3. Cookie without HttpOnly flag set
4. HTML does not specify charset
5. Content type incorrectly stated
Severity: | High |
Confidence: | Firm |
Host: | http://cdn.goodwaygroup |
Path: | /DDLImpression.asp |
GET /DDLImpression.asp Host: cdn.goodwaygroup.com Proxy-Connection: keep-alive Referer: http://s0.2mdn.net Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 500 Internal Server Error Cache-control: Public Content-Type: text/html Date: Sun, 06 Mar 2011 02:05:19 GMT Expires: Sun, 06 Mar 2011 05:05:19 GMT Server: Microsoft-IIS/6.0 Set-Cookie: ASPSESSIONIDSSBADBQR X-Powered-By: ASP.NET Content-Length: 343 <font face="Arial" size=2> <p>Microsoft OLE DB Provider for SQL Server</font> <font face="Arial" size=2>error '80040e07'</font> <p> <font face="Arial" size=2>Conversion failed when converting the nva ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://cdn.goodwaygroup |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.1 Host: cdn.goodwaygroup.com Proxy-Connection: keep-alive Referer: http://s0.2mdn.net Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Accept-Ranges: bytes Content-Type: text/xml Date: Sun, 06 Mar 2011 02:03:39 GMT ETag: "3b1abd724087cb1:ee0" Last-Modified: Thu, 18 Nov 2010 16:48:38 GMT Server: ECS (dca/532A) X-Cache: HIT X-Powered-By: ASP.NET Content-Length: 1219 <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="motifcdn.doubleclick.net"/> <allow-access-from domain="m.doubleclick.net"/> <allow-access-from domain="m2.doubleclick.net"/> <allow-access-from domain="m3.doubleclick.net"/> <allow-access-from domain="m.2mdn.net"/> <allow-access-from domain="m1.2mdn.net"/> <allow-access-from domain="m2.2mdn.net"/> <allow-access-from domain="*.2mdn.net"/> <allow-access-from domain="betadfa.doubleclick.net"/> <allow-access-from domain="dfa.doubleclick.net"/> <allow-access-from domain="betadfp.doubleclick.net"/> <allow-access-from domain="dfp.doubleclick.net"/> <allow-access-from domain="motifcdn2.doubleclick.net"/> <allow-access-from domain="ad.doubleclick.net"/> <allow-access-from domain="*.doubleclick.net"/> <allow-access-from domain="*.doubleclick.com"/> <allow-access-from domain="2mdn.aolcdn.com"/> <allow-access-from domain="*.aolcdn.com"/> <allow-access-from domain="testbed.goodwaygroup.com"/> <allow-access-from domain="*.goodwaygroup.com"/> ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://cdn.goodwaygroup |
Path: | /DDLImpression.asp |
GET /DDLImpression.asp Host: cdn.goodwaygroup.com Proxy-Connection: keep-alive Referer: http://s0.2mdn.net Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Cache-control: Public Content-Type: text/html Date: Sun, 06 Mar 2011 02:04:48 GMT Expires: Sun, 06 Mar 2011 05:04:48 GMT Server: Microsoft-IIS/6.0 Set-Cookie: ASPSESSIONIDSSBADBQR X-Powered-By: ASP.NET Content-Length: 2941 Message=[[{"DartCamp ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://cdn.goodwaygroup |
Path: | /DDLImpression.asp |
GET /DDLImpression.asp Host: cdn.goodwaygroup.com Proxy-Connection: keep-alive Referer: http://s0.2mdn.net Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Cache-control: Public Content-Type: text/html Date: Sun, 06 Mar 2011 02:04:48 GMT Expires: Sun, 06 Mar 2011 05:04:48 GMT Server: Microsoft-IIS/6.0 Set-Cookie: ASPSESSIONIDSSBADBQR X-Powered-By: ASP.NET Content-Length: 2941 Message=[[{"DartCamp ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://cdn.goodwaygroup |
Path: | /DDLImpression.asp |
GET /DDLImpression.asp Host: cdn.goodwaygroup.com Proxy-Connection: keep-alive Referer: http://s0.2mdn.net Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Cache-control: Public Content-Type: text/html Date: Sun, 06 Mar 2011 02:04:48 GMT Expires: Sun, 06 Mar 2011 05:04:48 GMT Server: Microsoft-IIS/6.0 Set-Cookie: ASPSESSIONIDSSBADBQR X-Powered-By: ASP.NET Content-Length: 2941 Message=[[{"DartCamp ...[SNIP]... |