1. Cross-site scripting (reflected)
2. Cookie scoped to parent domain
2.1. http://www.groupon.com/san-jose/deals/pure-barre-los-gatos-1
2.2. http://www.groupon.com/user_demographics/demographic_form_banner.html
3. Cross-domain Referer leakage
4. Cross-domain script include
5. Cookie without HttpOnly flag set
5.1. http://www.groupon.com/san-jose/deals/pure-barre-los-gatos-1
5.2. http://www.groupon.com/user_demographics/demographic_form_banner.html
6. Content type incorrectly stated
Severity: | Information |
Confidence: | Certain |
Host: | http://www.groupon.com |
Path: | /user_demographics |
GET /user_demographics Host: www.groupon.com Proxy-Connection: keep-alive Referer: http://www.groupon.com x-requested-with: XMLHttpRequest content-type: application/x-www-form accept: text/javascript, text/html, application/xml, text/xml, */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: b=2148c93a-394a-11e0-aca6 |
HTTP/1.1 200 OK Server: nginx/0.7.65 Date: Tue, 01 Mar 2011 17:29:41 GMT Content-Type: text/html; charset=utf-8 Set-Cookie: subscriber_email=test Set-Cookie: adchemy_id=; path=/ Set-Cookie: division=san-jose; path=/; expires=Fri, 01-Apr-2011 17:29:41 GMT Set-Cookie: email=test%40fastdial.net Set-Cookie: mobile=; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT Set-Cookie: _thepoint=c34d720c80 Status: 200 ETag: "8ef21b84a48ea392c57 X-Runtime: 44 Cache-Control: private, max-age=0, must-revalidate Connection: close <div class='clearfix' id='above_main'> <div class='demographic_banner clearfix' id='demographic <form action="/user_demogr ...[SNIP]... <div title='test@fastdial test@fastdial.net16b2a<script>alert(1)< </div> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.groupon.com |
Path: | /san-jose/deals/pure |
GET /san-jose/deals/pure Host: www.groupon.com Proxy-Connection: keep-alive Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: b=2148c93a-394a-11e0-aca6 |
HTTP/1.1 200 OK Server: nginx/0.7.65 Date: Tue, 01 Mar 2011 17:13:00 GMT Content-Type: text/html; charset=utf-8 Set-Cookie: subscriber_email=test Set-Cookie: utm_term=; domain=.groupon.com; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT Set-Cookie: _tpmed=; domain=.groupon.com; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT Set-Cookie: utm_campaign=; domain=.groupon.com; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT Set-Cookie: b=; domain=.groupon.com; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT Set-Cookie: external_uid=; domain=.groupon.com; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT Set-Cookie: _tpref=; domain=.groupon.com; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT Set-Cookie: _tpoid=; domain=.groupon.com; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT Set-Cookie: _tpref2=; domain=.groupon.com; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT Set-Cookie: _tpuid=; domain=.groupon.com; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT Set-Cookie: utm_source=; domain=.groupon.com; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT Set-Cookie: utm_content=; domain=.groupon.com; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT Set-Cookie: utm_medium=; domain=.groupon.com; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT Set-Cookie: _tpcid=; domain=.groupon.com; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT Set-Cookie: _tpaid=newsletter; domain=.groupon.com; path=/; expires=Tue, 08-Mar-2011 17:13:00 GMT Set-Cookie: adchemy_id=; path=/ Set-Cookie: _tpmed=email; domain=.groupon.com; path=/; expires=Tue, 08-Mar-2011 17:13:00 GMT Set-Cookie: division=san-jose; path=/; expires=Fri, 01-Apr-2011 17:13:00 GMT Set-Cookie: s=29108ae4-4427-11e0-ae71 Set-Cookie: email=test%40fastdial.net Set-Cookie: mobile=; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT Set-Cookie: email=test%40fastdial.net Set-Cookie: _thepoint=c34d720c80 Status: 200 ETag: "2c59701df41e4f9c877 X-S-COOKIE: 29108ae4-4427-11e0-ae71 X-Runtime: 161 Cache-Control: private, max-age=0, must-revalidate Connection: close <!DOCTYPE html> <!--[if lt IE 7 ]> <html class="ie6" lang="en" xmlns:fb="http://www <!--[if IE 7 ]> <html class="ie7" lang ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.groupon.com |
Path: | /user_demographics |
GET /user_demographics Host: www.groupon.com Proxy-Connection: keep-alive Referer: http://www.groupon.com x-requested-with: XMLHttpRequest content-type: application/x-www-form accept: text/javascript, text/html, application/xml, text/xml, */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: b=2148c93a-394a-11e0-aca6 |
HTTP/1.1 200 OK Server: nginx/0.7.65 Date: Tue, 01 Mar 2011 17:13:24 GMT Content-Type: text/html; charset=utf-8 Set-Cookie: subscriber_email=test Set-Cookie: adchemy_id=; path=/ Set-Cookie: division=san-jose; path=/; expires=Fri, 01-Apr-2011 17:13:24 GMT Set-Cookie: email=test%40fastdial.net Set-Cookie: mobile=; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT Set-Cookie: _thepoint=c34d720c80 Status: 200 ETag: "7a503aa81cd310231b4 X-Runtime: 38 Cache-Control: private, max-age=0, must-revalidate Connection: close <div class='clearfix' id='above_main'> <div class='demographic_banner clearfix' id='demographic <form action="/user_demogr ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.groupon.com |
Path: | /san-jose/deals/pure |
GET /san-jose/deals/pure Host: www.groupon.com Proxy-Connection: keep-alive Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: b=2148c93a-394a-11e0-aca6 |
HTTP/1.1 200 OK Server: nginx/0.7.65 Date: Tue, 01 Mar 2011 17:13:00 GMT Content-Type: text/html; charset=utf-8 Set-Cookie: subscriber_email=test Set-Cookie: utm_term=; domain=.groupon.com; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT Set-Cookie: _tpmed=; domain=.groupon.com; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT Set-Cookie: utm_campaign=; domain=.groupon.com; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT Set-Cookie: b=; domain=.groupon.com; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT Set-Cookie: external_uid=; domain=.groupon.com; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT Set-Cookie: _tpref=; domain=.groupon.com; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT Set-Cookie: _tpoid=; domain=.groupon.com; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT Set-Cookie: _tpref2=; domain=.groupon.com; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT Set-Cookie: _tpuid=; domain=.groupon.com; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT Set-Cookie: utm_source=; domain=.groupon.com; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT Set-Cookie: utm_content=; domain=.groupon.com; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT Set-Cookie: utm_medium=; domain=.groupon.com; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT Set-Cookie: _tpcid=; domain=.groupon.com; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT Set-Cookie: _tpaid=newsletter; domain=.groupon.com; path=/; expires=Tue, 08-Mar-2011 17:13:00 GMT Set-Cookie: adchemy_id=; path=/ Set-Cookie: _tpmed=email; domain=.groupon.com; path=/; expires=Tue, 08-Mar-2011 17:13:00 GMT Set-Cookie: division=san-jose; path=/; expires=Fri, 01-Apr-2011 17:13:00 GMT Set-Cookie: s=29108ae4-4427-11e0-ae71 Set-Cookie: email=test%40fastdial.net Set-Cookie: mobile=; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT Set-Cookie: email=test%40fastdial.net Set-Cookie: _thepoint=c34d720c80 Status: 200 ETag: "2c59701df41e4f9c877 X-S-COOKIE: 29108ae4-4427-11e0-ae71 X-Runtime: 161 Cache-Control: private, max-age=0, must-revalidate Connection: close <!DOCTYPE html> <!--[if lt IE 7 ]> <html class="ie6" lang="en" xmlns:fb="http://www <!--[if IE 7 ]> <html class="ie7" lang ...[SNIP]... <head> <link href='http://assets1 <script type="text/javascript"> ...[SNIP]... <meta content='text/html <link href="http://feeds <link href="http://assets1 <link href="http://assets1 <!--[if IE 6]> ...[SNIP]... </script> <link href='http://assets1 </head> ...[SNIP]... <a href="/set_home_area?home ...[SNIP]... <a href="/set_home_area?home ...[SNIP]... <a href="/set_home_area?home ...[SNIP]... <a href="/set_home_area?home ...[SNIP]... <a href="/set_home_area?home ...[SNIP]... <a href="/set_home_area?home ...[SNIP]... <a href="/set_home_area?home ...[SNIP]... <a href="/set_home_area?home ...[SNIP]... <a href="/set_home_area?home ...[SNIP]... <a href="/set_home_area?home ...[SNIP]... </li> <a href="http://groupon.ca">Montreal</a> ...[SNIP]... <li class='country'><a href="http://www.groupon ...[SNIP]... <li class='country'><a href="http://www.groupon ...[SNIP]... <li class='country'><a href="http://www ...[SNIP]... <li class='country'><a href="http://www ...[SNIP]... <li class='country'><a href="http://www ...[SNIP]... <li class='country'><a href="http://www.citydeal ...[SNIP]... <li class='country'><a href="http://www.groupon ...[SNIP]... <li class='country'><a href="http://www.groupon ...[SNIP]... <li class='country'><a href="http://www.groupon ...[SNIP]... <li class='country'><a href="http://www.ubuyibuy ...[SNIP]... <li class='country'><a href="http://www.citydeal ...[SNIP]... <li class='country'><a href="http://www.citydeal ...[SNIP]... <li class='country'><a href="http://www.groupon ...[SNIP]... <li class='country'><a href="http://www.groupon ...[SNIP]... <li class='country'><a href="http://www ...[SNIP]... <li class='country'><a href="http://www ...[SNIP]... <li class='country'><a href="http://www.groupon ...[SNIP]... <li class='country'><a href="http://www.groupon ...[SNIP]... <li class='country'><a href="http://www.groupon ...[SNIP]... <li class='country'><a href="http://www.groupon ...[SNIP]... <li class='country'><a href="http://www.groupon ...[SNIP]... <li class='country'><a href="http://www ...[SNIP]... <li class='country'><a href="http://www ...[SNIP]... <div class='countdown <img alt="Hourglass002" class="hourglass" src="http://assets1 <ul id='counter'> ...[SNIP]... <span><img alt="" class="ib" height="28" src="http://assets1 ...[SNIP]... <li title = "Share with twitter." class="twitter_share"> <a href="http://twitter.com Tweet! </a> ...[SNIP]... <li><img alt="Pure-barre4_los ...[SNIP]... juggling hammers while riding a tandem bike through a swimming pool. Today's Groupon invites your physique to try a new kind of fusion exercise: for $40, you get four ballet-Pilates-weights classes at <a href="http://www ...[SNIP]... <p>Devised by Pure Barre founder <a href="http://purebarre ...[SNIP]... <p><a href="http://www.la2day Times</a> featured it as a way to lose holiday stuffing. 14 <a href="http://www.yelp.com ...[SNIP]... <li>Anyone with a background in ballet can attest to the ass-kicking results that barre work produces ... <a href="http://www.la.com ...[SNIP]... <li>If you're looking for a truly effective workout with energizing music and a positive vibe, you can't beat Pure Barre Los Gatos! ... <a href="http://www.yelp.com ...[SNIP]... <li class='twitter'><a href="http://twitter.com ...[SNIP]... <li><a href="http://www ...[SNIP]... <div class='map_container'> <img alt="Staticmap?size <div class='info_bubble' id='map_info_bubble'> ...[SNIP]... <div class="modal_top"><img alt="" class="modal_close" height="39" id="close" src="http://assets1 ...[SNIP]... <div class='map_container'> <img alt="Staticmap?size </div> ...[SNIP]... <br /> <a href="http://maps.google ...[SNIP]... <a href="/deals/poppy-hills ...[SNIP]... <a href="/deals/spring-has ...[SNIP]... <a href="/deals/cinequest?c ...[SNIP]... <a href="/deals/any-mountain ...[SNIP]... <a href="/deals/poppy-hills ...[SNIP]... <a href="/deals/spring-has ...[SNIP]... <a href="/deals/cinequest?c ...[SNIP]... <a href="/deals/any-mountain ...[SNIP]... <a href="/deals/poppy-hills ...[SNIP]... <a href="/deals/poppy-hills ...[SNIP]... <a href="/deals/spring-has ...[SNIP]... <a href="/deals/spring-has ...[SNIP]... <a href="/deals/cinequest?c ...[SNIP]... <a href="/deals/cinequest?c ...[SNIP]... <a href="/deals/any-mountain ...[SNIP]... <a href="/deals/any-mountain ...[SNIP]... <a href="/deals/poppy-hills ...[SNIP]... <a href="/deals/poppy-hills ...[SNIP]... <a href="/deals/spring-has ...[SNIP]... <a href="/deals/spring-has ...[SNIP]... <a href="/deals/cinequest?c ...[SNIP]... <a href="/deals/cinequest?c ...[SNIP]... <a href="/deals/any-mountain ...[SNIP]... <a href="/deals/any-mountain ...[SNIP]... <a href="/deals/poppy-hills ...[SNIP]... <a href="/deals/spring-has ...[SNIP]... <a href="/deals/cinequest?c ...[SNIP]... <a href="/deals/any-mountain ...[SNIP]... <a href="/san-jose/all" alt="$70 for 18 Holes of Golf at Poppy Hills Golf Course and NCGA Membership ($147 Value)" class="sidedeal G_event E-DealsNearBy_ClickV ...[SNIP]... <a href="/san-jose/all" class="G_event E-DealsNearBy_ClickV ...[SNIP]... <a href="/san-jose/all" class="G_event E-DealsNearBy_ClickV ...[SNIP]... <a href="/san-jose/all" class="G_event E-DealsNearBy_ClickV ...[SNIP]... </h3> <img alt="The Groupon Promise" src="http://assets1 <p> ...[SNIP]... <dt class='bucket works'> <a href="http://www ...[SNIP]... <dd> Learn how to get your business featured on Groupon and enjoy the benefits. <a href="http://www ...[SNIP]... <dd><a href="http://www.twitter ...[SNIP]... <dd><a href="http://www.facebook ...[SNIP]... <dd><a href="http://feeds ...[SNIP]... <dd><a href="http://www ...[SNIP]... <dd><a href="http://www.meetup ...[SNIP]... <dd><a href="http://www ...[SNIP]... <dd><a href="http://www.flickr ...[SNIP]... </div> <script src="http://ajax <script src="http://ajax <script src="http://ajax <script src="http://assets1 ...[SNIP]... <![endif]--> <script src="http://assets1 <script src="http://assets1 <script src="http://platform <script src="http://assets1 ...[SNIP]... </script> <script src="http://assets1 <script src="http://assets1 ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.groupon.com |
Path: | /san-jose/deals/pure |
GET /san-jose/deals/pure Host: www.groupon.com Proxy-Connection: keep-alive Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: b=2148c93a-394a-11e0-aca6 |
HTTP/1.1 200 OK Server: nginx/0.7.65 Date: Tue, 01 Mar 2011 17:13:00 GMT Content-Type: text/html; charset=utf-8 Set-Cookie: subscriber_email=test Set-Cookie: utm_term=; domain=.groupon.com; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT Set-Cookie: _tpmed=; domain=.groupon.com; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT Set-Cookie: utm_campaign=; domain=.groupon.com; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT Set-Cookie: b=; domain=.groupon.com; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT Set-Cookie: external_uid=; domain=.groupon.com; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT Set-Cookie: _tpref=; domain=.groupon.com; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT Set-Cookie: _tpoid=; domain=.groupon.com; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT Set-Cookie: _tpref2=; domain=.groupon.com; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT Set-Cookie: _tpuid=; domain=.groupon.com; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT Set-Cookie: utm_source=; domain=.groupon.com; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT Set-Cookie: utm_content=; domain=.groupon.com; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT Set-Cookie: utm_medium=; domain=.groupon.com; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT Set-Cookie: _tpcid=; domain=.groupon.com; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT Set-Cookie: _tpaid=newsletter; domain=.groupon.com; path=/; expires=Tue, 08-Mar-2011 17:13:00 GMT Set-Cookie: adchemy_id=; path=/ Set-Cookie: _tpmed=email; domain=.groupon.com; path=/; expires=Tue, 08-Mar-2011 17:13:00 GMT Set-Cookie: division=san-jose; path=/; expires=Fri, 01-Apr-2011 17:13:00 GMT Set-Cookie: s=29108ae4-4427-11e0-ae71 Set-Cookie: email=test%40fastdial.net Set-Cookie: mobile=; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT Set-Cookie: email=test%40fastdial.net Set-Cookie: _thepoint=c34d720c80 Status: 200 ETag: "2c59701df41e4f9c877 X-S-COOKIE: 29108ae4-4427-11e0-ae71 X-Runtime: 161 Cache-Control: private, max-age=0, must-revalidate Connection: close <!DOCTYPE html> <!--[if lt IE 7 ]> <html class="ie6" lang="en" xmlns:fb="http://www <!--[if IE 7 ]> <html class="ie7" lang ...[SNIP]... </div> <script src="http://ajax <script src="http://ajax <script src="http://ajax <script src="http://assets1 ...[SNIP]... <![endif]--> <script src="http://assets1 <script src="http://assets1 <script src="http://platform <script src="http://assets1 ...[SNIP]... </script> <script src="http://assets1 <script src="http://assets1 ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.groupon.com |
Path: | /san-jose/deals/pure |
GET /san-jose/deals/pure Host: www.groupon.com Proxy-Connection: keep-alive Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: b=2148c93a-394a-11e0-aca6 |
HTTP/1.1 200 OK Server: nginx/0.7.65 Date: Tue, 01 Mar 2011 17:13:00 GMT Content-Type: text/html; charset=utf-8 Set-Cookie: subscriber_email=test Set-Cookie: utm_term=; domain=.groupon.com; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT Set-Cookie: _tpmed=; domain=.groupon.com; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT Set-Cookie: utm_campaign=; domain=.groupon.com; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT Set-Cookie: b=; domain=.groupon.com; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT Set-Cookie: external_uid=; domain=.groupon.com; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT Set-Cookie: _tpref=; domain=.groupon.com; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT Set-Cookie: _tpoid=; domain=.groupon.com; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT Set-Cookie: _tpref2=; domain=.groupon.com; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT Set-Cookie: _tpuid=; domain=.groupon.com; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT Set-Cookie: utm_source=; domain=.groupon.com; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT Set-Cookie: utm_content=; domain=.groupon.com; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT Set-Cookie: utm_medium=; domain=.groupon.com; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT Set-Cookie: _tpcid=; domain=.groupon.com; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT Set-Cookie: _tpaid=newsletter; domain=.groupon.com; path=/; expires=Tue, 08-Mar-2011 17:13:00 GMT Set-Cookie: adchemy_id=; path=/ Set-Cookie: _tpmed=email; domain=.groupon.com; path=/; expires=Tue, 08-Mar-2011 17:13:00 GMT Set-Cookie: division=san-jose; path=/; expires=Fri, 01-Apr-2011 17:13:00 GMT Set-Cookie: s=29108ae4-4427-11e0-ae71 Set-Cookie: email=test%40fastdial.net Set-Cookie: mobile=; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT Set-Cookie: email=test%40fastdial.net Set-Cookie: _thepoint=c34d720c80 Status: 200 ETag: "2c59701df41e4f9c877 X-S-COOKIE: 29108ae4-4427-11e0-ae71 X-Runtime: 161 Cache-Control: private, max-age=0, must-revalidate Connection: close <!DOCTYPE html> <!--[if lt IE 7 ]> <html class="ie6" lang="en" xmlns:fb="http://www <!--[if IE 7 ]> <html class="ie7" lang ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.groupon.com |
Path: | /user_demographics |
GET /user_demographics Host: www.groupon.com Proxy-Connection: keep-alive Referer: http://www.groupon.com x-requested-with: XMLHttpRequest content-type: application/x-www-form accept: text/javascript, text/html, application/xml, text/xml, */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: b=2148c93a-394a-11e0-aca6 |
HTTP/1.1 200 OK Server: nginx/0.7.65 Date: Tue, 01 Mar 2011 17:13:24 GMT Content-Type: text/html; charset=utf-8 Set-Cookie: subscriber_email=test Set-Cookie: adchemy_id=; path=/ Set-Cookie: division=san-jose; path=/; expires=Fri, 01-Apr-2011 17:13:24 GMT Set-Cookie: email=test%40fastdial.net Set-Cookie: mobile=; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT Set-Cookie: _thepoint=c34d720c80 Status: 200 ETag: "7a503aa81cd310231b4 X-Runtime: 38 Cache-Control: private, max-age=0, must-revalidate Connection: close <div class='clearfix' id='above_main'> <div class='demographic_banner clearfix' id='demographic <form action="/user_demogr ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://www.groupon.com |
Path: | /deals/pure-barre-los |
GET /deals/pure-barre-los Host: www.groupon.com Proxy-Connection: keep-alive Referer: http://www.groupon.com x-requested-with: XMLHttpRequest content-type: application/x-www-form accept: text/javascript, text/html, application/xml, text/xml, */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: b=2148c93a-394a-11e0-aca6 |
HTTP/1.1 200 OK Server: nginx/0.7.65 Content-Type: application/json; charset=utf-8 Status: 200 ETag: "229722a1959db235139 X-Runtime: 15 Cache-Control: max-age=60, public Age: 36 Date: Tue, 01 Mar 2011 17:18:23 GMT Expires: Tue, 01 Mar 2011 17:18:47 GMT Connection: keep-alive Content-Length: 769 {"deal_day":3,"deal_hour" ...[SNIP]... |