1. Cross-site scripting (reflected)
1.1. http://tap.rubiconproject.com/partner/agent/rubicon/channels.js [cb parameter]
1.2. http://tap.rubiconproject.com/partner/agent/rubicon/insight.js [&ak parameter]
1.3. http://tap.rubiconproject.com/partner/agent/rubicon/insight.js [as parameter]
1.4. http://tap.rubiconproject.com/partner/agent/rubicon/insight.js [cb parameter]
2. Cookie scoped to parent domain
2.1. http://tap.rubiconproject.com/oz/feeds/invite-media-rtb/tokens/
2.2. http://tap.rubiconproject.com/oz/feeds/targus/profile
2.3. http://tap.rubiconproject.com/oz/sensor
2.4. http://tap.rubiconproject.com/partner/agent/rubicon/channels.js
2.5. http://tap.rubiconproject.com/partner/agent/rubicon/insight.js
3. Cookie without HttpOnly flag set
3.1. http://tap.rubiconproject.com/oz/feeds/invite-media-rtb/tokens/
3.2. http://tap.rubiconproject.com/oz/feeds/targus/profile
3.3. http://tap.rubiconproject.com/oz/sensor
3.4. http://tap.rubiconproject.com/partner/agent/rubicon/channels.js
3.5. http://tap.rubiconproject.com/partner/agent/rubicon/insight.js
Severity: | High |
Confidence: | Certain |
Host: | http://tap.rubiconproject |
Path: | /partner/agent/rubicon |
GET /partner/agent/rubicon Host: tap.rubiconproject.com Proxy-Connection: keep-alive Referer: http://www.salon.com Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.237 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: au=GIP9HWY4-MADS-10.208 |
HTTP/1.1 200 OK Date: Thu, 27 Jan 2011 02:06:33 GMT Server: TRP Apache-Coyote/1.1 Cache-Control: no-store, no-cache, must-revalidate Content-Type: text/javascript;charset Content-Length: 965 Cache-control: private Set-Cookie: khaos=GIPAEQ2D-C-IOYY; Domain=.rubiconproject Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/ Connection: close var oo_profile={ tokenType : "0", tracking : "", tags : "Education,Beauty,Arts and Entertainment,Hobbies and Interests,Family and Parenting", tagcloud : [ { tag: "Education", weight: ...[SNIP]... 2,2109,3812,2239,2190 { url: "http://adadvisor.net ] }; try { oz_onPixelsLoaded387e1;alert(1)/ } catch(ignore) {} |
Severity: | High |
Confidence: | Certain |
Host: | http://tap.rubiconproject |
Path: | /partner/agent/rubicon |
GET /partner/agent/rubicon Host: tap.rubiconproject.com Proxy-Connection: keep-alive Referer: http://www.salon.com Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.237 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: au=GIP9HWY4-MADS-10.208 |
HTTP/1.1 200 OK Date: Thu, 27 Jan 2011 02:06:16 GMT Server: TRP Apache-Coyote/1.1 Cache-Control: max-age=14400 Last-Modified: Thu, 27 Jan 2011 02:06:16 GMT Expires: Thu, 27 Jan 2011 06:06:16 GMT Content-Type: text/javascript;charset Content-Length: 334 Set-Cookie: khaos=GIPAEQ2D-C-IOYY; Domain=.rubiconproject Connection: close var rp_response = { context : { oz_api : "insight" ,oz_api_key : "KSN7-G95ZM3FD31297";alert(1)/ ,oz_ad_server : "oas" }, insight : {"behavior": "Toys and Games"} }; var rp_insight = rp_response.insight ; try { oz_onInsightLoaded(rp } catch( ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://tap.rubiconproject |
Path: | /partner/agent/rubicon |
GET /partner/agent/rubicon Host: tap.rubiconproject.com Proxy-Connection: keep-alive Referer: http://www.salon.com Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.237 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: au=GIP9HWY4-MADS-10.208 |
HTTP/1.1 200 OK Date: Thu, 27 Jan 2011 02:06:16 GMT Server: TRP Apache-Coyote/1.1 Cache-Control: max-age=14400 Last-Modified: Thu, 27 Jan 2011 02:06:16 GMT Expires: Thu, 27 Jan 2011 06:06:16 GMT Content-Type: text/javascript;charset Content-Length: 366 Set-Cookie: khaos=GIPAEQ2D-C-IOYY; Domain=.rubiconproject Connection: close var rp_response = { context : { oz_api : "insight" ,oz_api_key : "KSN7-G95ZM3FD" ,oz_partner_channel : "3029/3141" ,oz_ad_server : "oas70d95";alert(1)/ }, insight : {"behavior": "Toys and Games"} }; var rp_insight = rp_response.insight ; try { oz_onInsightLoaded(rp } catch(ignore) {} |
Severity: | High |
Confidence: | Certain |
Host: | http://tap.rubiconproject |
Path: | /partner/agent/rubicon |
GET /partner/agent/rubicon Host: tap.rubiconproject.com Proxy-Connection: keep-alive Referer: http://www.salon.com Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.237 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: au=GIP9HWY4-MADS-10.208 |
HTTP/1.1 200 OK Date: Thu, 27 Jan 2011 02:06:16 GMT Server: TRP Apache-Coyote/1.1 Cache-Control: max-age=14400 Last-Modified: Thu, 27 Jan 2011 02:06:16 GMT Expires: Thu, 27 Jan 2011 06:06:16 GMT Content-Type: text/javascript;charset Content-Length: 366 Set-Cookie: khaos=GIPAEQ2D-C-IOYY; Domain=.rubiconproject Connection: close var rp_response = { context : { oz_api : "insight" ,oz_api_key : "KSN7-G95ZM3FD" ,oz_partner_channel : "3029/3141" ,oz_ad_server : "oas" }, insight : {"behavior": "Toys and Games"} }; var rp_insight = rp_response.insight ; try { oz_onInsightLoaded6f94c;alert(1)/ } catch(ignore) {} |
Severity: | Information |
Confidence: | Certain |
Host: | http://tap.rubiconproject |
Path: | /oz/feeds/invite-media |
GET /oz/feeds/invite-media Host: tap.rubiconproject.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: put_1902=CfTKz1vxnM4 |
HTTP/1.1 302 Moved Temporarily Date: Thu, 27 Jan 2011 04:35:34 GMT Server: TRP Apache-Coyote/1.1 p3p: CP="NOI CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT" Location: http://pixel.rubicon Content-Length: 0 Cache-control: private Set-Cookie: cd=false; Domain=.rubiconproject Set-Cookie: dq=12|3|9|0; Expires=Fri, 27-Jan-2012 04:35:34 GMT; Path=/ Set-Cookie: lm="27 Jan 2011 04:35:34 GMT"; Version=1; Domain=.rubiconproject Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/ Connection: close Content-Type: text/plain; charset=UTF-8 |
Severity: | Information |
Confidence: | Certain |
Host: | http://tap.rubiconproject |
Path: | /oz/feeds/targus/profile |
GET /oz/feeds/targus/profile Host: tap.rubiconproject.com Proxy-Connection: keep-alive Referer: http://www.salon.com Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.237 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: au=GIP9HWY4-MADS-10.208 |
HTTP/1.1 204 No Content Date: Wed, 26 Jan 2011 20:13:40 GMT Server: TRP Apache-Coyote/1.1 p3p: CP="NOI CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT" Cache-control: private Set-Cookie: cd=false; Domain=.rubiconproject Set-Cookie: dq=11|2|9|0; Expires=Thu, 26-Jan-2012 20:13:41 GMT; Path=/ Set-Cookie: xdp_ti="26 Jan 2011 20:13:41 GMT"; Version=1; Max-Age=604800; Path=/ Set-Cookie: lm="26 Jan 2011 20:13:41 GMT"; Version=1; Domain=.rubiconproject Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/ Content-Length: 0 Connection: close Content-Type: text/plain; charset=UTF-8 |
Severity: | Information |
Confidence: | Certain |
Host: | http://tap.rubiconproject |
Path: | /oz/sensor |
GET /oz/sensor HTTP/1.1 Host: tap.rubiconproject.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: put_1902=CfTKz1vxnM4 |
HTTP/1.1 204 No Content Date: Thu, 27 Jan 2011 04:35:36 GMT Server: TRP Apache-Coyote/1.1 p3p: CP="NOI CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT" Cache-Control: no-cache Expires: Tue, 01 Jan 2008 00:12:30 GMT Cache-control: private Set-Cookie: cd=false; Domain=.rubiconproject Set-Cookie: dq=12|2|10|0; Expires=Fri, 27-Jan-2012 04:35:36 GMT; Path=/ Set-Cookie: cd=false; Domain=.rubiconproject Set-Cookie: lm="27 Jan 2011 04:35:36 GMT"; Version=1; Domain=.rubiconproject Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/ Content-Length: 0 Connection: close Content-Type: text/plain; charset=UTF-8 |
Severity: | Information |
Confidence: | Certain |
Host: | http://tap.rubiconproject |
Path: | /partner/agent/rubicon |
GET /partner/agent/rubicon Host: tap.rubiconproject.com Proxy-Connection: keep-alive Referer: http://www.salon.com Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.237 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: au=GIP9HWY4-MADS-10.208 |
HTTP/1.1 200 OK Date: Wed, 26 Jan 2011 20:13:40 GMT Server: TRP Apache-Coyote/1.1 Cache-Control: no-store, no-cache, must-revalidate Content-Type: text/javascript;charset Content-Length: 965 Cache-control: private Set-Cookie: khaos=GIPAEQ2D-C-IOYY; Domain=.rubiconproject Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/ Connection: close var oo_profile={ tokenType : "0", tracking : "", tags : "Family and Parenting,Arts and Entertainment,Beauty tagcloud : [ { tag: "Famil ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://tap.rubiconproject |
Path: | /partner/agent/rubicon |
GET /partner/agent/rubicon Host: tap.rubiconproject.com Proxy-Connection: keep-alive Referer: http://www.salon.com Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.237 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: au=GIP9HWY4-MADS-10.208 |
HTTP/1.1 200 OK Date: Wed, 26 Jan 2011 20:11:35 GMT Server: TRP Apache-Coyote/1.1 Cache-Control: max-age=14400 Last-Modified: Wed, 26 Jan 2011 20:11:35 GMT Expires: Thu, 27 Jan 2011 00:11:35 GMT Content-Type: text/javascript;charset Content-Length: 339 Set-Cookie: khaos=GIPAEQ2D-C-IOYY; Domain=.rubiconproject Connection: close var rp_response = { context : { oz_api : "insight" ,oz_api_key : "KSN7-G95ZM3FD" ,oz_partner_channel : "3029/3141" ,oz_ad_server : "oas" }, insight : {"beha ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://tap.rubiconproject |
Path: | /oz/feeds/invite-media |
GET /oz/feeds/invite-media Host: tap.rubiconproject.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: put_1902=CfTKz1vxnM4 |
HTTP/1.1 302 Moved Temporarily Date: Thu, 27 Jan 2011 04:35:34 GMT Server: TRP Apache-Coyote/1.1 p3p: CP="NOI CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT" Location: http://pixel.rubicon Content-Length: 0 Cache-control: private Set-Cookie: cd=false; Domain=.rubiconproject Set-Cookie: dq=12|3|9|0; Expires=Fri, 27-Jan-2012 04:35:34 GMT; Path=/ Set-Cookie: lm="27 Jan 2011 04:35:34 GMT"; Version=1; Domain=.rubiconproject Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/ Connection: close Content-Type: text/plain; charset=UTF-8 |
Severity: | Information |
Confidence: | Certain |
Host: | http://tap.rubiconproject |
Path: | /oz/feeds/targus/profile |
GET /oz/feeds/targus/profile Host: tap.rubiconproject.com Proxy-Connection: keep-alive Referer: http://www.salon.com Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.237 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: au=GIP9HWY4-MADS-10.208 |
HTTP/1.1 204 No Content Date: Wed, 26 Jan 2011 20:13:40 GMT Server: TRP Apache-Coyote/1.1 p3p: CP="NOI CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT" Cache-control: private Set-Cookie: cd=false; Domain=.rubiconproject Set-Cookie: dq=11|2|9|0; Expires=Thu, 26-Jan-2012 20:13:41 GMT; Path=/ Set-Cookie: xdp_ti="26 Jan 2011 20:13:41 GMT"; Version=1; Max-Age=604800; Path=/ Set-Cookie: lm="26 Jan 2011 20:13:41 GMT"; Version=1; Domain=.rubiconproject Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/ Content-Length: 0 Connection: close Content-Type: text/plain; charset=UTF-8 |
Severity: | Information |
Confidence: | Certain |
Host: | http://tap.rubiconproject |
Path: | /oz/sensor |
GET /oz/sensor HTTP/1.1 Host: tap.rubiconproject.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: put_1902=CfTKz1vxnM4 |
HTTP/1.1 204 No Content Date: Thu, 27 Jan 2011 04:35:36 GMT Server: TRP Apache-Coyote/1.1 p3p: CP="NOI CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT" Cache-Control: no-cache Expires: Tue, 01 Jan 2008 00:12:30 GMT Cache-control: private Set-Cookie: cd=false; Domain=.rubiconproject Set-Cookie: dq=12|2|10|0; Expires=Fri, 27-Jan-2012 04:35:36 GMT; Path=/ Set-Cookie: cd=false; Domain=.rubiconproject Set-Cookie: lm="27 Jan 2011 04:35:36 GMT"; Version=1; Domain=.rubiconproject Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/ Content-Length: 0 Connection: close Content-Type: text/plain; charset=UTF-8 |
Severity: | Information |
Confidence: | Certain |
Host: | http://tap.rubiconproject |
Path: | /partner/agent/rubicon |
GET /partner/agent/rubicon Host: tap.rubiconproject.com Proxy-Connection: keep-alive Referer: http://www.salon.com Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.237 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: au=GIP9HWY4-MADS-10.208 |
HTTP/1.1 200 OK Date: Wed, 26 Jan 2011 20:13:40 GMT Server: TRP Apache-Coyote/1.1 Cache-Control: no-store, no-cache, must-revalidate Content-Type: text/javascript;charset Content-Length: 965 Cache-control: private Set-Cookie: khaos=GIPAEQ2D-C-IOYY; Domain=.rubiconproject Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/ Connection: close var oo_profile={ tokenType : "0", tracking : "", tags : "Family and Parenting,Arts and Entertainment,Beauty tagcloud : [ { tag: "Famil ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://tap.rubiconproject |
Path: | /partner/agent/rubicon |
GET /partner/agent/rubicon Host: tap.rubiconproject.com Proxy-Connection: keep-alive Referer: http://www.salon.com Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.237 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: au=GIP9HWY4-MADS-10.208 |
HTTP/1.1 200 OK Date: Wed, 26 Jan 2011 20:11:35 GMT Server: TRP Apache-Coyote/1.1 Cache-Control: max-age=14400 Last-Modified: Wed, 26 Jan 2011 20:11:35 GMT Expires: Thu, 27 Jan 2011 00:11:35 GMT Content-Type: text/javascript;charset Content-Length: 339 Set-Cookie: khaos=GIPAEQ2D-C-IOYY; Domain=.rubiconproject Connection: close var rp_response = { context : { oz_api : "insight" ,oz_api_key : "KSN7-G95ZM3FD" ,oz_partner_channel : "3029/3141" ,oz_ad_server : "oas" }, insight : {"beha ...[SNIP]... |