3. Cross-domain script include
Severity: | High |
Confidence: | Certain |
Host: | http://www.people.com |
Path: | /people/article/0, |
GET /5197b%0d%0abebdf294213/article/0,,20464356,00 Host: www.people.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 301 Moved Permanently Date: Tue, 08 Feb 2011 18:41:05 GMT Location: http://www.people.com bebdf294213/article/0,,20464356,00 Content-Length: 347 Connection: close Content-Type: text/html; charset=iso-8859-1 <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>301 Moved Permanently</title> </head><body> <h1>Moved Permanently</h1> <p>The document has moved <a href="http://www.people ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.people.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: www.people.com |
HTTP/1.1 200 OK Date: Tue, 08 Feb 2011 18:41:04 GMT Server: Apache Last-Modified: Fri, 24 Sep 2010 16:23:49 GMT ETag: "373-cdb58f40" Accept-Ranges: bytes Content-Length: 883 Content-Type: application/xml Vary: X-Catmap-Header P3P: CP='PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA PRE CUR ADMa DEVa TAIo PSAo PSDo IVAo IVDo CONo TELo OTPi OUR UNRo PUBi OTRo IND DSP CAO COR' Connection: close <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="*" secure="false"/> <allow-access-from domain="img2.timeinc.net"/> <allow-access-from domain="img2-short.timeinc.net"/> <allow-access-from domain="*.aol.com"/> <allow-access-from domain="*.digitalcity.com"/> <allow-access-from domain="*.aolcdn.com"/> <allow-access-from domain="*.channel.aol.com"/> <allow-access-from domain="*.aimtoday.com"/> <allow-access-from domain="*.aimtoday.aim.com"/> <allow-access-from domain="*.dashboard.aim.com"/> <allow-access-from domain="*.aim.com"/> <allow-access-from domain="peopleconnection.aol.com"/> <allow-access-from domain="*.peoplecmg.com"/> <allow-access-from domain="*.myspacecdn.com"/> <allow-access-from domain="*.taaz.com" secure="true"/> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.people.com |
Path: | /people/article/0, |
GET /people/article/0, Host: www.people.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Tue, 08 Feb 2011 18:41:04 GMT Server: Apache Accept-Ranges: bytes Content-Type: text/html; charset=utf-8 Vary: Accept-Encoding,X-Catmap P3P: CP='PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA PRE CUR ADMa DEVa TAIo PSAo PSDo IVAo IVDo CONo TELo OTPi OUR UNRo PUBi OTRo IND DSP CAO COR' Connection: close Content-Length: 37603 <!--[if IE 5]> Vignette StoryServer 6.0 Tue Feb 08 13:34:29 2011 <![endif]--> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR ...[SNIP]... <link rel="canonical" href="/people/article/0, <script type="text/javascript" language="javascript" src="http://img.timeinc <script type="text/javascript" language="javascript" src="http://js.adsonar <script type="text/javascript" language="javascript" src="http://img2-short <script type="text/javascript" language="javascript" src="http://img2-short ...[SNIP]... </script> <script type="text/javascript" language="javascript" src="http://connect ...[SNIP]... </script> <script type="text/javascript" src="http://img.timeinc <script type="text/javascript" src="http://img.timeinc ...[SNIP]... </script> <script type="text/javascript" src="http://admin ...[SNIP]... <!-- revsci --> <script src="http://js.revsci.net ...[SNIP]... </script> <script type="text/javascript" src="http://edge ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.people.com |
Path: | /people/article/0, |
GET /robots.txt HTTP/1.0 Host: www.people.com |
HTTP/1.1 200 OK Date: Tue, 08 Feb 2011 18:41:04 GMT Server: Apache Last-Modified: Mon, 25 Feb 2008 23:16:18 GMT ETag: "18a-c25a1480" Accept-Ranges: bytes Content-Length: 394 Content-Type: text/plain; charset=utf-8 Vary: X-Catmap-Header P3P: CP='PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA PRE CUR ADMa DEVa TAIo PSAo PSDo IVAo IVDo CONo TELo OTPi OUR UNRo PUBi OTRo IND DSP CAO COR', CP='PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA PRE CUR ADMa DEVa TAIo PSAo PSDo IVAo IVDo CONo TELo OTPi OUR UNRo PUBi OTRo IND DSP CAO COR' Connection: close # Welcome to Pathfinder's robots.txt # # If you have any questions about indexing our site, # especially regarding more efficient or convenient # methods, please write to: # # ...[SNIP]... |