1. Cross-site scripting (reflected)
1.1. https://www.shidirect.com/FeaturedBrands/FeaturedBrand.aspx [fname parameter]
3. SSL cookie without secure flag set
4. Cross-domain Referer leakage
5. Cookie without HttpOnly flag set
Severity: | High |
Confidence: | Certain |
Host: | https://www.shidirect.com |
Path: | /FeaturedBrands |
GET /FeaturedBrands Host: www.shidirect.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Connection: close Date: Wed, 05 Jan 2011 01:43:54 GMT Server: Microsoft-IIS/6.0 X-SID: 5 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Set-Cookie: .ASPXANONYMOUS=LPyG2 Set-Cookie: .SHIS=uhg2jeLV_LG40tg Set-Cookie: SBA=C9AeWj5nesap7erp0 Set-Cookie: .SHIFORMSAUTH=; expires=Tue, 12-Oct-1999 04:00:00 GMT; path=/; secure; HttpOnly Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 106658 Set-Cookie: BIGipServerShiDirect <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" > <html> <head id="ctl01_Head1"><title> www.shidirect.com - Featured Brand </title><meta http-equiv="X-UA ...[SNIP]... indow1", "RadWindow1", "radWindow_ctl01_Footer1 "", "" ,"Feedback", "", 0, 5, 1, true, null, null, null, "", "", null,true,null,"" ); /*]]> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://www.shidirect.com |
Path: | /FeaturedBrands |
GET /FeaturedBrands Host: www.shidirect.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Connection: close Date: Wed, 05 Jan 2011 01:44:08 GMT Server: Microsoft-IIS/6.0 X-SID: 2 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Set-Cookie: .ASPXANONYMOUS=-e Set-Cookie: .SHIS=uhg2jeLV_LG40tg Set-Cookie: SBA=C9AeWj5nesap7erp0 Set-Cookie: .SHIFORMSAUTH=; expires=Tue, 12-Oct-1999 04:00:00 GMT; path=/; secure; HttpOnly Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 106962 Set-Cookie: BIGipServerShiDirect <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" > <html> <head id="ctl01_Head1"><title> www.shidirect.com - Featured Brand </title><meta http-equiv="X-UA ...[SNIP]... ndow1", "RadWindow1", "radWindow_ctl01_Footer1 "", "" ,"Feedback", "", 0, 5, 1, true, null, null, null, "", "", null,true,null,"" ); /*]]> ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | https://www.shidirect.com |
Path: | /Default.aspx |
DEBUG /Default.aspx HTTP/1.0 Host: www.shidirect.com Command: start-debug |
HTTP/1.1 401 Unauthorized Connection: close Date: Wed, 05 Jan 2011 01:42:48 GMT Server: Microsoft-IIS/6.0 X-SID: 3 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 39 Set-Cookie: BIGipServerShiDirect Debug access denied to '/Default.aspx'. |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.shidirect.com |
Path: | /FeaturedBrands |
GET /FeaturedBrands Host: www.shidirect.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 302 Found Connection: close Date: Wed, 05 Jan 2011 01:42:46 GMT Server: Microsoft-IIS/6.0 X-SID: 2 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Location: /CustomError.htm Set-Cookie: .ASPXANONYMOUS=eSH7s Set-Cookie: .SHIS=uhg2jeLV_LG40tg Set-Cookie: SBA=C9AeWj5nesap7erp0 Set-Cookie: .SHIFORMSAUTH=; expires=Tue, 12-Oct-1999 04:00:00 GMT; path=/; secure; HttpOnly Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 135 Set-Cookie: BIGipServerShiDirect <html><head><title>Object moved</title></head><body <h2>Object moved to <a href="%2fCustomError.htm" </body></html> |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.shidirect.com |
Path: | /FeaturedBrands |
GET /FeaturedBrands Host: www.shidirect.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Connection: close Date: Wed, 05 Jan 2011 01:43:31 GMT Server: Microsoft-IIS/6.0 X-SID: 2 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Set-Cookie: .ASPXANONYMOUS=HXdky Set-Cookie: .SHIS=uhg2jeLV_LG40tg Set-Cookie: SBA=C9AeWj5nesap7erp0 Set-Cookie: .SHIFORMSAUTH=; expires=Tue, 12-Oct-1999 04:00:00 GMT; path=/; secure; HttpOnly Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 104998 Set-Cookie: BIGipServerShiDirect <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" > <html> <head id="ctl01_Head1"><title> www.shidirect.com - Featured Brand </title><meta http-equiv="X-UA ...[SNIP]... <td align="right" style="width:110px; height:40px;"> <img id="ctl01_ContentPla </td> ...[SNIP]... <div id="ctl01_ContentPla <img id="ctl01_ContentPla </div> ...[SNIP]... _repeaterProduct_ctl01 ...[SNIP]... _repeaterProduct_ctl02 ...[SNIP]... _repeaterProduct_ctl03 ...[SNIP]... _repeaterProduct_ctl01 ...[SNIP]... _repeaterProduct_ctl02 ...[SNIP]... _repeaterProduct_ctl03 ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.shidirect.com |
Path: | /FeaturedBrands |
GET /FeaturedBrands Host: www.shidirect.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 302 Found Connection: close Date: Wed, 05 Jan 2011 01:42:46 GMT Server: Microsoft-IIS/6.0 X-SID: 2 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Location: /CustomError.htm Set-Cookie: .ASPXANONYMOUS=eSH7s Set-Cookie: .SHIS=uhg2jeLV_LG40tg Set-Cookie: SBA=C9AeWj5nesap7erp0 Set-Cookie: .SHIFORMSAUTH=; expires=Tue, 12-Oct-1999 04:00:00 GMT; path=/; secure; HttpOnly Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 135 Set-Cookie: BIGipServerShiDirect <html><head><title>Object moved</title></head><body <h2>Object moved to <a href="%2fCustomError.htm" </body></html> |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.shidirect.com |
Path: | /FeaturedBrands |
GET /robots.txt HTTP/1.0 Host: www.shidirect.com |
HTTP/1.1 200 OK Content-Length: 114 Content-Type: text/plain Last-Modified: Fri, 09 Jul 2010 16:05:39 GMT Accept-Ranges: bytes ETag: "808bd692801fcb1:156a5c" Server: Microsoft-IIS/6.0 X-SID: 5 X-Powered-By: ASP.NET Date: Wed, 05 Jan 2011 01:42:48 GMT Connection: close Set-Cookie: BIGipServerShiDirect User-agent: * Disallow: # Sitemap file Sitemap: https://www.content.shi |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.shidirect.com |
Path: | /FeaturedBrands |
GET /FeaturedBrands Host: www.shidirect.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Connection: close Date: Wed, 05 Jan 2011 01:43:31 GMT Server: Microsoft-IIS/6.0 X-SID: 2 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Set-Cookie: .ASPXANONYMOUS=HXdky Set-Cookie: .SHIS=uhg2jeLV_LG40tg Set-Cookie: SBA=C9AeWj5nesap7erp0 Set-Cookie: .SHIFORMSAUTH=; expires=Tue, 12-Oct-1999 04:00:00 GMT; path=/; secure; HttpOnly Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 104998 Set-Cookie: BIGipServerShiDirect <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" > <html> <head id="ctl01_Head1"><title> www.shidirect.com - Featured Brand </title><meta http-equiv="X-UA ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.shidirect.com |
Path: | / |
Issued to: | www.shidirect.com |
Issued by: | VeriSign Class 3 Secure Server CA - G2 |
Valid from: | Wed Jun 16 19:00:00 CDT 2010 |
Valid to: | Sun Jun 16 18:59:59 CDT 2013 |
Issued to: | VeriSign Class 3 Secure Server CA - G2 |
Issued by: | VeriSign Trust Network |
Valid from: | Tue Mar 24 19:00:00 CDT 2009 |
Valid to: | Sun Mar 24 18:59:59 CDT 2019 |
Issued to: | VeriSign Trust Network |
Issued by: | VeriSign Trust Network |
Valid from: | Sun May 17 19:00:00 CDT 1998 |
Valid to: | Tue Aug 01 18:59:59 CDT 2028 |