 200 OK Date: Sat, 26 Feb 2011 00:19:24 GMT Server: Apache/1.3.37 (Unix) mod_perl/1.29 P3P: policyref="http://www P3P: policyref="http://www Cache-Control: max-age=900 Expires: Sat, 26 Feb 2011 00:34:24 GMT Set-Cookie: ATTACID=a3Z0aWQ9MTZs Set-Cookie: ANRTT=53615^1^1299284364 Set-Cookie: Tsid=0^1298679564 Set-Cookie: TData=99999|^|53575|53656 Set-Cookie: Anxd=x; expires=Sat, 26-Feb-11 06:19:24 GMT; path=/; domain=tacoda.at.atwola Set-Cookie: N=2:2d4ec7443dfa469e Set-Cookie: ATTAC=a3ZzZWc9OTk5OT Set-Cookie: eadx=1; path=/; expires=Sun, 26-Feb-12 00:19:24 GMT; domain=tacoda.at.atwola ntCoent-Length: 170 Content-Type: application/x-javascript Content-Length: 170 var ANUT=1; var ANOO=0; var ANSR=1; var ANTID='16lsqii1n1a3cr'; var ANSL='99999|^|53575|53656 ANRTXR(); |
Severity: | Information |
Confidence: | Certain |
Host: | http://tacoda.at.atwola |
Path: | / |
TRACE / HTTP/1.0 Host: tacoda.at.atwola.com Cookie: edd247fb6fa578c0 |
HTTP/1.1 200 OK Date: Sat, 26 Feb 2011 00:19:25 GMT Server: Apache/1.3.37 (Unix) mod_perl/1.29 Connection: close Content-Type: message/http TRACE / HTTP/1.0 Connection: Keep-Alive Cookie: edd247fb6fa578c0 Host: tacoda.at.atwola.com X-Forwarded-For: 173.193.214.243 X-LB-Client-IP: 173.193.214.243 |